Extended HSM for Cloud Computation Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing security measures, such as TPMs and virtualization, fail to provide adequate computation privacy and data confidentiality due to unfettered physical access to underlying hardware, allowing insiders to access sensitive data and tasks within cloud-hosted virtual machines.

Innovation Solution

The development of extended Hardware Security Modules (HSMs) with anti-tamper enclosures and additional security components that enable secure initialization, deployment, and management, ensuring sensitive data and tasks are encrypted and protected from physical access, even when hosted in a remote cloud environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional TPMs and virtualization mechanisms are used in cloud environments, then cloud service scalability and resource sharing are improved, but computation privacy and data confidentiality deteriorate due to unfettered physical access to underlying hardware

Engineering Contradiction:
Improvecloud service scalabilityVSAvoidcomputation privacy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the trust boundary by introducing a dedicated security module (HSM) that physically isolates cryptographic operations from the general-purpose cloud infrastructure. This segmentation creates a distinct secure zone where sensitive operations occur, separating the trusted execution environment from the untrusted cloud hardware, thereby maintaining privacy while allowing cloud scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The HSM acts as an intermediary between the cloud service provider and the client's sensitive data. It mediates cryptographic operations by receiving requests from the cloud environment, performing secure operations within its protected boundaries, and returning results without exposing the underlying data or keys to the cloud provider, thus preserving computation privacy while enabling cloud-based processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cloud providers are given physical access to underlying hardware for maintenance and management, then operational efficiency and service availability are improved, but security against insider access deteriorates

Engineering Contradiction:
Improveservice availabilityVSAvoidinsider access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system extracts the cryptographic security functions from the general-purpose cloud hardware and places them into a dedicated HSM. This extraction ensures that even though cloud providers maintain physical access to the overall system for operational efficiency, the critical cryptographic operations and data remain isolated in a separate security domain that prevents insider access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The HSM implements local quality by creating a specialized security zone with different access controls and protection mechanisms than the rest of the cloud infrastructure. Within this local secure environment, stringent physical and logical protections are applied specifically to cryptographic operations, while the broader cloud system maintains operational accessibility for cloud providers.

Inventive Principle:
Principle #3Local quality

3Productivity

If virtualization is used to isolate client workloads, then resource utilization and cost efficiency are improved, but isolation guarantees and security boundaries deteriorate due to potential VM escape and insider access

Engineering Contradiction:
Improveresource utilizationVSAvoidisolation guarantees
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system adds another dimension of isolation by moving cryptographic operations from the virtualized software layer into a physically protected hardware dimension. This dimensional shift creates a hardware-enforced security boundary that is independent of the virtualization layer, providing isolation guarantees that cannot be breached through software-based VM escape techniques while maintaining virtualization for resource efficiency.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11604901B2Systems and methods for using extended hardware security modules
Publication Date: 2023.03.14 PRIVATE MACHINES INC
  • US11604901B2 patent drawing
  • US11604901B2 patent drawing
  • US11604901B2 patent drawing

AI summary

An extended hardware security module (“HSM”) possessing additional security properties relative to conventional HSMs and methods for initializing, deploying, and managing such extended HSMs in a networked environment. In the preferred embodiment, an extended HSM includes additional hardware and software components that configure it to run sensitive client tasks on demand inside a cloud-hosted, anti-tamper HSM housing so as to ensure sensitive data is encrypted when stored or processed outside the housing. Methods for initializing, deploying, and managing provide a framework through which extended HSMs may be secured from their initial assembly through their availing for use and actual use over a network by one or more clients. Such use often entails repeated discrete sequential secure sessions and concurrent discrete secure sessions.