Remote management of hardware security module

By generating and encrypting a shared secret in a secure environment, and using a dual encryption mechanism and the public and private keys of a CA certificate for decryption, the security of the shared secret and the authenticity of requests in remote HSM management are solved, thus enabling secure management by remote administrators.

CN116671062BActive Publication Date: 2026-04-14INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INTERNATIONAL BUSINESS MACHINE CORPORATION
Filing Date
2021-12-03
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing HSM management solutions have shared secret security issues in remote management. The authenticity of remote administrator requests is difficult to verify, and the inability of administrators to assemble systems in the same physical space makes management impractical.

Method used

By generating and encrypting a shared secret in a secure environment, using a dual encryption mechanism, the remote administrator's request is verified and transmitted in a secure device, ensuring that the shared secret remains secure on the mobile device, and decryption and encryption are performed using the public and private keys of the CA certificate.

Benefits of technology

It enables remote administrators to securely manage HSMs, ensuring that shared secrets are not decrypted by unauthorized users during transmission, meeting dual control requirements, and ensuring the authenticity and security of requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116671062B_ABST
    Figure CN116671062B_ABST
Patent Text Reader

Abstract

A computer-implemented method for remote management of a hardware security module (HSM) includes receiving a command request from a mobile device. The command request includes an encrypted key portion and an encrypted signature key. The HSM decrypts the command request using a key associated with a secure enclave of the mobile device. The HSM decrypts the encrypted key portion and the encrypted signature key. Decrypting the encrypted key portion and the encrypted signature key includes using the key associated with the secure enclave of the mobile device and a key associated with a remote administrator associated with the mobile device. A command is generated for a domain having a target HSM. The command is generated using the decrypted key portion and the decrypted signature key. The command is transmitted to the domain for execution by the target HSM. Various other methods, systems, and computer-readable media are also disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] This invention generally relates to cryptography, and more particularly to the remote management of hardware security modules.

[0002] Computing systems can utilize various data security measures to protect data from unauthorized access. For example, a Hardware Security Module (HSM) is a computing device and associated software that provides cryptographic functionality to protect and manage cryptographic keys, including encryption and decryption functions for digital signatures, strong authentication, and other cryptographic features. An HSM can take the form of a physical plug-in card directly connected to or attached to a secure computing device or network server, or an external computing device.

[0003] Existing HSM management solutions utilize dual controls and other security technologies to ensure data protection. For example, an HSM management solution might require multiple administrators, each possessing a smart card containing a key portion of the HSM's master key, to simultaneously assemble in a physically secure space and present their respective smart cards, each containing its key portion, to the system for HSM configuration. However, HSM management can be impractical and hinder the necessary process if administrators cannot simultaneously gather in the same physical secure space. For instance, if one or more administrators cannot present their smart cards containing their respective key portions in the physical space, the HSM cannot be configured because all the key portions necessary to form the master key are absent. This can occur if everyone must work from home, one or more administrators are physically unable to access the secure space, or other similar obstacles prevent all required administrators from being physically present in the secure space.

[0004] Conventional techniques used for remote management of HSMs have raised concerns about the security surrounding the shared secret required by remote administrators and the authenticity of requests from legitimate remote administrators. A shared secret is a piece of data known only to the parties involved in secure communication. Remote administrators of a system need to utilize shared secrets to manage HSMs outside of a secure environment. One security issue stemming from existing technologies for HSM management involves how to securely transmit shared secrets to and from remote administrators. In some examples, the connection between mobile devices and servers can be compromised, and the shared secret can be intercepted by unauthorized users, thus compromising its security.

[0005] Some existing HSM management solutions enable the generation of shared secrets outside of a secure environment. In some cases, HSM management systems allow end users or remote administrators to generate their own shared secrets using their own identities or information about mobile devices. Shared secrets generated outside of a secure environment by a remote administrator may be vulnerable to exploitation if an attacker gains access to the information used to generate the shared secret (e.g., user identity, mobile device information, etc.) and decrypts or otherwise obtains the shared secret. If an attacker has already collected sufficient information about a user or has access to their device, this could make the system vulnerable and potentially compromised.

[0006] In some existing HSM management solutions, shared secrets may not be adequately protected outside of a secure environment when held by a remote administrator. For example, a shared secret might be stored unencrypted on a mobile device. If an unauthorized user accesses the mobile device, they could gain access to the unprotected shared secret, making the system vulnerable to unauthorized access.

[0007] In some existing HSM management solutions, management requests received from remote administrators may not be valid or trustworthy. An attacker could clone a device controlled by a remote administrator or access the device without knowing the remote administrator and attempt to gain system access. Such requests could appear valid or genuine, granting unauthorized users access to the system. Summary of the Invention

[0008] Embodiments of the present invention relate to a remote management hardware security module (HSM). According to one aspect of the invention, a computer-implemented method is provided, comprising receiving a command request from a mobile device by a processor of a computing device, the command request including an encrypted key portion and an encrypted signature key. The HSM decrypts the command request using a key associated with a security zone of the mobile device. The HSM decrypts the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key. Decrypting the encrypted key portion and the encrypted signature key involves using a key associated with a security zone of the mobile device and a key associated with a remote administrator, who is associated with the mobile device. Based on the command request, a command is generated for a domain having a target HSM. The command is generated using the decrypted key portion and the decrypted signature key. The command is transmitted to the domain for execution by the target HSM.

[0009] According to another aspect of the present invention, a system for remotely managing an HSM is provided. A non-limiting example of the system includes a memory having computer-readable instructions and one or more processors for executing the computer-readable instructions. The computer-readable instructions can implement the method described above.

[0010] According to another aspect of the present invention, a computer program product for remotely managing an HSM is provided, the computer program product including a computer-readable storage medium containing program instructions. The program instructions are executable by a processor to cause the processor to perform the methods described above.

[0011] Therefore, advantageously, one or more embodiments of the present invention securely manage shared secrets used for remote management of HSMs. This allows remote administrators to perform HSM management without having to assemble it in one location, while ensuring that the shared secrets remain protected.

[0012] Preferably, the present invention provides a method in which the command request may further include an encrypted login key associated with a remote administrator, and the computer-implemented method may further include an HSM decrypting the encrypted login key to generate a decrypted login key. Decrypting the encrypted login key involves using a key associated with a security zone of the mobile device and a key associated with the remote administrator, who is associated with the mobile device. The decrypted login key is transmitted to the domain along with the command. Therefore, advantageously, the login key can be transmitted to the domain along with the command.

[0013] Preferably, the present invention provides a method in which a second command request can be received from a second mobile device. The second command request may include a second encrypted key portion and a second encrypted signature key. The HSM decrypts the second command request using a key associated with a security zone of the mobile device. The HSM decrypts the second encrypted key portion and the second encrypted signature key to generate a second decrypted key portion and a second decrypted signature key. Decrypting the second encrypted key portion and the second encrypted signature key includes using a key associated with a security zone and different keys associated with different remote administrators linked to the second mobile device. Using the second decrypted key portion and the second decrypted signature key, a second command can be generated for a domain with a target HSM. The second command can be transmitted to the domain. Therefore, advantageously, multiple remote administrators with different key portions can remotely manage the HSM without having to assemble it in one location, while ensuring that shared secrets remain protected.

[0014] Preferably, the present invention provides a method in which the decrypted key portion and the second decrypted key portion are part of a master key associated with a target HSM of the domain. Therefore, advantageously, the HSM can be managed by different administrators using dual control, with each key portion being part of the HSM's master key.

[0015] Preferably, the invention provides a method in which a mobile device is provided by registering it in a secure area and associating it with a remote administrator. Therefore, advantageously, the mobile device used for remote management of the HSM is configured to ensure protection of the shared secrets used by the system.

[0016] Preferably, the invention provides a method in which the command can be signed using a decrypted signing key before being transmitted to the domain for execution by the target HSM. Therefore, advantageously, commands for remotely managing the HSM are protected by an additional security layer during transmission to the domain.

[0017] Preferably, the invention provides a method in which a message can be transmitted to a mobile device based on a result received from a domain. Therefore, advantageously, the result of a command received from the domain can be used to update the remote administrator.

[0018] According to another aspect of the present invention, a computer-implemented method for remotely managing a Hardware Security Module (HSM) is provided. A non-limiting example of the computer-implemented method includes receiving a load key request, comprising an encrypted key portion and an encrypted signature key, from a mobile device associated with a remote administrator by a processor of a computing device. The load key request from the mobile device can be verified. The encrypted key portion and the encrypted signature key can be decrypted to generate a decrypted key portion and a decrypted signature key. Decrypting the encrypted key portion and the encrypted signature key may include using a private key corresponding to the public key of a Certificate Authority (CA) certificate used for a secure area and a private key corresponding to the public key of a CA certificate for the remote administrator's profile. A load key command can be established for a domain specified in the load key request. The load key command may include the decrypted key portion and be signed using the decrypted signature key. The load key command may be transmitted to the domain for execution by a target Hardware Security Module (HSM) in that domain.

[0019] Therefore, advantageously, one or more embodiments of the present invention securely manage shared secrets used for remote management of HSMs. This allows remote administrators to perform HSM management without having to assemble it in one location, while ensuring that the shared secrets remain protected.

[0020] Preferably, the present invention provides a computer-implemented method in which a load key request is encrypted using a public key of a CA certificate for a secure zone, and verifying the load key request includes decrypting the load key request using a private key corresponding to the public key of the CA certificate for the secure zone. Therefore, advantageously, the load key request is encrypted by the mobile device to ensure that shared secrets are protected during the transmission of the request to the system.

[0021] According to another aspect of the invention, a computer-implemented method for remotely managing a Hardware Security Module (HSM) is provided. A non-limiting example of the computer-implemented method may include receiving, by a processor of a secure computing device, an encrypted Hardware Security Module (HSM) command request, including an encrypted key portion and an encrypted signature key, from a mobile device associated with a remote administrator. The encrypted HSM command request from the mobile device can be decrypted. The HSM of the secure computing device decrypts the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key. An HSM command corresponding to an encrypted HSM command request for a specified domain may be generated, at least in part, based on the decrypted key portion and the decrypted signature key. The HSM command may be sent to the specified domain for execution by a target HSM in the specified domain.

[0022] Therefore, advantageously, one or more embodiments of the present invention securely manage shared secrets used for remote management of HSMs. This allows remote administrators to perform HSM management without having to assemble it in one location, while ensuring that the shared secrets remain protected.

[0023] Preferably, the present invention provides a computer-implemented method in which a load key request is encrypted using a public key of a CA certificate for a secure zone, and verifying the load key request includes decrypting the load key request using a private key corresponding to the public key of the CA certificate for the secure zone. Therefore, advantageously, the load key request is encrypted by the mobile device to ensure that shared secrets are protected during the transmission of the request to the system.

[0024] Preferably, the present invention provides a computer-implemented method in which messages can be transmitted to a mobile device based on results received from a designated domain. Therefore, advantageously, the results of commands received from said domain are used to update a remote administrator.

[0025] Additional technical features and benefits are achieved through the technology of this invention. Embodiments and aspects of the invention are described in detail herein and are considered part of the claimed subject matter. For a better understanding, refer to the detailed description and accompanying drawings. Attached Figure Description

[0026] The proprietary details described herein are specifically pointed out and clearly claimed in the appended claims. The foregoing and other features and advantages of embodiments of the invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings, wherein:

[0027] Figure 1 This is a schematic diagram illustrating a mobile device for remote management of a hardware security module according to one or more example embodiments.

[0028] Figure 2This is a schematic diagram illustrating remote management of a hardware security module according to one or more example embodiments.

[0029] Figure 3 This is a process flowchart illustrating a method for providing a mobile device for remote management of a hardware security module, according to one or more example embodiments.

[0030] Figure 4 This is a process flowchart of an illustrative method for remotely managing a hardware security module by a mobile device, according to one or more example embodiments.

[0031] Figure 5 This is a process flowchart of an illustrative method for remotely managing a hardware security module by a security server, according to one or more example embodiments.

[0032] Figure 6 It is a computer system according to one or more embodiments of the present invention.

[0033] The figures described herein are illustrative. Many variations may be made to the figures or operations described herein without departing from the scope of the invention. For example, actions may be performed in a different order, or actions may be added, deleted, or modified. Furthermore, the term "coupling" and its variations describe a communication path between two elements and do not imply a direct connection between the elements without any intermediate elements / connections between them. All such variations are considered part of the specification. Detailed Implementation

[0034] Exemplary embodiments of the present invention particularly relate to systems, methods, computer-readable media, techniques, and approaches for the remote management of Hardware Security Modules (HSMs). Conventional methods for remotely managing HSMs have raised concerns about the security of shared secrets required by the remote administrator and the authenticity of requests from the remote administrator. Existing techniques for managing HSMs typically require administrators to assemble them simultaneously in the same physical space to ensure compliance with standards and regulations requiring the use of compliant management techniques to manage HSMs. However, this technique is impractical when administrators cannot physically assemble them in a single location.

[0035] One or more embodiments of the present invention address remote HSM management, wherein the HSM's master key is divided into key parts, stored in a protected storage device, and securely distributed to different remote administrators within a protected environment. Administrators can remotely manage the HSM while adhering to dual control requirements without having to physically assemble it in the same secure physical space. Shared secrets are securely distributed while ensuring that requests received by the system from administrators are authenticated to ensure that the requests originate from authorized administrators and that their mobile devices are not compromised.

[0036] In some embodiments, a security device, such as a security server, resides in a secure environment. A secure environment is a secure location, such as a secure room or floor in a building with limited access, where the security device supporting remote HSM management is located. The security device executes applications, such as web applications, to communicate with remotely located mobile devices outside the secure environment for remote HSM management. A mobile device, such as a smartphone, is provided in the secure environment. The mobile device is registered in the secure area and assigned to a remote administrator. When in the secure environment, a shared secret for HSM management is loaded onto the provided mobile device. The shared secret may include a key portion, which is a component of the master key used by the designated HSM. The shared secret is encrypted in the secure environment before being transmitted to the mobile device to ensure that the shared secret on the mobile device is secure and cannot be decrypted by the device's user, or, if the mobile device's security has been included, cannot be decrypted by anyone.

[0037] Remote administrators can take mobile devices outside the secure environment and use them for remote HSM management. For example, while outside the secure environment, a remote administrator can open an application on their mobile device and authenticate themselves, for instance, using multi-factor authentication. The remote administrator selects an HSM from the list for configuration and chooses a command to run on the target HSM in the specified domain. The remote administrator selects the desired shared secrets (e.g., loaded onto the mobile device during provisioning), such as the key portion and / or signing key, which were previously encrypted in the secure environment. The application uses the remote administrator's selection to establish a request and encrypts the request with the public key from the remote administrator's Certificate Authority (CA) certificate. The encrypted request is then transmitted to a secure device in the secure environment.

[0038] The security device receives encrypted requests from a remote administrator's mobile device. The security device verifies the requests and constructs an HSM command using information from the corresponding request received from the remote administrator's mobile device. Each HSM command is signed using a signing key obtained from the corresponding request and sent to the domain specified by the corresponding request. The command is executed by the target HSM in the specified domain. The target HSM receives requests from all specified remote administrators and can assemble key portions from each remote administrator until a master key is formed using the collected key portions. The HSM command is executed by the target HSM when the master key is complete. The result of the command executed by the target HSM is sent back to the security device. The security device can generate a message indicating the result received from the domain and send that message to the mobile device. The system and method described herein provide the ability to remotely manage HSMs using compliance-level management techniques such as dual-control while adhering to various standards and regulations.

[0039] A security challenge inherent in existing HSM management technologies is how to securely transmit shared secrets to and from remote administrators. In some examples, the connection between the mobile device and the server may be compromised, and the shared secret may be intercepted by an unintended recipient, thus compromising its security. One or more embodiments of the present invention facilitate the generation of shared secrets from an HSM by a secure device located in a secure environment. The shared secret can be double-encrypted. For example, a shared secret such as a key portion can be encrypted using a shared secret from a secure area of ​​the mobile device, and also using a shared secret associated with a specific remote administrator. The double-encrypted shared secret can then be loaded onto a mobile device provided by the remote administrator for remote management of the HSM. The double-encrypted shared secret generated by the HSM in a secure environment is never decrypted outside of that secure environment. When a remote administrator remotely manages the HSM, they can optionally include the double-encrypted shared secret in a command request sent to the secure device. Therefore, even if the double-encrypted shared secret is intercepted, it cannot be decrypted by an unauthorized user or used to remotely manage the HSM unless the mobile device from which it sends the secret has been properly verified by the secure device in a secure location.

[0040] Some existing HSM management solutions enable the generation of shared secrets outside of a secure environment. HSM management systems allow end users to generate shared secrets using their own identities or information about their mobile devices. Shared secrets generated outside of a secure environment by a remote administrator may be vulnerable to exploitation attacks if an attacker gains access to the information used to generate and decrypt or otherwise obtain the shared secret. One or more embodiments of the present invention facilitate the use of double-encrypted shared secrets generated and encrypted in a secure environment by a secure device and an associated HSM. The shared secret is not decrypted outside the secure environment and is not stored on the mobile device in a decrypted state. Therefore, shared secrets generated by the HSM of a secure device are protected outside the secure environment because they are double-encrypted and further encrypted when loaded onto the mobile device and when sent back to the secure device by the mobile device as part of an HSM command request for remote management of the HSM, thus eliminating the vulnerabilities presented by existing HSM management solutions.

[0041] The following will refer to Figure 1 and Figure 2 Provides a detailed description of a sample system for remote management of HSM. This will be combined with... Figures 3 to 5 Provide a detailed description of the corresponding computer-implemented method; in addition, combine... Figure 6 A detailed description of example computing systems and network architectures for implementing one or more embodiments described herein is provided.

[0042] Figure 1 This is a block diagram of an example system 100 provided by a mobile device for remotely managing HSMs. As shown in the diagram, the example system 100 may include one or more modules for performing one or more tasks. As will be explained in more detail below, these modules may include an HSM management module 135 of a security server 130 and / or applications 115A, 115B, 115C of corresponding mobile devices 110A, 110B, 110C. Although Figure 1 One or more modules in the application are shown as separate elements, but they can represent a single module or a part of an application.

[0043] Now for reference Figure 1 The system 100 configured according to an exemplary embodiment of the present invention includes a secure environment 105. A secure server 130 may be located within the secure environment 105. The secure environment 105 may be a secure location, such as a secure room or floor within a building of an organization or entity. The secure environment 105 may have limited or restricted access. Figure 1As shown in the embodiments, security server 130 includes HSM management module 135 and HSM 140. In one or more other embodiments of the invention, HSM 140 is connected to or attached to security server 130.

[0044] In some embodiments, setting up or configuring the security server 130 may include an HSM management module 135, which creates paths to one or more target HSMs. The HSM management module 135 may execute and / or manage applications, such as web applications, for communicating with mobile devices (e.g., 110A, 110B, 110C) that have been provided and are used from outside the security environment 105 to remotely manage one or more target HSMs. Additionally, the security server 130 may register in a security zone. A security zone is designated by a Certificate Authority (CA) and may represent the entity or organization that issues and / or manages certificates. In some embodiments, a CA smart card, CA certificate, etc., may define a security zone. A CA certificate may cryptographically link to devices (e.g., mobile devices 110A, 110B, 110C, security server 130, etc.).

[0045] In some embodiments, the HSM management module 135 can facilitate the generation and management of shared secrets 120A, 120B, 120C, and 120D. The HSM management module 135 can facilitate the generation and management of shared secrets 120A, 120B, 120C, and 120D by the HSM 140. Examples of shared secrets 120A, 120B, 120C, and 120D may include a remote administrator profile login key, a CCA normal mode signing key, a CCA PCI mode signing key, an EP11 signing key, and / or key portions. The CCA normal mode signing key may be an asymmetric key not bound by the Payment Card Industry (PCI). The CCA PCI mode signing key may be an asymmetric key conforming to PCI rules. The EP11 signing key may be an asymmetric key conforming to the PKCS#11 public key encryption API interface to a cryptographic token. The HSM management module 135 can facilitate the splitting, partitioning, or otherwise decomposing the master key of the target HSM into different key portions and assigning these key portions to different remote administrators. Each mobile device 110A, 110B, and 110C has different shared secrets 120A, 120B, and 120C (e.g., key portion, signing key, etc.), which can be encrypted using the public key of the security zone defined by the CA certificate and the corresponding public key of the corresponding remote administrator profile associated with each corresponding remote administrator. The HSM management module 135 can generate and store an encrypted shared secret 120D distributed to the mobile devices 110A, 110B, and 110C for remote management of the HSM.

[0046] The HSM management module 135 of the security server 130 can prepare shared secrets 120D so that they can be loaded onto mobile devices 110A, 110B, and 110C after they are provided and assigned to a specific remote administrator. The HSM management module 135 can encrypt the shared secrets 120D using the public key of the CA certificate defining the security zone (e.g., key portion, signing key, remote administrator login key, etc.). The HSM management module 135 can also encrypt the shared secrets using the public key of the remote administrator's profile certificate. In some embodiments, the HSM management module 135 can set a maximum download count to limit the number of times mobile devices 110A, 110B, and 110C can download the shared secrets 120D within a given time period.

[0047] Mobile devices 110A, 110B, and 110C are provided in a secure environment 105. In some embodiments, each mobile device is directly connected to a security server 130. For example, mobile device 110A can be connected to the security server 130 via a direct connection 150 (such as a Universal Serial Bus (USB) connection). In some embodiments, this can be achieved by installing a memory card with necessary data in mobile device 110A, scanning a QR code by mobile device 110A, or using a method such as Bluetooth. TM The mobile device 110A may be provided with short-range wireless technology such as Near Field Communication (NFC) or similar technology.

[0048] In some embodiments, mobile device 110A is registered in a security zone. Mobile device 110A can register in a security zone by downloading a CA certificate that defines the security zone. A security zone indicates the affiliation of the device with an entity or organization that manages and / or issues CA certificates. Mobile device 110A may be assigned to a remote administrator. In some embodiments, mobile device 110A is assigned to a remote administrator by loading a remote administrator profile login key sharing secret onto mobile device 110A, which may be the public key of the certificate of the remote administrator profile stored on HSM 140 of security server 130.

[0049] In some embodiments, applications 115A, 115B, and 115C for installation on the provided mobile devices 110A, 110B, and 110C may be stored on a security server 130 and transmitted to the mobile devices 110A, 110B, and 110C during provision. In some embodiments, applications 115A, 115B, and 115C may be available for download from an application distribution platform such as an app store or app market. Applications 115A, 115B, and 115C may be used by mobile devices 110A, 110B, and 110C to establish a secure connection to the security server 130 to communicate with the security server 130 to remotely manage one or more HSMs. If mobile devices 110A, 110B, and 110C download applications 115A, 115B, and 115C from an application distribution platform, the provision of mobile devices 110A, 110B, and 110C can be completed in a separate step within the secure environment 105. Applications 115A, 115B, and 115C on mobile devices 110A, 110B, and 110C may be PIN-protected by a remote administrator upon first application execution. Alternatively, the provided mobile devices 110A, 110B, and 110C may be protected by different PINs set by the remote administrator. Mobile device PINs may be required to conform to one or more security policies determined by the administrator of system 100. In some embodiments, applications 115A, 115B, and 115C may store shared secrets 120A, 120B, and 120C generated and encrypted by HSM 140 and transmitted to the respective mobile devices 110A, 110B, and 110C during provision. In some embodiments, shared secrets 120A, 120B, and 120C may include different key portions assigned to the respective mobile devices 110A, 110B, and 110C, which are combined to form a master key for accessing and managing the HSM. In some embodiments, shared secrets 120A, 120B, and 120C may be loaded onto mobile devices 110A, 110B, and 110C during provisioning while in secure environment 105. Shared secret 120D may be securely transferred to mobile devices 110A, 110B, and 110C after the mobile devices have been provided in secure environment 105 and subsequently transferred outside of secure environment 105.

[0050] In some embodiments, mobile devices 110A, 110B, and 110C are provided in a secure environment 105 and can be sent to a remote administrator outside the secure environment 105 and / or transported out of the secure environment 105 and physically delivered to the respective remote administrator.

[0051] Regarding Figure 1The embodiments described for System 100 can be implemented with any suitable logic, wherein the logic referred to herein may include any suitable hardware (e.g., a processor, an embedded controller, or an application-specific integrated circuit, etc.), software (e.g., an application, etc.), firmware, or any suitable combination of hardware, software, and firmware in the various embodiments.

[0052] Figure 2 This is a block diagram of an example system 200 for remote management of HSMs. As shown in the diagram, the example system 200 may include one or more modules for performing one or more tasks. As will be explained in more detail below, these modules may include an HSM management module 135 of a security server 130 and / or applications 115A, 115B, 115C running on corresponding mobile devices 110A, 110B, 110C. Although Figure 1 One or more modules in the application are shown as separate elements, but they can represent a single module or a part of an application.

[0053] In such Figure 1 As described in Figure 3 As further described in detail, after the mobile devices 110A, 110B, and 110C have been configured, they can be located away from the secure environment 105 and used remotely by their assigned remote administrators from outside the secure environment 105 to remotely manage the HSM. Applications 115A, 115B, and 115C loaded onto the respective mobile devices 110A, 110B, and 110C can be used to securely store their respective shared secrets 120A, 120B, and 120C, which are loaded onto their respective devices during or after provisioning. In some instances, the remote administrator of the mobile devices 110A, 110B, and 110C can execute their respective applications 115A, 115B, and 115C to establish a secure connection via network 210 to the security server 130 located in the secure environment 105. For example, a remote administrator of mobile device 110A can use application 115A to select parameters (e.g., the domain to be configured, the selection of shared secret 120A, the selection of commands, etc.) to generate an HSM command request for execution on an HSM in the specified domain. Application 115A can encrypt the HSM command request and securely send it to the HSM management module 135 of security server 130.

[0054] HSM management module 135 can receive and process one or more HSM command requests from mobile devices 110A, 110B, and 110C. In some embodiments, HSM management module 135 can verify the received HSM command requests received from mobile devices 110A, 110B, and 110C. In some examples, HSM management module 135 can instruct HSM 140 to decrypt encrypted requests and / or decrypt shared secrets 120A, 120B, and 120C received from mobile devices 110A, 110B, and 110C. HSM 140 can use the corresponding shared secret 120D stored in HSM 140 to decrypt encrypted requests and / or decrypt shared secrets 120A, 120B, and 120C. HSM management module 135 can then construct an HSM command based on the received HSM command request and send the command to a specified domain for execution by the target HSM, as specified in the HSM command request.

[0055] A designated domain (not shown) may receive commands from the HSM management module 135. The HSM management module 135 may send multiple commands from corresponding mobile devices 110A, 110B, and 110C. The target HSM of the designated domain may obtain shared secrets 120A, 120B, and 120C from the different commands received from the HSM management module 135, and may add the shared secrets 120A, 120B, and 120C to registers within the target HSM until a master key is formed. In some examples, the target HSM may perform logical operations (e.g., XOR) or other means of combining data to assemble the shared secrets 120A, 120B, and 120C (e.g., key portions) received from the different commands received from the HSM management module 135 to generate a master key, which can be used to execute commands received from the HSM management module 135. When the target HSM of the designated domain completes the execution of the commands, it sends the result back to the HSM management module 135. The HSM management module 135 can receive the results and generate messages indicating the results of commands executed by the target HSM to the corresponding mobile devices 110A, 110B, and 110C.

[0056] Regarding Figure 2 The embodiments described in System 200 can be implemented with any suitable logic, wherein the logic referred to herein may include any suitable hardware (e.g., a processor, an embedded controller, or an application-specific integrated circuit, etc.), software (e.g., an application, etc.), firmware, or any suitable combination of hardware, software, and firmware in various embodiments.

[0057] Now for reference Figure 3 According to an exemplary embodiment of the present invention, system 100 provides one or more mobile devices 110A, 110B, 110C. (See reference...) Figure 3The described process, in whole or in part, can be handled by Figure 1 The security server 130 in the secure environment 105 performs operations to provide one or more mobile devices 110A, 110B, and 110C. Within the secure environment 105, the mobile devices 110A, 110B, and 110C are provided one at a time. This can be achieved using direct connections 150 (such as USB connection, QR code scanning, NFC technology, or Bluetooth). TM (etc.) connect mobile devices 110A, 110B, 110C to security server 130 (one at a time) to provide mobile devices 110A, 110B, 110C.

[0058] At box 302, the method 300 for providing mobile devices includes registering mobile devices 110A, 110B, and 110C to a security zone. In some embodiments, mobile device 110A is registered in a security zone by downloading a CA certificate that defines the security zone on mobile device 110A. The CA certificate indicates the affiliation of a device such as mobile device 110A with an entity or organization that manages and / or issues CA certificates.

[0059] At block 304, the method 300 for providing a mobile device includes assigning a mobile device 110A to a remote administrator. In some embodiments, the HSM management module 135 may define or identify users and assign them to remote management profiles. In some embodiments, remote administrator profiles may be stored as a set of remote administrator profile objects. In some embodiments, remote management profile objects may be stored or contained on the HSM 140 of the security server 130. A remote management profile object may contain a remote management profile certificate and a private key corresponding to the public key in the certificate of the remote management profile. In some embodiments, the mobile device 110A is assigned to the remote administrator by loading the remote administrator profile login key secret.

[0060] At box 306, the method 300 for providing a mobile device includes loading a shared secret 120A onto a mobile device 110A. In some embodiments, the shared secret 120A is loaded onto the mobile device 110A during provision. In some embodiments, a user may request a security server 130 to send the shared secret 120A (e.g., an encrypted key portion, an encrypted signing key, etc.) via an application 115A running on the mobile device 110A. In some embodiments, the mobile device 110A may request a new shared secret 120A generated for that particular remote administrator via an application 115A running on the mobile device 110A. The new shared secret 120A may be encrypted by the security server 130 and sent to the mobile device 110A. This method may be repeated for each mobile device. For example, boxes 302 through 306 may be repeated for the mobile device 110B by connecting the mobile device 110B to the security server 130 using a direct connection 150, providing the mobile device 110B, downloading the application 115B, and loading the shared secret 120B generated and encrypted for the mobile device 110B. By using direct connection 150 to connect mobile device 110C to security server 130, providing mobile device 110C, downloading application 115C, and loading shared secret 120C generated and encrypted for mobile device 110C, repeating boxes 302 to 306 for mobile device 110C. Each mobile device 110A, 110B, 110C is provided by itself, because shared secrets 120A, 120B, 120C correspond to their respective mobile devices 110A, 110B, 110C.

[0061] Figure 3 The process flowchart is not intended to indicate that the operations of method 300 will be performed in any particular order, or that all operations of method 300 will be included in every case. Furthermore, method 300 may include any suitable number of additional operations.

[0062] Now for reference Figure 4 In block 402 of method 400, system 200 configured according to an exemplary embodiment of the present invention establishes a connection with security server 130. (See reference...) Figure 4 The described process, in whole or in part, can be provided by the process typically located in Figure 2Mobile devices 110A, 110B, and 110C, located outside the secure environment 105, execute HSMs for remote management. In some examples, application 115A on mobile device 110A establishes a connection to security server 130 via one or more networks 210. A remote administrator can open application 115A on mobile device 110A. Application 115A on mobile device 110A can be protected by a PIN set by the remote administrator when application 115A is first opened. In some embodiments, the remote administrator can specify a network address for accessing network applications running on security server 130. The remote administrator authenticates application 115A running on mobile device 110A, for example, through multi-factor authentication queries.

[0063] At block 404 of method 400, computer-executable instructions of application 115A, executed on mobile device 110A, generate an HSM command request for a target HSM of the domain. Application 115A facilitates a remote administrator to select the target HSM to configure from a list of available HSMs. The remote administrator can select a command to be executed on the target HSM, such as a LOADKEY command, and select a shared secret 120A required to execute that command on the target HSM. The shared secret 120A of mobile device 110A may include an encrypted key portion associated with the remote administrator's profile, an encrypted signing key, and / or an encrypted login key secret, loaded during and / or after the provision of mobile device 110A. Application 115A can use the remote administrator's selection to generate an HSM command request for a target HSM of a specified domain.

[0064] At block 406 of method 400, computer-executable instructions of application 115A executing on mobile device 110A encrypt the HSM command request. In some embodiments, application 115A encrypts the HSM command request with the public key of a CA certificate defining a security zone. Application 115A sends the encrypted HSM command request to security server 130 executing in security environment 105. In some examples, application 115A transmits the encrypted HSM command request to HSM management module 135 of security server 130.

[0065] At block 408 of method 400, the computer-executable instructions of application 115A receive a message from security server 130. For example, the message may include the result of an HSM command executed on a target HSM in a specified domain. In some examples, the message may display a positive or negative statement indicating the success or failure of the execution of the HSM command executed on the target HSM in the specified domain.

[0066] Figure 4The process flowchart is not intended to indicate that the operations of method 400 will be performed in any particular order, or that all operations of method 400 will be included in every case. Furthermore, method 400 may include any appropriate number of additional operations.

[0067] Now for reference Figure 5 At block 502 of method 500, the system 200 configured according to an exemplary embodiment of the present invention decrypts an HSM command request received from a mobile device such as 110A, 110B, or 110C. The HSM management module 135 can receive encrypted HSM command requests via a connection established by the corresponding applications 115A, 115B, 115C running on the mobile devices 110A, 110B, 110C, such as... Figure 3 As described above, HSM management module 135 can facilitate HSM 140 in decrypting requests received from mobile devices 110A, 110B, and 110C. For example, HSM 140 can decrypt received HSM command requests using a private key corresponding to the public key of the CA certificate defining the security zone. HSM management module 135 can facilitate the decryption of shared secrets 120A, 120B, and 120C received in the decryption request. HSM 140 can decrypt, for example, key portions associated with a remote administrator's profile, signing keys, and / or login keys, each of which can be encrypted independently of each other and double-encrypted using the public key of the CA certificate defining the security zone and the public key of the CA certificate for the remote administrator's profile. Under the guidance of the HSM management module 135, the HSM 140 can use the corresponding shared secret 120D stored on the HSM, such as a private key corresponding to the public key of the CA certificate defining the security zone, to decrypt the shared secrets 120A, 120B, and 120C of HSM command requests received from mobile devices 110A, 110B, and 110C. The HSM 140 can also use the shared secret 120D, such as a private key corresponding to the public key of the CA certificate in the remote administrator's profile, to decrypt the shared secrets 120A, 120B, and 120C of HSM command requests received from mobile devices 110A, 110B, and 110C.

[0068] At block 504 of method 500, computer-executable instructions of HSM management module 135, executed on security server 130, generate HSM commands for the domain to be configured. The HSM commands are generated based on an HSM command request received from mobile device 110A. The HSM commands include a key portion assigned to a remote administrator, decrypted by HSM 140. The HSM commands may include the domain to be configured as specified by the remote administrator when the HSM command request is generated. The HSM commands can be generated to be executed by the target HSM of the domain to be configured.

[0069] At block 506 of method 500, computer-executable instructions of the HSM management module 135, executed on security server 130, transmit HSM commands to the domain. In some embodiments, the key portion assigned to a remote administrator may be wrapped with a transport key negotiated between the target HSM being configured and security server 130.

[0070] At block 508 of method 500, computer-executable instructions of the HSM management module 135 executing on the security server 130 transmit a message to the mobile devices 110A, 110B, 110C that transmitted the HSM command request. In some embodiments, a message is generated in response to receiving the result of an HSM command executed by a target HSM of the domain being configured. The result of the target HSM is transmitted to the HSM management module 135 of the security server 130, and the message transmitted to the mobile device contains a positive or negative indication based on the result received from the target HSM of the domain being configured.

[0071] In some embodiments, the security server 130 receives encrypted requests from different mobile devices 110A, 110B, 110C associated with correspondingly assigned remote administrators. The HSM management module 135 of the security server 130 verifies the requests and constructs HSM commands using information from the corresponding requests received from the remote administrators' mobile devices 110A, 110B, 110C. Each HSM command is signed using a signing key obtained from the corresponding request and sent to the domain specified by the corresponding request. The command is executed by the target HSM in the specified domain. The target HSM receives HSM commands based on HSM command requests received by the security server 130 from all designated remote administrators. The target HSM in the specified domain assembles key portions from each remote administrator until a master key is formed using the collected key portions. In some examples, key portions from each command received from the target HSM are added to registers within the target HSM. The key portions stored in the registers of the target HSM can be combined using logical operations (e.g., XOR) or other means of combining data to generate the master key. The HSM command is executed by the target HSM when the master key is completed or formed. The result of the command executed by the target HSM is sent back to the HSM management module 135. The HSM management module 135 generates a message indicating the result received from the domain and sends the message to the corresponding mobile devices 110A, 110B, and 110C.

[0072] In some embodiments, an HSM management module 135 executing on security server 130 detects unusual or unauthorized access from a remote administrator's mobile devices. For example, HSM management module 135 receives multiple invalid requests from the same IP address. HSM management module 135 identifies mobile devices 110A, 110B, and 110C associated with the IP address and determines that the number of invalid requests exceeds a specified threshold. Mobile devices 110A, 110B, and 110C may be added to a restricted list or a denied list. In some examples, mobile devices 110A, 110B, and 110C are added to the list within a specified time period (e.g., 1 hour). In some embodiments, access to security server 130 by mobile devices 110A, 110B, and 110C is denied until the administrator removes mobile devices 110A, 110B, and 110C from the restricted list or denied list. In some embodiments, if mobile devices 110A, 110B, and 110C are on a restricted or denied list, then mobile devices 110A, 110B, and 110C can be remotely erased or the certificate of the remote administrator's profile can be revoked, thereby removing access from security server 130 by mobile devices 110A, 110B, and 110C. In some embodiments, if mobile devices 110A, 110B, and 110C are suspected of being compromised or compromised, then mobile devices 110A, 110B, and 110C can be remotely erased, or the certificate of the remote administrator's profile can be revoked by HSM management module 135 based on one or more security policies or by the system administrator. If mobile devices 110A, 110B, and 110C have been erased or the certificate of the remote administrator's profile has been revoked, then it will be necessary to bring mobile devices 110A, 110B, and 110C back to the security environment 105 to be provided again, or it will be necessary to provide the remote administrator with a new mobile device in the security environment 105 and deliver it to the remote administrator to enable him to gain access to the security server 130.

[0073] Figure 5 The process flowchart is not intended to indicate that the operations of method 500 will be performed in any particular order, or that all operations of method 500 will be included in every case. Furthermore, method 500 may include any appropriate number of additional operations.

[0074] Now go to Figure 6Computer system 600 is generally illustrated according to embodiments of the present invention. Computer system 600 may be an electronic computer architecture including and / or employing any number of computing devices and networks and combinations thereof, which utilize various communication technologies as described herein. Computer system 600 may be easily scalable, extensible, and modular, with the ability to change to different services or reconfigure some features independently of others. Computer system 600 may be, for example, a server, desktop computer, laptop computer, tablet computer, or smartphone. In some examples, computer system 600 may be a cloud computing node. Computer system 600 may be described in the general context of computer system executable instructions, such as program modules executed by the computer system. Typically, program modules may include routines, programs, objects, components, logic, data structures, etc., that perform specific tasks or implement specific abstract data types. Computer system 600 may be practiced in a distributed cloud computing environment, where tasks are performed by remote processing devices linked via a communication network. In a distributed cloud computing environment, program modules may reside in local and remote computer system storage media, including memory storage devices.

[0075] like Figure 6 As shown, the computer system 600 has one or more central processing units (CPUs) 601a, 601b, 601c, etc. (collectively referred to as, or collectively referred to as, processor 601). Processor 601 can be a single-core processor, a multi-core processor, a computing cluster, or any number of other configurations. Processor 601, also referred to as processing circuitry, is coupled to system memory 603 and various other components via system bus 602. System memory 603 may include read-only memory (ROM) 604 and random access memory (RAM) 605. ROM 604 is coupled to system bus 602 and may include a basic input / output system (BIOS) that controls certain basic functions of computer system 600. RAM is read-write memory coupled to system bus 602 for use by processor 601. System memory 603 provides temporary memory space for the operation of the instructions during operation. System memory 603 may include random access memory (RAM), read-only memory, flash memory, or any other suitable memory system.

[0076] Computer system 600 includes an input / output (I / O) adapter 606 and a communication adapter 607 coupled to a system bus 602. I / O adapter 606 may be a Small Computer System Interface (SCSI) adapter that communicates with a hard disk 608 and / or any other similar component. I / O adapter 606 and hard disk 608 are collectively referred to herein as mass storage device 610.

[0077] Software 611 for execution on computer system 600 may be stored in mass storage device 610. Mass storage device 610 is an example of a tangible storage medium readable by processor 601, wherein software 611 is stored as instructions executed by processor 601 to operate computer system 600, such as those described herein with reference to the accompanying drawings. Examples of computer program products and the execution of such instructions are discussed in more detail here. Communication adapter 607 interconnects system bus 602 with network 612, which may be an external network, enabling computer system 600 to communicate with other such systems. In one embodiment, a portion of system memory 603 and mass storage device 610 jointly store an operating system, which may be any suitable operating system, such as z / OS or AIX from IBM, to coordinate... Figure 6 The functions of the various components shown are illustrated.

[0078] Additional input / output devices are shown connected to system bus 602 via display adapter 615 and interface adapter 616. In one embodiment, adapters 606, 607, 615, and 616 may be connected to one or more I / O buses that are connected to system bus 602 via an intermediate bus bridge (not shown). Display 619 (e.g., screen or display monitor) is connected to system bus 602 via display adapter 615, which may include a graphics controller to improve the performance of graphics-intensive applications and video controllers. Keyboard 621, mouse 622, speaker 623, etc., may be interconnected to system bus 602 via interface adapter 616, which may include, for example, a super I / O chip integrating multiple device adapters into a single integrated circuit. Suitable I / O buses for connecting peripheral devices such as hard disk controllers, network adapters, and graphics adapters typically include common protocols such as Peripheral Component Interconnect (PCI). Therefore, as Figure 6 The computer system 600 configured therein includes processing capabilities in the form of a processor 601, storage capabilities including system memory 603 and mass storage device 610, input devices such as a keyboard 621 and a mouse 622, and output capabilities including a speaker 623 and a display 619.

[0079] In some embodiments, the communication adapter 607 may use any suitable interface or protocol (such as an Internet Minicomputer System Interface) to transmit data. The network 612 may be a cellular network, radio network, wide area network (WAN), local area network (LAN), or the Internet. External computing devices may connect to the computer system 600 via the network 612. In some examples, the external computing device may be an external network server or a cloud computing node.

[0080] It should be understood that Figure 6 The block diagram is not intended to indicate what computer system 600 should include. Figure 6 All the components shown, in contrast, computer system 600 may include Figure 6 Any suitable fewer or additional components not shown herein (e.g., additional memory components, embedded controllers, modules, additional network interfaces, etc.). Furthermore, the embodiments described herein with respect to computer system 600 can be implemented with any suitable logic, wherein the logic mentioned herein can include any suitable hardware (e.g., processor, embedded controller, or application-specific integrated circuit, etc.), software (e.g., applications, etc.), firmware, or any suitable combination of hardware, software, and firmware in various embodiments.

[0081] This invention can be a system, method, and / or computer program product at any possible level of technical detail integration. The computer program product may include one or more computer-readable storage media having computer-readable program instructions thereon for causing a processor to perform aspects of the invention.

[0082] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable optical disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices such as punch cards or recessed structures with instructions recorded thereon, and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0083] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a suitable computing / processing device, or via a network, such as the Internet, a local area network (LAN), a wide area network (WAN), and / or a wireless network, to an external computer or external storage device. The network may include copper cables, optical fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the respective computing / processing device.

[0084] Computer-readable program instructions for performing the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, integrated circuit configuration data, or source code or object code written in any combination of one or more programming languages ​​(including object-oriented programming languages ​​such as Smalltalk, C++, etc.) and procedural programming languages ​​(such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, to perform aspects of this invention, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute computer-readable program instructions to personalize the electronic circuits by utilizing the status information of the computer-readable program instructions.

[0085] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0086] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other device to operate in a particular manner, such that the computer-readable storage medium in which the instructions are stored includes an article of writing comprising instructions for implementing aspects of the functions / actions specified in one or more blocks of a flowchart and / or block diagram.

[0087] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus or other device, perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0088] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions comprising one or more executable instructions for implementing a specified logical function. In some alternative embodiments, the functions indicated in the blocks may occur in a non-consecutive order as shown in the figures. For example, two blocks shown consecutively may actually be executed substantially simultaneously, or these blocks may sometimes be executed in reverse order, depending on the functions involved. It will also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs the specified function or action or executes a combination of dedicated hardware and computer instructions.

[0089] Various embodiments of the invention have been described for illustrative purposes, but are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terminology used herein has been chosen to best explain the principles of the embodiments, their practical application, or improvements to existing technologies on the market, or to enable others skilled in the art to understand the embodiments described herein.

[0090] Various embodiments of the invention are described herein with reference to the accompanying drawings. Alternative embodiments of the invention may be devised without departing from the scope thereof. In the following description and drawings, various connections and positional relationships (e.g., above, below, adjacent, etc.) are illustrated between elements. Unless otherwise stated, these connections and / or positional relationships may be direct or indirect, and the invention is not intended to be limiting in this respect. Thus, coupling of entities may refer to direct or indirect coupling, and positional relationships between entities may be direct or indirect positional relationships. Furthermore, the various tasks and process steps described herein may be incorporated into a more comprehensive procedure or process with additional steps or functionality not described in detail herein.

[0091] The following definitions and abbreviations are used to interpret the claims and specification. As used herein, the terms “comprising,” “including,” “having,” “containing,” or any other variations thereof are intended to cover a non-exclusive inclusion. For example, a composition, mixture, process, method, article, or apparatus that comprises a list of elements is not necessarily limited to those elements, but may include other elements not expressly listed or inherent to such compositions, mixtures, processes, methods, articles, or apparatus.

[0092] Additionally, the term "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments or designs. The terms "at least one" and "one or more" can be understood to include any integer greater than or equal to one, i.e., one, two, three, four, etc. The term "multiple" can be understood to include any integer greater than or equal to two, i.e., two, three, four, five, etc. The term "connection" can include both indirect "connection" and direct "connection."

[0093] The terms “about,” “substantially,” “approximately,” and variations thereof are intended to include a degree of error associated with a measurement of a specific quantity based on the equipment available at the time of filing this application. For example, “about” may include a range of ±8%, 5%, or 2% of a given value.

[0094] For the sake of brevity, conventional techniques related to the manufacture and use of aspects of the present invention may or may not be described in detail herein. In particular, various aspects of the computing systems and specific computer programs used to implement the various technical features described herein are well known. Therefore, for the sake of brevity, many conventional implementation details are only briefly mentioned or omitted entirely herein, without providing well-known system and / or process details.

Claims

1. A computer-implemented method, comprising: The processor of the computing device receives a command request from the mobile device (110A), the command request including an encrypted key portion and an encrypted signature key; The command request is decrypted by the hardware security module HSM (140) using a key associated with the security zone of the mobile device; The HSM decrypts the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using a key associated with a security zone of the mobile device and a key associated with a remote administrator, who is associated with the mobile device. For a domain with a target HSM and based on the command request, a command is generated using the decrypted key portion and the decrypted signature key; as well as The command is transmitted to the domain for execution by the target HSM.

2. The computer-implemented method of claim 1, wherein the command request further includes an encrypted login key associated with the remote administrator, and the computer-implemented method further includes: The encrypted login key is decrypted by the HSM (140) to generate a decrypted login key, wherein decrypting the encrypted login key includes using a key associated with a security zone of the mobile device and a key associated with the remote administrator, who is associated with the mobile device; as well as The decrypted login key is sent to the domain along with the command.

3. The computer-implemented method according to claim 1 further includes: The processor of the computing device receives a second command request from the second mobile device (110B), the second command request including a second encrypted key portion and a second encrypted signature key; The HSM (140) decrypts the second command request using a key associated with the security zone of the mobile device (110A); The HSM decrypts the second encrypted key portion and the second encrypted signature key to generate a second decrypted key portion and a second decrypted signature key, wherein decrypting the second encrypted key portion and the second encrypted signature key includes using a key associated with the security zone and different keys associated with different remote administrators, the different remote administrators being associated with the second mobile device; For a domain having the target HSM, a second command is generated using the second decrypted key portion and the second decrypted signature key; as well as The second command is transmitted to the domain.

4. The computer-implemented method of claim 3, wherein the decrypted key portion and the second decrypted key portion are part of a master key associated with a target HSM of the domain.

5. The computer-implemented method of claim 1, further comprising providing the mobile device (110A) by registering the mobile device in the security zone and associating the mobile device with the remote administrator.

6. The computer-implemented method of claim 1 further includes signing the command using the decrypted signing key before transmitting the command to the domain for execution by the target HSM.

7. The computer-implemented method of claim 1 further includes transmitting a message to the mobile device (110A) based on a result received from the domain.

8. A computer system, comprising: One or more processors for executing computer-readable instructions, the computer-readable instructions controlling the one or more processors to perform operations, the operations including: Receive a command request from the mobile device (110A), the command request including an encrypted key portion and an encrypted signature key; The command request is decrypted by the hardware security module HSM (140) using a key associated with the security zone of the mobile device; The HSM decrypts the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using a key associated with a security zone of the mobile device and a key associated with a remote administrator, who is associated with the mobile device. For a domain with a target HSM and based on the command request, a command is generated using the decrypted key portion and the decrypted signature key; and The command is transmitted to the domain for execution by the target HSM.

9. The computer system of claim 8, wherein the command request further includes an encrypted login key associated with the remote administrator, and the operation further includes: The encrypted login key is decrypted by the HSM (140) to generate a decrypted login key, wherein decrypting the encrypted login key includes using a key associated with a security zone of the mobile device and a key associated with the remote administrator, who is associated with the mobile device; as well as The decrypted login key is sent to the domain along with the command.

10. The computer system of claim 8, wherein the operation further comprises: Receive a second command request from the second mobile device (110B), the second command request including a second encrypted key portion and a second encrypted signature key; The HSM (140) decrypts the second command request using a key associated with the security zone of the mobile device (110A); The HSM decrypts the second encrypted key portion and the second encrypted signature key to generate a second decrypted key portion and a second decrypted signature key, wherein decrypting the second encrypted key portion and the second encrypted signature key includes using a key associated with the security zone and different keys associated with different remote administrators, the different remote administrators being associated with the second mobile device; For a domain having the target HSM, a second command is generated using the second decrypted key portion and the second decrypted signature key; as well as The second command is transmitted to the domain.

11. The computer system of claim 10, wherein the decrypted key portion and the second decrypted key portion are part of a master key associated with a target HSM of the domain.

12. The computer system of claim 8, wherein the operation further comprises providing the mobile device by registering the mobile device in the security zone and associating the mobile device with the remote administrator (110A).

13. The computer system of claim 8, wherein the operation further comprises signing the command using the decrypted signing key before transmitting the command to the domain for execution by the target HSM.

14. The computer system of claim 8, wherein the operation further includes transmitting a message to the mobile device (110A) based on a result received from the domain.

15. A computer program product comprising a computer-readable storage medium having program instructions embodied therein, the program instructions being executable by one or more processors to cause the one or more processors to perform operations, the operations including: Receive a command request from the mobile device (110A), the command request including an encrypted key portion and an encrypted signature key; The command request is decrypted by the hardware security module HSM (140) using a key associated with the security zone of the mobile device; The HSM decrypts the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using a key associated with a security zone of the mobile device and a key associated with a remote administrator, who is associated with the mobile device. For a domain with a target HSM and based on the command request, a command is generated using the decrypted key portion and the decrypted signature key; as well as The command is transmitted to the domain for execution by the target HSM.

16. The computer program product of claim 15, wherein the command request further includes an encrypted login key associated with the remote administrator, and the operation further includes: The encrypted login key is decrypted by the HSM (140) to generate a decrypted login key, wherein decrypting the encrypted login key includes using a key associated with a security zone of the mobile device and a key associated with the remote administrator, who is associated with the mobile device; as well as The decrypted login key is sent to the domain along with the command.

17. The computer program product according to claim 15, further comprising: Receive a second command request from the second mobile device (110B), the second command request including a second encrypted key portion and a second encrypted signature key; The HSM (140) decrypts the second command request using a key associated with the security zone of the mobile device (110A); The HSM decrypts the second encrypted key portion and the second encrypted signature key to generate a second decrypted key portion and a second decrypted signature key, wherein decrypting the second encrypted key portion and the second encrypted signature key includes using a key associated with the security zone and different keys associated with different remote administrators, the different remote administrators being associated with the second mobile device; For a domain having the target HSM, a second command is generated using the second decrypted key portion and the second decrypted signature key; as well as The second command is transmitted to the domain.

18. The computer program product of claim 17, wherein the decrypted key portion and the second decrypted key portion are part of a master key associated with a target HSM of the domain.

19. The computer program product of claim 15, further comprising providing the mobile device by registering the mobile device in the security zone and associating the mobile device with the remote administrator (110A).

20. The computer program product of claim 15, further comprising signing the command using the decrypted signing key before transmitting the command to the domain for execution by the target HSM.

21. The computer program product of claim 15, further comprising transmitting a message to the mobile device (110A) based on a result received from the domain.

22. A computer-implemented method, comprising: The processor of the computing device receives a load key request, including an encrypted key portion and an encrypted signing key, from a mobile device (110A) associated with a remote administrator; Verify the loading key request from the mobile device; The encrypted key portion and the encrypted signature key are decrypted to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using a private key corresponding to the public key of the certificate authorization CA certificate used for the secure zone and a private key corresponding to the public key of the CA certificate of the remote administrator's profile. A load key command is established for the domain specified in the load key request, wherein the load key command includes the decrypted key portion and is signed using the decrypted signature key; as well as The command to load the key is transmitted to the domain for execution by the target hardware security module (HSM) of the domain.

23. The computer-implemented method of claim 22, wherein the load key request is encrypted using a public key of a CA certificate for the security zone, and verifying the load key request includes decrypting the load key request using a private key corresponding to the public key of the CA certificate for the security zone.

24. A computer-implemented method, comprising: The processor of the secure computing device receives an encrypted hardware security module (HSM) command request, which includes an encrypted key portion and an encrypted signature key, from a mobile device (110A) associated with a remote administrator. Decrypt the encrypted HSM command request from the mobile device; The HSM (140) of the secure computing device decrypts the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key; Based at least in part on the decrypted key portion and the decrypted signature key, an HSM command corresponding to an encrypted HSM command request for a specified domain is generated; as well as The HSM command is transmitted to the designated domain for execution by the target HSM in the designated domain.

25. The computer-implemented method of claim 24 further includes transmitting a message to the mobile device (110A) based on a result received from the designated domain.

Citation Information

Patent Citations

  • System and method for generating safety unit key based on reliable execution environment

    CN105790938A

  • Systems and methods for securing data

    CN107533616A