Accelerator Session Key Management via Switch Adjacency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data processing accelerators (DPAs) cannot communicate securely with each other, which is essential for cooperative data processing tasks, as existing technologies lack secure communication protocols to prevent unauthorized alteration or data theft.

Innovation Solution

Implementing a method where DPAs generate unique session keys for secure communication, stored in adjacency tables, allowing them to communicate securely with each other and the host device without the switch having access to these keys, enabling secure peer-to-peer communication and task delegation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If DPAs communicate with each other to perform cooperative data processing tasks, then productivity and functionality are improved, but security and reliability deteriorate due to lack of secure communication protocols

Engineering Contradiction:
Improvecooperative data processing capabilityVSAvoidcommunication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing secure communication channels and exchanging cryptographic keys between DPAs before they engage in cooperative data processing tasks. The host device facilitates key exchange and establishes security protocols in advance, ensuring that when DPAs communicate peer-to-peer for productivity enhancement, the security foundation is already in place. This resolves the contradiction by preparing security measures beforehand rather than attempting to secure communications after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The host device serves as an intermediary that facilitates secure communication between DPAs without being continuously involved in their peer-to-peer interactions. The host establishes initial secure channels, manages key distribution, and coordinates communication security, while allowing DPAs to communicate directly for productivity purposes. This intermediary approach enables both secure communication and efficient cooperative processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DPAs establish secure communication channels with unique session keys, then security and reliability are improved, but device complexity increases due to key management requirements

Engineering Contradiction:
Improvecommunication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The host device performs multiple functions including key generation, key distribution, security protocol establishment, and communication coordination. By consolidating these security management functions in the host, the patent reduces the complexity burden on individual DPAs while maintaining strong security. The host's multi-functionality allows it to manage the complexity centrally while DPAs focus on their primary processing roles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Once the host establishes initial secure channels and distributes keys, the DPAs autonomously manage their own secure communications using the provided cryptographic materials. Each DPA independently applies the security protocols and manages its own session keys for communications with other DPAs, reducing the ongoing management complexity that would otherwise fall on the host or require complex centralized control mechanisms.

Inventive Principle:
Principle #25Self-service

3Productivity

If DPAs communicate peer-to-peer without host intervention, then productivity is improved through direct communication, but security deteriorates as the host cannot monitor or control the communication

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidcommunication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The host performs preliminary security setup by establishing secure communication channels and distributing cryptographic keys to DPAs before they engage in peer-to-peer communication. This preliminary security configuration enables DPAs to communicate directly and efficiently without continuous host intervention, while maintaining security through pre-established secure channels. The host's preliminary actions create a secure foundation that allows autonomous DPA communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The host acts as an intermediary that sets up and manages the security infrastructure for DPA communications without continuously interfering in the actual data processing exchanges. By establishing secure channels and managing key distribution, the host enables productive peer-to-peer communication while maintaining security oversight, resolving the contradiction between direct communication efficiency and security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11558357B2Method for key sharing between accelerators with switch
Publication Date: 2023.01.17 BAIDU USA LLC
  • US11558357B2 patent drawing
  • US11558357B2 patent drawing
  • US11558357B2 patent drawing

AI summary

A host processing device (“host”) instructs a plurality of data processing (DP) accelerators to configure themselves for secure communications. The host generates an adjacency table of each of the plurality of DP accelerators (“DPAs”). The host is communicatively coupled to the plurality of DPAs via a switch. The host transmits, to the switch, a list of the DPAs and instructs the switch to generate an adjacency table of the DPAs that includes a unique identifier of each DPAs and a communication port of the switch associated with the DPA. The host establishes a session key communication with each DPA and sends the DPA a list of other DPAs that the DPA is to establish a session key with, for secure communications between the DPAs. The DPA establishes a different session key for each pair of the plurality of DPAs. When all DPAs have established a session key for communication with other DPAs, the host can assign work tasks for performance by a plurality of DPAs, each communicating over a separately secured communication channel.