Container Base Image Segmentation for Rapid Security Patching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud customers face inefficiencies and delays in patching non-product components, leading to slow security patching processes and potential service level agreement violations due to the need for organizations to package and update entire operating systems, Java, and application server software together.
Innovation Solution
The method involves building a new base application image in response to security vulnerabilities, updating a Helm chart, and deploying the new base application image to product containers, allowing for the separate patching of third-party components like the Tomcat image without requiring full product image updates, enabling rapid delivery of security patches and self-patch capabilities for customers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations package the operating system, Java, application server software, and product library together, then they can provide comprehensive security patches, but the patching process becomes slow and inefficient requiring multiple weeks for delivery
Solution Approach 1:
The patent segments the monolithic package into separate components: base application images containing only third-party components (OS, Java, application server) and product-specific components. This allows independent patching of security vulnerabilities in base images without requiring full repackaging, reducing patch delivery time from weeks to days while maintaining comprehensive security coverage.
Solution Approach 2:
The patent extracts third-party components into separate base application images that can be independently built, tested, and deployed. This extraction enables the organization to patch security vulnerabilities in the base image separately from product updates, eliminating the need to wait for complete package reconstruction and significantly accelerating the patching process.
2Reliability
If organizations wait for complete package updates including non-product components, then they ensure comprehensive security coverage, but service level agreements may be violated due to delays
Solution Approach 1:
By segmenting the application package into base images and product components, the patent enables parallel development and deployment of security patches. Base image patches can be delivered independently and applied across multiple products simultaneously, ensuring comprehensive security coverage while dramatically improving delivery speed and preventing SLA violations.
Solution Approach 2:
The patent implements preliminary action by pre-building and pre-testing base application images with security patches before they are needed. The base image segmentation allows security patches to be prepared in advance and independently validated, so when a vulnerability is discovered, pre-patched base images can be rapidly deployed without waiting for complete package reconstruction, ensuring both security coverage and timely delivery.
3Adaptability or versatility
If customers cannot patch non-product components independently, then organizations maintain centralized control, but the patching process becomes inefficient and requires considerable time across different products and cloud release versions
Solution Approach 1:
The patent segments the system into customer-controlled base application images and organization-controlled product components. This segmentation allows customers to independently manage and patch their own base images containing non-product components, while the organization maintains control over product-specific updates. This resolves the contradiction by enabling both centralized control where needed and independent customer patching for non-product components, dramatically improving patching efficiency across different products and cloud versions.
Data Source
AI summary
A system and method enables improved container security patching in a container orchestration cloud environment. The systems and methods provide several advantages over traditional methods, for example, by enabling the release of only one hardened base image for multiple products. In some embodiments, upon the reporting of a vulnerability, the systems and methods bifurcates a third party image (a base image) from a product image. Therefore, when a vulnerability occurs in the base image, an organization can ship only the base container image, rather than the product image, which avoids the development and testing processes that would otherwise be required.

