Hardware Security Module Interface Sharing in Collaborative Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for an apparatus and method to share a security module, such as a hardware security module (HSM) or software security module, within a collaborative network to enable low assurance devices to access high assurance transactions and services, as existing devices lack the necessary security features to perform such transactions independently.
Innovation Solution
A method and apparatus where a first communication device with secure access to the security module advertises its services to other devices, determines authorization, and processes security service messages between the devices and the security module, allowing authorized devices to access the security module's services, including cryptographic operations, thereby enabling low assurance devices to perform high assurance transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If low assurance devices are used in the collaborative network, then device complexity and cost are reduced, but the ability to perform high assurance transactions independently is lost
Solution Approach 1:
A gateway device is introduced as an intermediary between low assurance devices and the HSM. The gateway receives cryptographic service requests from low assurance devices, validates them against authorization policies, and forwards approved requests to the HSM. This mediator enables low assurance devices to access high assurance services without requiring them to have built-in HSM capabilities, thus resolving the contradiction between device simplicity and transaction security.
2Adaptability or versatility
If HSM services are shared across multiple devices in the collaborative network, then service versatility is improved, but security control and access management become more complex
Solution Approach 1:
The HSM is configured to provide universal cryptographic services to multiple devices in the collaborative network. A single HSM can serve high assurance devices, low assurance devices, and gateways simultaneously, performing key generation, encryption, decryption, and digital signature operations for all of them. This multi-functionality improves service versatility while avoiding the need for separate HSMs for each device type.
Solution Approach 2:
The gateway acts as a mediating layer that simplifies access management for the HSM. It implements authorization policies, validates device credentials, and manages session control, thereby shielding the HSM from direct complex access management tasks. This intermediary approach enables multiple devices to access HSM services securely without increasing HSM complexity.
3Reliability
If low assurance devices access HSM services through the gateway, then high assurance transaction capability is enabled, but network communication overhead increases
Solution Approach 1:
The gateway performs preliminary actions by pre-establishing security associations and authorization policies before low assurance devices need to access HSM services. During device pairing or network initialization, the gateway pre-configures access rights, validates device identities, and sets up cryptographic parameters. This preliminary setup reduces real-time communication overhead when actual HSM transactions occur, as the gateway can quickly route requests without performing complex validation during the transaction itself.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A first communication device having a secure access to a security module establishes a collaborative network by forming a collaborative security association with a second communication device associated with a user of the first communication device. The first communication device (a) sends an advertisement of services associated with the security module to the second communication device and receives an advertisement response from the second communication device or (b) receives a solicitation request for services associated with the security module from the second communication device. Responsive to receiving one of the advertisement response and the solicitation request, the first communication device determines whether the second communication device is authorized to access the security module. The first communication device processes and forwards security service messages between the second communication device and the security module, in response to determining that the second communication device is authorized to access the security module.