IP Library Granted Patent US 9,607,171
Granted Patent B2
US 9,607,171 · App. 14/537,026 · Granted Mar 28, 2017

Preventing sharing of sensitive information through code repositories

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,607,171
App. No.
14/537,026
Granted
Mar 28, 2017
Kind
B2
Abstract

Methods, systems, and computer program products for preventing sharing of sensitive information through code repositories are provided herein. A method includes detecting one or more items of sensitive information in a check-in associated with a given user in a shared version management system; automatically refactoring the one or more items of sensitive information in the check-in by externalizing the one or more items of sensitive information as an encrypted file; and upon acceptance by the user of one or more changes to the check-in, automatically (i) decrypting the encrypted file using one or more code repository credentials associated with the given user, and (ii) incorporating the one or more items of sensitive information into the check-in.

Claims (41)

1. A method comprising the following steps:

automatically determining one or more project settings associated with a user;

detecting one or more items of sensitive information in a check-in associated with the user in a shared version management system, wherein said check-in comprises an attempted submission of one or more local modifications made by the user to one or more files shared through the shared version management system, and wherein the items of sensitive information comprise one or more items of credential information that enable the user to access a particular application programming interface;

invoking a version management wrapper in response to said detecting, wherein said version management wrapper comprises a plug-in component to said shared version management system, and wherein the version management wrapper is configured to:

automatically refactor the one or more items of sensitive information in the check-in by externalizing the one or more items of sensitive information as an encrypted file; and

upon acceptance by the user of one or more changes to the check-in, and based on the determined project settings, automatically (i) decrypt the encrypted file using one or more code repository credentials associated with the user, and (ii) incorporate the one or more items of sensitive information into the check-in;

wherein said steps are executed by at least one computing device.

2. The method of claim 1 , wherein said detecting comprises performing code analysis to identify application programming interface key usage.

3. The method of claim 2 , wherein said performing code analysis comprises using a pattern library to identify application programming interface key usage.

4. The method of claim 2 , wherein said performing code analysis comprises performing backward code slicing to identify application programming interface key usage.

5. The method of claim 1 , wherein said encrypted file comprises an encrypted text file.

6. The method of claim 1 , comprising:

generating a preventive warning based on the one or more items of sensitive information detected in the check-in.

7. A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computing device to cause the computing device to:

automatically determine one or more project settings associated with a user;

detect one or more items of sensitive information in a check-in associated with the user in a shared version management system, wherein said check-in comprises an attempted submission of one or more local modifications made by the user to one or more files shared through the shared version management system, and wherein the items of sensitive information comprise one or more items of credential information that enable the user to access a particular application programming interface;

invoke a version management wrapper in response to said detecting, wherein said version management wrapper comprises a plug-in component to said shared version management system, and wherein the version management wrapper is configured to:

automatically refactor the one or more items of sensitive information in the check-in by externalizing the one or more items of sensitive information as an encrypted file; and

upon acceptance by the user of one or more changes to the check-in, and based on the determined project settings, automatically (i) decrypt the encrypted file using one or more code repository credentials associated with the user, and (ii) incorporate the one or more items of sensitive information into the check-in.

8. The computer program product of claim 7 , wherein said detecting comprises performing code analysis to identify application programming interface key usage.

9. A system comprising:

a memory; and

at least one processor coupled to the memory and configured for:

automatically determining one or more project settings associated with a user;

detecting one or more items of sensitive information in a check-in associated with the user in a shared version management system, wherein said check-in comprises an attempted submission of one or more local modifications made by the user to one or more files shared through the shared version management system, and wherein the items of sensitive information comprise one or more items of credential information that enable the user to access a particular application programming interface;

invoking a version management wrapper in response to said detecting, wherein said version management wrapper comprises a plug-in component to said shared version management system, and wherein the version management wrapper is configured to:

automatically refactor the one or more items of sensitive information in the check-in by externalizing the one or more items of sensitive information as an encrypted file; and

upon acceptance by the user of one or more changes to the check-in, and based on the determined project settings, automatically (i) decrypt the encrypted file using one or more code repository credentials associated with the user, and (ii) incorporate the one or more items of sensitive information into the check-in.

10. A method comprising the following steps:

automatically determining one or more project settings associated with a user;

detecting one or more items of sensitive information in a check-in associated with the user in a shared version management system, wherein said check-in comprises an attempted submission of one or more local modifications made by the user to one or more files shared through the shared version management system, and wherein the items of sensitive information comprise one or more items of credential information that enable the user to access a particular application programming interface;

invoking a version management wrapper in response to said detecting, wherein said version management wrapper comprises a plug-in component to said shared version management system, and wherein the version management wrapper is configured to:

automatically refactor the one or more items of sensitive information in the check-in by externalizing the one or more items of sensitive information as an anonymized file; and

upon acceptance by the user of one or more changes to the check-in, and based on the determined project settings, automatically replace the anonymized file in the check-in with a stored instance of the one or more items of sensitive information;

wherein said steps are executed by at least one computing device.

11. The method of claim 10 , wherein said detecting comprises performing code analysis to identify application programming interface key usage.

12. The method of claim 11 , wherein said performing code analysis comprises using a pattern library to identify application programming interface key usage.

13. The method of claim 11 , wherein said performing code analysis comprises performing backward code slicing to identify application programming interface key usage.

14. The method of claim 10 , wherein said externalizing comprises storing one or more user settings in a local file that is not committed.

15. The method of claim 10 , comprising:

generating a preventive warning based on the one or more items of sensitive information detected in the check-in.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: AIRBNB, INC.
Reel/Frame 056427/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2014
From: DHOOLIA, PANKAJ; KUMARASAMY MANI, SENTHIL KUMAR; PADHYE, ROHAN RAJU; SINHA, VIBHA SINGHAL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 034136/0839 →