IP Library › Granted Patent US 12,261,828
Granted Patent B2
US 12,261,828 · App. 18/063,095 · Granted Mar 25, 2025

Modifying security of microservices in a chain based on predicted confidential data flow through the microservices

Inventors: Sudheesh S. Kairali (Kozhikode, IN); Sarbajit K. Rakshit (Kolkata, IN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/0414G06F21/1064
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,828
App. No.
18/063,095
Granted
Mar 25, 2025
Kind
B2
Abstract

A method for protecting data from a user that traverses through a chain of microservices include retrieving information identifying the chain of microservices associated with a user identifier of the user and a time when the user provided data to the chain of microservices. A level of confidentiality stored in association with the user identifier and with the time is retrieved. One or more security measures corresponding to the stored level of confidentiality are implemented for each microservice of the chain of microservices during the time.

Claims (47)

1. A method for protecting data from a user when traversing a chain of microservices, the method comprising:

retrieving information identifying the chain of microservices associated with a user identifier of the user and a predicted time when the user will provide data to the chain of microservices;

retrieving a level of confidentiality stored in association with the user identifier of the user and the predicted time; and

implementing one or more security measures corresponding to the stored level of confidentiality for each microservice of the chain of microservices during the predicted time.

2. The method of claim 1 , further comprising:

implementing an alternative security measure for each microservice of the chain of microservices after the time.

3. The method of claim 2 , wherein the alternative security measure corresponds to a lower level of confidentiality than the level of confidentiality.

4. The method of claim 1 , further comprising:

implementing an alternative security measure for each microservice of the chain of microservices after the time in response to at least a threshold time passing from receipt of data having the level of confidentiality from the user.

5. The method of claim 1 , wherein retrieving information identifying the chain of microservices associated with the user identifier of the user and the time when the user provided data to the chain of microservices comprises:

monitoring interactions by the user during a training interval;

storing one or more times when data was received from the user during the training interval in association with the user identifier;

identifying one or more chains of microservices retrieved for the user in response to data received from the user;

storing an identified chain of microservices retrieved for corresponding data received from the user in association with a time when the data was received and the user identifier; and

retrieving the identified chain of microservices and the time when data was received based on the user identifier.

6. The method of claim 1 , wherein retrieving the level of confidentiality in association with the user identifier of the user and the time comprises:

determining a level of confidentiality for data received from the user during a training interval;

storing a time when data was received and a level of confidentiality determined for the data in association with a user identifier; and

retrieving the identified level of confidentiality associated with the user identifier and the time when data was received based on the user identifier.

7. The method of claim 1 , wherein implementing one or more security measures corresponding to the stored level of confidentiality for each microservice of the chain of microservices during the time comprises:

configuring the one or more security measures at an initialization time that is a threshold amount of time before the time.

8. The method of claim 7 , wherein the threshold amount of time is based on at least one of the one or more security measures.

9. The method of claim 1 , wherein implementing one or more security measures corresponding to the stored level of confidentiality for each microservice of the chain of microservices during the time comprises:

generating a replica of the chain of microservices; and

implementing the one or more security measures corresponding to the stored level of confidentiality for each microservice of the replica of the chain of microservices during the time.

10. An apparatus for protecting data from a user when traversing a chain of microservices, the apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out steps of:

retrieving information identifying the chain of microservices associated with a user identifier of the user and a predicted time when the user will provide data to the chain of microservices;

retrieving a level of confidentiality stored in association with the user identifier of the user and the predicted time; and

implementing one or more security measures corresponding to the stored level of confidentiality for each microservice of the chain of microservices during the predicted time.

11. The apparatus of claim 10 , wherein the steps further comprise:

implementing an alternative security measure for each microservice of the chain of microservices after the time.

12. The apparatus of claim 11 , wherein the alternative security measure corresponds to a lower level of confidentiality than the level of confidentiality.

13. The apparatus of claim 10 , wherein implementing one or more security measures corresponding to the stored level of confidentiality for each microservice of the chain of microservices during the time comprises:

configuring the one or more security measures at an initialization time that is a threshold amount of time before the time.

14. The apparatus of claim 13 , wherein the threshold amount of time is based on at least one of the one or more security measures.

15. A computer program product for protecting data from a user when traversing a chain of microservices, the computer program product disposed upon a computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out steps of:

retrieving information identifying the chain of microservices associated with a user identifier of the user and a predicted time when the user will provide data to the chain of microservices;

retrieving a level of confidentiality stored in association with the user identifier of the user and the predicted time; and

implementing one or more security measures corresponding to the stored level of confidentiality for each microservice of the chain of microservices during the predicted time.

16. The computer program product of claim 15 , wherein the computer readable medium further comprises computer program instructions that, when executed, cause the computer to carry out steps of:

implementing an alternative security measure for each microservice of the chain of microservices after the time.

17. The computer program product of claim 16 , wherein the alternative security measure corresponds to a lower level of confidentiality than the level of confidentiality.

18. The computer program product of claim 15 , wherein the computer readable medium further comprises computer program instructions that, when executed, cause the computer to carry out steps of:

implementing an alternative security measure for each microservice of the chain of microservices after the time in response to at least a threshold time passing from receipt of data having the level of confidentiality from the user.

19. The computer program product of claim 15 , wherein implementing one or more security measures corresponding to the stored level of confidentiality for each microservice of the chain of microservices during the time comprises:

configuring the one or more security measures at an initialization time that is a threshold amount of time before the time.

20. The computer program product of claim 19 , wherein the threshold amount of time is based on at least one of the one or more security measures.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: KAIRALI, SUDHEESH S.; RAKSHIT, SARBAJIT K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062020/0855 →
Continuity (1)
Related Publication 20240195787A1 · Jun 13, 2024
References Cited (15)
US 12045839B1 · Mishra · 2024 [cited by examiner]
US 20190102157A1 · Caldato · 2019 [cited by examiner]
US 20190171447A1 · Lepcha · 2019 [cited by examiner]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
US 20200296172A1 · Gunjal et al. · 2020 [cited by applicant]
US 20210306321A1 · Calegari · 2021 [cited by examiner]
US 20210312277A1 · Prabhudesai · 2021 [cited by examiner]
US 20240015080A1 · Illikkal · 2024 [cited by examiner]
US 20240330093A1 · Shwartz · 2024 [cited by examiner]
WO 2022019983A1 · 2022 [cited by applicant]
Acquaviva et al., Fater Microservice-to-Microservice encrypted communication with Kong Mesh and Intel, URL: https://networkbuilders.intel.com/blog/faster-microservice-to-microservice-encrypted-communication-with-kong-me… [cited by applicant]
Anonymous, Intelligent Fast Forwarding of the Usual Suspects in a Microservice Chain Based on Minimum Data Dimensions, IP.com No. IPCOM000268436D, IP.com Electronic Publication Date: Jan. 30, 2022, 4 pages. [cited by applicant]
Boldon James, Automated Data Classification, URL: https://www.boldonjames.com/data-classification/automated-classification/, 2022, printed Aug. 12, 2022, 4 pages. [cited by applicant]
Chetan Conikee, GDPR and Data Leakage: How Semantic Graphing Can Help, dated Aug. 16, 2018, 1 page. [cited by applicant]
Ilia Sotnikov, Data Classification: What It Is and How to Implement It, netwrix blog, URL: https://blog.netwrix.com/2020/09/02/data-classification/, published Sep. 2, 2020, Updated Jan. 13, 2022, 25 pages. [cited by applicant]