IP Library Granted Patent US 12,204,665
Granted Patent B2
US 12,204,665 · App. 17/959,741 · Granted Jan 21, 2025

Secure execution support for A.I. systems (and other heterogeneous systems)

Inventor: Richard H. Boivie (Monroe, CT)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/6209G06F9/54G06F21/602G06F21/72G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,665
App. No.
17/959,741
Granted
Jan 21, 2025
Kind
B2
Abstract

A method and apparatus for providing support for Secure Objects on a data processing system including providing a Secure Object comprising code and data that is protected on the data processing system on a first processor which is a first type of processor, wherein the data processing system includes a plurality of processors of different types, responsive to a portion of the Secure Object being needed to be executed on a second processor which is a second type of processor different than the first type of processor, by the first processor calling the second processor in a special interprocessor call, returning information by the second processor to the first processor, and retrieving, by the first processor, the information from the second processor.

Claims (38)

1. A method for providing support for Secure Objects on a data processing system comprising:

providing a Secure Object comprising code and data that is protected on the data processing system on a first processor which is a first type of processor, wherein the data processing system includes a plurality of processors of different types;

executing the Secure Object on the first processor;

determining that an identified portion of the Secured Object is to be processed on a second processor which is a second type of processor different than the first type of processor;

responsive to determining that the identified portion of the Secure Object is to be processed on the second processor, performing, using the first processor, a special interprocessor call to allow the second processor to access the identified portion of the Secured Object, wherein the special interprocessor call securely passes an encryption key from the first processor to the second processor which the second processor uses to access a cryptographically protected region in system memory;

processing, using the second processor, the identified portion of the Secured Object; and

returning information obtained by the second processor to the first processor.

2. The method according to claim 1 , in which the special interprocessor call securely passes an integrity value from the first processor to the second processor which the second processor uses to access a cryptographically protected region in system memory.

3. The method according to claim 1 , in which the special interprocessor call securely passes a Secure Object ID from the first processor to the second processor which the second processor uses to access a protected region in system memory.

4. The method according to claim 1 , wherein the second processor performs the processing requested in the special interprocessor call, storing encrypted information resulting from the processing in system memory.

5. The method according to claim 1 , wherein the return includes an integrity value for the Secure Object.

6. The method according to claim 1 , wherein the special interprocessor call includes an indication of a particular processor from among the first processor and the second processor that is being called, an indication of a specific function that is being requested and the data that should be processed.

7. The method according to claim 1 , wherein the data processing system is an artificial intelligence system.

8. The method according to claim 1 , wherein the second type of processor is one of a Central Processing Unit, a specialized processor, a Graphical Processing Unit, a Tensor Processing Unit, a Field Programmable Gate Array, an Artificial Neural Network, a Quantum Processor and a Cryptographic Processor,

wherein the first type of processor is one of the Central Processing Unit, the specialized processor, the Graphical Processing Unit, the Tensor Processing Unit, the Field Programmable Gate Array, the Artificial Neural Network, the Quantum Processor, and the Cryptographic Processor, and

wherein the first type of processor is different than the second type of processor.

9. A computer readable medium, storing a method for securing a Secure Object on a data processing system comprising:

providing a Secure Object comprising code and data that is protected on the data processing system on a first processor which is a first type of processor, wherein the data processing system includes a plurality of processors of different types;

executing the Secure Object on the first processor;

determining that an identified portion of the Secured Object is to be processed on a second processor which is a second type of processor different than the first type of processor;

responsive to determining that the identified portion of the Secure Object is to be processed on the second processor, performing, using the first processor, a special interprocessor call to allow a the second processor to access an the identified portion of the Secured Object, wherein the special interprocessor call securely passes an encryption key from the first processor to the second processor which the second processor uses to access a cryptographically protected region in system memory;

processing, using the second processor, the identified portion of the Secured Object; and

returning information obtained by the second processor to the first processor.

10. The computer readable medium according to claim 9 , in which the special interprocessor call securely passes an integrity value from the first processor to the second processor which the second processor uses to access a cryptographically protected region in system memory.

11. The computer readable medium according to claim 9 , in which the special interprocessor call securely passes a Secure Object ID from the first processor to the second processor which the second processor uses to access a protected region in system memory.

12. The computer readable medium according to claim 9 , wherein the second processor performs processing requested in the special interprocessor call, storing encrypted information resulting from the processing in system memory.

13. The computer readable medium according to claim 9 , wherein the return includes an integrity value for the Secure Object.

14. The computer readable medium according to claim 9 , wherein the special interprocessor call includes an indication of a particular processor from among the first processor and the second processor that is being called, an indication of a specific function that is being requested and the data that should be processed, and wherein the data processing system is an artificial intelligence system.

15. The computer readable medium according to claim 9 , wherein the second type of processor is one of a Central Processing Unit, a specialized processor, a Graphical Processing Unit, a Tensor Processing Unit, a Field Programmable Gate Array, an Artificial Neural Network, a Quantum Processor and a Cryptographic Processor,

wherein the first type of processor is one of the Central Processing Unit, the specialized processor, the Graphical Processing Unit, the Tensor Processing Unit, the Field Programmable Gate Array, the Artificial Neural Network, the Quantum Processor, and the Cryptographic Processor, and

wherein the first type of processor is different than the second type of processor.

16. A data processing system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable storage media, and program instructions stored on at least one of the one or more computer-readable tangible storage media for execution by at least one of the one or more processors via at least one of the one or more computer-readable memories, wherein the computer system is capable of performing a method comprising:

providing a Secure Object comprising code and data that is protected on the data processing system on a first processor which is a first type of processor, wherein the data processing system includes a plurality of processors of different types;

executing the Secure Object on the first processor;

determining that an identified portion of the Secured Object is to be processed on a second processor which is a second type of processor different than the first type of processor;

responsive to determining that the identified portion of the Secure Object is to be processed on the second processor, performing, using the first processor, a special interprocessor call to allow a the second processor to access an the identified portion of the Secured Object, wherein the special interprocessor call securely passes an encryption key from the first processor to the second processor which the second processor uses to access a cryptographically protected region in system memory;

processing, using the second processor, the identified portion of the Secured Object; and returning information obtained by the second processor to the first processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2022
From: BOIVIE, RICHARD H.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 061585/0250 →
Continuity (2)
Continuation 15977429 · May 11, 2018
Related Publication 20230034410A1 · Feb 2, 2023
References Cited (39)
US 9372967B2 · Boivie · 2016 [cited by applicant]
US 9727709B2 · Boivie · 2017 [cited by applicant]
US 11520913B2 · Boivie · 2022 [cited by applicant]
US 20060130128A1 · Gorancic · 2006 [cited by examiner]
US 20070226807A1 · Ginter et al. · 2007 [cited by applicant]
US 20080066075A1 · Nutter et al. · 2008 [cited by applicant]
US 20080295120A1 · Suzuki · 2008 [cited by examiner]
US 20120216051A1 · Boivie et al. · 2012 [cited by applicant]
US 20130067240A1 · Tamasi · 2013 [cited by examiner]
US 20140007044A1 · Aliseychik et al. · 2014 [cited by applicant]
US 20140053278A1 · Dellow · 2014 [cited by examiner]
US 20140304505A1 · Dawson · 2014 [cited by applicant]
US 20160041909A1 · Gu · 2016 [cited by examiner]
US 20160162171A1 · Yi · 2016 [cited by examiner]
US 20160171250A1 · Boivie et al. · 2016 [cited by applicant]
US 20160301759A1 · Xue · 2016 [cited by examiner]
US 20160378693A1 · Sasaki · 2016 [cited by examiner]
US 20170147798A1 · Yi · 2017 [cited by examiner]
US 20170286701A1 · Kim · 2017 [cited by examiner]
US 20170318008A1 · Mead · 2017 [cited by applicant]
US 20180373849A1 · Gidley · 2018 [cited by examiner]
US 20190012664A1 · Viola · 2019 [cited by examiner]
CN 101145173A · 2008 [cited by applicant]
CN 100580682C · 2010 [cited by applicant]
CN 102428473A · 2012 [cited by applicant]
CN 110472440B · 2023 [cited by applicant]
EP 3242241A1 · 2017 [cited by applicant]
Hategekimana et al., “Secure Hardware Kernels Execution in CPU+FPGA Heterogeneous Cloud,” 2018 International Conference on Field-Programmable Technology (FPT) Year: 2018 | Conference Paper | Publisher: IEEE. [cited by examiner]
Fan et al., “One Secure Access Scheme Based on Trusted Execution Environment,” 2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/ 12th IEEE International Conference O… [cited by examiner]
Chinese Office Action, dated Sep. 1, 2022, in Chinese Application No. 201910387553.X. [cited by applicant]
United States Office Action dated Apr. 14, 2022 in U.S. Appl. No. 15/977,429. [cited by applicant]
United States Office Action dated Oct. 29, 2021 in U.S. Appl. No. 15/977,429. [cited by applicant]
United States Office Action dated Jun. 2, 2021 in U.S. Appl. No. 15/977,429. [cited by applicant]
United States Office Action dated Feb. 5, 2021 in U.S. Appl. No. 15/977,429. [cited by applicant]
United States Office Action dated May 18, 2020 in U.S. Appl. No. 15/977,429. [cited by applicant]
United States Office Action dated Jan. 22, 2020 in U.S. Appl. No. 15/977,429. [cited by applicant]
United States Notice of Allowance dated Jul. 6, 2022 in U.S. Appl. No. 15/977,429. [cited by applicant]
Hategekimana et al., “Secure Hardware Kernels Execution in CPU+FPGA Heterogeneous Cloud,” 2018 International Conference on Field-Programmable Technology (FPT) Year: 20181 Conference Paper | Publisher: IEEE. [cited by applicant]
List of IBM Patents or Patent Applications Treated as Related, Oct. 31, 2023, 2 pages. [cited by applicant]