Tenant Key Security in Cloud Compute Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud service provider environments face challenges in securely managing tenant keys, as bulk encryption master keys are derived and extracted in the clear to random access memory, making them vulnerable to side-channel attacks and unauthorized access, especially in multi-cloud environments and ETSI NFV architectures.
Innovation Solution
A system comprising compute devices with cryptography logic units that securely receive and store tenant keys without exposing them to memory accessible by other tenants or system operators, using specialized communication protocols and hardware-based cryptographic operations to ensure secure encryption, decryption, and authentication services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If bulk encryption master keys are extracted to random access memory for use in cipher APIs, then encryption operations can be performed efficiently, but the keys become vulnerable to side-channel attacks and unauthorized access
Solution Approach 1:
The patent extracts the key management functionality from the general-purpose CPU and places it in a dedicated cryptography logic unit. The bulk encryption master key is derived and stored within this isolated hardware unit, extracting it from the vulnerable random access memory environment while maintaining efficient cryptographic operations through dedicated hardware circuits.
Solution Approach 2:
The cryptography logic unit acts as an intermediary between the storage media and the cipher APIs. It receives cryptographic operation requests from the host system, performs the actual encryption/decryption operations using the protected master key internally, and returns results without exposing the key to the host's random access memory, thus mediating the security risk.
2Ease of operation
If encryption keys are stored in accessible memory for easy retrieval, then key access is simple and fast, but other tenants and system operators can potentially access and compromise the keys
Solution Approach 1:
The patent segments the system into distinct security domains: the host system with its random access memory, and the isolated cryptography logic unit with its own protected memory space. The encryption key is stored in the segmented, isolated portion (cryptography logic unit), preventing access by other tenants or system operators while allowing the authorized host to access it through defined interfaces.
Solution Approach 2:
The cryptography logic unit provides local quality in terms of security isolation. Within this specific local environment, the key is protected from external access attempts. The unit has specialized communication interfaces that provide controlled, authenticated access paths, creating different access qualities for different entities (isolated for unauthorized users, accessible for authorized operations).
Data Source
AI summary
Technologies for providing secure utilization of tenant keys include a compute device. The compute device includes circuitry configured to obtain a tenant key. The circuitry is also configured to receive encrypted data associated with a tenant. The encrypted data defines an encrypted image that is executable by the compute device to perform a workload on behalf of the tenant in a virtualized environment. Further, the circuitry is configured to utilize the tenant key to decrypt the encrypted data and execute the workload without exposing the tenant key to a memory that is accessible to another workload associated with another tenant.


