Secure Secrets Proxy for Distributed Cloud Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing secrets in distributed computing environments, such as cloud computing, are hindered by manual processes and latency issues, making it difficult to securely access and process sensitive data across different environments.

Innovation Solution

A secure secrets proxy system is implemented, which includes a virtual asset instantiated in a computing environment to manage and cache secrets, using authentication data to authenticate and authorize access, thereby minimizing latency and operating across multiple environments securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secrets data is obtained from secrets distribution systems in a remote data center, then secrets can be securely distributed, but significant latencies occur and manual processes are required

Engineering Contradiction:
Improvesecure secrets distributionVSAvoidlatency in secrets retrieval
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-caching secrets data in the cloud computing environment before it is needed. The secrets distribution system proactively transfers and stores secrets data in the cloud data center, so that when virtual assets need to access secrets, they can retrieve them locally without waiting for remote data center communication, thus eliminating latency while maintaining security through controlled distribution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component - a secrets cache or storage mechanism in the cloud environment that acts as a mediator between the remote secrets distribution system and the virtual assets. This intermediary holds copies of secrets data locally, allowing fast retrieval without direct communication with the remote data center, while the intermediary itself maintains security protocols and access controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secrets management is performed manually, then security control is maintained, but the process is complicated and time-consuming

Engineering Contradiction:
Improvesecurity controlVSAvoidsecrets management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service by enabling virtual assets to automatically retrieve and manage their own secrets data from the cached storage in the cloud environment. The system provides automated authentication and retrieval mechanisms where virtual assets can independently access required secrets without manual intervention, thereby maintaining security through automated access controls while dramatically improving management efficiency and reducing time-consuming manual operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary setup and configuration of secrets distribution policies and cached data before operational needs arise. By pre-configuring the secrets cache with necessary data and establishing automated retrieval protocols in advance, the system eliminates the need for complex manual management during actual operations, allowing virtual assets to efficiently access secrets through pre-established automated processes.

Inventive Principle:
Principle #10Preliminary action

3Speed

If secrets are cached outside the secrets distribution system, then latency is minimized, but security risks may increase

Engineering Contradiction:
Improvesecrets retrieval speedVSAvoidsecrets security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces a secure intermediary layer - a controlled secrets cache in the cloud environment - that mediates between the remote secrets distribution system and virtual assets. This intermediary maintains security through implemented access controls, authentication mechanisms, and encrypted storage, while simultaneously enabling fast local retrieval of secrets by virtual assets without requiring continuous communication with the remote data center.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by implementing different security and access characteristics in different locations. The secrets cache in the cloud environment has locally optimized security measures and access protocols tailored to that environment, allowing fast retrieval by local virtual assets while maintaining appropriate security controls specific to the cloud setting, rather than using a one-size-fits-all approach.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3036644B1Method and system for providing a secure secrets proxy
Publication Date: 2018.12.19 INTUIT INC
  • EP3036644B1 patent drawingFigure 1
  • EP3036644B1 patent drawingFigure 2
  • EP3036644B1 patent drawingFigure 3

AI summary

A secure secrets proxy is instantiated in a first computing environment and includes secure secrets proxy authentication data for identifying itself to a secrets distribution management system in a second computing environment as a trusted virtual asset to receive and cache secrets data in a secure secrets cache outside the second computing environment. The secure secrets proxy requests one or more secrets to be cached and is then provided data representing the requested secrets in the secure secrets cache. The secure secrets proxy then receives secrets application request data from a second virtual asset instantiated in the first computing environment requesting one or more secrets be applied to second virtual asset data. The secure secrets proxy then obtains the required secrets from the secure secrets cache and coordinates the application of the secrets to the second virtual asset data.