Virtual Container Software Identification via Layered Image Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current desktop management tools are inadequate for managing virtual environments, as they cannot effectively identify and manage software within virtual containers, perform security checks, or interact with auto-start capabilities across multiple containers efficiently.

Innovation Solution

A method and system that utilize API sequencing and commands provided by virtualization vendors to manage virtual environments, allowing for the identification of installed software components in containers by determining identifiers for layered image data and retrieving information from a repository storage arrangement, enabling comprehensive management, security checks, and auto-start interactions without requiring antivirus or compliance manager installations in each container.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional desktop management tools are used, then they can manage traditional applications, but they cannot manage software installed in virtual containers

Engineering Contradiction:
Improvecapability to manage virtual containersVSAvoidmanagement system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that acts as a bridge between traditional desktop management tools and virtual container environments. This intermediary enables the management system to communicate with and manage software installed in containers without requiring complete system redesign, thus resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal management interface that can handle both traditional applications and virtual container software through a single system. This multi-functional approach allows the desktop management tool to adapt to different application types without increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a copy of antivirus/compliance manager is installed in each container, then security and compliance checks can be performed, but resource utilization becomes inefficient

Engineering Contradiction:
Improvesecurity and compliance managementVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple antivirus and compliance manager instances into a single centralized management system that can monitor and manage multiple containers simultaneously. This consolidation maintains security and compliance reliability while eliminating the redundant resource consumption that would result from having separate software copies in each container.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security and compliance management system that serves multiple containers through a single instance. This multi-functional system performs security scans, compliance checks, and management operations across all containers without requiring individual software copies, thus improving resource utilization while maintaining reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional management tools are used, then they can provide basic desktop management, but they cannot interact with virtual containers for security and patch management from a single point

Engineering Contradiction:
Improvesingle-point management capabilityVSAvoidcontainer interaction complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer that enables traditional desktop management tools to interact with virtual containers through a standardized interface. This intermediary handles the complexity of container communication, allowing users to perform security updates and patch management from a single point without dealing with underlying container complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the management system into distinct layers: a user-facing interface layer for ease of operation, and a backend intermediary layer that handles container-specific complexities. This segmentation allows the system to provide simple single-point management capabilities while isolating the interaction complexity in a dedicated intermediary component.

Inventive Principle:
Principle #1Segmentation

4Productivity

If virtualization is implemented to host multiple operating systems and applications, then resource efficiency improves, but the ability to manage and detect software in virtual environments deteriorates

Engineering Contradiction:
Improveresource efficiencyVSAvoidsoftware detection capability
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary detection mechanism that bridges the gap between virtualized environments and traditional software detection capabilities. This intermediary monitors and reports software installations within containers to the central management system, maintaining productivity benefits while restoring detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the virtualization environment continuously reports software installation and configuration information back to the management system. This feedback loop enables the system to detect and measure software in virtual environments without compromising resource efficiency, as the detection process occurs automatically through integrated monitoring.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10169056B2Effective management of virtual containers in a desktop environment
Publication Date: 2019.01.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10169056B2 patent drawing
  • US10169056B2 patent drawing
  • US10169056B2 patent drawing

AI summary

A method and system are provided for identifying installed software components in a container running in a virtual execution environment. The container is created by instantiating image data. The method includes determining a respective identifier for each of individual layers of a layered structure of the image data. The method further includes retrieving from a repository storage arrangement, information identifying at least one of the installed software components in the container, based on the respective identifier for at least one of the individual layers.