Cloud Vault Credential Extraction for Mobile Enterprise Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for enabling secure access to enterprise applications on mobile devices are inflexible and obsolete due to the rapid evolution of mobile devices and varying communication protocols, leading to challenges in connecting mobile devices to enterprise backend systems while ensuring robust security.
Innovation Solution
The implementation of a declarative browser-based client application development tool using the Mobile Cloud Service (MCS) from Oracle, which facilitates communication between mobile devices and enterprise systems through a cloud-based interface, translating protocols to REST architecture and providing secure adaptors for various enterprise systems, along with the Oracle Mobile Security Suite (OMSS) for secure containerization and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional secure access solutions are used for enterprise applications on mobile devices, then security is maintained, but flexibility and adaptability to evolving mobile devices and protocols deteriorate
Solution Approach 1:
The patent introduces a cloud-based interface and secure adaptors as intermediaries between mobile devices and enterprise backend systems. These adaptors translate various communication protocols to REST architecture and manage security credentials, allowing the system to adapt to different mobile devices and protocols without compromising security. The cloud service acts as a mediator that handles protocol translation and security management centrally.
Solution Approach 2:
The patent creates a universal cloud-based interface that can accommodate diverse mobile devices and communication protocols through a single platform. The secure adaptor component provides multi-functionality by supporting multiple protocol translations and security mechanisms, eliminating the need for device-specific security solutions and enabling broad adaptability while maintaining centralized security control.
2Speed
If certificate keys are stored locally on mobile devices, then access speed is improved, but security risks increase
Solution Approach 1:
The patent extracts sensitive security credentials (certificate keys, passwords) from the mobile device environment and stores them securely in a cloud-based vault. When access is needed, the system retrieves only the necessary credentials temporarily, uses them for authentication, and then securely deletes them. This extraction approach eliminates the security risk of long-term local storage while maintaining fast access through efficient cloud retrieval and caching mechanisms.
Solution Approach 2:
The system performs preliminary secure retrieval of credentials from the cloud vault before actual access operations. Credentials are fetched in advance when needed, cached temporarily in secure memory, and automatically invalidated after use. This preliminary action with automatic invalidation ensures that credentials are available when needed for fast access while minimizing the window of vulnerability.
3Ease of operation
If security credentials are transmitted over the network, then centralized security management is achieved, but exposure to network attacks increases
Solution Approach 1:
The patent implements mechanisms to rapidly transmit security credentials over the network and immediately invalidate them after use. The system rushes through the credential transmission process efficiently using secure protocols, then quickly rotates or invalidates the credentials to prevent reuse. This approach minimizes the time window for potential network interception while maintaining centralized management capabilities.
Solution Approach 2:
The system employs a discard-and-recover strategy where security credentials are transmitted securely, used for authentication, and then discarded (invalidated) immediately afterward. New credentials are generated and made available for subsequent operations. This continuous cycle of secure transmission, usage, and invalidation reduces network exposure while enabling centralized security management through automated credential rotation.
Data Source
AI summary
A system performs secure storage of certificate keys. The system receives a user password and a certificate that is locked by the user password. The certificate is configured to be used for signing binaries of an application. The system sends, to a build server, the user password and the certificate that is locked by the user password. The system then receives, from the build server, a first portion of a certificate key and the certificate that is locked by the certificate key, and stores the first portion of the certificate key and the certificate that is locked by the certificate key.


