SmartNIC Zero-Trust Authentication for RDMA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-based access control mechanisms for RDMA communications are inadequate for implementing zero-trust security policies, as they are tied to network locations and struggle with scalability and granular control, especially in environments with multiple connections and diverse access control policies.

Innovation Solution

The implementation of zero-trust authentication and policy enforcement capabilities within SmartNICs, which leverage programmable Smart Network Interface Cards to apply fine-grained, application-dependent policies on a connection-by-connection basis, using application-level attributes to control RDMA connections and data packets without requiring changes to existing RDMA applications or protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network-based access control mechanisms are used for RDMA communications, then implementation is straightforward using existing infrastructure, but they are tied to network locations and cannot provide granular application-level control

Engineering Contradiction:
Improveease of implementationVSAvoidgranular control capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the access control mechanism into two parts: network-level identification (GID, QPN) and application-level attributes (application ID, security credentials, performance parameters). This segmentation allows the system to maintain simple network-based routing while adding granular application-level control through the identity table and attribute association, resolving the contradiction between ease of implementation and granular control capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an identity table as an intermediary data structure that maps network identifiers (GID, QPN) to application-level attributes. This intermediary layer enables the system to translate simple network-based access control into granular application-aware policies without requiring changes to the underlying RDMA protocol or network infrastructure, thus maintaining ease of operation while achieving fine-grained control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If fine-grained application-dependent policies are applied to each RDMA connection, then security and control are improved, but policy management complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-populating the identity table with application-level attributes and security credentials before RDMA connections are established. This allows the SmartNIC to automatically retrieve and enforce appropriate policies during connection setup without requiring complex real-time policy decisions, thereby improving security control while reducing policy management complexity during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing applications to register their own attributes and security credentials in the identity table during initialization. This self-registration mechanism reduces the burden on centralised policy management systems, as applications autonomously provide their own policy parameters, simplifying overall policy management while maintaining fine-grained security control.

Inventive Principle:
Principle #25Self-service

3Reliability

If application-level attributes are tracked and enforced for RDMA connections, then zero-trust security is achieved, but processing overhead and system complexity increase

Engineering Contradiction:
Improvezero-trust securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex application-level attribute management functionality from the main RDMA processing path and places it in a separate identity table structure. This extraction allows the SmartNIC to maintain simple, high-speed RDMA packet processing while offloading attribute lookup and policy enforcement to dedicated hardware resources, thereby achieving zero-trust security without significantly increasing overall system complexity or processing overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If existing RDMA applications and protocols are modified to support zero-trust authentication, then fine-grained control is achieved, but compatibility and ease of deployment are reduced

Engineering Contradiction:
Improvefine-grained controlVSAvoidease of deployment
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent uses the identity table as an intermediary that sits between existing RDMA applications/protocols and the zero-trust authentication mechanism. This intermediary approach allows the system to enforce fine-grained application-level control policies without modifying any existing RDMA application code or protocol specifications. The SmartNIC transparently intercepts RDMA packets, looks up application attributes in the identity table, and enforces policies, thereby achieving adaptability while maintaining ease of deployment through backward compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12113859B2Zero-trust authentication for secure remote direct memory access
Publication Date: 2024.10.08 NOKIA SOLUTIONS & NETWORKS OY
  • US12113859B2 patent drawing
  • US12113859B2 patent drawing
  • US12113859B2 patent drawing

AI summary

Various example embodiments for supporting zero-trust policy enforcement in a communication system are presented herein. Various example embodiments for supporting zero-trust policy enforcement in a communication system may be configured to support zero-trust policy enforcement, including zero-trust authentication, for Remote Direct Memory Access (RDMA) communications. Various example embodiments for supporting zero-trust policy enforcement for RDMA communications may be configured to support transparent zero-trust policy enforcement for RDMA communications by leveraging programmable Smart Network Interface Cards (SmartNICs). Various example embodiments for supporting zero-trust policy enforcement for RDMA communications based on leveraging of programmable SmartNICs may be configured to support zero-trust policy enforcement for RDMA communications by applying zero-trust policies on a connection-by-connection basis within SmartNICs for RDMA connections between RDMA applications hosted on end hosts served by the SmartNICs.