Techniques for shared credential management
The system addresses the challenge of managing multiple access credentials by intercepting and updating requests with credentials from a vault, ensuring seamless access and transparent password updates across third-party services.
Patent Information
- Application Number
- PCT/CA2025/050064
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-17
- Filing Date
- 2025-01-16
- Publication Date
- 2025-07-24
AI Technical Summary
Managing a multitude of access credentials for various third-party services is intractable, especially when credentials need periodic updates, and administrators lack effective tools for centralized management.
A system comprising a client computing device, a credential vault, and a request management computing system that intercepts requests, retrieves missing credentials from a vault, and seamlessly injects them into requests to third-party services, enabling centralized credential management and policy enforcement.
Facilitates seamless access to multiple third-party services with transparent password updates, reducing administrative burden and enhancing security through centralized credential management.
Smart Images

Figure CA2025050064_24072025_PF_FP_ABST
Abstract
Description
TECHNIQUES FOR SHARED CREDENTIAL MANAGEMENTCROSS-REFERENCE(S) TO RELATED APPLICATION(S)
[0001] This application claims the benefit of Provisional Application No. 63 / 621774, filed January 17, 2024, the entire disclosure of which is hereby incorporated by reference herein for all purposes.BACKGROUND
[0002] One problem in the operation of complex computing systems is the management of credentials such as user login information. A single user of a client computing device, when interacting with or developing for a complex system, may access numerous third- party services, including but not limited to databases, cloud systems, artificial intelligence systems, and so on. However, each of the third-party services may use separate credentials (that is, the single user may have separate login information such as usernames and passwords for each of the third-party services). Management of a multiplicity of access credentials by the single user can quickly become intractable, particularly when considering that each third-party service may require that credentials be updated periodically (e.g., a password may expire after a given amount of time and need to be reset). Furthermore, in an enterprise system wherein administrators are tasked with managing access to portions of the system, administrators may have little to no ability to manage access to the third-party services when desired.
[0003] It should be noted that this is a problem unique to computing technology - only in computing technology is the need for credential management such as this present. Further, while remembering and managing a small number of passwords may be possible, managing a large number of passwords for multiple users and multiple systems cannot practically be performed in the human mind.
[0004] What is desired are systems and techniques that solve these technical problems and allow for centralized management of access to third-party services.SUMMARY
[0005] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This summary is not intended to identify key features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.
[0006] In some embodiments, a system comprising a client computing device, a credential vault computing system, a third-party service, and a request management computing system is provided. The request management computing system includes a request management engine configured to perform actions comprising: receiving, by the request management engine from the client computing device, a request to access the third- party service; determining, by the request management engine, whether the request includes an access credential associated with the third-party service; in response to determining that the request does include the access credential associated with the third- party service, transmitting, by the request management engine, the request as received from the client computing device to the third-party service; and in response to determining that the request does not include the access credential associated with the third-party service: obtaining, by the request management engine, the access credential from the credential vault computing system; updating, by the request management engine, the request to include the access credential; and transmitting, by the request management engine, the updated request to the third-party service.
[0007] In some embodiments, a computer-implemented method of managing access to third-party computing resources is provided. A request management computing system receives, from a client computing device, a request to access a third-party service. The request management computing system determines whether the request includes an access credential associated with the third-party service. In response to determining that the request does include the access credential associated with the third-party service, the request management computing system transmits the request as received from the client computing device to the third-party service. In response to determining that the requestdoes not include the access credential associated with the third-party service, the request management computing system obtains the access credential from a credential vault computing system, updates the request to include the access credential, and transmits the updated request to the third-party service.
[0008] In some embodiments, a non-transitory computer-readable medium having computer-executable instructions stored thereon is provided. The instructions, in response to execution by one or more processors of a computing system, cause the computing system to perform a method as described above. In some embodiments, a computing system configured to perform a method as described above is provided.BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The foregoing aspects and many of the attendant advantages of this invention will become more readily appreciated as the same become better understood by reference to the following detailed description, when taken in conjunction with the accompanying drawings, wherein:
[0010] FIG. 1 is a block diagram of a system for centralized management of access to third-party services according to various aspects of the present disclosure.
[0011] FIG. 2 is a block diagram that illustrates aspects of a non-limiting example embodiment of request management computing system according to various aspects of the present disclosure.
[0012] FIG. 3 is a block diagram that illustrates aspects of a non-limiting example embodiment of a client computing device according to various aspects of the present disclosure.
[0013] FIG. 4A - FIG. 4C are a flowchart that illustrates a non-limiting example embodiment of a method of managing access to third-party computing resources, according to various aspects of the present disclosure.
[0014] FIG. 5 is a schematic illustration of a non-limiting example of communication between components of a non-limiting example embodiment of a system described herein.DETAILED DESCRIPTION
[0015] FIG. 1 is a block diagram of a system for centralized management of access to third-party services according to various aspects of the present disclosure. A client computing device 102 (e.g., a laptop computing device, a desktop computing device, a mobile computing device, etc.) connects to one or more third-party services 106 via a request management computing system 104. The third-party services 106 may include cloud services (e.g., Amazon Web Services (AWS) services, Google Cloud services, Microsoft Azure services, etc.), database services (e.g., a MongoDB database service, a Redis database service, a Postgres database service, etc.), a web service, or any other type of service accessible via a network that uses authentication. A user of the client computing device 102 may have authentication credentials (e.g., login information such as usemame / password) for each of the separate third-party services 106.
[0016] The client computing device 102 provides credentials associated with a user for accessing the request management computing system 104, after which the client computing device 102 is considered authenticated by the request management computing system 104. Thereafter, the request management computing system 104 intercepts requests from the client computing device 102 that are otherwise directed to the third-party services 106. If the requests do not include credentials for accessing the third-party services 106, the request management computing system 104 retrieves the credentials for the third-party services 106 from a credential vault computing system 110. In some embodiments, the credential vault computing system 110 may be implemented by the request management computing system 104. In some embodiments, the credential vault computing system 110 may be a credential vault operated by another party (e.g., a Google Cloud Secret Manager, a Microsoft Azure Key Vault, a Bitwarden Secrets Manager, an Amazon Web Services Secrets Manager, etc.).
[0017] After having obtained the credentials, the request management computing system 104 then seamlessly injects the credentials into the requests before relaying them to the appropriate third-party service 106. In this way, the user of the client computing device102 can seamlessly access the third-party service 106 without needing to provide separate access credentials for each of the third-party services 106.
[0018] The request management computing system 104 may also manage access policies in its own right (e.g., user A has the right to access Third-Party Service B) using a policy service 108, and so access by users to the third-party services 106 may be easily controlled by administrators of the request management computing system 104 without having administrative rights to any of the third-party services 106. In some embodiments, the policy service 108 may be implemented by the request management computing system 104. In some embodiments, the policy service 108 may be a policy service provided by another party (e.g., an Open Policy Agent (OP A) service, an Amazon Web Services Identity and Access Management (AWS I AM) service, etc.).
[0019] The request management computing system 104 may also manage updating passwords to the third-party services 106 when such passwords expire or otherwise desired to be changed. Since these passwords are stored in a credential vault computing system 110 accessed by the request management computing system 104, these changes may be made transparently to the user of the client computing device 102. This is particularly useful for third-party services 106 that require periodic resetting of passwords, as the user may continue to access all of the third-party services 106 for which the request management computing system 104 is managing password updates by simply authenticating with the request management computing system 104, and thereby without having to manage the multitude of updated passwords managed by the request management computing system 104.
[0020] Further details of the configuration of the client computing device 102 and request management computing system 104 are provided below.
[0021] FIG. 2 is a block diagram that illustrates aspects of a non-limiting example embodiment of request management computing system according to various aspects of the present disclosure. The illustrated request management computing system 104 may be implemented by any computing device or collection of computing devices, including butnot limited to a desktop computing device, a laptop computing device, a mobile computing device, a server computing device, a computing device of a cloud computing system, and / or combinations thereof. In some embodiments, the request management computing system 104 is provided within a Kubemetes system or another container orchestration system. In some embodiments, one or more of the third-party services 106 are also provided within the container orchestration system that provides the request management computing system 104.
[0022] As shown, the request management computing system 104 includes one or more processors 202, one or more communication interfaces 204, a user data store 208, a service data store 216, and a computer-readable medium 206.
[0023] In some embodiments, the processors 202 may include any suitable type of general-purpose computer processor. In some embodiments, the processors 202 may include one or more special-purpose computer processors or Al accelerators optimized for specific computing tasks, including but not limited to graphical processing units (GPUs), vision processing units (VPUs), and tensor processing units (TPUs).
[0024] In some embodiments, the communication interfaces 204 include one or more hardware and or software interfaces suitable for providing communication links between components. The communication interfaces 204 may support one or more wired communication technologies (including but not limited to Ethernet, FireWire, and USB), one or more wireless communication technologies (including but not limited to Wi-Fi, WiMAX, Bluetooth, 2G, 3G, 4G, 5G, and LTE), and / or combinations thereof.
[0025] As shown, the computer-readable medium 206 has stored thereon logic that, in response to execution by the one or more processors 202, cause the request management computing system 104 to provide a request management engine 210, a request decoder engine 212, and a request updater engine 214. In some embodiments, the request management engine 210 is configured to receive requests from client computing devices 102, to verify that users associated with the client computing devices 102 are authorized to use the request management computing system 104 based on information stored in the userdata store 208, and to manage requests directed to third-party services 106 from the client computing devices 102.
[0026] In some embodiments, a plurality of request decoder engines 212 and request updater engines 214 may be provided. In some embodiments, each request decoder engine 212 is configured to receive requests directed to a specific third-party service 106, and to decode the requests to determine if they include access credentials. In some embodiments, each request updater engine 214 is configured to update requests directed to a specific third- party service 106 to include credentials retrieved from the credential vault computing system 110.
[0027] The request management engine 210 may use information stored in the service data store 216 to determine which third-party service 106 a given request is directed to, as well as the identity of the appropriate request decoder engine 212 and request updater engine 214 to be used for the given request. In some embodiments, an operator of a given third-party service 106 may provide the request management computing system 104 with a given request decoder engine 212 and a given request updater engine 214 configured to handle requests formatted for the given third-party service 106. In this way, the request management computing system 104 can easily be updated to support new third-party services 106, regardless of the request format used. In some embodiments, if a standard request format is shared by more than one third-party service 106, then a shared request decoder engine 212 and / or request updater engine 214 may be used by those third-party services 106.
[0028] Further details of the configuration of each of these components are provided below.
[0029] As used herein, "computer-readable medium" refers to a removable or nonremovable device that implements any technology capable of storing information in a volatile or non-volatile manner to be read by a processor of a computing device, including but not limited to: a hard drive; a flash memory; a solid state drive; random-access memory(RAM); read-only memory (ROM); a CD-ROM, a DVD, or other disk storage; a magnetic cassette; a magnetic tape; and a magnetic disk storage.
[0030] As used herein, "engine" refers to logic embodied in hardware or software instructions, which can be written in one or more programming languages, including but not limited to C, C++, C#, COBOL, JAVA™, PHP, Perl, HTML, CSS, JavaScript, VBScript, ASPX, Go, and Python. An engine may be compiled into executable programs or written in interpreted programming languages. Software engines may be callable from other engines or from themselves. Generally, the engines described herein refer to logical modules that can be merged with other engines, or can be divided into sub-engines. The engines can be implemented by logic stored in any type of computer-readable medium or computer storage device and be stored on and executed by one or more general purpose computers, thus creating a special purpose computer configured to provide the engine or the functionality thereof. The engines can be implemented by logic programmed into an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or another hardware device.
[0031] As used herein, "data store" refers to any suitable device configured to store data for access by a computing device. One example of a data store is a highly reliable, highspeed relational database management system (DBMS) executing on one or more computing devices and accessible over a high-speed network. Another example of a data store is a key-value store. However, any other suitable storage technique and / or device capable of quickly and reliably providing the stored data in response to queries may be used, and the computing device may be accessible locally instead of over a network, or may be provided as a cloud-based service. A data store may also include data stored in an organized manner on a computer-readable storage medium, such as a hard disk drive, a flash memory, RAM, ROM, or any other type of computer-readable storage medium. One of ordinary skill in the art will recognize that separate data stores described herein may be combined into a single data store, and / or a single data store described herein may beseparated into multiple data stores, without departing from the scope of the present disclosure.
[0032] FIG. 3 is a block diagram that illustrates aspects of a non-limiting example embodiment of a client computing device according to various aspects of the present disclosure. The illustrated client computing device 102 may be implemented by any computing device or collection of computing devices, including but not limited to a desktop computing device, a laptop computing device, a mobile computing device, a server computing device, a computing device of a cloud computing system, and / or combinations thereof.
[0033] As shown, the client computing device 102 includes one or more processors 302, one or more communication interfaces 304, a mapping data store 308, and a computer- readable medium 306.
[0034] In some embodiments, the processors 302 may include any suitable type of general-purpose computer processor. In some embodiments, the processors 302 may include one or more special-purpose computer processors or Al accelerators optimized for specific computing tasks, including but not limited to graphical processing units (GPUs), vision processing units (VPUs), and tensor processing units (TPUs).
[0035] In some embodiments, the communication interfaces 304 include one or more hardware and or software interfaces suitable for providing communication links between components. The communication interfaces 304 may support one or more wired communication technologies (including but not limited to Ethernet, FireWire, and USB), one or more wireless communication technologies (including but not limited to Wi-Fi, WiMAX, Bluetooth, 2G, 3G, 4G, 5G, and LTE), and / or combinations thereof.
[0036] As shown, the computer-readable medium 306 has stored thereon logic that, in response to execution by the one or more processors 302, cause the client computing device 102 to provide a proxy engine 310 and a client engine 312. In some embodiments, the client engine 312 is configured to generate requests for transmission via a network. Insome embodiments, the client engine 312 may be, may include, or may be implemented within a web browser or other program. In some embodiments, the proxy engine 310 is configured to transmit user login information to the request management computing system 104 to establish a connection between the client computing device 102 and the request management computing system 104, to receive requests from the client engine 312, to determine whether the destination of the requests are associated with third-party services 106 based on information in the mapping data store 308, and to selectively transmit the requests to the request management computing system 104 instead of directly to the destinations when appropriate. Further details of the configuration of these components will be provided below.
[0037] FIG. 4A - FIG. 4C are a flowchart that illustrates a non-limiting example embodiment of a method of managing access to third-party computing resources, according to various aspects of the present disclosure. In the method 400, the request management computing system 104 automatically manages credentials and access to the third-party services 106.
[0038] From a start block, the method 400 proceeds to block 402, where a proxy engine 310 of a client computing device 102 submits an authentication request on behalf of a user of the client computing device 102 to a request management computing system 104. Any suitable authentication technique may be used between the proxy engine 310 and the request management computing system 104. For example, in some embodiments the proxy engine 310 may request a user name and password from the user, and may transmit the user name and password to the request management computing system 104 as part of the authentication request, and the request management computing system 104 may check the user name and password against user account information stored in the user data store 208. In some embodiments, more complex authentication techniques may be used, including but not limited to two-factor authentication and / or passkeys.
[0039] At block 404, the request management computing system 104 associates the user with the client computing device 102 in response to the authentication request. In someembodiments, an identifier of the client computing device 102, such as a network identifier (e.g., an IP address, a MAC address, etc.), may be associated with the user, and stored in a record in the user data store 208 such that subsequent requests received by the request management computing system 104 from the network identifier will also be associated with the user. In some embodiments, a cookie, an access token, or other identifying data may be assigned to the client computing device 102 to be transmitted along with future requests, and may be stored in a record in the user data store 208 such that subsequent requests received by the request management computing system 104 that include the identifying data will also be associated with the user.
[0040] At block 406, a client engine 312 of the client computing device 102 generates a request, and provides the request to the proxy engine 310. In some embodiments, the request may be an HTTP request, or may be a request in any other suitable format.
[0041] At block 408, the proxy engine 310 queries a mapping data store 308 of the client computing device 102 to determine whether a destination of the request is a third-party service 106 managed by the request management computing system 104. In some embodiments, the mapping data store 308 stores identifying information of each of the third-party services 106 managed by the request management computing system 104, and may compare identifying information within the request to the identifying information stored in the mapping data store 308 to determine whether the destination is associated with a third-party service 106. In some embodiments, the mapping data store 308 may include or may be implemented as a static DNS host table having entries for the host names for the third-party services 106 that direct to an IP address of the request management computing system 104.
[0042] The method 400 then proceeds to a decision block 410, where a determination is made based on whether the destination of the request is a third-party service 106 managed by the request management computing system 104. If it was determined that the destination of the request is not a third-party service 106 managed by the request management computing system 104, then the result of decision block 410 is NO, and the method 400proceeds to block 412. At block 412, the proxy engine 310 provides the request directly to the destination. In this way, the client computing device 102 is configured to seamlessly and concurrently support management of communication with some third-party services 106 via the request management computing system 104 without interfering with communication with other network services. The method 400 then proceeds to an end block and terminates.
[0043] Returning to decision block 410, if it was determined that the destination of the request is a third-party service 106 managed by the request management computing system 104, then the result of decision block 410 is YES, and the method 400 proceeds to a continuation terminal ("terminal A"). From terminal A (FIG. 4B), the method 400 proceeds to block 414, where a request management engine 210 of the request management computing system 104 receives the request.
[0044] At block 416, the request management engine 210 determines a destination third- party service 106 for the request. In some embodiments, the request management engine 210 may use characteristics of the request (e.g., a destination network address and / or host name, a header of the request, etc.) to query the service data store 216 to determine the destination third-party service 106.
[0045] At block 418, the request management engine 210 determines a level of access for the user associated with the client computing device 102 with respect to the third-party service 106. In some embodiments, the policy service 108 may be used to manage policies for the users which may be of varied types. As a simple example, policies stored in the policy service 108 may indicate whether access to the third-party service 106 is granted or denied for the user. In other embodiments, more detailed policies may be set, and / or may specify more complex behavior involving other actions to be taken in response to requests from the user, as described below.
[0046] The method 400 then proceeds to a decision block 420, where the request management engine 210 determines whether the level of access indicates that the user is permitted to access the third-party service 106. Any policy that allows access for the usermay be considered a level of access that indicates that the user is permitted to access the third-party service 106, even if there are other actions specified in the policy.
[0047] If the user is not permitted to access the third-party service 106, then the result of decision block 420 is NO, and the method 400 proceeds to block 422. At block 422, the request management engine 210 transmits a response to the proxy engine 310 denying the request. In some embodiments, the response may include a “forbidden” HTTP response code (e.g., a 403 code), or may indicate denial of the request in any other suitable fashion. The method 400 then proceeds to an end block and terminates.
[0048] Returning to decision block 420, if the user is permitted to access the third-party service 106, then the result of decision block 420 is YES, and the method 400 proceeds to another decision block 424. At decision block 424, the request management engine 210 determines whether the level of access indicates that another action should be performed in addition to servicing the request. In some embodiments, this may be a “warn” level of access, to indicate that the request should be allowed, but may be considered suspicious such that a warning notification should be recorded and / or transmitted to an administrator for review. The policy service 108 may be configured to perform advanced processing and consideration of a variety of data sources to determine if a “warn” level of access is warranted. For example, the policy service 108 may check a current status of the user, and may set the “warn” level of access if the user is attempting to access a third-party service 106 while the current status indicates that the user is on vacation or otherwise not expected to be using the system 100. As another example, the policy service 108 may check whether the user is associated with a support ticket associated with the third-party service 106, assigned to a distribution list or other group associated with the third-party service 106, or would otherwise be indicated as being expected to access the third-party service 106.
[0049] If it is determined that some other action should be performed in addition to servicing the request, then the result of decision block 424 is YES, and the method 400 proceeds to block 426, where the request management engine 210 performs an additional action related to the request by the user for the third-party service 106. In someembodiments, the additional action may include storing and / or transmitting a notification related to the request and the user to an administrator of the request management computing system 104 or the third-party service 106. In other embodiments, any other suitable additional action may be performed.
[0050] The method 400 then proceeds to a continuation terminal ("terminal B"). Returning to decision block 424, if a warning should not be transmitted, then the result of decision block 424 is NO, and the method 400 skips block 426 and instead proceeds directly to terminal B.
[0051] From terminal B (FIG. 4C), the method 400 proceeds to block 428, where the request management engine 210 transmits the request to a request decoder engine 212 associated with the third-party service 106 to determine whether the request includes credentials for the third-party service 106. Any suitable response may be provided from the request decoder engine 212 to the request management engine 210, including but not limited to a true / false value indicating whether the request includes credentials.
[0052] The request management engine 210 may use information stored in the service data store 216 to identify the associated request decoder engine 212. The credentials within the request may include a user name and / or password for an initial request, and / or may include an access token if the user has previously been authenticated to the third-party service 106.
[0053] In some embodiments, if a simple encoding scheme (e.g., HTTP basic auth) is being used, the request decoder engine 212 may simply extract the user name and password from the URL of the request using standard techniques. In some embodiments, if a proprietary format is used to embed the user credentials in the request, then the request decoder engine 212 may use proprietary techniques to determine whether the request contains user credentials. In some embodiments, the request decoder engine 212 associated with a given third-party service 106 may have access to decoding credentials associated with the given third-party service 106 (e.g., a private key, an encryption / decryption key, etc.) usable to decode the request. Such decoding credentials may be retrieved by therequest decoder engine 212 from the credential vault computing system 110 or from any other suitable location. By using a request decoder engine 212 that is provided by the operator of the third-party service 106, the request management computing system 104 does not have to otherwise be specially configured to handle the proprietary techniques used by the third-party service 106, thus increasing the flexibility of the request management computing system 104 to operate with a wide variety of third-party services 106.
[0054] At decision block 430, a determination is made based on whether or not the request includes credentials. If it was determined that the request does not include credentials (e.g., the response from the request decoder engine 212 is FALSE), then the result of decision block 430 is NO, and the method 400 proceeds to block 432. At block 432, the request management engine 210 retrieves credentials associated with the third- party service 106 for the user from a credential vault computing system 110. The credentials may include a user name and password, a certificate, and / or any other type of login credentials).
[0055] At block 434, the request management engine 210 transmits the credentials and the request to a request updater engine 214 associated with the third-party service 106 to add the credentials to the request. As with the request decoder engine 212, the request updater engine 214 may be provided by the operator of the third-party service 106 to add the credentials to the request using any technique desired by the operator of the third-party service 106. In some embodiments, if a simple encoding scheme (e.g., HTTP basic auth) is being used, the request updater engine 214 may simply insert the user name and password into the URL using standard techniques. In some embodiments, if a proprietary format is used to embed the user credentials in the request, then the request updater engine 214 may use proprietary techniques to insert the access credentials into the request. In some embodiments, the request updater engine 214 associated with a given third-party service 106 may have access to decoding and / or encoding credentials associated with the given third-party service 106 (e.g., a private key, an encryption / decryption key, etc.) usable todecode the request, insert the access credentials, and then re-encode the updated request. Such decoding and / or encoding credentials may be retrieved from the credential vault computing system 110 or from any other suitable location. The use of a request updater engine 214, similar to the use of the request decoder engine 212, increases the flexibility of the request management computing system 104 to operate with a wide variety of third- party services 106. The method 400 then proceeds to block 436.
[0056] Returning to decision block 430, if it was determined that the request does include credentials, then the result of decision block 430 is YES, and the method 400 proceeds directly to block 436. At block 436, the request management engine 210 transmits the request to the third-party service 106. The method 400 then proceeds to optional block 438, where the third-party service 106 transmits a response to the client computing device 102. The response may either be transmitted directly to the client computing device 102 from the third-party service 106, or may be relayed to the client computing device 102 via the request management engine 210. The response, assuming the authentication was successful, may include an access token. In such a case, a subsequent request from the client computing device 102 to the same third-party service 106 would include the access token, and the request management engine 210 may be able to pass along the request to the third-party service 106 without having to update the request after the request decoder engine 212 detects the access token in the subsequent request. Optional block 438 is illustrated and described as optional because in some embodiments, the third-party service 106 may successfully process the request without transmitting a response.
[0057] The method 400 then proceeds to an end block and terminates. For each of the illustrated end blocks of the method 400, the method 400 may terminate entirely, or may return to block 406 to process a subsequent request from the client computing device 102.
[0058] FIG. 5 is a schematic illustration of a non-limiting example of communication between components of a non-limiting example embodiment of the system 100 during a method such as a non-limiting example embodiment of method 400, according to various aspects of the present disclosure. The client computing device 102 is illustrated at thebottom of the drawing. The request management computing system 104 is illustrated at the top left of the drawing. Various different systems operated by third-parties (i.e., parties other than the request management computing system 104 and the client computing device 102) are illustrated at the top right of the drawing. A set of circled numbers (step 502 - step 514) illustrate points of the communication that correspond to the method 400 described above, and are provided for clarity of the description.
[0059] It is assumed in FIG. 5 that a user of the client computing device 102 has authenticated with the request management computing system 104, and so the request management computing system 104 has identified the user associated with the client computing device 102 (i.e., the actions of block 402 and block 404 have already occurred).
[0060] At step 502 (block 406), the client engine 312 generates a request (e.g., an HTTP request or any other suitable request format), which is intercepted by the proxy engine 310. Assuming that the proxy engine 310 determines that the request is intended for a third- party service 106 managed by the request management computing system 104 (block 408 and decision block 410), then at step 504, the proxy engine 310 provides the request to the request management computing system 104.
[0061] Once the request management engine 210 receives the request (block 414), the request management engine 210 determines a third-party service 106 targeted by the request (block 416). At step 506 (block 418), the request management engine 210 consults a policy service 108 to determine whether the user is allowed to access the third-party service 106.
[0062] Assuming it was determined that the level of access for the user permits access and does not indicate additional actions to be taken, at step 508 (block 428), the request management engine 210 provides the request to a request decoder engine 212 associated with the third-party service 106 to determine whether credentials have been supplied in the request.
[0063] Assuming it is determined that the request does not include credentials, then at step 510 (block 432), the request management engine 210 retrieves the access credentials (e.g., a user name and password, or other login credentials) from a credential vault computing system 110.
[0064] At step 512 (block 434), the request management engine 210 provides the request and the access credentials to a request updater engine 214 associated with the third-party service 106, and the request updater engine 214 updates the request to include the access credentials.
[0065] Once the request has been updated, at step 514 (block 436), the request management engine 210 transmits the updated request to the third-party service 106. In some embodiments, the third-party service 106 will respond to the request, and the response is transmitted to the client computing device 102 (optional block 438).
[0066] While illustrative embodiments have been illustrated and described, it will be appreciated that various changes can be made therein without departing from the spirit and scope of the invention.EXAMPLES
[0067] Below are a set of numbered, non-limiting, example embodiments of the present disclosure.
[0068] Example 1. A system, comprising: a client computing device; a credential vault computing system; a third-party service; and a request management computing system comprising a request management engine configured to perform actions comprising: receiving, by the request management engine from the client computing device, a request to access the third-party service; determining, by the request management engine, whether the request includes an access credential associated with the third-party service; in response to determining that the request does include the access credential associated with the third- party service, transmitting, by the request management engine, the request as received from the client computing device to the third-party service; and in response to determining that the request does not include the access credential associated with the third-party service: obtaining, by the request management engine, the access credential from the credential vault computing system; updating, by the request management engine, the request to include the access credential; and transmitting, by the request management engine, the updated request to the third-party service.
[0069] Example 2. The system of example 1, wherein the credential vault computing system is a Google Cloud Secret Manager, a Microsoft Azure Key Vault, a Bitwarden Secrets Manager, or Amazon Web Services Secrets Manager.
[0070] Example 3. The system of example 1 or 2, wherein the third-party service is a cloud function, a web service, a MongoDB database, a Redis database, or a Postgres database.
[0071] Example 4. The system of any one of examples 1-3, wherein the access credential includes at least one of login information or an access token provided in response to a previous login.
[0072] Example 5. The system of any one of examples 1-4, wherein the actions further comprise: determining, by the request management engine, whether the request complies with a policy prior to retransmitting the request to the third-party service or transmitting the updated request to the third-party service.
[0073] Example 6. The system of example 5, wherein determining whether the request complies with a policy includes using a policy service.
[0074] Example 7. The system of example 6, wherein the policy service is an Open Policy Agent (OP A) service or an Amazon Web Services Identity and Access Management (IAM) service.
[0075] Example 8. The system of any one of examples 1-7, further comprising a plurality of third-party services, wherein the third-party service is included in the plurality of third- party services; and wherein the actions further comprise: determining, by the request management engine, the third-party service of the plurality of third-party services associated with the request based on content of the request.
[0076] Example 9. The system of example 8, wherein determining the third-party service associated with the request based on content of the request includes extracting a host value from a URL of the request.
[0077] Example 10. The system of example 8 or 9, wherein the request management computing system further comprises a plurality of request decoder engines; wherein each request decoder engine of the plurality of request decoder engines is associated with a third- party service of the plurality of third-party services; wherein determining whether the request includes the access credential associated with the third-party service includes providing the request to the request decoder engine associated with the third-party service; and wherein each request decoder engine is configured to perform actions comprising: receiving the request from the request management engine; and decoding the request using a decoding technique associated with the third-party service to determine whether the request includes the access credential.
[0078] Example 11. The system of any one of examples 8-10, wherein the request management computing system further comprises a plurality of request updater engines; wherein each request updater engine of the plurality of request updater engines is associated with a third-party service of the plurality of third-party services; wherein updating the request to include the access credential includes providing the request and the access credential to the request updater engine associated with the third-party service; and wherein each request updater engine is configured to perform actions comprising: receiving the request and the access credential from the request management engine; and inserting the access credential into the request using an editing technique associated with the third-party service.
[0079] Example 12. A computer-implemented method of managing access to third-party computing resources, the method comprising: receiving, by a request management computing system from a client computing device, a request to access a third-party service; determining, by the request management computing system, whether the request includes an access credential associated with the third-party service; in response to determining that the request does include the access credential associated with the third-party service, transmitting, by the request management computing system, the request as received from the client computing device to the third-party service; and in response to determining that the request does not include the access credential associated with the third-party service: obtaining, by the request management computing system, the access credential from a credential vault computing system; updating, by the request management computing system, the request to include the access credential; and transmitting, by the request management computing system, the updated request to the third-party service.
[0080] Example 13. The computer-implemented method of example 12, wherein the access credential includes at least one of login information or an access token provided in response to a previous login.
[0081] Example 14. The computer-implemented method of example 12 or 13, further comprising: determining, by the request management computing system, whether therequest complies with a policy prior to retransmitting the request to the third-party service or transmitting the updated request to the third-party service.
[0082] Example 15. The computer-implemented method of any one of examples 12-14, further comprising: determining, by the request management computing system, the third- party service associated with the request based on content of the request.
[0083] Example 16. The computer-implemented method of example 15, wherein determining the third-party service associated with the request based on content of the request includes extracting a host value from a URL of the request.
[0084] Example 17. The computer-implemented method of example 15 or 16, wherein determining whether the request includes the access credential associated with the third- party service includes: providing, by the request management computing system, the request to a request decoder engine associated with the third-party service.
[0085] Example 18. The computer-implemented method of any one of examples 15-17, wherein updating the request to include the access credential includes: providing, by the request management computing system, the request and the access credential to a request updater engine associated with the third-party service.
[0086] Example 19. A non-transitory computer-readable medium having computerexecutable instructions stored thereon that, in response to execution by one or more processors of a computing system, cause the computing system to perform a method as recited in any one of example 12 to example 18.
[0087] Example 20. A computing system configured to perform a method as recited in any one of example 12 to example 19.
Claims
CLAIMSThe embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:
1. A system, comprising: a client computing device; a credential vault computing system; a third-party service; and a request management computing system comprising a request management engine configured to perform actions comprising: receiving, by the request management engine from the client computing device, a request to access the third-party service; determining, by the request management engine, whether the request includes an access credential associated with the third-party service; in response to determining that the request does include the access credential associated with the third-party service, transmitting, by the request management engine, the request as received from the client computing device to the third-party service; and in response to determining that the request does not include the access credential associated with the third-party service: obtaining, by the request management engine, the access credential from the credential vault computing system; updating, by the request management engine, the request to include the access credential; and transmitting, by the request management engine, the updated request to the third-party service.
2. The system of claim 1, wherein the credential vault computing system is a Google Cloud Secret Manager, a Microsoft Azure Key Vault, a Bitwarden Secrets Manager, or Amazon Web Services Secrets Manager.
3. The system of claim 1, wherein the third-party service is a cloud function, a web service, a MongoDB database, a Redis database, or a Postgres database.
4. The system of claim 1, wherein the access credential includes at least one of login information or an access token provided in response to a previous login.
5. The system of claim 1, wherein the actions further comprise: determining, by the request management engine, whether the request complies with a policy prior to retransmitting the request to the third-party service or transmitting the updated request to the third-party service.
6. The system of claim 5, wherein determining whether the request complies with a policy includes using a policy service.
7. The system of claim 6, wherein the policy service is an Open Policy Agent (OP A) service or an Amazon Web Services Identity and Access Management (IAM) service.
8. The system of claim 1, further comprising a plurality of third-party services, wherein the third-party service is included in the plurality of third-party services; and wherein the actions further comprise: determining, by the request management engine, the third-party service of the plurality of third-party services associated with the request based on content of the request.
9. The system of claim 8, wherein determining the third-party service associated with the request based on content of the request includes extracting a host value from a URL of the request.
10. The system of claim 8, wherein the request management computing system further comprises a plurality of request decoder engines; wherein each request decoder engine of the plurality of request decoder engines is associated with a third-party service of the plurality of third-party services;wherein determining whether the request includes the access credential associated with the third-party service includes providing the request to the request decoder engine associated with the third-party service; and wherein each request decoder engine is configured to perform actions comprising: receiving the request from the request management engine; and decoding the request using a decoding technique associated with the third- party service to determine whether the request includes the access credential.
11. The system of claim 8, wherein the request management computing system further comprises a plurality of request updater engines; wherein each request updater engine of the plurality of request updater engines is associated with a third-party service of the plurality of third-party services; wherein updating the request to include the access credential includes providing the request and the access credential to the request updater engine associated with the third- party service; and wherein each request updater engine is configured to perform actions comprising: receiving the request and the access credential from the request management engine; and inserting the access credential into the request using an editing technique associated with the third-party service.
12. A computer-implemented method of managing access to third-party computing resources, the method comprising: receiving, by a request management computing system from a client computing device, a request to access a third-party service; determining, by the request management computing system, whether the request includes an access credential associated with the third-party service; in response to determining that the request does include the access credential associated with the third-party service, transmitting, by the request management computingsystem, the request as received from the client computing device to the third-party service; and in response to determining that the request does not include the access credential associated with the third-party service: obtaining, by the request management computing system, the access credential from a credential vault computing system; updating, by the request management computing system, the request to include the access credential; and transmitting, by the request management computing system, the updated request to the third-party service.
13. The computer-implemented method of claim 12, wherein the access credential includes at least one of login information or an access token provided in response to a previous login.
14. The computer-implemented method of claim 12, further comprising: determining, by the request management computing system, whether the request complies with a policy prior to retransmitting the request to the third-party service or transmitting the updated request to the third-party service.
15. The computer-implemented method of claim 12, further comprising: determining, by the request management computing system, the third-party service associated with the request based on content of the request.
16. The computer-implemented method of claim 15, wherein determining the third- party service associated with the request based on content of the request includes extracting a host value from a URL of the request.
17. The computer-implemented method of claim 15, wherein determining whether the request includes the access credential associated with the third-party service includes:providing, by the request management computing system, the request to a request decoder engine associated with the third-party service.
18. The computer-implemented method of claim 15, wherein updating the request to include the access credential includes: providing, by the request management computing system, the request and the access credential to a request updater engine associated with the third-party service.
19. A non-transitory computer-readable medium having computer-executable instructions stored thereon that, in response to execution by one or more processors of a computing system, cause the computing system to perform a method as recited in any one of claim 12 to claim 18.
20. A computing system configured to perform a method as recited in any one of claim 12 to claim 18.
Citation Information
Patent Citations
Enhanced security of secret data for dynamic user groups
US20210167949A1
Secure permissioning of access to user accounts, including secure deauthorization of access to user accounts
US20230080415A1
Access management system and method employing secure credentials
US6668322B1