IP Library Patent Application 12317446
Patent Application
App. No. 12/317,446

System management mode isolation in firmware

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/317,446
Abstract

A system, method, and computer-readable medium with instructions for capturing a system management interrupt instruction by trusted system management mode code running in a system. The system management interrupt instruction is dispatched to other system management mode code, which may be untrusted. In response to an attempt to access a protected resource of the system by the other system management mode code, a determination is made whether the second system management mode code is authorized to access the protected resource. If the second system management mode code is not authorized to access the protected resource, access to the protected resource by the other system management mode code is prevented. Other embodiments are described and claimed.

Claims (80)

1 . A method comprising:

capturing a system management interrupt instruction by trusted system management mode code running in a system;

dispatching the system management interrupt instruction to second system management mode code;

in response to an attempt to access a protected resource of the system by the second system management mode code, determining whether the second system management mode code is authorized to access the protected resource;

preventing access to the protected resource by the second system management mode code if the second system management mode code is not authorized to access the protected resource.

2 . The method of claim 1 wherein

the determining whether the second system management mode code is authorized to access the protected resource comprises determining whether the second system management mode code is present in an availability bit for a page table entry of a page table for a memory page associated with the protected resource.

3 . The method of claim 1 , further comprising:

launching an isolation driver to control access to the protected resource before untrusted system management mode code is launched.

4 . The method of claim 1 , further comprising:

designating a resource of the system as protected by setting an availability bit to unavailable in a page table entry of a page table for a memory page associated with the resource.

5 . The method of claim 1 wherein

the protected resource is an operating system kernel.

6 . The method of claim 5 wherein

the second system management mode code comprises an OEM SMM driver.

7 . The method of claim 1 wherein

the protected resource is flash memory on a motherboard of the system.

8 . The method of claim 1 wherein

the protected resource is a driver execution environment driver core.

9 . The method of claim 1 wherein

the protected resource is an OEM SMM driver.

10 . The method of claim 1 wherein the protected resource is a model-specific register.

11 . The method of claim 10 wherein

the second system management mode code comprises an OEM SMM driver.

12 . The method of claim 1 wherein

the protected resource is UEFI runtime service code.

13 . A system comprising:

a trusted system management mode module to capture a system management interrupt instruction;

a dispatcher to dispatch the system management interrupt instruction to second system management mode code;

a determining module to determine whether the second system management mode code is authorized to access a protected resource of the system;

a preventing module to prevent access to the protected resource by the second system management mode code if the second system management mode code is not authorized to access the protected resource.

14 . The system of claim 13 wherein

the determining module determines whether the second system management mode code is authorized to access the protected resource by determining whether the second system management mode code is present in an availability bit for a page table entry of a page table for a memory page associated with the protected resource.

15 . The system of claim 13 , further comprising:

an isolation driver that is launched to control access to the protected resource before untrusted system management mode code is launched.

16 . The system of claim 13 , further comprising:

a protection module to designate a resource of the system as protected by setting an availability bit to unavailable in a page table entry of a page table for a memory page associated with the resource.

17 . The system of claim 13 wherein

the protected resource is an operating system kernel.

18 . The system of claim 13 wherein

the second system management mode code comprises an OEM SMM driver.

19 . The system of claim 13 wherein

the protected resource is flash memory on a motherboard of the system.

20 . The system of claim 13 wherein

the protected resource is a driver execution environment driver core.

21 . The system of claim 13 wherein

the protected resource is an OEM SMM driver.

22 . The system of claim 13 wherein

the protected resource is a model-specific register.

23 . The system of claim 22 wherein

the second system management mode code comprises an OEM SMM driver.

24 . The system of claim 13 wherein

the protected resource is UEFI runtime service code.

25 . A computer-readable storage medium comprising:

trusted system management mode instructions to capture a system management interrupt instruction;

dispatching instructions to dispatch the system management interrupt instruction to second system management mode code;

determining instructions to determine whether the second system management mode code is authorized to access a protected resource of a system;

preventing instructions to prevent access to the protected resource by the second system management mode code if the second system management mode code is not authorized to access the protected resource.

26 . The computer-readable medium of claim 25 wherein

the determining instructions determine whether the second system management mode code is authorized to access the protected resource comprises by determining whether the second system management mode code is present in an availability bit for a page table entry of a page table for a memory page associated with the protected resource.

27 . The computer-readable medium of claim 25 , further comprising:

launching instructions to launch an isolation driver to control access to the protected resource before untrusted system management mode code is launched.

28 . The computer-readable medium of claim 25 , further comprising:

designating instructions to designate a resource of the system as protected by setting an availability bit to unavailable in a page table entry of a page table for a memory page associated with the resource.

29 . The computer-readable medium of claim 25 wherein

the protected resource is an operating system kernel.

30 . The computer-readable medium of claim 29 wherein

the second system management mode code comprises an OEM SMM driver.

31 . The computer-readable medium of claim 25 wherein

the protected resource is flash memory on a motherboard of the system.

32 . The computer-readable medium of claim 25 wherein

the protected resource is a driver execution environment driver core.

33 . The computer-readable medium of claim 25 wherein

the protected resource is an OEM SMM driver.

34 . The computer-readable medium of claim 25 wherein

the protected resource is a model-specific register.

35 . The computer-readable medium of claim 34 wherein

the second system management mode code comprises an OEM SMM driver.

36 . The computer-readable medium of claim 25 wherein

the protected resource is UEFI runtime service code.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2022
From: INTEL CORPORATION
To: TAHOE RESEARCH, LTD.
Reel/Frame 061827/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2010
From: YAO, JIEWEN; ZIMMER, VINCENT J.; LONG, QIN
To: INTEL CORPORATION
Reel/Frame 024017/0791 →