Smart NIC Secure Channels for Disaggregated Hardware Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Disaggregated hardware in data centers lacks a secure data transmission mechanism, leaving hosts vulnerable to malicious attacks due to the breakdown of the trusted computing environment.
Innovation Solution
Implementing an initiator host with a smart network interface card (SNIC) equipped with a trust platform module (TPM) and security engine to establish a secure data channel with a target host's SNIC, using cryptographic key pairs and security engines to authenticate and encrypt data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If disaggregated hardware devices are made accessible from different applications executing in different hosts, then resource utilization efficiency and adaptability are improved, but the trusted computing environment breaks down and security against malicious attacks deteriorates
Solution Approach 1:
The patent introduces Smart Network Interface Cards (SNICs) as intermediary devices between applications and disaggregated hardware. Each SNIC includes a TPM that acts as a mediator to establish secure channels, authenticate devices, and protect data transmissions. This intermediary layer enables resource sharing across hosts while maintaining security boundaries, resolving the contradiction between accessibility and trustworthiness.
Solution Approach 2:
The patent segments the trusted computing environment by assigning individual TPMs to each SNIC and disaggregated hardware device. This segmentation creates isolated security zones that can be individually authenticated and secured, allowing resources to be shared across hosts while maintaining distinct security boundaries for each participant in the disaggregated architecture.
2Reliability
If conventional TPM approaches are applied to disaggregated hardware devices, then security protection is improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent merges the TPM functionality directly into the network interface card, creating a unified Smart Network Interface Card that combines networking capabilities with security functions. This integration simplifies the overall system architecture by eliminating separate TPM hardware components and reducing the complexity of managing distributed TPMs across multiple hosts and devices.
3Reliability
If secure data channels are established between all hosts and disaggregated hardware devices, then security against malicious attacks is improved, but communication overhead and system complexity increase
Solution Approach 1:
The patent implements preliminary authentication and secure channel establishment through the SNIC's TPM before data transmissions begin. The TPM pre-establishes cryptographic credentials and secures communication channels in advance, so that subsequent data transmissions between applications and disaggregated hardware occur over already-secured pathways, reducing the overhead of repeated security handshakes.
Data Source
AI summary
This disclosure is directed to methods and systems that establish a secure data channel between a host and a disaggregated hardware device (“DHD”) of a data center. The system comprises an initiator host that runs objects, such as virtual machines and containers. The host includes an initiator smart network interface card (“SNIC”). The initiator SNIC includes a virtual device, a trust platform module (“TPM”) and a security engine. The system also comprises a target host equipped with a DHD and a target SNIC. The target SNIC includes a TPM and a security engine. The TPM and the security engine of the initiator SNIC and the TPM and the security engine of the target SNIC establish a secure data channel between an object running on the host and the DHD.


