Virtual Data Processing Accelerator Key Sharing via Switch
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data processing accelerators (DPAs) cannot securely communicate with each other, which is essential for cooperative data processing tasks, as existing technologies lack secure communication protocols to prevent unauthorized alteration or data theft.
Innovation Solution
Implementing a method where a host device and virtual data processing accelerators (VDPs) establish unique session keys for secure communication channels, ensuring that each VDP can securely communicate with the host and other VDPs through a switch, using virtual communication channels with distinct session keys for each pair of endpoints, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If Data Processing Accelerators communicate with each other to perform cooperative data processing tasks, then productivity and processing capability are improved, but security and reliability deteriorate because existing technologies lack secure communication protocols
Solution Approach 1:
The patent segments the communication system into virtual channels, with each channel having its own dedicated session key. This segmentation allows multiple DPAs to communicate simultaneously while maintaining individual security boundaries, preventing unauthorized access between different communication streams.
Solution Approach 2:
The patent changes the security parameter by implementing unique session keys for each virtual channel and endpoint pair. This parameter change transforms the communication from insecure to secure by introducing cryptographic protection at the channel level without affecting the underlying physical communication infrastructure.
2Reliability
If unique session keys are established for each virtual communication channel between DPAs, then communication security is improved, but device complexity increases due to key management requirements
Solution Approach 1:
The patent implements self-service key management where each DPA autonomously generates and manages its own session keys for virtual channels. The host device facilitates initial key establishment but does not centrally manage all keys, allowing DPAs to independently secure their communications without requiring complex centralized key distribution infrastructure.
Solution Approach 2:
The host device acts as an intermediary that facilitates initial key establishment between DPAs and the switch infrastructure. The host helps set up the secure communication framework by establishing virtual channels and initiating key exchange, but the actual security management is distributed to the endpoint devices.
3Reliability
If virtual communication channels with distinct session keys are implemented for each endpoint pair, then security against unauthorized access is improved, but loss of information increases due to potential key distribution errors
Solution Approach 1:
The patent performs preliminary key establishment actions during the virtual channel setup phase, before actual data transmission begins. Session keys are generated and distributed in advance through the host device, ensuring that secure communication pathways are ready and verified before sensitive data exchange occurs, preventing key distribution errors during active communication.
Data Source
AI summary
A host processing device instructs a plurality of virtual data processing (VDP) accelerators, configured on each of a plurality of data processing accelerators. The VDP accelerators configure themselves for secure communications. The host device generates an adjacency table of each of the plurality of VDP accelerators. Then the host device then establishes a session key communication with each VDP accelerator and sends the VDP accelerator a list of other VDP accelerators that the VDP accelerator is to establish a session key with, for secure communications between the VDP accelerators. The VDP accelerator establishes a different session key for each pair of the plurality of VDP accelerators. When all DP accelerators have established a session key for communication with other VDP accelerators, according to the respective list of other VDP accelerators sent by the host device, then the host device can assign work tasks for performance by a plurality of VDP accelerators, each communicating over a separately secured virtual communication channel.


