IP Library Granted Patent US 10,936,383
Granted Patent B2
US 10,936,383 · App. 15/604,154 · Granted Mar 2, 2021

Hard coded credential bypassing

Inventor: Gulshan Govind Vaswani (Bangalore, IN)
Assignee: Micro Focus Software Inc.
G06F9/543H04L63/0815H04W12/0608
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,936,383
App. No.
15/604,154
Granted
Mar 2, 2021
Kind
B2
Abstract

An existing application processing on a client device initiates a function to provide a hard coded credential to a remote target application for purposes of logging into and gaining access to the remote target application. A hook to the function causes an agent to be activated, the agent dynamically contacts a credential vault to obtain a randomly generated credential for access to the remote target application. The hook injects the randomly generated credential over the hard coded credential supplied by the existing application and the function is initiated. The function logs into the target application using the randomly generated credential providing the existing application access to the remote target application. The hard coded credential is bypassed by the randomly generated credential.

Claims (36)

1. A method for bypassing hard coded credentials, comprising:

bypassing an internal portion of processing for an existing application processing on a client by replacing an addresses in memory associated with an internal function call made by the internal portion of the existing application with a different address associated with the method,

wherein the internal function is a call made by the existing application to a target application for authenticating the existing application to the target application for access;

obtaining a randomly generated credential on behalf of the existing application by at least computing a checksum value for the existing application,

authenticating the existing application based on the checksum value, and

obtaining the randomly generated credential for the existing application based on the authenticating;

injecting the randomly generated credential into the internal portion of the processing by replacing a credential generated by the existing application with the randomly generated credential and calling the address in memory of the internal function with the randomly generated credential causing the internal function of the existing application to call the target application and log the existing application into the target application using the randomly generated credential instead of the credential; and processing the method without any coding modifications made to the existing application.

2. The method of claim 1 , wherein bypassing further includes processing a hook to jump to the method processing when the existing application calls the internal portion as a call to the internal function made by the existing application.

3. The method of claim 2 , wherein processing further includes processing the hook as a trampoline function that processes as a first instruction of the internal function.

4. The method of claim 2 , wherein processing further includes processing the hook as an Application Programming Interface (API) hook that is a dynamically linked library injected into a processing space within the existing application on the client.

5. The method of claim 1 , wherein obtaining further includes authenticating to a credential store and making a request for the randomly generated credential.

6. The method of claim 5 , wherein authenticating further includes obtaining processing information for the existing application from an Operating System (OS) that the existing application processes within on the client.

7. The method of claim 6 , wherein obtaining further includes passing the processing information to the credential store for authenticating the request.

8. The method of claim 1 , wherein injecting further includes writing over a hard coded credential representing the credential with the randomly generated credential, wherein the hard coded credential provided as input to the internal portion by the existing application when the existing application called the internal portion.

9. The method of claim 8 , wherein writing further includes reporting to a credential store from which the randomly generated credential was obtained that the existing application has received the randomly generated credential.

10. The method of claim 1 further comprising, processing the method as an Operating System (OS) hooking Application Programming Interface (API) and an agent that process on the client.

11. A method for bypassing hard coded credentials, comprising: receiving a request for a credential from an agent processing on a client,

wherein the agent is processed when an internal portion of an existing application calls a memory address associated with an internal function of the existing application and the internal function calls a target application with an application-generated credential produced by the existing application;

obtaining a randomly generated credential on behalf of the existing application by at least computing a checksum value for the existing application,

authenticating the request made by the existing application based on processing information comprising at least the checksum value computed by the agent for the existing application and provided by the agent;

provide the credential to the agent for the agent to inject into the internal portion by replacing the application-generated credential with the credential and calling the memory address to invoke the internal function,

causing the internal function to call the target application and log the existing application into the target application with the credential for authenticated access to the target application; and processing the method without any coding modifications made to the existing application.

12. The method of claim 11 , wherein receiving further includes receiving the request based on the existing application attempting to internally process the internal function that logs into the target application with a hard coded credential provided by the existing application to the function as the application-generated credential.

13. The method of claim 11 , wherein authenticating further includes providing the processing information to a policy engine to authenticate the existing application for the request.

14. The method of claim 11 , wherein providing further includes maintaining the credential with an account that the existing application has with the target application.

15. The method of claim 14 , wherein maintaining further includes processing an Application Programming Interface (API) of the target application to randomly create and define the credential for the account through the target application in advance of receiving the request from the agent.

16. The method of claim 15 , wherein processing further includes processing the API to establish a new randomly generated credential that replaces the credential for the account in response to receiving an indication from the agent that the existing application has logged into the target application with the credential thereby invaliding the credential for access to the target application a next time that the existing application attempts to log into the target application.

17. The method of claim 11 , wherein injecting further includes placing a lock on the credential when provided to the agent ensuring that the credential cannot be provided or used by a different existing application and different agent interfaced to the method.

18. A system for bypassing hard coded credentials, comprising:

a server configured with a credential manager;

wherein the credential manager is configured to:

a) execute on at least one hardware processor of the server,

b) interact with an agent of a client to authenticate an existing application of the client for a randomly generated replacement credential to an original hardcoded credential of the existing application by using at least a checksum value computed for the existing application by the agent,

c) provide the replacement credential to the agent to replace the original hardcoded credential with the replacement credential within memory for an executing version of the existing application and without any coding modifications to the existing application for the executing version of the existing application to authenticate to a target application, and

d) manage an account that the existing application has with the target application to define the replacement credential and to change the replacement credential.

19. The system of claim 18 , wherein the credential manager is further configured, in b), to: 1) provide processing information for the existing application to a policy engine that evaluates policies in view of the processing information and 2) receive an authorization back from the policy engine indicating that the existing application is to receive the replacement credential based on the processing information.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2026
From: MICRO FOCUS SOFTWARE INC.
To: MICRO FOCUS LLC
Reel/Frame 073758/0781 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY TO MICRO FOCUS SOFTWARE INC. INCORRECTLY FILED AS MICRO PREVIOUSLY RECORDED ON REEL 042662 FRAME 0556. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 3, 2020
From: VASWANI, GULSHAN GOVIND
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 052073/0814 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: VASWANI, GULSHAN GOVIND
To: MICRO
Reel/Frame 042662/0556 →