IP Library › Granted Patent US 11,044,229
Granted Patent B2
US 11,044,229 · App. 15/853,404 · Granted Jun 22, 2021

Dynamically opening ports for trusted application processes hosted in containers

Inventors: Ling Lan (Austin, TX); Hongxia Li (Markham, CA); Hai Long Liu (Beijing, CN); Xin Peng Liu (Tiantongyuan, CN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/0236G06F21/44G06F21/53G06F21/6281H04L63/0263H04L63/08H04L63/0807H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,044,229
App. No.
15/853,404
Granted
Jun 22, 2021
Kind
B2
Abstract

A port listening request dynamically generated by an application process hosted in a container can be identified. Whether the application process hosted in the container is trusted can be determined. Responsive to determining that the application process hosted in the container is trusted, a first port to be used as an external port for the application process can be dynamically selected, and a port assignment can be communicated to a container engine, the port assignment indicating the first port is assigned to the application process. The first port can be mapped to a second port assigned as an internal port for the application process. The first port can be opened for the application process.

Claims (31)

1. A system, comprising:

a processor programmed to initiate executable operations comprising:

identifying a port listening request dynamically generated by an application process hosted in a container;

responsive to identifying the port listening request dynamically generated by the application process hosted in the container, determining whether the application process hosted in the container is trusted;

responsive to determining that the application process hosted in the container is trusted, dynamically selecting a first port to be used as an external port for the application process, and communicating a port assignment to a container engine, the port assignment indicating the first port is assigned to the application process;

mapping the first port to a second port assigned as an internal port for the application process; and

opening the first port for the application process.

2. The system of claim 1 , wherein mapping the first port to the second port enables the application process to listen to the first port by listening to the second port.

3. The system of claim 1 , the executable operations further comprising:

authenticating the port listening request, wherein communicating the port assignment to the container engine for the container further is responsive to authenticating the port listening request.

4. The system of claim 3 , wherein a dynamic port manager deployed external to the container receives a permission token representing the authenticated port listening request and performs the dynamically selecting the first port for the application process.

5. The system of claim 3 , wherein a dynamic port manager deployed within the container receives a permission token representing the authenticated port listening request and performs the dynamically selecting the first port for the application process.

6. The system of claim 1 , wherein communicating the port assignment to the container engine creates a new container-aware port channel for an application, external to the container hosting the application process, to access the application process.

7. The system of claim 1 , the executable operations further comprising:

detecting the application process is no longer listening to the first port assigned to the application process; and

responsive to detecting the application process is no longer listening to the first port assigned to the application process, closing the first port.

8. A computer program product comprising a computer readable storage medium having program code stored thereon, the program code executable by a processor to perform a method comprising:

identifying, by the processor, a port listening request dynamically generated by an application process hosted in a container;

responsive to identifying the port listening request dynamically generated by the application process hosted in the container, determining, by the processor, whether the application process hosted in the container is trusted;

responsive to determining that the application process hosted in the container is trusted, dynamically selecting, by the processor, a first port to be used as an external port for the application process, and communicating, by the processor, a port assignment to a container engine, the port assignment indicating the first port is assigned to the application process;

mapping, by the processor, the first port to a second port assigned as an internal port for the application process; and

opening, by the processor, the first port for the application process.

9. The computer program product of claim 8 , wherein mapping the first port to the second port enables the application process to listen to the first port by listening to the second port.

10. The computer program product of claim 8 , the method further comprising:

authenticating the port listening request, wherein communicating the port assignment to the container engine for the container further is responsive to authenticating the port listening request.

11. The computer program product of claim 10 , wherein a dynamic port manager deployed external to the container receives a permission token representing the authenticated port listening request and performs the dynamically selecting the first port for the application process.

12. The computer program product of claim 10 , wherein a dynamic port manager deployed within the container receives a permission token representing the authenticated port listening request and performs the dynamically selecting the first port for the application process.

13. The computer program product of claim 8 , wherein communicating the port assignment to the container engine creates a new container-aware port channel for an application, external to the container hosting the application process, to access the application process.

14. The computer program product of claim 8 , the method further comprising:

detecting the application process is no longer listening to the first port assigned to the application process; and

responsive to detecting the application process is no longer listening to the first port assigned to the application process, closing the first port.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2017
From: LAN, LING; LI, HONGXIA; LIU, HAI LONG; LIU, XIN PENG
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044474/0343 →
Continuity (1)
Related Publication 20190199687A1 · Jun 27, 2019