IP Library Patent Application 18983027
Patent Application
App. No. 18/983,027

SECRETS MANAGEMENT SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/983,027
Abstract

A method and server system for using secured secrets by distributed systems are disclosed. The method can include receiving, from a first user system, a request for a credential. The method can further include in response to the request, generating a credential blob and signature data of the credential blob. The credential blob can include encrypted secrets data and credential metadata. The method can further include sending, to the first user system, the credential blob and the signature data. The method can further include receiving, from the first user system, a service request with the credential blob and the signature data. The method can further include in response to the service request, building artifact data that includes the credential blob. The method can further include deploying the artifact data and the signature data to a second user system.

Claims (57)

1 . A computer-implemented method for using secured secrets by distributed systems, the method comprising:

receiving, by a server system from a first user system, a request for a credential;

in response to the request, generating, by the server system, a credential blob and signature data of the credential blob, the credential blob including encrypted secrets data and credential metadata;

sending, by the server system to the first user system, the credential blob and the signature data of the credential blob;

receiving, by the server system from the first user system, a service request with the credential blob and the signature data of the credential blob;

in response to the service request, building, by the server system, artifact data including the credential blob; and

deploying, by the server system, the artifact data and the signature data to a second user system.

2 . The method of claim 1 , further comprising:

receiving, by the server system from the second user system, a decryption request to decrypt the encrypted secrets data;

in response to the decryption request, obtaining, by the server system, the credential blob from the artifact data, and the signature data of the credential blob;

determining, by the server system, whether the signature data of the credential blob is valid;

in response to determining that the signature data of the credential blob is valid, decrypting, by the server system, the encrypted secrets data of the credential blob to produce decrypted secrets data; and

providing, by the server system, the decrypted secrets data to the second user system.

3 . The method of claim 2 , wherein the encrypted secrets data of the credential blob is decrypted using a credential wrapping key.

4 . The method of claim 2 , further comprising:

in response to the decryption request, validating, by the server system, a service identity authorized to decrypt the encrypted secrets data.

5 . The method of claim 4 , wherein validating the service identity authorized to decrypt the encrypted secrets data comprises checking the service identity against an access control list in the credential blob.

6 . The method of claim 1 , further comprising:

encrypting, by the server system, secrets data using a credential wrapping key to produce the encrypted secrets data.

7 . The method of claim 1 , wherein the signature data of the credential blob is signed using a signing private key.

8 . The method of claim 1 , wherein the credential metadata is unencrypted.

9 . One or more non-transitory computer readable storage media having instructions stored thereupon which, when executed by a server system having at least a processor and a memory therein, cause the server system to perform operations, the operations comprising:

receiving, by a server system from a first user system, a request for a credential;

in response to the request, generating, by the server system, a credential blob and signature data of the credential blob, the credential blob including encrypted secrets data and credential metadata;

sending, by the server system to the first user system, the credential blob and the signature data of the credential blob;

receiving, by the server system from the first user system, a service request with the credential blob and the signature data of the credential blob;

in response to the service request, building, by the server system, artifact data including the credential blob; and

deploying, by the server system, the artifact data and the signature data to a second user system.

10 . The non-transitory computer readable storage media of claim 9 , wherein the operations further comprise:

receiving, by the server system from the second user system, a decryption request to decrypt the encrypted secrets data;

in response to the decryption request, obtaining, by the server system, the credential blob from the artifact data, and the signature data of the credential blob;

determining, by the server system, whether the signature data of the credential blob is valid;

in response to determining that the signature data of the credential blob is valid, decrypting, by the server system, the encrypted secrets data of the credential blob to produce decrypted secrets data; and

providing, by the server system, the decrypted secrets data to the second user system.

11 . The non-transitory computer readable storage media of claim 10 , wherein the encrypted secrets data of the credential blob is decrypted using a credential wrapping key.

12 . The non-transitory computer readable storage media of claim 10 , wherein the operations further comprise: in response to the decryption request, validating, by the server system, a service identity authorized to decrypt the encrypted secrets data.

13 . The non-transitory computer readable storage media of claim 12 , wherein validating the service identity authorized to decrypt the encrypted secrets data comprises checking the service identity against an access control list in the credential blob.

14 . The non-transitory computer readable storage media of claim 9 , wherein the operations further comprise: encrypting, by the server system, secrets data using a credential wrapping key to produce the encrypted secrets data.

15 . The non-transitory computer readable storage media of claim 9 , wherein the signature data of the credential blob is signed using a signing private key.

16 . The non-transitory computer readable storage media of claim 9 , wherein the credential metadata is unencrypted.

17 . A server system, comprising:

a memory; and

a processor coupled with the memory configured to perform operations comprising:

receiving, by a server system from a first user system, a request for a credential;

in response to the request, generating, by the server system, a credential blob and signature data of the credential blob, the credential blob including encrypted secrets data and credential metadata;

sending, by the server system to the first user system, the credential blob and the signature data of the credential blob;

receiving, by the server system from the first user system, a service request with the credential blob and the signature data of the credential blob;

in response to the service request, building, by the server system, artifact data including the credential blob; and

deploying, by the server system, the artifact data and the signature data to a second user system.

18 . The server system of claim 17 , wherein the operations further comprise:

receiving, by the server system from the second user system, a decryption request to decrypt the encrypted secrets data;

in response to the decryption request, obtaining, by the server system, the credential blob from the artifact data, and the signature data of the credential blob;

determining, by the server system, whether the signature data of the credential blob is valid;

in response to determining that the signature data of the credential blob is valid, decrypting, by the server system, the encrypted secrets data of the credential blob to produce decrypted secrets data; and

providing, by the server system, the decrypted secrets data to the second user system.

19 . The server system of claim 18 , wherein the encrypted secrets data of the credential blob is decrypted using a credential wrapping key.

20 . The server system of claim 19 , wherein the operations further comprise: in response to the decryption request, validating, by the server system, a service identity authorized to decrypt the encrypted secrets data.

Assignments (2)
CHANGE OF NAME Recorded Mar 13, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 075093/0754 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2024
From: MUKHERJEE, SOUMIL; NIELSEN, HANS; DREIER, DANIEL; KHANDELWAL, ANKIT; WRIGHT, JORDAN; LUDWIG, KELBY; GAGNON, CAMERON; CARLETON, PAUL; STUBBLEFIELD, ADAM
To: STRIPE, INC.
Reel/Frame 069601/0644 →