Multi-tenancy protection for accelerators
Abstract
An accelerator includes a memory, a compute zone to receive an encrypted workload downloaded from a tenant application running in a virtual machine on a host computing system attached to the accelerator, and a processor subsystem to execute a cryptographic key exchange protocol with the tenant application to derive a session key for the compute zone and to program the session key into the compute zone. The compute zone is to decrypt the encrypted workload using the session key, receive an encrypted data stream from the tenant application, decrypt the encrypted data stream using the session key, and process the decrypted data stream by executing the workload to produce metadata.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An accelerator comprising:
a memory; a first compute zone to receive an encrypted workload downloaded from a tenant application running in a virtual machine on a host computing system attached to the accelerator; a processor subsystem to execute a cryptographic key exchange protocol with the tenant application to derive a session key for the first compute zone and to program the session key into the first compute zone, wherein the first compute zone is to decrypt the encrypted workload using the session key, receive an encrypted data stream from the tenant application, decrypt the encrypted data stream using the session key, and process the decrypted data stream by executing the workload to produce metadata.
2 . The accelerator of claim 1 , wherein the tenant application communicates with the first compute zone over a physical function of a bus coupling the host computing system and the accelerator.
3 . The accelerator of claim 1 , wherein the accelerator comprises a plurality of compute zones and the first compute zone is isolated from other compute zones in the accelerator.
4 . The accelerator of claim 1 , comprising a plurality of compute zones and data stored in a protected region of the memory assigned to the first compute zone is isolated from access by other compute zones in the accelerator.
5 . The accelerator of claim 4 , wherein the first compute zone stores the decrypted data stream and the metadata in the protected region of the memory assigned to the first compute zone.
6 . The accelerator of claim 4 , wherein the protected region of the memory is assigned to the first compute zone by setting one or more using isolated memory region (IMR) registers in the processor subsystem.
7 . The accelerator of claim 1 , wherein the first compute zone encrypts the metadata using the session key and sends the encrypted metadata to the tenant application.
8 . The accelerator of claim 1 , wherein the processor subsystem operates in a trusted execution environment.
9 . The accelerator of claim 1 , wherein the first compute zone comprises one or more cryptographic engines to perform cryptographic operations on the encrypted workload and the encrypted data stream; one or more media engines to perform media operations on the decrypted data stream, and one or more inference engines to execute the decrypted workload to process the decrypted data stream.
10 . The accelerator of claim 9 , wherein the one or more inference engines comprise one or more machine learning models.
11 . The accelerator of claim 1 , comprising an accelerator embodying the memory, the first compute function and the processor subsystem, as a system on a chip (SoC) attached the host computing system over one or more physical functions of a bus.
12 . The accelerator of claim 11 , wherein the host computing system comprises a resource manager to detect one or more compute zones in the accelerator, assign at least one physical function to each of the one or more detected compute zones, receive a request to assign the first compute zone to the tenant application, assign the first compute zone to the virtual machine of the tenant application, start the virtual machine, and start the tenant application in the virtual machine.
13 . The accelerator of claim 12 , wherein the virtual machine comprises a compute zone driver to detect the physical function coupled to the first compute zone and to cause the accelerator to initialize the first compute zone.
14 . A method comprising:
receiving, by a first compute zone of an accelerator, an encrypted workload downloaded from a tenant application running in a virtual machine on a host computing system attached to the accelerator; executing, by a processor subsystem of the accelerator, a cryptographic key exchange protocol with the tenant application to derive a session key for the first compute zone and to program the session key into the first compute zone, decrypting, by the first compute zone, the encrypted workload using the session key; receiving, by the first computer zone, an encrypted data stream from the tenant application; decrypting, by the first compute zone, the encrypted data stream using the session key; and processing, by the first compute zone, the decrypted data stream by executing the workload to produce metadata.
15 . The method of claim 14 , wherein the accelerator comprises a plurality of compute zones and comprising isolating, by the accelerator, data stored in a protected region of the memory assigned to the first compute zone from access by other compute zones in the accelerator.
16 . The method of claim 14 , comprising storing, by the first compute zone, the decrypted data stream and the metadata in a protected region of a memory assigned to the first compute zone.
17 . The method of claim 14 , wherein the first compute zone encrypts the metadata using the session key and sends the encrypted metadata to the tenant application.
18 . One or more non-transitory computer-readable storage mediums having stored thereon executable computer program instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
Receiving an encrypted workload downloaded from a tenant application running in a virtual machine on a host computing system attached to the accelerator; Executing a cryptographic key exchange protocol with the tenant application to derive a session key for a first compute zone and to program the session key into the first compute zone, decrypting the encrypted workload using the session key; receiving an encrypted data stream from the tenant application; decrypting the encrypted data stream using the session key; and processing the decrypted data stream by executing the workload to produce metadata.
19 . The one or more mediums of claim 18 , wherein the accelerator comprises a plurality of compute zones and wherein the instructions further include instructions for comprising isolating data stored in a protected region of the memory assigned to the first compute zone from access by other compute zones in the accelerator.
20 . The one or more mediums of claim 18 , wherein the instructions further include instructions for storing the decrypted data stream and the metadata in a protected region of a memory assigned to the first compute zone.Join the waitlist — get patent alerts
Track US2022311594A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.