Multi-Tenant Edge Secure Tunnels With Parent–Child Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant networks, existing methods for managing encryption keys are inefficient and insecure, particularly when large-scale tenants share resources, leading to potential security risks and scalability issues.

Innovation Solution

A method and system for managing encryption keys in multi-tenant edge devices that generate parent keys for inter-device communication and child keys per tenant interface, with the network provider managing parent keys and tenants managing child keys, reducing the number of keys required and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption key management methods are used in multi-tenant networks, then security can be maintained for each tenant, but the number of keys required increases significantly and management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments encryption keys into two distinct types: parent keys managed by the network provider and child keys managed by individual tenants. This segmentation allows each entity to manage only the keys relevant to their responsibilities, reducing overall key management complexity while maintaining security. Parent keys are used for establishing secure tunnels, while child keys are used for tenant-specific encryption, enabling independent management of each key type.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces parent keys as an intermediary mechanism between the network provider and tenants. Instead of the network provider directly managing all tenant-specific keys, parent keys serve as an intermediate layer that facilitates secure communication. The network provider manages parent keys for tunnel establishment, while tenants manage child keys for their own data encryption, with the parent-child key relationship enabling secure communication without requiring the network provider to manage every tenant's keys directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate encryption keys are generated for each tenant interface, then security is enhanced, but the number of keys required increases with the number of tunnels

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of encryption keys
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the key management structure into parent keys (managed by network provider) and child keys (managed by tenants). Each tenant interface uses a child key, but these child keys are derived from or associated with parent keys that are reused across multiple tenants. This segmentation reduces the total number of keys required compared to generating completely separate keys for each tenant interface, as parent keys can serve multiple child keys.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Parent keys are designed to be universal and can be reused across multiple tenants and interfaces. Instead of creating unique keys for every tenant interface combination, the same parent key can authenticate and encrypt multiple child keys belonging to different tenants. This multi-functionality of parent keys significantly reduces the total number of keys required in the system while maintaining security for each tenant interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the network provider manages all encryption keys, then centralized control is achieved, but scalability is limited and management overhead increases

Engineering Contradiction:
Improvecentralized controlVSAvoidscalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments key management responsibilities between the network provider and tenants. The network provider retains control over parent keys, maintaining centralized authority for tunnel establishment and overall security policy. Tenants are empowered to manage their own child keys, enabling them to independently configure and secure their own interfaces without requiring network provider intervention for each key operation. This segmentation enables the system to scale to many tenants while maintaining centralized control over critical security functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Tenants are enabled to perform self-service key management for their child keys. They can generate, store, and manage their own child keys without requiring the network provider to create or distribute them individually. This self-service capability allows tenants to rapidly provision new interfaces and tenants without creating additional work for the network provider, significantly improving scalability while the network provider maintains centralized control through parent key management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12438698B2Managing encryption keys of secure tunnels in multi-tenant edge devices
Publication Date: 2025.10.07 CISCO TECHNOLOGY INC
  • US12438698B2 patent drawing
  • US12438698B2 patent drawing
  • US12438698B2 patent drawing

AI summary

Disclosed are systems, apparatuses, methods, computer readable medium, and circuits for managing encryption keys in a multi-tenant network edge device. According to at least one example, a method includes: receiving tenant resource information at the multi-tenant network edge device; generating at least one parent encryption key; generating a plurality of child encryption keys; creating a routing connection to a network controller for each tenant in the plurality of tenants; transmitting the at least one parent encryption key and the plurality of child encryption keys to the network controller for distribution to the plurality of tenants; receiving a plurality of advertisements of transport locators from the network controller, wherein each advertisement includes a parent encryption key or a child encryption key; selecting a set of encryption keys from the plurality of advertisements; and forming a secure tunnel.