Commodity Hardware Cryptographic Service via Chipset Secure Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cybersecurity systems relying on hardware security modules (HSMs) face challenges with high costs, scalability issues, and increased latency when handling numerous cryptographic operations.
Innovation Solution
A cybersecurity system utilizing a chip set to manage secure memory spaces, allowing protected applications to perform cryptographic operations, such as encryption, decryption, and hashing, without relying on HSMs, thereby reducing costs and improving scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware security modules (HSMs) are used to perform cryptographic operations, then security is improved, but cost increases and scalability decreases
Solution Approach 1:
The patent creates a virtual copy of the HSM functionality through a software-based cryptographic service that runs on commodity hardware. Instead of requiring physical HSM devices, the system instantiates virtual cryptographic instances that replicate HSM operations, thereby eliminating the need for expensive specialized hardware while maintaining security functions.
Solution Approach 2:
The patent replaces the mechanical/physical HSM system with a software-based cryptographic service running on general-purpose processors. The cryptographic operations that traditionally required specialized hardware circuits are now performed through software implementations, substituting physical security modules with virtualized computational services.
2Reliability
If hardware security modules (HSMs) are used to perform cryptographic operations, then security is improved, but device complexity and scalability are reduced
Solution Approach 1:
The patent segments the cryptographic service into multiple virtual instances that can be independently created and managed. Each virtual cryptographic instance operates as a separate unit, allowing the system to scale horizontally by simply instantiating additional virtual instances on available commodity hardware, thereby improving scalability without compromising security.
Solution Approach 2:
The patent creates a universal cryptographic service platform that can perform multiple cryptographic functions (encryption, decryption, hashing, key management) on general-purpose hardware. This multi-functional approach allows a single infrastructure to handle diverse cryptographic operations, eliminating the need for specialized hardware for each function and improving overall system scalability.
3Reliability
If hardware security modules (HSMs) are used to perform cryptographic operations, then security is ensured, but latency increases
Solution Approach 1:
The patent introduces a cryptographic service layer that acts as an intermediary between applications and the underlying hardware resources. This service layer manages cryptographic operations efficiently by maintaining cached keys and utilizing hardware acceleration capabilities of modern processors, thereby reducing the time required for cryptographic operations compared to traditional HSM architectures.
Solution Approach 2:
The patent performs preliminary actions by pre-loading cryptographic keys into secure memory spaces and pre-establishing security contexts before they are needed for actual cryptographic operations. This preparation work reduces the time required during actual encryption/decryption operations, as the system does not need to retrieve keys or initialize security contexts during time-critical operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The solution herein describes a software module that works in combination with certain hardware (e.g., a particular chipset) to obtain the level of security provided by an HSM. The software module can be implemented on a commodity server. The software module can utilize an HSM or key custodian to obtain cryptographic keys. The cryptographic keys may be stored on the commodity server within a secure memory space managed by the commodity server's chip set. While stored, access to the cryptographic keys may be managed by the chip set. The chip set can ensure that only protected applications associated with the cryptographic keys may access said keys.