Hardware Security Processor for Multi-Tenant Cloud Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, tenants lack trust in the security of their sensitive information due to the lack of control over access and execution of their data, as existing systems do not effectively prevent unauthorized access or execution by other tenants or users.
Innovation Solution
A security processor residing within the hardware layer of the network information system, which requires a security code from the tenant for the CPU to execute objects, ensuring that only authorized processing occurs based on a tenant-provided security map, thereby involving the tenant in the security process and maintaining trust.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multi-tenant architecture is used to share software, infrastructure, or platform across multiple clients, then service efficiency and resource utilization are improved, but tenant trust and security control deteriorate due to lack of control over access and execution of sensitive information
Solution Approach 1:
The system segments security control into two distinct layers: (1) infrastructure-level shared resources maintained by the service provider, and (2) tenant-level security maps and credential verification implemented by the tenant. This segmentation allows multi-tenant resource sharing while giving tenants direct control over their security policies and access credentials, thereby maintaining both service efficiency and tenant trust.
Solution Approach 2:
The patent introduces an intermediary security verification mechanism where the service provider's infrastructure acts as a mediator that enforces tenant-defined security maps. The infrastructure layer mediates between multiple tenants by verifying credentials against tenant-provided security maps, enabling secure resource sharing without requiring tenants to directly manage physical infrastructure, thus maintaining both efficiency and security control.
2Ease of operation
If centralized security control is implemented by the service provider, then system management is simplified, but tenant control and authorization over their own data deteriorate
Solution Approach 1:
Security control is segmented into management functions (handled by the service provider for simplicity) and authorization functions (handled by tenants for control). The service provider manages the infrastructure and security map storage, while tenants define their own security maps and credentials, allowing each party to operate within their expertise domain.
Solution Approach 2:
Tenants are empowered to self-define their security maps, set their own credentials, and control their data access policies without requiring service provider intervention. The system automatically enforces these tenant-defined policies through the infrastructure layer, enabling tenants to maintain full control over their data while the service provider focuses on infrastructure management.
3Ease of manufacture
If security verification is performed at higher software layers, then implementation is simpler, but security against unauthorized execution at hardware layer deteriorates
Solution Approach 1:
The patent extends security verification from the traditional software layer down into the hardware layer by integrating security map storage and credential verification directly into the processing unit. This dimensional extension ensures that security checks occur at the point of execution, preventing unauthorized access before it can affect the system, while the overall architecture remains manageable through automated enforcement.
Solution Approach 2:
The processing unit acts as an intermediary that bridges the software security policies (tenant-defined security maps) and hardware execution. It verifies credentials against the security map stored in its memory before allowing execution of code or access to data, ensuring that security enforcement occurs at the critical hardware-software boundary without requiring complex manual configuration.
4Device complexity
If security maps and credentials are stored externally, then security processor functionality is simplified, but access control speed and efficiency deteriorate
Solution Approach 1:
The security map is nested directly within the processing unit's memory space, creating a hierarchical structure where the security processor can access credentials immediately without external communication overhead. This nesting of the security map within the hardware layer eliminates access delays while keeping the security processor's external interface simple.
Solution Approach 2:
The patent merges the security map storage function with the processing unit's memory subsystem, combining data storage and security verification functions into a single integrated component. This merging eliminates the need for separate external storage and access mechanisms, thereby improving access control speed without significantly increasing the security processor's functional complexity.
Data Source
AI summary
Systems and methods for providing information security in a network environment are disclosed. The method includes initiating processing, invoked by a user, of at least one of a plurality of objects in a processing unit of a hardware layer, wherein the plurality of objects is hosted for a tenant. The method further includes determining that the processing of the at least one of the plurality of objects by the processing unit is authorized by the tenant based on a security map provided by the tenant and accessible by the processing unit within the hardware layer. The method further includes allowing the processing of the object based on a result of the determining.


