Distributed self sovereign identities for network function virtualization

    公开(公告)号:US11757650B2

    公开(公告)日:2023-09-12

    申请号:US16765686

    申请日:2018-12-28

    申请人: Intel Corporation

    摘要: Various systems and methods for distributing orchestration of network services using blockchain technology are disclosed. A bid is posted for orchestration of a network service to be delivered using NFV using a DSFC contract blockchain. The device, DSFC contract and initiator of a request for the network service are identified using a self-sovereign identity blockchain. The device determines it is to orchestrate the network service based on the DSFC contract blockchain and identifies at least one entity to provide the network service from a DWH contract blockchain that contains DWH contract bids of entities for the network service. The entities and DWH contract are identified using the self-sovereign identity blockchain. The device ensures that the DWH contract is being executed by the at least one entity according to the DWH contract and provides remuneration after fulfillment.

    Technologies for accelerated orchestration and attestation with edge device trust chains

    公开(公告)号:US11444846B2

    公开(公告)日:2022-09-13

    申请号:US16368980

    申请日:2019-03-29

    申请人: Intel Corporation

    摘要: Technologies for accelerated orchestration and attestation include multiple edge devices. An edge appliance device performs an attestation process with each of its components to generate component certificates. The edge appliance device generates an appliance certificate that is indicative of the component certificates and a current utilization of the edge appliance device and provides the appliance certificate to a relying party. The relying party may be an edge orchestrator device. The edge orchestrator device receives a workload scheduling request with a service level agreement requirement. The edge orchestrator device verifies the appliance certificate and determines whether the service level agreement requirement is satisfied based on the appliance certificate. If satisfied, the workload is scheduled to the edge appliance device. Attestation and generation of the appliance certificate by the edge appliance device may be performed by an accelerator of the edge appliance device. Other embodiments are described and claimed.

    Attestation token sharing in edge computing environments

    公开(公告)号:US11425111B2

    公开(公告)日:2022-08-23

    申请号:US16683410

    申请日:2019-11-14

    申请人: Intel Corporation

    摘要: Various approaches for implementing attestation using an attestation token are described. In an edge computing system deployment, an edge computing device includes an attestable feature (e.g., resource, service, entity, property, etc.) which is accessible from use of an attestation token, by the operations of: obtaining a first instance of a token that provides proof of attestation for an accessible feature of the edge computing device, with the token including data to indicate trust level designations for the feature as attested by an attestation provider; receiving, from a prospective user of the feature, a request to use the feature and a second instance of the token, with the second instance of the token originating from the attestation provider; and providing access to the feature based on a verification of the instances of the token, by using the verification to confirm attestation of the trust level designations for the feature.

    KEY PROTECTION FOR COMPUTING PLATFORM

    公开(公告)号:US20220021540A1

    公开(公告)日:2022-01-20

    申请号:US17320762

    申请日:2021-05-14

    申请人: Intel Corporation

    摘要: A security accelerator device stores a first credential that is uniquely associated with the individual security accelerator device and represents a root of trust to a trusted entity. The device establishes a cryptographic trust relationship with a client entity that is based on the root of trust, the cryptographic trust relationship being represented by a second credential. The device receives and store a secret credential of the client entity, which is received via communication secured by the second credential. Further, the device executes a cryptographic computation using the secret client credential on behalf of the client entity to produce a computation result.

    Technologies for accelerated hierarchical key caching in edge systems

    公开(公告)号:US11212085B2

    公开(公告)日:2021-12-28

    申请号:US16368982

    申请日:2019-03-29

    申请人: Intel Corporation

    IPC分类号: H04L9/08

    摘要: Technologies for accelerated key caching in an edge hierarchy include multiple edge appliance devices organized in tiers. An edge appliance device receives a request for a key, such as a private key. The edge appliance device determines whether the key is included in a local key cache and, if not, requests the key from an edge appliance device included in an inner tier of the edge hierarchy. The edge appliance device may request the key from an edge appliance device included in a peer tier of the edge hierarchy. The edge appliance device may activate per-tenant accelerated logic to identify one or more keys in the key cache for eviction. The edge appliance device may activate per-tenant accelerated logic to identify one or more keys for pre-fetching. Those functions of the edge appliance device may be performed by an accelerator such as an FPGA. Other embodiments are described and claimed.