IP Library Granted Patent US 12,657,322
Granted Patent B2
US 12,657,322 · App. 18/496,461 · Granted Jun 16, 2026

Integrity verification mechanism for protection against container migration attacks

Inventors: Alan Barnett (County Cork, IE); Ahmed Khalid (Cork, IE); Matthew Keating (Cork, IE)
Assignee: Dell Products L.P.
G06F21/6218G06F21/54G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,322
App. No.
18/496,461
Granted
Jun 16, 2026
Kind
B2
Abstract

One example method includes receiving, at a target, a migrated container, the container being migrated by a source, retrieving, by the target, a first container hash from an immutable distributed ledger, the first container hash being created at the source by hashing the container, and the first container hash being written by the source to the immutable distributed ledger, hashing, at the target, the container to create a second container hash, writing, by the target, the second container hash to the immutable distributed ledger, and determining, by the target, whether the first container hash and the second container hash match, and a failure of the first container hash to match the second container hash indicates that in-flight tampering of the container has occurred while the container was migrating from the source to the target.

Claims (32)

1 . A method, comprising:

receiving, at a target, a migrated container, the container being migrated by a source;

retrieving, by the target, a first container hash from an immutable distributed ledger, the first container hash being created at the source by hashing the container, and the first container hash being written by the source to the immutable distributed ledger;

hashing, at the target, the received container to create a second container hash;

writing, by the target, the second container hash to the immutable distributed ledger; and

determining, by the target, whether the first container hash and the second container hash match,

wherein a failure of the first container hash to match the second container hash indicates that in-flight tampering of the container has occurred while the container was migrating from the source to the target, and

wherein, when the first container hash is determined to match the second container hash, the received container is permitted to resume operation at the target and, when the received container is subsequently verified by an external storage site, the received container is permitted to access container data, which is externally stored at the external storage site.

2 . The method as recited in claim 1 , wherein the immutable distributed ledger comprises a blockchain, and the first container hash and the second container hash comprise respective blocks of the blockchain.

3 . The method as recited in claim 1 , wherein when the first container hash is determined to match the second container hash, the received container is permitted to start running at the target.

4 . The method as recited in claim 1 , wherein both the first container hash and the second container hash are non-reversible.

5 . The method as recited in claim 1 , wherein the immutable distributed ledger is configured to enforce access control to the received container, and one or more other containers, on a per-container basis.

6 . The method as recited in claim 1 , wherein the immutable distributed ledger enables an authorized entity, needing access to another container, to independently verify whether or not the another container has been tampered with while the another container was in-flight to that authorized entity.

7 . The method as recited in claim 1 , wherein the received container is exported as a compressed file prior to creation of the first container hash.

8 . The method as recited in claim 1 , wherein when the first container hash and the second container hash do not match each other, the received container is discarded, and the source is informed of the failure.

9 . The method as recited in claim 1 , wherein retrieving the first container hash comprises retrieving an ID of the received container and an ID of a component, of the source, that created the first container hash.

10 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving, at a target, a migrated container, the container being migrated by a source;

retrieving, by the target, a first container hash from an immutable distributed ledger, the first container hash being created at the source by hashing the container, and the first container hash being written by the source to the immutable distributed ledger;

hashing, at the target, the received container to create a second container hash;

writing, by the target, the second container hash to the immutable distributed ledger; and

determining, by the target, whether the first container hash and the second container hash match,

wherein a failure of the first container hash to match the second container hash indicates that in-flight tampering of the container has occurred while the container was migrating from the source to the target, and

wherein, when the first container hash is determined to match the second container hash, the received container is permitted to resume operation at the target and, when the received container is subsequently verified by an external storage site, the received container is permitted to access container data, which is externally stored at the external storage site.

11 . The non-transitory storage medium as recited in claim 10 , wherein the immutable distributed ledger comprises a blockchain, and the first container hash and the second container hash comprise respective blocks of the blockchain.

12 . The non-transitory storage medium as recited in claim 10 , wherein when the first container hash is determined to match the second container hash, the received container is permitted to start running at the target.

13 . The non-transitory storage medium as recited in claim 10 , wherein both the first container hash and the second container hash are non-reversible.

14 . The non-transitory storage medium as recited in claim 10 , wherein the immutable distributed ledger is configured to enforce access control to the received container, and one or more other containers, on a per-container basis.

15 . The non-transitory storage medium as recited in claim 10 , wherein the immutable distributed ledger enables an authorized entity, needing access to another container, to independently verify whether or not the another container has been tampered with while the another container was in-flight to that authorized entity.

16 . The non-transitory storage medium as recited in claim 10 , wherein the received container is exported as a compressed file prior to creation of the first container hash.

17 . The non-transitory storage medium as recited in claim 10 , wherein when the first container hash and the second container hash do not match each other, the received container is discarded, and the source is informed of the failure.

18 . The non-transitory storage medium as recited in claim 10 , wherein retrieving the first container hash comprises retrieving an ID of the received container and an ID of a component, of the source, that created the first container hash.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: BARNETT, ALAN; KHALID, AHMED; KEATING, MATTHEW
To: DELL PRODUCTS L.P.
Reel/Frame 065375/0315 →
Continuity (1)
Related Publication 20250139270A1 · May 1, 2025
References Cited (17)
US 10396997B2 · Brady · 2019 [cited by examiner]
US 11296867B2 · Scott · 2022 [cited by examiner]
US 11588646B2 · Ilany et al. · 2023 [cited by examiner]
US 20150156188A1 · Wang · 2015 [cited by examiner]
US 20180109501A1 · Pawgi · 2018 [cited by examiner]
US 20190332421A1 · Kozlowski · 2019 [cited by examiner]
US 20200192689A1 · Smith, IV · 2020 [cited by examiner]
US 20210319441A1 · Knobel · 2021 [cited by examiner]
US 20220091874A1 · Janakiram · 2022 [cited by examiner]
US 20220114273A1 · Njemanze · 2022 [cited by examiner]
US 20230027329A1 · Durham · 2023 [cited by examiner]
US 20230342496A1 · Doshi · 2023 [cited by examiner]
US 20240235843A1 · Davies · 2024 [cited by examiner]
CN 114172729A · 2022 [cited by examiner]
Immutable Log Storage as a Service on Private and Public Blockchains (Year: 2021). [cited by examiner]
A Multilayer Distributed Ledger Technology Architecture for Immutable Registry of Mobility and Location Information (Year: 2022). [cited by examiner]
The Approach to Managing Provenance Metadata and Data Access Rights in Distributed Storage Using the Hyperledger Blockchain Platform (Year: 2018). [cited by examiner]