Distributed Cryptographic Object Management Across Remote Sites

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic object management systems face challenges in scalability, latency, and disaster recovery, particularly in EMV issuance systems, due to geographical segregation of Hardware Security Modules (HSMs) and limitations in crypto-processing capacity.

Innovation Solution

Implementing a system that securely stores cryptographic objects in a persistent layer and relies on HSMs for crypto-processing, with load balancing and replication to manage latency and ensure availability, while supporting virtually unlimited tokens and reducing IT administration costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic objects are stored in centralized HSMs, then security is maintained, but scalability and access latency worsen across geographically distributed sites

Engineering Contradiction:
ImprovesecurityVSAvoidaccess latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the centralized cryptographic object storage into distributed persistent layers across multiple geographically separated sites. Each site maintains local copies of cryptographic objects, allowing HSMs at different locations to access objects locally without centralized coordination, thereby reducing access latency while maintaining security through distributed architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional layer (persistent layer) between HSMs and cryptographic objects, transforming the traditional direct access model into a multi-layered architecture. This dimensional change allows cryptographic objects to be stored persistently in accessible locations while HSMs maintain security control, resolving the contradiction between security and access speed

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Quantity of substance

If HSM capacity is increased to handle more cryptographic objects, then cryptographic object management improves, but system complexity and cost increase

Engineering Contradiction:
Improvecryptographic object capacityVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent extracts the storage function of cryptographic objects from HSMs and places it in separate persistent layers. This extraction allows HSMs to focus on security-critical operations while capacity requirements are met by scalable persistent storage systems, reducing HSM complexity and cost while maintaining or increasing overall system capacity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The persistent layer serves multiple functions: storing cryptographic objects, providing load balancing, enabling disaster recovery through replication, and supporting multiple HSMs across different sites. This multi-functionality reduces the need for specialized high-capacity HSM hardware, simplifying the system architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If HSMs are geographically segregated for disaster recovery, then availability improves, but access latency and runtime failures increase

Engineering Contradiction:
Improvedisaster recovery capabilityVSAvoidruntime access failure
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements local quality by placing persistent layers with cryptographic object copies at each geographically distributed site. This allows HSMs to access cryptographic objects from local persistent layers rather than remote centralized storage, maintaining disaster recovery capabilities while minimizing access latency through local availability

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary action by pre-replicating cryptographic objects to persistent layers at multiple geographically distributed sites before failures occur. This ensures that when disasters or network issues happen, HSMs can immediately access locally cached cryptographic objects without runtime failures or delays

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If manual centralized management is used for production sites, then control is maintained, but system availability and scalability are reduced

Engineering Contradiction:
Improvecentralized controlVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service through automated load balancing and failover mechanisms that operate without manual centralized intervention. The system automatically routes requests to available HSMs and manages cryptographic object distribution across sites, maintaining centralized control policies while enabling decentralized autonomous operation that improves availability and scalability

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11610005B2Cryptographic object management across multiple remote sites
Publication Date: 2023.03.21 ENTRUST CORP
  • US11610005B2 patent drawing
  • US11610005B2 patent drawing
  • US11610005B2 patent drawing

AI summary

A cryptographic object management system is provided that includes physically separated first and second object management sites. The first and second object management sites each respectively include HSMs, a HSM server connected to each of the HSMs, and a persistent layer connected to the HSM server. The HSM servers respectively manage operation of each of the HSMs. The HSM server of the first object management site includes an object manager module that manages and controls the cryptographic object management system. The persistent layers respectively store cryptographic objects for use by the HSMs. Each of the HSMs respectively performs crypto-processing on one or more of the cryptographic objects.