Microservice Security Risk Reduction via Service Mesh Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Applications with distributed microservices in a cloud-based architecture face increased security risks due to data communication across multiple networks, including those under third-party control, making it difficult to ensure security without specific security functions provided by the cloud environment.

Innovation Solution

The system employs a security management framework that analyzes the security risks of distributed microservices and adds security services to the application package, deploying them on the cloud platform to reduce security risks, independent of the cloud environment's security features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If distributed microservices architecture is used to enable scalable data utilization, then productivity and adaptability are improved, but security risk increases due to network communication between services

Engineering Contradiction:
Improvedata utilization scalabilityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the application into multiple microservices that can be independently deployed and managed. Each microservice is a self-contained unit that communicates through standardized interfaces, enabling scalable data utilization while maintaining security boundaries between services. The segmentation allows security risks to be isolated to specific services rather than affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a service mesh as an intermediary layer between microservices. The service mesh handles security concerns such as authentication, authorization, and encryption for inter-service communication, allowing the microservices to focus on business logic while the intermediary manages security risks associated with network communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud platform deployment is used to achieve flexible infrastructure, then adaptability is improved, but security control deteriorates when relying on third-party network environments

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidthird-party network security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements security configurations and policies before deploying microservices to the cloud platform. Security templates, authentication mechanisms, and network policies are pre-configured in the service mesh, ensuring that security controls are in place before the application encounters third-party network environments, thus maintaining security control while enjoying cloud deployment flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The service mesh creates a controlled, secure communication environment between microservices, isolating them from external third-party network risks. This 'inert environment' encrypts and secures inter-service communication, protecting the application from harmful factors in the external cloud network while maintaining the benefits of cloud platform deployment.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Reliability

If more security services are added to reduce security risk, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security services into a unified service mesh architecture. Instead of implementing separate security components for each microservice, the service mesh consolidates authentication, authorization, encryption, and monitoring functions into a single integrated layer, reducing overall system complexity while maintaining comprehensive security coverage across all microservices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The service mesh provides universal security functionality that can be applied to any microservice without requiring service-specific security implementations. The same security policies and mechanisms work across all services in the system, simplifying security management and reducing complexity by eliminating the need for multiple specialized security components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11899799B2Security risk reduction method and security risk reduction system
Publication Date: 2024.02.13 HITACHI LTD
  • US11899799B2 patent drawing
  • US11899799B2 patent drawing
  • US11899799B2 patent drawing

AI summary

A system performs an application update process based on security management information that is information including meta information for each of a plurality of security services. The application update process is a process for adding one or more security services including a security service that reduces the security risk of an application having a plurality of distributed microservices having a graph structure relationship to the application.