Container Image Provenance via Distributed Ledger
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mechanisms for managing container images in distributed ledger networks lack standardization, automated image ownership discovery, and efficient provenance verification, leading to complexity in PKI setup, resource-intensive libraries, and manual tracking of dependencies and changes.
Innovation Solution
A method and system for accessing container images in a distributed ledger network that involves receiving requests, determining customization needs, extracting features, identifying pre-published images, and generating customized images based on reconciliation of metadata, using public keys, smart contracts, and certificates, without relying on a separate Public Key Infrastructure (PKI) framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PKI infrastructure is used for image provenance verification, then authentication and authorization are enabled, but device complexity and setup management complexity increase significantly
Solution Approach 1:
The patent extracts the cryptographic verification functionality from the complex PKI infrastructure and implements it directly within the distributed ledger network using native digital signatures and public key cryptography. This eliminates the need for external PKI components while maintaining security verification capabilities.
Solution Approach 2:
The distributed ledger acts as an intermediary that provides built-in authentication and authorization mechanisms through smart contracts and digital signatures. This mediator replaces the external PKI infrastructure, enabling provenance verification through the ledger's inherent cryptographic protocols rather than through separate PKI components.
2Loss of information
If manual tracking of image dependencies and changes is performed, then ownership discovery is possible, but productivity and automation level are reduced
Solution Approach 1:
The system implements self-service automated tracking where the distributed ledger automatically records all image dependencies, versions, and ownership changes through immutable transaction logs. Smart contracts automatically execute to track provenance information without requiring manual intervention, enabling the system to self-monitor and self-report ownership and dependency information.
Solution Approach 2:
The patent implements feedback mechanisms where the distributed ledger continuously provides automated feedback about image provenance, dependency relationships, and ownership changes. This feedback loop enables real-time tracking and discovery of image ownership and dependencies without manual processes.
3Reliability
If resource-intensive PKI libraries are used for provenance verification, then authentication is achieved, but use of energy and computational resources increase
Solution Approach 1:
The patent removes the dependency on resource-intensive external PKI libraries and extracts only the essential cryptographic verification functionality. By using the distributed ledger's native digital signature verification and public key infrastructure, the system achieves provenance authentication with significantly reduced computational overhead and energy consumption.
4Reliability
If each enterprise maintains internal governance for image provenance, then certification authority is established, but adaptability and standardization across enterprises are reduced
Solution Approach 1:
The patent implements a universal distributed ledger-based provenance system that serves multiple enterprises simultaneously. The same ledger infrastructure, smart contract templates, and verification mechanisms work across different enterprises and cloud providers, providing a multi-functional platform that maintains enterprise-specific governance while enabling cross-enterprise interoperability and standardization.
Solution Approach 2:
The system segments provenance management into enterprise-specific policy layers while maintaining a unified distributed ledger infrastructure. Each enterprise can define its own governance rules and certification policies within the shared ledger framework, allowing customization at the policy level while maintaining standardization at the technical implementation level across enterprises.
Data Source
AI summary
A technique is provided for accessing container images in a distributed ledger network environment, in which, basis the receipt of a request from a consumer for accessing the container images, it is determined whether the container images require to be generated based on a customization performed on pre-published container images. The pre-published container images are updated in the nodes of the distributed ledger network, based on at least public keys of publishers of the pre-published container images, smart contracts, and certificates associated with the publisher. Based on the determined requirement, features for performing the customization are extracted based on inputs received from the consumer and a set of pre-published container images are identified from the pre-published container images and associated metadata from respective nodes of the network. The customized container images are generated based on reconciliation of the metadata of the identified set of pre-published container images.


