Unified Credential Store for Remote Network Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large enterprise networks, managing and securing access credentials for numerous computing devices and services is challenging due to their scattered storage across various applications and databases, leading to difficulties in securing and retrieving the correct credentials for remote network management.
Innovation Solution
Implementing a unified credential store within a remote network management platform, where credentials are encrypted and accessed through a proxy server, allowing for efficient mapping and retrieval of credentials using labels associated with endpoint identifiers, enabling secure and centralized management across multiple instances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credentials are stored in scattered locations across various applications and databases, then credentials can be accessed by multiple services, but security management becomes difficult and credential retrieval becomes inefficient
Solution Approach 1:
The patent consolidates credentials scattered across multiple applications and databases into a single unified credential store. This centralized repository collects all credentials in one location, making them easier to manage and retrieve while improving security control. The unified store eliminates the need to search through multiple distributed storage locations.
Solution Approach 2:
The patent introduces a credential service as an intermediary component that sits between applications and the unified credential store. This service handles credential retrieval, validation, and distribution requests, simplifying access for applications while maintaining centralized control and security policies.
2Reliability
If credentials are stored in a unified credential store, then security management is improved and retrieval is efficient, but all credentials cannot be accessed by all services
Solution Approach 1:
The patent implements role-based access control where different services and applications are granted specific access permissions to specific credentials based on their needs. The credential service evaluates access requests against defined policies, allowing each service to access only the credentials necessary for its function, thereby maintaining security while providing appropriate flexibility.
3Reliability
If credentials are encrypted in the unified credential store, then security is improved, but credential access requires additional decryption steps
Solution Approach 1:
The patent implements a caching mechanism where frequently accessed credentials are decrypted and stored in an encrypted cache within the credential service. This preliminary decryption action reduces the time required for subsequent access to the same credentials, as the cache can provide them more quickly while maintaining security through controlled access to the cache itself.
Data Source
AI summary
An example embodiment may involve receiving, by a server device that stores a plurality of access credentials for computing devices that are disposed within a managed network, a request containing a label and an indication of an application service. The server device may be disposed within a remote network management platform that remotely manages the managed network. The example embodiment may further involve mapping, by the server device, the label and the application service to an endpoint identifier of a target computing device that is disposed within the managed network. The endpoint identifier may be associated with particular access credentials that are usable to access the application service executing on the target computing device. The example embodiment may further involve transmitting, by the server device, the endpoint identifier and the particular access credentials.


