US 12,034,836 B1
Systems and methods for hardware security module communication management
Jeff J. Stapleton, O'Fallon, MO (US)
Assigned to Wells Fargo Bank, N.A., San Francisco, CA (US)
Filed by Wells Fargo Bank, N.A., San Francisco, CA (US)
Filed on Jun. 30, 2022, as Appl. No. 17/810,236.
Int. Cl. H04L 9/08 (2006.01); G06F 21/72 (2013.01); H04L 9/14 (2006.01); H04L 9/40 (2022.01)
CPC H04L 9/0819 (2013.01) [G06F 21/72 (2013.01); H04L 9/0852 (2013.01); H04L 9/0869 (2013.01); H04L 9/14 (2013.01); H04L 9/0816 (2013.01); H04L 9/0827 (2013.01); H04L 9/0833 (2013.01); H04L 63/062 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method for hardware security module (HSM) communication management comprising:
deriving, by key derivation circuitry of a first HSM, a first cryptographic key based on an initial key and a first set of seed bits, wherein deriving the first cryptographic key establishes a first communication group comprising the first HSM and a second HSM based on the second HSM having also derived the first cryptographic key;
receiving, by communications hardware of the first HSM, a secure message comprising a second cryptographic key from a key exchange management device, wherein the second cryptographic key is associated with a second communication group comprising a third HSM and a fourth HSM;
deriving, by the key derivation circuitry of the first HSM, a third cryptographic key based on the first cryptographic key and the second cryptographic key, wherein deriving the third cryptographic key establishes a third communication group comprising the first HSM, the second HSM, the third HSM, and the fourth HSM based on the second HSM, the third HSM, and the fourth HSM having also derived the third cryptographic key; and
performing, by data protection circuitry of the first HSM, a first cryptographic data protection action using the third cryptographic key, wherein the first cryptographic data protection action facilitates secure communication between HSMs of the third communication group.