EP3036643B1

Method and system for distributing secrets

Abstract

This record has no abstract on file.

EP3036643B1, drawing sheet 1
Sheet 1 of 6

Term

8 yearsleft in the term

Expires 30 September 2034.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

13 claims: 1 independent, 12 dependent

  1. 1
    A system for distributing secrets comprising:at least one processor;and at least one memory coupled to the at least one processor, the at least one memory having stored therein instructions which when executed by any set of the one or more processors, perform a process for distributing secrets, the process for distributing secrets including: providing secrets data (100A, ... 104A) representing one or more secrets required to access associated resources (170C, 170R);providing secrets distribution policy data (124) representing one or more secrets distribution factors used to control the distribution of the one or more secrets;receiving secrets request data (142) from a requesting virtual asset (140) for secrets data necessary to access one or more associated resources;obtaining requesting virtual asset profile data (143) associated with the requesting virtual asset;authenticating the requesting virtual asset;analyzing the requesting virtual asset profile data using one or more of the one or more secrets distribution factors to generate authorized secrets data (100S, 101S, 103S) for the requesting virtual asset;and providing the requesting virtual asset access to the authorized secrets data for the requesting virtual asset;wherein the one or more secrets comprise one or more secret classes, each of the secret classes being associated with a resource type, whereby the secrets are classified according to the type of resource the secret is used to access, wherein the secrets request data comprises a request for certain classes of secrets associated with specific resources, and wherein the secrets distribution factors are used to control the distribution of the classes of secrets;and wherein the requesting virtual asset profile data are analyzed using one or more of the one or more secrets distribution factors to determine what secret classes the requesting virtual asset legitimately needs, and to generate authorized secret classes data for the requesting virtual asset indicating the classes of secrets the requesting virtual asset is authorized to receive;the method further comprising obtaining authorized secrets set data (134) for the requesting virtual asset representing a set of secrets for the requesting virtual asset obtained in accordance with the authorized secret classes data for the requesting virtual asset;wherein providing the requesting virtual asset access to the authorized secrets set data for the requesting virtual asset includes: encrypting the authorized secrets set data for the requesting virtual asset;assigning identification data (137) to the encrypted authorized secrets set data (136) for the requesting virtual asset;storing the encrypted authorized secrets set data for the requesting virtual asset in a secrets store (160);providing the requesting virtual asset the identification data and an encryption key (138) for identifying and decrypting the encrypted authorized secrets set data for the requesting virtual asset;and providing the requesting virtual asset access to the secrets store.
  2. 2
    The system for distributing secrets of Claim 1 wherein at least one of the one or more classes of secrets is selected from the group of classes of secrets consisting of:database access secrets;external services access secrets;internal services access data;passwords;passphrases;biometric data;digital certificates;encryption keys;and SSL certificates.
  3. 3
    The system for distributing secrets of Claim 1 wherein at least one of the one or more resource types is selected from the group of resource types consisting of:databases and data;external services;internal services;cloud-based services;data center-based services;the Internet;a cloud;applications;encrypted data;authenticated SSL communication channels;wireless accessible services;and any communication channels.
  4. 4
    The system for distributing secrets of Claim 1 wherein at least one of the one or more secrets distribution factors is selected from the group of secrets distribution factors consisting of:a determination as to whether owner identification data associated with the owner of the requesting virtual asset is included in a registry of trusted owners' owner identification data;a determination as to whether the requesting virtual asset is in compliance with one or more security policies;a determination as to how long the requesting virtual asset has currently been operating;a determination of the number of resources associated with the requesting virtual asset;a determination of modules or capabilities associated with the requesting virtual asset;a determination of the type of requesting virtual asset and the legitimate access requirements of that type of requesting virtual asset;and any combination thereof.
  5. 5
    The system for distributing secrets of Claim 1 wherein the secrets request data is received from the requesting virtual asset through a resource services gateway (121), and optionally wherein the requesting virtual asset is communicatively coupled to the resource services gateway via a secure communications channel, and optionally wherein the secure communications channel is an authenticated Secure Sockets Layer (SSL) communications channel.
  6. 6
    The system for distributing secrets of Claim 1 wherein the secrets request data is received from the requesting virtual asset through a resource services gateway proxy (187), and optionally wherein the requesting virtual asset is communicatively coupled to the resource services gateway proxy via a secure communications channel (181A).
  7. 7
    The system for distributing secrets of Claim 6 wherein the secure communications channel is an authenticated Secure Sockets Layer (SSL) communications channel or any private communications channel.
  8. 8
    The system for distributing secrets of Claim 1 wherein authenticating the requesting virtual asset includes determining whether owner identification data associated with the owner of the requesting virtual asset is included in a registry (125) of trusted owners' owner identification data, and optionally wherein owner identification data is an account number associated with the owner of the requesting virtual asset.
  9. 9
    The system for distributing secrets of Claim 1 wherein the number and type of secrets distribution factors used to analyze the requesting virtual asset profile data is determined by the type of requesting virtual asset.
  10. 10
    The system for distributing secrets of Claim 1 wherein the number and type of secrets distribution factors used to analyze the requesting virtual asset profile data is determined by the capabilities of requesting virtual asset.
  11. 11
    The system for distributing secrets of Claim 1 wherein the number and type of secrets distribution factors used to analyze the requesting virtual asset profile data is determined by the reputation profile of the virtual requesting asset.
  12. 12
    The system for distributing secrets of Claim 1 wherein the number and type of secrets distribution factors used to analyze the requesting virtual asset profile data is determined by the resources associated with the requesting virtual asset.