Enforcement Points for Microservice Security Boundaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing security systems fail to effectively provide secure virtual boundaries for distributed microservices, leading to vulnerabilities in network traffic inspection and real-time threat detection across disparate physical servers.

Innovation Solution

A system comprising distributed microservice components with enforcement points and a director module that creates logical security boundaries, intercepts network traffic, and manages sessions and settings to enforce security policies and detect malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed microservice components are deployed across different physical servers to improve scalability and flexibility, then system adaptability and productivity are improved, but security boundary enforcement and threat detection capability deteriorate

Engineering Contradiction:
Improvemicroservice deployment flexibilityVSAvoidsecurity boundary enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces enforcement points as intermediary components deployed alongside microservice components across distributed servers. These enforcement points act as mediators that inspect and control network traffic between microservices, enabling security boundary enforcement without requiring centralized control or altering the distributed deployment architecture. The enforcement points locally enforce security policies at each deployment location, resolving the contradiction between distributed flexibility and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional perimeter-based security models are used to simplify security management, then device complexity is reduced, but they fail to provide effective security for distributed microservices across multiple physical servers

Engineering Contradiction:
Improvesecurity management complexityVSAvoiddistributed microservice security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security enforcement function into multiple distributed enforcement points, each deployed alongside specific microservice components. Instead of a single perimeter security layer, security is segmented and distributed across multiple locations matching the microservice architecture. Each enforcement point handles security for its associated microservice components, providing effective security for distributed deployments while maintaining manageable complexity through standardized enforcement point deployment.

Inventive Principle:
Principle #1Segmentation

3Productivity

If network traffic between distributed microservice components is not inspected in real-time, then processing overhead is reduced, but threat detection capability and exfiltration prevention deteriorate

Engineering Contradiction:
Improvemicroservice communication efficiencyVSAvoidthreat detection capability
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The enforcement points perform self-service by autonomously inspecting and controlling network traffic between microservice components without requiring external security management intervention. Each enforcement point independently monitors its local traffic, detects threats, and enforces security policies in real-time. This self-service capability enables continuous security monitoring with minimal overhead, as enforcement points operate autonomously at the edge of the microservice architecture rather than requiring centralized traffic inspection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10178070B2Methods and systems for providing security to distributed microservices
Publication Date: 2019.01.08 GRYPHO5 LLC
  • US10178070B2 patent drawing
  • US10178070B2 patent drawing
  • US10178070B2 patent drawing

AI summary

Systems for providing security to distributed microservices are provided herein. In some embodiments, a system includes a plurality of microservices, each of the plurality of microservices having a plurality of distributed microservice components. At least a portion of the distributed microservice components execute on different physical or virtual servers in a data center or a cloud. The system also includes a plurality of logical security boundaries, with each of the plurality of logical security boundaries being created by a plurality of enforcement points positioned in association with the plurality of distributed microservice components. Each of plurality of microservices is bounded by one of the plurality of logical security boundaries.