Stateless Service-Mediated Security Module for HSM Resource Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional hardware security module (HSM) services are expensive for both customers and resource providers due to underutilization, as customers are charged for dedicated HSM devices even when they are idle, leading to inefficient resource management.
Innovation Solution
Implementing a service-based HSM model where security modules are allocated to customers on an as-needed basis, using virtual security module instances that can be loaded and unloaded as required, with cryptographic material securely stored and managed to prevent unauthorized access, allowing only actual usage to be billed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated HSM device is allocated to a customer over a period of time, then security is improved, but cost increases and resource utilization decreases
Solution Approach 1:
The patent segments the HSM resource into multiple virtual instances (HSM1, HSM2, HSM3) that can be dynamically allocated to different customers. Instead of dedicating entire physical HSM devices to single customers, the system divides the physical HSM capacity into virtual segments that can be shared across multiple customers based on demand, thereby improving resource utilization while maintaining security through virtualization isolation.
Solution Approach 2:
The patent implements dynamic allocation of HSM virtual instances to customers based on real-time demand. The system can allocate, suspend, and terminate virtual HSM instances dynamically rather than maintaining static dedicated allocations. This allows the system to adapt resource distribution to actual usage patterns, ensuring security when needed while minimizing resource waste during periods of low utilization.
2Reliability
If a dedicated HSM device is allocated to a customer, then security is improved, but cost increases
Solution Approach 1:
The patent makes a single physical HSM device serve multiple customers through virtualization, creating universal HSM instances that can be allocated to different customers as needed. The virtual HSM instances provide customer-specific security functionality while sharing the underlying physical infrastructure, thereby reducing the total number of physical HSM devices required and lowering overall costs while maintaining security standards.
Solution Approach 2:
The patent combines multiple customer workloads onto shared physical HSM infrastructure through virtualization. By merging the resource requirements of multiple customers into a unified virtualized platform, the system achieves economies of scale, reducing per-customer costs while maintaining security through virtual isolation boundaries that prevent unauthorized access between customers.
3Reliability
If HSM devices are allocated to customers even when idle, then security is maintained, but resource waste increases
Solution Approach 1:
The patent implements periodic allocation and suspension of HSM virtual instances based on customer demand cycles. Instead of continuously allocating HSM resources to customers regardless of usage, the system periodically assesses whether virtual HSM instances should be active or suspended, allocating resources only during periods when security operations are actually needed. This periodic activation approach maintains security when required while eliminating resource waste during idle periods.
Solution Approach 2:
The patent dynamically adjusts the allocation state of virtual HSM instances based on real-time monitoring of customer needs. The system can transition virtual instances between active and suspended states dynamically, ensuring that HSM resources are consumed only when security operations are actually being performed. This dynamic state management eliminates the resource waste associated with continuously allocated but idle HSM devices while maintaining security readiness when needed.
Data Source
AI summary
Secure operations can be performed using security module instances offered as a web service through a resource provider environment. State data and cryptographic material can be loaded and unloaded from the instance as needed, such that the instance can be reused for operations of different customers. The material and data can be stored as a bundle encrypted using a key specific to the hardware security module and a key specific to the resource provider, such that the bundle can only be decrypted in an instance of that type of security module from the associated manufacturer and operated by that particular resource provider. The customer is then only responsible for the allocation of that instance during the respective cryptographic operation(s).


