Data Processing Accelerator Grouping for Secure Cluster Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data processing accelerator clusters used for AI model training and inference face challenges in ensuring data security and authenticity, particularly due to the risk of AI model leakage, theft, or alteration, and the difficulty in authenticating third-party accelerators, which can compromise security and energy efficiency.
Innovation Solution
Implementing a method that configures data processing accelerators into secure and non-secure resource groups within a cluster, using a host device to manage communication links and authenticate accelerators through shared secrets, and dynamically repartitioning resources to optimize energy use and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data processing accelerators are interconnected in a cluster to provide adequate computational power, then processing capacity is improved, but security risk increases due to potential model leakage or theft through communication links
Solution Approach 1:
The patent segments the cluster into secure and non-secure groups by controlling communication links. Accelerators are partitioned into isolated groups where secure accelerators only communicate with other secure accelerators, preventing model leakage to non-secure accelerators while maintaining computational throughput through distributed processing within secure groups
Solution Approach 2:
The host device serves as an intermediary that manages and controls communication links between accelerators. It dynamically configures which accelerators can communicate with each other, acting as a gatekeeper that allows necessary data flow for computation while blocking unauthorized model extraction paths
2Productivity
If the number of data processing accelerators is increased to handle maximum workload, then processing capacity is improved, but energy consumption and heat generation increase
Solution Approach 1:
The system dynamically configures communication links and accelerator groupings based on workload requirements. When full computational power is needed, more accelerators are activated and interconnected. When workload decreases, accelerators are deactivated or placed in low-power states, and communication links are reduced, thereby lowering energy consumption and heat generation while maintaining maximum workload capacity when needed
3Ease of manufacture
If third-party data processing accelerators are used to reduce cost, then device complexity is reduced, but authentication difficulty increases due to inability to verify manufacturer authenticity
Solution Approach 1:
Each accelerator carries a unique identifier that enables self-authentication. The host device queries this identifier and verifies the accelerator's security credentials independently, allowing the system to self-verify the authenticity and security posture of third-party accelerators without requiring external certification or trusted manufacturer verification
Data Source
AI summary
Systems and methods are disclosed for data protection in a cluster of data processing accelerators (DPAs) using a policy that partitions the DPAs into one or more group of DPAs in the cluster. A host device instructs the DPAs to organize themselves into non-overlapping groups according to a policy for each DPA in the cluster. The policy indicates, for each DPA, one or more other DPAs the DPA is to establish a communication link with, to implement the grouping. Once grouped, the host device and a DPA can access all resources of the DPA. DPAs in the same group as a first DPA can access non-secure resources, but not secure resources, of the first DPA. DPAs in a different group from the first DPA cannot access any resources of the first DPA. A scheduler in the host device can allocate processing tasks to any group in the cluster.


