Method and device for improving privacy for following service

By employing unobtrusive encryption technology, the edge computing system can select appropriate edge computing devices for service migration when the location of end-user devices changes, thus solving the problems of performance degradation and privacy protection, and achieving efficient service migration and privacy protection.

CN121128136APending Publication Date: 2025-12-12INTEL CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380097867.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-06-28
Filing Date
2023-12-20
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In edge computing, changes in the location of end-user devices can lead to a decline in service performance, compromise user privacy, and the potential for third-party service providers to leak location information, thereby affecting user privacy and security.

Method used

By employing unintentional encryption technology, the computing key for encrypting user and location information is provided through the access device, allowing third-party service providers to process it without decryption, and selecting candidate edge computing devices for service migration, thus maintaining user privacy.

Benefits of technology

It improves service execution performance while protecting end-user privacy, and is suitable for zero-trust and low-trust environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121128136A_ABST
    Figure CN121128136A_ABST
Patent Text Reader

Abstract

Methods, apparatus, systems, and articles of manufacture for migrating cloud-based workloads are disclosed. The exemplary instructions cause the programmable circuitry to at least cause anonymous information corresponding to the user device to be transmitted to the network device and to migrate a virtual execution environment from the first computing device to the second computing device based on a response from the network device, the virtual execution environment executing at least a portion of the workload for the end user device.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] In recent years, edge computing nodes have been implemented to perform tasks to provide services to end-user devices. For example, when a user uses a service provided by a service provider (also known as a third-party service provider), one or more edge computing nodes perform one or more tasks and provide the output to the end-user device. This conserves the resources of the end-user device. If the end-user device is a mobile device (e.g., a smartphone, tablet, laptop, etc.), it can move away from the edge computing node currently performing the task for it. As the end-user device moves further away from the edge computing node, the performance, quality, and user experience of the service degrade (e.g., increased latency, reduced throughput, etc.). Attached Figure Description

[0002] Figure 1 An overview of the edge cloud configuration for edge computing is shown.

[0003] Figure 2 It illustrates the operational layer between endpoints, edge cloud, and cloud computing environments.

[0004] Figure 3 This is a block diagram of an exemplary environment for networking and services in an edge computing system.

[0005] Figure 4 The deployment of a virtual edge configuration in an edge computing system running across multiple edge nodes and multiple tenants is illustrated.

[0006] Figure 5 Various computing arrangements for deploying virtual execution environments in edge computing systems are shown.

[0007] Figure 6 Exemplary computing and communication use cases involving mobile access applications in an exemplary edge computing system are illustrated.

[0008] Figure 7 This is a block diagram of an exemplary system described in conjunction with the exemplary teachings disclosed herein, which is used to improve the privacy of a Follow-Me service.

[0009] Figure 8 yes Figure 7 A block diagram of an exemplary implementation of the processor circuitry in the image.

[0010] Figure 9 yes Figure 7 A block diagram of an exemplary implementation of a wireless access network intelligent controller circuit.

[0011] Figure 10This is a flowchart illustrating exemplary machine-readable instructions and / or operations that can be executed, instantiated, and / or implemented by programmable circuitry to achieve... Figure 8 Exemplary processor circuitry and / or Figure 9 An example of a wireless access network intelligent controller.

[0012] Figure 11 This is a block diagram of an exemplary processor platform including programmable circuitry configured to execute, instantiate, and / or implement computer-readable instructions and / or implement... Figure 10 Exemplary operations in [the document] to achieve Figure 9 An example of a wireless access network intelligent controller.

[0013] Figure 12A This is a block diagram of an exemplary implementation of an exemplary compute node, which can be deployed on... Figure 1 and / or Figure 7 One of the edge computing systems shown.

[0014] Figure 12B This is a block diagram of an exemplary processor platform including programmable circuitry configured to execute, instantiate, and / or implement computer-readable instructions and / or implement... Figure 10 Exemplary operations in [the document] to achieve Figure 8 An example processor circuit is shown in the figure.

[0015] Figure 13 yes Figure 8 and / or Figure 9 A block diagram of an exemplary implementation of a programmable circuit.

[0016] Figure 14 yes Figure 8 and / or Figure 9 A block diagram of an exemplary implementation of a programmable circuit.

[0017] Figure 15 This is a block diagram of an exemplary software / firmware / instruction distribution platform (e.g., one or more servers) used to distribute software, instructions, and / or firmware (e.g., corresponding to...) Figure 10 The exemplary machine-readable instructions in the document are distributed to end users and / or consumers (e.g., for licensing, selling and / or using), retailers (e.g., for selling, reselling, licensing and / or sublicensing) and / or original equipment manufacturers (OEMs) (e.g., for inclusion in products to be distributed to, for example, retailers and / or other end users such as direct purchase customers).

[0018] Generally, the same reference numerals will be used throughout the accompanying drawings (one or more drawings) and the accompanying written description to refer to the same or similar parts. The drawings are not necessarily drawn to scale. Detailed Implementation

[0019] The descriptive terms “first,” “second,” “third,” etc., are used herein to distinguish multiple elements or components that may be mentioned individually. Unless otherwise stated or understood based on their context, these descriptive terms are not intended to assign any priority or chronological order, but are merely labels used to refer to multiple elements or components separately to facilitate understanding of the disclosed instances. In some instances, the descriptive term “first” may be used to refer to one element in a specific embodiment, while the same element may be referred to in the claims using different descriptive terms (e.g., “second” or “third”). In these cases, it should be understood that these descriptive terms are used merely for the convenience of referring to multiple elements or components.

[0020] As used herein, the phrase “in communication” (including variations thereof) covers direct and / or indirect communication via one or more intermediate components and does not require direct physical communication (e.g., wired communication) and / or continuous communication, but additionally includes selective communication at periodic intervals, predetermined intervals, non-periodic intervals and / or one-off events.

[0021] As used herein, “programmable circuit” is defined to include: (i) one or more application-specific circuits (e.g., application-specific integrated circuits, ASICs) configured to perform one or more specific operations and including one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors); and / or (ii) one or more general-purpose semiconductor-based circuits that can be programmed with instructions to perform one or more specific functions and / or one or more operations and include one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors). Examples of programmable circuits include programmable microprocessors such as a central processing unit (CPU) (which can execute first instructions to perform one or more operations and / or functions), field programmable gate arrays (FPGAs) (which can be programmed with second instructions to instantiate one or more operations and / or functions corresponding to the first instructions through the configuration and / or construction of the FPGA), graphics processing units (GPUs) (which can execute first instructions to perform one or more operations and / or functions), digital signal processors (DSPs) (which can execute first instructions to perform one or more operations and / or functions), XPUs, network processing units (NPUs), one or more microcontrollers (which can execute first instructions to perform one or more operations and / or functions), and / or integrated circuits such as application-specific integrated circuits (ASICs). For example, an XPU can be implemented by a heterogeneous computing system that includes various types of programmable circuits (e.g., one or more FPGAs, one or more CPUs, one or more GPUs, one or more NPUs, one or more DSPs, etc. and / or any combination thereof) and orchestration technology (e.g., one or more application programming interfaces (APIs) that can assign one or more computing tasks to any one or more programmable circuits of various types that are suitable and can be used to perform one or more computing tasks.

[0022] The integrated circuit / circuit system used in this article is defined as one or more semiconductor packages containing one or more circuit elements (such as transistors, capacitors, inductors, resistors, current paths, diodes, etc.). For example, an integrated circuit can be implemented as one or more of the following: ASIC, FPGA, chip, microchip, programmable circuit, semiconductor substrate coupled with multiple circuit elements, system on chip (SoC), etc.

[0023] Workloads (such as application design running on computing devices) continue to shift from personal computers (PCs) and mobile devices to the cloud, where they are executed as part of service packages. For example, Microsoft... TM ("Teams") and Google TM Word processing and spreadsheet software from companies like Docs have been pushed from PCs to the cloud. In these instances, end-user devices can use applications maintained by service providers. The applications running on the end-user devices can communicate with corresponding producer applications in the cloud and / or at the edge, which execute one or more parts of the workload, rather than performing the workload on the end-user device. In these instances, edge and / or cloud computing devices install Virtual Execution Environments (VEEs) (e.g., one or more containers, virtual machines, applications, software, etc.) to execute workloads and transmit the results to the end-user devices to provide services to the end users.

[0024] While cloud and edge devices typically remain stationary, end-user devices can move from one location to another. For example, an end-user device can be carried from one location to another by a user or device (e.g., a drone, a car, etc.). Although service providers can initially select edge and / or cloud devices located near the end-user device when initiating a service, these devices may become less close as the end-user device moves. As the distance between the end-user device and the edge device increases, overall performance and / or user experience degrade. For example, the farther the end-user device is from the edge device, the lower the throughput, the higher the latency, the more packets are dropped, and so on. Therefore, protocols can be adapted to migrate the functionality of performing tasks from a first edge device to a second edge device closer to the end-user device to improve performance. These protocols can be referred to as “follow-up” services. In the examples disclosed herein, to improve performance and / or user experience, a virtual execution environment capable of performing workloads can be migrated from an edge device to a different edge device located closer to the end-user device.

[0025] To determine which edge devices (or edge devices) should be closer to the end-user device for service migration to improve performance, cloud / edge service providers may attempt to track the user's location. In some instances, cloud / edge service providers may request permission to track the user's location. If the user accepts the request, the cloud / edge service provider collects location information from the access network (e.g., base stations, cellular networks, private networks, access points, etc.) to migrate the virtual execution environment from one edge device to another closer to the end-user device. However, some users may not want service providers to know and / or track their location. For example, some users may not want to expose their privacy to third-party service providers. Furthermore, some users may be concerned that data breaches and / or security vulnerabilities of third-party cloud / edge service providers could expose their location to attackers.

[0026] The examples disclosed herein maintain the privacy of user and / or location information associated with end-user devices while still facilitating the migration of third-party services within cloud and / or edge networks. The examples disclosed herein enable protocols at access devices in the access network (e.g., base stations, cellular base stations, access points, etc.) to inadvertently provide encrypted user and / or location information corresponding to the end-user device, along with a computational key, to a third-party service provider. Inadvertent encryption allows the device to use the computational key to acquire and process decrypted data without decrypting and / or otherwise determining the decrypted information. Thus, without decrypting the encrypted location and / or user information and / or without being able to otherwise determine the encrypted location and / or user information, the third-party service provider can use the computational key to process the encrypted location and / or user information to identify a set of candidate edge and / or cloud computing devices near the end-user device. Therefore, when the actual location and / or identification of the end-user of the end-user device cannot be confirmed, the third-party edge device can provide edge and / or cloud computing devices as candidates for service migration. The third-party service provider provides candidate edge and / or cloud computing nodes to the access device, and the access device decrypts the encrypted response and selects one of the candidates to migrate the service. Access devices send migration instructions to edge and / or compute nodes and / or their coordinators to migrate services from previous edge and / or compute nodes to selected edge and / or compute nodes. This service migration improves service performance without compromising (e.g., preserving) end-user privacy. The examples disclosed herein can be applied in zero-trust or low-trust environments.

[0027] Figure 1This is a block diagram 100 illustrating an overview of a configuration for edge computing, which includes a processing layer referred to as the “edge cloud” in many instances. As shown, the edge cloud 110 is commonly located at an edge location, such as an access point, base station, or access device 140, a local processing center 150, or a central office 120, and therefore may include multiple examples of entities, devices, and equipment. Compared to the cloud data center 130, the edge cloud 110 is located closer to endpoint (consumer and producer) data sources and / or endpoints 160 (e.g., autonomous vehicles 161, user equipment 162, commercial and industrial equipment 163, video capture equipment 164, drones 165, smart city and building equipment 166, sensors and Internet of Things (IoT) devices 167, consumer / customer presence equipment (CPE) 168, etc.). Consumer / customer presence equipment 168 may include gateways or home edge devices. In some instances, mobile devices 162, vehicles 161, IoT devices 167, home computing devices, etc., can connect to CPE 168. The computing, memory, and storage resources provided at the edge of the edge cloud 110 are crucial for providing ultra-low latency response times for the services and functions used by the endpoint data source 160 and for reducing network backhaul traffic from the edge cloud 110 to the cloud data center 130 (thus improving energy consumption and overall network usage, among other benefits). In some instances, endpoint 160 may be included in the edge cloud 110 as part of its near edge.

[0028] Computing, memory, and storage resources are scarce and typically decrease with edge location (e.g., less processing resources are available at a consumer endpoint device than at a base station and at a central office). However, the closer an edge location is to the endpoint (e.g., user equipment, UE), the more space and power constraints tend to be. Therefore, edge computing attempts to reduce the amount of resources required for network services by distributing more resources that are geographically and temporally closer to the network access point. In this way, edge computing attempts to either direct computing resources to workload data or vice versa, where appropriate.

[0029] The following describes various aspects of an edge cloud architecture that encompasses multiple potential deployments and addresses limitations that network operators or service providers may face in their respective infrastructures. These include configuration variations based on edge location (as the performance and capabilities of, for example, base station-level edges may be more constrained in multi-tenant scenarios); configuration based on resource types such as compute, memory, storage, fabric, or acceleration resources available at the edge location, location layer, or location group; service, security, management, and coordination capabilities; and related objectives for achieving the availability and performance of end-user services. These deployments can handle processing at network layers, which can be considered "device edge," "near edge," "immediately adjacent edge," "local edge," "mid edge," "user equipment edge," or "far edge," depending on latency, distance, and timing characteristics.

[0030] Edge computing is an emerging paradigm where computation typically occurs at or near the “edge” of a network, using computing platforms (e.g., x86 or ARM computing hardware architectures) implemented at base stations, gateways, network routers, or other devices closer to the endpoints that generate and use data. For example, an edge gateway server might be equipped with pools of memory and storage resources to perform real-time computation for low-latency use cases (e.g., autonomous driving or video surveillance) of connected client devices. Alternatively, a base station could be enhanced with computing and acceleration resources to directly handle service workloads for connected user devices without requiring further data transmission via a backhaul network. Or, as another example, central office network management hardware could be replaced with standardized computing hardware that performs virtualized network functions and provides computing resources for the execution of service and consumer functions for connected devices. In edge computing networks, there may be scenarios where computing resources are “moved” to data and scenarios where data is “moved” to computing resources. Alternatively, as an example, the computing, acceleration, and network resources of a base station can be provided to expand as needed to meet workload demands by activating dormant capacity (which requires reservation and can be expanded on demand), thereby addressing extreme and emergency situations or extending the lifespan of deployed resources within a significantly extended realized lifespan.

[0031] Figure 2 This illustrates the operational layer between endpoints, edge cloud, and cloud computing environments. Specifically, Figure 2An example of computing use case 205 is illustrated, utilizing the edge cloud 110 across multiple illustrative network computing layers. These layers begin with an endpoint (device and item) layer 200, which connects to the edge cloud 110 for data creation, analysis, and data usage activities. The edge cloud 110 can span multiple network layers, such as the edge device layer 210 (containing gateways, locally deployed servers, or network devices (nodes 215) located in the physically nearest edge system); the network access layer 220 (covering base stations, radio processors, network hubs, regional data centers (DCs), or local network devices (devices 225)); and any devices, apparatuses, or nodes located in between (not shown in detail in layer 212). Network communication within and between the layers of the edge cloud 110 can be conducted via any number of wired or wireless media (including via connection architectures and technologies not shown).

[0032] The range of latency instances caused by network communication distance and processing time limitations can include: less than 1 millisecond (ms) at endpoint layer 200; less than 5 ms at edge device layer 210; and even 10 ms to 40 ms when communicating with nodes at network access layer 220. Beyond the edge cloud 110 are the core network 230 and cloud data center 240 layers, each with longer latency (e.g., ranging from 50-60 ms at core network layer 230 to 100 ms or longer at cloud data center layer). Therefore, operations at core network data center 235 or cloud data center 245 (with at least 50 ms to 100 ms or longer latency) will not be able to perform many of the time-critical functions of use case 205. Each of these latency values ​​is provided for illustrative and comparative purposes; it should be understood that the use of other access network media and technologies can further reduce latency. In some instances, relative to network sources and destinations, corresponding portions of a network can be categorized into “device edge” layers, “immediate edge” layers, “local edge” layers, “near edge” layers, “mid edge” layers, or “far edge” layers. For example, from the perspective of core network data center 235 or cloud data center 245, the central office or content data network can be considered to be located within the “near edge” layer (“close” to the cloud, with high latency values ​​when communicating with devices and endpoints in use case 205), while access points, base stations, locally deployed servers, or network gateways can be considered to be located within the “far edge” layer (“far” from the cloud, with low latency values ​​when communicating with devices and endpoints in use case 205). It should be understood that other classifications of a particular network layer as “immediate edge,” “local” edge, “near” edge, “mid edge,” or “far edge” can be based on latency, distance, number of network hops, or other measurable characteristics measured from sources in any of network layers 200-240.

[0033] Because multiple services leverage the edge cloud, various use cases 205 can access resources under the pressure of usage from input flows. To achieve low latency, services executing within the edge cloud 110 balance varying requirements by: (a) priority (throughput or latency) and quality of service (QoS) (e.g., traffic for autonomous vehicles may have higher priority than temperature sensors in terms of response time requirements; or there may be performance sensitivities / bottlenecks at compute / accelerator resources, memory resources, storage resources, or network resources, depending on the application); (b) reliability and resilience (e.g., some input flows need to be acted upon and traffic routed based on mission-critical reliability, while some other input flows can tolerate occasional failures, depending on the application); and (c) physical constraints (e.g., power, cooling, and form factor).

[0034] The end-to-end service view of these use cases involves the concept of service flow and is associated with transactions. A transaction details the overall service requirements of the entities using the service, as well as the related services for resources, workloads, workflows, business function requirements, and business level requirements. Services executed in the terminology can be managed at each layer to ensure real-time contractual compliance with transactions throughout the service's lifecycle. When a component in a transaction fails to meet its agreed Service Level Agreement (SLA), the system as a whole (the component in the transaction) can provide the following capabilities: (1) understanding the impact of the SLA breach; (2) enhancing other components in the system to restore the overall transaction SLA; and (3) implementing remedial steps.

[0035] Therefore, considering these changes and service characteristics, edge computing within the edge cloud 110 can provide the ability to serve and respond to multiple applications for use cases 205 (e.g., object tracking, video surveillance, connected cars, etc.) in real-time or near real-time, while meeting the ultra-low latency requirements of these applications. These advantages support entirely new categories of applications (Virtual Network Functions (VNFs), Function as a Service (FaaS), Edge as a Service (EaaS), standard processes, etc.) that cannot leverage traditional cloud computing due to latency or other limitations.

[0036] However, along with the advantages of edge computing come the following considerations. Devices located at the edge are often resource-constrained, thus putting pressure on the use of edge resources. This is typically addressed by centralizing memory and storage resources for use by multiple users (tenants) and devices. The edge may be power and cooling-constrained, so power-intensive applications need to take power consumption into account. There may be inherent power-performance trade-offs in these centralized memory resources, as many may employ emerging memory technologies where more power requires greater memory bandwidth. Similarly, enhanced security is needed for hardware and functions trusted by the root trust, as edge locations may be unattended or may even require licensed access (e.g., when located in a third-party location). These issues are amplified in edge clouds¹ ...

[0037] At a more general level, an edge computing system can be described as encompassing any number of deployments at the layers (network layers 200-240) operating in the previously discussed edge cloud 110, providing coordination from clients and distributed computing devices. One or more edge gateway nodes, one or more edge aggregation nodes, and one or more core data centers can be distributed across the network layers to provide implementations of the edge computing system by or on behalf of a telecommunications service provider (“telco” or “TSP”), an IoT service provider, a cloud service provider (CSP), an enterprise entity, or any other number of entities. Various implementations and configurations of the edge computing system can be provided dynamically, such as when they are coordinated to meet service objectives.

[0038] Consistent with the examples provided in this article, client computing nodes can be manifested as any type of endpoint component, device, appliance, or other item capable of communicating as a data producer or consumer. Furthermore, the labels “node” or “device” used in edge computing systems do not necessarily imply that these nodes or devices operate in the role of a client or agent / servant / follower; rather, any node or device in an edge computing system refers to an individual entity, node, or subsystem, including discrete or connected hardware or software configurations that facilitate or utilize the edge cloud.

[0039] Thus, the edge cloud 110 is formed by the network components and functional characteristics operated by and present in the edge gateway nodes, edge aggregation nodes, or other edge computing nodes in network layers 210-230. Therefore, the edge cloud 110 can be embodied as any type of network providing edge computing resources and / or storage resources located near endpoint devices (e.g., mobile computing devices, IoT devices, smart devices, etc.) supporting a Radio Access Network (RAN) discussed herein. Additionally or alternatively, the edge cloud 110 can be a home network connected to the edge and / or the cloud via a FIOS link or a cable television network. In other words, the edge cloud 110 can be conceived as the "edge" connecting endpoint devices and traditional network access points, which serve as entry points into service provider core networks (including mobile operator networks such as Global System for Mobile Communications (GSM), Long-Term Evolution (LTE), 4G / 5G, etc.) while also providing storage and / or computing capabilities. Other types and forms of network access (e.g., Wi-Fi, long-range wireless technologies, and wired networks including optical networks) can also be used to replace or combine with these 3GPP operator networks.

[0040] The network components of the edge cloud 110 can be servers, multi-tenant servers, electric computing devices, appliances, home gateways, client workstations, client mobile personal computers (PCs), smartphones, and / or any other type of computing device. For example, the edge cloud 110 can be an electric computing device, which is a standalone processing system including a enclosure, chassis, or housing. In some cases, edge devices are devices present in the network for a specific purpose (e.g., traffic lights), but they have processing capabilities or other capabilities that can be used for other purposes. These edge devices can be independent of other networked devices and have an enclosure (with form factors suited to their primary purpose); however, they can still be used for other computing tasks that do not interfere with their primary task. Edge devices include Internet of Things (IoT) devices. Electric computing devices can include hardware and software components to manage local issues (such as device temperature, vibration, resource utilization, updates, power issues, physical and network security, etc.). Figure 13B describes exemplary hardware for implementing an electrical computing device. The edge cloud 110 may also include one or more servers and / or one or more multi-tenant servers. Such servers can implement virtual computing environments (such as hypervisors for deploying virtual machines and operating systems for implementing virtual execution environments). These virtual computing environments provide an execution environment in which one or more applications can run in isolation from one or more other applications.

[0041] Figure 3 A block diagram of an exemplary environment 300 is shown, in which various client endpoints 310 (client endpoints in the form of mobile devices, computers, autonomous vehicles, commercial computing devices, and industrial processing devices) exchange requests and responses with an exemplary edge cloud 110. For example, client endpoints 310 can achieve network access via a wired broadband network by exchanging requests and responses 322 via a locally deployed network system 332. Some client endpoints 310 (such as mobile computing devices) can achieve network access via a wireless broadband network by exchanging requests and responses 324 via an access point (e.g., a cellular network tower) 334. Some client endpoints 310 (such as autonomous vehicles) can obtain network access for requests and responses 326 via a wireless vehicular network through a street-based network system 336. However, regardless of the type of network access, the TSP can deploy aggregation points 342, 344 within the edge cloud 110 to aggregate traffic and requests. Therefore, within the edge cloud 110, the TSP can deploy various computing and storage resources (such as at edge aggregation nodes 340) to provide the requested content. Edge aggregation nodes 340 and other systems of the edge cloud 110 connect to a cloud or data center 360, which utilizes a backhaul network 350 to meet higher latency requests from the cloud / data center for websites, applications, database servers, etc. Additional or merged examples of edge aggregation nodes 340 and aggregation points 342, 344 (including those deployed on a single server frame) may also exist in other areas of the edge cloud 110 or the TSP infrastructure.

[0042] Figure 4 This illustrates the deployment and coordination of virtual edge configurations across an entire edge computing system operating across multiple edge nodes and multiple tenants. Specifically, Figure 4The diagram illustrates the collaboration between a first edge node 422 and a second edge node 424 in an edge computing system 400 to handle requests and responses from various client endpoints 410 (e.g., smart city / building systems, mobile devices, computing devices, commercial / logistics systems, industrial systems, etc.) connected to various virtual edge instances. Here, virtual edge instances 432 and 434 provide edge computing capabilities and processing within an edge cloud, while also connecting to a cloud / data center 440 to enable higher latency requests to websites, applications, database servers, etc. However, the edge cloud supports processing collaboration between multiple edge nodes for multiple tenants or entities.

[0043] exist Figure 4 In the examples, these virtual edge examples include: a first virtual edge 432 provided to a first tenant (tenant 1), which provides a first combination of edge storage, computing, and services; and a second virtual edge 434, which provides a second combination of edge storage, computing, and services. Virtual edge examples 432 and 434 are distributed among edge nodes 422 and 424, and may include scenarios where requests and responses are implemented from the same or different edge nodes. The configuration of edge nodes 422 and 424 working in a distributed and collaborative manner is based on edge provisioning function 450. The ability of edge nodes 422 and 424 to provide collaborative operation for applications and services among multiple tenants is based on coordination function 460.

[0044] It should be understood that some of these devices 410 are multi-tenant devices, where tenant 1 can run within a tenant 1 “slice,” while tenant 2 can run within a tenant 2 “slice” (and, in further instances, additional tenants or subtenants may exist; and each tenant may even be specifically authorized and transactionally bound to a specific set of features, all the way to specific hardware features). Trusted multi-tenant devices may also contain tenant-specific cryptographic keys, such that the combination of keys and slices can be considered a “Root of Trust” (RoT) or a tenant-specific RoT. A Device Identity Composition Engine (DICE) architecture can also be used to dynamically compute and compose the RoT, allowing the construction of a hierarchical trusted computing infrastructure using a single DICE hardware building block for layering device capabilities (such as field-programmable gate arrays (FPGAs)). The RoT can also be used in trusted computing scenarios to achieve “fan-out,” which is beneficial for supporting multi-tenancy. In a multi-tenant environment, the corresponding edge nodes 422, 424 can serve as security feature enforcement points for the local resources allocated to multiple tenants on each node. Furthermore, tenant runtime and application execution (e.g., in Examples 432, 434) can be used as execution points for security features that create virtual edge abstractions of resources that may span multiple physical hosting platforms. Finally, the coordination function 460 at the coordination entity can serve as a security feature execution point for scheduling resources along tenant boundaries.

[0045] Edge computing nodes can be partitioned with resources (memory, CPU, GPU, interrupt controller, input / output (I / O) controller, memory controller, bus controller, etc.), and this partitioning can include RoT capabilities. Furthermore, the fan-out and layering based on the DICE model can be further applied to edge nodes. Cloud computing nodes, composed of virtual execution environments, FaaS engines, servlets, servers, or other computing abstractions, can be partitioned according to the DICE layering and fan-out structure to support RoT scenarios for each cloud computing node. Therefore, the corresponding devices 410, 422, and 440 across RoT can coordinate the establishment of a Distributed Trusted Computing Base (DTCB), thereby establishing a tenant-dedicated virtual trusted secure channel that links all components end-to-end.

[0046] Furthermore, it should be understood that virtual execution environments (e.g., containers, virtual machines, etc.) can have dedicated keys for data or workloads that protect their contents from access by the previous edge node. As part of a virtual execution environment migration, the container group (pod) controller at the source edge node can obtain a migration key from the container group controller at the target edge node, where this migration key is used to wrap the virtual execution environment's dedicated keys. When the virtual execution environment / container group is migrated to the target edge node, the unpacking key is exposed to the container group controller, which then decrypts the wrapped key. At this point, these keys can be used to perform operations on the virtual execution environment's dedicated data. The migration functionality can be gated by appropriately authenticated edge nodes and container group managers (as described above).

[0047] In a further example, edge computing systems are extended to enable the coordination of multiple applications in a multi-owner, multi-tenant environment using virtual execution environments (deployable execution environments that provide code and necessary dependencies to execute instructions (e.g., programs)). Multi-tenant coordinators can be used to perform key management, trust anchor management, and other functions. Figure 4 Other security features related to the provisioning and lifecycle of the trusted “slice” concept. For example, edge computing systems can be configured to handle requests and responses from various client endpoints originating from multiple virtual edge instances (as well as from the cloud or remote data centers). The use of these virtual edge instances can simultaneously support multiple tenants and multiple applications (e.g., Augmented Reality (AR) / Virtual Reality (VR), enterprise applications, content delivery, gaming, and compute offloading). Furthermore, there can be various types of applications within virtual edge instances (e.g., general applications; latency-sensitive applications; latency-critical applications; user plane applications; web applications; etc.). Virtual edge instances can also span systems owned by multiple owners in different geographical locations (or corresponding computing systems and resources jointly owned or managed by multiple owners).

[0048] For example, each of edge nodes 422 and 424 can enable the use of virtual execution environments (e.g., providing the use of virtual execution environment (VEE) “container groups” 426 and 428, which consist of one or more virtual execution environments). In a configuration using one or more virtual execution environment container groups, the container group controller or coordinator is responsible for local control and coordination of the virtual execution environments within the container group. Various edge node resources (e.g., storage resources, compute resources, and service resources depicted in hexagons) provided for the corresponding edge slices 432 and 434 are partitioned according to the needs of each virtual execution environment.

[0049] By using virtual execution environment (VExecution Environment) container groups, the container group controller oversees the partitioning and allocation of VExecution Environments and resources. The container group controller receives instructions from a coordinator (e.g., Coordinator 460) instructing the controller on how best to partition physical resources and for how long (e.g., by receiving Key Performance Indicator (KPI) targets based on an SLA contract). The container group controller determines which VExecution Environments require which resources and for how long to complete the workload and meet the SLA. The container group controller also manages VExecution Environment lifecycle operations (e.g., creating VExecution Environments, providing them with resources and applications, coordinating intermediate results among multiple VExecution Environments working together on a distributed application, and dismantling VExecution Environments when the workload is complete). Furthermore, the container group controller can act as a security mechanism, preventing resource allocation before proper tenant authentication or providing data or workloads to VExecution Environments before the authentication results are met.

[0050] Furthermore, by using virtual execution environment (VEX) container groups, tenant boundaries can still exist only within the context of each container group in the VEX. If each tenant-specific container group has its own tenant-specific container group controller, there will be a shared container group controller to consolidate resource allocation requests, avoiding typical resource scarcity scenarios. Further controls can be provided to ensure the authentication and trustworthiness of container groups and their controllers. For example, the coordinator 460 can provide authentication verification policies to the local container group controller that performs authentication verification. If the authentication satisfies the policy for the first tenant container group controller but not for the second tenant container group controller, the second container group can be migrated to a different edge node that satisfies it. Alternatively, the first container group can be allowed to execute, and a different shared container group controller can be installed and invoked before the second container group executes.

[0051] Figure 5Additional computing arrangements for deploying virtual execution environments in an edge computing system are illustrated. As a simplified example, system arrangements 510 and 520 depict settings in which container group controllers (e.g., Virtual Execution Environment (VEE) managers 511 and 521 and a Virtual Execution Environment (VEE) coordinator 531) are adapted to initiate virtual execution environment container groups, functions, and function-as-a-service examples via execution via compute node (515 in arrangement 510) or to execute containerized virtualized network functions individually via execution via compute node (523 in arrangement 520). This arrangement is suitable for use in an exemplary system arrangement 530 (using compute node 537) with multiple tenants, wherein virtual execution environment container groups (e.g., container group 512), functions (e.g., function 513, VNF 522, and VNF 536), and function-as-a-service examples (e.g., FaaS example 514) are launched within virtual machines dedicated to the respective tenants (e.g., virtual machines (VMs) 534, 535 for tenants 532, 533) (other than the execution of virtualized network functions). This arrangement is further suitable for use in a system arrangement 540 (providing virtual execution environments 542, 543), or for executing various functions, applications, and functions on compute node 544 under the coordination of a virtual execution environment (VEE)-based coordination system 541.

[0052] Figure 5 The system layout illustrated provides an architecture that treats virtual execution environments (e.g., VMs and / or virtual execution environments) equally in terms of application composition (and the resulting application is a combination of these three elements). Each element may involve using one or more accelerator (FPGA, ASIC) components as a local backend. Thus, under the coordination of a coordinator, applications can be partitioned among multiple edge owners.

[0053] exist Figure 5 In such cases, the container group controller / virtual execution environment manager, virtual execution environment coordinator, and individual nodes can provide secure execution points. However, tenant isolation can be coordinated, where resources allocated to one tenant differ from those allocated to a second tenant, but the edge owner collaborates to ensure resource allocation is not shared at the tenant boundary. Alternatively, resource allocation can be isolated at the tenant boundary, as tenants can allow "use" based on subscriptions or transactions / contracts. In these cases, the edge owner can employ virtualization, virtual execution environmentization, enclaves, and hardware partitioning schemes to enforce leasing. Other isolated environments can include: bare metal (dedicated) devices, virtual machines, virtual execution environments, virtual machines on virtual execution environments, or combinations thereof.

[0054] In further examples, software-defined or controlled silicon hardware and other configurable hardware aspects can be integrated with the applications, functions, and services of an edge computing system. The ability of a resource or hardware element to repair a portion of itself or its workload (e.g., through upgrades, reconfigurations, or by providing new features within the hardware configuration itself) can be used to ensure that the element fulfills its contractual or service level agreement obligations.

[0055] It should be understood that the edge computing systems and deployments discussed in this article are applicable to a wide range of solutions, services, and / or use cases involving mobility. As an example, Figure 6 Exemplary simplified vehicle computing and communication use cases are illustrated, relating to mobile access applications in an exemplary edge computing system 600 that implements an edge cloud (e.g., Figure 1 (Edge cloud 110 in the context of this use case). In this use case, the corresponding client computing node 610 can be embodied as an in-vehicle computing system (e.g., an in-vehicle navigation and / or infotainment system) located in the corresponding vehicle, which communicates with the exemplary edge gateway node 620 while traversing a road. For example, the edge gateway node 620 can be located in a roadside cabinet or other enclosure built into a structure with other independent mechanical facilities (which can be placed along the road, at a road intersection, or at other locations near the road). As the corresponding vehicle travels along the road, the connection between its client computing node 610 and one of the specific edge gateway nodes 620 can be propagated to maintain consistent connectivity and context for the exemplary client computing node 610. Similarly, mobile edge nodes can be aggregated for high-priority services or based on throughput or latency resolution requirements for one or more underlying services (e.g., in the case of a drone). The corresponding edge gateway device 620 includes a certain amount of processing and storage capacity. Thus, some data processing and / or storage for the client computing node 610 can be performed on one or more edge gateway nodes 620.

[0056] Edge gateway node 620 can communicate with one or more edge resource nodes 640, which are exemplarily manifested as computing servers, appliances, or components located at or within a communication base station 642 (e.g., a base station of a cellular network). As described above, the one or more corresponding edge resource nodes 640 include a certain amount of processing and storage capacity, such that some data processing and / or storage for client computing node 610 can be performed on one or more edge resource nodes 640. For example, less urgent or less important data processing can be performed by one or more edge resource nodes 640, while more urgent or more important data processing can be performed by edge gateway device 620 (e.g., depending on the capabilities of each component or information indicating urgency or importance in the request). Work can continue on the edge resource nodes when processing priorities change during processing activity based on data access, data location, or latency. Similarly, configurable system or hardware resources themselves can be activated (e.g., via a local coordinator) to provide additional resources to meet new demands (e.g., adapting computing resources to workload data).

[0057] One or more edge resource nodes 640 also communicate with a core data center 650, which may include computing servers, appliances, and / or other components located in a central location (e.g., the central office of a cellular communication network). An exemplary core data center 650 may provide a gateway to a global network cloud 660 (e.g., the Internet) for the operation of an edge cloud 110 formed by one or more edge resource nodes 640 and edge gateway devices 620. Furthermore, in some instances, the core data center 650 may include a certain amount of processing and storage capacity so that some data processing and / or storage (e.g., low-urgency or low-importance or high-complexity processing) for client computing devices can be performed on the core data center 650.

[0058] Edge gateway node 620 or one or more edge resource nodes 640 can provide access to stateful application 632 and geographically distributed database 634. While application 632 and database 634 are shown as horizontally distributed at one layer of edge cloud 110, it should be understood that application resources, services, or other components can be vertically distributed throughout the edge cloud (including portions of the application running at client compute node 610, other portions at edge gateway node 620 or one or more edge resource nodes 640, etc.). Furthermore, as described above, peering relationships can exist at any level to fulfill service objectives and obligations. Additionally, data for a specific client or application can be moved from one edge to another based on changing conditions (e.g., based on accelerated resource availability, following vehicle movement, etc.). For example, predictions can be made based on the "decay rate" of access to identify the next owner to continue, or to determine when data or compute access will no longer be feasible. These and other services can be utilized to accomplish the work required to maintain transaction compliance and integrity.

[0059] In further scenarios, a Virtual Execution Environment (VEE) 636 (or a group of containers of VEEs) can be flexibly migrated from one edge node 620 to other edge nodes (e.g., another edge node 620, one of one or more edge resource nodes 640, etc.), so that the VEEs with applications and workloads do not need to be refactored, recompiled, and reinterpreted for migration work. However, in these settings, some remedies or "swaps" may be applied.

[0060] (swizzling) Translation operations. For example, the physical hardware at one or more edge resource nodes 640 may differ from the hardware at the edge gateway node 620; therefore, the Hardware Abstraction Layer (HAL) constituting the bottom edge of the virtual execution environment will be remapped to the physical layer of the target edge node. This may involve some form of late-binding technique (such as binary translation of the HAL from the virtual execution environment's native format to the physical hardware format), or it may involve mapping interfaces and operations. As part of the virtual execution environment's lifecycle, a container group controller can be used to drive interface mapping, which includes migration to / from different hardware environments.

[0061] Figure 6The scenarios covered can utilize various types of mobile edge nodes (such as edge nodes carried in vehicles (cars / trucks / trams / trains) or other mobile units), as the edge node will move along the platform carrying it to other geographical locations. Through vehicle-to-vehicle communication, individual vehicles can even act as network edge nodes for other vehicles (e.g., to perform caching, reporting, data aggregation, etc.). Therefore, it should be understood that the application components provided in the various edge nodes can be distributed across static or mobile settings, including some functions or operations at individual endpoint devices or edge gateway nodes 620, some other functions or operations at one or more edge resource nodes 640, and coordination between other functions or operations in the core data center 650 or the global network cloud 660.

[0062] In further configurations, edge computing systems can implement FaaS computing capabilities by using appropriate executable applications and functions. In one instance, developers write function code (e.g., "computer code" in this document) representing one or more computer functions and upload that function code to a FaaS platform, such as one provided by an edge node or data center. Triggers (e.g., service use cases or edge processing events) utilize the FaaS platform to initiate the execution of the function code.

[0063] In one instance of FaaS, a virtual execution environment (VRE) is used to provide an environment for executing functional code (e.g., applications that may be provided by a third party). The VRE can be any isolated execution entity (such as a process, a Docker or Kubernetes VRE, a virtual machine, etc.). In edge computing systems, various data center, edge, and endpoint (including mobile) devices are used to "spin up" on-demand scaling of functionalities (e.g., activating and / or assigning functional actions). The functional code executes on physical infrastructure devices (e.g., edge computing nodes) and the underlying virtualized VRE. Finally, in response to execution completion, the VRE is "stopped" on the infrastructure (e.g., deactivated and / or deallocated).

[0064] Other aspects of FaaS can support the deployment of edge functions as a service, including support for corresponding functions of edge computing as a service (Edge as a Service or "EaaS"). Additional features of FaaS may include: fine-grained billing components (which enable customers (e.g., computer code developers) to pay only when their code is executed); a common data store (for storing data that can be reused by one or more functions); coordination and management between functions; function execution management, parallelism, and integration; management of virtual execution environments and function storage space; coordination of acceleration resources available for functions; and function allocation between virtual execution environments (including "hot" virtual execution environments that are already deployed or running and "cold" virtual execution environments that require initialization, deployment, or configuration).

[0065] The edge computing system 600 may include or communicate with an edge provisioning node 644. The edge provisioning node 644 may provide software (such as...) Figure 13 The exemplary computer-readable instruction 1382 in B is distributed to various recipients for implementing any of the methods described herein. The exemplary edge provisioning node 644 can be implemented by any computer server, home server, content delivery network, virtual server, software distribution system, central facility, storage device, storage node, data facility, cloud service, etc., capable of storing and / or transmitting software instructions (e.g., code, scripts, executable binaries, virtual execution environments, file packages, compressed files, and / or derivatives thereof) to other computing devices. One or more components of the exemplary edge provisioning node 644 can be located in the cloud, a local area network, an edge network, a wide area network, the Internet, and / or any other location communicatively coupled to one or more recipients. Recipients can be customers, clients, collaborators, users, etc., of the entity that owns and / or operates the edge provisioning node 644. For example, the entity that owns and / or operates the edge provisioning node 644 can be software instructions (e.g., code, scripts, executable binaries, virtual execution environments, file packages, compressed files, and / or derivatives thereof). Figure 13 The developer, seller, and / or licensor (or its customers and / or consumers) of the exemplary computer-readable instruction 1382 in B. Recipients may be consumers, service providers, users, retailers, OEMs, etc., who purchase the software instructions and / or license the software instructions for use and / or resell and / or sublicense.

[0066] In one instance, edge provisioning node 644 includes one or more servers and one or more storage devices. As described below, the storage devices carry computer-readable instructions (e.g., ...). Figure 13(Example computer-readable instruction 1382 in B). Similar to the edge gateway device 620 described above, one or more servers of the edge provisioning node 644 communicate with the base station 642 or other network communication entities. In some instances, as part of a business transaction, one or more servers respond to a request to transmit software instructions to a requesting party. Payment for the delivery, sale, and / or licensing of the software instructions may be handled by one or more servers of a software distribution platform and / or via a third-party payment entity. The server enables purchasers and / or licensors to download the computer-readable instruction 1382 from the edge provisioning node 644. For example, it may correspond to... Figure 13 The software instructions of the exemplary computer-readable instructions 1382 in B can be downloaded to an exemplary processor platform that will execute the computer-readable instructions 1382 to implement the methods described herein.

[0067] In some instances, one or more processor platforms executing the computer-readable instructions 1382 may be physically located in different geographical locations, legal jurisdictions, etc. In some instances, one or more servers of the edge provisioning node 644 periodically execute software instructions (e.g., Figure 13 Example computer-readable instructions 1382 in B provide, transmit, and / or force updates to ensure that improvements, patches, updates, etc., are distributed to software instructions implemented at end-user devices. In some instances, different components of the computer-readable instructions 1382 may be distributed from different sources and / or to different processor platforms; for example, different libraries, plug-ins, components, and other types of computing modules (whether compiled or interpreted) may be distributed from different sources and / or to different processor platforms. For example, a portion of the software instructions (e.g., a script that is not executable on its own) may be distributed from a first source, while an interpreter (capable of executing the script) may be distributed from a second source.

[0068] In further examples, it can be based on Figure 13 A and Figure 13 The components shown in section B implement any computing node or device discussed in conjunction with this edge computing system and environment. A corresponding edge computing node can be embodied as a device, appliance, computer, or other "article" capable of communicating with other edge components, networking components, or endpoint components. For example, an edge computing device can be embodied as a personal computer, server, smartphone, mobile computing device, smart appliance, in-vehicle computing system (e.g., navigation system), a standalone device with an external chassis, enclosure, etc., or other device or system capable of performing the functions described.

[0069] Figure 7 This is a block diagram of an exemplary environment 700 for improving privacy for follow services, based on examples disclosed herein. Exemplary environment 700 includes... Figure 1 , Figure 2 , Figure 3 and / or Figure 6 The exemplary edge cloud 110 and exemplary cloud / data center 130 are shown in the example. The exemplary environment 700 further includes an exemplary coordinator 701 (including exemplary processor circuitry 702), an exemplary network 703, one or more exemplary edge computing devices 704, an exemplary end-user device 706, and one or more exemplary access devices 708. The one or more exemplary access devices 708 include an exemplary Radio Access Network (RAN) Intelligent Controller Circuit (RIC) 710 and an exemplary core network 712. Although... Figure 7 The instances described herein correspond to cloud-based networks, but the instances disclosed herein can be applied to any type of computing environment (e.g., virtual machines, server racks, etc.) and can be deployed anywhere from edge computing device 704 to cloud 130 and / or including edge computing device 704 to cloud 130. In some instances, cloud / data center 130 corresponds to... Figure 3 and / or Figure 4 Cloud / data centers 360, 440 and / or Figure 6 The global network cloud 660 in the example. In some instances, the exemplary edge computing device 704 may correspond to... Figure 1 One or more exemplary endpoints 160 and / or Figure 4 and / or Figure 6 Examples of edge nodes are 422, 424, 620, and 644. In some instances, coordinator 701 may correspond to... Figure 4 and / or Figure 5 One or more coordinators 460, 531. Although Figure 1 An instance includes a coordinator 701 and an edge computing device 704, but can have any number of cloud and / or edge computing devices. In some instances, environment 700 can be a low-trust or zero-trust environment.

[0070] Figure 7 The exemplary coordinator 701 is a network device that provides cloud-based and / or edge-based services. For example, coordinator 701 may be a computing device (e.g., a server) that connects to the exemplary edge computing device 704 via an interface to monitor and / or assist in the operation of the connected device. In some instances, coordinator 701 is a cloud backend and / or is implemented by that cloud backend. In some instances, coordinator 701 is a server and / or is implemented by that server, which implements and manages virtual machines or servers in a rack. Figure 7In one example, coordinator 701 is implemented in a cloud-based server 130. The exemplary cloud-based server 130 may be implemented in a private cloud and / or a public cloud. In some instances, coordinator 701 is additionally or alternatively implemented in an edge cloud 110. Coordinator 701 includes processor circuitry 702 to process encrypted user and / or location information associated with end-user equipment 706 without decoding or otherwise determining the user and / or location information, as described below. Figure 8 Further description.

[0071] Figure 7 The exemplary network 703 is a system comprising an interconnected system that exchanges data between a coordinator 701 and a processing device (e.g., an exemplary edge computing device 704). The exemplary network 703 can be implemented using any type of public or private network (such as, but not limited to, the Internet, telephone networks, local area networks (LANs), cable television networks, and / or wireless networks). To enable communication via the exemplary network 703, the coordinator 701 and / or the edge computing device 704 include a communication interface capable of connecting to Ethernet, Digital Subscriber Line (DSL), telephone lines, coaxial cables, any wireless connection method, etc.

[0072] Figure 7 The exemplary edge cloud 110 includes an exemplary edge computing device 704. Although Figure 7 Examples include the exemplary edge cloud 110, but Figure 7This can be described in conjunction with fog domains, IoT domains, virtual machine (VM) domains, multi-access edge computing (MEC) domains, etc. The exemplary edge computing device 704 is a device operating within the exemplary edge cloud 110. Edge computing device 704 can be a server, broker, coordinator, fog device, virtual machine, and / or any other type of computing device operating in a cloud-based environment. In some instances, edge computing device 704 is a device (e.g., mobile device, camera, drone, smart device, sensor, server, computer, IoT device, and / or any other computing device) that accesses the services of exemplary coordinator 701 through an interface connection (e.g., direct connection or connection via one or more gateways, one or more edge devices, etc.). The exemplary edge computing device 704 can install a virtual execution environment to perform tasks corresponding to the services provided to end-user device 706. As used herein, a virtual execution environment may include and / or implement one or more virtual machines, one or more containers, one or more producer applications and / or software to perform the portion of the workload corresponding to the service. End-user device 706 can implement applications that facilitate the execution of workloads in a virtual execution environment implemented by edge computing device 704. For example, if a user downloads an image processing application provided by a third-party service provider implementing edge computing device 704, the image processing application can instruct edge computing device 704 to perform a workload to process image data at edge computing device 704 (e.g., using a virtual execution environment) and return the results to end-user device 706, thereby saving resources for end-user device 706. In some instances, when end-user device 706 leaves the first edge computing device 704, the first edge computing device 704 can receive instructions to migrate the virtual execution environment to another edge computing device 704 that is now closer to end-user device 706, allowing the second edge computing device to execute the workload, as further described below. In this way, regardless of the location of end-user device 706, services provided by third parties can follow end-user device 706 to improve performance by reducing latency, increasing throughput, etc.

[0073] One or more exemplary access devices 708 provide connectivity to network 703 to end user equipment 706. In some instances, one or more access devices 708 are base stations that allow end user equipment 706 to access network 703. In some instances, one or more access devices 708 are cellular (e.g., 3G, 4G, 5G, etc.) base stations. In some instances, one or more access devices 708 are one or more Wi-Fi stations (e.g., access points). One or more base stations may determine detailed location information related to the location of end user equipment 706 based on signals obtained from end user equipment 706 and / or the location of one or more access devices 708. Furthermore, access devices 708 may determine user information and / or identifiers (IDs) associated with end user and / or end user equipment 706. For example, if end user equipment 706 is implemented in and / or connected to a vehicle, access device 708 may determine the vehicle identification number (VIN) and / or other identification information of the vehicle. One or more access devices 708 include RIC circuitry 710 and core network circuitry 712. RIC circuitry 710 tracks the location of end-user device 706 and determines when to trigger a service migration of the virtual execution environment to perform workloads for end-user device 706 from a first edge computing device in one or more edge computing devices 704 to a second edge computing device in one or more edge computing devices 704. When RIC circuitry 710 determines that a service migration should occur, it encrypts (e.g., using an inadvertent encryption protocol) the user identifier (e.g., user identification information, identifier, VIN, etc.) and / or location information of end-user device 706 and generates an evaluation key. Core network circuitry 712 transmits the encrypted information and evaluation key to coordinator 701, enabling processor circuitry 702 to identify one or more candidate edge computing devices 704 located near end-user device 706 based on the acquired encrypted data. After coordinator 701 responds with candidate terminal computing device locations (e.g., obtained via core network circuitry 712), RIC circuitry 710 selects one of the candidate edge device locations based on the location of the candidate terminal computing device relative to the end user equipment and / or the availability and / or capability of one or more edge computing devices 704. In some instances, the selection of candidate edge device locations is performed at the coordination level. For example, each computing domain (e.g., edge or cloud) includes a corresponding control domain that has information to determine where tasks need to be scheduled. After confirming a specific edge location, information is forwarded from the edge / cloud control domain (e.g., coordinator 701) to the wireless network domain (e.g., base station).After the RIC circuit 710 selects an edge computing device to perform the workload, the RIC circuit 710 triggers a service migration protocol to migrate the virtual execution environment required to perform the workload from the previous edge computing device to the selected edge computing device 704. This is described below. Figure 9 The exemplary RIC circuit 710 will be further described below.

[0074] Figure 8 It shows Figure 7 A block diagram of the processor circuitry 702 in the coordinator 701. The exemplary processor circuitry 702 includes an exemplary interface circuitry 800 and an exemplary data processing circuitry 802.

[0075] Figure 8 The exemplary interface circuitry 800 communicates with one or more exemplary access devices 708 and / or one or more edge computing devices 704 via an exemplary network 703. For example, the interface circuitry 800 may obtain encrypted data from one or more access devices 708, including end-user equipment identification information and / or location information (e.g., corresponding to the location of end-user equipment 706). Furthermore, the interface circuitry 800 obtains an evaluation key. The evaluation key allows the data processing circuitry 802 to process the obtained encrypted data without decryption and / or otherwise determining the user identification and / or location information from the encrypted information. Additionally, after the data processing circuitry 802 determines the location of a candidate edge computing device to perform a workload, the interface circuitry 800 transmits information related to the candidate edge computing device to the exemplary access device 708 via the network 703.

[0076] Figure 8 The exemplary data processing circuit 802 uses an evaluation key to evaluate encrypted information without decrypting it. Thus, even when the identity or location of the end-user device 706 cannot be determined, the data processing circuit 802 can use the key to verify the validity of the end-user (e.g., based on encrypted user identification information and / or credential information) and select candidate edge computing device locations. The candidate edge computing device locations correspond to edge computing devices 704 located near the end-user device 706 (e.g., based on encrypted location information). By using an inadvertent processing protocol, even if the processing circuit 802 cannot access and / or determine the encrypted information, it is able to process the encrypted information and use it with the evaluation key to generate candidate locations. After processing the encrypted information to confirm the candidate locations, the processing circuit 802 instructs the interface circuit 800 to send a response including the candidate end-user device locations. Because the processed data is still encrypted rather than decrypted, the response will also be encrypted. This response may include information required to access and / or confirm the candidate edge computing device (e.g., identifier, IP address, credentials, etc.).

[0077] Figure 8 The exemplary migration circuit 804 coordinates the migration of the virtual execution environment from a first edge device location to a second edge device location selected by RIC 710. To coordinate the migration, the exemplary migration circuit 804 can execute a migration protocol. For example, the migration protocol may include instructing the selected edge computing device to download the virtual execution environment and execute the workload in parallel with the previous edge computing device until the selected edge computing device is fully operational. In this way, the end user device 706 will not experience interruptions and / or delays in the execution of workloads corresponding to services. While the migration circuit 804 is in... Figure 7 The coordinator 701 is implemented in the processor circuit 702, but the migration circuit 804 can also be implemented in a separate device.

[0078] Figure 9 It shows Figure 7 A block diagram of the RIC circuit 710 in the access device 708. The exemplary RIC circuit 710 includes an exemplary interface circuit 900, an exemplary location processing circuit 902, an exemplary encryption circuit 904, an exemplary decryption circuit 906, and an exemplary edge device selection circuit 908.

[0079] Figure 9 The exemplary interface circuitry 900 obtains information from the core network circuitry 712. For example, the interface circuitry 900 may obtain signal strength information corresponding to the location of the end user equipment 706 (e.g., from the end user equipment 706 and / or from other access devices). Furthermore, the interface circuitry 900 may instruct the core network 712 to transmit encrypted data with a computation key to the exemplary coordinator 701 via network 703. Additionally, the interface circuitry 900 may obtain an encrypted response from the coordinator 701 that identifies candidate edge computing device locations for virtual execution environment migration to perform workloads corresponding to services for the end user equipment 706.

[0080] An exemplary location processing circuit 902 processes data corresponding to the location of end-user equipment 706 to determine the location of end-user equipment 706. For example, the location processing circuit 902 may utilize signal strength indications corresponding to end-user equipment 706 to confirm the location of end-user equipment 706. Signal strength indications may include signal strength indications acquired and / or determined locally and / or acquired and / or determined at other access devices. For example, the location processing circuit 902 may utilize signal strength indications from two or more access devices to triangulate the location of the end-user equipment. The location processing circuit 902 may employ any location determination technique to determine the location of end-user equipment 706. Furthermore, the exemplary location processing circuit 902 tracks the location of end-user equipment 706 to determine when the movement of end-user equipment 706 exceeds a threshold distance. Thus, when the movement of end-user equipment 706 exceeds the threshold distance, the location processing circuit 902 may trigger a service migration protocol (e.g., to determine if there is another edge computing device more suitable for performing producer applications to handle workloads for end-user equipment 706).

[0081] Figure 9 The exemplary encryption circuit 904 in the example encrypts location and / or end-user equipment identification information (e.g., identifier, identification information, VIN, etc.). In some instances, encryption circuit 904 can obtain credential information from end-user equipment 706 (e.g., via interface circuit 900). In these instances, encryption circuit 904 can encrypt the credential information. Furthermore, encryption circuit 904 generates a computation key. As described above, the computation key allows coordinator 701 to process the encrypted identification, location, and / or credential information using the computation key without decrypting and / or otherwise determining the identification, location, and / or credential information, thereby maintaining the privacy of the user of end-user equipment 706. Thus, when end-user equipment 706 moves and a third-party service provider cannot determine the location and / or identification information corresponding to end-user equipment 706, a follow-up service can be initiated to migrate the virtual execution environment to an edge device near end-user equipment 706. In some instances, encryption circuit 904 encrypts the identification, location, and / or credential information in response to a trigger signal from location processing circuit 902. The encryption circuit 904 instructs the interface circuit 900 to transmit one or more data packets containing encrypted data to the coordinator 701 via the core network circuit 712.

[0082] Figure 9The exemplary decryption circuit 906 in the diagram obtains an encrypted response from the coordinator 701, which includes the location of a candidate edge computing device 704 selected by the coordinator 701. As described above, the candidate edge computing devices 704 are selected based on their proximity to the end-user device 706. The decryption circuit 906 decrypts the encrypted response from the coordinator 701 to determine the candidate edge computing device 704. Because the coordinator 701 processes (but does not decrypt) the encrypted information from the encryption circuit 904, the response is still encrypted based on the encryption technique performed by the encryption circuit 904. Therefore, the decryption circuit 906 decrypts the response based on the encryption technique employed by the encryption circuit 904 to determine the candidate edge computing device.

[0083] Figure 9 An exemplary edge device selection circuit 908 selects one of the candidate edge computing devices to serve workloads for end user device 706. For example, edge device selection circuit 908 may communicate (e.g., via interface circuitry 900 and / or core network 712) with candidate edge computing devices 704 and / or coordinator 701 to determine the capabilities and / or capacity of the candidate edge computing devices. Edge device selection circuit 908 selects one of the candidate edge computing devices 704 to migrate a virtual execution environment from a previous edge computing device, thereby performing workloads for end user device 706. In some instances, edge device selection circuit 908 selects a candidate edge computing device based on its capabilities (e.g., the ability to perform workloads), capacity (e.g., the resources available for performing workloads), and / or location (e.g., its location relative to end user device 706). Edge device selection circuit 908 may weigh any one or more of capability, capacity, and / or location substantially based on user and / or manufacturer preferences. After the edge device selection circuit 908 selects an edge computing device, it instructs (e.g., by sending one or more instructions via interface circuit 900 and / or core network 712) that the edge computing device 704 currently executing the workload migrates the virtual execution environment corresponding to the workload to the selected edge computing device (e.g., direct migration or migration via coordinator 701). These instructions may correspond to a migration protocol to ensure that services provided to end user equipment 706 are not interrupted before, after, and / or during the migration.

[0084] Despite Figure 8 and Figure 9 The implementation is shown in the figure. Figure 7 The processor circuit 702 and / or RIC circuit 710 in the example are shown, but Figure 8 and / or Figure 9One or more elements, processes, and / or devices shown may be combined, divided, rearranged, omitted, deleted, and / or implemented in any other way. Furthermore, Figure 8 and / or Figure 9 The interface circuit 800, data processing circuit 802, migration circuit 804, interface circuit 900, position processing circuit 902, encryption circuit 904, decryption circuit 906, edge device selection circuit 9082, and / or (more generally) exemplary processor circuit 702 and / or RIC circuit 710 can be implemented individually in hardware or in combination with software and / or firmware. Therefore, for example, Figure 8 and / or Figure 9 The interface circuit 800, data processing circuit 802, migration circuit 804, interface circuit 900, position processing circuit 902, encryption circuit 904, decryption circuit 906, edge device selection circuit 9082, and / or (more generally) the exemplary processor circuit 702 and / or RIC circuit 710 can be implemented by programmable circuitry in combination with machine-readable instructions (e.g., firmware or software), processor circuitry, one or more analog circuits, one or more digital circuits, one or more logic circuits, one or more programmable processors, one or more programmable microcontrollers, one or more graphics processors (GPUs), one or more digital signal processors (DSPs), one or more ASICs, one or more programmable logic devices (PLDs), and / or one or more field-programmable logic devices (FPLDs) (such as FPGAs). Furthermore, Figure 8 and / or Figure 9 The exemplary processor circuit 702 and / or RIC circuit 710 may include one or more elements, processes, and / or devices as a response to Figure 8 and / or Figure 9 The elements, processes, and / or devices shown may be supplemented or substituted, and / or may include more than one of any or all of the elements, processes, and devices shown.

[0085] exist Figure 10 and / or Figure 12B The diagram illustrates exemplary machine-readable instructions (which can be executed by programmable circuitry to implement and / or instantiate) Figure 8 and / or Figure 9 The exemplary processor circuit 702 and / or RIC circuit 710 in the text) and / or represent exemplary operations (which can be executed by programmable circuitry to implement and / or instantiate) Figure 8 and / or Figure 9 One or more flowcharts of exemplary processor circuitry 702 and / or RIC circuitry 710 (as shown below). Machine-readable instructions can be generated by programmable circuitry (such as those combined with...). Figure 11 and / or Figure 12BThe programmable circuitry 1112, 1252 shown in the exemplary processor platforms 1100, 1250 discussed herein executes one or more executable programs or one or more portions of one or more executable programs, and / or may be executed by the following combination Figure 13 and / or Figure 14 The exemplary programmable circuits discussed (e.g., FPGAs) perform one or more functions or parts thereof. In some instances, machine-readable instructions cause operations, tasks, etc., to be performed and / or executed in a real-world manner in an automated manner. As used herein, “automation” means without human intervention.

[0086] The program may be embodied in instructions (e.g., software and / or firmware) stored on one or more non-transitory computer-readable and / or machine-readable storage media (such as cache memory, magnetic storage devices or magnetic disks (e.g., floppy disks, hard disk drives, HDDs), etc.), optical storage devices or optical disks (e.g., Blu-ray discs, compact discs, digital versatile discs, DVDs), redundant arrays of independent disks (RAID), registers, ROM, solid-state drives (SSDs), SSD memory, non-volatile memory (e.g., electrically erasable programmable read-only memory, EEPROM, flash memory, etc.), volatile memory (e.g., any type of random access memory, RAM, etc.) and / or any other storage device or disk). Instructions of a non-transitory computer-readable and / or machine-readable medium may be programmed and / or executed by programmable circuitry located in one or more hardware devices, but the entire program and / or portions thereof may alternatively be executed and / or instantiated and / or embodied in dedicated hardware by one or more hardware devices other than programmable circuitry. Machine-readable instructions may be distributed across multiple hardware devices and / or executed by two or more hardware devices (e.g., server and client hardware devices). For example, client hardware devices may be implemented by endpoint client hardware devices (e.g., hardware devices associated with human and / or machine users) or by intermediate client hardware device gateways (e.g., radio access networks (RAN)) that may facilitate communication between the server and endpoint client hardware devices. Similarly, a non-transitory computer-readable storage medium may include one or more media. Furthermore, although combined with... Figure 10The one or more flowcharts shown illustrate an exemplary procedure, but alternative implementations may be used. Figure 8 and / or Figure 9 Many other methods exist for the exemplary processor circuitry 702 and / or RIC circuitry 710 in the flowchart. For example, the execution order of blocks in one or more flowcharts can be changed, and / or some of the blocks can be changed, deleted, or combined. Additionally or alternatively, any or all blocks of the flowchart can be implemented by one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, comparator, operational amplifier, logic circuitry, etc.) configured to perform the corresponding operation but not to perform software or firmware. Programmable circuitry can be distributed across different network locations and / or locally distributed across one or more hardware devices (e.g., single-core processors (e.g., single-core CPUs), multi-core processors (e.g., multi-core CPUs, XPUs, etc.)). For example, programmable circuitry can be a CPU and / or FPGA located in the same package (e.g., the same integrated circuit (IC) package or in two or more separate enclosures), one or more processors in a single machine, multiple processors distributed across multiple servers in a server rack, multiple processors distributed across one or more server racks, and / or any one or more combinations thereof.

[0087] The machine-readable instructions described herein may be stored in one or more of the following formats: compressed format, encrypted format, segmented format, compiled format, executable format, packaged format, etc. The machine-readable instructions described herein may be stored as data (e.g., computer-readable data, machine-readable data, one or more bits (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), bit streams (e.g., computer-readable bit streams, machine-readable bit streams, etc.)), or data structures (e.g., as one or more parts of instructions, code, code representation, etc.) that can be used to create, manufacture, and / or produce machine-executable instructions. For example, machine-readable instructions may be segmented and stored on one or more storage devices, disks, and / or computing devices (e.g., servers) located in the same or different locations (e.g., in the cloud, edge devices, etc.) within a network or network set. Machine-readable instructions may require one or more of the following to be installed, modified, adapted, updated, combined, supplemented, configured, decrypted, decompressed, unpacked, distributed, redistributed, compiled, etc., so that they can be directly read, interpreted, and / or executed by computing devices and / or other machines. For example, machine-readable instructions may be stored in multiple parts that are individually compressed, encrypted, and / or stored on separate computing devices, wherein these parts, when decrypted, decompressed, and / or combined, form a set of computer-executable and / or machine-executable instructions that implement one or more functions and / or operations that may together form a program such as that described herein.

[0088] In another instance, machine-readable instructions may be stored in a state readable by programmable circuitry, but additional libraries (e.g., Dynamic Link Libraries (DLLs)), Software Development Kits (SDKs), Application Programming Interfaces (APIs), etc., are required to execute the machine-readable instructions on a specific computing device or other device. In yet another instance, the machine-readable instructions may need to be configured (e.g., storage settings, data input, recorded network addresses, etc.) before they can be fully or partially executed. Therefore, as used herein, machine-readable, computer-readable, and / or machine-readable media may include instructions and / or one or more programs, regardless of their specific format or state.

[0089] The machine-readable instructions described herein can be represented by any past, present, or future instruction language, scripting language, programming language, etc. For example, machine-readable instructions can be represented by any of the following languages: C, C++, Java, C#, Perl, Python, JavaScript, HyperText Markup Language (HTML), Structured Query Language (SQL), Swift, etc.

[0090] As described above, executable instructions (e.g., computer-readable and / or machine-readable instructions) stored on one or more non-transitory computer-readable and / or machine-readable media can be used to implement... Figure 10 The exemplary operation is described herein. As used herein, the terms “non-transitory computer-readable medium,” “non-transitory computer-readable storage medium,” “non-transitory machine-readable medium,” and / or “non-transitory machine-readable storage medium” are explicitly defined to include any type of computer-readable storage device and / or storage disk, excluding propagation signals and transmission media. Examples of such non-transitory computer-readable medium, non-transitory computer-readable storage medium, non-transitory machine-readable medium, and / or non-transitory machine-readable storage medium include optical storage devices, magnetic storage devices, HDDs, flash memory, read-only memory (ROM), CDs, DVDs, caches, any type of RAM, registers, and / or any other storage device or storage disk in which information is stored for any duration (e.g., storage for an extended period of time, permanent storage, temporary storage, temporary buffering, and / or cached information). As used herein, the terms “non-transitory computer-readable storage device” and “non-transitory machine-readable storage device” are defined to include any physical hardware (mechanical hardware, magnetic hardware, and / or electrical hardware) that retains information for a certain period of time, but excludes propagation signals and transmission media. Examples of non-transitory computer-readable storage devices and / or non-transitory machine-readable storage devices include any type of random access memory, any type of read-only memory, solid-state memory, flash memory, optical disk, hard disk, disk drive, and / or redundant array of independent disks (RAID) system. As used herein, the term "device" refers to a physical structure (such as mechanical and / or electrical equipment, hardware and / or circuitry) that may or may not be configured by computer-readable instructions, machine-readable instructions, etc., and / or is manufactured to execute computer-readable instructions, machine-readable instructions, etc.

[0091] The terms “including” and “comprising” (and all their forms and tenses) are used herein as open-ended terms. Therefore, whenever a claim uses any form of “include” or “comprise” (e.g., includes, includes, comprising, including, having, etc.) as an introduction or in any kind of claim statement, it should be understood that additional elements, terms, etc., may be present without exceeding the scope of the corresponding claim or statement. As used herein, when the phrase “at least” is used as a transitional term, for example, in the introduction of a claim, it is open-ended, unlike the term “comprising”.

[0092] The terms “comprising” and “including” are used in the same way. When used, for example, in the form of A, B and / or C, the term “and / or” refers to any combination or subset of A, B, C (e.g., (1) only A; (2) only B; (3) only C; (4) A and B; (5) A and C; (6) B and C; or (7) A and B and C). As used herein in the context of describing structures, components, goods, objects and / or articles, the phrase “at least one of A and B” is intended to refer to an implementation that includes (1) at least one A, (2) at least one B or (3) at least one A and at least one B. Similarly, as used herein in the context of describing structures, components, goods, objects and / or articles, the phrase “at least one of A or B” is intended to refer to an implementation that includes (1) at least one A, (2) at least one B or (3) at least one A and at least one B. As used herein in the context of describing the implementation or execution of processes, instructions, actions, activities and / or steps, the phrase "at least one of A and B" is intended to refer to an implementation comprising (1) at least one A, (2) at least one B or (3) at least one A and at least one B. Similarly, as used herein in the context of describing the implementation or execution of processes, instructions, actions, activities and / or steps, the phrase "at least one of A or B" is intended to refer to an implementation comprising (1) at least one A, (2) at least one B or (3) at least one A and at least one B.

[0093] As used herein, the use of a single word (e.g., “a”, “an”, “first”, “second”, etc.) does not exclude “a plurality”. The term “a” or “an” as used herein refers to one or more of that object. The terms “a” (or “an”), “one or more”, and “at least one” are used interchangeably herein. Furthermore, while multiple means, elements, or actions are listed separately, they may be implemented by, for example, the same entity or object. Moreover, although individual features may be included in different instances or claims, these features may be combined, and inclusion in different instances or claims does not imply that the combination of features is infeasible and / or disadvantageous.

[0094] Figure 10 This is a flowchart illustrating exemplary machine-readable instructions and / or exemplary operations 1000, which can be executed, instantiated, and / or implemented by one or more programmable circuits to improve privacy for follow-up services. For example, exemplary operation 1000 can be... Figure 9 The RIC circuit 710 in the middle is used to execute, instantiate and / or implement, and the exemplary operation 1001 can be performed by... Figure 8 The processor circuit 702 in the middle is used to execute, instantiate and / or implement. Figure 10 The exemplary machine-readable instructions and / or exemplary operations 1000 begin at block 1002; at block 1002, location processing circuitry 902 determines the location of end user equipment 706. As described above, location processing circuitry 902 may determine the location of end user equipment 706 based on one or more signal strengths determined at one or more access devices 708. For example, RIC 710 may determine the signal strength of a signal from end user equipment 706, obtain signal strength from other access devices, and determine the location of end user equipment 706 based on the signal strength and the location of the access devices.

[0095] At block 1004, location processing circuitry 902 determines whether a change in the location of end-user equipment 706 exceeds a threshold amount. The threshold amount can be any threshold based on user and / or manufacturer preferences. In some instances, location processing circuitry 902 may additionally or alternatively determine when a time threshold amount occurs. For example, if a time threshold amount is exceeded without migrating the virtual execution environment, location processing circuitry 902 may transmit anonymous location information to coordinator 701 to determine whether the virtual execution environment should be migrated to a different edge computing device 704.

[0096] If the location processing circuit 902 determines that the location change of the end user equipment 706 does not exceed a threshold amount (block 1004: No), control returns to block 1002. If the location processing circuit 902 determines that the location change of the end user equipment 706 exceeds the threshold amount (block 1004: Yes), the exemplary encryption circuit 904 anonymizes the end user equipment location and identification information (e.g., identifier, VIN, etc.) by employing inadvertent encryption techniques (block 1006). At block 1008, the encryption circuit 904 obfuscates the user traffic corresponding to the end user equipment 706. In some instances, user traffic is provided to the coordinator 701 to allow the cloud backend to identify and associate user information without identifying the association between the user and the service.

[0097] At block 1010, in the event that the encrypted and / or obfuscated information cannot be determined, exemplary encryption circuitry 904 generates an evaluation key for assessing the encrypted and / or obfuscated information. As described above, coordinator 701 can utilize the evaluation key to process identification, location, and / or traffic information to authenticate the user and verify the edge computing device 704 located near end-user equipment 706 without decrypting and / or otherwise determining the encrypted information. At block 1012, exemplary interface circuitry 900 transmits the anonymous and / or obfuscated information, along with the evaluation key, to interface circuitry 800 of processing circuitry 802 in coordinator 701 via network 703 (e.g., using exemplary core network 712).

[0098] At block 1014, exemplary data processing circuitry 802 of processor circuitry 702 in coordinator 701 utilizes an evaluation key to process anonymous and / or obfuscated information to generate an encrypted result by (a) verifying the user and / or service and / or (b) selecting candidate edge computing devices based on identification, location, and / or traffic information. At block 1016, exemplary interface circuitry 800 transmits the encrypted result (e.g., one or more candidate edge computing devices) to exemplary access device 708 via network 703. Because the encrypted data is processed without decrypting the data, the result is encrypted without coordinator 701 needing to encrypt the result.

[0099] At block 1018, exemplary decryption circuitry 906 decrypts the processed result to confirm the candidate edge location generated by coordinator 701. Decryption circuitry 906 decrypts the processed result based on the encryption technique performed at block 1006. At block 1020, exemplary device edge selection circuitry 908 selects an edge computing device from the candidate edge computing devices. As described above, edge device selection circuitry 908 can communicate with one or more candidate edge computing devices 704 and / or one or more coordinators to determine the capabilities, capacity, and / or location of the candidate edge computing devices. Edge device selection circuitry 908 selects one of the candidate edge computing devices based on its capabilities, capacity, and / or location. At block 1022, exemplary interface circuitry 900 transmits instructions to coordinator 701 to migrate the virtual execution environment of the edge computing device currently performing workloads for end-user device 706 to the selected edge computing device. In some instances, interface circuitry 900 can transmit instructions to core network 712 to directly transfer migration instructions to the edge computing device currently performing the workload and / or a selected edge computing device. In some instances, encryption circuitry 904 encrypts instructions destined for core network 712 (e.g., using inadvertent encryption) to trigger workload migration.

[0100] At block 1024, the migration circuitry 804 of the coordinator 701 executes a migration protocol to migrate the virtual execution environment to a selected edge device. The migration protocol transfers the virtual execution environment to the selected edge computing device, allowing workloads to be transferred to and / or executed by the selected edge computing device to continue serving the end user device 706. Thus, when the end user device 706 moves, by migrating the virtual execution environment to an edge device near the end user device 706, services can follow the end user device 706 to execute workloads corresponding to that service.

[0101] Figure 11 This is a block diagram of an exemplary programmable circuit platform 1100, which is configured to perform and / or instantiate... Figure 10 The exemplary machine-readable instructions and / or exemplary operations in the document are for the purpose of implementing Figure 8 and / or Figure 9 The processor circuit 702 and / or RIC circuit 710 are included. For example, the programmable circuit platform 1100 can be a server, personal computer, workstation, self-learning machine (e.g., neural network), or any other type of computing and / or electronic device.

[0102] The programmable circuit platform 1100 of the illustrated example includes a programmable circuit 1112. The programmable circuit 1112 of the illustrated example is hardware. For example, the programmable circuit 1112 can be implemented by one or more integrated circuits, logic circuits, FPGAs, microprocessors, CPUs, GPUs, DSPs, and / or microcontrollers from any desired family or manufacturer. The programmable circuit 1112 can be implemented by one or more semiconductor-based (e.g., silicon-based) devices. In this example, the programmable circuit 1112 implements... Figure 9 The interface circuit 900, position processing circuit 902, encryption circuit 904, decryption circuit 906 and / or edge device selection circuit are included.

[0103] The programmable circuit 1112 of the illustrated example includes local memory 1113 (e.g., cache, registers, etc.). The programmable circuit 1112 of the illustrated example communicates with main memory 1114 and 1116 (including volatile memory 1114 and non-volatile memory 1116) via bus 1118. The volatile memory 1114 may be Synchronous Dynamic Random Access Memory (SDRAM), Dynamic Random Access Memory (DRAM), etc. Dynamic Random Access Memory And / or any other type of RAM device. The non-volatile memory 1116 can be implemented using flash memory and / or any other desired type of memory device. Access to the main memory 1114, 1116 in the illustrated example is controlled by the memory controller 1117. In some instances, the memory controller 1117 can be implemented by one or more integrated circuits, logic circuits, microcontrollers, or any other type of circuit from any desired family or manufacturer to manage the data flow to and from the main memory 1114, 1116.

[0104] The programmable circuit platform 1100 of the illustrated example also includes interface circuitry 1120. Interface circuitry 1120 can be implemented in hardware according to any type of interface standard, such as Ethernet interface, Universal Serial Bus (USB) interface, Bluetooth interface, Near Field Communication (NFC) interface, Peripheral Component Interconnect (PCI) interface, and / or Peripheral Component Interconnect Express (PCIe) interface.

[0105] In the illustrated example, one or more input devices 1122 are connected to interface circuitry 1120. The one or more input devices 1122 allow a user (e.g., a human user, machine user, etc.) to input data and / or commands into programmable circuitry 1112. For example, the one or more input devices 1122 may be implemented using a keyboard, buttons, a mouse, and / or a touchscreen.

[0106] One or more output devices 1124 are also connected to the interface circuitry 1120 of the illustrated example. For example, one or more output devices 1124 may be implemented by a display device (e.g., a light-emitting diode (LED), an organic light-emitting diode (OLED), a liquid crystal display (LCD), a cathode ray tube (CRT) display, an in-plane switching (IPS) display, a touchscreen, etc.) and / or a speaker. Therefore, the interface circuitry 1120 of the illustrated example typically includes a graphics driver card, a graphics driver chip, and / or graphics processing unit circuitry (e.g., a GPU).

[0107] The interface circuit 1120 of the illustrated example also includes communication devices (such as transmitters, receivers, transceivers, modems, residential gateways, wireless access points, and / or network interfaces) to facilitate the exchange of data with external machines (e.g., any type of computing device) via network 1126. For example, communication can be made via Ethernet connections, digital subscriber line (DSL) connections, telephone line connections, coaxial cable systems, satellite systems, beyond-line-of-sight wireless systems, line-of-sight wireless systems, cellular telephone systems, optical connections, etc.

[0108] The programmable circuit platform 1100 of the illustrated example also includes one or more mass storage disks or devices 1128 for storing firmware, software, and / or data. Examples of these mass storage disks or devices 1128 include magnetic storage devices (e.g., floppy disks, drives, HDDs, etc.), optical storage devices (e.g., Blu-ray discs, CDs, DVDs, etc.), RAID systems, and / or solid-state storage disks or devices (such as flash memory devices and / or SSDs).

[0109] It can be by Figure 10 The machine-readable instructions 1132 implemented by the machine-readable instructions in the document can be stored in a mass storage device 1128, a volatile memory 1114, a non-volatile memory 1116 and / or at least one non-transitory computer-readable storage medium (such as a removable CD or DVD).

[0110] Figure 12AThis is a block diagram of an exemplary implementation of an exemplary edge computing node 1200, which includes a computing engine (also referred to herein as "computing circuitry") 1202, an input / output (I / O) subsystem 1208, a data storage 1210, a communication circuitry subsystem 1212, and one or more optional peripheral devices 1214. In other instances, the corresponding computing device may include other or additional components, such as those typically found in a computer (e.g., a display, peripheral devices, etc.). Furthermore, in some instances, one or more illustrative components may be incorporated into another component or otherwise formed as part of that component. The exemplary edge computing node 1200 in Figure 12 can be deployed in... Figures 1 to 4 and / or Figure 6 and Figure 7 In one of the edge computing systems shown, to achieve Figures 1 to 4 and / or Figure 6 and Figure 7 Any edge computing node.

[0111] The exemplary compute node 1200 can be embodied as any type of engine, device, or collection of devices capable of performing various computing functions. In some instances, compute node 1200 can be embodied as a single device (such as an integrated circuit, embedded system, field-programmable gate array (FPGA), system-on-a-chip (SoC), or other integrated system or device). In an illustrative example, compute node 1200 includes or is embodied as processor 1204 and memory 1206. The exemplary processor 1204 can be embodied as any type of processor capable of performing the functions described herein (e.g., executing applications). For example, processor 1204 can be embodied as one or more multi-core processors, microcontrollers, processing units, specialized or dedicated processing units, or other processors or processing / control circuitry.

[0112] In some instances, processor 1204 may be embodied as, included as, or coupled to an FPGA, application-specific integrated circuit (ASIC), reconfigurable hardware or hardware circuitry, or other specialized hardware to facilitate the performance of the functions described herein. Similarly, in some instances, processor 1204 may be embodied as a specialized x-processing unit (xPU) (also known as a data processing unit (DPU)), infrastructure processing unit (IPU), or network processing unit (NPU). Such an xPU may be embodied as a standalone circuit or circuit package, integrated within a SoC, or integrated with network circuitry (e.g., in a SmartNIC), acceleration circuitry, storage devices, or AI hardware (e.g., a GPU or a programmable FPGA). Such an xPU may be designed to be programmed to process one or more data streams outside of a CPU or general-purpose processing hardware and perform specific tasks and actions for those data streams (such as hosting microservices, performing service management or coordination, organizing or managing server or data center hardware, managing a service mesh, or collecting and distributing telemetry data). However, it should be understood that the xPU, SOC, CPU and other variants of processor 1204 can work together to perform many types of operations and instructions within and on behalf of compute node 1200.

[0113] The exemplary memory 1206 can be embodied as any type of volatile memory (e.g., dynamic random access memory (DRAM), etc.) or non-volatile memory or data memory capable of performing the functions described herein. Volatile memory can be a storage medium that requires power to maintain the state of the data stored in it. Non-limiting examples of volatile memory can include various types of random access memory (RAM) (such as DRAM or static random access memory (SRAM)). One particular type of DRAM that can be used in a memory module is synchronous dynamic random access memory (SDRAM).

[0114] In one example, memory device 1206 is a group-addressable memory device (such as those based on NAND or NOR technology). Memory device 1206 may also include three-dimensional intersection memory devices (e.g., 3DXPoint TM Memory device 1206 can refer to the die itself and / or packaged memory products. In some instances, 3D cross-point memory (e.g., memory) is used. 3D XPoint TMThe memory may include a transistorless stackable cross-point architecture, where memory cells are located at the intersection of word lines and bit lines and are individually addressable, and where bit storage is based on variations in body resistance. In some instances, all or part of the memory 1206 may be integrated into the processor 1204. The memory 1206 may store various software and data used during operation (such as one or more applications, data operated by one or more applications, libraries, and drivers).

[0115] Exemplary computing circuitry 1202 is communicatively coupled to other components of computing node 1200 via I / O subsystem 1208, which may be embodied as circuitry and / or components facilitating input / output operations with computing circuitry 1202 (e.g., having processor 1204 and / or main memory 1206) and other components of computing circuitry 1202. For example, I / O subsystem 1208 may be embodied as or otherwise include a memory controller hub, input / output control hub, integrated sensor hub, firmware device, communication links (e.g., point-to-point links, bus links, wires, cables, light guides, printed circuit board traces, etc.) and / or other components and subsystems facilitating input / output operations. In some instances, I / O subsystem 1208 may form part of a system-on-a-chip (SoC) and be incorporated into computing circuitry 1202 along with one or more of the processor 1204, memory 1206, and other components of computing circuitry 1202.

[0116] One or more descriptive data storage devices 1210 can be embodied as any type of device configured for short-term or long-term data storage (e.g., memory devices and circuitry, memory cards, hard disk drives, solid-state drives, or other data storage devices). Individual data storage devices 1210 may include a system partition that stores data and firmware code for the data storage device 1210. Individual data storage devices 1210 may also include one or more operating system partitions that, depending on the type of compute node 1200, store data files and executable files for the operating system.

[0117] The exemplary communication circuit 1212 can be embodied as any communication circuit, device, or combination thereof capable of enabling communication between the computing circuit 1202 and another computing device (e.g., an edge gateway implementing an edge computing system) via a network. The exemplary communication circuit 1212 can be configured to employ any one or more communication technologies (e.g., wired or wireless communication) and associated protocols (e.g., cellular networking protocols such as 3GPP 4G or 5G standards, such as IEEE 802.11 / ...). Wireless LAN protocols, wireless WAN protocols, Ethernet, Bluetooth, Bluetooth Low Energy, and protocols such as IEEE 802.15.4 or... This communication is achieved using IoT protocols, Low-power Wide-area Network (LPWAN) or Low-power Wide-area (LPWA) protocols.

[0118] The illustrative communication circuitry 1212 includes a Network Interface Controller (NIC) 1220 (also referred to as a Host Fabric Interface (HFI)). The exemplary NIC 1220 may be embodied as one or more interposer boards, daughter cards, network interface cards, controller chips, chipsets, or other devices that can be used by the compute node 1200 to connect to another compute device (e.g., an edge gateway node). In some instances, the NIC 1220 may be embodied as part of a system-on-a-chip (SoC) including one or more processors, or included in a multi-chip package that also includes one or more processors. In some instances, the NIC 1220 may include a local processor (not shown) and / or local memory (not shown), both located locally within the NIC 1220. In these instances, the local processor of the NIC 1220 is capable of performing one or more functions of the compute circuitry 1202 described herein. Additionally or alternatively, in these instances, the local memory of the NIC 1220 may be integrated into one or more components of the client compute node at the board level, slot level, chip level, and / or other levels.

[0119] Furthermore, in some instances, the corresponding compute node 1200 may include one or more peripheral devices 1214. These peripheral devices 1214 may include any type of peripheral device present in a computing device or server (such as audio input devices, displays, other input / output devices, interface devices, and / or other peripheral devices), depending on the specific type of compute node 1200. In further instances, the compute node 1200 may be embodied by a corresponding edge computing node (whether a client, gateway, or aggregation node) in an edge computing system or similar form of appliance, computer, subsystem, circuit, or other component.

[0120] In a more detailed example Figure 12B An exemplary computing device 1250 is shown (e.g., Figure 7 and / or Figure 8 A block diagram of the coordinator 701 in the computing device, which is configured to perform... Figure 10The instructions in the document are used to implement the techniques described herein (e.g., operations, processes, methods, and sets of methods). When implemented as a computing device or part of a computing device (e.g., implemented as a mobile device, base station, server, gateway, etc.), the computing device 1250 provides a closer view of the corresponding components of node 1200. The computing device 1250 may include any combination of the hardware or logic components mentioned herein, and it may include any device that can be used in or coupled to edge communication networks or combinations thereof. These components may be implemented as integrated circuits (ICs), portions thereof, discrete electronic devices, or other modules, instruction sets, programmable logic or algorithms, hardware, hardware accelerators, software, firmware, or combinations thereof adapted in the computing device 1250, or implemented as components otherwise incorporated within the chassis of a larger system. For example, computing device 1250 may be, for example, a server, personal computer, workstation, self-learning machine (e.g., neural network), mobile device (e.g., cellular phone, smartphone, or tablet computer such as iPad™), personal digital assistant (PDA), internet-connected appliance, DVD player, CD player, digital video recorder, Blu-ray player, game console, personal video recorder, set-top box, headset or other wearable device, Internet of Things (IoT) device, or any other type of computing device.

[0121] The computing device 1250 may include processing circuitry in the form of programmable circuitry 1252, which may be a microprocessor, multi-core processor, multi-threaded processor, ultra-low voltage processor, embedded processor, xPU / DPU / IPU / NPU, dedicated processing unit, specialized processing unit, or other known processing element. Programmable circuitry 1252 may be part of a system-on-a-chip (SoC), wherein programmable circuitry 1252 and other components are formed as a single integrated circuit or a single package (such as the Edison from Intel Corporation in Santa Clara, California). TM Or Galileo TM (SoC board). As an example, the programmable circuit 1252 may include a SoC-based... Architecture Core TM CPU processors (such as Quark) TM Atom TM i3, i5, i14, i9 or MCU-type processors or those available from (Another such processor is available). However, any number of other processors can be used (e.g., those available from Advanced MicroDevices, Inc., Sunnyvale, California). The processor was acquired from MIPS Technologies, Inc. in Sunnyvale, California. Designed or licensed from ARM Holdings, Ltd. or its customers or licensees or adopters based on (Design). Processors may include, for example, from Inc.'s A5-A13 processor, from Snapdragon by Technologies, Inc. TM The processor or OMAP from Texas Instruments, Inc. TM Units such as processors. The programmable circuit 1252 and its auxiliary circuitry can be in single-slot, multi-slot, or various other forms (including limited hardware configurations or those including fewer than...). Figure 12B The configuration of all components shown is provided. In this example, the processor implements... Figure 8 At least one of the exemplary interface circuit 800 and / or data processing circuit 802 in the example.

[0122] Programmable circuitry 1252 can communicate with system memory 1254 via interconnect 1256 (e.g., a bus). Any number of memory devices can be used to provide a fixed amount of system memory. As an example, memory 1254 can be random access memory (RAM) designed according to the Joint Electron Devices Engineering Council (JEDEC) standards (such as DDR or mobile DDR standards (e.g., LPDDR, LPDDR2, LPDDR3, or LPDDR4)). In specific instances, the memory components can conform to JEDEC-issued DRAM standards (e.g., JESD149F for DDR SDRAM, JESD149-2F for DDR2 SDRAM, JESD149-3F for DDR3 SDRAM, JESD149-4A for DDR4 SDRAM, JESD209 for low-power DDR (LPDDR), JESD209-2 for LPDDR2, JESD209-3 for LPDDR3, and JESD209-4 for LPDDR4). These standards (and similar standards) can be referred to as DDR-based standards, and the communication interfaces of storage devices implementing these standards can be referred to as DDR-based interfaces. In various implementations, individual memory devices can be any number of different package types (e.g., Single Die Package (SDP), Dual Die Package (DDP), or Quad Die Package (Q114P)). In some instances, these devices can be directly soldered to the motherboard to provide a lower profile solution; in other instances, these devices are configured as one or more memory modules, which are coupled to the motherboard via given connectors. Any number of other memory implementations can be used, such as other types of memory modules (e.g., different kinds of Dual Inline Memory Modules (DIMMs), including but not limited to micro DIMMs or mini DIMMs).

[0123] To provide persistent storage for information such as data, applications, and operating systems, memory 1258 can also be coupled to programmable circuitry 1252 via interconnect 1256. In one example, memory 1258 can be implemented via a solid-state disk drive (SSDD). Other devices that can be used for memory 1258 include flash memory cards (such as Secure Digital (SD) cards, microSD cards, eXtreme Digital (XD) graphics cards, etc.) and Universal Serial Bus (USB) flash drives. In one example, the memory device may be or may include memory devices using chalcogenide glass, multi-threshold NAND flash memory, NOR flash memory, single-level or multi-level phase-change memory (PCM), resistive memory, nanowire memory, ferroelectric transistor random access memory (FeTRAM), antiferroelectric memory, magnetoresistive random access memory (MRAM) incorporating memristor technology, resistive memory including metal oxide base, oxygen vacancy base and conductive bridge random access memory (CB-RAM), or spin transfer torque (STT)-MRAM, devices based on spintronic magnetic junction memory, devices based on magnetic tunneling junction (MTJ), devices based on domain walls (DW) and spin-orbit transfer (STT) memory. OrbitTransfer (SOT) devices, thyristor-based memory devices, or combinations of the above devices or other memory.

[0124] In a low-power implementation, memory 1258 may be on-chip memory or a register associated with programmable circuitry 1252. However, in some instances, memory 1258 may be implemented using a micro hard disk drive (HDD). Furthermore, as a complement or alternative to the aforementioned techniques, any number of new technologies (such as resistive random access memory, phase-change memory, holographic memory, or chemical memory) may be used for memory 1258.

[0125] These components can communicate via Interconnect 1256. Interconnect 1256 can include any number of technologies, including Industry Standard Architecture (ISA), Extended ISA (EISA), Peripheral Component Interconnect (PCI), Peripheral Component Interconnect Extended (PCIx), PCI express (PCIe), or any number of other technologies. Interconnect 1256 can be, for example, a proprietary bus used in a SoC-based system. It can include other bus systems such as Inter-Integrated Circuit (I2C) interfaces, Serial Peripheral Interface (SPI) interfaces, point-to-point interfaces, and power buses.

[0126] Interconnect 1256 couples programmable circuitry 1252 to transceiver 1266 for communication with the connected edge device 1262. Transceiver 1266 can use any number of frequencies and protocols (e.g., 2.4 GHz transmission according to the IEEE 802.15.4 standard), and may employ protocols such as Bluetooth Special Interest Groups (SIGN). Bluetooth Low Energy (BLE) as defined by the Special Interest Group Low Energy (BLE) standard or Standards, etc. Any number of wireless devices configured for a specific wireless communication protocol can be used for connection to the connected edge device 1262. For example, a Wireless Local Area Network (WLAN) unit can be used to implement the standard according to the Institute of Electrical and Electronics Engineers (IEEE) 802.11. Communication. In addition, wireless wide area communication, for example, according to cellular protocols or other wireless wide area protocols, can be carried out via a wireless wide area network (WWAN) unit.

[0127] The wireless network transceiver 1266 (or multiple transceivers) can communicate using various standards or wireless devices for communication at different ranges. For example, the computing device 1250 can use a Bluetooth Low Energy (BLE) based local transceiver or another low-power wireless device to communicate with nearby devices (e.g., within approximately 10 meters) to save power. Alternatively, other medium-power wireless devices can be used to reach more distant connected edge devices 1262 (e.g., within approximately 50 meters). These two communication technologies can be implemented using a single wireless device at different power levels, or via separate transceivers (e.g., a local transceiver employing BLE and a transceiver employing...). This is implemented using a separate grid transceiver.

[0128] The device may include a wireless network transceiver 1266 (e.g., a radio transceiver) to communicate with devices or services in the edge cloud 1295 via LAN or WAN protocols. The wireless network transceiver 1266 may be a low-power wide-area (LPWA) transceiver conforming to the IEEE 802.15.4 or IEEE 802.15.4g standards. The computing device 1250 may employ LoRaWAN, developed by Semtech and the LoRa Alliance. TM (Long-distance wide area network) Communication over a wide area. The techniques described herein are not limited to these, but can be any number of other cloud transceivers, such as Sigfox and other technologies, that can be used to achieve long-distance, low-bandwidth communication. In addition, other communication techniques described in the IEEE 802.15.4e standard (such as time-slotted channel frequency hopping) can be employed.

[0129] As a supplement to the system mentioned for wireless network transceiver 1266, any number of other radio communications and protocols, as described herein, can be employed. For example, transceiver 1266 may include a cellular transceiver employing spread spectrum (SPA / SAS) communication to achieve high-speed communication. Furthermore, any number of other protocols (such as those for medium-speed communication and providing network communication) can be employed. (Network). Transceiver 1266 may include any number of radio devices compatible with Third Generation Partnership Project (3GPP) specifications (such as LTE and 5th Generation (5G) communication systems), which will be discussed in more detail at the end of this disclosure. A network interface controller (NIC) 1268 may be included to provide wired communication to nodes or other devices of the edge cloud 1295 (such as connected edge devices 1262, for example, operating in a mesh). Wired communication may provide Ethernet connectivity or may be based on other types of networks (such as Controller Area Network (CAN), Local Interconnect Network (LIN), DeviceNet, ControlNet, Data Highway+, PROFIBUS, or PROFINET, etc.). Additional NICs 1268 may be included to allow connectivity to a second network (e.g., a first NIC 1268 provides communication with the cloud via Ethernet, and a second NIC 1268 provides communication with other devices via another type of network).

[0130] Given various types of suitable communication from a device to another component or network, the suitable communication circuitry used by the device may include or be embodied by any one or more of components 1264, 1266, 1268, or 1270. Thus, in various instances, suitable means for communication (e.g., receiving, transmitting, etc.) may be embodied by such communication circuitry.

[0131] The computing device 1250 may include or be coupled to acceleration circuitry 1264, which may be embodied by one or more Artificial Intelligence (AI) accelerators, neural compute sticks, neuromorphic hardware, FPGAs, a row of GPUs, a row of xPUs / DPUs / IPUs / NPUs, one or more SoCs, one or more CPUs, one or more digital signal processors, application-specific ASICs, or other specialized processors or circuits designed to perform one or more specialized tasks. These tasks may include AI processing (including machine learning, training, inference, and classification operations), visual data processing, network data processing, object detection, rule analysis, etc. These tasks may also include specific edge computing tasks related to service management and service operations discussed elsewhere in this document.

[0132] Interconnect 1256 can couple programmable circuitry 1252 to a sensor hub or external interface 1270 for connecting additional devices or subsystems. These devices may include sensors 1272 (e.g., accelerometers, level sensors, flow sensors, optical sensors, camera sensors, temperature sensors, global navigation system (e.g., GPS) sensors, pressure sensors, atmospheric pressure sensors, etc.). The hub or interface 1270 can also be used to connect computing device 1250 to actuator 1274 (e.g., power switches, valve actuators, audible sound generators, visual warning devices, etc.).

[0133] In some alternative instances, various input / output (I / O) devices may be present within or connected to computing device 1250. For example, a display or other output device 1284 may be included to display information (such as sensor readings or actuator positions). Input devices 1286 (such as touchscreens or keyboards) may be included to accept input. Output devices 1284 may include any number of audio or visual displays, including simple visual outputs (such as binary status indicators (e.g., light-emitting diodes (LEDs)) and multi-character visual outputs) or more complex outputs (such as displays (e.g., liquid crystal display (LCD) screens) where the output of characters, graphics, multimedia objects, etc., is generated or produced from the operation of computing device 1250. In the case of this system, the display or console hardware may be used to provide output and receive input from the edge computing system; manage components or services of the edge computing system; verify the status of edge computing components or services; or perform any other number of management functions or service use cases.

[0134] Battery 1276 can power computing device 1250, but in instances where computing device 1250 is installed in a fixed location, it can have a power source coupled to the mains grid; or the battery can be used as a backup power source or for temporary power. Battery 1276 can be a lithium-ion battery or a metal-air battery (such as a zinc-air battery, an aluminum-air battery, a lithium-air battery, etc.).

[0135] The computing device 1250 may include a battery monitor / charger 1278 to track the state of charge (SoCh) of the battery 1276, if included. The battery monitor / charger 1278 may be used to monitor other parameters of the battery 1276 (such as the state of health (SoH) and state of function (SoF)) to provide fault prediction. The battery monitor / charger 1278 may include a battery monitoring integrated circuit (such as the LTC4020 or LTC2990 from Linear Technologies, the ADT7488A from ON Semiconductor in Phoenix, Arizona, or the UCD90xxx series IC from Texas Instruments in Dallas, Texas). The battery monitor / charger 1278 can transmit information about the battery 1276 to programmable circuitry 1252 via interconnect 1256. The battery monitor / charger 1278 may also include an analog-to-digital (ADC) converter that enables the programmable circuitry 1252 to directly monitor the voltage of the battery 1276 or the current from the battery 1276. Battery parameters can be used to determine actions that the computing device 1250 can perform (e.g., transmission frequency, mesh network operation, sensing frequency, etc.).

[0136] Power block 1280 or other power sources coupled to the grid can be coupled to battery monitor / charger 1278 to charge battery 1276. In some instances, power block 1280 can be replaced by a wireless power receiver to wirelessly obtain power, for example, via a loop antenna in computing device 1250. Wireless battery charging circuitry (such as the LTC4020 chip from Linear Technologies, Milpitas, California) can be included in battery monitor / charger 1278. Specific charging circuitry can be selected based on the size of battery 1276 and the resulting required current. Charging can be performed using standards such as the Airfuel standard issued by the Airfuel Consortium, the Qi wireless charging standard issued by the Wireless Power Consortium, or the Rezence charging standard issued by the Alliance for Wireless Power.

[0137] Memory 1258 may include instructions 1282 in the form of software, firmware, or hardware commands to implement the techniques described herein. Although these instructions 1282 are shown as blocks of code included in memory 1254 and memory 1258, it is understood that any block of code may be replaced with hardwired circuitry, such as that embedded in an application-specific integrated circuit (ASIC).

[0138] In one instance, instructions 1282 provided via memory 1254, storage 1258, or programmable circuitry 1252 may be embodied in a non-transitory machine-readable medium 1260, which includes code for directing programmable circuitry 1252 to perform electronic operations within computing device 1250. Programmable circuitry 1252 may access non-transitory machine-readable medium 1260 via interconnect 1256. For example, non-transitory machine-readable medium 1260 may be embodied by the device described for storage 1258, or may include a specific storage unit (such as an optical disc, flash drive, or any number of other hardware devices). Non-transitory machine-readable medium 1260 may include instructions to direct programmable circuitry 1252 to perform a specific sequence of actions or flow, as described, for example, in one or more flowcharts and one or more block diagrams relating to the operations and functions described above. As used herein, the terms "machine-readable medium" and "computer-readable medium" are interchangeable.

[0139] In a specific instance, instructions 1282 on programmable circuit 1252 (alone or in combination with instructions 1282 on machine-readable medium 1260) can configure the execution or operation of Trusted Execution Environment (TEE) 1290. In one instance, TEE 1290 serves as a protected area accessible to programmable circuit 1252 for secure execution of instructions and secure access to data. For example, it can be configured using... Software Guard Extensions (SGX) or Hardware security extensions Management Engine (ME) or A Converged Security Manageability Engine (CSME) is used to provide various implementations of the TEE 1290 and its associated security zones in programmable circuitry 1252 or memory 1254. Through the TEE 1290 and programmable circuitry 1252, other aspects of security hardening, hardware root of trust, and trusted or protected operation can be implemented in device 1250. As described above, the TEE 1290 can process privacy-sensitive telemetry data (e.g., AI inference on telemetry data). In these instances, the TEE 1290 can ensure that various interests (e.g., conditions) are met as conditions for accepting and / or disclosing telemetry data.

[0140] In further examples, machine-readable media also includes any tangible medium capable of storing, encoding, or carrying machine-executable instructions and causing the machine to perform any one or more methods of this disclosure, or capable of storing, encoding, or carrying data structures used by or associated with those instructions. Therefore, "machine-readable media" can include, but is not limited to, solid-state memory and optical and magnetic media. Specific examples of machine-readable media include non-volatile memory, including but not limited to, semiconductor memory devices (e.g., electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM)) and flash memory devices; magnetic disks (e.g., internal hard disks and removable disks); magneto-optical disks; and CD-ROM and DVD-ROM disks. Instructions embodied in machine-readable media can also be transmitted or received via a network interface device using a communication network employing a transmission medium and any of a variety of transmission protocols (e.g., Hypertext Transfer Protocol, HTTP).

[0141] Machine-readable media can be provided by storage devices or other means capable of carrying data in a non-transitory format. In one instance, information stored or otherwise provided on a machine-readable medium can represent instructions (such as the instructions themselves or a format from which instructions can be derived). Such a format from which instructions can be derived can include source code, encoded instructions (e.g., encoded instructions in compressed or encrypted form), packaged instructions (e.g., divided into multiple packages), etc. Information representing instructions in a machine-readable medium can be processed by processing circuitry into instructions to perform any of the operations discussed herein. For example, deriving instructions from information (e.g., processing by processing circuitry) can include: compiling (e.g., compiling from source code, object code, etc.), interpreting, loading, organizing (e.g., dynamic or static linking), encoding, decoding, encrypting, decrypting, packaging, unpacking, or otherwise manipulating information into instructions.

[0142] In one instance, deriving instructions can include assembling, compiling, or interpreting information (e.g., via processing circuitry) to create instructions from some intermediate or preprocessed format provided by a machine-readable medium. Instructions can be created by combining, unpacking, and modifying information provided in multiple parts. For example, the information may reside within multiple compressed source code packages (or object code or binary executable code, etc.) on one or more remote servers. The source code packages can be encrypted during transmission over a network, decrypted, decompressed, or assembled (e.g., linked) if necessary, compiled or interpreted on a local machine (e.g., compiled or interpreted into a library, standalone executable, etc.), and executed by the local machine.

[0143] Figure 10 The machine-executable instructions 1000 and 1001 can be stored in memory 1254, storage 1258 and / or on a removable non-transitory computer-readable storage medium (such as a CD or DVD).

[0144] Figure 13 yes Figure 11 and Figure 12B A block diagram of an exemplary implementation of the programmable circuits 1112 and 1252. In this example, Figure 11 and Figure 12B The programmable circuits 1112 and 1252 are implemented by the microprocessor 1300. For example, the microprocessor 1300 can be a general-purpose microprocessor (e.g., a general-purpose microprocessor circuit). The microprocessor 1300 executes... Figure 10 The flowchart contains part or all machine-readable instructions to effectively convey... Figure 2 The circuits in the code are instantiated as logic circuits to perform operations corresponding to those machine-readable instructions. In some such instances, Figure 8 and / or Figure 9 The circuitry in the microprocessor 1300 is instantiated by the hardware circuitry of the microprocessor 1300 in conjunction with machine-readable instructions. For example, the microprocessor 1300 can be implemented by multi-core hardware circuitry (such as a CPU, DSP, GPU, XPU, etc.). While it can include any number of exemplary cores 1302 (e.g., one core), this instance of the microprocessor 1300 is a multi-core semiconductor device including N cores. The cores 1302 of the microprocessor 1300 can operate independently or collaboratively to execute machine-readable instructions. For example, machine code corresponding to firmware, embedded software programs, or software programs can be executed by one core of core 1302, or by multiple cores of core 1302 at the same or different times. In some instances, the machine code corresponding to firmware, embedded software programs, or software programs is divided into threads and executed in parallel by two or more cores of core 1302. The software program can correspond to... Figure 10 The flowchart in the diagram represents part or all of the machine-readable instructions and / or operations.

[0145] Core 1302 can communicate via a first exemplary bus 1304. In some instances, the first bus 1304 can be implemented as a communication bus to enable communication with one or more associated cores 1302. For example, the first bus 1304 can be implemented as at least one of an internal integrated circuit (I2C) bus, a serial peripheral interface (SPI) bus, a PCI bus, or a PCIe bus. Additionally or alternatively, the first bus 1304 can be implemented as any other type of computing or electrical bus. Core 1302 can acquire data, instructions, and / or signals from one or more external devices via exemplary interface circuitry 1306. Core 1302 can output data, instructions, and / or signals to one or more external devices via interface circuitry 1306. While the core 1302 of this instance includes exemplary local memory 1320 (e.g., a Level 1 (L1) cache that can be divided into an L1 data cache and an L1 instruction cache), the microprocessor 1300 also includes exemplary shared memory 1310, which can be shared by the cores (e.g., a Level 2 (L2) cache) for high-speed access to data and / or instructions. Data and / or instructions can be transferred (e.g., shared) by writing to and / or reading from the shared memory 1310. The local memory 1320 and shared memory 1310 of each core 1302 can be multi-level cache memory and main memory (e.g., Figure 11 and Figure 12BThis is part of a hierarchy of storage devices (main memory 1114, 1116, 1254, 1258). Generally, higher-level memory in the hierarchy exhibits shorter access times and smaller storage capacity compared to lower-level memory. Variations within the cache hierarchy are managed (e.g., coordinated) by cache coherence strategies.

[0146] Each core 1302 may be referred to as a CPU, DSP, GPU, or any other type of hardware circuitry. Each core 1302 includes control unit circuitry 1314, arithmetic and logic (AL) circuitry (sometimes referred to as an ALU) 1316, multiple registers 1318, local memory 1320, and a second exemplary bus 1322. Other structures may exist. For example, each core 1302 may include vector unit circuitry, single-instruction multiple-data (SIMD) unit circuitry, load / store unit (LSU) circuitry, branch / jump unit circuitry, floating-point unit (FPU) circuitry, etc. The control unit circuitry 1314 includes semiconductor-based circuitry configured to control (e.g., coordinate) data movement within the corresponding core 1302. The AL circuitry 1316 includes semiconductor-based circuitry configured to perform one or more mathematical and / or logical operations on the data within the corresponding core 1302. In some instances, the AL circuit 1316 performs integer-based arithmetic. In other instances, the AL circuit 1316 also performs floating-point arithmetic. In still other instances, the AL circuit 1316 may include a first AL circuit performing integer-based arithmetic and a second AL circuit performing floating-point arithmetic. In some instances, the AL circuit 1316 may be referred to as an Arithmetic Logic Unit (ALU).

[0147] Register 1318 is a semiconductor-based structure used to store data and / or instructions (such as the results of one or more operations performed by the AL circuit 1316 corresponding to core 1302). For example, register 1318 may include one or more vector registers, one or more SIMD registers, one or more general-purpose registers, one or more flag registers, one or more segment registers, one or more machine-specific registers, one or more instruction pointer registers, one or more control registers, one or more debug registers, one or more memory management registers, one or more machine check registers, etc. Figure 13As shown, registers 1318 can be arranged in a group. Alternatively, registers 1318 can be organized in any other arrangement, form, or structure (e.g., by distributing them throughout core 1302 to reduce access time). The second bus 1322 can be implemented by at least one of an I2C bus, an SPI bus, a PCI bus, or a PCIe bus.

[0148] Each core 1302 and / or more generally, the microprocessor 1300 may include structures that complement and / or replace those structures shown and described above. For example, one or more clock circuits, one or more power supplies, one or more power gates, one or more cache home agents (CHAs), one or more converged / common mesh stops (CMSs), one or more shifters (e.g., one or more barrel shifters), and / or other circuitry may be present. The microprocessor 1300 is a semiconductor device fabricated to include a plurality of transistors interconnected to implement the above-described structures in one or more integrated circuits (ICs) contained in one or more packages.

[0149] Microprocessor 1300 may include one or more accelerators (e.g., acceleration circuitry, hardware accelerators, etc.) and / or work in conjunction with them. In some instances, accelerators are implemented by logic circuitry to perform certain tasks faster and / or more efficiently than a general-purpose processor. Examples of accelerators include ASICs and FPGAs (such as those discussed herein). GPUs, DSPs, and / or other programmable devices may also be accelerators. Accelerators may be onboard with microprocessor 1300, located in the same chip package as microprocessor 1300, and / or in one or more separate packages from microprocessor 1300.

[0150] Figure 14 yes Figure 11 and Figure 12B A block diagram of another exemplary implementation of the programmable circuits 1112 and 1252 is shown. In this example, the programmable circuits 1112 and 1252 are implemented by the FPGA circuit 1400. For example, the FPGA circuit 1400 can be implemented by an FPGA. For example, the FPGA circuit 1400 can be used to perform operations that, in other cases, can be executed by executing corresponding machine-readable instructions. Figure 13 The exemplary microprocessor 1300 is used for execution. However, once configured, the FPGA circuitry 1400 instantiates operations and / or functions corresponding to machine-readable instructions in the hardware, and therefore can often execute operations / functions faster than a general-purpose microprocessor executing corresponding software.

[0151] More specifically, with the above Figure 13 The microprocessor 1300 in the middle (which is a general-purpose device that can be programmed to execute commands) is a general-purpose device that can be programmed to execute commands. Figure 10 Compared to a flowchart or multiple flowcharts that represent some or all of the machine-readable instructions, but whose interconnections and logic circuitry are fixed at the time of manufacture, Figure 14 The FPGA circuit 1400 in the example includes interconnects and logic circuits, which can be configured, constructed, programmed, and / or interconnected in different ways after manufacturing to instantiate, for example, a circuit corresponding to a FPGA circuit. Figure 10 A flowchart or one or more of the flowcharts represent a portion or all of the operations / functions of machine-readable instructions. Specifically, the FPGA circuit 1400 can be considered an array of logic gates, interconnects, and switches. Switches can be programmed to change the way logic gates are interconnected, effectively forming one or more dedicated logic circuits (unless and until the FPGA circuit 1400 is reprogrammed). The configured logic circuits enable logic gates to cooperate in different ways to perform different operations on data received by the input circuits. Those operations can correspond to... Figure 10 One or more flowcharts represent a portion or all of the instructions (e.g., software and / or firmware). Thus, the FPGA circuit 1400 can be configured and / or constructed to effectively represent the corresponding... Figure 10 The FPGA circuit 1400 instantiates some or all of the machine-readable instructions of one or more flowcharts into a dedicated logic circuit, thereby executing the operations / functions corresponding to those software instructions in a dedicated manner similar to that of an ASIC. Therefore, the FPGA circuit 1400 can execute operations / functions corresponding to the instructions faster than a general-purpose microprocessor. Figure 10 The same operation / function for some or all of the machine-readable instructions.

[0152] exist Figure 14In some instances, the FPGA circuit 1400 is configured and / or constructed in response to being programmed (and / or reprogrammed once or multiple times) based on a binary file. In some instances, the binary file can be compiled and / or generated based on instructions in a Hardware Description Language (HDL) (such as Lucid, VHSIC Hardware Description Language (VHDL), or Verilog). For example, a user (e.g., a human user, a machine user, etc.) can write code or programs corresponding to one or more operations / functions in the HDL; this code / program can be translated into a low-level language as needed; and the code / program (e.g., low-level language code / program) can be converted (e.g., by a compiler, software application, etc.) into a binary file. In some instances, Figure 14 The FPGA circuit 1400 in the middle can access and / or load binary files to enable Figure 14 The FPGA circuit 1400 in the file is configured and / or constructed to perform one or more operations / functions. For example, a binary file may consist of a bit stream (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), data (e.g., computer-readable data, machine-readable data, etc.), and / or... Figure 14 The FPGA circuitry 1400 is implemented using machine-readable instructions accessible to it. Figure 14 The configuration and / or construction of the FPGA circuit 1400 or one or more portions thereof.

[0153] In some instances, binary files are compiled, generated, transformed, and / or otherwise output from a unified software platform used for programming FPGAs. For example, the unified software platform can translate first instructions (e.g., code or program) corresponding to one or more operations / functions in a high-level language (e.g., C, C++, Python, etc.) into second instructions corresponding to one or more operations / functions in an HDL. In some such instances, binary files are compiled, generated, and / or otherwise output from the unified software platform based on the second instructions. In some instances, Figure 14 The FPGA circuit 1400 in the middle can access and / or load binary files to enable Figure 14 The FPGA circuit 1400 in the file is configured and / or constructed to perform one or more operations / functions. For example, a binary file may consist of a bit stream (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), data (e.g., computer-readable data, machine-readable data, etc.), and / or... Figure 14 The FPGA circuitry 1400 is implemented using machine-readable instructions accessible to it. Figure 14 The configuration and / or construction of the FPGA circuit 1400 or one or more portions thereof.

[0154] Figure 14 The FPGA circuitry 1400 includes exemplary input / output (I / O) circuitry 1402 for acquiring data from and / or outputting data to exemplary configuration circuitry 1404 and / or external hardware 1406. For example, configuration circuitry 1404 may be implemented by interface circuitry that can acquire binary files (which may be implemented as bitstreams, data, and / or machine-readable instructions) to configure FPGA circuitry 1400 or one or more portions thereof. In some such instances, configuration circuitry 1404 may acquire binary files from a user, a machine (e.g., hardware circuitry (e.g., programmable circuitry or dedicated circuitry) that can implement artificial intelligence / machine learning (AI / ML) models to generate binary files), and / or any combination thereof. In some instances, external hardware 1406 may be implemented by external hardware circuitry. For example, external hardware 1406 may be implemented by… Figure 13 It is implemented using the 1300 microprocessor.

[0155] The FPGA circuit 1400 also includes an array of exemplary logic gates 1408, a plurality of exemplary configurable interconnects 1410, and exemplary memory circuitry 1412. The logic gates 1408 and the configurable interconnects 1410 can be configured to instantiate corresponding to... Figure 10 One or more operations / functions and / or other required operations of at least a portion of the machine-readable instructions. Figure 14 The logic gate circuit 1408 shown is fabricated in the form of blocks or groups. Each block includes semiconductor-based electrical structures that can be configured into logic circuits. In some instances, the electrical structures include logic gates (e.g., AND gates, OR gates, NOR gates, etc.) that provide the basic building blocks for the logic circuits. Each logic gate circuit 1408 contains electrically controllable switches (e.g., transistors) to implement the configuration of the electrical structures and / or logic gates to form a circuit that performs the desired operation / function. The logic gate circuit 1408 may include other electrical structures (such as look-up tables (LUTs), registers (e.g., flip-flops or latches), multiplexers, etc.).

[0156] The configurable interconnect 1410 of the example shown is a conductive path, trace, via, etc., which may include electrically controllable switches (e.g., transistors) whose states can be changed by programming (e.g., using an HDL instruction language) to activate or deactivate one or more connections between one or more logic gates 1408, thereby programming the desired logic circuitry.

[0157] The storage circuit 1412 in the illustrated example is configured to store one or more results of one or more operations performed by the corresponding logic gates. The storage circuit 1412 can be implemented using registers, etc. In the illustrated example, the storage circuit 1412 is distributed within the logic gate circuit 1408 to facilitate access and improve execution speed.

[0158] Figure 14 The exemplary FPGA circuit 1400 also includes exemplary dedicated operating circuitry 1414. In this example, dedicated operating circuitry 1414 includes dedicated circuitry 1416, which can be invoked to implement common functions without requiring on-site programming of these functions. Examples of such dedicated circuitry 1416 include memory (e.g., DRAM) controller circuitry, PCIe controller circuitry, clock circuitry, transceiver circuitry, memory, and multiplier-accumulator circuitry. Other types of dedicated circuitry may be present. In some instances, FPGA circuitry 1400 may also include exemplary general-purpose programmable circuitry 1418 (e.g., exemplary CPU 1420 and / or exemplary DSP 1422). Additionally or alternatively, other general-purpose programmable circuitry 1418 (e.g., GPU, XPU, etc.) may be present, which can be programmed to perform other operations.

[0159] Although Figure 13 and Figure 14 It shows Figure 11 and Figure 12B The two exemplary implementations of programmable circuits 1112 and 1252 are shown, but many other methods are conceivable. For example, FPGA circuitry may include an onboard CPU (e.g., Figure 13 (One or more exemplary CPUs 1420 in the example). Therefore, Figure 11 and Figure 12B The programmable circuits 1112 and 1252 in the middle can be further combined by at least Figure 13 The exemplary microprocessor 1300 and Figure 14 This is implemented using an exemplary FPGA circuit 1400. In some such hybrid instances, Figure 13 One or more cores 1302 in the system can execute commands by Figure 10 The first part of a machine-readable instruction represented by one or more flowcharts in the diagram is used to perform one or more first operations / functions. Figure 14 The FPGA circuit 1400 in the FPGA can be configured and / or constructed to perform operations corresponding to those performed by the FPGA circuit 1400 in ... Figure 10 The flowchart in the diagram represents one or more second operations / functions in the second part of machine-readable instructions, and / or the ASIC can be configured and / or constructed to perform operations corresponding to those specified by the ASIC. Figure 10 The flowchart represents one or more third operations / functions in the third part of a machine-readable instruction.

[0160] It should be understood that, Figure 8 and / or Figure 9 Some or all of the circuitry can therefore be instantiated at the same or different times. For example, Figure 13 The same and / or different parts of the microprocessor 1300 can be programmed to execute one or more parts of machine-readable instructions at the same and / or different times. In some instances, Figure 14 The same and / or different parts of the FPGA circuit 1400 can be configured and / or constructed to perform operations / functions corresponding to one or more parts of machine-readable instructions at the same and / or different times.

[0161] In some instances, Figure 8 and / or Figure 9 Some or all of the circuitry can be instantiated, for example, in one or more threads that execute concurrently and / or sequentially. For example, Figure 13 The microprocessor 1300 can execute machine-readable instructions in one or more threads that execute concurrently and / or sequentially. In some instances, Figure 14 The FPGA circuit 1400 can be configured and / or constructed to perform operations / functions concurrently and / or sequentially. Furthermore, in some instances, Figure 8 and / or Figure 9 Part or all of the processor circuit 702 and / or RIC circuit 710 in the processor circuit can be Figure 13 It is implemented in one or more virtual execution environments (e.g., virtual machines and / or containers) that execute on the microprocessor 1300.

[0162] In some instances, Figure 11 and Figure 12B The programmable circuits 1112 and 1252 can be housed in one or more packages. For example, Figure 13 The microprocessor 1300 and / or Figure 14 The FPGA circuitry 1400 can be housed in one or more packages. In some instances, the XPU can be... Figure 11 and Figure 12A The programmable circuits 1112 and 1252 in the package are used to implement this, and they can be in one or more packages. For example, the XPU can be included in a package containing a CPU (e.g., Figure 13 The microprocessor 1300 in Figure 14 CPU 1420, etc. in one package), and DSP in another package (e.g., Figure 14 DSP 1422 in one package), GPU in another package, and FPGA in yet another package (e.g., Figure 14 (FPGA circuit 1400 in the middle).

[0163] Figure 15 A block diagram of an exemplary software distribution platform 1505 is shown, which is used to distribute software (such as...) Figure 11 and Figure 12A The exemplary machine-readable instructions 1132, 1282 in the software distribution platform are distributed to other hardware devices (e.g., hardware devices owned and / or operated by a third party from the owner and / or operator of the software distribution platform). The exemplary software distribution platform 1505 can be implemented by any computer server, data facility, cloud service, etc., capable of storing software and transferring it to other computing devices. A third party can be a customer of the entity that owns and / or operates the software distribution platform 1505. For example, the entity owning and / or operating the software distribution platform 1505 can be the software (e.g., software...). Figure 11 and Figure 12B The developer, seller, and / or licensor of the exemplary machine-readable instructions 1132, 1282 in the example are listed. Third parties may be consumers, users, retailers, OEMs, etc., who purchase and / or license the software for use and / or resell and / or sublicense. In the illustrated example, the software distribution platform 1505 includes one or more servers and one or more storage devices. The storage devices store the machine-readable instructions 1132, 1282, which may correspond to... Figure 10 The exemplary machine-readable instructions are as described above. One or more servers of the exemplary software distribution platform 1505 communicate with the exemplary network 1510, which may correspond to any one or more Internet and / or any of the exemplary networks described above. In some instances, as part of a business transaction, one or more servers respond to a request to deliver software to a requesting party. Payment for the delivery, sale, and / or licensing of the software may be processed by one or more servers of the software distribution platform and / or through a third-party payment entity. The servers enable purchasers and / or licensors to download machine-readable instructions 1132, 1282 from the software distribution platform 1505. For example, this may correspond to... Figure 10 Software containing exemplary machine-readable instructions can be downloaded to exemplary programmable circuit platforms 1100 and 1250, which will execute machine-readable instructions 1132 and 1282 to implement processor circuitry 702 and / or RIC circuitry 710. In some instances, one or more servers of software distribution platform 1505 periodically distribute the software (e.g., Figure 11 and Figure 12B The exemplary machine-readable instructions 1132, 1282 in the document provide, transmit, and / or force updates to ensure that improvements, patches, updates, etc., are distributed and applied to the software at the end-user device. Although referred to as software above, distributed “software” may alternatively be firmware.

[0164] As can be understood from the foregoing, exemplary systems, apparatuses, artifacts, and methods for improving privacy in follow services have been disclosed. By migrating virtual execution environments based on the location of end-user devices while simultaneously maintaining the privacy of the end-user devices (e.g., identification, location, etc.), the disclosed systems, apparatuses, artifacts, and methods improve the efficiency of using computing devices and the performance of edge-based workload computing. Therefore, the disclosed systems, apparatuses, artifacts, and methods address one or more improvements to the operation of machines (such as computers, networks, and / or other electronic and / or mechanical devices).

[0165] This document discloses exemplary methods, apparatuses, systems, and artifacts for migrating cloud-based workloads. Further examples and combinations thereof include: Example 1 includes a non-transitory machine-readable storage medium comprising instructions to cause programmable circuitry to transmit at least anonymous information corresponding to a user device to a network device, and to migrate a virtual execution environment from a first computing device to a second computing device based on a response from the network device, the virtual execution environment performing at least a portion of a workload for the user device.

[0166] Example 2 includes the machine-readable storage medium of Example 1, wherein instructions cause programmable circuitry to generate an evaluation key that facilitates the processing of anonymous information without decrypting the anonymous information.

[0167] Example 3 includes the machine-readable storage medium of Example 2, wherein the evaluation key will facilitate the processing of anonymous information without requiring the network device to determine at least one of the user equipment's location or user equipment's identifier.

[0168] Example 4 includes the machine-readable storage medium of Example 1, wherein instructions cause programmable circuitry to employ unintentional encryption to encrypt location information corresponding to a user device, the encrypted location information being included in anonymous information.

[0169] Example 5 includes the machine-readable storage medium of Example 4, wherein instructions cause programmable circuitry to encrypt location information after the location of a user equipment changes by more than a threshold amount.

[0170] Example 6 includes the machine-readable storage medium of Example 1, wherein instructions cause programmable circuitry to determine a second computing device based on a response from a network device.

[0171] Example 7 includes the machine-readable storage medium of Example 1, wherein instructions cause programmable circuitry to track the location of a user equipment.

[0172] Example 8 includes the machine-readable storage medium of Example 1, wherein instructions cause programmable circuitry to fuzzify user traffic information corresponding to a user device and to transmit the fuzzy user traffic information to a network device.

[0173] Example 9 includes the machine-readable storage medium of Example 1, wherein instructions cause programmable circuitry to decrypt a response from a network device to identify a candidate edge computing device, and to determine a second computing device based on at least one of the capabilities of a second computing device, the capacity of a second computing device, or the location of a second computing device.

[0174] Example 10 includes an apparatus for migrating cloud-based workloads, the apparatus including interface circuitry, machine-readable instructions, and programmable circuitry for: instantiating or executing at least one of the machine-readable instructions to transmit anonymous information corresponding to a user device to a network device; and migrating a virtual execution environment from a first computing device to a second computing device based on a response from the network device, the virtual execution environment performing at least a portion of the workload for the user device.

[0175] Example 11 includes the apparatus of Example 10, wherein programmable circuitry generates an evaluation key that facilitates the processing of anonymous information without decrypting it.

[0176] Example 12 includes the apparatus of Example 11, wherein evaluating the key will facilitate the processing of anonymous information without requiring the network device to determine at least one of the location of the user equipment or the identifier of the user equipment.

[0177] Example 13 includes the apparatus of Example 10, wherein the programmable circuitry employs unintentional encryption to encrypt location information corresponding to a user device, the encrypted location information being included in anonymous information.

[0178] Example 14 includes the apparatus of Example 13, wherein the programmable circuitry encrypts location information after the location of the user equipment changes by more than a threshold amount.

[0179] Example 15 includes the apparatus of Example 10, wherein programmable circuitry determines a second computing device based on a response from a network device.

[0180] Example 16 includes the apparatus of Example 10, wherein programmable circuitry tracks the location of user equipment.

[0181] Example 17 includes the apparatus of Example 10, wherein the programmable circuitry encrypts identification information corresponding to a user equipment, the encrypted identification information being included in anonymous information.

[0182] Example 18 includes the apparatus of Example 10, wherein the programmable circuitry performs fuzzing on user traffic information corresponding to a user device and transmits the fuzzy user traffic information to a network device.

[0183] Example 19 includes the apparatus of Example 10, wherein the programmable circuitry decrypts a response from a network device to identify a candidate edge computing device and determines a second computing device based on at least one of the capabilities of the second computing device, the capacity of the second computing device, or the location of the second computing device.

[0184] Example 20 includes a non-transitory machine-readable storage medium comprising: interface circuitry for transmitting anonymous information corresponding to a user device to a network device; and edge device selection circuitry for migrating a virtual execution environment from a first computing device to a second computing device based on a response from the network device, the virtual execution environment performing at least a portion of a workload for the user device.

[0185] Example 21 includes a non-transitory machine-readable storage medium comprising instructions to cause programmable circuitry to process anonymous information using at least a key, to perform processing of the anonymous information without knowing the anonymous information to generate a list of candidate edge computing devices for performing workloads, to transfer the list of candidate edge computing devices, and to perform a migration protocol to migrate a virtual execution environment to an edge computing device selected from the list of candidate edge computing devices.

[0186] Example 22 includes the non-transitory machine-readable storage medium of Example 21, wherein anonymous information is encrypted and programmable circuitry processes the anonymous information without decrypting it.

[0187] Example 23 includes the non-transitory machine-readable storage medium of Example 21, wherein the anonymous information includes location information, and the programmable circuitry generates a list of candidate edge computing devices based on the location information.

[0188] Example 24 includes the non-transitory machine-readable storage medium of Example 23, wherein programmable circuitry generates a list of candidate edge computing devices based on location information without determining the location information.

[0189] Example 25 includes the non-transitory machine-readable storage medium of Example 21, wherein programmable circuitry will execute a migration protocol for an end user device without knowing the identification information corresponding to the end user device.

[0190] While certain exemplary methods, apparatuses, and articles of manufacture are disclosed herein, the scope of this patent is not limited thereto. Rather, this patent covers all methods, apparatuses, and articles of manufacture that fall fully within the scope of the claims of this patent.

Claims

1. A machine-readable storage medium comprising instructions to cause a programmable circuit to perform at least the following operations: To transmit anonymous information corresponding to the user equipment to the network device; and Based on a response from the network device, a virtual execution environment is migrated from a first computing device to a second computing device, the virtual execution environment being at least a portion of the workload performed by the user equipment.

2. The machine-readable storage medium of claim 1, wherein the instructions cause the programmable circuit to generate an evaluation key that facilitates the processing of the anonymous information without decrypting the anonymous information.

3. The machine-readable storage medium of claim 2, wherein the evaluation key facilitates the processing of the anonymized information without the network device determining at least one of the location of the user equipment or the identifier of the user equipment.

4. The machine-readable storage medium of claim 1, wherein the instructions cause the programmable circuit to use an unintentional encryption technique to encrypt location information corresponding to the user equipment, the encrypted location information being included in the anonymous information.

5. The machine-readable storage medium of claim 4, wherein the instructions cause the programmable circuit to encrypt the location information after the location change of the user equipment exceeds a threshold amount.

6. The machine-readable storage medium according to any one of claims 1 to 5, wherein the instructions cause the programmable circuitry to determine the second computing device based on the response from the network device.

7. The machine-readable storage medium according to any one of claims 1 to 5, wherein the instructions cause the programmable circuitry to track the location of the user equipment.

8. The machine-readable storage medium according to any one of claims 1 to 5, wherein the instructions cause the programmable circuitry to perform the following operations: The user traffic information corresponding to the user equipment is subjected to fuzzy processing; and The fuzzy user traffic information is transmitted to the network device.

9. The machine-readable storage medium according to any one of claims 1 to 5, wherein the instructions cause the programmable circuit to perform the following operations: Decrypt the response from the network device to confirm the candidate edge computing device; and The second computing device is determined based on at least one of the capabilities of the second computing device, the capacity of the second computing device, or the location of the second computing device.

10. An apparatus for migrating cloud-based workloads, the apparatus comprising: Interface circuit; Machine-readable instructions; as well as A programmable circuit for instantiating or executing at least one of the machine-readable instructions to perform the following operations: This enables the transmission of anonymous information corresponding to the user device to the network device. as well as Based on a response from the network device, a virtual execution environment is migrated from a first computing device to a second computing device, the virtual execution environment being at least a portion of the workload performed by the user equipment.

11. The apparatus of claim 10, wherein the programmable circuitry generates an evaluation key that facilitates the processing of the anonymous information without decrypting the anonymous information.

12. The apparatus of claim 11, wherein the evaluation key facilitates the processing of the anonymized information without the network device determining at least one of the location of the user equipment or the identifier of the user equipment.

13. The apparatus of claim 10, wherein the programmable circuit employs an unintentional encryption technique to encrypt location information corresponding to the user equipment, the encrypted location information being included in the anonymized information.

14. The apparatus of claim 13, wherein the programmable circuit encrypts the location information after the location change of the user equipment exceeds a threshold amount.

15. The apparatus of any one of claims 10 to 14, wherein the programmable circuitry determines the second computing device based on the response from the network device.

16. The apparatus of any one of claims 10 to 14, wherein the programmable circuitry tracks the location of the user equipment.

17. The apparatus of claim 10, wherein the programmable circuit encrypts identification information corresponding to the user equipment, the encrypted identification information being included in the anonymized information.

18. The apparatus according to any one of claims 10 to 14, wherein the programmable circuitry performs the following operations: The user traffic information corresponding to the user equipment is subjected to fuzzy processing; and The fuzzy user traffic information is transmitted to the network device.

19. The apparatus according to any one of claims 10 to 14, wherein the programmable circuitry performs the following operations: Decrypt the response from the network device to confirm the candidate edge computing device; and The second computing device is determined based on at least one of the capabilities of the second computing device, the capacity of the second computing device, or the location of the second computing device.

20. A machine-readable storage medium comprising: An interface circuit is used to transmit anonymous information corresponding to a user device to a network device. as well as An edge device selection circuit is used to migrate a virtual execution environment from a first computing device to a second computing device based on a response from the network device, the virtual execution environment being at least a portion of the workload performed by the user equipment.

21. The machine-readable storage medium of claim 20, further comprising cryptographic circuitry for generating an evaluation key that facilitates the processing of the anonymous information without decrypting the anonymous information.

22. An apparatus comprising: A means for transmitting anonymous information corresponding to a user device to a network device; as well as A means for migrating a virtual execution environment from a first computing device to a second computing device based on a response from the network device, the virtual execution environment being at least a portion of the workload performed by the user equipment.

23. The apparatus of claim 22, further comprising means for generating an evaluation key, the evaluation key facilitating the processing of the anonymous information without decrypting the anonymous information.

24. A method comprising: This enables the transmission of anonymous information corresponding to the user device to the network device. as well as Based on a response from the network device, a virtual execution environment is migrated from a first computing device to a second computing device, the virtual execution environment being at least a portion of the workload performed by the user equipment.

25. The method of claim 24, further comprising: An evaluation key is generated that facilitates the processing of the anonymous information without decrypting it.