Multi-tenant Cloud Encryption via Key Fragmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based information processing systems face security threats as tenants rely on shared infrastructure, leading to concerns about data protection from both competing tenants and cloud service providers, limiting the adoption of cloud services.
Innovation Solution
Implementing a security protocol that uses a combination of tenant-specific and private keys, where the private key is hidden within applications running on virtual machines, ensuring encryption of processing job results with both keys, thus protecting data from unauthorized access by other tenants and the cloud service provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud service providers use shared physical hardware resources for multiple tenants, then resource utilization and cost efficiency are improved, but security risks and trust issues increase
Solution Approach 1:
The patent segments the encryption key into multiple fragments and distributes them across different tenants and the cloud service provider. No single entity possesses the complete key, thereby enabling shared resource usage while preventing any one party from accessing all data independently.
Solution Approach 2:
The patent introduces an intermediary key fragmentation mechanism that mediates between the need for shared resources and security requirements. The key fragments act as intermediaries that collectively enable decryption only when properly combined, preventing direct access to plaintext data by any single party.
2Ease of operation
If cloud service providers assume trust in their personnel and infrastructure, then operational simplicity is improved, but security against insider threats deteriorates
Solution Approach 1:
The encryption key is segmented into multiple fragments held by different parties including tenants and the cloud service provider. This segmentation ensures that even if cloud personnel are compromised, they cannot access the complete key or decrypt data without the tenant-held key fragments.
Solution Approach 2:
The system preemptively addresses insider threats by designing an architecture where no single party, including cloud service providers, has unilateral access to decrypted data. The key fragmentation mechanism预先 prevents potential misuse of trusted positions.
3Object-affected harmful factors
If tenants encrypt files before uploading to cloud storage, then data confidentiality is improved, but verification complexity and resource requirements increase
Solution Approach 1:
The patent extracts the verification burden from the tenant and relocates it to the cloud service provider. The provider must demonstrate possession of key fragments and prove encryption capabilities without requiring tenants to perform complex verification operations.
Solution Approach 2:
The system implements a feedback mechanism where the cloud service provider provides cryptographic proofs to tenants verifying that data is properly encrypted. This feedback loop enables tenants to confirm security without directly performing complex verification computations.
4Speed
If cloud service providers store files in unencrypted form for efficient processing, then processing speed is improved, but data security deteriorates
Solution Approach 1:
The patent enables processing of encrypted data by segmenting the decryption operation into key fragment combinations that occur only when needed. Data remains encrypted during storage and can be processed in encrypted form or decrypted temporarily with proper key fragment authorization.
Solution Approach 2:
The system changes the encryption parameter state dynamically - data remains in encrypted state during storage and can transition to decrypted state only when processing is required and proper authorization is obtained through key fragment combination.
Data Source
AI summary
Cloud infrastructure of an information processing system comprises one or more processing devices implementing a plurality of virtual machines. The cloud infrastructure is configured to receive a processing job from a tenant, to obtain a first key specific to the tenant, to determine a second key utilizing information supplied by the tenant, and to encrypt one or more results of the processing job utilizing a combination of the first key and the second key. At least a portion of the second key is determined by at least one application that is run on at least one virtual machine of the cloud infrastructure in conjunction with performance of the processing job. The encrypted results of the processing job may be stored in a virtual memory of the cloud infrastructure and transmitted to the tenant.


