IP Library › Granted Patent US 10,055,578
Granted Patent B1
US 10,055,578 · App. 15/157,031 · Granted Aug 21, 2018

Secure software containers

Inventors: Ronald R. Marquardt (Woodinville, WA); Lyle W. Paczkowski (Mission Hills, KS); Carl J. Persson (Olathe, KS); Arun Rajagopal (Leawood, KS)
Assignee: Sprint Communications Company L.P.
G06F21/53G06F21/44G06F21/602H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,055,578
App. No.
15/157,031
Granted
Aug 21, 2018
Kind
B1
Abstract

A computer system that comprises a processor, a non-transitory memory, and a system application stored in the non-transitory memory. When executed by the processor, the application receives a request to create a software container, creates the container, generates a signature of the container, creates a container security token that comprises the signature and embeds the container security token in the container, and returns the container with the embedded container security token. The application receives a request to launch an application in the container, determines a confirmation signature of the container provided by the application launch request, compares the confirmation signature to the signature of the container security token in the container, determines that the confirmation signature and the signature of the container security token in the software container match, and responsive to determining the signatures match launches the application in the software container provided by the application launch request.

Claims (54)

1. A method of providing an execution environment with a software container, each step of the method performed by a system application executing on a first computer system, the method comprising:

receiving a request for a software container, where the request for the software container is received from a second computer system, where the second computer system is different from the first computer system;

creating a software container comprising a container security token, where the token comprises a signature of the software container and an identity of an application to be executed in the software container;

sending the software container comprising the container security token to the second computer system;

receiving a request from the second computer system to launch an application in the software container, wherein the request comprises the software container and identifies the application in the software container;

determining a confirmation signature of the identified software container;

comparing the confirmation signature to the signature in the container security token;

comparing the application identity provided in the request to launch the application in the software container to the application identity in the container security token; and

in response to determining that the confirmation signature matches the signature in the container security token and to determining that the application identity provided in the request to launch the application matches the application identity in the container security token, launching execution of the application in the software container on the second computer system.

2. The method of claim 1 , wherein the signature of the software container is a hash calculated over the software container, determining the confirmation signature comprises calculating a confirmation hash over the software container identified in the request, and comparing the confirmation signature to the signature in the container security token comprises comparing the two hash values.

3. The method of claim 1 , wherein the signature of the software container is a checksum calculated over the software container, determining the confirmation signature comprises calculating a confirmation checksum over the software container identified in the request, and comparing the confirmation signature to the signature in the container security token comprises comparing the two checksum values.

4. The method of claim 1 , wherein the token further comprises a time-to-live value and further comprising comparing the time-to-live value in the container security token to a current system time by the system application prior to launching execution of the application in the software container.

5. The method of claim 4 , further comprising comparing the time-to-live value in the container security token to the current system time periodically by the system application after launching execution of the application in the software container.

6. The method of claim 5 , further comprising terminating execution of the application in the software container and destroying the software container when the time-to-live value is determined to be exceeded.

7. The method of claim 5 , further comprising prompting the application to invoke an application programming interface (API) of the system application to extend the time-to-live value stored in the container security token.

8. A computer system, comprising:

a processor;

a non-transitory memory; and

a system application stored in the non-transitory memory that, when executed by the processor,

receives a request to create a software container,

creates the software container,

generates a signature of the software container,

creates a container security token that comprises the signature and an identity of an application to be executed in the software container,

embeds the container security token in the software container,

returns the software container with the embedded container security token,

receives an application launch request to launch an application in the software container, where the application launch request comprises the software container and identifies the application in the software container,

determines a confirmation signature of the software container provided by the application launch request,

compares the confirmation signature to the signature of the container security token in the software container provided by the application launch request,

determines that the confirmation signature and the signature of the container security token in the software container provided by the application launch request match,

compares the application identity provided in the application launch request to the application identity in the container security token, and

responsive to determining the signatures match and to determining that the application identity provided in the application launch request matches the application identity in the container security token, launches, on the second computer system, the application in the software container provided by the application launch request.

9. The computer system of claim 8 , wherein the system application further:

receives a request to create a second software container,

creates the second software container,

generates a second signature of the second software container,

creates a second container security token that comprises the second signature,

embeds the second container security token in the second software container,

returns the second software container with the embedded second container security token,

receives a second application launch request to launch a second application in the second software container, where the second application launch request comprises the second software container,

determines a second confirmation signature of the second software container provided by the second application launch request,

compares the confirmation signature to the second signature of the second container security token in the second software container provided by the second application launch request,

determines that the second confirmation signature and the second signature of the second container security token in the second software container provided by the second application launch request do not match, and responsive to determining the signatures do not match rejects the second application launch request and does not launch the second application in the second software container provided by the second application launch request.

10. The computer system of claim 8 , wherein the signature of the software container is one of a hash value determined over the software container or a checksum determined over the software container.

11. The computer system of claim 8 , wherein the system application further encrypts the signature and the container security token comprises the encrypted signature.

12. The computer system of claim 8 , wherein the system application further:

creates a time-to-live value associated with the software container, wherein the container security token further comprises the time-to-live value,

compares the time-to-live value stored in the signature of the container security token in the software container provided by the application launch request to a current time maintained by the computer system, and

determines that the time-to-live value does not exceed the current time.

13. The computer system of claim 12 , wherein the system application provides an application programming interface to request extension of the time-to-live value in the signature of the container security token in the software container.

14. The method of claim 1 , wherein the software container sent to the second computer system is an inactive software container that comprises the container security token.

15. The method of claim 14 , wherein the inactive software container comprises information about resource allocations.

16. The method of claim 14 , wherein the inactive software container comprises configuration information.

17. The method of claim 8 , wherein the software container is an inactive software container that comprises the container security token.

18. The method of claim 17 , wherein the inactive software container comprises information about resource allocations.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2016
From: MARQUARDT, RONALD R.; PACZKOWSKI, LYLE W.; PERSSON, CARL J.; RAJAGOPAL, ARUN
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 038626/0480 →
Cited By (4)
US 12,204,658 US 12,504,983 US 12,602,479 US 12,608,475