Programmable Integrated Circuit as Remote Trust Anchor for Multitenancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-tenant programmable logic devices face challenges in securely managing and validating encrypted intellectual property (IP) among tenants, as existing solutions require plaintext access and lack assurance that cloud service providers enforce multitenancy rules correctly, especially when dealing with third-party IP.

Innovation Solution

A modular multitenancy secure system architecture is implemented, where a programmable integrated circuit acts as a remote trusted anchor, enabling secure partial reconfigurations and enforcing valid instantiations within self-contained execution units, allowing for parallel workload execution and supporting third-party encrypted IP, while reducing trust requirements on cloud service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a software constraint checker is used to validate bitstreams, then multitenancy rules can be enforced, but plaintext access is required which compromises security for encrypted IP

Engineering Contradiction:
Improvemultitenancy rule enforcementVSAvoidplaintext access requirement
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a hardware-based constraint validation mechanism that acts as an intermediary between the cloud service provider and the tenant bitstreams. This hardware validator processes encrypted bitstreams without requiring plaintext access, validating multitenancy rules while maintaining encryption. The hardware intermediary resolves the contradiction by enabling rule enforcement without compromising the security benefit of encrypted IP.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the cloud service provider manages multitenancy, then resource sharing is enabled, but trust assumptions are required between tenants and provider

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidtrust assumption
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements self-service multitenancy management where the programmable logic device autonomously validates and enforces multitenancy rules through hardware-based constraint checking. The device independently manages tenant isolation and resource allocation without requiring continuous trust in the cloud service provider's software constraint checker. This self-service approach enables resource sharing while eliminating the need for trust assumptions between tenants and provider.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If partial reconfiguration is used for multitenancy, then flexible resource allocation is achieved, but isolation between tenants becomes difficult to maintain

Engineering Contradiction:
Improveresource allocation flexibilityVSAvoidtenant isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the programmable logic device into distinct configuration regions, each dedicated to specific tenants or workload types. This physical segmentation through hardware constraint validation ensures that partial reconfigurations for different tenants occur in isolated regions, maintaining strict tenant isolation while preserving the flexibility of partial reconfiguration for resource allocation. The segmentation approach resolves the contradiction by enabling flexible allocation within secure boundaries.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240314213A1Programmable integrated circuit configured as a remote trust anchor to support multitenancy
Publication Date: 2024.09.19 INTEL CORP
  • US20240314213A1 patent drawing
  • US20240314213A1 patent drawing
  • US20240314213A1 patent drawing

AI summary

A multitenancy system that includes a host provider, a programmable device, and multiple tenants is provided. The host provider may publish a multitenancy mode sharing and allocation policy that includes a list of terms to which the programmable device and tenants can adhere. The programmable device may include a secure device manager configured to operate in a multitenancy mode to load a tenant persona into a given partial reconfiguration (PR) sandbox region on the programmable device. The secure device manager may be used to enforce spatial isolation between different PR sandbox regions and temporal isolation between successive tenants in one PR sandbox region.