IP Library › Granted Patent US 12,489,642
Granted Patent B2
US 12,489,642 · App. 18/354,991 · Granted Dec 2, 2025

Identity based hierarchical sessions

Inventors: Volker Urban (Böblingen, DE); Tamas Visegrady (Zurich, CH); Reinhard Theodor Buendgen (Tuebingen, DE); Michael D. Hocker (Staatsburg, NY); Eric David Rossman (Hopewell Junction, NY)
Assignee: International Business Machines Corporation
H04L9/3271H04L9/0841H04L9/3073H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,642
App. No.
18/354,991
Granted
Dec 2, 2025
Kind
B2
Abstract

According to one embodiment, a method, computer system, and computer program product for establishing identity-based hierarchical sessions on a hardware security module (HSM) for binding secure keys to a guest system, is disclosed. The present invention may include establishing a communication channel between the guest system and the HSM, wherein the communication channel is identity-based, end-to-end and encrypted, thereby establishing a session, transferring login information of the guest system through the communication channel to the HSM, maintaining a predefined security level throughout a hierarchy of the sessions, wherein no child session has a higher security level than its parent session, and performing a challenge-response protocol based on a session ownership verification with the guest, such that an HSM generated and secured key is bound to a related session.

Claims (43)

1 . A computer-implemented method for establishing identity-based hierarchical sessions on a hardware security module (HSM) for binding secure keys to a guest system, the method comprising:

establishing a communication channel between the guest system and the HSM, wherein the communication channel is identity-based, end-to-end, and encrypted, thereby establishing a session;

transferring login information of the guest system through the communication channel to the HSM;

maintaining a predefined security level throughout a hierarchy of sessions, wherein each child session does not have a higher security level than its parent session; and

performing a challenge-response protocol based on a session ownership verification with the guest, such that an HSM-generated and secured key is bound to an associated session.

2 . The method of claim 1 , further comprising:

transmitting a challenge of the challenge-response protocol via the communication channel from the HSM to the guest system.

3 . The method of claim 1 , wherein the establishing the communication channel is based on a public/private key pair of the HSM and a transmitted code allowing a symmetrical encryption/decryption key to be derived.

4 . The method of claim 3 , wherein the deriving the symmetrical encryption/decryption key is based on a Diffie-Hellman algorithm.

5 . The method of claim 1 , further comprising:

using the communication channel to configure a new session to be a child session of an existing session such that the child session is cryptographically dependent on the parent session.

6 . The method of claim 1 , wherein the guest system is executed on a hypervisor.

7 . The method of claim 1 , wherein a function of a firmware of a computer system facilitates a communication between the guest system and the HSM.

8 . The method of claim 1 , further comprising:

deallocating the communication channel and an associated state of the guest system and/or a related session.

9 . The method of claim 1 , further comprising:

deallocating the session and an associated state of the guest system; and/or

deallocating one or more child sessions that have been associated with a parent session upon deallocation of the parent session.

10 . The method of claim 1 , further comprising:

marking a session as a supervisor session; and/or

a separate interface for deallocating one or more sessions and their child sessions that have been marked as supervisor sessions.

11 . The method of claim 1 , further comprising:

upon determining that a child session has a lower security level than its targeted parent session, rejecting a request to open the child session.

12 . A session management system for establishing identity-based hierarchical sessions on a hardware security module (HSM) for binding secure keys to a guest system, the session management system comprising:

one or more processors and a memory operatively coupled to the one or more processors, wherein the memory stores program code portions which, when executed by the one or more processors, enable the one or more processors to:

establish a communication channel between the guest system and the HSM, wherein the communication channel is identity-based, end-to-end and encrypted, thereby establishing a session;

transfer login information of the guest system through the communication channel to the HSM;

maintain a predefined security level throughout a hierarchy of sessions, wherein each child session does not have a higher security level than its parent session; and

perform a challenge-response protocol based on a session ownership verification with the guest, such that an HSM-generated and secured key is bound to an associated session.

13 . The session management system of claim 12 , wherein the one or more processors are further enabled to:

transmit a challenge of the challenge-response protocol via the communication channel from the HSM to the guest system.

14 . The session management system of claim 12 , wherein the establishing the communication channel is based on a public/private key pair of the HSM and a transmitted code allowing a symmetrical encryption/decryption key to be derived.

15 . The session management system of claim 14 , wherein the deriving the symmetrical encryption/decryption key is based on a Diffie-Hellman algorithm.

16 . The session management system of claim 12 , wherein the one or more processors are further enabled to use the communication channel to configure a new session to be a child session of an existing session such that the child session is cryptographically dependent on the parent session.

17 . The session management system of claim 12 , further comprising:

a hypervisor on which the guest system is executed.

18 . The session management system of claim 12 , wherein a function of a firmware of a computer system facilitates a communication between the guest system and the HSM.

19 . The session management system of claim 12 , wherein the one or more processors are further enabled to deallocate the communication channel and a related state of the guest system and/or a related session.

20 . A computer program product for establishing identity-based hierarchical sessions on a hardware security module (HSM) for binding secure keys to a guest system, program instructions being executable by one or more computing systems or controllers to cause the one or more computing systems to:

establish a communication channel between the guest system and the HSM, wherein the communication channel is identity-based, end-to-end, and encrypted, thereby establishing a session:

transfer login information of the guest system through the communication channel to the HSM:

maintain a predefined security level throughout a hierarchy of sessions, wherein each child session does not have a higher security level than its parent session; and

perform a challenge-response protocol based on a session ownership verification with the guest, such that an HSM-generated and secured key is bound to an associated session.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2023
From: URBAN, VOLKER; VISEGRADY, TAMAS; BUENDGEN, REINHARD THEODOR; HOCKER, MICHAEL D.; ROSSMAN, ERIC DAVID
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064314/0044 →
Priority Claims (1)
GB 2307761 · May 24, 2023 · national
Continuity (1)
Related Publication 20240396747A1 · Nov 28, 2024
References Cited (84)
US 4494189A · Bean · 1985 [cited by applicant]
US 5535416A · Feeney · 1996 [cited by applicant]
US 6453392B1 · Flynn, Jr. · 2002 [cited by applicant]
US 7143287B2 · Bade · 2006 [cited by applicant]
US 7639819B2 · Ho · 2009 [cited by applicant]
US 8826039B2 · Chou · 2014 [cited by applicant]
US 9578017B2 · Ferguson · 2017 [cited by applicant]
US 9720721B2 · Bacher · 2017 [cited by applicant]
US 9767293B2 · Boenisch · 2017 [cited by applicant]
US 9836308B2 · Boenisch · 2017 [cited by applicant]
US 9928080B2 · Boenisch · 2018 [cited by applicant]
US 10284534B1 · Perlman · 2019 [cited by applicant]
US 10771263B2 · Smith · 2020 [cited by applicant]
US 11023619B2 · Buendgen · 2021 [cited by applicant]
US 11500988B2 · Buendgen · 2022 [cited by applicant]
US 11533174B2 · Buendgen et al. · 2022 [cited by applicant]
US 20090110191A1 · Sanvido · 2009 [cited by applicant]
US 20110246785A1 · Linsley · 2011 [cited by applicant]
US 20110302400A1 · Maino · 2011 [cited by examiner]
US 20120179909A1 · Sagi · 2012 [cited by applicant]
US 20160239667A1 · Boenisch · 2016 [cited by applicant]
US 20160241393A1 · Boenisch et al. · 2016 [cited by applicant]
US 20180332011A1 · Gray · 2018 [cited by applicant]
US 20190296896A1 · Resch · 2019 [cited by examiner]
US 20190296897A1 · Resch · 2019 [cited by examiner]
US 20190297064A1 · Resch · 2019 [cited by examiner]
US 20190356475A1 · Resch · 2019 [cited by examiner]
US 20190392143A1 · Hall · 2019 [cited by applicant]
US 20200053065A1 · Wisniewski · 2020 [cited by applicant]
US 20200067698A1 · Schmatz · 2020 [cited by examiner]
US 20200089916A1 · Buendgen · 2020 [cited by applicant]
US 20200169401A1 · Dooley · 2020 [cited by applicant]
US 20200228351A1 · Kreft · 2020 [cited by applicant]
US 20200266982A1 · Schmatz · 2020 [cited by examiner]
US 20200285746A1 · Buendgen · 2020 [cited by examiner]
US 20210232709A1 · Buendgen · 2021 [cited by examiner]
US 20210234681A1 · Buendgen · 2021 [cited by examiner]
US 20220393857A1 · Anand · 2022 [cited by examiner]
US 20230031297A1 · Buendgen · 2023 [cited by applicant]
US 20230131348A1 · Landerholm · 2023 [cited by examiner]
US 20230318826A1 · Anand · 2023 [cited by examiner]
US 20240154799A1 · Berzati · 2024 [cited by examiner]
US 20240396747A1 · Urban · 2024 [cited by examiner]
US 20250004700A1 · Woo · 2025 [cited by examiner]
CN 101044489A · 2007 [cited by applicant]
CN 103701607A · 2014 [cited by applicant]
CN 103368973B · 2016 [cited by applicant]
CN 114930328A · 2022 [cited by applicant]
DE 112020005625T5 · 2022 [cited by applicant]
EP 3913850A1 · 2021 [cited by examiner]
GB 2607794A · 2022 [cited by applicant]
GB 2630336A · 2024 [cited by applicant]
JP 2023511834A · 2023 [cited by applicant]
WO 2011015626A1 · 2011 [cited by applicant]
WO WO2011156261A1 · 2011 [cited by examiner]
WO 2018218349A1 · 2018 [cited by applicant]
WO 2021152383A1 · 2021 [cited by applicant]
WO 2023076905A1 · 2023 [cited by applicant]
WO 2024240499A1 · 2024 [cited by applicant]
Fisher-Ogden, John, “Hardware Support for Efficient Virtualization,” University of California, San Diego, Tech. Rep. 12, 2006 (no further date information available), pp. 1-12. [cited by applicant]
Gum, P. H., “System/370 Extended Architecture: Facilities for Virtual Machines,” IBM J. Res. Develop., vol. 27, No. 6, Nov. 1983, pp. 530-544. [cited by applicant]
Hughes, James et al., “Transparent Multi-core Cryptographic Support on Niagara CMT Processors,” Second International Workshop on Multicore Software Engineering, May 2009, pp. 1-8. [cited by applicant]
IBM, “z/Architecture—Principles of Operation,” IBM Publication No. SA22-7832-11, Twelfth Edition, Sep. 2017, pp. 1-1902. [cited by applicant]
International Search Report and Written Opinion, PCT/IB2020/061733, Mar. 23, 2021, pp. 1-8. [cited by applicant]
Klimm, Alexander et al., “An Adaptive and Scalable Multiprocessor System For Xilinx FPGAs Using Minimal Sized Processor Cores,” 2008 IEEE International Symposium on Parallel and Distributed Processing, Apr. 2008, pp. 1-… [cited by applicant]
Lal, Shankar et al., “Securing VNF Communication in NFVI,” 2017 IEEE Conference on Standards for Communications and Networking (CSCN), Sep. 2017, pp. 187-192. [cited by applicant]
Le Vinh, Thinh et al., “Trusted Platforms to Secure Mobile Cloud Computing,” 2014 IEEE International Conference on High Performance Computing and Communications, 2014 IEEE 6th International Symposium on Cyberspace Safet… [cited by applicant]
Mell, Peter and Tim Grance, “The NIST Definition of Cloud Computing,” National Institute of Standards and Technology, Information Technology Laboratory, Special Publication 800-145, Sep. 2011, pp. 1-7. [cited by applicant]
Intellectual Property Office, Patents Act 1977: Examination Report under Section 18(3), Apr. 14, 2025, 5 Pages, GB Application No. 2212344.2. [cited by applicant]
IBM: List of IBM Patents or Patent Applications Treated as Related (Appendix P), Nov. 28, 2023, 2 pages. [cited by applicant]
Intellectual Property Office, “Patents Act 1977: Search Report under Section 17(5),” Intellectual Property Office, Nov. 17, 2023, 4 pages, GB No. GB2307761.3. [cited by applicant]
Japanese Patent Office, “Notice of Reasons for Refusal,” Japanese Patent Office, May 20, 2024, 4 pages, JP Patent Application No. 2022-539306, Machine Translated. [cited by applicant]
Reply to the UK examination report dated Apr. 14, 2024, Application No. GB 2212344.2, 3 pages. [cited by applicant]
International Searching Authority, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or Declaration,” Patent Cooperation Treaty, Jul. 19, 2… [cited by applicant]
Disclosed Anonymously, “Method for Optimized Batch Cryptographic Deletion Utilizing a Hardware Security Module and Tree-Based Encryption Key Management,” IP.com, Nov. 17, 2021, 8 pages, IP.com No. IPCOM000267727D, Retri… [cited by applicant]
Disclosed Anonymously, “NHIP—Network Hosts Identity Protocol,” IP.com, Jun. 10, 2020, 3 pages, IP.com No. IPCOM000262549D, Retrieved from the Internet: <URL: https://priorart.ip.com/IPCOM/000262549>. [cited by applicant]
Disclosed Anonymously, “System and Method to Use Hybrid Data Encryption Keys for Data-at-Rest Encryption in Cloud,” IP.com, Feb. 1, 2021, 4 pages, IP.com No. IPCOM000264856D, Retrieved from the Internet: <URL: https://p… [cited by applicant]
Eisele, “Introducing Hardware Security Modules to Embedded Systems for Electric Vehicles charging according to ISO/IEC 15118,” Datasheet [online], Vector Informatik GmbH, Mar. 17, 2017, 19 pages, Retrieved from the Inte… [cited by applicant]
Han, et al., “Toward Scaling Hardware Security Module for Emerging Cloud Services,” SysTEX '19: Proceedings of the 4th Workshop on System Software for Trusted Execution [research article], Oct. 2019, 6 pages, Article No… [cited by applicant]
Kallewoof, “bips /bip-0032.mediawiki,” Github [online], 2021 [accessed on Jul. 11, 2023], 11 pages, Retrieved from the Internet: <URL: https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki>. [cited by applicant]
NXP Semiconductors, et al., “i.MX 8X SECO HSMv2 FIPS 140-2 Non-Proprietary Security Policy Document Version 2.0,” Datasheet [online], Feb. 7, 2022, 16 pages, Retrieved from the Internet: <URL: https://csrc.nist.gov/CSRC… [cited by applicant]
Pitney Bowes, “X4i Hardware Security Module (HSM) FIPS 140-2 Non-Proprietary Security Policy,” Datasheet [online], Pitney Bowes, Inc., 2020 [accessed on Jul. 11, 2023], 25 pages, Retrieved from the Internet: <URL: https… [cited by applicant]
Urban, et al., “Identity Based Hierarchical Sessions,” Application and Drawings, Filed on May 24, 2023, 38 Pages, Related GB Patent Application Serial No. 2307761.3. [cited by applicant]
Wikipedia, “Password-authenticated key agreement”, Wikipedia, the free encyclopedia, [accessed on Jul. 11, 2023], 4 Pages, Retrieved from the Internet: <URL: https://en.wikipedia.org/wiki/Password-authenticated_key_agre… [cited by applicant]