Cross-Tenancy Container Resource Association With Subnet Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing container orchestration systems face challenges in managing and securing the deployment and management of containerized applications across different environments, particularly in large-scale applications, and there is a need for improved security and isolation of network resources in cloud computing infrastructure.

Innovation Solution

A virtual agent executes on a virtual node within a container orchestration system, utilizing a Resource Principal Session Token (RPST) to determine subnet matching and enforce policies for request validation, ensuring secure communication and resource management between control and data planes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If container orchestration systems allow cross-tenancy resource deployment, then resource utilization and scalability are improved, but security and isolation between different tenants deteriorate

Engineering Contradiction:
Improvecross-tenancy resource deploymentVSAvoidsecurity and isolation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments network resources by assigning specific subnets to different virtual agents and their associated container instances. This segmentation isolates network traffic between tenants while allowing controlled cross-tenancy deployment, resolving the contradiction between resource scalability and security isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces subnet matching as an intermediary mechanism that validates and controls communication between virtual agents and container instances across different tenancies. This intermediary layer enables secure cross-tenancy resource association while maintaining isolation boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If network resources are shared across multiple tenants, then resource efficiency is improved, but unauthorized access and security risks increase

Engineering Contradiction:
Improveresource efficiencyVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback mechanisms through policy validation that continuously monitors and controls access requests between virtual agents and container instances. The system validates subnet associations and enforces policies to prevent unauthorized access while maintaining efficient resource sharing.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the security parameter from static isolation to dynamic subnet-based validation. By using Resource Principal Session Tokens (RPST) to encode subnet associations and validating these parameters during policy enforcement, the system enables secure efficient resource sharing across tenancies.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If strict subnet matching policies are enforced, then security and isolation are improved, but system complexity and request validation overhead increase

Engineering Contradiction:
Improvesecurity and isolationVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by pre-associating subnets with virtual agents during resource provisioning and encoding this information in Resource Principal Session Tokens. This preliminary configuration reduces runtime complexity by avoiding dynamic subnet discovery and validation during request processing.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If subnet-based policy validation is implemented, then unauthorized access is prevented, but request processing time and validation overhead increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidrequest processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-associating subnets with virtual agents during resource provisioning and encoding this information in Resource Principal Session Tokens. This preliminary configuration reduces runtime complexity by avoiding dynamic subnet discovery and validation during request processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250294020A1Cross-Tenancy Resource Association For Container Orchestration System
Publication Date: 2025.09.18 ORACLE INT CORP
  • US20250294020A1 patent drawing
  • US20250294020A1 patent drawing
  • US20250294020A1 patent drawing

AI summary

Techniques for a container orchestration system are disclosed. A container instance control plane receives a request corresponding to a container instance associated with a particular subnet. The container instance control plane determines if a first subnet assigned to the virtual agent matches the particular subnet associated with the container instance. Responsive to determining that the first subnet assigned to the virtual agent matches the particular subnet associated with the container instance, the container instance control plane permits the request corresponding to the container instance. Based at least on the request being permitted, the container instance control plane executes at least one operation corresponding to the request.