Tenant Data Encryption via Local Key Generation for SaaS Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Software as a Service (SaaS) architecture faces challenges in providing customization and ensuring security and privacy for customers, as centralized management can lead to security concerns and limitations in tailoring software applications to meet diverse customer needs.
Innovation Solution
The implementation of a method that generates custom keys for tenant data, encrypts it, and uses a public certificate from the Vault Service for additional encryption, ensuring secure storage and transfer, along with an index encrypted with a public key for secure manipulation and access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If centralized management of SaaS applications is implemented, then scalability and maintenance efficiency are improved, but security concerns and customization limitations worsen
Solution Approach 1:
The patent segments the key management system into customer-side key generation and host-side key storage. The customer appliance generates and retains encryption keys locally, while only encrypted data is transmitted to the host data center. This segmentation ensures that even with centralized management, the host cannot access plaintext customer data, resolving the security concern while maintaining maintenance efficiency.
2Productivity
If centralized management of SaaS applications is implemented, then scalability and maintenance efficiency are improved, but customization capabilities worsen
Solution Approach 1:
The patent enables local customization at the customer appliance level while maintaining centralized host management. Each customer can configure their own encryption parameters, key retention policies, and data processing rules locally, allowing customization without compromising the centralized maintenance and update capabilities of the host system.
3Reliability
If customer data is encrypted with custom keys before transfer, then security is improved, but system complexity worsens
Solution Approach 1:
The customer appliance autonomously generates encryption keys, encrypts data, and manages key retention without requiring complex host-side encryption infrastructure. This self-service approach simplifies the overall system by shifting encryption responsibilities to the customer端, improving security while avoiding the complexity of centralized key management.
Data Source
AI summary
An extensible servicing hosting platform is provided that supports the design, build and concurrent deployment of multiple web accessible services on a services hosting platform. The services hosting platform comprises a services hosting framework capable of hosting multiple service applications, each of which may be shared by multiple tenants that each customize their use of a particular application service by extending the application service to exploit run time platform services within a service execution pipeline. The services hosting framework may easily be leveraged by applications to decrease the time associated with developing, deploying and maintaining high quality services in a cost effective manner.


