Service Mesh Dynamic Access Control for Secret Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional service meshes face challenges in handling secrets and third-party service authentication, leading to complex development processes, security risks, and increased time spent on comparing service costs and performance.

Innovation Solution

Implementing a dynamic access control system that abstracts authentication operations to the service mesh, using a service broker to manage secrets and credentials, isolating them from user-space containers, and employing mTLS for secure connections, allowing applications to access services without direct credential provision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If applications store secrets in API servers or configuration files, then authentication to third-party services is enabled, but security risks increase and development complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service mesh as an intermediary layer between applications and third-party services. The service mesh handles authentication and secret management centrally, eliminating the need for applications to store or manage secrets directly. This mediator approach reduces security risks while maintaining authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts secret management and authentication logic from individual applications and places it in the service mesh infrastructure. By taking out these sensitive operations from user-space applications, the system eliminates the security risks associated with storing secrets in configuration files or API servers while preserving the authentication function.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If applications include code to handle secrets and read from environment variables, then third-party service access is enabled, but development complexity increases and development cycle prolongs

Engineering Contradiction:
Improveservice access capabilityVSAvoidapplication code complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The service mesh provides self-service authentication where the infrastructure automatically handles secret retrieval and credential management. Applications simply need to reference service names in the service mesh, and the system automatically provisions and manages the necessary authentication credentials without requiring developers to write custom authentication code.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The service mesh implements a universal authentication mechanism that works for multiple third-party services through a single infrastructure layer. Instead of requiring applications to implement service-specific authentication logic, the service mesh provides a unified interface that abstracts away the differences between various service providers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If developers manually compare third-party services for cost and performance, then service selection is enabled, but time investment increases and development efficiency decreases

Engineering Contradiction:
Improveservice selection capabilityVSAvoidservice comparison time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The service mesh incorporates feedback mechanisms that automatically monitor service performance, cost, and availability. This feedback information is made available to developers through the service mesh interface, enabling informed service selection without requiring manual research and comparison of third-party service providers.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12034728B2Dynamic access control in service mesh with service broker
Publication Date: 2024.07.09 EMC IP HLDG CO LLC
  • US12034728B2 patent drawing
  • US12034728B2 patent drawing
  • US12034728B2 patent drawing

AI summary

One example method includes performing dynamic access control in a computing network. A computing environment is configured such that an application can access a service without specifying secrets. The secrets needed to access the service are obtained and stored in a credential store. The secrets can be obtained using the service mesh in a manner that isolates the application from the secrets.