IP Library Granted Patent US 9,087,200
Granted Patent B2
US 9,087,200 · App. 13/527,547 · Granted Jul 21, 2015

Method and apparatus to provide secure application execution

Inventors: Francis X. McKeen (Portland, OR); Carlos V. Rozas (Portland, OR); Uday R. Savagaonkar (Portland, OR); Simon P. Johnson (Beaverton, OR); Vincent Scarlata (Beaverton, OR); Michael A. Goldsmith (Lake Oswego, OR); Ernie Brickell (Hillsboro, OR); Jiang Tao Li (Beaverton, OR); Howard C. Herbert (Phoenix, AZ); Prashant Dewan (Hillsboro, OR); Stephen J. Tolopka (Portland, OR); Gilbert Neiger (Portland, OR); David Durham (Beaverton, OR); Gary Graunke (Hillsboro, OR); Bernard Lint (Mountain View, CA); Don A. Van Dyke (Rescue, CA); Joseph Cihula (Hillsboro, OR); Stalinselvaraj Jeyasingh (Beaverton, OR); Stephen R. Van Doren (Portland, OR); Dion Rodgers (Hillsboro, OR); John Garney (Portland, OR); Asher Altman (Bedford, MA)
Assignee: Intel Corporation
G06F21/60G06F21/53G06F21/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,087,200
App. No.
13/527,547
Granted
Jul 21, 2015
Kind
B2
Abstract

A technique to enable secure application and data integrity within a computer system. In one embodiment, one or more secure enclaves are established in which an application and data may be stored and executed.

Claims (13)

1. A processor comprising:

execution logic to perform:

at least a first instruction to move protected data between an enclave page cache (EPC) and a storage area outside of the EPC during execution of a program accessing the protected data, wherein the program is to run in a protected mode; and

at least a second instruction to enable debugging of the program accessing the protected data, wherein the debugging includes usurping the protected mode of the program and wherein the protected mode of the program is usurped only if the EPC includes a debug flag that is associated with the program.

2. The processor of claim 1 , wherein a security map (SMAP) is to help ensure an integrity of the program when the program is stored in a hard disk drive or protected memory.

3. A processor comprising:

execution logic to perform:

at least a first instruction to dynamically access at least one information field to determine an integrity of protected data stored in an enclave page cache (EPC) that is being accessed by a program in a protected mode, wherein the at least one information field includes a secure map (SMAP) field and a security information (SEC_INFO) field; and

at least a second instruction to enable debugging of the program accessing the protected data, wherein the debugging includes usurping the protected mode of the program and wherein the protected mode of the program is usurped only if the EPC includes a debug flag that is associated with the program.

4. A processor comprising:

execution logic to perform:

at least a first instruction to move protected data between an enclave page cache (EPC) and a storage area outside of the EPC during execution of a software program accessing the protected data, wherein the software program is to run in a protected mode, wherein a crypto memory aperture (CMA) protects the software program against attacks when the software program is executing; and a secure map (SMAP) protects the software program when the software program is not executing; and

at least a second instruction to enable debugging of the software program accessing the protected data, wherein the debugging includes usurping the protected mode of the software program and wherein the protected mode of the software program is usurped only if the EPC includes a debug flag that is associated with the software program.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2012
From: MCKEEN, FRANCIS X.; ROZAS, CARLOS V.; SAVAGAONKAR, UDAY R.; JOHNSON, SIMON P.; SCARLATA, MICHAEL A.; GOLDSMITH, MICHAEL A.; BRICKELL, ERNIE; LI, JIANG TAO; HERBERT, HOWARD C.; DEWAN, PARSHANT; TOLOPKA, STEPHEN J.; NEIGER, GILBERT; DURHAM, DAVID; GRAUNKE, GARY; LINT, BERNARD; VAN DYKE, DON A.; CIHULA, JOSEPH; JEYASINGH, STALINSELVARAJ; VAN DOREN, STEPHEN R.; RODGERS, DION; GARNEY, JOHN; ALTMAN, ASHER
To: INTEL CORPORATION
Reel/Frame 029276/0288 →
Continuity (2)
Continuation In Part PCTUS2009069212 · Dec 22, 2009
Related Publication 20130159726A1 · Jun 20, 2013