Per-Tenant Encryption Orchestration for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern datacenters face vulnerabilities in high-speed data exchange due to unencrypted data, which can be exploited by malicious attacks, and existing encryption methods introduce inefficiencies and security risks, particularly in hardware-level key management and network-level security tunnels.

Innovation Solution

Implementing an encryption orchestrator that orchestrates on-demand, per-tenant resource enclaves using a secure secret key distribution scheme across server boundaries, leveraging out-of-band key exchange and datalink layer encryption to ensure data is encrypted only when in transit or at rest, with isolated key management and support for Quantum Key Distribution (QKD) devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If data is transmitted unencrypted for high-speed data exchange, then data transmission speed is improved, but security against malicious attacks deteriorates

Engineering Contradiction:
Improvedata transmission speedVSAvoidsecurity against malicious attacks
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary key establishment and encryption setup before data transmission begins. Encryption keys are pre-distributed and configured in the network devices, so that when data needs to be transmitted, the encryption is already in place and ready to operate, minimizing the overhead during actual data transfer

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional software-based encryption with hardware-level encryption capabilities embedded in network devices. This hardware substitution enables encryption operations to occur at line rate without significant performance degradation, resolving the contradiction between encryption security and transmission speed

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If encryption is applied to all data transmissions, then security is improved, but processing overhead and complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements selective encryption where only specific data flows and transmissions require encryption, rather than encrypting all data uniformly. The encryption is applied locally at the network devices based on policy decisions, allowing the system to maintain security where needed while avoiding unnecessary complexity in other areas

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements automated key management and encryption orchestration that operates autonomously without requiring manual intervention. The system self-configures encryption parameters, manages key distribution, and coordinates encryption/decryption operations across network devices, significantly reducing operational complexity

Inventive Principle:
Principle #25Self-service

3Productivity

If hardware-level encryption is implemented, then encryption speed is improved, but key management security risks increase

Engineering Contradiction:
Improveencryption processing speedVSAvoidkey management security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system segments key management responsibilities and separates key generation, storage, and usage functions across different trusted components. Keys are divided into multiple shares or distributed across multiple devices, so that no single hardware component holds the complete key, reducing the security risk while maintaining hardware-level encryption performance

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces trusted intermediaries or key management services that mediate between the hardware encryption capabilities and the actual encryption keys. These intermediaries securely manage key distribution and rotation, protecting the hardware components from direct key exposure while enabling fast hardware-based encryption operations

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If network-level security tunnels are used, then data protection is improved, but latency and overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidtransmission latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system moves encryption from the network layer to the data link layer or hardware level, changing the dimensional plane where encryption occurs. This allows encryption to be applied closer to the physical transmission medium, enabling parallel processing and eliminating the sequential overhead that causes latency in traditional network-layer encryption approaches

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20260039455A1On-demand formation of secure user domains
Publication Date: 2026.02.05 MELLANOX TECHNOLOGIES LTD(IL)
  • US20260039455A1 patent drawing
  • US20260039455A1 patent drawing
  • US20260039455A1 patent drawing

AI summary

Systems, data processing systems, and methods, among other things, are disclosed. An illustrative system includes an encryption orchestrator that analyzes a packet, obtains a tenant identifier (ID) from the packet, determines whether a tenant associated with the tenant ID currently has sufficient encryption credit available, and enables an encryption resource to process the packet using an encryption key associated with the tenant ID in response to determining that the tenant associated with the tenant ID currently has sufficient encryption credit available.