US20150358161A1

Systems and methods for secured backup of hardware security modules for cloud-based web services

Claim Score by NHIP

Read claim 20, the broadest

Abstract

A new approach is proposed to support secured hardware security module (HSM) backup for a plurality of web services hosted in a cloud to offload their key storage, management, and crypto operations to the HSM. Each HSM is a high-performance, FIPS 140-compliant security solution for crypto acceleration of the web services. Each HSM includes multiple partitions isolated from each other, where each HSM partition is dedicated to support one of the web service hosts/servers to offload its crypto operations via a HSM virtual machine (VM) over the network. The HSM-VM is configured to export objects from the key store of a first HSM partition to a key store of a second HSM partition, wherein the second HSM partition is configured to serve the key management and crypto operations offloaded from the web service host once the objects exported from the key store of the first HSM partition are received.

US20150358161A1, drawing sheet 1
Sheet 1 of 11

Term

8.7 yearsto projected expiry

Projected expiry 28 May 2035, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

31 claims: 2 independent, 29 dependent

  1. 1
    A system for secured hardware security module (HSM) backup for cloud-based web services, comprising:a plurality of HSM service units, wherein each of the HSM service units further comprises: a first HSM partition on an HSM adapter, wherein the first HSM partition is configured to: store a plurality of types of objects for key management and crypto operations offloaded from a web service host in a key store of the first HSM partition in an isolated and tamper proof environment on the HSM adapter;perform the crypto operations offloaded from the web service host using the stored objects of the web service host;an HSM virtual machine (VM) running on a host, which in operation, is configured to: offload the key management and crypto operations from the web service host to the HSM partition;export a plurality of objects from the key store of the first HSM partition to a key store of a second HSM partition, wherein the second HSM partition is configured to serve the key management and crypto operations offloaded from the web service host once the objects exported from the key store of the first HSM partition are received.
  2. 20
    Broadest claimClaim Score 49, average(NHIP)A method for secured hardware security module (HSM) communication for cloud-based web services, comprising:storing a plurality of types of objects for key management and crypto operations offloaded from a web service host in a key store of a first HSM partition in an isolated and tamper proof environment on an HSM adapter;offloading the key management and crypto operations from the web service host to the first HSM partition;performing the crypto operations offloaded from the web service host using the stored objects of the web service host;exporting a plurality of objects from the key store of the first HSM partition to a key store of a second HSM partition, wherein the second HSM partition is configured to serve the key management and crypto operations offloaded from the web service host once the objects exported from the key store of the first HSM partition are received.