Cybersecurity

AI Redefines Trust in Data Center Security

The sharp increase in demand for computing capabilities is driving data center operators to broaden the concept of security to include chip identity, firmware integrity, supply chain records, and readiness for post-quantum cryptography. Industry experts believe that the “zero-trust” model and continuous monitoring have become more important, but they add cost and complexity and may worsen product certification delays.

2026-09-03
6 min read
6 views
فريق تحرير certi.news
AI Redefines Trust in Data Center Security

The surge in AI workloads is driving data centers to rebuild the concept of security trust from the ground up. The issue is no longer limited to firewalls or anti-malware software; it extends to proving that every chip, server, firmware image, and network component is actually what it is supposed to be, and that it has not been tampered with during manufacturing, shipping, installation, or operation.

In an article published by Semiconductor Engineering on September 3, 2026, Brendan Heffernan, an associate editor at the site, presents the views of experts from Keysight Technologies, Infineon Technologies, and Secure-IC, a Cadence company, in addition to Synopsys and Rambus. Their common thread is that the expansion of data centers, the increasing value of the data they host, and the evolution of cyber-physical attacks make trust an interconnected chain rather than a single point of control.

From Threat Control to Proving Trust

Scott Register, vice president of the enterprise sector at Keysight Technologies, describes a shift from thinking about security “controls” to thinking about “trust” supported by evidence. He gives the example of a client in the Middle East that canceled a large server order after discovering a 48-hour gap during which it could not prove the integrity of the equipment while it was being transported.

This example practically shows that component integrity does not begin when the component arrives at the data center. The operator needs to know its origin, the parties that handled it, and whether it was replaced or modified, and then continue verifying it after it enters service. Consequently, design is moving toward “zero-trust” architectures, in which every access or connection is treated as originating from an untrusted party until authentication and encryption prove otherwise.

Unclonable Identity and Monitoring During Operation

Physical unclonable functions, known by the abbreviation PUF, are emerging as one of the technologies that can support tracking component identities. According to Sylvain Guilley, chief technology officer and co-founder of Secure-IC, these functions can be used as an anchor for a hardware identity and a record of its creation, testing, assembly, and transfer of ownership, much like a passport for the component that extends through the moment the data center is operated.

But proving hardware identity upon delivery is not enough. Dana Neustadter, senior director of product management for security solutions at Synopsys, points to the importance of tamper resistance, vulnerability scanning in firmware and infrastructure, and the use of measured boot or real-time system integrity monitoring. She says that monitoring during operation remains one of the least-attended areas of defense, even though an attack may occur after a component has passed through manufacturing, installation, and initial verification.

More Layers or Smarter Layers?

Multilayered defense is no longer merely an optional practice added after the system is designed. The approach the industry calls “defense in depth” requires interconnected protection for confidential computing, silicon security, firmware, networks, access management, virtualization, AI models, and their training infrastructure.

However, increasing the number of layers alone does not solve the problem. Ajay Kapoor, director of product management for silicon units at Rambus, explains that the focus is shifting to intelligent, adaptive layers capable of continuous verification, operating on the assumption that a breach will occur and limiting its impact rather than merely attempting to prevent it. This requires hardware roots of trust, cryptographic agility, and secure update mechanisms, alongside continuous measurement and operational data that help detect changes.

Post-Quantum Readiness Puts Pressure on the Supply Chain

Cryptographic agility is particularly important because many systems deployed today may continue protecting sensitive data for a decade or more. Devices and firmware therefore need to support updates to algorithms, key sizes, and operating modes, rather than locking in a single algorithm that requires replacing the entire system when requirements change.

The article points to Caliptra, an open-source project for a hardware root of trust under the Open Compute Project Foundation, as one of the efforts aimed at building low-level roots of trust, particularly in systems composed of chiplet modules that may come from different manufacturers. Reed Hinkel, director of strategic programs at Synopsys, also links adoption of these technologies to NIST standards for data centers hosting sensitive government workloads and to deadlines associated with the transition to post-quantum cryptography.

But the same trend creates a bottleneck. The need to certify products under FIPS 140-3 has led, according to Hinkel, to a major accumulation of certification requests, which may delay the release of post-quantum solutions and prevent government entities from purchasing products that are technically ready but have not completed certification.

When Cybersecurity Meets Physical Systems

The scope of risk extends to cooling, heating, ventilation, power, sensors, and cameras. Experts warn of attack chains that combine physical tampering, supply chain compromise, credential theft, firmware attacks, ransomware, and large-scale denial-of-service attacks.

Register also draws attention to timing attacks that could target power-grid synchronization, since a deviation of milliseconds in timing signals could cause operational problems. The source does not provide a specific incident proving that this scenario occurred, but presents it as a threat surface that has not received enough attention, particularly as the cost of software-defined radios and drones declines.

Why Does This Shift Matter?

The actual change is the transfer of security responsibility from the network team to a full lifecycle that begins with chip design and its creation record, passes through manufacturing, transportation, and assembly, and ends with component monitoring, updating, and disposal. Data center operators, chip designers, firmware suppliers, certification bodies, and government entities that rely on cloud infrastructure are all affected by this shift.

However, the source does not establish that a single global standard has settled these requirements, nor does it specify a comprehensive schedule for applying them outside the context of GovCloud workloads and U.S. government requirements. Continuous verification and cryptographic agility also add costs in silicon area, design, certification, and deployment. The issue will therefore remain a balance between the speed of building AI capabilities, the depth of assurances required, and the certification ecosystem’s ability to accommodate new products.

News source
Semiconductor Engineering
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news