Composable Trusted Execution Environments for Heterogeneous Accelerators
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure execution environments are limited to general-purpose processors and cannot extend trust and security to special-purpose processors and accelerators, failing to scale for heterogeneous workloads that require latency and security sensitivity, especially in evolving microservices and Function-as-a-Service models.
Innovation Solution
The development of dynamic, scalable, and composable trustworthy execution environments (CTEEs) that leverage cryptographic protections and access controls to create per-tenant secure execution environments across multiple heterogeneous components, dynamically assembled and scaled to securely execute multi-tenant workloads on heterogeneous computing platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure execution environments are limited to general-purpose processors, then security and integrity are maintained, but adaptability and versatility are reduced
Solution Approach 1:
The system segments the computing platform into multiple heterogeneous processing components (CPUs, GPUs, FPGAs, accelerators) and creates separate secure execution enclaves on each component. This segmentation allows security to be maintained on each individual component while enabling the system to adapt to diverse workload requirements across different component types.
Solution Approach 2:
The secure execution environment is designed to be universal across multiple processor types and architectures. The same security framework can instantiate secure enclaves on CPUs, GPUs, FPGAs, and other accelerators, making the security solution adaptable to heterogeneous workloads without requiring architecture-specific implementations.
2Adaptability or versatility
If secure execution environments are extended to special-purpose processors and accelerators, then adaptability is improved, but device complexity increases
Solution Approach 1:
The system introduces an intermediary secure execution environment layer that manages the complexity of heterogeneous processing components. This intermediary layer handles the instantiation and management of secure enclaves across different processor types, shielding users from the underlying complexity while enabling broad adaptability.
Solution Approach 2:
The secure execution environment dynamically adapts to the specific processing component being used. Rather than requiring static configuration for each processor type, the system dynamically instantiates appropriate secure enclaves based on the workload requirements and available hardware, reducing the need for pre-planned complexity.
3Productivity
If heterogeneous workloads are executed across multiple processing components, then productivity is improved, but reliability deteriorates
Solution Approach 1:
The system implements nested secure execution enclaves where each processing component (CPU, GPU, FPGA, accelerator) contains its own secure enclave within the broader heterogeneous computing platform. This nesting ensures that security is maintained at each level of the hierarchy, allowing productive use of multiple component types while preserving integrity and confidentiality within each enclave.
Data Source
AI summary
In one embodiment, an apparatus comprises a processor to: receive a request to configure a secure execution environment for a first workload; configure a first set of secure execution enclaves for execution of the first workload, wherein the first set of secure execution enclaves is configured on a first set of processing resources, wherein the first set of processing resources comprises one or more central processing units and one or more accelerators; configure a first set of secure datapaths for communication among the first set of secure execution enclaves during execution of the first workload, wherein the first set of secure datapaths is configured over a first set of interconnect resources; configure the secure execution environment for the first workload, wherein the secure execution environment comprises the first set of secure execution enclaves and the first set of secure datapaths.


