Protecting workloads in kubernetes

    公开(公告)号:GB2603710B

    公开(公告)日:2022-11-23

    申请号:GB202205814

    申请日:2020-09-04

    Applicant: IBM

    Abstract: Aspects of the invention include obtaining, via a processor, an original docker image from a customer, encrypting a disk image using content from the original docker image and encrypting a bootloader. A re-packaged image is created using the encrypted disk image and the secure encrypted bootloader. The re-packaged image is deployed by inserting the re-package image into a pod container and by means of using a mutating webhook, granting elevated privileges to said container and creating a secured Kubernetes pod for protecting workloads, wherein the secured Kubernetes pod has at least one virtual machine containing the pod container.

    HSM self-destruction in a hybrid cloud KMS solution

    公开(公告)号:GB2590588B

    公开(公告)日:2021-12-08

    申请号:GB202105442

    申请日:2019-09-19

    Applicant: IBM

    Abstract: A method includes: federating, by a computer device, a proxy hardware security module from a physical hardware security module; storing, by the computer device, the proxy hardware security module; receiving, by the computer device, a first one of a plurality of periodic identifying communications from the physical hardware security module; and erasing, by the computer device, the proxy hardware security module as a result of the computer device not receiving a second one of the plurality of periodic identifying communications.

    Integrating a communication bridge into a data procesing system

    公开(公告)号:GB2532732A

    公开(公告)日:2016-06-01

    申请号:GB201420905

    申请日:2014-11-25

    Applicant: IBM

    Abstract: A further communication bridge 14 is integrated into a running data processing system 210, which comprises a communication client 10 running a first operating system 16 having no own communication stack and at least a first communication bridge 12 running a second operating system 18 having an own communication stack 20. The first communication bridge 12 acts as a master communication bridge 26 and the further communication bridge 14 runs a third operating system 19 having an own communication stack 22. The further communication bridge 14 announces itself as a slave communication bridge 28 to the master communication bridge 26 at an announcement time and the master communication bridge 26 executes a quiesce process on a network adapter 68 and on an API 62 of the communication client 10 when there are no data packets in a queue with a sending time earlier than the announcement time. The master communication bridge 26 extracts the state of its communication stack 20, sends it to the further communication bridge 14 and resumes the network adapter 68 and the API 62.

    Protecting workloads in kubernetes

    公开(公告)号:GB2603710A

    公开(公告)日:2022-08-10

    申请号:GB202205814

    申请日:2020-09-04

    Applicant: IBM

    Abstract: Aspects of the invention include obtaining, via a processor, an original docker image from a customer, encrypting a disk image using content from the original docker image and encrypting a bootloader. A re-packaged image is created using the encrypted disk image and the secure encrypted bootloader. The re-packaged image is deployed by inserting the re-package image into a pod container and by means of using a mutating webhook, granting elevated privileges to said container and creating a secured Kubernetes pod for protecting workloads, wherein the secured Kubernetes pod has at least one virtual machine containing the pod container.

    Integrating a communication bridge into a data procesing system

    公开(公告)号:GB2532732B

    公开(公告)日:2019-06-26

    申请号:GB201420905

    申请日:2014-11-25

    Applicant: IBM

    Abstract: Integrating a further communication bridge into a running data processing system. The data processing system includes a communication client running a first operating system having no own communication stack and at least a first communication bridge running a second operating system having an own communication stack. The first communication bridge is configured as a master communication bridge. The further communication bridge announces itself as a slave communication bridge at an announcement time. The master communication bridge executes a quiesce process on the network adapter and on the API of the communication client when there are no data packets in the queue with a sending time earlier than the announcement time. The master communication bridge extracts the state of its communication stack and sends it to the further communication bridge. The master communication bridge resumes the network adapter and the API.

    Dynamically assigning network addresses

    公开(公告)号:GB2558163A

    公开(公告)日:2018-07-11

    申请号:GB201420129

    申请日:2014-11-12

    Applicant: IBM

    Abstract: A server (14) is provided in a network (210) for dynamically assigning network addresses to virtual network adapters in virtual machines (VMs) (10,12). A sniffer (30) extracts network IP addresses associated with MAC addresses of the VMs from packets sent between the server and the VMs. A table (26, 28) stores the extracted addresses with the corresponding MAC addresses and status information for each VM. If a VM status is suspended, a daemon (32) periodically sends renewal requests to the server so that the VMs assigned IP address is not reassigned to another network component while it is suspended. The renewal messages cease when the VM returns to operation.

Patent Agency Ranking