Self-Describing Security Containers for Software-Defined Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In software-defined environments (SDEs), existing security solutions struggle to provide end-to-end security due to the dynamic and virtualized nature of resources, which breaks the association between security policies and underlying hardware, leading to challenges in maintaining integrity and confidentiality across heterogeneous resources.
Innovation Solution
The implementation of self-describing security containers that include metadata for resource-divisible portions, allowing for the generation of sub-containers representing compute, storage, and network resources, enabling fine-grained security mechanisms and dynamic adjustment in response to security events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtualization and cloud solutions are used to abstract computing, storage, and network resources, then resource utilization and flexibility are improved, but the association between security policies and underlying hardware is broken, leading to security management challenges
Solution Approach 1:
The patent introduces security containers as intermediary objects that bind security policies to virtualized resources. These containers act as mediators between the abstracted resources and security management systems, maintaining security associations despite the broken hardware-linkage in virtualized environments.
Solution Approach 2:
The patent segments security management into hierarchical levels: global security policies, container-specific security contexts, and resource-level security attributes. This segmentation allows security policies to be applied at appropriate abstraction levels while maintaining traceability to underlying hardware resources.
2Ease of operation
If standardization of underlying system architecture is implemented to simplify resource abstraction, then ease of operation is improved, but the ability to leverage special micro-architecture capabilities is reduced
Solution Approach 1:
The patent applies local quality by allowing different security container configurations and policy strictness levels for different resource types. Standardized abstraction is applied where generic security is sufficient, while specialized micro-architecture capabilities maintain their specific security contexts and policies where needed.
Solution Approach 2:
The security container framework provides universal security management across heterogeneous resources while allowing each container to specify architecture-specific security attributes. This multi-functionality enables both standardized security policies and architecture-specific optimizations to coexist.
3Manufacturing precision
If workload-optimized system approach with tight integration is used, then manufacturing precision is improved, but labor-intensive optimization is required
Solution Approach 1:
The patent performs preliminary security optimization by pre-configuring security containers with workload-specific security attributes and policies before workload deployment. This advance preparation enables tight workload-security integration without requiring labor-intensive optimization during deployment, as security contexts are established upfront.
4Adaptability or versatility
If dynamic creation and destruction of software-defined systems is enabled, then adaptability is improved, but maintaining end-to-end security becomes more difficult
Solution Approach 1:
The patent implements self-service security by enabling security containers to automatically inherit, maintain, and enforce their security policies during dynamic creation, migration, and destruction. The containers self-manage their security contexts without requiring complex external orchestration, reducing security management complexity despite system dynamics.
Data Source
AI summary
There is a computer program product and computer system that includes program instructions programmed to identify, in a software-defined environment, a security container describing a workload and a set of resources required by the workload, the security container including self-describing sub-containers having associated metadata describing content of a respectively corresponding sub-container; determine, for the workload, a set of resource-divisible portions of the workload including a compute-resource portion; generate a plurality of sub-containers within the security container, a sub-container within the plurality of sub-containers being a self-describing sub-container having associated metadata describing the content of the sub-container representing only one resource-divisible portion, the sub-container being an operating system sub-container; and responsive to identifying a security event while processing the workload, adjust a security mechanism associated with the security container. The plurality of sub-containers represents an end-to-end run time environment for processing the workload.


