Targeted Container Virtualization for Resource Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization systems virtualize all components of a computer system or server, which is inefficient and costly, as they do not allow for targeted or selective virtualization of only the necessary resources, leading to unnecessary resource allocation and usage.
Innovation Solution
A method for targeted container virtualization where only specific components or resources, such as memory, I/O operations, disk space, and network, can be virtualized, allowing for flexible isolation and management of resources, enabling more efficient use of hardware and reduced costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complete virtualization of all cloud resources is implemented, then resource isolation and security are improved, but system complexity and cost increase significantly
Solution Approach 1:
The patent segments virtualization into two distinct layers: container-level virtualization for application isolation and host-level virtualization for infrastructure management. This allows selective application of virtualization where needed (in containers) while avoiding unnecessary virtualization overhead in other areas, thereby reducing overall system complexity while maintaining security and isolation.
Solution Approach 2:
The patent applies virtualization with different qualities to different parts of the system. Container virtualization provides full isolation for applications requiring security, while host resources can share virtualization infrastructure when isolation is not critical. This local differentiation of virtualization quality reduces unnecessary complexity while maintaining required security boundaries.
2Reliability
If all components are virtualized, then resource isolation is achieved, but resource allocation efficiency decreases due to unnecessary virtualization overhead
Solution Approach 1:
The patent implements partial virtualization by applying container virtualization only to the extent necessary for application isolation, rather than virtualizing all components. This partial action approach avoids excessive virtualization overhead while still achieving the required resource isolation for containerized applications, thereby improving resource allocation efficiency.
3Reliability
If full system virtualization is implemented, then security and isolation are improved, but cost increases due to unnecessary resource allocation
Solution Approach 1:
The patent segments security requirements into container-level security (handled by container virtualization) and host-level security (handled by host security mechanisms). This segmentation allows security to be implemented only where necessary for application isolation, reducing unnecessary resource allocation while maintaining required security levels.
Solution Approach 2:
The patent changes the virtualization parameter from binary (fully virtualized or not virtualized) to a spectrum of virtualization levels. Containers can be virtualized to the extent needed for their security requirements, while host resources can operate with less virtualization overhead. This parameter change allows optimization of resource allocation according to actual security needs.
Data Source
AI summary
A method and computer program product for targeted container virtualization, where only separate components of a computer system or a server are virtualized. The OS kernel and other server resources are not virtualized. Only selected components—applications or resources are targeted for virtualization instead of virtualization of the entire system. Targeted virtualization provides for more flexible container isolation from each other and from a host node. This, in turn, provides for optimized more flexible cloud infrastructure. Each element within a container virtualization model is optional in terms of virtualization. The element's virtualization option can be turned on and off by an administrator or by a client who owns the container.


