Software Container Configuration Attestation for Supply Chain Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional software containers are susceptible to cybersecurity breaches and unsuitable for large-scale deployment due to vulnerabilities that can be exploited without leaving a trail of corrupted configuration data, posing risks to software supply chains.
Innovation Solution
A system and method for securing software containers using machine-readable configuration data, involving a scoring engine to evaluate and generate scores based on configuration data, and an attestation module to provide trustworthiness assessments, with features like immutable file formats and encryption to ensure integrity and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional software containers are used for deployment, then deployment speed and ease are improved, but security vulnerability and trustworthiness deteriorate
Solution Approach 1:
The patent applies preliminary action by generating cryptographic hashes of configuration files during the container build process and embedding them in the container image. This pre-computation of security verification data enables rapid security checking at deployment without compromising container startup speed, thus maintaining high productivity while improving reliability.
Solution Approach 2:
The patent introduces cryptographic hash values as an intermediary between the configuration files and the security verification process. These hash values serve as mediators that can be quickly compared to verify file integrity, enabling fast security validation that maintains deployment speed while ensuring container trustworthiness.
2Difficulty of detecting and measuring
If security scanning is performed on container components, then security detection capability is improved, but configuration data integrity deteriorates due to corruption
Solution Approach 1:
The patent creates cryptographic hash copies of the original configuration files and embeds these hash copies within the container image. These hash copies serve as immutable reference data that can be used for verification without requiring access to the original files, thus maintaining configuration integrity while enabling security detection.
Solution Approach 2:
The patent applies preliminary anti-action by pre-computing cryptographic hashes of configuration files and embedding them in the container before deployment. This pre-prepared verification data prevents attackers from corrupting configuration files during scanning, as any modification would be immediately detectable through hash comparison, thus protecting configuration integrity while enabling security detection.
3Reliability
If cryptographic verification is implemented for configuration files, then security integrity is improved, but processing time and complexity increase
Solution Approach 1:
The patent implements preliminary action by generating cryptographic hashes of all configuration files during the container build process and embedding these hash values in the container image. This pre-computation eliminates the need for time-consuming cryptographic verification during container runtime, as the embedded hashes can be quickly compared against actual configuration files, thus maintaining configuration integrity while minimizing verification processing time.
4Measurement precision
If comprehensive security evaluation is performed on software supply chain, then security assessment accuracy is improved, but system complexity increases
Solution Approach 1:
The patent applies segmentation by breaking down the security evaluation process into discrete, independently verifiable components - each configuration file is hashed separately, and each hash is embedded as a distinct element in the container image. This modular approach enables comprehensive security assessment of the entire supply chain while keeping the complexity of individual evaluation units manageable and tractable.
Data Source
AI summary
Techniques for data security transactions using software container machine readable configuration data are described, including receiving an artifact associated with a software container, parsing the artifact to identify source code of the software container and a supply chain, invoking a scoring engine to evaluate the source code to identify a component associated with the software container and to generate a score associated with the component, the score being generated by referencing an identifier of the component against a library of referenced identifiers to determine whether a security tool is being invoked and the component is assigned a score, and generating an aggregate score.


