Security-Induced Container Relocation in Orchestrated Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In orchestrated environments, container instances on weakly protected host systems are insufficiently protected due to changing security states and vulnerabilities, necessitating a method to dynamically relocate container instances to more secure systems.

Innovation Solution

A method for automatic, security-induced relocation of container instances, where an orchestration device launches a container instance on a first guest computer with a specific security level, receives a security alarm message with criticality parameters, determines a new security level based on a relocation policy, and relocates the container instance to a second guest computer with the appropriate security level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If container instances are operated on weakly protected host systems to optimize resources and reduce costs, then resource efficiency and operating costs are improved, but security protection level deteriorates

Engineering Contradiction:
Improveoperating costsVSAvoidsecurity protection level
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent implements dynamic security level adjustment by monitoring security states and automatically relocating container instances between host systems with different security levels. The orchestration apparatus changes the deployment configuration in real-time based on security conditions, transforming the static security level into a dynamic parameter that adapts to changing threat environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the security level parameter of host systems based on monitored security states. When security threats are detected, the orchestration apparatus modifies the deployment configuration to relocate container instances from low-security to high-security host systems, effectively changing the security parameter in response to environmental conditions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If container instances are permanently operated on highly secure host systems to ensure sufficient protection, then security protection level is improved, but resource efficiency and operating costs deteriorate

Engineering Contradiction:
Improvesecurity protection levelVSAvoidoperating costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system dynamically adjusts security levels based on real-time monitoring of security states. Container instances are relocated to high-security host systems only when security threats are detected, and returned to low-security systems when threats subside, making the security level a dynamic rather than static parameter.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The orchestration apparatus periodically monitors security states and triggers relocation actions only when necessary. This periodic monitoring and conditional relocation ensures that high-security resources are utilized only when needed, optimizing the balance between security and cost.

Inventive Principle:
Principle #19Periodic action

3Reliability

If security monitoring and relocation capabilities are added to the orchestration system, then security protection level is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protection levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The orchestration apparatus is designed to perform multiple functions: traditional container orchestration tasks plus security state monitoring and automatic relocation decisions. By making the orchestration system multi-functional, the patent avoids adding separate dedicated security systems, thereby limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements automated security monitoring and relocation without requiring manual intervention. The orchestration apparatus autonomously monitors security states, evaluates threats, and executes relocation decisions based on predefined policies, enabling the system to serve its own security needs without external management overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250094562A1Automatic, security-induced relocation of at least one container instance
Publication Date: 2025.03.20 SIEMENS AG
  • US20250094562A1 patent drawing
  • US20250094562A1 patent drawing
  • US20250094562A1 patent drawing

AI summary

A method and device for the automatic, security-induced relocation of at least one container instance in an orchestrated environment that contains more than one guest computer managed by an orchestration apparatus is provided, including the following steps: the orchestration apparatus launching the container instance on a first guest computer that comprises security functions in accordance with a first security level, receiving a security alarm message including at least one criticality parameter that indicates a security status of the orchestrated environment from a monitoring apparatus in the orchestration apparatus, the orchestration apparatus determining a second security level, different from the first security level, for the container instance based on a relocation policy depending on the criticality parameter, the orchestration apparatus relocating the container instance to a second guest computer in the orchestrated environment that includes security functions in accordance with the second security level.