IP Library › Patent Application 18819954
Patent Application
App. No. 18/819,954

Data Plane Management Systems and Methods Using Native Modules

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/819,954
Abstract

Systems and methods for data plane management are disclosed herein. An example method includes deploying a native module that is embedded in a service routing layer of the service mesh, assigning a security policy to the native module from a bootstrapping layer of the service mesh, the security policy enabling the native module to detect patterns in the service mesh data that are indicative of sensitive information, evaluating service mesh data by the native module with the security policy, and transmitting telemetry to a cloud-based command module when the native module has detected patterns in the service mesh data.

Claims (36)

1 . A method for data plane management, the method comprising:

deploying, in a service mesh, a native module comprising natively compiled code, the native module being embedded in a service routing layer of the service mesh;

assigning a security policy to the native module from a bootstrapping layer of the service mesh, the security policy enabling the native module to detect patterns in service mesh data that are indicative of sensitive information;

evaluating service mesh data by the native module with the security policy; and

transmitting telemetry to a cloud-based command module when the native module has detected patterns in the service mesh data.

2 . The method according to claim 1 , further comprising monitoring the service mesh data between a first microservice and a second microservice.

3 . The method according to claim 2 , further comprising:

mapping service interactions between the first microservice and the second microservice; and

annotating the service interactions with tracing that is indicative of sensitive data.

4 . The method according to claim 1 , wherein deploying comprises distributing the native module to a virtual machine or container of each microservice or sidecar in the service mesh.

5 . The method of claim 1 , wherein the native module is an input guardrail for an artificial intelligence application.

6 . The method of claim 1 , wherein the native module is an output guardrail for an artificial intelligence application.

7 . The method according to claim 1 , further comprising verifying an existence of sensitive information the service mesh data by the cloud-based command module.

8 . The method according to claim 7 , further comprising rate limiting a set of traffic moving through a sidecar, based on the verifying.

9 . The method according to claim 7 , further comprising generating, by the cloud-based command module, a dashboard that includes information pertaining to the service mesh data that comprises the sensitive information.

10 . The method according to claim 7 , further comprising redacting the sensitive information from the service mesh data.

11 . The method according to claim 10 , further comprising replacing the sensitive information with a string of characters that does not include sensitive information.

12 . A system, comprising:

a native module comprising natively compiled code, the native module deployed in each compatible node of a service mesh, the native module being installed on a sidecar of the compatible node and being configured to apply a security policy that is used to search raw data for patterns that are indicative of sensitive data;

a command module that:

assigns the security policy to the native module;

receives telemetry data from the native module, the telemetry data comprising an indication that the raw data possesses patterns that are indicative of sensitive data; and

verify that the raw data includes the sensitive data; and

a data lake scanner that is configured to evaluate stored data of the service mesh for sensitive information.

13 . The system according to claim 12 , wherein the security policy is disseminated by a random native module of the service mesh.

14 . The system according to claim 12 , wherein the command module is configured to:

map service interactions between two or more compatible nodes of the service mesh;

annotate the service interactions with tracing that is indicative of sensitive data; and

provide the annotated service interactions on a dashboard.

15 . The system according to claim 12 , wherein a random native module is configured to distribute the security policy when received from the command module.

16 . The system according to claim 12 , wherein the native module is an input guardrail for an artificial intelligence application.

17 . The system according to claim 12 , wherein the native module is an output guardrail for an artificial intelligence application.

18 . The system according to claim 12 , wherein the command module is configured to case a native module to rate limit the compatible node based on the verifying.

19 . The system according to claim 12 , wherein the command module is configured to generate a dashboard that includes information pertaining to the service mesh data that comprises the sensitive information.

20 . The system according to claim 12 , wherein the command module is configured to redact the sensitive information from the service mesh data.

21 . The system according to claim 20 , wherein the command module is configured to replace the sensitive information with a string of characters that does not include sensitive information.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2025
From: LEAKSIGNAL, INC.
To: F5, INC.
Reel/Frame 070884/0890 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2024
From: BRUCE, MAXWELL; ROTH, ISSAC; HALES, WESLEY
To: LEAKSIGNAL INC.
Reel/Frame 068485/0762 →