Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

3 results about "Admission controller" patented technology

Resource deployment management method and system

PendingCN121541975ASoftware simulation/interpretation/emulationAdmission controllerVerification
The invention discloses a resource deployment management method and system, and the method comprises the steps: obtaining a resource deployment request submitted by a user, and the resource deployment request comprises configuration data; calling an access controller to perform global verification on the resource deployment request; if the resource deployment request passes the global verification, generating a deployment instruction based on the configuration data; a deployment instruction is sent to the resource deployment platform, so that the resource deployment platform deploys a corresponding operation unit, and the operation unit is injected into the auxiliary container meeting the requirement condition of the configuration data. According to the scheme, all the resource deployment requests are uniformly managed through the access controller, the corresponding deployment instructions can be generated for deployment only after the resource deployment requests pass the global verification, and compared with a traditional scheme, the number of access control assemblies in the system is remarkably reduced, and the resource deployment efficiency is improved. And meanwhile, the global verification can avoid the problem of resource deployment conflict possibly caused by separate realization of different functions in the traditional scheme.
Owner:BEIJING QIYI CENTURY SCI & TECH CO LTD

An isolation and security system for use in multi-tenant container orchestration

PCT designated stageWO2026147379A1Data integrityEngineering
The invention relates to an isolation and security system running on a server for use in multi-tenant container orchestration. The system of the invention aims to improve security and efficiency by providing isolated network, storage, and control plane environments for each tenant on multi-tenant container orchestration platforms. In this context, network isolation is achieved by using tenant-specific network overlay protocols, unique VXLAN Network Identifier (VNI), distributed routing mechanisms and network policy engine. Complete storage isolation and performance continuity are ensured through separate storage pools, encryption keys, and a storage QoS manager, for each tenant. Control plane isolation is supported by tenant-specific schedulers, admission controllers, and API endpoints, thus, an independent and secure management is offered. Tenant management processes are made efficient with automatic onboarding, dynamic resource allocation, and isolation verifier, and security is guaranteed. Isolated monitoring and log management are carried out with metric aggregators, log managers and anomaly detection engines, and the data integrity and security are guaranteed throughout the system in line with the principle of zero trust architecture.
Owner:BTS KURUMSAL BİLİŞİM TEKNOLOJİLERİ ANONİM ŞİRKETİ

Techniques for contextually applying a security policy on a software container

A system and method for applying a cybersecurity contextual policy in a computing environment are disclosed. In an embodiment, the method includes: detecting a cybersecurity object on a virtualization, the virtualization deployed in a computing environment; detecting a policy of the computing environment, the policy including a conditional rule; generating a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and configuring an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.
Owner:WIZ INC