Network Mesh Service Authentication via Intermediary Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed computing environments like cloud computing face challenges in ensuring the security and privacy of healthcare data, particularly due to centralization of data which increases the risk of data theft and loss, and compliance with regulations such as HIPAA, GDPR, and others.

Innovation Solution

A computer-implemented method utilizing a centralized network mesh for service-to-service communication and authentication, which involves receiving service requests, obtaining information from caches or service registries, retrieving security rules, forwarding requests, and managing access using security keys to ensure secure interactions between services across distributed computing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is centralized on cloud computing platforms, then resource sharing, flexibility, and deployment speed are improved, but security and privacy risks increase due to centralized data storage and access

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service mesh as an intermediary layer between services and the network. The service mesh handles authentication, authorization, and secure communication protocols, allowing services to communicate securely without exposing sensitive data to the public network. This mediator approach resolves the contradiction by enabling fast cloud deployment while maintaining security through the service mesh's security layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into isolated service domains using service meshes. Each service or group of services operates within its own mesh domain with controlled access boundaries. This segmentation prevents lateral movement of attackers and limits the impact of security breaches, allowing centralized cloud deployment while reducing overall security risk through isolation.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If cloud computing is used for healthcare data storage and management, then scalability and cost-effectiveness are improved, but compliance with regulations like HIPAA and GDPR becomes more difficult

Engineering Contradiction:
ImprovescalabilityVSAvoidcompliance complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The service mesh acts as an intermediary that enforces compliance policies between services. It provides built-in support for HIPAA and GDPR requirements through automated authentication, encryption, and access control mechanisms. This mediator layer handles compliance complexity centrally, allowing scalable cloud deployment while simplifying regulatory compliance through standardized security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements configurable security parameters within the service mesh that can be adjusted to meet different regulatory requirements. Security settings such as encryption strength, authentication methods, and data retention policies can be dynamically changed to comply with HIPAA, GDPR, or other regulations without affecting system scalability.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If service-to-service communication is enabled in distributed environments, then system functionality and collaboration are improved, but authentication and security management complexity increase

Engineering Contradiction:
Improvesystem functionalityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The service mesh serves as a centralized authentication intermediary that manages service-to-service communication security. It handles token validation, mutual authentication, and authorization decisions automatically, eliminating the need for complex peer-to-peer authentication logic. This mediator approach enables full system functionality while reducing authentication complexity to a centralized management plane.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Services within the mesh automatically authenticate and authorize each other through the service mesh without requiring manual configuration. The service mesh provides self-service authentication mechanisms where services present their identities and receive automatic authorization decisions, reducing operational complexity while maintaining secure communication.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12341776B2Service to service communication and authentication via a central network mesh
Publication Date: 2025.06.24 GENENTECH INC
  • US12341776B2 patent drawing
  • US12341776B2 patent drawing
  • US12341776B2 patent drawing

AI summary

The present disclosure relates to techniques for service to service communication and authentication via a network mesh. Particularly, aspects are directed to receiving, at a network mesh, a service request for a first service, and obtaining information associated with the first service. The information includes a location of a first pod encapsulating the first service. The network mesh using the location of the first pod, retrieves security rules specific for the first pod. The network mesh forwards the service request to the first service based on the security rules of the first pod and obtains results of the service request from the first service. The results include a sub result obtained from a second service in accordance with security rules for the first pod encapsulating the first service and security rules for a second pod encapsulating the second service.