Ephemeral Storage Encryption for Container Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In container runtime environments, data stored on disk can remain accessible after a container is destroyed, posing a security risk as it may be read by unauthorized entities, as existing technologies fail to ensure secure deletion and encryption of ephemeral data.

Innovation Solution

The system generates a temporary encryption key stored in kernel memory, creating an encrypted ephemeral layer accessible only to the container, which is destroyed upon container shutdown, ensuring that only the container can access and encrypt data within this layer, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If container data is stored on disk for persistence, then data availability is improved, but security is worsened because data remains accessible after container destruction

Engineering Contradiction:
Improvedata availabilityVSAvoidunauthorized access to data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the security parameter of stored data by introducing encryption. Data is encrypted on disk using encryption keys that are destroyed when containers stop, transforming the data from accessible to inaccessible state while maintaining persistence. This resolves the contradiction by allowing data to remain on disk (improving reliability) while making it unreadable without proper keys (preventing unauthorized access).

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts the encryption keys from the container runtime environment and stores them separately in the host OS kernel memory. This separation means that when a container is destroyed, its data remains on disk but the key to access it is destroyed in the host kernel, effectively removing the means to access the data while preserving the data itself for potential recovery or auditing purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If encryption keys are stored in host OS kernel memory, then access control is improved, but key security is worsened due to potential host compromise

Engineering Contradiction:
Improveaccess controlVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic key management where encryption keys are created, stored, and destroyed based on container lifecycle events. Keys are dynamically allocated when containers start and automatically destroyed when containers stop, creating a transient security relationship that adapts to operational needs while minimizing exposure time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary encryption of container data before it is written to persistent storage. By encrypting data in advance using keys that will be destroyed afterward, the system ensures data is protected from the moment of creation, preventing any window of vulnerability where unencrypted data might exist on disk.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If temporary encryption keys are destroyed upon container stop, then security is improved, but data recovery is worsened

Engineering Contradiction:
Improvedata protectionVSAvoiddata recoverability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements a cushioning mechanism by maintaining encrypted data on disk even after key destruction. The encrypted data acts as a cushion or backup state that preserves information in an inaccessible form, allowing for potential key recovery or system restoration scenarios while maintaining security during normal operation.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent creates a copy of the encryption key in the host OS kernel memory that persists beyond the container lifecycle. This key copy serves as a recovery mechanism, allowing authorized systems to retrieve and decrypt data if needed, while the original container-specific key is destroyed to maintain security during operation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11216566B1System and method for encryption of ephemeral storage
Publication Date: 2022.01.04 VIRTUOZZO INT GMBH
  • US11216566B1 patent drawing
  • US11216566B1 patent drawing
  • US11216566B1 patent drawing

AI summary

Disclosed are systems and methods for encryption of an ephemeral layer of one or more containers. An exemplary method comprises detecting a container starting execution in an operating system, generating a temporary encryption key and storing the temporary encryption key in memory of a kernel of the operating system, creating an encrypted area as the ephemeral layer in a storage device, the encrypted area accessible only by the container, providing to the container access to the encrypted area, and responsive to stopping execution of the container, destroying the temporary encryption key.