Security Accelerator Emulating HSM for Scalable Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional Hardware Security Modules (HSMs) have a high price-to-performance ratio, making them difficult to scale and expensive to deploy in cloud environments, especially for cryptographic key management, which is crucial for security and compliance in regulated industries like banking and e-commerce.
Innovation Solution
The development of a security accelerator that provides a scalable, high-performance mechanism for key protection, enabling secure cryptographic processing and key management within computing devices and network systems, including network function virtualization (NFV) and 5G deployments, using a security accelerator that securely provisions and manages cryptographic keys without exposing them to cloud operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional HSM appliances are deployed for key management, then security protection is improved, but cost and scalability are worsened
Solution Approach 1:
The patent creates a virtual copy of HSM functionality through software emulation rather than requiring physical HSM hardware. The system emulates HSM operations using standard computing resources, allowing multiple virtual HSM instances to run on a single physical server. This copying approach maintains security functions while eliminating the high cost and scalability limitations of physical HSM appliances.
Solution Approach 2:
The patent replaces the mechanical/physical HSM hardware system with a software-based emulation system. Instead of using dedicated hardware modules with specialized cryptographic circuits, the system uses software running on general-purpose processors to perform cryptographic operations. This substitution maintains functional equivalence while dramatically improving scalability and reducing costs.
2Productivity
If HSM bandwidth is increased to support cloud scaling, then key management capability is improved, but cost becomes impractically expensive
Solution Approach 1:
The patent makes the HSM functionality universal by implementing it as a software service that can be instantiated multiple times on standard computing hardware. Instead of requiring dedicated HSM bandwidth for each instance, a single physical server can host multiple virtual HSM instances, each providing full key management capability. This multi-functionality approach scales productivity without proportionally increasing cost.
Solution Approach 2:
The system creates multiple copies of HSM functionality through software virtualization, allowing unlimited scalability without requiring proportional increases in physical HSM bandwidth or hardware resources. Each virtual instance is an independent copy that can be deployed on-demand, enabling cloud-scale key management at minimal cost.
3Reliability
If cryptographic keys are made invisible to cloud operators for compliance, then security is improved, but key management complexity is worsened
Solution Approach 1:
The patent introduces a virtual HSM intermediary layer between the cloud operator and the cryptographic keys. This virtual HSM acts as a mediator that provides key management functions to applications while maintaining key secrecy. The intermediary encapsulates complex key management operations, allowing cloud operators to access cryptographic services without ever seeing or accessing the actual keys, thus meeting compliance requirements while simplifying management.
Data Source
AI summary
A security accelerator device stores a first credential that is uniquely associated with the individual security accelerator device and represents a root of trust to a trusted entity. The device establishes a cryptographic trust relationship with a client entity that is based on the root of trust, the cryptographic trust relationship being represented by a second credential. The device receives and store a secret credential of the client entity, which is received via communication secured by the second credential. Further, the device executes a cryptographic computation using the secret client credential on behalf of the client entity to produce a computation result.


