Danny Berler is lead security architect at SanDisk, provides next gen security solutions for the companies consumer, client and enterprise products. working closely with engineering team to provide end to end security solutions to protect user data and SanDisk intellectual property .
Key Per IO is a NVMe standard that enables confidential computing, allowing hosts to control security keys. However, multi-tenant environments often need more features, including effective key management, optimized memory utilization, and simplified processes for tenant on-boarding and off-boarding. In this paper, we propose a scalable approach to deploying Key Per IO, including techniques for key distribution and ownership, per-I/O encryption handling, and scaled tenant management.By integrating these enhancements, the industry can fully realize strict key separation through zero-trust storage models, tenant-controlled cryptography, and device-independent key ownership, driving more robust and scalable security solutions.