Container Security Policy Inclusion with Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management and security of containers in microservices architecture, particularly during massive deployments, are challenging due to their distributed and decoupled nature, requiring effective security measures that are agnostic to underlying infrastructure.

Innovation Solution

Integrating security information into containers, building service-specific security images with read-only security contracts, and deploying these containers into groups with a security helper process that enforces security policies, ensuring secure communication and preventing unauthorized portability or theft.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If containers are deployed in a distributed and decoupled manner to achieve portability and flexibility, then container deployment speed and adaptability are improved, but security management complexity and difficulty increase

Engineering Contradiction:
Improvecontainer portabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security manager that centralizes security management across all containers. This security manager provides multi-functional capabilities including policy enforcement, credential management, and security monitoring for diverse container types and deployment scenarios, thereby simplifying security management while maintaining container portability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a security manager as an intermediary component between containers and the underlying infrastructure. This mediator handles security policies, credentials, and access control, shielding individual containers from security management complexity while enabling secure communication and operations across the distributed container environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies are enforced at the container level to maintain security compliance, then security reliability is improved, but deployment time and operational overhead increase

Engineering Contradiction:
Improvesecurity complianceVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring security policies and credentials within container images during the build process. Security contexts, access control lists, and cryptographic materials are embedded in advance, allowing containers to be deployed immediately with security enforcement already in place, eliminating post-deployment security configuration delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service security enforcement where containers automatically apply their own security policies and manage their credentials through the security manager. Containers self-register, self-configure security contexts, and self-enforce access control rules, reducing operational overhead and accelerating deployment while maintaining security compliance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10554690B2Security policy inclusion with container deployment
Publication Date: 2020.02.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10554690B2 patent drawing
  • US10554690B2 patent drawing
  • US10554690B2 patent drawing

AI summary

An approach is provided in which an information handling system creates a container that includes security information. The information handling system deploys the container to a container group and, in turn, performs a security-related action based on the security information.