Edge Device Service Enclaves for Secure Low-Latency Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized cloud computing environments are inadequate for managing IoT devices that are geographically distant or in disconnected regions, leading to latency issues and inability to meet time-sensitive data processing requirements.

Innovation Solution

Implementing a cloud-computing edge device that provides a distributed computing cluster with service enclaves, allowing secure communication and processing at the edge through virtual substrate networks, enabling isolated network traffic between services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If centralized cloud computing environment is used, then cloud infrastructure services are provided, but latency increases and time-sensitive data processing requirements cannot be met

Engineering Contradiction:
Improvedata processing latencyVSAvoiddistributed computing cluster complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The centralized cloud computing environment is segmented into distributed edge computing nodes deployed geographically close to data sources. Each edge device contains isolated service enclaves that process data locally, eliminating the need to transmit all data to centralized servers and thereby reducing latency while distributing computational workload across multiple locations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The architecture transitions from a single centralized dimension to a multi-dimensional distributed network of edge devices. Service enclaves are isolated within individual edge devices using virtual substrate networks, creating a hierarchical structure that spans from local edge processing to broader cloud connectivity, enabling low-latency processing without sacrificing centralized management capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If service enclaves are isolated from other components, then security is enhanced, but network communication complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidvirtual substrate network complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A virtual substrate network acts as an intermediary layer between isolated service enclaves and external components. This mediator enables secure communication by routing traffic through controlled interfaces, allowing services to remain isolated for security while maintaining necessary network connectivity through the virtualization layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The service enclaves are enclosed in virtualized isolation boundaries that provide security while allowing controlled interaction. The virtual substrate network forms a flexible communication layer that connects isolated services without compromising their security boundaries, enabling both isolation and connectivity simultaneously.

Inventive Principle:
Principle #30Flexible shells and thin films

Data Source

PatentUS20250284557A1Edge device service enclaves
Publication Date: 2025.09.11 ORACLE INT CORP
  • US20250284557A1 patent drawing
  • US20250284557A1 patent drawing
  • US20250284557A1 patent drawing

AI summary

Techniques are described for implementing a secure enclave within an edge device (e.g., an edge device of a computing cluster of edge devices). In some embodiments, a service enclave comprising a plurality of services can be implemented. The plurality of services can be implemented within respective containers and communicatively connected to one another via a virtual substrate network of the cloud-computing edge device. The virtual substrate network may be dedicated to network traffic between services of the plurality of services. A first service of the enclave may generate and transmit a message to a second service of the enclave for processing. One or more operations may be executed by the second service based on reception of the message.