Programmable Integrated Circuit as Remote Trust Anchor for Multitenancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multi-tenant programmable logic devices face challenges in securely managing and validating encrypted intellectual property (IP) among tenants, as existing solutions require plaintext access and lack assurance that cloud service providers enforce multitenancy rules correctly, especially when dealing with third-party IP.
Innovation Solution
A modular multitenancy secure system architecture is implemented, where a programmable integrated circuit acts as a remote trusted anchor, enabling secure partial reconfigurations and enforcing valid instantiations within self-contained execution units, allowing for parallel workload execution and supporting third-party encrypted IP, while reducing trust requirements on cloud service providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a software constraint checker is used to validate bitstreams, then multitenancy rules can be enforced, but plaintext access is required which compromises security for encrypted IP
Solution Approach 1:
The patent introduces a hardware-based constraint validation mechanism that acts as an intermediary between the cloud service provider and the tenant bitstreams. This hardware validator processes encrypted bitstreams without requiring plaintext access, validating multitenancy rules while maintaining encryption. The hardware intermediary resolves the contradiction by enabling rule enforcement without compromising the security benefit of encrypted IP.
2Adaptability or versatility
If the cloud service provider manages multitenancy, then resource sharing is enabled, but trust assumptions are required between tenants and provider
Solution Approach 1:
The patent implements self-service multitenancy management where the programmable logic device autonomously validates and enforces multitenancy rules through hardware-based constraint checking. The device independently manages tenant isolation and resource allocation without requiring continuous trust in the cloud service provider's software constraint checker. This self-service approach enables resource sharing while eliminating the need for trust assumptions between tenants and provider.
3Adaptability or versatility
If partial reconfiguration is used for multitenancy, then flexible resource allocation is achieved, but isolation between tenants becomes difficult to maintain
Solution Approach 1:
The patent segments the programmable logic device into distinct configuration regions, each dedicated to specific tenants or workload types. This physical segmentation through hardware constraint validation ensures that partial reconfigurations for different tenants occur in isolated regions, maintaining strict tenant isolation while preserving the flexibility of partial reconfiguration for resource allocation. The segmentation approach resolves the contradiction by enabling flexible allocation within secure boundaries.
Data Source
AI summary
A multitenancy system that includes a host provider, a programmable device, and multiple tenants is provided. The host provider may publish a multitenancy mode sharing and allocation policy that includes a list of terms to which the programmable device and tenants can adhere. The programmable device may include a secure device manager configured to operate in a multitenancy mode to load a tenant persona into a given partial reconfiguration (PR) sandbox region on the programmable device. The secure device manager may be used to enforce spatial isolation between different PR sandbox regions and temporal isolation between successive tenants in one PR sandbox region.


