Container Orchestration Deployment with Pre-Install Vulnerability Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to prevent the deployment of container orchestration platforms on Information Handling Systems (IHSs) with known vulnerabilities, leading to potential security and functional issues.

Innovation Solution

Implement a remote access controller in IHSs that integrates a vulnerability management service within a container orchestration platform installer, which checks for known vulnerabilities in hardware components and blocks the deployment if vulnerabilities are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If administrators manually configure hardware and software components of servers throughout their lifetime, then the servers can be adapted to different customer requirements and updated with new functionality, but the servers become increasingly vulnerable to known security and functional vulnerabilities due to inconsistent configuration practices

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidvulnerability to known issues
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary vulnerability proofing by evaluating hardware component configurations against known vulnerability catalogs before allowing container orchestration platform installation. The remote access controller proactively checks if proposed configurations match vulnerable patterns identified in security advisories, preventing vulnerable deployments before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop where vulnerability information from security advisories and catalogs is continuously integrated into the deployment validation process. The remote access controller receives vulnerability data, updates its evaluation criteria, and uses this feedback to block or approve configurations, ensuring configurations are consistently validated against the latest known vulnerabilities.

Inventive Principle:
Principle #23Feedback

2Productivity

If servers are updated with new hardware and software configurations to meet changing customer needs, then the servers remain functional and adaptable, but the updates may introduce known vulnerabilities that administrators are unaware of

Engineering Contradiction:
Improveserver functionalityVSAvoidintroduction of vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Before applying hardware or software updates, the system evaluates the proposed configurations against vulnerability catalogs to identify potential issues. The remote access controller checks update configurations in advance, preventing updates that would introduce known vulnerabilities while allowing functional improvements to proceed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by blocking configurations that match vulnerable patterns identified in security advisories. Rather than allowing vulnerable updates to be applied and then detecting them later, the system proactively prevents the application of updates with known issues through configuration evaluation against vulnerability databases.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If administrators use differing protocols and procedures to configure servers, then customization and adaptation to specific policies are achieved, but inconsistency in configuration leads to increased vulnerability

Engineering Contradiction:
Improveconfiguration freedomVSAvoidconfiguration consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The remote access controller serves as an intermediary that mediates between administrator configuration actions and the actual system state. It enforces consistent vulnerability evaluation rules across all configuration operations, ensuring that regardless of which administrator performs the configuration or what protocol they use, the vulnerability assessment remains uniform and based on authoritative catalogs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of configuration validation by introducing automated vulnerability pattern matching. Instead of relying on administrator judgment or manual checking, the system transforms configuration validation into an automated process that compares configurations against structured vulnerability catalogs, ensuring consistent evaluation across all administrators and procedures.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If the system blocks deployment of container orchestration platforms with vulnerable configurations, then security and stability are improved, but the deployment process is delayed or prevented

Engineering Contradiction:
Improvedeployment securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs vulnerability evaluation as a preliminary action before deployment begins. By checking configurations against vulnerability catalogs in advance and providing feedback on issues, the system prevents vulnerable deployments from proceeding while allowing valid deployments to continue without interruption, minimizing overall deployment time delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12468817B2Vulnerability proofing container orchestration platform deployment
Publication Date: 2025.11.11 DELL PROD LP
  • US12468817B2 patent drawing
  • US12468817B2 patent drawing
  • US12468817B2 patent drawing

AI summary

Vulnerability proofing container orchestration platform deployment includes a remote access controller detecting a container orchestration platform installer comprising vulnerability management service instructions and executing the vulnerability management service instructions. This causes the remote controller to identify configurations for one or more of the hardware component(s) of the IHS in the container orchestration platform installer, access a plurality of catalogs specifying known vulnerabilities of hardware components and determine whether the hardware component configuration(s) in the container orchestration platform installer are identified as vulnerable in one or more of the catalogs. The remote controller blocks use of the container orchestration platform installer by the IHS until the hardware component configurations within the container orchestration platform installer are modified to include no configurations with vulnerabilities identified in the plurality of catalogs.