Hardware Security Module Architecture for Isolated DMA Offload
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Evita standard for hardware security modules (HSMs) does not provide guidance on how to organize and integrate the necessary hardware modules, leading to a lack of secure and efficient HSM architectures in compliance with the standard.
Innovation Solution
An HSM architecture that includes an HSM bus matrix, HSM master modules with a CPU core and DMA, HSM slave modules with encryption/decryption engines, and an HSM SRAM for secure storage, integrated with a host system to provide data isolation and efficient data movement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the HSM CPU core processes all data movement tasks, then security control is centralized, but the operating efficiency of the HSM decreases due to heavy processing load
Solution Approach 1:
The patent segments the data movement functionality from the HSM CPU core by introducing a separate HSM DMA module. This segmentation allows the CPU core to focus on security-critical processing while the DMA handles data movement tasks, thereby resolving the contradiction between centralized security control and operating efficiency.
Solution Approach 2:
The HSM DMA acts as an intermediary between the HSM CPU core and external devices/buses. It mediates all data movement operations, enabling the CPU core to maintain security control without being burdened by data transfer overhead, thus improving operating efficiency while preserving security.
2Reliability
If the HSM integrates multiple cryptographic engine modules, then security functionality is enhanced, but the device complexity increases
Solution Approach 1:
The patent implements a universal HSM bus matrix that can accommodate multiple types of cryptographic engine modules (symmetric, asymmetric, hash modules). This multi-functional bus structure allows the HSM to provide comprehensive security functionality while managing complexity through a standardized interface framework.
Solution Approach 2:
The HSM bus matrix uses configurable parameters (such as address mapping, access permissions, and data width) to adapt to different cryptographic engine modules. This parameter-based configuration allows multiple module types to be integrated without increasing structural complexity, as the same bus infrastructure can be reconfigured for different module types.
3Reliability
If the HSM SRAM stores all sensitive information, then data isolation from host is improved, but the storage capacity becomes limited
Solution Approach 1:
The patent implements a nested storage architecture where the HSM SRAM (providing secure isolation) contains or is complemented by additional secure storage areas. This nested structure allows sensitive information to be stored in the isolated HSM SRAM while maintaining the data isolation boundary, effectively managing both isolation requirements and storage capacity needs.
Data Source
AI summary
The present invention provides an HSM and a controller. The HSM includes an HSM bus matrix and, connected to the HSM bus matrix, a plurality of HSM master modules, an HSM external bus port, an HSM SRAM and a plurality of HSM slave modules. The HSM master modules include an HSM CPU core and an HSM DMA. The HSM slave modules include at least one encryption/decryption engine module. The HSM of the present invention complies with the Evita standard, and through storing sensitive information in the HSM SRAM or the like, provides secure execution and storage. Not only data isolation between the HSM and an external host, and hence protection of sensitive information, can be provided, the use of the HSM DMA allows the HSM CPU core to be offloaded from heavy data movement, thereby enhancing operating efficiency of the HSM CPU core.


