Composable Trusted Execution Environments for Heterogeneous Accelerators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure execution environments are limited to general-purpose processors and cannot extend trust and security to special-purpose processors and accelerators, failing to scale for heterogeneous workloads that require latency and security sensitivity, especially in evolving microservices and Function-as-a-Service models.

Innovation Solution

The development of dynamic, scalable, and composable trustworthy execution environments (CTEEs) that leverage cryptographic protections and access controls to create per-tenant secure execution environments across multiple heterogeneous components, dynamically assembled and scaled to securely execute multi-tenant workloads on heterogeneous computing platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure execution environments are limited to general-purpose processors, then security and integrity are maintained, but adaptability and versatility are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the computing platform into multiple heterogeneous processing components (CPUs, GPUs, FPGAs, accelerators) and creates separate secure execution enclaves on each component. This segmentation allows security to be maintained on each individual component while enabling the system to adapt to diverse workload requirements across different component types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure execution environment is designed to be universal across multiple processor types and architectures. The same security framework can instantiate secure enclaves on CPUs, GPUs, FPGAs, and other accelerators, making the security solution adaptable to heterogeneous workloads without requiring architecture-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If secure execution environments are extended to special-purpose processors and accelerators, then adaptability is improved, but device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary secure execution environment layer that manages the complexity of heterogeneous processing components. This intermediary layer handles the instantiation and management of secure enclaves across different processor types, shielding users from the underlying complexity while enabling broad adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The secure execution environment dynamically adapts to the specific processing component being used. Rather than requiring static configuration for each processor type, the system dynamically instantiates appropriate secure enclaves based on the workload requirements and available hardware, reducing the need for pre-planned complexity.

Inventive Principle:
Principle #15Dynamics

3Productivity

If heterogeneous workloads are executed across multiple processing components, then productivity is improved, but reliability deteriorates

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements nested secure execution enclaves where each processing component (CPU, GPU, FPGA, accelerator) contains its own secure enclave within the broader heterogeneous computing platform. This nesting ensures that security is maintained at each level of the hierarchy, allowing productive use of multiple component types while preserving integrity and confidentiality within each enclave.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12079341B2Composable trusted execution environments
Publication Date: 2024.09.03 INTEL CORP
  • US12079341B2 patent drawing
  • US12079341B2 patent drawing
  • US12079341B2 patent drawing

AI summary

In one embodiment, an apparatus comprises a processor to: receive a request to configure a secure execution environment for a first workload; configure a first set of secure execution enclaves for execution of the first workload, wherein the first set of secure execution enclaves is configured on a first set of processing resources, wherein the first set of processing resources comprises one or more central processing units and one or more accelerators; configure a first set of secure datapaths for communication among the first set of secure execution enclaves during execution of the first workload, wherein the first set of secure datapaths is configured over a first set of interconnect resources; configure the secure execution environment for the first workload, wherein the secure execution environment comprises the first set of secure execution enclaves and the first set of secure datapaths.