Fog Node Container Security Assessment and Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current fog computing systems lack a mechanism to provide network security and policy-driven control for containerized applications, allowing unrestricted access to resources and potential unauthorized usage.

Innovation Solution

A device in a network gathers characteristics of a container application, performs a security assessment, and controls its execution based on the assessment, using a local or remote security mechanism to prevent loading or restrict access to resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If container applications are deployed in fog computing systems without security control mechanisms, then ease of operation and deployment speed are improved, but network security and resource protection deteriorate

Engineering Contradiction:
Improveease of deploymentVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs security assessment of container applications before deployment by gathering characteristics (image parameters, network parameters, exposed ports, library versions) and evaluating them against security policies. This preliminary security check prevents unauthorized applications from being deployed while maintaining smooth deployment operations for approved applications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A security control mechanism acts as an intermediary between the container deployment system and network resources. This mediator gathers application characteristics, assesses security risks, and controls access permissions, thereby protecting network resources while allowing legitimate applications to operate without additional complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If security assessment and control mechanisms are implemented for container applications, then network security and resource protection are improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improveunauthorized accessVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The security control mechanism is segmented into distinct functional modules: characteristic gathering module (image parameters, network parameters, exposed ports, library versions), security assessment module (policy evaluation), and access control module. This segmentation allows each module to perform its specific function independently, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system automatically gathers container application characteristics and performs security assessments without requiring manual intervention. The security control mechanism self-manages the deployment and monitoring processes, reducing operational complexity while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security assessment is performed on all container characteristics, then security thoroughness is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity thoroughnessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security assessment focuses on gathering and evaluating key characteristics that are most relevant to security risks (image parameters, network parameters, exposed ports, library versions) rather than analyzing every possible aspect of the container application. This partial action approach ensures thorough security assessment of critical areas while reducing processing time and computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10693913B2Secure and policy-driven computing for fog node applications
Publication Date: 2020.06.23 CISCO TECHNOLOGY INC
  • US10693913B2 patent drawing
  • US10693913B2 patent drawing
  • US10693913B2 patent drawing

AI summary

In one embodiment, a device in a network gathers characteristics of a container application on the device. The device provides the gathered characteristics of the container application for security assessment. The device receives an indication of the security assessment based on the provided characteristics of the container application. The device controls execution of the container application based on the received indication of the security assessment.