Key management methods, systems, and programs
The system integrates HSMs and key management services to manage encryption keys across multiple vendors and locations, addressing the limitations of traditional HSMs by enabling secure and flexible key operations in a multi-tenant cloud environment.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- INTERNATIONAL BUSINESS MACHINE CORPORATION
- Filing Date
- 2022-05-18
- Publication Date
- 2026-04-28
AI Technical Summary
In a multi-tenant cloud environment, hardware security modules (HSMs) cannot store all encryption keys for multiple clients, necessitating the storage of keys in a wrapped form outside the HSM, which complicates key management and security.
A system and method for integrated HSM and key management services that parse, translate, and route encryption key operation requests across vendor-specific HSMs, enabling location- and vendor-independent key operations by using a tableless router and middleware to manage encryption transactions.
Facilitates secure, efficient, and flexible key management across multiple HSMs, allowing clients to use any vendor's HSMs located anywhere, enhancing security and operational flexibility.
Smart Images

Figure 0007853041000001 
Figure 0007853041000002 
Figure 0007853041000003
Abstract
Description
[Technical Field]
[0001] This invention relates to encryption key management, and more particularly to key management for multiple hardware security modules (HSMs). [Background technology]
[0002] In a multi-tenant cloud environment, each client instance requires an encrypted key to access encrypted services or perform encrypted operations. Because a typical hardware security module (HSM) cannot store all the keys for all clients and the services they may request, keys may be stored outside the HSM in a wrapped (i.e., encrypted) form within a key storage management (KSM) database. The root key required to decrypt instance and service-related keys is stored in the HSM, and this process takes place within the HSM. [Overview of the Initiative]
[0003] Methods and systems for integrated HSM and key management services are disclosed. According to one embodiment, a cryptographic service request is issued by a client instance to key management service (KMS) logic in a KMS cloud instance. The KMS logic parses the request, verifies authorization for the request, identifies the instance ID, and provides additional information to the request as required by the Hardware Security Module (HSM) middleware and hardware. A router receives the request from the KMS logic, routes the request to the service based on the instance ID, and the service forwards the request to the HSM middleware. The HSM middleware parses the HSM type from the request, translates the request into HSM vendor-specific instructions, and routes the translated request to the HSM. According to one embodiment, the HSM is isolated from the KSM cloud instance in a cloud computing environment, and in some embodiments, the HSM is on-premises at a physical client site.
[0004] One embodiment of the present invention discloses a method in the Key Management System Database (KMS DB) of a KMS cloud instance that includes receiving a client service request from a client instance, which includes an encryption key operation request including an instance identification (ID) and a hardware security module ID (HSM ID), and routing the encryption key operation request to HSM middleware associated with the instance ID. The method further includes parsing the encryption key operation request into one or more encryption transactions in the HSM middleware based on the HSM ID, translating the one or more encryption transactions into a vendor-specific HSM language associated with the HSM ID, and sending the translated one or more encryption transactions to a vendor-specific HSM associated with the vendor-specific HSM language outside the KMS cloud instance, based on the instance ID and the HSM ID.
[0005] A computer program product for integrated HSM and key management services is disclosed, the computer program product including a computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable by one or more computer processors to receive client service requests from a client instance, including encryption key operation requests including an instance identification (ID) and a hardware security module ID (HSM ID) in the KMS cloud instance's key management system database (KMS DB), route the encryption key operation requests to the HSM middleware associated with the instance ID, and parse the encryption key operation requests into one or more cryptographic transactions in the HSM middleware based on the HSM ID. The computer-readable program code is further executable to translate one or more cryptographic transactions into a vendor-specific HSM language associated with the HSM ID, and to send the translated one or more cryptographic transactions to a vendor-specific HSM associated with the vendor-specific HSM language outside the KMS cloud instance, based on the instance ID and HSM ID.
[0006] A system is disclosed that includes memory containing computer-readable code for integrated HSM and key management services, and one or more processors configured with computer-readable code to receive client service requests from a client instance, including encryption key operation requests in the KMS cloud instance's key management system database (KMS DB), which include an instance identification (ID) and a hardware security module ID (HSM ID), and to route the encryption key operation requests to the HSM middleware associated with the instance ID. The one or more processors are further configured with computer-readable code to parse the encryption key operation requests in the HSM middleware based on the HSM ID into one or more encryption transactions, translate the one or more encryption transactions into a vendor-specific HSM language associated with the HSM ID, and, based on the instance ID and HSM ID, send the translated one or more encryption transactions to a vendor-specific HSM associated with the vendor-specific HSM language outside the KMS cloud instance. [Brief explanation of the drawing]
[0007] [Figure 1] This document illustrates a cloud computing environment according to one embodiment. [Figure 2] An abstract model layer according to one embodiment is shown. [Figure 3] A system for an integrated hardware security module (HSM) and key management service (KMS) according to one embodiment is shown. [Figure 4] A flowchart for an integrated HSM and key management service according to one embodiment is shown. [Figure 5] A method for an integrated HSM and key management service according to one embodiment is shown. [Figure 6] An exemplary computing system for an integrated HSM and key management service, according to one embodiment, is shown. [Modes for carrying out the invention]
[0008] The following references are made to embodiments presented in this disclosure. However, the scope of this disclosure is not limited to the embodiments specifically described. Instead, any combination of the following features and elements should be considered for carrying out and practicing possible embodiments, whether or not they relate to different embodiments. Furthermore, embodiments disclosed herein may achieve advantages that exceed other possible solutions or the prior art, but whether or not a particular advantage is achieved by a given embodiment does not limit the scope of this disclosure. Accordingly, the following aspects, features, embodiments, and advantages are merely illustrative and should not be considered elements or limitations of the appended claims unless expressly enumerated in the claims. Similarly, references to “invention” should not be interpreted as generalizations of any inventive subject matter disclosed herein and should not be considered elements or limitations of the appended claims unless expressly enumerated in the claims.
[0009] Methods and systems for integrated HSM and key management services are disclosed. According to one embodiment, a cryptographic service request is issued by a client instance to key management service (KMS) logic in a KMS cloud instance. The KMS logic parses the request, verifies authorization for the request, identifies the instance ID, and provides additional information to the request as required by the Hardware Security Module (HSM) middleware and hardware. A router receives the request from the KMS logic, routes the request to the service based on the instance ID, and the service forwards the request to the HSM middleware. The HSM middleware parses the HSM type from the request, translates the request into HSM vendor-specific instructions, and routes the translated request to the HSM. According to one embodiment, the HSM is isolated from the KSM cloud instance in a cloud computing environment, and in some embodiments, the HSM is on-premises at a physical client site.
[0010] While this disclosure includes a detailed description of cloud computing, it should be understood that the embodiments of the teachings set forth herein are not limited to cloud computing environments. Rather, embodiments of the present invention can be implemented in conjunction with any other type of computing environment that is currently known or may be developed in the future.
[0011] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that are rapidly provisioned and released with minimal administrative effort or interaction with service providers. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.
[0012] The characteristics are as follows:
[0013] On-demand self-service: Cloud consumers can unilaterally provision computing capabilities such as server time and network storage automatically as needed, without requiring human interaction with service providers.
[0014] Broad network access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).
[0015] Resource sharing: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically allocated and reallocated according to demand. Location independence has implications in that consumers generally do not have control or knowledge of the exact location of the resources provided, but may be able to specify the location at a higher level of abstraction (e.g., country, state, or data center).
[0016] Rapid Scalability: Capabilities can be provisioned quickly and elastically to scale out instantly, sometimes automatically, and released quickly to scale in instantly. To consumers, the capabilities available for provisioning often appear unlimited and can be purchased at any quantity at any time.
[0017] Measurability of services: The cloud system automatically controls and optimizes resource usage by leveraging measurement capabilities at an abstract level suitable for the types of services (e.g., storage, processing, bandwidth, and active user accounts). The amount of resource usage can be monitored, controlled, and reported, providing transparency to both the provider and consumer of the services being utilized.
[0018] The service model is as follows.
[0019] Software as a Service (SaaS): The capabilities provided to the consumer are to use the provider's applications running on the cloud infrastructure. The applications are accessible from various client devices through a thin - client interface such as a web browser (e.g., web - based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating system, storage, or even individual application capabilities, although limited user - specific application configuration settings may be an exception.
[0020] Platform as a Service (PaaS): The capabilities provided to the consumer are to deploy consumer - created or consumer - acquired applications, created using programming languages and tools supported by the provider, onto the cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating system, or storage, but has control over the deployed applications and, to the extent possible, the application - hosting environment configuration.
[0021] Infrastructure as a Service (IaaS): The capabilities provided to the consumer are to provision other basic computing resources that enable the deployment and execution of processing, storage, networks, and any software that the consumer may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over the operating systems, storage, deployed applications, and performs limited control over the select networking components (e.g., host firewalls) as much as possible.
[0022] The deployment models are as follows.
[0023] Private cloud: The cloud infrastructure is operated solely for an organization. The cloud infrastructure may be managed by the organization or a third party and may exist on-premises or off-premises.
[0024] Community cloud: The cloud infrastructure is shared by multiple organizations and supports a specific community with shared concerns (e.g., mission, security requirements, policies, and compliance considerations). The cloud infrastructure may be managed by the organization or a third party and may exist on-premises or off-premises.
[0025] Public cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services.
[0026] Hybrid cloud: The cloud infrastructure remains a unique entity but is a composition of two or more clouds (private, community, or public) joined by standardized or proprietary technologies (e.g., cloud bursting for load balancing between clouds) that enable data and application portability.
[0027] Cloud computing environments are service-oriented, centered on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is the infrastructure, including a network of interconnected nodes.
[0028] Referring here to Figure 1, an exemplary cloud computing environment 50 is shown. As illustrated, the cloud computing environment 50 includes one or more cloud computing nodes 10 that can communicate with local computing devices used by cloud consumers, such as personal digital assistants (PDAs) or mobile phones 54A, desktop computers 54B, laptop computers 54C, or automotive computer systems 54N, or a combination thereof. The nodes 10 can communicate with each other. They can be grouped physically or virtually within one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or a combination thereof (not shown). This makes it possible for the cloud computing environment 50 to offer infrastructure, platforms, or software, or a combination thereof, as a service that does not require cloud consumers to maintain resources on their local computing devices. The types of computing devices 54A-N shown in Figure 1 are intended to be illustrative only, and it should be understood that the computing node 10 and the cloud computing environment 50 can communicate with any type of computerized device via any type of network or network-addressable connection or both (for example, using a web browser).
[0029] Referring here to Figure 2, a set of functional abstraction layers provided by the cloud computing environment 50 (Figure 1) is shown. The components, layers, and functionalities shown in Figure 2 are intended to be illustrative only, and it should be understood in advance that embodiments of the invention are not limited thereto. As illustrated, the following layers and corresponding functionalities are provided:
[0030] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include a mainframe 61, a RISC (Reduced Instruction Set Computer) architecture-based server 62, a server 63, a blade server 64, a storage device 65, and network and networking components 66. In some embodiments, the software components include network application server software 67 and database software 68.
[0031] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities are provided: virtual servers 71, virtual storage 72, virtual networks 73 including virtual private networks, virtual applications and operating systems 74, and virtual clients 75.
[0032] For example, the management layer 80 may provide the functions described below. Resource provisioning 81 provides the dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Measurement and pricing 82 provides cost tracking as resources are used within the cloud computing environment and provides billing or invoices for the consumption of these resources. For example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources. The user portal 83 provides consumers and system administrators with access to the cloud computing environment. Service level management 84 provides cloud computing resource allocation and management to ensure that the required service levels are met. Service level agreement (SLA) planning and execution 85 provides the pre-placement and procurement of cloud computing resources whose future needs are anticipated in accordance with the SLA.
[0033] The workload layer 90 provides examples of functions that utilize the cloud computing environment. Examples of workloads and functions provided from this layer include mapping and navigation 91, software development and lifecycle management 92, virtual classroom education delivery 93, data analysis processing 94, transaction processing 95, and management for cryptographic operations services and client instances.
[0034] Figure 3 shows a system 300 for an integrated hardware security module (HSM) and key management service (KMS) according to one embodiment. The system 300 includes a client instance 303, which may be an instance within a KMS cloud instance 306, which may be a virtual cloud such as a virtual private cloud, or an instance coupled to the KMS cloud instance 306. According to one embodiment, the KMS cloud instance 306 is a cloud environment hosted in a closed, distributed computing environment, which in one embodiment may be a public cloud. The KMS cloud instance 306 includes key management system (KMS) logic 309, which includes key management logic and at least one key management database. The KMS logic 309 is coupled to a router 311, which is implemented as a virtual computing cluster such as a Kubernetes cluster. According to one embodiment, the router 311 may be a tableless router and leverage the routing capabilities of the virtual computing cluster's inherent routing capabilities. By not utilizing routing tables, embodiments using a table-less version of router 311 can achieve better computing performance by freeing up memory used by such tables. Furthermore, the virtual compute cluster employed in router 311 may be used to deploy additional components of KMS cloud instance 306, such as KMS logic 309, services, middleware, and gateways, as described later. In these embodiments, router 311 uses the client instance ID and service request to forward the request from KMS logic 309 to service 1313~service, based on a service request from client instance 303, which will be described in more detail below in relation to Figure 4. n+1 It redirects to one of several service handlers, such as 321. Service 1313 ~ Service n+1321 may be multi-tenant (MT) or single-tenant (ST) depending on the nature of the clients and additional systems connected to the KMS cloud instance 306. In the embodiment shown in Figure 3, the KMS cloud instance 306 is connected to client instance 303, as well as the cloud system and the on-premises system.
[0035] For example, router 311 forwards client service requests for key management to service 1313, and service 1313 similarly provides service requests to hardware security module (HSM1) middleware 324. HSM1 middleware 324 then provides HSM1 middleware 324~HSM n+1Middleware 333 is one of several HSM middlewares connected to Router 311. The HSM middleware includes a database of HSM vendor HSM products and a language associated with each product. When a client service request is received, the HSM middleware receiving the request parses request metadata indicating the specific HSM requested by the client and associates the request with a translation module for translating the request into a language that the HSM can receive and respond to. According to the disclosed embodiment, a client service request passed through Router 311 is received by HSM1 middleware 324. HSM1 middleware 324 parses the client service request to determine the Hardware Security Module (HSM) (described below) requested to perform the service request, determines the vendor-specific HSM language associated with the requested HSM, and translates the client service request into the appropriate HSM language. By recognizing vendor-specific HSM languages and translating client service requests into appropriate HSM languages, client service requests for HSM services may be HSM vendor-independent, allowing client instances to request services from any number of HSMs depending on the nature of the request and the desired level of security. Furthermore, since router 311 can direct client service requests to the correct HSM middleware for a given HSM required by the request, the location of the HSMs required to serve a client service request may be in the same cloud as client instance 303, a different cloud, on-premises at a physical client site, or any site specified by the HSM service provider.By enabling location-independent and HSM vendor-independent requests, vendor and location-independent lock-in is avoided, thereby allowing clients to use HSMs provided by any vendor, hosted virtually or physically in any location the client deems appropriate, and providing clients with the degree or scope of control over the physical security of the HSM as required by the client.
[0036] Each of the HSM middleware 324-333 is connected to gateway 1336-gateway n It is connected to gateways such as 339. Each gateway is connected to KMS cloud instance 306 and network 1342~network n To manage data flow to and from networks connected to KMS cloud instance 306, such as 345, the gateway provides functionality to KMS cloud instance 306 to act as a boundary for KMS cloud instance 306. According to one embodiment, the gateway may be a dedicated hardware device or may be implemented as software on a dedicated computer or distributed computing system.
[0037] The receiving gateway communicates client service requests to an appropriate network, such as one of networks 342-345. (HSM1349-HSM) n+1 In an HSM, such as one of the above, a client service request may be performed by providing an encryption operation. In this context, the encryption operation in the HSM may be the encryption of one or more service keys using a customer root key (CRK) stored in the HSM in response to a client service request, thereby enabling client instance 303 to perform the encryption operation. In this context, the encryption operation may include, for example, encryption, decryption, wrapping, unwrapping, signing, and one or more service keys, in addition to key generation, rotation, and deletion.
[0038] Figure 4 shows a flowchart 400 for an integrated HSM and key management service according to one embodiment. At node 405, a client instance such as client instance 103 in Figure 3 issues a client service request, such as a “key wrapping” encryption key operation request, to encrypt a specific data encryption key (DEK) to the Key Management Service (KMS) logic, such as KMS logic 309 (i.e., “wrap” the key). The KMS logic verifies the client service request at node 410. In this context, the KMS logic checks the client service request credentials (e.g., instance ID, password, and authorization key) for proper authorization at node 415, makes the request, and extracts the client instance ID. At node 420, data in the KMS logic database associated with the instance ID, such as the instance key encryption key (IKEK), is associated with the client service request. The KMS logic then checks the instance ID for the single-tenant (ST) tag at node 425, and services 1116-service n+1 The client service request is forwarded to a service associated with the client instance, such as one of 321. According to one embodiment, the service may be addressed by "<client instance>-service" by system 100 in Figure 3. Note that in one embodiment, the instance ID may have a multitenant (MT) tag, which is then routed accordingly. In this example, the instance ID has an ST tag, and the disclosure herein applies equally to instance IDs having an MT tag. The KMS logic adds any additional information necessary to satisfy the client service request based on data collected from the client instance's KMS logic DB entry. According to one embodiment, the additional information may relate, in this example, to a key hierarchy related to the wrapped key.
[0039] At node 435, the client service request is routed through a router such as router 311 in FIG. 3. The router performs a lookup of a service such as one of services 1116 to service n+1 321 based on the instance ID of the client instance. The service, in this example, transfers the client service request to an HSM middleware such as one of HSM middleware 327 to HSM n+1 middleware 333 in FIG. 3.
[0040] At node 440, HSM middleware such as HSM middleware 327 to HSM n+1 middleware 333 in FIG. 3 issues a specific HSM transformation request based on the HSM ID referenced in the client service request for the HSM. The HSM middleware parses the request, issues the associated HSM transaction to the associated HSM, and the HSM can be located anywhere accessible on the network connected to the HSM middleware. At node 445, an HSM such as one of HSM2351 to HSM n+1 357 in FIG. 3 executes the service request and provides the result to the HSM middleware. In the current example, in the case of an "encryption key wrapping" request, the HSM middleware unwraps the IKEK and the custom root key (CRK) associated with the client instance, and then receives a random number used for encrypting the "wrapped" key from the HSM.
[0041] At node 450, the HSM middleware transfers the executed service request, in this example, the "wrapped" key, and provides it to the router. At node 455, the executed service request is transferred to the KMS logic and, at node 460, is transferred from the KMS logic to the client instance.
[0042] Figure 5 shows a method 500 for an integrated HSM and key management service according to one embodiment. In operation 505, the method receives a client service request from a client instance in the Key Management System Database (KMS DB) of the KMS cloud instance, which includes an encryption key operation request that includes an instance identifier (ID) and a hardware security module ID (HSM ID).
[0043] In operation 510, the encryption key operation request is routed to the HSM middleware associated with the instance ID. According to one embodiment, routing the encryption key is performed by a tableless router including the cluster, and the routing is based on the cluster's implicit routing capabilities.
[0044] In operation 515, method 500 parses the encryption key operation request into one or more encryption transactions in the HSM middleware based on the HSM ID.
[0045] In operation 520, one or more encrypted transactions are translated into the vendor-specific HSM language associated with the HSM ID.
[0046] In operation 525, method 500 sends one or more translated cryptographic transactions to a vendor-specific HSM associated with a vendor-specific HSM language outside the KMS cloud instance, based on the instance ID and HSM ID.
[0047] According to one embodiment, Method 500 may further include receiving one or more completed encrypted transactions from an HSM ID in HSM middleware within a KMS cloud instance, receiving the one or more completed encrypted transactions in a router, and providing the one or more completed encrypted transactions to a client instance. According to one embodiment, receiving a client service request includes verifying authorization of the client service request, and the encrypted transaction includes receiving a data encryption key (DEK) request from the client instance. According to one embodiment, the method includes decrypting an instance key encryption key (IKEK) and a customer root key (CRK) in the HSM. The method may further include receiving a random number from the HSM and issuing a start-continue-end encrypted transaction in the HSM. According to one embodiment, the one or more completed encrypted transactions are DEKs.
[0048] Figure 6 shows an exemplary computing system 600 for an integrated HSM and key management service according to one embodiment, the computing system 600 may perform methods described herein, such as those shown in Figures 4 and 5.
[0049] The computing system 600 includes a central processing unit (CPU) 602 connected to a data bus 616. The CPU 602 is configured to process computer-executable instructions stored, for example, in memory 608 or storage 610, in order to cause the computing system 600 to perform the methods described herein, for example with respect to Figures 4 and 5. The CPU 602 is included to represent a single CPU, multiple CPUs, a single CPU with multiple processing cores, and other forms of processing architecture capable of executing computer-executable instructions.
[0050] The computing system 600 further includes an input / output (I / O) device 612 and an interface 604, the interface 604 enabling the computing system 600 to interface with the input / output device 612, such as a keyboard, display, mouse device, pen input, and other devices that enable interaction with the computing system 600. Note that the computing system 600 may connect to external I / O devices (e.g., external display devices) through physical and wireless connections.
[0051] The computing system 600 further includes a network interface 606, which provides the computing system 600 with access to an external network 614 and thereby to external computing devices.
[0052] The computing system 600 further includes a memory 608, which in this example includes a receive module 618, a routing module 620, a parse module 624, a translation module 626, and a transmit module 626, as described in relation to Figures 3 to 5, for performing the operations described in Figures 4 and 5.
[0053] For simplicity, Figure 6 shows a single memory 608, but it should be noted that the various forms stored in memory 608 are stored in different physical memories, including memory located remotely from the computing system 600, except for those accessible by the CPU 602 via internal data connections such as the bus 616.
[0054] Storage 610 includes client service request data 628, client instance data 630, encryption key operation data 632, HSM middleware data 634, router data 636, transformation data 638, and vendor-specific HSM data 640, as described in relation to Figures 4 and 5.
[0055] The descriptions of various embodiments of the present invention are presented for illustrative purposes only and are not intended to be exhaustive or limit the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein has been selected to best describe the principles of the embodiments, their practical applications, or the technical improvements to the technology available on the market, or to make the embodiments disclosed herein understandable to others skilled in the art.
[0056] In the foregoing, references have been made to embodiments presented in this disclosure. However, the scope of this disclosure is not limited to the embodiments specifically described. Instead, any combination of features and elements is considered for carrying out and practicing possible embodiments, whether or not they relate to different embodiments. Furthermore, while embodiments disclosed herein may achieve advantages that exceed other possible solutions or the prior art, whether or not a particular advantage is achieved by a given embodiment does not limit the scope of this disclosure. Thus, the aspects, features, embodiments, and advantages discussed herein are merely illustrative and should not be considered elements or limitations of the appended claims unless expressly enumerated in the claims. Similarly, references to “invention” should not be interpreted as generalizations of any inventive subject matter disclosed herein and should not be considered elements or limitations of the appended claims unless expressly enumerated in the claims.
[0057] Aspects of the present invention may take the form of a complete hardware embodiment, a complete software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware embodiments, all generally referred to herein as “circuit,” “module,” or “system.”
[0058] The present invention may be a system, method, or computer program product, or a combination thereof, at any possible level of technical detail of integration. A computer program product may include a computer-readable storage medium (or a set of mediums) having computer-readable program instructions thereon for causing a processor to perform an aspect of the present invention.
[0059] A computer-readable storage medium may be a tangible device capable of holding and storing instructions for use by an instruction-executing device. A computer-readable storage medium may, but is not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of those described above. A non-exhaustive list of more specific examples of computer-readable storage media includes portable computer diskettes, hard disks, random-access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random-access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disks (DVDs), memory sticks, floppy(R) disks, mechanically encoded devices such as punch cards or grooved raised structures on which instructions are recorded, and any suitable combination of those described above. The computer-readable storage media used herein should not be interpreted as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses passing through optical fiber cables), or electrical signals transmitted through wires.
[0060] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface within each computing / processing device receives computer-readable program instructions from the network and transfers them for storage on the computer-readable storage medium within each computing / processing device.
[0061] The computer-readable program instructions for performing the operation of the present invention may be either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk(R) and C++, and procedural programming languages such as the C programming language or a similar programming language. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions by individualizing the electronic circuit using state information of computer-readable program instructions in order to carry out aspects of the present invention.
[0062] Aspects of the present invention are described herein with reference to flowcharts or block diagrams, or both, of methods, apparatus (systems), and computer program products according to embodiments of the invention. Each block in the flowchart or block diagram, or both, and any combination of blocks in the flowchart or block diagram, or both, should be understood to be implemented by computer-readable program instructions.
[0063] These computer-readable program instructions may be provided to a computer or a processor of another programmable data processing device for manufacturing machines, such that the instructions executed by the processor of the computer or other programmable data processing device generate means for performing functions / operations specified in one or more blocks of a flowchart or block diagram or both. These computer-readable program instructions may also be stored in a computer-readable storage medium in which the instructions are stored, such that the storage medium contains a product containing instructions for performing modes of functions / operations specified in one or more blocks of a flowchart or block diagram or both.
[0064] Computer-readable program instructions may also be loaded onto a computer, other programmable device, or other device to perform a series of operational steps on the computer, other programmable device, or other device in order to produce a computer-executed process.
[0065] The flowcharts and block diagrams in the drawings illustrate the architecture, function, and operation of possible embodiments of the systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or part of an instruction containing one or more executable instructions for performing a specified logical function. In some alternative embodiments, the functions described within a block may occur in an order other than that shown in the drawings. For example, two consecutively shown blocks may actually be executed simultaneously, substantially simultaneously, partially or entirely in overlapping time, to be realized as a single step, or the blocks may be executed in reverse order depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, or both, and any combination of blocks in a block diagram or flowchart, or both, is performed by a dedicated hardware-based system that performs a specified function or operation, or executes a combination of dedicated hardware and computer instructions.
[0066] Embodiments of the present invention may be provided to end users through a cloud computing infrastructure. Cloud computing generally refers to the provisioning of scalable computing resources as a service over a network. More formally, cloud computing may be defined as a computing capability that provides an abstraction between computing resources and their underlying technical architecture (e.g., servers, storage, networks), enabling convenient on-demand network access to a shared pool of configurable computing resources that are rapidly provisioned and released with minimal administrative effort or service provider interaction. Thus, cloud computing enables users to access virtual computing resources in the “cloud” (e.g., storage, data, applications, and even fully virtualized computing systems) regardless of the underlying physical systems (or the location of those systems) used to provide the computing resources.
[0067] Typically, cloud computing resources are provided to users on a pay-per-use basis, where users are charged only for the computing resources actually used (e.g., the amount of storage space consumed by the user, or the number of virtualization systems instantiated by the user). Users can access any of the resources residing in the cloud at any time, from anywhere over the internet or a connected network. In the context of the present invention, users can access applications or related data available in the cloud. For example, a system and method for an integrated HSM and key management service according to one embodiment can run on a computing system in the cloud and provide encryption operations and encryption key management operations. In such a case, the system and method for an integrated HSM and key management service can receive encryption operations as client service requests from a client instance, and the HSM can receive encryption keys returned from the HSM, which is provisioned in the cloud or stored on-premises at the client site and suitable for encryption / decryption operations, at the client instance. By doing so, users can access this information from any computing system attached to a network connected to the cloud (e.g., the internet).
[0068] While the above describes embodiments of the present invention, other embodiments and further embodiments of the invention can be devised without departing from the basic scope and the scope defined by the following claims.
Claims
1. It is a method, In the KMS cloud instance's key management system database (KMS DB), receiving a client service request from a client instance, wherein the client service request includes an encryption key operation request that includes an instance identifier (ID) and a hardware security module ID (HSM ID), and the receiving of such request. The encryption key operation request is routed to the HSM middleware associated with the instance ID. Based on the HSM ID, the HSM middleware parses the encryption key operation request into one or more encryption transactions. Converting one or more of the aforementioned encrypted transactions into the vendor-specific HSM language associated with the HSM ID, Based on the instance ID and the HSM ID, the one or more encrypted transactions that have been converted are sent to a vendor-specific HSM associated with the vendor-specific HSM language outside the KMS cloud instance. Methods that include...
2. Within the KMS cloud instance, the HSM middleware receives one or more completed encrypted transactions from a vendor-specific HSM identified by the HSM ID. The router receives the completed one or more encrypted transactions, To provide the completed one or more encrypted transactions to the client instance. The method according to claim 1, further comprising:
3. The method according to claim 1, wherein routing of the encryption key operation request is performed by a tableless router including a cluster, and the routing is based on the implicit routing function of the cluster.
4. The method of claim 2, wherein receiving the client service request further includes verifying the authorization of the client service request, and the encryption transaction includes receiving a data encryption key (DEK) request from the client instance.
5. The method according to claim 4, further comprising decrypting the instance key encryption key (IKEK) and the customer root key (CRK) in the vendor-specific HSM.
6. The method according to claim 5, further comprising receiving a random number from the vendor-specific HSM and issuing a start-continue-end encrypted transaction in the vendor-specific HSM.
7. The method according to claim 6, wherein the completed one or more encrypted transactions include a DEK.
8. A computer program product for integrated HSM and key management services, wherein the computer program product is Includes a computer-readable storage medium having embodied computer-readable program code, wherein the computer-readable program code is In the KMS cloud instance's key management system database (KMS DB), a client service request is received from the client instance, including an encryption key operation request that includes the instance identifier (ID) and hardware security module ID (HSM ID). The encryption key operation request is routed to the HSM middleware associated with the instance ID. Based on the HSM ID, the HSM middleware parses the encryption key operation request into one or more encryption transactions. Convert the one or more encrypted transactions into the vendor-specific HSM language associated with the HSM ID, Based on the instance ID and the HSM ID, the one or more converted encrypted transactions are sent to a vendor-specific HSM associated with the vendor-specific HSM language outside the KMS cloud instance. A computer program product that is executed on one or more computer processors.
9. The aforementioned computer-readable program code, Within the KMS cloud instance, the HSM middleware receives one or more completed encrypted transactions from a vendor-specific HSM identified by the HSM ID. The router receives the one or more completed encrypted transactions. Provide the completed one or more encrypted transactions to the client instance. The computer program product according to claim 8, which is executed by one or more computer processors as described above.
10. The computer program product according to claim 8, wherein routing of the encryption key operation requests is performed by a tableless router including a cluster, and the routing is based on the implicit routing function of the cluster.
11. The computer program product according to claim 9, wherein the computer-readable program code that causes one or more processors to receive the client service request further causes one or more processors to verify the authorization of the client service request, and the encrypted transaction receives a data encryption key (DEK) request from the client instance.
12. The computer program product according to claim 11, wherein the computer-readable program code causes one or more computer processors to further execute the decryption of the instance key encryption key (IKEK) and the customer root key (CRK) in the vendor-specific HSM.
13. The computer program product according to claim 12, wherein the computer-readable program code causes one or more computer processors to further execute a start-continue-end encrypted transaction in the vendor-specific HSM, which receives a random number from the vendor-specific HSM.
14. The computer program product according to claim 13, wherein the one or more completed encrypted transactions include a DEK.
15. It is a system, Memory containing computer-readable code for integrated HSM and key management services, One or more processors, In the KMS cloud instance's key management system database (KMS DB), a client service request is received from the client instance, and the client service request includes an encryption key operation request that includes the instance identifier (ID) and the hardware security module ID (HSM ID). The encryption key operation request is routed to the HSM middleware associated with the instance ID. Based on the HSM ID, the HSM middleware parses the encryption key operation request into one or more encryption transactions. Convert the one or more encrypted transactions into the vendor-specific HSM language associated with the HSM ID, Based on the instance ID and the HSM ID, the one or more converted encrypted transactions are sent to a vendor-specific HSM associated with the vendor-specific HSM language outside the KMS cloud instance. The one or more processors, which are composed of the computer-readable code, A system equipped with these features.
16. The aforementioned computer-readable code is Within the KMS cloud instance, the HSM middleware receives one or more completed encrypted transactions from a vendor-specific HSM identified by the HSM ID. The router receives the one or more completed encrypted transactions. Provide the completed one or more encrypted transactions to the client instance. The system according to claim 15, further executed by the one or more processors.
17. The system according to claim 15, wherein routing of the encryption key operation requests is performed by a tableless router including a cluster, and the routing is based on the implicit routing function of the cluster.
18. The system according to claim 16, wherein the computer-readable code causing one or more processors to receive the client service request further causes one or more processors to verify the authorization of the client service request, and the encrypted transaction receives a data encryption key (DEK) request from the client instance.
19. The system according to claim 18, wherein the computer-readable code is further executed by one or more processors to decrypt the instance key encryption key (IKEK) and the customer root key (CRK) in the vendor-specific HSM.
20. The system according to claim 19, wherein the computer-readable code is further executed by one or more processors to receive random numbers from the vendor-specific HSM and issue start-continue-end encrypted transactions in the vendor-specific HSM.
Citation Information
Patent Citations
Data security processing with expected value
JP2018504806A
Key management system and method
WO2019212773A1
Cloud based key management
WO2019245676A1