Multi-Tenant HSM Key Security via Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional hardware security modules (HSMs) hosted by service providers face inefficiencies and security vulnerabilities due to single-tenancy solutions, leading to underutilization of cryptographic resources and potential misuse or exposure of tenants' cryptographic keys.

Innovation Solution

A method for secure data transfer between tenant and service provider systems, involving the generation of access control lists, cryptographic key pairs, and certificates to ensure secure storage and use of cryptographic keys, with validation and encryption processes to maintain key security and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-tenancy solution with dedicated cryptographic appliances per tenant is used, then each tenant can securely manage their cryptographic keys, but the service provider must provision and maintain separate appliances for each tenant, resulting in underutilization of cryptographic resources and increased operational complexity

Engineering Contradiction:
Improvecryptographic key securityVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the cryptographic infrastructure into virtualized security domains, where each tenant's cryptographic operations are isolated in their own secure context within a shared physical HSM. This allows multiple tenants to use the same physical appliance while maintaining security boundaries, thus improving resource utilization while preserving key security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal cryptographic platform where a single HSM can serve multiple tenants simultaneously through virtualization. The system provides multi-tenancy capabilities, allowing one appliance to perform cryptographic functions for many different organizations, thereby eliminating underutilization while maintaining security through access control lists and cryptographic isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If the service provider is granted administrative access to manage cryptographic appliances, then they can provision and maintain the infrastructure, but they also gain the ability to export raw key material, creating security vulnerabilities and potential misuse of tenant keys

Engineering Contradiction:
Improveinfrastructure management capabilityVSAvoidkey exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the ability to export raw key material from the service provider's administrative privileges. The HSM is designed so that even with full administrative access, the service provider cannot export tenant keys. Keys remain confined within the HSM's secure boundary, and the service provider can only perform cryptographic operations without accessing the actual key material.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary architectural layer between the service provider and tenant keys. The HSM's secure boundary and access control mechanisms act as intermediaries that allow the service provider to manage the appliance (provisioning, configuration) while blocking access to raw key material. This intermediary layer decouples management capability from key exposure risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If cryptographic resources are shared across multiple tenants, then resource utilization improves, but the complexity of managing security boundaries and access control increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities where each tenant's cryptographic operations automatically enforce their own security boundaries through access control lists stored within the HSM. The system autonomously manages security contexts and validates access requests without requiring manual configuration of security boundaries, thereby reducing management complexity while enabling multi-tenancy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter changes in the form of access control lists and security context identifiers to dynamically manage multi-tenant environments. By changing security parameters (access control policies, cryptographic contexts) rather than physical configurations, the system can easily accommodate multiple tenants with different security requirements on the same hardware platform, reducing operational complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12143476B2Method of data transfer, a method of controlling use of data and cryptographic device
Publication Date: 2024.11.12 NCIPHER SECURITY LTD
  • US12143476B2 patent drawing
  • US12143476B2 patent drawing
  • US12143476B2 patent drawing

AI summary

A method of data transfer from a tenant to a service provider comprises encrypting the data with a public key of a key pair generated by a secure device within the service provider system. The data thus cannot be accessed by the service provider during transmission.The data is generated with a corresponding access control list, which specifies that a valid certificate must be presented in order to grant a particular use of the data once stored. The tenant can thus retain control of the use of the data even though it has been transferred out of the tenant system.A method of controlling use of data securely stored in the service provider system comprises issuing a use certificate having an expiry time to the party requesting use of the data. The use certificate must be validated before use of the stored data is granted. This enables the tenant to grant use of the stored data for a limited time period.