IP Library Granted Patent US 11,461,084
Granted Patent B2
US 11,461,084 · App. 17/193,159 · Granted Oct 4, 2022

Optimizing docker image encryption—kubernetes using shamir secrets to enforce multiple constraints in container runtime environment

Inventors: Kfir Wolfson (Beer Sheva, IL); Jehuda Shemer (Kfar Saba, IL); Stav Sapir (Beer Sheba, IL); Naor Radami (Shokeda, IL)
Assignee: EMC IP HOLDING COMPANY LLC
G06F8/61G06F9/45558H04L9/085H04L9/0825G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,461,084
App. No.
17/193,159
Granted
Oct 4, 2022
Kind
B2
Abstract

One example method includes using a primary key to encrypt a decryption key, splitting the primary key into ‘n’ parts, where at least ‘k’ parts of the ‘n’ parts are required to restore the primary key, and ‘k’≤‘n’, storing some of the ‘k’ parts in respective locations in a production environment, and one of the stored ‘k’ parts is held by a verifier stage, receiving, at the verifier stage, a request for restoration of the primary key, where the request is received from a deployment pod and the request includes a subset of the ‘k’ parts and the encrypted decryption key, performing, by the verifier stage, a validation process concerning the deployment pod, and restoring, by the verifier stage, the primary key, wherein the primary key is restored using the ‘k’ part held by the verifier stage.

Claims (34)

1. A method, comprising:

using a primary key to encrypt a decryption key;

splitting the primary key into ‘n’ parts, where at least ‘k’ parts of the ‘n’ parts are required in order to restore the primary key, and ‘k’=‘n’;

storing some of the ‘k’ parts in different respective locations in a production environment, and one of the ‘k’ parts that is stored is held by a verifier stage;

receiving, at the verifier stage, a request for restoration of the primary key, where the request is received from a deployment pod and the request includes a subset of the ‘k’ parts and the encrypted decryption key;

performing, by the verifier stage, a validation process concerning the deployment pod;

upon successful validation of the deployment pod, restoring, by the verifier stage, the primary key, wherein the primary key is restored using the ‘k’ part held by the verifier stage, and using the subset of the ‘k’ parts received from the deployment pod; and

using, by the verifier stage, the restored primary key to decrypt the encrypted decryption key received from the deployment pod.

2. The method as recited in claim 1 , further comprising transmitting, by the verifier stage, the decrypted decryption key to the deployment pod.

3. The method as recited in claim 2 , further comprising using, by the deployment pod, the decryption key received from the verifier stage to decrypt sensitive content needed to run a container that is included in the deployment pod.

4. The method as recited in claim 1 , further comprising verifying information in a deployment manifest associated with the deployment pod and, upon successful verifying, adding one of the parts of the subset of ‘k’ parts to the deployment manifest, and transmitting the deployment manifest to a deployment controller.

5. The method as recited in claim 1 , further comprising encrypting sensitive content of a container using an encryption key, and the encryption key serves as the decryption key that is encrypted using the primary key.

6. The method as recited in claim 1 , wherein the primary key is not restored by the verifier stage unless the deployment pod is validated.

7. The method as recited in claim 1 , wherein the method is performed in a production environment, and one of the parts in the subset of ‘k’ parts is provided at least indirectly to the deployment pod by an entity outside of the production environment.

8. The method as recited in claim 1 , wherein one of the parts in the subset of ‘k’ parts is provided at least indirectly to the deployment pod by a deployment verification service.

9. The method as recited in claim 1 , wherein the decryption key received by the deployment pod is not stored anywhere.

10. The method as recited in claim 1 , wherein the parts of the primary key are never all transmitted together.

11. A computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

using a primary key to encrypt a decryption key;

splitting the primary key into ‘n’ parts, where at least ‘k’ parts of the ‘n’ parts are required in order to restore the primary key, and ‘k’=‘n’;

storing some of the ‘k’ parts in different respective locations in a production environment, and one of the ‘k’ parts that is stored is held by a verifier stage;

receiving, at the verifier stage, a request for restoration of the primary key, where the request is received from a deployment pod and the request includes a subset of the ‘k’ parts and the encrypted decryption key;

performing, by the verifier stage, a validation process concerning the deployment pod;

upon successful validation of the deployment pod, restoring, by the verifier stage, the primary key, wherein the primary key is restored using the ‘k’ part held by the verifier stage, and using the subset of the ‘k’ parts received from the deployment pod; and

using, by the verifier stage, the restored primary key to decrypt the encrypted decryption key received from the deployment pod.

12. The computer readable storage medium as recited in claim 11 , wherein the operations further comprise transmitting, by the verifier stage, the decrypted decryption key to the deployment pod.

13. The computer readable storage medium as recited in claim 12 , wherein the operations further comprise using, by the deployment pod, the decryption key received from the verifier stage to decrypt sensitive content needed to run a container that is included in the deployment pod.

14. The computer readable storage medium as recited in claim 11 , wherein the operations further comprise verifying information in a deployment manifest associated with the deployment pod and, upon successful verifying, adding one of the parts of the subset of ‘k’ parts to the deployment manifest, and transmitting the deployment manifest to a deployment controller.

15. The computer readable storage medium as recited in claim 11 , wherein the operations further comprise encrypting sensitive content of a container using an encryption key, and the encryption key serves as the decryption key that is encrypted using the primary key.

16. The computer readable storage medium as recited in claim 11 , wherein the primary key is not restored by the verifier stage unless the deployment pod is validated.

17. The computer readable storage medium as recited in claim 11 , wherein the computer readable storage medium is performed in a production environment, and one of the parts in the subset of ‘k’ parts is provided at least indirectly to the deployment pod by an entity outside of the production environment.

18. The computer readable storage medium as recited in claim 11 , wherein one of the parts in the subset of ‘k’ parts is provided at least indirectly to the deployment pod by a deployment verification service.

19. The computer readable storage medium as recited in claim 11 , wherein the decryption key received by the deployment pod is not stored anywhere.

20. The computer readable storage medium as recited in claim 11 , wherein the parts of the primary key are never all transmitted together.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME ON THE COVERSHEET NEEDS TO BE CORRECTED TO EMC IP HOLDING COMPANY LLC ISTEAD OF EMC IP HOLDING COMPANY PREVIOUSLY RECORDED AT REEL: 059336 FRAME: 0005. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 29, 2022
From: WOLFSON, KFIR; SHEMER, JEHUDA; SAPIR, STAV; RADAMI, NAOR
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 061005/0839 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: WOLFSON, KFIR; SHEMER, JEHUDA; SAPIR, STAV; RADAMI, NAOR
To: EMC IP HOLDING COMPANY
Reel/Frame 059336/0005 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
Cited By (1)
US 12,437,084