HSM Signature Enforcement via Token Augmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware security modules (HSMs) face challenges in maintaining the security of private tokens while requiring multiple approvals for electronic object signatures, as existing solutions either compromise security by allowing access to private tokens or expose the HSM to potential attacks through entity-written code or administrator login.

Innovation Solution

An HSM that maintains public key/private token pairs for entities, applies entity signatures based on predefined requirements without installing entity code or requiring administrator login, by augmenting private tokens with public keys of approving entities and recording approvals to apply signatures once conditions are met, including quorum, timing, and veto functionalities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrator login is required to apply entity signatures, then signature control is achieved, but security is compromised and operational complexity increases

Engineering Contradiction:
Improvesignature application processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The HSM automatically monitors approval conditions and applies signatures without administrator intervention. The system self-manages the signature application process by detecting when approval conditions are met and autonomously executing the signature, eliminating the need for administrator login while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Approval conditions are pre-configured in the HSM before signature events occur. The system pre-establishes the rules and conditions that must be met for signature application, allowing automated enforcement without real-time administrator intervention.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If entity-written code is installed on HSM to manage approvals, then signature requirements can be enforced, but HSM security is compromised to attacks

Engineering Contradiction:
Improvesignature requirement enforcementVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary approval mechanism where the HSM acts as a trusted mediator between entities. Instead of installing entity code on the HSM, the system uses a standardized approval interface where entities submit approval requests that the HSM validates against pre-configured conditions, eliminating security risks from custom code while maintaining enforcement capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If private token access is permitted for signature application, then signature functionality is achieved, but security is compromised

Engineering Contradiction:
Improvesignature applicationVSAvoidprivate token security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The HSM automatically detects when approval conditions are met and self-executes the signature application using the private token without external access requests. This self-service mechanism eliminates the security risk of private token exposure while maintaining signature functionality.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures approval conditions and authorization rules within the HSM before signature events occur. This preliminary setup allows the HSM to autonomously enforce security policies and apply signatures only when pre-defined conditions are satisfied, without requiring external access to the private token.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12184787B2Hardware security module that enforces signature requirements
Publication Date: 2024.12.31 SECUROSYS SA
  • US12184787B2 patent drawing
  • US12184787B2 patent drawing
  • US12184787B2 patent drawing

AI summary

In an embodiment, an HSM may provide a cryptographic signature service. The HSM may maintain key/token pairs for various users/entities and for a first entity for which signature may be desired. The HSM may ensure that the requirements for the entity's signature are met, and then may apply the entity's signature. In an embodiment, the HSM may augment the private token for the first entity with the public keys of users/entities which are to approve the entity's signature. As the approvals are received, the HSM may record the approvals and may apply the signature once the approvals are received.