Centralized Secret Management Service for Data Center Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large data centers face challenges in managing secret-related information, such as passwords and certificates, which are vulnerable to unauthorized access and become cumbersome to update or expand due to exponential growth in the number of secrets required.

Innovation Solution

Implementing a centralized front end service that generates and stores secrets for data centers, allowing access to back end storage while maintaining security and scalability by preventing direct access to secrets within the data centers, thus enabling secure and efficient management of secrets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If secret information is stored in multiple locations within data centers, then accessibility and availability are improved, but security and vulnerability to unauthorized access deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts secret information from individual data center locations and consolidates it into a centralized secret management service. This removes secrets from distributed storage locations where they could be compromised, while maintaining centralized control and accessibility through secure APIs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secret management service as an intermediary between data centers and secret information. This mediator handles secret generation, storage, rotation, and access control centrally, eliminating the need for data centers to store secrets locally while maintaining secure access through controlled interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data centers are updated or expanded, then system growth and capability are improved, but the number of secrets needed grows exponentially increasing complexity

Engineering Contradiction:
Improvesystem growthVSAvoidsecret management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal secret management service that handles all secret-related operations for any number of data centers through a single system. This multi-functional service manages secret generation, storage, rotation, and access control centrally, allowing system expansion without proportional increases in secret management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic secret management where secrets can be automatically generated, rotated, and revoked based on operational needs. This dynamic approach allows data centers to be added or removed flexibly without manual secret distribution or complex tracking of secret lifecycles across multiple locations.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If secrets are distributed across multiple data center locations, then local access and autonomy are improved, but security control and centralized management deteriorate

Engineering Contradiction:
Improvelocal accessVSAvoidcentralized management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a secret management service as an intermediary that provides local access capabilities through secure APIs while maintaining centralized control. Data centers can access secrets locally through the service interface without storing them, achieving both local operational autonomy and centralized security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the secret storage function from data center locations while retaining the access function through centralized service interfaces. This separation allows data centers to maintain local access capabilities without the security risks of distributed secret storage, as secrets remain centrally managed and controlled.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9135460B2Techniques to store secret information for global data centers
Publication Date: 2015.09.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9135460B2 patent drawing
  • US9135460B2 patent drawing
  • US9135460B2 patent drawing

AI summary

Techniques to store secret information for global data centers securely may provide a front end service for a back end data store. The front end service may be responsible for deployment, upgrade, and disaster recovery aspects, and so forth, of data center maintenance. Data centers may access data and data-related services from the back end data store through the front end service. Secrets that are needed to access secure data may be stored on behalf of the data centers without providing the secrets to the data centers.