Protected Cryptographic Environment Using Bastion and HSM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The physical separation of sensitive cryptographic keys stored on hardware security modules (HSMs) in offline environments creates cumbersome and expensive key retrieval and assembly processes for cryptographic operations, making them time-consuming and inefficient.
Innovation Solution
A protected network environment is created using a bastion computer system and HSM, where sensitive cryptographic keys are encrypted with multiple keys, including an HSM key, a service provider key, and an administrative key, allowing secure access and use within an isolated network for cryptographic operations without physical key assembly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive cryptographic keys are physically separated and stored in offline environments, then security is improved, but operational efficiency and accessibility deteriorate
Solution Approach 1:
The cryptographic key is segmented into multiple parts and distributed across different HSMs in separate physical locations. This segmentation maintains security through physical separation while enabling operational efficiency through automated key assembly processes that combine key parts programmatically when needed for cryptographic operations.
Solution Approach 2:
A key assembly system acts as an intermediary between the physically separated HSMs and the cryptographic operation requests. This intermediary automatically retrieves key parts from distributed HSMs, assembles them in controlled environments, and facilitates cryptographic operations without requiring manual physical retrieval and assembly ceremonies.
2Reliability
If cryptographic keys are stored on distributed HSMs in secure physical locations, then security is improved, but operational complexity and cost increase
Solution Approach 1:
The key assembly system operates autonomously to retrieve key parts from distributed HSMs and assemble them automatically. This self-service capability eliminates the need for manual key assembly ceremonies, reducing operational complexity and costs while maintaining the security benefits of distributed key storage.
Solution Approach 2:
Key parts are pre-distributed to multiple HSMs in secure locations before they are needed for cryptographic operations. This preliminary distribution maintains security while enabling rapid key assembly when operations are required, reducing operational complexity by having key parts readily available in predetermined locations.
3Reliability
If manual key assembly ceremonies are conducted to use cryptographic keys, then security control is maintained, but time consumption and expense increase
Solution Approach 1:
The manual mechanical process of key assembly ceremonies is replaced with an automated computational system. The key assembly system programmatically retrieves key parts from HSMs and assembles them electronically, maintaining security control through controlled access mechanisms while dramatically reducing time consumption and eliminating the need for physical presence of key administrators.
Solution Approach 2:
The system performs preliminary setup by distributing key parts to HSMs and establishing automated assembly protocols in advance. This preliminary action enables rapid key assembly operations without requiring time-consuming manual ceremonies, while security control is maintained through pre-configured access controls and authentication mechanisms.
Data Source
AI summary
A secret cryptographic key is stored in a protected state. While in the protected state, the secret cryptographic key is encrypted with a plurality of cryptographic keys, each of which is used to re-create the plaintext version of the secret cryptographic key. A service operated by an online service provider creates an isolated network environment containing a bastion computer system in communication with an HSM. After establishing the isolated network environment, the online service provider provides a service provider key to the HSM. An HSM key is present on the HSM, and an administrator key is provided by one or more key administrators. Using the HSM key, the service provider key, and the administrator key, the HSM performs cryptographic operations using the secret cryptographic key. When complete, the isolated network environment is deconstructed and the secret cryptographic key is returned to online storage in a protected state.


