Mechanism · Network taps and certifiers
Technical detail
On this page
Secure Gateway Device (SeGaDev) 1:
- Placement. The device sits on the north-south boundary, between TLS termination at the frontend gateway and the internal fabric. If traffic is end-to-end encrypted internally, the device hashes ciphertext and the prover stores session keys 1.
- Pipeline. (1) Sanitization by an active warden, which replaces exploitable header fields (ephemeral source ports, TCP initial sequence numbers, session IDs) with pseudorandom values, keeps connection-tracking tables, and releases buffered packets on a fixed schedule to suppress timing and analogue modulation; (2) hashing of a configurable group of packets (the "hashing boundary") over payloads only; (3) transmission of hashes alone to the verifier on a dedicated fibre, with a passive splitter giving the prover a copy and a prover-controlled "timing warden" re-timing the hash stream 1.
- Shared randomness and timestamps. Shared pseudorandom values come from a commit-then-reveal coin flip between prover- and verifier-supplied generators, precomputed in bulk and consumed in FIFO order. Timestamps are taken by both parties on receipt of hashes, not by the tap 1 3.
- Audit. The verifier selects stored hashes; the prover returns preimages (prompt, output, token start index, token count) to a verification facility that replays the computation and compares hashes. With k random challenges, a misreported fraction p is detected with probability 1 − (1 − p)^k; k = 3,200 detects 0.1% misreporting at 96% confidence 1.
- Storage. A pessimistic upper bound (100k Hopper GPUs at 2,000 tokens/s each, one token per streaming frame) is about 200 PB of SHA-256 hashes and 1,260 PB of prover-held plaintext per year, about €22.5 million in drives 1.
- Dictionary attacks. Against verifier dictionary attacks on hashes of short outputs, the paper recommends at least 5 tokens per hashed template, or at least 10 if the attacker filters for likely tokens 1.
- Residual covert channels. A 10 ms re-timing window at 100 Gbps holds up to about 625k packets, so packet-count modulation must be fixed per connection per window. Output nondeterminism leaves about 0.1 bit per token even with seed-synchronized replay, which gives about 40 Mbit/s for 200k GPUs at 2,000 tokens/GPU/s. Feigned hardware failures give about 1 kbit/day 1.
- Line-rate hashing (Amodo). On an AMD EPYC 9354P with DPDK, all tested algorithms except BLAKE3 reached the receive baseline at 1500-byte frames once enough threads were used; at 64-byte frames none reached line rate within the CPU's physical core count. Offloading to the tested DPU did not reach the target. SipHash-1-3-128 was the leading candidate, and FPGA or ASIC hashing is expected to be needed for some plans 7.
- Passive optics (Amodo). Amodo computes a 1.45 dB link margin, which it calls tight, for an example 53 GBaud link; a 95/5 split costs about 0.25 dB on the live leg and about 13 dB on the monitor leg 6.