Multi-Tenant Edge Secure Tunnels With Parent–Child Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant networks, existing methods for managing encryption keys are inefficient and insecure, particularly when large-scale tenants share resources, leading to potential security risks and scalability issues.
Innovation Solution
A method and system for managing encryption keys in multi-tenant edge devices that generate parent keys for inter-device communication and child keys per tenant interface, with the network provider managing parent keys and tenants managing child keys, reducing the number of keys required and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption key management methods are used in multi-tenant networks, then security can be maintained for each tenant, but the number of keys required increases significantly and management complexity increases
Solution Approach 1:
The patent segments encryption keys into two distinct types: parent keys managed by the network provider and child keys managed by individual tenants. This segmentation allows each entity to manage only the keys relevant to their responsibilities, reducing overall key management complexity while maintaining security. Parent keys are used for establishing secure tunnels, while child keys are used for tenant-specific encryption, enabling independent management of each key type.
Solution Approach 2:
The patent introduces parent keys as an intermediary mechanism between the network provider and tenants. Instead of the network provider directly managing all tenant-specific keys, parent keys serve as an intermediate layer that facilitates secure communication. The network provider manages parent keys for tunnel establishment, while tenants manage child keys for their own data encryption, with the parent-child key relationship enabling secure communication without requiring the network provider to manage every tenant's keys directly.
2Reliability
If separate encryption keys are generated for each tenant interface, then security is enhanced, but the number of keys required increases with the number of tunnels
Solution Approach 1:
The patent segments the key management structure into parent keys (managed by network provider) and child keys (managed by tenants). Each tenant interface uses a child key, but these child keys are derived from or associated with parent keys that are reused across multiple tenants. This segmentation reduces the total number of keys required compared to generating completely separate keys for each tenant interface, as parent keys can serve multiple child keys.
Solution Approach 2:
Parent keys are designed to be universal and can be reused across multiple tenants and interfaces. Instead of creating unique keys for every tenant interface combination, the same parent key can authenticate and encrypt multiple child keys belonging to different tenants. This multi-functionality of parent keys significantly reduces the total number of keys required in the system while maintaining security for each tenant interface.
3Adaptability or versatility
If the network provider manages all encryption keys, then centralized control is achieved, but scalability is limited and management overhead increases
Solution Approach 1:
The patent segments key management responsibilities between the network provider and tenants. The network provider retains control over parent keys, maintaining centralized authority for tunnel establishment and overall security policy. Tenants are empowered to manage their own child keys, enabling them to independently configure and secure their own interfaces without requiring network provider intervention for each key operation. This segmentation enables the system to scale to many tenants while maintaining centralized control over critical security functions.
Solution Approach 2:
Tenants are enabled to perform self-service key management for their child keys. They can generate, store, and manage their own child keys without requiring the network provider to create or distribute them individually. This self-service capability allows tenants to rapidly provision new interfaces and tenants without creating additional work for the network provider, significantly improving scalability while the network provider maintains centralized control through parent key management.
Data Source
AI summary
Disclosed are systems, apparatuses, methods, computer readable medium, and circuits for managing encryption keys in a multi-tenant network edge device. According to at least one example, a method includes: receiving tenant resource information at the multi-tenant network edge device; generating at least one parent encryption key; generating a plurality of child encryption keys; creating a routing connection to a network controller for each tenant in the plurality of tenants; transmitting the at least one parent encryption key and the plurality of child encryption keys to the network controller for distribution to the plurality of tenants; receiving a plurality of advertisements of transport locators from the network controller, wherein each advertisement includes a parent encryption key or a child encryption key; selecting a set of encryption keys from the plurality of advertisements; and forming a secure tunnel.


