11 रिपॉजिटरी
Automated generation and revocation of short-lived credentials on demand.
Distinguishing note: Focuses on the lifecycle management of temporary credentials, distinct from static secret storage.
Explore 11 awesome GitHub repositories matching security & cryptography · Dynamic Credential Provisioning. Refine with filters or upvote what's useful.
Vault is a centralized secrets management platform designed to secure, store, and control access to sensitive credentials such as API keys, passwords, certificates, and encryption keys. At its core, the system employs a barrier-based cryptographic sealing mechanism that requires an unseal process to decrypt internal storage, ensuring that sensitive data remains protected. It provides identity-based access control to manage granular permissions across distributed infrastructure, effectively centralizing security policies and authentication for both human and machine workloads. What distinguish
Generates short-lived, automatically rotated credentials to minimize the impact of potential security breaches.
Infisical is a centralized secrets management platform designed to store, synchronize, and control access to sensitive credentials and configuration data across distributed development, staging, and production environments. It employs client-side encryption to ensure that secrets remain unreadable to the underlying storage infrastructure, while providing a hierarchical permission model to govern both user and machine access. The platform distinguishes itself through dynamic credential provisioning, which generates short-lived access tokens that are automatically revoked after use. It supports
Generates short-lived credentials on demand through cloud providers and automatically revokes them after use.
Pulumi is an infrastructure-as-code framework that enables the definition, deployment, and management of cloud resources using general-purpose programming languages. It functions as a cloud resource orchestrator that coordinates the lifecycle of heterogeneous infrastructure by executing code to construct dependency graphs and reconciling the desired state against actual cloud environments. The platform distinguishes itself through a language-host runtime bridge that allows developers to use standard programming languages to define infrastructure, rather than relying solely on domain-specific
Issues short-lived, just-in-time credentials via OIDC that automatically expire to eliminate risks associated with static access keys.
Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n
Exchanges long-lived tokens for unique host identifiers and secrets during initial connection to eliminate manual pre-configuration.
This project is an open-source software development kit and framework for implementing the Matter smart home standard. It provides a universal IPv6-based application layer and a cluster-based data model to ensure interoperability between diverse smart home devices and controllers. The system is distinguished by its multi-transport network abstraction, which maps Bluetooth LE, Thread, and Wi-Fi implementations to a common layer. It includes specialized tooling for secure device commissioning via QR codes and NFC, as well as a comprehensive over-the-air firmware update system for distributing s
Sends Thread or Wi-Fi credentials from a controller to a device to enable local network joining.
WiFiManager is a captive portal and web server framework used for configuring wireless credentials and network settings on ESP8266 microcontrollers. It provides an embedded network configuration interface that allows users to connect devices to a wireless network via a web browser rather than hardcoding credentials. The system functions by temporarily acting as a wireless host and redirecting incoming web requests to a local configuration page. It distinguishes itself through a customizable portal that supports user-defined input parameters, visual themes, and multi-language localization to c
Connecting an ESP8266 device to a wireless network by entering credentials through a web browser instead of hardcoding them.
AliOS-Things इंटरनेट से जुड़े उपकरणों के लिए एक स्केलेबल ऑपरेटिंग सिस्टम है। यह हार्डवेयर पेरिफेरल्स, नेटवर्क कनेक्टिविटी, और विविध CPU आर्किटेक्चर में सुरक्षित डेटा निष्पादन के प्रबंधन के लिए एक एम्बेडेड फर्मवेयर फ्रेमवर्क और रनटाइम प्रदान करता है। इस सिस्टम में क्लाउड निर्भरता के बिना ऑडियो और इमेज पैटर्न को स्थानीय रूप से संसाधित करने के लिए एक एज AI इन्फरेंस इंजन शामिल है। इसमें स्वचालित ऑनबोर्डिंग, रिमोट डायग्नोस्टिक्स, और लॉग रिपोर्टिंग के लिए क्लाउड कनेक्टिविटी SDK, साथ ही संसाधन-सीमित हार्डवेयर पर हाई-लेवल कोड निष्पादित करने के लिए एक स्क्रिप्टिंग इंजन भी है। कनेक्टिविटी को TCP/IP, BLE, और LoRaWAN प्रोटोकॉल का समर्थन करने वाले एक हल्के नेटवर्किंग स्टैक के माध्यम से संभाला जाता है। यह फ्रेमवर्क मॉड्यूलर फर्मवेयर संरचना और डेटा ट्रांसफर को कम करने के लिए डिफरेंशियल इमेजेस का उपयोग करके सुरक्षित ओवर-द-एयर अपडेट का समर्थन करता है। हार्डवेयर एकीकरण को बोर्ड सपोर्ट पैकेजेस और डिवाइस नोड्स व फ़ाइलों के लिए एक वर्चुअल फ़ाइल सिस्टम एब्स्ट्रैक्शन के माध्यम से प्रबंधित किया जाता है। डेटा सुरक्षा को निष्पादन वातावरण की सुरक्षा के लिए एन्क्रिप्शन और विश्वसनीय स्टोरेज के माध्यम से लागू किया जाता है। सिस्टम में हार्डवेयर-स्तरीय यूज़र इंटरफेस इंटरैक्शन को सक्षम करने के लिए स्क्रीन और कैमरों के लिए ड्राइवर्स भी शामिल हैं।
Handles network configuration and provisioning, including Bluetooth-based setup for internet connectivity.
This project is an IoT cloud integration SDK and C++ library designed to connect ESP32 hardware to a remote management service. It provides a communication bridge that enables real-time, bidirectional data exchange between embedded devices and remote clients. The library utilizes a cloud-relay communication model and key-based device authentication to secure the connection between hardware and the cloud. It includes a dedicated provisioning tool for securely transferring wireless network credentials to devices during initial setup. The framework integrates directly with the ESP-IDF developme
Implements a secure handshake process to transfer wireless network credentials to the device during setup.
Blynk एक एम्बेडेड डिवाइस फ़्रेमवर्क और IoT क्लाउड कनेक्टिविटी लाइब्रेरी है जिसे माइक्रोकंट्रोलर और रिमोट प्रबंधन प्लेटफ़ॉर्म के बीच सुरक्षित, द्वि-दिशात्मक संचार स्थापित करने के लिए डिज़ाइन किया गया है। यह एक IoT डिवाइस प्रबंधन टूल की मुख्य पहचान प्रदान करता है, जो डिवाइस स्थितियों के सिंक्रोनाइज़ेशन, रिमोट हार्डवेयर नियंत्रण, और क्लाउड-आधारित इंटरफ़ेस के लिए हार्डवेयर डेटा की मैपिंग को सक्षम बनाता है। प्रोजेक्ट एक वर्चुअल-पिन सिस्टम के माध्यम से खुद को अलग करती है जो क्लाउड संचार को भौतिक पिन से डीकूपल करता है, जिससे हार्डवेयर-स्वतंत्र डेटा विनिमय की अनुमति मिलती है। यह उन्नत आर्किटेक्चरल ऑफ़लोडिंग का भी समर्थन करती है, जहां नेटवर्क संचार को गैर-कनेक्टेड माइक्रोकंट्रोलर का समर्थन करने के लिए एक समर्पित को-प्रोसेसर को सौंपा जा सकता है। लाइब्रेरी स्वचालित डिवाइस प्रोविज़निंग, ओवर-द-एयर फ़र्मवेयर अपडेट, और फ़्लीट प्रबंधन के लिए एक मल्टी-टेनेंट संगठनात्मक संरचना सहित क्षमताओं की एक विस्तृत श्रृंखला को कवर करती है। यह MQTT और HTTPS जैसे विभिन्न संचार प्रोटोकॉल को एकीकृत करती है, और लॉजिक-आधारित स्वचालन, टाइम-सीरीज़ डेटा स्टोरेज, और रीयल-टाइम निगरानी के लिए मोबाइल और वेब डैशबोर्ड के निर्माण के लिए टूल प्रदान करती है। प्रोजेक्ट C++ में कार्यान्वित है।
Enables secure transfer of WiFi credentials and device identifiers from a mobile app to hardware.
This project is a reference library of firmware examples and a development framework for creating embedded C applications on the RP2040 microcontroller. It provides a collection of hardware peripheral drivers and foundational patterns for managing system resources in resource-constrained environments. The library features reference implementations for programmable I/O state machines, allowing for the creation of custom hardware-level protocols. It also provides a multicore embedded framework to distribute computational workloads across multiple processor cores using symmetric processing. The
Provides a mechanism to collect and save Wi-Fi credentials using a temporary access point and web page.
यह प्रोजेक्ट एक Kubernetes कंट्रोलर है जो HashiCorp Vault से कंटेनरीकृत वर्कलोड में सीक्रेट्स को पुनः प्राप्त करने और इंजेक्ट करने को स्वचालित करता है। एक कंट्रोल लूप के रूप में कार्य करते हुए, यह संवेदनशील कॉन्फ़िगरेशन डेटा और प्रमाणीकरण टोकन को सीधे एप्लिकेशन वातावरण में वितरित करने के लिए क्लस्टर स्थिति की निगरानी करता है, जिससे स्टेटिक क्रेडेंशियल्स की आवश्यकता समाप्त हो जाती है। यह सिस्टम साइडकार-आधारित इंजेक्शन तंत्र के माध्यम से खुद को अलग बनाता है जो रनटाइम पर सीक्रेट्स को माउंट करने के लिए पॉड लाइफसाइकिल इवेंट्स को इंटरसेप्ट करता है। यह डायनामिक क्रेडेंशियल प्रोविज़निंग का समर्थन करता है, जो दीर्घकालिक एक्सेस कुंजियों से जुड़े सुरक्षा जोखिमों को कम करने के लिए मांग पर अल्पकालिक टोकन उत्पन्न करता है। परिचालन विश्वसनीयता सुनिश्चित करने के लिए, कंट्रोलर सर्वसम्मति-आधारित स्टेट रेप्लिकेशन और स्वचालित पीयर डिस्कवरी का उपयोग करके कई इंस्टेंस में उच्च उपलब्धता बनाए रखता है। प्लेटफ़ॉर्म में व्यापक सुरक्षा और अवलोकन सुविधाएँ शामिल हैं, जैसे आंतरिक संचार के लिए म्यूचुअल TLS प्रमाणीकरण और एन्क्रिप्टेड ट्रैफ़िक प्रबंधन। यह बाहरी विश्लेषण टूल के साथ संगत प्रमाणित एंडपॉइंट्स के माध्यम से परिचालन प्रदर्शन डेटा को उजागर करके निगरानी के लिए इन-बिल्ट समर्थन भी प्रदान करता है।
Generates short-lived authentication tokens on demand to replace static credentials and reduce long-term access risks.