Shadow Tenant Bucket for FPGA Acceleration Engine Image Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current uniform storage and management of Acceleration Engine Images (AEIs) in FPGA accelerated cloud servers pose security risks as they are not user-specific, leading to potential unauthorized access and data leakage.

Innovation Solution

Implementing a data management method that utilizes shadow tenant buckets, where each user has a dedicated storage space associated with a unique identifier, ensuring that AEIs are stored and managed securely, with permission-based access control and asynchronous resource release mechanisms to prevent data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If uniform storage and management of AEI is implemented, then storage simplicity is improved, but security deteriorates due to potential unauthorized access and data leakage

Engineering Contradiction:
Improvestorage simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the uniform storage space into multiple shadow tenant buckets, each dedicated to a specific user. This segmentation isolates user data while maintaining centralized management, resolving the contradiction between storage simplicity and security by organizing storage space into user-specific segments that are easier to manage and protect individually.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different storage qualities to different users by creating shadow tenant buckets with unique identifiers for each user. Each bucket has localized access control policies, allowing simplified management at the system level while providing enhanced security at the user level through differentiated storage characteristics.

Inventive Principle:
Principle #3Local quality

2Reliability

If shadow tenant buckets are created for each user, then security is improved through isolation, but device complexity increases due to additional management overhead

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by automatically creating shadow tenant buckets and assigning unique identifiers to users before data storage occurs. This preliminary setup eliminates the need for complex manual configuration during data management operations, reducing management overhead while maintaining security through pre-established isolation boundaries.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service mechanisms where shadow tenant buckets automatically manage their own isolation and access control based on user identifiers. The buckets self-organize and enforce security policies without requiring external intervention for each access decision, reducing management complexity while maintaining strong security boundaries.

Inventive Principle:
Principle #25Self-service

3Reliability

If permission verification is performed for each AEI access, then security is improved, but processing time increases

Engineering Contradiction:
Improveaccess control securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs permission verification in advance by establishing access rules and shadow tenant bucket associations before data access operations. This preliminary permission setup allows the system to quickly determine access validity during actual data operations, reducing processing time while maintaining security through pre-validated access control policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3848802B1Data management method and apparatus, and server
Publication Date: 2024.10.30 HUAWEI TECH CO LTD
  • EP3848802B1 patent drawingFigure 1
  • EP3848802B1 patent drawingFigure 2
  • EP3848802B1 patent drawingFigure 3

AI summary

This application provides a data management method and apparatus, and a server. The method includes: receiving, by a management server, a first request; determining, based on an identifier of a first user in the first request, whether a shadow tenant bucket associated with the identifier of the first user exists; and if the shadow tenant bucket associated with the identifier of the first user exists, storing, in the shadow tenant bucket associated with the identifier of the first user, an acceleration engine image AEI that the first user requests to register, where a shadow tenant bucket is used to store an AEI of a specified user, and each shadow tenant bucket is in a one-to-one correspondence with a user. In this way, security of storage of the AEI is improved.