Hardware Security Unit as Certificate Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing systems face challenges in securely managing trust relationships and protecting sensitive information, particularly in ensuring the integrity and authenticity of software modules and cryptographic functions, which are often reliant on external mechanisms that can be cumbersome and vulnerable to unauthorized access.

Innovation Solution

Integration of a hardware security unit within the data processing system that acts as a hardware certificate authority, utilizing a pair of smart key devices to enable cryptographic functionality only when physically allowed by a system administrator, and establishing mutual trust relationships among server processes based on the hardware security unit, with the hardware security unit signing software and issuing digital certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware security unit is integrated into the data processing system to act as a hardware certificate authority, then the security and integrity of cryptographic functions are enhanced, but the device complexity increases

Engineering Contradiction:
Improvesecurity and integrity of cryptographic functionsVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the certificate authority functionality with the hardware security unit into a single integrated component. The hardware security unit contains both the cryptographic processing capabilities and the certificate authority functions, including private key storage and digital certificate issuance, merging what would traditionally be separate security infrastructure components into one unified hardware device that resides within the data processing system.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If smart key devices are used to physically control access to cryptographic functionality, then unauthorized access is prevented, but the ease of operation decreases due to physical authentication requirements

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The smart key device acts as an intermediary between the system administrator and the hardware security unit. It serves as a physical mediator that must be present and authenticated to enable cryptographic functions, creating a trusted bridge that ensures only authorized personnel can activate security features while maintaining a relatively simple user experience through plug-and-play operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the hardware security unit acts as a certificate authority to issue digital certificates for software modules, then mutual trust relationships are established among server processes, but the manufacturing precision requirements increase for securing the certificate authority functions

Engineering Contradiction:
Improvemutual trust relationships among server processesVSAvoidmanufacturing precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The hardware security unit is segmented into distinct functional components: a secure element for private key generation and storage, a certificate authority module for issuing digital certificates, and an interface module for communicating with software modules. This segmentation allows each component to be optimized and secured independently, with the private key generation isolated in a tamper-resistant zone, while the certificate issuance functions operate in a controlled environment within the same hardware unit.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7711951B2Method and system for establishing a trust framework based on smart key devices
Publication Date: 2010.05.04 META PLATFORMS INC
  • US7711951B2 patent drawing
  • US7711951B2 patent drawing
  • US7711951B2 patent drawing

AI summary

A mechanism is provided for securing cryptographic functionality within a host system such that it may only be used when a system administrator physically allows it via a hardware security token. In addition, a hardware security unit is integrated into a data processing system, and the hardware security unit acts as a hardware certificate authority. The hardware security unit may be viewed as supporting a trust hierarchy or trust framework within a distributed data processing system. The hardware security unit can sign software that is installed on the machine that contains the hardware security unit. Server processes that use the signed software that is run on the machine can establish mutual trust relationships with the hardware security unit and amongst the other server processes based on their common trust of the hardware security unit.