Secure AI Cloud Cluster Using SMC DPUs for Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities face risks of public disclosure of confidential and proprietary information when using cloud-based generative AI services, which can prevent them from utilizing these services for business purposes.

Innovation Solution

A new network architecture for secure AI computing is proposed, utilizing secure, multi-core (SMC) data processing units (DPUs) with gateways that ensure a secure interface through encryption, along with high-speed interconnects and secure AI cloud clusters to protect client data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If entities use cloud-based generative AI services, then they can access advanced AI capabilities and productivity benefits, but their confidential and proprietary information may be publicly disclosed

Engineering Contradiction:
Improveaccess to AI servicesVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the AI computing environment into isolated containers or virtualized instances, where each entity's data and processing operations are separated from others. This segmentation prevents cross-contamination and public disclosure while maintaining access to shared AI infrastructure, thus resolving the contradiction between productivity gains from cloud AI services and data security concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer (such as a secure gateway, encryption module, or trusted execution environment) between the entity's confidential data and the public AI platform. This intermediary protects sensitive information during transmission and processing, enabling entities to utilize cloud-based AI services without risking public disclosure of their proprietary information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If entities avoid public AI platforms to protect confidential information, then data security is maintained, but they cannot leverage generative AI services for business purposes

Engineering Contradiction:
Improvedata securityVSAvoidbusiness utility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent moves the interaction from a traditional public platform dimension to a new dimension of secure, private, or hybrid AI environments. By creating alternative access pathways (such as private cloud deployments, on-premises solutions, or secured API gateways), entities can maintain data security while still accessing generative AI capabilities for business purposes, thus resolving the contradiction between security and utility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If confidential information is entered into public AI platforms, then AI processing capabilities are utilized, but the information enters the public domain

Engineering Contradiction:
ImproveAI processing capabilityVSAvoidinformation secrecy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions to protect information before it enters the AI processing pipeline. This includes encrypting data prior to transmission, implementing access controls, and establishing secure communication channels. By preparing these protective measures in advance, entities can utilize AI processing capabilities without risking the secrecy of their confidential information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameters of information transmission and processing by applying encryption transformations, anonymization techniques, or differential privacy methods. These parameter changes modify the state of confidential information so that it can be processed by AI systems while maintaining secrecy, thus resolving the contradiction between adaptability to AI processing and preservation of information secrecy.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250148101A1Method and apparatus for cloud platform for secure artificial intelligence computing
Publication Date: 2025.05.08 MARVELL ASIA PTE LTD
  • US20250148101A1 patent drawing
  • US20250148101A1 patent drawing
  • US20250148101A1 patent drawing

AI summary

A new approach is proposed that contemplates system and method to support a new network architecture for secure AI computing based on one or more secure, multi-core (SMC) data processing units (DPUs). Each of the SMC DPUs includes a gateway that ensures a secure interface and operating environment for the SMC DPU through encryption. Each of the SMC DPUs may further include a microprocessor core, one or more general purpose processing units (XPU cores) and/or customized processing units (CXPU cores), and a communications interface (COMM I/F) to external memories and other processing units. In some embodiments, a secure AI cloud cluster is constructed using multiple SMC DPUs along with one or more of switches, memories, separate XPUs, and high-speed interconnects (including optical interconnects) to ensure protection of client data for cloud-based AI services.