Hardware Security Module Authenticated Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for authenticated transmission of data sets and programs to hardware security modules (HSMs) require high security measures at production sites, which are expensive, time-consuming, and prone to malfunctions, especially when implemented in unprotected or poorly protected environments.

Innovation Solution

A method involving the generation and use of variable and fixed codes, where a system manufacturer calculates and stores specific fixed codes within the HSM memory, allowing secure transmission without the need for special security measures at the production site, by using algorithms only accessible within the HSM, ensuring only authorized data sets and programs can be loaded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high security measures are implemented at production sites for authenticated transmission, then security against unauthorized data loading is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity against unauthorized data loadingVSAvoidsecurity measures at production site
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security-critical algorithms from the host system and places them exclusively within the HSM. This extraction eliminates the need for complex security measures at the production site, as the HSM becomes the sole guardian of security, performing all authenticated transmission and data generation operations independently.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The HSM performs self-service by independently executing authenticated transmission of data sets and generating authorized data using algorithms stored within its own memory. This self-contained operation eliminates dependency on external security infrastructure, allowing the HSM to autonomously ensure security without requiring protected production environments.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If algorithms are made accessible at production site for data generation, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvedata generation capabilityVSAvoidprotection against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The algorithms are extracted from the production site environment and relocated exclusively to the HSM memory. This ensures that while the HSM maintains full data generation capability, the algorithms remain inaccessible to unauthorized entities at the production site, preserving security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The HSM acts as an intermediary between the production site and the algorithms. All data generation operations must be routed through the HSM, which mediates access to the algorithms stored in its secure memory, preventing direct access while maintaining operational functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If proprietary algorithms are stored within HSM for secure operations, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity through proprietary algorithmsVSAvoidHSM internal structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the algorithms, data sets, and HSM functionality into a single integrated unit. By combining these elements within the HSM memory, the patent reduces overall system complexity despite the increased internal sophistication of the HSM, as external security infrastructure becomes unnecessary.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8205088B2Method for the authenticated transmission of a personalized data set or program to a hardware security module in particular of a franking machine
Publication Date: 2012.06.19 FRANCOTYP POSTALIA AG & CO KG
  • US8205088B2 patent drawing
  • US8205088B2 patent drawing
  • US8205088B2 patent drawing

AI summary

In a method and arrangement for authenticated transmission of a personalized data set or program to a hardware security module in a device such as a franking machine, a system manufacturer buys security modules, from a security module manufacturer and incorporate the security modules at a production site in the device and loads a data set and/or an application program into the security module, making the device operable. Authentication occurs using a first security module-specific fixed code, a second security module-specific fixed code that is calculated from the first code according to a given algorithm, and a third security module-specific fixed code that is calculated from the second code and the data in the data set and/or in the program.