Remote Management of Hardware Security Modules
The method securely distributes and encrypts HSM key portions to enable remote management, addressing the impracticality and security concerns of existing HSM solutions by ensuring secure transmission and compliance with dual control.
Patent Information
- Application Number
- JP2023534181
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-11
- Filing Date
- 2021-12-03
- Publication Date
- 2025-10-22
- Estimated Expiration
- 2041-12-03
AI Technical Summary
Existing HSM management solutions require administrators to be physically present in the same location, leading to impractical scenarios and security vulnerabilities such as shared secret interception and unauthorized access due to insecure transmission and generation outside the secure environment.
A method for remotely managing HSMs by distributing a master key into encrypted key portions to different administrators, using doubly encrypted shared secrets and secure device verification to ensure compliance with dual control requirements, ensuring secure transmission and protection of shared secrets.
Enables remote administrators to manage HSMs securely without physical co-location, protecting shared secrets and ensuring request authenticity, thus adhering to compliance standards.
Smart Images

Figure 0007758735000001 
Figure 0007758735000002 
Figure 0007758735000003
Abstract
Description
[Technical Field]
[0001] The present invention relates generally to cryptography, and more particularly to remote management of hardware security modules. [Background technology]
[0002] Computing systems can utilize a variety of data security measures to protect data from unauthorized access. For example, a hardware security module (HSM) is a computing device and associated software that provides cryptographic functions for protecting and managing cryptographic keys, including encryption and decryption functions for digital signatures, strong authentication, and other cryptographic functions. HSMs can be in the form of a physical plug-in card or an external computing device that is directly connected to or attached to a secure computing device or network server.
[0003] Existing technologies for HSM management solutions utilize dual controls and other security techniques to ensure data protection. For example, an HSM management solution may require multiple administrators, each holding a smart card containing a key portion of the master key for the HSM, to gather in a secure physical space at the same time and present their smart cards containing each key portion to the system to configure the HSM. However, in situations where the administrators cannot gather in the same secure physical space at the same time, HSM management may be impractical and hinder the required process. For example, if one or more administrators cannot be present in the physical space to present their smart cards containing each key portion, the HSM cannot be configured because not all of the key portions necessary to form the master key are present. This may occur if everyone must work from home, if one or more administrators are physically unable to travel to the secure space, or if there is some other similar obstacle that prevents all of the required administrators from being physically present in the secure space.
[0004] Previous techniques for remotely managing HSMs have raised security concerns surrounding the shared secret required by the remote administrator and the authenticity of requests from the authentic remote administrator. The shared secret is data known only to the parties involved in the secure communication. The remote administrator of the system must utilize the shared secret to manage the HSM outside of the secure environment. One security concern arising from existing techniques for HSM management involves how to securely transport the shared secret to and from the remote administrator. In some instances, the connection between the mobile device and the server can be compromised, allowing the shared secret to be intercepted by an unauthorized user, thus compromising the security of the shared secret.
[0005] Some existing HSM management solutions allow shared secrets to be generated outside of the secure environment. In some cases, HSM management systems allow end users or remote administrators to generate their own shared secrets using their own identity or information about their mobile devices. Shared secrets generated outside of the secure environment by remote administrators may be vulnerable to exploitation if an attacker can access the information used to generate the shared secret (e.g., user identity, mobile device information, etc.) and decrypt or otherwise obtain the shared secret. If an attacker gathers sufficient information about the user or gains access to the user's device, they can make the system vulnerable to attack, and such a system may be destroyed.
[0006] In some existing HSM management solutions, shared secrets may not be sufficiently protected outside of a secure environment when held by a remote administrator. For example, shared secrets may not be encrypted by the mobile device and may be stored unencrypted on the mobile device. If an unauthorized user gains access to the mobile device, the unauthorized user may be able to obtain the unprotected shared secret, thus making the system vulnerable to access by unauthorized users.
[0007] In some existing HSM management solutions, management requests received from a remote administrator may not be valid or authentic. An attacker may attempt to access the system by cloning a device controlled by the remote administrator or by accessing the device without the remote administrator's knowledge. Such requests may appear valid or authentic and provide unauthorized users with access to the system. Summary of the Invention
[0008] An embodiment of the present invention is directed to remotely managing a hardware security module (HSM). According to an aspect of the present invention, a computer-implemented method is provided that includes receiving, by a processor of a computing device, a command request from a mobile device, the command request including an encrypted key portion and an encrypted signing key. The HSM decrypts the command request using a key associated with a security zone of the mobile device. The HSM decrypts the encrypted key portion and the encrypted signing key to generate a decrypted key portion and a decrypted signing key. Decrypting the encrypted key portion and the encrypted signing key includes using a key associated with the security zone of the mobile device and a key associated with a remote administrator associated with the mobile device. A command is generated for a domain including a target HSM and is based on the command request. The command is generated using the decrypted key portion and the decrypted signing key. The command is sent to the domain for execution by the target HSM.
[0009] According to another aspect of the present invention, a system for remotely managing an HSM is provided. A non-limiting example of the system includes a memory containing computer-readable instructions and one or more processors for executing the computer-readable instructions. The computer-readable instructions may implement the method described above.
[0010] According to another aspect of the present invention, there is provided a computer program product for remotely managing an HSM, the computer program product including a computer-readable storage medium having program instructions embodied thereon, the program instructions being executable by a processor to cause the processor to perform the method described above.
[0011] Advantageously, therefore, one or more embodiments of the present invention securely manage shared secrets used to remotely manage HSMs, thereby enabling remote administrators to perform HSM management without the need to be in one central location, while ensuring that the shared secrets remain protected.
[0012] Preferably, the present invention provides a method in which the command request can further include an encrypted logon key associated with the remote administrator, and the computer-implemented method further includes the HSM decrypting the encrypted logon key to generate a decrypted logon key. Decrypting the encrypted logon key includes using a key associated with the security zone of the mobile device and a key associated with the remote administrator associated with the mobile device. The decrypted logon key is transmitted to the domain along with the command. In this manner, the logon key can advantageously be transmitted to the domain along with the command.
[0013] The present invention preferably provides a method in which a second command request can be received from a second mobile device. The second command request can include a second encrypted key portion and a second encrypted signing key. The HSM decrypts the second command request using a key associated with the mobile device's security zone. The HSM decrypts the second encrypted key portion and the second encrypted signing key to generate a second decrypted key portion and a second decrypted signing key. Decrypting the second encrypted key portion and the second encrypted signing key includes using a key associated with the security zone and a different key associated with a different remote administrator associated with the second mobile device. A second command can be generated for a domain containing the target HSM using the second decrypted key portion and the second decrypted signing key. The second command can be transmitted to the domain. Advantageously, multiple remote administrators having different key portions can remotely manage the HSM without having to meet in one location, while ensuring that shared secrets remain protected.
[0014] The present invention preferably provides a method wherein the decrypted key portion and the second decrypted key portion are portions of a master key associated with a target HSM of the domain. Advantageously, the HSM can thus be administered using dual control by different administrators using different key portions that are portions of the HSM's master key.
[0015] The present invention preferably provides a method by which a mobile device may be provisioned by registering the mobile device within a security zone and associating the mobile device with a remote administrator. Advantageously, therefore, a mobile device used to remotely administer an HSM is configured to ensure protection of shared secrets used by the system.
[0016] The present invention preferably provides a method whereby commands can be signed using a decrypted signing key before sending the commands to a domain for execution by a target HSM. Advantageously, commands for remotely managing HSMs are thus protected by an additional layer of security during transmission to the domain.
[0017] The present invention preferably provides a method whereby a message can be sent to a mobile device based on results received from a domain, thus advantageously updating a remote administrator with the results of commands received from the domain.
[0018] According to another aspect of the present invention, a computer-implemented method directed to remotely managing an HSM is provided. A non-limiting example of the computer-implemented method includes receiving, by a processor of a computing device, a key load request from a mobile device associated with a remote administrator, the key load request including an encrypted key portion and an encrypted signature key. The validity of the key load request from the mobile device may be verified. The encrypted key portion and the encrypted signature key may be decrypted to generate a decrypted key portion and a decrypted signature key. Decrypting the encrypted key portion and the encrypted signature key may include using a private key corresponding to the public key of a certificate authority (CA) certificate for the security zone and a private key corresponding to the public key of a CA certificate for the remote administrator's profile. A key load command may be constructed for a domain specified by the key load request. The key load command may include the decrypted key portion and is signed using the decrypted signature key. The key load command may be sent to a target hardware security module (HSM) for the domain for execution by the domain.
[0019] Advantageously, therefore, one or more embodiments of the present invention securely manage shared secrets used to remotely manage HSMs, thereby enabling remote administrators to perform HSM management without the need to be in one central location, while ensuring that the shared secrets remain protected.
[0020] The present invention preferably provides a computer-implemented method in which the key read request is encrypted using the public key of a CA certificate for the security zone, and validating the key read request includes decrypting the key read request using a private key corresponding to the public key of the CA certificate for the security zone. Advantageously, the key read request is thus encrypted by the mobile device to ensure that the shared secret is protected during transmission of the request to the system.
[0021] According to another aspect of the present invention, a computer-implemented method directed to remotely managing an HSM is provided. A non-limiting example of the computer-implemented method may include receiving, by a processor of a secure computing device, an encrypted hardware security module (HSM) command request from a mobile device associated with the remote administrator, the encrypted HSM command request including an encrypted key portion and an encrypted signature key. The encrypted HSM command request from the mobile device may be decrypted. The HSM of the secure computing device may decrypt the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key. An HSM command corresponding to the encrypted HSM command request for a specified domain may be generated based at least in part on the decrypted key portion and the decrypted signature key. The HSM command may be sent to the specified domain for execution by a target HSM of the specified domain.
[0022] Advantageously, therefore, one or more embodiments of the present invention securely manage shared secrets used to remotely manage HSMs, thereby enabling remote administrators to perform HSM management without the need to be in one central location, while ensuring that the shared secrets remain protected.
[0023] The present invention preferably provides a computer-implemented method in which the key read request is encrypted using the public key of a CA certificate for the security zone, and validating the key read request includes decrypting the key read request using a private key corresponding to the public key of the CA certificate for the security zone. Advantageously, the key read request is thus encrypted by the mobile device to ensure that the shared secret is protected during transmission of the request to the system.
[0024] The present invention preferably provides a computer-implemented method in which a message may be sent to a mobile device based on results received from a specified domain, thereby advantageously updating a remote administrator with the results of commands received from the domain.
[0025] Other technical features and advantages are realized by the techniques of the present invention. Embodiments and aspects of the present invention are described in detail herein and are considered a part of the claimed subject matter. For a better understanding, please refer to the detailed description and drawings.
[0026] The particulars of the proprietary rights set forth herein are particularly pointed out and distinctly claimed in the claims at the conclusion of the specification. The foregoing and other features and advantages of embodiments of the present invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings. [Brief explanation of the drawings]
[0027] [Figure 1]1 is a schematic diagram illustrating provisioning of a mobile device for remote management of a hardware security module in accordance with one or more example embodiments. [Figure 2] 1 is a schematic diagram illustrating remote management of a hardware security module in accordance with one or more example embodiments. [Figure 3] FIG. 1 is a process flow diagram of an exemplary method for provisioning a mobile device for remote management of a hardware security module according to one or more example embodiments. [Figure 4] FIG. 1 is a process flow diagram of an exemplary method for remote management of a hardware security module by a mobile device, according to one or more example embodiments. [Figure 5] FIG. 1 is a process flow diagram of an exemplary method for remote management of a hardware security module by a secure server according to one or more example embodiments. [Figure 6] 1 is a diagram of a computer system according to one or more embodiments of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0028] The diagrams shown herein are exemplary. There may be many variations of the diagrams or operations described herein without departing from the scope of the invention. For example, operations may be performed in a different order, or operations may be added, deleted, or modified. Also, the term "coupled" and variations thereof indicate that a communication path exists between two elements, and do not imply a direct connection between elements with no intervening elements / connections between them. All of these variations are considered part of this specification.
[0029]
[0003] Exemplary embodiments of the present invention relate, inter alia, to systems, methods, computer-readable media, techniques, and means for remote management of Hardware Security Modules (HSMs). Conventional approaches for remotely managing HSMs raise concerns about the security of shared secrets required by the remote administrator and the authenticity of requests from the remote administrator. Existing techniques for managing HSMs typically require the administrators to congregate in the same physical space at the same time to ensure compliance with standards and regulations that require HSMs to be managed using conformance level management techniques. However, in environments where administrators cannot physically congregate in one location, such techniques are impractical.
[0030] One or more embodiments of the present invention are directed to remote HSM management, in which a master key for an HSM is separated into key portions, stored in protected storage, and securely distributed to different remote administrators within a protected environment. Administrators can remotely manage HSMs without requiring physical gathering within the same secure physical space while adhering to dual control requirements. The shared secret is securely distributed while ensuring that requests received from administrators by the system are authorized to ensure that the requests come from authorized administrators and that the security of the administrators' mobile devices has not been compromised.
[0031] In some embodiments, a secure device, such as a secure server, resides within the secure environment. The secure environment is a secure location, such as a secure room or floor within a building with restricted access, where a secure device used to support remote HSM management is located. The secure device runs an application, such as a web application, to communicate with a remotely located mobile device outside the secure environment for remote HSM management. A mobile device, such as a smartphone, is provisioned within the secure environment. The mobile device is registered with a security zone and assigned to a remote administrator. A shared secret used for HSM management is loaded onto the provisioned mobile device while it is within the secure environment. The shared secret may include a key portion that is a component of a master key used by a designated HSM. The shared secret is encrypted within the secure environment before being transferred to the mobile device, and if mobile device security is included, ensures that the shared secret on the mobile device is secure and cannot be decrypted by the device user or anyone else.
[0032] Remote administrators can carry mobile devices outside the secure environment and use them for remote HSM management. For example, while outside the secure environment, the remote administrator can open an application on their mobile device and authenticate themselves, such as by using multi-factor authentication. The remote administrator selects an HSM from a list of HSMs and selects commands to run on the target HSM for the specified domain. The remote administrator selects any required shared secrets (e.g., loaded onto the mobile device during provisioning), such as key portions and / or signing keys already encrypted within the secure environment. The application constructs a request using the remote administrator's selection and encrypts this request using the public key in the remote administrator's certification authority (CA) certificate. The encrypted request is sent to the secure device within the secure environment.
[0033] The secure device receives encrypted requests from the remote administrator's mobile device. The secure device verifies the validity of the requests and constructs an HSM command using information from each request received from the remote administrator's mobile device. Each HSM command is signed using a signing key obtained from each request and sent to the domain specified by each request. This command is executed by the target HSM in the specified domain. The target HSM receives requests from all specified remote administrators and may collect key portions from each remote administrator until a master key is formed using the collected key portions. Upon completion of the master key, the HSM command is executed by the target HSM. The results of the command executed by the target HSM are sent back to the secure device. The secure device may generate a message indicating the results received from the domain and send this message to the mobile device. The systems and methods described herein provide the ability to remotely manage HSMs while complying with various standards and regulations using compliance level management techniques, such as dual control.
[0034] One security concern arising from existing technologies for HSM management is how to securely transport a shared secret to and from a remote administrator. In some instances, the connection between the mobile device and the server may be compromised, allowing the shared secret to be intercepted by an unintended recipient, thus compromising the security of the shared secret. One or more embodiments of the present invention facilitate the generation of a shared secret by an HSM in a secure device within a secure environment. The shared secret may be doubly encrypted. For example, a shared secret, such as a key portion, may be encrypted using a shared secret for the mobile device's security zone and a shared secret associated with a particular remote administrator. The doubly encrypted shared secret may then be loaded onto a provisioned mobile device used by the remote administrator for remote management of the HSM. The doubly encrypted shared secret generated by the HSM within the secure environment is never decrypted while outside the secure environment. When the remote administrator remotely manages the HSM, the remote administrator can select a doubly encrypted shared secret to include in a command request sent to the secure device. Therefore, even if intercepted, the doubly encrypted shared secret cannot be decrypted by an unauthorized user and used to remotely administer the HSM unless the mobile device from which the doubly encrypted shared secret originated is properly validated by a secure device at a secure location.
[0035] Some existing HSM management solutions allow shared secrets to be generated outside of the secure environment. The HSM management system may allow end users to generate shared secrets using their own identity or information about the mobile device. Shared secrets generated outside of the secure environment by a remote administrator may be vulnerable to exploitation if an attacker can access the information used to generate the shared secret and decrypt or otherwise obtain the shared secret. One or more embodiments of the present invention facilitate the use of doubly encrypted shared secrets generated and encrypted within the secure environment by the secure device and associated HSM. The shared secrets are not decrypted outside of the secure environment and are not stored in a decrypted state on the mobile device. Thus, shared secrets generated by the HSM of the secure device are protected outside of the secure environment because they are doubly encrypted when loaded onto the mobile device and further encrypted when sent back to the secure device by the mobile device as part of an HSM command request to remotely manage the HSM, thus eliminating a vulnerability presented by existing HSM management solutions.
[0036] An exemplary system for remote management of HSMs is described in detail below with reference to Figures 1 and 2. A corresponding computer-implemented method is described in detail with reference to Figures 3-5. Additionally, an exemplary computing system and network architecture for implementing one or more of the embodiments described herein is described in detail with reference to Figure 6.
[0037] FIG. 1 is a block diagram of an example system 100 for provisioning mobile devices to remotely manage HSMs. As shown in this figure, the example system 100 may include one or more modules for performing one or more tasks. As described in further detail below, the modules may include an HSM management module 135 on a secure server 130, or applications 115A, 115B, 115C on each mobile device 110A, 110B, 110C, or both. While the modules in FIG. 1 are shown as separate elements, one or more of the modules in FIG. 1 may represent portions of a single module or application.
[0038] Referring now to FIG. 1 , a system 100 configured in accordance with an example embodiment of the present invention includes a secure environment 105. A secure server 130 can be located within the secure environment 105. The secure environment 105 can be a secure location, such as a secure room or floor within an organization's or entity's building. The secure environment 105 can include limited or restricted access. As shown in the embodiment of FIG. 1 , the secure server 130 includes an HSM management module 135 and an HSM 140. In one or more embodiments of the present invention, the HSM 140 is connected to or attached to the secure server 130.
[0039] In some embodiments, setting up or configuring secure server 130 may include HSM management module 135 creating paths to one or more target HSMs. HSM management module 135 may run and / or manage applications, such as web applications, used to communicate with mobile devices (e.g., 110A, 110B, 110C) that are provisioned and used from outside secure environment 105 to remotely manage one or more target HSMs. Additionally, secure server 130 may be enrolled in a security zone. A security zone may be designated by a certification authority (CA) and represent an entity or organization that issues and / or manages certificates. In some embodiments, a CA smart card, CA certificate, etc. may define a security zone. The CA certificate may cryptographically link devices (e.g., mobile devices 110A, 110B, 110C, secure server 130, etc.).
[0040] In some embodiments, the HSM management module 135 can facilitate the generation and management of shared secrets 120A, 120B, 120C, and 120D. The HSM management module 135 can facilitate the generation and management of shared secrets 120A, 120B, 120C, and 120D by the HSM 140. Examples of shared secrets 120A, 120B, 120C, and 120D can include a remote administrator profile logon key, CCA normal mode signing keys, CCA PCI mode signing keys, EP11 signing keys, or key portions or combinations thereof. The CCA normal signing keys can be asymmetric keys that are not subject to payment card industry (PCI) restrictions. The CCA PCI mode signing keys can be asymmetric keys that comply with PCI rules. The EP11 signing key can be an asymmetric key that conforms to the PKCS#11 public key cryptography API interface to the cryptographic token. The HSM management module 135 can separate, split, or otherwise decompose the target HSM's master key into different key portions and facilitate assigning those key portions to different remote administrators. Each mobile device 110A, 110B, 110C contains a different shared secret 120A, 120B, 120C (e.g., key portion, signing key, etc.) that can be encrypted by the public key of a CA certificate defining a security zone and each public key of each remote administrator profile associated with each remote administrator. The HSM management module 135 can generate and store encrypted shared secrets 120D that are distributed to the mobile devices 110A, 110B, 110C used to remotely manage the HSM.
[0041] The HSM management module 135 of the secure server 130 can prepare the shared secret 120D so that after the mobile devices 110A, 110B, 110C are provisioned, the shared secret 120D can be loaded onto the mobile devices 110A, 110B, 110C and assigned to a particular remote administrator. The HSM management module 135 can encrypt the shared secret 120D (e.g., key portions, signature keys, remote administrator logon keys, etc.) using the public key of a CA certificate that defines a security zone. The HSM management module 135 can encrypt the shared secret using the public key of a certificate in the remote administrator's profile. In some embodiments, the HSM management module 135 can set a maximum download count to limit the number of times the shared secret 120D can be downloaded to the mobile devices 110A, 110B, 110C within a certain period of time.
[0042] Mobile devices 110A, 110B, 110C are provisioned within secure environment 105. In some embodiments, each mobile device is directly connected to secure server 130. For example, mobile device 110A may be connected to secure server 130 via a direct connection 150, such as a Universal Serial Bus (USB) connection. In some embodiments, mobile device 110A may be provisioned by installing a memory card containing the necessary data into mobile device 110A, by scanning a QR code by mobile device 110A, by using short-range wireless technology such as Bluetooth™ or Near Field Communication (NFC), or similar technology.
[0043] In some embodiments, mobile device 110A is registered with a security zone. Mobile device 110A may be registered with a security zone by downloading a CA certificate that defines the security zone. A security zone indicates the device's association with the entity or organization that manages and / or issues the CA certificate. Mobile device 110A may be assigned to a remote administrator. In some embodiments, mobile device 110A is assigned to a remote administrator by loading the remote administrator's profile logon key shared secret into mobile device 110A, which may be the public key of the remote administrator's profile certificate stored in HSM 140 of secure server 130.
[0044] In some embodiments, applications 115A, 115B, 115C for installation on provisioned mobile devices 110A, 110B, 110C may be stored on secure server 130 and transferred to mobile devices 110A, 110B, 110C upon provisioning. In some embodiments, applications 115A, 115B, 115C may be downloadable from an application distribution platform, such as an app store or app marketplace. Applications 115A, 115B, 115C may be used by mobile devices 110A, 110B, 110C to establish a secure connection with secure server 130 and communicate with secure server 130 to remotely manage one or more HSMs. Provisioning of the mobile devices 110A, 110B, 110C may occur in separate steps within the secure environment 105 when the mobile devices 110A, 110B, 110C download applications 115A, 115B, 115C from an application distribution platform. The applications 115A, 115B, 115C on the mobile devices 110A, 110B, 110C may be PIN-protected by a PIN set by a remote administrator when the application is first run. Additionally, the provisioned mobile devices 110A, 110B, 110C may be protected by a different PIN set by the remote administrator. The mobile device PIN may be required to comply with one or more security policies determined by the administrator of the system 100. In some embodiments, applications 115A, 115B, 115C may store shared secrets 120A, 120B, 120C that are generated and encrypted by HSM 140 and transferred to each mobile device 110A, 110B, 110C upon provisioning. In some embodiments, shared secrets 120A, 120B, 120C may include different key portions assigned to each mobile device 110A, 110B, 110C, which are combined to form a master key for accessing and managing the HSM.In some embodiments, shared secret 120A, 120B, 120C may be loaded into mobile device 110A, 110B, 110C at provisioning time while within secure environment 105. Shared secret 120D may be securely transmitted to mobile device 110A, 110B, 110C after the mobile device is provisioned while within secure environment 105, and then transported outside of secure environment 105.
[0045] In some embodiments, mobile devices 110A, 110B, 110C may be provisioned within secure environment 105 and sent to a remote administrator outside secure environment 105, or transported out of secure environment 105 and physically delivered to each remote administrator, or both.
[0046] The embodiments described herein with respect to system 100 of FIG. 1 may be implemented using any suitable logic, which as referred to herein may, in various embodiments, include any suitable hardware (e.g., a processor, embedded controller, or application specific integrated circuit, among others), software (e.g., an application, among others), firmware, or any suitable combination of hardware, software, and firmware.
[0047] FIG. 2 is a block diagram of an example system 200 for remotely managing HSMs. As shown in this figure, the example system 200 may include one or more modules for performing one or more tasks. As described in further detail below, the modules may include an HSM management module 135 on the secure server 130, or applications 115A, 115B, 115C running on each mobile device 110A, 110B, 110C, or both. While the modules in FIG. 1 are shown as separate elements, one or more of the modules in FIG. 1 may represent portions of a single module or application.
[0048] After mobile devices 110A, 110B, and 110C are provisioned, as illustrated in FIG. 1 and described in further detail in FIG. 3, the mobile devices may be located far away from secure environment 105 and used by a remote administrator assigned to the mobile devices to remotely manage the HSM from outside secure environment 105. The applications 115A, 115B, and 115C loaded on each mobile device 110A, 110B, and 110C may be used to securely store each shared secret 120A, 120B, and 120C loaded on each mobile device during provisioning or after provisioning is complete. In some examples, the remote administrator of mobile devices 110A, 110B, and 110C can execute each application 115A, 115B, and 115C on each mobile device and establish a secure connection with secure server 130 located within secure environment 105 via network 210. For example, a remote administrator on mobile device 110A can use application 115A to select parameters (e.g., domain to configure, selection of shared secret 120A, selection of command, etc.) and generate an HSM command request to be executed on the HSM for the specified domain. Application 115A can encrypt the HSM command request and securely transmit the command request to HSM management module 135 of secure server 130.
[0049] HSM management module 135 can receive and process one or more HSM command requests from mobile devices 110A, 110B, and 110C. In some embodiments, HSM management module 135 can verify the validity of HSM command requests received from mobile devices 110A, 110B, and 110C. In some examples, HSM management module 135 can instruct HSM 140 to decrypt encrypted requests and / or shared secrets 120A, 120B, and 120C received from mobile devices 110A, 110B, and 110C. HSM 140 can decrypt encrypted requests and / or shared secrets 120A, 120B, and 120C using corresponding shared secrets 120D stored in HSM 140. The HSM management module 135 can then construct an HSM command based on the received HSM command request and send this command to the specified domain for execution by the target HSM as specified in the HSM command request.
[0050] A designated domain (not shown) can receive commands from the HSM management module 135. The HSM management module 135 can send multiple commands from each of the mobile devices 110A, 110B, 110C. The target HSM of the designated domain can obtain shared secrets 120A, 120B, 120C from the different commands received from the HSM management module 135 and add the shared secrets 120A, 120B, 120C to a register internal to the target HSM until a master key is formed. In some examples, the target HSM can perform a logical operation (e.g., exclusive OR) or other means of combining data to assemble the shared secrets 120A, 120B, 120C (e.g., key portions) received from the different commands received from the HSM management module 135 to generate a master key, which can be used to execute the commands received from the HSM management module 135. Upon completion of execution of the command by the target HSM for the specified domain, the results are sent back to HSM management module 135. HSM management module 135 receives the results and can generate a message to each mobile device 110A, 110B, 110C indicating the result of the command executed by the target HSM.
[0051] The embodiments described herein with respect to system 200 of FIG. 2 may be implemented using any suitable logic, which as referred to herein may, in various embodiments, include any suitable hardware (e.g., a processor, embedded controller, or application specific integrated circuit, among others), software (e.g., an application, among others), firmware, or any suitable combination of hardware, software, and firmware.
[0052] Referring now to FIG. 3, a system 100 configured in accordance with an example embodiment of the present invention provisions one or more mobile devices 110A, 110B, 110C. To provision one or more mobile devices 110A, 110B, 110C, all or a portion of the processing described with reference to FIG. 3 may be performed by a secure server 130 within the secure environment 105 of FIG. 1. The mobile devices 110A, 110B, 110C are provisioned one-by-one within the secure environment 105. The mobile devices 110A, 110B, 110C may be provisioned by connecting the mobile devices 110A, 110B, 110C with the secure server 130 (one-by-one) using a direct connection 150, such as using a USB connection, scanning a QR code, using NFC technology, or Bluetooth™.
[0053] At block 302, the method 300 for provisioning a mobile device includes enrolling the mobile device 110A, 110B, 110C in a security zone. In some embodiments, the mobile device 110A is enrolled in the security zone by downloading a CA certificate to the mobile device 110A that defines the security zone. The CA certificate indicates the association of the device (e.g., the mobile device 110A) with the entity or organization that manages and / or issues the CA certificate.
[0054] At block 304, the method 300 for provisioning a mobile device includes assigning the mobile device 110A to a remote administrator. In some embodiments, the HSM management module 135 can define or identify a user and assign them to a remote administrator profile. In some embodiments, the remote administrator profile can be stored as a set of remote administrator profile objects. In some embodiments, the remote administrator profile objects can be stored or included in the HSM 140 of the secure server 130. The remote administrator profile object can include a remote administrator profile certificate and a private key corresponding to the public key in the remote administrator profile certificate. In some embodiments, the mobile device 110A is assigned to the remote administrator by loading the logon key secret of the remote administrator profile.
[0055] At block 306, the method 300 for provisioning a mobile device includes loading a shared secret 120A into the mobile device 110A. In some embodiments, the shared secret 120A may be loaded into the mobile device 110A at provisioning time. In some embodiments, a user may request the secure server 130 to send the shared secret 120A (e.g., an encrypted key portion, an encrypted signature key, etc.) via an application 115A running on the mobile device 110A. In some embodiments, the mobile device 110A may request a new shared secret 120A generated for that particular remote administrator via an application 115A running on the mobile device 110A. The new shared secret 120A may be encrypted by the secure server 130 and sent to the mobile device 110A. This method may be repeated for each mobile device. For example, blocks 302-306 may be repeated using mobile device 110B by connecting mobile device 110B to secure server 130 using direct connection 150, provisioning mobile device 110B, downloading application 115B, and reading shared secret 120B generated and encrypted for mobile device 110B. Blocks 302-306 may be repeated using mobile device 110C by connecting mobile device 110C to secure server 130 using direct connection 150, provisioning mobile device 110C, downloading application 115C, and reading shared secret 120C generated and encrypted for mobile device 110C. Because shared secrets 120A, 120B, and 120C correspond to each mobile device 110A, 110B, and 110C, each mobile device 110A, 110B, and 110C is independently provisioned.
[0056] 3 is not intended to imply that the operations of method 300 be performed in any particular order, nor that all of the operations of method 300 are included in all instances. Additionally, method 300 may include any suitable number of additional operations.
[0057] Referring now to FIG. 4 , at block 402 of method 400, system 200 configured in accordance with an example embodiment of the present invention establishes a connection with secure server 130. To remotely manage an HSM, all or a portion of the processing described with reference to FIG. 4 may be performed by mobile devices 110A, 110B, 110C, which are typically outside secure environment 105 of FIG. 2 . In some examples, application 115A on mobile device 110A establishes a connection with secure server 130 via one or more networks 210. A remote administrator can open application 115A on mobile device 110A. Application 115A on mobile device 110A may be protected by a PIN set by the remote administrator when application 115A is first opened. In some embodiments, the remote administrator can specify a web address to access a web application running on secure server 130. The remote administrator authenticates to application 115A running on mobile device 110A, such as via a multi-factor authentication challenge.
[0058] At block 404 of method 400, computer-executable instructions of application 115A executing on mobile device 110A generate an HSM command request to a target HSM for a domain. Application 115A facilitates a remote administrator's selection of a target HSM to be configured from a list of available HSMs. The remote administrator can select a command to execute on the target HSM, such as a LOADKEY command, and select a shared secret 120A needed to execute the command on the target HSM. Mobile device 110A's shared secret 120A is associated with the remote administrator's profile and can include an encrypted key portion, an encrypted signature key, or an encrypted logon key secret, or a combination thereof, loaded during provisioning of mobile device 110A, after mobile device 110A is provisioned, or both. Application 115A can use the remote administrator's selection to generate an HSM command request to a target HSM for the specified domain.
[0059] At block 406 of method 400, computer-executable instructions of application 115A executing on mobile device 110A encrypt an HSM command request. In some embodiments, application 115A encrypts the HSM command request using the public key of a CA certificate that defines a security zone. Application 115A sends the encrypted HSM command request to secure server 130 executing within secure environment 105. In some examples, application 115A sends the encrypted HSM command request to HSM management module 135 of secure server 130.
[0060] At block 408 of method 400, the computer-executable instructions of application 115A receive a message from secure server 130. For example, the message may include the results of an HSM command executed on a target HSM of a specified domain. In some examples, the message may display a positive or negative statement indicating the success or failure of the execution of the HSM command executed on the target HSM of the specified domain.
[0061] 4 is not intended to imply that the operations of method 400 be performed in any particular order, nor that all of the operations of method 400 are included in all instances. Additionally, method 400 may include any suitable number of additional operations.
[0062] Referring now to FIG. 5 , at block 502 of method 500, system 200 configured in accordance with an example embodiment of the present invention decrypts an HSM command request received from a mobile device, such as 110A, 110B, or 110C. HSM management module 135 may receive the encrypted HSM command request via a connection established by each application 115A, 115B, or 115C running on mobile device 110A, 110B, or 110C, as described in FIG. 3 . HSM management module 135 may facilitate decrypting the request received from mobile device 110A, 110B, or 110C by HSM 140. For example, HSM 140 may decrypt the received HSM command request using a private key corresponding to the public key of a CA certificate that defines a security zone. HSM management module 135 may facilitate decrypting the shared secret 120A, 120B, or 120C received in the decrypted request. For example, HSM 140 can decrypt key portions, signature keys, and / or logon keys associated with a remote administrator's profile, each of which may be encrypted independently of the other and may be doubly encrypted using the public key of a CA certificate defining a security zone and the public key of a CA certificate for the remote administrator's profile. Following direction from HSM management module 135, HSM 140 can decrypt shared secrets 120A, 120B, and 120C in HSM command requests received from mobile devices 110A, 110B, and 110C using a corresponding shared secret 120D stored in the HSM, such as a private key corresponding to the public key of a CA certificate for the security zone. HSM 140 can decrypt shared secrets 120A, 120B, and 120C in HSM command requests received from mobile devices 110A, 110B, and 110C using a shared secret 120D, such as a private key corresponding to the public key of a CA certificate for the remote administrator's profile.
[0063] At block 504 of method 500, computer-executable instructions of HSM management module 135 executing on secure server 130 generate an HSM command for the domain to be configured. The HSM command is generated based on an HSM command request received from mobile device 110A. The HSM command includes a portion of a key assigned to the remote administrator that was decrypted by HSM 140. The HSM command may include the domain to be configured as specified by the remote administrator when the HSM command request was generated. The HSM command may be generated for execution by a target HSM for the domain to be configured.
[0064] At block 506 of method 500, computer-executable instructions of HSM management module 135 executing on secure server 130 send an HSM command to the domain. In some embodiments, the portion of the key assigned to the remote administrator may be wrapped using a transport key negotiated between the configured target HSM and secure server 130.
[0065] At block 508 of method 500, computer-executable instructions of HSM management module 135 executing on secure server 130 send a message to mobile device 110A, 110B, 110C that sent the HSM command request. In some embodiments, this message is generated in response to receiving a result of executing the HSM command by a target HSM of the configured domain. The result from the target HSM is sent to HSM management module 135 of secure server 130, and the message to the mobile device includes a positive or negative indication based on the result received from the target HSM of the configured domain.
[0066] In some embodiments, secure server 130 receives encrypted requests from different mobile devices 110A, 110B, 110C associated with each assigned remote administrator. HSM management module 135 of secure server 130 validates the requests and constructs HSM commands using information from each request received from the remote administrator's mobile devices 110A, 110B, 110C. Each HSM command is signed using a signing key obtained from each request and sent to the domain specified by each request. The command is executed by a target HSM for the specified domain. The target HSM receives HSM commands based on the HSM command requests received by secure server 130 from all specified remote administrators. The target HSM for the specified domain collects key portions from each of the remote administrators until a master key is formed using the collected key portions. In some examples, the key portions from each command received by the target HSM are added to an internal register of the target HSM. The key portions stored in the registers of the target HSM may be combined using a logical operation (e.g., XOR (exclusive OR)) or other means of combining data to generate a master key. Upon completion or formation of the master key, an HSM command is executed by the target HSM. The results of the command executed by the target HSM are sent back to the HSM management module 135. The HSM management module 135 generates a message indicating the results received from the domain and sends this message to each mobile device 110A, 110B, 110C.
[0067] In some embodiments, the HSM management module 135 running on the secure server 130 detects abnormal or unauthorized access by a remote administrator's mobile device. For example, the HSM management module 135 receives multiple invalid requests from the same IP address. The HSM management module 135 identifies the mobile devices 110A, 110B, and 110C associated with this IP address and determines that the number of invalid requests exceeds a specified threshold. The mobile devices 110A, 110B, and 110C may be added to a restricted or denied list. In some examples, the mobile devices 110A, 110B, and 110C are added to the list for a specified period of time (e.g., one hour). In some embodiments, the mobile devices 110A, 110B, and 110C are denied access to the secure server 130 until the administrator removes the mobile devices 110A, 110B, and 110C from the restricted or denied list. In some embodiments, if mobile device 110A, 110B, 110C is on a restricted or denied list, mobile device 110A, 110B, 110C may be remotely wiped or the certificates in the remote administrator's profile may be revoked, thereby removing access by mobile device 110A, 110B, 110C to secure server 130. In some embodiments, if mobile device 110A, 110B, 110C is suspected of being compromised or intruded upon, mobile device 110A, 110B, 110C may be remotely wiped or the certificates in the remote administrator's profile may be revoked by HSM management module 135 based on one or more security policies or by a system administrator.If the mobile device 110A, 110B, 110C is erased or the certificate of the remote administrator's profile is revoked, the mobile device 110A, 110B, 110C must be returned to the secure environment 105 and re-provisioned, or a new mobile device must be provisioned in the secure environment 105 for the remote administrator and delivered to the remote administrator, in order for the remote administrator to gain access to the secure server 130.
[0068] 5 is not intended to imply that the operations of method 500 be performed in any particular order, nor that all of the operations of method 500 are included in all instances. Additionally, method 500 may include any suitable number of additional operations.
[0069] Referring now to FIG. 6, a computer system 600 is generally illustrated in accordance with an embodiment of the present invention. Computer system 600 can be an electronic computer framework comprising and / or employing any number and combination of computing devices and networks utilizing various communication technologies, as described herein. Computer system 600 is easily scalable, extensible, and modular, and can have the ability to change to different services or reconfigure some functions independently of other functions. Computer system 600 can be, for example, a server, desktop computer, laptop computer, tablet computer, or smartphone. In some examples, computer system 600 can be a cloud computing node. Computer system 600 can be described in the general context of instructions executable by a computer system, such as program modules being executed by the computer system. Typically, program modules can include routines, programs, objects, components, logic, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer system 600 may operate in a distributed cloud computing environment where tasks are performed by remote processing devices that are linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media including memory storage devices.
[0070] As shown in FIG. 6, computer system 600 includes one or more central processing units (CPUs) 601a, 601b, 601c, etc. (collectively or generally referred to as processors 601). Processor 601 can be a single-core processor, a multi-core processor, a computing cluster, or any number of other configurations. Processor 601, also referred to as a processing circuit, is coupled to system memory 603 and various other components via a system bus 602. System memory 603 can include read-only memory (ROM) 604 and random access memory (RAM) 605. ROM 604 is coupled to system bus 602 and may include a basic input / output system (BIOS) that controls certain basic functions of computer system 600. RAM is read-write memory coupled to system bus 602 for use by processor 601. System memory 603 provides temporary memory space for the execution of the aforementioned instructions during operation. The system memory 603 may include random access memory (RAM), read-only memory, flash memory, or any other suitable memory system.
[0071] Computer system 600 includes an input / output (I / O) adapter 606 and a communications adapter 607 coupled to a system bus 602. I / O adapter 606 may be a small computer system interface (SCSI) adapter that communicates with a hard disk 608 and / or any other similar components. I / O adapter 606 and hard disk 608 are collectively referred to herein as mass storage 610.
[0072] Software 611 for execution on computer system 600 may be stored in mass storage 610. Mass storage 610 is an example of a tangible storage medium readable by processor 601, on which software 611 is stored as instructions for execution by processor 601 to cause computer system 600 to operate as described herein below with respect to various figures. Examples of computer program products and the execution of such instructions are described in further detail herein. Communications adapter 607 interconnects system bus 602 with network 612, which may be an external network, enabling computer system 600 to communicate with other such systems. In one embodiment, system memory 603 and a portion of mass storage 610 collectively store an operating system, which may be any suitable operating system, such as IBM Corporation's z / OS or AIX operating systems, to coordinate the functions of the various components illustrated in FIG. 6.
[0073] Other input / output devices are shown connected to system bus 602 via display adapter 615 and interface adapter 616. In one embodiment, adapters 606, 607, 615, and 616 may be connected to one or more I / O buses, which are connected to system bus 602 through an intermediate bus bridge (not shown). A display 619 (e.g., a screen or display monitor) is connected to system bus 602 by display adapter 615, which may include a graphics controller to improve performance for graphics-intensive applications and a video controller. A keyboard 621, mouse 622, speaker 623, etc. may be interconnected to system bus 602 via interface adapter 616, which may include, for example, a super I / O chip that integrates multiple device adapters into a single integrated circuit. I / O buses suitable for connecting peripheral devices such as hard disk controllers, network adapters, and graphics adapters typically include common protocols such as PCI (Peripheral Component Interconnect). Thus, as configured in Figure 6, computer system 600 includes processing capabilities in the form of processor 601, storage capabilities including system memory 603 and mass storage 610, input means such as keyboard 621 and mouse 622, and output capabilities including speakers 623 and display 619.
[0074] In some embodiments, communications adapter 607 may transmit data using any suitable interface or protocol, such as an Internet or small computer system interface, among others. Network 612 may be a cellular network, a wireless network, a wide area network (WAN), a local area network (LAN), or the Internet, among others. External computing devices may connect to computer system 600 via network 612. In some examples, the external computing device may be an external web server or a cloud computing node.
[0075] It should be understood that the block diagram of Figure 6 is not intended to indicate that computer system 600 will include all of the components shown in Figure 6. Rather, computer system 600 may include any suitable fewer components or additional components not shown in Figure 6 (e.g., additional memory components, embedded controllers, modules, additional network interfaces, etc.). Furthermore, the embodiments described herein with respect to computer system 600 may be implemented using any suitable logic, which, as referred to herein, in various embodiments, may include any suitable hardware (e.g., a processor, embedded controller, or application specific integrated circuit, among others), software (e.g., an application, among others), firmware, or any suitable combination of hardware, software, and firmware.
[0076] The present invention may be a system, method, or computer program product, or any combination thereof, at any possible level of technical detail of integration. The computer program product may include a computer-readable storage medium containing computer-readable program instructions for causing a processor to perform aspects of the present invention.
[0077] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media includes portable floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanically encoded devices such as punch cards or ridge structures in grooves on which instructions are recorded, and any suitable combination thereof. As used herein, computer-readable storage media should not be construed as being ephemeral signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses passing through fiber optic cable), or electrical signals transmitted over wires.
[0078] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or storage device over a network (e.g., the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof). This network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage on a computer-readable storage medium within each computing / processing device.
[0079] Computer-readable program instructions for carrying out the operations of the present invention may be source or object code written in any combination of one or more programming languages, including assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or object-oriented programming languages such as Smalltalk®, C++, and procedural programming languages such as the “C” programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider). In some embodiments, to carry out aspects of the present invention, electronic circuitry including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute computer-readable program instructions to customize the electronic circuitry by utilizing state information of the computer-readable program instructions.
[0080] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0081] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to create a machine, where the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for performing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may be stored on a computer-readable storage medium and capable of directing a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner, such that the computer-readable storage medium on which the instructions are stored comprises an article of manufacture containing instructions for performing aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0082] Computer-readable program instructions may be loaded into a computer, other programmable data processing apparatus, or other device such that the instructions, which execute on the computer, other programmable apparatus, or other device, perform the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams, thereby causing a series of operable steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process.
[0083] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, comprising one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions shown in the blocks may occur out of the order shown in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or in the reverse order, depending on the functionality involved. It is also noted that each block in the block diagrams and / or flowchart diagrams, and combinations of blocks included in the block diagrams and / or flowchart diagrams, may be implemented by a special-purpose hardware-based system that performs the specified function or operation or executes a combination of special-purpose hardware and computer instructions.
[0084] The description of various embodiments of the present invention is presented for illustrative purposes, but is not intended to be exhaustive and is not limited to the disclosed embodiments. Many changes and modifications will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terms used in this specification are selected to best explain the principles, practical applications, or technical improvements of the embodiments beyond those found in the market, or to enable others skilled in the art to understand the embodiments described herein.
[0085] Various embodiments of the present invention are described herein with reference to the associated drawings. Alternate embodiments of the present invention may be devised without departing from the scope of the present invention. In the following description and in the drawings, various connections and relationships (e.g., above, below, adjacent, etc.) between elements are shown. These connections and / or relationships may be direct or indirect unless otherwise specified, and the present invention is not intended to be limited in this respect. Thus, coupling of entities may refer to direct or indirect coupling, and relationships between entities may be direct or indirect. Furthermore, various operations and process steps described herein may be combined into a more comprehensive procedure or process that includes additional steps or functions not specifically described herein.
[0086] The following definitions and abbreviations are used in interpreting the claims and this specification. As used herein, the terms "comprises," "comprising," "includes," "including," "has," "having," "containing," or "containing," or any other variation thereof, are intended to cover a non-exclusive inclusion. For example, a composition, mixture, process, method, article, or apparatus that includes a list of elements is not necessarily limited to only those elements and can include other elements not expressly stated or inherent in such composition, mixture, process, method, article, or apparatus.
[0087] Additionally, the term "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments or designs. The terms "at least one" and "one or more" may be understood to include any integer number greater than or equal to one (i.e., 1, 2, 3, 4, etc.). The term "plurality" may be understood to include any integer number greater than or equal to two (i.e., 2, 3, 4, 5, etc.). The term "connected" may include both an indirect "connected" and a direct "connected."
[0088] The terms "about," "substantially," "approximately," and variations thereof are intended to include the degree of error associated with measurement of the particular quantity based on the equipment available at the time of filing this application. For example, "about" can include a range of ±8%, or 5%, or 2% of the particular value.
[0089] For purposes of brevity, prior art related to making and using aspects of the present invention may or may not be described in detail herein. In particular, various aspects of computing systems and particular computer programs for implementing various technical features described herein are well known. Thus, for purposes of brevity, many conventional implementation details are only briefly described or omitted entirely herein, without providing details of known systems and / or processes.
Claims
1. receiving, by a processor of a computing device, a command request from a mobile device (110A), the command request including an encrypted key portion and an encrypted signature key; decrypting, by a Hardware Security Module (HSM) (140), the command request using a key associated with a security zone of the mobile device; decrypting, by the HSM, the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using the key associated with the security zone of the mobile device and a key associated with a remote administrator associated with the mobile device; generating a command based on the command request to a domain containing a target HSM using the decrypted key portion and the decrypted signing key; sending the command to the domain for execution by the target HSM.
2. the command request further includes an encrypted logon key associated with the remote administrator, the computer-implemented method comprising: decrypting, by the HSM (140), the encrypted logon key to generate a decrypted logon key, wherein decrypting the encrypted logon key includes using the key associated with the security zone of the mobile device and the key associated with the remote administrator associated with the mobile device; The computer-implemented method of claim 1 , further comprising: sending the decrypted logon key along with the command to the domain.
3. receiving, by the processor of the computing device, a second command request from a second mobile device (110B), the second command request including a second encrypted key portion and a second encrypted signature key; decrypting, by the HSM (140), the second command request using the key associated with the security zone of the mobile device (110A); decrypting, by the HSM, the second encrypted key portion and the second encrypted signature key to generate a second decrypted key portion and a second decrypted signature key, wherein decrypting the second encrypted key portion and the second encrypted signature key includes using the key associated with the security zone and a different key associated with a different remote administrator associated with the second mobile device; generating a second command to the domain containing the target HSM using the second decrypted key portion and the second decrypted signing key; The computer-implemented method of claim 1 , further comprising: sending the second command to the domain.
4. The computer-implemented method of claim 3 , wherein the decrypted key portion and the second decrypted key portion are portions of a master key associated with the target HSM of the domain.
5. 2. The computer-implemented method of claim 1, further comprising provisioning the mobile device (110A) by registering the mobile device within the security zone and associating the mobile device with the remote administrator.
6. 2. The computer-implemented method of claim 1, further comprising signing the command using the decrypted signing key before sending the command to the domain for execution by the target HSM.
7. The computer-implemented method of claim 1 , further comprising sending a message to the mobile device (110A) based on the results received from the domain.
8. 1. A system comprising one or more processors for executing computer readable instructions, said computer readable instructions controlling said one or more processors to: receiving a command request from a mobile device (110A), the command request including an encrypted key portion and an encrypted signature key; decrypting, by a Hardware Security Module (HSM) (140), the command request using a key associated with a security zone of the mobile device; decrypting, by the HSM, the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using the key associated with the security zone of the mobile device and a key associated with a remote administrator associated with the mobile device; generating a command based on the command request to a domain containing a target HSM using the decrypted key portion and the decrypted signing key; and sending the command to the domain for execution by the target HSM.
9. The command request further includes an encrypted logon key associated with the remote administrator, and the action is: decrypting, by the HSM (140), the encrypted logon key to generate a decrypted logon key, wherein decrypting the encrypted logon key includes using the key associated with the security zone of the mobile device and the key associated with the remote administrator associated with the mobile device; 9. The system of claim 8, further comprising: transmitting the decrypted logon key along with the command to the domain.
10. The operation is receiving a second command request from a second mobile device (110B), the second command request including a second encrypted key portion and a second encrypted signature key; decrypting, by the HSM (140), the second command request using the key associated with the security zone of the mobile device (110A); decrypting, by the HSM, the second encrypted key portion and the second encrypted signature key to generate a second decrypted key portion and a second decrypted signature key, wherein decrypting the second encrypted key portion and the second encrypted signature key includes using the key associated with the security zone and a different key associated with a different remote administrator associated with the second mobile device; generating a second command to the domain containing the target HSM using the second decrypted key portion and the second decrypted signing key; and transmitting the second command to the domain.
11. 11. The system of claim 10, wherein the decrypted key portion and the second decrypted key portion are portions of a master key associated with the target HSM of the domain.
12. 9. The system of claim 8, wherein the actions further include provisioning the mobile device by registering the mobile device within the security zone and associating the mobile device with the remote administrator.
13. 9. The system of claim 8, wherein the operations further include signing the command using the decrypted signing key before sending the command to the domain for execution by the target HSM.
14. The system of claim 8 , wherein the actions further include sending a message to the mobile device (110A) based on the results received from the domain.
15. 1. A computer program product comprising a computer-readable storage medium having program instructions embodied thereon, the computer program product comprising: receiving a command request from a mobile device (110A), the command request including an encrypted key portion and an encrypted signature key; decrypting, by a Hardware Security Module (HSM) (140), the command request using a key associated with a security zone of the mobile device; decrypting, by the HSM, the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using the key associated with the security zone of the mobile device and a key associated with a remote administrator associated with the mobile device; generating a command based on the command request to a domain containing a target HSM using the decrypted key portion and the decrypted signing key; and transmitting the command to the domain for execution by the target HSM.
16. The command request further includes an encrypted logon key associated with the remote administrator, and the action is: decrypting, by the HSM (140), the encrypted logon key to generate a decrypted logon key, wherein decrypting the encrypted logon key includes using the key associated with the security zone of the mobile device and the key associated with the remote administrator associated with the mobile device; 16. The computer program product of claim 15, further comprising: transmitting the decrypted logon key along with the command to the domain.
17. receiving a second command request from a second mobile device (110B), the second command request including a second encrypted key portion and a second encrypted signature key; decrypting, by the HSM (140), the second command request using the key associated with the security zone of the mobile device (110A); decrypting, by the HSM, the second encrypted key portion and the second encrypted signature key to generate a second decrypted key portion and a second decrypted signature key, wherein decrypting the second encrypted key portion and the second encrypted signature key includes using the key associated with the security zone and a different key associated with a different remote administrator associated with the second mobile device; generating a second command to the domain containing the target HSM using the second decrypted key portion and the second decrypted signing key; and transmitting the second command to the domain.
18. 18. The computer program product of claim 17, wherein the decrypted key portion and the second decrypted key portion are portions of a master key associated with the target HSM of the domain.
19. 16. The computer program product of claim 15, further comprising provisioning the mobile device (110A) by registering the mobile device within the security zone and associating the mobile device with the remote administrator.
20. 16. The computer program product of claim 15, further comprising signing the command using the decrypted signing key before sending the command to the domain for execution by the target HSM.
21. 16. The computer program product of claim 15, further comprising sending a message to the mobile device (110A) based on the results received from the domain.
22. receiving, by a processor of the computing device, a key read request from a mobile device (110A) associated with a remote administrator, the key read request including the encrypted key portion and the encrypted signature key; validating the key read request from the mobile device; decrypting the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key, wherein decrypting the encrypted key portion and the encrypted signature key includes using a private key corresponding to a public key of a certification authority (CA) certificate for a security zone and a private key corresponding to a public key of a CA certificate of the remote administrator's profile; constructing a key load command for the domain specified by the key load request, the key load command including a portion of the decrypted key and signed using the decrypted signing key; sending the key read command to the domain for execution by a target Hardware Security Module (HSM) of the domain.
23. 23. The computer-implemented method of claim 22, wherein the key read request is encrypted using the public key of the CA certificate for the security zone, and wherein validating the key read request comprises decrypting the key read request using the private key that corresponds to the public key of the CA certificate for the security zone.
24. receiving, by a processor of the secure computing device, from a mobile device (110A) associated with a remote administrator, an encrypted hardware security module (HSM) command request including an encrypted key portion and an encrypted signature key; decrypting the encrypted HSM command request from the mobile device; decrypting, by an HSM (140) of the secure computing device, the encrypted key portion and the encrypted signature key to generate a decrypted key portion and a decrypted signature key; generating an HSM command corresponding to the encrypted HSM command request for a specified domain based at least in part on the decrypted key portion and the decrypted signing key; sending the HSM command to the specified domain for execution by a target HSM of the specified domain.
25. 25. The computer-implemented method of claim 24, further comprising sending a message to the mobile device (110A) based on the results received from the specified domain.
Citation Information
Patent Citations
Secure communication of network traffic
JP2019531646A
Cryptographic key distribution
US20170222802A1
Methods for loading a profile to a secure element, manager and personalisable secure element
US20190121797A1