Invention Grant
- Patent Title: Block device signature-based integrity protection for containerized applications
-
Application No.: US16671064Application Date: 2019-10-31
-
Publication No.: US11263309B2Publication Date: 2022-03-01
- Inventor: Md Nazmus Sakib , Jeffrey A. Sutherland , Deven Robert Desai , Jaskaran Singh Khurana , Scott Randall Shell , Jessica M. Krynitsky
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Fiala & Weaver P.L.L.C.
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/52 ; G06F21/51

Abstract:
Integrity verification of a containerized application using a block device signature is described. For example, a container deployed to a host system is signed with a single block device signature. The operating system of the host system implements an integrity policy to verify the integrity of the container when the container is loaded into memory and when its program code executes. During such events, the operating system verifies whether the block device signature is valid. If the block device signature is determined to be valid, the operating system enables the program code to successfully execute. Otherwise, the program code is prevented from being executed. By doing so, certain program code or processes that are not properly signed are prevented from executing, thereby protecting the host system from such processes. Moreover, by using a single block device signature for a container, the enforcement of the integrity policy is greatly simplified.
Public/Granted literature
- US20210133313A1 BLOCK DEVICE SIGNATURE-BASED INTEGRITY PROTECTION FOR CONTAINERIZED APPLICATIONS Public/Granted day:2021-05-06
Information query