Blind Secret Rotation With Encrypted Key Materials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secret management systems expose secrets to attack during rotation, as they store and manage clear secrets, which can be accessed by compromised privileged users or cloud breaches, increasing the risk of network compromise.

Innovation Solution

Implement a blind secret management system where the secret management system remains unaware of the clear secret, generating and rotating encrypted key materials using a secret rotation manager and rotation agent, ensuring the secret is never decrypted within the management system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the secret management system stores and manages clear secrets during rotation, then the secret can be easily rotated and managed, but the secret is exposed to attack through compromised privileged users or cloud breaches

Engineering Contradiction:
Improvesecret rotation managementVSAvoidsecret exposure to attack
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption layer between the secret management system and the clear secret. The secret management system stores and manages only encrypted secrets, while a key management system acts as an intermediary to handle the encryption keys. This mediator approach allows the secret management system to operate with ease while preventing direct exposure of clear secrets to attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the secret management function into two distinct components: a secret management system that handles encrypted secrets and a key management system that manages encryption keys. This segmentation isolates the clear secret handling from the secret management process, reducing the attack surface while maintaining operational capability.

Inventive Principle:
Principle #1Segmentation

2Extent of automation

If the secret management system has access to the clear secret for use during rotation, then the secret can be rotated automatically, but the clear secret may be accessed by a compromised privileged user

Engineering Contradiction:
Improveautomatic secret rotationVSAvoidsecurity against privileged user compromise
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The key management system serves as an intermediary that provides encrypted secrets to the secret management system without exposing clear secrets to privileged users. The key management system handles the cryptographic operations, allowing automatic rotation while maintaining security even if privileged user accounts are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If the secret is updated in both the secret management system and the target network environment during rotation, then the secret rotation is complete, but the secret is subject to attack in multiple locations

Engineering Contradiction:
Improvesecret rotation completionVSAvoidmultiple attack vectors
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the secret storage and management across multiple locations: the secret management system stores only encrypted secrets, while the target network environment stores decrypted secrets locally. This segmentation limits the impact of breaches at any single location while maintaining complete rotation functionality.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250310093A1Blind secret management and rotation
Publication Date: 2025.10.02 CYBER ARK SOFTWARE LTD
  • US20250310093A1 patent drawing
  • US20250310093A1 patent drawing
  • US20250310093A1 patent drawing

AI summary

Disclosed embodiments relate to providing blind secret management and rotation. Techniques include identifying, by a secret rotation manager operating in a first network environment, an encrypted version of a first key material, generating, by the secret rotation manager, an additional key material, combining the encrypted first key material and the additional key material, and providing the combined key material to a rotation agent operating in a second network environment, wherein the rotation agent is configured to decrypt the encrypted first key material from the combined key material, and wherein the rotation agent is configured to generate, according to a secret generation policy, a secret using at least the combined key material.