IP Library › Granted Patent US 12,587,380
Granted Patent B2
US 12,587,380 · App. 18/381,835 · Granted Mar 24, 2026

Trusted execution environment for distributed data security in the service mesh

Inventors: Charles Fleming (Oxford, MS); Ramana Rao V. R. Kompella (Foster City, CA)
Assignee: Cisco Technology, Inc.
H04L9/3218G06F21/64H04L9/3234G06F21/57G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,380
App. No.
18/381,835
Granted
Mar 24, 2026
Kind
B2
Abstract

In one implementation, a method is disclosed comprising: associating, by a device in a service mesh, a security function with a portion of an online application that is executed in a distributed manner across the service mesh; executing, by the device, the security function and the portion of the online application within a trusted execution environment of the device to produce output data; generating, by the device, a cryptographic proof for the output data based on the security function; and providing, by the device, the output data and the cryptographic proof to a remote execution environment within the service mesh to establish a verifiable data lineage for the output data.

Claims (35)

1 . A method, comprising:

associating, by a device in a service mesh, a security function with a portion of an online application that is executed in a distributed manner across the service mesh;

executing, by the device, the security function and the portion of the online application within a trusted execution environment of the device to produce output data;

generating, by the device and based on the security function, a cryptographic proof for the output data comprising a remote attestation that a security policy defined for the portion of the online application was applied during an execution that produced the output data within the trusted execution environment; and

providing, by the device, the output data and the cryptographic proof to a remote execution environment within the service mesh to establish a verifiable data lineage for the output data.

2 . The method of claim 1 , wherein executing the portion of the online application includes hosting a runtime environment for an application programming interface (API) server associated with the portion of the online application.

3 . The method of claim 1 , wherein the security function is associated with secure communications of a packet across a network.

4 . The method of claim 1 , wherein the security function is associated with secure file system access operations.

5 . The method of claim 1 , wherein the remote execution environment comprises a microservice node in the service mesh.

6 . The method of claim 1 , wherein the remote execution environment is a trusted execution environment.

7 . The method of claim 1 , wherein the remote execution environment is not a trusted execution environment.

8 . The method of claim 1 , wherein the portion of the online application is a trusted version that is pre-installed within the trusted execution environment.

9 . The method of claim 1 , wherein the portion of the online application is dynamically uploaded to the trusted execution environment on an as-needed basis.

10 . The method of claim 1 , wherein the trusted execution environment utilizes a hardware-based encryption to protect data integrity during execution of the portion of the online application.

11 . The method of claim 1 , wherein providing the cryptographic proof to the remote execution environment includes providing the cryptographic proof in a chain with prior cryptographic proofs.

12 . A tangible, non-transitory, computer-readable medium having computer-executable instructions stored thereon that, when executed by a processor on a computer, cause the computer to perform a method comprising:

associating, in a service mesh, a security function with a portion of an online application that is executed in a distributed manner across the service mesh;

executing the security function and the portion of the online application within a trusted execution environment of a device to produce output data;

generating, based on the security function, a cryptographic proof for the output data comprising a remote attestation that a security policy defined for the portion of the online application was applied during an execution that produced the output data within the trusted execution environment; and

providing the output data and the cryptographic proof to a remote execution environment within the service mesh to establish a verifiable data lineage for the output data.

13 . The tangible, non-transitory, computer-readable medium as in claim 12 , wherein executing the portion of the online application includes hosting a runtime environment for an application programming interface (API) server associated with the portion of the online application.

14 . The tangible, non-transitory, computer-readable medium as in claim 12 , wherein the security function is associated with secure communications of a packet across a network.

15 . The tangible, non-transitory, computer-readable medium as in claim 12 , wherein the remote execution environment comprises a microservice node in the service mesh.

16 . The tangible, non-transitory, computer-readable medium as in claim 12 , wherein the cryptographic proof includes an attestation that a security policy defined for the portion of the online application is applied to its execution within the trusted execution environment.

17 . The tangible, non-transitory, computer-readable medium as in claim 12 , wherein the remote execution environment in a trusted execution environment.

18 . The tangible, non-transitory, computer-readable medium as in claim 12 , wherein the remote execution environment is not a trusted execution environment.

19 . The tangible, non-transitory, computer-readable medium as in claim 12 , wherein providing the cryptographic proof to the remote execution environment includes providing the cryptographic proof in a chain with prior cryptographic proofs.

20 . An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process, when executed, configured to:

associate, in a service mesh, a security function with a portion of an online application that is executed in a distributed manner across the service mesh;

execute the security function and the portion of the online application within a trusted execution environment of a device to produce output data;

generate, based on the security function, a cryptographic proof for the output data comprising a remote attestation that a security policy defined for the portion of the online application was applied during an execution that produced the output data within the trusted execution environment; and

provide the output data and the cryptographic proof to a remote execution environment within the service mesh to establish a verifiable data lineage for the output data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2023
From: FLEMING, CHARLES; KOMPELLA, RAMANA RAO V. R.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 065280/0834 →
Continuity (1)
Related Publication 20250132918A1 · Apr 24, 2025
References Cited (16)
US 20150381575A1 · Bhargav-Spantzel · 2015 [cited by examiner]
US 20180109538A1 · Kumar et al. · 2018 [cited by applicant]
US 20190188712A1 · Fedorov · 2019 [cited by examiner]
US 20200272737A1 · Ji · 2020 [cited by applicant]
US 20210019420A1 · Regupathy · 2021 [cited by examiner]
US 20220058268A1 · Thom · 2022 [cited by examiner]
US 20220129542A1 · Sun et al. · 2022 [cited by applicant]
US 20220329573A1 · Sood et al. · 2022 [cited by applicant]
US 20230036165A1 · Bursell · 2023 [cited by examiner]
US 20230394150A1 · Schmatz · 2023 [cited by examiner]
US 20240220639A1 · Sahu · 2024 [cited by examiner]
US 20240241960A1 · King · 2024 [cited by examiner]
US 20240291650A1 · Cela · 2024 [cited by examiner]
US 20240427908A1 · Huo · 2024 [cited by examiner]
Adam et al. Partially Trusting the Service Mesh Control Plane Oct. 23, 2022 arXiv:2210.12610 (Year: 2022). [cited by examiner]
Hashicorp Developer: “Secure Applications with Service Sidecar Proxies”, online: https://developer.hashicorp.com/consul/tutorials/kubernetes/service-mesh-application-secure-networking, accessed Nov. 17, 2023, 13 Pages. [cited by applicant]