IP Library Granted Patent US 12,386,608
Granted Patent B2
US 12,386,608 · App. 18/526,917 · Granted Aug 12, 2025

Boot and update from runtime merged image fragments

Inventors: Matthaus Alden Wesemann (Redmond, WA); Hakki Tunc Bostanci (Redmond, WA); Aaron Farmer (Seattle, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F8/656G06F8/66G06F9/4408H04L67/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,608
App. No.
18/526,917
Granted
Aug 12, 2025
Kind
B2
Abstract

A feature is updated on a computing device. One or more composite image files are accessed that correspond to updates to be implemented in the computing device. The composite image files are signed containers. A runtime in-memory merge of the composite image files is performed. The merged composite image files are exposed as a read-only volume. The features are made available to the computing device. A system boot using the read-only volume can be initiated.

Claims (37)

1. A computer-implemented method for updating an operating system of a computing device, the method comprising:

determining an update that is to be implemented in the operating system;

accessing a plurality of composite image files that correspond to the update, each of the composite image files comprising an image fragment of a set of image fragments that collectively form a complete operating system image, wherein the composite image files are included in a signed container containing files for implementing the update to the operating system;

merging the image fragments on the computing device; and

initiating a system boot of the computing device using the merged image fragments.

2. The computer-implemented method of claim 1 , wherein the merging comprises performing an in-memory merge.

3. The computer-implemented method of claim 1 , wherein a layout of the composite image files comprises a root file, a metadata region, and one or more data regions.

4. The computer-implemented method of claim 3 , wherein the one or more data regions include a small data region and a data region.

5. The computer-implemented method of claim 4 , wherein the small data region is for file content that is less than a predetermined size, and the data region is for file content that meets or exceeds the predetermined size.

6. The computer-implemented method of claim 5 , wherein the data region is aligned with a start of each region to a page size.

7. The computer-implemented method of claim 1 , wherein the signed container includes data to track what directory or key is associated with security for the signed container.

8. The computer-implemented method of claim 1 , wherein the composite image files are processed as individual packages prior to delivery to the computing device.

9. The computer-implemented method of claim 1 , further comprising storing modifications to the operating system defined by the composite image files as a read-write layer.

10. The computer-implemented method of claim 1 , further comprising exposing the merged image fragments as a read-only volume, wherein the system boot is initiated using the read-only volume.

11. A system comprising:

one or more processors;

a memory in communication with the one or more processors, the memory having computer-readable instructions stored thereupon which, when executed by the one or more processors, cause the system to perform operations comprising:

determining an operating system update that is to be implemented in a computing device;

accessing a plurality of files and data associated with the operating system update;

generating a plurality of image fragments for implementing the operating system update, the image fragments collectively forming a complete operating system image, wherein the image fragments are combinable at the computing device by merging the image fragments; and

sending the plurality of image fragments to the computing device.

12. The system of claim 11 , wherein a layout of the plurality of image fragments comprises a root file, a metadata region, and one or more data regions.

13. The system of claim 12 , wherein:

the one or more data regions include a small data region and a data region;

the small data region is for file content that is less than a predetermined size;

the data region is for file content that meets or exceeds the predetermined size; and

the data region is aligned with a start of each region to a page size.

14. The system of claim 11 , wherein the merging comprises a runtime in-memory merge of the image fragments.

15. The system of claim 11 , wherein the image fragments are included in a signed container.

16. A computer-readable medium having encoded thereon computer-executable instructions that, when executed, cause one or more processing units of a computing device to execute operations comprising:

accessing a plurality of image fragments that correspond to an update that is to be implemented in the computing device, the image fragments collectively forming a complete operating system image;

merging the image fragments; and

initiating a system boot using the merged image fragments.

17. The computer-readable medium of claim 16 , wherein the merging comprises performing a runtime in-memory merge of the image fragments.

18. The computer-readable medium of claim 16 , wherein the plurality of image fragments are included in a signed container.

19. The computer-readable medium of claim 16 , wherein the merged image fragments are exposed as a read-only volume, and the system boot is initiated using the read-only volume.

20. The computer-readable medium of claim 16 , wherein the image fragments are processed as individual packages prior to delivery to the computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2023
From: WESEMANN, MATTHAUS ALDEN; BOSTANCI, HAKKI TUNC; FARMER, AARON
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 065738/0420 →
Continuity (2)
Continuation 17527067 · Nov 15, 2021
Related Publication 20240211247A1 · Jun 27, 2024
References Cited (12)
US 5732275A · Kullick · 1998 [cited by examiner]
US 10175970B2 · Li · 2019 [cited by examiner]
US 10863239B2 · Anderson · 2020 [cited by examiner]
US 10936296B2 · Mitra · 2021 [cited by examiner]
US 20010014968A1 · Mohammed · 2001 [cited by examiner]
US 20190069027A1 · Anderson · 2019 [cited by examiner]
Kubiatowicz, John, et al. “Oceanstore: An architecture for global-scale persistent storage.” ACM SIGOPS Operating Systems Review 34.5 (2000): pp. 190-201. (Year: 2000). [cited by examiner]
Kreutz, Diego, Fernando MV Ramos, and Paulo Verissimo. “Towards secure and dependable software-defined networks.” Proceedings of the second ACM SIGCOMM workshop on Hot topics in software defined networking. 2013. pp. 50… [cited by examiner]
Wetherall, David J., John V. Guttag, and David L. Tennenhouse. “ANTS: A toolkit for building and dynamically deploying network protocols.” 1998 IEEE Open Architectures and Network Programming. IEEE, 1998.pp. 117-129. (Y… [cited by examiner]
Linden, Theodore A. “Operating system structures to support security and reliable software.” ACM Computing Surveys (CSUR) 8.4 (1976): pp. 409-455. (Year: 1976). [cited by examiner]
Neamtiu, Iulian, et al. “Practival dynamic software updating for C.” ACM SIGPLAN Notices 41.6 (2006): 72-83. (Year: 2006). [cited by examiner]
Chen, Daming D., et al. “Towards automated dynamic analysis for linux-based embedded firmware.” NDSS. vol. 1. 2016. pp. 1-16 (Year: 2016). [cited by examiner]