IP Library › Granted Patent US 12,580,924
Granted Patent B2
US 12,580,924 · App. 17/558,966 · Granted Mar 17, 2026

Telemetry restriction mechanism

Inventors: Luis Kida (Beaverton, OR); Neerav Parikh (Hillsboro, OR); Reshma Lal (Portland, OR)
Assignee: INTEL CORPORATION
H04L63/105H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,924
App. No.
17/558,966
Granted
Mar 17, 2026
Kind
B2
Abstract

An apparatus comprising a network interface card (NIC), including packet processing circuitry to determine whether the NIC is to operate according to a first telemetry protection mode to prevent copying of packet data payloads for telemetry or a second telemetry protection mode to enable copying of packet payloads for telemetry.

Claims (29)

1 . An apparatus comprising:

a network interface card (NIC), including packet processing circuitry to receive a packet from a tenant via a network, process the packet to examine a message indicating whether one or more network connections associated with the tenant is to operate as a confidential connection and enable the NIC to operate according to a first telemetry protection mode to prevent duplication and mirroring of telemetry packet data payloads upon determining that the message indicates that the one or more network connections are to operate as the confidential connection, wherein a telemetry protection mode including the first telemetry protection mode or a second telemetry protection mode is determined based on a destination of the packet, wherein the packet processing circuitry to generate a telemetry packet for telemetry monitoring, the telemetry packet including a replacement payload upon determining that the packet is associated with the first telemetry protection mode, wherein the replacement payload substitutes an original payload of the telemetry packet while preventing duplication of the replacement payload.

2 . The apparatus of claim 1 , wherein the packet processing circuitry further to enable the NIC to operate according to the second telemetry protection mode to enable duplication and mirroring of telemetry packet data payloads upon determining that the message indicates that the one or more network connections are not to operate as the confidential connection.

3 . The apparatus of claim 2 , wherein the packet processing circuitry to receive data from a host and determine that the telemetry packet is to be generated.

4 . The apparatus of claim 3 , wherein the packet processing circuitry is further to determine the telemetry protection mode associated with a packet to be transmitted.

5 . The apparatus of claim 4 , wherein the packet processing circuitry is further to generate a header specifying the telemetry packet including a replacement payload upon determining that the packet is associated with the first telemetry protection mode.

6 . The apparatus of claim 5 , wherein the packet processing circuitry to generate a header specifying the telemetry packet including the duplicate payload of the packet upon determining that the packet is associated with the second telemetry protection mode.

7 . The apparatus of claim 1 , wherein the replacement payload comprises empty payload data.

8 . The apparatus of claim 7 , wherein the replacement payload comprises statistics payload data.

9 . The apparatus of claim 7 , wherein the packet processing circuitry to generate the telemetry packet that includes a duplicate payload of the packet upon determining that the packet is associated with the second telemetry protection mode.

10 . The apparatus of claim 9 , wherein the packet processing circuitry to transmit the telemetry packet to a telemetry consumer.

11 . A method comprising:

receiving a packet via a network;

processing the packet, wherein processing includes:

examining a header within the packet to determine a destination of the packet;

determining that the destination is associated with one or more confidential connections associated with a tenant based on the destination of the packet;

preventing duplication and mirroring of telemetry packet data payloads upon determining that the destination is associated is associated with the one or more confidential connections, wherein a telemetry protection mode including a first telemetry protection mode or a second telemetry protection mode is determined based on the destination of the packet; and

generating a telemetry packet for telemetry monitoring, the telemetry packet including a duplicate payload of the packet upon determining that the packet is associated with the second telemetry protection mode, wherein the replacement payload substitutes an original payload of the telemetry packet while preventing duplication of the replacement payload.

12 . The method of claim 11 , further comprising generating the telemetry packet including a replacement payload including empty payload data.

13 . The method of claim 11 , wherein the replacement payload comprises statistics payload data.

14 . The method of claim 11 , further comprising transmitting the telemetry packet to a telemetry consumer.

15 . At least one non-transitory computer readable medium having instructions stored thereon, which when executed, cause a computing device to perform operations comprising:

receiving a packet via a network;

processing the packet, including:

examining a header within the packet to determine a destination of the packet;

determining that the destination is associated with one or more confidential connections associated with a tenant based on the destination of the packet;

preventing duplication and mirroring of telemetry packet data payloads upon determining that the destination is associated is associated with the one or more confidential connections, wherein a telemetry protection mode including a first telemetry protection mode or a second telemetry protection mode is determined based on the destination of the packet; and

generating a telemetry packet for telemetry monitoring, the telemetry packet including a replacement payload including empty payload data, wherein the replacement payload substitutes an original payload of the telemetry packet while preventing duplication of the replacement payload.

16 . The computer readable medium of claim 15 , wherein the operations further comprise generating the telemetry packet including a duplicate payload of the packet upon determining that the packet is associated with the second telemetry protection mode.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2022
From: KIDA, LUIS; PARIKH, NEERAV; LAL, RESHMA
To: INTEL CORPORATION
Reel/Frame 058743/0496 →
Continuity (1)
Related Publication 20220116403A1 · Apr 14, 2022
References Cited (10)
US 10574702B1 · Rickerd et al. · 2020 [cited by applicant]
US 20180063197A1 · Pope · 2018 [cited by examiner]
US 20200220713A1 · Li et al. · 2020 [cited by applicant]
US 20210160275A1 · Anderson · 2021 [cited by examiner]
US 20210194894A1 · Anderson · 2021 [cited by examiner]
US 20230198946A1 · Zacks · 2023 [cited by examiner]
WO 2023121746A · 2023 [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/US2022/046252, mailed Jan. 30, 2023, 10 pages. [cited by applicant]
Publication of CN Application No. 202280044875.4, mailed Feb. 26, 2024, 4 pages. [cited by applicant]
Non-Final Office Action issued in U.S. Appl. No. 18/756,763 mailed Sep. 22, 2025, 13 pages. [cited by applicant]