Remote Trust Domains for Secure RDMA I/O Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies do not provide a comprehensive solution for implementing confidential computing with remote devices, particularly in a disaggregated data center environment, where I/O devices and hosts supporting trust domains are located on different physical machines, and existing RDMA protocols do not ensure a trusted environment for secure data transfer.
Innovation Solution
The implementation of a TDX-IO architecture that extends trust domain extensions to remote devices by using secure communication protocols like SPDM and TDISP, along with RDMA protocols secured by DTLS or proprietary sRDMA, to establish and maintain trust relationships between remote I/O devices and trust domains, ensuring secure data transfer and confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If RDMA protocols are used for remote device communication, then data transfer speed is improved, but security and confidentiality are worsened because existing RDMA protocols do not ensure a trusted environment
Solution Approach 1:
The patent introduces a remote device service trust domain as an intermediary between the RDMA protocol and remote devices. This trust domain acts as a mediator that provides attestation capabilities, verifying the identity and trustworthiness of remote devices before allowing data transfer. The trust domain includes a trust domain manager that handles authentication and establishes secure communication channels, thereby maintaining both high-speed data transfer and enhanced security through this intermediate layer.
2Reliability
If trust domain extensions are extended to remote devices in disaggregated data centers, then security is improved, but system complexity is worsened due to the need for additional trust establishment protocols
Solution Approach 1:
The patent creates a universal remote device service trust domain that can serve multiple remote devices and multiple trust domains across the disaggregated data center. This single trust domain structure provides multi-functional capabilities including authentication, attestation, and key management for various device types and communication protocols. By consolidating these security functions into a universal trust domain rather than implementing separate security mechanisms for each device, the system achieves comprehensive security coverage while reducing overall system complexity.
Data Source
AI summary
Examples include techniques to implement confidential computing with a remote device via use of trust domains. Examples are described of establishing secure communication sessions between a trust domain supported by a hardware processor core on a first host platform and an input/output (I/O) device resident on a second host platform.


