Security Accelerator Emulating HSM for Scalable Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Hardware Security Modules (HSMs) have a high price-to-performance ratio, making them difficult to scale and expensive to deploy in cloud environments, especially for cryptographic key management, which is crucial for security and compliance in regulated industries like banking and e-commerce.

Innovation Solution

The development of a security accelerator that provides a scalable, high-performance mechanism for key protection, enabling secure cryptographic processing and key management within computing devices and network systems, including network function virtualization (NFV) and 5G deployments, using a security accelerator that securely provisions and manages cryptographic keys without exposing them to cloud operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional HSM appliances are deployed for key management, then security protection is improved, but cost and scalability are worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoidcost and scalability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of HSM functionality through software emulation rather than requiring physical HSM hardware. The system emulates HSM operations using standard computing resources, allowing multiple virtual HSM instances to run on a single physical server. This copying approach maintains security functions while eliminating the high cost and scalability limitations of physical HSM appliances.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/physical HSM hardware system with a software-based emulation system. Instead of using dedicated hardware modules with specialized cryptographic circuits, the system uses software running on general-purpose processors to perform cryptographic operations. This substitution maintains functional equivalence while dramatically improving scalability and reducing costs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If HSM bandwidth is increased to support cloud scaling, then key management capability is improved, but cost becomes impractically expensive

Engineering Contradiction:
Improvekey management capabilityVSAvoidcost
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent makes the HSM functionality universal by implementing it as a software service that can be instantiated multiple times on standard computing hardware. Instead of requiring dedicated HSM bandwidth for each instance, a single physical server can host multiple virtual HSM instances, each providing full key management capability. This multi-functionality approach scales productivity without proportionally increasing cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates multiple copies of HSM functionality through software virtualization, allowing unlimited scalability without requiring proportional increases in physical HSM bandwidth or hardware resources. Each virtual instance is an independent copy that can be deployed on-demand, enabling cloud-scale key management at minimal cost.

Inventive Principle:
Principle #26Copying

3Reliability

If cryptographic keys are made invisible to cloud operators for compliance, then security is improved, but key management complexity is worsened

Engineering Contradiction:
Improvesecurity and complianceVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual HSM intermediary layer between the cloud operator and the cryptographic keys. This virtual HSM acts as a mediator that provides key management functions to applications while maintaining key secrecy. The intermediary encapsulates complex key management operations, allowing cloud operators to access cryptographic services without ever seeing or accessing the actual keys, thus meeting compliance requirements while simplifying management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11757647B2Key protection for computing platform
Publication Date: 2023.09.12 INTEL CORP
  • US11757647B2 patent drawing
  • US11757647B2 patent drawing
  • US11757647B2 patent drawing

AI summary

A security accelerator device stores a first credential that is uniquely associated with the individual security accelerator device and represents a root of trust to a trusted entity. The device establishes a cryptographic trust relationship with a client entity that is based on the root of trust, the cryptographic trust relationship being represented by a second credential. The device receives and store a secret credential of the client entity, which is received via communication secured by the second credential. Further, the device executes a cryptographic computation using the secret client credential on behalf of the client entity to produce a computation result.