Cryptographic Material Distribution via Secure Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in securely distributing and managing cryptographic material for remote computing resources, particularly in ensuring secure communication and timely renewal without interruption.

Innovation Solution

A cryptographic material management service is implemented to provision, store, and update cryptographic material using secure modules, which are logically attached to computing resources, preventing exposure and ensuring continuous availability through transparent renewal processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic material is distributed to computing resources, then secure communication is enabled, but security exposure and compromise risk increase

Engineering Contradiction:
Improvesecure communicationVSAvoidcryptographic material exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts cryptographic material from the computing resources themselves and stores it in external secure modules (HSMs, TPMs, or cloud-based secure storage). This separation allows computing resources to perform cryptographic operations without having direct access to or exposure of the actual cryptographic material, thereby enabling secure communication while minimizing security exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces secure modules as intermediary components between the computing resources and the cryptographic material. These secure modules act as mediators that hold and manage cryptographic material securely, allowing computing resources to communicate securely through cryptographic operations performed by the intermediary secure modules without directly accessing the sensitive material.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If cryptographic material is stored securely in external modules, then exposure is prevented, but system complexity increases

Engineering Contradiction:
Improvecryptographic material exposureVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent employs universal secure modules that can be deployed across multiple computing resources and serve multiple functions (storage, key management, cryptographic operations). This multi-functionality reduces overall system complexity by consolidating cryptographic capabilities into standardized, reusable components rather than requiring custom cryptographic implementations at each computing resource.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements automated cryptographic material management where secure modules and computing resources can autonomously perform operations such as key generation, distribution, and renewal without requiring manual intervention. This self-service capability simplifies system operation and reduces the complexity of managing cryptographic materials across distributed computing resources.

Inventive Principle:
Principle #25Self-service

3Reliability

If cryptographic material is renewed manually, then security control is maintained, but service interruption occurs

Engineering Contradiction:
Improvesecurity controlVSAvoidcommunication continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements automated renewal processes that proactively regenerate and distribute cryptographic material before existing material expires. This preliminary action ensures that cryptographic material is always valid and available, preventing service interruptions while maintaining security control through automated, policy-driven renewal operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuous cryptographic operations by implementing seamless renewal mechanisms where cryptographic material is updated without interrupting computing resource operations. The system maintains continuous security by ensuring that cryptographic material is always available and valid, eliminating gaps that would occur with manual renewal processes.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11115223B2Cryptographic material distribution and management
Publication Date: 2021.09.07 AMAZON TECH INC
  • US11115223B2 patent drawing
  • US11115223B2 patent drawing
  • US11115223B2 patent drawing

AI summary

A method and apparatus for distributing cryptographic material are disclosed. In the method and apparatus, cryptographic material is obtained and it is determined that the cryptographic material is to be made available for use by one or more computing resources. The cryptographic material is then sent to one or more secure modules, whereby a secure module of the one or more secure modules is programmatically accessible to a computing resource of the one or more computing resources and programmatic access enables the computing resource to request performance of one or more cryptographic operations using the cryptographic material while exporting the cryptographic material to the computing resource is denied.