Quantum Secure Multi-Tenant Telemetry via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-tenant environments face challenges in ensuring data confidentiality, securing telemetry data against quantum threats, and managing access effectively, leading to potential breaches and unauthorized access.

Innovation Solution

A system comprising a network device, collector, and server that uses key identifiers for encryption and policy tokens to control access, ensuring quantum secure data transmission and enforcement of access policies across multiple tenants, leveraging a distributed ledger for secure storage and retrieval of policy tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If shared telemetry services are implemented in a conventional multi-tenant environment, then cost is reduced, but data confidentiality cannot be ensured across all tenants

Engineering Contradiction:
ImprovecostVSAvoiddata confidentiality
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent segments the shared telemetry service into multiple independent tenants, each with their own encrypted data spaces. Each tenant's data is encrypted with tenant-specific keys, allowing shared infrastructure while maintaining isolated confidential data spaces for each tenant.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encryption keys and policy tokens as intermediaries between the shared telemetry service and tenant data. These intermediaries enable the service to handle multiple tenants' data confidentially by controlling access through cryptographic mechanisms rather than requiring separate service instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If independent per-tenant telemetry services are implemented, then data confidentiality is ensured, but cost becomes prohibitive and impractical

Engineering Contradiction:
Improvedata confidentialityVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple tenants' telemetry services into a single shared infrastructure while maintaining data confidentiality through encryption. Instead of deploying separate service instances for each tenant, the system combines them and uses cryptographic mechanisms to ensure each tenant's data remains confidential.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal telemetry service that can handle multiple tenants' data simultaneously. The service has multi-functionality to serve different tenants with different security requirements through a single infrastructure, using policy tokens and encryption keys to adapt to each tenant's confidentiality needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If conventional access control is used in multi-tenant environments, then ease of operation is maintained, but quantum security is not achieved

Engineering Contradiction:
Improveaccess controlVSAvoidquantum security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the security parameter from classical encryption to post-quantum cryptography. By adopting quantum-resistant encryption algorithms and key management mechanisms, the system maintains ease of operation while achieving security that withstands quantum computing threats.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240421979A1Apparatus, system, and method for achieving quantum secure data in multi-tenant environments
Publication Date: 2024.12.19 JUNIPER NETWORKS INC
  • US20240421979A1 patent drawing
  • US20240421979A1 patent drawing
  • US20240421979A1 patent drawing

AI summary

A disclosed computing device capable of achieving quantum secure data in multi-tenant environments may include (1) a cooling device and (2) circuitry communicatively coupled to the cooling device, wherein the circuitry is configured to (A) alternate between periods of high computing activity that increases heat emission and periods of low computing activity that decreases the heat emission and (B) direct the cooling device to decrease cooling power during the periods of high computing activity and increase the cooling power during the periods of low computing activity. Various other apparatuses, systems, and methods are also disclosed.