Host Computing Hardware Isolation via Offload Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared data center environments, customers seeking full access to hardware resources face risks of unintentional or malicious modifications, which can affect subsequent users, highlighting the need for secure management and isolation of hardware components.

Innovation Solution

Implementing an offload engine component and baseboard management component with hardware latches to control access to critical system components like SBIOS and hard drive controllers, ensuring secure management and isolation of hardware resources, and establishing control plane functions independent of customer processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers are granted full access to hardware resources in a shared data center environment, then customer control and customization capabilities are improved, but security risks and potential harmful modifications increase

Engineering Contradiction:
Improvecustomer controlVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments hardware resource access into two distinct modes: virtualized access for standard customers and controlled physical access for customers requiring full hardware control. This segmentation allows the data center to provide both high-level security through virtualization and low-level access when needed, resolving the contradiction between customer control and security risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary management layer that mediates between customers and physical hardware resources. This intermediary implements security policies, monitors for harmful modifications, and controls access to prevent security risks while still allowing customers to access hardware resources when appropriate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If virtualization is implemented to increase data center resource utilization, then resource efficiency is improved, but customer access to specific hardware resources is reduced

Engineering Contradiction:
Improveresource utilizationVSAvoidhardware access
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system dynamically switches between virtualized and physical access modes based on customer requirements and security conditions. When security risks are detected or full hardware access is required, the system transitions from virtualized to physical access, and vice versa, allowing the data center to optimize resource utilization while providing hardware access when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal access framework that can operate in multiple modes (virtualized and physical) within the same data center environment. This multi-functionality allows the system to provide both virtualization for resource efficiency and direct hardware access for customers needing specific hardware control, eliminating the need to choose between the two approaches.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If physical access to computing devices is allowed, then customer customization and hardware control are improved, but risk of malicious modifications affecting other users increases

Engineering Contradiction:
Improvehardware controlVSAvoidsystem integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback mechanisms that continuously monitor physical computing devices for unauthorized modifications. When modifications are detected, the system can alert administrators, isolate the affected device, or revert changes, thereby maintaining system integrity while still allowing physical access for legitimate customization needs.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements preliminary security measures such as authentication, authorization, and pre-configured security policies before customers gain physical access to hardware. These preliminary actions ensure that only authorized modifications are permitted, preventing malicious changes while allowing legitimate hardware control and customization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9032196B1Management of components in a hosting architecture
Publication Date: 2015.05.12 AMAZON TECH INC
  • US9032196B1 patent drawing
  • US9032196B1 patent drawing
  • US9032196B1 patent drawing

AI summary

A service provider can maintain one or more host computing devices which may be utilized as bare metal instances by one or more customers of the service provider. Illustratively, each host computing device includes hardware components that are configured in a manner to allow the service provider to implement one or more processes upon a power cycle of the host computing device and prior to access of the host computing device resources by customers. In one aspect, a hosting platform includes components arranged in a manner to limit modifications to software or firmware on hardware components. In another aspect, the hosting platform can implement management functions for establishing control plane functions between the host computing device and the service provider that is independent of the customer. Additionally, the management functions can also be utilized to present different hardware or software attributes of the host computing device.