Microservice Chain Security for Dynamic Confidential Outputs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems fail to dynamically adjust security measures based on the sensitivity of information, leading to inefficient use of resources and potential delays in accessing sensitive data.

Innovation Solution

A method that identifies microservice chains in a network computer, analyzes user profiles and data entry points, and predicts when a microservice will generate confidential output, dynamically upgrading security measures to ensure secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all data is treated at the highest level of security, then data confidentiality is improved, but access efficiency and user productivity deteriorate

Engineering Contradiction:
Improvedata confidentialityVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by classifying data into different sensitivity levels (e.g., public, internal, confidential, restricted) and applying appropriate security measures to each level. This allows high-security measures for sensitive data while maintaining easier access for less sensitive data, resolving the contradiction between overall confidentiality and access efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic security measures that automatically adjust based on data sensitivity classification. Security protocols, access controls, and monitoring levels are dynamically modified according to the classified data type, enabling the system to optimize both confidentiality and accessibility in real-time.

Inventive Principle:
Principle #15Dynamics

2Reliability

If high-level security measures are applied to all data, then data protection is improved, but system complexity and cost increase

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces system complexity by applying security measures locally based on data classification rather than uniformly across all data. This allows simple security for public data and complex security only for restricted data, optimizing the balance between protection and complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial security measures only where necessary based on data sensitivity classification. Instead of over-protecting all data with maximum security, the system applies appropriate security levels selectively, reducing unnecessary complexity and cost while maintaining adequate protection for sensitive information.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of manufacture

If uniform security classification is applied to all data, then implementation simplicity is improved, but security effectiveness and adaptability deteriorate

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent enhances security effectiveness by implementing differentiated classification categories (public, internal, confidential, restricted) that match the actual sensitivity of different data types. This localized approach maintains implementation simplicity through automated classification while achieving superior security effectiveness compared to uniform treatment.

Inventive Principle:
Principle #3Local quality

4Productivity

If automated security classification is implemented, then security responsiveness is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improvesecurity responsivenessVSAvoidclassification system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated data classification where the system automatically analyzes and classifies data based on predefined criteria without requiring manual intervention. This automation enhances security responsiveness while the use of predefined classification rules keeps the computational complexity manageable.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12381852B2Providing dynamic network security based on importance of proprietary content
Publication Date: 2025.08.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12381852B2 patent drawing
  • US12381852B2 patent drawing
  • US12381852B2 patent drawing

AI summary

A method, computer system, and a computer program product are provided for establishing security measures for a content. In one embodiment, the method comprises identifying at least a microservice chain in a network computer. Each microservice chain has more than one microservice linked to one another and each microservice includes a plurality of applications bundled together. Any use profiles associated with the microservice chain are identified and all data entry points into each microservice are determined. Each microservice is analyzed to predict when each microservice in the chain will provide a confidential output. Once any microservice chain is deemed to be providing a confidential output, any predicted exits in the microservice deemed to be generating an output content are upgraded so that all predicted exists provide a confidential output.