Connectable Electronic Module Secure Element Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for providing hardware security modules as services in cloud computing infrastructures fail to guarantee isolation of client data and lack flexibility and scalability, leading to potential unauthorized access and increased costs due to resource pooling.

Innovation Solution

A connectable electronic module with clusters of secure elements is designed to allocate secure elements exclusively to authenticated clients, ensuring data isolation and allowing dynamic resource allocation based on client needs, using a module controller to manage cryptographic operations and store unique master cryptographic keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hardware security modules are pooled and shared in cloud computing infrastructure, then resource utilization and cost efficiency are improved, but data isolation and security are compromised

Engineering Contradiction:
Improveresource utilizationVSAvoiddata isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the hardware security module into multiple isolated secure elements, each capable of independent operation. Each secure element maintains its own secure storage and processing capabilities, ensuring that data from different clients remains isolated even when sharing the same physical hardware. This segmentation allows the system to pool resources while maintaining data isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by giving each secure element within the hardware module distinct security properties and isolation boundaries. Each secure element has its own secure storage area and cryptographic processing capabilities, creating localized security zones that prevent cross-contamination of data between different clients while still utilizing the same physical hardware resources.

Inventive Principle:
Principle #3Local quality

2Quantity of substance

If multiple clients share the same hardware security module, then infrastructure costs are reduced, but the risk of unauthorized access increases

Engineering Contradiction:
Improveinfrastructure resourcesVSAvoidunauthorized access risk
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The hardware security module is divided into multiple independent secure elements, each with its own security boundary. This segmentation ensures that even if one secure element is compromised, other elements remain protected, thereby reducing the overall risk of unauthorized access while allowing multiple clients to share the same physical infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted platform module or security manager as an intermediary that controls access to individual secure elements. This intermediary enforces authentication and authorization policies, ensuring that only authorized clients can access their designated secure elements, thereby mitigating unauthorized access risks while enabling resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If hardware security modules are allocated dynamically to clients, then flexibility and scalability are improved, but guaranteeing data confidentiality becomes more difficult

Engineering Contradiction:
Improvedynamic allocation flexibilityVSAvoiddata confidentiality
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The hardware security module is segmented into multiple isolated secure elements, each with dedicated secure storage. When dynamically allocating resources to clients, the system can assign specific secure elements to specific clients, ensuring that even during dynamic allocation, data confidentiality is maintained through physical isolation within the segmented architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-configuring secure elements with client-specific cryptographic keys and security policies before allocation. This ensures that when dynamic allocation occurs, the confidentiality protections are already in place, eliminating the risk of information loss during the allocation process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250007708A1Connectable electronic module comprising clusters of secure elements
Publication Date: 2025.01.02 IDEMIA FRANCE SAS
  • US20250007708A1 patent drawing
  • US20250007708A1 patent drawing
  • US20250007708A1 patent drawing

AI summary

Electronic module able to be connected to a host device, said electronic module comprising:one or more clusters of secure elements, each of the secure elements of one and the same cluster being connected to a common communication bus associated with said cluster;an electronic module controller configured, on the one hand, to communicate with the host device and with the common communication bus of each of the clusters and, on the other hand, to control the execution of cryptographic operations by one or more secure elements;wherein:the module controller is furthermore configured to allocate one or more secure elements of one or more clusters to one or more authenticated clients, each of the secure elements allocated to each authenticated client locally storing a unique master cryptographic key specific to each of said authenticated clients;each of the secure elements allocated to each of the authenticated clients implements a cryptographic operation using a cryptographic key specific to each of the allocated secure elements;each of the secure elements allocated to each of the authenticated clients is configured to decrypt the input data of the cryptographic operation and/or to encrypt the output data of the cryptographic operation using the unique master cryptographic key.