AMD · Filed Mar 31, 2025 · Published Oct 1, 2026

AMD Patents a Hardware Circuit That Blocks Unauthorized GPU Memory Access

When multiple programs share the same GPU memory, one rogue process could peek at another's data. AMD is patenting a dedicated hardware circuit to catch that before it happens.

A computer system with a central processor, memory, input/output circuitry, and accelerator units, all connected to manage memory access. Drawing from patent filing US 2026/0299800 A1.
A computer system with a central processor, memory, input/output circuitry, and accelerator units, all connected to manage memory access.
See all 6 drawings from this filing ↓
Publication number US 2026/0299800 A1
Applicant ATI Technologies ULC
Filing date Mar 31, 2025
Publication date Oct 1, 2026
Inventors Robert Landon Pelt, Steven Jidong Tu, Abin Thomas, Alexander Joseph Branover, Nippon HarshadKumar Raval, Chetty Somu Karuppan
US classification 711/163
Examiner HASAN, MOHAMMAD S (Art Unit 2138)
Status when we published Approved; patent expected soon (Sep 8, 2026)
Document 20 claims

What AMD's GPU memory security check actually does

A shared office printer keeps everyone's documents separate, so your colleague can't pull your files off the tray by mistake. GPUs work similarly: dozens of programs share the same pool of memory, and something has to make sure each one only touches its own portion.

That "something" is usually software, which adds delays and complexity. AMD's patent describes a dedicated piece of hardware, a security circuit built directly into the chip, that watches every memory request as it travels through the processor. If a request comes from a program that isn't on the approved list, the circuit blocks it before anything sensitive is exposed.

This matters most in cloud computing, where your AI workload and a stranger's workload might run side by side on the same GPU. A hardware-level check is faster and harder to trick than a software one, and it keeps each client's data walled off from every other client on the chip.

From the filing · CLAIM 1
… a security circuit configured to authorize client access to allocated regions of the physical memory based on whether an intercepted memory translation corresponds to an authorized client.

Translation: A special hardware guard checks every memory request to ensure only approved programs can read or write to specific physical memory areas.

How the security circuit intercepts memory translations

The patent describes an apparatus containing multiple processors, all sharing a single pool of physical memory. Each processor handles memory translation, which is the process of converting the addresses a program thinks it is using into real locations on the chip. This translation layer is where security problems can surface.

The key component is a security circuit that sits in the path of those translations and intercepts each one before it completes. The circuit checks whether the requesting client, meaning the program or virtual machine making the request, is on an authorized list for that region of memory. If it isn't, access is denied.

The term confidential compute refers to environments where data must stay private even from the hardware operator, such as a cloud provider. This is increasingly important for AI inference and training, where model weights and user data are sensitive.

The patent's approach is notable because the check lives in dedicated hardware rather than in a software driver or hypervisor layer (the software that manages virtual machines). Hardware checks are:

  • Faster, since they don't require a software round-trip
  • More consistent, since they can't be misconfigured by a driver update
  • Harder to bypass, since they operate below the software stack

What this means for AI workloads and shared GPU clouds

Cloud GPU instances are already the backbone of most commercial AI work. When a data center runs hundreds of AI jobs on the same physical GPU, the boundary between those jobs is only as trustworthy as the security layer enforcing it. A hardware circuit that enforces those boundaries directly on the chip raises that bar considerably compared to software-only approaches.

For enterprise and regulated industries, where healthcare records or financial models might run on shared infrastructure, a hardware-level memory check could make GPU cloud computing acceptable in environments where it currently isn't. It also reduces the performance penalty of confidential compute, since the check happens in silicon rather than through extra software handshakes. a growing pile of AMD confidential-compute filings suggests the company is treating this as a platform priority rather than a one-off feature.

AMD's 21st filing we've tracked since June in the GPU rendering race builds on a dispatch skip system and self-selecting code path chip.

Editorial take

The ship-path question here is straightforward: this is a hardware patent, which means it needs to be designed into a future chip before it does anything for anyone. Software security can ship in a driver update next quarter; a security circuit has to be taped out, manufactured, and deployed in actual products, which puts any real-world impact at least a chip generation away.

That said, the problem it addresses is real and growing. Shared GPU memory isolation is already a weak point in cloud AI infrastructure, and the industry is moving toward confidential compute standards precisely because software-only solutions leave too many gaps. AMD building this into silicon rather than relying on firmware is the right engineering instinct.

The patent itself is fairly narrow, describing the security circuit's authorization check without fully specifying how the authorized-client list is built or managed. The implementation details that matter most for security, like how you prove a client is who it claims to be, are not described here. This reads like one piece of a larger architecture, not a complete solution on its own.

There are more where this came from

We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.

The drawings

6 drawing sheets from US 2026/0299800 A1 · click any drawing to enlarge

Patent filing page

Source. Full patent text and figures from the official USPTO publication PDF.
Reader comments

Be the first to weigh in

Start the discussion

Real name or a handle, either is fine. Comments are read by a person before they appear, so allow a little time. Keep it about the filing.