IP Library Granted Patent US 11,216,566
Granted Patent B1
US 11,216,566 · App. 16/731,381 · Granted Jan 4, 2022

System and method for encryption of ephemeral storage

Inventors: Dmitry Monakhov (Moscow, RU); Pavel Emelyanov (Moscow, RU); Alexey Kobets (Seattle, WA)
Assignee: Virtuozzo International GmbH
G06F21/602G06F11/1461G06F21/6218H04L9/0863H04L9/0891G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,216,566
App. No.
16/731,381
Granted
Jan 4, 2022
Kind
B1
Abstract

Disclosed are systems and methods for encryption of an ephemeral layer of one or more containers. An exemplary method comprises detecting a container starting execution in an operating system, generating a temporary encryption key and storing the temporary encryption key in memory of a kernel of the operating system, creating an encrypted area as the ephemeral layer in a storage device, the encrypted area accessible only by the container, providing to the container access to the encrypted area, and responsive to stopping execution of the container, destroying the temporary encryption key.

Claims (56)

1. A method for encryption of an ephemeral layer of one or more containers comprising:

detecting a container starting execution in an operating system;

generating a temporary encryption key, wherein generating the temporary encryption key comprises: performing a snapshot on a base root file system of the container;

performing incremental snapshots of changes to the file system of the container:

encrypting an ephemeral layer of the container using the temporary encryption key; and

attaching the ephemeral layer to the base root file system of the container;

storing the temporary encryption key in memory of a kernel of the operating system;

creating an encrypted area as the ephemeral layer in a storage device, wherein the encrypted area is an empty subdirectory of the ephemeral layer of the container, and container has read-write access to the encrypted area, and the encrypted area accessible only by the container;

providing to the container access to the encrypted area; and

responsive to stopping execution of the container, destroying the temporary encryption key.

2. The method of claim 1 , further comprising:

upon a request from one container of the plurality of containers to access the encrypted area, determining whether the one container has access to the temporary encryption key; and

responsive to determining that the one container has access, allowing the one container to access the encrypted area, otherwise returning an error.

3. The method of claim 1 , further comprising: when the operational request is a read request, decrypting data in the encrypted area after access is allowed; and when the operational request is a write request, encrypting the data in the encrypted area after access is allowed.

4. The method of claim 1 , wherein the temporary encryption key is stored in the kernel memory, not written to a physical disk and is inaccessible by processes in the user space of the container.

5. The method of claim 1 , further comprising:

providing the container with an identifier for the temporary encryption key.

6. The method of claim 1 , further comprising:

securing the temporary encryption key using a key management that stores all generated keys; and

providing the generated keys to trusted parties.

7. The method of claim 1 , further comprising: writing the temporary encryption key to a location in local storage; encrypting the location with a slow encryption algorithm with a generated key; and protecting the generated key.

8. The method of claim 1 , further comprising:

destroying the container; and

destroying the encrypted area.

9. The method of claim 1 , further comprising:

attaching the encrypted area as snapshot changes storage for the container root file system.

10. A system for encryption of an ephemeral layer of one or more containers comprising:

a memory; and a processor configured to:

detect a container starting execution in an operating system;

generate a temporary encryption key, wherein generating the temporary encryption key comprises:

performing a snapshot on a base root file system of the container;

performing incremental snapshots of changes to the file system of the container:

encrypting an ephemeral layer of the container using the temporary encryption key; and

attaching the ephemeral layer to the base root file system of the container;

store the temporary encryption key in memory of a kernel of the operating system;

create an encrypted area as the ephemeral layer in a storage device, wherein the encrypted area is an empty subdirectory of the ephemeral layer of the container, and container has read-write access to the encrypted area, and the encrypted area accessible only by the container;

provide to the container access to the encrypted area; and

responsive to stopping execution of the container, destroy the temporary encryption key.

11. The system of claim 10 , upon a request from one container of the plurality of containers to access the encrypted area, the processor further being configured to:

determine whether the one container has access to the temporary encryption key; and

responsive to determining that the one container has access, allow the one container to access the encrypted area, otherwise return an error.

12. The system of claim 10 , the processor further being configured to: when the operational request is a read request, decrypt data in the encrypted area after access is allowed; and when the operational request is a write request, encrypt the data in the encrypted area after access is allowed.

13. A non-transitory computer readable medium storing thereon computer readable instructions for encryption of an ephemeral layer of one or more containers, including instructions for:

detecting a container starting execution in an operating system;

generating a temporary encryption key, wherein generating the temporary encryption key comprises:

performing a snapshot on a base root file system of the container;

performing incremental snapshots of changes to the file system of the container:

encrypting an ephemeral layer of the container using the temporary encryption key; and

attaching the ephemeral layer to the base root file system of the container;

storing the temporary encryption key in memory of a kernel of the operating system;

creating an encrypted area as the ephemeral layer in a storage device, wherein the encrypted area is an empty subdirectory of the ephemeral layer of the container, and container has read-write access to the encrypted area, and, the encrypted area accessible only by the container;

providing to the container access to the encrypted area; and

responsive to stopping execution of the container, destroying the temporary encryption key.

14. The non-transitory computer readable medium of claim 13 , the instructions further comprising instructions for:

upon a request from one container of the plurality of containers to access the encrypted area, determining whether the one container has access to the temporary encryption key; and

responsive to determining that the one container has access, allowing the one container to access the encrypted area, otherwise returning an error.

Assignments (7)
SECURITY INTEREST IN TRADEMARK, PATENT, AND COPYRIGHT RIGHTS Recorded Dec 22, 2022
From: VIRTUOZZO INTERNATIONAL GMBH; ONAPP LIMITED
To: WILMINGTON TRUST (LONDON) LIMITED
Reel/Frame 062206/0557 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2022
From: MONAKHOV, DMITRY; EMELYANOV, PAVEL
To: VIRTUOZZO INTERNATIONAL GMBH
Reel/Frame 062102/0225 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE ADDRESS PREVIOUSLY RECORDED AT REEL: 057102 FRAME: 0987. ASSIGNOR(S) HEREBY CONFIRMS THE EMPLOYMENT AGREEMENT . Recorded Dec 15, 2022
From: PARALLELS INC.
To: VIRTUOZZO INC
Reel/Frame 062133/0823 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2022
From: VIRTUOZZO INC
To: VIRTUOZZO INTERNATIONAL GMBH
Reel/Frame 062100/0322 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE ADDRESS PREVIOUSLY RECORDED AT REEL: 057050 FRAME: 0538. ASSIGNOR(S) HEREBY CONFIRMS THE EMPLOYMENT AGREEMENT . Recorded Dec 15, 2022
From: KOBETS, ALEXEY
To: PARALLELS INC.
Reel/Frame 062133/0898 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2021
From: PARALLELS INC.
To: VIRTUOZZO INC
Reel/Frame 057102/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2021
From: KOBETS, ALEXEY
To: PARALLELS INC.
Reel/Frame 057050/0538 →
Cited By (3)
US 12,216,779 US 12,225,111 US 12,314,408