Hierarchical Key Storage for HSM Capacity Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware Security Modules (HSMs) face limitations in storage capacity, making it impractical to store a large number of cryptographic keys, which are required to comply with regulations and business policies, as they often have limited secure data storage space, such as 64 KB, necessitating a solution to manage key storage efficiently.

Innovation Solution

Implementing a system with a hierarchical key management approach that initially stores keys in high-security hardware storage and reclassifies them for relocation to lower-security storage based on usage and data usage rules, using a key-encryption key (KEK) to encrypt the reclassified keys, allowing for more efficient use of HSMs and reducing storage costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored in Hardware Security Modules to maintain high security levels, then security is improved, but storage capacity is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent divides key storage into multiple hierarchical levels: high-security HSM storage for critical keys and lower-security external storage for less critical keys. This segmentation allows the system to maintain high security for essential keys while storing additional keys in more capacity-abundant lower-security storage, resolving the contradiction between security and storage capacity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different storage locations are assigned different security qualities based on key criticality. Critical keys reside in high-security HSMs, while non-critical keys are stored in lower-security external storage. This local quality differentiation enables the system to optimize both security and storage capacity by matching storage security level to key importance.

Inventive Principle:
Principle #3Local quality

2Reliability

If all cryptographic keys are stored in high-security Hardware Security Modules, then security is maintained, but operational costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system segments key storage based on security requirements and cost considerations. By storing only critical keys in expensive HSMs and less critical keys in cheaper external storage, the system reduces operational costs while maintaining security for essential functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs cheaper external storage solutions for keys that do not require high-security protection. These lower-cost storage mechanisms are used for keys with reduced criticality, effectively replacing expensive HSM capacity with more economical storage options where appropriate.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Adaptability or versatility

If a large number of cryptographic keys are stored in Hardware Security Modules to meet regulatory requirements, then compliance is improved, but storage space is insufficient

Engineering Contradiction:
ImprovecomplianceVSAvoidstorage space
Core Design Contradiction:
Adaptability or versatilityVSVolume of stationary object

Solution Approach 1:

The hierarchical storage architecture segments keys into different categories based on compliance requirements and storage needs. Critical compliance keys remain in HSMs, while additional compliance-related keys are stored in external lower-security storage, enabling the system to meet regulatory requirements without HSM space constraints.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from a single-dimension storage approach (all keys in HSM) to a multi-dimensional storage hierarchy that considers both security levels and storage capacity. This dimensional expansion allows the system to accommodate more keys while satisfying both security and compliance requirements.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10523424B2Optimizing use of hardware security modules
Publication Date: 2019.12.31 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10523424B2 patent drawing
  • US10523424B2 patent drawing
  • US10523424B2 patent drawing

AI summary

Use of cryptographic key-store hardware security modules is optimized in a system having a first scarce high-security key storage device and a second more plentiful low-security key storage device comprising securing a cryptographic key to the higher security level by initially storing the key in the first storage device, then responsive to an event, evaluating the stored key against one or more rules, and subsequent to the evaluation, reclassifying the stored key for relocation, encrypting the reclassified key using a key-encryption key; relocating the reclassified key into the second, lower-security storage device, and storing the key-encryption key in the first storage device.