THE IMPLEMENTATION OF A METHOD FOR WORKING WITH SENSITIVE DATA USED BY VARIOUS SERVICES AND SYSTEMS

U. Dzelendzyak, N. Mashtaler
{"title":"THE IMPLEMENTATION OF A METHOD FOR WORKING WITH SENSITIVE DATA USED BY VARIOUS SERVICES AND SYSTEMS","authors":"U. Dzelendzyak, N. Mashtaler","doi":"10.23939/istcmtm2022.04.056","DOIUrl":null,"url":null,"abstract":"The article describes the method of working with sensitive data used by various services and systems, including CRM/ERM systems, as well as the implementation of storing this data using the classic .NET FRAMEWORK. The main driver of this initiative is a missing centralized repository for connection strings to various systems like databases, CRM/ERM systems (for example. Netsuite or Salesforce), system variables, other sensitive info (for example tokens), and third-party components. The problem here is that each application has stored these connection strings in its configuration (usually in the web. config). It means one connection string is multiplied in many places and if there is a change in credentials, for example, the change must be done in all these application configurations. Finally, it would be better to have any registry of which connection string is used where. This is adding complexity for global updates, and it also doesn't help with security (since credentials to production systems are in the configuration and thus in source control, where they are visible to anybody).","PeriodicalId":415989,"journal":{"name":"Measuring Equipment and Metrology","volume":"53 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Measuring Equipment and Metrology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23939/istcmtm2022.04.056","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The article describes the method of working with sensitive data used by various services and systems, including CRM/ERM systems, as well as the implementation of storing this data using the classic .NET FRAMEWORK. The main driver of this initiative is a missing centralized repository for connection strings to various systems like databases, CRM/ERM systems (for example. Netsuite or Salesforce), system variables, other sensitive info (for example tokens), and third-party components. The problem here is that each application has stored these connection strings in its configuration (usually in the web. config). It means one connection string is multiplied in many places and if there is a change in credentials, for example, the change must be done in all these application configurations. Finally, it would be better to have any registry of which connection string is used where. This is adding complexity for global updates, and it also doesn't help with security (since credentials to production systems are in the configuration and thus in source control, where they are visible to anybody).
用于处理各种服务和系统使用的敏感数据的方法的实现
本文描述了处理各种服务和系统(包括CRM/ERM系统)使用的敏感数据的方法,以及使用经典的。net框架存储这些数据的实现。该计划的主要驱动因素是缺少用于将字符串连接到各种系统(例如数据库、CRM/ERM系统)的集中存储库。Netsuite或Salesforce)、系统变量、其他敏感信息(例如令牌)和第三方组件。这里的问题是,每个应用程序都将这些连接字符串存储在其配置中(通常在web中)。配置)。这意味着一个连接字符串在许多地方被复制,例如,如果凭据发生了更改,则必须在所有这些应用程序配置中进行更改。最后,最好有任何连接字符串在哪里使用的注册表。这增加了全局更新的复杂性,而且对安全性也没有帮助(因为生产系统的凭证位于配置中,因此在源代码控制中,任何人都可以看到它们)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信