Safe Shell Container for Secure Virtual Container Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual container inspection technologies lack efficient methods for defining and enforcing constrained capabilities and resource constraints, leading to potential security risks and side-effects during inspection processes in container-based virtualization environments.

Innovation Solution

A system comprising a processor and memory that executes computer executable components, including a container inspection control component and a container inspection component, which define and enforce constrained capabilities and resource constraints to inspect virtual containers safely, using mechanisms like access control components, resource constraint components, and security constructs to prevent write operations and ensure read-only access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional container inspection methods are used, then inspection capabilities are comprehensive, but security risks and side-effects increase

Engineering Contradiction:
Improveinspection securityVSAvoidside-effects during inspection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a safe shell container as an intermediary layer between the inspection tool and the virtual container. This safe shell container implements read-only access controls and filters inspection operations, allowing comprehensive inspection while preventing harmful write operations and side-effects. The safe shell container acts as a mediator that enables secure inspection by blocking potentially harmful actions while allowing safe read operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If read-only access is enforced, then container integrity is preserved, but inspection flexibility is reduced

Engineering Contradiction:
Improvecontainer state integrityVSAvoidinspection operation flexibility
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The safe shell container dynamically adjusts access permissions based on the inspection context. While maintaining overall read-only constraints to preserve container integrity, the system can dynamically allow specific write operations when explicitly authorized through the control component. This dynamic permission management enables both integrity preservation and inspection flexibility by adapting access levels to specific inspection needs rather than applying static constraints.

Inventive Principle:
Principle #15Dynamics

3Reliability

If constrained capabilities are defined, then security is improved, but device complexity increases

Engineering Contradiction:
Improveinspection securityVSAvoidcontrol component complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control component segments security policies into distinct, manageable constraint definitions. Rather than implementing a monolithic complex security system, the patent divides capabilities into separate constraint categories (read-only constraints, resource constraints, operation constraints) that can be independently defined and managed. This segmentation reduces the perceived and actual complexity by organizing security controls into modular, composable units that can be applied selectively.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11659003B2Safe shell container facilitating inspection of a virtual container
Publication Date: 2023.05.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11659003B2 patent drawing
  • US11659003B2 patent drawing
  • US11659003B2 patent drawing

AI summary

Systems, computer-implemented methods, and computer program products that facilitate container inspection components of a container-based virtualization environment are provided. According to an embodiment, a system can comprise a memory that stores computer executable components and a processor that executes the computer executable components stored in the memory. The computer executable components can comprise a container inspection control component that can define one or more constrained capabilities of a container inspection. The computer executable components can further comprise a container inspection component that can inspect a virtual container based on the one or more constrained capabilities.