Network Interface Controller Data Encryption for Multi-Tenant Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant datacenter environments, there is a security gap when data is transmitted to a network controller, as communications may be in plaintext, potentially accessible by malicious tenants or attackers.

Innovation Solution

A network interface controller (NIC) is designed to handle secure communication with trusted environments by employing cryptography engines, key storage, and packet processing blocks to encrypt and decrypt data, ensuring that plaintext is not transmitted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted in plaintext to the network controller, then communication simplicity is maintained, but security is compromised as data may be accessible by malicious tenants or attackers

Engineering Contradiction:
Improvedata securityVSAvoidencryption infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network interface controller (NIC) with integrated cryptographic capabilities as an intermediary between the trusted environment and the network. This NIC includes a cryptography engine that encrypts data before it leaves the trusted environment and decrypts incoming data, preventing plaintext exposure on the network while maintaining secure communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual or software-based encryption/decryption processes with dedicated hardware cryptographic engines integrated into the NIC. This hardware-based approach provides more reliable and efficient cryptographic operations, ensuring data security while reducing the computational burden on the host system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If encryption is implemented for all data transmissions, then security is improved, but processing overhead and energy consumption increase

Engineering Contradiction:
Improvedata protectionVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements encryption at the source (within the trusted environment) before data is transmitted to the network. The NIC encrypts data immediately when it leaves the trusted environment, and decrypts data immediately when it arrives, minimizing the time data spends in encrypted form and reducing overall energy consumption compared to continuous encryption throughout the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses hardware-based cryptographic engines in the NIC to perform encryption and decryption operations, which are more energy-efficient than software-based cryptographic implementations. This hardware acceleration reduces the energy overhead of encryption while maintaining strong security protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If plaintext communication is used, then processing speed is maintained, but security risk increases due to potential data access by unauthorized parties

Engineering Contradiction:
Improvesecurity assuranceVSAvoidcryptographic engine
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The NIC acts as a secure intermediary that handles all cryptographic operations, isolating the complexity of encryption/decryption from the main processing systems. The cryptography engine within the NIC manages key storage, encryption, and decryption transparently, providing security assurance without requiring complex cryptographic management in the host system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent separates cryptographic functions into a dedicated NIC with its own cryptography engine and key storage, independent from the main computing system. This segmentation allows the cryptographic subsystem to operate independently with optimized security measures while the main system focuses on data processing, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12339978B2Network interface with data protection
Publication Date: 2025.06.24 INTEL CORP
  • US12339978B2 patent drawing
  • US12339978B2 patent drawing
  • US12339978B2 patent drawing

AI summary

A network interface controller (NIC) to interact with virtual environments when they are within a trusted environment protected by a cryptography scheme. The NIC performs encryption of data in accordance with the cryptographic scheme of a target trusted environment prior to copying the data for access by the target trusted environment.