Hardware Memory Encryption for Container Workload Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Container workloads in cloud computing environments rely on unsecure cloud providers, necessitating the need for enhanced security measures to protect data from unintended or malicious access.

Innovation Solution

Employing hardware memory encryption and protection technologies to encrypt workload binaries and definitions, using mock workload definitions during runtime, and orchestrating cluster operations to conceal workload execution, while dynamically adjusting secure VM resources based on workload requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If container workloads are run in cloud computing environments, then resource efficiency and scalability are improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveresource efficiencyVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system segments the workload execution environment by creating isolated secure VMs for each workload. The workload binary, workload definition, and execution environment are separated and protected individually through encryption, allowing resource efficiency while preventing unauthorized access at the workload level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces secure VMs as intermediary layers between the cloud provider infrastructure and the container workloads. These secure VMs act as mediators that provide hardware-based memory encryption and protection, enabling cloud resource efficiency while blocking unauthorized access paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If hardware memory encryption is implemented for workload protection, then security against unauthorized access is improved, but system complexity increases

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements self-service security where the secure VMs automatically perform memory encryption and decryption operations using hardware-based security features. The workload definitions specify security requirements, and the system automatically provisions appropriate secure VMs with the necessary encryption capabilities, reducing manual configuration complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by encrypting workload binaries and definitions before they are deployed to the cloud environment. The secure VMs are pre-configured with hardware-based memory encryption capabilities, and security policies are established in advance, simplifying the overall system operation while maintaining high security.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If workload binaries and definitions are encrypted, then data protection is improved, but processing speed deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing speed
Core Design Contradiction:
Object-affected harmful factorsVSSpeed

Solution Approach 1:

The patent replaces software-based encryption/decryption operations with hardware-based security features in secure VMs. The memory encryption is performed at the hardware level using CPU-based encryption engines, which significantly reduces the processing overhead compared to software-only solutions while maintaining strong data protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the encryption parameters by using hardware-accelerated encryption with optimized key management. The secure VMs utilize hardware security modules that provide fast encryption/decryption operations, and the encryption schemes are tuned to minimize performance impact while ensuring data protection.

Inventive Principle:
Principle #35Parameter changes

4Object-affected harmful factors

If secure VMs are used for workload execution, then security isolation is improved, but resource efficiency deteriorates

Engineering Contradiction:
Improvesecurity isolationVSAvoidresource efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent makes secure VMs universal by designing them to handle multiple different workload types and security requirements through a standardized interface. The secure VMs can execute various container workloads while maintaining security isolation, and the underlying infrastructure can be shared across multiple tenants, improving resource efficiency compared to dedicated secure hardware for each workload.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11354151B2Hardware memory encryption and protection for containers
Publication Date: 2022.06.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11354151B2 patent drawing
  • US11354151B2 patent drawing
  • US11354151B2 patent drawing

AI summary

In an approach for securing container workloads, a processor encrypts workload binaries. A processor uploads the workload binaries to a software repository. A processor encrypts a workload definition. A processor replaces the workload definition with a mock workload definition. A processor references the encrypted workload definition in the mock workload definition. A processor submits the mock workload definition to a master node.