Blockchain-Based Key Transfer Between Hardware Security Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Hardware Security Modules (HSMs) face challenges in securely and reliably transferring cryptographic keys between HSMs, ensuring certainty of key ownership and non-repudiation of the transfer.

Innovation Solution

A computer-implemented method using a blockchain to securely transfer cryptographic keys between HSMs, where a digitally signed record in the blockchain validates the transfer and ensures non-repudiation, with miner components confirming the state of the blockchain through proof of work.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are transferred between HSMs using conventional methods, then the transfer can be readily effected, but certainty of key ownership and non-repudiation of the transfer cannot be assured

Engineering Contradiction:
Improveease of key transferVSAvoidcertainty of key ownership
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A blockchain system serves as an intermediary between HSMs during key transfer operations. The blockchain records and validates key ownership transitions through cryptographically secured transactions, providing an impartial mediator that both simplifies the transfer process and guarantees ownership certainty through its immutable ledger and consensus mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic keys are transferred between HSMs using conventional methods, then the transfer can be readily effected, but non-repudiation of the transfer cannot be assured

Engineering Contradiction:
Improveease of key transferVSAvoidnon-repudiation assurance
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The blockchain system provides continuous feedback regarding key ownership status through its distributed ledger. Each key transfer generates a recorded transaction that is visible and verifiable across the network, creating an auditable trail that prevents repudiation while maintaining ease of operation through automated smart contract enforcement.

Inventive Principle:
Principle #23Feedback

3Reliability

If blockchain is used to manage key transfers between HSMs, then certainty of key ownership and non-repudiation are assured, but the complexity of the system increases

Engineering Contradiction:
Improvecertainty of key ownershipVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses cryptographic copies and representations of keys within the blockchain ecosystem rather than directly managing physical key materials. Digital representations and cryptographic proofs are copied and validated across the distributed network, ensuring ownership certainty while abstracting away the complexity of direct HSM-to-HSM key management.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12341872B2Hardware security module management
Publication Date: 2025.06.24 BRITISH TELECOM PLC
  • US12341872B2 patent drawing
  • US12341872B2 patent drawing
  • US12341872B2 patent drawing

AI summary

A computer implemented method of a secure computing component to provide access to a cryptographic key, the key being associated with the secure component by a digitally signed record in a blockchain wherein the blockchain is accessible via a network and includes a plurality of records validated by miner computing components, the method including receiving a request from another secure computing component to associate the key with the other component, the request having associated identification information for a requester of the key; responsive to a verification of an entitlement of the requester, generating a new record for storage in the blockchain, the new record associating the key with the other component and being validated by the miner components; and further responsive to the verification, securely transferring the key to the other component so as to provide access to the key to the key requester via the other component.