IP Library › Granted Patent US 12,730,661
Granted Patent B2
US 12,730,661 · App. 18/191,343 · Granted Sep 8, 2026

Secure sidecar container

Inventors: Peter Eberlein (Malsch, DE); Volker Driesen (Heidelberg, DE)
Assignee: SAP SE
G06F9/45558G06F8/63G06F9/547G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,661
App. No.
18/191,343
Granted
Sep 8, 2026
Kind
B2
Abstract

A secure side car (SSC) manager reads development artifacts and an application configuration file. Stubs and skeletons are created for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file. Main application code is compiled for the main application. An application container image is created for the main application and a SSC image for each of the one or more SSC library containers. An application container corresponding to the application container image and a SSC library container corresponding to each SSC image or each of the one or more SSC library containers is deployed. A service mesh proxy, which controls network access for libraries within each SSC library container, is configured.

Claims (41)

1 . A computer-implemented method, comprising:

reading, by a secure side car (SSC) manager, development artifacts and an application configuration file;

creating, by the SSC manager, stubs and skeletons for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file, wherein the stubs provide local application programming interfaces (APIs) for remote functionality implemented by libraries in the one or more SSC library containers, and wherein the stubs are configured to marshal API parameters and send the API parameters to the skeletons in the one or more SSC library containers;

compiling, by the SSC manager, main application code for the main application, wherein compiling comprises linking the created stubs to the main application code;

creating, by the SSC manager, an application container image for the main application and a SSC image for each of the one or more SSC library containers;

deploying, by the SSC manager, an application container corresponding to the application container image and a SSC library container corresponding to each SSC image for each of the one or more SSC library containers; and

configuring, by the SSC manager, a service mesh proxy, which controls network access for libraries within each SSC library container and is configured to enable container specific network filtering.

2 . The computer-implemented method of claim 1 , wherein the development artifacts include one or more of application coding for the main application, configuration, and which libraries the main application can use, and wherein the application configuration file contains one or more of a configuration for the one or more SSC library containers, which libraries are configured to run in the one or more SSC library containers, and allowed destinations for the one or more SSC library containers.

3 . The computer-implemented method of claim 1 , wherein the compiling, by the SSC manager, main application code for the main application comprises adding stubs for transparent remote calls to containerized libraries.

4 . The computer-implemented method of claim 1 , wherein the application container image for the main application and the SSC image for each of the one or more SSC library containers is stored in a container registry.

5 . The computer-implemented method of claim 1 , comprising checking desired locations to permit containerized libraries to access against a corporate policy repository of trusted destinations.

6 . The computer-implemented method of claim 1 , wherein default network access for a SSC library container is no outbound communication allowed, no inbound communication from outside the SSC library container, and communication only with the application container.

7 . The computer-implemented method of claim 1 , comprising providing reporting functionality with respect to each SSC library container and associated libraries.

8 . A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations, comprising:

reading, by a secure side car (SSC) manager, development artifacts and an application configuration file;

creating, by the SSC manager, stubs and skeletons for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file, wherein the stubs provide local application programming interfaces (APIs) for remote functionality implemented by libraries in the one or more SSC library containers, and wherein the stubs are configured to marshal API parameters and send the API parameters to the skeletons in the one or more SSC library containers;

compiling, by the SSC manager, main application code for the main application, wherein compiling comprises linking the created stubs to the main application code;

creating, by the SSC manager, an application container image for the main application and a SSC image for each of the one or more SSC library containers;

deploying, by the SSC manager, an application container corresponding to the application container image and a SSC library container corresponding to each SSC image for each of the one or more SSC library containers; and

configuring, by the SSC manager, a service mesh proxy, which controls network access for libraries within each SSC library container and is configured to enable container specific network filtering.

9 . The non-transitory, computer-readable medium of claim 8 , wherein the development artifacts include one or more of application coding for the main application, configuration, and which libraries the main application can use, and wherein the application configuration file contains one or more of a configuration for the one or more SSC library containers, which libraries are configured to run in the one or more SSC library containers, and allowed destinations for the one or more SSC library containers.

10 . The non-transitory, computer-readable medium of claim 8 , wherein the compiling, by the SSC manager, main application code for the main application comprises adding stubs for transparent remote calls to containerized libraries.

11 . The non-transitory, computer-readable medium of claim 8 , wherein the application container image for the main application and the SSC image for each of the one or more SSC library containers is stored in a container registry.

12 . The non-transitory, computer-readable medium of claim 8 , comprising checking desired locations to permit containerized libraries to access against a corporate policy repository of trusted destinations.

13 . The non-transitory, computer-readable medium of claim 8 , wherein default network access for a SSC library container is no outbound communication allowed, no inbound communication from outside the SSC library container, and communication only with the application container.

14 . The non-transitory, computer-readable medium of claim 8 , comprising providing reporting functionality with respect to each SSC library container and associated libraries.

15 . A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations, comprising:

reading, by a secure side car (SSC) manager, development artifacts and an application configuration file;

creating, by the SSC manager, stubs and skeletons for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file, wherein the stubs provide local application programming interfaces (APIs) for remote functionality implemented by libraries in the one or more SSC library containers, and wherein the stubs are configured to marshal API parameters and send the API parameters to the skeletons in the one or more SSC library containers;

compiling, by the SSC manager, main application code for the main application, wherein compiling comprises linking the created stubs to the main application code;

creating, by the SSC manager, an application container image for the main application and a SSC image for each of the one or more SSC library containers;

deploying, by the SSC manager, an application container corresponding to the application container image and a SSC library container corresponding to each SSC image for each of the one or more SSC library containers; and

configuring, by the SSC manager, a service mesh proxy, which controls network access for libraries within each SSC library container and is configured to enable container specific network filtering.

16 . The computer-implemented system of claim 15 , wherein the development artifacts include one or more of application coding for the main application, configuration, and which libraries the main application can use, and wherein the application configuration file contains one or more of a configuration for the one or more SSC library containers, which libraries are configured to run in the one or more SSC library containers, and allowed destinations for the one or more SSC library containers.

17 . The computer-implemented system of claim 15 , wherein the compiling, by the SSC manager, main application code for the main application comprises adding stubs for transparent remote calls to containerized libraries.

18 . The computer-implemented system of claim 15 , wherein the application container image for the main application and the SSC image for each of the one or more SSC library containers is stored in a container registry.

19 . The computer-implemented system of claim 15 , comprising checking desired locations to permit containerized libraries to access against a corporate policy repository of trusted destinations.

20 . The computer-implemented system of claim 15 , wherein default network access for a SSC library container is no outbound communication allowed, no inbound communication from outside the SSC library container, and communication only with the application container.

21 . The computer-implemented system of claim 15 , comprising providing reporting functionality with respect to each SSC library container and associated libraries.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2023
From: EBERLEIN, PETER; DRIESEN, VOLKER
To: SAP SE
Reel/Frame 063125/0571 →
Continuity (1)
Related Publication 20240330031A1 · Oct 3, 2024
References Cited (35)
US 8423954B2 · Ronen et al. · 2013 [cited by applicant]
US 8782676B2 · Dokovski et al. · 2014 [cited by applicant]
US 9558216B2 · Florendo et al. · 2017 [cited by applicant]
US 10387443B2 · Tran et al. · 2019 [cited by applicant]
US 10482080B2 · Auer et al. · 2019 [cited by applicant]
US 10671630B2 · Tran et al. · 2020 [cited by applicant]
US 10674438B2 · Bregler et al. · 2020 [cited by applicant]
US 10747528B2 · Tal · 2020 [cited by applicant]
US 10783485B2 · Yao et al. · 2020 [cited by applicant]
US 11030164B2 · Eberlein et al. · 2021 [cited by applicant]
US 11093443B2 · Bregler et al. · 2021 [cited by applicant]
US 11144871B2 · Yao et al. · 2021 [cited by applicant]
US 11188386B2 · Okman · 2021 [cited by applicant]
US 11275758B2 · Tran et al. · 2022 [cited by applicant]
US 11281767B2 · Suneja et al. · 2022 [cited by applicant]
US 11386062B2 · Ofenloch · 2022 [cited by applicant]
US 20130263139A1 · Schejter et al. · 2013 [cited by applicant]
US 20190205815A1 · Yao et al. · 2019 [cited by applicant]
US 20190294779A1 · Suneja et al. · 2019 [cited by applicant]
US 20210182251A1 · Eberlein et al. · 2021 [cited by applicant]
US 20210365405A1 · Bregler et al. · 2021 [cited by applicant]
US 20210400021A1 · Barton et al. · 2021 [cited by applicant]
US 20220050723A1 · Okman · 2022 [cited by applicant]
US 20220188285A1 · Ofenloch · 2022 [cited by applicant]
US 20220300611A1 · Sivaswamy · 2022 [cited by examiner]
US 20230125847A1 · Sato · 2023 [cited by examiner]
US 20230319044A1 · Warnicke · 2023 [cited by examiner]
US 20230385122A1 · Mehrotra · 2023 [cited by examiner]
US 20240291866A1 · Kaveri Poompatnam Chandrasekaran · 2024 [cited by examiner]
U.S. Appl. No. 16/688,941, Auer et al., filed Nov. 19, 2019. [cited by applicant]
Containiq.com [online], “Kubernetes Sidecar Container: Best Practices and Examples” Mar. 13, 2023, retrieved on Mar. 15, 2023, retrieved from URL <https://www.containiq.com/post/kubernetes-sidecar-container>, 8 pages. [cited by applicant]
Esecurityplanet.com [online], “Top 10 Container Security Solutions” Oct. 20, 2022, retrieved on Mar. 15, 2023, retrieved from URL <https://www.esecurityplanet.com/products/container-and-kubernetes-security-vendors/>, 14… [cited by applicant]
Jimmysong.io [online], “Understanding How Envoy Sidecar Intercept and Route Traffic in Istio Service Mesh” Dec. 27, 2018, retrieved on Mar. 15, 2023, retrieved from URL <https://jimmysong.io/en/blog/understanding-how-en… [cited by applicant]
Distributed Systems: Concepts and Design, 5th Edition, Pearson (ed), May 2011, 598 pages. [cited by applicant]
Extended European Search Report in European Appln. No. 23193813.5, mailed on Jan. 29, 2024, 9 pages. [cited by applicant]