Trusted Execution Environment for GPU Secure Multi-Tenant Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing multiple processing units, such as graphics processing units (GPUs) and central processing units (CPUs), in virtualized environments is extremely difficult, especially in multi-tenant environments where physical computing resources are shared.

Innovation Solution

A Trusted Execution Environment (TEE) is established using a parallel processing unit (PPU) like a GPU, where the PPU operates within a TEE implemented by CPUs. This environment uses encryption and secure key negotiation between the virtual machine and the PPU's secure microcontroller to protect data from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple tenants share the same physical computing resources in a virtualized environment, then resource utilization efficiency is improved, but security of processing units becomes extremely difficult to ensure

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity of processing units
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the virtualized computing environment by creating isolated execution contexts for each tenant using encrypted virtual machines. Each tenant's workloads are confined to their own encrypted VM instance, which is isolated from other tenants even though they share the same physical PPU resources. This segmentation allows multiple tenants to securely share infrastructure while maintaining individual security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of encryption and secure execution environments between the tenants and the shared physical resources. The hypervisor, combined with TEE technology and cryptographic primitives, acts as a mediator that manages resource allocation while preventing unauthorized access. This intermediary layer enables secure multi-tenant sharing by mediating all access requests through security checks and encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a Trusted Execution Environment is established with encryption and secure key negotiation, then data security against unauthorized access is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security mechanisms where the system automatically performs cryptographic key generation, negotiation, and management without requiring manual intervention. The secure microcontroller automatically establishes encrypted communication channels, generates session keys, and manages authentication credentials. This automation reduces operational complexity while maintaining high security standards through consistent, error-free cryptographic operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent adds a new dimension of security by implementing TEE-based encrypted execution environments alongside the traditional virtualization layer. This creates a multi-layered architecture where security operations occur in a separate cryptographic dimension, using hardware-enforced isolation and cryptographic primitives that operate independently from the software virtualization stack. This dimensional addition provides security without significantly increasing operational complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250117473A1Secure execution for multiple processor devices using trusted executing environments
Publication Date: 2025.04.10 NVIDIA CORP
  • US20250117473A1 patent drawing
  • US20250117473A1 patent drawing
  • US20250117473A1 patent drawing

AI summary

Apparatuses, systems, and techniques to generate a trusted execution environment including multiple accelerators. In at least one embodiment, a parallel processing unit (PPU), such as a graphics processing unit (GPU), operates in a secure execution mode including a protect memory region. Furthermore, in an embodiment, a cryptographic key is utilized to protect data during transmission between the accelerators.