Tenant Key Security in Cloud Compute Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud service provider environments face challenges in securely managing tenant keys, as bulk encryption master keys are derived and extracted in the clear to random access memory, making them vulnerable to side-channel attacks and unauthorized access, especially in multi-cloud environments and ETSI NFV architectures.

Innovation Solution

A system comprising compute devices with cryptography logic units that securely receive and store tenant keys without exposing them to memory accessible by other tenants or system operators, using specialized communication protocols and hardware-based cryptographic operations to ensure secure encryption, decryption, and authentication services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If bulk encryption master keys are extracted to random access memory for use in cipher APIs, then encryption operations can be performed efficiently, but the keys become vulnerable to side-channel attacks and unauthorized access

Engineering Contradiction:
Improveencryption operation efficiencyVSAvoidside-channel attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key management functionality from the general-purpose CPU and places it in a dedicated cryptography logic unit. The bulk encryption master key is derived and stored within this isolated hardware unit, extracting it from the vulnerable random access memory environment while maintaining efficient cryptographic operations through dedicated hardware circuits.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cryptography logic unit acts as an intermediary between the storage media and the cipher APIs. It receives cryptographic operation requests from the host system, performs the actual encryption/decryption operations using the protected master key internally, and returns results without exposing the key to the host's random access memory, thus mediating the security risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If encryption keys are stored in accessible memory for easy retrieval, then key access is simple and fast, but other tenants and system operators can potentially access and compromise the keys

Engineering Contradiction:
Improvekey access simplicityVSAvoidkey security isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the system into distinct security domains: the host system with its random access memory, and the isolated cryptography logic unit with its own protected memory space. The encryption key is stored in the segmented, isolated portion (cryptography logic unit), preventing access by other tenants or system operators while allowing the authorized host to access it through defined interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptography logic unit provides local quality in terms of security isolation. Within this specific local environment, the key is protected from external access attempts. The unit has specialized communication interfaces that provide controlled, authenticated access paths, creating different access qualities for different entities (isolated for unauthorized users, accessible for authorized operations).

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250106191A1Technologies for providing secure utilization of tenant keys
Publication Date: 2025.03.27 INTEL PRODUCTS IP LLC
  • US20250106191A1 patent drawing
  • US20250106191A1 patent drawing
  • US20250106191A1 patent drawing

AI summary

Technologies for providing secure utilization of tenant keys include a compute device. The compute device includes circuitry configured to obtain a tenant key. The circuitry is also configured to receive encrypted data associated with a tenant. The encrypted data defines an encrypted image that is executable by the compute device to perform a workload on behalf of the tenant in a virtualized environment. Further, the circuitry is configured to utilize the tenant key to decrypt the encrypted data and execute the workload without exposing the tenant key to a memory that is accessible to another workload associated with another tenant.