IP Library › Granted Patent US 12,494,912
Granted Patent B2
US 12,494,912 · App. 17/797,458 · Granted Dec 9, 2025

One-time-use secret bootstrapping in container-orchestrated environments

Inventors: Rafael da Fonte Lopes da Silva (Porto Alegre, BR); Natalia Machado dos Santos (Porto Alegre, BR); Mauricio Coutinho Moraes (Porto Alegre, BR)
Assignee: Hewlett-Packard Development Company, L.P.
H04L9/3228H04L9/3213H04L67/1044
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,494,912
App. No.
17/797,458
Granted
Dec 9, 2025
Kind
B2
Abstract

An example system includes a one-time-use secret (OTUS) deployer engine to: provide an OTUS within a container-orchestrated environment (COE). The example system further includes: a non-OTUS provider engine to: provide a non-OTUS in exchange for the OTUS; and, invalidate the OTUS when the non-OTUS is provided. The example system further includes: a first container engine to: in response to bootstrapping, receive the OTUS from the OTUS deployer engine; and receive the non-OTUS from the non-OTUS provider engine in exchange for the OTUS. The example system further includes: a replica of the first container engine, to: in response to bootstrapping, after the first container engine, receive the OTUS from the OTUS deployer engine; attempt to receive the non-OTUS from the non-OTUS provider engine in exchange for the OTUS; receive an indication from the non-OTUS provider engine that the OTUS is invalid; and receive the non-OTUS from the first container engine.

Claims (66)

1 . A system comprising:

a one-time-use secret (OTUS) deployer engine to: provide an OTUS within a container-orchestrated environment (COE);

a non-OTUS provider engine to: provide a non-OTUS in exchange for the OTUS; and, invalidate the OTUS when the non-OTUS is provided;

a first container engine to: in response to bootstrapping, receive the OTUS from the OTUS deployer engine; and receive the non-OTUS from the non-OTUS provider engine in exchange for the OTUS; and

a second container engine, that is a replica of the first container engine, to: in response to bootstrapping, after the first container engine, receive the OTUS from the OTUS deployer engine; attempt to receive the non-OTUS from the non-OTUS provider engine in exchange for the OTUS; receive an indication from the non-OTUS provider engine that the OTUS is invalid; and receive the non-OTUS from the first container engine via a peer-to-peer network of the COE,

wherein at least one of the first container engine or the second container engine is further to broadcast the non-OTUS to other replicas of the first container engine of the peer-to-peer network.

2 . The system of claim 1 , further comprising:

a COE engine to: in response to the non-OTUS expiring, kill one of the first container engine and the second container engine; and generate a third container engine that is a replica of the first container engine and the second container engine,

the third container engine to: in response to bootstrapping, receive a new OTUS from the OTUS deployer engine; receive a new non-OTUS from the non-OTUS provider engine in exchange for the new OTUS; and provide the new non-OTUS to remaining replicas of the first container engine and the second container engine.

3 . The system of claim 1 , further comprising:

a third container engine, that is a respective replica of the first container engine and the second container engine, the third container engine to: in response to bootstrapping, after the first container engine, receive the OTUS from the OTUS deployer engine; attempt to receive the non-OTUS from the non-OTUS provider engine in exchange for the OTUS; receive a respective indication from the non-OTUS provider engine that the OTUS is invalid; and receive the non-OTUS from the first container engine or the second container engine.

4 . The system of claim 1 , further comprising:

a COE engine to coordinate the OTUS and the non-OTUS between the OTUS deployer engine and the non-OTUS provider engine.

5 . The system of claim 1 , wherein:

the OTUS is usable only one time, the OTUS comprising: a one-time-use password; or a one-time-use token; or a non-renewable access token; or a one-time use security token; or a one-time use credential; or a one-time use cryptographic key; and

the non-OTUS is usable more than one time, the non-OTUS for use in communicating with components that use secrets to provide services, the non-OTUS comprising: a multiple-use password; or a multiple-use token; or a renewable access token; or a multiple-use security token; or a multiple-use credential; or a multiple-use cryptographic key.

6 . The system of claim 1 , wherein the second container engine is to receive the non-OTUS from the first container engine by:

in response to receiving the indication from the non-OTUS provider engine that the OTUS is invalid: requesting the non-OTUS from the first container engine and receiving the non-OTUS from the first container engine in response to the request.

7 . The system of claim 1 , further comprising:

a COE engine to re-generate the first container engine as the second container engine.

8 . A method comprising:

receiving, in response to bootstrapping at a first container of a container-orchestrated environment (COE), a one-time-use secret (OTUS) from an OTUS deployer;

receiving, at the first container, a non-OTUS from a non-OTUS provider, in exchange for the OTUS, the OTUS becoming invalid in response to the exchange of the OTUS for the non-OTUS;

receiving, in response to bootstrapping at a second container of the COE, the non-OTUS from the first container, rather than the non-OTUS provider, via a peer-to-peer network of the COE, the second container comprising a replica of the first container;

providing, at the first container and the second container, same application services, the same application services at least partially provided in conjunction with the non-OTUS; and

broadcasting, at at least one of the first container or the second container, the non-OTUS to other replicas of the first container of the peer-to-peer network.

9 . The method of claim 8 , further comprising:

receiving, in response to bootstrapping at a third container of the COE, the non-OTUS from the first container or the second container, rather than the non-OTUS provider, via the peer-to-peer network, the third container comprising a replica of the first container and the second container.

10 . The method of claim 8 ,

wherein the broadcasting the non-OTUS includes broadcasting, at both of the first container and the second container, the non-OTUS to other replicas of the first container of the peer-to-peer network.

11 . The method of claim 8 , further comprising:

requesting, at the second container, the non-OTUS from the first container.

12 . The method of claim 8 , wherein sharing the non-OTUS in the peer-to-peer network, by replicas of the first container, occurs via a peer-to-peer service.

13 . The method of claim 8 , wherein receiving the non-OTUS from the first container includes:

attempting to receive, at the second container, the non-OTUS from the non-OTUS provider, in exchange for the OTUS;

receiving, at the second container, an indication that the OTUS is invalid from the non-OTUS provider; and

requesting, at the second container, the non-OTUS from the first container.

14 . The method of claim 8 , wherein:

the OTUS is usable only one time, the OTUS comprising: a one-time-use password; or a one-time-use token; or a non-renewable access token; or a one-time use security token; or a one-time use credential; or a one-time use cryptographic key; and

the non-OTUS is usable more than one time, the non-OTUS for use in communicating with components that use secrets to provide services, the non-OTUS comprising: a multiple-use password; or a multiple-use token; or a renewable access token; or a multiple-use security token; or a multiple-use credential; or a multiple-use cryptographic key.

15 . A non-transitory computer-readable medium comprising instructions that, when executed by a processor, cause the processor to:

receive, in response to bootstrapping, at a first container of a container-orchestrated environment (COE), a one-time-use secret (OTUS) from an OTUS deployer;

receive, at the first container, a non-OTUS from a non-OTUS provider, in exchange for the OTUS, the OTUS becoming invalid in response to the exchange of the OTUS for the non-OTUS;

store, by the first container, the non-OTUS at a first volatile memory;

receive, via a peer-to-peer network of the COE and in response to bootstrapping at a second container of the COE, the non-OTUS from the first container, rather than the non-OTUS provider, the second container comprising a replica of the first container;

broadcast, by at least one of the first container or the second container, the non-OTUS to other replicas of the first container of the peer-to-peer network;

store, by the second container, the non-OTUS at a second volatile memory; and

provide, at the first container and the second container, same application services of the COE, the same application services at least partially provided in conjunction with the non-OTUS.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed, further cause the processor to:

in response to the non-OTUS expiring, kill one of the first container and the second container;

generate a third container of the COE that is a replica of the first container and the second container;

receive, in response to bootstrapping at the third container, a new OTUS from the OTUS deployer;

receive, at the third container, a new non-OTUS from the non-OTUS provider, in exchange for the new OTUS, the new OTUS becoming invalid in response to the exchange of the new OTUS for the new non-OTUS;

store, by the third container, the non-OTUS at a third volatile memory;

provide, by the third container, the new non-OTUS to remaining replicas in the COE; and

overwrite, at remaining replicas, the non-OTUS with the new non-OTUS at respective volatile memories.

17 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed, further cause the processor to:

cause the OTUS and the non-OTUS to be available in association with one other at the non-OTUS provider.

18 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed, further cause the processor to:

provide a respective OTUS deployer and a respective non-OTUS provider for the first container and the second container.

19 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed, further cause the processor to:

provide respective peer-to-peer addresses of replicas of the first container to all the replicas of the first container, the non-OTUS being shared between the replicas of a peer-to-peer network via the respective peer-to-peer addresses.

20 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed, cause the processor to receive the non-OTUS from the first container by:

attempting to receive, at the second container, the non-OTUS from the non-OTUS provider, in exchange for the OTUS;

receiving, at the second container, an indication that the OTUS is invalid from the non-OTUS provider; and

requesting, at the second container, the non-OTUS from the first container.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2022
From: DA FONTE LOPES DA SILVA, RAFAEL; MACHADO DOS SANTOS, NATALIA; COUTINHO MORAES, MAURICIO
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 060716/0122 →
Continuity (1)
Related Publication 20230078967A1 · Mar 16, 2023
References Cited (16)
US 9851968B2 · Straub · 2017 [cited by applicant]
US 10013668B2 · Straub · 2018 [cited by applicant]
US 10127401B2 · Stuntebeck et al. · 2018 [cited by applicant]
US 10831399B2 · Bett · 2020 [cited by examiner]
US 10938641B1 · Fritz · 2021 [cited by examiner]
US 11354060B2 · Jayaraman · 2022 [cited by examiner]
US 11416587B1 · den Hartog · 2022 [cited by examiner]
US 20110126207A1 · Wipfel · 2011 [cited by examiner]
US 20140380441A1 · Stauth et al. · 2014 [cited by applicant]
US 20170116424A1 · Aamir · 2017 [cited by examiner]
US 20180196654A1 · Bo et al. · 2018 [cited by applicant]
US 20180227182A1 · Patton et al. · 2018 [cited by applicant]
US 20180314598A1 · Nanivadekar · 2018 [cited by examiner]
US 20190065323A1 · Dhamdhere · 2019 [cited by examiner]
US 20190146816A1 · Reno et al. · 2019 [cited by applicant]
Gross, T., “Secrets management in the Autopilot Pattern”, Jan. 26, 2017, Retrieved at https://www.joyent.com/blog/secrets-management-in-the-autopilotpattern, 7 pages. [cited by applicant]