IP Library Granted Patent US 11,595,212
Granted Patent B2
US 11,595,212 · App. 17/069,436 · Granted Feb 28, 2023

Secure approval chain for runtime protection

Inventors: Kfir Wolfson (Beer Sheva, IL); Jehuda Shemer (Kfar Saba, IL); Stav Sapir (Beer Sheva, IL); Naor Radami (Shokeda, IL)
Assignee: EMC IP Holding Company LLC
H04L9/3213G06F21/51G06F21/53H04L9/14H04L9/30H04L9/3236H04L9/3242H04L9/3247H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,212
App. No.
17/069,436
Granted
Feb 28, 2023
Kind
B2
Abstract

A secure approval chain for runtime protection is disclosed. As an application or pod is developed in a pipeline, an approval engine ensures that the pod is approved by all approvers. The approval engine generates a deployment token that is added to the configuration data of the pod and that can be used at deployment to perform various security operations including pod verification, runtime environment control and enforcement, and pod or application verification.

Claims (28)

1. A method, comprising:

generating, by an approval engine, a security tuple for a pod that is passing through a pipeline, wherein the security tuple includes first fields that uniquely identify the pod;

generating a hash of the security tuple;

generating, by the approval engine, a deployment token that includes the hash of the security tuple and second fields;

cryptographically signing, by all of the approvers, the deployment token, wherein each of the approvers uses a private key to cryptographically sign the deployment token, wherein the approval engine is aware of all of the multiple approvers, requires all of the approvers to cryptographically sign the deployment token, and prevents any of the approvers from being bypassed;

adding, by the approval engine, the cryptographically signed deployment token to configuration data of the pod; and

executing a webhook when the pod is deployed to a runtime environment, wherein the webhook validates signatures of the approvers.

2. The method of claim 1 , further comprising cryptographically signing the deployment token with multiple private keys associated with corresponding to multiple approvers.

3. The method of claim 1 , further comprising the webhook generating a hash from the first fields and comparing the generated hash with the hash of the security tuple included in the deployment token, wherein the pod is rejected when the hashes do not match.

4. The method of claim 3 , further comprising validating conditions for the runtime environment, the conditions including a target platform identifier and target platform configurations.

5. The method of claim 4 , further comprising adding decryption data to the configuration information of the pod when the webhook validates the pod.

6. The method of claim 5 , further comprising node verification by providing the pod with decryption keys when the pod is valid and ensuring that only authorized pods operate in the runtime environment.

7. The method of claim 1 , further comprising verifying, all of the signatures using public keys of the approvers.

8. The method of claim 1 , further comprising deploying the pod to an approved runtime environment.

9. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

generating, by an approval engine, a security tuple for a pod that is passing through a pipeline, wherein the security tuple includes first fields that uniquely identify the pod;

generating a hash of the security tuple;

generating, by the approval engine, a deployment token that includes the hash of the security tuple and second fields;

cryptographically signing, by all of the approvers, the deployment token, wherein each of the approvers uses a private key to cryptographically sign the deployment token, wherein the approval engine is aware of all of the multiple approvers, requires all of the approvers to cryptographically sign the deployment token, and prevents any of the approvers from being bypassed;

adding, by the approval engine, the cryptographically signed deployment token to configuration data of the pod; and

executing a webhook when the pod is deployed to a runtime environment, wherein the webhook validates signatures of the approvers.

10. The non-transitory storage medium of claim 9 , further comprising cryptographically signing the deployment token with multiple private keys associated with corresponding to multiple approvers.

11. The non-transitory storage medium of claim 9 , further comprising the webhook generating a hash from the first fields and comparing the generated hash with the hash of the security tuple included in the deployment token, wherein the pod is rejected when the hashes do not match.

12. The non-transitory storage medium of claim 11 , further comprising validating conditions for the runtime environment, the conditions including a target platform identifier and target platform configurations.

13. The non-transitory storage medium of claim 12 , further comprising adding decryption data to the configuration information of the pod when the webhook validates the pod.

14. The non-transitory storage medium of claim 13 , further comprising node verification by providing the pod with decryption keys when the pod is valid and ensuring that only authorized pods operate in the runtime environment.

15. The non-transitory storage medium of claim 9 , further comprising verifying, all of the signatures using public keys of the approvers.

16. The non-transitory storage medium of claim 9 , further comprising deploying the pod to an approved runtime environment.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2020
From: WOLFSON, KFIR; SHEMER, JEHUDA; SAPIR, STAV; RADAMI, NAOR
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054041/0792 →