A Lightweight Privileged Account Management System for Develpoment and Operation

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Privileged accounts are used in both software and hardware during the DevOps process. However, hard-coded privileged accounts in development may not be deleted before submitted to customers, which leads to a greater risk of leakage and results in a larger attack surface. Furthermore, privileged accounts are closely related but widely distributed across the DevOps project, meaning that a leak of any privileged account could result in the entire project being paralyzed. Therefore, privileged account management systems that span the entire development and operation process are needed to address the issue of hard-coded accounts. This paper proposes a privileged account management solution to prevent hard-coded privileged accounts and uniformly manage privileged accounts in DevOps projects. The solution is designed for DevOps scenarios based on Zero Trust thinking, which includes two working stages: development and operation & maintenance. In the development stage, developers apply for encryption keys from the management center and use them to encrypt privileged accounts in the source code. In the operation & maintenance stage, users set their own passwords, which are stored locally, and the management center periodically updates the encryption keys. Finally, this paper discusses the defensive capabilities of the proposed solution against several security risks.

Original languageEnglish
Title of host publicationProceedings - 2023 IEEE 8th International Conference on Smart Cloud, SmartCloud 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages194-199
Number of pages6
ISBN (Electronic)9798350313505
DOIs
StatePublished - 2023
Event8th IEEE International Conference on Smart Cloud, SmartCloud 2023 - Tokyo, Japan
Duration: 16 Sep 202318 Sep 2023

Publication series

NameProceedings - 2023 IEEE 8th International Conference on Smart Cloud, SmartCloud 2023

Conference

Conference8th IEEE International Conference on Smart Cloud, SmartCloud 2023
Country/TerritoryJapan
CityTokyo
Period16/09/2318/09/23

Keywords

  • Development and Operations
  • Keywords—privileged account management
  • Zero Trust
  • data security
  • hard-coded risk

Fingerprint

Dive into the research topics of 'A Lightweight Privileged Account Management System for Develpoment and Operation'. Together they form a unique fingerprint.

Cite this