Host Channel Manager Secure Channel for Data Processing Accelerators
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for secure communication channels between host systems and data processing accelerators, such as AI accelerators, to protect sensitive transactions and data from unauthorized access, as existing solutions fail to adequately safeguard against data leaks.
Innovation Solution
A method and system for establishing a secure information exchange channel between a host system and a data processing accelerator, involving the generation of session keys based on key pairs, encryption of data, and secure transmission over a bus, utilizing an accelerator channel manager and a host channel manager to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data processing accelerators are used for sensitive transactions, then processing capability is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The system segments the communication channel into multiple layers: physical bus layer, protocol layer, and application layer. Each layer has its own security mechanisms, with the bus layer providing physical isolation and the protocol layer providing cryptographic protection. This segmentation allows the accelerator to maintain high processing capability while multiple security layers protect against unauthorized access.
Solution Approach 2:
The patent introduces an intermediary secure channel between the host system and data processing accelerator. This channel uses cryptographic protocols to mediate all communications, ensuring that sensitive data transmitted during processing operations remains protected. The intermediary layer adds security without significantly impacting the accelerator's processing capability.
2Ease of operation
If existing communication channels are used, then ease of operation is maintained, but data protection capability deteriorates
Solution Approach 1:
The system establishes security protocols and cryptographic key pairs before any data processing operations begin. The secure channel is pre-configured with encryption algorithms and authentication mechanisms, so that when sensitive data needs to be transmitted, the protection is already in place. This preliminary setup maintains ease of operation during actual processing while preventing data leaks.
Solution Approach 2:
The patent changes the cryptographic parameters dynamically based on the sensitivity and type of data being processed. Different encryption algorithms and key lengths are applied depending on the specific transaction requirements. This allows the system to maintain simple operation for standard communications while providing enhanced protection for sensitive operations through parameter adjustment.
Data Source
AI summary
According to one embodiment, a system receives, at a host channel manager (HCM) of a host system, a request from an application to establish a secure channel with a data processing (DP) accelerator, where the DP accelerator is coupled to the host system over a bus. In response to the request, the system generates a first session key for the secure channel based on a first private key of a first key pair associated with the HCM and a second public key of a second key pair associated with the DP accelerator. In response to a first data associated with the application to be sent to the DP accelerator, the system encrypts the first data using the first session key. The system then transmits the encrypted first data to the DP accelerator via the secure channel over the bus.


