Connectable Electronic Module Secure Element Clusters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for providing hardware security modules as services in cloud computing infrastructures fail to guarantee isolation of client data and lack flexibility and scalability, leading to potential unauthorized access and increased costs due to resource pooling.
Innovation Solution
A connectable electronic module with clusters of secure elements is designed to allocate secure elements exclusively to authenticated clients, ensuring data isolation and allowing dynamic resource allocation based on client needs, using a module controller to manage cryptographic operations and store unique master cryptographic keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If hardware security modules are pooled and shared in cloud computing infrastructure, then resource utilization and cost efficiency are improved, but data isolation and security are compromised
Solution Approach 1:
The patent segments the hardware security module into multiple isolated secure elements, each capable of independent operation. Each secure element maintains its own secure storage and processing capabilities, ensuring that data from different clients remains isolated even when sharing the same physical hardware. This segmentation allows the system to pool resources while maintaining data isolation.
Solution Approach 2:
The patent implements local quality by giving each secure element within the hardware module distinct security properties and isolation boundaries. Each secure element has its own secure storage area and cryptographic processing capabilities, creating localized security zones that prevent cross-contamination of data between different clients while still utilizing the same physical hardware resources.
2Quantity of substance
If multiple clients share the same hardware security module, then infrastructure costs are reduced, but the risk of unauthorized access increases
Solution Approach 1:
The hardware security module is divided into multiple independent secure elements, each with its own security boundary. This segmentation ensures that even if one secure element is compromised, other elements remain protected, thereby reducing the overall risk of unauthorized access while allowing multiple clients to share the same physical infrastructure.
Solution Approach 2:
The patent introduces a trusted platform module or security manager as an intermediary that controls access to individual secure elements. This intermediary enforces authentication and authorization policies, ensuring that only authorized clients can access their designated secure elements, thereby mitigating unauthorized access risks while enabling resource sharing.
3Adaptability or versatility
If hardware security modules are allocated dynamically to clients, then flexibility and scalability are improved, but guaranteeing data confidentiality becomes more difficult
Solution Approach 1:
The hardware security module is segmented into multiple isolated secure elements, each with dedicated secure storage. When dynamically allocating resources to clients, the system can assign specific secure elements to specific clients, ensuring that even during dynamic allocation, data confidentiality is maintained through physical isolation within the segmented architecture.
Solution Approach 2:
The patent implements preliminary action by pre-configuring secure elements with client-specific cryptographic keys and security policies before allocation. This ensures that when dynamic allocation occurs, the confidentiality protections are already in place, eliminating the risk of information loss during the allocation process.
Data Source
AI summary
Electronic module able to be connected to a host device, said electronic module comprising:one or more clusters of secure elements, each of the secure elements of one and the same cluster being connected to a common communication bus associated with said cluster;an electronic module controller configured, on the one hand, to communicate with the host device and with the common communication bus of each of the clusters and, on the other hand, to control the execution of cryptographic operations by one or more secure elements;wherein:the module controller is furthermore configured to allocate one or more secure elements of one or more clusters to one or more authenticated clients, each of the secure elements allocated to each authenticated client locally storing a unique master cryptographic key specific to each of said authenticated clients;each of the secure elements allocated to each of the authenticated clients implements a cryptographic operation using a cryptographic key specific to each of the allocated secure elements;each of the secure elements allocated to each of the authenticated clients is configured to decrypt the input data of the cryptographic operation and/or to encrypt the output data of the cryptographic operation using the unique master cryptographic key.


