Virtualized Hardware Security Module for Isolated Cryptographic Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The need for separate HSMs for general and special applications leads to inefficiency and increased costs due to the inability to service different types of cryptographic operations with a single physical HSM.

Innovation Solution

A single physical HSM is virtualized into multiple logically partitioned instances, allowing each instance to handle either general or special cryptographic operations, eliminating the need for separate HSMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate physical HSMs are used for general and special applications, then security requirements for different applications are met, but cost and device complexity increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidnumber of HSM devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides a single physical HSM into multiple virtual instances, each instance being logically segmented to handle specific application types (general or special applications). This segmentation allows different security policies and cryptographic operations to be isolated within the same physical device, meeting security requirements without needing multiple physical HSMs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal HSM platform that can serve multiple purposes through virtualization. A single physical HSM device can simultaneously service both general applications (e.g., encryption/decryption) and special applications (e.g., payment operations) by creating different virtual instances, making the device multi-functional and eliminating the need for separate dedicated HSMs for each application type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate physical HSMs are used for general and special applications, then application-specific security requirements are satisfied, but cost increases

Engineering Contradiction:
Improveapplication-specific securityVSAvoidnumber of HSM devices
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple HSM functions into a single physical device through virtualization. By combining general-purpose cryptographic operations and special-purpose cryptographic operations into one physical HSM with multiple virtual instances, the system reduces the quantity of HSM devices from multiple separate units to a single consolidated device, thereby reducing cost while maintaining application-specific security.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple physical HSMs are deployed for different applications, then security isolation is achieved, but resource utilization efficiency decreases

Engineering Contradiction:
Improvesecurity isolationVSAvoidHSM utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the HSM resource pool into multiple virtual instances that provide security isolation similar to physical separation. Each virtual instance can be configured with specific security policies and cryptographic algorithms appropriate for its intended application type, achieving security isolation through virtual boundaries rather than physical separation, thereby improving resource utilization efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250225510A1Virtualized hardware security module
Publication Date: 2025.07.10 MARVELL ASIA PTE LTD
  • US20250225510A1 patent drawing
  • US20250225510A1 patent drawing
  • US20250225510A1 patent drawing

AI summary

A hardware security module (HSM) includes a first HSM instance and a second HSM instance. The first HSM instance is configured to process a first type of service request. The second HSM instance is configured to process a second type of service request. The first HSM instance and the second HSM instance are physically on a same HSM. The first HSM instance is logically separated from the second HSM instance. The first type of service request is a service request that differs from the second type of service request.