Network-Supported Edge Orchestration for Trusted Low-Latency Workloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing edge computing systems face challenges in providing secure, low-latency orchestration due to their highly distributed and heterogeneous nature, making it complex to manage data security, isolation, and compute needs across diverse execution devices.

Innovation Solution

A network-supported orchestration system uses a preamble to represent end-user or compute requirements, enabling last-mile orchestration decisions and ensuring secure, low-latency operations by leveraging edge cloud configurations with trusted execution platforms and multi-tenant security features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If edge computing systems use highly distributed and heterogeneous execution devices, then service capabilities and compliance with security requirements are improved, but device complexity and difficulty of managing data security increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidorchestration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary orchestration layer that mediates between the heterogeneous edge execution devices and the central management system. This intermediary translates diverse device capabilities and security requirements into standardized orchestration commands, simplifying management while maintaining security compliance across distributed devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments security management into discrete, device-specific security contexts that can be independently configured and enforced. Each edge device maintains its own security policy context, allowing granular control over data security without requiring complex centralized management of all devices uniformly.

Inventive Principle:
Principle #1Segmentation

2Loss of time

If compute resources are placed in remote locations away from conventional data centers, then network latency is reduced, but security clearance of compute devices becomes unknown and fluctuating

Engineering Contradiction:
Improvenetwork latencyVSAvoidsecurity guarantee
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary security verification by evaluating and caching security clearance information for remote edge devices before compute tasks are assigned. This preliminary action ensures that only devices meeting required security standards are selected for execution, maintaining security guarantees despite remote device placement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The orchestration system continuously monitors and updates security clearance status of remote edge devices, providing real-time feedback to the task assignment process. This feedback mechanism ensures that security requirements are maintained even as device security states may fluctuate over time.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple trusted execution platforms are used to broker workload payloads, then security is improved, but device complexity and orchestration overhead increase

Engineering Contradiction:
Improvetrusted execution securityVSAvoidplatform coordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal interface layer that enables multiple trusted execution platforms to be managed through a common orchestration mechanism. This universal interface abstracts platform-specific details, allowing the system to leverage multiple security platforms without proportionally increasing coordination complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4155933B1Network supported low latency security-based orchestration
Publication Date: 2025.09.03 INTEL CORP
  • EP4155933B1 patent drawingFigure 1
  • EP4155933B1 patent drawingFigure 2
  • EP4155933B1 patent drawingFigure 3

AI summary

Various aspects of methods, systems, and use cases include security-based orchestration. A method may include evaluating, within a secure environment of an untrusted device, a preamble to determine a set of security requirements. The method may include, providing, to an attestation server, an indication of security parameters for services of the untrusted device corresponding to security requirements of the set of security requirements, and in response to receiving a confirmation from the attestation server, providing a request to the untrusted device outside the secure environment to generate a trusted domain including the services.