Managed Network Device Fabric Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High-performance computing networks, such as InfiniBand™ fabrics, are vulnerable to malicious software and firmware due to the assumption that all elements are trusted, leading to potential spoofing and denial-of-service attacks.
Innovation Solution
Implementing a system with managed network devices that control management access, verify data packet headers, and rate-limit management messages, using a fabric manager to configure and manage the network, thereby preventing unauthorized access and ensuring the integrity and availability of the fabric.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If all elements of the fabric are assumed to be trusted, then the network fabric can operate with simple access control, but the network becomes vulnerable to malicious software and firmware attacks
Solution Approach 1:
The patent segments the network fabric into trusted and untrusted zones by introducing managed network devices that act as security boundaries. These devices divide the fabric into management partitions, allowing simple operation within trusted zones while providing security control at partition boundaries, thus resolving the contradiction between operational simplicity and security reliability.
Solution Approach 2:
The managed network devices serve as intermediary components between untrusted computing nodes and the trusted fabric core. These intermediaries enforce access control policies and manage partitions, enabling the fabric to maintain simple operation characteristics while gaining security against malicious software through the mediating security devices.
2Reliability
If managed network devices enforce access control and partitions, then security against spoofing attacks improves, but device complexity increases
Solution Approach 1:
The patent applies local quality by implementing access control and partition enforcement only at specific locations (managed network devices) rather than throughout the entire fabric. This localized approach provides strong spoofing protection at critical boundaries while keeping the overall device complexity manageable, as only specific devices bear the security enforcement burden.
Solution Approach 2:
The managed network devices perform multiple functions including access control enforcement, partition management, and spoofing prevention, consolidating security functions into universal devices. This multi-functionality approach improves spoofing protection while managing complexity by combining multiple security tasks into single devices rather than requiring separate specialized components.
3Reliability
If management access is controlled and rate-limiting is implemented, then denial-of-service attack mitigation improves, but network performance may be impacted
Solution Approach 1:
The patent implements dynamic rate-limiting mechanisms that adjust management access control based on traffic conditions and threat detection. The system dynamically responds to potential denial-of-service attacks by modulating access permissions and rate limits, thereby mitigating attacks while maintaining normal network performance under legitimate operation conditions.
Solution Approach 2:
The managed network devices incorporate feedback mechanisms that monitor management traffic patterns and adjust access control policies accordingly. This feedback-driven approach allows the system to distinguish between legitimate management operations and malicious denial-of-service attempts, enabling attack mitigation while preserving network performance through adaptive rather than static access control.
Data Source
AI summary
Technologies for fabric security include one or more managed network devices coupled to one or more computing nodes via high-speed fabric links. A managed network device enables a port and, while enabling the port, securely determines the node type of the link partner coupled to the port. If the link partner is a computing node, management access is not allowed at the port. The managed network device may allow management access at certain predefined ports, which may be connected to one of more management nodes. Management access may be allowed for additional ports in response to management messages received from the management nodes. The managed network device may check and verify data packet headers received from a compute node at each port. The managed network device may rate-limit management messages received from a compute node at each port. Other embodiments are described and claimed.


