Multitenant Flash Storage Encryption with Controller-Managed Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage systems face challenges in efficiently managing and securing data across multiple tenants in a shared storage environment, particularly in terms of data encryption and access control.

Innovation Solution

Implementing multitenant encryption in a managed flash storage device storage system, where encryption keys are managed by a storage system controller and applied at the tenant level, ensuring secure and efficient data storage and access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in a shared storage environment without tenant-level encryption, then storage capacity and accessibility are improved, but data security and confidentiality deteriorate

Engineering Contradiction:
Improveshared storage accessibilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the shared storage system into multiple encrypted volumes, with each volume dedicated to a specific tenant and protected by a unique encryption key. This segmentation allows multiple tenants to share the same physical storage infrastructure while maintaining isolated security boundaries, thus improving both shared storage accessibility and data security simultaneously

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If encryption is implemented at the tenant level with separate keys, then data security is improved, but system complexity and key management overhead increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidencryption key management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the key management functions into a centralized storage system controller that automatically manages encryption keys for multiple tenants. This consolidation reduces key management overhead by providing unified key generation, storage, and rotation capabilities, while still maintaining tenant-level encryption isolation and data confidentiality

Inventive Principle:
Principle #5Merging (Combining)

3Object-affected harmful factors

If multiple encryption keys are managed manually, then data security is improved, but operational efficiency and time consumption worsen

Engineering Contradiction:
Improvedata protectionVSAvoidkey management time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements self-service key management where the storage system controller automatically generates, stores, and manages encryption keys without requiring manual intervention. The system autonomously handles key rotation, renewal, and secure distribution to authorized components, significantly reducing the time and effort required for key management while maintaining robust data protection

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250272009A1Providing multitenant encryption in a managed flash storage device storage system
Publication Date: 2025.08.28 PURE STORAGE INC
  • US20250272009A1 patent drawing
  • US20250272009A1 patent drawing
  • US20250272009A1 patent drawing

AI summary

Encrypted data is stored in flash memory of one or more storage devices for multiple tenants. The multiple tenants have corresponding encryption keys for encrypting and decrypting data stored for the multiple tenants. An input/output (I/O) request to access a portion of the encrypted data associated with a particular tenant is received by a storage system controller. The I/O request includes protection information for the portion of the encrypted data. A particular encryption key associated with the particular tenant is identified using the protection information. The requested I/O operation is performed using the particular encryption key.