System Control Processor Key Management for Multi-Tenant TEE Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face inefficiencies in allocating and managing computing resources for multi-tenant environments, leading to potential data breaches and suboptimal service quality due to inadequate resource separation and management.

Innovation Solution

Implementing a system control processor manager that utilizes a three-resource set model to dynamically allocate and manage computing resources, including a control resource set, compute resource set, and hardware resource set, with a trusted execution environment (TEE) for secure data storage and identity verification, ensuring resource allocation matches service demands and maintaining tenant isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If computing resources are shared across multi-tenant environments, then resource utilization efficiency improves, but security risks and data breach potential increase due to inadequate resource separation

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system divides computing resources into distinct sets (control resource set, compute resource set, hardware resource set) and assigns them to different tenants through logically composed systems. Each tenant receives isolated control resources while sharing compute and hardware resources, enabling efficient resource utilization without compromising security through proper segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system control processor acts as an intermediary between tenants and shared computing resources. It manages resource allocation, enforces isolation policies, and mediates access to shared hardware and compute resources, allowing multiple tenants to share resources securely through a centralized control mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If resource allocation is dynamic and flexible to match service demands, then service quality improves, but system complexity increases

Engineering Contradiction:
Improveservice qualityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system enables dynamic resource allocation where compute and hardware resources can be reassigned between tenants based on service demands. The system control processor monitors resource usage patterns and dynamically adjusts allocations to match actual service needs, improving service quality through adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The control resource set serves multiple functions: it manages resource allocation, enforces security policies, tracks usage patterns, and coordinates access to shared hardware and compute resources across multiple tenants. This multi-functionality reduces overall system complexity by consolidating management tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If strict tenant isolation is implemented, then data security improves, but resource sharing efficiency decreases

Engineering Contradiction:
Improvetenant isolationVSAvoidresource sharing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments control resources by tenant while allowing shared access to compute and hardware resources. Each tenant has dedicated control resources for isolation and security management, while compute and hardware resources are pooled and shared efficiently across multiple tenants through the system control processor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different types of resources have different isolation characteristics. Control resources maintain strict local isolation for security, while compute and hardware resources implement shared access with controlled isolation. This differentiated approach allows efficient resource sharing without compromising the security isolation that is most critical for data protection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12567951B2Using secured key management with system control processors for multi-tenancy and backend secured storage devices
Publication Date: 2026.03.03 DELL PROD LP
  • US12567951B2 patent drawing
  • US12567951B2 patent drawing
  • US12567951B2 patent drawing

AI summary

A system control processor manager is programmed to obtain a configuration request for a trusted execution environment (TEE) associated with a tenant. In response to receiving the configuration request, the system control processor manager may generate the TEE associated with the tenant, communicate with a key management system (KMS) to obtain a set of keys associated with the tenant, store the set of keys in the TEE, and configure a set of secured storage devices associated with the tenant with the set of keys. The system control processor may service multiple configuration requests associated with multiple tenants.