Edge Provisioning With Ephemeral Credentials for Remote IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional centralized cloud computing systems are inadequate for managing workflows at geographically remote devices, particularly in scenarios with IoT devices that are not close to the cloud infrastructure, disconnected regions, or locations with no Internet connectivity, leading to latency issues and suboptimal resource provisioning.

Innovation Solution

A cloud-infrastructure edge computing device is provided that operates at remote locations separate from the centralized cloud computing environment, enabling low-latency processing and provisioning of resources by generating ephemeral credentials and configuration manifests to access centralized cloud resources, even in isolated environments without public network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If centralized cloud computing systems are used for remote IoT devices, then resource management is simplified, but network latency increases and time sensitivity requirements cannot be met

Engineering Contradiction:
Improveresource management complexityVSAvoidnetwork latency
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system segments cloud computing resources into centralized management components and distributed edge execution components. Edge devices are provisioned with local copies of workflow managers and computing resources, allowing data processing to occur locally rather than requiring constant communication with centralized cloud servers, thereby reducing network latency while maintaining centralized provisioning capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from a single-dimensional centralized cloud architecture to a multi-dimensional hybrid architecture that includes centralized cloud, edge devices, and local execution environments. This dimensional expansion allows workloads to be distributed across multiple locations and time zones, enabling time-sensitive processing at the edge while maintaining centralized resource management.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If conventional provisioning techniques are used for edge devices, then resource allocation is straightforward, but error rates increase and provisioning delays occur

Engineering Contradiction:
Improveprovisioning simplicityVSAvoidprovisioning success rate
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary validation of provisioning requests against access control policies before actual resource allocation. The workflow manager validates whether the requesting user has appropriate permissions and whether the requested resources are available and accessible to the target edge device, generating detailed provisioning reports that document each validation step. This preliminary action prevents errors from occurring during actual provisioning execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements comprehensive feedback mechanisms throughout the provisioning process, including real-time validation results, access control policy checks, and provisioning status reporting. The workflow manager provides feedback to users about provisioning success or failure reasons, and maintains detailed logs of provisioning operations for audit and troubleshooting purposes, enabling continuous improvement of provisioning reliability.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If centralized workflow managers are used for remote devices, then centralized control is maintained, but management effectiveness decreases for geographically remote operations

Engineering Contradiction:
Improvecentralized controlVSAvoidworkflow management effectiveness
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The system extracts the workflow execution functionality from centralized cloud servers and places it directly on edge devices through locally deployed workflow managers. This allows workflow execution to occur autonomously at the edge without requiring continuous connection to centralized servers, while centralized systems retain the ability to provision, configure, and monitor edge workflows. The extraction of execution capabilities to the edge resolves the contradiction between centralized control and remote management effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12547471B2Techniques for managing edge device provisioning
Publication Date: 2026.02.10 ORACLE INT CORP
  • US12547471B2 patent drawing
  • US12547471B2 patent drawing
  • US12547471B2 patent drawing

AI summary

Techniques discussed herein relate to managing aspects of provisioning cloud-computing edge devices. In some embodiments, a user request specifying one or more resources to be provisioned at a cloud-computing edge device may be received by a cloud-computing device operated by a cloud-computing provider. An ephemeral credential may be generated for the edge device and used to determine whether access control policies exist that enable the edge device to access the resource(s). If the resource(s) are accessible, a manifest may be generated in accordance with the user request. The manifest may specify a configuration for the cloud-computing edge device and includes information related to the resource. Operations may be subsequently executed to provision the cloud-computing edge device in accordance with the manifest. However, if the resource(s) are not accessible, the user request may be denied.