IP Library Granted Patent US 12671694
Granted Patent B1
US 12671694 · App. 19/043,658 · Granted Jun 30, 2026

Intelligent system for cloud container orchestrator infrastructure security

Inventor: Vinod Maghnani (Gurugram Haryana, IN)
Assignee: Bank of America Corporation
H04L63/102G06F21/6254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671694
App. No.
19/043,658
Granted
Jun 30, 2026
Kind
B1
Abstract

A system for enhancing cloud container security in a cloud network. The systems may include a visualization tool for periodic surveillance of a cloud container. A visualization engine may utilize the data from the visualization tool to periodically measure the dynamic proximity of multiple Kubernetes to the cloud container. When multiple Kubernetes are functioning in proximity to the cloud container, a deep learning engine may determine a profile and a level of authorization for each Kubernetes in proximity of the cloud container using a Kubernetes profile database. The deep learning engine may determine the Kubernetes with the least level of authorization and forward that information to a machine learning (“ML”) masking rule engine. The ML masking rule engine redacts and/or masks less sensitive information at a fixed point in time and more sensitive information dynamically in real time.

Claims (89)

1 . A system for enhancing cloud container security in a cloud network, the system comprising:

a cloud container;

a visualization tool;

a visualization engine;

a Kubernetes® profile database;

a deep learning engine;

a machine learning (“ML”) masking rule engine;

said visualization tool configured to provide, at fixed intervals of time, dynamic surveillance of the cloud container for presence of one or more Kubernetes in dynamic proximity to the cloud container, said cloud container and said visualization tool present in the cloud network;

said visualization engine configured to measure dynamic proximity of one or more Kubernetes to the cloud container, at fixed intervals of time, using data from the visualization tool;

when one or more Kubernetes are within a visual field of interest of the cloud container and within a pre-determined proximity threshold of the cloud container, said deep learning engine is configured to:

analyze dynamic proximity data of the one or more Kubernetes received from the visualization engine to determine a Kubernetes profile of the one or more Kubernetes;

determine a level of authorization for the one or more Kubernetes by looking up the Kubernetes profile of the one or more Kubernetes in the Kubernetes profile database;

wherein said Kubernetes profile database comprises pre-determined correlations between a Kubernetes profile and a level of authorization to access sensitive information on the cloud container, said Kubernetes profile comprises a customized configuration of each of the one or more Kubernetes;

provide the ML masking rule engine with the level of authorization of the Kubernetes;

the ML masking rule engine is configured to:

redact and/or mask a first group of sensitive information fields in the cloud container based on the level of authorization of the Kubernetes;

dynamically redact and/or dynamically mask a second group of sensitive information fields in the cloud container, in real time, based on the level of authorization of the Kubernetes;

wherein the second group of sensitive information fields comprise fields that are more sensitive than the first group of sensitive information fields.

2 . The system of claim 1 wherein, when two or more Kubernetes are within the visual field of interest of the cloud container and within the pre-determined proximity threshold of the cloud container, further comprising:

the ML masking rule engine is configured to:

redact and/or mask a first group of sensitive information fields in the cloud container based on a level of authorization of a first Kubernetes;

dynamically redact and/or dynamically mask a second group of sensitive information fields in the cloud container, in real time, based on the level of authorization of the first Kubernetes;

wherein the second group of sensitive information fields comprise fields that are more sensitive than the first group of sensitive information fields;

redact and/or mask a third group of sensitive information fields in the cloud container based on a level of authorization of a second Kubernetes; and

dynamically redact and/or dynamically mask a fourth group of sensitive information fields in the cloud container, in real time, based on the level of authorization of the second Kubernetes;

wherein:

the fourth group of sensitive information fields comprise fields that are more sensitive than the third group of sensitive information fields;

the first group of sensitive information fields and the third group of sensitive information fields are different from one another; and

the second group of sensitive information fields and the fourth group of sensitive information fields are different from one another.

3 . The system of claim 1 wherein the cloud network is a private cloud network.

4 . The system of claim 1 wherein the cloud network is a public cloud network.

5 . The system of claim 1 wherein the cloud network is a hybrid cloud network, said hybrid cloud network comprises aspects of a private cloud network and aspects of a public cloud network.

6 . The system of claim 1 wherein:

the cloud container comprises a container image; and

before redaction and masking, the container image is visible to a Kubernetes that is within the visual field of interest of the cloud container and is within the pre-determined proximity threshold of the cloud container.

7 . The system of claim 1 wherein the visualization tool is a camera.

8 . A method for enhancing cloud container security in a cloud network, the method comprising:

providing, using a visualization tool, dynamic surveillance of a cloud container, at fixed intervals of time, for presence of one or more Kubernetes® in dynamic proximity to the cloud container, said cloud container and said visualization tool present in the cloud network;

measuring, using a visualization engine, dynamic proximity of one or more Kubernetes to the cloud container, at fixed intervals of time, using images from the visualization tool;

when one or more Kubernetes are within a visual field of interest of the cloud container and a pre-determined proximity threshold of the cloud container, analyzing, using a deep learning engine, dynamic proximity data of the one or more Kubernetes received from the visualization engine to determine a Kubernetes profile of the one or more Kubernetes;

determining, using the deep learning engine, a level of authorization for the one or more Kubernetes by looking up the Kubernetes profile in a Kubernetes profile database;

wherein said Kubernetes profile database comprises pre-determined correlations between a Kubernetes profile and a level of authorization to access sensitive information on the cloud container, said Kubernetes profile comprises a customized configuration of the one or more Kubernetes;

providing, using the deep learning engine, a machine learning (“ML”) masking rule engine with the level of authorization of the Kubernetes;

redacting and/or masking, using the ML masking rule engine, a first group of sensitive information fields in the cloud container based on the level of authorization of the Kubernetes;

dynamically redacting and/or dynamically masking, using the ML masking rule engine, a second group of sensitive information fields in the cloud container, in real time, based on the level of authorization of the Kubernetes;

wherein the second group of sensitive information fields comprise fields that are more sensitive than the first group of sensitive information fields.

9 . The method of claim 8 wherein, when two or more Kubernetes are within the visual field of interest of the cloud container and within the pre-determined proximity threshold of the cloud container, further comprising:

redacting and/or masking, using the ML masking engine, a first group of sensitive information fields in the cloud container based on a level of authorization of a first Kubernetes;

dynamically redacting and/or dynamically masking, using the ML masking engine, a second group of sensitive information fields in the cloud container, in real time, based on the level of authorization of the first Kubernetes;

wherein the second group of sensitive information fields comprise fields that are more sensitive than the first group of sensitive information fields;

redacting and/or masking, using the ML masking engine, a third group of sensitive information fields in the cloud container based on a level of authorization of a second Kubernetes; and

dynamically redacting and/or dynamically masking, using the ML masking engine, a fourth group of sensitive information fields in the cloud container, in real time, based on the level of authorization of the second Kubernetes;

wherein:

the fourth group of sensitive information fields comprise fields that are more sensitive than the third group of sensitive information fields;

the first group of sensitive information fields and the third group of sensitive information fields are different from one another; and

the second group of sensitive information fields and the fourth group of sensitive information fields are different from one another.

10 . The method of claim 8 wherein the cloud network is a private cloud network.

11 . The method of claim 8 wherein the cloud network is a public cloud network.

12 . The method of claim 8 wherein the cloud network is a hybrid cloud network, said hybrid cloud network comprises aspects of a private cloud network and aspects of a public cloud network.

13 . The method of claim 8 wherein:

the cloud container comprises a container image; and

before redaction and masking, the container image is visible to a Kubernetes that is within the visual field of interest of the cloud container and is within the pre-determined proximity threshold of the cloud container.

14 . A system for enhancing cloud container security in a cloud network, the system comprising:

a cloud container;

a visualization tool;

a visualization engine;

a Kubernetes® profile database;

a deep learning engine;

a machine learning (“ML”) masking rule engine;

said visualization tool configured to provide, at fixed intervals of time, dynamic surveillance of the cloud container for presence of two or more Kubernetes in dynamic proximity to the cloud container, said cloud container and said visualization tool present in the cloud network;

said visualization engine configured to measure dynamic proximity of two or more Kubernetes to the cloud container, at fixed intervals of time, using data from the visualization tool;

when two or more Kubernetes are within a visual field of interest of the cloud container and within a pre-determined proximity threshold of the cloud container, said deep learning engine is configured to:

analyze dynamic proximity data of the two or more Kubernetes received from the visualization engine to determine a Kubernetes profile for each of the two or more Kubernetes;

determine a level of authorization for each of the two or more Kubernetes by looking up the Kubernetes profile for each of the two or more Kubernetes in the Kubernetes profile database;

wherein said Kubernetes profile database comprises pre-determined correlations between a Kubernetes profile and a level of authorization to access sensitive information on the cloud container, said Kubernetes profile comprises a customized configuration of the one or more Kubernetes;

determine which level of authorization from the two or more Kubernetes provides a least level of authorization;

provide the ML masking rule engine with the least level of authorization for the two or more Kubernetes;

the ML masking rule engine is configured to:

redact and/or mask a first group of sensitive information fields in the cloud container based on the least level of authorization of the two or more Kubernetes;

dynamically redact and/or dynamically mask a second group of sensitive information fields in the cloud container, in real time, based on the least level of authorization of the Kubernetes;

wherein the second group of sensitive information fields comprise information that is more sensitive than the first group of sensitive information fields.

15 . The system of claim 14 wherein determination of the least level of authorization is based on the level of authorization of a Kubernetes that has a least amount of privileges to view sensitive information from the two or more Kubernetes.

16 . The system of claim 14 wherein the cloud network is a private cloud network.

17 . The system of claim 14 wherein the cloud network is a public cloud network.

18 . The system of claim 14 wherein the cloud network is a hybrid cloud network, said hybrid cloud network comprises aspects of a private cloud network and aspects of a public cloud network.

19 . The system of claim 14 wherein:

the cloud container comprises a container image; and

before redaction and masking, the container image is visible to a Kubernetes that is within the visual field of interest of the cloud container and is within the pre-determined proximity threshold of the cloud container.

20 . The system of claim 14 wherein the visualization tool is a camera.