CI/CD Pipeline Credential Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The adoption of DevOps in software development increases the risk of governance and oversight challenges due to the blurring of lines between code generation and deployment, requiring a mechanism that maintains controls and approvals while optimizing speed, agility, and efficiency.

Innovation Solution

A method and system for controlling access to a security credential in a CI/CD pipeline, involving a processor that receives and tests software code, requests authorization from a credential source upon successful testing, and deploys the code to a predetermined destination, ensuring secure operations and efficient governance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If DevOps practices are adopted to enable rapid software deployment, then productivity and speed are improved, but governance and oversight control deteriorate

Engineering Contradiction:
Improvesoftware deployment speedVSAvoidgovernance control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary credential verification mechanism between the development team and production environment. The system automatically verifies credentials against stored certification data, acting as a mediator that enables rapid deployment while maintaining governance control through automated validation rather than human intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service automation where the deployment pipeline automatically requests, verifies, and manages credentials without human intervention. The credential source automatically responds to deployment requests by verifying certifications and providing appropriate credentials, eliminating the need for manual governance processes while maintaining control.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional segregation of duties is maintained between development and deployment teams, then governance control is improved, but productivity and agility deteriorate

Engineering Contradiction:
Improvesegregation of dutiesVSAvoiddeployment frequency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical system of human-based segregation of duties with an automated credential verification system. Instead of relying on human team members to enforce separation between development and deployment, the system uses automated credential validation to maintain control while allowing the same team to perform both functions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The deployment system serves itself by automatically managing credential verification and acquisition. The same team that develops code can also deploy it, as the system autonomously ensures proper authorization through automated credential checking, eliminating the need for separate deployment teams.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual credential verification processes are used to ensure security, then reliability is improved, but productivity and efficiency deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoiddeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual credential verification with automated electronic verification. The credential source automatically validates certifications against stored data and provides credentials through automated processes, eliminating manual security checks while maintaining or enhancing security reliability through consistent automated validation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The automated credential verification system operates continuously without interruption to deployment processes. Unlike manual verification that stops the workflow, the automated system continuously validates credentials in real-time, allowing deployment actions to proceed without pause while security checks are performed.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20220292177A1Method and system for controlling access to security credential in continuous integration / continuous deployment pipeline
Publication Date: 2022.09.15 JPMORGAN CHASE BANK NA
  • US20220292177A1 patent drawing
  • US20220292177A1 patent drawing
  • US20220292177A1 patent drawing

AI summary

Methods and systems for controlling and governing access to a security credential are provided. A method includes: receiving a first set of software code; testing the first set of code; receiving a certification that the first set of code has passed a compliance posture of an organization; requesting, from a credential source, either a credential that indicates that the certification has been received and/or an authorization to use the credential; and when the credential and/or the authorization to use the credential has been received, deploying the first set of software code in a predetermined destination and/or modifying the configuration of a controlled destination system. The method may be implemented in a continuous integration/continuous deployment (CI/CD) pipeline environment.