Software Image Compliance Screening for Edge Vulnerability Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to manage vulnerabilities in undesirable software images hosted by edge devices, which can hinder or negate computer-implemented services due to the inability to directly assess these images at remote sites.

Innovation Solution

A method and system for managing edge devices that host software objects by identifying and prioritizing remediation of undesirable software images through simulation environments, using identifiers, compliance decisions, and workload queue systems to ensure adherence to compliance standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If vulnerability testing is performed directly on edge devices, then measurement precision is improved, but device complexity and operational disruption increase

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidtesting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

A simulation environment acts as an intermediary between the vulnerability testing system and edge devices. The simulation environment replicates edge device behavior and software image execution, allowing vulnerability testing to be performed on suspected software images without directly accessing or disrupting actual edge devices. This intermediary approach maintains measurement precision while reducing device complexity and operational disruption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the edge device environment through simulation. Instead of testing directly on physical edge devices, the system instantiates software images in a simulated environment that mirrors the target edge device architecture and operating conditions. This copying approach enables accurate vulnerability assessment without the complexity and disruption of direct device testing.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive vulnerability testing is performed on all software images, then reliability is improved, but productivity decreases

Engineering Contradiction:
Improvesoftware image securityVSAvoidsoftware image deployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs vulnerability testing in advance before software images are deployed to edge devices. By testing software images in the simulation environment prior to deployment, the system identifies and remediates vulnerabilities beforehand, ensuring reliability without delaying actual deployment operations. The simulation environment enables parallel testing that does not block the deployment pipeline.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability testing process is extracted from the deployment workflow and performed separately in the simulation environment. This separation allows comprehensive security testing to occur independently without creating bottlenecks in the deployment pipeline, maintaining both reliability and productivity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If direct assessment of software images is performed at remote sites, then measurement precision is improved, but ease of operation worsens

Engineering Contradiction:
Improvesoftware image evaluation accuracyVSAvoidremote testing capability
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The simulation environment serves as a centralized intermediary that enables remote vulnerability assessment. Instead of requiring direct access to edge devices at remote sites, the system centralizes testing operations in the simulation environment, which can be accessed and controlled remotely. This maintains measurement precision while significantly improving ease of operation for remote users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12566866B2Identification of an undesirable software image
Publication Date: 2026.03.03 DELL PROD LP
  • US12566866B2 patent drawing
  • US12566866B2 patent drawing
  • US12566866B2 patent drawing

AI summary

Methods and systems for managing operation of edge devices that host software objects are disclosed. The operation of the edge devices may be managed by monitoring the software objects. The software objects may be monitored by managing vulnerabilities of an undesirable software image on which a portion of software objects is based. The vulnerabilities of the undesirable software object may be managed by generating a compliance decision based on compliance standards that are met by the undesirable software object. The compliance decision may be used to generate a prioritization for remediation of the undesirable software image.