Hardware Security Module for Distributed Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information security systems face challenges in minimizing the security boundary, overloading trusted processing assets, and requiring inflexible cryptographic operations, which hinder secure and efficient transmission of traffic and cryptographic keys.
Innovation Solution
A security architecture with a hardware-based security module integrated in a client machine, featuring separate key caches and the ability to interface external cryptographic accelerators, enables secure authentication and configuration through a secure handshake process, allowing for secure key management and revocation, as well as flexible reconfiguration of logic within the security boundary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cryptographic operations are performed using software-based processing, then flexibility and ease of configuration are improved, but processing speed and computational efficiency deteriorate
Solution Approach 1:
The system divides cryptographic processing into two segments: a hardware security module that performs computationally intensive operations at high speed, and software components that provide flexible configuration and key management. This segmentation allows each component to optimize for its specific function, resolving the contradiction between speed and flexibility.
Solution Approach 2:
A hardware security module acts as an intermediary between the untrusted host system and the cryptographic operations. It provides a trusted execution environment that performs fast cryptographic processing while being controlled by flexible software interfaces, thus bridging the gap between speed and adaptability requirements.
2Reliability
If the security boundary is expanded to include more processing logic, then security control is improved, but the trusted processing assets become overloaded
Solution Approach 1:
The invention extracts cryptographic processing functions from the general-purpose host system and places them in a dedicated hardware security module. This extraction reduces the load on trusted processing assets in the host while maintaining strong security control through the isolated hardware module with its own secure key storage and processing capabilities.
3Adaptability or versatility
If the security boundary is minimized to reduce trusted assets, then processing flexibility is improved, but security control may be weakened
Solution Approach 1:
The hardware security module serves as a trusted intermediary that can be minimally integrated into the system architecture while providing strong security controls. It handles sensitive cryptographic operations in isolation, allowing the rest of the system to remain flexible and untrusted, thus achieving both minimal security boundary and strong security control.
4Reliability
If cryptographic operations are performed with extensive validation and authentication, then security is improved, but communication overhead and processing time increase
Solution Approach 1:
The system performs authentication and validation operations in advance during key establishment and handshake phases. Once authenticated, subsequent cryptographic operations can proceed with reduced overhead since the trusted relationship is already established. The hardware security module maintains session state to avoid repeated full authentication cycles.
Data Source
AI summary
A security architecture in which a security module is integrated in a client machine, wherein the client machine includes a local host that is untrusted. The security module performs encryption and decryption algorithms, authentication, and public key processing. The security module also includes separate key caches for key encryption keys and application keys. A security module can also interface a cryptographic accelerator through an application key cache. The security module can authorize a public key and an associated key server. That public key can subsequently be used to authorize additional key servers. Any of the authorized key servers can use their public keys to authorize the public keys of additional key servers. Secure authenticated communications can then transpire between the client and any of these key servers. Such a connection is created by a secure handshake process that takes place between the client and the key server. A time value can be sent from the key server to the client, allowing for secure revocation of keys. In addition, secure configuration messages can be sent to the security module.


