Scalable PKI Key Management via HSM Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition to a smart grid poses significant technological challenges, particularly in providing secure communication and key management for millions of devices, as existing solutions struggle to scale efficiently and securely.

Innovation Solution

A scalable public-key infrastructure (PKI) system utilizing a Hardware Security Module (HSM) for encrypting and decrypting association keys, allowing concurrent processing and key management across a large network, with features like load balancing and key rollover to maintain security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional key management system is used for smart grid devices, then security can be maintained for individual devices, but the system cannot scale efficiently to millions of devices

Engineering Contradiction:
ImprovesecurityVSAvoidscaling efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments key management by creating hierarchical key structures where a small number of wrapping keys stored in HSMs manage large numbers of association keys. Each device has an association ID that maps to its keys, dividing the key management space into manageable segments that can be handled independently at scale.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces HSMs as intermediary components that mediate between the application layer and the key storage. The HSMs hold wrapping keys and perform cryptographic operations, acting as a secure intermediary that enables scalable key management without requiring every application to directly manage individual device keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple applications concurrently access key management resources, then system functionality is enhanced, but resource contention and performance degradation occur

Engineering Contradiction:
Improveconcurrent application supportVSAvoidoperations per second
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system segments cryptographic operations by creating separate HSM sessions for different applications. Each application can have its own session context with cached keys, allowing concurrent access without blocking. The association ID to key mapping is segmented into application-specific viewings, enabling parallel processing of cryptographic requests.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-caching association keys in HSM sessions when applications start or when keys are first needed. This preliminary key retrieval and caching eliminates the need for repeated key unwrapping operations during concurrent access, maintaining high performance across multiple simultaneous applications.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cryptographic keys are stored securely in HSM, then security is improved, but key retrieval and processing time increases

Engineering Contradiction:
Improvekey securityVSAvoidkey retrieval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary key retrieval by obtaining association keys from the HSM during session initialization or first-use scenarios. These keys are then cached in the application's memory or session context, so subsequent cryptographic operations can proceed without repeated HSM access, dramatically reducing retrieval time while maintaining security through the initial HSM-protected key storage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The key management system dynamically adapts its behavior based on access patterns. Frequently accessed association keys are kept in cached state longer, while less frequently used keys are maintained in encrypted storage. The system dynamically balances between keeping keys readily available (faster access) and maintaining them securely encrypted (higher security), adjusting the trade-off based on operational needs.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10764261B2System and method for enabling a scalable public-key infrastructure on a smart grid network
Publication Date: 2020.09.01 ITRON NETWORKED SOLUTIONS INC
  • US10764261B2 patent drawing
  • US10764261B2 patent drawing
  • US10764261B2 patent drawing

AI summary

A method for enabling a scalable public-key infrastructure (PKI) comprises invoking a process of receiving a message for a device, identifying an association ID for the device, retrieving encrypted association keys stored on the server for communicating with the device, the encrypted association keys encrypted using a wrapping key stored on a Hardware Security Module (HSM). The method further comprises sending the message and the encrypted association keys to the HSM, unwrapping, by the HSM, the encrypted association keys to create unwrapped association keys, cryptographically processing the message to generate a processed message, deleting the unwrapped association keys, sending the processed message to the device, and invoking, concurrently and by a second application, the process.