Context-Aware Microsegmentation for Distributed Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing security systems lack effective methods to enforce context-aware security policies across distributed microservices, which are essential for protecting virtual machines and network traffic in a dynamic and distributed environment.

Innovation Solution

The implementation of a context-aware microsegmented network that uses enforcement points to create logical security boundaries around virtual machines, selecting and applying contextual security policies based on attributes such as location and security attributes, and a central enforcement controller to determine packet forwarding paths and apply security policies to network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If context-aware security policies are implemented across distributed microservices, then security control precision is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity control precisionVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system segments the distributed microservices environment into individually addressable units with unique identifiers and attributes. Each microservice can be independently tagged and secured, allowing precise security control without managing the entire distributed system as a monolithic complex entity. This segmentation enables granular policy application to specific services while simplifying overall security management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including a tagging service that assigns metadata to microservices, a policy decision point that evaluates security rules, and a policy enforcement point that implements security controls. These intermediaries abstract the complexity of context-aware security, mediating between the distributed microservices and security policies without requiring direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If granular security policies are applied to individual virtual machines, then security granularity is improved, but policy management complexity increases

Engineering Contradiction:
Improvesecurity granularityVSAvoidpolicy management complexity
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The system employs universal security policies that can be applied across multiple microservices with different attributes. A single policy can target services based on common characteristics such as service type, sensitivity level, or deployment environment, allowing the same policy to uniformly secure diverse microservices. This universality reduces the number of individual policies needed while maintaining granular control through attribute-based targeting.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes attribute-based targeting where security policies are defined in terms of service attributes rather than specific service identities. By changing the parameter space from individual service names to attribute dimensions (e.g., sensitivity, service type, location), the system achieves granular control through flexible parameter combinations, simplifying policy management while maintaining precision.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If real-time threat detection is implemented in distributed environments, then detection capability is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-tagging microservices with identifying attributes and metadata before security evaluation is needed. This advance preparation of service identification information allows real-time threat detection to focus only on evaluating security rules against pre-computed attributes, rather than gathering service information during threat analysis. This preliminary tagging reduces processing overhead during actual threat detection while maintaining high detection capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10158672B2Context aware microsegmentation
Publication Date: 2018.12.18 GRYPHO5 LLC
  • US10158672B2 patent drawing
  • US10158672B2 patent drawing
  • US10158672B2 patent drawing

AI summary

Context aware microservice networks and contextual security policies for microservice networks are provided herein. In some embodiments, a system includes a plurality of microservices, each of the plurality of microservices having a plurality of distributed microservice components. At least a portion of the distributed microservice components execute on different physical or virtual servers in a data center or a cloud. The system also includes a plurality of logical security boundaries, with each of the plurality of logical security boundaries being created by a plurality of enforcement points positioned in association with the plurality of distributed microservice components. Each of plurality of microservices is bounded by one of the plurality of logical security boundaries.