Secure Application Configuration Secret Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application architectures lack secure and efficient methods for processing secret values, particularly in cloud applications, where configuration values and secret values are often stored together, leading to potential exposure and lack of versioning control.

Innovation Solution

A computer-implemented method that retrieves configuration and secret values from separate repositories, hashes and signs them using a private key, and stores them as environment variables in a release file, ensuring secure processing and integrity validation during application execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If configuration values and secret values are stored together in the same repository, then ease of access and management is improved, but security is worsened due to potential exposure of secret values

Engineering Contradiction:
Improveease of access and managementVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the repository into two separate repositories: a first repository for configuration files containing configuration values, and a second repository for secret values. This segmentation allows each repository to be accessed and managed independently, improving security by isolating sensitive secret values while maintaining ease of access through separate access controls and management workflows.

Inventive Principle:
Principle #1Segmentation

2Reliability

If secret values are stored in a vault without versioning, then security is improved by centralized control, but versioning control is worsened making it difficult to track changes

Engineering Contradiction:
Improvesecurity controlVSAvoidversioning control
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent pre-generates hash values and digital signatures for secret values before they are stored in the second repository. When secret values are updated, the system calculates new hash values and signatures in advance, allowing for seamless versioning and change tracking without compromising the security benefits of centralized vault control. This preliminary preparation enables automatic version comparison and audit trails.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If configuration values are decoupled from application code and stored in environment, then flexibility is improved, but security is worsened due to potential exposure in environment variables

Engineering Contradiction:
ImproveflexibilityVSAvoidexposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts secret values from environment variables and stores them in a secure second repository. Configuration files in the first repository contain only configuration values and references to secret values, not the actual secrets. This extraction eliminates the exposure risk associated with environment variables while preserving the flexibility of decoupled configuration management, as secrets can be securely referenced without being embedded in environment configurations.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If hash values and signatures are generated and stored, then validation capability is improved, but data processing complexity is worsened

Engineering Contradiction:
Improvevalidation capabilityVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates hash copies and signature copies of secret values that are stored alongside the original secret values in the second repository. These copies serve as validation mechanisms without requiring complex real-time processing. When validating secret values, the system simply compares the hash of the current value against the stored hash copy, and verifies the signature against the stored signature copy, greatly simplifying the validation process while maintaining high precision and security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11496302B2Securely processing secret values in application configurations
Publication Date: 2022.11.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11496302B2 patent drawing
  • US11496302B2 patent drawing
  • US11496302B2 patent drawing

AI summary

Provided are techniques for securely processing secret values in application configurations. A configuration file for an application is retrieved from a first repository, where the configuration file stores a configuration value and a link to a secret value in a second repository. The secret value is retrieved from the second repository using the link. The configuration value is hashed to output a hashed configuration value and the secret value is hashed to output a hashed secret value. The hashed configuration value is signed, with a private key, to output a hashed and signed configuration value, and the hashed secret value is signed, with the private key, to output a hashed and signed secret value. The configuration value, the secret value, the hashed and signed configuration value, and the hashed and signed secret value are stored in a release file. The application is executed using the release file.