IP Library › Granted Patent US 12,634,126
Granted Patent B1
US 12,634,126 · App. 18/193,089 · Granted May 19, 2026

Discovery and attestation of hardware security modules

Inventors: SengMing Yeoh (Arlington, VA); Graeme Farquharson (Sammamish, WA)
Assignee: Amazon Technologies, Inc.
H04L9/0877H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,126
App. No.
18/193,089
Granted
May 19, 2026
Kind
B1
Abstract

Approaches presented herein relate to the providing of cryptographic-related functionality using shared computing resources. A fleet of hardware security modules (HSMs) can be similarly configured such that requests to perform cryptography-related tasks can be routed to any of the HSMs in the fleet. Additional HSMs can be connected, and those HSMs can be automatically discovered and authenticated, such as by requesting responses to challenge questions along with identifying information such as an expected serial number. Once a server can attest to the HSM as a trusted resource, a provisioning workflow can be initiated to configure the HSM and provide the appropriate keys so the HSM can be routed requests as part of the fleet. Multiple users may then have requests processed by the fleet as part of a security-related service offering.

Claims (47)

1 . A computer-implemented method, comprising:

providing a plurality of hardware security modules to perform a set of cryptographic tasks as part of a secure data processing service, the secure data processing service provided using a network of computing resources;

receiving a discover packet from an additional hardware security module connected to the network of computing resources;

transmitting, in response to receiving the discover packet, a request to the additional hardware security module for attestation information;

receiving, in response to the request and from the additional hardware security module, the attestation information, the attestation information including at least a predetermined identifier and a challenge question response;

determining that the attestation information includes expected values for the predetermined identifier and the challenge question response;

initiating a provisioning workflow for the secure data processing service, the provisioning workflow including configuring the additional hardware security module to satisfy one or more requirements for the set of cryptographic tasks and providing one or more master keys to the additional hardware security module;

assigning a communication address to each of a pair of communication ports of the additional hardware security module; and

providing additional hardware security module as available to perform the set of cryptography tasks using the one or more master keys as part of the secure data processing service, wherein a subsequent request to perform one of the cryptographic tasks is allowed to be routed to either communication address of the additional hardware security module or another hardware security module of the plurality of hardware security modules.

2 . The computer-implemented method of claim 1 , wherein the set of cryptographic tasks relate to electronic payments, and wherein the one or more requirements for the set of cryptographic tasks correspond to requirements for performing tasks relating to the electronic payments.

3 . The computer-implemented method of claim 1 , wherein the attestation information further includes a timestamp, and wherein determining that the attestation information includes expected values includes determining that the timestamp is in a time window between when the request for the attestation information was sent and a time when the response with the attestation information was received.

4 . The computer-implemented method of claim 1 , wherein the communication addresses are Internet protocol (IP) addresses assigned by a dynamic host configuration protocol (DHCP) server of the secure data processing service.

5 . The computer-implemented method of claim 4 , wherein the pair of communication ports are connected to the DHCP server using at least two switches and at least two communication channels, and wherein the DHCP server is allowed to re-route the subsequent request using any of the pair of communication ports, the at least two switches, and the at least two communication channels.

6 . A computer-implemented method, comprising:

receiving a discover packet from secure hardware device connected to a set of hardware resources;

transmitting, in response to receiving the discover packet, a request to the secure hardware device for attestation information;

receiving, in response to the request and from the secure hardware device, the attestation information, including at least a predetermined identifier of the secure hardware device and a challenge question response generated by the secure hardware device in response to the request;

determining that the attestation information includes one or more expected attestation values corresponding to the predetermined identifier and the challenge question response;

assigning at least one communication address to the secure hardware device; and

provisioning the secure hardware device to receive, using the at least one communication address, requests to perform cryptography-related tasks as part of the set of hardware resources.

7 . The computer-implemented method of claim 6 , further comprising:

initiating, in response to determining that the attestation information includes one or more expected attestation values, a provisioning workflow for the secure hardware device, the provisioning workflow including configuring the secure hardware device to satisfy one or more requirements for the cryptography-related tasks and providing one or more master keys to the secure hardware device.

8 . The computer-implemented method of claim 7 , wherein the cryptography-related tasks including at least encrypting, decrypting, or authenticating data using one or more of the master keys scored to the secure hardware device.

9 . The computer-implemented method of claim 6 , wherein the secure hardware device is a hardware security module (HSM).

10 . The computer-implemented method of claim 9 , further comprising:

adding the HSM to an existing fleet of HSMs, wherein requests to perform the cryptography-related tasks are allowed to be directed to any of the HSMs in the fleet.

11 . The computer-implemented method of claim 10 , wherein

the fleet of HSMs is provided to perform the cryptography-related tasks as part of a security-related service provided using a set of shared resources.

12 . The computer-implemented method of claim 6 , wherein the attestation information includes at least one of an expected serial number of the secure hardware device, a challenge question response, or a timestamp within an expected time window.

13 . The computer-implemented method of claim 6 , wherein the at least one communication address is assigned using a dynamic host configuration protocol (DHCP) server.

14 . The computer-implemented method of claim 6 , wherein a load balancer is allowed to balance incoming requests across one or more DHCP servers, a number of the one or more DHCP servers allowed to scale over time.

15 . The computer-implemented method of claim 6 , wherein the secure hardware device includes two communication ports, and wherein a communication address is automatically assigned to each of the two communication ports of the secure hardware device after determining that the attestation information includes one or more expected attestation values.

16 . A system, comprising:

a processor; and

memory including instructions that, when executed by the processor, cause the system to:

receive a discover packet from a secure hardware device connected to a set of hardware resources;

transmit, in response to receiving the discover packet, a request to the secure hardware device for attestation information;

receive, in response to the request and from the secure hardware device, the attestation information, including at least a predetermined identifier of the secure hardware device and a challenge question response generated by the secure hardware device in response to the request;

determine that the attestation information includes one or more expected attestation values corresponding to the predetermined identifier and the challenge question response;

assign at least one communication address to the secure hardware device; and

provision the secure hardware device to receive, using the at least one communication address, requests to perform cryptography-related tasks as part of the set of hardware resources.

17 . The system of claim 16 , wherein the instructions when executed further cause the system to:

initiate, in response to determining that the attestation information includes one or more expected attestation values, a provisioning workflow for the secure hardware device, the provisioning workflow including configuring the secure hardware device to satisfy one or more requirements for the cryptography-related tasks and providing one or more master keys to the secure hardware device.

18 . The system of claim 16 , wherein the secure hardware device is a hardware security module (HSM), and wherein the instructions when executed further cause the system to:

adding the HSM to an existing fleet of HSMs, wherein requests to perform the cryptography-related tasks are allowed to be directed to any of the HSMs in the fleet.

19 . The system of claim 18 , wherein the fleet of HSMs is provided to perform the cryptography-related tasks as part of a security-related service provided using a set of shared resources.

20 . The system of claim 16 , wherein the attestation information includes at least one of an expected serial number of the secure hardware device, a challenge question response, or a timestamp within an expected time window.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2024
From: YEOH, SENGMING; FARQUHARSON, GRAEME
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 067369/0085 →
References Cited (111)
US 8544092B2 · Hermann · 2013 [cited by examiner]
US 8572368B1 · Deacon · 2013 [cited by examiner]
US 9135444B2 · Carter · 2015 [cited by examiner]
US 9438421B1 · Roth · 2016 [cited by examiner]
US 9584325B1 · Brandwine · 2017 [cited by examiner]
US 9660970B1 · Rubin · 2017 [cited by examiner]
US 9906493B1 · Rodgers · 2018 [cited by examiner]
US 9992029B1 · Jackson · 2018 [cited by examiner]
US 10311240B1 · Nissler · 2019 [cited by examiner]
US 10425225B1 · Grubin · 2019 [cited by examiner]
US 10461943B1 · Norum · 2019 [cited by examiner]
US 10778429B1 · Rubin · 2020 [cited by examiner]
US 11811729B1 · Sharma · 2023 [cited by examiner]
US 12095909B1 · Campagna · 2024 [cited by examiner]
US 12126713B1 · Ramanathan · 2024 [cited by examiner]
US 12278799B2 · Kim · 2025 [cited by examiner]
US 12355783B2 · Klawe · 2025 [cited by examiner]
US 20050251857A1 · Schunter · 2005 [cited by examiner]
US 20050268103A1 · Camenisch · 2005 [cited by examiner]
US 20050289347A1 · Ovadia · 2005 [cited by examiner]
US 20060026325A1 · Huang · 2006 [cited by examiner]
US 20080319779A1 · Hughes · 2008 [cited by examiner]
US 20090214040A1 · Funk · 2009 [cited by examiner]
US 20090300348A1 · Aciicmez · 2009 [cited by examiner]
US 20110055559A1 · Li · 2011 [cited by examiner]
US 20110292947A1 · Vobbilisetty · 2011 [cited by examiner]
US 20110296230A1 · Chen · 2011 [cited by examiner]
US 20120140923A1 · Lee · 2012 [cited by examiner]
US 20130166754A1 · Christenson · 2013 [cited by examiner]
US 20130212387A1 · Oberheide · 2013 [cited by examiner]
US 20140006776A1 · Scott-Nash · 2014 [cited by examiner]
US 20140033310A1 · Cheng · 2014 [cited by examiner]
US 20140283098A1 · Phegade · 2014 [cited by examiner]
US 20140289528A1 · Baghdasaryan · 2014 [cited by examiner]
US 20150149776A1 · Chastain · 2015 [cited by examiner]
US 20150271150A1 · Barnett · 2015 [cited by examiner]
US 20150281966A1 · Griot · 2015 [cited by examiner]
US 20150382195A1 · Grim · 2015 [cited by examiner]
US 20160050563A1 · Bronk · 2016 [cited by examiner]
US 20160142212A1 · Sarangdhar · 2016 [cited by examiner]
US 20160285875A1 · Lenz · 2016 [cited by examiner]
US 20160315768A1 · Fu · 2016 [cited by examiner]
US 20160315907A1 · Nantel · 2016 [cited by examiner]
US 20170155513A1 · Acar · 2017 [cited by examiner]
US 20170250814A1 · Brickell · 2017 [cited by examiner]
US 20170257365A1 · Gonzalez · 2017 [cited by examiner]
US 20170317969A1 · Masurekar · 2017 [cited by examiner]
US 20170339561A1 · Wennemyr · 2017 [cited by examiner]
US 20170366520A1 · Templin · 2017 [cited by examiner]
US 20180007125A1 · Onno · 2018 [cited by examiner]
US 20180034626A1 · Yamada · 2018 [cited by examiner]
US 20180101847A1 · Pisut, IV · 2018 [cited by examiner]
US 20180114000A1 · Taylor · 2018 [cited by examiner]
US 20180167203A1 · Belenko · 2018 [cited by examiner]
US 20180181756A1 · Campagna · 2018 [cited by examiner]
US 20180234255A1 · Fu · 2018 [cited by examiner]
US 20180248743A1 · Chandrashekhar · 2018 [cited by examiner]
US 20190020647A1 · Sinha · 2019 [cited by examiner]
US 20190065733A1 · Forehand · 2019 [cited by examiner]
US 20190140828A1 · Wheeler · 2019 [cited by examiner]
US 20190149539A1 · Scruby · 2019 [cited by examiner]
US 20190238517A1 · D'Agostino · 2019 [cited by examiner]
US 20190319790A1 · Fenner · 2019 [cited by examiner]
US 20190342177A1 · Shah · 2019 [cited by examiner]
US 20190377907A1 · Fu · 2019 [cited by examiner]
US 20190386974A1 · Fernando · 2019 [cited by examiner]
US 20200021445A1 · Caceres · 2020 [cited by examiner]
US 20200027022A1 · Jha · 2020 [cited by examiner]
US 20200053065A1 · Wisniewski · 2020 [cited by examiner]
US 20200084620A1 · Jana · 2020 [cited by examiner]
US 20200097661A1 · Block · 2020 [cited by examiner]
US 20200099536A1 · Block · 2020 [cited by examiner]
US 20200159966A1 · Sibert · 2020 [cited by examiner]
US 20200175179A1 · Iyer · 2020 [cited by examiner]
US 20200177384A1 · Iyer · 2020 [cited by examiner]
US 20200196122A1 · Junk · 2020 [cited by examiner]
US 20210044575A1 · Kong · 2021 [cited by examiner]
US 20210081545A1 · Mulligan · 2021 [cited by examiner]
US 20210105265A1 · Yang · 2021 [cited by examiner]
US 20210218559A1 · Xia · 2021 [cited by examiner]
US 20210234678A1 · Armleder · 2021 [cited by examiner]
US 20210334010A1 · Charles · 2021 [cited by examiner]
US 20220004627A1 · Smith · 2022 [cited by examiner]
US 20220038272A1 · Hershman · 2022 [cited by examiner]
US 20220108028A1 · Gorog · 2022 [cited by examiner]
US 20220114249A1 · Grancharov · 2022 [cited by examiner]
US 20220131854A1 · Joshi · 2022 [cited by examiner]
US 20220179674A1 · Goel · 2022 [cited by examiner]
US 20220311614A1 · Stolbikov · 2022 [cited by examiner]
US 20220315240A1 · Kubisiak · 2022 [cited by examiner]
US 20220377113A1 · Hoffpauir, IV · 2022 [cited by examiner]
US 20220393868A1 · Mozano · 2022 [cited by examiner]
US 20230074708A1 · Shen · 2023 [cited by examiner]
US 20230103259A1 · Raman · 2023 [cited by examiner]
US 20230179478A1 · Ishikawa · 2023 [cited by examiner]
US 20230185606A1 · Menes · 2023 [cited by examiner]
US 20230188341A1 · Ying · 2023 [cited by examiner]
US 20230319573A1 · Li · 2023 [cited by examiner]
US 20230379353A1 · Fichter · 2023 [cited by examiner]
US 20230391345A1 · Sarkar · 2023 [cited by examiner]
US 20230396431A1 · Liu · 2023 [cited by examiner]
US 20230421462A1 · Xie · 2023 [cited by examiner]
US 20240004681A1 · Graf · 2024 [cited by examiner]
US 20240048380A1 · Berger · 2024 [cited by examiner]
US 20240080663A1 · Huang · 2024 [cited by examiner]
US 20240089239A1 · Kakaiya · 2024 [cited by examiner]
US 20240163264A1 · Kim · 2024 [cited by examiner]
US 20240235852A1 · Cate · 2024 [cited by examiner]
US 20240248994A1 · Singh · 2024 [cited by examiner]
US 20240257097A1 · Arora · 2024 [cited by examiner]
US 20250103737A1 · Shea · 2025 [cited by examiner]