Hybrid Key Derivation for Multi-Tenant Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for securing customer data in multi-tenant database environments face challenges such as performance issues with asymmetric key cryptography, security risks due to persistence of private keys on application servers, and vulnerability to quantum computing attacks, particularly when using RSA encryption and key wrapping.
Innovation Solution
A method that involves an application server storing a key identifier associated with a private key, requesting a symmetric key from a security server using a public key and salt value, and using the derived symmetric key for encryption and decryption, while ensuring the private key remains inaccessible to the application server, thereby enhancing security and reducing computational overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If asymmetric key cryptography is used to encrypt data, then security is improved, but encryption speed deteriorates
Solution Approach 1:
The encryption process is segmented into two parts: asymmetric key cryptography is used only for encrypting the symmetric key (key wrapping), while the actual data encryption is performed using symmetric key cryptography. This division allows the system to benefit from the security of asymmetric encryption without suffering from its slow speed when encrypting large amounts of data.
Solution Approach 2:
A symmetric key acts as an intermediary between the asymmetric key pair and the data. The public key encrypts the symmetric key, and then the symmetric key encrypts the data. This intermediary approach combines the advantages of both cryptographic methods while avoiding their individual disadvantages.
2Ease of operation
If private keys are persisted on application servers, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The private key is extracted from the application server environment and stored exclusively in the security server's HSM. The application server receives only the public key and encrypted data, eliminating the security risk of private key persistence on application servers while maintaining operational capability through the public key interface.
Solution Approach 2:
The HSM acts as an intermediary that holds the private key securely. Instead of the application server directly accessing or storing the private key, all private key operations are performed within the HSM, which mediates between the application server's encryption needs and the private key's secure storage requirements.
3Reliability
If RSA encryption with key wrapping is used, then security is improved, but vulnerability to quantum computing attacks increases
Solution Approach 1:
The system changes the cryptographic parameters by implementing a hybrid encryption scheme that combines asymmetric and symmetric cryptography with proper key management. This parameter change in the cryptographic approach provides quantum-resistant security while maintaining current security standards.
Solution Approach 2:
The HSM serves as a quantum-resistant intermediary that manages asymmetric key pairs and performs key wrapping operations. By offloading these operations to the HSM and using it as an intermediary layer, the system achieves quantum-resistant security without compromising operational efficiency.
4Speed
If symmetric key is derived and stored in in-memory cache, then encryption speed is improved, but memory usage increases
Solution Approach 1:
The symmetric key is derived periodically on-demand when needed for encryption operations and stored temporarily in in-memory cache. The key is not persistently stored but available in memory during active use, providing fast encryption speeds while limiting memory usage to only when the key is actively required.
Solution Approach 2:
The system derives the symmetric key itself when needed rather than relying on external key distribution. The application server requests key derivation from the security server, stores it temporarily in its own in-memory cache, and uses it for encryption, making the system self-sufficient while optimizing memory utilization.
Data Source
AI summary
Methods and systems for securing customer data in a multi-tenant database environment are described. A key identifier received from a security server may be stored by an application server. The key identifier may be associated with a private key that is accessible by the security server and not accessible by the application server. A request to derive a symmetric key may be transmitted from the application server to the security server, the request including a public key generated by the application server, a salt value, and the key identifier. The symmetric key may then be derived based on the transmitted public key and the private key using a key derivation function. The application server may then receive and store the symmetric key in an in-memory cache, and be used to securely encrypt data received by the application server from client devices.


