Obfuscation Computing System for HPC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High-performance computing (HPC) systems face increased cybersecurity concerns due to the sharing of resources among various users, leading to both external and internal security threats, and traditional encryption methods can cause significant computational overhead.

Innovation Solution

An obfuscation computing system is introduced to perform code-level and system-level obfuscation, acting as an intermediary between user computing systems and nodes in a distributed HPC platform, obfuscating commands, system management tasks, and network traffic to enhance data confidentiality and integrity without substantial computational overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption methods are used to secure HPC resources, then data confidentiality is improved, but computational overhead increases significantly

Engineering Contradiction:
Improvedata confidentialityVSAvoidcomputational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an obfuscation computing system as an intermediary component between user computing systems and HPC nodes. This intermediary performs code-level and system-level obfuscation to protect data confidentiality without requiring traditional encryption of all data, thereby reducing computational overhead while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security approach from traditional encryption parameters to obfuscation parameters. By transforming commands, system management tasks, and network traffic through obfuscation rather than encryption, the system achieves data protection with significantly lower computational cost, as obfuscation operates on information entropy rather than cryptographic key operations.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If HPC resources are shared among multiple users, then resource utilization is improved, but security threats increase

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity threats
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The obfuscation computing system acts as a mediator between multiple users accessing shared HPC resources. It intercepts and obfuscates commands and data before they reach the nodes, preventing unauthorized users from snooping or modifying each other's data while allowing seamless resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the HPC system into user computing systems, an obfuscation computing system, and HPC nodes. This segmentation isolates security functions from computational functions, allowing multiple users to share resources while the obfuscation layer prevents security threats between them.

Inventive Principle:
Principle #1Segmentation

3Reliability

If code-level obfuscation is performed, then data confidentiality is improved, but system complexity increases

Engineering Contradiction:
Improvedata confidentialityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The obfuscation computing system is positioned as an intermediary layer that handles code-level obfuscation. By separating obfuscation logic from the HPC nodes and user systems, the patent manages system complexity - the intermediary absorbs the complexity of obfuscation transformations while presenting simplified interfaces to both users and nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11461477B1Obfuscation for high-performance computing systems
Publication Date: 2022.10.04 ARCHITECTURE TECH CORP
  • US11461477B1 patent drawing
  • US11461477B1 patent drawing
  • US11461477B1 patent drawing

AI summary

An example method includes initializing, by an obfuscation computing system, communications with nodes in a distributed computing platform, the nodes including one or more compute nodes and a controller node, and performing at least one of: (a) code-level obfuscation for the distributed computing platform to obfuscate interactions between an external user computing system and the nodes, wherein performing the code-level obfuscation comprises obfuscating data associated with one or more commands provided by the user computing system and sending one or more obfuscated commands to at least one of the nodes in the distributed computing platform; or (b) system-level obfuscation for the distributed computing platform, wherein performing the system-level obfuscation comprises at least one of obfuscating system management tasks that are performed to manage the nodes or obfuscating network traffic data that is exchanged between the nodes.