Cloud key management for system management
By using asymmetric key pairs in the cloud platform environment, the public key encrypts the credentials and stores them in the credential manager, while the private key is decrypted by the credential usage component. This solves the security vulnerability of credential management in the cloud platform and achieves higher security and flexibility.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-18
- Publication Date
- 2026-03-17
AI Technical Summary
Communication and security management between software systems running in different trust zones pose risks of security vulnerabilities and loss of control over confidential data, especially in cloud platform environments where existing technologies struggle to effectively manage and protect credential information.
An asymmetric key pair approach is used, with the public key stored in the credential manager and the private key stored in the credential usage component. The credential is encrypted with the public key and decrypted at the credential usage component, ensuring the security of the credential during transmission and storage and preventing the private key from being decrypted in the credential manager.
It improves the security and flexibility of voucher management, reduces the risk of unauthorized operations, simplifies system complexity, and enhances the protection of voucher information.
Smart Images

Figure CN116155528B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to computer-implemented methods, software, and systems for data processing. BACKGROUND
[0002] Software complexity is continually increasing and is causing changes in the lifecycle management and maintenance of software applications and platform systems. Software applications and systems can provide services and access to resources. Management of software applications and systems that provide services to end users and resources to customers and end users can be associated with security requirements for requesting authorization. Customer needs are shifting with increasing demands for flexibility and efficiency in process and landscape management. SUMMARY
[0003] Implementations of the present disclosure are generally directed to computer- implemented methods for credential management.
[0004] One example method can include operations such as receiving, in a landscape environment, a request associated with authentication of a requestor; and responsive to receiving the request, loading, at a credential manager running in the landscape environment, an encrypted credential responsive to the request, wherein the encrypted credential is saved at storage by the credential manager, wherein the encrypted credential comprises a credential encrypted with a public key and provided to the credential manager in encrypted form for use in requesting authentication in the landscape environment; and providing the encrypted credential to a credential using component running in the landscape environment for decrypting the encrypted credential with a private key, wherein the private key is saved by the credential using component in the landscape environment, and wherein the private key and the public key are an asymmetric key pair for authorizing the request.
[0005] In some instances, the example method can include the received request is a request associated with authentication of a requestor to perform an operation at a software system, wherein the request is received at a first trust zone of the landscape environment and the software system is running in a second trust zone of the landscape environment.
[0006] In some instances, the received request in the example method can be a request associated with authentication of a requestor to perform an operation at a software system, wherein the credential using component is running in a first trust zone of the landscape environment, and wherein the credential manager is running in a second trust zone of the landscape environment separate from the first trust zone.
[0007] In some instances, the software system is running in a first trust zone of the landscape environment.
[0008] In some instances, responsive to receiving the encrypted credential from the credential manager, the encrypted credential is decrypted at the credential using component, and wherein the decrypted credential is provided by the credential using component to the software system to authenticate the identity of the requestor.
[0009] In some instances, the example method can further include operations such as: responsive to receiving the encrypted credential at the credential use component, decrypting the encrypted credential with the private key; and sending a request for the software system to perform the operation, wherein the sent request includes the decrypted credential for authorizing performance of the operation associated with the received request for authentication.
[0010] In some instances, the requestor can be authorized to perform the operation at the software system, and wherein the received request identifies the software system by referencing an internal identifier as a target context for performing authentication of the encrypted credential.
[0011] In some instances, the credential manager can run as part of a cloud platform application to provide a landscape management service for the software system, wherein the software system runs on cloud platform infrastructure of a first trust zone of a landscape environment.
[0012] In some instances, the credential manager and the credential use component can run on separate isolated cloud platforms.
[0013] In some instances, the example method can further include: receiving instructions at a user interface associated with the credential manager to create a key pair including a public key and a private key; and responsive to the received instructions, configuring the credential manager and the credential use component to respectively save the public key and the private key, wherein the configuring includes: providing the public key to be saved by the credential manager; and providing the private key to be saved at the credential use component.
[0014] In some instances, the key pair can be associated with an account involving one or more management systems, and wherein one or more users are associated with the account.
[0015] In some instances, the example method can include receiving at a user interface associated with the credential manager credentials provided by a user for accessing the software system from a plurality of systems associated with the credential manager; encrypting the received credentials at the user interface by using the private key saved at the credential use component; and providing the encrypted credentials to a cloud landscape manager to save the encrypted credentials, wherein the cloud platform manager includes the credential manager and domain specific logic for configuring, managing, and saving platform landscape configurations of a platform landscape environment, wherein the platform landscape environment includes the software system and is associated with one or more customer accounts, and wherein each customer account is associated with different credentials authorizing access to at least one of the software systems.
[0016] The present disclosure also provides a computer-readable storage medium coupled to one or more processors and having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to perform operations in accordance with implementations of the methods provided herein.
[0017] The present disclosure also provides a system for implementing the methods provided herein. The system includes one or more processors, and a computer readable storage medium coupled to the one or more processors having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to perform operations in accordance with implementations of the methods provided herein.
[0018] It should be appreciated that methods according to the present disclosure can include any combination of the aspects and features described herein. That is, methods according to the present disclosure are not limited to the combinations of aspects and features specifically described herein, but also include any combination of the aspects and features provided.
[0019] The details of one or more implementations of the present disclosure are set forth in the accompanying drawings and the description below. Other features and advantages of the present disclosure will become apparent from the description and drawings, and from the claims. BRIEF DESCRIPTION OF DRAWINGS
[0020] Figure 1 An example system that can perform implementations of the present disclosure is depicted.
[0021] Figure 2 is a system diagram of an example system including a landscape environment configured to manage credentials in a secure manner according to implementations of the present disclosure.
[0022] Figure 3 is a block diagram of an example method for credential management according to implementations of the present disclosure.
[0023] Figure 4 is a system diagram of an example landscape environment including a credential manager and a credential usage component for securely holding credentials authenticating requests at a management system according to implementations of the present disclosure.
[0024] Figure 5 is a sequence diagram of an example method for configuring, holding, and using credentials authenticating requests related to a management system according to implementations of the present disclosure.
[0025] Figure 6 is a schematic diagram of an example computer system that can be used to perform implementations of the present disclosure. DETAILED DESCRIPTION
[0026] The present disclosure describes various tools and techniques for credential management.
[0027] In some instances, customers manage and operate their software applications and systems that are hosted in different platform environments. For example, a customer system can be hosted in an account region (or platform space) defined for the customer on a cloud platform. The customer can use a landscape management service provided by a service provided to manage the landscape (or environment) in which the customer's applications and systems run. Cloud computing is associated with the development and management of a network of mixed applications that span across various environments and trust zones (e.g., platform spaces or environments controlled by different owners). Different applications can be provided by different software providers and can provide different resources and / or services.
[0028] Landscape management is associated with providing support to customers running software applications and systems in various platform environments (e.g., interconnected or isolated). In some instances, the software applications and systems can be hosted in a public cloud platform environment. In some of these instances, multiple applications and systems associated with a customer can be hosted in a public cloud region of the cloud platform and can be managed based on services provided by a landscape management tool.
[0029] In some instances, a customer's applications and / or systems can be coupled with other services and applications associated with the landscape management services provided for the applications and / or systems to run correctly (e.g., in compliance with requirements to provide a request to an end user). For example, multiple entities of an application can be launched to support higher demands of a given application to meet high availability requirements of the application.
[0030] In some instances, communication between entities running in different trust zones and implementing different functionalities provided by different providers and sources is associated with increased security concerns. Communication between different entities in a network of services and applications can introduce security vulnerabilities and risks of uncontrolled confidential data. Access to a customer's landscape and systems can be associated with high security restrictions.
[0031] In some instances, a landscape management tool or a landscape management solution can be implemented and hosted as a software as a service (SaaS) solution that can be communicatively coupled with one or more platform environments capable of managing software applications and systems. In some instances, a landscape management tool can provide landscape management services to a customer's hosted software systems at a given cloud platform. In some instances, a landscape management tool can receive a request associated with managing a software system.
[0032] In some instances, a management system can run in a customer's trust zone that is different from a trust zone in which a landscape management tool can run. The management applications and / or systems can be associated with authentication requirements for authenticating execution requests of operations (or actions) requested by other applications and / or users.
[0033] In some instances, the landscape management tool can provide an interface for receiving requests to configure authentication rules for accessing systems from a management system in a secure manner. In some instances, the landscape management tool can be configured to provide credential management to support secure enforcement of requests at the management system. The landscape management tool can store a protected version of a credential for authentication at the management system, which can be used when requesting an operation or action for enforcement. In some instances, the protected version of the credential can be an encrypted version of the credential, which can be received by the landscape management tool to save. In some instances, the credential can be provided by a user having an account on the management system. For example, the credential can relate to a user being authorized for a given user role to have access to certain operations for a certain period of time, for a user group, or for a list of identifiers users identified by their user identifiers and / or names, etc.
[0034] In some instances, the landscape management tool can be configured to send instructions (or requests) to a management system to request an operation to be performed by an agent (e.g., an enforcement engine) running in a defined target environment. The agent can be hosted in a location very close to the management system, for example, running within a platform space of a trust zone of the management system. In some instances, the landscape management tool can send instructions to the agent to request an operation to be performed at a first system, where the instructions can include a protected version of a credential to request authorization for the operation enforcement. The protected version of the credential can be decrypted by the agent within the trust environment of the management system, and the decrypted credential can be used to authenticate the request for operation enforcement.
[0035] In some instances, the landscape management tool can provide credential management logic to store credentials associated with different management systems and different customers and / or users. For example, the landscape management tool can organize a store of credentials identified based on system identifiers, user identifiers, and / or user role identifiers, etc. In some instances, upon receiving a request at the landscape management tool to perform an operation at a first system, the request can be evaluated to determine a corresponding protected credential (e.g., by loading the credential based on domain logic, by querying a credential store, or other suitable examples).
[0036] In some instances, the landscape management tool can only save encrypted credentials in an encrypted format without requiring a key to decrypt the credential, and without requiring access to the credential in decrypted format. In some instances, the determined protected credential can be provided to an agent to decrypt the protected version of the credential and request authorization for enforcement of the requested operation based on the decrypted credential. In some instances, the agent can be hosted in a trust network zone of the requester (e.g., a user or an application). The agent can have access to a persistent store where private keys for decrypting corresponding encrypted credentials can be maintained.
[0037] In some instances, the agent can be configured to store a relevant private key of the associated management system, and thus be able to decrypt received encrypted credentials on demand. In some instances, when a request includes encrypted credentials, the encrypted credentials are decrypted upon receipt of the request to perform an operation on the management system. In those instances, the agent can store logic to decrypt the credentials, without storing the credentials themselves or storing the credentials in encrypted format, and the landscape management tool can store the credentials, but only in encrypted format. In some instances, configuration of the request and determination of the credentials that authorize the request based on the landscape management logic to perform the request at the management system can be associated with multiple advantages. For example, separation of storage of the decryption key and the encrypted credentials can provide improved security and flexibility.
[0038] In some instances, the credentials that authenticate the request at the management system can be provided by a user, and can be encrypted with a public key, where the encrypted credentials can be stored at the landscape management tool (or at a storage associated with the tool) to preserve the credential information. A private key corresponding to the public key to form a key pair (e.g., an asymmetric key pair) can be stored at the agent. The agent can request to perform an operation in a trust zone of the management system. Thus, the private key and the public key can be stored at separate locations, and the encrypted credentials can be stored with the public key at a storage location managed by the landscape management tool.
[0039] In some instances, configuration of the landscape management tool and the agent can ensure that the credentials (e.g., as private protected data) can be decrypted by the owner or possessor of the decryption key in the context of a specific use case for invoking a given operation at the management system. Since the owner of the private key does not have general access to the credentials, but uses the credentials provided by the landscape management tool at the time of the request, the risk of security attacks and credential compromise is reduced. In those instances, the landscape management tool cannot access the private key to decrypt the encrypted credentials, and cannot use the credentials in decrypted form, and thus provides them to the credential using component in encrypted form. As a result, a security breach at the landscape management tool can be associated with a lower risk of performing unauthorized operations at the management system.
[0040] In some instances, the private key can be saved with non-confidential data in a semantically useful context, without unnecessarily increasing the complexity of the agent implementation. The organization can be associated with increased consistency and reduced complexity of the agent logic implementation.
[0041] Figure 1An example architecture 100 according to implementations of the present disclosure is depicted. In the depicted example, the example architecture 100 includes a client device 102, a client device 104, a network 110, and a cloud environment 106 and a cloud environment 108. The cloud environment 106 can include one or more server devices and databases (e.g., processors, memory). In the depicted example, a user 114 interacts with the client device 102 and a user 116 interacts with the client device 104.
[0042] In some examples, the client device 102 and / or the client device 104 can communicate with the cloud environment 106 and / or the cloud environment 108 through the network 110. The client device 102 can include any appropriate type of computing device, such as a desktop computer, a laptop computer, a handheld computer, a tablet computer, a personal digital assistant (PDA), a cellular telephone, a web appliance, a camera, a smart phone, an enhanced general packet radio service (EGPRS) mobile phone, a media player, a navigation device, an email device, a game console, or any appropriate combination or
[0043] In some implementations, the cloud environment 106 includes at least one server and at least one data store 120. In Figure 1 In the depicted example, the cloud environment 106 is intended to represent a variety of forms of servers, including but not limited to web servers, application servers, proxy servers, network servers, and / or server pools. Generally, a server system accepts requests for application services and provides such services to any number of client devices (e.g., the client device 102 on the network 110).
[0044] According to implementations of the present disclosure, and as described above, the cloud environment 106 can host applications and databases that run on a host infrastructure. In some instances, the cloud environment 106 can include a plurality of cluster nodes that can represent physical or virtual machines. The hosted applications and / or services can run on VMs that are hosted on the cloud infrastructure. In some instances, one application and / or service can run as a plurality of application instances on a plurality of corresponding VMs, with each instance running on a corresponding VM.
[0045] Figure 2 A system diagram of an example system including a landscape environment 200 configured to manage credentials in a secure manner according to implementations of the present disclosure.
[0046] In some instances, landscape environment 200 includes customer network 205, cloud platform 210, and public infrastructure as a service (IaaS) cloud account 220 as separate network segments that can be managed by different entities. In some instances, a customer can deploy, launch, and manage software applications and systems on public IaaS cloud account 220 based on landscape management services provided by cloud landscape manager 240 hosted on cloud platform 210. Cloud landscape manager 240 can receive requests initiated through user interface (UI) applications and / or browsers 235 running on computing devices connected to customer network 205, and these requests are directed to actions and / or operations to be performed on one or more systems running on public IaaS cloud account 220. For example, a user (e.g., administrator) 230 can request to launch or stop an application running at the customer’s public IaaS cloud account 220 by sending a request to perform an operation at cloud landscape manager 240 through a mobile portable device connected to customer network 205.
[0047] In some instances, customer network 205 is managed according to customer network requirements defined for the customer and can be considered a trust zone of the customer. For example, a customer’s applications, such as UI applications or browsers 235, can be hosted at customer network 205 as a secure environment for requesting operations associated with the customer’s cloud-based applications and systems (e.g., management system 260). In some instances, customer network 205 and the customer’s public IaaS cloud account 220 can be part of a first trust zone of landscape environment 200.
[0048] In some instances, a customer can have an associated management system 260 running on public IaaS cloud account 220. Public IaaS cloud account 220 provides cloud platform resources for hosting and running software applications and systems managed by the customer associated with customer network 205.
[0049] In some instances, cloud platform 210 portion of landscape environment 200 can be considered a second trust zone hosting cloud landscape manager 240, where the second trust zone is different from the trust zone of the software management provided by cloud landscape manager 240. Cloud landscape manager 240 can provide services to systems including management system 260 running on public IaaS cloud account 220. In some instances, the services provided by cloud landscape manager 240 can be associated with performing system management tasks at management system 260.
[0050] In some instances, end user 230 can trigger execution of operations in landscape environment 200 through a UI application or browser 235. UI / browser 235 can communicate with cloud landscape manager 240. In some instances, cloud landscape manager 240 implements backend services that are the actual domain logic and functionality that combines various atomic operations into overall higher-granularity operations such as workflows. The domain logic implemented at cloud landscape manager 240 can support flexible execution of different management processes.
[0051] In some instances, cloud landscape manager 240 can request execution of operations at systems of management system 260 through an agent such as execution engine 245. As previously described, cloud landscape manager 240 can be a landscape management tool. Cloud landscape manager 240 can store encrypted credentials associated with systems including management system 260. In some instances, the credentials can be provided to UI / browser 235 by end user 230 and can be encrypted with a public key and provided to cloud landscape manager 240 in encrypted form. Cloud landscape manager 240 can communicate with execution engine 245 to request execution engine 245 to request execution of operations based on authorization from the provided encrypted credentials. In some instances, execution engine 245 can be invoked to facilitate communication with management system to execute operations. In some instances, execution engine 245 runs in a first trust zone of the customer and can bypass firewall configurations that can exist between different trust zones (e.g., between a first trust zone of the management system and a second trust zone of cloud platform 210) to perform direct communication with the management system. In more cases, customer network 205 and public IaaS cloud account 220 can be part of a single trust zone or can be separate trust zones. In those instances, landscape environment 200 includes three trust zones corresponding to customer network 205, cloud platform 210, and public IaaS cloud account 220.
[0052] In some instances, execution engine 245 can store a decryption key to decrypt the provided encrypted credentials and use the decryption key to authorize execution of operations requested at the management system. In some instances, execution engine 245 is implemented as a light engine that includes a limited implementation of logic with reduced complexity to reduce execution disruptions due to maintenance actions (e.g., updates). In some instances, execution engine 245 is deployed at the customer’s public IaaS cloud account to support secure execution of landscape management operations.
[0053] In some examples, the execution engine 245 receives instructions to execute a request based on logic implemented at the cloud landscape manager 240. The cloud landscape manager 240 implements logic for the configuration of the landscape environment 200. In some examples, the implemented configuration can include hostnames, IP addresses, system structures, and passwords, among other potential confidential data related to landscape management.
[0054] In some examples, the cloud landscape manager 240 tightly holds the domain logic and associated credentials together to preserve the association between the logic and the related credentials. In some examples, by preserving the association between the domain logic and the credentials, the cloud landscape manager 240 can be implemented with reduced complexity and without relying on references to separate secure storage.
[0055] In some examples, the management system 260 is associated with system-specific authentication 250 that is defined per system and includes authentication requirements (e.g., authentication models, metadata, rules, etc.) for performing different operations.
[0056] Figure 3 is a block diagram of an example method 300 for credential management according to implementations of the present disclosure. In some examples, the example method 300 can be implemented in the landscape environment 200 and can be performed by Figure 2 the cloud landscape manager 240. The example method 300 can be implemented at a credential manager (or landscape management tool as previously described) that provides a service for secure management of credentials for operations requested at a management system by users associated with the management system (e.g., a given account, group, or user role, etc.). In some examples, a user can request, through the credential manager, to perform an operation on the management system. The performance of the operation can be associated with authentication requirements and credential authentication.
[0057] At 310, a request associated with performance of an operation at a software system is received at a credential manager. In some examples, the credential manager can be deployed as part of a cloud environment manager, such as shown by the cloud environment manager 240. Figure 2
[0058] In some examples, the credential manager can run as part of a cloud platform application that includes the software system in order to provide landscape management services for the software system. The software system can run on cloud platform infrastructure of a first trust zone of a landscape environment. The software system can be similar to, for example, the management system 260. Figure 2
[0059] The received request can be received via a web application, a browser, a desktop application, or a native application, among other examples of applications that can be used to send a request for performance of an operation. In some examples, the request can be received by a web application that isFigure 3 The UI / browser 235 of the software system receives the request. The request can be received from a first trust zone managed by a customer associated with the software system. Further, the request can be initiated by one user or a group of users, or can be based on a schedule implemented at the application for performing the request. Other suitable examples of how the request can be initiated in an automated or manual manner can be used.
[0060] In some instances, the received request can be received from a UI application or browser connected to a customer network of a customer associated with a system running in a landscape environment managed by a cloud landscape manager. The received request can be a request to perform a management operation that will be authenticated prior to software system execution.
[0061] In some instances, the received request is received from a user authorized to perform an operation at the software system (e.g., an end user 230 of the software system). The received request identifies the software system by referencing at least one of a system name or a network address. Figure 2
[0062] At 320, an encrypted credential responsive to the request is loaded at a credential manager running in a second trust zone of the landscape environment. The encrypted credential can be used to authorize performance of the operation. In some instances, the encrypted credential can be saved directly with other information related to the software system (e.g., a system name, IP address, or other suitable information). The credential manager can retain a reference to the public key as an encryption key. In some instances, the public key can be used for further encryption, such as based on a proof fingerprint.
[0063] In some other instances, the credential manager loads the encrypted credential by querying and invoking the encrypted credential from storage. The encrypted credential can be saved at storage and can be a protected version of the credential encrypted with a public key of a customer associated with the request received at 310. In some instances, the public key can be associated with a credential of a user of the software system. The encrypted credential can be invoked based on an identification of the system that the request is performed.
[0064] At 330, the encrypted credential is provided by the credential manager to a credential use component running in a first trust zone of the landscape environment for decrypting the encrypted credential with the private key. The credential use component can be a component that implements logic to process received requests associated with one or more management systems and invoke performance of actions at the one or more management systems (based on the received requests). The private key is maintained by the credential use component and the private and public keys can form an asymmetric key pair generated for authorization of requests for performance at the software system. The key pair can be generated at the first trust zone as a dedicated key pair for a particular credential associated with the software system. In some instances, the key pair can be associated with an account with the one or more management systems and one or more users can be associated with the account.
[0065] In some instances, the credential manager and the credential use component can run on separate isolated cloud platforms.
[0066] In some instances, the encrypted credential is decrypted at the credential use component in response to receiving the encrypted credential from the credential manager.
[0067] In some instances, the decrypted credential is provided by the credential use component to the software system to authenticate the identity of the user associated with the request. In some instances, the decryption can be performed upon receipt of the encrypted credential and can be performed based on a pre-stored private key. In some instances, the private and public keys are an asymmetric key pair generated for authorization of requests for performance at the software system. The private and public keys can be stored in separate entities to support improved security in performance of operations at the management systems through the landscape management solution.
[0068] In some instances, the encrypted credential is decrypted at the credential use component in response to receiving the encrypted credential from the credential manager. In some instances, the credential use component successfully decrypts the encrypted credential when the private key matches the public key referenced by the encrypted credential. The decrypted credential can be provided by the credential use component to the software system to authenticate the identity of the user associated with the request.
[0069] In some instances, the encrypted credential is decrypted at the credential use component on demand and in response to receiving the encrypted credential. In some instances, after decryption, a request to perform an operation on the software system is sent. The sent request includes the decrypted credential for authorization of performance of the operation. The credential use component can or can not maintain a decrypted version of the credential.
[0070] Figure 4 is a system diagram of an example landscape environment 400 including a credential manager and a credential use component for securely maintaining credentials for authentication of requests at management systems in accordance with implementations of the present disclosure.
[0071] In some instances, landscape environment 400 includes a first trust zone 405 and a second trust zone 410. In some instances, a trust zone can be defined as a network area of a landscape that is considered a secure area for inter-entity communication. Multiple trust zones can be considered a single group, where communication between entities can not be monitored and filtered through a firewall. In some instances, communication between one trust zone and another trust zone, or between a group of trust zones and another group of trust zones, can be performed according to security requirements for request and resource exchange between different networks.
[0072] In some instances, there can be an untrust zone between first trust zone 405 and second trust zone 410, where at least some requests between the first trust zone and the second trust zone are sent through the untrust zone. Communications handled with entities operating in the untrust zone can be handled according to security rules defined for incoming and outgoing network traffic.
[0073] In some instances, first trust zone 405 contains a platform infrastructure and credential usage component 460 for hosting and running a UI application 420 to support receiving requests for performing operations at software systems managed by a customer. As an example, UI application 420 can be similar to UI / browser 235 of Figure 2 , and credential usage component 460 can be similar to execution engine 245 of Figure 2 . In some instances, execution engine 245 can be hosted on the same cloud platform where one or more managed software systems are hosted.
[0074] In some instances, second trust zone 410 includes a landscape manager 430 that is a landscape management tool, such as a landscape management cloud application. As an example, landscape manager 430 can be similar to cloud landscape manager 240 of Figure 2 . Landscape manager 430 includes a credential manager 440 (e.g., credential manager discussed in Figure 3 ) and domain logic 435 for handling requests for performing operations related to landscape management of a customer’s managed systems (e.g., systems hosted at first trust zone 405).
[0075] In some instances, at the first trust zone 405, the UI 420 is a component that provides the end user 415 access to enter a set of credentials that will be saved at the landscape manager 430 and used by the credential usage component 460 to authorize requested operations performed by the landscape manager 430 at the management system. In some instances, the UI 420 includes logic that receives information from the end user 415 that includes credentials for a particular software system managed by the landscape manager 430. The UI 420 can encrypt the credentials according to an encryption scheme and provide them to the landscape manager 430. The encrypted credentials 445 can include additional verification(s) that, when evaluated later, can be used to determine the authenticity of the encrypted credentials 445. For example, the encryption can be performed with a checksum, a signature, and a validity date, among others.
[0076] In some instances, the landscape manager 430 can communicate directly with the UI 420. The landscape manager 430 includes actual domain logic 435 of how to manage systems running on underlying infrastructure (e.g., private cloud IaaS) and a credential manager 440. The credential manager 440 includes logic that saves the encrypted credentials 445 received from the UI 420 in association with the management system. In some instances, the encrypted credentials 445 can be saved directly with other non-confidential information related to the credentials. For example, the encrypted credentials 445 can be saved with information including, but not limited to, system name, virtual machine name hosting the system, IP address of the system, DNS name, certificates, and / or user account information (e.g., user password, user identifier, user role), among other suitable information.
[0077] In some instances, the credential manager 440 can receive a public key from the credential usage component running at the first trust zone 405. In some instances, a single public key can be associated with multiple credentials associated with multiple systems and one or more customers. In other instances, each credential can be encrypted with a separate, different public key. In some instances, the landscape manager 430 can maintain a reference of the encrypted credentials 445 to the encrypted public key 450 for that credential. In some instances, the public key can be used for further encryption performed by the landscape manager 430.
[0078] In some instances, the private key 425 can be used to encrypt credentials, and the public key 450 that can decrypt credentials can form an asymmetric key pair generated by the asymmetric key generator 422. In some instances, the asymmetric key generator 422 can be configured as part of the credential usage component 460. In some other instances, the asymmetric key generator 422 can be an external component, where the key transfer to the credential usage component and the landscape manager, respectively, can be done automatically through a network, through inter-process communication, and through user manual activity (e.g., uploading a certificate), among other examples of data transfer.
[0079] In some instances, the credential manager 440 can receive a request from the UI 420 to perform an operation related to a first management system. Upon receiving the request, the credential manager 440 can load a set of encrypted credentials 445 responsive to the received request and trigger an action(s) for requesting the credential usage component 460 to perform the operation at the first management system. In some instances, the action of triggering the credential usage component 460 to request the performance of the operation can include providing the encrypted credentials 445 loaded from the credential manager 440 to the credential usage component 460. In some instances, the triggering request to perform the action can be based on a domain logic portion of the domain logic 435 associated with the first management system.
[0080] In some instances, in response to triggering the action for the credential manager 440 to perform the operation at the first management system, the credential usage component 460 can retrieve the received request to perform the domain logic provided with the triggered action and the encrypted credentials 445 (e.g., provided as a payload of the triggering request). The credential usage component 460 can include a decrypter 427 that can use the internally held private key 425 to decrypt the encrypted credentials 445 provided by the credential manager.
[0081] Figure 5 is a sequence diagram of an example method 500 for configuring, holding, and using credentials for authenticating requests related to a management system, in accordance with implementations of the present disclosure. In some instances, the method 500 can be implemented in Figure 2 the landscape environment 200 of FIG. 1, Figure 4 the landscape environment 400 of FIG. 2, or any other suitable system or environment. As shown, the example method 500 can be performed in conjunction with a UI application 510 (e.g., similar to or different from the UI 235 of FIG. 1 or the UI 420 of FIG. 2), a credential manager 515 (e.g., similar to or different from the credential manager and the landscape manager discussed throughout this application and with respect to Figure 2 , Figure 4 and Figure 2 , Figure 3 and Figure 4 As shown, the example method 500 can be performed in conjunction with a UI application 510 (e.g., similar to or different from the UI 235 of FIG. 1 or the UI 420 of FIG. 2), a credential manager 515 (e.g., similar to or different from the credential manager and the landscape manager discussed throughout this application and with respect to Figure 2the execution engine 245 or Figure 4 associated with the credential use component 460) are implemented.
[0082] In some instances, the example method 500 includes configuring a credential manager and a credential use component that provide secure execution of landscape management operations requested by a user at a landscape management tool for operations performed at a management system. The execution of the method 500 can be performed in accordance with the described methods of performing execution of operations that are authenticated based on credentials provided in encrypted form by a credential manager and decrypted by a credential use component. The method 500 can be performed in conjunction with the credential manager 515 and the credential use component 520 as they are hosted and run at different trust zones of a landscape environment.
[0083] In some instances, the method 500 includes operations associated with setting encryption and decryption keys for protecting credentials associated with a management system, configuring a credential manager 515 and a credential use component 520 for secure exchange of protected information to authorize a request to perform an action (or actions) at a management system, and processing a request to perform an operation, where the request is received at a landscape manager for performance at the management system based on processing of the execution by a credential use component that is run at the same trust zone as the management system.
[0084] In some instances, the credential manager 515 and the credential use component 520 are configured to store key information for encrypting and decrypting confidential information. The credential manager 515 stores a key for encrypting confidential information, while the credential use component 520 stores a key for decrypting the confidential information associated with the key used for encryption. In some instances, the credential information includes a credential for authentication at a management system associated with the credential manager 515. The credential can be similar to the credential discussed in Figures 2-4
[0085] In some instances, the initiation of the key generation trigger action 525 triggers the generation of a key pair that includes a public key and a private key. In some instances, the trigger action can be initiated manually by a user (e.g., an administrator and a user of a particular role, etc.) or automatically (e.g., based on a scheduled event). At 530, the key pair is provided to the credential use component 520. The key pair includes a private key (PrK) 540 and a public key (PuK) 535. The credential use component 520 can save the private key 545. At 555, the credential use component 520 provides the public key 535 to the credential manager 515 for saving.
[0086] At 570, a request is received at the credential manager 515 to load the public key and use the public key to encrypt (at 575) credentials entered by the user through the UI application 510. At 557, the credentials are encrypted at the UI application and provided to the credential manager 515 at 581. At 582, the credential manager 515 saves the encrypted credentials.
[0087] At 585, a request is received at the credential manager 515 to trigger performance of an operation (or action) at the management system. In some instances, the received request can be similar to the request received at 310 of FIG. 3. In some instances, the request is received from a user and provided through the UI application 510. In other instances, the triggering performance of the operation can be invoked automatically. For example, the operation triggered at 585 can be performed according to a schedule of performance of operations related to the management system associated with the credential manager. Figure 3
[0088] At 588, in response to the triggered action, the credential manager 515 sends a request to the credential use component 520 to load the associated private key in response to the requested operation for performance. At 589, the credential manager 515 loads the encrypted credentials corresponding to the triggered action and, at 590, provides the encrypted credentials to the credential use component 520.
[0089] At 592, the credential use component decrypts (at 588) the encrypted credentials based on the loaded associated private key and, at 593, provides the decrypted credentials for requesting performance of the operation. At 593, the credential use component 520 sends a request to the management system to perform the operation.
[0090] Referring now to Figure 6 , a schematic diagram of an example computing system 600 is provided. The system 600 can be used for the operations described in connection with the implementations described herein. For example, the system 600 can be included in any or all of the server components discussed herein. The system 600 includes a processor 610, a memory 620, a storage device 630, and an input / output device 640. The components 610, 620, 630, and 640 are interconnected using a system bus 650. The processor 610 is capable of processing instructions for execution within the system 600. In some implementations, the processor 610 is a single-threaded processor. In some implementations, the processor 610 is a multi-threaded processor. The processor 610 is capable of processing instructions stored by the memory 620 or the storage device 630 to display graphical information for a user interface on the input / output device 640.
[0091] Memory 620 stores information within system 600. In some embodiments, memory 620 is a computer readable medium. In some embodiments, memory 620 is a volatile memory unit. In some embodiments, memory 620 is a non-volatile memory unit. Storage device 630 can provide mass storage for system 600. In some embodiments, storage device 630 is a computer readable medium. In some embodiments, storage device 630 can be a floppy disk device, a hard disk device, an optical disk device, or a tape device. Input / output device 640 provides input / output operations for system 600. In some embodiments, input / output device 640 includes a keyboard and / or pointing device. In some embodiments, input / output device 640 includes a display unit for displaying graphical user interfaces.
[0092] The described features can be implemented in digital electronic circuitry, or in computer hardware, firmware, software, or in combinations of them. The apparatus can be implemented in a computer program product tangibly embodied in an information carrier (e.g., in a machine-readable storage device for execution by a programmable processor); and method operations can be performed by a programmable processor executing a program of instructions to perform desired functions by operating on input data and generating output. The described features can be implemented advantageously in one or more computer programs that are executable on a programmable system including at least one programmable processor coupled to receive data and instructions from, and to transmit data and instructions to, a data storage system, at least one input device, and at least one output device. A computer program is a set of instructions that can be used, directly or indirectly, in a computer to perform a desired activity or bring about a desired result. A computer program can be written in any form of programming language, including compiled or interpreted languages, and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
[0093] As an example, a suitable processor for executing an instruction program includes a general purpose and special purpose microprocessor, and the like, either single-chip or multi-chip. Generally, a processor will receive instructions and data from a read-only memory or a random access memory or both. The elements of a computer can include a processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer also can include, or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data files, such as magnetic, magneto-optical disks, or optical disks. A storage device suitable for tangibly embodying computer program instructions and data is used in the
[0094] To provide for interaction with a user, the features can be implemented on a computer having a display device, e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor, for displaying information to the user and a keyboard and a pointing device, e.g., a mouse or a trackball, by which the user can provide input to the computer. The features can be implemented using computer-readable media for carrying or having computer-executable instructions or data structures stored thereon. Such computer- readable media can be any available media that can be accessed by a general purpose or special purpose computer, such as a RAM, ROM, EEPROM, CD-ROM, optical disk, etc. Computer-readable media
[0095] These features can be implemented in a computer system that includes a back-end component, such as a data server, or that includes a middleware component, such as an application server or an Internet server, or that includes a front-end component, such as a client computer having a graphical user interface or an Internet browser, or any combination of them. The components of the system can be connected by any form or medium of digital data communication, such as a communication network. Examples of communication networks include, e.g., a LAN, a WAN, and the computers and networks forming the Internet.
[0096] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a network, such as the described one. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.
[0097] Also, the logic flows depicted in the figures do not require the particular order shown, or sequential order, to achieve desirable results. In addition, other actions can be provided, or operations can be eliminated, from the described flows, and other components can be added to, or removed from, the described systems. Accordingly, other implementations are within the scope of the following claims.
[0098] A number of implementations have been described. Nevertheless, it will be understood that various modifications can be made without departing from the spirit and scope of the disclosure. Accordingly, other implementations are within the scope of the following claims.
[0099] In view of the subject matter described above, the following examples list is disclosed, wherein a feature of an isolated example or a combination of more than one feature of said examples, and optionally in combination with one or more features of one or more other examples, are other examples falling within the disclosure.
[0100] Example 1. A computer-implemented method for credential management, the method performed by one or more processors, wherein the method comprises:
[0101] receiving, in a landscape environment, a request associated with authentication of a requestor; and
[0102] in response to receiving the request:
[0103] loading, at a credential manager running in the landscape environment, an encrypted credential in response to the request, wherein the encrypted credential is saved at storage by the credential manager, wherein the encrypted credential comprises a credential encrypted with a public key and provided to the credential manager in encrypted form for use in requesting authentication at the landscape environment;
[0104] and wherein the encrypted credential is provided to a credential using component running in the landscape environment for decrypting the encrypted credential with a private key, wherein the private key is saved by the credential using component in the landscape environment, and
[0105] wherein the private key and the public key are an asymmetric key pair used for authorization requests.
[0106] Example 2. The method of example 1, wherein the request is associated with authentication of a requestor for performing an operation at a software system, wherein the request is received at a first trust zone of the landscape environment and the software system runs at a second trust zone of the landscape environment.
[0107] Example 3. The method of example 1, wherein the request is associated with authentication of a requestor for performing an operation at a software system, wherein the credential using component runs at a first trust zone of the landscape environment, and wherein the credential manager runs at a second trust zone of the landscape environment separate from the first trust zone.
[0108] Example 4. The method of example 3, wherein the software system runs at the first trust zone of the landscape environment.
[0109] Example 5. The method of example 1, wherein the credential manager is a first credential manager running in a first trust zone of the landscape environment, and wherein the credential using component is a second credential manager running in a second trust zone of the landscape environment separate from the first trust zone.
[0110] Example 5. The method of any one of Examples 1-4, wherein, in response to receiving the encrypted credential from the credential manager, the encrypted credential is decrypted at the credential use component, and wherein the decrypted credential is provided by the credential use component to the software system to authenticate the identity of the requestor.
[0111] Example 6. The method of any one of Examples 1-5, further comprising:
[0112] decrypting, in response to receiving the encrypted credential at the credential use component, the encrypted credential with the private key; and
[0113] sending a request for the software system to perform an operation, wherein the sent request includes the decrypted credential for authorization of performance of the operation associated with the received authentication request.
[0114] Example 7. The method of any one of Examples 1-6, wherein the requestor is authorized to perform operations at the software system, and wherein the received request identifies the software system by referencing an internal identifier as a target context for performance of authentication of the encrypted credential.
[0115] Example 8. The method of any one of Examples 1-7, wherein the credential manager runs as part of a cloud platform application to provide landscape management services to the software system, wherein the software system runs on cloud platform infrastructure of a first trust zone of a landscape environment.
[0116] Example 9. The method of any one of Examples 1-8, wherein the credential manager and the credential use component run on separate isolated cloud platforms.
[0117] Example 10. The method of any one of Examples 1-9, further comprising:
[0118] receiving instructions at a user interface associated with the credential manager to create a key pair including a public key and a private key; and
[0119] in response to the received instructions, configuring the credential manager and the credential use component to respectively hold the public key and the private key, wherein the configuring includes:
[0120] providing the public key to be held by the credential manager; and
[0121] providing the private key to be held at the credential use component.
[0122] Example 11. The method of any one of Examples 1-10, wherein the key pair is associated with an account with respect to one or more management systems, and wherein one or more users are associated with the account.
[0123] Example 12. The method of any one of Examples 1-10, further comprising:
[0124] receiving, at a user interface associated with the credential manager, credentials provided by a user for accessing the software system from a plurality of systems associated with the credential manager;
[0125] encrypting, at the user interface, the received credentials by using a private key saved at the credential usage component; and
[0126] providing the encrypted credentials to a cloud landscape manager for saving the encrypted credentials, wherein the cloud platform manager comprises the credential manager and domain specific logic for configuring, managing and saving a platform landscape configuration of a platform landscape environment, wherein the platform landscape environment comprises the software system and is associated with one or more customer accounts, and wherein each customer account is associated with different credentials authorizing access to at least one of the software systems.
Claims
1. A computer-implemented method for credential management, the method performed by one or more processors, wherein the method comprises: receiving a request from a first trust zone of a landscape environment, wherein the landscape environment comprises a customer network, a cloud platform, and a public infrastructure as a service (IaaS) cloud account, the public IaaS cloud account configured to provide cloud platform resources for hosting and running software applications and systems managed by a customer associated with the customer network, wherein the request is associated with an authentication of a requestor for performing an operation at a software system, the software system running at the first trust zone of the landscape environment; and in response to receiving the request: loading, at a credential manager running at a second trust zone of the landscape environment separate from the first trust zone, an encrypted credential in response to the request, wherein the encrypted credential is saved at storage by the credential manager, wherein the encrypted credential comprises a credential encrypted with a public key and provided to the credential manager in encrypted form for use in authenticating requests at the landscape environment, the credential manager saving the encrypted credential at storage without having a key to decrypt the credential and without accessing the credential in decrypted form; and providing the encrypted credential to a credential using component running in the first trust zone of the landscape environment for decrypting the encrypted credential with a private key, wherein the private key is saved by the credential using component in the first trust zone of the landscape environment, and wherein the private key and the public key are an asymmetric key pair for authorizing requests, decrypting the encrypted credential with the private key in response to receiving the encrypted credential at the credential using component; and sending a request to perform the operation associated with the received request for authentication at the software system, wherein the sent request includes the decrypted credential for authorizing performance of the operation associated with the received authentication request, wherein the trust zones of the landscape environment are network regions of the landscape environment that correspond to secure areas of communications between entities, and wherein communications between one trust zone and another trust zone, or between one group of trust zones and another group of trust zones, are performed according to security requirements for request and resource exchange between different networks, wherein multiple trust zones form a single group, wherein communications between entities are not monitored and filtered through a firewall, and wherein the customer network and the public IaaS cloud account of the customer correspond to the first trust zone of the landscape environment and the cloud platform corresponds to the second trust zone of the landscape environment.
2. The method of claim 1, further comprising authorizing the requestor to perform the operation at the software system, and wherein the received request associated with authentication of the requestor identifies the software system by referencing an internal identifier as a target context for performing authentication of the encrypted credential.
3. The method of claim 1, wherein the credential manager runs as part of a cloud platform application to provide landscape management services for the software system, wherein the software system runs on cloud platform infrastructure at the first trust zone of the landscape environment.
4. The method of claim 1, wherein the credential manager and the credential using component run at separate isolated cloud platforms.
5. The method of claim 1, further comprising: receiving instructions at a user interface associated with the credential manager to create a key pair comprising a public key and a private key; and in response to the received instructions, configuring the credential manager and a credential using component to correspondingly hold the public key and the private key, wherein the configuring comprises: providing the public key to be held by the credential manager; and and providing the private key to be held at the credential using component.
6. The method of claim 1, further comprising: receiving, at a user interface associated with the credential manager, credentials provided by a user for accessing a software system from a plurality of systems associated with the credential manager; encrypting, at the user interface, the received credentials by using the public key held at the credential manager; and providing the encrypted credentials to the cloud landscape manager for holding the encrypted credentials.
7. A non-transitory computer-readable medium coupled to one or more processors and having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving a request from a first trust zone of a landscape environment, wherein the landscape environment comprises a customer network, a cloud platform, and a public infrastructure as a service (IaaS) cloud account configured to provide cloud platform resources for hosting and running software applications and systems managed by a customer associated with the customer network, wherein the request is associated with an authentication of a requestor for performing an operation at a software system running at the first trust zone of the landscape environment; and in response to receiving the request: loading, at a credential manager running at a second trust zone of the landscape environment separate from the first trust zone, encrypted credentials in response to the request, wherein the encrypted credentials are held at storage by the credential manager, wherein the encrypted credentials comprise credentials encrypted with a public key and provided to the credential manager in encrypted form for use in authenticating requests at the landscape environment, the credential manager holding the encrypted credentials at the storage without having a key to decrypt the credentials and without accessing the credentials in decrypted form; and providing the encrypted credentials to a credential using component running in the first trust zone of the landscape environment for decrypting the encrypted credentials with a private key, wherein the private key is held by the credential using component in the first trust zone of the landscape environment, and wherein the private key and the public key are an asymmetric key pair for authorizing the request, in response to receiving the encrypted credentials at the credential using component, decrypting the encrypted credentials with the private key; and sending the request to perform the operation associated with the received request for authentication at the software system, wherein the sent request comprises the decrypted credentials for authorizing performance of the operation associated with the received request for authentication, wherein the trust zones of the landscape environment are network regions of the landscape environment that correspond to secure areas of communications between entities, and wherein communications between one trust zone and another trust zone, or between one group of trust zones and another group of trust zones, are performed according to security requirements of the exchange of requests and resources between different networks, wherein a plurality of trust zones form a single group, wherein communications between entities are not monitored and filtered through a firewall, and wherein the customer network and the customer's public IaaS cloud account correspond to a first trust zone of the landscape environment and the cloud platform corresponds to a second trust zone of the landscape environment.
8. The computer-readable medium of claim 7, further comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: the request received in association with the requestor's authentication identifies the software system by referencing an internal identifier as a target context for performing authentication of the credential used for encryption.
9. The computer-readable medium of claim 7, wherein the credential manager runs as part of a cloud platform application to provide a landscape management service for the software system, wherein the software system runs on cloud platform infrastructure at the first trust zone of the landscape environment.
10. The computer-readable medium of claim 7, wherein the credential manager and the credential using component run at separate isolated cloud platforms.
11. The computer-readable medium of claim 7, further comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving instructions at a user interface associated with the credential manager to create a key pair comprising a public key and a private key; and in response to the received instructions, configuring the credential manager and the credential using component to respectively hold the public key and the private key, wherein the configuring comprises: providing the public key to be held by the credential manager; and providing the private key to be held at the credential using component.
12. The computer-readable medium of claim 7, further comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving, at a user interface associated with the credential manager, credentials provided by a user for accessing the software system from a plurality of systems associated with the credential manager; encrypting, at the user interface, the received credentials using the public key held at the credential manager; and providing the encrypted credentials to the cloud landscape manager for holding the encrypted credentials.
13. A system for credential management, comprising: a computing device; and a computer-readable storage device coupled to the computing device and having stored thereon instructions that, when executed by the computing device, cause the computing device to perform operations comprising: receiving a request from a first trust zone of a landscape environment, wherein the landscape environment comprises a customer network, a cloud platform, and a public infrastructure as a service (IaaS) cloud account, the public IaaS cloud account configured to provide cloud platform resources for hosting and running software applications and systems managed by a customer associated with the customer network, wherein the request is associated with a requestor's authentication for performing an operation at a software system, the software system running at the first trust zone of the landscape environment; and in response to receiving the request: at a credential manager operating at a second trust zone of the landscape environment separate from the first trust zone, loading the encrypted credential in response to the request, wherein the encrypted credential is saved at storage by the credential manager, wherein the encrypted credential comprises the credential encrypted with the public key and provided to the credential manager in encrypted form for use in requesting authentication at the landscape environment, the credential manager saving the encrypted credential at storage without having a key to decrypt the credential and without accessing the credential in decrypted form; and providing the encrypted credential to a credential use component operating in the first trust zone of the landscape environment for decrypting the encrypted credential with the private key, wherein the private key is saved by the credential use component in the first trust zone of the landscape environment, and wherein the private key and the public key are an asymmetric key pair for the authorization request, decrypting the encrypted credential with the private key in response to receiving the encrypted credential at the credential use component; and sending a request at the software system to perform an operation associated with the received request for authentication, wherein the sent request includes the decrypted credential for authorization of performance of the operation associated with the received request for authentication, wherein the trust zones of the landscape environment are network zones of the landscape environment that correspond to secure areas of communication between entities, and wherein communication between one trust zone and another trust zone, or between one group of trust zones and another group of trust zones, is performed according to security requirements of request and resource exchange between different networks, wherein a plurality of trust zones form a single group, wherein communication between entities is not monitored and filtered through a firewall, and wherein the customer network and the customer's public IaaS cloud account correspond to the first trust zone of the landscape environment and the cloud platform corresponds to the second trust zone of the landscape environment.
Citation Information
Patent Citations
Secure Credential Store
US20100161965A1
Security credential deployment in cloud environment
US20140082349A1