Hardware Accelerator Secure Channel for Data Center Confidentiality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data centers face challenges in ensuring the security of customers' confidential data processing due to the lack of control over the data center's processes and hardware, making it difficult for customers to trust the processing of sensitive tasks.

Innovation Solution

Establishing secure communication channels directly between clients and hardware accelerators within the data center using preconfigured cryptographic information, which is stored and maintained within the hardware accelerators, inaccessible to host computing devices, allowing for secure data processing and potential expansion to multiple accelerators for increased processing capacity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data processing is performed in centralized data centers with multiple computing devices, then processing efficiency and capacity are improved, but security control and customer trust deteriorate because customers cannot verify who accesses their confidential data

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the data processing system into isolated hardware accelerator units, each dedicated to specific customers. This segmentation allows multiple customers to share data center resources while maintaining separate, secure processing environments that prevent unauthorized access to confidential data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hardware accelerators as intermediary processing units between customer data and the data center infrastructure. These accelerators act as trusted mediators that process confidential data without allowing host computing devices or other processes to access the data, thereby maintaining security while enabling centralized processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic information is stored within hardware accelerators inaccessible to host computing devices, then security is improved, but system complexity increases due to isolated cryptographic key management

Engineering Contradiction:
ImprovesecurityVSAvoidcryptographic key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service cryptographic key management within hardware accelerators. Each accelerator independently stores and manages its own cryptographic information without requiring access from host computing devices. This self-contained approach enhances security while the automated key management protocols reduce the operational burden of complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary configuration of cryptographic information during hardware accelerator initialization or manufacturing. By pre-configuring security credentials before the accelerators enter service, the system reduces ongoing management complexity while maintaining high security standards throughout operation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure communication channels are established directly to hardware accelerators, then confidentiality is improved, but communication infrastructure complexity increases

Engineering Contradiction:
ImproveconfidentialityVSAvoidcommunication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal communication protocols that allow hardware accelerators to establish secure channels using standard cryptographic mechanisms. By designing the communication infrastructure to be multi-functional and protocol-agnostic, the system achieves strong confidentiality without requiring custom, complex communication pathways for each accelerator.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3284008B1Protecting communications with hardware accelerators for increased workflow security
Publication Date: 2020.06.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3284008B1 patent drawingFigure 1
  • EP3284008B1 patent drawingFigure 2
  • EP3284008B1 patent drawingFigure 3

AI summary

To protect customer data and provide increased workflow security for processing requested by a customer, a secure communicational channel can be established between a customer and one or more hardware accelerators such that even processes executing on a host computing device hosting such hardware accelerators are excluded from the secure communicational channel. An encrypted bitstream is provided to hardware accelerators and the hardware accelerators obtain therefrom cryptographic information supporting the secure communicational channel with the customer. Such cryptographic information is stored and used exclusively from within the hardware accelerator, rendering it inaccessible to processes executing on a host computing device. The cryptographic information can be a shared secret, an appropriate one of a pair of cryptographic keys, or other like cryptographic information. Similarly, the encrypted bitstream can comprise the cryptographic information, computer-executable instructions executable by the processing circuitry of the hardware accelerator to derive such cryptographic information, or combinations thereof.