NIC Control Plane Separation for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud hosting scenarios, the exposure of physical hardware to tenants compromises the security of the provider's infrastructure and network, as malicious or compromised tenants can access the kernel space, leading to potential attacks.
Innovation Solution
The control plane and data plane of the network interface controller (NIC) are separated, with the control plane being restricted to trusted entities and the data plane accessible to all physical functions, preventing untrusted physical functions from performing hardware configuration operations, thus isolating potential attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the kernel space of physical machines is made accessible to customers for bare metal hosting, then direct hardware access and performance are improved, but security and trust of the provider's infrastructure deteriorate
Solution Approach 1:
The patent segments the control plane into trusted and untrusted control paths, allowing direct hardware access for performance while isolating security-critical functions. The trusted control path is restricted to provider-controlled entities, while the untrusted path serves customer requests, preventing malicious tenants from compromising the entire system.
Solution Approach 2:
The patent introduces an intermediary trusted entity (provider-controlled physical function or remote driver) that mediates between customer requests and hardware configuration. This intermediary validates and sanitizes control plane requests, blocking malicious operations while allowing legitimate ones, thus maintaining security without sacrificing direct hardware access capability.
2Adaptability or versatility
If the same physical hardware is shared between regular and bare metal tenants, then resource utilization and cost efficiency are improved, but security risks and attack surface increase
Solution Approach 1:
The patent applies segmentation by creating separate trusted and untrusted control paths within the same physical hardware. This allows multiple tenants to share hardware resources while isolating their control plane access, preventing cross-tenant attacks through the segmented control paths.
Solution Approach 2:
The patent implements local quality by assigning different security characteristics to different control paths. The trusted control path has strict security restrictions for provider infrastructure protection, while the untrusted control path provides broader access for customer operations, allowing the same hardware to serve different security requirements simultaneously.
3Reliability
If control plane access is restricted to trusted entities only, then security and protection of infrastructure are improved, but operational flexibility and customer control deteriorate
Solution Approach 1:
The patent segments control plane access into trusted and untrusted paths, allowing restricted access for infrastructure protection while maintaining customer control through the untrusted path. This segmentation enables both high reliability for provider operations and flexibility for customer operations.
Solution Approach 2:
The patent makes the control plane universally accessible through multiple paths - both trusted and untrusted entities can access control plane functions through their respective paths. This multi-functionality allows the same control plane to serve both security-restricted provider operations and flexible customer operations.
Data Source
AI summary
Technologies for control plane separation at a network interface controller (NIC) of a compute device configured to transmit, by a resource of the compute device, commands to a physical function managed by a network interface controller (NIC) of the compute device. The NIC is further to establish a data plane separate from a control plane, wherein the control plane comprises one of the trusted control path and the untrusted control path. Additionally, the resource is configured to transmit the commands via one of the trusted control path or the untrusted control path based on a trust level associated with the physical function. Other embodiments are described herein.


