IP Library Granted Patent US 12,592,818
Granted Patent B2
US 12,592,818 · App. 18/822,595 · Granted Mar 31, 2026

Tamper response against physical and logical attacks on an hsm

Inventors: Sumant Das (Davie, FL); Indresh Singh (Delray Beach, FL)
Assignee: THALES DIS CPL USA, INC.
H04L9/0877G06F21/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,818
App. No.
18/822,595
Granted
Mar 31, 2026
Kind
B2
Abstract

Provided is an electronic hardware sub-system within a multi-tenant Hardware Security Module (HSM) for tamper response against physical and logical attacks against the HSM. An HSM Manager manages and orchestrates the vHSMs for dynamic fraud analysis by way of a Tamper Prevention System, wherein a Watchdog detects intrusions and declares Tamper Events, and a Tamper Enforcement Module signals HSM Actors about a tamper state action responsive to said Tamper Event and intrusions. Once enabled, it protects multi-tenant applications against cryptographic attacks and offers continuous fraud detection in a layered approach that intelligently detects a root cause of an attack and isolated an impacted area in a tenant partition. Other embodiments disclosed.

Claims (53)

1 . An electronic hardware sub-system within a multi-tenant Hardware Security Module (HSM) suitable for use for tamper response against physical and logical attacks against the HSM, the electronic hardware sub-system comprising:

a Main Processor (MP) running an operating system (OS) that produces virtualized HSM instances (vHSMs) per tenant using virtualization technologies that are one among containers or micro Virtual Machines (uVMs) running crypto services logic;

a Sensor Processor (SP) communicatively coupled to said MP over a PCIe communication channel to provide tamper handling against physical and logical attacks of said virtualized HSM instances on said HSM; and,

an HSM Manager executing in said MP to

manage and orchestrate said vHSMs for dynamic fraud analysis by way of a Tamper Prevention System on the HSM, and communicatively coupled to crypto client applications operating as tenants and sending API commands to said multi-tenant HSM,

detect any kind of intrusions that happen at an actual tenant level of crypto API services offered by the HSM to them, and then,

identify, and separate out, affected API services of a particular tenant to isolate physical and logical attacks against other tenants,

wherein the MP and SP are distinct hardware devices that each can include one or more Central Processing Units (CPUs) and memory coupled to the one or more CPUs where the memory includes computer instructions which when executed by the one or more processors causes the one or more processors to perform the operations related to fraud analysis, threat detection, and tamper management.

2 . The electronic hardware sub-system of claim 1 , wherein said HSM Manager provides a Hardware as a Service (HaaS) to said crypto client applications for each vHSM tenant by way of a Crypto API Service to both:

tenant users along a crypto services path in a Virtual Private Network (VPN) connection to the HSM; and

tenant administrators along an administrative operations path in said VPN connection to the HSM,

wherein said actual tenant level comprise data, access controls, security policies, and separate administration access assigned to a particular tenant vHSM.

3 . The electronic hardware sub-system of claim 2 , wherein said HSM Manager processes and responds to API commands said crypto client applications over a TCP/TLS connection per tenant for satisfying cryptographic service requests.

4 . The electronic hardware sub-system of claim 2 , wherein said Tamper Prevention System comprises:

a Physical Sensor process including voltage sensors, physical sensors, gryroscopic sensors and temperature sensors communicatively coupled to and controlled by said SP; and

a Logical Sensor process including security controls, network security, behavioral security, and intrusion detection rules communicatively coupled to and controlled by said MP.

5 . The electronic hardware sub-system of claim 4 , wherein the Logical Sensor process implements an Extended Berkeley Packet Filter (eBPF) in a Linux Operating System on the MP for fraud analysis observability and tracing to detect fraud in a Multi-Tenant configuration of the HSM.

6 . The electronic hardware sub-system of claim 4 , wherein the Tamper Prevention System further comprises:

a Watchdog for detecting intrusions and declaring a Tamper Event; and

a Tamper Enforcement Module to signal HSM Actors about a tamper state action responsive to said Tamper Event and intrusions,

wherein said Tamper Prevention System runs on a separate hardware running its own kernel than said HSM.

7 . The electronic hardware sub-system of claim 6 , wherein said Tamper Event consists of:

a hard tamper system level to clear keys and shutdown the HSM for all tenants;

a soft tamper system level to delete root keys but preserve Tenants' keys intact;

a hard tamper tenant level to shutdown particular tenants and initiate soft tamper actions on other tenants; and

a soft tamper tenant level to halt only crypto operations for a detected tenant of a respective vHSM and send an alert to the HSM to re-commission to become fully operational again.

8 . The electronic hardware sub-system of claim 7 , wherein said Tamper Enforcement Module generates a continuous tamper event matrix to identify threats and associated severities to determine an appropriate response to said Tamper Event, wherein Tamper Enforcement Module sends signals to individual vHSMs and underlying virtualized infrastructure, upon appropriate tamper event detection to stop processing crypto functions.

9 . The electronic hardware sub-system of claim 6 , wherein said HSM Actors comprise:

a crypto client application for calling crypto API over TCP/UDP/HTTP(s) for crypto operations on said HSM; and

an administrator for management API over TCP/UDP/HTTP(s) for asset management of said HSM.

10 . The electronic hardware sub-system of claim 6 , wherein said HSM Actors comprise:

a Crypto API Service providing a virtualization layer to perform cryptographic operations starting from said HSM Manager; and

a Data Storage for holding tenant keys to perform management operations starting from said HSM Manager,

wherein said virtualization layer is managed by the HSM Manager acting on behalf of a platform operator.

11 . The electronic hardware sub-system of claim 6 , wherein said Watchdog:

monitors calls to said Crypto API Service within an operating system layer to identify system call behaviors;

monitors traffic from a caller to a callee function for said system calls at other layers, and identifies if that system call behavior is normal or an anomaly for said system calls.

12 . A method suitable with an electronic hardware sub-system within a multi-tenant Hardware Security Module (HSM) for tamper response against physical and logical attacks against the HSM, the method comprising steps of:

by way of a Main Processor (MP), running an operating system (OS) that produces virtualized HSM instances (vHSMs) per tenant using virtualization technologies that are one among containers or micro Virtual Machines (uVMs) running crypto services logic;

by way of a Sensor Processor (SP) communicatively coupled to said MP over a PCIe communication channel, providing tamper handling against physical and logical attacks of said virtualized HSM instances on said HSM; and

by way of an HSM Manager executing on said MP,

managing and orchestrating said vHSMs for dynamic fraud analysis by way of a Tamper Prevention System on the HSM, and communicatively coupled to crypto client applications operating as tenants and sending crypto API commands to said multi-tenant HSM,

detecting intrusions that happen at an actual tenant level of crypto API services offered by the HSM to them, and then,

identifying, and separating out, affected API services of a particular tenant to isolate physical and logical attacks against other tenants.

13 . The method of claim 1 , further comprising,

by way of a Watchdog, detecting intrusions and declaring a Tamper Event; and

by way of a Tamper Enforcement Module, signaling HSM Actors about a tamper state action responsive to said Tamper Event and intrusions,

wherein said Tamper Prevention System comprises said Watchdog and Tamper Enforcement Module that run on a separate hardware running its own kernel than said HSM.

14 . The method of claim 12 , further comprising:

clearing keys and shutting down the HSM for all tenants responsive to a hard tamper system level′

deleting root keys while preserving Tenants' keys intact responsive to a soft tamper system level;

shutting down particular tenants and initiating soft tamper actions on other tenants responsive to a hard tamper tenant level; and

halting only crypto operations for a detected tenant of a respective vHSM and send an alert to the HSM to re-commission to become fully operational again responsive to a soft tamper tenant level.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2024
From: DAS, SUMANT; SINGH, INDRESH
To: THALES DIS CPL USA, INC.
Reel/Frame 069646/0743 →
Continuity (1)
Related Publication 20260067079A1 · Mar 5, 2026
References Cited (6)
US 11475140B1 · Buonora · 2022 [cited by examiner]
US 20160028551A1 · Hussain · 2016 [cited by examiner]
US 20190034357A1 · Nunez Mencias · 2019 [cited by examiner]
US 20220067221A1 · Schiattarella · 2022 [cited by examiner]
US 20250192999A1 · Kumar · 2025 [cited by examiner]
US 20250245032A1 · Couture · 2025 [cited by examiner]