Static Resource Partitioning for Data Processing Accelerator Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data processing accelerators, such as AI accelerators, lack effective partitioning and isolation, allowing malicious entities to access sensitive data and models through communication channels, compromising security.

Innovation Solution

Implementing statically partitioned resources and virtual functions within data processing accelerators, where each virtual machine is assigned a dedicated virtual function to access specific resources, ensuring no access to other resources, and using resource management units for dynamic updates to meet request sizes, while employing SR-IOV and TPM-based secure boot for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If communication channels are enabled between DPAs for data processing operations, then productivity and data processing capability are improved, but security and data protection deteriorate as malicious DPAs can access sensitive AI models and data from other DPAs

Engineering Contradiction:
Improvedata processing capabilityVSAvoiddata protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the DPA system into isolated execution environments using secure enclaves or containers. Each DPA instance operates within its own segmented environment that prevents unauthorized access to other DPAs' memory spaces, AI models, and data, while still allowing controlled communication through secure channels for collaborative data processing tasks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted execution environment or secure intermediary layer that mediates all communication between DPAs. This intermediary verifies and controls data exchanges, ensuring that sensitive AI models and proprietary data remain protected while enabling necessary communication for data processing operations through authenticated and encrypted channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If resource sharing is implemented among multiple DPAs to improve utilization efficiency, then productivity is improved, but security and isolation between DPAs deteriorate, allowing malicious entities to obtain unauthorized access to AI models and data

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidunauthorized access to sensitive data
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments shared resources into isolated virtualized resource pools, where each DPA can access allocated resources through controlled interfaces. This segmentation allows efficient resource sharing while maintaining strict boundaries that prevent malicious DPAs from accessing or corrupting other DPAs' allocated resources, AI models, and data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality control by providing each DPA with customized security policies and access controls tailored to its specific resource allocations. This allows different security levels and access permissions for different resource types, enabling efficient sharing while maintaining appropriate isolation and protection for each DPA's sensitive assets.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11822964B2Data protection with static resource partition for data processing accelerators
Publication Date: 2023.11.21 BAIDU USA LLC
  • US11822964B2 patent drawing
  • US11822964B2 patent drawing
  • US11822964B2 patent drawing

AI summary

Embodiments of the disclosure discloses a method and system for a virtualization environment for a data processing (DP) accelerator. In one embodiment, a data processing (DP) accelerator includes one or more statically partitioned resources and one or more virtual functions (VFs) each associated with one of the one or more statically partitioned resources. A virtual machine (VM) of a host is assigned one of the one or more VFs to access the statically partitioned resources associated with the assigned VF. The VM has no access to the rest of the one or more statically partitioned resources of the DP accelerator.