IP Library › Granted Patent US 12,579,301
Granted Patent B2
US 12,579,301 · App. 18/199,321 · Granted Mar 17, 2026

Data plane management systems and methods

Inventors: Maxwell Bruce (Reno, NV); Issac Roth (San Francisco, CA); Wesley Hales (Woodstock, CA)
Assignee: F5, Inc.
G06F21/6245H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,301
App. No.
18/199,321
Granted
Mar 17, 2026
Kind
B2
Abstract

Systems and methods for data plane management are disclosed herein. An example method includes deploying a WASM that is embedded in a service routing layer of the service mesh, assigning a security policy to the WASM from a bootstrapping layer of the service mesh, the security policy enabling the WASM to detect patterns in the service mesh data that are indicative of sensitive information, evaluating service mesh data by the WASM with the security policy, and transmitting telemetry to a cloud-based command module when the WASM has detected patterns in the service mesh data.

Claims (41)

1 . A method for data plane management, the method comprising:

deploying, in a service mesh, a WebAssembly (WASM) that is embedded in a service routing layer of the service mesh;

assigning a security policy to the WASM from a bootstrapping layer of the service mesh, the security policy enabling the WASM to detect patterns in service mesh data that are indicative of sensitive information;

receiving, from the WASM, telemetry comprising an indication that the service mesh data possesses the patterns indicative of the sensitive information;

evaluating the service mesh data by the WASM with the security policy; and

transmitting the telemetry to a cloud-based command module when the WASM has detected the patterns in the service mesh data.

2 . The method according to claim 1 , further comprising monitoring the service mesh data between a first microservice and a second microservice.

3 . The method according to claim 2 , further comprising:

mapping service interactions between the first microservice and the second microservice; and

annotating the service interactions with tracing that is indicative of sensitive data.

4 . The method according to claim 1 , wherein deploying comprises distributing the WASM to a virtual machine or container of each microservice or sidecar in the service mesh.

5 . The method according to claim 4 , wherein the WASM is approximately two to four megabytes in size.

6 . The method according to claim 1 , further comprising:

verifying an existence of the sensitive information in the service mesh data by the cloud-based command module.

7 . The method according to claim 6 , further comprising rate limiting a set of traffic moving through a sidecar, based on the verifying.

8 . The method according to claim 6 , further comprising generating, by the cloud-based command module, a dashboard that includes information pertaining to the service mesh data that comprises the sensitive information.

9 . The method according to claim 6 , further comprising redacting the sensitive information from the service mesh data.

10 . The method according to claim 9 , further comprising:

replacing the sensitive information with a string of characters that does not include the sensitive information.

11 . A system, comprising:

a WebAssembly (WASM) deployed in each WASM compatible node of a service mesh, the WASM being installed on a sidecar of the each WASM compatible node and being configured to apply a security policy that is used to search raw data for patterns that are indicative of sensitive data;

a memory comprising instructions stored thereon;

a processor configured of executing the stored instructions to:

assign, using a command module, the security policy to the WASM;

receive, using the command module, telemetry data from the WASM, the telemetry data comprising an indication that the raw data possesses patterns that are indicative of sensitive data; and

verify, using the command module, that the raw data includes the sensitive data; and

a data lake scanner that is configured to evaluate stored data of the service mesh for sensitive information.

12 . The system according to claim 11 , wherein the security policy is disseminated by a random WASM of the service mesh.

13 . The system according to claim 11 , wherein the command module is configured to:

map service interactions between two or more WASM compatible nodes of the service mesh;

annotate the service interactions with tracing that is indicative of the sensitive data; and

provide the annotated service interactions on a dashboard.

14 . The system according to claim 11 , wherein a random WASM is configured to:

distribute the security policy when the security policy is received from the command module.

15 . The system according to claim 11 , wherein the WASM is approximately two to four megabytes in size.

16 . The system according to claim 11 , wherein the command module is configured to:

case a WASM to rate limit the each WASM compatible node based on the verifying.

17 . The system according to claim 11 , wherein the command module is configured to generate a dashboard that includes information pertaining to the service mesh data that comprises the sensitive information.

18 . The system according to claim 11 , wherein the command module is configured to redact the sensitive information from the service mesh data.

19 . The system according to claim 18 , wherein the command module is configured to:

replace the sensitive information with a string of characters that does not include the sensitive information.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2025
From: LEAKSIGNAL, INC.
To: F5, INC.
Reel/Frame 070884/0890 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2023
From: BRUCE, MAXWELL; ROTH, ISSAC; HALES, WESLEY
To: LEAKSIGNAL INC
Reel/Frame 063697/0653 →
Continuity (1)
Related Publication 20240386130A1 · Nov 21, 2024
References Cited (9)
US 20210334384A1 · Ranjan · 2021 [cited by examiner]
US 20210383014A1 · Yang · 2021 [cited by examiner]
US 20220156369A1 · Narayanaswamy · 2022 [cited by examiner]
US 20240134725A1 · Bosch · 2024 [cited by examiner]
US 20240364720A1 · Golway · 2024 [cited by examiner]
Huyen, Chip, “Buidling a Generative AI Platform,” hyuenchip.com; Jul. 25, 2024, 30 pages. [cited by applicant]
Spires et al., “Built with Fastly Spotlight: LeakSignal stops GenAI data leaks”, available online: <URL:https://www.fastly.com/blog/built-with-fastly-spotlight-leaksignal-stops-genai-data-leaks/>, accessed Aug. 2, 2024,… [cited by applicant]
EP Extended Search Report issued in EP Application No. 25193190.3, mailed on Aug. 8, 2025, 9 pp. [cited by applicant]
Grant, Dasher et al: “Architectures for Protecting Cloud Data Planes”, arxiv. org, Cornell University Library, 201 Olin Library Cornell University Ithica, NY 14853, Jan. 31, 2022, XP091141327, 43 pp. [cited by applicant]