Virtual Key Management Domains for Multi-Tenant Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face challenges in providing end-to-end cryptographic security across all layers of a virtualized datacenter, particularly in multi-tenant settings, due to the complexity of managing public/private key pairs and security policies, which complicates data isolation and protection from malicious attacks.
Innovation Solution
A broadcast encryption-based virtual key management system (VKMS) is implemented, creating per-tenant key management domains using multiple management key variants to secure data across any combination of resources, allowing symmetric keys to be established for various trust levels within each domain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PKI-based encryption techniques are used to secure data between two parties, then end-to-end trust and security can be established, but the complexity of managing multiple public/private key pairs and security policies becomes prohibitive in multi-tenant cloud environments
Solution Approach 1:
The patent segments the key management system into virtual key management domains, with each tenant having their own isolated key space. This segmentation allows PKI-based security to be maintained within each domain while avoiding the complexity of managing keys across the entire multi-tenant infrastructure. Each tenant's data is encrypted with keys specific to their domain, providing end-to-end security without requiring the cloud provider to manage all key pairs.
Solution Approach 2:
The patent introduces a virtual key management domain as an intermediary layer between the cloud provider's infrastructure and the tenant's data. This intermediary manages the PKI key pairs and security policies within each tenant's isolated domain, shielding the complexity from both the provider's infrastructure team and the tenant's application team. The intermediary handles key generation, distribution, and rotation automatically.
2Reliability
If external encryption management is implemented by cloud customers to protect their data, then data confidentiality can be preserved, but the burden of managing encryption keys and authentication protocols becomes significant
Solution Approach 1:
The patent enables tenants to self-configure their own virtual key management domains with their own key spaces and security policies. Each tenant can independently manage their encryption keys and authentication protocols within their isolated domain without requiring external assistance from the cloud provider. The system automatically handles key lifecycle management, reducing the operational burden while maintaining strong confidentiality.
3Reliability
If traditional network isolation mechanisms are used in cloud datacenters, then data isolation between tenants can be achieved, but non-traditional physical network configurations negate these isolation mechanisms and complicate VPN keying techniques
Solution Approach 1:
The patent moves the isolation mechanism from the network layer to the cryptographic layer by implementing virtual key management domains. Instead of relying on traditional network isolation (VLANs, physical segmentation) that is negated by non-traditional cloud network configurations, the patent establishes isolation through cryptographic boundaries - each tenant's data is encrypted with domain-specific keys that provide isolation regardless of the underlying network topology or VPN configuration.
Data Source
AI summary
Tenants in a multi-tenant shared deployment are provided their own distinct key spaces over which they control a key management system. In this manner, virtual key management domains are created on a per-tenant (per-customer) basis so that, whenever a particular customer's data is co-tenanted, stored, transmitted or virtualized in the IT infrastructure of the provider's datacenter(s), it is secured using key management materials specific to that customer. This assures that the entirety of a tenant's data remains secure by cryptographically isolating it from other tenants' applications. The virtual key management domains are established using a broadcast encryption (BE) protocol and, in particular, a multiple management key variant scheme of that protocol. The broadcast encryption-based virtual key management system (VKMS) and protocol achieves per-tenant (as well as per-application) secured isolation of data and can be used across any combination of resources in or across all levels of a co-tenanted IT infrastructure.


