IP Library › Granted Patent US 10,498,726
Granted Patent B2
US 10,498,726 · App. 15/076,883 · Granted Dec 3, 2019

Container independent secure file system for security application containers

Inventors: Charles W. Cross, Jr. (Wellington, FL); Victor S. Moore (Gainesville, FL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/0853G06F21/62H04L63/0435G06F9/455G06F21/6209H04L63/061H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,498,726
App. No.
15/076,883
Granted
Dec 3, 2019
Kind
B2
Abstract

Embodiments include method, systems and computer program products for a container independent secure file system for security application containers. In some embodiments, a request for a virtualized application container may be received. A passphrase may be obtained from a user. A key may be obtained. A files system of the virtualized application container may be prepared for a specified mount point using the passphrase and key. The file system may be initiated in response to the request.

Claims (34)

1. A computer-implemented method comprising:

receiving a request for a virtualized application container;

obtaining, via a user device, a passphrase from a user;

obtaining a key from a key management server using a universal unique identifier (UUID), wherein the UUID corresponds to the passphrase from the user;

preparing a file system of the virtualized application container for a specified mount point determined based on the passphrase and the key, wherein the specified mount point determines which applications and plugins are available in the virtualized application container; and

initiating the file system in response to the request, wherein preparing the file system includes encrypting the file system is based on the UUID.

2. The computer-implemented method of claim 1 , wherein the file system of the virtualized application container is associated with an encrypted virtual disk image.

3. The computer-implemented method of claim 1 , wherein the file system of the virtualized application container is associated with an encrypted directory.

4. The computer-implemented method of claim 1 , wherein preparing the file system further comprises:

applying a two-factor encryption to the file system using the passphrase and the key.

5. The computer-implemented method of claim 1 , wherein the key is stored on a secure element of a host device which is separate from a central processing unit of the host device.

6. A computer program product comprising a non-transitory storage medium readable by a processing circuit and storing instructions for execution by the processing circuit for performing a method comprising:

receiving a request for a virtualized application container;

obtaining, via a user device, a passphrase from a user;

obtaining a key from a key management server using a universal unique identifier (UUID), wherein the UUID corresponds to the passphrase from the user;

preparing a file system of the virtualized application container for a specified mount point determined based on the passphrase and the key, wherein the specified mount point determines which applications and plugins are available in the virtualized application container; and

initiating the file system in response to the request,

wherein preparing the file system includes encrypting the file system is based on the UUID.

7. The computer program product of claim 6 , wherein the file system of the virtualized application container is associated with an encrypted virtual disk image.

8. The computer program product of claim 6 , wherein the file system of the virtualized application container is associated with an encrypted directory.

9. The computer program product of claim 6 , wherein preparing the file system further comprises:

applying a two-factor encryption to the file system using the passphrase and the key.

10. A system, comprising:

a hardware processor in communication with one or more types of memory, the processor configured to:

receive a request for a virtualized application container;

obtain, via a user device, a passphrase from a user;

obtain a key from a key management server using a universal unique identifier (UUID), wherein the UUID corresponds to the passphrase from the user;

prepare a file system of the virtualized application container for a specified mount point determined based on the passphrase and the key, wherein the specified mount point determines which applications and plugins are available in the virtualized application container; and

initiate the file system in response to the request,

wherein preparing the file system includes encrypting the file system is based on the UUID.

11. The system of claim 10 , wherein the file system of the virtualized application container is associated with an encrypted virtual disk image.

12. The system of claim 10 , wherein the file system of the virtualized application container is associated with an encrypted directory.

13. The system of claim 10 , wherein, to prepare the file system, the processor is further configured to:

apply a two-factor encryption to the file system using the passphrase and the key.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE FIRST INVENTOR'S NAME TO CHARLES W. CROSS JR. PREVIOUSLY RECORDED ON REEL 038100 FRAME 0053. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 4, 2016
From: CROSS, CHARLES W., JR.; MOORE, VICTOR S.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 040220/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2016
From: CROSS, CHARLES W.; MOORE, VICTOR S.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038100/0053 →
Continuity (1)
Related Publication 20170279797A1 · Sep 28, 2017