Golden Container Registry for Moving Target Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems are vulnerable to hacker attacks due to their static nature, making them susceptible to unauthorized modifications and cyber threats.

Innovation Solution

Implementing a method and system for golden container storage using a container registry to securely store templates (golden containers) within a service platform, employing a moving target defense strategy by constantly recreating containers with new IP and MAC addresses, thereby making the system dynamic and difficult to exploit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If containers are constantly recreated with new IP and MAC addresses, then system security is improved, but system complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements moving target defense by dynamically changing container identifiers (IP addresses and MAC addresses) on a regular basis. Containers are recreated with new identifiers instead of maintaining static ones, making it difficult for attackers to track and exploit vulnerabilities. This dynamic approach directly resolves the contradiction by improving security through constant change while managing complexity through automated container lifecycle management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses container templates (golden containers) that can be copied and deployed repeatedly. Instead of creating containers from scratch each time, the system copies verified secure templates and applies new identifiers to them. This copying mechanism simplifies the complexity management by reusing proven container configurations while maintaining security through identifier rotation.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If containers are constantly recreated, then hacker attack susceptibility is reduced, but operational complexity increases

Engineering Contradiction:
Improvehacker attack susceptibilityVSAvoidoperational complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements dynamic container recreation with new identifiers to counter hacker attacks. By continuously changing the operational characteristics of containers, the system makes it difficult for attackers to map, track, or exploit vulnerabilities. The dynamic nature of the system directly addresses the harmful factors while the automation layer manages operational complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The container management system automatically handles the lifecycle of containers including creation, identification, and recreation. The system self-manages the complexity of tracking and recreating containers with new identifiers without requiring manual intervention. This self-service capability reduces operational complexity despite the constant recreation of containers for security purposes.

Inventive Principle:
Principle #25Self-service

3Reliability

If a container registry is implemented for secure storage, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a container registry that stores template containers (golden containers) as copies. These templates serve as verified secure bases that can be repeatedly deployed. The registry approach centralizes security management by storing and managing verified container images, simplifying the security architecture while improving reliability through centralized control and verification of container templates.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10333951B1Method and system for implementing golden container storage
Publication Date: 2019.06.25 EMC IP HLDG CO LLC
  • US10333951B1 patent drawing
  • US10333951B1 patent drawing
  • US10333951B1 patent drawing

AI summary

A method and a system for implementing golden container storage. Specifically, the disclosed method and system entail the creation of a container registry to securely store golden containers (or templates) for containers of specific application types that execute within a service platform. Given short retention spans, the containers are constantly being cycled out. Each recreated container is modeled after one of the golden containers, and assigned new Internet Protocol (IP) and/or media access control (MAC) addresses rather than assuming the existing addresses of the containers the recreated containers replace. Substantively, embodiments of the invention employ these tactics towards implementing a moving target defense (MTD) strategy.