On-Demand Secure User Domains with Per-Tenant Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern datacenters face vulnerabilities in high-speed data exchange due to malicious attacks, particularly when data is unencrypted, with challenges in efficient encryption and key management across shared resources and server boundaries, and network-level security approaches introducing additional risks.
Innovation Solution
Implementing an encryption orchestrator that orchestrates on-demand, per-tenant resource enclaves using a secure secret key distribution scheme, leveraging out-of-band key exchange and datalink layer encryption to secure data transfers across servers, with a Root of Trust (RoT) for isolated key management and encryption at the SERDES level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If data is transmitted unencrypted for high-speed data exchange, then data transmission speed is improved, but security against malicious attacks deteriorates
Solution Approach 1:
The patent segments encryption management by creating per-tenant resource enclaves with isolated key management. Each tenant gets a dedicated confidentiality enclave on shared computing resources, preventing cross-tenant key exposure while maintaining high-speed encrypted data exchange within each enclave.
Solution Approach 2:
The patent introduces an encryption orchestrator as an intermediary that manages key distribution and enclave formation. The orchestrator coordinates between tenants and computing resources, enabling secure encrypted communication without requiring tenants to directly manage complex key exchange protocols.
2Reliability
If encryption is implemented across shared resources, then security is improved, but key management complexity deteriorates
Solution Approach 1:
The patent divides the key management system into separate confidentiality enclaves for each tenant. Each enclave maintains isolated encryption keys specific to that tenant, eliminating the need for a single complex key management system that would need to secure multiple tenants' data simultaneously.
Solution Approach 2:
Each tenant's confidentiality enclave autonomously manages its own encryption keys and security parameters. The enclave self-configures secure communication channels and key exchange protocols, reducing the burden on external key management infrastructure.
3Reliability
If network-level security approaches are used, then security coverage is improved, but additional security risks are introduced
Solution Approach 1:
The patent moves security from the network dimension to the data link dimension by implementing encryption at the SERDES level. This dimensional shift allows security to be enforced at a lower protocol layer, protecting data before it enters the network stack and preventing network-level attacks from compromising security.
Solution Approach 2:
The patent extracts key management and encryption functions from the network layer and places them in dedicated confidentiality enclaves at the data link layer. This extraction removes vulnerable network-level security components while maintaining comprehensive security coverage through enclave-based protection.
4Adaptability or versatility
If encryption keys are exposed to software for processing, then encryption flexibility is improved, but vulnerability to software attacks deteriorates
Solution Approach 1:
The patent extracts encryption key management from the software domain and places it in hardware-based confidentiality enclaves. The enclaves provide isolated secure environments that protect keys from software attacks while maintaining encryption flexibility through programmable enclave configurations.
Solution Approach 2:
The confidentiality enclave acts as an intermediary between software applications and encryption operations. Software can request encryption services from the enclave without directly accessing keys, maintaining flexibility through API interfaces while protecting keys from software vulnerabilities.
Data Source
AI summary
Systems, data processing systems, and methods, among other things, are disclosed. An illustrative system includes an encryption orchestrator that analyzes a packet, obtains a tenant identifier (ID) from the packet, determines whether a tenant associated with the tenant ID currently has sufficient encryption credit available, and enables an encryption resource to process the packet using an encryption key associated with the tenant ID in response to determining that the tenant associated with the tenant ID currently has sufficient encryption credit available.


