HSM and TPM Failures in Cloud: A Real-World Taxonomy and Emerging Defenses
Shams Shaikh, Trima P. Fernandes e Fizardo

TL;DR
This paper analyzes real-world failures of HSMs and TPMs in cloud environments, proposing a taxonomy of attack vectors and evaluating emerging defenses to improve cryptographic key security.
Contribution
It introduces the first comprehensive taxonomy of cloud HSM and TPM failures based on real-world cases and assesses new defense strategies against these threats.
Findings
Identified common architectural flaws in cloud HSMs and TPMs.
Evaluated emerging defenses like confidential computing and dKMS.
Provided a practical framework for enhancing cloud cryptographic security.
Abstract
As cloud infrastructure becomes the backbone of modern organizations, the security of cryptographic key management, especially using Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs), faces unprecedented challenges. While these hardware-based solutions offer strong protection in isolated environments, their effectiveness is being undermined by cloud-native threats such as misconfigurations, compromised APIs, and lateral privilege escalations. This paper presents a comprehensive analysis of publicly disclosed attacks and breaches involving HSMs and TPMs in cloud environments, identifying recurring architectural and operational flaws. We propose a taxonomy of attack vectors based on real-world case studies and threat intelligence reports, highlighting the gaps between hardware trust anchors and dynamic cloud ecosystems. Furthermore, we evaluate emerging defensive…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
