AI-Driven Hardware-Enabled Platform Security | The Six Five Summit
Residing in the lowest layer of the hardware stack and integrating all security functions within a single SoC or module, the Axiado TCU effectively acts as a “last line of defense,” even when all other network functions have been compromised. The TCU detects and stops ongoing attacks and recovers the system from an attack with AI intelligence.
Transcript
Hi, my name is Gopi and Gopi Sirini, president and CEO of Company ero. We are a cybersecurity hardware company. We make chips and also the cards and to data centers, networking market.
We're around a hundred people company in 5-year-old, and we are complying through pretty much every standard in the market, uh, headquarters in San Jose, in offices, in Hyderabad, in India, and also Taiwan. What are we solving? There is a big problem of ransomware in the market.
What is a ransomware? Ransomware is nothing but somebody. Bad actor came into your system, however, the way he came into it, and he takes over your system as a super user and asks for ransom.
R he encrypts your hard disk and looks for game. In both cases, he's touching the most of the hardware systems, hardware controller and management side present solutions, all of them. 99% of the companies, if not, uh, hundreds or thousands, all of them are addressing to protect at the port of entry of the system means bad actor coming into your system, whether it's a kernel level, whether firmware level, they're trying to protect that report of entry.
What we do, we are complimentary to that even after the port of entry is not able to stop it. And we are the last line of defense standing at the platform and which is last line of defense. The bad actor coming to us, we just talked about to the hardware platform or hard disk.
That's where we detect and protect, right? While it is happening, not after the fact, today's most of the software solutions are after the fact something happened. We can detect and stop.
That's the company back. There are trillions of dollars spent on this one, and I don't need to belabor these numbers. So in these conditions, what happened just afterward, attacks.
If there isn't a ransomware attack, unfortunately there is no recovery. If you care about the content and a platform, you had to pay the money to the guy and you got the system back. Once you got the system back, unfortunately this was a super user attack and you don't know what exactly happened, how the bad actor came in.
So the 99% of the times you had to throw away the whole system. And then not only the productivity, last system cost, the replacement cost, all that money happens and there's, as we talked about, there is no forensic data. How we came in so that these systems cannot be protected in the future on whatever the way these guys came in, because you don't have a data after even recovery.
There is a lot of delayed patch. You have to file to the federal government and everybody has to be aware of what exactly happened or some level of that, and you had to share with everybody, with all that information to come to every person. Let's say there's an attack happen, an ex company for me to be as a CISO to knowing that company happened, the reporting process and all that takes around 90 days and I will know the attack type in 90 days as a CISO for my company, but the patches and everything, it takes another 90 days for it to fix.
It means I'm vulnerable for close to 180 days, uh, or more. Present solutions are all piecemeal and discreet and the only solution something in the market today is against, these are called zero, zero trust. These zero trust means that you don't trust the application or any platform.
Every time you run an application, you want to be tested again, authenticated again. Unfortunately, if there is your so-called root of trust or main key itself is compromise. Doesn't matter how many times you ask as a zero trust model, you'll be able to answer bad actor.
It will be able to answer. That's where we come into the picture. We make that so-called hardware, root of trust, true immutable hardware, root of trust.
Make sure that that's protected high. That's where our company comes into and we are a complimentary, again, we're complimented to every solution in the market. Palo Alto, the world, CrowdStrike, the word snowflake, the word we are complimentary to that.
Here is a pictorial view of the pay, you know, uh, what we do. And because we end of the day, we make silicon cards. If you look on the left side, uh, there are pay attention to my cursor.
Uh, there are network ports and also the management ports just to give the history. com, a cloud will, you know, do a mapping name mapping. ERO will come convert you to this firewall, and you come to the data, uh, particular server through that network port for the last decade or so, firewall is proven to be not enough security or it's a perimeter security only.
Then everybody in the industry decided to, uh, create something called DPU on the data port, and that's, that's the DPA, you know, deep packet inspection, et cetera, to protect those data ports in the world of already accepted on this DPU, let's focus on the management port. Those management ports used to be only on intranet only means your IT guy is sitting within the house, within the building, within the premises, within the intranet subnet itself. But the world changed for last after decade to a little more than that, and especially pandemic mean more that your IT guy is also on the cloud now and he's also coming through the same firewall or similar firewall technology.
Our premises of company is simple. If the world accepted the firewall is not good enough security to be network ports protection and we created another DPU in there, how in the world we are okay with a management port, which is more sacred for you to be exposed to the same firewall technology and pray God that it will take care of itself. You need A-A-D-P-U LIFE device on the control and management side.
That's where we come into picture. Our product is called trusted control and compute units called TC. We do similar of DPU functions, but a lot more because this is a key key management attestation, all that stuff works today.
You see that there are discrete components who addressing this solution today, I won't say solving, but addressing uh, TPM trusted platform module. You see the red dots on the left side picture, BMC, baseboard management controller, A ROT, root of trust, Landon Motherboard and possibly a PGN firmware combination. All these chips comes from a different companies and these are all on the motherboard.
If there is an attack happens, you have to get the patch from all of these guys. And this is a old school legacy at a bandaid solution. As a ro, we came up with a company TCU.
We integrate functionally all these five or full chips and a plus the PG combination plus the ware into a single chip as a TCU. We also work with the industry standard, the open compute platform guys, everybody logos are enlist here. All of these guys are, you know, advocated to a modular management.
Nick, similar to the data Nick, you need a management nick that's called now D-C-S-C-M Data Center Secure control module. And you can see the right side picture, that's Intel based DC SCM. You can see that's double stack, uh, card itself.
And now our card is smaller. You can see in there functionally we integrated. I'll jump to the image of that and come back in here.
So if you look at this is what the present card looks like and which is double stacked and bigger in physical comparison to the scale, you can see how our, how our card looks. That's our chip where one third the power, one third the size, but 20 x powerful on a computing plus I AI engines on top. I'll talk about the AI engines.
What we solve going into, jumping back to what problem we are solving, we give a platform security, I'll talk about the ai, how we do with that and how we protect against side channel attacks, supply chain attacks, ransomware attacks, image manipulation attacks and infiltration attacks and lifecycle management. All that stuff will do, will go through that. So we make a platform security because we, we residing on the platform physically not the cloud-based.
We can still authenticate through the cloud HSM, but we are on the platform at the boot time at the run and network security, the ethernet ports on the control and management port. What is exposed behind the firewall today? Unfortunately there is no firewall security we have in a hardware firewall.
Security booster by AI able to detect even insider attacks means your IT guy turns into the bad actor. I'll be able to detect that based on the behavior and learnings and what the behavior, what he's touching, how that attacks are coming and all that we'll be able to detect. That means we're the only company in the market today can tell you that where there is no physical security we'll be able to detect based on what's happening there and then you can put the rules engine on top as a system vendor, whether you wanna stop or just collect the forensic data, boot time security today when it's booting up.
Uh, today's BMC and every other solution is a dumb CPUs that was meant for done for 25 years ago. Uh, when they're booting up itself, there's hackers are becoming smarter. They share these things to be outside and how you manipulate the image, how are you able to give a side channel glitches, et cetera.
But you need an intelligent processor, intelligent technology to be able to accelerate the computing level. So we have a AI driven B time security. We're able to monitor every single on the board, every attestation a contextual awareness.
We know based on that we can detect that. And then all that zero zero trust, uh, security provided by everybody else. We become an authentication attestation for that, making it a true zero trust on that.
And operational security lifecycle management. Anytime these devices, every platform has a social security number type, which is the trustee manufacturing time it was programmed and that's is for the management of lifecycle. Pretty much that is used for authentication of your system every time.
The problem it is, it's, it's uh, programmed by somebody at a manufacturing time. It's not trustworthy completely. And every deployer CSP cloud service products wanted another level of lifecycle management ownership transfers.
We have a proprietary way of doing it. Paid algorithm with a secure way how we can do the operational device cycle management. Ransomware attacks, as I talked about, ransomware attack is nothing but somebody checking a hardware over.
We trained our AI engine completely going through the existing CVU database reported uh, vulnerability dissolve of them and we collect the hardware, traces, the datasets. How does the bad actor look in each attack in a hardware traces that's trained to our AI engine and it's able to detect any time that kind of blacklister pattern is happening and we'll be able to stop that. Again, there's nobody can do this today and it continues to be learnable means we can teach more, update these models.
We do the inferencing on the chip and collect at the cloud and then able to do the models training on the cloud and push it back. So this is the ship inferencing for us and it has the neural engines inside. So anything of so-called, you know, there is no true zero day attack.
We should be able to learn based on the what is being trained already and predict something close to that and based on the neurals and we could stop more than what has been already trained. Can I say a hundred percent? Obviously nobody can say that, but we're much better than the human trying to do a a logical engines or software doing it versus a neural engine doing it here.
That accelerator computing advantage has been used in here. So we can do the last two of them. Dynamic thermal management and lack rack level.
If we are on each blade or each server on a rack, we have a proprietary rack level management that we, if one person detects something, you know, one blade detects something happened bad in an anomaly detection, it's able to share between the full rack and we can detect through the to share through the network switches. Top OFAC switches are firewall based in that we can detect everybody. You can isolate.
So every CISO would allow to have this to detection and isolation normally takes close to 30 to 40 days. We can do it in 30 to 40 seconds. Okay, and the last one is the dynamic thermal mini today whole rack.
If you know the POE total dollar spent more than 50 cents or 45 cents has spent on the power management of the rack and the whole server itself. We are all the server fan controls and thermal management happens based on the a sensor thermal sensor. Today we can add on top of the thermal sensor based on the load management.
We can change the fans and fan controls this way. We presented in one of the, one of the, uh, forums recently and it's public data. We can get around 18 plus percent of PUE efficiency in that this should save a lot of money for the overall CSO deployment.
With that said, uh, I will leave it to these, uh, we have a multiple different form factor cards you can see on the left side. This is, uh, we showed at A GTC conference. These are Nvidia IFF internal form factor card on the left side of the right version.
That's for all Nvidia MDH platforms and further. And we contributed the second card, which we showed 3001 that's contributed to OCP. It's available for anybody to download and uh, implement themself.
And uh, third one, which is 3002 in here and that's a standard D-C-S-C-M horizontal card that's available. You can swap an existing systems with this and uh, 3003 is the smallest form factor card for us. What I showed a comparison, uh, that's functionality was everybody does exactly the same thing.
It's a different form factor. The last one, not the least, uh, customers came up and asked for their PCI based card also. So this is being used as the a data security completely all the way to the edge system.
Whether it's a medical iot, industrial iot, just FAP the plugin card. We will provide the security all the way to the end. Uh, we're working with all the companies on the top able to get their security expansion software all the way to the edge device.
Uh, finally to summarize, what we do is we give a forensic data, which is not available today by anybody and we can detect the anomaly and isolation within 30 to 40 seconds compared to 30 to 40 days. We can do the key management and ownership provisioning. This will help us the modularity and also sharing the systems and reusability and also shifting one to other for co-locate data center guys, resiliency as we talked about, we can recover, we can update these models and it's a future proof.
Uh, it's an AI models which is can be attest, you know, runtime to also, we can work through that. That means it's future, uh, enabled proof. I won't say a hundred percent, but we can make a lot better than what is today qua.
And we talked about thermal management that we can give you a lot of POE improvement. So thank you. If you need to learn more about it, you can reach out to us or you know, send us email, reach us at any of the forums, meetings, conferences, uh, reach out to me and my number.
I'll leave it there. Here we don't have a direct competition in the market today. It's all discreet components and most of the NIH type, you know, everybody's built their own solutions.
Everybody believes that they have their own solution. But until we prove, uh, plugin card swapping to show our value and they can see so far has been our customers or partners have been great. They see a value will continue to work and we're looking for, uh, more customers obviously.
And also we are hiring be part of the industry changing technology. Please do reach out to us. Thank you.


