HSM Fleet Key Synchronization via Intermediary Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Maintaining synchronized cryptographic keys across a fleet of Hardware Security Modules (HSMs) is challenging due to their non-exportability, making it difficult to manage and secure large-scale computing environments effectively.

Innovation Solution

Implementing an HSM management hub that organizes HSMs into a fleet, using a fleet key for synchronization and encryption, and employing public-private key cryptography to distribute and manage cryptographic information, ensuring secure communication and backup/restore processes without exposing the fleet key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored in HSMs to secure data, then security is improved, but the ability to maintain synchronized keys across multiple HSMs deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidkey synchronization
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a key distribution system that acts as an intermediary between HSMs. This system includes a key distribution center that securely distributes cryptographic keys to multiple HSMs, enabling synchronized key management without requiring direct communication between HSMs. The intermediary handles the complexity of key synchronization while maintaining the security isolation of individual HSMs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the key management function by separating key storage (in HSMs) from key distribution (handled by the key distribution center). This segmentation allows HSMs to maintain their security isolation while the distribution center coordinates key synchronization across the fleet, resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #1Segmentation

2Productivity

If multiple HSMs are used to improve cryptographic operation performance, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvecryptographic operation performanceVSAvoidfleet management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The key distribution center serves multiple functions: it distributes keys to HSMs, coordinates key synchronization, and manages the fleet of HSMs. This multi-functionality consolidates what would otherwise be complex distributed management into a single centralized system, improving productivity while managing complexity through functional consolidation rather than proliferation of management components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11784811B2Storage of cryptographic information
Publication Date: 2023.10.10 AMAZON TECH INC
  • US11784811B2 patent drawing
  • US11784811B2 patent drawing
  • US11784811B2 patent drawing

AI summary

Fault-tolerant storage of cryptographic information maintained on a fleet of HSMs may be provided by dividing the cryptographic information into a number of stripes which are distributed and stored on individual HSMs in the HSM fleet. Parity information is generated which allows one or more stripes to be regenerated if one or more stripes becomes corrupt or is lost. The parity information may be stored on an HSM in the HSM fleet, or outside the fleet on a storage service, HSM management hub, tangible computer-readable media, or other device. If an HSM in the HSM fleet fails, resulting in the loss of a stripe, an HSM in the fleet can recover the missing stripe by re-creating the missing stripe from the remaining stripes combined with the parity information. In some examples, stripes are mirrored within the fleet of HSMs.