A security architect is designing a data security solution for a B2B SaaS platform that handles highly sensitive customer data across multiple tenants. The platform must ensure that each tenant's data is cryptographically isolated from other tenants, even if the underlying storage infrastructure is shared. Which combination of key management and data encryption strategy would best achieve this tenant-level cryptographic isolation?
- ACentralized Key Management System (KMS) with a single master key for all tenants and data-at-rest encryption.
- BClient-side encryption where each customer manages their own encryption keys before uploading data.
- CDisk-level encryption on the shared storage infrastructure using a platform-managed key.
- DHardware Security Module (HSM) for generating and protecting a unique encryption key per tenant, used for tenant-specific data encryption.
Show answer & explanationAnswer & explanation
Correct answer: D. Hardware Security Module (HSM) for generating and protecting a unique encryption key per tenant, used for tenant-specific data encryption.
Using an HSM to generate and protect a unique encryption key per tenant, combined with tenant-specific data encryption, provides strong cryptographic isolation. The HSM ensures the keys are protected, and unique keys prevent one tenant's data from being compromised if another's key is exposed.
Why the other options are wrong
- A. A single master key for all tenants introduces a single point of compromise, failing to provide cryptographic isolation between tenants.
- B. Client-side encryption shifts key management burden to customers, which might not be feasible or consistent, and doesn't directly address the platform's responsibility for cryptographic isolation.
- C. Disk-level encryption with a platform-managed key protects data from physical theft but does not provide cryptographic isolation between logical tenants on the same shared infrastructure.
Centralized HSM and KMS for Multi-Tenant Isolation
Leveraging Hardware Security Modules (HSM) and a Key Management System (KMS) to generate, store, and manage unique encryption keys for each tenant, ensuring cryptographic separation of data in a shared multi-tenant environment.
- HSMs provide tamper-resistant hardware for key protection.
- Unique keys per tenant prevent cross-tenant data access.
- KMS manages the lifecycle of these tenant-specific keys.
Memory trick: HSM & KMS: 'Hardware Shields Keys' for each tenant's 'Kingdom'.