IP Library Granted Patent US 9,747,102
Granted Patent B2
US 9,747,102 · App. 13/729,371 · Granted Aug 29, 2017

Memory management in secure enclaves

Inventors: Rebekah Leslie (Portland, OR); Carlos V. Rozas (Portland, OR); Vincent R. Scarlata (Beaverton, OR); Simon P. Johnson (Beaverton, OR); Uday R. Savagaonkar (Portland, OR); Barry E. Huntley (Hillsboro, OR); Vedvyas Shanbhogue (Austin, TX); Ittai Anati (Haifa, IL); Francis X. Mckeen (Portland, OR); Michael A. Goldsmith (Lake Oswego, OR); Ilya Alexandrovich (Haifa, IL); Alex Berenzon (Zikhron Ya'akov, IL); Wesley H. Smith (Raleigh, NC); Gilbert G. Neiger (Portland, OR)
Assignee: Intel Corporation
G06F9/30047G06F9/30076G06F9/44G06F12/084G06F12/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,747,102
App. No.
13/729,371
Granted
Aug 29, 2017
Kind
B2
Abstract

Embodiments of an invention for memory management in secure enclaves are disclosed. In one embodiment, a processor includes an instruction unit and an execution unit. The instruction unit is to receive a first instruction and a second instruction. The execution unit is to execute the first instruction, wherein execution of the first instruction includes allocating a page in an enclave page cache to a secure enclave. The execution unit is also to execute the second instruction, wherein execution of the second instruction includes confirming the allocation of the page.

Claims (33)

1. A processor comprising:

an instruction unit to receive a first instruction, a second instruction, and a third instruction; and

an execution unit to execute the first instruction, wherein

execution of the first instruction includes allocating a first page in an enclave page cache to a secure enclave,

execution of the second instruction in connection with execution of the first instruction includes confirming the allocating of the first page,

execution of the third instruction includes de-allocating the first page in the enclave page cache from the secure enclave and setting a modified indicator in an entry for the first page in the enclave page cache map, wherein the first page is not modifiable while the modified indicator is set, and

execution of the second instruction in connection with execution of the third instruction includes confirming the de-allocating of the first page and clearing the modified indicator.

2. The processor of claim 1 , wherein execution of the first instruction also includes setting a pending indicator in an entry for the first page in an enclave page cache map.

3. The processor of claim 2 , wherein execution of the second instruction also includes clearing the pending indicator.

4. The processor of claim 2 , wherein the first page is not accessible by the secure enclave while the pending indicator is set.

5. A method comprising:

receiving a first request from a secure enclave for more memory space in an enclave page cache;

receiving a first instruction from an operating system;

in response to receiving the first instruction, allocating a first page in the enclave page cache to the secure enclave;

receiving a second instruction from the secure enclave in connection with executing the first instruction;

in response to receiving the second instruction, confirming the allocating of the first page;

receiving a second request from the secure enclave to de-allocate the first page in the enclave page cache;

receiving a third instruction from the operating system;

in response to receiving the third instruction, de-allocating the first page and setting a modified indicator in an entry for the second page in an enclave page cache map wherein the first page is not modifiable while the modified indicator is set;

receiving the second instruction from the secure enclave in connection with executing the third instruction; and

in response to receiving the second instruction, confirming the de-allocating of the first page and clearing the modified indicator.

6. The method of claim 5 , further comprising, in response to receiving the first instruction, setting a pending indicator in an entry for the first page in an enclave page cache map.

7. The method of claim 6 , further comprising, in response to receiving the second instruction, clearing the pending indicator.

8. The method of claim 7 , wherein the first page is not accessible by the secure enclave while the pending indicator is set.

9. A system comprising:

a memory; and

a processor including

an instruction unit to receive a first instruction, a second instruction, and a third instruction; and

an execution unit to execute the first instruction, wherein

execution of the first instruction includes allocating a first page in an enclave page cache to a secure enclave,

execution of the second instruction in connection with execution of the first instruction includes confirming the allocating of the first page,

execution of the third instruction includes de-allocating the first page in the enclave page cache from the secure enclave and setting a modified indicator in an entry for the first page in the enclave page cache map, wherein the first page is not modifiable while the modified indicator is set, and

execution of the second instruction in connection with execution of the third instruction includes confirming the de-allocating of the first page and clearing the modified indicator.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2015
From: LESLIE-HURD, REBEKAH; ROZAS, CARLOS V.; SCARLATA, VINCENT R.; JOHNSON, SIMON P.; SAVAGAONKAR, UDAY R.; HUNTLEY, BARRY E.; SHANBHOGUE, VEDVYAS; ANATI, ITTAI; MCKEEN, FRANCIS X.; GOLDSMITH, MICHAEL A.; ALEXANDROVICH, ILYA; BERENZON, ALEX; SMITH, WESLEY H.; NEIGER, GILBERT
To: INTEL CORPORATION
Reel/Frame 036313/0755 →
Continuity (1)
Related Publication 20140189326A1 · Jul 3, 2014