Patents by Inventor Kapil Sood

Kapil Sood has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260141123
    Abstract: An apparatus and method for extending IO device security protocols to integrated processors. For example, an example processor package comprises: a plurality of cores to execute instructions; an interconnect fabric coupled to the plurality of cores; memory interface circuitry coupled to the interconnect fabric, the memory interface circuitry to couple the plurality of cores to one or more memories; a root complex comprising: security circuitry operable as a root of trust (ROT) and a bridge to the interconnect fabric, the security circuitry to establish secure communication with one or more Root Complex Integrated Endpoint (RCiEP) devices integral to the processor package; and a Security Protocol and Data Model (SPDM) engine of the security circuitry to provide RCiEP encryption and SPDM protocol services to establish secure communication channels with each RCiEP device.
    Type: Application
    Filed: March 28, 2025
    Publication date: May 21, 2026
    Applicant: Intel Corporation
    Inventors: Arie AHARON, Kapil SOOD, Rupin H. VAKHARWALA, Eric GEISLER, Tessil THOMAS, Shalini SHARMA, Lakshmi SRINIVAS, Asher ALTMAN
  • Publication number: 20260093629
    Abstract: An apparatus of an aspect includes a cache coherency protocol controller to receive a first packet of a cache coherency protocol. The first packet is to have been transmitted from a device over a communication link. The first packet has one or more bits to indicate destination location where data from the device is to be routed. The apparatus also includes circuitry coupled with the cache coherency protocol controller to receive the first packet. The circuitry is to generate a second packet based on the first packet. The second packet is to indicate the destination location. The apparatus also includes a fabric coupled with the circuitry to receive the second packet. The fabric is to route the data to the destination location indicated by the second packet. In one aspect, the cache coherency protocol is a CXL.cache cache coherency protocol. Other apparatus, methods, and systems are also disclosed.
    Type: Application
    Filed: September 27, 2024
    Publication date: April 2, 2026
    Inventors: Kishore Karthikeyan, Niall McDonnell, Yen-Cheng Liu, Daniel Joe, Naveen Lakkakula, Kapil Sood, Chitra Natarajan
  • Patent number: 12519835
    Abstract: Examples described herein relate to extending a first trust domain of a service to a service mesh interface executed in a network interface device and to at least one device coupled to the network interface device. In some examples, extending the first trust domain of the service to the service mesh interface executed in the network interface device and to the at least one device coupled to the network interface device includes causing execution of the service mesh interface in a second trust domain in the network interface device; providing a third trust domain for the at least one device, when connected to the network interface device; and extending the first trust domain into the second trust domain or the third trust domain.
    Type: Grant
    Filed: December 12, 2022
    Date of Patent: January 6, 2026
    Assignee: Intel Corporation
    Inventors: Kapil Sood, Patrick Connor, Scott P. Dubal, James R. Hearn
  • Publication number: 20260006009
    Abstract: Various methods, systems, and use cases for securely managing, generating, and controlling access to keys in a service mesh are discussed herein. In various examples, key protection operations include service mesh signing key protection and service mesh communication key protection, for a secure transport session between services such as conducted with mutual transport layer security (mTLS). For instance, such key protection operations may be used to establish communications between the service host and another entity within the service mesh, in a secure transport session, based on use of a private key (secured using a confidential computing technology) in a secure enclave or other secure compute environment to sign one or more keys for the secure transport session.
    Type: Application
    Filed: August 28, 2025
    Publication date: January 1, 2026
    Inventors: Kapil Sood, Srinivasa Addepalli, Dong Guo, Sakari Poussa, Kailun Qin, Ismo Puustinen, Veronika Karpenko
  • Patent number: 12481492
    Abstract: Various systems and methods for enabling derivation and distribution of an attestation manifest for a software update image are described. In an example, these systems and methods include orchestration functions and communications, providing functionality and components for a software update process which also provides verification and attestation among multiple devices and operators.
    Type: Grant
    Filed: January 23, 2024
    Date of Patent: November 25, 2025
    Assignee: Intel Corporation
    Inventors: Ned M. Smith, Kshitij Arun Doshi, John Joseph Browne, Vincent J. Zimmer, Francesc Guim Bernat, Kapil Sood
  • Publication number: 20250356036
    Abstract: Examples described herein relate to a chiplet comprising a circuitry to store a security policy, specific to the chiplet, and a second chiplet comprising a second circuitry to store a second security policy, specific to the second chiplet. In some examples, at least two of the multiple chiplets are from different chiplet manufacturers.
    Type: Application
    Filed: August 4, 2025
    Publication date: November 20, 2025
    Inventors: Kapil SOOD, Anjali SOOD
  • Publication number: 20250322082
    Abstract: Examples herein relate to an interface selectively providing access to a memory region for a work request from an entity by providing selective access to a physical address of the memory region and selective access to a cryptographic key for use by a memory controller to access the memory region. In some examples, providing selective access to a physical address conversion is based on one or more of: validation of a certificate received with the work request and an identifier of the entity being associated with a process with access to the memory region. Access to the memory region can be specified. A memory region can be a page or sub-page sized region. Different access rights can be associated with different sub-portions of the memory region, wherein the access rights comprise one or more of: create, read, update, delete, write, or notify.
    Type: Application
    Filed: May 21, 2025
    Publication date: October 16, 2025
    Applicant: Intel Corporation
    Inventors: Ned SMITH, Kshitij A. DOSHI, Francesc GUIM BERNAT, Kapil SOOD, Tarun VISWANATHAN
  • Patent number: 12425380
    Abstract: Various methods, systems, and use cases for securely managing, generating, and controlling access to keys in a service mesh are discussed herein. In various examples, key protection operations include service mesh signing key protection and service mesh communication key protection, for a secure transport session between services such as conducted with mutual transport layer security (mTLS). For instance, such key protection operations may be used to establish communications between the service host and another entity within the service mesh, in a secure transport session, based on use of a private key (secured using a confidential computing technology) in a secure enclave or other secure compute environment to sign one or more keys for the secure transport session.
    Type: Grant
    Filed: March 25, 2022
    Date of Patent: September 23, 2025
    Assignee: Intel Corporation
    Inventors: Kapil Sood, Srinivasa Addepalli, Dong Guo, Sakari Poussa, Kailun Qin, Ismo Puustinen, Veronika Karpenko
  • Patent number: 12339978
    Abstract: A network interface controller (NIC) to interact with virtual environments when they are within a trusted environment protected by a cryptography scheme. The NIC performs encryption of data in accordance with the cryptographic scheme of a target trusted environment prior to copying the data for access by the target trusted environment.
    Type: Grant
    Filed: February 2, 2021
    Date of Patent: June 24, 2025
    Assignee: Intel Corporation
    Inventors: Kapil Sood, Patrick Connor
  • Patent number: 12333025
    Abstract: Examples herein relate to an interface selectively providing access to a memory region for a work request from an entity by providing selective access to a physical address of the memory region and selective access to a cryptographic key for use by a memory controller to access the memory region. In some examples, providing selective access to a physical address conversion is based on one or more of: validation of a certificate received with the work request and an identifier of the entity being associated with a process with access to the memory region. Access to the memory region can be specified to be one or more of: create, read, update, delete, write, or notify. A memory region can be a page or sub-page sized region. Different access rights can be associated with different sub-portions of the memory region, wherein the access rights comprise one or more of: create, read, update, delete, write, or notify.
    Type: Grant
    Filed: September 19, 2023
    Date of Patent: June 17, 2025
    Assignee: Intel Corporation
    Inventors: Ned Smith, Kshitij A. Doshi, Francesc Guim Bernat, Kapil Sood, Tarun Viswanathan
  • Patent number: 12277228
    Abstract: Disclosed herein are embodiments related to security in cloudlet environments. In some embodiments, for example, a computing device (e.g., a cloudlet) may include: a trusted execution environment; a Basic Input/Output System (BIOS) to request a Key Encryption Key (KEK) from the trusted execution environment; and a Self-Encrypting Storage (SES) associated with the KEK; wherein the trusted execution environment is to verify the BIOS and provide the KEK to the BIOS subsequent to verification of the BIOS, and the BIOS is to provide the KEK to the SES to unlock the SES for access by the trusted execution environment.
    Type: Grant
    Filed: July 18, 2023
    Date of Patent: April 15, 2025
    Assignee: Intel Corporation
    Inventors: Yeluri Raghuram, Susanne M. Balle, Nigel Thomas Cook, Kapil Sood
  • Publication number: 20250106191
    Abstract: Technologies for providing secure utilization of tenant keys include a compute device. The compute device includes circuitry configured to obtain a tenant key. The circuitry is also configured to receive encrypted data associated with a tenant. The encrypted data defines an encrypted image that is executable by the compute device to perform a workload on behalf of the tenant in a virtualized environment. Further, the circuitry is configured to utilize the tenant key to decrypt the encrypted data and execute the workload without exposing the tenant key to a memory that is accessible to another workload associated with another tenant.
    Type: Application
    Filed: December 10, 2024
    Publication date: March 27, 2025
    Applicant: Intel Corporation
    Inventors: Kapil Sood, Seosamh O'Riordain, Ned M. Smith, Tarun Viswanathan
  • Patent number: 12244507
    Abstract: Systems and techniques for intelligent data forwarding in edge networks are described herein. A request may be received from an edge user device for a service via a first endpoint. A time value may be calculated using a timestamp of the request. Motion characteristics may be determined for the edge user device using the time value. A response to the request may be transmitted to a second endpoint based on the motion characteristics.
    Type: Grant
    Filed: September 25, 2020
    Date of Patent: March 4, 2025
    Assignee: Intel Corporation
    Inventors: Francesc Guim Bernat, Ned M. Smith, Kshitij Arun Doshi, Suraj Prabhakaran, Timothy Verrall, Kapil Sood, Tarun Viswanathan
  • Patent number: 12206552
    Abstract: Various aspects of methods, systems, and use cases for multi-entity (e.g., multi-tenant) edge computing deployments are disclosed. Among other examples, various configurations and features enable the management of resources (e.g., controlling and orchestrating hardware, acceleration, network, processing resource usage), security (e.g., secure execution and communication, isolation, conflicts), and service management (e.g., orchestration, connectivity, workload coordination), in edge computing deployments, such as by a plurality of edge nodes of an edge computing environment configured for executing workloads from among multiple tenants.
    Type: Grant
    Filed: December 11, 2020
    Date of Patent: January 21, 2025
    Assignee: Intel Corporation
    Inventors: Francesc Guim Bernat, Kshitij Arun Doshi, Kapil Sood, Tarun Viswanathan
  • Patent number: 12199962
    Abstract: Technologies for providing secure utilization of tenant keys include a compute device. The compute device includes circuitry configured to obtain a tenant key. The circuitry is also configured to receive encrypted data associated with a tenant. The encrypted data defines an encrypted image that is executable by the compute device to perform a workload on behalf of the tenant in a virtualized environment. Further, the circuitry is configured to utilize the tenant key to decrypt the encrypted data and execute the workload without exposing the tenant key to a memory that is accessible to another workload associated with another tenant.
    Type: Grant
    Filed: February 7, 2024
    Date of Patent: January 14, 2025
    Assignee: Intel Corporation
    Inventors: Kapil Sood, Seosamh O'Riordain, Ned M. Smith, Tarun Viswanathan
  • Publication number: 20240419844
    Abstract: Systems, apparatus, articles of manufacture, and methods are disclosed for confidential computing security management for a multi-chiplet, multi-accelerator system-in-package. An example multi-die System-In-Package (SiP) includes a first die including a circuit. Additionally, the example multi-die SiP includes a second die to authenticate the circuit to permit secure communication within the SiP.
    Type: Application
    Filed: August 30, 2024
    Publication date: December 19, 2024
    Inventors: Kapil Sood, Arie Aharon, Asher M. Altman, Venkidesh Krishna Iyer, Eli Kupermann, Pere Monclus, Lokpraveen Bhupathy Mosur, Yanai Moyal, Nicholas G. Ross
  • Publication number: 20240419616
    Abstract: Systems, apparatus, articles of manufacture, and methods are disclosed for memory access for multi-chiplet system-in-package. Example instructions cause at least one circuit in a system-in-package (SiP) to reserve a region in a memory associated with the SiP for exclusive use by a first die of the SiP apart from a second die of the SiP. For example, the memory is for use by multiple, respective, dies of the SiP.
    Type: Application
    Filed: August 30, 2024
    Publication date: December 19, 2024
    Inventors: Kapil Sood, Naveen Lakkakula, Lokpraveen Bhupathy Mosur, Vladimir Beker, Yen-Cheng Liu, Filip Schmole, Patrick Fleming, Liron Shacham
  • Patent number: 12132825
    Abstract: Technologies for accelerated key caching in an edge hierarchy include multiple edge appliance devices organized in tiers. An edge appliance device receives a request for a key, such as a private key. The edge appliance device determines whether the key is included in a local key cache and, if not, requests the key from an edge appliance device included in an inner tier of the edge hierarchy. The edge appliance device may request the key from an edge appliance device included in a peer tier of the edge hierarchy. The edge appliance device may activate per-tenant accelerated logic to identify one or more keys in the key cache for eviction. The edge appliance device may activate per-tenant accelerated logic to identify one or more keys for pre-fetching. Those functions of the edge appliance device may be performed by an accelerator such as an FPGA. Other embodiments are described and claimed.
    Type: Grant
    Filed: December 23, 2021
    Date of Patent: October 29, 2024
    Assignee: Intel Corporation
    Inventors: Timothy Verrall, Thomas Willhalm, Francesc Guim Bernat, Karthik Kumar, Ned M. Smith, Rajesh Poornachandran, Kapil Sood, Tarun Viswanathan, John J. Browne, Patrick Kutch
  • Publication number: 20240319979
    Abstract: Various systems and methods for enabling derivation and distribution of an attestation manifest for a software update image are described. In an example, these systems and methods include orchestration functions and communications, providing functionality and components for a software update process which also provides verification and attestation among multiple devices and operators.
    Type: Application
    Filed: January 23, 2024
    Publication date: September 26, 2024
    Inventors: Ned M. Smith, Kshitij Arun Doshi, John Joseph Browne, Vincent J. Zimmer, Francesc Guim Bernat, Kapil Sood
  • Publication number: 20240305616
    Abstract: Technologies for providing secure utilization of tenant keys include a compute device. The compute device includes circuitry configured to obtain a tenant key. The circuitry is also configured to receive encrypted data associated with a tenant. The encrypted data defines an encrypted image that is executable by the compute device to perform a workload on behalf of the tenant in a virtualized environment. Further, the circuitry is configured to utilize the tenant key to decrypt the encrypted data and execute the workload without exposing the tenant key to a memory that is accessible to another workload associated with another tenant.
    Type: Application
    Filed: February 7, 2024
    Publication date: September 12, 2024
    Inventors: Kapil Sood, Seosamh O'Riordain, Ned M. Smith, Tarun Viswanathan