Per Tenant Encryption Key Segmentation for Shared Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data storage arrays using per drive encryption keys are inadequate for securing data when storage resources are shared among multiple tenants, as removing one tenant does not prevent other tenants from accessing their data due to shared storage resources.
Innovation Solution
Implementing unique tenant encryption keys, where each tenant's data is encrypted with a distinct per tenant key, allowing the key to be destroyed when the tenant is removed, while maintaining access for other tenants' data stored on the same resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If per drive encryption keys are used to secure data on storage drives, then data security is improved when storage drives are removed, but data accessibility deteriorates when storage resources are shared among multiple tenants
Solution Approach 1:
The encryption key is segmented into two distinct components: a per-tenant key specific to each tenant's data and a per-drive key associated with the storage drive. This segmentation allows the system to destroy only the per-tenant key when a tenant is removed, while preserving the per-drive key and other tenants' data on the same drive, thus resolving the contradiction between security and accessibility in shared storage environments
Solution Approach 2:
Different encryption keys are applied to different tenants' data on the same storage drive. Each tenant's data is encrypted with their own unique per-tenant key, allowing localized key destruction for individual tenants without affecting other tenants' data accessibility, thereby maintaining both security and accessibility
2Reliability
If per tenant encryption keys are used to secure data isolation, then data security for removed tenants is improved, but system complexity increases due to key management
Solution Approach 1:
The encryption key management is segmented into per-tenant keys and per-drive keys with distinct responsibilities. Per-tenant keys handle tenant-specific data isolation and can be independently destroyed, while per-drive keys manage drive-level encryption. This segmentation simplifies key management compared to a single comprehensive key system, as each key type has a specific scope and lifecycle
Solution Approach 2:
The patent introduces an intermediary key hierarchy where per-tenant keys act as intermediaries between tenants and their encrypted data, while per-drive keys serve as intermediaries between the storage system and the physical drives. This intermediary structure provides a clear key management pathway and reduces overall system complexity by organizing key relationships in a hierarchical manner
Data Source
AI summary
One embodiment is directed to a technique which secures data on a set of storage drives of a data storage system. The technique involves encrypting data from a first tenant using a first tenant key to form first tenant encrypted data and storing the first tenant encrypted data on the set of storage drives. The technique further involves encrypting data from a second tenant using a second tenant key to form second tenant encrypted data and storing the second tenant encrypted data on the set of storage drives, the first tenant being different from the second tenant, and the first tenant key and the second tenant key being per tenant keys which are different from each other. The technique further involves destroying the first tenant key to prevent the first tenant encrypted data stored on the set of storage drives from being decrypted while maintaining the second tenant key to enable decryption of the second tenant encrypted data stored on the set of storage drives.


