Trajectory Management for Microservice Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In service mesh architectures, ensuring that data moving through microservices adheres to appropriate security levels based on its confidentiality is challenging, as different types of data have varying levels of confidentiality and require tailored security enforcement.

Innovation Solution

A computer-implemented method that identifies the confidentiality levels of source and processed data by analyzing metadata, then selects a trajectory path through microservices that meets the required security levels, generating and executing a workflow to enforce these security levels during data movement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data moves through multiple microservices in a service mesh architecture, then data processing capabilities are enhanced, but security enforcement becomes more complex and difficult to maintain

Engineering Contradiction:
Improvedata processing capabilityVSAvoidsecurity enforcement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a trajectory management system that acts as an intermediary between data sources and microservices. This system includes a trajectory path identifier that automatically determines the confidentiality level of data and selects appropriate trajectory paths with predefined security rules, thereby simplifying security enforcement in complex service mesh architectures without compromising data processing capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-defining multiple trajectory paths with different security levels before data movement occurs. The system analyzes data confidentiality levels in advance and selects the appropriate pre-configured path, eliminating the need for complex real-time security decisions during data processing and reducing enforcement complexity

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If different types of data are processed through the same trajectory path, then system simplicity is maintained, but security levels may not be adequately enforced for confidential data

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity level enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by creating different trajectory paths with specific security characteristics tailored to different data confidentiality levels. Instead of using a uniform approach for all data, the system configures specific security rules (such as encryption, access control) for specific trajectory paths based on the sensitivity requirements of the data they carry, thereby maintaining both simplicity and reliability

Inventive Principle:
Principle #3Local quality

3Measurement precision

If security rules are dynamically adjusted for each data trajectory, then security enforcement accuracy is improved, but computational overhead increases

Engineering Contradiction:
Improvesecurity enforcement accuracyVSAvoidcomputational overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent reduces computational overhead by performing security rule assignment in advance. Trajectory paths are pre-configured with appropriate security rules based on confidentiality levels during system setup or deployment. When data moves through the service mesh, the trajectory management system simply selects the pre-configured path matching the data's confidentiality level, avoiding complex real-time security rule generation and significantly reducing computational overhead while maintaining high security enforcement accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12309202B2Enforcing security rules along a trajectory of data movement
Publication Date: 2025.05.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12309202B2 patent drawing
  • US12309202B2 patent drawing
  • US12309202B2 patent drawing

AI summary

Provided are techniques for enforcing security rules along a trajectory of data movement. Confidentiality levels of source data and of processed data at different points of an existing trajectory path in an application landscape are identified by analyzing source metadata of the source data and processed metadata of the processed data. One or more trajectory paths that meet security levels that correspond to the confidentiality levels are identified by analyzing microservice generated logs and an application landscape description with reference to the confidentiality levels of the source data and the processed data. A trajectory path is selected from the one or more trajectory paths. A workflow is generated to move the source data and the processed data through the selected trajectory path, and the workflow is executed to move the source data and the processed data through microservices of the selected trajectory path while enforcing the security levels.