Secure Accelerator Pairing via Trusted Agent Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computing systems lack effective mechanisms to ensure secure communication between hardware accelerators, particularly in trusted execution environments, as malicious accelerators can access and manipulate data across different trust domains without detection, compromising security.
Innovation Solution
A computing device architecture that includes a trusted agent to verify and configure I/O devices, establish secure communication channels, and manage trusted execution environments, using techniques like attestation protocols and cryptographic keys to ensure only authorized accelerators within the same trust boundary can communicate securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If peer-to-peer accelerator communication is enabled, then communication efficiency between accelerators is improved, but security risk increases due to potential unauthorized access from malicious accelerators
Solution Approach 1:
The patent introduces a host device as an intermediary that mediates all peer-to-peer accelerator communications. The host device verifies trust relationships, manages cryptographic keys, and authorizes communication channels between accelerators. This mediator approach enables direct accelerator-to-accelerator communication for efficiency while maintaining security through centralized trust management and authorization protocols.
2Speed
If direct accelerator-to-accelerator communication is implemented, then data transfer speed is improved, but trust boundary enforcement becomes more complex
Solution Approach 1:
The patent implements preliminary trust verification and cryptographic key establishment through the host device before accelerators can communicate directly. Trust boundaries are pre-defined and authorized by the host, with cryptographic credentials established in advance. This preliminary action enables fast direct communication while simplifying trust boundary enforcement, as the complex verification work is completed beforehand rather than during data transfer.
Data Source
AI summary
Technologies for secure device configuration and management include a computing device having an I/O device. A trusted agent of the computing device is trusted by a virtual machine monitor of the computing device. The trusted agent executes an attestation algorithm to generate a first secure attestation for the first I/O device and a second secure attestation for the second I/O device, obtains a peer-to-peer communication key, and forwards the peer-to-peer communication key to the first I/O device and a second I/O device to enable secure peer-to-peer communication between the first I/O device and the second I/O device over a communication link secured by the peer-to-peer communication key. Other embodiments are described and claimed.


