IP Library › Granted Patent US 11,651,112
Granted Patent B2
US 11,651,112 · App. 17/712,350 · Granted May 16, 2023

Enabling stateless accelerator designs shared across mutually-distrustful tenants

Inventors: Alpa Trivedi (Portland, OR); Carlos Rozas (Portland, OR)
Assignee: INTEL CORPORATION
G06F21/85G06F9/30101G06F9/3877G06F9/505G06F11/0709G06F11/0751G06F11/0754G06F11/0793G06F11/3058G06F15/177G06F15/7825G06F15/7867G06F30/331G06F30/398G06N3/04H04L9/0877H04L63/0442H04L63/12H04L63/20G06F11/0772G06F11/3051G06F21/30G06F21/44G06F21/53G06F21/57G06F21/575G06F21/71G06F21/73G06F21/74G06F21/76G06F30/31G06F2111/04G06F2119/12G06F2221/034G06N3/08G06N20/00H04L9/008H04L9/0841
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,651,112
App. No.
17/712,350
Filed
Apr 4, 2022
Granted
May 16, 2023
Kind
B2
Art Unit
2431
USPC
713/150
Abstract

An apparatus to facilitate enabling stateless accelerator designs shared across mutually-distrustful tenants is disclosed. The apparatus includes a fully-homomorphic encryption (FHE)-capable circuitry to establish a secure session with a trusted environment executing on a host device communicably coupled to the apparatus; generate, as part of establishing the secure session, per-tenant FHE keys for each tenant utilizing the FHE-capable circuitry, the per-tenant FHE keys utilized to encrypt tenant data provided to an FHE-capable compute kernel of the FHE-capable circuitry; process tenant data that is in an FHE-encrypted format encrypted with a per-tenant FHE key of the per-tenant FHE keys; and store the tenant data that is in the FHE-encrypted format encrypted with the per-tenant FHE key of the per-tenant FHE keys.

Claims (36)

1. An apparatus comprising:

a fully-homomorphic encryption (FHE)-capable circuitry to:

establish a secure session with a trusted environment executing on a host device communicably coupled to the apparatus;

generate, as part of establishing the secure session, per-tenant FHE keys for each tenant utilizing the FHE-capable circuitry, the per-tenant FHE keys utilized to encrypt tenant data provided to an FHE-capable compute kernel of the FHE-capable circuitry;

process tenant data that is in an FHE-encrypted format encrypted with a per-tenant FHE key of the per-tenant FHE keys; and

store the tenant data that is in the FHE-encrypted format encrypted with the per-tenant FHE key of the per-tenant FHE keys;

wherein an orchestrator component that is communicably coupled to the FHE-capable circuitry facilitates establishing the secure session with the trusted environment on the host device.

2. The apparatus of claim 1 , wherein the FHE-capable circuitry comprises at least one of the FHE-capable compute kernel comprising a partial configuration bitstream of a field-programmable gate array (FPGA) or an FHE-capable neural network.

3. The apparatus of claim 1 , wherein the FHE-capable circuitry to process the tenant data that is in the FHE-encrypted format comprising at least one of ciphertext or opaque data.

4. The apparatus of claim 1 , wherein the secure session is established using at least one of Diffie Hellman specification or a Security Protocol and Data Model (SPDM) specification.

5. The apparatus of claim 1 , wherein the trusted environment comprises a trusted execution environment (TEE) of the host device.

6. The apparatus of claim 1 , wherein the FHE-capable circuitry to process the tenant data and to process other tenant data encrypted with other per-tenant FHE keys in at least one of a time-sliced or temporal multi-tenant usage model.

7. The apparatus of claim 1 , wherein the apparatus comprises a hardware accelerator device comprising at least one a graphic processing unit (GPU), a central processing unit (CPU), or a programmable integrated circuit (IC).

8. The apparatus of claim 7 , wherein the programmable IC comprises at least one of a field programmable gate array (FPGA), a programmable array logic (PAL), a programmable logic array (PLA), a field programmable logic array (FPLA), an electrically programmable logic device (EPLD), an electrically erasable programmable logic device (EEPLD), a logic cell array (LCA), or a complex programmable logic devices (CPLD).

9. A method comprising:

establishing, by a fully-homomorphic encryption (FHE)-capable circuitry of an accelerator device, a secure session with a trusted environment executing on a host device communicably coupled to the accelerator device;

generating, by the FHE-capable circuitry as part of establishing the secure session, per-tenant FHE keys for each tenant utilizing the FHE-capable circuitry, the per-tenant FHE keys utilized to encrypt tenant data provided to an FHE-capable compute kernel of the FHE-capable circuitry;

processing, by the FHE-capable circuitry, tenant data that is in an FHE-encrypted format encrypted with a per-tenant FHE key of the per-tenant FHE keys; and

storing, by the FHE-capable circuitry, the tenant data that is in the FHE-encrypted format encrypted with the per-tenant FHE key of the per-tenant FHE keys;

wherein an orchestrator component that is communicably coupled to the FHE-capable circuitry facilitates establishing the secure session with the trusted environment on the host device.

10. The method of claim 9 , wherein the FHE-capable circuitry comprises at least one of the FHE-capable compute kernel comprising a partial configuration bitstream of a field-programmable gate array (FPGA) or an FHE-capable neural network.

11. The method of claim 9 , wherein the FHE-capable circuitry to process the tenant data that is in the FHE-encrypted format comprising at least one of ciphertext or opaque data.

12. The method of claim 9 , wherein the FHE-capable circuitry to process the tenant data and to process other tenant data encrypted with other per-tenant FHE keys in at least one of a time-sliced or temporal multi-tenant usage model.

13. The method of claim 9 , wherein the accelerator device comprising at least one a graphic processing unit (GPU), a central processing unit (CPU), or a programmable integrated circuit (IC), and wherein the programmable IC comprises at least one of a field programmable gate array (FPGA), a programmable array logic (PAL), a programmable logic array (PLA), a field programmable logic array (FPLA), an electrically programmable logic device (EPLD), an electrically erasable programmable logic device (EEPLD), a logic cell array (LCA), or a complex programmable logic devices (CPLD).

14. The method of claim 9 , wherein the trusted environment comprises a trusted execution environment (TEE) of the host device.

15. A non-transitory machine readable storage medium comprising instructions that, when executed, cause at least one processor to at least:

establish, by a fully-homomorphic encryption (FHE)-capable circuitry of an accelerator device comprising the at least one processor, a secure session with a trusted environment executing on a host device communicably coupled to the accelerator device;

generate, by the FHE-capable circuitry as part of establishing the secure session, per-tenant FHE keys for each tenant utilizing the FHE-capable circuitry, the per-tenant FHE keys utilized to encrypt tenant data provided to an FHE-capable compute kernel of the FHE-capable circuitry;

process, by the FHE-capable circuitry, tenant data that is in an FHE-encrypted format encrypted with a per-tenant FHE key of the per-tenant FHE keys; and

store, by the FHE-capable circuitry, the tenant data that is in the FHE-encrypted format encrypted with the per-tenant FHE key of the per-tenant FHE keys;

wherein an orchestrator component that is communicably coupled to the FHE-capable circuitry facilitates establishing the secure session with the trusted environment on the host device.

16. The non-transitory machine readable storage medium of claim 15 , wherein the FHE-capable circuitry comprises at least one of the FHE-capable compute kernel comprising a partial configuration bitstream of a field-programmable gate array (FPGA) or an FHE-capable neural network.

17. The non-transitory machine readable storage medium of claim 15 , wherein the FHE-capable circuitry to process the tenant data that is in the FHE-encrypted format comprising at least one of ciphertext or opaque data.

18. The non-transitory machine readable storage medium of claim 15 , wherein the FHE-capable circuitry to process the tenant data and to process other tenant data encrypted with other per-tenant FHE keys in at least one of a time-sliced or temporal multi-tenant usage model.

19. The non-transitory machine readable storage medium of claim 15 , wherein the trusted environment comprises a trusted execution environment (TEE) of the host device.

20. The non-transitory machine readable storage medium of claim 15 , wherein the secure session is established using at least one of Diffie Hellman specification or a Security Protocol and Data Model (SPDM) specification.

Continuity (3)
Continuation 17130407 · Dec 22, 2020
Provisional Application 63083783 · Sep 25, 2020
Related Publication 20220222203A1 · Jul 14, 2022
Cited By (3)
US 12,287,909 US 12,340,007 US 12,346,489