IP Library Granted Patent US 7,543,145
Granted Patent B2
US 7,543,145 · App. 11/072,733 · Granted Jun 2, 2009

System and method for protecting configuration settings in distributed text-based configuration files

Assignee: Microsoft Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,543,145
App. No.
11/072,733
Granted
Jun 2, 2009
Kind
B2
Abstract

System and methods for protecting sensitive data stored in a text-based configuration file. In a web server application, data associated with sensitive information such as connection information for a remote database may be stored within a configuration file and accessed whenever a request for information from that database is received. To prevent unwanted access to remote database, the portion of the configuration file with sensitive information is encrypted. A decryption provider selected by the requesting server or client application decrypts the sensitive data using the decryption key, retrieves protected data from the remote database, and the configuration server provides a response based on the sensitive data protecting access to the remote database. The encryption/decryption process is transparent to the web server application consuming the configuration.

Claims (40)

1. A computer-implemented method for protecting connection strings in a mark-up language (ML) configuration file, the method comprising:

receiving a request on a configuration server, wherein the request includes a request for sensitive configuration setting data located in a database of the configuration server, wherein the request includes decryption provider information;

in response to receiving the request, retrieving a ML configuration file related to the request, wherein the ML configuration file includes encrypted connection strings used to obtain the sensitive configuration setting data from the database of the configuration server;

in response to retrieving the ML configuration file related to the request, utilizing the decryption provider information to decrypt the connection strings of the ML configuration file;

accessing, by the configuration server, the sensitive configuration setting data located in the database of the configuration server based on the decrypted connection strings;

building, by the configuration server, an output file that includes the sensitive configuration setting data; and

sending the output file to a sender of the request.

2. The computer-implemented method of claim 1 , wherein the decryption provider information includes a location of a decryption provider, wherein utilizing the decryption provider information to decrypt the connection strings of the ML configuration file includes sending the ML configuration file to the location of the decryption provider for decryption.

3. The computer-implemented method of claim 1 , wherein the connection strings are encrypted by at least one member of a group comprising: RSA encryption, password wrap encryption, and computational-based encryption.

4. The computer-implemented method of claim 1 , wherein the ML configuration file includes a provider of encryption for the encrypted connection strings.

5. The computer-implemented method of claim 1 , wherein the ML configuration file includes an address for an encryption type, an address for an encryption method and an address for an encryption key.

6. The computer-implemented method of claim 1 , wherein the output file is a ML output file.

7. The computer-implemented method of claim 6 , wherein the ML output file is at least one member of a group comprising: an XML output file and a HTML output file.

8. A computer-readable storage medium having computer-executable instructions for protecting connection strings in a mark-up language (ML) configuration file, the instructions comprising:

receiving a request on a configuration server, wherein the request includes a request for sensitive configuration setting data located in a database of the configuration server;

in response to receiving the request, retrieving a ML configuration file related to the request, wherein the ML configuration file includes encrypted connection strings used to obtain the sensitive configuration setting data from the database of the configuration server;

in response to retrieving the ML configuration file related to the request, utilizing decryption provider information to decrypt the connection strings of the ML configuration file;

accessing, by the configuration server, the sensitive configuration setting data located in the database of the configuration server based on the decrypted connection strings;

building, by the configuration server, an output file that includes the sensitive configuration setting data; and

sending the output file to a sender of the request.

9. The computer-readable storage medium of claim 8 , wherein the decryption provider information includes a location of a decryption provider, wherein utilizing the decryption provider information to decrypt the connection strings of the ML configuration file includes sending the ML configuration file to the location of the decryption provider for decryption.

10. The computer-readable storage medium of claim 8 , wherein the connection strings are encrypted by at least one member of a group comprising: RSA encryption, password wrap encryption, and computational-based encryption.

11. The computer-readable storage medium of claim 8 , wherein the ML configuration file includes a provider of encryption for the encrypted connection strings.

12. The computer-readable storage medium of claim 8 , wherein the ML configuration file includes an address for an encryption type, an address for an encryption method and an address for an encryption key.

13. The computer-readable storage medium of claim 8 , wherein the output file is a ML output file.

14. The computer-readable storage medium of claim 13 , wherein the ML output file is at least one member of a group comprising: an XML output file and a HTML output file.

15. A system for protecting connection strings in a mark-up language (ML) configuration file, the system comprising:

a processor of a configuration server; and

a memory of a configuration server having computer-executable instructions stored thereon, wherein the computer-executable instructions are configured for:

receiving a request, wherein the request includes a request for sensitive configuration setting data located in a database of the configuration server;

in response to receiving the request, retrieving a ML configuration file related to the request, wherein the ML configuration file includes encrypted connection strings used to obtain the sensitive configuration setting data from the database of the configuration server;

in response to retrieving the ML configuration file related to the request, utilizing decryption provider information to decrypt the connection strings of the ML configuration file;

accessing the sensitive configuration setting data located in the database of the configuration server based on the decrypted connection strings;

building an output file that includes the sensitive configuration setting data; and

sending the output file to a sender of the request.

16. The system of claim 15 , wherein the decryption provider information includes a location of a decryption provider, wherein utilizing the decryption provider information to decrypt the connection strings of the ML configuration file includes sending the ML configuration file to the location of the decryption provider for decryption.

17. The system of claim 15 , wherein the connection strings are encrypted by at least one member of a group comprising: RSA encryption, password wrap encryption, and computational-based encryption.

18. The system of claim 15 , wherein the ML configuration file includes a provider of encryption for the encrypted connection strings.

19. The system of claim 15 , wherein the ML configuration file includes an address for an encryption type, an address for an encryption method and an address for an encryption key.

20. The system of claim 15 , wherein the output file is a ML output file.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034543/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2005
From: OLSON, ERIK B.; VASANDANI, MANU; COHN, MARCHEL
To: MICROSOFT CORPORATION
Reel/Frame 016187/0027 →
Continuity (1)
Related Publication 20060200665A1 · Sep 7, 2006