Multi-Port Hardware Security Module With Hardwired Interconnection Matrix

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current hardware security modules (HSMs) face challenges in providing secure, efficient, and scalable solutions for network infrastructure, particularly in minimizing tampering risks and supporting multiple applications within a tamper-resistant environment.

Innovation Solution

A hardware security module with multiple hardware ports, segregated storage spaces, and a cryptographic engine, integrated within a common integrated circuit architecture, allowing for secure port-specific cryptographic processing and communication channel management through a hardwired port interconnection matrix, which can be reconfigurable to redefine logic and invoke communication channel resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple HSMs are interconnected within a network architecture to provide various data security services, then security coverage is improved, but device complexity and hardware footprint increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidhardware footprint
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple HSM functionalities into a single integrated device with multiple hardware ports. Each port can independently access segregated storage spaces containing different cryptographic keys, eliminating the need for multiple separate HSM devices while maintaining comprehensive security coverage across multiple network applications.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The HSM device is designed with multi-functionality to serve multiple network applications simultaneously through its multiple hardware ports. The device can provide cryptographic services to different applications via different ports, each with dedicated access to specific key storage spaces, thereby reducing hardware footprint while maintaining security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a network attached HSM is used with an appliance server to interface with distinct services, then adaptability is improved, but device complexity increases due to intermediary software

Engineering Contradiction:
Improveservice interface capabilityVSAvoidsoftware intermediary complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic processing functionality from software intermediaries and implements it directly in hardware through multiple dedicated ports. Each hardware port can independently access specific cryptographic keys in segregated storage spaces, eliminating the need for appliance servers and software-based request sorting while maintaining adaptability to multiple services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware ports themselves act as direct intermediaries between network applications and cryptographic key storage, bypassing software-based appliance servers. This hardware-level mediation provides direct, secure access to cryptographic functions while reducing software complexity and improving processing efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If HSM access software is executed on an appliance server to manage processing requests, then ease of operation is improved, but reliability decreases due to software-based access control

Engineering Contradiction:
Improverequest management capabilityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based access control mechanisms with hardware-based enforcement through segregated storage spaces and dedicated hardware ports. Each hardware port has built-in logic to access only its designated key storage spaces, providing tamper-resistant access control that is more reliable than software-based permission systems while maintaining ease of operation through hardware-enforced security policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If multiple HSMs are used to service multiple network applications, then productivity is improved, but loss of substance increases due to redundant hardware

Engineering Contradiction:
Improveservice capacityVSAvoidhardware resources
Core Design Contradiction:
ProductivityVSLoss of substance

Solution Approach 1:

The patent merges the functionality of multiple HSM devices into a single multi-port HSM device. Each hardware port can independently service different network applications with dedicated access to specific cryptographic keys, maintaining high service capacity while eliminating redundant hardware resources that would be required if separate HSM devices were used for each application.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11803666B2Hardware security module, and trusted hardware network interconnection device and resources
Publication Date: 2023.10.31 CRYPTO4A TECH INC
  • US11803666B2 patent drawing
  • US11803666B2 patent drawing
  • US11803666B2 patent drawing

AI summary

Described are various embodiments of a hardware security module, hardwired port interconnection matrix, and embedded communication channel resources operable on selected hardware port-specific data communicated via this matrix.