Invention Grant
- Patent Title: Secret protection during software development life cycle
-
Application No.: US17649513Application Date: 2022-01-31
-
Publication No.: US11997215B2Publication Date: 2024-05-28
- Inventor: Prasad Peddada , Matthew Schechtman , Taher Elgamal
- Applicant: salesforce.com, inc.
- Applicant Address: US CA San Francisco
- Assignee: Salesforce, Inc.
- Current Assignee: Salesforce, Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Kowert, Hood, Munyon, Rankin & Goetzel, P.C.
- Agent Dean M. Munyon
- Main IPC: G06F21/60
- IPC: G06F21/60 ; H04L9/08 ; H04L9/32

Abstract:
Techniques are disclosed relating to the protection of secrets within a software development lifecycle. Developers can use an encryption service to encrypt a secret to be used by an application within a package. The secret can be associated with the application, and then encrypted and included in a package that is signed and passed through a software automation pipeline to a data center that hosts the production server for the application. The application executing on the production server can request that the secret be decrypted by a decryption service after package verification. A developer can also specify, in a manifest file, a set of secrets needed for applications executing in the same data center. The manifest file may be passed from the software development environment to the data center, where the specified secrets are created and used by the applications without ever residing or being accessible outside the data center.
Public/Granted literature
- US20230246845A1 Secret Protection During Software Development Life Cycle Public/Granted day:2023-08-03
Information query