IP Library Granted Patent US 12,513,005
Granted Patent B2
US 12,513,005 · App. 18/662,429 · Granted Dec 30, 2025

KMS dedicated HSM design (direct access)

Inventors: Frederick Bosco (Portland, OR); Pankaj Bhandula (Redmond, WA); Ankit Goyal (Redmond, WA); Nitin Handa (Foster City, CA)
Assignee: Oracle International Corporation
H04L9/3263H04L9/0825H04L9/0877H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,005
App. No.
18/662,429
Granted
Dec 30, 2025
Kind
B2
Abstract

A method of providing access to a hardware security module (HSM) partition may include receiving request for access to the HSM partition from a client device. The request may include a leaf certificate signed with a public key associated with a user and a secret key associated with the client device. The method may include verifying the request using the leaf certificate and a trust anchor certificate signed with a public key associated with the client device. The method may include a first connection between the HSM partition and the client device. The method may include verifying the request using the leaf certificate and an authentication certificate stored on the HSM partition. The method may include establishing a second connection between the client device and the HSM partition such that the computing system is isolated from the second connection.

Claims (45)

1 . A method of providing access to a hardware security module (HSM) partition, comprising:

receiving, by a control server of a computing system, request for access to the HSM partition from a client device, the request comprising a leaf certificate signed with a public key associated with a user and a secret key associated with the client device;

verifying, by the control server of the computing system, the request using the leaf certificate and a trust anchor certificate signed with a public key associated with the client device;

in response to verifying the leaf certificate:

establishing, by the control server of the computing system, a first connection between the HSM partition and the client device;

verifying, by a service executed on the HSM partition, the request using the leaf certificate and an authentication certificate stored on the HSM partition; and

in response to verifying the request the leaf certificate and the authentication certificate stored on the HSM partition:

establishing, by the computing system, a second connection between the client device and the HSM partition such that the computing system is isolated from the second connection.

2 . The method of claim 1 , wherein at least one of the first connection and the second connection is made via a private endpoint of a private cloud network.

3 . The method of claim 2 , wherein the private endpoint comprises an undiscoverable IP address.

4 . The method of claim 1 , wherein at least one of the first connection and the second connection is made via a load balancer with a public IP address.

5 . The method of claim 4 , wherein the load balancer comprises a port associated with the HSM partition.

6 . The method of claim 1 , wherein one or more replica partitions are hosted on respective HSMs, the replica partitions identical to the HSM partition.

7 . The method of claim 1 , wherein the second connection is used to receive instructions to create users and/or create keys.

8 . The method of claim 1 , wherein the first connection comprises an mTLS connection.

9 . The method of claim 1 , wherein the second connection comprises a TLS connection.

10 . A system, comprising:

one or more processors;

a control server;

a certificate service; and

a computer memory comprising instructions that, when executed by the one or more processors cause the system to perform operations to:

receive, by the control server, request for access to an HSM partition from a client device, the request comprising a leaf certificate signed with a public key associated with a user and a secret key associated with the client device;

verify, by the control server, the request using the leaf certificate and a trust anchor certificate signed with a public key associated with the client device;

in response to verifying the leaf certificate:

establish, by the control server, a first connection between the HSM partition and the client device;

verify, by the certificate service executed on the HSM partition, the request using the leaf certificate and an authentication certificate stored on the HSM partition; and

in response to verifying the request the leaf certificate and an authentication certificate stored on the HSM partition:

establish, by the control server, a second connection between the client device and the HSM partition.

11 . The system of claim 10 , wherein at least one of the first connection and the second connection is made via a private endpoint of a private cloud network.

12 . The system of claim 11 , wherein the private endpoint comprises an undiscoverable IP address.

13 . The system of claim 10 , wherein at least one of the first connection and the second connection is made via a load balancer with a public IP address.

14 . The system of claim 13 , wherein the load balancer comprises a port associated with the HSM partition.

15 . The system of claim 10 , wherein one or more replica partitions are hosted on respective HSMs, the replica partitions identical to the HSM partition.

16 . The system of claim 10 , wherein the second connection is used to receive instructions to create users and/or create keys.

17 . A non-transitory computer-readable memory comprising instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, by a control server of a computing system, request for access to an HSM partition from a client device, the request comprising a leaf certificate signed with a public key associated with a user and a secret key associated with the client device;

verifying, by the control server of the computing system, the request using the leaf certificate and a trust anchor certificate signed with a public key associated with the client device;

in response to verifying the leaf certificate:

establishing, by the control server of the computing system, a first connection between the HSM partition and the client device;

verifying, by a service executed on the HSM partition, the request using the leaf certificate and an authentication certificate stored on the HSM partition; and

in response to verifying the request the leaf certificate and an authentication certificate stored on the HSM partition:

establishing, by the computing system, a second connection between the client device and the HSM partition such that the computing system is isolated from the second connection.

18 . The non-transitory computer-readable memory of claim 17 , wherein at least one of the first connection and the second connection is made via a private endpoint of a private cloud network.

19 . The non-transitory computer-readable memory of claim 18 , wherein the private endpoint comprises an undiscoverable IP address.

20 . The non-transitory computer-readable memory of claim 17 , wherein at least one of the first connection and the second connection is made via a load balancer with a public IP address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2024
From: BOSCO, FREDERICK; BHANDULA, PANKAJ; GOYAL, ANKIT; HANDA, NITIN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067563/0240 →
Continuity (2)
Provisional Application 63466907 · May 16, 2023
Related Publication 20240388451A1 · Nov 21, 2024
References Cited (34)
US 10680816B2 · Antoni et al. · 2020 [cited by applicant]
US 11210079B2 · Fassino et al. · 2021 [cited by applicant]
US 20160359853A1 · Fitzgerald et al. · 2016 [cited by applicant]
US 20170012774A1 · Antoni et al. · 2017 [cited by applicant]
US 20190140844A1 · Brown et al. · 2019 [cited by applicant]
US 20190253264A1 · Singaravelu et al. · 2019 [cited by applicant]
US 20200021430A1 · Grubin et al. · 2020 [cited by applicant]
US 20200186355A1 · Davies · 2020 [cited by applicant]
US 20200257827A1 · Kounavis · 2020 [cited by examiner]
US 20210067505A1 · Gandhi et al. · 2021 [cited by applicant]
US 20210344508A1 · Dasen et al. · 2021 [cited by applicant]
US 20220166637A1 · Keskikangas et al. · 2022 [cited by applicant]
US 20220353073A1 · Nguyen · 2022 [cited by applicant]
US 20220376929A1 · Nagaratnam et al. · 2022 [cited by applicant]
US 20230239163A1 · Liu · 2023 [cited by examiner]
US 20230299979A1 · Kushwaha et al. · 2023 [cited by applicant]
US 20230394152A1 · Sarkar · 2023 [cited by applicant]
WO 2011006912A1 · 2011 [cited by applicant]
WO 2023187371A1 · 2023 [cited by applicant]
Creating an NTLS Connection Using a Self-Signed Appliance Certificate and a Client Certificate Signed by a Trusted Certificate Authority, Available Online at: https://thalesdocs.com/gphsm/luna/7/docs/network/Content/adm… [cited by applicant]
FIPS 140-2 Level 3—Non-Proprietary Security Policy—NITROXIII CNN35XX-NFBE HSM Family, Available Online at: https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/14… [cited by applicant]
HSM Partitions, Available Online at: https://thalesdocs.com/gphsm/luna/6.3/docs/usb/Content/administration/partitions/hsm_partitions.htm, Accessed from Internet on Jan. 17, 2024, 1 page. [cited by applicant]
IBM Cloud HSM, Available Online at: https://developers.cloudflare.com/ssl/keyless-ssl/hardware-security-modules/IBM-cloud-hsm/, Accessed from Internet on Jan. 17, 2024, pp. 1-4. [cited by applicant]
Initialize the Cluster, Available Online at: https://docs.aws.amazon.com/cloudhsm/latest/userguide/initialize-cluster.html, 2024, 4 pages. [cited by applicant]
Integrate Managed HSM with Azure Private Link, Configure Azure Key Vault Managed HSM with Private Endpoints , Microsoft Learn, Available Online at: https://learn.microsoft.com/en-us/azure/key-vault/managed-hsm/private-l… [cited by applicant]
Key Sovereignty, Availability, Performance, and Scalability in Managed HSM, Available Online at: https://learn.microsoft.com/en-us/azure/key-vault/managed-hsm/managed-hsm-technical-details, Aug. 3, 2023, 4 pages. [cited by applicant]
Ownership of Application Partitions, Available Online at: https://thalesdocs.com/gphsm/luna/6.3/docs/network/Content/overview/product_line/ownership_of_partitions.htm, Accessed from Internet on Jan. 17, 2024, pp. 1-3. [cited by applicant]
Patentability Search Report mailed on Jan. 18, 2024, 10 pages. [cited by applicant]
Patentability Search Report mailed on Jan. 17, 2024, 11 pages. [cited by applicant]
Using Hardware Security Modules with CredHub, Available Online at: https://docs.vmware.com/en/VMware-Tanzu-Application-Service/5.0/tas-for-vms/hsm-config.html, Jan. 16, 2024, pp. 1-7. [cited by applicant]
Using HSM-based Secrets Encryption, Version 1.28, GKE on VMware, Available Online at: https://cloud.google.com/anthos/clusters/docs/on-prem/latest/how-to/hsm-secrets-encryption, Accessed from Internet on Jan. 18, 2024, … [cited by applicant]
Chen, Proposal: Istio Envoy mTLS Private Key Protection with HSM, Issue #36296, GitHub, Available Online at: https://github.com/istio/istio/issues/36296, Nov. 30, 2021, 6 pages. [cited by applicant]
Roy, Understanding and Generating Certificate Signing Requests (CSRs) Using Luna Cloud HSM—A Comprehensive Guide, Available Online at: https://www.encryptionconsulting.com/understanding-and-generating-certificate-signin… [cited by applicant]
U.S. Appl. No. 18/662,434, Notice of Allowance, Mailed On Sep. 12, 2025, 13 pages. [cited by applicant]