Hybrid Key Derivation for Multi-Tenant Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for securing customer data in multi-tenant database environments face challenges such as performance issues with asymmetric key cryptography, security risks due to persistence of private keys on application servers, and vulnerability to quantum computing attacks, particularly when using RSA encryption and key wrapping.

Innovation Solution

A method that involves an application server storing a key identifier associated with a private key, requesting a symmetric key from a security server using a public key and salt value, and using the derived symmetric key for encryption and decryption, while ensuring the private key remains inaccessible to the application server, thereby enhancing security and reducing computational overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric key cryptography is used to encrypt data, then security is improved, but encryption speed deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidencryption speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The encryption process is segmented into two parts: asymmetric key cryptography is used only for encrypting the symmetric key (key wrapping), while the actual data encryption is performed using symmetric key cryptography. This division allows the system to benefit from the security of asymmetric encryption without suffering from its slow speed when encrypting large amounts of data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A symmetric key acts as an intermediary between the asymmetric key pair and the data. The public key encrypts the symmetric key, and then the symmetric key encrypts the data. This intermediary approach combines the advantages of both cryptographic methods while avoiding their individual disadvantages.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If private keys are persisted on application servers, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improvekey accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The private key is extracted from the application server environment and stored exclusively in the security server's HSM. The application server receives only the public key and encrypted data, eliminating the security risk of private key persistence on application servers while maintaining operational capability through the public key interface.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The HSM acts as an intermediary that holds the private key securely. Instead of the application server directly accessing or storing the private key, all private key operations are performed within the HSM, which mediates between the application server's encryption needs and the private key's secure storage requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If RSA encryption with key wrapping is used, then security is improved, but vulnerability to quantum computing attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidquantum computing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system changes the cryptographic parameters by implementing a hybrid encryption scheme that combines asymmetric and symmetric cryptography with proper key management. This parameter change in the cryptographic approach provides quantum-resistant security while maintaining current security standards.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The HSM serves as a quantum-resistant intermediary that manages asymmetric key pairs and performs key wrapping operations. By offloading these operations to the HSM and using it as an intermediary layer, the system achieves quantum-resistant security without compromising operational efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Speed

If symmetric key is derived and stored in in-memory cache, then encryption speed is improved, but memory usage increases

Engineering Contradiction:
Improveencryption speedVSAvoidmemory usage
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The symmetric key is derived periodically on-demand when needed for encryption operations and stored temporarily in in-memory cache. The key is not persistently stored but available in memory during active use, providing fast encryption speeds while limiting memory usage to only when the key is actively required.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system derives the symmetric key itself when needed rather than relying on external key distribution. The application server requests key derivation from the security server, stores it temporarily in its own in-memory cache, and uses it for encryption, making the system self-sufficient while optimizing memory utilization.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11522686B2Securing data using key agreement
Publication Date: 2022.12.06 SALESFORCE INC
  • US11522686B2 patent drawing
  • US11522686B2 patent drawing
  • US11522686B2 patent drawing

AI summary

Methods and systems for securing customer data in a multi-tenant database environment are described. A key identifier received from a security server may be stored by an application server. The key identifier may be associated with a private key that is accessible by the security server and not accessible by the application server. A request to derive a symmetric key may be transmitted from the application server to the security server, the request including a public key generated by the application server, a salt value, and the key identifier. The symmetric key may then be derived based on the transmitted public key and the private key using a key derivation function. The application server may then receive and store the symmetric key in an in-memory cache, and be used to securely encrypt data received by the application server from client devices.