GPU-Centric Attestation for Confidential Compute Mode

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current graphics processing units (GPUs) face challenges in efficiently processing graphics data due to the limitations of fixed function computational units and the need for improved parallel processing techniques, particularly in SIMT architectures, which can lead to inefficiencies in executing program instructions synchronously.

Innovation Solution

Implementing a GPU-centric assessment of confidential compute mode using attestation to enhance security and performance by ensuring secure I/O operations through Trusted Execution Environment (TEE)-I/O support, enabling trusted I/O virtualization and secure partitions within the GPU architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If fixed function computational units are used in GPUs, then hardware implementation is simpler, but processing versatility and adaptability are limited

Engineering Contradiction:
Improvehardware implementation simplicityVSAvoidprocessing versatility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a unified computational unit architecture that can dynamically configure between different operational modes (confidential compute mode and non-confidential compute mode) within the same hardware structure. The execution engine is designed to handle both encrypted and unencrypted workloads using the same physical resources, allowing the GPU to serve multiple functions without requiring separate dedicated hardware for each mode.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If confidential compute mode with TEE-I/O support is implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds the Trusted Execution Environment (TEE) functionality within the existing GPU execution engine architecture. The confidential compute mode is implemented as a nested layer within the standard GPU execution pipeline, where the same execution engine can operate in either confidential or non-confidential mode depending on the workload requirements. This nesting approach allows security functionality to be integrated without requiring a completely separate hardware architecture.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The execution engine is designed with multi-functionality to handle both confidential and non-confidential workloads using the same hardware resources. The system can dynamically switch between modes without requiring duplicate hardware paths, thereby enhancing security while minimizing the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure partitions and trusted I/O virtualization are implemented, then isolation of compute resources is improved, but system complexity increases

Engineering Contradiction:
Improveisolation of compute resourcesVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements logical segmentation of the execution engine into isolated partitions that can handle different workload types. Each partition maintains independent security contexts and can be independently configured for confidential or non-confidential operation. This segmentation provides resource isolation without requiring complete physical separation of hardware components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The same physical execution engine resources are designed to support multiple operational modes and partition types through software-controlled configuration. This universal design allows secure partitions and trusted I/O virtualization to be implemented through firmware and driver layers rather than requiring complex hardware virtualization infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If synchronous execution of parallel threads is enforced in SIMT architecture, then processing efficiency is improved, but flexibility in executing diverse operations is reduced

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidflexibility in executing operations
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic execution capabilities within the SIMT architecture that allow the execution engine to adapt its synchronization behavior based on the specific workload requirements. The system can dynamically switch between synchronous execution modes (for maximum efficiency in uniform operations) and more flexible execution modes (for diverse operations requiring different synchronization patterns), thereby maintaining high productivity while improving operational flexibility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250292352A1GPU-centric assessment of confidential compute mode using attestation
Publication Date: 2025.09.18 INTEL CORP
  • US20250292352A1 patent drawing
  • US20250292352A1 patent drawing
  • US20250292352A1 patent drawing

AI summary

An apparatus to facilitate GPU-centric assessment of confidential compute mode using attestation is disclosed. The apparatus includes processing cores of a graphics processor communicably coupled to a baseboard management controller (BMC), the one or more processing cores to: cause the BMC to request CPU attestation evidence from a workload (WL) attesting environment of a central processing unit (CPU) that is communicably coupled to the graphics processor; select a graphics confidential compute (CC) mode of the graphics processor; communicate the graphics CC mode to a tenant management console orchestrator (TMCO) of the CPU; receive, by an attestation verifier of the processing cores, the CPU attestation evidence comprising CPU partition evidence of a CPU partition, the CPU partition evidence collected by the WL attesting environment of the CPU; and verify, by the attestation verifier, the CPU partition evidence and identify a CPU partition CC mode based on the CPU partition evidence.