Availability of signature keys

By monitoring and managing the availability of signature keys across cryptographic modules, the method addresses the challenge of ensuring one-time use, enhancing security and availability in cryptographic operations.

WO2026154008A1PCT designated stage Publication Date: 2026-07-23UTIMACO IS GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
UTIMACO IS GMBH
Filing Date
2026-01-14
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Stateful cryptographic algorithms require careful handling to ensure that one-time signature keys are used only once to maintain security, as manual processes are error-prone and automated processes can lead to bottlenecks in availability.

Method used

Implement a method to monitor and manage the availability of signature keys across multiple cryptographic modules, determining deviations from predefined policies and initiating corrective actions to maintain availability, ensuring each key is used only once.

Benefits of technology

Ensures high-security signing processes without bottlenecks by maintaining the availability of one-time signature keys, enhancing the reliability and efficiency of cryptographic operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2026050830_23072026_PF_FP_ABST
    Figure EP2026050830_23072026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is inter alia a method, wherein the method comprises: - obtaining information indicating a current availability of signature keys at at least one cryptographic module of a plurality of cryptographic modules; - determining whether the current availability deviates from a predefined availability of the signature keys at the at least one cryptographic module; and - causing a corrective action if it is determined that the current availability deviates from the predefined availability.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] RU 241380DE / fb

[0002] Availability of signature keys

[0003] TECHNICAL FIELD

[0004] Various exemplary embodiments according to the present disclosure relate to the availability of signature keys at at least one cryptographic module. It is to be understood that the presentation of various exemplary embodiments in the following is merely by way of examples and is not to be construed as limitations on the scope of the present disclosure.

[0005] BACKGROUND

[0006] Stateful cryptographic algorithms require special handling in the operational phase, in order to take the state and the associated consequences into account. For example, the private signature keys of so-called stateful hash-based signature algorithms consist of a set of one-time signature keys. It must be ensured in the operational phase that each of these one-time signature keys is used no more than once, otherwise a significant loss of security occurs.

[0007] If state handling involves manual security processes carried out by a human, there is a very high risk of errors that directly lead to a loss of long-term security (which may go unnoticed by the operator). If, however, technologically secured security processes are used for state handling, there is no risk of a loss of security, although manual handling, monitoring of the state, etc. is still required. This manual part does not endanger the security of the signature system, but it can lead to bottlenecks in availability.

[0008] SUMMARY OF SOME EXEMPLARY EMBODIMENTS

[0009] Various example embodiments according to the present disclosure may have the effect of ensuring availability of signature keys at a plurality of cryptographic modules. In particular, state management policies indicating a predefined availability of stateful signature keys may be monitored, causing a corrective action if is determined that a current availability deviates from a predefined availability of the stateful signature keys.According to a first aspect of the present disclosure, a method is disclosed, wherein the method comprises:

[0010] obtaining information indicating a current availability of signature keys at at least one cryptographic module of a plurality of cryptographic modules;

[0011] determining whether the current availability deviates from a predefined availability of the signature keys at the at least one cryptographic module; and

[0012] causing a corrective action if it is determined that the current availability deviates from the predefined availability.

[0013] According to a second aspect of the present disclosure, a method is disclosed, wherein the method comprises:

[0014] receiving, at a cryptographic module, information indicating a corrective action, after it is determined that a current availability of signature keys at the cryptographic module deviates from a predefined availability of the signature keys at the cryptographic module; and

[0015] implementing the corrective action.

[0016] Further according to the first and second aspect, a respective apparatus is disclosed, wherein the apparatus is configured to perform and / or control or wherein the apparatus comprise means (e.g. computer means) for performing and / or controlling the respective method according to the first, second or third aspect. Such means of the apparatus may for example be implemented in hardware and / or software. They may comprise for example at least one processor for executing computer program code for performing the required functions, at least one memory storing the program code, or both. Alternatively or additionally, they may for example comprise circuitry that is designed to implement the required functions, for example implemented in a chipset or a chip, like an integrated circuit In general, the means may comprise for example one or more processing means or processors.

[0017] Further according to the first and second aspect, a respective apparatus is disclosed, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform and / or to control the respective method according to the firstand second aspect

[0018] RU / fb 241380DEAn apparatus according to the first aspect may for example be a network apparatus (e.g. a network server) that may be configured to manage network resources (e.g. network traffic) within a network (e.g. a Local Area Network, Wide Area Network or Cellular Network). Therein, a network (e.g. a computer network) may for example be understood as group of interconnected devices (e.g. computers, servers, printers, and other hardware) that may be connected through communication channels (e.g. wires, fibre optics or wireless connections) for facilitating communication and resource sharing. For example, the network apparatus (e.g. a SM unit) according to the first aspect may be part of a network including one or more apparatuses according to the second aspect (e.g. one or more cryptographic modules). Considering for example a network comprising a plurality of cryptographic modules, a SM unit as the network apparatus according to the first aspect may for example receive signing request from an application and forward theses signing requests to the plurality of cryptographic modules.

[0019] An apparatus according to the second aspect may for example be a cryptographic module such as a hardware security module (HSM) or a respective unit (e.g. a control unit or a local SM unit) of an HSM. An HSM may for example be understood as a device that safeguards and manages and / or generates electronic keys, performs encryption and decryption, authentication and other cryptographic functions. For example, an HSM may comprise tamper-resistant and tamper-evident hardware components, such as secure chips and sensors, for preventing unauthorized access, hacking or physical attacks. In particular, an HSM may for example comprise a secure cryptographic processor configured to provide cryptographic functions and secure key management An HSM may for example further comprise a secure electronic memory for storing cryptographic keys (e.g. signature keys) and other sensitive data. Such an electronic memory may be secured by physical security measures and may include tamper- resistant features to prevent unauthorized access. To give some non-limiting examples, these physical security measures may be tamper-evident seals, intrusion detection sensors or self-destruct mechanisms to prevent physical attacks and tampering. An HSM may for example further comprise one or more secure communication interfaces, which may allow for secure data transfer. To give some non-limiting examples, these secure communication interfaces may be U B, Ethernet, or similar communication interfaces that support secure transmission protocols. An HSM may for example be operated by a particular management software that allow for configuring the HSM, monitoring usage and managing keys or security policies.

[0020] RU / fb 241380DEFurther according to the first and second aspect, a respective computer program is disclosed, wherein the computer program when executed by a processor of an apparatus causes the apparatus to perform the respective method according to the first or second aspect

[0021] The computer program may be stored on computer-readable storage medium, in particular a tangible and / or non-transitory medium. The computer readable storage medium could for example be a disk or a memory or the like. The computer program could be stored in the computer readable storage medium in the form of instructions encoding the computer- readable storage medium. The computer readable storage medium may be intended for taking part in the operation of a device, like an internal or external memory, for example a Read-Only Memory (ROM) or hard disk of a computer, or be intended for distribution of the program, like an optical disc.

[0022] According to a third aspect of the present disclosure, a system is disclosed, wherein the system comprises:

[0023] the apparatus according to the first aspect; and

[0024] the apparatus according to the second aspect.

[0025] For example, the system may comprise at least one apparatus (e.g. a network server or an SM unit) according to the first aspect and a plurality of apparatuses (e.g. a plurality of cryptographic modules) according to the second aspect Further, the system may comprise an application apparatus (e.g. an application server) that sends signing requests including the information to be signed to the apparatus according to the first aspect

[0026] For example, signature keys may be understood as one-time ciyptographic keys that are used only once for creating a particular signature. Reusing such one-time signature keys may lead to potential forgery (e.g. by compromising the security of the signature scheme). Therefore, a signature key may for example be a stateful signature key (e.g. having the state "used” or "unused”). For example, a signature key may for example be considered available at a cryptographic module if the signature key is stored at the respective cryptographic module and / or if it is in an unused state. As soon as such an available signature key has been used at the respective cryptographic module (or e.g. retrieved from a secure electronic memory of the cryptographic module) for a signing process (e.g. for creating a signature at the cryptographic module based on the signature key), the signature key becomes used and thus unavailable.

[0027] RU / fb 241380DEFor example, information indicating a current availability of signature keys at one particular cryptographic module of a plurality of cryptographic modules may be obtained. In addition to the current availability of signature keys at this particular cryptographic module, further information indicating respective current availabilities of signature keys at further cryptographic modules may be obtained. Information indicating a current availability of signature keys may for example be understood to mean that a value (e.g. a numerical value) representing the current availability of signature keys may be determined based on the information indicating the current availability.

[0028] For example, a current availability of signature keys may be understood as an actual availability status of signature keys at the at least one cryptographic module, while a predefined availability of signature keys may be understood as target availability status of signature keys at the at least one cryptographic module (e.g. a desired or required availability of signature keys e.g. according to an SM policy). In particular, the current availability of signature keys may correspond to the availability of signature keys at the point in time at which the step of obtaining information indicating the current availability of signature keys is performed. The predefined availability of signature keys at the at least one cryptographic module may be defined by a state management (SM) policy and information indicating such an SM policy may be stored at an apparatus performing the method according to the first aspect An SM policy may then for example be understood as policy defining a required availability of signature keys at one or more cryptographic modules.

[0029] For example, determining whether the current availability deviates from a predefined availability of the signature keys may comprise comparing a value (e.g. a numerical value) representing the current availability to a value (e.g. a numerical value) representing the predefined availability. It may for example be determined that the current availability deviates from the predefined availability of the signature key if the value representing the current availability differs from the value representing the predefined availability by more than a predetermined tolerance.

[0030] Considering that information indicating respective current availabilities of signature keys at more than one cryptographic module may be obtained, it may for example be determined whether the respective current availability of signatures keys at each cryptographic module deviates from a respective predefined availability of the signature keys at the corresponding cryptographic module.

[0031] RU / fb 241380DEA corrective action may for example be understood as action that addresses (e.g. resolves according to an SM policy indicating the predefined availability) the determined deviation between the current and predetermined availability. For example, after causing a corrective action, the following current availability of signature keys at the at least one cryptographic module may not deviate from the predefined availability of signature keys. Causing the corrective action for example means that an apparatus performing the method may directly perform the corrective action (e.g. without involving another apparatus), or that an apparatus performing the method may indirectly perform the corrective action (e.g. by instructing another apparatus of the second aspect to perform the corrective action).

[0032] Receiving information indicating a corrective action may for example follow after causing the corrective action if it is determined that the current availability deviates from the predefined availability. For example, an apparatus performing causing the corrective action may transmit information indicating the corrective action to another apparatus receiving the information indicating the corrective action and implementing the corrective action.

[0033] Implementing the corrective action may for example mean that the corrective action is performed (e.g. put into effect), for example for the purpose of addressing (e.g. reducing or resolving) a determined deviation between the current availability and a predetermined availability of the signature keys.

[0034] Advantageously, the various aspects of the present disclosure as described above provide an approach for ensuring availability of signature keys within a network including a plurality of cryptographic modules. In particular, since it is determined when current availabilities of signature keys at the plurality of cryptographic modules deviate from predefined availabilities defined by one or more SM policies, corrective actions are caused and implemented addressing the determined deviation. At the same time, cryptographic modules may provide high security signing processes based on stateful signature algorithms. Advantageously, an application server requesting signing processes from the plurality of cryptographic modules may therefore benefit from the high security of stateful signing processes, but without being affected by any bottlenecks in availability that typically accompany the use of stateful signature keys due to the finite number of available signature keys.

[0035] RU / fb 241380DEIn the following, further exemplary features and exemplary embodiments of the different aspects of the present disclosure will be described in more detail.

[0036] According to an exemplary embodiment of the first aspect of the present disclosure, the obtained information indicating a current availability is received from the at least one cryptographic module.

[0037] In another example, information indicating a current availability at the at least one cryptographic module may be obtained based on an initial signature key availability at the at least one cryptographic module and by tracking previous signing requests forwarded to the at least one cryptographic module.

[0038] According to an exemplaiy embodiment of the first aspect of the present disclosure, the method further comprises:

[0039] receiving a signing request, wherein it is determined whether the current availability deviates from the predefined availability of the signature keys in response to receiving the signing request; and

[0040] providing the signing request to the at least one cryptographic module after causing the corrective action.

[0041] According to an exemplaiy embodiment of the second aspect of the present disclosure, the method further comprises:

[0042] providing, before receiving information indicating a corrective action, information indicating a current availability of signature keys at the cryptographic module; and / or receiving a signing request, after implementing the corrective action.

[0043] For example, the steps of determining whether the current availability deviates from the predefined availability and providing information indicating a corrective action may be performed after a signing request (which e.g. includes information to be signed by a cryptographic module) is received from an application apparatus and after information indicating a current availability of signature keys at a cryptographic module is received from the cryptographic module. Thereafter, the signing request is forwarded to a cryptographic module after a corrective action has been caused and implemented. Advantageously, this approach ensures that the current availability of signature keys at the cryptographic modules is checked

[0044] RU / fb 241380DEagainst SM policies and corrected (if necessary) every time a signing request needs to be processed.

[0045] According to an exemplary embodiment of the first aspect of the present disclosure, the predefined availability of the signature keys at the at least one cryptographic module comprises one or more of the following:

[0046] a predefined amount of signature keys available at the at least one cryptographic module; and / or

[0047] a predefined amount of signature keys used by the at least one cryptographic module within a predefined time period.

[0048] For example, the predefined availability of signature keys at the least one cryptographic module may comprise a predefined amount of signature keys available at the at least one cryptographic module, which may be an absolute number of signature keys (e.g. x available signature keys) or a relative number of signature keys (e.g. x % available signature keys in relation to a total number of available signature keys at the plurality of cryptographic modules). Additionally or alternatively, a predefined availability of signature keys at the at least one ciyptographic module may comprise a predefined amount of signature keys used (e.g. used for creating signatures) by the cryptographic module within a predefined time period of seconds, minutes, hours or days. Therein, a predefined low number (e.g. an absolute or relative number) of signature keys used by the cryptographic module within a predefined time period may indicate a predefined high availability of signature keys at the cryptographic module.

[0049] According to an exemplaiy embodiment of the first aspect of the present disclosure, the current availability of the signature keys at the at least one cryptographic module comprises one or more of the following:

[0050] a current amount of signature keys available at the at least one cryptographic module; and / or

[0051] a current amount of signature keys used by the at least one cryptographic module within a predefined time period.

[0052] For example, the current availability of signature keys at the least one cryptographic module may comprise a current amount of signatures keys available at the at least one cryptographic module, which may be an absolute number of signature keys (e.g. x available signature keys) or a relative number of signature keys (e.g. x % available signature keys in relation to a total number

[0053] RU / fb 241380DEof available signature keys at the plurality of cryptographic modules). Additionally or alternatively, a current availability of signature keys at the at least one cryptographic may comprise a current amount of signature keys used (e.g. used for creating signatures) by the cryptographic module within a predefined time period of seconds, minutes, hours or days.

[0054] Therein, a high number (e.g. an absolute or relative number) of signature keys used by the cryptographic module within a predefined period of seconds, minutes, hours or days may indicate a low availability of signature keys at the cryptographic module.

[0055] According to an exemplaiy embodiment of the first aspect of the present disclosure, the determining whether the current availability deviates from a predefined availability of the signature keys at the at least one cryptographic module comprises one or more of the following:

[0056] determining whether a current amount of signature keys available at the at least one cryptographic module deviates from a predefined number of signature keys available at the at least one cryptographic module; and / or

[0057] determining whether a current amount of signature keys used by the at least one cryptographic module within a predefined time period deviates from a predefined amount of signature keys used by the at least one cryptographic module within a predefined time period.

[0058] For example, it may be determined whether a current amount of signature keys (e.g. x signature keys or x % available signature keys) available at the at least one cryptographic module deviates from (e.g. is below or above) a predefined amount of signature keys (e.g. y signature keys or y % available signature keys) available at the at least one cryptographic module. In another example, it may be determined whether a current amount of signature keys used by the at least one cryptographic module (e.g. used for creating signatures) within a predefined time period of seconds, minutes, hours or days deviates from (e.g. is below or above) a predefined amount of signature keys used by the at least one cryptographic module within the predefined time period.

[0059] According to an exemplary embodiment of the first aspect of the present disclosure, the obtained information represents a current availability of signature keys at each cryptographic module of the plurality of cryptographic modules.

[0060] For example, information representing a current availability of signature keys at each cryptographic module of the plurality of cryptographic modules may be understood to mean that the information represents a respective current availability of signatures at each respective

[0061] RU / fb 241380DEcryptographic module (e.g. a first current availability at a first cryptographic module, a second current availability at a second cryptographic module and so on). In such an example, an SM policy may likewise define a predefined availability of signatures at each cryptographic module (e.g. a first predefined availability at a first cryptographic module, a second predefined availability at a second ciyptographic module and so on). Determining whether the current availability deviates from the predefined availability may then for example comprise comparing a first current availability with a first predefined availability, a second current availability with a second predefined availability and so on. In this example, it may be determined that the current availability deviates from the predefined availability when at least the first current availability differs from the first predefined availability, or the second current availability differs from the second predefined availability and so on.

[0062] For example, a plurality of cryptographic modules may comprise any number of cryptographic modules. The plurality of cryptographic modules may for example be given by all cryptographic modules in a network or by a subgroup of cryptographic modules in a network.

[0063] According to an exemplaiy embodiment of the first aspect of the present disclosure, the current availability of the signature keys at the at least one cryptographic module comprises:

[0064] a current distribution of the available signature keys across the plurality of cryptographic modules.

[0065] Considering for example information indicating a respective current availability of signature keys at each cryptographic module of a plurality of cryptographic modules, a current distribution of the available signature keys across the plurality of cryptographic modules may be obtained. For example, information may be obtained indicating that currently a number of x signature keys is available at a first cryptographic module, a number of y signature keys is available at a second cryptographic module and a number of z signature keys is available at a third cryptographic module. According to the resulting distribution of currently available signature keys across the plurality of three cryptographic modules, a portion of x / (x+y+z) signature keys is currently available at the first cryptographic module, a portion of y / (x+y+z) signature keys is currently available at the second cryptographic module, and a portion of z / (x+y+z) signature keys is currently available at the third cryptographic module. For example, it may thus be indicated whether the currently available signature keys are equally distributed across the three ciyptographic modules or whether an excessive number of signature keys is available at one particular cryptographic module.

[0066] RU / fb 241380DEAccording to an exemplaiy embodiment of the first aspect of the present disclosure, the predefined availability of the signature keys at the at least one cryptographic module comprises:

[0067] a predefined distribution of available signature keys across the plurality of cryptographic modules.

[0068] For example, a predefined availability of signature keys at each cryptographic module of a plurality of cryptographic modules may comprise a predefined distribution of the available signature keys across the plurality of cryptographic modules. For example, according to a predefined availability of signature keys, it may be predefined that a number of x signature keys is available at a first cryptographic module, a number of y signature keys is available at a second cryptographic module and a number of z signature keys is available at HSM 150. According to the resulting predefined distribution of available signature keys across the plurality of cryptographic modules, it may be predefined that a portion of x / (x+y+z) signature keys is available at the first cryptographic module, a portion of y / (x+y+z) signature keys is available at the second cryptographic module, and a portion of z / (x+y+z) signature keys is available at third cryptographic module. It may thus be predefined that the available signature keys are equally distributed across the cryptographic modules (e.g. x=y=z within a predefined tolerance) or that for example an excessive number of signature keys is available at one particular cryptographic module.

[0069] According to an exemplary embodiment of the first aspect of the present disclosure, determining whether the current availability deviates from a predefined availability of the signature keys at the at least one cryptographic module comprises:

[0070] determining whether a current distribution of available signature keys across the plurality of cryptographic modules deviates from a predefined distribution of available signature keys across the plurality of cryptographic modules.

[0071] For example, it may be determined whether a distribution of currently available signature keys across the plurality of cryptographic modules (e.g. a portion of x / (x+y+z) signature keys currently available at a first cryptographic module, a portion of y / (x+y+z) signature keys currently available at a second cryptographic module, and a portion of z / (x+y+z) signature keys currently available at a third ciyptographic module) deviates from (e.g. is different within a predefined tolerance) a predefined distribution of available signature keys across the plurality of cryptographic modules (e.g. a predefined portion of x / (x+y+z) signature keys available at the

[0072] RU / fb 241380DEfirst cryptographic module, a predefined portion ofy / (x+y+z) signature keys available at the second cryptographic modules, and a predefined portion of z / (x+y+z) signature keys available at the third cryptographic module).

[0073] According to an exemplary embodiment of the first aspect of the present disclosure, determining whether the current availability deviates from a predefined availability of the signature keys at the at least one cryptographic module further comprises:

[0074] determining an identity of the at least one cryptographic module at which the current availability deviates from a predefined availability of the signature keys.

[0075] For example, an identity of the at least one cryptographic module may be given by an identifier or an address that (e.g. uniquely) identifies the at least cryptographic module (e.g. within a network comprising a plurality of cryptographic modules).

[0076] According to an exemplaiy embodiment of the first aspect of the present disclosure, causing a corrective action comprises one or more of the following:

[0077] providing one or more additional signature keys to the at least one cryptographic module; and / or

[0078] retrieving one or more available signature keys from the at least one cryptographic module; and / or

[0079] instructing the at least one cryptographic module to generate one or more additional signature keys; and / or

[0080] outputting information indicating a deviation between the current availability of the signature keys at the at least one cryptographic module and the predefined availability of the signature keys at the at least one cryptographic module; and / or

[0081] discontinuing forwarding signing requests to the at least one cryptographic module.

[0082] For example, if it is determined that a current amount of signature keys (e.g. x signature keys or x % available signature keys) available at a particular cryptographic module is below a predefined amount of signature keys (e.g. y signature keys or y % available signature keys) available at this particular cryptographic module, causing a corrective action may comprise providing one or more additional signature keys (e.g. unused signature keys) to the particular cryptographic module and / or instructing the particular cryptographic module to generate one or more additional signature keys. Alternatively or additionally, forwarding signing requests to

[0083] RU / fb 241380DEthe particular cryptographic module may be discontinued (e.g. for the purpose of blocking the particular cryptographic module from receiving future signing requests).

[0084] In another example, if it is determined that a current amount of signature keys used by a particular cryptographic module (e.g. used for creating signatures) within a predefined time period is above a predefined amount of signature keys used by this particular cryptographic module within a predefined time period, causing a corrective action may comprise providing one or more additional signature keys (e.g. unused signature keys) to the particular cryptographic module and / or instructing the particular cryptographic module to generate one or more additional signature keys. Alternatively or additionally, forwarding signing requests to the particular cryptographic module may be discontinued (e.g. for the purpose of blocking the particular cryptographic module from receiving future signing requests).

[0085] In another example, if it is determined that a current amount of signature keys (e.g. x available signature keys or x % available signature keys) available at a particular cryptographic module is above a predefined amount of signature keys (e.g. y available signature keys or y % available signature keys) available at the particular cryptographic module, causing a corrective action may comprise retrieving one or more additional signature keys (e.g. unused signature keys) from the particular cryptographic module.

[0086] In another example, if it is determined that a current amount of signature keys used by a particular cryptographic module (e.g. used for creating signatures) within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days) is below a predefined amount of signature keys used by the particular cryptographic module within a predefined time period, causing a corrective action may comprise retrieving one or more additional signature keys (e.g. unused signature keys) from the particular cryptographic module.

[0087] In another example, if it may be determined that a distribution of currently available signature keys across the plurality of cryptographic modules deviates from (e.g. is different within a predefined tolerance) a predefined distribution of available signature keys across the plurality of cryptographic modules, causing a corrective action may comprise providing one or more additional signature keys to particular cryptographic modules at which the amount of availability signature keys is too low according to the predefined distribution (or e.g. instructing such cryptographic modules to generate one or more additional signature keys), and / or

[0088] RU / fb 241380DEretrieving one or more additional signature keys from such cryptographic modules at which the amount of signature keys is too high according to the predefined distribution.

[0089] In another example, the predefined distribution may be an equal distribution of available signature keys across the plurality of cryptographic modules (e.g. requiring that the same amount of signature keys is available at each cryptographic module of the plurality of cryptographic modules, e.g. within a tolerance of 10 %). If it may for example be determined that a current distribution of signature key across the plurality of cryptographic modules deviates from such a predefined equal distribution, a corrective action may comprise providing additional signature keys and / or retrieve signature keys from the respective cryptographic modules such that the predefined equal distribution reached.

[0090] In another example, if it may be determined that the current availability of signature keys deviates from the predefined availability of signature keys, causing a corrective action may comprise outputting information indicating the determined deviation between the current availability the predefined availability of the signature keys at the respective cryptographic module.

[0091] According to an exemplaiy embodiment of the second aspect of the present disclosure, the information indicating a corrective action comprises one or more of the following:

[0092] one or more additional signature keys; and / or

[0093] an instruction to generate one or more additional signature keys at the cryptographic module; and / or

[0094] a request to provide one or more available signature keys by the cryptographic module.

[0095] For example, the information indicating a corrective action may comprise one or more of the following examples, depending on the caused corrective action as described above for the first aspect. For example, the corrective action may comprise one or more additional signature keys or an instruction to generate one or more additional signature keys at a particular cryptographic module, if it is determined that a current amount of signature keys available at the particular cryptographic module is below a predefined amount of signature keys, or if it is determined that a current amount of signature keys used by the particular cryptographic module within a predefined time period is above a predefined amount of signature keys used the particular cryptographic module within a predefined time period. In another example, the corrective action may comprise a request to provide one or more available signature keys by a particular

[0096] RU / fb 241380DEcryptographic module, if it is determined that a current amount of signature keys available at the particular cryptographic module is above a predefined amount of signature keys, or if it is determined that a current amount of signature keys used by the particular cryptographic module within a predefined time period is below a predefined amount of signature keys used by the particular cryptographic module.

[0097] According to an exemplary embodiment of the second aspect of the present disclosure, implementing the corrective action comprises one or more of the following:

[0098] storing one or more additional signature keys included in the received information indicating a corrective action in a secure electronic memory of the cryptographic module; and / or

[0099] generating one or more additional signature keys at the cryptographic module according to an instruction included in the received information indicating a corrective action; and / or

[0100] providing one or more available signature keys by the cryptographic module according to an instruction included in the received information indicating a corrective action.

[0101] For example, implementing the corrective action may comprise one or more of the following examples, depending on the caused corrective action as described above for the first aspect In a non-limiting example, implementing the corrective action may comprise storing one or more additional signature keys included in the received information indicating a corrective action in a secure electronic memory of the cryptographic module. In another example, implementing the corrective action may comprise generating one or more additional signature keys at the cryptographic module according to an instruction included in the received information indicating a corrective action. In another example, implementing the corrective action may comprise providing one or more available signature keys by the cryptographic module according to an instruction included in the received information indicating a corrective action.

[0102] According to an exemplary embodiment of the second aspect of the present disclosure, the corrective action is implemented if it is determined that the corrective action represented by the received information is not in conflict with a locally predefined availability of signature keys at the cryptographic module.

[0103] In addition to an SM policy as described above for the first aspect, further local SM policies may be present at respective cryptographic modules according to the second aspect These local SM

[0104] RU / fb 241380DEpolicies may define a respective locally predefined availability of signature keys at the respective cryptographic modules. For example, the predefined availability of signature keys defined by a local SM policy may comprise a predefined minimum amount (e.g. an absolute or relative number) of signature keys required to be available at the corresponding cryptographic module. The local SM policy may only apply to the respective cryptographic module and may have priority over a (not local) SM policy.

[0105] According to an exemplaiy embodiment of the first or second of the present disclosure, a signature key is available at a cryptographic module if it is stored in a secure electronic memory of the cryptographic module and / or if it is in an unused state.

[0106] For example, an unused signature key that is considered available at the cryptographic module may be stored in the secure electronic memory of the cryptographic module or stored in another electronic memoiy of the cryptographic module. In another example, the fact that a signature key is stored in the secure electronic memory may imply that this signature key is unused (e.g. because it is removed from the secure electronic memory when it is used for creating a signature).

[0107] It is to be understood that the presentation of the embodiments disclosed herein is merely by way of examples and non-limiting.

[0108] Herein, the disclosure of a method step shall also be considered as a disclosure of means for performing the respective method step. Likewise, the disclosure of means for performing a method step shall also be considered as a disclosure of the method step itself.

[0109] Other features of the present disclosure will become apparent from the following detailed description considered in conjunction with the accompanying drawings. It is to be understood, however, that the drawings are designed solely for purposes of illustration and not as a definition of the limits of the present disclosure, for which reference should be made to the appended claims. It should be further understood that the drawings are not drawn to scale and that they are merely intended to conceptually illustrate the structures and procedures described herein.

[0110] RU / fb 241380DEBRIEF DESCRIPTION OF THE FIGURES

[0111] Some example embodiments will now be described with reference to the accompanying drawings.

[0112] Fig. 1 shows an exemplary embodiment of a system according to the third aspect of the present disclosure;

[0113] Fig. 2 shows a flow chart illustrating an exemplary embodiment of a method according to the first aspect of the present disclosure;

[0114] Fig. 3 shows a flow chart illustrating an exemplary embodiment of a method according to the second aspect of the present disclosure;

[0115] Fig. 4 shows a block diagram of an exemplary embodiment of an apparatus according to the first aspect of the present disclosure;

[0116] Fig. 5 shows a block diagram of an exemplary embodiment of an apparatus according to the second aspect of the present disclosure; and

[0117] Fig. 6 is a schematic illustration of examples of tangible and non-transitory computer- readable storage media.

[0118] DETAILED DESCRIPTION OF THE FIGURES

[0119] The following description serves to deepen the understanding of the present disclosure and shall be understood to complement and be read together with the description of exemplary embodiments of the present disclosure as provided in the above summary section of this specification.

[0120] Fig. 1 shows an exemplary embodiment of a system 100 according to the third aspect of the present disclosure. System 100 may be understood as computer network comprising various apparatuses such as application unit 110, state management (SM) unit 120, a plurality of cryptographic modules 130, 140, 150 (which e.g. include respective local SM units 132, 142, 152), SM operator unit 160, and monitoring unit 170 as further described below. These

[0121] RU / fb 241380DEapparatuses may be connected by communication paths as shown in Fig. 1 for transmitting electronic information between each other. An example of SM unit 120 is given by apparatus 400 shown in Fig. 4, which may be configured to perform the steps of flow chart 200 illustrated in Fig. 2. An example of a respective cryptographic module 130, 140, 150 or an example of local SM units 132, 142, 152 is given by apparatus 500 shown in Fig. 5, which maybe configured to perform the steps of flow chart 300 illustrated in Fig. 3.

[0122] Application unit 110 maybe given by an application server at which pieces of electronic information needs to be digitally signed. Such signing may comprise determining a hash value of the information to be signed and encrypting the hash value with a private signature key, thereby creating a digital signature. Within system 100, signature keys are stored in secure electronic memories of a plurality of ciyptographic modules 130, 140, 150.

[0123] When a piece of electronic information needs to be signed at application unit 110, application unit 110 may send a signing request including the information to be signed to SM unit 120. SM unit 120 receives and forwards the signing request to one of the cryptographic modules 130, 140. 150, at which a digital signature of the information included in the signing request is created. The created digital signature is then sent from the corresponding cryptographic module 130, 140, 150 back to SM unit 120, which forwards the digital signature to application unit 110.

[0124] Cryptographic modules 130, 140, 150 may be given by respective hard security modules (HSMs) 130. 140. 150, which maybe understood as respective devices that safeguard and manage and / or generate electronic keys, perform encryption and decryption, authentication and other cryptographic functions. HSMs 130, 140, 150 may comprise tamper-resistant and tamper-evident hardware components, such as secure chips and sensors, for preventing unauthorized access, hacking or physical attacks. In particular, HSMs 130, 140, 150 may comprise respective secure electronic memories to store signature keys for signing requests forwarded by SM unit 120.

[0125] Signature keys that are stored at HSMs 130, 140, 150 and used for creating signatures at HSMs 130, 140, 150 in system 100 may be understood as one-time cryptographic keys that are used only once for creating a particular signature (e.g. based on a stateful hash-based signature algorithm). Reusing such one-time signature keys may lead to potential forgery (e.g. by compromising the security of the signature scheme). Accordingly, HSMs 130, 140, 150 may perform respective state handling for avoiding key reuse by maintaining state information,

[0126] RU / fb 241380DEwhich may indicate a state of a respective signature key (e.g. whether the signature key has already been used or not). Such state information of a signature keys needs to be kept current, in particular before the signature keys are requested for use to ensure key freshness.

[0127] The number of signature keys stored at HSMs 130, 140, 150 may be limited due to the structural design of the stateful hash-based signature scheme used in system 100. This may be because of the finite number of leaf nodes in the underlying Merkle tree representing the private / public signature key pairs. In addition, practical considerations like tree size, computational overhead and storage constraints may restrict the total key capacity. Since security requires that each private signature key stored at HSMs 130, 140, 150 is used exactly once to avoid vulnerabilities, the number of available signature keys at HSMs 130, 140, 150 that may be used for signing processes is limited.

[0128] SM unit 120 (e.g. a network server) obtains information indicating a current availability of signature keys atatleastone (e.g. each) HSM ofthe plurality ofHSMs l30, 140, 150 (e.g. by receiving such information from the HSMs 130, 140, 150, or based on an initial signature key availability at HSMs 130, 140, 150 and by tracking previous signing requests forwarded to HSMs 130, 140, 150). SM unit 120 may then determine whether the current availability deviates from a predefined availability of the signature keys at the at least one (e.g. each) HSM of the plurality of HSMs 130, 140, 150. If it is determined that the current availability deviates from the predefined availability, SM unit 120 may cause a corrective action to address the determined deviation.

[0129] The predefined availability of signature keys at the plurality of HSMs 130, 140, 150 maybe defined by SM policy 121 and may be understood as a target availability of signature keys at the plurality of HSMs 130, 140, 150 according to SM policy 121. In particular, information indicating SM policy 121 maybe stored at SM unit 120, wherein SM unit 120 may also store information indicating further SM policies not shown in Fig. 1. The predefined availability of signature keys defined by SM policy 121 may comprise a predefined amount (e.g. an absolute or relative number) of signature keys available at the at least one (e.g. each) HSM of the plurality of HSMs 130, 140, 150. Additionally or alternatively, the predefined availability of signature keys defined by SM policy 121 may comprise a predefined amount (e.g. an absolute or relative number) of signature keys used by the atleastone (e.g. each) HSM ofthe plurality of HSMs 130, 140, 150 within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days).

[0130] RU / fb 241380DEIn addition to SM policy 121 at SM unit 120, system 100 may include further local SM policies 131, 141, 151 at the respective HSMs 130, 140, 150. These local SM policies 131, 141, 151 may define a respective locally predefined availability of signature keys atthe HSMs 131, 141, 151. For example, the predefined availability of signature keys defined by local SM policy 131 (or local SM policies 141, 151) may comprise a predefined minimum amount (e.g. an absolute or relative number) of signature keys required to be available at HSM 130 (or atHSM 140, 150). Local SM policies 131, 141, 151 may only apply to the respective HSM 130, 140, 150 and may have priority over SM policy 121 at SM unit 120. Therefore, a corrective action caused by SM unit 120 (e.g. which is represented by information at the HSMs 130, 140, 150) maybe implemented at a respective HSM 130, 140, 150 if (e.g. only if) it is determined that the corrective action is not in conflict with the locally predefined availability of signature keys defined by the respective local SM policies 131, 141, 151.

[0131] For communicating with SM unit 120, HSMs 130, 140, 150 may include respective local SM units 132, 142, 152. Considering that HSMs 130, 140, 150 may be understood as passive cryptographic modules that may need to be triggered externally for implementing a corrective action, local SM units 132, 142, 152 may perform steps such as providing information indicating a current availability of signature keys, receiving information indicating a corrective action and implementing the corrective action.

[0132] The plurality of HSMs 130, 140, 150 maybe operated by SM operator unit 160, which for example initializes HSMs 130, 140, 150, defines their operational parameters and manages their other respective functionalities and configurations. The plurality of HSMs 130, 140, 150 may then form a particular operating site operated by SM operator 160. SM operator 160 and SM unit 120 may further report to global monitoring platform 170.

[0133] Fig. 2 shows a flow chart 200 illustrating an exemplary embodiment of a method according to the first aspect of the present disclosure. It may for example be assumed that the steps of flow chart 200 are performed and / or controlled by an apparatus according to the first aspect of the present disclosure (e.g. apparatus 400 described with reference to Fig. 4 as network server). Without limiting the scope of the present disclosure, the steps of flow chart 200 are described in the following in view of system 100 according to Fig. 1. Accordingly, it may be assumed in the following that the steps of flow chart 200 are performed by SM unit 120 and that a plurality of cryptographic modules is given by the plurality of HSMs 130, 140, 150.

[0134] RU / fb 241380DEIt may further be assumed in the following that a signature key is considered available at an HSM 130, 140, 150 if it is stored at the respective HSM (e.g. in a secure electronic memory of the respective HSM) and if it is in an unused state. As soon as such an available signature key has been used at the respective HSM for a signing process (e.g. for creating a signature at the HSM), the signature key becomes used and thus unavailable. Since security requires that each signature key stored at HSMs 130, 140, 150 is used exactly once to avoid vulnerabilities, the number of available signatures keys available at HSMs 130, 140, 150 that may be used for signing processes is limited.

[0135] Step 201 is obtaining information indicating a current availability of signature keys at at least one cryptographic module of a plurality of cryptographic modules.

[0136] Considering the plurality of HSMs 130, 140, 150 as plurality of cryptographic modules, SM unit 120 may for example obtain information indicating a current availability of signature keys at at least HSM 130. The current availability of signature keys at HSM 130 may then comprise a current amount of signatures keys available at HSM 130, which may be an absolute number of signature keys (e.g. x available signature keys) or a relative number of signature keys (e.g. x % available signature keys in relation to a total number of available signature keys at the plurality of HSMs 130, 140, 150). Additionally or alternatively, a current availability of signature keys at HSM 130 may comprise a current amount of signature keys used (e.g. used for creating signatures) by HSM 130 within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days). Therein, a high number (e.g. an absolute or relative number) of signature keys used by HSM 130 within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days) may indicate a low availability of signature keys at HSM 130.

[0137] In addition to the current availability of signature keys at HSM 130, further information indicating a respective current availability of signature keys at HSM 140 and HSM 150 may be obtained in step 201. Considering that information indicating a respective current availability of signature keys at each HSM 130, 140, 150 maybe obtained at SM unit 120, a current distribution of the available signature keys across the plurality of HSMs 130, 140, 150 may be obtained. For example, SM unit 120 may obtain information indicating that currently a number of x signature keys is available at HSM 130, a number of y signature keys is available at HSM 140 and a number of z signature keys is available at HSM 150. According to the resulting distribution of currently available signature keys across the plurality of HSMs 130, 140, 150, a portion of x / (x+y+z) signature keys is currently available at HSM 130, a portion of y / (x+y+z) signature keys is

[0138] RU / fb 241380DEcurrently available at HSM 140, and a portion of z / (x+y+z) signature keys is currently available at HSM 150. For example, it may thus be indicated whether the currently available signature keys are equally distributed across the HSMs 130, 140, 150 or whether an excessive number of signature keys is available at one particular HSM.

[0139] SM unit 120 may obtain information in step 201 by receiving such information from the HSMs 130, 140, 150, or based on an initial signature key availability at HSMs 130, 140, 150 and by tracking previous signing requests forwarded to the HSMs 130, 140, 150.

[0140] Step 202 is determining whether the current availability deviates from a predefined availability of the signature keys at the at least one cryptographic module.

[0141] Considering the plurality of HSMs 130, 140, 150 as plurality of cryptographic modules, SM unit 120 may determine whether the current availability of signature keys atthe HSMs 130, 140, 150 deviates from a predefined current availability of signature keys atthe HSMs 130, 140, 150. The current availability of signature keys may then be understood as an actual availability status of signature keys atthe HSMs 130, 140, 150, while the predefined availability of signature keys may be understood as target availability status of signature keys atthe HSMs 130, 140, 150. In step 202, a potential deviation between the actual availability status and the target availability status is determined. The predefined availability of signature keys atthe plurality of HSMs 130, 140, 150 may be defined by SM policy 121 and information indicating SM policy 121 may be stored at SM unit 120. SM policy 121 may then be understood as policy defining a required availability of signature keys at HSMs 130, 140, 150.

[0142] The predefined availability of signature keys at HSM 130 may comprise a predefined amount of signature keys available at HSM 130, which may be an absolute number of signature keys (e.g. x available signature keys) or a relative number of signature keys (e.g. x % available signature keys in relation to a total number of available signature keys atthe plurality of HSMs 130, 140, 150). Additionally or alternatively, a predefined availability of signature keys at HSM 130 may comprise a predefined amount of signature keys used (e.g. used for creating signatures) by HSM 130 within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days). Therein, a predefined high number (e.g. an absolute or relative number) of signature keys used by HSM 130 within a predefined time period may indicate a predefined low availability of signature keys at HSM 130.

[0143] RU / fb 241380DEConsidering the plurality of HSMs 130, 140, 150 as plurality of cryptographic modules, it may be determined at step 202 whether the current availability of signatures keys at HSM 130 deviates from a predefined availability of the signature keys at HSM 130.

[0144] In addition to the predefined availability of signature keys at HSM 130, it may further be determined at step 202 whether the respective current availability of signatures keys at HSMs 140, 150 deviates from a respective predefined availability of the signature keys at HSMs 140, 150. A predefined availability of signature keys at each HSM 130, 140, 150 may then comprise a predefined distribution of the available signature keys across the plurality of HSMs 130, 140, 150. For example, according to a predefined availability of signature keys, it may be predefined that a number of x signature keys is available at HSM 130, a number of y signature keys is available at HSM 140 and a number of z signature keys is available at HSM 150. According to the resulting predefined distribution of available signature keys across the plurality of HSMs 130, 140, 150, it may be predefined that a portion of x / (x+y+z) signature keys is available at HSM 130, a portion of y / (x+y+z) signature keys is available at HSM 140, and a portion of z / (x+y+z) signature keys is available at HSM 150. It may thus be predefined that the available signature keys are equally distributed across the HSMs 130, 140, 150 (e.g. x=y=z within a predefined tolerance) or that for example an excessive number of signature keys is available at one particular HSM.

[0145] To give a non-limiting example of step 202, SM unit 120 may determine whether a current amount of signature keys (e.g. x signature keys or x % available signature keys) available at HSM 130 deviates from (e.g. is below or above) a predefined amount of signature keys (e.g. y signature keys or y % available signature keys) available at HSM 130. Further, SM unit 120 may determine whether a current amount of signature keys (e.g. x available signature keys or x % available signature keys) available at HSM 140 deviates from (e.g. is below or above) a predefined amount of signature keys (e.g. y available signature keys or y % available signature keys) available at HSM 140, and whether a current amount of signature keys (e.g. x available signature keys or x % available signature keys) available at HSM 150 deviates from (e.g. is below or above) a predefined amount of signature keys (e.g. y available signature keys or y % available signature keys) available at HSM 150.

[0146] In another example of step 202, SM unit 120 may determine whether a current amount of signature keys used by HSM 130 (e.g. used for creating signatures) within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days) deviates from (e.g. is below

[0147] RU / fb 241380DEor above) a predefined amount of signature keys used by HSM 130 within a predefined time period. In another example of step 202, SM unit 120 may determine whether a current amount of signature keys used by HSM 140 (e.g. used for creating signatures) within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days) deviates from (e.g. is below or above) a predefined amount of signature keys used by HSM 140 within a predefined time period, and whether a current amount of signature keys used by HSM 150 (e.g. used for creating signatures) within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days) deviates from (e.g. is below or above) a predefined amount of signature keys used by HSM 150 within a predefined time period.

[0148] In another example of step 202, SM unit 120 may determine whether a distribution of currently available signature keys across the plurality of HSMs 130, 140, 150 (e.g. a portion of x / (x+y+z) signature keys currently available at HSM 130, a portion of y / (x+y+z) signature keys currently available at HSM 140, and a portion of z / (x+y+z) signature keys currently available at HSM 150) deviates from (e.g. is different within a predefined tolerance) a predefined distribution of available signature keys across the plurality of HSMs 130, 140, 150 (e.g. a predefined portion of x / (x+y+z) signature keys available at HSM 130, a predefined portion ofy / (x+y+z) signature keys available at HSM 140, and a predefined portion of z / (x+y+z) signature keys available at HSM 150).

[0149] As part of step 202, SM unit may further determine an identity of the respective one or more HSM 130, 140, 150 at which the current availability deviates from a predefined availability of the signature keys.

[0150] Step 203 is causing a corrective action if it is determined that the current availability deviates from the predefined availability.

[0151] Assuming that it is determined in step 202 as described above that the current availability of signature keys at HSMs 130, 140, 150 deviates from the predefined availability of signature keys at HSMs 130, 140, 150 (e.g. according to SM policy 121), SM unit 120 may cause a corrective action in step 203, wherein the corrective action addresses (e.g. resolves according to SM policy 121) the deviation determined in step 202. In particular, after causing a corrective action in step 203, the following current availability of signature keys at HSMs 130, 140, 150 may not deviate from the predefined availability of signature keys at HSMs 130, 140, 150.

[0152] RU / fb 241380DESome non-limiting examples for such corrective actions are given in the following:

[0153] If SM unit 120 may determine that a current amount of signature keys (e.g. x signature keys or x % available signature keys) available at HSM 130 (or HSMs 140, 150) is below a predefined amount of signature keys (e.g. y signature keys or y % available signature keys) available at HSM 130 (or HSMs 140, 150), causing a corrective action may comprise providing one or more additional signature keys (e.g. unused signature keys) by SM unit 120 to HSM 130 (or HSMs 140, 150) and / or instructing HSM 130 (or HSMs 140, 150) by SM unit 120 to generate one or more additional signature keys. Alternatively or additionally, SM unit 120 may discontinue forwarding signing requests to HSM 130 (or HSMs 140, 150, e.g. for the purpose of blocking such HSMs from receiving future signing requests).

[0154] If SM unit 120 may determine that a current amount of signature keys used by HSM 130 (or HSMs 140, 150, e.g. used for creating signatures) within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days) is above a predefined amount of signature keys used by HSM 130 (or HSMs 140, 150) within a predefined time period, causing a corrective action may comprise providing one or more additional signature keys (e.g. unused signature keys) by SM unit 120 to HSM 130 (or HSMs 140, 150) and / or instructing HSM 130 (or HSMs 140, 150) by SM unit 120 to generate one or more additional signature keys. Alternatively or additionally, SM unit 120 may discontinue forwarding signing requests to HSM 130 (or HSMs 140, 150, e.g. for the purpose of blocking such HSMs from receiving future signing requests).

[0155] If SM unit 120 may determine that a current amount of signature keys (e.g. x available signature keys or x % available signature keys) available at HSM 130 (or HSMs 140, 150) is above a predefined amount of signature keys (e.g. y available signature keys or y % available signature keys) available at HSM 130 (or HSMs 140, 150), causing a corrective action may comprise retrieving one or more additional signature keys (e.g. unused signature keys) by SM unit 120 from HSM 130 (or HSMs 140, 150).

[0156] If SM unit 120 may determine that a current amount of signature keys used by HSM 130 (or HSMs 140, 150, e.g. used for creating signatures) within a predefined time period (e.g. a predefined period of seconds, minutes, hours or days) is below a predefined amount of signature keys used by HSM 130 (or HSMs 140, 150) within a predefined time period, causing a corrective action may comprise retrieving one or more additional signature keys (e.g. unused signature keys) by SM unit 120 from HSM 130 (or HSMs 140, 150).

[0157] RU / fb 241380DEIf SM unit 120 may determine that a distribution of currently available signature keys across the plurality of HSMs 130, 140, 150 (e.g. a portion of x / (x+y+z) signature keys currently available at HSM 130, a portion ofy / (x+y+z) signature keys currently available at HSM 140, and a portion of z / (x+y+z) signature keys currently available at HSM 150) deviates from (e.g. is different within a predefined tolerance) a predefined distribution of available signature keys across the plurality of HSMs 130, 140, 150 (e.g. a predefined portion ofx / (x+y+z) signature keys available at HSM 130, a predefined portion ofy / (x+y+z) signature keys available at HSM 140, and a predefined portion of z / (x+y+z) signature keys available at HSM 150), causing a corrective action by SM unit 120 may comprise providing one or more additional signature keys to HSMs 130, 140, 150 at which the amount of availability signature keys is too low according to the predefined distribution (or e.g. instructing such HSMs to generate one or more additional signature keys), and / or retrieving one or more additional signature keys from HSMs 130, 140, 150 at which the amount of signature keys is too high according to the predefined distribution.

[0158] In another example, the predefined distribution may be an equal distribution of available signature keys across the plurality of HSMs 130, 140, 150 (e.g. requiring that the same amount of signature keys is available at each HSM 130, 140, 150, e.g. within a tolerance of 10 %). If SM unit 120 may detect in step 202 that a current distribution of signature key across HSMs 130, 140, 150 deviates from such a predefined equal distribution, SM unit 120 may cause a corrective action in step 203 and provide additional signature keys and / or retrieve signature keys from the respective HSMs 130, 140, 150 such thatthe predefined equal distribution reached.

[0159] Determining whether a deviation between the current availability deviates from the predefined availability and causing a corrective action may be further be expressed in various forms. For example:

[0160] if ["amount of signature keys available at HSM 130" + "total amount of

[0161] signature keys available at all HSMs 130, 140, 150" / 10)] < [["total amount of signature keys available at all HSMs 130, 140, 150") / (number of plurality of

[0162] HSMs 130, 140, 150)]";

[0163] then provide additional signature keys to HSMs 130, 140, 150 to reach an

[0164] equal distribution of signature keys available at all HSMs 130, 140, 150;

[0165] RU / fb 241380DEIn another example, if SM unit 120 determines that the current availability of signature keys deviates from the predefined availability of signature keys in step 202, causing a corrective action in step 203 may comprise outputting information indicating the determined deviation between the current availability the predefined availability of the signature keys at the corresponding HSM 130, 140, 150. In this example, SM unit 120 may report the determined deviation to another unit (e.g. to monitoring unit 170), at which further actions may be performed addressing the deviation.

[0166] Steps 202 and 203 may be performed by SM unit 120 in response to receiving a signing request by SM unit 120 from application unit 110. SM unit 120 may provide the signing request to one of the HSMs 130, 140, 150 after causing a corrective action in step 203. In another example, steps 202 and 203 may be performed at period time intervals.

[0167] Fig. 3 shows a flow chart 300 illustrating an exemplary embodiment of a method according to the second aspect of the present disclosure. It may for example be assumed that the steps of flow chart 300 are performed and / or controlled by an apparatus according to the second aspect of the present disclosure (e.g. apparatus 500 described with reference to Fig. 5 as cryptographic module). Without limiting the scope of the present disclosure, the steps of flow chart 300 are described in the following in view of system 100 according to Fig. 1. Accordingly, it may be assumed in the following that the steps of flow chart 300 are performed by local SM unit 132 (or local SM units 142, 152).

[0168] Step 301 is receiving, at a cryptographic module, information indicating a corrective action, after it is determined that a current availability of signature keys at the cryptographic module deviates from a predefined availability of the signature keys at the cryptographic module.

[0169] Step 301 may follow after performing step 203 as described above with reference to Fig. 2. Accordingly, local SM unit 132 may receive at HSM 130 information indicating the corrective action as caused by SM unit 120 according to step 203. In particular, step 301 may be performed after SM unit 120 determines that a current availability of signature keys at HSM 130 deviates from a predefined availability of the signature keys at HSM 130 (see step 202 as described above with reference to Fig. 2).

[0170] The information indicating a corrective action may comprise one or more of the following examples, depending on the corrective action caused by SM unit 120 as described above for

[0171] RU / fb 241380DEsteps 202 and 203. In a non-limiting example, the corrective action may comprise one or more additional signature keys or an instruction to generate one or more additional signature keys at HSM 130 (e.g. if SM unit 120 in step 202 determines that a current amount of signature keys available at HSM 130 is below a predefined amount of signature keys, or ifSM unit 120 in step 203 determines that a current amount of signature keys used by HSM 130 within a predefined time period is above a predefined amount of signature keys used by HSM 130 within a predefined time period). In another example, the corrective action may comprise a request to provide one or more available signature keys by HSM 130 to SM unit 120 (e.g. if SM unit 120 in step 202 determines that a current amount of signature keys available at HSM 130 is above a predefined amount of signature keys, or ifSM unit 120 in step 203 determines that a current amount of signature keys used by HSM 130 within a predefined time period is below a predefined amount of signature keys used by HSM 130 within a predefined time period).

[0172] Before performing step 301, local SM unit 132 may provide information indicating a current availability of signature keys at HSM 130 to SM unit 120, wherein SM unit 120 may obtain such information in step 201 as described above with reference to Fig. 2.

[0173] Step 302 is implementing the corrective action.

[0174] Implementing the corrective action in step 302 by local SM unit 132 may comprise one or more of the following examples, depending on the corrective action caused by SM unit 120 as described above for steps 202, 203 and 301. In a non-limiting example, implementing the corrective action by local SM unit 132 may comprise storing one or more additional signature keys included in the received information indicating a corrective action in a secure electronic memory of HSM 130. In another example, implementing the corrective action by local SM unit 132 may comprise generating one or more additional signature keys at HSM 130 according to an instruction included in the received information indicating a corrective action. In another example, implementing the corrective action by local SM unit 132 may comprise providing one or more available signature keys by HSM 130 to SM unit 120 according to an instruction included in the received information indicating a corrective action.

[0175] Following implementing the corrective action in step 302, local SM unit 132 may receive a signing request forwarded by SM unit 120.

[0176] RU / fb 241380DEIn a non-limiting example of step 302, local SM unit 132 may implement the corrective action if (e.g. only if) local SM unit 132 determines that the corrective action is notin conflict with the locally predefined availability of signature keys defined by local SM policy 131. For example, the predefined availability of signature keys defined by local SM policy 131 may comprise a predefined minimum amount (e.g. an absolute or relative number) of signature keys required to be available atHSM 130. Local SM policy 131 may only apply to the respective HSM 130 and may have priority over SM policy 121 at SM unit 120. If for example implementing the corrective action in step 302 comprises a request to provide one or more available signature keys by HSM 130 to SM unit 120, local SM unit 132 may only implement the corrective action if providing the one or more available signature keys is not conflict with the predefined minimum amount of signature keys required to be available at HSM 130.

[0177] Advantageously, as described by the non-limiting example of the steps 201 to 203 performed by SM unit 120 with reference to Fig. 2 and the corresponding steps 301 and 302 performed by local SM unit 131 with reference to Fig. 3, the present disclosure provides an approach of ensuring availability of signature keys (e.g. private stateful signature keys of stateful hash-based signature algorithms) within a network including a plurality of HSMs 130, 140, 150. In particular, since SM unit 120 determines when current availabilities of signature keys at the plurality of HSMs 130, 140, 150 deviate from predefined availabilities defined by one or more SM policies, corrective actions are caused and implemented addressing the determined deviation. Atthe same time, HSMs 130, 140, 150 may provide high security signing processes based on stateful signature algorithms. Advantageously, application unit 110 requesting signing processes from the plurality of HSMs, may therefore benefit from the high security of stateful signing processes, but without being affected by any bottlenecks in availability that typically accompany the use of stateful signature keys due to the finite number of available signature keys.

[0178] The solution according to the present disclosure may further provide the following advantages:

[0179] • Security: The security is based on the underlying technical processes and procedures for state handling atthe HSMs;

[0180] • Availability: Automated monitoring and compliance with predefined SM policies helps to prevent bottlenecks in state management;

[0181] • Transparency in the direction of the application, since the application that executes the business logic is not concerned with state management tasks.

[0182] RU / fb 241380DEFurther referring to system 100 shown in Fig. 1 and flow charts 200, 300 shown in Fig. 2 and Fig.

[0183] 3, SM unit 120, SM policy 121 and HSMs 130, 140, 150 may have the following exemplary characteristics:

[0184] HSMs 130, 140, 150:

[0185] • include secure state handling and technical processes for secure state handling of stateful signature keys;

[0186] • may be passive components that need to be triggered by respective local SM units 132, 142, 152.

[0187] SM policy 121:

[0188] • defines the availability conditions with regard to the state for individual HSMs (individually per HSM or generally);

[0189] • defines conditions for "availability status" (e.g. high, med, low, very low, critical);

[0190] exemplary conditions:

[0191] signature key quantity > limit;

[0192] not more than x operations within predefined time interval (to detect exhaustion);

[0193] • defines consequences (e.g. an HSM without available keys will no longer be accessed); exemplary consequences:

[0194] blocking of HSM / manual intervention;

[0195] reporting / monitoring;

[0196] key transfer actions.

[0197] SM unit 120:

[0198] • implemented as non-security-related component that actively controls HSMs 130, 140, 150;

[0199] • interprets and implements SM policy 121;

[0200] • controls load balancing and communicates with the global monitoring;

[0201] • may be set up hierarchically.

[0202] Fig. 4 shows a block diagram of an exemplary embodiment of an apparatus according to the first aspect of the present disclosure. As such, apparatus 400 may for example correspond to SM unit 120 illustrated in Fig. 1 and may be configured to perform the steps of flow chart 200 illustrated in Fig. 2.

[0203] RU / fb 241380DEApparatus 400 may comprise a processor 401 which may represent a single processor or two or more processors (which e.g. are at least partially coupled, e.g. via a bus). Processor 401 may execute a program code stored in program memory 402 (e.g. program code causing apparatus 400 to perform embodiments according to the present disclosure or parts thereof) and may interface with a main memory 403. Program memory 402 may further comprise an operating system (e.g. a Linux-based operating system) for processor 401. Some or all of memories 402 and 403 may also be included into processor 401.

[0204] Moreover, processor 401 may control one or more communication interface(s) 404 which may be configured to communicate with further apparatuses (e.g. apparatus 500). The one or more communication interface(s) 404 may provide one or more wireline and / or wireless connections. To give some non-limiting examples, a wireline connection may be serial connection (e.g. according to the RS-232 standard), an Ethernet connection (according to any release of the IEEE-802.3 standard) and / or a Universal Serial Bus (USB) connection (e.g. according to any release of the USB standard). Non-limiting examples for a wireless connection may be a Wireless Local Area Network (WLAN) connection (e.g. according to the IEEE-802.11 standard family) or a Bluetooth connection (e.g. according to any release of the IEEE-802.15.1 standard).

[0205] In a non-limiting example, apparatus 400 may be understood as a network server that may be configured to manage a network including a plurality of apparatuses as described with reference to Fig. 5 (e.g. a plurality of cryptographic modules).

[0206] Fig. 5 shows a block diagram of an exemplary embodiment of an apparatus according to the second aspect of the present disclosure. As such, apparatus 500 may for example correspond to a respective cryptographic module 130, 140, 150 or a respective local SM unit 132, 142, 152 illustrated in Fig. 1 and may be configured to perform the steps of flow chart 300 illustrated in Fig. 3.

[0207] Apparatus 500 may comprise a processor 501 which may represent a single processor or two or more processors (which e.g. are at least partially coupled, e.g. via a bus). Processor 501 may execute a program code stored in program memory 502 (e.g. program code causing apparatus 500 to perform embodiments according to the present disclosure or parts thereof) and may interface with a main memory 503. Program memory 502 may further comprise an operating

[0208] RU / fb 241380DEsystem (e.g. a Linux-based operating system) for processor 501. Some or all of memories 502 and 503 may also be included into processor.

[0209] Moreover, processor 501 may control one or more communication interface(s) 504 which may be configured to communicate with further apparatuses. The one or more communication interface (s) 504 may provide one or more wireline and / or wireless connections. To give some non-limiting examples, a wireline connection may be serial connection (e.g. according to the RS-232 standard), an Ethernet connection (according to any release of the IEEE-802.3 standard) and / or a Universal Serial Bus (USB) connection (e.g. according to any release of the USB standard). Non-limiting examples for a wireless connection may be a Wireless Local Area Network (WLAN) connection (e.g. according to the IEEE-802.11 standard family) or a Bluetooth connection (e.g. according to any release of the IEEE-802.15.1 standard).

[0210] In a non-limiting example, apparatus 500 maybe understood as an HSM or a component of an HSM as described with reference to Fig. 1. Processor 501 may then be a secure cryptographic processor and memory 502 and / or memory 503 may be a secure electronic memory secured by physical security measures. It may be understood that apparatus 500 may comprise further components, such as for example further components of a HSM.

[0211] Fig. 6 is a schematic illustration of examples of tangible and non-transitoiy computer-readable storage media according to the present disclosure that may for example be used to implement memory 402 of Fig. 4 and / or memory 502 of Fig. 5. To this end, Fig. 6 displays a flash memory 600, which may for example be soldered or bonded to a printed circuit board, a solid-state drive 601 comprising a plurality of memory chips (e.g. Flash memory chips), a magnetic hard drive 602, a Secure Digital (SD) card 603, a Universal Serial Bus (USB) memory stick 604, an optical storage medium 605 (such as for example a CD-ROM or DVD) and a magnetic storage medium 606.

[0212] Any presented connection in the disclosed embodiments is to be understood in a way that the involved components are operationally coupled. Thus, the connections can be direct or indirect with any number or combination of intervening elements, and there may be merely a functional relationship between the components.

[0213] Any of the processors mentioned in the present disclosure may be a processor of any suitable type. Any processor may comprise but is not limited to one or more microprocessors, one or

[0214] RU / fb 241380DEmore processors with accompanying digital signal processors, one or more processors without accompanying digital signal processors, one or more special-purpose computer chips, one or more field-programmable gate arrays (FPGAS), one or more controllers, one or more application-specific integrated circuits (ASICS), or one or more computers. The relevant structure / hardware has been programmed in such a way to carry out the described function.

[0215] Moreover, any of the actions or steps described or illustrated in the present disclosure may be implemented using executable instructions in a general-purpose or special-purpose processor and stored on a computer-readable storage medium (e.g., disk, memory, or the like) to be executed by such a processor. References to ‘computer-readable storage medium’ should be understood to encompass specialized circuits such as FPGAs, ASICs, signal processing devices, and other devices.

[0216] The wording "A, or B, or C, or a combination thereof’ or "at least one of A, B and C” may be understood to be not exhaustive and to include at least the following: (i) A, or (ii) B, or (iii) C, or (iv) A and B, or (v) A and C, or (vi) B and C, or (vii) A and B and C.

[0217] It will be understood that the embodiments disclosed herein are only exemplary, and that any feature presented for a particular exemplary embodiment may be used with any aspect of the present disclosure on its own or in combination with any feature presented for the same or another particular exemplary embodiment and / or in combination with any other feature not mentioned. It will further be understood that any feature presented for an example embodiment in a particular category may also be used in a corresponding manner in an example embodiment of any other category.

[0218] RU / fb 241380DE

Claims

RU 241380DE / fbC L A I M S1. A method (200) comprising:obtaining (201) information indicating a current availability of signature keys at at least one cryptographic module (130;140;150) of a plurality of cryptographic modules (130;140;150);determining (202) whether the current availability deviates from a predefined availability of the signature keys at the at least one cryptographic module (130;140;150); andcausing (203) a corrective action if it is determined that the current availability deviates from the predefined availability.

2. The method (200) according to claim 1, wherein the obtained information indicating a current availability is received from the at least one cryptographic module (130;140;150).

3. The method (200) according to claim 1 or claim 2, wherein the method further comprises:receiving a signing request, wherein it is determined whether the current availability deviates from the predefined availability of the signature keys in response to receiving the signing request; andproviding the signing request to the at least one cryptographic module (130; 140; 150) after causing (203) the corrective action.

4. The method (200) according to any of the claims 1 to 3, wherein the predefined availability of the signature keys at the at least one cryptographic module (130; 140; 150) comprises one or more of the following:a predefined amount of signature keys available at the at least one cryptographic module (130;140;150); and / ora predefined amount of signature keys used by the at least one cryptographic module (130;140;150) within a predefined time period.

5. The method according to any of the claims 1 to 4, wherein the current availability of the signature keys atthe at least one cryptographic module (130;140;150) comprises one or more of the following:a current amount of signature keys available at the at least one cryptographic module (130;140;150); and / ora current amount of signature keys used by the at least one cryptographic module (130;140;150) within a predefined time period.

6. The method (200) according to any of the claims 1 to 5, wherein determining (202) whether the current availability deviates from a predefined availability of the signature keys atthe atleastone cryptographic module (130;140;150) comprises one or more of the following:determining whether a current amount of signature keys available at the at least one cryptographic module (130;140;150) deviates from a predefined number of signature keys available atthe atleastone cryptographic module (130;140;150); and / or determining whether a current amount of signature keys used by the at least one cryptographic module (130;140;150) within a predefined time period deviates from a predefined amount of signature keys used by the at least one cryptographic module (130;140;150) within a predefined time period.

7. The method (200) according to any of the claims 1 to 6, wherein the obtained information indicates a current availability of signature keys at each cryptographic module (130;140;150) of the plurality of cryptographic modules (130;140;150).

8. The method (200) according to claim 7, wherein the current availability of the signature keys atthe atleastone cryptographic module (130;140;150) comprises:a current distribution of the available signature keys across the plurality of cryptographic modules (130;140;150).

9. The method (200) according to any of the claims 7 and 8, wherein the predefined availability of the signature keys atthe atleastone cryptographic module (130; 140; 150) comprises:a predefined distribution of available signature keys across the plurality of cryptographic modules (130;140;150).RU / fb 241380DE10. The method (200) according to any of the claims 7 to 9, wherein determining (202) whether the current availability deviates from a predefined availability of the signature keys at the atleastone cryptographic module (130;140;150) comprises: determining whether a current distribution of available signature keys across the plurality of cryptographic modules deviates from a predefined distribution of available signature keys across the plurality of cryptographic modules (130;140;150).

11. The method (200) according to any of the claims 1 to 10, wherein determining (202) whether the current availability deviates from a predefined availability of the signature keys at the atleastone cryptographic module (130;140;150) further comprises: determining an identity of the atleastone cryptographic module (130;140;150) at which the current availability deviates from a predefined availability of the signature keys.

12. The method (200) according to any of the claims 1 to 11, wherein causing (203) a corrective action comprises one or more of the following:providing one or more additional signature keys to the at least one cryptographic module (130;140;150); and / orretrieving one or more available signature keys from the at least one cryptographic module (130;140;150); and / orinstructing the at least one cryptographic module to generate one or more additional signature keys; and / oroutputting information indicating a deviation between the current availability of the signature keys at the at least one cryptographic module and the predefined availability of the signature keys atthe atleastone cryptographic module (130;140;150); and / or discontinuing forwarding signing requests to the at least one cryptographic module (130;140;150).

13. A method (300) comprising:receiving (301), at a cryptographic module (130;140;150), information indicating a corrective action, after it is determined that a current availability of signature keys at the cryptographic module (130;140;150) deviates from a predefined availability of the signature keys atthe cryptographic module (130;140;150); andimplementing (302) the corrective action.RU / fb 241380DE14. The method (300) according to claim 13, wherein the information indicating a corrective action comprises one or more of the following:one or more additional signature keys; and / oran instruction to generate one or more additional signature keys at the cryptographic module (130;140;150); and / ora request to provide one or more available signature keys by the cryptographic module (130;140;150).

15. The method (300) according to claim 13 or claim 14, wherein implementing the corrective action comprises one or more of the following:storing one or more additional signature keys included in the received information indicating a corrective action in a secure electronic memory of the cryptographic module (130;140;150); and / orgenerating one or more additional signature keys at the cryptographic module according to an instruction included in the received information indicating a corrective action; and / orproviding one or more available signature keys by the cryptographic module(130; 140; 150) according to an instruction included in the received information indicating a corrective action.

16. The method (300) according to any of the claims 13 to 15, wherein the method further comprises:providing, before receiving (301) information indicating a corrective action, information indicating a current availability of signature keys at the cryptographic module; and / or receiving a signing request, after implementing (302) the corrective action.

17. The method (300) according to any of the claims 13 to 16, wherein the corrective action is implemented if it is determined that the corrective action indicated by the received information is not in conflict with a locally predefined availability of signature keys at the cryptographic module (130;140;150).

18. The method (200;300) according to any of the claims 1 to 17, wherein a signature key is available at a cryptographic module (130;140;150) if it is stored in a secure electronic memory of the cryptographic module (130; 140; 150) and / or if it is in an unused state.RU / fb 241380DE19. An apparatus (120;400) configured to perform and / or comprising means (401;402;403;404) for performing the method (200) according to any of the claims 1 to 12 and 18.

20. An apparatus (130;140;150;132;142;152;500) configured to perform and / or comprising means (501;502;503;504) for performing the method (300) according to any of the claims 13 to 18.

21. A system (100) comprising the apparatus (120;400) according to claim 19 and the apparatus (130;140;150;132;142;152;500) according to claim 20.RU / fb 241380DE