Organization · Research organization
Center for a New American Security
An independent, bipartisan, nonprofit national-security policy organization; publisher of a report proposing on-chip mechanisms, including location verification, for governing AI chips.
www.cnas.org · also called CNAS
CNAS describes itself as an independent, bipartisan, nonprofit organization that develops national security and defense policies. Its 2024 report Secure, Governable Chips, by Aarne, Fist and Withers, proposes on-chip mechanisms for governing AI chips 1:
- Hardened security module. The report proposes a module that enforces valid firmware and up-to-date operating licenses and supports remote attestation, rolled out in stages from firmware changes to tamper-evident and then tamper-proof hardware 1. See Hardware-enabled guarantees (flexHEG) and guarantee processors, Hardware performance throttling and licensing and TEE remote attestation for AI workloads.
- Hardening and effort. It judges that existing on-chip features must be hardened before they can be relied on in adversarial settings, and estimates that leading firms could build the required functionality with 18 months to 4 years of effort 1.
- Location verification. It illustrates ping-based checks with a landmark server in Paris: a reply within 9 ms would place a chip inside a circle that excludes countries subject to export restrictions 1. It expects hundreds of landmarks worldwide 1. See Chip location verification.
- Ownership tracking. It writes that on-chip mechanisms would need a way to track who owns data-centre AI chips, supported by supply-chain tracking and know-your-customer policies 1; see Chip registries and manufacturing records.
Mechanisms
Mechanisms this organization has designed, built, evaluated or supplied.
- Timing a chip's signed replies to trusted servers at known places, so that the speed of light bounds how far away the chip can be.
- On-chip mechanisms that cut an AI accelerator's performance when a license expires or a trusted trigger fires, bounding what the hardware can do.
- Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used.
Publications
Sources this organization authored or published.
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. RecordCited by Chip location verification; Chip registries and manufacturing records; Hardware-enabled guarantees (flexHEG) and guarantee processors; Hardware performance throttling and licensing; TEE remote attestation for AI workloads; Hardware-enabled mechanism (HEM); Center for a New American Security
Sources
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordSupports: Secure, Governable Chips: security module, staged rollout, hardening, development effort, location verification, ownership tracking