Container Image Provenance via Distributed Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mechanisms for managing container images in distributed ledger networks lack standardization, automated image ownership discovery, and efficient provenance verification, leading to complexity in PKI setup, resource-intensive libraries, and manual tracking of dependencies and changes.

Innovation Solution

A method and system for accessing container images in a distributed ledger network that involves receiving requests, determining customization needs, extracting features, identifying pre-published images, and generating customized images based on reconciliation of metadata, using public keys, smart contracts, and certificates, without relying on a separate Public Key Infrastructure (PKI) framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI infrastructure is used for image provenance verification, then authentication and authorization are enabled, but device complexity and setup management complexity increase significantly

Engineering Contradiction:
Improveimage provenance verificationVSAvoidPKI infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic verification functionality from the complex PKI infrastructure and implements it directly within the distributed ledger network using native digital signatures and public key cryptography. This eliminates the need for external PKI components while maintaining security verification capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The distributed ledger acts as an intermediary that provides built-in authentication and authorization mechanisms through smart contracts and digital signatures. This mediator replaces the external PKI infrastructure, enabling provenance verification through the ledger's inherent cryptographic protocols rather than through separate PKI components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If manual tracking of image dependencies and changes is performed, then ownership discovery is possible, but productivity and automation level are reduced

Engineering Contradiction:
Improveimage ownership trackingVSAvoidautomated dependency tracking
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system implements self-service automated tracking where the distributed ledger automatically records all image dependencies, versions, and ownership changes through immutable transaction logs. Smart contracts automatically execute to track provenance information without requiring manual intervention, enabling the system to self-monitor and self-report ownership and dependency information.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms where the distributed ledger continuously provides automated feedback about image provenance, dependency relationships, and ownership changes. This feedback loop enables real-time tracking and discovery of image ownership and dependencies without manual processes.

Inventive Principle:
Principle #23Feedback

3Reliability

If resource-intensive PKI libraries are used for provenance verification, then authentication is achieved, but use of energy and computational resources increase

Engineering Contradiction:
Improveprovenance authenticationVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent removes the dependency on resource-intensive external PKI libraries and extracts only the essential cryptographic verification functionality. By using the distributed ledger's native digital signature verification and public key infrastructure, the system achieves provenance authentication with significantly reduced computational overhead and energy consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If each enterprise maintains internal governance for image provenance, then certification authority is established, but adaptability and standardization across enterprises are reduced

Engineering Contradiction:
Improveimage certificationVSAvoidcross-enterprise standardization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal distributed ledger-based provenance system that serves multiple enterprises simultaneously. The same ledger infrastructure, smart contract templates, and verification mechanisms work across different enterprises and cloud providers, providing a multi-functional platform that maintains enterprise-specific governance while enabling cross-enterprise interoperability and standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments provenance management into enterprise-specific policy layers while maintaining a unified distributed ledger infrastructure. Each enterprise can define its own governance rules and certification policies within the shared ledger framework, allowing customization at the policy level while maintaining standardization at the technical implementation level across enterprises.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10884725B2Accessing container images in a distributed ledger network environment
Publication Date: 2021.01.05 WIPRO LTD
  • US10884725B2 patent drawing
  • US10884725B2 patent drawing
  • US10884725B2 patent drawing

AI summary

A technique is provided for accessing container images in a distributed ledger network environment, in which, basis the receipt of a request from a consumer for accessing the container images, it is determined whether the container images require to be generated based on a customization performed on pre-published container images. The pre-published container images are updated in the nodes of the distributed ledger network, based on at least public keys of publishers of the pre-published container images, smart contracts, and certificates associated with the publisher. Based on the determined requirement, features for performing the customization are extracted based on inputs received from the consumer and a set of pre-published container images are identified from the pre-published container images and associated metadata from respective nodes of the network. The customized container images are generated based on reconciliation of the metadata of the identified set of pre-published container images.