IP Library Granted Patent US 11,553,039
Granted Patent B2
US 11,553,039 · App. 17/653,695 · Granted Jan 10, 2023

Service meshes and smart contracts for zero-trust systems

Inventors: Vijay Madisetti (Johns Creek, GA); Arshdeep Bahga (Chandigarh, IN)
H04L67/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,553,039
App. No.
17/653,695
Granted
Jan 10, 2023
Kind
B2
Abstract

A blockchain-enabled cloud-based service mesh environment including a network service mesh network that includes network service domains that communicate with each other and an application service mesh network positioned in communication with the network service mesh network, the application service mesh network including applications that communicate with each other and a network service domain. A plurality of smart contracts record information including resource assignment and consumption information from the network service mesh network and the application service mesh network are recorded to a blockchain network.

Claims (57)

1. A blockchain-enabled cloud-based service mesh environment comprising:

a network service mesh network comprising a plurality of network service domains configured to communicate with each other; and

an application service mesh network positioned in communication with the network service mesh network, the application service mesh network comprising a plurality of applications configured to communicate with each other and a network service domain of the plurality of network service domains;

wherein a plurality of smart contracts record information comprising resource assignment and consumption information from the network service mesh network and the application service mesh network are recorded to a blockchain network.

2. The environment of claim 1 wherein each network service domain comprises:

a plurality of network service endpoints configured to communicate with a network service client; and

a network service manager configured to broadcast the availability of the plurality of network service endpoints to network service clients.

3. The environment of claim 1 wherein the network service mesh network further comprises:

a global variable name system comprising a plurality of registered global variables; and

a bulletin board server configured to update information about the plurality of registered global variables responsive to messages received from the plurality of applications by the bulletin board server;

wherein the plurality of smart contracts comprises registered global variables; and

wherein the plurality of smart contracts is configured to be updated responsive to changes in registered global variables comprised thereby.

4. The environment of claim 3 wherein:

the bulletin board server comprises a plurality of topics, each topic comprising a registered global variable; and

the topics of the plurality of topics are configured to be subscribed to by the plurality of applications, such that information regarding updates to the registered global variable comprised by the topic is sent to applications that subscribe to the topic.

5. The environment of claim 4 wherein:

malicious traffic coming from an application is identified by comparing traffic coming therefrom to a smart contract associated with an application; and

the bulletin board server is configured to perform a mitigation action responsive to the malicious traffic.

6. The environment of claim 5 wherein the mitigation action comprises at least one of advertising the malicious traffic through the global variable name system, isolating the affected application, and migrating tasks to be performed by the application to another application of the plurality of applications.

7. The environment of claim 1 wherein:

a first plurality of smart contracts record information comprising a first set of resource assignment and consumption information from the network service mesh network is recorded to a first blockchain network; and

a second plurality of smart contracts record information comprising a second set of resource assignment and consumption information from the application service mesh network is recorded to a second blockchain network.

8. The environment of claim 7 further comprising:

a global variable name system comprising a plurality of registered global variables; and

a bulletin board server configured to update information about the plurality of registered global variables responsive to messages received from users by the bulletin board server;

wherein the first and second pluralities of smart contracts comprise registered global variables; and

wherein the first and second pluralities of smart contracts are configured to be updated responsive to changes in registered global variables comprised thereby.

9. The environment of claim 1 wherein the plurality of applications comprises at least one of a containerized network function, a virtual network function, a worker node, a server, a container, a pod, and a virtual machine.

10. The environment of claim 9 wherein at least a subset of the plurality of network service domains are managed by a Kubernetes installation.

11. The environment of claim 1 is based on containers.

12. The environment of claim 1 wherein the resource assignment and consumption information is monitored for performance constraint checks.

13. The environment of claim 1 wherein the resource assignment and consumption information is monitored for security constraint checks.

14. The environment of claim 1 wherein the resource assignment and consumption information comprises network slicing information.

15. A blockchain-enabled cloud-based service mesh environment comprising:

a network service mesh network comprising:

a plurality of network service domains configured to communicate with each other;

a global variable name system comprising a plurality of registered global variables; and

a bulletin board server; and

an application service mesh network positioned in communication with the network service mesh network, the application service mesh network comprising a plurality of applications configured to communicate with each other and a network service domain of the plurality of network service domains;

wherein the bulletin board server is configured to update information about the plurality of registered global variables responsive to messages received from the plurality of applications by the bulletin board server;

wherein the plurality of applications comprises at least one of a containerized network function, a virtual network function, a worker node, a server, a container, a pod, and a virtual machine;

wherein a plurality of smart contracts record information comprising resource assignment and consumption information from the network service mesh network and the application service mesh network and a registered global variable are recorded to a blockchain network; and

wherein the plurality of smart contracts is configured to be updated responsive to changes in registered global variables comprised thereby.

16. The environment of claim 15 wherein the cloud-based environment is based on containers.

17. The environment of claim 15 wherein the resource assignment and consumption information is monitored for performance constraint checks.

18. The environment of claim 15 wherein the resource assignment and consumption information is monitored for security constraint checks.

19. The environment of claim 15 wherein the resource assignment and consumption information comprises network slicing information.

20. A blockchain-enabled cloud-based service mesh environment based on containers, comprising:

a network service mesh network comprising:

a plurality of network service domains configured to communicate with each other;

a global variable name system comprising a plurality of registered global variables; and

a bulletin board server; and

an application service mesh network positioned in communication with the network service mesh network, the application service mesh network comprising a plurality of applications configured to communicate with each other and a network service domain of the plurality of network service domains;

wherein the plurality of applications comprises at least one of a containerized network function, a virtual network function, a worker node, a server, a container, a pod, and a virtual machine;

wherein at least a subset of the plurality of network service domains are managed by a Kubernetes installation;

wherein the resource assignment and consumption information is monitored for at least one of performance constraint checks and security constraint checks; and

wherein a plurality of smart contracts record information comprises network slicing information comprising network slicing information from the network service mesh network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2026
From: MADISETTI, VIJAY
To: VM INNOVATIONS I, LLC
Reel/Frame 075116/0289 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2022
From: BAHGA, ARSHDEEP
To: MADISETTI, VIJAY
Reel/Frame 059630/0108 →
Continuity (10)
Continuation 17302552 · May 6, 2021
Continuation In Part 16286932 · Feb 27, 2019
Continuation In Part 16127283 · Sep 11, 2018
Provisional Application 63175069 · Apr 15, 2021
Provisional Application 63172743 · Apr 9, 2021
Provisional Application 63166301 · Mar 26, 2021
Provisional Application 63080051 · Sep 18, 2020
Provisional Application 62618784 · Jan 18, 2018
Provisional Application 62557820 · Sep 13, 2017
Related Publication 20220191272A1 · Jun 16, 2022