Smart NIC Secure Channels for Disaggregated Hardware Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Disaggregated hardware in data centers lacks a secure data transmission mechanism, leaving hosts vulnerable to malicious attacks due to the breakdown of the trusted computing environment.

Innovation Solution

Implementing an initiator host with a smart network interface card (SNIC) equipped with a trust platform module (TPM) and security engine to establish a secure data channel with a target host's SNIC, using cryptographic key pairs and security engines to authenticate and encrypt data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If disaggregated hardware devices are made accessible from different applications executing in different hosts, then resource utilization efficiency and adaptability are improved, but the trusted computing environment breaks down and security against malicious attacks deteriorates

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidtrusted computing environment
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces Smart Network Interface Cards (SNICs) as intermediary devices between applications and disaggregated hardware. Each SNIC includes a TPM that acts as a mediator to establish secure channels, authenticate devices, and protect data transmissions. This intermediary layer enables resource sharing across hosts while maintaining security boundaries, resolving the contradiction between accessibility and trustworthiness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the trusted computing environment by assigning individual TPMs to each SNIC and disaggregated hardware device. This segmentation creates isolated security zones that can be individually authenticated and secured, allowing resources to be shared across hosts while maintaining distinct security boundaries for each participant in the disaggregated architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional TPM approaches are applied to disaggregated hardware devices, then security protection is improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the TPM functionality directly into the network interface card, creating a unified Smart Network Interface Card that combines networking capabilities with security functions. This integration simplifies the overall system architecture by eliminating separate TPM hardware components and reducing the complexity of managing distributed TPMs across multiple hosts and devices.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If secure data channels are established between all hosts and disaggregated hardware devices, then security against malicious attacks is improved, but communication overhead and system complexity increase

Engineering Contradiction:
Improvesecurity against malicious attacksVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication and secure channel establishment through the SNIC's TPM before data transmissions begin. The TPM pre-establishes cryptographic credentials and secures communication channels in advance, so that subsequent data transmissions between applications and disaggregated hardware occur over already-secured pathways, reducing the overhead of repeated security handshakes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12537667B2Methods and systems for using smart network interface cards to secure data transmission between an initiator host running an object and a target host equipped with a disaggregated hardware device that satisfies hardware specifications of the object
Publication Date: 2026.01.27 VMWARE INC
  • US12537667B2 patent drawing
  • US12537667B2 patent drawing
  • US12537667B2 patent drawing

AI summary

This disclosure is directed to methods and systems that establish a secure data channel between a host and a disaggregated hardware device (“DHD”) of a data center. The system comprises an initiator host that runs objects, such as virtual machines and containers. The host includes an initiator smart network interface card (“SNIC”). The initiator SNIC includes a virtual device, a trust platform module (“TPM”) and a security engine. The system also comprises a target host equipped with a DHD and a target SNIC. The target SNIC includes a TPM and a security engine. The TPM and the security engine of the initiator SNIC and the TPM and the security engine of the target SNIC establish a secure data channel between an object running on the host and the DHD.