Invention Grant
- Patent Title: Synchronizable hardware security module
-
Application No.: US16428840Application Date: 2019-05-31
-
Publication No.: US10887294B2Publication Date: 2021-01-05
- Inventor: Benjamin Philip Grubin , Benjamin Samuel
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Davis Wright Tremaine LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/08 ; H04L9/16 ; H04L9/12 ; H04L9/30 ; H04L9/32

Abstract:
A set of cryptographic keys are synchronized across a set of HSMs that are configured in an HSM cluster. The set of cryptographic keys is maintained in a synchronized state by HSM cluster clients running on client computer systems with corresponding client applications. If the HSM cluster becomes unsynchronized, an HSM cluster client attempts to lock the HSM cluster and reestablish synchronization of the cryptographic keys across the HSM cluster. HSMs within the HSM cluster are able to establish an encrypted communication channel to other HSMs without revealing the contents of their communications to their respective host computer systems. Individual HSMs in the HSM cluster may include features that assist the HSM cluster client in determining whether each HSM is up-to-date, identifying particular keys that are not up-to-date, and copying keys from one HSM to another HSM within the HSM cluster.
Public/Granted literature
- US20190305951A1 SYNCHRONIZABLE HARDWARE SECURITY MODULE Public/Granted day:2019-10-03
Information query