Distributed Code Signing with HSM Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized code signing systems face issues with performance, availability, and security, particularly when uploading large images or during intermittent connections, which can halt critical development and compromise device security.

Innovation Solution

A distributed data signing architecture that uses a local server for code signing and encryption services, with encrypted signing keys stored in a hardware security module (HSM), allowing for local processing and reduced reliance on centralized systems, ensuring better availability and scalability while maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized code signing system is used, then key management and security control are simplified, but system availability and performance deteriorate when connections are intermittent or servers are down

Engineering Contradiction:
Improvesystem availabilityVSAvoiddistributed architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized code signing system is segmented into distributed code signing servers deployed at multiple locations. Each server can independently perform signing operations, eliminating the single point of failure inherent in centralized systems. The segmentation allows the system to maintain availability even when some servers are inaccessible.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Code signing capability is distributed to local servers that can operate autonomously without requiring constant connection to a central authority. Each local server maintains the necessary signing keys and can service signing requests locally, providing quality service regardless of central system status.

Inventive Principle:
Principle #3Local quality

2Productivity

If large code images are uploaded to a centralized system for signing, then comprehensive security control is maintained, but upload speed and performance deteriorate

Engineering Contradiction:
Improvesigning operation speedVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The signing operation is extracted from the centralized system and performed locally at distributed servers. Only the essential signing function is distributed, while security policies and key management remain controlled through the centralized key server, maintaining security while improving performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A key server acts as an intermediary between the distributed code signing servers and the centralized security infrastructure. The key server distributes signing keys to local servers and receives signed code images, enabling fast local signing operations while maintaining centralized security oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If signing keys are stored in encrypted form in databases, then security is improved, but key retrieval and decryption time increases

Engineering Contradiction:
Improvekey securityVSAvoidkey retrieval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Signing keys are pre-loaded into the HSM modules of distributed code signing servers in encrypted form. The encryption allows rapid retrieval and in-memory decryption without repeated database access, maintaining both security and performance for time-sensitive signing operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20220417032A1Distributed signing system
Publication Date: 2022.12.29 ARRIS ENTERPRISES LLC
  • US20220417032A1 patent drawing
  • US20220417032A1 patent drawing
  • US20220417032A1 patent drawing

AI summary

A system and method for signing or encrypting data is disclosed. The method comprises providing, from a first device, data signing information for storage in a first database, the data signing information having at least one key comprising a signing key Ks, wherein the signing key Ks is encrypted according to a wrapping key Kw before storage in the first database; receiving a data signing request comprising a representation of the data; retrieving, in a second device communicatively coupled to an hardware security module (HSM) storing the wrapping key Kw, the stored data signing information from a second database, wherein at least a portion of the second database including the stored signing information is pushed from the first database to the second database; decrypting, in the HSM, the encrypted signing key according to the wrapping key Kw stored in the HSM to recover the signing key Ks; and signing the representation of the data according to the recovered signing key.