Patent · US Active

Security layer for containers in multi-tenant environments

US10326744B1 · kind B1 · utility

64Cited by
10References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 21, 2016
Grant dateJun 18, 2019
Priority date
Expiry dateJul 22, 2036

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2009/45587
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

An apparatus comprises at least one container host device implementing containers for respective tenants of a multi-tenant environment. The containers are configured to utilize storage resources of at least one storage platform. A given one of the containers comprises at least one application, and an application file system security layer configured to communicate with the storage platform. The application file system security layer comprises a container storage volume supported by the storage platform, and an encryption engine configured to encrypt and decrypt data of the container storage volume utilizing one or more data encryption keys that are encrypted under a tenant-specific key encryption key. The tenant-specific key encryption key is provided to the application file system security layer by a tenant key manager that is external to the container. The tenant key manager is illustratively controlled by the tenant for which the given container is implemented.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.