Software Container Configuration Attestation for Supply Chain Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional software containers are susceptible to cybersecurity breaches and unsuitable for large-scale deployment due to vulnerabilities that can be exploited without leaving a trail of corrupted configuration data, posing risks to software supply chains.

Innovation Solution

A system and method for securing software containers using machine-readable configuration data, involving a scoring engine to evaluate and generate scores based on configuration data, and an attestation module to provide trustworthiness assessments, with features like immutable file formats and encryption to ensure integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional software containers are used for deployment, then deployment speed and ease are improved, but security vulnerability and trustworthiness deteriorate

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity trustworthiness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by generating cryptographic hashes of configuration files during the container build process and embedding them in the container image. This pre-computation of security verification data enables rapid security checking at deployment without compromising container startup speed, thus maintaining high productivity while improving reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic hash values as an intermediary between the configuration files and the security verification process. These hash values serve as mediators that can be quickly compared to verify file integrity, enabling fast security validation that maintains deployment speed while ensuring container trustworthiness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If security scanning is performed on container components, then security detection capability is improved, but configuration data integrity deteriorates due to corruption

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidconfiguration data integrity
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent creates cryptographic hash copies of the original configuration files and embeds these hash copies within the container image. These hash copies serve as immutable reference data that can be used for verification without requiring access to the original files, thus maintaining configuration integrity while enabling security detection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies preliminary anti-action by pre-computing cryptographic hashes of configuration files and embedding them in the container before deployment. This pre-prepared verification data prevents attackers from corrupting configuration files during scanning, as any modification would be immediately detectable through hash comparison, thus protecting configuration integrity while enabling security detection.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If cryptographic verification is implemented for configuration files, then security integrity is improved, but processing time and complexity increase

Engineering Contradiction:
Improveconfiguration integrityVSAvoidverification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by generating cryptographic hashes of all configuration files during the container build process and embedding these hash values in the container image. This pre-computation eliminates the need for time-consuming cryptographic verification during container runtime, as the embedded hashes can be quickly compared against actual configuration files, thus maintaining configuration integrity while minimizing verification processing time.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If comprehensive security evaluation is performed on software supply chain, then security assessment accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidevaluation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by breaking down the security evaluation process into discrete, independently verifiable components - each configuration file is hashed separately, and each hash is embedded as a distinct element in the container image. This modular approach enables comprehensive security assessment of the entire supply chain while keeping the complexity of individual evaluation units manageable and tractable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250378162A1Data security transactions using software container machine readable configuration data
Publication Date: 2025.12.11 SYLABS IP HOLDINGS LLC SERIES E
  • US20250378162A1 patent drawing
  • US20250378162A1 patent drawing
  • US20250378162A1 patent drawing

AI summary

Techniques for data security transactions using software container machine readable configuration data are described, including receiving an artifact associated with a software container, parsing the artifact to identify source code of the software container and a supply chain, invoking a scoring engine to evaluate the source code to identify a component associated with the software container and to generate a score associated with the component, the score being generated by referencing an identifier of the component against a library of referenced identifiers to determine whether a security tool is being invoked and the component is assigned a score, and generating an aggregate score.