/Container Mode Management Engine In A Security Management System
Abstract

Methods, systems, and computer storage media for providing container secure computing modes using a container mode management engine of a security management system. A container secure computing mode can include a secure state in which a container operates to prioritize security measures and practices. A container secure computing mode can be assigned to a container instance and enforced via a container security agent. In operation, a container instance is initialized, the container instance is associated with a container security agent having a secure compute mode transition control for the container instance. Based on the secure compute mode transition control, the container instance is transitioned into a secure state. A container operation of the container instance is accessed. The execution of the container operation is restricted based on the secure state of the container instance. The secure state is associated with a secure state configuration that supports restricting the container operation.

Full Text

What is claimed is:

Methods, systems, and computer storage media for providing container secure computing modes using a container mode management engine of a security management system. A container secure computing mode can include a secure state in which a container operates to prioritize security measures and practices. A container secure computing mode can be assigned to a container instance and enforced via a container security agent. In operation, a container instance is initialized, the container instance is associated with a container security agent having a secure compute mode transition control for the container instance. Based on the secure compute mode transition control, the container instance is transitioned into a secure state. A container operation of the container instance is accessed. The execution of the container operation is restricted based on the secure state of the container instance. The secure state is associated with a secure state configuration that supports restricting the container operation.
Timeline
Filed
03/26/2026
Published
07/30/2026
Granted
Not Available
IPC Codes(1)
G06F 21/53:by executing in a restricted environment, e.g. sandbox or secure virtual machine