US2024045968A1PendingUtilityA1

Composable trusted execution environments

Assignee: INTEL CORPPriority: Dec 17, 2018Filed: Oct 23, 2023Published: Feb 8, 2024
Est. expiryDec 17, 2038(~12.4 yrs left)· nominal 20-yr term from priority
G06F 2009/45587G06F 9/45558G06F 2009/45562G06F 21/57G06F 9/505G06F 21/85G06F 21/72G06F 21/53G06F 2221/034G06F 9/5077
75
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In one embodiment, an apparatus comprises a processor to: receive a request to configure a secure execution environment for a first workload; configure a first set of secure execution enclaves for execution of the first workload, wherein the first set of secure execution enclaves is configured on a first set of processing resources, wherein the first set of processing resources comprises one or more central processing units and one or more accelerators; configure a first set of secure datapaths for communication among the first set of secure execution enclaves during execution of the first workload, wherein the first set of secure datapaths is configured over a first set of interconnect resources; configure the secure execution environment for the first workload, wherein the secure execution environment comprises the first set of secure execution enclaves and the first set of secure datapaths.

Claims

exact text as granted — not AI-modified
1 . A device, comprising:
 input/output (I/O) circuitry to communicate over an interconnect; and   processing circuitry to:
 receive, via the I/O circuitry, a request to configure the device for inclusion in a trusted execution environment (TEE) on a virtual machine (VM), wherein the TEE is to be configured on a processor and the device, and wherein the TEE is to include an encrypted data stream for communication over the interconnect between the processor and the device; and 
 configure, based on the request, the device to be included in the TEE. 
   
     
     
         2 . The device of  claim 1 , wherein the interconnect comprises a Peripheral Component Interconnect Express (PCIe) interconnect. 
     
     
         3 . The device of  claim 2 , wherein:
 the processor is a central processing unit (CPU); and   the device is a graphics processing unit (GPU).   
     
     
         4 . The device of  claim 3 , wherein:
 the TEE is a first TEE, the VM is a first VM, the encrypted data stream is a first encrypted data stream, and the request is a first request; and   the processing circuitry is further to:
 receive, via the I/O circuitry, a second request to configure the GPU for inclusion in a second TEE on a second VM, wherein the second TEE is to be configured on the CPU and the GPU, and wherein the second TEE is to include a second encrypted data stream for communication over the PCIe interconnect between the CPU and the GPU; and 
 configure, based on the second request, the GPU to be included in the second TEE. 
   
     
     
         5 . The device of  claim 4 , wherein:
 the first TEE is associated with a first tenant; and   the second TEE is associated with a second tenant.   
     
     
         6 . The device of  claim 3 , wherein:
 the CPU is a first CPU, the TEE is a first TEE, the VM is a first VM, the encrypted data stream is a first encrypted data stream, and the request is a first request; and   the processing circuitry is further to:
 receive, via the I/O circuitry, a second request to configure the GPU for inclusion in a second TEE on a second VM, wherein the second TEE is to be configured on a second CPU and the GPU, and wherein the second TEE is to include a second encrypted data stream for communication over the PCIe interconnect between the second CPU and the GPU; and 
 configure, based on the second request, the GPU to be included in the second TEE. 
   
     
     
         7 . The device of  claim 3 , wherein the TEE is a composed TEE, wherein the composed TEE is a cryptographically-isolated execution environment distributed across the CPU and the GPU. 
     
     
         8 . The device of  claim 7 , wherein the composed TEE includes:
 a first TEE on the CPU;   a second TEE on the GPU; and   the encrypted data stream for communication between the first TEE and the second TEE.   
     
     
         9 . The device of  claim 8 , wherein the processing circuitry is further to execute one or more workloads in the second TEE on the GPU. 
     
     
         10 . The device of  claim 9 , wherein the one or more workloads include:
 a virtual network function (VNF) workload;   a Function-as-a-Service (FaaS) workload;   a Platform-as-a-Service (PaaS) workload;   an Infrastructure-as-a-Service (IaaS) workload; or   a Software-as-a-Service (SaaS) workload.   
     
     
         11 . The device of  claim 1 , wherein the processing circuitry is further to send, via the I/O circuitry, a device signature for the device to the processor, wherein the device signature cryptographically attests a configuration of the device. 
     
     
         12 . The device of  claim 1 , wherein the device is:
 a graphics processing unit (GPU);   an artificial intelligence accelerator;   a cryptography accelerator;   a compression accelerator;   a field-programmable gate array (FPGA); or   a network interface controller.   
     
     
         13 . The device of  claim 1 , further comprising a memory coupled to the processing circuitry to store instructions, wherein the instructions, when executed by the processing circuitry, cause the processing circuitry to:
 receive, via the I/O circuitry, the request to configure the device for inclusion in the TEE on the VM; and   configure, based on the request, the device to be included in the TEE.   
     
     
         14 . A system, comprising:
 input/output (I/O) circuitry to communicate with one or more devices over an interconnect; and   processing circuitry to:
 receive, via the I/O circuitry, a device signature from a first device of the one or more devices, wherein the device signature cryptographically attests a configuration of the first device; and 
 configure a composed trusted execution environment (TEE) on a virtual machine (VM), wherein the composed TEE is distributed across the processing circuitry and the first device, and wherein an encrypted data stream is configured for communication over the interconnect between the processing circuitry and the first device within the composed TEE. 
   
     
     
         15 . The system of  claim 14 , further comprising a central processing unit (CPU), wherein the CPU comprises the processing circuitry. 
     
     
         16 . The system of  claim 15 , further comprising a Peripheral Component Interconnect Express (PCIe) controller, wherein the PCIe controller comprises the I/O circuitry, and wherein the interconnect comprises a Peripheral Component Interconnect Express (PCIe) interconnect. 
     
     
         17 . The system of  claim 16 , further comprising the first device, wherein the first device is a graphics processing unit (GPU). 
     
     
         18 . The system of  claim 17 , wherein:
 the composed TEE is a first composed TEE, the VM is a first VM, and the encrypted data stream is a first encrypted data stream; and   the processing circuitry is further to configure a second composed TEE on a second VM, wherein the second composed TEE is distributed across the CPU and the GPU, and wherein a second encrypted data stream is configured for communication over the PCIe interconnect between the CPU and the GPU within the second composed TEE.   
     
     
         19 . The system of  claim 18 , wherein:
 the first composed TEE is associated with a first tenant; and   the second composed TEE is associated with a second tenant.   
     
     
         20 . The system of  claim 17 , wherein:
 the device signature is a first device signature, the composed TEE is a first composed TEE, the VM is a first VM, the encrypted data stream is a first encrypted data stream, and the GPU is a first GPU; and   the processing circuitry is further to:
 receive, via the I/O circuitry, a second device signature from a second GPU, wherein the second device signature cryptographically attests a configuration of the second GPU; and 
 configure a second composed TEE on a second VM, wherein the second composed TEE is distributed across the CPU and the second GPU, and wherein a second encrypted data stream is configured for communication over the PCIe interconnect between the CPU and the second GPU within the second composed TEE. 
   
     
     
         21 . The system of  claim 17 , wherein:
 the device signature is a first device signature, the encrypted data stream is a first encrypted data stream, and the GPU is a first GPU; and   the processing circuitry is further to:
 receive, via the I/O circuitry, a second device signature from a second GPU, wherein the second device signature cryptographically attests a configuration of the second GPU; 
 configure a second encrypted data stream for communication over the PCIe interconnect between the CPU and the second GPU within the composed TEE; and 
 assign the second GPU and the second encrypted data stream to the composed TEE. 
   
     
     
         22 . The system of  claim 14 , wherein the composed TEE includes:
 a first TEE on the processing circuitry;   a second TEE on the first device; and   the encrypted data stream for communication between the first TEE and the second TEE.   
     
     
         23 . The system of  claim 14 , wherein the processing circuitry is further to:
 authenticate, based on the device signature, a hardware identity or a firmware identity of the first device.   
     
     
         24 . The system of  claim 14 , wherein the processing circuitry to configure the composed TEE on the VM is further to:
 configure a memory controller to encrypt data stored in memory assigned to the composed TEE.   
     
     
         25 . The system of  claim 14 , wherein the processing circuitry is further to deploy one or more workloads for execution in the composed TEE. 
     
     
         26 . The system of  claim 25 , wherein the one or more workloads include:
 a virtual network function (VNF) workload;   a Function-as-a-Service (FaaS) workload;   a Platform-as-a-Service (PaaS) workload;   an Infrastructure-as-a-Service (IaaS) workload; or   a Software-as-a-Service (SaaS) workload.   
     
     
         27 . The system of  claim 14 , wherein the first device comprises:
 a graphics processing unit (GPU);   an artificial intelligence accelerator;   a cryptography accelerator;   a compression accelerator;   a field-programmable gate array (FPGA); or   a network interface controller.   
     
     
         28 . The system of  claim 14 , further comprising a memory coupled to the processing circuitry to store instructions, wherein the instructions, when executed by the processing circuitry, cause the processing circuitry to:
 receive, via the I/O circuitry, the device signature from the first device of the one or more devices; and   
       configure the composed TEE on the VM. 
     
     
         29 . A method, comprising:
 receiving, via input/output (I/O) circuitry, a request to configure a device for inclusion in a trusted execution environment (TEE) on a virtual machine (VM), wherein the TEE is to be configured on a processor and the device, and wherein the TEE is to include an encrypted data stream for communication over an interconnect between the processor and the device;   sending, via the I/O circuitry, a device signature for the device to the processor, wherein the device signature cryptographically attests a configuration of the device; and   configuring the device to be included in the TEE.   
     
     
         30 . The method of  claim 29 , wherein the interconnect comprises a Peripheral Component Interconnect Express (PCIe) interconnect. 
     
     
         31 . The method of  claim 30 , wherein:
 the processor is a central processing unit (CPU); and   the device is a graphics processing unit (GPU).   
     
     
         32 . The method of  claim 31 , wherein:
 the TEE is a first TEE, the VM is a first VM, and the encrypted data stream is a first encrypted data stream; and   the method further comprises:
 receiving, via the I/O circuitry, a request to configure the GPU for inclusion in a second TEE on a second VM, wherein the second TEE is to be configured on the CPU and the GPU, and wherein the second TEE is to include a second encrypted data stream for communication over the PCIe interconnect between the CPU and the GPU; and 
 configuring the GPU to be included in the second TEE. 
   
     
     
         33 . The method of  claim 32 , wherein:
 the first TEE is associated with a first tenant; and   the second TEE is associated with a second tenant.   
     
     
         34 . The method of  claim 31 , wherein:
 the CPU is a first CPU, the TEE is a first TEE, the VM is a first VM, and the encrypted data stream is a first encrypted data stream; and   the method further comprises:
 receiving, via the I/O circuitry, a request to configure the GPU for inclusion in a second TEE on a second VM, wherein the second TEE is to be configured on a second CPU and the GPU, and wherein the second TEE is to include a second encrypted data stream for communication over the PCIe interconnect between the second CPU and the GPU; and 
 configuring the GPU to be included in the second TEE. 
   
     
     
         35 . The method of  claim 31 , wherein the TEE is a composed TEE, wherein the composed TEE is a cryptographically-isolated execution environment distributed across the CPU and the GPU. 
     
     
         36 . The method of  claim 35 , wherein the composed TEE includes:
 a first TEE on the CPU;   a second TEE on the GPU; and   the encrypted data stream for communication between the first TEE and the second TEE.   
     
     
         37 . The method of  claim 36 , further comprising executing one or more workloads in the second TEE on the GPU. 
     
     
         38 . The method of  claim 37 , wherein the one or more workloads include:
 a virtual network function (VNF) workload;   a Function-as-a-Service (FaaS) workload;   a Platform-as-a-Service (PaaS) workload;   an Infrastructure-as-a-Service (IaaS) workload; or   a Software-as-a-Service (SaaS) workload.   
     
     
         39 . The method of  claim 29 , wherein the device is:
 a graphics processing unit (GPU);   an artificial intelligence accelerator;   a cryptography accelerator;   a compression accelerator;   a field-programmable gate array (FPGA); or   a network interface controller.   
     
     
         40 . At least one non-transitory computer-readable medium having instructions stored thereon, wherein the instructions, when implemented or executed on processing circuitry of a device, cause the processing circuitry to:
 receive, via input/output (I/O) circuitry, a request to configure the device for inclusion in a trusted execution environment (TEE) on a virtual machine (VM), wherein the TEE is to be configured on a processor and the device, and wherein the TEE is to include an encrypted data stream for communication over an interconnect between the processor and the device;   send, via the I/O circuitry, a device signature for the device to the processor, wherein the device signature cryptographically attests a configuration of the device; and   configure the device to be included in the TEE.   
     
     
         41 . The computer-readable medium of  claim 40 , wherein the interconnect comprises a Peripheral Component Interconnect Express (PCIe) interconnect. 
     
     
         42 . The computer-readable medium of  claim 41 , wherein:
 the processor is a central processing unit (CPU); and   the device is a graphics processing unit (GPU).   
     
     
         43 . The computer-readable medium of  claim 42 , wherein:
 the TEE is a first TEE, the VM is a first VM, and the encrypted data stream is a first encrypted data stream; and   the instructions further cause the processing circuitry to:
 receive, via the I/O circuitry, a request to configure the GPU for inclusion in a second TEE on a second VM, wherein the second TEE is to be configured on the CPU and the GPU, and wherein the second TEE is to include a second encrypted data stream for communication over the PCIe interconnect between the CPU and the GPU; and 
 configure the GPU to be included in the second TEE. 
   
     
     
         44 . The computer-readable medium of  claim 43 , wherein:
 the first TEE is associated with a first tenant; and   the second TEE is associated with a second tenant.   
     
     
         45 . The computer-readable medium of  claim 42 , wherein:
 the CPU is a first CPU, the TEE is a first TEE, the VM is a first VM, and the encrypted data stream is a first encrypted data stream; and   the instructions further cause the processing circuitry to:
 receive, via the I/O circuitry, a request to configure the GPU for inclusion in a second TEE on a second VM, wherein the second TEE is to be configured on a second CPU and the GPU, and wherein the second TEE is to include a second encrypted data stream for communication over the PCIe interconnect between the second CPU and the GPU; and 
 configure the GPU to be included in the second TEE. 
   
     
     
         46 . The computer-readable medium of  claim 42 , wherein the TEE is a composed TEE, wherein the composed TEE is a cryptographically-isolated execution environment distributed across the CPU and the GPU. 
     
     
         47 . The computer-readable medium of  claim 46 , wherein the composed TEE includes:
 a first TEE on the CPU;   a second TEE on the GPU; and   the encrypted data stream for communication between the first TEE and the second TEE.   
     
     
         48 . The computer-readable medium of  claim 47 , wherein the instructions further cause the processing circuitry to execute one or more workloads in the second TEE on the GPU. 
     
     
         49 . The computer-readable medium of  claim 48 , wherein the one or more workloads include:
 a virtual network function (VNF) workload;   a Function-as-a-Service (FaaS) workload;   a Platform-as-a-Service (PaaS) workload;   an Infrastructure-as-a-Service (IaaS) workload; or   a Software-as-a-Service (SaaS) workload.   
     
     
         50 . The computer-readable medium of  claim 40 , wherein the device is:
 a graphics processing unit (GPU);   an artificial intelligence accelerator;   a cryptography accelerator;   a compression accelerator;   a field-programmable gate array (FPGA); or   a network interface controller.

Join the waitlist — get patent alerts

Track US2024045968A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.