IP Library Granted Patent US 11,321,493
Granted Patent B2
US 11,321,493 · App. 16/697,772 · Granted May 3, 2022

Hardware security module, and trusted hardware network interconnection device and resources

Inventors: Bruno Couillard (Gatineau, CA); Bradley Clare Ritchie (Kemptville, CA); James Ross Goodman (Ottawa, CA); Jean-Pierre Fiset (Ottawa, CA)
Assignee: CRYPTO4A TECHNOLOGIES INC.
G06F21/72G06F21/76G06F21/78G06F21/85G06F21/87H04L9/0897
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,321,493
App. No.
16/697,772
Granted
May 3, 2022
Kind
B2
Abstract

Described are various embodiments of a hardware security module, hardwired port interconnection matrix, and embedded communication channel resources operable on selected hardware port-specific data communicated via this matrix.

Claims (28)

1. A hardware security module comprising:

two or more hardware ports, each one of which operable to electronically receive given input hardware port-specific cryptographic data thereon to initiate execution of an internal cryptographic process as a function thereof;

two or more segregated hardware port-specific storage spaces, each physically isolated in hardware from any other of said hardware port-specific storage spaces, operatively linked to a corresponding hardware port via a corresponding hardware link, and storing respective secured hardware port-specific cryptographic data thereon exclusively retrievable upon said given input hardware port-specific cryptographic data corresponding thereto and being received via said corresponding hardware port such that said respective secured hardware port-specific cryptographic data is inaccessible in hardware upon said given input hardware port-specific data being received via a distinct hardware port; and

a cryptographic engine operable to execute said cryptographic process based on said secured port-specific cryptographic data retrieved from said segregated hardware port-specific storage spaces as a function of said given input port-specific cryptographic data;

wherein a given segregated hardware port-specific storage space is exclusively accessible in hardware, independent of said given input hardware port-specific cryptographic data, via said corresponding hardware link.

2. The hardware security module of claim 1 , wherein the hardware security module further comprises a hardwired port interconnection matrix that operatively interconnects at least two of said hardware ports in accordance with predefined hardwired port-specific logic, wherein said interconnection matrix is reconfigurable to redefine said hardwired port-specific logic.

3. The hardware security module of claim 1 , wherein at least one said hardware link invokes an embedded communication channel resource operable on selected hardware port-specific data communicated therethrough, wherein said communication channel resource comprises at least one of an inline channel cryptographic resource, a data channel diode resource, a data channel filter resource, a data channel comparator resource, a trusted metering function, a trusted flow control function, a trusted function expander, a trusted controllable event counter, or a data channel sniffer resource.

4. The hardware security module of claim 1 , wherein at least one said hardware link invokes a trusted metering function operable on hardware port-specific data communicated therethrough, wherein said trusted metering function is operable to track transactions communicated on a given hardware channel and output cryptographically authenticated metering messages accordingly.

5. The hardware security module of claim 1 , wherein at least one said hardware link invokes a trusted flow control function, wherein said trusted flow control function applies cryptographically authenticated flow control restrictions on transactions communicated on a given hardware channel.

6. The hardware security module of claim 1 , wherein at least one said hardware link invokes a trusted function expander, wherein a data transaction relayed or triggered on a given input hardware channel is securely distributed and synchronized across multiple output hardware channels.

7. The hardware security module of claim 1 , wherein at least one said hardware link invokes a trusted controllable event counter.

8. The hardware security module of claim 7 , wherein said trusted controllable event counter applies cryptographically authenticated control over a designated event counting threshold thereof such that a trigger invoked upon reaching said threshold is securely adjustable.

9. The hardware security module of claim 8 , wherein said trusted controllable event counter is operatively associated with an onboard clock frequency signal to securely adjust output timing data associated therewith.

10. The hardware security module of claim 1 , wherein each said segregated hardware port-specific storage space is physically isolated in hardware from any other said segregated hardware port-specific storage space.

11. The hardware security module of claim 1 , wherein said cryptographic engine comprises distinct hardware port-specific cryptographic engines or a same said cryptographic engine that is commonly operable to execute a same said cryptographic process for each of said secured port-specific cryptographic data irrespective of hardware port-specificity.

12. The hardware security module of claim 1 , wherein each of said segregated hardware port-specific storage spaces comprises distinct partitions of a common embedded storage media each operatively hardwired to said corresponding one of said hardware ports.

13. The hardware security module of claim 1 , wherein each said segregated hardware port-specific storage space comprises distinctly embedded storage media operatively hardwired to said corresponding one of said hardware ports.

14. A hardware security module comprising:

two or more hardware ports, each one of which operable to electronically receive given input hardware port-specific cryptographic data thereon to initiate execution of an internal cryptographic process as a function thereof;

two or more segregated hardware port-specific storage spaces, each operatively linked to a corresponding hardware port via a corresponding hardware link, and storing respective secured hardware port-specific cryptographic data thereon exclusively retrievable upon said given input hardware port-specific cryptographic data corresponding thereto and being received via said corresponding hardware port;

a cryptographic engine operable to execute said cryptographic process based on said secured port-specific cryptographic data retrieved from said segregated hardware port-specific storage spaces as a function of said given input port-specific cryptographic data; and

a hardwired port interconnection matrix that operatively interconnects at least two some of said hardware ports in accordance with predefined hardwired port-specific logic and invokes an embedded communication channel resource operable on selected hardware port-specific data communicated via said matrix;

wherein a given segregated hardware port-specific storage space is exclusively accessible in hardware, independent of said given input hardware port-specific cryptographic data, via said corresponding hardware link.

15. The hardware security module of claim 14 , wherein said communication channel resource comprises a trusted metering function that tracks transactions communicated on a given hardware channel and outputs cryptographically authenticated metering messages accordingly.

16. The hardware security module of claim 15 , wherein said transactions comprise at least one of data transactions, event transactions or request transactions.

17. The hardware security module of claim 14 , wherein said communication channel resource comprises a trusted flow control function that applies cryptographically authenticated flow control restrictions on transactions communicated on a given hardware channel.

18. The hardware security module of claim 14 , wherein said communication channel resource comprises a trusted function expander, wherein a data transaction relayed or triggered on a given input hardware channel is securely distributed and synchronized across multiple output hardware channels.

19. The hardware security module of claim 14 , wherein said communication channel resource comprises a trusted controllable event counter that applies cryptographically authenticated control over a designated event counting threshold thereof such that a trigger invoked upon reaching said threshold is securely adjustable.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2021
From: COUILLARD, BRUNO; RITCHIE, BRADLEY CLARE; GOODMAN, JAMES ROSS; FISET, JEAN-PIERRE
To: CRYPTO4A TECHNOLOGIES INC.
Reel/Frame 055249/0765 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2020
From: COUILLARD, BRUNO; RITCHIE, BRADLEY CLARE; GOODMAN, JAMES ROSS; FISET, JEAN-PIERRE
To: CRYPTO4A TECHNOLOGIES INC.
Reel/Frame 051786/0980 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2020
From: COUILLARD, BRUNO; RITCHIE, BRADLEY CLARE; GOODMAN, JAMES ROSS; FISET, JEAN-PIERRE
To: CRYPTO4A TECHNOLOGIES INC.
Reel/Frame 051787/0033 →
Continuity (5)
Continuation In Part PCTCA2018050630 · May 30, 2018
Provisional Application 62772901 · Nov 29, 2018
Provisional Application 62513103 · May 31, 2017
Provisional Application 62532138 · Jul 13, 2017
Related Publication 20200097682A1 · Mar 26, 2020