Secure GPU Telemetry Save and Restore Over Global Counters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current graphics processing units (GPUs) face challenges in efficiently managing secure telemetry data transmission and storage due to the complexity of parallel processing architectures, particularly in SIMT architectures, which can lead to security vulnerabilities and inefficiencies in data management.

Innovation Solution

Implementing a secure virtualized telemetry system with save and restore over global counters, utilizing a graphics processing unit (GPU) with dedicated circuitry for secure I/O operations and trusted execution environments to ensure secure data transmission and storage, while maintaining high processing efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure telemetry system is implemented in parallel graphics processing, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the secure telemetry system into distinct functional modules: counter units for generating unique identifiers, encryption units for securing data, and dedicated circuitry for I/O operations. This modular segmentation allows each component to handle specific security tasks independently, improving overall data security while managing system complexity through organized functional division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dedicated circuitry and trusted execution environments as intermediary layers between the parallel graphics processing units and the external I/O system. These intermediaries handle encryption, authentication, and data transmission security, isolating the complex security operations from the main processing architecture and providing a controlled interface for secure telemetry operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated circuitry for secure I/O operations is added, then security is improved, but processing efficiency may deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the secure I/O circuitry directly into the graphics processing unit architecture, combining security functions with existing processing resources. The dedicated circuitry for encryption, authentication, and telemetry operations is integrated alongside the parallel processing units, allowing security operations to occur concurrently with graphics processing without requiring separate processing cycles or additional external hardware.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements preliminary action by pre-configuring trusted execution environments and establishing security contexts before telemetry operations begin. Authentication credentials, encryption keys, and security parameters are prepared and loaded into the dedicated circuitry in advance, enabling rapid secure operations during actual telemetry data transmission without real-time security setup overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250284522A1Secure virtualized telemetry with save and restore over global counters
Publication Date: 2025.09.11 INTEL CORP
  • US20250284522A1 patent drawing
  • US20250284522A1 patent drawing
  • US20250284522A1 patent drawing

AI summary

An apparatus having secure virtualized telemetry with save and restore over global counters is disclosed. The apparatus includes processor circuitry comprising: execution circuitry to provide a trusted execution environment (TEE) to host a virtual machine (VM), the TEE to: responsive to attesting secure telemetry endpoint circuitry as part of TCB of the TEE, map, within VF BAR space of the VM, the secure telemetry endpoint circuitry as a logical endpoint for the VM hosted by the TEE; and establish a trusted session between the VM and the secure telemetry endpoint circuitry; and the secure telemetry endpoint circuitry to: procure telemetry data corresponding to operation of the VM, wherein the telemetry data is stored in telemetry data storage of the secure telemetry endpoint circuitry that is accessible via the VF BAR space; and provide a hardware-assisted path for the VM to request access to the telemetry data procured for the VM.