IP Library Granted Patent US 12,562,900
Granted Patent B2
US 12,562,900 · App. 18/371,665 · Granted Feb 24, 2026

Secure secrets management in an integration platform

Inventors: Eric Diamond (Conshohocken, PA); Dana Burkart (San Jose, CA); Aleksandr Morozyuk (East Norriton, PA)
Assignee: Boomi, LP
H04L9/0894H04L9/085H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,562,900
App. No.
18/371,665
Granted
Feb 24, 2026
Kind
B2
Abstract

Conventionally, a custom solution must be built for the integration of secrets stored in a secrets manager. Embodiments integrate secrets using an integration process that retrieves a secret from the secrets manager, marks the secret so that it can be appropriately handled, and stores the secret within a container-level environment extension, such that the secret can be utilized by other integration processes within the same runtime container. For enhanced security, the secret is always encrypted within communications and when at rest (e.g., within the environment extension).

Claims (48)

1 . A method comprising using at least one hardware processor to:

by a first integration process within a runtime container of an integration platform,

retrieve a first secret from a secrets manager via an element of the first integration process, wherein the first secret is associated with a parameter that indicates that the first secret is a secret, and

store the first secret in an environment extension within the runtime container, wherein the stored first secret is encrypted;

subsequently, by a second integration process within the runtime container,

retrieve the first secret from the environment extension, and

utilize the first secret within an element of the second integration process; and

securely delete the environment extension when the runtime container is un-instantiated.

2 . The method of claim 1 , wherein retrieving the first secret comprises encrypting the first secret during communication of the first secret from the secrets manager to the first integration process.

3 . The method of claim 2 , wherein the first secret is encrypted during the communication using an encryption key from a key manager.

4 . The method of claim 3 , wherein the encryption key is a container-level key that is specific to the runtime container.

5 . The method of claim 1 , wherein the stored first secret is encrypted using an encryption key from a key manager.

6 . The method of claim 5 , wherein the encryption key is a container-level key that is specific to the runtime container.

7 . The method of claim 1 , wherein utilizing the first secret comprises decrypting the first secret retrieved from the environment extension, and wherein the second integration process securely deletes the decrypted first secret after utilizing the decrypted first secret.

8 . The method of claim 1 , wherein utilizing the first secret comprises sending the first secret to a third-party system without decrypting the first secret.

9 . The method of claim 1 , wherein the first secret comprises access information.

10 . The method of claim 9 , wherein the access information is for a third-party system.

11 . The method of claim 1 , wherein the first secret is personally identifiable information.

12 . The method of claim 1 , further comprising using the at least one hardware processor to, by a third integration process within the runtime container:

determine whether or not a second secret is stored within the environment extension;

when determining that the second secret is stored within the environment extension, retrieve the second secret from the environment extension;

when determining that the second secret is not stored within the environment extension, retrieve the second secret from the secrets manager, and store the second secret in the environment extension within the runtime container, wherein the stored second secret is encrypted; and

utilize the second secret within an element of the third integration process.

13 . The method of claim 1 , wherein the first integration process is a dedicated process that periodically retrieves the first secret from the secrets manager, and stores the first secret in the environment extension.

14 . The method of claim 1 , wherein the first secret represents a data field, and wherein the data field is stored in the environment extension.

15 . The method of claim 1 , wherein the first secret represents a data field, and wherein a reference to the data field on the secrets manager is stored in the environment extension, without storing the data field itself in the environment extension.

16 . The method of claim 15 , wherein retrieving the first secret from the environment extension comprises retrieving the first secret from the secrets manager via the reference.

17 . The method of claim 1 , further comprising using the at least one hardware processor to, by the first integration process, pass the first secret from the element of the first integration process to another element of the first integration process, wherein the first secret is stored in the environment extension by the other element of the first integration process.

18 . A system comprising:

at least one hardware processor; and

software that is configured to, when executed by the at least one hardware processor, perform the method of claim 1 .

19 . A non-transitory computer-readable medium having instructions stored therein, wherein the instructions, when executed by a processor, cause the processor to perform the method of claim 1 .

20 . A method comprising using at least one hardware processor to:

by a first integration process within a runtime container of an integration platform,

retrieve a first secret from a secrets manager via an element of the first integration process, wherein the first secret is associated with a parameter that indicates that the first secret is a secret, and

store the first secret in an environment extension within the runtime container, wherein the stored first secret is encrypted;

subsequently, by a second integration process within the runtime container,

retrieve the first secret from the environment extension, and

utilize the first secret within an element of the second integration process; and

by a third integration process within the runtime container,

determine whether or not a second secret is stored within the environment extension,

when determining that the second secret is stored within the environment extension, retrieve the second secret from the environment extension,

when determining that the second secret is not stored within the environment extension, retrieve the second secret from the secrets manager, and store the second secret in the environment extension within the runtime container, wherein the stored second secret is encrypted, and

utilize the second secret within an element of the third integration process.

21 . A system comprising:

at least one hardware processor; and

software that is configured to, when executed by the at least one hardware processor, perform the method of claim 20 .

22 . A non-transitory computer-readable medium having instructions stored therein, wherein the instructions, when executed by a processor, cause the processor to perform the method of claim 20 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: DIAMOND, ERIC; BURKART, DANA; MOROZYUK, ALEKSANDR
To: BOOMI, LP
Reel/Frame 064995/0567 →
Continuity (1)
Related Publication 20250106020A1 · Mar 27, 2025
References Cited (3)
US 10708051B2 · Bhat · 2020 [cited by examiner]
US 20200033847A1 · Way · 2020 [cited by examiner]
US 20230041959A1 · Guccione · 2023 [cited by examiner]