IP Library › Granted Patent US 12,437,084
Granted Patent B2
US 12,437,084 · App. 18/075,503 · Granted Oct 7, 2025

System and method of hiding security sensitive features in untrusted environments

Inventors: Juelong Yin (Shanghai, CN); Hao Wang (Shanghai, CN); Dmitry Vladimirovich Krivenok (Dublin, IE); Chaowen Han (Shanghai, CN)
Assignee: Dell Products L.P.
G06F21/602G06F21/54G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,084
App. No.
18/075,503
Granted
Oct 7, 2025
Kind
B2
Abstract

Techniques for hiding security-sensitive features in untrusted environments. The techniques include inserting, in a development build image, one or more security-sensitive scripts encrypted with a unique encryption key for the development build image, and inserting, in a release build image, the security-sensitive scripts encrypted with a different unique encryption key for the release build image. The techniques further include saving the unique encryption key for the development build image in an artifact repository, and securely deleting the different unique encryption key for the release build image. In this way, user access to certain software code or scripts, device files, and/or other security-sensitive features can be restricted in a manner that is more user friendly to software development and/or information technology (or “DevOps”) engineers.

Claims (72)

1. A method comprising:

performing a plurality of software build processes including a process of a pre-release version of a software build, and a process of a release version of the software build,

the process of the pre-release version of the software build comprising:

generating a pre-release version of a software build image;

generating a security-sensitive script, a first encryption key, and specified software components;

encrypting the security-sensitive script with the first encryption key, the specified software components being unencrypted;

inserting the security-sensitive script encrypted with the first encryption key, and the unencrypted specified software components, into the pre-release version of the software build image; and

saving and storing the first encryption key to allow decryption of the encrypted security-sensitive script inserted into the pre-release version of the software build image during testing of the pre-release version of the software build image; and

the process of the release version of the software build comprising:

generating a release version of the software build image;

generating a second encryption key, the second encryption key being different from the first encryption key such that each of the pre-release version of the software build image and the release version of the software build image has its own unique encryption key for encrypting the security-sensitive script;

encrypting the security-sensitive script with the second encryption key;

inserting the security-sensitive script encrypted with the second encryption key, and the unencrypted specified software components, into the release version of the software build image; and

securely deleting the second encryption key to prevent decryption of the encrypted security-sensitive script inserted into the release version of the software build image after releasing the release version of the software build image as a final product.

2. The method of claim 1 wherein encrypting the security-sensitive script with the first encryption key includes encrypting the security-sensitive script using one of a first encryption technique and a second encryption technique, the second encryption technique being different from the first encryption technique.

3. The method of claim 2 wherein encrypting the security-sensitive script with the second encryption key includes encrypting the security-sensitive script using the one of the first encryption technique and the second encryption technique.

4. The method of claim 3 further comprising:

implementing the first encryption technique as a symmetric encryption technique; and

implementing the second encryption technique as an asymmetric encryption technique.

5. The method of claim 1 further comprising:

deploying the pre-release version of the software build image to be executed on a storage system in a development and test environment.

6. The method of claim 5 further comprising:

sending, in a deployment package, the first encryption key for the pre-release version of the software build image to the storage system in the development and test environment,

wherein the first encryption key is detected by the storage system in the deployment package,

wherein the security-sensitive script inserted into the pre-release version of the software build image is decrypted by the storage system with the first encryption key, and

wherein, in response to decryption of the security-sensitive script inserted into the pre-release version of the software build image being successful, the security-sensitive script is executed by the storage system.

7. A system comprising:

a memory; and

processing circuitry configured to execute program instructions out of the memory to:

perform a plurality of software build processes including a process of a pre-release version of a software build, and a process of a release version of the software build,

the process of the pre-release version of the software build comprising:

generating a pre-release version of a software build image;

generating a security-sensitive script, a first encryption key, and specified software components;

encrypting the security-sensitive script with the first encryption key, the specified software components being unencrypted;

inserting the security-sensitive script encrypted with the first encryption key, and the unencrypted specified software components, into the pre-release version of the software build image; and

saving and storing the first encryption key to allow decryption of the encrypted security-sensitive script inserted into the pre-release version of the software build image during testing of the pre-release version of the software build image; and

the process of the release version of the software build comprising:

generating a release version of the software build image;

generating a second encryption key, the second encryption key being different from the first encryption key such that each of the pre-release version of the software build image and the release version of the software build image has its own unique encryption key for encrypting the security-sensitive script;

encrypting the security-sensitive script with the second encryption key;

inserting the security-sensitive script encrypted with the second encryption key, and the unencrypted specified software components, into the release version of the software build image; and

securely deleting the second encryption key to prevent decryption of the encrypted security-sensitive script inserted into the release version of the software build image after releasing the release version of the software build image as a final product.

8. The system of claim 7 wherein the processing circuitry is further configured to execute the program instructions out of the memory to encrypt the security-sensitive script with the first encryption key using one of a first encryption technique and a second encryption technique, the second encryption technique being different from the first encryption technique.

9. The system of claim 8 wherein the processing circuitry is further configured to execute the program instructions out of the memory to encrypt the security-sensitive script with the second encryption key using the one of the first encryption technique and the second encryption technique.

10. The system of claim 9 wherein the first encryption technique is implemented as a symmetric encryption technique, and wherein the second encryption technique is implemented as an asymmetric encryption technique.

11. The system of claim 7 wherein the processing circuitry is further configured to execute the program instructions out of the memory to deploy the pre-release version of the software build image to be executed on a storage system in a development and test environment.

12. The system of claim 11 wherein the processing circuitry is further configured to execute the program instructions out of the memory to send, in a deployment package, the first encryption key for the pre-release version of the software build image to the storage system in the development and test environment, wherein the first encryption key is detected by the storage system in the deployment package, wherein the security-sensitive script inserted into the pre-release version of the software build image is decrypted by the storage system with the first encryption key, and wherein, in response to decryption of the security-sensitive script inserted into the pre-release version of the software build image being successful, the security-sensitive script is executed by the storage system.

13. A computer program product including a set of non-transitory, computer-readable media having instructions that, when executed by processing circuitry, cause the processing circuitry to perform a method comprising:

performing a plurality of software build processes including a process of a pre-release version of a software build, and a process of a release version of the software build,

the process of the pre-release version of the software build comprising:

generating a pre-release version of a software build image;

generating a security-sensitive script, a first encryption key, and specified software components;

encrypting the security-sensitive script with the first encryption key, the specified software components being unencrypted;

inserting the security-sensitive script encrypted with the first encryption key, and the unencrypted specified software components, into the pre-release version of the software build image; and

saving and storing the first encryption key to allow decryption of the encrypted security-sensitive script inserted into the pre-release version of the software build image during testing of the pre-release version of the software build image; and

the process of the release version of the software build comprising:

generating a release version of the software build image;

generating a second encryption key, the second encryption key being different from the first encryption key such that each of the pre-release version of the software build image and the release version of the software build image has its own unique encryption key for encrypting the security-sensitive script;

encrypting the security-sensitive script with the second encryption key;

inserting the security-sensitive script encrypted with the second encryption key, and the unencrypted specified software components, into the release version of the software build image; and

securely deleting the second encryption key to prevent decryption of the encrypted security-sensitive script inserted into the release version of the software build image after releasing the release version of the software build image as a final product.

14. The computer program product of claim 13 wherein encrypting the security-sensitive script with the first encryption key includes encrypting the security-sensitive script with the first encryption key using one of a first encryption technique and a second encryption technique, the second encryption technique being different from the first encryption technique.

15. The computer program product of claim 14 wherein encrypting the security-sensitive script with the second encryption key includes encrypting the security-sensitive script with the second encryption key using the one of the first encryption technique and the second encryption technique.

16. The computer program product of claim 15 wherein the method further comprises:

implementing the first encryption technique as a symmetric encryption technique; and

implementing the second encryption technique as an asymmetric encryption technique.

17. The computer program product of claim 13 wherein the method further comprises:

deploying the pre-release version of the software build image to be executed on a storage system in a development and test environment; and

sending, in a deployment package, the first encryption key for the pre-release version of the software build image to the storage system in the development and test environment,

wherein the first encryption key is detected by the storage system in the deployment package,

wherein the security-sensitive script inserted into the pre-release version of the software build image is decrypted by the storage system with the first encryption key, and

wherein, in response to decryption of the security-sensitive script inserted into the pre-release version of the software build image being successful, the security-sensitive script is executed by the storage system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2023
From: YIN, JUELONG; WANG, HAO; KRIVENOK, DMITRY VLADIMIROVICH; HAN, CHAOWEN
To: DELL PRODUTCS L.P.
Reel/Frame 062262/0390 →
Continuity (1)
Related Publication 20240184897A1 · Jun 6, 2024
References Cited (12)
US 9536095B1 · Buendgen · 2017 [cited by examiner]
US 10262155B1 · Sun et al. · 2019 [cited by applicant]
US 11099837B2 · Bell, IV et al. · 2021 [cited by applicant]
US 11340928B2 · Kulkarni et al. · 2022 [cited by applicant]
US 11379209B2 · Liu et al. · 2022 [cited by applicant]
US 11455405B2 · Wolfson et al. · 2022 [cited by applicant]
US 11461084B2 · Wolfson · 2022 [cited by examiner]
US 20150213273A1 · Yasukawa · 2015 [cited by examiner]
US 20210157623A1 · Chandrashekar · 2021 [cited by examiner]
US 20210279326A1 · Adam · 2021 [cited by examiner]
US 20220147334A1 · Gunning · 2022 [cited by examiner]
US 20240214358A1 · Einarsson · 2024 [cited by examiner]