Hardware Security Module Segmentation for Cryptographic Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data processing devices lack flexibility and security, limiting their operational efficiency and integrity in handling cryptographic tasks.

Innovation Solution

Incorporating a hardware security module and a separate cryptography module that can operate independently, with dedicated data interfaces and buses for secure and efficient data exchange, enabling the hardware security module to handle configuration tasks while the cryptography module performs cryptographic calculations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single integrated security module is used, then device complexity is reduced, but flexibility and security are insufficient

Engineering Contradiction:
ImproveflexibilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security system into two separate modules: a hardware security module (HSM) and a cryptography module. The HSM handles configuration tasks and secure key management, while the cryptography module performs cryptographic calculations. This segmentation allows each module to be optimized for its specific function, improving overall flexibility and security without requiring a single complex integrated design.

Inventive Principle:
Principle #1Segmentation

2Productivity

If cryptographic calculations are performed within the hardware security module, then security is improved, but processing efficiency and scalability are limited

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts the cryptographic calculation functions from the hardware security module and places them in a separate cryptography module. This allows the HSM to focus on secure key management and configuration, while the cryptography module handles computationally intensive cryptographic operations. The separation enables parallel processing and improves overall processing efficiency while maintaining security through the HSM's controlled access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a dedicated second data bus as an intermediary communication channel between the hardware security module and the cryptography module. This separate communication path allows secure exchange of cryptographic data without exposing it to the main system bus, enhancing security while enabling efficient data transfer for cryptographic processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple data interfaces are provided for different components, then security domains are separated, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements different data interface characteristics for different communication needs: a first data bus for general system communication and a second dedicated data bus specifically for secure communication between the HSM and cryptography module. Each interface is optimized for its specific purpose, with the second bus providing enhanced security features for cryptographic data transmission while the first bus handles general system operations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11238166B2Data processing device and operating method therefor
Publication Date: 2022.02.01 ROBERT BOSCH GMBH
  • US11238166B2 patent drawing
  • US11238166B2 patent drawing
  • US11238166B2 patent drawing

AI summary

Data processing device, in particular, for a control unit, the data processing device including at least one computing device, a memory device, a hardware security module and at least one cryptography module.