Security-Induced Container Relocation in Orchestrated Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In orchestrated environments, container instances on weakly protected host systems are insufficiently protected due to changing security states and vulnerabilities, necessitating a method to dynamically relocate container instances to more secure systems.
Innovation Solution
A method for automatic, security-induced relocation of container instances, where an orchestration device launches a container instance on a first guest computer with a specific security level, receives a security alarm message with criticality parameters, determines a new security level based on a relocation policy, and relocates the container instance to a second guest computer with the appropriate security level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If container instances are operated on weakly protected host systems to optimize resources and reduce costs, then resource efficiency and operating costs are improved, but security protection level deteriorates
Solution Approach 1:
The patent implements dynamic security level adjustment by monitoring security states and automatically relocating container instances between host systems with different security levels. The orchestration apparatus changes the deployment configuration in real-time based on security conditions, transforming the static security level into a dynamic parameter that adapts to changing threat environments.
Solution Approach 2:
The system changes the security level parameter of host systems based on monitored security states. When security threats are detected, the orchestration apparatus modifies the deployment configuration to relocate container instances from low-security to high-security host systems, effectively changing the security parameter in response to environmental conditions.
2Reliability
If container instances are permanently operated on highly secure host systems to ensure sufficient protection, then security protection level is improved, but resource efficiency and operating costs deteriorate
Solution Approach 1:
The system dynamically adjusts security levels based on real-time monitoring of security states. Container instances are relocated to high-security host systems only when security threats are detected, and returned to low-security systems when threats subside, making the security level a dynamic rather than static parameter.
Solution Approach 2:
The orchestration apparatus periodically monitors security states and triggers relocation actions only when necessary. This periodic monitoring and conditional relocation ensures that high-security resources are utilized only when needed, optimizing the balance between security and cost.
3Reliability
If security monitoring and relocation capabilities are added to the orchestration system, then security protection level is improved, but system complexity increases
Solution Approach 1:
The orchestration apparatus is designed to perform multiple functions: traditional container orchestration tasks plus security state monitoring and automatic relocation decisions. By making the orchestration system multi-functional, the patent avoids adding separate dedicated security systems, thereby limiting the increase in overall system complexity.
Solution Approach 2:
The system implements automated security monitoring and relocation without requiring manual intervention. The orchestration apparatus autonomously monitors security states, evaluates threats, and executes relocation decisions based on predefined policies, enabling the system to serve its own security needs without external management overhead.
Data Source
AI summary
A method and device for the automatic, security-induced relocation of at least one container instance in an orchestrated environment that contains more than one guest computer managed by an orchestration apparatus is provided, including the following steps: the orchestration apparatus launching the container instance on a first guest computer that comprises security functions in accordance with a first security level, receiving a security alarm message including at least one criticality parameter that indicates a security status of the orchestrated environment from a monitoring apparatus in the orchestration apparatus, the orchestration apparatus determining a second security level, different from the first security level, for the container instance based on a relocation policy depending on the criticality parameter, the orchestration apparatus relocating the container instance to a second guest computer in the orchestrated environment that includes security functions in accordance with the second security level.


