Securing data in multitenant environment
Abstract
Methods, systems, and computer programs are presented for secure data encryption in a multi-tenant service platform. One method includes an operation for detecting a write request to write index data to storage. The write request is from a first user from a group of users, and the storage is configured to store index data for the group of users. Further, the method includes operations for authenticating that the first user is approved for access to the storage, and for identifying a first encryption key for the first user, where each user from the group of users has a separate encryption key. Further yet, the method includes encrypting the index data with the first encryption key and storing the encrypted index data in the storage.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
encrypting, by one or more processors, transcripts of conversations corresponding to multiple users, the transcripts being encrypted with a transcript encryption key; indexing, by the one or more processors, first portions of the transcripts, the first portions being indexed by first index data corresponding to a first user among the multiple users; identifying, by the one or more processors, a first index encryption key that corresponds to the first user, the first index encryption key being distinct from the transcript encryption key with which the transcripts are encrypted; and encrypting, by the one or more processors, the first index data that indexes the first portions of the transcripts and corresponds to the first user with the first index encryption key distinct from the transcript encryption key.
2 . The method of claim 1 , further comprising:
storing the encrypted first index data of the first user in a corresponding first folder of a storage, the first folder corresponding to the first user.
3 . The method of claim 1 , wherein:
the first index encryption key that corresponds to the first user among the multiple users is unique among multiple index encryption keys that each correspond to a different user among the multiple users.
4 . The method of claim 3 , wherein:
the transcript encryption key with which the transcripts are encrypted is distinct from each of the multiple index encryption keys that each correspond to a different user among the multiple users.
5 . The method of claim 1 , wherein:
the identifying of the first index encryption key of the first user includes selecting the first index encryption key from multiple index encryption keys that are each unique among the multiple index encryption keys and that each correspond to a different user among the multiple users.
6 . The method of claim 1 , further comprising:
detecting a read request from the first user to read the first index data; accessing the first index encryption key of the first user; accessing the first index data based on the read request from the first user; decrypting the first index data with the first index encryption key of the first user; and providing the decrypted first index data in response to the read request.
7 . The method of claim 1 , further comprising:
storing the encrypted first index data of the first user in a corresponding first partition of a storage, the first partition corresponding to the first user.
8 . A system comprising:
a memory comprising instructions; and one or more computer processors, wherein the instructions, when executed by the one or more computer processors, cause the system to perform operations comprising: encrypting transcripts of conversations corresponding to multiple users, the transcripts being encrypted with a transcript encryption key; indexing first portions of the transcripts, the first portions being indexed by first index data corresponding to a first user among the multiple users; identifying a first index encryption key that corresponds to the first user, the first index encryption key being distinct from the transcript encryption key with which the transcripts are encrypted; and encrypting the first index data that indexes the first portions of the transcripts and corresponds to the first user with the first index encryption key distinct from the transcript encryption key.
9 . The system of claim 8 , wherein the operations further comprise:
storing the encrypted first index data of the first user in a corresponding first folder of a storage, the first folder corresponding to the first user.
10 . The system of claim 8 , wherein:
the first index encryption key that corresponds to the first user among the multiple users is unique among multiple index encryption keys that each correspond to a different user among the multiple users.
11 . The system of claim 10 , wherein:
the transcript encryption key with which the transcripts are encrypted is distinct from each of the multiple index encryption keys that each correspond to a different user among the multiple users.
12 . The system of claim 8 , wherein:
the identifying of the first index encryption key of the first user includes selecting the first index encryption key from multiple index encryption keys that are each unique among the multiple index encryption keys and that each correspond to a different user among the multiple users.
13 . The system of claim 8 , wherein the operations further comprise:
detecting a read request from the first user to read the first index data; accessing the first index encryption key of the first user; accessing the first index data based on the read request from the first user; decrypting the first index data with the first index encryption key of the first user; and providing the decrypted first index data in response to the read request.
14 . The system of claim 8 , wherein the operations further comprise:
storing the encrypted first index data of the first user in a corresponding first partition of a storage, the first partition corresponding to the first user.
15 . A non-transitory machine-readable storage medium comprising instructions that, when executed by a machine, cause the machine to perform operations comprising:
encrypting transcripts of conversations corresponding to multiple users, the transcripts being encrypted with a transcript encryption key; indexing first portions of the transcripts, the first portions being indexed by first index data corresponding to a first user among the multiple users; identifying a first index encryption key that corresponds to the first user, the first index encryption key being distinct from the transcript encryption key with which the transcripts are encrypted; and encrypting the first index data that indexes the first portions of the transcripts and corresponds to the first user with the first index encryption key distinct from the transcript encryption key.
16 . The non-transitory machine-readable storage medium of claim 15 , wherein the operations further comprise:
storing the encrypted first index data of the first user in a corresponding first folder of a storage, the first folder corresponding to the first user.
17 . The non-transitory machine-readable storage medium of claim 15 , wherein:
the first index encryption key that corresponds to the first user among the multiple users is unique among multiple index encryption keys that each correspond to a different user among the multiple users.
18 . The non-transitory machine-readable storage medium of claim 17 , wherein:
the transcript encryption key with which the transcripts are encrypted is distinct from each of the multiple index encryption keys that each correspond to a different user among the multiple users.
19 . The non-transitory machine-readable storage medium of claim 15 , wherein:
the identifying of the first index encryption key of the first user includes selecting the first index encryption key from multiple index encryption keys that are each unique among the multiple index encryption keys and that each correspond to a different user among the multiple users.
20 . The non-transitory machine-readable storage medium of claim 15 , wherein the operations further comprise:
detecting a read request from the first user to read the first index data; accessing the first index encryption key of the first user; accessing the first index data based on the read request from the first user; decrypting the first index data with the first index encryption key of the first user; and providing the decrypted first index data in response to the read request.Join the waitlist — get patent alerts
Track US2023325517A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.