Trajectory Management for Microservice Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In service mesh architectures, ensuring that data moving through microservices adheres to appropriate security levels based on its confidentiality is challenging, as different types of data have varying levels of confidentiality and require tailored security enforcement.
Innovation Solution
A computer-implemented method that identifies the confidentiality levels of source and processed data by analyzing metadata, then selects a trajectory path through microservices that meets the required security levels, generating and executing a workflow to enforce these security levels during data movement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data moves through multiple microservices in a service mesh architecture, then data processing capabilities are enhanced, but security enforcement becomes more complex and difficult to maintain
Solution Approach 1:
The patent introduces a trajectory management system that acts as an intermediary between data sources and microservices. This system includes a trajectory path identifier that automatically determines the confidentiality level of data and selects appropriate trajectory paths with predefined security rules, thereby simplifying security enforcement in complex service mesh architectures without compromising data processing capabilities
Solution Approach 2:
The patent implements preliminary action by pre-defining multiple trajectory paths with different security levels before data movement occurs. The system analyzes data confidentiality levels in advance and selects the appropriate pre-configured path, eliminating the need for complex real-time security decisions during data processing and reducing enforcement complexity
2Ease of operation
If different types of data are processed through the same trajectory path, then system simplicity is maintained, but security levels may not be adequately enforced for confidential data
Solution Approach 1:
The patent applies local quality by creating different trajectory paths with specific security characteristics tailored to different data confidentiality levels. Instead of using a uniform approach for all data, the system configures specific security rules (such as encryption, access control) for specific trajectory paths based on the sensitivity requirements of the data they carry, thereby maintaining both simplicity and reliability
3Measurement precision
If security rules are dynamically adjusted for each data trajectory, then security enforcement accuracy is improved, but computational overhead increases
Solution Approach 1:
The patent reduces computational overhead by performing security rule assignment in advance. Trajectory paths are pre-configured with appropriate security rules based on confidentiality levels during system setup or deployment. When data moves through the service mesh, the trajectory management system simply selects the pre-configured path matching the data's confidentiality level, avoiding complex real-time security rule generation and significantly reducing computational overhead while maintaining high security enforcement accuracy
Data Source
AI summary
Provided are techniques for enforcing security rules along a trajectory of data movement. Confidentiality levels of source data and of processed data at different points of an existing trajectory path in an application landscape are identified by analyzing source metadata of the source data and processed metadata of the processed data. One or more trajectory paths that meet security levels that correspond to the confidentiality levels are identified by analyzing microservice generated logs and an application landscape description with reference to the confidentiality levels of the source data and the processed data. A trajectory path is selected from the one or more trajectory paths. A workflow is generated to move the source data and the processed data through the selected trajectory path, and the workflow is executed to move the source data and the processed data through microservices of the selected trajectory path while enforcing the security levels.


