Method and device for enhancing security of hardware security module by using artificial intelligence

By introducing artificial intelligence into the hardware security module, monitoring and analyzing application service requests, identifying and blocking abnormal behaviors, the problem of HSM being difficult to identify and respond to security threats in the face of complex cyber attacks is solved, and stronger security defense and compliance support is achieved.

CN120068097APending Publication Date: 2025-05-30MARVELL ASIA PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411726904.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-04-30
Filing Date
2024-11-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing hardware security modules (HSMs) are difficult to identify and deal with security threats and vulnerabilities when facing complex cyber attacks, especially if system administrator credentials are leaked.

Method used

Using hardware security modules supported by artificial intelligence (AI) are trained to monitor and analyze service requests from applications, identify potential security threats that are abnormal behavior or deviate from normal mode, and prevent related encryption operations.

Benefits of technology

Real-time security threat visibility to HSM is achieved, providing an additional layer of security, enhancing cyber attack defense capabilities, and helping to meet compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068097A_ABST
    Figure CN120068097A_ABST
Patent Text Reader

Abstract

A new approach is presented that accounts for systems and methods that use artificial intelligence (AI) to support security enhancements of hardware security modules (HSMs). Specifically, one or more AI models are trained using a dataset of the HSM to establish a pattern of normal / typical behavior for each of a plurality of applications requesting a service of the HSM. When the HSM is running, an AI security module running on the HSM is configured to use the one or more trained AI models to continuously monitor and analyze service requests from the plurality of applications to the HSM to identify security vulnerabilities / threats. If the AI model detects an anomaly or deviates from its normal behavior pattern, the AI security module marks the application as a potential security threat and prevents the HSM from performing the encryption operation requested by the application.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related Applications

[0002] This application is a non - provisional application and claims the benefit and priority of Provisional Application No. 63 / 604,180, filed on November 29, 2023, which is incorporated herein by reference in its entirety. BACKGROUND OF THE INVENTION

[0004] A Hardware Security Module (HSM) is a physical computing device used to protect and manage the secrets and confidential information (e.g., digital keys and data) of users who use the HSM for applications. The HSM plays a crucial role in providing a secure environment for various cryptographic operations such as encryption and decryption, digital signatures, strong authentication, and other cryptographic functions. The HSM is mainly used to generate, export, store, and manage cryptographic keys, secure computations through encryption and decryption, and protect users' sensitive data from unauthorized access and attacks.

[0005] HSMs typically have certain security protection measures to prevent tampering from cyberattacks. However, as the landscape of cybersecurity threats continues to evolve, these security protection measures may be insufficient to identify complex security threats and vulnerabilities in the HSM. For example, the HSM may not have a solution for recently occurring cyberattacks, and if the credentials of the system administrator are compromised, the HSM may not be able to detect the cyberattack.

[0006] The above examples of the related art and their related limitations are intended to be illustrative and not exclusive. Other limitations of the related art will become apparent by reading the specification and studying the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] When read in conjunction with the Figure 1 accompanying drawings, the aspects of the present disclosure can be best understood from the following detailed description. It should be noted that, in accordance with standard practice in the industry, the various features are not drawn to scale. In fact, the dimensions of the various features may be arbitrarily increased or decreased for the clarity of discussion.

[0008] Figure 1 An example of a schematic diagram of a system for enhancing HSM security with artificial intelligence support according to an aspect of the present embodiment is depicted.

[0009] Figure 2 An example of a flowchart of a process for enhancing HSM security with artificial intelligence support according to an aspect of the present embodiment is depicted. DETAILED DESCRIPTION

[0010] Numerous different embodiments or examples for implementing different features of the subject matter are provided below. Specific examples of components and arrangements are described below to simplify the present disclosure. Of course, these are merely examples and are not intended to be limiting. Additionally, the present disclosure may repeat reference numerals and / or letters in the various examples. Such repetition is for simplicity and clarity purposes and does not in itself dictate a relationship between the various embodiments and / or configurations discussed.

[0011] Before describing the various embodiments in more detail, it should be understood that the embodiments are not restrictive as the elements in these embodiments can vary. It should also be understood that the elements of a particular embodiment described and / or illustrated herein can be readily separated from the particular embodiment and can optionally be combined with or substituted for elements in any of several other embodiments. It should further be understood that the terms used herein are for the purpose of describing certain concepts and that the terms are not intended to be limiting. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood in the field to which the embodiments belong.

[0012] A new method is proposed that considers systems and methods for enhancing the security of a hardware security module (HSM) using artificial intelligence (AI). Specifically, a dataset of the HSM is used to train one or more AI models to establish a pattern of normal / typical behavior for each of multiple applications (users of the HSM) that request services from the HSM. When the HSM is running, an AI security module running on the HSM is configured to continuously monitor and analyze service requests from the multiple applications to the HSM using one or more trained AI models to identify security vulnerabilities / threats. If the AI model detects an anomaly or deviation from its normal behavior pattern, the AI security module marks the application as a potential security threat and prevents the HSM from performing the cryptographic operations requested by the application.

[0013] By continuously monitoring the service requests of applications, the proposed method provides real-time visibility into security vulnerabilities and threats against the HSM. Since the HSM is used to protect and process sensitive data of applications / users, running an AI model on the HSM provides an additional layer of security for users and makes it more difficult for network attackers to tamper with or compromise the HSM. Additionally, the AI-driven HSM can help meet the compliance requirements of the HSM.

[0014] Figure 1An example of a schematic diagram of a system 100 with enhanced security of an HSM supported by artificial intelligence is depicted. Although these schematic diagrams describe the components as functionally independent, this description is for illustrative purposes only. It is obvious that the components depicted in this figure can be arbitrarily combined or divided into separate software, firmware, and / or hardware components. Additionally, it is equally obvious that regardless of how these components are combined or divided, they can be executed on the same host or multiple hosts, and multiple hosts among them can be connected through one or more networks.

[0015] In Figure 1 the example, system 100 includes a basic I / O (BIO) module 104, a key management and encryption operation module 106, a secure storage device 108, and an AI security module 110. System 100 and its components operate on a hardware security module (HSM) 102, which is a multi-chip embedded hardware / firmware encryption module with software, firmware, hardware, or another component for implementation purposes. In some embodiments, HSM 102 is certified according to Federal Information Processing Standards (FIPS) 140-2 levels 2 and 3 for performing secure key management encryption (crypto) operations. In some embodiments, HSM 102 is pre-configured with default networks and authentication credentials such that HSM 102 can be compatible with FIPS / Common Criteria / PCI for key management and encryption operations. In some embodiments, the FIPS-certified HSM 102 includes one or more processors and storage units (not shown). In some embodiments, one or more processors include a multi-core processor and a secure processor, where the secure processor is configured to perform encryption operations using a hardware accelerator with embedded software implementing security algorithms.

[0016] In Figure 1 the example, BIO module 104 is configured to accept multiple service requests from multiple applications / users to HSM 102, where each of the multiple applications can be, but is not limited to, cloud-based user applications, for example, user applications hosted by a network service such as Amazon Web Services (AWS). Here, BIO module 104 communicates with the multiple applications through a network (not shown) following certain communication protocols such as the TCP / IP protocol. Such a network can be, but is not limited to, the Internet, an intranet, a wide area network (WAN), a local area network (LAN), a wireless network, Bluetooth, WiFi, a mobile communication network, or any other network type.

[0017] In some embodiments, the BIO module 104 is configured to parse each of the received service requests to identify the type of service requested by a particular application. Here, the types of services requested include, but are not limited to, key generation, key export, key deletion, secure key and data storage, and encryption (e.g., encryption and decryption) operations on keys and data. The BIO module 104 then calls the key management and encryption operation module 106 to the appropriate handler / component to process the particular type of service requested by the application and the data embedded in or pointed to by the service request. Once the key management and encryption operation module 106 has processed the service request, the BIO module 104 can compose a response including the processing result and transmit the response back to the application that sent the service request.

[0018] In Figure 1 an example, the key management and encryption operation module 106 is configured to perform key management or encryption operations / services according to the type of service requested by each of the multiple applications. For non-limiting examples, the key management or encryption operations can be, but are not limited to, generating new keys, storing keys in the secure storage device 108, exporting keys back to the application, deleting existing keys from the secure storage device 108, using keys to encrypt or decrypt data, and storing the encrypted or decrypted data in the secure storage device 108. The key management and encryption operation module 106 then provides the processing result (e.g., the generated key) back to the requesting application through the BIO module 104. In some embodiments, the key management and encryption operation module 106 is configured to stop or abort the key management or encryption operation if an alert for a potential security hazard is raised for a particular operation and / or application for the requested service. In such a case, the key management and encryption operation module 106 will notify the requesting application through the BIO module 104 that its service request has been rejected.

[0019] In Figure 1 an example, the secure storage device 108 is configured to maintain various types of information / data associated with multiple applications in a secure environment. Such information includes, but is not limited to, keys, encrypted data, decrypted data, and any other confidential or proprietary information of each of the multiple applications. In some embodiments, the secure storage device 108 includes multiple types of storage devices, including but not limited to dynamic random access memory (DRAM) and flash memory for key and data storage, ferroelectric RAM (FRAM) for storing critical logs, and eFuse for one-time key writing that cannot be erased, etc.

[0020] In some embodiments, the BIO module 104 is configured to also send each of the multiple service requests to the AI security module 110 for security risk analysis. InFigure 1 In the example, the AI security module 110 is configured to continuously monitor and analyze each of a plurality of service requests received by the HSM 102 to identify security risks associated with service requests from a specific application via one or more AI models. Here, each of the one or more AI models is a software component that applies one or more algorithms to data to identify patterns, make predictions, or make decisions. In some embodiments, the one or more AI models include an anomaly detection model 112 that uses one or more statistical methods or machine learning algorithms to detect anomalies in the data. This model does not rely on predefined rules or patterns and can detect previously unseen threats such as zero-day attacks. In some embodiments, the one or more AI models include a behavior analysis model 114 that establishes a baseline / pattern of normal behavior and then analyzes deviations from that pattern through service requests to detect suspicious activities. This model relies on predefined rules that make it more suitable for known or internal threats or abuse patterns. By combining both the anomaly detection model and the behavior analysis model, the AI security module 110 significantly enhances the overall security of the HSM 102.

[0021] In some embodiments, before the one or more AI models are deployed / loaded into the AI security module 110, the one or more AI models are pre-trained in advance using one or more large datasets from a plurality of service requests from each application to the HSM 102 in the applications that use the service. Here, the training of the one or more AI models is a process of teaching the AI models to perform one or more tasks by exposing the AI models to large datasets. In some embodiments, the datasets used to train the one or more AI models include, but are not limited to, request log volumes from multiple applications, transactions performed on the applications, and other historical security-related data of the HSM 102. In some embodiments, the AI security module 110 is configured to continuously train the one or more AI models using the data received after the one or more AI models have been deployed (e.g., service requests of an application) in order to maintain the accuracy of the one or more AI models and update them to the latest after deployment.

[0022] During training, one or more models analyze a dataset to learn about anomalies and identify / establish behavioral patterns associated with each of multiple applications for use by the application during the lifecycle of cryptographic operations using one or more functions and services in the HSM 102. For example, the behavioral patterns associated with an application may include one or more of the following: the distribution of multiple service requests sent by the application over a specific period (e.g., days, months, years, or since start of use), the type and / or frequency of services requested by the service requests (e.g., the frequency of requests to export or delete keys), how many service requests have been previously rejected, etc. The behavioral patterns establish a baseline / threshold for "normal" behavior for each application using the HSM 102, where the AI security module 110 can utilize such behavioral patterns to predict potential security threats via anomaly detection and behavioral analysis of the application.

[0023] Utilizing one or more AI models, the AI security module 110 is configured to identify one or more anomalies, e.g., security risks and vulnerabilities associated with service requests from an application, or if a service request deviates from the application's behavioral pattern by more than a specific threshold. In some embodiments, the threshold may be specified or defined by a user. For example, if the application has just requested the same key in the previous moment, or has requested the same key multiple times in a short period, the AI security module 110 may consider a service request from the application to generate or export a master key to be suspicious, indicating that the application may have been compromised or hijacked by an attacker. For example, if the application requests encryption or decryption of data multiple times in a short period, the AI security module 110 may consider the application to be suspicious.

[0024] If an anomaly or deviation is detected in a service request of an application, the AI security module 110 may send an alert to the key management and cryptographic operations module 106 to stop the execution of the key management or cryptographic operations requested by the application. In some embodiments, the alert may trigger a tamper protection mechanism of the key management and cryptographic operations module 106 to protect existing user keys and data from being accessed or tampered with by the application. In some embodiments, the key management and cryptographic operations module 106 is configured to block any future service requests from the application if an alert is received. In some embodiments, the key management and cryptographic operations module 106 is configured to notify the administrator, user, owner, or host of the application via the BIO module 104 that the application may have been compromised by an attacker to initiate a cyberattack.

[0025] Figure 2Flowchart 200 depicts an example of a process for enhancing HSM security with the support of artificial intelligence. Although, for illustrative purposes, the figure describes the functional steps in a particular order, these processes are not limited to any specific order or step arrangement. Those skilled in the relevant art will understand that the various steps depicted in the figure can be omitted, rearranged, combined, and / or adapted in various ways.

[0026] In Figure 2 the example of, flowchart 200 begins at block 202, where a service request from an application is received and provided for both key management or encryption operations and security risk analysis of the application. Flowchart 200 continues to step 204, where key management or encryption operations are performed according to the service request of the application. Flowchart 200 continues to step 206, where, based on one or more AI models, if the service request has an anomaly or deviates from the behavior pattern of the application by more than a specific threshold, the service request is analyzed to identify one or more security risks and vulnerabilities associated with the service request from the application. Flowchart 200 ends at step 208, where, once an alert that one or more security risks and vulnerabilities have been identified is received, the key management or encryption operations requested by the application are stopped.

[0027] The foregoing description of the various embodiments of the claimed subject matter is provided for purposes of illustration and description. It is not intended to be exhaustive or to limit the claimed subject matter to the precise forms disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art. The embodiments were chosen and described in order to best describe the principles of the invention and its practical application, thereby enabling others skilled in the relevant art to understand the claimed subject matter, the various embodiments suitable for the particular purposes contemplated, and the various modifications.

Claims

1. A system running on a hardware security module HSM, comprising: An I / O module configured to accept a service request from an application to the HSM, and provide the service request from the application to a key management and cryptographic operation module and an artificial intelligence AI security module, wherein the key management and cryptographic operation module is used for key management or cryptographic operation, and the AI ​​security module is used for security analysis of the application; The key management and encryption operation module is configured to perform the key management or encryption operation according to the service request of the application; and The AI ​​security module is configured to: analyzing the service request received by the HSM to identify one or more security risks and vulnerabilities associated with the service request from the application if the service request has an anomaly or deviates from a behavior pattern of the application by more than a certain threshold, according to one or more AI models; and If the one or more security risks and vulnerabilities are identified, an alert is sent to the key management and cryptographic operation module to stop performing the key management or cryptographic operation requested by the application.

2. The system of claim 1, wherein: The I / O module is configured to identify a type of service requested by an application to be performed by the HSM.

3. The system of claim 1, wherein: The I / O module is configured to, once the service request has been processed, compose a response including a processing result and transmit the response back to the application that sent the service request.

4. The system of claim 1, wherein: The I / O module is configured to notify the application that the service request has been denied if the alert for the service request of the application is received.

5. The system of claim 1, wherein: The key management or cryptographic operation is one of: generating a key, storing the key to a secure storage device, exporting the key back to the application, deleting an existing key from the secure storage device, using the key to encrypt or decrypt data, and storing the encrypted or decrypted data in the secure storage device.

6. The system of claim 1, wherein: The key management and cryptographic operations module is configured to stop or suspend the key management or cryptographic operations if the alert is received.

7. The system of claim 1, wherein: The key management and cryptographic operations module is configured to block any future service requests from the application if the alert is received.

8. The system of claim 1, wherein: The key management and cryptographic operations module is configured to notify an administrator, user, owner, or host of the application that the application has been compromised.

9. The system of claim 1, wherein: Before the one or more AI models are deployed in the AI ​​security module, the one or more AI models are trained in advance using one or more data sets of multiple service requests from the application to the HSM.

10. The system of claim 9, wherein: The AI ​​security module is configured to continuously train the one or more AI models using data of the application received after the one or more AI models have been deployed.

11. The system of claim 1, wherein: The one or more AI models include an anomaly detection model, which uses one or more statistical methods or machine learning algorithms to detect the anomaly in the service request without relying on predefined rules or patterns.

12. The system of claim 1, wherein: The one or more AI models include a behavioral analytics model that establishes the behavioral patterns associated with the application with respect to its use of one or more functions and services in the HSM during a lifecycle of cryptographic operations.

13. The system of claim 12, wherein: The behavior pattern associated with the application includes one or more of: a distribution of multiple service requests sent by the application within a specific time period, a type and / or frequency of services requested by the service requests, and how many of the service requests were previously rejected.

14. A system comprising: Hardware Security Module HSM, configured as: Accepting a service request from an application and providing the service request from the application for both: key management or cryptographic operations and security risk analysis of the application; performing the key management or encryption operation according to the service request of the application; analyzing the service request to identify one or more security risks and vulnerabilities associated with the service request from the application if the service request has an anomaly or deviates from a behavior pattern of the application by more than a certain threshold, according to one or more AI models; and Upon receiving an alert that the one or more security risks and vulnerabilities have been identified, ceasing to perform the key management or cryptographic operations requested by the application.

15. The system of claim 14, wherein: The HSM is a multi-chip embedded hardware / firmware encryption module.

16. The system of claim 14, wherein: The HSM includes a secure storage device configured to maintain keys and data storage devices associated with the application in a secure environment.

17. A method for enhancing the security of a hardware security module (HSM), comprising: Accepting a service request from an application and providing the service request from the application for both: key management or cryptographic operations and security risk analysis of the application; performing the key management or encryption operation according to the service request of the application; analyzing the service request to identify one or more security risks and vulnerabilities associated with the service request from the application if the service request has an anomaly or deviates from a behavior pattern of the application by more than a certain threshold, according to one or more AI models; and Upon receiving an alert that the one or more security risks and vulnerabilities have been identified, ceasing to perform the key management or cryptographic operations requested by the application.

18. The method according to claim 17, further comprising: A type of service requested by the application to be performed by the HSM is identified.

19. The method according to claim 17, further comprising: Once the service request has been processed, a response including the results of the processing is composed and transmitted back to the application that sent the service request.

20. The method according to claim 17, further comprising: If the alert for the service request for the application is received, the application is notified that the service request has been denied.

21. The method according to claim 17, further comprising: If the alert is received, any future service requests from the application are blocked.

22. The method according to claim 17, further comprising: An administrator, user, owner, or host of the application is notified that the application has been compromised.

23. The method according to claim 17, further comprising: Before the one or more AI models are deployed to the HSM, the one or more AI models are pre-trained using one or more data sets of a plurality of service requests from the application to the HSM.

24. The method according to claim 23, further comprising: The one or more AI models are continuously trained using data of the application received after the one or more AI models have been deployed to the HSM.

25. The method of claim 17, further comprising: One or more statistical methods or machine learning algorithms are used to detect the anomaly in the service request without relying on predefined rules or patterns.

26. The method of claim 17, further comprising: The behavior pattern associated with the application is established for the application's use of one or more functions and services in the HSM during a lifecycle of cryptographic operations.

27. A system, comprising: means for accepting service requests from an application and providing said service requests from said application for both key management or cryptographic operations and security risk analysis of said application; means for performing said key management or cryptographic operation in accordance with said service request by said application; means for analyzing the service request to identify one or more security risks and vulnerabilities associated with the service request from the application if the service request has an anomaly or deviates from a behavioral pattern of the application beyond a certain threshold, based on one or more AI models; as well as Means for ceasing to perform the key management or cryptographic operation requested by the application upon receiving an alert that the one or more security risks and vulnerabilities have been identified.