Edge deployment with single touch point

WO2026174485A1PCT designated stage Publication Date: 2026-08-27LENOVO GLOBAL TECH (TAIWAN) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/078192
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2026-08-27

Smart Images

  • Figure CN2025078192_27082026_PF_FP_ABST
    Figure CN2025078192_27082026_PF_FP_ABST
Patent Text Reader

Abstract

A method for edge deployment with a single touch point includes receiving, by a first edge computing device, a deployment request from an external electronic device. The method includes, in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and one or more additional edge computing devices. The method includes receiving, by the first edge computing device a deployment instruction from the external electronic device and forwarding the deployment instruction to one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.
Need to check novelty before this filing date? Find Prior Art

Description

EDGE DEPLOYMENT WITH SINGLE TOUCH POINTFIELD

[0001] The subject matter disclosed herein relates to edge deployment and more particularly relates to edge deployment with single touch point.BACKGROUND

[0002] During edge deployment operations, such as installation of an operating system or application, updating software, configuring an application, removing an application, or the like, at a customer’s location, an onsite engineer may not have access to the customer’s network. In such cases, the onsite engineer, connects an external electronic device, for example, a laptop, one by one to each of the edge servers, to perform edge deployment operations. Connecting the external electronic device to the edge servers one by one to deploy the edge servers one at a time may be inconvenient and time consuming for the onsite engineer. BRIEF SUMMARY

[0003] A method for edge deployment with single touch point is disclosed. An apparatus and computer program product also perform the functions of the method. The method includes receiving, by a first edge computing device, a deployment request from the external electronic device to deploy software on the first computing device and one or more additional edge computing devices. The method includes, in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices. The method includes receiving, by the first edge computing device, a deployment instruction from the external electronic device and forwarding the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.

[0004] An apparatus for edge deployment with single touch point includes a processor and non-transitory computer readable storage media storing code. The code is executable by the processor to perform operations that include receiving, by a first edge computing device, a deployment request from the external electronic device to deploy software on the first computing device and one or more additional edge computing devices. The operations include, in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices. The operations include receiving, by the first edge computing device, a deployment instruction from the external electronic device and forwarding the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.

[0005] A program product for edge deployment with single touch point includes a non-transitory computer readable storage medium storing code. The code is configured to be executable by a processor to perform operations that include receiving, by a first edge computing device, a deployment request from the external electronic device to deploy software on the first computing device and one or more additional edge computing devices. The operations include, in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices. The operations include receiving, by the first edge computing device, a deployment instruction from the external electronic device and forwarding the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.BRIEF DESCRIPTION OF THE DRAWINGS

[0006] A more particular description of the embodiments briefly described above will be rendered by reference to specific embodiments that are illustrated in the appended drawings. Understanding that these drawings depict only some embodiments and are not therefore to be considered to be limiting of scope, the embodiments will be described and explained with additional specificity and detail through the use of the accompanying drawings, in which:

[0007] Figure 1 is a schematic block diagram illustrating a system for software deployment in multiple edge computing devices, according to various embodiments;

[0008] Figure 2 is a schematic block diagram illustrating an apparatus for software deployment in multiple edge computing devices, according to various embodiments;

[0009] Figure 3 is a schematic block diagram illustrating another apparatus for software deployment in multiple edge computing devices, according to various embodiments;

[0010] Figure 4 is a schematic flow chart diagram illustrating a method for software deployment in multiple edge computing devices, according to various embodiments; and

[0011] Figure 5 is a schematic flow chart diagram illustrating another method for software deployment in multiple edge computing devices, according to various embodiments.DETAILED DESCRIPTION

[0012] As will be appreciated by one skilled in the art, aspects of the embodiments may be embodied as a system, method or program product. Accordingly, embodiments may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc. ) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a “circuit, ” “module” or “system. ” Furthermore, embodiments may take the form of a program product embodied in one or more computer readable storage devices storing machine readable code, computer readable code, and / or program code, referred hereafter as code. The storage devices, in some embodiments, are tangible, non-transitory, and / or non-transmission.

[0013] Many of the functional units described in this specification have been labeled as modules, in order to more particularly emphasize their implementation independence. For example, a module may be implemented as a hardware circuit comprising custom very large scale integrated ( “VLSI” ) circuits or gate arrays, off-the-shelf semiconductors such as logic chips, transistors, or other discrete components. A module may also be implemented in programmable hardware devices such as a field programmable gate array ( “FPGA” ) , programmable array logic, programmable logic devices or the like.

[0014] Modules may also be implemented in code and / or software for execution by various types of processors. An identified module of code may, for instance, comprise one or more physical or logical blocks of executable code which may, for instance, be organized as an object, procedure, or function. Nevertheless, the executables of an identified module need not be physically located together, but may comprise disparate instructions stored in different locations which, when joined logically together, comprise the module and achieve the stated purpose for the module.

[0015] Indeed, a module of code may be a single instruction, or many instructions, and may even be distributed over several different code segments, among different programs, and across several memory devices. Similarly, operational data may be identified and illustrated herein within modules, and may be embodied in any suitable form and organized within any suitable type of data structure. The operational data may be collected as a single data set, or may be distributed over different locations including over different computer readable storage devices. Where a module or portions of a module are implemented in software, the software portions are stored on one or more computer readable storage devices.

[0016] Any combination of one or more computer readable medium may be utilized. The computer readable medium may be a computer readable storage medium. The computer readable storage medium may be a storage device storing the code. The storage device may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, holographic, micromechanical, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable) , or electrical signals transmitted through a wire.

[0017] More specific examples (a non-exhaustive list) of the storage device would include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory ( “RAM” ) , a read-only memory ( “ROM” ) , an erasable programmable read-only memory ( “EPROM” or Flash memory) , a portable compact disc read-only memory ( “CD-ROM” ) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this document, a computer readable storage medium may be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.

[0018] Code for carrying out operations for embodiments may be written in any combination of one or more programming languages including an object oriented programming language such as Python, Ruby, R, Java, Java Script, Smalltalk, C++, C sharp, Lisp, Clojure, PHP, or the like, and conventional procedural programming languages, such as the "C" programming language, or the like, and / or machine languages such as assembly languages. The code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network ( “LAN” ) or a wide area network ( “WAN” ) , or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider) .

[0019] Reference throughout this specification to “one embodiment, ” “an embodiment, ” or similar language means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, appearances of the phrases “in one embodiment, ” “in an embodiment, ” and similar language throughout this specification may, but do not necessarily, all refer to the same embodiment, but mean “one or more but not all embodiments” unless expressly specified otherwise. The terms “including, ” “comprising, ” “having, ” and variations thereof mean “including but not limited to, ” unless expressly specified otherwise. An enumerated listing of items does not imply that any or all of the items are mutually exclusive, unless expressly specified otherwise. The terms “a, ” “an, ” and “the” also refer to “one or more” unless expressly specified otherwise.

[0020] Furthermore, the described features, structures, or characteristics of the embodiments may be combined in any suitable manner. In the following description, numerous specific details are provided, such as examples of programming, software modules, user selections, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., to provide a thorough understanding of embodiments. One skilled in the relevant art will recognize, however, that embodiments may be practiced without one or more of the specific details, or with other methods, components, materials, and so forth. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of an embodiment.

[0021] Aspects of the embodiments are described below with reference to schematic flowchart diagrams and / or schematic block diagrams of methods, apparatuses, systems, and program products according to embodiments. It will be understood that each block of the schematic flowchart diagrams and / or schematic block diagrams, and combinations of blocks in the schematic flowchart diagrams and / or schematic block diagrams, can be implemented by code. This code may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the schematic flowchart diagrams and / or schematic block diagrams block or blocks.

[0022] The code may also be stored in a storage device that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the storage device produce an article of manufacture including instructions which implement the function / act specified in the schematic flowchart diagrams and / or schematic block diagrams block or blocks.

[0023] The code may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the code which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0024] The schematic flowchart diagrams and / or schematic block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of apparatuses, systems, methods and program products according to various embodiments. In this regard, each block in the schematic flowchart diagrams and / or schematic block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions of the code for implementing the specified logical function (s) .

[0025] It should also be noted that, in some alternative implementations, the functions noted in the block may occur out of the order noted in the Figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. Other steps and methods may be conceived that are equivalent in function, logic, or effect to one or more blocks, or portions thereof, of the illustrated Figures.

[0026] Although various arrow types and line types may be employed in the flowchart and / or block diagrams, they are understood not to limit the scope of the corresponding embodiments. Indeed, some arrows or other connectors may be used to indicate only the logical flow of the depicted embodiment. For instance, an arrow may indicate a waiting or monitoring period of unspecified duration between enumerated steps of the depicted embodiment. It will also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and code.

[0027] The description of elements in each figure may refer to elements of proceeding figures. Like numbers refer to like elements in all figures, including alternate embodiments of like elements.

[0028] As used herein, a list with a conjunction of “and / or” includes any single item in the list or a combination of items in the list. For example, a list of A, B and / or C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C or a combination of A, B and C. As used herein, a list using the terminology “one or more of” includes any single item in the list or a combination of items in the list. For example, one or more of A, B and C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C or a combination of A, B and C. As used herein, a list using the terminology “one of” includes one and only one of any single item in the list. For example, “one of A, B and C” includes only A, only B or only C and excludes combinations of A, B and C. As used herein, “a member selected from the group consisting of A, B, and C, ” includes one and only one of A, B, or C, and excludes combinations of A, B, and C. ” As used herein, “a member selected from the group consisting of A, B, and C and combinations thereof” includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C or a combination of A, B and C.

[0029] A method for edge deployment with single touch point is disclosed. An apparatus and computer program product also perform the functions of the method. The method includes receiving, by a first edge computing device, a deployment request from the external electronic device to deploy software on the first computing device and one or more additional edge computing devices. The method includes, in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices. The method includes receiving, by the first edge computing device, a deployment instruction from the external electronic device and forwarding the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.

[0030] In some embodiments, the method includes validating a Security Protocol and Data Model ( “SPDM” ) certificate for each of the one or more additional edge computing devices. In some embodiments, the method includes, determining for each of the additional edge computing devices, that its root Certificate Authority ( “CA” ) is identical to a root CA of the first edge computing device to identify one or more valid edge computing devices of the one or more additional edge computing devices. In other embodiments, the first edge computing device receives the SPDM certificate from each of the additional edge computing devices by sending a validation request to each of the additional edge computing devices.

[0031] In some embodiments, the external electronic device interfaces with a Baseboard Management Controller ( “BMC” ) of the first edge computing device. In other embodiments, the secure communication channel includes a wired connection that includes a switch or a router. In other embodiments, the secure communication channel includes a daisy-chain wired connection. In other embodiments, the secure communication channel includes a wireless communication. In some embodiments, the external electronic device may be present on site with the first edge computing device and the one or more additional edge computing devices. In some embodiments, the first edge computing device and the one or more additional edge computing devices are initially in a pre-deployment phase.

[0032] An apparatus for edge deployment with single touch point includes a processor and non-transitory computer readable storage media storing code. The code is executable by the processor to perform operations that include receiving, by a first edge computing device, a deployment request from the external electronic device to deploy software the first computing device and on one or more additional edge computing devices. The operations include, in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices. The operations include receiving, by the first edge computing device, a deployment instruction from the external electronic device and forwarding the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.

[0033] In some embodiments, the operations include validating an SPDM certificate for each of the one or more additional edge computing devices to identify one or more valid edge computing devices. In other embodiments, the operations include determining for each of the additional edge computing devices, that its root CA is identical to a root CA of the first edge computing device to identify one or more valid edge computing devices of the one or more additional edge computing devices. In some embodiments, the first edge computing device receives the SPDM certificate from each of the additional edge computing devices by sending a validation request to each of the additional edge computing devices.

[0034] In some embodiments, the external electronic device interfaces with a BMC of the first edge computing device. In other embodiments, the secure communication channel includes a wired connection that includes a switch or a router. In other embodiments, the secure communication channel includes a daisy-chain wired connection. In other embodiments, the secure communication channel includes a wireless communication. In some embodiments, the external electronic device is present on site with the first edge computing device and the one or more additional edge computing devices.

[0035] A program product for edge deployment with single touch point includes a non-transitory computer readable storage medium storing code. The code is configured to be executable by a processor to perform operations that include receiving, by a first edge computing device, a deployment request from the external electronic device to deploy software on the first computing device and one or more additional edge computing devices. The operations include, in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices. The operations include receiving, by the first edge computing device, a deployment instruction from the external electronic device and forwarding the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.

[0036] In some embodiments, the operations include validating an SPDM certificate for each of the one or more additional edge computing devices to identify one or more valid edge computing devices. In other embodiments, the operations include, determining for each of the additional edge computing devices, that its root CA is identical to a root CA of the first edge computing device to identify one or more valid edge computing devices of the one or more additional edge computing devices identifying the one or more valid edge computing devices of the additional edge computing devices by determining for each of the additional edge computing devices, that a root CA is identical to a root CA of the first edge computing device.

[0037] Figure 1 is schematic block diagram illustrating a system 100 for software deployment in multiple edge computing devices 104a-104n, according to various embodiments. The system 100 includes a deployment apparatus 102, edge computing devices 104a-104n (collectively or generally “104” ) , Baseboard Management Controllers ( “BMC” ) 106a-106n (collectively or generally “106” ) , computer network 108, and external electronic device 110, which are described below.

[0038] After a manufacturer has shipped one or more edge computing devices 104 to a customer, an on-site engineer deploys the one or more edge computing devices 104 at the customer’s location. During edge deployment operations, such as installation of an operating system or application, updating software, configuring an application, removing an application, or the like, at the customer’s location, the onsite engineer may not have access to the customer’s network. In such cases, the on-site engineer, connects an external electronic device 110, one by one to each of the edge computing devices 104, to perform edge deployment operations. Connecting the external electronic device 110 to each of the edge computing devices 104 one by one to deploy the edge computing devices one at a time may be inconvenient and time consuming.

[0039] The deployment apparatus 102, enables the on-site engineer to deploy all the edge computing devices 104, by connecting the external electronic device 110 to any one edge computing device 104a, 104b, …, or 104n. For example, as shown in Figure 1, the on-site engineer may connect the external electronic device 110 to the first edge computing device 104a and deploy all the edge computing devices 104, without having to connect the external electronic device 110 to the one or more additional edge computing devices 104b-104n.

[0040] In some embodiments, the deployment apparatus 102 of the first edge computing device 104a, receives a deployment request from the external electronic device 110 to deploy software on the edge computing devices 104. The deployment apparatus 102, in response to receiving the deployment request, establishes a secure communication channel between the edge computing devices 104. In some embodiments, the deployment apparatus 102 of the first edge computing device 104a, further receives a deployment instruction from the external electronic device 110.

[0041] In some embodiments, the deployment apparatus 102 of the first edge computing device 104a forwards the received deployment instruction to each of the one or more additional edge computing devices 104b-104n to deploy the edge computing devices 104. In general, deploying an edge computing device refers to setting up a computing system at the edge of the network, for example, closer to a customer’s location where the data is generated or consumed. Setting up a computing system may include installation of an operating system or application, updating software, configuring an application, removing an application, or the like. In some embodiments, the external electronic device may be connected to the first BMC 106a of the first edge computing device 104a. In other embodiments, the external electronic device 110 may connect to the first edge computing device 104a through another communication interface. The communication interface may be, for example, but not limited to a Universal Serial Bus ( “USB” ) port, a Network Interface Card ( “NIC” ) , etc. While Figure 1 shows the external electronic device 110 connected to the first BMC 106a of the first edge computing device 104a to deploy all of the edge computing devices 104, one of skill in the art will recognize that the external electronic device 110 may be connected to any one of the other BMCs 106b-106n of the one or more additional edge computing devices 104, to deploy all of the edge computing devices 104.

[0042] In some embodiments, the deployment apparatus 102 of the first edge computing device 104a validates a device certificate of the one or more additional edge computing devices 104b-104n to identify one or more valid edge computing devices 104b-104n of the one or more additional edge computing devices 104b-104n to establish the secure communication channel. The first edge computing device 104a validates the device certificate of the one or more additional edge computing devices 104b-104n to ensure the identity of the one or more additional edge computing devices 104b-104n and prevent unauthorized devices from connecting to the network. Typically, each of the edge computing devices has its own device certificate, which is also known as server certificate. In some embodiments, the device certificate used by the deployment apparatus 102 for validation may be an SPDM certificate. For example, the deployment apparatus 102 validates an SPDM certificate for each of the edge computing devices 104a-104n, to establish trust between the edge computing devices 104 prior to establishing a communication channel between the edge computing devices 104.

[0043] In some embodiments, the deployment apparatus 102 of the first edge computing device 104a sends a validation request to each of the one or more additional edge computing devices 104b-104n to receive a device certificate from each of the one or more additional edge computing devices 104b-104n. In an example, the validation request may be a request to challenge the identity of the edge other computing devices 104b-104n.

[0044] In some embodiments the deployment apparatus 102 of the first edge computing device 104a, identifies one or more valid edge computing devices 104 by determining, for each of the one or more additional edge computing devices 104b-104n, that a root CA of the one or more additional edge computing devices 104b-104n is identical to a root CA of the first edge computing device 104a. For example, the first edge computing device 104a may consider the second edge computing device 104b to be valid for further communication if the root CA of the first edge computing device 104a matches with the root CA of the second edge computing device 104b. In some embodiments, each of the device certificates or the SPDM certificates, signed by a common root CA, may be embedded in the respective BMCs 106. For example, each of the device certificates or the SPDM certificates, signed by the common root CA, may be stored in a NAND flash of the respective BMCs 106. In some embodiments, each of the device certificates or the SPDM certificates, signed by the common root CA, may be encrypted and / or stored in a secured NAND flash memory of the respective BMCs 106 for protection.

[0045] The system 100 includes edge computing devices 104a-104n that include the BMCs 106a-n respectively and the deployment apparatus 102. In some embodiments, the edge computing device 104 includes one or more processors, memory, non-volatile data storage, a network interface cards ( “NIC” ) , communication buses, etc. The edge computing devices 104 may be, for example, but not limited to, edge servers. The edge servers, may be of different forms, for example, rack mounted servers, desktop computers, workstations, etc. For example, a rack mounted server, also referred to as rack server, is a computer dedicated to server use and designed for installation in a framework called a rack. The rack has multiple mounting slots, or bays, each meant to hold a hardware unit secured with screws. For example, a desktop computer is personal computer designed to be used at a stationary location and a workstation is a desktop computer that is designed to handle demanding technical tasks that require high computational power. In some embodiments the edge computing devices 104 refers to the computing recourses that are placed at the edge of the network which is close to the customer’s location (e.g., end-user’s location) to process data locally.

[0046] In general, a data center is a large-scale centralized facility that provide the computational power and storage needed for various operations, from running cloud services to hosting websites and managing enterprise applications, whereas an edge server is located closer to an end user to reduce latency and improve the performance of applications and services by processing data closer to where the data is generated or consumed. Typically, the edge servers include a management controller such as a BMC that allows the edge server to be managed remotely.

[0047] The customer’s location may be, for example, a grocery store, a gas station, or other businesses that need computing capability to process data locally. The edge computing devices 104 are connected to each other by using the computer network 108. The edge computing devices 104 are initially in a pre-deployment phase. For example, the edge computing devices 104 may not be deployed yet when the manufacturer of the edge computing devices 104 has shipped the edge computing devices 104 to the customer.

[0048] The system 100 includes BMC 106 which is configured to interface with the external electronic device 110 for edge deployment. In some embodiments, the BMC 106 is an Controller ( “XCC” ) by In other embodiments, the BMC 106 is Management Engine ( “ME” ) by In other embodiments, the BMC 106 is another type by another manufacturer. In general, a BMC in an edge computing device 104 may be a controller used to monitor and manage the edge computing device 104 remotely. The BMC may be, for example, used for health monitoring, power management, firmware management, event logging, security, etc.

[0049] In some embodiments, any one of the BMCs 106 that connects with the external electronic device 110 may be assigned as a group lead to manage all the other BMCs 106 during edge deployment. In some embodiments, the first BMC 106a, for example, may be a group lead for the BMCs 106, that manages the other BMCs 106b-106n during edge deployment. In some embodiments, the BMCs 106 may be connected, by the customer, to a management network for subsequent deployments and / or software updates.

[0050] In some embodiments, the BMCs 106, upon deploying the edge computing devices 104, is configured to communicate with a management server (not shown) over a management network. In some embodiments, the management server is an XClarity Administrator ( “XCA” ) by Lenovo. In some embodiments the management server is on-site with the edge computing devices 104. In some embodiments, the management server is connected over a management network to an off-site management server. In various embodiments, the off-site management server is an XCA or an XClarity Orchestrator ( “XCO” ) by Lenovo.

[0051] The system 100 includes an external electronic device 110 that sends a deployment request and a deployment instruction to the first edge computing device 104a. The external electronic device may be, for example, but not limited to, a laptop, a mobile phone, a smartphone, a tablet, etc. The external electronic device 110 is present on site with the edge computing devices 104. For example, the on-site engineer may utilize the external electronic device 110 at a customer’s location to deploy the edge computing devices 104. In some embodiments, the external electronic device 110 interfaces with the first BMC 106a of the first edge computing device 104a. In some embodiments, the external electronic device 110, to interface with the first BMC 106a, may be connected to a USB port of the first edge computing device 104a. While Figure 1 shows the external electronic device 110 interfaces with the first BMC 106a of the first edge computing device 104a for edge deployment, one of skill in the art will recognize that the external electronic device 110 may be interfaced with any one of the BMC 106 of the edge computing devices 104, to deploy all of the edge computing devices 104.

[0052] In some embodiments, the connection between the external electronic device 110 and the BMC 106 may be a wired connection. In other embodiments the connection between the external electronic device 110 and the BMC 106 may be a wireless connection. In various embodiments, using a wired connection between the external electronic device 110 and the first edge computing device 104a to receive the deployment request, may be a more secure method when compared to using a wireless connection between the external electronic device 110 and the first edge computing device 104a.

[0053] The system 100 includes a computer network 108 that connects the edge computing devices 104. The computer network 108, in some embodiments, may be set up temporarily to deploy the edge computing devices 104. Upon deployment, another computer network 108 may be set up permanently. In some embodiments, the computer network 108 may include a switch, a router, a server, cabling, etc. In some embodiments, the computer network 108 may include a wired connection that includes one of a switch and a router. In some embodiments, the computer network 108, may include a daisy-chain wired connection to eliminate the use of a switch and / or a router. In other embodiments, the computer network 108 may be a wireless connection. The wireless connection may be a mobile telephone network. The wireless connection may also employ a Wi-Fi network based on any one of the Institute of Electrical and Electronics Engineers ( “IEEE” ) 802.11 standards. Alternatively, the wireless connection may be a connection. In addition, the wireless connection may employ a Radio Frequency Identification ( “RFID” ) communication including RFID standards established by the International Organization for Standardization ( “ISO” ) , the International Electrotechnical Commission ( “IEC” ) , the American Society for Testing and the DASH7TM Alliance, and EPCGlobalTM.

[0054] Alternatively, the wireless connection may employ a connection based on the IEEE 802 standard. In one embodiment, the wireless connection employs a Z- connection as designed by Sigma Alternatively, the wireless connection may employ an and / or connection as defined by Innovations Inc. of Cochrane, Canada.

[0055] The wireless connection may be an infrared connection including connections conforming at least to the Infrared Physical Layer Specification ( “IrPHY” ) as defined by the Infrared Data Alternatively, the wireless connection may be a cellular telephone network communication. All standards and / or connection types include the latest version and revision of the standard and / or connection type as of the filing date of this application.

[0056] Figure 2 is a schematic block diagram illustrating an apparatus 200 for software deployment in multiple edge computing devices 104, according to various embodiments. The apparatus 200 includes a deployment apparatus 102 that includes a receiver module 202, a secure channel module 204, an instruction receiver module 206, and a forwarding module 208 which are described below. In some embodiments, the apparatus 200 is implemented using executable code stored on a computer readable storage device, which is non-transitory. The code is executable on a processor. In other embodiments, all or a portion of the apparatus 200 is implemented using a programmable hardware device and / or hardware circuits.

[0057] The apparatus 200 includes a receiver module 202 configured to receive, by a first edge computing device 104a, a deployment request that includes a request to deploy software on the first edge computing device 104a and the other edge computing device 104b-104n, from the external electronic device 110. In some embodiment, the receiver module 202 may receive the deployment request, from the external electronic device 110 through a wired connection. In other embodiments, the receiver module 202 may receive the deployment request, from the external electronic device 110 through a wireless connection. In various embodiments, using a wired connection between the external electronic device 110 and the first edge computing device 104a to receive the deployment request, may be a more secure method when compared to using a wireless connection between the external electronic device 110 and the first edge computing device 104a. In other embodiments, the wireless connection includes security protocols to make the wireless connection secure.

[0058] The deployment request, in some embodiments, received by the receiver module 202, may be a request to deploy the first edge computing device 104a. As used herein, deploying an edge computing device 104 includes instructions to an edge computing device 104 to bring the edge computing device 104 from an initial state as delivered by a manufacturer, computer vendor, or the like to a state where the edge computing device 104 is operational for an intended purpose of the edge computing device 104. In some embodiments, deployment operations include installing software, updating software, registering the software, establishing communication channels, implementing security protocols, or the like.

[0059] In some embodiments, the deployment request includes a request to deploy software on the first edge computing device 104a and one or more additional edge computing devices 104b-104n. In other embodiments, the deployment request includes a request to deploy software on the first edge computing device 104a and the request to deploy the software on the one or more additional edge computing devices 104b-104n is implicit. In the embodiments, the receiver module 202 interprets the deployment request to include the one or more additional edge computing devices 104b-104n. In other embodiments, the deployment request includes other instructions, such as to register the software, to implement security protocols, to reach out to a management server or other remote computing device to establish communications, or the like. In some embodiments, the deployment request may be a signal to trigger the deployment apparatus 102. In some embodiments, the deployment request may include a deployment instruction to deploy the edge computing devices 104. In some embodiments, the deployment request may be a simple instruction recognized by the receiver module 202. In other embodiments, the deployment request may be a complex instruction that identifies the one or more edge computing devices 104 to be deployed. In other embodiments, the deployment request, received by the receiver module 202, may be a request to deploy all of the edge computing devices 104. In other embodiments, the deployment request, received by the receiver module 202, may be a request to deploy one or more valid edge computing devices 104b-104n of the edge computing devices 104.

[0060] The apparatus 200 includes a secure channel module 204 configured to establish, in response to receiving a deployment request, a secure communication channel between the first edge computing device 104a and the one or more additional edge computing devices 104b-104n. In some embodiments, the secure communication channel may be established by the first edge computing device 104a. In other embodiments, the secure communication channel may be established based, at least in part, on a user’s input to the external electronic device. In other embodiments, the secure communication channel may be established completely based on a user’s input to the external electronic device. In some embodiments, the secure communication channel, may be established between the first edge computing device 104a and the one or more valid edge computing devices 104b-104n of the one or more additional edge computing devices 104b-104n.

[0061] In general, a security protocol enables the establishment of secure communication channels to ensures a secure communication and interaction between devices, particularly in the environments such as edge servers and data centers. The security protocol, to build a trustworthy environment, facilitates authentication, data integrity, data confidentiality, mutual attestation, standardization, or the like. The security protocol also provides a device the ability to challenge another device to prove its identity.

[0062] In some embodiments, the secure channel module uses a security protocol to establish a secure communication channel between the edge computing devices 104. In some embodiments, the secure channel module 204 may use “SPDM” which is a standard prepared by the Distributed Management Task Force ( “DMTF” ) , to establish a secure communication channel between the edge computing devices 104. In general, SPDM was designed to establish security trust between devices (e.g. between BMC and PCIe devices) within a server over Management Component Transport Protocol ( “MCTP” ) designed by DMTF. The SPDM, in the embodiments, may be used to establish security trust between the edge computing devices 104 and / or BMCs 106 of each of the edge computing devices 104 over the computer network 108.

[0063] In some embodiments, the secure channel module 204 may use security protocols such as OpenSPDM, Secure Sockets Layer ( “SSL” ) protocol, Simple Network Management Protocol ( “SNMP” ) , Datagram Transport Layer Security ( “DTLS” ) or the like, to establish a secure communication channel between the edge computing devices 104. In some embodiments, the secure channel module 204 may use any other security protocol that may be developed and / or standardized in the future, to establish a secure communication channel. In some embodiments, the secure communication channel established by the secure channel module 204, may be established for a limited period to deploy the edge computing devices 104. For example, the secure communication channel may be terminated upon the deployment of the edge computing devices 104.

[0064] In some embodiments, the secure communication channel may be established, by the secure channel module 204, by using a wired connection that includes a switch and / or a router. In other embodiments, the secure communication channel may be established, by the secure channel module 204, by using a daisy-chain wired connection. In other embodiments, the secure communication channel may be established, by the secure channel module 204, by using a wireless connection.

[0065] The apparatus 200 includes an instruction receiver module 206 configured to receive, by the first edge computing device 104a, a deployment instruction from the external electronic device 110. In some embodiments, the deployment instruction may be the same as the deployment request described above. The deployment instruction, in some embodiments, may be an instruction to deploy software on the edge computing devices 104. In some embodiments, the deployment instruction may be, for example, a set of sequential processes that installs and / or updates software on the edge computing devices 104. In some embodiments, the deployment instruction may be an instruction to deploy the one or more valid edge computing devices 104.

[0066] In some embodiments, the deployment instruction may be received by the instruction receiver module 206 in response to the establishment of the secure communication channel. In some embodiments, the deployment instruction may be received by the instruction receiver module 206 based on the on-site engineer’s input on the external electronic device 110. In the embodiments, the on-site engineer’s input may partly be a trigger to receive the deployment instruction by the instruction receiver module. In other embodiments, the on-site engineer’s input may fully be the trigger to receive the deployment instruction by the instruction receiver module.

[0067] In some embodiments, the instruction receiver module 206 may receive multiple instructions that may be different from one another and performs different operations. In the embodiments, a second instruction may be received upon completion of the operations of the first instruction. In some embodiments, based on the on-site engineer’s input to the external electronic device, the instruction receiver module 206 may receive the multiple instructions sequentially and / or individually.

[0068] In some embodiment, the instruction receiver module 206 may receive the deployment instruction, from the external electronic device 110 through a wired connection from the external electronic device 110. In some embodiments, the instruction receiver module 206 may receive the deployment instruction, from the external electronic device 110 through a wireless connection. In various embodiments, using a wired connection between the external electronic device 110 and the first edge computing device 104a, to receive the deployment instruction, may be a more secure method than using a wireless connection between the external electronic device 110 and the first edge computing device 104a. In other embodiments, the wireless connection includes security protocols to make the wireless connection secure. The instruction receiver module 206, in some embodiments, may reside inside the BMC 106.

[0069] The apparatus 200 includes a forwarding module 208 configured to forward, by the first edge computing device 104a, the deployment instruction received by the instruction receiver module 206, to the one or more additional edge computing devices 104b-104n, through the secure communication channel, to deploy the first edge computing device 104a and the one or more additional edge computing devices 104b-104n. In some embodiments, the forwarding module 208 may forward multiple instructions received by the instruction receiver module 206, sequentially and / or individually to the one or more additional edge computing devices 104b-104n, through the secure communication channel. In some embodiments, forwarding module 208 may accumulate the instructions received by the instruction receiver module 206, and then forward all the accumulated instructions at once.

[0070] The forwarding module 208 of the first edge computing device 104a forwards the deployment instruction to the one or more additional edge computing devices 104b-104n through the secure communication channel established by the secure channel module 204. The forwarding module 208 of the first edge computing device 104a, in some embodiments, may send a copy of the deployment instruction to each of the one or more additional edge computing devices 104b-104n. In some embodiments, the secure communication channel may be terminated when the forwarding module 208 completes forwarding every instruction received by the instruction receiver module 206. In other embodiments, the secure communication channel may be terminated based on an input from an on-site engineer. In other embodiments, the secure communication channel may be terminated after bringing the edge computing device 104 from an initial state as delivered by a manufacturer, computer vendor, or the like to a state where the edge computing device 104 is operational for an intended purpose of the edge computing device 104.

[0071] Figure 3 is a schematic block diagram illustrating another apparatus 300 for software deployment in multiple edge computing devices 104, according to various embodiments. The apparatus 300 includes the deployment apparatus 102 that includes a receiver module 202, a secure channel module 204, an instruction receiver module 206, and a forwarding module 208 which are substantially similar to those described above in relation to the apparatus 200 of Figure 2. The deployment apparatus 102 includes, in various embodiments, a validation module 302, and / or a comparator module 304, which are described below. In various embodiments, all or a portion of the apparatus 300 is implemented similar to the apparatus 200 of Figure 2. In some embodiments, the apparatus 300 is implemented using executable code stored on a computer readable storage device, which is non-transitory. The code is executable on a processor. In other embodiments, all or a portion of the apparatus 200 is implemented using a programmable hardware device and / or hardware circuits.

[0072] The apparatus 300 includes a validation module 302 configured to validate, by the first edge computing device 104a, a device certificate of the one or more additional edge computing devices 104b-104n to identify one or more valid edge computing devices 104b-104n of the one or more additional edge computing devices 104b-104n. In some embodiments, the device certificate may be an SDPM certificate that includes the device information of the edge computing devices 104. The SPDM certificate, in some embodiments, may all be signed with the same root CA.

[0073] In some embodiments, the manufacturer of the edge computing devices 104 signs all of the devices that are manufactured with the same root CA. In other embodiments, the manufacturer of the edge computing devices 104, before shipping the edge computing devices 104 to a customer, may sign only the edge computing devices 104 that are being shipped to a customer, with the same root CA.

[0074] In some embodiments, the validation module 302 may receive the device certificate from each of the one or more additional edge computing devices 104b-104n by sending a validation request, by the first edge computing device 104a to each of the one or more additional edge computing devices 104b-104n. In other embodiments, the validation module 302 may receive the SPDM certificate from each of the one or more additional edge computing devices 104b-104n by sending a validation request, by the first edge computing device to each of the one or more additional edge computing devices 104b-104n.

[0075] In some embodiments, the validation request sent by the first edge computing device 104a may be, a request for the one or more additional edge computing devices 104b-104n to share the identity information of the one or more additional edge computing devices 104b-104n. In some embodiments, the validation request sent by the first edge computing device 104a, may be a request that is recognizable by the valid edge computing devices 104b-104n of the one or more additional edge computing devices 104b-104n.

[0076] In general, a root certificate is a public key certificate that identifies a root CA. A certificate authority ( “CA” ) is an entity that may store, sign and issue digital certificates. A digital certificate certifies that a named subject owns a public key, allowing others (e.g., relying parties) to trust signatures or assertions made about the corresponding root CA. A CA, acting as a trusted third party, is trusted by both the certificate's subject (e.g., owner) and the relying party.

[0077] The apparatus 300 includes a comparator module 304 configured to identify, by the first edge computing device 104a, one or more valid edge computing devices 104b-104n of the one or more additional edge computing devices 104b-104n by determining, for each of the one or more additional edge computing devices 104b-104n, that a root CA of the other edge computing device 104b-104n is identical to a root CA of the first edge computing device 104a.

[0078] In some embodiments, the comparator module 304, to identify one or more valid edge computing devices 104b-104n of the one or more additional edge computing devices 104b-104n, may verify for each of the one or more additional edge computing devices 104b-104n whether an SPDM certificate of each of the one or more additional edge computing devices 104b-104n and an SPDM of the first edge computing device 104a is signed by the same root CA.

[0079] For example, the first edge computing device 104a determines that the second edge computing device 104b is valid for further communication if the root CA of the first edge computing device 104a matches with the root CA of the second edge computing device 104b. In some embodiments, for example, if the root CA of the second edge computing device 104b does not match with the root CA of the first edge computing device 104a, then the first edge computing device 104a, may not further communicate with the second edge computing device 104b.

[0080] Figure 4 is a schematic flow chart diagram illustrating a method 400 for software deployment in multiple edge computing devices 104, according to various embodiments. The method 400 begins and receives 402 a deployment request, by the first edge computing device 104a, from the external electronic device 110 to deploy software on the edge computing devices 104. The method 400 establishes 404, in response to receiving a deployment request, a secure communication channel between the first edge computing device 104a and the one or more additional edge computing devices 104b-104n. In some embodiments, the method 400, establishes 404 a secure communication channel by using a wired connection that includes one of a switch and a router. In some embodiments, the method 400, establishes 404 a secure communication channel by using a daisy chain wired connection. In other embodiments, the method 400, establishes 404 a secure communication channel by using a wireless connection.

[0081] The method 400, receives 406 a deployment instruction, by the first edge computing device 104a, from the external electronic device 110. In some embodiments, the method 400, receives 406 the deployment instruction through a wired connection. In other embodiments, the method 400, receives 406 the deployment instruction through a wireless connection. The method 400, forwards 408, by the first edge computing device 104a, the deployment instruction to the one or more additional edge computing devices 104b-104n, through the secure communication channel to deploy the edge computing devices 104, and the method 400 ends. In various embodiments, all or a portion of the method 400 is implemented using the receiver module 202, the secure channel module 204, the instruction receiver module 206, and / or the forwarding module 208.

[0082] Figure 5 is a schematic flow chart diagram illustrating another method 500 for software deployment in multiple edge computing devices 104, according to various embodiments. The method 500 begins and receives 502, by the first edge computing device 104a, a deployment request from the external electronic device 110 to deploy software on the edge computing devices 104. The method 500 validates 504 a security protocol certificate of a first edge computing device 104a. In some embodiments, the security protocol of the first edge computing device is validated to check if the first edge computing device 104a is a trusted device. For example, when a user (e.g., on-site engineer) , connects an external electronic device to an edge computing device (e.g., 104a) , the edge computing device needs to be checked for its validity to confirm that it is not a malicious device. In some embodiments, the first edge computing device is validated by the external electronic device. In other embodiments, the validation is performed by the first edge computing device 104a. The method 500 sends 506, by the first edge computing device 104a, a validation request to each of the one or more additional edge computing devices 104b-104n, to challenge the identity of the one or more additional edge computing devices 104b-104n.

[0083] The method 500, receives 508, by the first edge computing device 104a, a security protocol certificate from an additional edge computing devices (e.g., 104b) and determines 510 if the received security protocol certificate is valid. In some embodiments, the security protocol certificate may be an SPDM certificate. If the method 500 determines 510 that the security protocol is valid, the method 500 determines 512 for the additional edge computing device 104b if a root CA of the additional edge computing device 104b matches a root CA of the first edge computing device 104a. If the method 500 determines 512 that the root CA of the corresponding additional edge computing devices 104b matches the root CA of the first edge computing device 104a, the method 500 marks 514 the additional edge computing device 104b as valid and determines 516 if there are any more additional edge computing devices (e.g., 104c-104n) to be checked for validity.

[0084] If the method 500 determines 516 that there is additional edge computing device 104c-104n that have not been checked for validity, the method 500 returns and receives 508 a security protocol certificate from a next edge computing device (e.g., 104c) . If the method 500 determines 510 that the security protocol certificate of the additional edge computing device 104b is invalid or determines 512 that the root CA of the additional edge computing device 104b does not match the root CA of the first edge computing device 104a, the method 500 identifies 518 the additional edge computing device 104b as invalid and determines 516 if there are any of the additional edge computing devices (e.g., 104c-104n) that have not been checked for validity.

[0085] If the method 500 determines 516 that there are no more additional edge computing devices 104 to be checked for validity, the method 500 establishes 520 a secure communication channel between the first edge computing device 104a and the one or more valid edge computing devices 104b-104n. The method 500, receives 522, by the first edge computing device 104a, a deployment instruction, from the external electronic device 110 and forwards 524, by the first edge computing device 104a, the deployment instruction to the one or more additional edge computing devices 104b-104n that are valid, through the secure communication channel to deploy the edge computing devices 104, and the method 500 ends. In various embodiments, all or a portion of the method 500 is implemented using the receiver module 202, the secure channel module 204, the instruction receiver module 206, the forwarding module 208, a validation module 302, and / or a comparator module 304.

[0086] Embodiments may be practiced in other specific forms. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the invention is, therefore, indicated by the appended claims rather than by the foregoing description. All changes which come within the meaning and range of equivalency of the claims are to be embraced within their scope.

Claims

1.A method comprising:receiving, by a first edge computing device, a deployment request from an external electronic device, the deployment request comprising a request to deploy software on the first edge computing device and one or more additional edge computing devices;in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices;receiving, by the first edge computing device, a deployment instruction from the external electronic device; andforwarding, by the first edge computing device, the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.2.The method of claim 1, further comprising validating a Security Protocol and Data Model ( “SPDM” ) certificate for each of the additional edge computing devices.3.The method of claim 2, wherein the first edge computing device receives the SPDM certificate from each of the additional edge computing devices by sending a validation request to each of the additional edge computing devices.4.The method of claim 1, further comprising determining for each of the additional edge computing devices, that a root Certificate Authority ( “CA” ) is identical to a root CA of the first edge computing device to identify one or more valid edge computing devices of the one or more additional edge computing devices.5.The method of claim 1, wherein the external electronic device interfaces with a Baseboard Management Controller ( “BMC” ) of the first edge computing device.6.The method of claim 1, wherein the secure communication channel comprises a wired connection, wherein the wired connection comprises one of a switch and a router.7.The method of claim 1, wherein the secure communication channel comprises a daisy-chain wired connection.8.The method of claim 1, wherein the secure communication channel comprises a wireless connection.9.The method of claim 1, wherein the external electronic device is present on site with the first edge computing device and the one or more additional edge computing devices.10.The method of claim 1, wherein the first edge computing device and the one or more additional edge computing devices are initially in a pre-deployment phase.11.An apparatus comprising:a processor; anda non-transitory computer-readable storage media storing code, the code being executable by the processor to perform operations comprising:receiving, by a first edge computing device, a deployment request from an external electronic device, the deployment request comprising a request to deploy software on the first edge computing device and one or more additional edge computing devices;in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices;receiving, by the first edge computing device, a deployment instruction from the external electronic device; andforwarding, by the first edge computing device, the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.12.The apparatus of claim 11, wherein the operations further comprise validating a Security Protocol and Data Model ( “SPDM” ) certificate for each of the additional edge computing devices.13.The apparatus of claim 12, wherein the first edge computing device receives the SPDM certificate from each of the additional edge computing devices by sending a validation request to each of the additional edge computing devices.14.The apparatus of claim 11, wherein the operations further comprise identifying the one or more valid edge computing devices of the additional edge computing devices by determining for each of the additional edge computing devices, that a root Certificate Authority ( “CA” ) is identical to a root CA of the first edge computing device.15.The apparatus of claim 11, wherein the external electronic device interfaces with a Baseboard Management Controller ( “BMC” ) of the first edge computing device.16.The apparatus of claim 11, wherein the secure communication channel is selected from the group consisting of a wired connection, wherein the wired connection comprises one of a switch and a router, a daisy-chain wired connection, and a wireless connection.17.The apparatus of claim 11, wherein the external electronic device is present on site with the first edge computing device and the one or more additional edge computing devices.18.A program product comprising a non-transitory computer-readable storage medium storing code, the code being configured to be executable by a processor to perform operations comprising:receiving, by a first edge computing device, a deployment request from an external electronic device, the deployment request comprising a request to deploy software on the first edge computing device and one or more additional edge computing devices;in response to receiving the deployment request, establishing a secure communication channel between the first edge computing device and the one or more additional edge computing devices;receiving, by the first edge computing device, a deployment instruction from the external electronic device; andforwarding, by the first edge computing device, the deployment instruction to the one or more additional edge computing devices through the secure communication channel to deploy the first edge computing device and the one or more additional edge computing devices.19.The program product of claim 18, wherein the operations further comprise validating a Security Protocol and Data Model ( “SPDM” ) certificate for each of the additional edge computing devices.20.The program product of claim 18, wherein the operations further comprise determining for each of the additional edge computing devices, that a root Certificate Authority ( “CA” ) is identical to a root CA of the first edge computing device to identify one or more valid edge computing devices of the one or more additional edge computing devices.