IP Library › Granted Patent US 12,495,031
Granted Patent B2
US 12,495,031 · App. 18/372,035 · Granted Dec 9, 2025

End to end artifact trust in cloud environments

Inventors: Tobias D.F. Weisserth (Redmond, WA); Qiming Chen (Seattle, WA); Sohail A. Hirani (Redmond, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L63/0823H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,031
App. No.
18/372,035
Granted
Dec 9, 2025
Kind
B2
Abstract

Techniques are described for providing end-to-end content trust for artifact types managed by a service provider, regardless of where or how the artifacts are deployed or applied in a target environment. The described trust mechanism is agnostic to the specific type of artifact and where the artifact is being applied from within a cloud environment.

Claims (48)

1 . A method for managing trusted content in a computing network operated by a computing service provider, the method comprising:

receiving, by the computing service provider from a publisher, an artifact that is usable for deployments in the computing network;

determining that the artifact is associated with a resource type for an artifact store implemented at the computing service provider, wherein:

the artifact store holds artifacts under management of the computing service provider;

the service provider manages underlying registry and storage mechanisms for the artifacts; and

the artifact store requires publishers of artifacts to provide a valid signature for each artifact that the publishers declare and enter into the artifact store;

receiving, by the computing service provider from the publisher, a signature for the artifact, wherein the signature is based on a signing certificate obtained from a certificate authority;

verifying, by the computing service provider, the signature;

in response to verifying the signature, re-signing, by the computing service provider, the artifact with a certificate generated and managed by the computing service provider; and

using the re-signed artifact as a source of trust for the artifact for distribution and lifecycle of the artifact for the deployments in the computing network.

2 . The method of claim 1 , wherein the method is agnostic to a type of the artifact.

3 . The method of claim 2 , wherein the artifact is one of a container image, Helm package, Helm chart, configuration schema, templates, or virtual machine images.

4 . The method of claim 1 , further comprising providing immutability and versioning for the artifact.

5 . The method of claim 1 , further comprising revoking the artifact as a trusted artifact.

6 . The method of claim 1 , further comprising storing a plurality of re-signed artifacts in an artifact store.

7 . The method of claim 1 , wherein the verifying of the signature is based on a trust policy.

8 . A computing device comprising:

a memory storing thereon instructions that when executed by a processing system of the computing device, cause the computing device to perform operations comprising:

receiving, from a publisher, an artifact that is usable for deployments in a computing network;

determining that the artifact is associated with a resource type for an artifact store implemented at a computing service provider, wherein:

the artifact store holds artifacts under management of the computing service provider;

the service provider manages underlying registry and storage mechanisms for the artifacts; and

the artifact store requires publishers of artifacts to provide a valid signature for each artifact that the publishers declare and enter into the artifact store;

receiving, from the publisher, a signature for the artifact, wherein the signature is based on a signing certificate obtained from a certificate authority;

verifying the signature;

in response to verifying the signature, re-signing the artifact with a certificate generated and managed by a service provider; and

using the re-signed artifact as a source of trust for the artifact for distribution and lifecycle of the artifact for the deployments in the computing network.

9 . The computing device of claim 8 , wherein the operations are agnostic to a type of the artifact.

10 . The computing device of claim 9 , wherein the artifact is one of a container image, Helm package, Helm chart, configuration schema, templates, or virtual machine images.

11 . The computing device of claim 8 , further comprising instructions that when executed by a processing system of the computing device, cause the computing device to perform operations comprising providing immutability and versioning for the artifact.

12 . The computing device of claim 8 , further comprising instructions that when executed by a processing system of the computing device, cause the computing device to perform operations comprising revoking the artifact as a trusted artifact.

13 . The computing device of claim 8 , further comprising instructions that when executed by a processing system of the computing device, cause the computing device to perform operations comprising storing a plurality of re-signed artifacts in an artifact store.

14 . The computing device of claim 8 , wherein the verifying of the signature is based on a trust policy.

15 . A computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by one or more processors of a system, cause the system to perform operations comprising:

receiving, from a publisher, an artifact that is usable for deployments in a computing network;

determining that the artifact is associated with a resource type for an artifact store implemented at a computing service provider, wherein:

the artifact store holds artifacts under management of the computing service provider;

the service provider manages underlying registry and storage mechanisms for the artifacts; and

the artifact store requires publishers of artifacts to provide a valid signature for each artifact that the publishers declare and enter into the artifact store;

receiving, from the publisher, a signature for the artifact, wherein the signature is based on a signing certificate obtained from a certificate authority;

verifying the signature;

in response to verifying the signature, re-signing the artifact with a certificate generated and managed by a service provider; and

using the re-signed artifact as a source of trust for the artifact for distribution and lifecycle of the artifact for the deployments in the computing network.

16 . The computer-readable storage medium of claim 15 , wherein the operations are agnostic to a type of the artifact.

17 . The computer-readable storage medium of claim 16 , wherein the artifact is one of a container image, Helm package, Helm chart, configuration schema, templates, or virtual machine images.

18 . The computer-readable storage medium of claim 15 , further comprising computer-executable instructions stored thereupon which, when executed by one or more processors of a system, cause the system to perform operations comprising providing immutability and versioning for the artifact.

19 . The computer-readable storage medium of claim 15 , further comprising computer-executable instructions stored thereupon which, when executed by one or more processors of a system, cause the system to perform operations comprising revoking the artifact as a trusted artifact.

20 . The computer-readable storage medium of claim 15 , further comprising computer-executable instructions stored thereupon which, when executed by one or more processors of a system, cause the system to perform operations comprising storing a plurality of re-signed artifacts in an artifact store.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: WEISSERTH, TOBIAS D.F.; CHEN, QIMING; HIRANI, SOHAIL A.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 065577/0187 →
Continuity (2)
Provisional Application 63525144 · Jul 5, 2023
Related Publication 20250016149A1 · Jan 9, 2025
References Cited (14)
US 10057243B1 · Kumar · 2018 [cited by examiner]
US 20070245414A1 · Chan · 2007 [cited by examiner]
US 20080098229A1 · Hartrell · 2008 [cited by examiner]
US 20210397712A1 · Gajananan · 2021 [cited by examiner]
US 20220019418A1 · Mckay · 2022 [cited by examiner]
US 20230353381A1 · Bhamidipati · 2023 [cited by examiner]
CN 104376252B · 2017 [cited by applicant]
CN 105471918B · 2018 [cited by applicant]
CN 113138867A · 2021 [cited by applicant]
Jibilian, et al., “The US is Readying Sanctions Against Russia Over the SolarWinds Cyber Attack. Here's a Simple Explanation of How the Massive Hack Happened and Why it's Such a Big Deal”, Retrieved From: https://www.bu… [cited by applicant]
Lorenc, Dan, “Notary V2 and Cosign”, Retrieved From: https://dlorenc.medium.com/notary-v2-and-cosign-b816658f044d, Nov. 8, 2021, 14 Pages. [cited by applicant]
Panato, et al., “Sigstore Cosign”, Retrieved From: https://github.com/sigstore/cosign, Retrieved Date: May 26, 2023, 15 Pages. [cited by applicant]
Zha, et al., “Notary Project Specifications”, Retrieved From: https://github.com/notaryproject/specifications, Aug. 4, 2023, 3 Pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/036345, mailed on Oct. 10, 2024, 14 pages. [cited by applicant]