---
格式版本: 2
标题: "One-Click Multi-Tenant Security with NVIDIA Quantum InfiniBand | NVIDIA Technical Blog"
原文链接: "https://developer.nvidia.com/blog/one-click-multi-tenant-security-with-nvidia-quantum-infiniband/"
发布日期: "2026-06-11"
发布时间校准状态: "found"
发布时间来源: "llm:strict_original_body"
发布时间证据: "div class=post-info: Jun 11, 2026"
发布时间校准原因: "日期位于标题下方的 post-info 区域，符合文章发布时间的典型位置特征，且无其他事件日期干扰。"
发布时间校准置信度: "100"
发布时间候选数量: 8
发布时间严格候选数量: 2
发布时间原页读取状态: "原页面来自已抓取 HTML"
发布时间未找到原因: "候选日期无效或 LLM 未确认"
发布时间校准时间: "2026-07-20T12:41:27+08:00"
发现时间: "2026-07-20T11:40:00+08:00"
入库时间: "2026-07-20T04:48:12.215Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://developer.nvidia.com/blog/"
匹配关键词:
  []
相关厂家:
  - "NVIDIA"
相关专家:
  []
内容类型: "网页"
抓取工具: "AgentKey Scrape"
清洗工具: "AgentKey Markdown + LLM 正文裁剪"
原始附件:
  []
AI优质: "否"
AI打分: 42
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "NVIDIA官方技术博客，来源权威。但内容聚焦InfiniBand网络多租户安全配置（UFM安全配置文件），属于网络软件/安全运维层面，未涉及超节点、AI Rack、机柜级系统架构、供电、散热、高速互连硬件或量产部署等核心主题，技术细节与…"
AI质检模型: "qwen3.6-plus"
AI质检时间: "2026-07-20T12:48:12+08:00"
AI主题相关性: 8
AI来源权威性: 14
AI新颖性: 10
AI技术细节: 6
AI商业部署信号: 2
AI完整性: 2
图片摘要:
  - "✓ ./assets/img-527b9ffe.png | photo | 展示NVIDIA UFM Enterprise界面的三屏工作台，包含网络拓扑、仪表盘及系统健康监控视图。"
  - "✓ ./assets/img-4afaf588.webp | screenshot | UFM Cyber AI界面截图，显示System Health下的InfiniBand网络安全验证功能及一键运行报告按钮。"
  - "✓ ./assets/img-c4fef478.webp | screenshot | 网络安全验证配置弹窗，支持设置Verbosity Level（如Errors）及Test Pkeys Settings选项。"
  - "✓ ./assets/img-a36fce05.webp | screenshot | 安全验证结果列表，详细列出opensm.conf等源文件中的潜在安全漏洞及具体参数错误描述。"
  - "✗ ./assets/img-bab70b95.webp | ad | 广告：NVIDIA GTC Berlin注册推广"
  - "✗ ./assets/img-9d3a9443.webp | ad | 广告：NVIDIA SIGGRAPH 2026活动推广"
采集批次: "2026年7月20日11点39分58秒"
采集批次ID: "20260720-113958-114"
去重键: "https://developer.nvidia.com/blog/one-click-multi-tenant-security-with-nvidia-quantum-infiniband"
---

[NVIDIA Quantum InfiniBand](https://www.nvidia.com/en-us/networking/products/infiniband/) now offers intent-based security profiles in Unified Fabric Manager (UFM) that enable multi-tenant fabric security in a single click.

NVIDIA Quantum InfiniBand supports three profiles: General, Bare Metal Cloud, and Secured Bare Metal Cloud. Network administrators can now auto-configure:

- Partition Key (PKey) isolation
- Management Datagram (MAD) key protection
- Global Unique Identifier (GUID)-based access control
- Continuous validation

This cuts deployment time to minutes from hours or days, letting cloud providers run hardware-enforced tenant isolation across tens of thousands of GPUs without manual Subnet Manager (SM) configuration.

With the exponential growth of AI, HPC, and hyperscale cloud computing, the integrity of the network fabric is more critical than ever, yet many networks treat security as an afterthought.

InfiniBand takes the opposite approach: security extends across every layer of the fabric. While InfiniBand is best known for ultra-low latency, high throughput, and massive scalability, its [multilayered security architecture](https://docs.nvidia.com/networking/display/nvidiainfinibandsecurityoverviewandguidelines) is equally robust.

This post explains how intent-based profiles make it easy to deploy.

## Why traditional networks fall short on multi-tenant security

InfiniBand is a software-defined, centrally managed fabric. In traditional networking, endpoints often operate independently, making their own routing, resource, and policy decisions. This lack of centralized oversight can lead to misconfigurations, inconsistent policies, and security vulnerabilities. NVIDIA Quantum InfiniBand avoids this by centralizing control in UFM, which enforces global policies, optimizes routes, monitors health, and proactively secures the fabric.

Despite NVIDIA providing robust solutions such as integrity mechanisms and hardware-enforced tenant isolation, such features remain underutilized because Quantum InfiniBand isn’t as widely understood as Ethernet.

There is currently a critical need to bridge the gap between InfiniBand’s advanced security capabilities and the user’s ability to easily implement them without deep domain expertise. In agentic AI environments that are connecting tens of thousands of GPUs with thousands of switches, even a minor configuration error in tenant isolation can compromise sensitive proprietary data or disrupt massive distributed workloads. Security features must be scalable and easy to deploy to make customers’ work easier and their clusters more secure.

To address these issues, NVIDIA presents a one-click solution for enabling InfiniBand security features.

## What are intent-based security profiles for NVIDIA Quantum InfiniBand?

NVIDIA is introducing intent-based security profiles to simplify and standardize security configuration across different deployment models. Instead of manually configuring multiple parameters, users can select a predefined profile, and UFM will automatically orchestrate all underlying security settings.

The following are key benefits of intent-based profiles:

- **Fewer errors**: Profiles implement and deploy security features as NVIDIA engineering intends, protecting against misunderstandings or missing documentation.
- **Configuration time reduction**: Transitioning from manual, multi-step UFM/SM configurations to pre-configured, intent-based profiles can reduce learning, adapting configurations, and deployment and testing time to minutes from hours or days.
- **Zero-touch scaling**: Hundreds of nodes can be added to a multi-tenant environment without a linear increase in security management overhead.
- **No security downtime**: When a new security feature is added, it is added to the relevant profile configurations, removing the transition phase between releasing a new feature and enabling it in deployment.

The General profile is designed for single-tenant environments with a basic out-of-the-box configuration.

Bare Metal Cloud is tailored for multi-tenant cloud environments and Secured Bare Metal Cloud is a hardened profile for highly secure multi-tenant environments.

The following sections will go into more detail about the Bare Metal Cloud and Secured Bare Metal Cloud profile types.

### The Bare Metal Cloud profile

The Bare Metal Cloud profile enables [PKey-based isolation](https://docs.nvidia.com/networking/display/winof2v31052010lts/infiniband+network#src-132450561_InfiniBandNetwork-PKeysDefaultandnon-defaultPKeys), providing tenant separation within cloud environments over the InfiniBand management network.

Analogous to Ethernet VLANs, InfiniBand partitioning with PKeys defines which nodes or ports can access network resources, using hardware mechanisms to prevent ports in one partition from accessing another.

What makes this mechanism particularly well-suited to multi-tenant deployments is that partition assignment is controlled entirely by the SM: Nodes can’t determine their own partitions, and applications can’t specify which partition to use; they can only reference partitions already assigned to their port.

Port attributes are stored in hardware and are accessible only via the Management Key (MKey), which is known exclusively to the SM and the InfiniBand silicon. This architecture gives cloud service providers and data center operators a strong isolation guarantee. Tenants sharing the same physical InfiniBand fabric are cryptographically and logically separated at the hardware level, with no reliance on host-side software enforcement that a tenant with elevated privileges could circumvent.

### The Secured Bare Metal Cloud profile

The Secured Bare Metal Cloud profile builds on PKey isolation and enables a comprehensive set of security features required for secure multi-tenant cloud environments:

- Full MAD key protection with randomized seeds, including: MKEY, VSKEY, PMKEY, CCKEY, Class C key (N2N), AM and job keys, SMKEY, and SAKEY
- GUID-based access control using the `allowed_guid_list` feature
- Service-level authentication via `service_key` (e.g., for AM services)
- Enhanced SA trust model applied to all commands
- MAD rate limiting (MAD Limiter) to protect against abuse and congestion
	- DoS/DDoS Protection: Automatically identifies and limits excessive packet rates from individual nodes to protect the management node.
		- Source-Based Rate Limiting: Operates by monitoring and controlling traffic based on the source LID address of each node.

This approach reduces complexity, minimizes configuration errors, and ensures consistent security enforcement across deployments, allowing users to align infrastructure behavior with their intended operational model.

## How to validate NVIDIA Quantum InfiniBand security posture with CSV

Another feature supported for NVIDIA Quantum InfiniBand deployments is Continuous Security Verification (CSV). This is a new UFM diagnostic capability that performs static analysis and log-based auditing. It provides users with a “Security Health Score” as well as specific, automated remediation steps for any detected vulnerabilities.

Combined with intent-based profiles, this proactive diagnostic tool is critical for ensuring efficient and secure network operations.

In Figure 1, below, the screenshots show the flow for generating the security report.

In the System Health tab, users select Security from the top menu.

![An image of the UFM user interface, displaying the ability to run a new security report](./assets/img-4afaf588.webp)

Figure 1: Users can validate network security posture with the System Health Security dashboard in UFM Cyber AI

Next, users select the desired verbosity level (Errors, Errors and Warnings, and Info), as well as the option to test PKeys settings, and then run the report. See Figure 2, below:

![An image of the UFM user interface, displaying the ability to choose verbosity level](./assets/img-c4fef478.webp)

Figure 2: The security validation report displays different outputs based on selected verbosity

Once the report is completed, the results will display a list of errors, warnings, and information messages based on the selected verbosity level. See Figure 3, below:

![An image of the UFM user interface, displaying a list of network parameters that could be potential vulnerabilities](./assets/img-a36fce05.webp)

Figure 3: The System Health Security report displays a list of potential network security vulnerabilities

## Going further

For more information about guidelines and best practices for translating complex fabric security features into actionable deployment, learn more by reading the [NVIDIA Quantum InfiniBand security white paper](https://docs.nvidia.com/networking/display/nvidiainfinibandsecurityoverviewandguidelines).

![图片](./assets/img-527b9ffe.png)

![An image of the UFM user interface, displaying the ability to run a new security report](./assets/img-4afaf588.webp)_Figure 1: Users can validate network security posture with the System Health Security dashboard in UFM Cyber AI_

![An image of the UFM user interface, displaying the ability to choose verbosity level](./assets/img-c4fef478.webp)_Figure 2: The security validation report displays different outputs based on selected verbosity_

![An image of the UFM user interface, displaying a list of network parameters that could be potential vulnerabilities](./assets/img-a36fce05.webp)_Figure 3: The System Health Security report displays a list of potential network security vulnerabilities_

- ![图片](./assets/img-bab70b95.webp)

- ![图片](./assets/img-9d3a9443.webp)
