IP Library Granted Patent US 11,727,107
Granted Patent B1
US 11,727,107 · App. 17/540,070 · Granted Aug 15, 2023

Machine scanning system with distributed credential storage

Inventor: James Edward Cancilla (Milton, CA)
Assignee: Rapid7 Inc.
G06F21/45H04L9/0825H04L9/0897H04L9/3226
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,727,107
App. No.
17/540,070
Granted
Aug 15, 2023
Kind
B1
Abstract

Systems and methods are disclosed to implement a machine scanning system that stores machine access credentials in a distributed fashion in a pool of scanner nodes. In embodiments, a storage manager node is selected from the pool to manage the storage of each new credential. The storage manager partitions the credential into portions and distributes the portions among the nodes, which may store the portions under different encryptions. A credential storage metadata is updated to indicate portion assignments and also distributed. At scanning time, the node selected to perform the scan uses the credential storage metadata to gather the portions and reconstruct the credential. In embodiments, the portions may be assigned so that no single node holds all portions of the credential, and at least two nodes hold each portion. Advantageously, the disclosed storage scheme enhances the security and availability of access credentials used by the machine scanning system.

Claims (44)

1. A system, comprising:

one or more hardware processors with associated memory that implement a machine scanning system that implements a group of machine scanner nodes of, including a first machine scanner node configured to:

receive a credential to perform a scan of a machine and determine that the credential is to be partitioned and distributed among multiple machine scanner nodes in the group;

partition the credential into a plurality of portions;

assign individual ones of the portions to respective ones of the machine scanner nodes in the group;

send the portions to their assigned machine scanner nodes to be stored by the assigned machine scanner nodes; and

update a credential storage metadata to indicate the assigned machine scanner nodes for individual ones of the portions, wherein the individual ones of the assigned machine scanner nodes are configured to use the credential storage metadata to reconstruct the credential.

2. The system of claim 1 , wherein the first machine scanner node is configured to send the credential storage metadata to the assigned machine scanner nodes.

3. The system of claim 1 , wherein the first machine scanner node is configured to:

compute a checksum of the credential and include the checksum in the credential storage metadata, wherein individual ones of the assigned machine scanner nodes are configured to verify the credential after the reconstruction using the checksum.

4. The system of claim 1 , wherein a first one of the assigned machine scanner nodes is configured to:

receive a request to perform a scan of the machine;

determine, based on a credential storage metadata, that a portion of the credential is stored at a second one of the assigned machine scanner nodes;

obtain the portion from the second assigned machine scanner node;

reconstruct the credential using the portion; and

access the machine using the credential to perform the scan of the machine.

5. The system of claim 1 , wherein:

the second assigned machine scanner node is configured to store the portion of the credential in an encrypted form; and

the first assigned machine scanner node is configured to decrypt the portion after obtaining the portion.

6. The system of claim 1 , wherein the machine scanning system is configured to receive a distribution policy via a configuration interface, wherein the portions of the credential are assigned according to the distribution policy.

7. The system of claim 6 , wherein the distribution policy specifies a number of portions that the credential is to be partitioned into.

8. The system of claim 6 , wherein the distribution policy specifies that no machine scanner node in the group is assigned more than one portion of the credential.

9. The system of claim 6 , wherein the distribution policy specifies that each of the portions is assigned redundantly to at least two machine scanner nodes in the group.

10. The system of claim 6 , wherein the distribution policy specifies to reassign the portions periodically.

11. The system of claim 6 , wherein the distribution policy specifies to reassign the portions of the credential in response to a membership change of the group.

12. The system of claim 6 , wherein the distribution policy specifies to reassign the portions of the credential in response to detection of an abnormal access to the machine.

13. The system of claim 6 , wherein the distribution policy specifies to reassign the portions of the credential in response to a membership change of the group.

14. A method, performed by one or more hardware processors with associated memory that implement a machine scanning system of a group of machine scanner nodes, the method comprising:

receiving a credential to perform a scan of a machine and determining that the credential is to be partitioned and distributed among multiple machine scanner nodes in the group;

partitioning the credential into a plurality of portions;

assigning individual ones of the portions to respective ones of the machine scanner nodes in the group;

sending the portions to their assigned machine scanner nodes to be stored by the assigned machine scanner nodes; and

updating a credential storage metadata to indicate the assigned machine scanner nodes for individual ones of the portions, wherein the individual ones of the assigned machine scanner nodes are configured to use the credential storage metadata to reconstruct the credential.

15. The method of claim 14 , further comprising sending the credential storage metadata to the assigned machine scanner nodes.

16. The method of claim 14 , furthering comprising receiving a distribution policy via a configuration interface of the machine scanning system, wherein the portions of the credential are assigned according to the distribution policy.

17. The method of claim 16 , wherein the distribution policy specifies that the assignment is to be performed based on one or more availability characteristics of the machine scanner nodes.

18. The method of claim 16 , wherein the distribution policy specifies that no machine scanner node in the group is assigned more than one portion of the credential.

19. The method of claim 16 , wherein the distribution policy specifies that each of the portions of the credential is assigned redundantly to at least two machine scanner nodes in the group.

20. One or more non-transitory computer-accessible storage media storing program instructions that when executed on or across one or more processors implement at least a portion of a machine scanning system, wherein the machine scanning system implements a group of machine scanner nodes, and the program instructions cause machine scanning system to:

receive a credential to perform a scan of a machine and determine that the credential is to be partitioned and distributed among multiple machine scanner nodes in the group;

partition the credential into a plurality of portions;

assign individual ones of the portions to respective ones of the machine scanner nodes in the group;

send the portions to their assigned machine scanner nodes to be stored by the assigned machine scanner nodes; and

update a credential storage metadata to indicate the assigned machine scanner nodes for individual ones of the portions, wherein the individual ones of the assigned machine scanner nodes are configured to use the credential storage metadata to reconstruct the credential.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: CANCILLA, JAMES EDWARD
To: RAPID7, INC.
Reel/Frame 068702/0553 →
Continuity (1)
Continuation 16874577 · May 14, 2020