IP Library Granted Patent US 10,127,030
Granted Patent B1
US 10,127,030 · App. 15/061,209 · Granted Nov 13, 2018

Systems and methods for controlled container execution

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,127,030
App. No.
15/061,209
Granted
Nov 13, 2018
Kind
B1
Abstract

In one embodiment, a method is performed by a computer system. The method includes receiving a request to execute a particular container. The method further includes retrieving a manifest of the particular container from a data store, the manifest indicating a plurality of items included in the particular container. In addition, the method includes validating one or more signatures of the container that are associated with the items indicated in the manifest. Also, the method includes determining an execution context of the request. Further, the method includes accessing an applicable execution policy for the determined execution context. Additionally, the method includes, responsive to a determination that the applicable execution policy is satisfied, causing the particular container to be installed on a target resource.

Claims (53)

1. A method comprising, by a computer system:

receiving a request to execute a particular container;

retrieving a manifest of the particular container from a data store, the manifest comprising a listing of a plurality of items included in the particular container, a plurality of signatures, and a plurality of hashes of the plurality of items;

wherein the plurality of signatures each comprise a signature of a purported source of at least one of the plurality of items;

for each signature of the plurality of signatures, retrieving, from a key store that is external to a container runtime of the particular container, a public key of the purported source;

for each signature of the plurality of signatures, validating the signature using the retrieved public key of the purported source;

validating contents of the particular container in relation to the manifest based, at least in part, on a comparison of the plurality of hashes from the manifest to hashes of corresponding items in the particular container;

determining an execution context of the request, the execution context comprising information related to a location where the particular container would be executed;

accessing an applicable execution policy, from among a plurality of execution policies, for the determined execution context; and

responsive to a determination that the applicable execution policy is satisfied, causing the particular container to be installed on an isolated user-space instance in a shared kernel space on an operating system of a target resource.

2. The method of claim 1 , comprising:

wherein the particular container comprises one or more sub-containers;

traversing the particular container; and

validating signatures of the one or more sub-containers.

3. The method of claim 1 , wherein the plurality of signatures comprise signatures of a plurality of purported sources.

4. The method of claim 1 , wherein the applicable execution policy that is accessed is different for different execution contexts.

5. The method of claim 1 , wherein the applicable execution policy is applicable to multiple container formats.

6. The method of claim 1 , wherein the execution context comprises information related to a user responsible for the request.

7. An information handling system comprising a processor and executable instructions, wherein the processor is operable to implement the executable instructions comprising:

receiving a request to execute a particular container on an isolated user-space instance in a shared kernel space on an operating system;

retrieving a manifest of the particular container from a data store, the manifest comprising a listing of a plurality of items included in the particular container, a plurality of signatures, and a plurality of hashes of the plurality of items;

wherein the plurality of signatures each comprise a signature of a purported source of at least one of the plurality of items;

for each signature of the plurality of signatures, retrieving, from a key store that is external to a container runtime of the particular container, a public key of the purported source;

for each signature of the plurality of signatures, validating the signature using the retrieved public key of the purported source;

validating contents of the particular container in relation to the manifest based, at least in part, on a comparison of the plurality of hashes from the manifest to hashes of corresponding items in the particular container;

determining an execution context of the request, the execution context comprising information related to the isolated user-space instance in the shared kernel space on the operating system where the particular container would be executed;

accessing an applicable execution policy, from among a plurality of execution policies, for the determined execution context; and

responsive to a determination that the applicable execution policy is satisfied, causing the particular container to be installed on the isolated user-space instance in the shared kernel space on the operating system of a target resource.

8. The information handling system of claim 7 , the method comprising:

wherein the particular container comprises one or more sub-containers;

traversing the particular container; and

validating signatures of the one or more sub-containers.

9. The information handling system of claim 7 , wherein the plurality of signatures comprise signatures of a plurality of purported sources.

10. The information handling system of claim 7 , wherein the applicable execution policy that is accessed is different for different execution contexts.

11. The information handling system of claim 7 , wherein the applicable execution policy is applicable to multiple container formats.

12. The information handling system of claim 7 , wherein the execution context comprises information related to a user responsible for the request.

13. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

receiving a request to execute a particular container on an isolated user-space instance in a shared kernel space on an operating system;

retrieving a manifest of the particular container from a data store, the manifest comprising a listing of a plurality of items included in the particular container, a plurality of signatures, and a plurality of hashes of the plurality of items;

wherein the plurality of signatures each comprise a signature of a purported source of at least one of the plurality of items;

for each signature of the plurality of signatures, retrieving, from a key store that is external to a container runtime of the particular container, a public key of the purported source;

for each signature of the plurality of signatures, validating the signature using the retrieved public key of the purported source;

validating contents of the particular container in relation to the manifest based, at least in part, on a comparison of the plurality of hashes from the manifest to hashes of corresponding items in the particular container;

determining an execution context of the request, the execution context comprising information related to the isolated user-space instance in the shared kernel space on the operating system where the particular container would be executed;

accessing an applicable execution policy, from among a plurality of execution policies, for the determined execution context; and

responsive to a determination that the applicable execution policy is satisfied, causing the particular container to be installed on the isolated user-space instance in the shared kernel space on the operating system of a target resource.

14. The computer-program product of claim 13 , the method comprising:

wherein the particular container comprises one or more sub-containers;

traversing the particular container; and

validating signatures of the one or more sub-containers.

15. The computer-program product of claim 13 , wherein the plurality of signatures comprise signatures of a plurality of purported sources.

16. The computer-program product of claim 13 , wherein the applicable execution policy that is accessed is different for different execution contexts.

17. The computer-program product of claim 13 , wherein the applicable execution policy is applicable to multiple container formats.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2016
From: MORTMAN, DAVID; MCNEILL, CAMPBELL
To: DELL SOFTWARE INC.
Reel/Frame 039261/0928 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
Cited By (3)
US 12,192,214 US 12,346,680 US 12,717,897