IP Library Granted Patent US 12,277,213
Granted Patent B2
US 12,277,213 · App. 17/922,194 · Granted Apr 15, 2025

Method and device for securely starting up a container instance

Inventors: Christian Peter Feist (Munich, DE); Christian Knierim (Munich, DE)
Assignee: SIEMENS AKTIENGESELLSCHAFT
G06F21/53G06F21/32G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,277,213
App. No.
17/922,194
Filed
Oct 28, 2022
Granted
Apr 15, 2025
Kind
B2
Art Unit
2435
USPC
726/26
Abstract

A method for securely starting up a container instance in one or more execution environments for one or more components of a technical installation, such an execution environment being designed to execute the container instance includes the following method steps: a) providing a configurable check function that is performed before and/or while starting up the container instance, b) logging each step for preparing at least one execution limitation required for starting up and/or executing the container instance, c) checking each logged step using at least one permissibility criterion configured in the check function, and d) completing the startup and if necessary the execution of the container instance if the at least one permissibility criterion is satisfied, or e) initiating an alerting measure or a measure that counteracts the startup if at least one of the possible permissibility criteria is not satisfied.

Claims (21)

1. A method for securely starting up a container instance in one or more execution environments for one or more components of a technical installation, such an execution environment being designed to execute the container instance, the method comprising:

a) providing a configurable check function that is performed before and/or while starting up the container instance;

b) logging each step for preparing at least one execution limitation required for starting up and/or executing the container instance;

c) checking each logged step using at least one permissibility criterion configured in the check function, wherein the at least one permissibility criterion is a rights signature to be fulfilled; and

d) completing a startup and if necessary the execution of the container instance, in response to the at least one permissibility criterion being satisfied, or

e) initiating an alerting measure or a measure that counteracts the startup in response to at the least one permissibility criteria not being satisfied.

2. The method as claimed in claim 1 , wherein steps c) to e) are repeated as required, on an event-controlled basis and/or on a time-controlled basis while executing the container instance.

3. The method as claimed in claim 1 , wherein a respective hash value is determined and logged for each execution limitation.

4. The method as claimed in claim 1 , wherein all the determined hash values are combined with one another in each such step to form a total value, and a total value and a change therein that arises with each step are logged.

5. The method as claimed in claim 4 , wherein the total value is representable or is represented by a fingerprint.

6. The method as claimed in claim 4 , wherein the total value is compared with the corresponding configured permissibility criterion.

7. The method as claimed in claim 1 , wherein besides the at least one execution limitation one or more environment parameters of the execution environment are also logged and are concurrently taken into consideration when forming a total value.

8. A device for securely starting up a container instance in one or more execution environments for one or more components of a technical installation, such an execution environment being designed to execute the container instance, the device comprising:

a processor coupled to a memory, the processor configured to:

a) provide a configurable check function before and/or while starting up the container instance;

b) log each step for preparing at least one execution limitation required for starting up and/or executing the container instance;

c) compare each logged step with a permissibility criterion configured in the check function, wherein the permissibility criterion is a rights signature to be fulfilled; and

d) complete a startup and if necessary the execution of the container instance, in response to the permissibility criterion being satisfied, or

e) initiate an alerting measure and/or a measure that counteracts the startup, in response to the possible permissibility criteria not being satisfied.

9. The device as claimed in claim 8 , wherein the memory is internally integrated or an externally linked to the processor of the device.

10. A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method as claimed in claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2023
From: FEIST, CHRISTIAN PETER; KNIERIM, CHRISTIAN
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 063245/0728 →
Priority Claims (1)
EP 20172838 · May 5, 2020 · regional
Continuity (1)
Related Publication 20230161867A1 · May 25, 2023
References Cited (26)
US 10146936B1 · Khanduja · 2018 [cited by applicant]
US 11423140B1 · Abdulhayoglu · 2022 [cited by examiner]
US 11573814B1 · Aithal · 2023 [cited by examiner]
US 11734418B1 · Epstein · 2023 [cited by examiner]
US 11775331B1 · Wilkinson · 2023 [cited by examiner]
US 11941426B1 · Melkild · 2024 [cited by examiner]
US 20110202313A1 · Wilson · 2011 [cited by examiner]
US 20160274928A1 · Linton · 2016 [cited by examiner]
US 20200389416A1 · Sharifi Mehr · 2020 [cited by examiner]
US 20210334377A1 · Drori · 2021 [cited by examiner]
US 20220197689A1 · Hotinger · 2022 [cited by examiner]
US 20220215088A1 · Kosaka · 2022 [cited by examiner]
US 20220237007A1 · Bleve · 2022 [cited by examiner]
US 20220382874A1 · Kumar · 2022 [cited by examiner]
US 20220391238A1 · Wagner · 2022 [cited by examiner]
US 20220413936A1 · Elliott · 2022 [cited by examiner]
US 20230006988A1 · Menth · 2023 [cited by examiner]
US 20230090689A1 · Knierim · 2023 [cited by examiner]
US 20230252163A1 · Stopel · 2023 [cited by examiner]
US 20230289176A1 · Myers · 2023 [cited by examiner]
US 20230325492A1 · Michalevsky · 2023 [cited by examiner]
US 20230412628A1 · Huang · 2023 [cited by examiner]
US 20240111659A1 · Reisinger · 2024 [cited by examiner]
CN 108733455A · 2018 [cited by applicant]
EP 3557463A1 · 2019 [cited by applicant]
PCT International Search Report and Written Opinion of International Searching Authority mailed Jun. 9, 2021 corresponding to PCT International Application No. PCT/EP2021/060939 filed Apr. 27, 2021. [cited by applicant]