Customer-Controlled Encryption Keys for SaaS Multi-Tenancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SaaS providers manage both storage and encryption keys, which may not satisfy customers who want more control over their sensitive data and encryption keys.

Innovation Solution

Implementing a method that enables shared SaaS multi-tenancy using customer data storage and customer-controlled data encryption keys, where customers maintain control over their encryption keys (DEK and KEK) and storage, ensuring exclusive access and management of their sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SaaS providers manage both storage and encryption keys, then system simplicity and ease of operation are improved, but customer control over data security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidcustomer control over data security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the data management function by separating storage management (handled by SaaS provider) from key management (handled by customer). This segmentation allows each party to maintain control over their respective domains, resolving the contradiction between operational simplicity and customer security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key management system as an intermediary component that enables customers to control their encryption keys while working with the SaaS provider's storage system. This intermediary allows customers to maintain security control without complicating the overall system operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If customers maintain control over encryption keys, then data security and privacy are improved, but system complexity is worsened

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key management function from the storage system, allowing customers to maintain control over their encryption keys independently. This extraction improves data security by ensuring customers hold their own keys while the system remains relatively simple through clear functional separation.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If SaaS providers store encryption keys for data retrieval, then data accessibility is improved, but customer control and security are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoidcustomer control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements dynamic key management where customers can control key access on-demand. The key management system allows customers to grant or revoke access to their encryption keys, enabling flexible data accessibility while maintaining customer control and security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250148115A1System and Method to enable Shared SaaS Multi-Tenancy using Customer Data Storage, Customer-controlled Data Encryption Keys
Publication Date: 2025.05.08 GOLDMAN SACHS BANK USA
  • US20250148115A1 patent drawing
  • US20250148115A1 patent drawing
  • US20250148115A1 patent drawing

AI summary

In a method for controlling access to customer data of a multi-tenant software as a service (SaaS) system, a SaaS agent at a user endpoint sends a request for storage credentials to a SaaS agent facing application interface (API) of a SaaS system cloud. The storage credentials provide access to a SaaS encrypted data store of the multi-tenant SaaS system. The SaaS agent receives the storage credentials from the SaaS agent facing API, and the SaaS agent uses the storage credentials to store customer data in the SaaS encrypted data store. A customer-controlled encryption key is maintained on a customer-controlled cloud hosting a key management system (KMS). The customer-controlled cloud is in communication with the SaaS agent facing API.