IP Library Granted Patent US 11,106,512
Granted Patent B2
US 11,106,512 · App. 16/522,596 · Granted Aug 31, 2021

System and method for container provenance tracking

Inventors: Nisha Kumar-Mayernik (Tualatin, OR); Malini Bhandaru (San Jose, CA); John Hawley (Hillsboro, OR); Darren Hart (Portland, OR); Tim Pepper (Tigard, OR)
Assignee: VMware, Inc.
G06F9/545G06F16/1805G06F40/169H04L9/0643H04L9/3247H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,106,512
App. No.
16/522,596
Granted
Aug 31, 2021
Kind
B2
Abstract

A system and computer-implemented method for container provenance tracking uses a build instruction file of a container image to output a new provenance document associated with the container image for distribution. For each file system layer of the container image specified in the build instruction file, an existing provenance document for the file system layer is inserted into the new provenance document. If there is no existing provenance document, information about each software component included in the file system layer is retrieved and inserted into the new provenance document.

Claims (43)

1. A computer-implemented method for container provenance tracking, the method comprising:

receiving a build instruction file for a container image that includes multiple file system layers;

for each file system layer of the container image specified in the build instruction file:

when a provenance document exists for the file system layer of the container image being processed, inserting the provenance document into a new provenance document for the container image; and

when a provenance document does not exist for the file system layer of the container image being processed, retrieving information about each software component included in the file system layer of the container image and inserting the information about each software component into the new provenance document;

inserting the build instruction file into the new provenance document in a structured text format;

signing the new provenance document using private key and certificate before the new provenance document is finalized; and

outputting the new provenance document as a finalized provenance document associated with the container image for distribution.

2. The computer-implemented method of claim 1 , further comprising inserting a configuration file into the new provenance document in the structured text format.

3. The computer-implemented method of claim 1 , further comprising extracting information about a build environment for the container image and inserting the information about the build environment into the new provenance document.

4. The computer-implemented method of claim 3 , wherein the information about the build environment includes information about build hardware and firmware.

5. The computer-implemented method of claim 1 , wherein retrieving information about each software component included in the file system layer of the container image includes employing a software tool to access a software component included in the file system layer.

6. The computer-implemented method of claim 5 , wherein the software component includes a software package, source code or a file.

7. The computer-implemented method of claim 1 , further comprising maintaining hash for the new provenance document by chain hashing.

8. The method of claim 1 , further comprising responding to user questions about the container image with answers using the finalized provenance document to find the answers to the user questions.

9. A non-transitory computer-readable storage medium containing program instructions for container provenance tracking, wherein execution of the program instructions by one or more processors of a computer system causes the one or more processors to perform steps comprising:

receiving a build instruction file for a container image that includes multiple file system layers;

for each file system layer of the container image specified in the build instruction file:

when a provenance document exists for the file system layer of the container image being processed, inserting the provenance document into a new provenance document for the container image; and

when a provenance document does not exist for the file system layer of the container image being processed, retrieving information about each software component included in the file system layer of the container image and inserting the information about each software component into the new provenance document;

inserting the build instruction file into the new provenance document in a structured text format;

signing the new provenance document using private key and certificate before the new provenance document is finalized; and

outputting the new provenance document as a finalized provenance document associated with the container image for distribution.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the steps further comprise inserting a configuration file into the new provenance document in the structured text format.

11. The non-transitory computer-readable storage medium of claim 9 , wherein the steps further comprises extracting information about a build environment for the container image and inserting the information about the build environment into the new provenance document.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the information about the build environment includes information about build hardware and firmware.

13. The non-transitory computer-readable storage medium of claim 9 , wherein retrieving information about each software component included in the file system layer of the container image includes employing a software tool to access a software component included in the file system layer.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the software component includes a software package, source code or a file.

15. The non-transitory computer-readable storage medium of claim 9 , wherein the steps further comprise maintaining hash for the new provenance document by chain hashing.

16. The non-transitory computer-readable storage medium of claim 9 , wherein the steps further comprise responding to user questions about the container image with answers using the finalized provenance document to find the answers to the user questions.

17. A system comprising:

memory; and

at least one processor configured to:

receive a build instruction file for a container image that includes multiple file system layers;

for each file system layer of the container image specified in the build instruction file:

when a provenance document exists for the file system layer of the container image being processed, insert the provenance document into a new provenance document for the container image; and

when a provenance document does not exist for the file system layer of the container image being processed, retrieve information about each software component included in the file system layer of the container image and insert the information about each software component into the new provenance document;

insert the build instruction file into the new provenance document in a structured text format;

sign the new provenance document using private key and certificate before the new provenance document is finalized; and

output the new provenance document as a finalized provenance document associated with the container image for distribution.

18. The system of claim 17 , wherein the at least one processor is configured to employ a software tool to access a software component included in the file system layer to retrieve information about the software component.

19. The system of claim 17 , wherein the at least one processor is configured to insert a configuration file into the new provenance document in the structured text format.

20. The system of claim 17 , wherein the at least one processor is configured to extract information about a build environment for the container image and inserting the information about the build environment into the new provenance document.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2020
From: KUMAR-MAYERNIK, NISHA; BHANDARU, MALINI; HAWLEY, JOHN; HART, DARREN; PEPPER, TIM
To: VMWARE, INC.
Reel/Frame 053333/0707 →