Self-Describing Security Containers for Software-Defined Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined environments (SDEs), existing security solutions struggle to provide end-to-end security due to the dynamic and virtualized nature of resources, which breaks the association between security policies and underlying hardware, leading to challenges in maintaining integrity and confidentiality across heterogeneous resources.

Innovation Solution

The implementation of self-describing security containers that include metadata for resource-divisible portions, allowing for the generation of sub-containers representing compute, storage, and network resources, enabling fine-grained security mechanisms and dynamic adjustment in response to security events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualization and cloud solutions are used to abstract computing, storage, and network resources, then resource utilization and flexibility are improved, but the association between security policies and underlying hardware is broken, leading to security management challenges

Engineering Contradiction:
Improveresource flexibilityVSAvoidsecurity policy association
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces security containers as intermediary objects that bind security policies to virtualized resources. These containers act as mediators between the abstracted resources and security management systems, maintaining security associations despite the broken hardware-linkage in virtualized environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security management into hierarchical levels: global security policies, container-specific security contexts, and resource-level security attributes. This segmentation allows security policies to be applied at appropriate abstraction levels while maintaining traceability to underlying hardware resources.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If standardization of underlying system architecture is implemented to simplify resource abstraction, then ease of operation is improved, but the ability to leverage special micro-architecture capabilities is reduced

Engineering Contradiction:
Improveresource abstraction simplicityVSAvoidmicro-architecture capability leverage
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing different security container configurations and policy strictness levels for different resource types. Standardized abstraction is applied where generic security is sufficient, while specialized micro-architecture capabilities maintain their specific security contexts and policies where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security container framework provides universal security management across heterogeneous resources while allowing each container to specify architecture-specific security attributes. This multi-functionality enables both standardized security policies and architecture-specific optimizations to coexist.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If workload-optimized system approach with tight integration is used, then manufacturing precision is improved, but labor-intensive optimization is required

Engineering Contradiction:
Improveworkload optimization precisionVSAvoidoptimization effort
Core Design Contradiction:
Manufacturing precisionVSEase of manufacture

Solution Approach 1:

The patent performs preliminary security optimization by pre-configuring security containers with workload-specific security attributes and policies before workload deployment. This advance preparation enables tight workload-security integration without requiring labor-intensive optimization during deployment, as security contexts are established upfront.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If dynamic creation and destruction of software-defined systems is enabled, then adaptability is improved, but maintaining end-to-end security becomes more difficult

Engineering Contradiction:
Improvesystem dynamicsVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security by enabling security containers to automatically inherit, maintain, and enforce their security policies during dynamic creation, migration, and destruction. The containers self-manage their security contexts without requiring complex external orchestration, reducing security management complexity despite system dynamics.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10534911B2Security within a software-defined infrastructure
Publication Date: 2020.01.14 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10534911B2 patent drawing
  • US10534911B2 patent drawing
  • US10534911B2 patent drawing

AI summary

There is a computer program product and computer system that includes program instructions programmed to identify, in a software-defined environment, a security container describing a workload and a set of resources required by the workload, the security container including self-describing sub-containers having associated metadata describing content of a respectively corresponding sub-container; determine, for the workload, a set of resource-divisible portions of the workload including a compute-resource portion; generate a plurality of sub-containers within the security container, a sub-container within the plurality of sub-containers being a self-describing sub-container having associated metadata describing the content of the sub-container representing only one resource-divisible portion, the sub-container being an operating system sub-container; and responsive to identifying a security event while processing the workload, adjust a security mechanism associated with the security container. The plurality of sub-containers represents an end-to-end run time environment for processing the workload.