Virtual Hardware Security Module Emulation in Processor Cache

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Hardware Security Modules (HSMs) are expensive, limited in availability, and often dedicated to specific virtual machines, making it difficult to provide sufficient security for multiple virtual machines, while also being physically and logically protected from unauthorized access.

Innovation Solution

A software-based security module that emulates a virtual hardware security module, allowing for secure storage and management of secret data using a processor with multiple cache levels, enabling secure mode switching, data encryption, and access control through an interface, which can be programmed and deployed on remote systems without relying on system administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical hardware security modules are used, then security protection is provided, but cost and availability are limited

Engineering Contradiction:
Improvesecurity protectionVSAvoidavailability for multiple virtual machines
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtual copy of the hardware security module functionality through software implementation. The virtual HSM emulates the cryptographic operations and security functions of physical HSMs in a software environment, allowing multiple virtual machines to access security services without requiring separate physical devices for each. This copying approach maintains security functionality while dramatically improving availability and scalability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual HSM is designed to serve multiple virtual machines simultaneously, providing universal security services across different domains. A single virtual HSM instance can handle cryptographic operations for numerous VMs, making the security infrastructure universal rather than dedicated to a single machine or function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If hardware security modules are dedicated to specific virtual machines, then security is maintained, but resource utilization is inefficient

Engineering Contradiction:
ImprovesecurityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the security functions that would traditionally be distributed across multiple dedicated physical HSMs into a single consolidated virtual HSM. This consolidation allows multiple virtual machines to share the same security infrastructure, improving resource utilization while maintaining security through virtualization-based isolation and controlled access mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If software-based security module is used, then cost and flexibility are improved, but security protection against unauthorized access must be ensured

Engineering Contradiction:
ImproveflexibilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The virtual HSM acts as an intermediary layer between virtual machines and the underlying system resources. It provides controlled access to cryptographic operations and sensitive data, mediating all security-related requests through a standardized interface. This intermediary position allows the system to maintain flexibility while enforcing security policies and preventing unauthorized access through centralized control and authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11204881B2Computer system software/firmware and a processor unit with a security module
Publication Date: 2021.12.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11204881B2 patent drawing
  • US11204881B2 patent drawing
  • US11204881B2 patent drawing

AI summary

Technology for decrypting and using a security module in a processor cache in a secure mode such that dynamic address translation prevents access to portions of the volatile memory outside of a secret store in a volatile memory.