CN114096965B - 容器的黑盒安全性 - Google Patents
容器的黑盒安全性 Download PDFInfo
- Publication number
- CN114096965B CN114096965B CN202080050367.8A CN202080050367A CN114096965B CN 114096965 B CN114096965 B CN 114096965B CN 202080050367 A CN202080050367 A CN 202080050367A CN 114096965 B CN114096965 B CN 114096965B
- Authority
- CN
- China
- Prior art keywords
- container
- component
- memory
- computer
- decryption
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/575—Secure boot
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
- G06F21/79—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2115—Third party
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2141—Access rights, e.g. capability lists, access control lists, access tables, access matrices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2147—Locking files
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2149—Restricted operating environment
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/509,137 US11409880B2 (en) | 2019-07-11 | 2019-07-11 | Blackbox security for containers |
| US16/509,137 | 2019-07-11 | ||
| PCT/EP2020/068570 WO2021004863A1 (en) | 2019-07-11 | 2020-07-01 | Blackbox security for containers |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN114096965A CN114096965A (zh) | 2022-02-25 |
| CN114096965B true CN114096965B (zh) | 2024-07-26 |
Family
ID=71465331
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN202080050367.8A Active CN114096965B (zh) | 2019-07-11 | 2020-07-01 | 容器的黑盒安全性 |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US11409880B2 (https=) |
| EP (1) | EP3997602B1 (https=) |
| JP (1) | JP7495190B2 (https=) |
| CN (1) | CN114096965B (https=) |
| WO (1) | WO2021004863A1 (https=) |
Families Citing this family (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11520895B2 (en) * | 2020-12-07 | 2022-12-06 | Samsung Electronics Co., Ltd. | System and method for dynamic verification of trusted applications |
| JP7610428B2 (ja) * | 2021-03-02 | 2025-01-08 | 日立Astemo株式会社 | 制御装置 |
| US12093367B2 (en) * | 2021-05-03 | 2024-09-17 | Carnegie Mellon University | System and method for providing provable end-to-end guarantees on commodity heterogeneous interconnected computing platforms |
| EP4170490A1 (de) * | 2021-10-19 | 2023-04-26 | Siemens Aktiengesellschaft | Priorisieren eines zugriffs von einer containerinstanz auf eine datei in einer dateisystemressource |
| CN114329531B (zh) * | 2021-12-21 | 2025-05-13 | 绿盟科技集团股份有限公司 | 一种容器加密方法、装置、电子设备及存储介质 |
| CN114547661B (zh) * | 2022-03-21 | 2024-09-20 | 京东科技信息技术有限公司 | 应用配置数据的加解密方法、装置、设备和存储介质 |
| CN114760154B (zh) * | 2022-06-14 | 2022-08-19 | 国网浙江省电力有限公司温州供电公司 | 基于电力载波跨安全区的数据隔离传输方法及通信机器人 |
| US12242879B2 (en) | 2022-07-06 | 2025-03-04 | International Business Machines Corporation | Protecting container images and runtime data |
| US12481520B2 (en) * | 2023-03-17 | 2025-11-25 | International Business Machines Corporation | Dynamic control of eBPF program execution in an operating system kernel |
| CN116842529B (zh) * | 2023-07-13 | 2024-07-26 | 海光信息技术股份有限公司 | 一种计算机程序产品、软件运行方法及其相关装置 |
| CN117873637B (zh) * | 2023-12-14 | 2025-09-05 | 天翼云科技有限公司 | 一种基于内存分级和内存压缩的内存热点消除方法 |
| US12395599B2 (en) * | 2024-01-26 | 2025-08-19 | Dell Products L.P. | Secure static facsimiles of digital information by an information handling system |
| US12598065B2 (en) * | 2024-05-10 | 2026-04-07 | Red Hat, Inc. | Managing data encryption during system upgrades |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106663038A (zh) * | 2014-06-30 | 2017-05-10 | 亚马逊科技公司 | 用于机器学习的特征处理配方 |
| CN107003815A (zh) * | 2014-12-09 | 2017-08-01 | 国际商业机器公司 | 云环境中机密数据的自动化管理 |
Family Cites Families (24)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP4007873B2 (ja) | 2002-07-09 | 2007-11-14 | 富士通株式会社 | データ保護プログラムおよびデータ保護方法 |
| JP5116325B2 (ja) | 2007-03-15 | 2013-01-09 | 株式会社リコー | 情報処理装置、ソフトウェア更新方法及び画像処理装置 |
| US8468356B2 (en) | 2008-06-30 | 2013-06-18 | Intel Corporation | Software copy protection via protected execution of applications |
| US8412945B2 (en) | 2011-08-09 | 2013-04-02 | CloudPassage, Inc. | Systems and methods for implementing security in a cloud computing environment |
| US9032506B2 (en) | 2012-08-09 | 2015-05-12 | Cisco Technology, Inc. | Multiple application containerization in a single container |
| US20140108793A1 (en) | 2012-10-16 | 2014-04-17 | Citrix Systems, Inc. | Controlling mobile device access to secure data |
| AU2014254276B2 (en) | 2013-04-15 | 2016-11-17 | Amazon Technologies, Inc. | Host recovery using a secure store |
| EP3161635B1 (en) * | 2014-06-30 | 2023-11-01 | Amazon Technologies, Inc. | Machine learning service |
| US9703965B1 (en) | 2014-06-30 | 2017-07-11 | EMC IP Holding Company LLC | Secure containers for flexible credential protection in devices |
| US9635055B2 (en) | 2015-01-28 | 2017-04-25 | defend7, Inc. | Encryption levels for secure application containers |
| US20160292431A1 (en) | 2015-04-02 | 2016-10-06 | defend7, Inc. | Management of encryption keys in an application container environment |
| US9710401B2 (en) * | 2015-06-26 | 2017-07-18 | Intel Corporation | Processors, methods, systems, and instructions to support live migration of protected containers |
| US10114947B1 (en) | 2016-06-29 | 2018-10-30 | Symantec Corporation | Systems and methods for logging processes within containers |
| US10263988B2 (en) * | 2016-07-02 | 2019-04-16 | Intel Corporation | Protected container key management processors, methods, systems, and instructions |
| US11403086B2 (en) | 2016-10-28 | 2022-08-02 | Virtuozzo International Gmbh | System and method for upgrading operating system of a container using an auxiliary host |
| US10691816B2 (en) | 2017-02-24 | 2020-06-23 | International Business Machines Corporation | Applying host access control rules for data used in application containers |
| US10496610B2 (en) | 2017-03-07 | 2019-12-03 | Code 42 Software, Inc. | Self destructing portable encrypted data containers |
| US20180285139A1 (en) | 2017-04-02 | 2018-10-04 | vEyE Security Ltd. | Hypervisor-based containers |
| US10587411B2 (en) | 2017-04-11 | 2020-03-10 | International Business Machines Corporation | Zero-knowledge verifiably attestable transaction containers using secure processors |
| US10909248B2 (en) * | 2017-06-29 | 2021-02-02 | Microsoft Technology Licensing, Llc | Executing encrypted boot loaders |
| US11601467B2 (en) * | 2017-08-24 | 2023-03-07 | L3 Technologies, Inc. | Service provider advanced threat protection |
| US11184323B2 (en) * | 2017-09-28 | 2021-11-23 | L3 Technologies, Inc | Threat isolation using a plurality of containers |
| US10001990B2 (en) | 2017-10-26 | 2018-06-19 | Iomaxis, Llc | Method and system for enhancing application container and host operating system security in a multi-tenant computing environment |
| US11017092B2 (en) * | 2018-09-27 | 2021-05-25 | Intel Corporation | Technologies for fast launch of trusted containers |
-
2019
- 2019-07-11 US US16/509,137 patent/US11409880B2/en active Active
-
2020
- 2020-07-01 WO PCT/EP2020/068570 patent/WO2021004863A1/en not_active Ceased
- 2020-07-01 JP JP2022500153A patent/JP7495190B2/ja active Active
- 2020-07-01 EP EP20736646.9A patent/EP3997602B1/en active Active
- 2020-07-01 CN CN202080050367.8A patent/CN114096965B/zh active Active
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106663038A (zh) * | 2014-06-30 | 2017-05-10 | 亚马逊科技公司 | 用于机器学习的特征处理配方 |
| CN107003815A (zh) * | 2014-12-09 | 2017-08-01 | 国际商业机器公司 | 云环境中机密数据的自动化管理 |
Also Published As
| Publication number | Publication date |
|---|---|
| JP7495190B2 (ja) | 2024-06-04 |
| WO2021004863A1 (en) | 2021-01-14 |
| EP3997602A1 (en) | 2022-05-18 |
| CN114096965A (zh) | 2022-02-25 |
| JP2022539465A (ja) | 2022-09-09 |
| US11409880B2 (en) | 2022-08-09 |
| EP3997602B1 (en) | 2025-06-18 |
| US20210012011A1 (en) | 2021-01-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN114096965B (zh) | 容器的黑盒安全性 | |
| US12105805B2 (en) | Binding secure keys of secure guests to a hardware security module | |
| JP7397557B2 (ja) | セキュア実行ゲスト所有者環境制御 | |
| JP7601522B2 (ja) | コンテンツ管理方法、システム、プログラム | |
| JP7546675B2 (ja) | セキュア・ゲストへのセキュリティ・モジュールのセキュア・オブジェクトのバインディング | |
| US12050700B2 (en) | Secure execution guest owner controls for secure interface control | |
| JP2023551527A (ja) | 準同型暗号化を使用したセキュアなコンピューティング・リソース配置 | |
| US20200089916A1 (en) | Binding a hardware security module (hsm) to protected software | |
| CN114661411B (zh) | 在云基础架构中供应安全/加密的虚拟机 | |
| Johnson et al. | Confidential Container Groups: Implementing confidential computing on Azure container instances | |
| JP2023542527A (ja) | ヘテロジニアス暗号化を通したソフトウェア・アクセス | |
| Hashizume | A reference architecture for cloud computing and its security applications | |
| HK40057234A (en) | Secure execution guest owner controls for secure interface control |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant |