Compliance-Aware Runtime Container Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing containerization technologies lack compliance-awareness, leading to potential security and compliance violations, and require an underlying operating system, which increases complexity and vulnerability.

Innovation Solution

A system comprising a processor, memory, and components like a collection component, risk assessment component, compliance component, and construction component that identifies and assesses risks, determines compliance, and generates compliance-aware runtime containers allowing applications to execute without an underlying operating system, reducing vulnerability and complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing containerization technologies are used, then applications can be containerized, but compliance and security violations may occur due to lack of compliance-awareness

Engineering Contradiction:
Improvecompliance and security assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing compliance and security assessments during the container build phase before the container is deployed. The compliance component evaluates the container image against predefined compliance rules and security policies in advance, identifying and flagging potential violations before they can cause issues in production. This proactive approach ensures compliance assurance without adding complexity to the runtime execution environment.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If an underlying operating system is included in the container, then the application can execute, but the attack surface increases and complexity increases

Engineering Contradiction:
Improveapplication execution capabilityVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies the extraction principle by removing the underlying operating system from the container image, keeping only the minimal necessary components for application execution. The container is designed to run without a full OS, extracting out the harmful attack surface associated with OS-level vulnerabilities while preserving the essential functionality needed for the application to execute. This creates a lighter, more secure container image that maintains operational capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If an underlying operating system is included in the container, then the application can execute, but compliance costs increase

Engineering Contradiction:
Improveapplication execution capabilityVSAvoidcompliance costs
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent applies extraction by removing the operating system layer that generates compliance overhead, retaining only the essential runtime components. This reduction in container complexity directly lowers compliance costs by eliminating the need to audit and manage OS-level configurations, patches, and security policies, while still providing sufficient functionality for application execution.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If runtime compliance assessment is performed, then compliance violations can be detected, but processing time increases

Engineering Contradiction:
Improvecompliance detection accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing comprehensive compliance assessments during the container build and image creation phase, rather than during runtime deployment. The compliance component evaluates the container image against all predefined rules and policies in advance, caching the compliance status. This allows rapid runtime deployment without repeating the time-consuming assessment process, thereby maintaining high compliance detection accuracy while minimizing processing time delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10803177B2Compliance-aware runtime generation based on application patterns and risk assessment
Publication Date: 2020.10.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10803177B2 patent drawing
  • US10803177B2 patent drawing
  • US10803177B2 patent drawing

AI summary

Systems, computer-implemented methods and/or computer program products that facilitate compliance-aware runtime generation of containers are provided. In one embodiment, a computer-implemented method comprises: identifying, by a system operatively coupled to a processor, information used by a target application to containerize; determining whether one or more risk violations exist for the information within one or more defined thresholds; determining whether a compliance or a security violation exists in the information, wherein the determining whether the compliance or security violation exists is performed based on a determination by the risk assessment component that one or more risk violations do not exist; and generating a new container of components corresponding to defined components of the target application that allow the target application to execute without an underlying operating system, wherein the generating is based on a determination that no compliance or security violation exists in the information.