Invention Grant
- Patent Title: Techniques for data security in a multi-tenant environment
-
Application No.: US15076264Application Date: 2016-03-21
-
Publication No.: US10270781B2Publication Date: 2019-04-23
- Inventor: Gregory B. Roth , Eric Jason Brandwine , Graeme D. Baer
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee Address: US WA Seattle
- Agency: Hogan Lovells US LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/31 ; G06F21/60 ; G06F9/455

Abstract:
The usage of data in a multi-tenant environment can be controlled by utilizing functionality at the hypervisor level of various resources in the environment. Data can be associated with various tags, security levels, and/or compartments. The ability of resources or entities to access the data can depend at least in part upon whether the resources or entities are also associated with the tags, security levels, and/or compartments. Limitations on the usage of the data can be controlled by one or more policies associated with the tags, security levels, and/or compartments. A control service can monitor traffic to enforce the appropriate rules or policies, and in some cases can prevent encrypted traffic from passing beyond a specified egress point unless the encryption was performed by a trusted resource with the appropriate permissions.
Public/Granted literature
- US20160205110A1 TECHNIQUES FOR DATA SECURITY IN A MULTI-TENANT ENVIRONMENT Public/Granted day:2016-07-14
Information query