IP Library Granted Patent US 11,991,155
Granted Patent B2
US 11,991,155 · App. 17/184,364 · Granted May 21, 2024

Methods and systems for securing containerized applications

Inventors: William Rodgers Ackerly (Washington, DC); Julian Embry Herwitz (Arlington, VA); Timothy Robert Tschampel (Reston, VA)
Assignee: Virtru Corporation
H04L63/0428H04L9/085H04L9/3268H04L63/10H04L67/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,991,155
App. No.
17/184,364
Granted
May 21, 2024
Kind
B2
Abstract

A method for securing data access by containerized applications includes intercepting, by a first container executing on a first computing device and associated with a containerized application in a second container executing on the first computing device, a first Internet Protocol (IP) request from the containerized application. The first container determines that the IP request is addressed to a second computing device executing a resource that the containerized application is authorized to access. The first container encrypts a payload portion of the IP request and transmits, to the resource, a second IP request with the encrypted payload portion. The first container receives, from the resource, a response. The first container requests, from a third computing device, a cryptographic key for decrypting the response. The first container decrypts, with the cryptographic key, a payload portion of the response and transmits, to the containerized application, the decrypted payload portion of the response.

Claims (31)

1. A method for securing data access by containerized applications, the method comprising:

intercepting, by a first container executing on a first computing device and associated with a containerized application in a second container executing on the first computing device, a first Internet Protocol (IP) request from the containerized application;

determining, by the first container, that the first IP request is addressed to a second computing device executing a resource that the containerized application is authorized to access;

encrypting, by the first container, a payload portion of the first IP request;

transmitting, by the first container, to the resource, a second IP request with the encrypted payload portion;

receiving, by the first container, from the resource, a response to the second IP request;

requesting, by the first container, from a third computing device, a cryptographic key for decrypting the response to the second IP request;

decrypting, by the first container, with the cryptographic key, a payload portion of the response; and

transmitting, by the first container, to the containerized application, the decrypted payload portion of the response.

2. The method of claim 1 further comprising providing, by the first container, an attestation certificate to the third computing device with the request for the cryptographic key.

3. The method of claim 1 further comprising providing, by the first container, a shared secret to a third computing device with the request for the cryptographic key.

4. The method of claim 1 further comprising:

receiving, by the first container, a first signature associated with the containerized application;

accessing, by the first container, a registry of containerized applications, the registry including a second signature for the containerized application;

determining, by the first container, whether the first signature and the second signature satisfy a threshold level of similarity; and

attesting, by the first container, to the resource, a level of validity of the containerized application making the first IP request.

5. A method for securing data transmission by containerized applications, the method comprising:

intercepting, by a first container executing on a first computing device and associated with a containerized application in a second container executing on the first computing device, a first Internet Protocol (IP) request from the containerized application, the request including a request to transmit data to a second computing device;

determining, by the first container, that the containerized application is authorized to access a resource executed by the second computing device;

encrypting, by the first container, a payload portion of the IP request; and

transmitting, by the first container, to the resource, a second IP request with the encrypted payload portion.

6. A system for securing data transmission by containerized applications comprising:

a first computing device executing a first container and a second container, the first container associated with a containerized application in the second container, the first container further comprising:

means for intercepting a first Internet Protocol (IP) request from the containerized application;

means for determining that the first IP request is addressed to a second computing device executing a resource that the containerized application is authorized to access;

means for encrypting a payload portion of the first IP request;

means for transmitting, to the resource, a second IP request with the encrypted payload portion;

means for receiving, from the resource, a response to the second IP request;

means for requesting, from a third computing device, a cryptographic key for decrypting the response to the second IP request;

means for decrypting, with the cryptographic key, a payload portion of the response; and

means for transmitting, to the containerized application, the decrypted payload portion of the response.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Feb 7, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: VIRTRU CORPORATION
Reel/Frame 066412/0348 →
SECURITY INTEREST Recorded Feb 6, 2024
From: VIRTRU CORPORATION
To: STIFEL BANK
Reel/Frame 066398/0565 →
SECURITY INTEREST Recorded Oct 6, 2021
From: VIRTRU CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 057718/0099 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2021
From: ACKERLY, WILLIAM RODGERS; HERWITZ, JULIAN EMBRY; TSCHAMPEL, TIMOTHY ROBERT
To: VIRTRU CORPORATION
Reel/Frame 055591/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2021
From: ACKERLY, WILLIAM RODGERS; HERWITZ, JULIAN EMBRY; TSCHAMPEL, TIMOTHY ROBERT
To: VIRTRU CORPORATION
Reel/Frame 055591/0322 →
Continuity (3)
Provisional Application 63046182 · Jun 30, 2020
Provisional Application 62982313 · Feb 27, 2020
Related Publication 20210281548A1 · Sep 9, 2021
Cited By (1)
US 12,411,973