Cloud-Based Credential Store with an Access-Management Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional workflows for accessing networked services in cloud computing environments are inefficient, resource-intensive, and pose security risks due to direct credential management and wide attack surfaces, especially in systems like Vault™ and Boundary™.

Innovation Solution

A credential store and library within an identity-based access management system that dynamically generates and manages credentials on-the-fly from multiple sources, minimizing direct access to secrets management systems and reducing operational burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users directly access the secrets management system to obtain credentials, then they can authenticate to networked services, but the attack surface increases and operational burden increases

Engineering Contradiction:
ImprovesecurityVSAvoidattack surface
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an access management system as an intermediary between users and the secrets management system. This intermediary holds a stored credential that it uses to access the secrets management system on behalf of users, thereby eliminating the need for users to directly access the secrets management system and reducing the attack surface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates credential storage and management functions into distinct components: the access management system holds a stored credential, while the secrets management system maintains the actual secrets. This segmentation allows the attack surface to be minimized while maintaining security functionality.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If users directly access the secrets management system to obtain credentials, then they can authenticate to networked services, but the process becomes inefficient and time-consuming

Engineering Contradiction:
Improvecredential access processVSAvoidtime to obtain credential
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The access management system performs preliminary actions by storing a credential in advance that can be used to access the secrets management system. When a user needs a credential, the access management system already has the necessary authentication capability, eliminating the need for users to perform time-consuming authentication steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access management system provides self-service functionality by automatically obtaining credentials from the secrets management system using its stored credential, without requiring user intervention for authentication. This automates the credential acquisition process and significantly reduces the time required.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If secrets are stored directly in the access management system, then user access is simplified, but credential management becomes complex and security risks increase

Engineering Contradiction:
Improveuser access managementVSAvoidcredential management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent uses the access management system as an intermediary that holds a stored credential rather than actual secrets. This intermediary approach simplifies user access while keeping the complex credential management functionality in the dedicated secrets management system, avoiding the complexity of managing rotation and auditing in the access management system.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If secrets are stored directly in the access management system, then user access is simplified, but the attack surface increases

Engineering Contradiction:
Improveuser access managementVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The access management system acts as an intermediary that stores only a credential (not actual secrets) used to access the secrets management system. This maintains ease of user access while significantly reducing the attack surface, as the access management system does not hold sensitive secrets that could be compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the actual secrets from the access management system and stores them only in the secrets management system. The access management system retains only the minimal credential necessary to access the secrets management system, thereby taking out the harmful element (secrets) from the access management system and reducing the attack surface.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12463959B2Cloud-based secrets management credential store
Publication Date: 2025.11.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12463959B2 patent drawing
  • US12463959B2 patent drawing
  • US12463959B2 patent drawing

AI summary

A system and method for accessing and using one or more networked services of a cloud computing infrastructure by a user of a client computer includes an identity-based access management system that is configured to receive a request for a session via an API to use a specific service of the one or more networked services. A credential store includes a credential library that receives and stores credentials for authorizing and enabling the session with the specific service of the one or more networked services. A target service is configured to authorize and enable the session based on the received credentials. A secrets management system is configured to authenticate the user and the client computer to access and use the specific service authorized by the target service, and to generate a lease to a credential that is transmitted to the client computer to authorize the session with the specific service.