Host Memory Buffer Mutual Authentication for Secure Workload Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing NVMe systems lack secure mechanisms to establish trustworthy connections between Host Memory Buffer (HMB) controllers and workloads, vulnerable to spoofing attacks and data exfiltration, necessitating a need for workload identity verification and secure communication protocols.

Innovation Solution

Implementing mutual authentication between HMBs and workloads using trusted execution environments and public/private key pairs, with a mutual validation orchestrator to verify and generate identity certificates, establishing secure communication tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If HMB controller provides exclusive access to host system memory without authentication, then memory access speed and efficiency are improved, but security is worsened due to vulnerability to spoofing attacks and data exfiltration

Engineering Contradiction:
Improvememory access speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an authentication intermediary layer between the HMB controller and workloads. This intermediary verifies workload identities and manages authentication credentials, allowing fast memory access for authenticated workloads while blocking unauthorized access attempts. The intermediary acts as a security gatekeeper that maintains both security and performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication actions before granting HMB access. Workloads must present valid credentials and undergo verification before being assigned HMB regions. This preliminary security check prevents spoofing attacks and ensures that only authorized workloads can access the memory buffer, resolving the security vulnerability without impacting subsequent access speed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If mutual authentication protocol is implemented between HMB and workloads, then security and confidentiality are improved, but system complexity is worsened due to additional authentication layers

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that handles multiple authentication scenarios through a single standardized protocol. The HMB controller uses the same authentication mechanism for different workload types (virtual machines, containers, applications), reducing the need for multiple specialized authentication systems and managing complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system is designed to be self-service where workloads automatically present their credentials and receive authentication decisions without manual intervention. The HMB controller autonomously verifies credentials and manages access rights, reducing the operational complexity burden on system administrators while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Reliability

If workload identity verification is required before HMB access, then access control is improved, but processing time is worsened due to additional verification steps

Engineering Contradiction:
Improveaccess controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs identity verification as a preliminary action during workload initialization or HMB assignment, before the workload begins memory access operations. By completing authentication upfront, the system ensures strict access control while allowing authenticated workloads to access HMB regions without repeated verification delays during actual memory operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication process from the memory access process. Identity verification is separated into a distinct preliminary phase, while memory access operations proceed independently once authentication is complete. This segmentation allows access control to be enforced without continuously interrupting memory access performance.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250238252A1Mutual authentication between workloads and a host memory buffer for confidential and secure memory management systems
Publication Date: 2025.07.24 DELL PROD LP
  • US20250238252A1 patent drawing
  • US20250238252A1 patent drawing
  • US20250238252A1 patent drawing

AI summary

Disclosed systems and methods respond to detecting an application workload requesting access to a host memory buffer (HMB) associated with a nonvolatile storage device of an information handling system by performing mutual authentication operations. The mutual authentication operations may include authenticating the application to the HMB and authenticating the HMB to the application. Responsive to successful completion of the mutual authentication operations, disclosed methods and systems may establish a secure communications tunnel enabling the application workload to access at least a portion of the HMB securely.