US2022158850A1PendingUtilityA1

Methods and apparatus for offloading signature revocation checking on acceleration circuitry

Assignee: INTEL CORPPriority: Dec 21, 2018Filed: Feb 4, 2022Published: May 19, 2022
Est. expiryDec 21, 2038(~12.4 yrs left)· nominal 20-yr term from priority
H04L 9/3247H04L 9/0833H04L 9/0891H04L 9/0847H04L 9/3218H04L 9/3221H04L 9/0825H04L 9/3066
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system includes a host processor operable to communicate with a remote requestor to perform operations for attesting a trusted system. The system also includes a hardware acceleration coprocessor coupled to the host processor. The host processor is further operable to offload at least some of the operations onto the hardware acceleration coprocessor to free up processing power on the host processor.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 a host processor operable to communicate with a remote requestor to perform operations for attesting a trusted system; and   a hardware acceleration coprocessor coupled to the host processor, wherein the host processor is further operable to offload at least some of the operations onto the hardware acceleration coprocessor to free up processing power on the host processor.   
     
     
         2 . The system of  claim 1 , wherein the hardware acceleration coprocessor comprises a processing circuit selected from the group consisting of: an application-specific integrated circuit (ASIC), a programmable logic device (PLD), a graphics processing unit (GPU), and a central processing unit (CPU). 
     
     
         3 . The system of  claim 1 , wherein the hardware acceleration coprocessor comprises a field-programmable gate array (FPGA) device, and wherein the host processor is operable to calculate a threshold of diminishing returns to determine whether or not to offload the at least some of the operations onto the FPGA device. 
     
     
         4 . The system of  claim 1 , wherein the host processor is operable to calculate a threshold of diminishing returns to determine whether or not to offload the at least some of the operations onto the hardware acceleration coprocessor. 
     
     
         5 . The system of  claim 4 , wherein the host processor is operable to determine whether a number of signatures for the operations to be processed is greater than the threshold of diminishing returns. 
     
     
         6 . The system of  claim 1 , wherein the hardware acceleration coprocessor comprises a dynamic configurator that is operable to reallocate programmable resources on the hardware acceleration coprocessor by reconfiguring the programmable resources with more instances of sign bitstreams or more instances of verify bitstreams to perform the at least some of the operations. 
     
     
         7 . The system of  claim 5 , wherein the hardware acceleration coprocessor schedules either a sign operation or a verify operation if the number of signatures for the operations to be processed is greater than the threshold of diminishing returns. 
     
     
         8 . The system of  claim 7 , wherein the hardware acceleration coprocessor is operable to write data that is used for prove functions to a first memory and to invoke a separate prove functional instance for each signature in a signature revocation list for the at least some of the operations, and wherein the hardware acceleration coprocessor is operable to write data that is used for verify functions to a second memory and to invoke a separate verify functional instance for each signature in the signature revocation list for the at least some of the operations. 
     
     
         9 . The system of  claim 1 , wherein the hardware acceleration coprocessor is operable to perform the at least some of the operations that verify membership in a group while maintaining anonymity. 
     
     
         10 . A system, comprising:
 a host processor that communicates with a remote requestor to perform operations for attesting a trusted system; and   a hardware acceleration coprocessor coupled to the host processor, wherein the host processor offloads at least a subset of the operations to the hardware acceleration coprocessor, wherein the subset of the operations implement a group identity, wherein each member of the group identity possesses a unique private key, and wherein verification of each member of the group identity is accomplished using a public key to verify each of the unique private keys.   
     
     
         11 . The system of  claim 10 , wherein the hardware acceleration coprocessor comprises a processing circuit selected from the group consisting of: an application-specific integrated circuit (ASIC), a programmable logic device (PLD), a graphics processing unit (GPU), and a central processing unit (CPU). 
     
     
         12 . The system of  claim 10 , wherein the subset of the operations that the host processor offloads to the hardware acceleration coprocessor comprise sign operations and verify operations. 
     
     
         13 . The system of  claim 10 , wherein the host processor calculates a threshold of diminishing returns to determine whether or not to offload the at least the subset of the operations to the hardware acceleration coprocessor. 
     
     
         14 . The system of  claim 13 , wherein the host processor determines whether a number of signatures for the operations to be processed is greater than the threshold of diminishing returns. 
     
     
         15 . The system of  claim 10 , wherein the hardware acceleration coprocessor comprises a dynamic configurator that reallocates programmable resources on the hardware acceleration coprocessor by reconfiguring the programmable resources with more instances of sign bitstreams or more instances of verify bitstreams to perform the at least the subset of the operations. 
     
     
         16 . A method for offloading a workload to a hardware acceleration coprocessor, the method comprising:
 performing operations for attesting a trusted system using a host processor that communicates with a remote requestor;   offloading at least a subset of the operations from the host processor to the hardware acceleration coprocessor, wherein the hardware acceleration coprocessor is coupled to the host processor; and   performing the subset of the operations on the hardware acceleration coprocessor comprising implementing a group identity, wherein each member of the group identity possesses a unique private key, and verifying each member of the group identity using a public key to verify each of the unique private keys.   
     
     
         17 . The method of  claim 16 , wherein offloading at least the subset of the operations from the host processor to the hardware acceleration coprocessor comprises calculating a threshold of diminishing returns to determine whether or not to offload the subset of the operations to the hardware acceleration coprocessor. 
     
     
         18 . The method of  claim 17 , wherein offloading at least the subset of the operations from the host processor to the hardware acceleration coprocessor further comprises determining whether a number of signatures for the operations to be processed is greater than the threshold of diminishing returns. 
     
     
         19 . The method of  claim 18 , wherein performing the subset of the operations on the hardware acceleration coprocessor comprises scheduling either a sign operation or a verify operation if the number of signatures for the operations to be processed is greater than the threshold of diminishing returns. 
     
     
         20 . The method of  claim 16  further comprising:
 reallocating programmable resources on the hardware acceleration coprocessor using a dynamic configurator by reconfiguring the programmable resources with more instances of sign bitstreams or more instances of verify bitstreams to perform the subset of the operations.

Join the waitlist — get patent alerts

Track US2022158850A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.