IP Library › Granted Patent US 12,381,852
Granted Patent B2
US 12,381,852 · App. 18/160,683 · Granted Aug 5, 2025

Providing dynamic network security based on importance of proprietary content

Inventors: Binoy Thomas (Kozhikode, IN); Sudheesh S. Kairali (Kozhikode, IN); Malarvizhi Kandasamy (Bangalore, IN); Sarbajit K. Rakshit (Kolkata, IN)
Assignee: International Business Machines Corporation
H04L63/0414H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,852
App. No.
18/160,683
Granted
Aug 5, 2025
Kind
B2
Abstract

A method, computer system, and a computer program product are provided for establishing security measures for a content. In one embodiment, the method comprises identifying at least a microservice chain in a network computer. Each microservice chain has more than one microservice linked to one another and each microservice includes a plurality of applications bundled together. Any use profiles associated with the microservice chain are identified and all data entry points into each microservice are determined. Each microservice is analyzed to predict when each microservice in the chain will provide a confidential output. Once any microservice chain is deemed to be providing a confidential output, any predicted exits in the microservice deemed to be generating an output content are upgraded so that all predicted exists provide a confidential output.

Claims (35)

1. A method for establishing security measures for a content, comprising:

identifying a plurality of microservice chains at in a network computer, wherein each microservice chain has at least two linked microservices and each of the at least two linked microservices includes a plurality of bundled applications;

identifying said plurality of microservice chains in said network per user profile and per data entry input points, wherein at least a user and any profiles for said user associated with the at least one microservice chain and determining any data entry points into each of the at least one microservice chain;

analyzing each of the at least two linked microservices to predict when each of the at least two linked microservices in the at least one microservice chain will provide a confidential output;

once any microservice in the at least one microservice chain is deemed to be providing the confidential output, upgrade any predicted exits in the at least one microservice chain deemed to be generating an output content so that all said predicted exits provide the confidential output.

2. The method of claim 1 , wherein said analysis includes checking data dimensions of any possible input and any user profile prior history to determine a data flow in said microservice chain.

3. The method of claim 1 , wherein security measures between any of at least two linked services will be upgraded to confidential when at least one of the at least two linked services are deemed to be producing a confidential outcome.

4. The method of claim 3 , wherein the at least one microservice chain is modified to add or remove a service, and wherein said service is dynamically upgraded to reflect whether each of its microservices are to provide said confidential outcome.

5. The method of claim 1 , wherein data security measures include a plurality of different security levels beside a confidential and a non-nonconfidential level and the at least one microservice chain will upgrade any of said services to a highest level identified amongst the at least one microservice chain.

6. The method of claim 1 , wherein a plurality of microservice chains are associated to more than one user.

7. The method of claim 1 , further comprising determining confidentiality level of input and output data of each of the at least two linked microservices.

8. A computer system for providing a security measures for a content,

comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is enabled to perform the steps:

identifying a plurality of microservice chains at in a network computer, wherein each microservice chain has at least two linked microservices and each of the at least two linked microservices includes a plurality of bundled applications;

identifying said plurality of microservice chains in said network per user profile and per data entry input points, wherein at least a user and any profiles for said user associated with the at least one microservice chain and determining any data entry points into each of the at least one microservice chain;

analyzing each of the at least two linked microservices to predict when each of the at least two linked microservices in the at least one microservice chain will provide a confidential output;

once any microservice in the at least one microservice chain is deemed to be providing the confidential output, upgrade any predicted exits in the at least one microservice chain deemed to be generating an output content so that all said predicted exits provide the confidential output.

9. The computer system of claim 8 , wherein said analysis includes checking data dimensions of any possible input and any user profile prior history to determine a data flow in said microservice chain.

10. The computer system of claim 8 , wherein security measures between any of at least two linked services will be upgraded to confidential when at least one of the at least two linked services are deemed to be producing a confidential outcome.

11. The computer system of claim 10 , wherein the at least one microservice chain is modified to add or remove a service, and wherein said service is dynamically upgraded to reflect whether each of its microservices are to provide said confidential outcome.

12. The computer system of claim 8 , wherein data security measures include a plurality of different security levels beside a confidential and a non-nonconfidential level and the at least one microservice chain will upgrade any of said services to a highest level identified amongst the at least one microservice chain.

13. The computer system of claim 8 , wherein a plurality of microservice chains are associated to more than one user.

14. The computer system of claim 8 , further comprising determining confidentiality level of input and output data of each of the at least two linked microservices.

15. A computer program product for providing security measures for a content, comprising:

one or more computer-readable storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor, the program instructions comprising:

identifying a plurality of microservice chains at in a network computer, wherein each microservice chain has at least two linked microservices and each of the at least two linked microservices includes a plurality of bundled applications;

identifying said plurality of microservice chains in said network per user profile and per data entry input points, wherein at least a user and any profiles for said user associated with the at least one microservice chain and determining any data entry points into each of the at least one microservice chain;

analyzing each of the at least two linked microservices to predict when each of the at least two linked microservices in the at least one microservice chain will provide a confidential output;

once any microservice in the at least one microservice chain is deemed to be providing the confidential output, upgrade any predicted exits in the at least one microservice chain deemed to be generating an output content so that all said predicted exits provide the confidential output.

16. The computer program product of claim 15 , wherein said analysis includes checking data dimensions of any possible input and any user profile prior history to determine a data flow in said microservice chain.

17. The computer program product of claim 15 , wherein security measures between any of at least two linked services will be upgraded to confidential when at least one of the at least two linked services are deemed to be producing a confidential outcome.

18. The computer program product of claim 15 , wherein the at least one microservice chain is modified to add or remove a service, and wherein said service is dynamically upgraded to reflect whether each of its microservices are to provide a confidential outcome.

19. The computer program product of claim 18 , wherein data security measures include a plurality of different security levels beside a confidential and a non-nonconfidential level and the at least one microservice chain will upgrade any of said services to a highest level identified amongst the at least one microservice chain.

20. The computer program product of claim 19 , further comprising determining confidentiality level of input and output data of each of the at least two linked microservices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2023
From: THOMAS, BINOY; KAIRALI, SUDHEESH S.; KANDASAMY, MALARVIZHI; RAKSHIT, SARBAJIT K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062514/0476 →
Continuity (1)
Related Publication 20240259351A1 · Aug 1, 2024
References Cited (18)
US 10999312B2 · Indira · 2021 [cited by applicant]
US 11012520B2 · Gunjal · 2021 [cited by applicant]
US 11057393B2 · Coffing · 2021 [cited by examiner]
US 11134059B2 · Barton · 2021 [cited by applicant]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20190207954A1 · Ahuja · 2019 [cited by applicant]
US 20210392477A1 · Taft · 2021 [cited by applicant]
US 20220050897A1 · Gaddam · 2022 [cited by examiner]
US 20240259351A1 · Thomas · 2024 [cited by examiner]
CN 112671861A · 2021 [cited by applicant]
WO 2022103681A1 · 2022 [cited by applicant]
C. Gerking and D. Schubert, “Component-Based Refinement and Verification of Information-Flow Security Policies for Cyber-Physical Microservice Architectures,” 2019 IEEE International Conference on Software Architecture … [cited by examiner]
Chandramouli, et al., “Attribute-based Access Control for Microservices-based Applications Using a Service Mesh”, NIST Special Publication 800-204B, Aug. 2021, 41 pgs., Retrieved from the Internet: <https://csrc.nist.ri… [cited by applicant]
IBM, “Service Mesh on Red Hat OpenShift on IBM Cloud”, IBM.com, Last Updated Sep. 22, 2022, 17 pgs., Retrieved from the Internet: <https://www.ibm.com/cloud/blog/service-mesh-on-red-hat-openshift>. [cited by applicant]
James, “Automated Data Classification Tools & Automation Software”, BoldonJames.com, [Jan. 4, 2023], 5 pgs., Retrieved from the Internet: <https://www.boldonjames.com/data-classification/automated-classification/>. [cited by applicant]
Machupalli, “Service Mesh on Red Hat OpenShift”, Jun. 2, 2020, 4 pgs., Retrieved from the Internet: <https://cloud.ibm.com/docs/solution-tutorials?topic=solution-tutorials-openshift-service-mesh>. [cited by applicant]
Nagendra, et al., “Coordinated Dataflow Protection for Ultra-High Bandwidth Science Networks”, ResearchGate, ACSAC '19, Dec. 9-13, 2019, San Juan, PR, USA, 17 pgs., <https://www.researchgate.net/publication/337457518>. [cited by applicant]
Sotnikov, “Data Classification: What It Is and How to Implement It”, Netwrix, [accessed Jan. 13, 2023], 25 pgs., Retrieved from the Internet: <https://blog.netwrix.com/2020/09/02/data-classification/>. [cited by applicant]