Multitenant Flash Storage Encryption with Controller-Managed Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems face challenges in efficiently managing and securing data across multiple tenants in a shared storage environment, particularly in terms of data encryption and access control.
Innovation Solution
Implementing multitenant encryption in a managed flash storage device storage system, where encryption keys are managed by a storage system controller and applied at the tenant level, ensuring secure and efficient data storage and access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is stored in a shared storage environment without tenant-level encryption, then storage capacity and accessibility are improved, but data security and confidentiality deteriorate
Solution Approach 1:
The patent segments the shared storage system into multiple encrypted volumes, with each volume dedicated to a specific tenant and protected by a unique encryption key. This segmentation allows multiple tenants to share the same physical storage infrastructure while maintaining isolated security boundaries, thus improving both shared storage accessibility and data security simultaneously
2Object-affected harmful factors
If encryption is implemented at the tenant level with separate keys, then data security is improved, but system complexity and key management overhead increase
Solution Approach 1:
The patent merges the key management functions into a centralized storage system controller that automatically manages encryption keys for multiple tenants. This consolidation reduces key management overhead by providing unified key generation, storage, and rotation capabilities, while still maintaining tenant-level encryption isolation and data confidentiality
3Object-affected harmful factors
If multiple encryption keys are managed manually, then data security is improved, but operational efficiency and time consumption worsen
Solution Approach 1:
The patent implements self-service key management where the storage system controller automatically generates, stores, and manages encryption keys without requiring manual intervention. The system autonomously handles key rotation, renewal, and secure distribution to authorized components, significantly reducing the time and effort required for key management while maintaining robust data protection
Data Source
AI summary
Encrypted data is stored in flash memory of one or more storage devices for multiple tenants. The multiple tenants have corresponding encryption keys for encrypting and decrypting data stored for the multiple tenants. An input/output (I/O) request to access a portion of the encrypted data associated with a particular tenant is received by a storage system controller. The I/O request includes protection information for the portion of the encrypted data. A particular encryption key associated with the particular tenant is identified using the protection information. The requested I/O operation is performed using the particular encryption key.


