Disaggregated Secure Processor Pool for Dynamic Data Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems lack flexible security measures to effectively protect data-in-use, data-in-motion, and data-at-rest, particularly in data centers, where security configurations are often inflexible and not dynamically scalable to match workload characteristics.

Innovation Solution

A disaggregated computing system is introduced, featuring a secure processor pool that allows for dynamic provisioning of server entities with secure processors and memory, using cryptographic information to encrypt data-in-use and ensure secure execution within the secure processor's memory, while maintaining encryption keys in a privileged table accessible only to the security manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional fixed security configurations are used, then security measures are implemented, but they cannot be dynamically scaled to match workload characteristics and are expensive

Engineering Contradiction:
Improvedynamic scalability of security measuresVSAvoidsecurity configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security by allowing security measures to be scaled up or down based on workload characteristics. The system can provision security resources dynamically rather than maintaining fixed security configurations, enabling adaptability to varying security requirements while optimizing resource utilization and cost efficiency.

Inventive Principle:
Principle #15Dynamics

2Reliability

If encryption is applied to protect data-in-use, then data visibility is prevented upon unauthorized access, but encryption keys must be stored in memory which creates security vulnerabilities

Engineering Contradiction:
Improvedata protection reliabilityVSAvoidmemory-based key storage vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts encryption keys from vulnerable memory storage and relocates them to secure enclaves or hardware security modules. This separation removes keys from the attack surface of general-purpose memory while maintaining their functionality for encryption operations, thereby protecting against memory-based attacks such as cold boot attacks and memory parsing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces enclaves or hardware security modules as intermediary components between the encryption algorithm and the key storage. These intermediaries provide a secure boundary that protects keys from direct access by the operating system or malicious software, while still enabling encryption operations to proceed normally.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If CPU registers are used to store encryption keys, then cold boot attacks are protected, but not all data-in-use is protected

Engineering Contradiction:
Improvecold boot attack protectionVSAvoidcomprehensive data-in-use protection
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements a universal protection mechanism using enclaves that can protect all data-in-use regardless of its location or state. Unlike CPU register-based protection which is limited to specific key storage, enclaves provide comprehensive protection for entire memory regions containing data, code, and keys, offering multi-functional security coverage for all data-in-use scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If enclaves with special registers and circuits are used, then memory encryption is achieved, but the system complexity increases and flexibility is reduced

Engineering Contradiction:
Improvememory encryption capabilityVSAvoidsecurity configuration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic enclave provisioning that allows enclaves to be created, configured, and destroyed based on workload requirements. This dynamic approach enables the system to provide strong memory encryption when needed while maintaining flexibility to adjust security configurations and resource allocation according to changing security requirements and workload characteristics.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10901918B2Constructing flexibly-secure systems in a disaggregated environment
Publication Date: 2021.01.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10901918B2 patent drawing
  • US10901918B2 patent drawing
  • US10901918B2 patent drawing

AI summary

Server resources in a data center are disaggregated into shared server resource pools, which include a pool of secure processors. Advantageously, servers are constructed dynamically, on-demand and based on a tenant's workload requirements, by allocating from these resource pools. According to this disclosure, secure processor modules for new servers are allocated to provide security for data-in-use (and data-at-rest) in a dynamic fashion so that virtual and non-virtual capacity can be adjusted in the disaggregate compute system without any downtime, e.g., based on workload security requirements and data sensitivity characteristics. The approach herein optimizes an overall utilization of an available secure processors resource pool in the disaggregated environment. The resulting disaggregate compute system that is configured according to the approach cryptographically-protects workload data whenever it is outside the CPU chip.