Hardware Security Module Pre-Processing for MLS Key Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commodity cryptographic service providers (CSPs) lack infrastructure for Multi-Level Security (MLS) compliance, failing to enforce key-usage restrictions and securely manage cryptographic services in high-assurance environments, limiting their use in MLS environments due to inadequate key-transport capabilities and lack of attribute association with raw host-visible data.

Innovation Solution

A hardware security module comprising a central processing unit and a pre-processing unit that decapsulates incoming encapsulated requests by parsing header infrastructure information, allowing for secure crypto-operations and key-usage enforcement, while maintaining binary-compatible functionality for applications unaware of MLS extensions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If commodity cryptographic service providers are used in MLS environments, then binary-compatible functionality is maintained, but key-usage restrictions cannot be securely enforced and attribute association with raw host-visible data is lacking

Engineering Contradiction:
Improvebinary-compatible functionalityVSAvoidkey-usage restriction enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the cryptographic service provider into two distinct components: a commodity CSP that handles binary-compatible cryptographic operations, and a separate MLS compliance layer that handles key-usage restriction enforcement and attribute association. This segmentation allows each component to specialize in its strength while working together to achieve both compatibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary layer is introduced between the commodity CSP and the MLS environment. This intermediary acts as a bridge that translates MLS security requirements into commands that the commodity CSP can execute, enabling key-usage restriction enforcement without compromising binary-compatible functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MLS compliance is implemented in hardware security systems, then key-usage restrictions can be enforced, but memory constraints and performance degradation occur

Engineering Contradiction:
Improvekey-usage restriction enforcementVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the complex MLS compliance logic and attribute association mechanisms from the main hardware security system into a separate software layer or co-processor. This extraction reduces the memory footprint and processing overhead within the critical path of cryptographic operations, thereby maintaining performance while still enforcing key-usage restrictions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary actions by pre-processing and validating key-usage attributes and MLS policies before cryptographic operations are executed. This preliminary validation prevents the need for complex runtime checks during cryptographic operations, thus maintaining performance while ensuring compliance.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If attribute association is added to commodity CSP inputs, then MLS rule enforcement becomes possible, but the complexity of the CSP interface increases

Engineering Contradiction:
ImproveMLS rule enforcement capabilityVSAvoidCSP interface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal attribute association mechanism that can handle multiple MLS rules and key-usage restrictions through a single, standardized interface. This universal approach allows the CSP to enforce various MLS policies without requiring separate complex interfaces for each rule type, thus reducing overall interface complexity while maintaining comprehensive enforcement capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10296765B2Multi-level security enforcement
Publication Date: 2019.05.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10296765B2 patent drawing
  • US10296765B2 patent drawing
  • US10296765B2 patent drawing

AI summary

Embodiments of the present invention may involve providing security to a computing device. The providing security to a computing device may involve performing crypto-operations. A security system may include a central processing unit and a pre-processing unit. The pre-processing unit may be configured for receiving an incoming encapsulated request, parsing header infrastructure information of the encapsulated request, decapsulating the request, and providing the decapsulated request to the central processing unit for further processing.