Virtualized Hardware Security Module for Isolated Cryptographic Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The need for separate HSMs for general and special applications leads to inefficiency and increased costs due to the inability to service different types of cryptographic operations with a single physical HSM.
Innovation Solution
A single physical HSM is virtualized into multiple logically partitioned instances, allowing each instance to handle either general or special cryptographic operations, eliminating the need for separate HSMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate physical HSMs are used for general and special applications, then security requirements for different applications are met, but cost and device complexity increase
Solution Approach 1:
The patent divides a single physical HSM into multiple virtual instances, each instance being logically segmented to handle specific application types (general or special applications). This segmentation allows different security policies and cryptographic operations to be isolated within the same physical device, meeting security requirements without needing multiple physical HSMs.
Solution Approach 2:
The patent creates a universal HSM platform that can serve multiple purposes through virtualization. A single physical HSM device can simultaneously service both general applications (e.g., encryption/decryption) and special applications (e.g., payment operations) by creating different virtual instances, making the device multi-functional and eliminating the need for separate dedicated HSMs for each application type.
2Reliability
If separate physical HSMs are used for general and special applications, then application-specific security requirements are satisfied, but cost increases
Solution Approach 1:
The patent merges multiple HSM functions into a single physical device through virtualization. By combining general-purpose cryptographic operations and special-purpose cryptographic operations into one physical HSM with multiple virtual instances, the system reduces the quantity of HSM devices from multiple separate units to a single consolidated device, thereby reducing cost while maintaining application-specific security.
3Reliability
If multiple physical HSMs are deployed for different applications, then security isolation is achieved, but resource utilization efficiency decreases
Solution Approach 1:
The patent segments the HSM resource pool into multiple virtual instances that provide security isolation similar to physical separation. Each virtual instance can be configured with specific security policies and cryptographic algorithms appropriate for its intended application type, achieving security isolation through virtual boundaries rather than physical separation, thereby improving resource utilization efficiency.
Data Source
AI summary
A hardware security module (HSM) includes a first HSM instance and a second HSM instance. The first HSM instance is configured to process a first type of service request. The second HSM instance is configured to process a second type of service request. The first HSM instance and the second HSM instance are physically on a same HSM. The first HSM instance is logically separated from the second HSM instance. The first type of service request is a service request that differs from the second type of service request.


