IP Library Granted Patent US 7,734,932
Granted Patent B2
US 7,734,932 · App. 10/879,349 · Granted Jun 8, 2010

System and method for securing executable code

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,734,932
App. No.
10/879,349
Granted
Jun 8, 2010
Kind
B2
Abstract

A system and method for the secure storage of executable code and the secure movement of such code from memory to a processor. The method includes the storage of an encrypted version of the code. The code is then decrypted and decompressed as necessary, before re-encryption in storage. The re-encrypted executable code is then written to external memory. As a cache line of executable code is required, a fetch is performed but intercepted. In the interception, the cache line is decrypted. The plain text cache line is then stored in an instruction cache associated with a processor.

Claims (40)

1. A system for secure execution of processor instructions, the system comprising:

a processor;

an instruction cache in communication with said processor;

a memory controller in communication with said instruction cache; and

a security controller in communication with said instruction cache and configured to

decrypt, using a first key, an encrypted first block of data comprising executable code,

decrypt an encrypted second block of data by executing said executable code in said first block, and

encrypt said second block on a per instruction basis,

wherein said memory controller is configured to intercept fetches of instructions to be executed by said processor, and fetch an instruction of said second block encrypted on a per instruction basis; and

wherein said security controller is further configured to decrypt said fetched instruction to obtain a resulting instruction, and load said resulting instruction into said instruction cache to be executed by said processor.

2. The system of claim 1 , wherein said security controller comprises logic for decrypting said encrypted first block using the Triple Data Encryption Standard (3DES) algorithm.

3. The system of claim 1 , further comprising a key management module that comprises:

logic for receiving said first key in encrypted form;

logic for decrypting said encrypted first key using a session key; and

logic for forwarding said first key to said security controller.

4. The system of claim 1 , wherein said security controller comprises:

logic for encrypting said second block using the Advanced Encryption Standard (AES) algorithm; and

logic for decrypting said instruction of said second block using said AES algorithm.

5. The system of claim 4 , wherein said logic for encrypting said second block comprises logic that implements a cipher block chaining (CBC) mode of said AES algorithm; and

said logic for decrypting said instruction of said second block comprises logic that implements said CBC mode of said AES algorithm.

6. The system of claim 5 , wherein

said logic for encrypting said second block comprises logic that implements the decryption mode of said CBC mode of said AES algorithm; and

said logic for decrypting said instruction of said second block comprises logic that implements the encryption mode of said CBC mode of said AES algorithm.

7. The system of claim 1 , wherein said security controller is configured to

encrypt said second block using an address, corresponding to a location in memory of said instruction, as an initialization vector (IV) for a block encryption algorithm; and

decrypt said instruction using said address as said IV.

8. A system for secure execution of processor instructions, the system comprising:

a first memory containing boot code and an image encrypted with a first key;

a secure embedded processor system, comprising:

a processor;

an instruction cache in communication with said processor;

a memory controller in communication with said instruction cache; and

a security controller in communication with said instruction cache; and

a second memory, external to said secure embedded processor system, in communication with said first memory, said memory controller, and said security controller,

such that said image encrypted with said first key is transferred to said second memory, decrypted, and re-encrypted using a second key, and such that a cache line of said image encrypted with said second key is then read from said second memory, decrypted with said second key, and stored in said instruction cache for execution by said processor,

wherein said security controller comprises:

logic for re-encrypting said image using the Advanced Encryption Standard (AES) algorithm; and

logic for decrypting said cache line using said AES algorithm; and

wherein said logic for re-encrypting said image uses an address of said second memory as an initialization vector (IV) for said AES algorithm, wherein said address corresponds to the location in said second memory of said cache line; and

said logic for decrypting said cache line uses said address as said IV.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 47630 FRAME: 344. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 21, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 048883/0267 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF MERGER TO 9/5/2018 PREVIOUSLY RECORDED AT REEL: 047196 FRAME: 0687. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047630/0344 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047196/0687 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2004
From: BUER, MARK
To: BROADCOM CORPORATION
Reel/Frame 015536/0364 →