IP Library Granted Patent US 11,675,913
Granted Patent B2
US 11,675,913 · App. 17/025,324 · Granted Jun 13, 2023

Optimizing container image encryption

Inventors: Kfir Wolfson (Beer Sheva, IL); Jehuda Shemer (Kfar Saba, IL); Stav Sapir (Beer Sheva, IL); Amos Zamir (Beer Sheva, IL); Naor Radami (Shokeda, IL)
Assignee: EMC IP HOLDING COMPANY LLC
G06F21/602G06F9/45545G06F21/629G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,675,913
App. No.
17/025,324
Granted
Jun 13, 2023
Kind
B2
Abstract

One example method includes packaging a containerized application into at least two images. The first image may include the main application and the second image includes a decryptor. Sensitive information associated with the application is encrypted and included in the second image. The decryptor operates separately from the main application. After the decryptor successfully completes, the main application is run. The main application may include a copier layer to copy any data decrypted by the decryptor into the main application.

Claims (26)

1. A method, comprising:

packaging an application that is associated with sensitive data into at least a first image and a second image by placing first layers in the first image, the first layers including a copier layer configured to perform copying and by placing second layers in the second image, wherein the second layers include a decryptor layer configured to perform decryption and an encrypted layer that includes the sensitive data in an encrypted form;

configuring the second image to run before the first image;

running the second image as an initialization container and running the first image as a main container after the initialization container, wherein execution of the initialization container includes decrypting, by the decryptor, the encrypted layer to obtain decrypted sensitive data; and

running the copier layer, wherein the copier layer copies the decrypted sensitive data.

2. The method of claim 1 , further comprising storing the decrypted sensitive data in a directory of a filesystem.

3. The method of claim 2 , further comprising running the first image as the main container after the initialization container successfully completes.

4. The method of claim 3 , further comprising running the copier layer, wherein the copier layer copies the decrypted sensitive data in the directory to a location in a layer root directory associated with the main container, which includes a main application.

5. The method of claim 1 , further comprising generating a pod specification such that the second image runs and completes before the first image is run.

6. The method of claim 1 , further comprising generating the encrypted layer by encrypting one or more sensitive layers of the sensitive data.

7. The method of claim 1 , wherein packaging the application includes dividing an image into the first image and the second image or constructing a command file for the first image and a command file for the second image.

8. The method of claim 7 , further comprising placing the decryptor layer in the second image such that the decryptor layer in the second image is not dependent on an operating system included in the first image.

9. The method of claim 1 , further comprising creating the first image and the second image.

10. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

packaging an application that is associated with sensitive data into at least a first image and a second image by placing first layers in the first image, the first layers including a copier layer configured to perform copying and by placing second layers in the second image, wherein the second layers include a decryptor layer configured to perform decryption and an encrypted layer that includes the sensitive data in an encrypted form;

configuring the second image to run before the first image;

running the second image as an initialization container and running the first image as a main container after the initialization container, wherein execution of the initialization container includes decrypting, by the decryptor, the encrypted layer to obtain decrypted sensitive data; and

running the copier layer, wherein the copier layer copies the decrypted sensitive data.

11. The non-transitory storage medium of claim 10 , further comprising storing the decrypted sensitive data in a directory of a filesystem.

12. The non-transitory storage medium of claim 11 , further comprising running the first image as the main container after the initialization container successfully completes.

13. The non-transitory storage medium of claim 12 , further comprising running the copier layer, wherein the copier layer copies the decrypted sensitive data to a location in a layer root directory associated with the main container, which includes a main application.

14. The non-transitory storage medium of claim 10 , further comprising generating a pod specification such that the second image runs and completes before the first image is run.

15. The non-transitory storage medium of claim 10 , further comprising generating the encrypted layer by encrypting one or more sensitive layers of the sensitive data.

16. The non-transitory storage medium of claim 10 , wherein packaging the application includes dividing an image into the first image and the second image or constructing a command file for the first image and a command file for the second image.

17. The non-transitory storage medium of claim 16 , further comprising placing the decryptor layer in the second image such that the decryptor layer in the second image is not dependent on an operating system included in the first image.

18. The non-transitory storage medium of claim 10 , the second image including a signal layer and a stop-signal layer that identify a location of the encrypted layer in the second image.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2020
From: WOLFSON, KFIR; SHEMER, JEHUDA; SAPIR, STAV; ZAMIR, AMOS; RADAMI, NAOR
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 053817/0761 →