HSM Link Encryption and Key Diversification for Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant Hardware Security Module (HSM) architectures, ensuring that concurrently running applications on the same or different processors do not have access to another application's data, memory, or processes is a primary security concern, particularly due to the risk of data leakage through side channel analysis.

Innovation Solution

Implementing a Link Encryption and Key Diversification interoperability system within the HSM, utilizing a HSM Key Diversification Function (KDF) to generate AES-256 VF Keys specific to each Virtual Function (VF), ensuring each VF has its own encryption and decryption keys for secure communication over PCIe channels, and incorporating Cyclic Redundancy Check (CRC) for data transfer error detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple tenant applications are hosted on the same virtual HSM to improve resource utilization and reduce costs, then productivity and cost-efficiency are improved, but security isolation between tenants deteriorates due to potential side channel analysis attacks

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the shared HSM resources by implementing virtualization layers (VFIO, VF) that divide the physical HSM into multiple virtual instances. Each tenant application is assigned to a specific virtual HSM instance, creating logical isolation boundaries. This segmentation allows multiple tenants to share the same physical hardware while maintaining secure separation through virtualization mechanisms and dedicated communication channels for each tenant.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If cryptographic services are shared across multiple tenants on the same HSM to improve ease of operation and management, then ease of operation is improved, but security risks increase due to potential data leakage between tenants

Engineering Contradiction:
ImprovemanagementVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces virtualization intermediaries (virtual HSM instances, VFIO drivers, and communication channels) that act as mediators between tenant applications and the shared cryptographic hardware. These intermediaries manage the cryptographic services centrally while enforcing security policies, allowing easy operational management through unified interfaces while preventing direct access that could lead to data leakage between tenants.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If hardware resources are shared among multiple tenant applications to reduce device complexity and cost, then device complexity is reduced, but security isolation deteriorates due to concurrent execution on shared processors

Engineering Contradiction:
Improvehardware configurationVSAvoidcryptographic security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent adds a virtualization dimension to the shared hardware architecture, creating layers of abstraction between the physical hardware and tenant applications. By introducing virtual HSM instances and communication channels as additional dimensional layers, the system maintains simple shared hardware while achieving security isolation through the virtualization dimension, allowing concurrent executions to be logically separated despite sharing the same physical processors.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12470379B2Link encryption and key diversification on a hardware security module
Publication Date: 2025.11.11 THALES DIS CPL USA INC
  • US12470379B2 patent drawing
  • US12470379B2 patent drawing
  • US12470379B2 patent drawing

AI summary

A Hardware Security Module (HSM) (900), and method thereof, suitable for use in securely servicing cryptographic requests from multiple tenant applications to preserve end-to-end privacy is provided. A Link Encryption and Key Diversification interoperability (43) between two processors provides cryptographic and logical isolation between multiple tenant applications on the HSM (900) that use and share more than one PCIe Physical Function (30) over more than one Virtual Function (VF) (21) to one or more Crypto Units (CU) (61) for satisfying a request (46) of an HSM cryptographic services. An Output Feedback (OFB) block with CRC support is further provided with encryption and decryption. The HSM as configured is more resistant to side channel attacks.