System for orchestrated management of identity security functions in container-based multi-cloud environments

The system addresses inefficiencies in distributed cloud environments by orchestrating identity security functions across multiple cloud environments, providing centralized management with distributed enforcement and dynamic adaptation to container states, thus improving security adaptability and reducing manual reconfiguration needs.

DE202026100671U1Active Publication Date: 2026-05-21GAHLOT RAKESH EDISON +3
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
GAHLOT RAKESH EDISON
Filing Date
2026-02-06
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing distributed cloud environments lack cross-environmental coordination of identity security functions, suffer from static safety rule assignment without considering dynamic container states, and require manual reconfiguration during state changes, leading to inefficiencies in centralized administration and enforcement.

Method used

A system that captures identity security functions on a container-specific basis, orchestrates them across multiple cloud environments, and enforces them in a coordinated manner, with centralized administration and distributed enforcement, adapting to dynamic container states without manual reconfiguration.

Benefits of technology

Enables centralized management of identity security with distributed enforcement, ensuring environment-wide and state-dependent control of security measures, thereby reducing configuration efforts and enhancing security adaptability.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

System for the orchestrated management of identity security functions in container-based multi-cloud environments, comprehensive an identity data capture unit, trained to capture identity-related security parameters from multiple distributed, container-based computing environments, an orchestration control unit, trained to coordinate the control of identity and access security functions across multiple cloud environments, a policy linking unit, trained to assign safety rules to container-related execution states, and a security enforcement unit trained to execute identity-related security measures within the respective computing environment, the system coordinates identity security functions across environments without imposing a fixed prioritization of individual cloud environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The invention relates to the technical field of distributed computing infrastructures and security systems. In particular, the invention relates to a technical system for the coordinated management and enforcement of identity-related security functions in container-based multi-cloud environments. State of the art

[0002] In distributed cloud environments, identity and access security functions are typically managed either in isolation for each computing environment or centrally without direct reference to container-related execution states. Such established solutions have several technical limitations, including: • lack of cross-environmental coordination of identity security functions, • Static safety rule assignment without considering dynamic container states, • Centralized administration without direct enforcement in the respective computing environment or vice versa, • Increased configuration effort when changing the execution states.

[0003] A system that captures identity security functions on a container-specific basis, orchestrates them based on state, and simultaneously enforces them in a coordinated manner across multiple cloud environments without prescribing a fixed prioritization of individual environments is not known from the state of the art. Object of the invention

[0004] The invention is based on the objective of providing a technical system that: • Identity security functions coordinated across environments, • Controls safety measures based on container and condition, • enables centralized administration with distributed enforcement, and • Dynamic changes to container execution states are taken into account without manual reconfiguration. Summary of the invention

[0005] The invention relates to a system for the orchestrated management of identity security functions in container-based multi-cloud environments. The system comprises an identity data acquisition unit for capturing identity-related security parameters from multiple distributed computing environments, an orchestration control unit for the coordinated control of identity and access security functions across multiple cloud environments, and a policy linking unit for assigning security rules to container-related execution states.

[0006] Furthermore, a security enforcement unit is provided, which executes identity-related security measures directly within the respective computing environment. The control of security functions is environment-wide and state-dependent, based on current container states and security events, without prescribing a fixed prioritization of individual cloud environments. This enables centralized management of identity security with distributed enforcement.

[0007] Identity security functions are controlled based on the state and without fixed prioritization of individual cloud environments, thus enabling centralized management while simultaneously implementing distributed technical enforcement of security measures.

[0008] The system comprises an identity data capture unit, an orchestration control unit, a policy linking unit, and a security enforcement unit, which work together functionally to manage and enforce identity-related security measures on a container-specific, state-dependent, and environment-wide basis. Detailed description of the invention

[0009] The invention relates to a system for the orchestrated management of identity security functions in container-based multi-cloud environments. The system comprises an identity data acquisition unit for capturing identity-related security parameters from multiple distributed computing environments, an orchestration control unit for the coordinated control of identity and access security functions across multiple cloud environments, and a policy linking unit for assigning security rules to container-related execution states. Furthermore, a security enforcement unit is provided, which executes identity-related security measures directly within the respective computing environment. The control of the security functions is environment-wide and state-dependent, based on current container states and security events, without prescribing a fixed prioritization of individual cloud environments.This enables centralized management of identity security while simultaneously allowing for distributed enforcement.

[0010] The identity data collection unit is designed to collect identity-related security parameters from multiple distributed, container-based computing environments. This collection is container-specific and allows for the assignment of security parameters to a specific logical execution instance. The orchestration control unit is designed to coordinate identity and access security functions across multiple cloud environments. This control is state-dependent, based on current container states and security events, and does not prioritize individual cloud environments. The policy linking unit is designed to dynamically link identity security rules with changing container-related execution states. The security enforcement unit is designed to execute identity-related security measures directly within the respective computing environment. Identity data capture unit

[0011] The identity data capture unit is designed to capture identity-related security parameters from multiple distributed, container-based computing environments.

[0012] Data collection is performed on a container-specific basis, allowing security parameters to be assigned to a specific logical execution instance. This enables targeted control of identity security measures at the level of individual container instances. Orchestration control unit

[0013] The orchestration control unit is designed to coordinate identity and access security functions across multiple cloud environments.

[0014] Control is condition-dependent, based on current container states and security events, without specifying a fixed prioritization of individual cloud environments. Policy linking unit

[0015] The policy linking unit is designed to dynamically link identity security rules with changing container-related execution states.

[0016] This allows security rules to be automatically adapted to changes in container states without requiring manual reconfiguration. Security Enforcement Unit

[0017] The security enforcement unit is trained to execute identity-related security measures directly within the respective computing environment.

[0018] This enables centralized management of identity security while simultaneously allowing distributed enforcement across individual cloud environments.

Claims

[1] System for orchestrated management of identity security functions in container-based multi-cloud environments, encompassing an identity data capture unit, trained to capture identity-related security parameters from multiple distributed, container-based computing environments, an orchestration control unit, trained to coordinate the control of identity and access security functions across multiple cloud environments, a policy linking unit, trained to assign safety rules to container-related execution states, and a security enforcement unit trained to execute identity-related security measures within the respective computing environment, the system coordinates identity security functions across environments without imposing a fixed prioritization of individual cloud environments. [2] System according to claim 1, wherein the orchestration control unit is configured to apply identity security functions state-dependently to multiple distributed cloud environments, based on current container states and security events. [3] System according to claim 1, wherein the identity data acquisition unit acquires the security parameters on a container-related basis and assigns each to a logical execution instance, and wherein the policy linking unit dynamically links the security rules with changing container-related execution states, so that the security enforcement unit executes identity-related security measures directly within the respective computing environment.