Dedicated HSM Partition Ownership for CSP-Independent Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud service providers (CSPs) may have access to secure resources managed by organizations, compromising data security due to lack of trust and regulatory compliance issues, as they control the Hardware Security Module (HSM) partitions.

Innovation Solution

A method and system where the CSP provisions an HSM partition for an organization, generating a Partition Owner Trust Anchor Certificate (POTAC) and Partition Owner Authentication Certificate (POAC) to ensure the organization is its own source of truth for authentication, removing CSP control over the partition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the cloud services provider controls the HSM partition, then the CSP can manage and access secure resources, but the organization cannot ensure that only authorized parties access the stored resources

Engineering Contradiction:
Improvedata securityVSAvoidCSP access control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The HSM is divided into multiple partitions, with each partition dedicated to a specific organization. The partitioning mechanism isolates secure resources so that the CSP's control plane can provision and manage partitions without being able to access the cryptographic operations or data within each partition. This segmentation resolves the contradiction by enabling CSP management capabilities while ensuring organizational control over access to secure resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A partition owner authentication certificate (POAC) and partition owner trust anchor certificate (POTAC) system acts as an intermediary between the CSP and the organization's secure resources. The certificates establish a trust relationship where the CSP can provision partitions but cannot access the private keys or cryptographic operations. The intermediary certificate mechanism enables the CSP to manage partition provisioning while preventing unauthorized access to secure resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If the CSP manages the HSM, then provisioning and management is simplified, but regulatory compliance requirements cannot be met due to lack of organizational control

Engineering Contradiction:
Improveprovisioning simplicityVSAvoidregulatory compliance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The HSM partitioning mechanism separates management functions from cryptographic operations. The CSP retains simplified provisioning and management capabilities through the control plane, while each organizational partition maintains independent cryptographic control. This segmentation allows the CSP to provide easy provisioning without compromising the regulatory compliance needed for organizational control over secure resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each organizational partition operates with autonomous cryptographic control through its own private keys and authentication certificates. The partition can independently manage its own cryptographic operations and access control without requiring CSP intervention. This self-service capability enables regulatory compliance while the CSP maintains simplified provisioning through automated certificate management.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the CSP has access to secure resources, then management and monitoring is easier, but trust is compromised as the CSP can observe and access stored information

Engineering Contradiction:
Improvemanagement capabilityVSAvoidtrust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the HSM into isolated partitions where the CSP's control plane can manage partition provisioning but cannot access cryptographic operations or stored data. This segmentation enables the CSP to maintain management capabilities through automated certificate management while building trust by preventing observation or access to organizational secure resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The POAC and POTAC certificate system serves as an intermediary that enables CSP management functions while preventing direct access to secure resources. The certificates create a trust boundary where the CSP can perform provisioning and management tasks but cannot observe or access the actual cryptographic operations or stored information, thereby maintaining both ease of operation and trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12526160B2KMS dedicated HSM design (claiming ownership)
Publication Date: 2026.01.13 ORACLE INT CORP
  • US12526160B2 patent drawing
  • US12526160B2 patent drawing
  • US12526160B2 patent drawing

AI summary

A method may include receiving a request for a secure partition on an HSM from a client device and provisioning the secure partition on the HSM. The method may include generating a control server and a load balancer. The method may include generating, by a certificate service, a CSR signed by the certificate service. The method may include transmitting the CSR to the client device and receiving a first certificate including the public key of the first public private key pair and a private key of a second public private key pair. The method may include receiving a second certificate generated by an external certificate authority and signed with a public key of the second public private key pair. The method may include storing the first certificate and the second certificate on the secure partition in a location such that the second is accessible by the control server.