Container Image Access Enforcement Across Orchestration Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies lack effective mechanisms to authenticate and enforce licensing compliance for container images across multiple orchestration platforms, leading to unauthorized replication and use beyond licensing terms.

Innovation Solution

A system and method that generates microservice container images with hardcoded metadata, creates pre-defined hash data, and uses a hardware security module to digitally sign and store this data in key management databases, enabling authentication and integrity checks through entitlement signature secrets to enforce trustworthy access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If container images are distributed across multiple orchestration platforms, then deployment flexibility and scalability are improved, but security control and licensing compliance deteriorate due to lack of authentication mechanisms

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication by generating and embedding digital signatures in container images before deployment. The entitlement signature secret (ESS) is created in advance and stored in key management databases, enabling verification to occur before the container image is executed on any orchestration platform. This preliminary action ensures security control is established prior to deployment across multiple platforms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between container images and orchestration platforms. The ESS acts as an intermediary credential that container images present to orchestration platforms for verification. This intermediary layer enables secure communication and trust establishment without requiring direct integration between each platform and the container image creator.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users receive access to container images, then ease of operation is improved, but unauthorized replication and use beyond licensing terms increases

Engineering Contradiction:
Improveaccess to container imagesVSAvoidunauthorized replication
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system implements feedback control by continuously verifying container image authenticity during deployment and execution. The orchestration platform checks the ESS against the stored digital signature in the key management database, providing real-time feedback on whether the container image is authorized. This feedback mechanism prevents unauthorized replication by denying execution to unverified or tampered container images.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by pre-embedding authentication credentials and verification logic within container images before distribution. The digital signature and ESS are incorporated into the container image itself, creating an inherent security mechanism that actively prevents unauthorized replication. This preliminary protective action is built into the container image structure, making unauthorized use detectable and preventable.

Inventive Principle:
Principle #9Preliminary anti-action

3Device complexity

If traditional authentication systems are used, then implementation simplicity is maintained, but fine-grained access control and licensing enforcement capability deteriorates

Engineering Contradiction:
Improveauthentication system complexityVSAvoidaccess control granularity
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The authentication system is segmented into distinct functional components: ESS generation, digital signature creation, key management database storage, and verification modules. Each component handles a specific aspect of the authentication process, allowing for fine-grained control and verification at different stages. This segmentation enables precise access control by verifying specific credentials (ESS, digital signatures) rather than relying on coarse authentication mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension to authentication by incorporating entitlement signature secrets and digital signatures as additional verification layers beyond traditional username/password or token-based systems. This multi-dimensional approach includes: (1) container image identity, (2) ESS credentials, (3) digital signature verification, and (4) licensing term validation. This additional dimension enables fine-grained access control and precise licensing enforcement.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12602502B2System and method for providing trustworthy access enforcement to microservice container images on orchestration platforms
Publication Date: 2026.04.14 PRIVAFY INC
  • US12602502B2 patent drawing
  • US12602502B2 patent drawing
  • US12602502B2 patent drawing

AI summary

A system and a method for providing trustworthy access enforcement to one or more microservice container images on one or more orchestration platforms is disclosed. The system generates the one or more microservice container images along with pre-defined hardcoded elements. The system creates a pre-defined hash data and store in one or more key management databases to analyze authenticity and integrity of the one or more orchestration platforms. The system executes the one or more microservice container images on the one or more orchestration platforms for obtaining metadata associated with the one or more orchestration platforms at a time of execution of the one or more microservice container images. The system generates entitlement signature secret (ESS) data of the one or more orchestration platforms to compare with the pre-defined hash data for trustworthy access enforcement of the one or more microservice container images on the one or more orchestration platforms.