Proxy Server Credential Sharing via Encrypted Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Proxy servers in managed networks require access to credentials for network operations, leading to inefficiencies as the number of proxy servers grows, and existing methods expose credentials to security risks.

Innovation Solution

A system for sharing access to credentials across proxy servers using encrypted forms of credential keys, ensuring secure and efficient distribution among a set of proxy servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are stored in an encrypted format in a remote network management platform or security vault, then security is improved, but device complexity and configuration overhead increase as the number of proxy servers grows

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments credential access by introducing credential sets that can be selectively assigned to proxy servers. Instead of managing individual credential configurations for each server, the system divides credentials into manageable sets that can be shared across multiple servers, reducing configuration overhead while maintaining security through encrypted storage in the remote platform.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal credential sharing where a single credential set can be accessed by multiple proxy servers simultaneously. This multi-functional approach allows any proxy server in the network to access shared credentials through a standardized mechanism, eliminating the need for server-specific credential configurations and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If per-proxy-server credential associations are configured, then access control is improved, but productivity decreases as the number of proxy servers increases

Engineering Contradiction:
Improveaccess controlVSAvoidconfiguration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system merges individual proxy server credential configurations into shared credential sets. Multiple proxy servers can be assigned to the same credential set, combining what would otherwise be separate configuration tasks into a single administrative action. This significantly improves productivity when adding new proxy servers to the network.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system enables credential sets to be copied or reused across multiple proxy servers without creating duplicate configurations. When a new proxy server needs access to credentials, the system can efficiently copy the credential set assignment rather than creating new per-server configurations, maintaining access control while dramatically improving configuration efficiency.

Inventive Principle:
Principle #26Copying

3Productivity

If shared credential access is implemented across proxy servers, then productivity is improved, but security risks increase if credentials or encryption keys are exposed to third parties

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system introduces a remote network management platform as an intermediary between proxy servers and credentials. This intermediary securely stores encrypted credentials and manages the distribution process. The platform acts as a trusted mediator that authenticates proxy servers before allowing credential access, preventing direct exposure of credentials or encryption keys to third parties while enabling efficient shared access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the state of credentials from plaintext to encrypted form stored in the remote platform. By transforming credentials into an encrypted parameter state, the system maintains productivity through efficient sharing while eliminating security exposure - the encrypted credentials cannot be read or exposed to third parties without the proper decryption keys, which remain protected in the intermediary platform.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12425195B2Client-side sharing of cryptographic keys
Publication Date: 2025.09.23 SERVICENOW INC
  • US12425195B2 patent drawing
  • US12425195B2 patent drawing
  • US12425195B2 patent drawing

AI summary

An example may involve determining that a first proxy server is to share security credentials with a set of one or more proxy servers, wherein the set of one or more proxy servers is associated with the security credentials, and wherein the set of one or more proxy servers includes a second proxy server; transmitting, to the second proxy server, a request for the first proxy server to have access to the security credentials; and receiving, from the second proxy server, a credential key in an encrypted form, wherein the credential key is configured to decrypt the security credentials.