Token-based authentication and access delegation for HW-accelerated telco cloud solution

Semih Ince, David Espès, Guy Gogniat, Renaud Santoro, Julien Lallet · 2022

Telecommunications networks evolve towards cloud computing. The vast deployment of heavy processing applications (e.g., AI/ML) in telco has introduced performance constraints. The recent emergence of FPGA-based clouds brings new opportunities for telco services to guarantee a good quality of service and performance. In a telco context as in a cloud context, security is critical. Telecom Operator (TO) privacy and data protection must be ensured in FPGA-based cloud solutions. First, the method used to remotely access the FPGA cloud must be secure. Then, each TO’s execution context has to be isolated to protect user privacy and confidentiality. For that, authorizations must be defined and access control policies need to be properly enforced. In this paper, an authentication and tokenized FPGA access delegation scheme adapted from OAuth 2 is described. This solution brings a new token-based approach for FPGA devices and proposes a secure access delegation protocol for the cloudification of 5G networks and beyond. The access token is a lightweight solution to securely share information and enforce access control inside a multi-user FPGA. The proposed solution allows a TO to securely share third party cloud resources with another TO subcontractor. The sharing process involves a Trusted Authority (TA) and works without the approval of the FPGA cloud owner. This mechanism and the associated FPGA environment reinforces the highly sought privacy and confidentiality in FPGA clouds. FPGA resource allocation and reconfiguration is achieved in 503 ms and is 37.8% faster when compared to the literature. Performance results show flexibility and cost efficiency for telco services.

Read the paper · More papers on PaperTik