Multitenant Data Protection Service Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information rights management systems rely on a single shared security root of trust, limiting scalability and requiring discrete systems at security boundaries, which is detrimental in multi-tenant scenarios like online services.
Innovation Solution
Implementing a data protection service that uses unique encryption keys for each tenant, allowing only specific keys to decrypt their data, thereby enabling multiple security roots of trust within a single system, allowing for segregation and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single shared security root of trust is used for all tenants, then system simplicity is maintained, but scalability is limited and discrete systems must be deployed at security boundaries
Solution Approach 1:
The patent segments the shared security root of trust into tenant-specific security roots. Each tenant is assigned a unique security root (e.g., unique encryption keys, certificates, or cryptographic parameters) that is independent from other tenants. This segmentation allows the system to scale to multiple tenants while maintaining security boundaries, as each tenant's data is protected by their own security root rather than a shared one.
Solution Approach 2:
The patent introduces a new dimension of tenancy identification into the security model. Instead of a flat shared security model, the system adds a tenant identifier dimension that maps to specific security roots. This dimensional change enables the system to differentiate between tenants and apply appropriate security policies, allowing scalability without compromising security or requiring discrete systems.
2Reliability
If discrete systems are deployed at security boundaries between organizations, then security isolation is achieved, but system scalability is detrimentally affected
Solution Approach 1:
The patent merges multiple tenant-specific security roots into a single unified data protection service. Instead of deploying separate discrete systems for each tenant or organization, the system combines them under one service infrastructure that dynamically applies the appropriate security root based on tenant identification. This merging achieves both security isolation (through unique security roots) and scalability (through a unified service).
Solution Approach 2:
The patent creates a universal data protection service that serves multiple tenants with different security requirements. The service is designed to be multi-functional, handling authentication, encryption, and data protection for various tenants using their respective security roots. This universal approach eliminates the need for discrete systems while maintaining security isolation and enabling scalability across multiple organizations.
3Ease of operation
If a common key is used to access data for all organizations, then system simplicity is maintained, but data security and tenant isolation are compromised
Solution Approach 1:
The patent applies local quality by assigning different security characteristics to different tenants. Instead of using a uniform common key for all organizations, each tenant receives a unique security root tailored to their specific security requirements. This local differentiation maintains data security and tenant isolation while the centralized management of these unique keys preserves system simplicity and ease of operation.
Data Source
AI summary
Implementing a data protection service. One method includes receiving a request to provision a first tenant among a plurality of tenants managed by a single data protection service. A tenant is defined as an entity among a plurality of entities. A single data protection service provides data protection services to all tenants in the plurality of tenants. A first encryption key used to decrypt the first tenant's data at the data store is stored. The first encryption key is specific to the first tenant and thus cannot be used to decrypt other tenants' data at the data store from among the plurality of tenants. Rather each tenant in the plurality of tenants is associated with an encryption key, not usable by other tenants, used at the data store to decrypt data on a tenant and corresponding key basis.


