IP Library › Granted Patent US 12,519,835
Granted Patent B2
US 12,519,835 · App. 18/079,558 · Granted Jan 6, 2026

Confidential computing environment including devices connected to a network interface device

Inventors: Kapil Sood (Portland, OR); Patrick Connor (Beaverton, OR); Scott P. Dubal (Oregon City, OR); James R. Hearn (Hillsboro, OR)
Assignee: Intel Corporation
H04L63/20H04L67/10H04L67/51
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,835
App. No.
18/079,558
Filed
Dec 12, 2022
Granted
Jan 6, 2026
Kind
B2
Art Unit
2441
USPC
709/203
Abstract

Examples described herein relate to extending a first trust domain of a service to a service mesh interface executed in a network interface device and to at least one device coupled to the network interface device. In some examples, extending the first trust domain of the service to the service mesh interface executed in the network interface device and to the at least one device coupled to the network interface device includes causing execution of the service mesh interface in a second trust domain in the network interface device; providing a third trust domain for the at least one device, when connected to the network interface device; and extending the first trust domain into the second trust domain or the third trust domain.

Claims (43)

1 . At least one non-transitory computer-readable medium, comprising instructions stored thereon, that if executed by one or more processors, cause the one or more processors to:

execute an orchestrator to extend a first trust domain of a service to a service mesh interface executed in a network interface device and to at least one device coupled to the network interface device;

wherein the extend the first trust domain of the service to the service mesh interface executed in the network interface device and to the at least one device coupled to the network interface device comprises:

cause execution of the service mesh interface in a second trust domain in the network interface device; and

extend the first trust domain into the second trust domain.

2 . The computer-readable medium of claim 1 , wherein the extend the first trust domain of the service to the service mesh interface executed in the network interface device and to the at least one device coupled to the network interface device comprises:

provide a third trust domain for the at least one device, when connected to the network interface device; and

extend the first trust domain into the third trust domain.

3 . The computer-readable medium of claim 1 , comprising instructions stored thereon, that if executed by one or more processors, cause the one or more processors to:

execute the orchestrator to:

assign a unique identity per assignable interface for access to the at least one device and

perform attestation of the at least one device based on the unique identity and a firmware signature.

4 . The computer-readable medium of claim 3 , wherein connections based on the assignable interface do not share keys after authentication.

5 . The computer-readable medium of claim 2 , comprising instructions stored thereon, that if executed by one or more processors, cause the one or more processors to:

assign the at least one device to the third trust domain based on authentication of the at least one device.

6 . The computer-readable medium of claim 1 , wherein the at least one device comprises one or more of: a storage device, accelerator, graphics processing unit (GPU), general purpose GPU (GPGPU), and/or a memory device.

7 . The computer-readable medium of claim 2 , wherein the service mesh interface is associated with an infrastructure provider and the first and third trust domains are provided for a tenant.

8 . The computer-readable medium of claim 2 , wherein the service mesh interface is associated with a tenant and the first, second, and third trust domains are provided for the tenant.

9 . The computer-readable medium of claim 1 , wherein the network interface device comprises one or more of: a network interface controller (NIC), a remote direct memory access (RDMA)-enabled NIC, SmartNIC, router, switch, forwarding element, infrastructure processing unit (IPU), or data processing unit (DPU).

10 . A method comprising:

providing a confidential computing security environment for multiple tenants to execute one or more services within multiple associated trust domains,

wherein: one or more services associated with a tenant access a service mesh interface within a trust domain, wherein the service mesh interface is executed by a network interface device and the one or more services associated with the tenant are to access at least one device coupled to the network interface device via at least one secure channel; and

performing attestation to determine whether the trust domain is to be extended to communicate with a trust domain of the service mesh interface and the at least one secure channel.

11 . The method of claim 10 , wherein the at least one secure channel is associated with an assignable interface for access to the at least one device.

12 . The method of claim 10 , comprising:

performing attestation of the at least one device based on at least one device identity and at least one firmware signature.

13 . The method of claim 10 , wherein the at least one device comprises one or more of: a storage device, accelerator, graphics processing unit (GPU), general purpose GPU (GPGPU), and/or a memory device.

14 . The method of claim 10 , wherein the service mesh interface is provided by an infrastructure provider.

15 . The method of claim 10 , wherein the service mesh interface is associated with the tenant associated with the one or more services.

16 . An apparatus comprising:

a network interface device comprising:

a network interface;

at least one processor; and

circuitry to:

execute a service mesh interface in a first trust domain in the at least one processor;

provide a second trust domain for one or more devices connected to the network interface device via one or more device interfaces;

perform attestation to determine whether a trust domain is to be extended to communicate with the first trust domain and the second trust domain;

extend the trust domain in which a service is executed to include the first trust domain and the second trust domain; and

transmit one or more packets to the service mesh interface from the service.

17 . The apparatus of claim 16 , wherein the circuitry is to:

assign the one or more devices to the second trust domain based on authentication of the one or more devices.

18 . The apparatus of claim 16 , wherein the one or more devices comprise one or more of: a storage device, accelerator, graphics processing unit (GPU), general purpose GPU (GPGPU), and/or a memory device.

19 . The apparatus of claim 16 , wherein the service mesh interface is associated with an infrastructure provider and the first and second trust domains are provided for a tenant.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2023
From: SOOD, KAPIL; CONNOR, PATRICK; DUBAL, SCOTT P.; HEARN, JAMES R.
To: INTEL CORPORATION
Reel/Frame 062274/0674 →
Continuity (2)
Continuation In Part 17845898 · Jun 21, 2022
Related Publication 20230106581A1 · Apr 6, 2023
References Cited (15)
US 11019033B1 · Perlman et al. · 2021 [cited by applicant]
US 12245117B1 · Scriber · 2025 [cited by examiner]
US 20080222711A1 · Michaelis · 2008 [cited by examiner]
US 20170041347A1 · Nagaratnam et al. · 2017 [cited by applicant]
US 20200092254A1 · Goeringer · 2020 [cited by examiner]
US 20210117249A1 · Doshi et al. · 2021 [cited by applicant]
US 20210135983A1 · Farnham · 2021 [cited by applicant]
US 20220086148A1 · Chaganti · 2022 [cited by examiner]
US 20220094690A1 · Tarkhanyan et al. · 2022 [cited by applicant]
US 20220329573A1 · Sood et al. · 2022 [cited by applicant]
US 20230205562A1 · Basak · 2023 [cited by examiner]
Microsoft Learn, “Security Management”, https://learn.microsoft.com/en-us/windows/win32/secmgmt/primary-and-trusted-domains, Jan. 7, 2021, 371 pages. [cited by applicant]
Red Hat, “What's a service mesh?”, https://www.redhat.com/en/topics/microservices/what-is-a-service-mesh, Published Jun. 29, 2018, 7 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/845,898, Mailed Sep. 17, 2024, 17 pages. [cited by applicant]
First Office Action for U.S. Appl. No. 17/845,898, Mailed Jun. 7, 2024, 26 pages. [cited by applicant]
Cited By (1)
US 12,726,350