Multi-Tenant HSM Key Security via Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional hardware security modules (HSMs) hosted by service providers face inefficiencies and security vulnerabilities due to single-tenancy solutions, leading to underutilization of cryptographic resources and potential misuse or exposure of tenants' cryptographic keys.
Innovation Solution
A method for secure data transfer between tenant and service provider systems, involving the generation of access control lists, cryptographic key pairs, and certificates to ensure secure storage and use of cryptographic keys, with validation and encryption processes to maintain key security and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single-tenancy solution with dedicated cryptographic appliances per tenant is used, then each tenant can securely manage their cryptographic keys, but the service provider must provision and maintain separate appliances for each tenant, resulting in underutilization of cryptographic resources and increased operational complexity
Solution Approach 1:
The patent segments the cryptographic infrastructure into virtualized security domains, where each tenant's cryptographic operations are isolated in their own secure context within a shared physical HSM. This allows multiple tenants to use the same physical appliance while maintaining security boundaries, thus improving resource utilization while preserving key security.
Solution Approach 2:
The patent implements a universal cryptographic platform where a single HSM can serve multiple tenants simultaneously through virtualization. The system provides multi-tenancy capabilities, allowing one appliance to perform cryptographic functions for many different organizations, thereby eliminating underutilization while maintaining security through access control lists and cryptographic isolation.
2Ease of operation
If the service provider is granted administrative access to manage cryptographic appliances, then they can provision and maintain the infrastructure, but they also gain the ability to export raw key material, creating security vulnerabilities and potential misuse of tenant keys
Solution Approach 1:
The patent extracts the ability to export raw key material from the service provider's administrative privileges. The HSM is designed so that even with full administrative access, the service provider cannot export tenant keys. Keys remain confined within the HSM's secure boundary, and the service provider can only perform cryptographic operations without accessing the actual key material.
Solution Approach 2:
The patent introduces an intermediary architectural layer between the service provider and tenant keys. The HSM's secure boundary and access control mechanisms act as intermediaries that allow the service provider to manage the appliance (provisioning, configuration) while blocking access to raw key material. This intermediary layer decouples management capability from key exposure risk.
3Productivity
If cryptographic resources are shared across multiple tenants, then resource utilization improves, but the complexity of managing security boundaries and access control increases
Solution Approach 1:
The patent implements self-service capabilities where each tenant's cryptographic operations automatically enforce their own security boundaries through access control lists stored within the HSM. The system autonomously manages security contexts and validates access requests without requiring manual configuration of security boundaries, thereby reducing management complexity while enabling multi-tenancy.
Solution Approach 2:
The patent uses parameter changes in the form of access control lists and security context identifiers to dynamically manage multi-tenant environments. By changing security parameters (access control policies, cryptographic contexts) rather than physical configurations, the system can easily accommodate multiple tenants with different security requirements on the same hardware platform, reducing operational complexity.
Data Source
AI summary
A method of data transfer from a tenant to a service provider comprises encrypting the data with a public key of a key pair generated by a secure device within the service provider system. The data thus cannot be accessed by the service provider during transmission.The data is generated with a corresponding access control list, which specifies that a valid certificate must be presented in order to grant a particular use of the data once stored. The tenant can thus retain control of the use of the data even though it has been transferred out of the tenant system.A method of controlling use of data securely stored in the service provider system comprises issuing a use certificate having an expiry time to the party requesting use of the data. The use certificate must be validated before use of the stored data is granted. This enables the tenant to grant use of the stored data for a limited time period.


