- 专利标题: METHOD TO ENABLE SHARED SAAS MULTI-TENANCY USING CUSTOMER DATA STORAGE, CUSTOMER CONTROLLED DATA ENCRYPTION KEYS
-
申请号: PCT/US2020/051781申请日: 2020-09-21
-
公开(公告)号: WO2021055935A1公开(公告)日: 2021-03-25
- 发明人: GHAFOOR, Khurram , KREMER, Alexander
- 申请人: PROOFPOINT, INC. , OBSERVEIT LTD
- 申请人地址: 892 Ross Drive; 177 Huntington Avenue, Suite 3
- 专利权人: PROOFPOINT, INC.,OBSERVEIT LTD
- 当前专利权人: PROOFPOINT, INC.,OBSERVEIT LTD
- 当前专利权人地址: 892 Ross Drive; 177 Huntington Avenue, Suite 3
- 代理机构: WHITCOMB, Jonathan, B.
- 优先权: US62/903,831 2019-09-21
- 主分类号: G06F9/44
- IPC分类号: G06F9/44 ; G06F9/455 ; G06F11/28 ; G06F15/173 ; G06F15/177
摘要:
A system controls access to data for customer of a multi-tenant software as a service (SaaS) system. A multi-tenant SaaS system cloud includes a metadata store. A customer- controlled storage realm includes a customer-controlled key management system (KMS) and a data store for storing encrypted customer data objects. An agent at a user endpoint identifies customer data for storage in the customer data store, transmits metadata and telemetry information related to the customer data to a SaaS application interface (API), and provides a storage reference for a SaaS metadata store. The agent is pre-configured with credentials from the KMS for storing customer data objects in the data store. The customer-controlled storage realm is not in direct communication with the SaaS system cloud.