PSMCU Processor Key Segmentation for HSM Mode Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hardware security modules (HSMs) face challenges in seamlessly switching between PCI-HSM and non-PCI-HSM modes without requiring new hardware, as existing solutions lack flexible key management and access control mechanisms to ensure compliance and security.
Innovation Solution
The implementation of a Physical Security Monitoring Control Unit (PSMCU) processor within a security enclosure that stores and controls access to cryptographic keys, allowing operation in either PCI-HSM or non-PCI-HSM modes by granting access to top-level keys based on the mode, ensuring secure key management and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single HSM is used to operate in multiple modes (PCI-HSM and non-PCI-HSM), then hardware cost is reduced and device versatility is improved, but key management complexity and security control difficulty increase
Solution Approach 1:
The patent segments cryptographic keys into two distinct categories: first cryptographic keys for PCI-HSM mode and second cryptographic keys for non-PCI-HSM mode. The PSMCU processor maintains separate access control for each key set, allowing the single HSM to operate in multiple modes while managing key complexity through systematic division and isolation of cryptographic materials.
2Reliability
If access to cryptographic keys is restricted based on operation mode, then security is improved and compliance is achieved, but operational flexibility and ease of operation are reduced
Solution Approach 1:
The PSMCU processor dynamically adjusts key access permissions based on the current operation mode. When operating in PCI-HSM mode, the PSMCU grants access only to first cryptographic keys and restricts access to second cryptographic keys. When in non-PCI-HSM mode, the access permissions are dynamically reversed. This dynamic adaptation maintains security while enabling operational flexibility without requiring physical hardware changes.
Solution Approach 2:
The PSMCU processor acts as an intermediary between the application and the cryptographic keys. It receives mode indication from the application, determines the appropriate key set for access, and mediates the key retrieval process. This intermediary layer enforces security policies and mode-specific access controls while presenting a unified interface to the application, maintaining both security and ease of operation.
3Reliability
If separate cryptographic keys are maintained for different modes, then compliance with PCI-HSM regulations is achieved and security is improved, but device complexity and key management overhead increase
Solution Approach 1:
The patent implements a universal key management architecture where the PSMCU processor handles multiple cryptographic key sets within a single device. The PSMCU provides multi-functional key management capabilities: storing first cryptographic keys for PCI-HSM mode, storing second cryptographic keys for non-PCI-HSM mode, and dynamically switching between them based on operation mode. This universal approach achieves compliance while consolidating key management functions in a single processor rather than requiring separate hardware for each mode.
Data Source
AI summary
According to examples, an apparatus may include a security enclosure, a main processor housed in the security enclosure, and a physical security monitoring control unit (PSMCU) processor housed in the security enclosure. The PSMCU processor may cause the apparatus to switchably operate between a first mode and a second mode. In the first mode, the PSMCU processor may allow access by the main processor to a first cryptographic key while preventing access by the main processor to a second cryptographic key. In addition, in the second mode, the PSMCU processor may allow access by the main processor to the second cryptographic key while preventing access by the main processor to the first cryptographic key.


