Blockchain-Mediated Cryptographic Key Transfer Between HSMs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for secure and reliable transfer of cryptographic keys between Hardware Security Modules (HSMs) while ensuring certainty of key ownership and non-repudiation of the transfer, especially due to geographical or network topology changes or HSM migration.

Innovation Solution

A computer-implemented method using a blockchain network where a key is transferred by generating and validating new records to associate the key with a receiving HSM, ensuring secure access and ownership through miner validation, with cryptocurrency transactions constraining access and ownership.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cryptographic keys are transferred between HSMs using conventional methods, then key transfer capability is improved, but certainty of ownership and non-repudiation deteriorate

Engineering Contradiction:
Improvekey transfer capabilityVSAvoidcertainty of ownership
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a blockchain as an intermediary mediator between HSMs for key transfer operations. The blockchain records and validates key transfer transactions through distributed consensus, providing an impartial third-party verification system that ensures both key transfer capability and certainty of ownership simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the blockchain continuously validates and records key ownership states. Each key transfer operation generates a transaction that is validated by the network, providing real-time feedback on ownership status and creating an auditable trail that prevents repudiation.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If cryptographic keys are transferred between HSMs, then operational flexibility is improved, but security and non-repudiation deteriorate

Engineering Contradiction:
Improveoperational flexibilityVSAvoidrepudiation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary actions by recording key transfer intentions and validating them through blockchain consensus before the actual key transfer occurs. This preliminary validation ensures that all parties agree on the transfer terms, preventing later repudiation while maintaining operational flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The blockchain acts as an intermediary that mediates the key transfer process, recording all transactions in an immutable ledger. This intermediary system provides cryptographic proof of transfer, eliminating repudiation risk while allowing flexible key movement between HSMs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If blockchain validation is implemented for key transfer, then ownership certainty is improved, but system complexity increases

Engineering Contradiction:
Improveownership certaintyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal nature of blockchain technology, which can handle multiple functions including key transfer validation, ownership certification, and audit logging within a single system. This multi-functionality reduces overall system complexity compared to implementing separate mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The blockchain system provides self-service validation through its distributed consensus mechanism. The network automatically validates and records key transfer transactions without requiring external arbitration or complex manual verification processes, simplifying the overall system architecture while maintaining high ownership certainty.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11469891B2Expendable cryptographic key access
Publication Date: 2022.10.11 BRITISH TELECOM PLC
  • US11469891B2 patent drawing
  • US11469891B2 patent drawing
  • US11469891B2 patent drawing

AI summary

A computer implemented method of a receiving secure computing component to provide access to a cryptographic key for a key requester, the key being associated with an owning secure computing component by a digitally signed record in a blockchain wherein the blockchain is accessible via a network and includes a plurality of records validated by miner computing components, wherein the key requester has associated a quantity of cryptocurrency by a digitally signed record in the blockchain, the method including: receiving a request from the key requester to access the key; generating a first new record for storage in the blockchain to transfer a predetermined quantity of cryptocurrency associated with the requester to be associated with the receiving component, the first new record being validated by the miner components; responsive to the validation of the first new record, communicating a request to the owning component to transfer the key to the receiving component; responsive to securely receiving the key at the receiving component and a validation of a second new record in the blockchain, the second new record associating the key with the receiving component, providing the requester with secure access to the key.