IP Library Patent Application 14865511
Patent Application
App. No. 14/865,511

HARDWARE-ASSISTED SOFTWARE VERIFICATION AND SECURE EXECUTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/865,511
Abstract

In an example, there is disclosed a computing apparatus, including a processor operable to execute a plurality of instructions forming a program; and a verification engine, operable to: receive an execution control data (ECD) for the program; and monitor execution of only some instructions of the program to ensure that they are consistent with the ECD. In some embodiments, the monitoring engine may include a correctness monitoring unit (CMU) in processor hardware. There is also disclosed one or more computer-readable storage mediums having stored thereon executable instructions for providing a monitoring engine, and a computer-implemented method of providing a monitoring engine.

Claims (33)

1 . A computing apparatus, comprising:

a processor operable to execute a plurality of instructions comprising a program, wherein a first portion of the program is formally proven safe, and wherein a second portion of the program is designated as needing monitoring; and

a verification engine, operable to:

receive an execution control data (ECD) for the program; and

monitor only the second portion of the program to ensure that it is consistent with the ECD.

2 . The computing apparatus of claim 1 , wherein the verification engine comprises a correctness monitoring unit (CMU).

3 . The computing apparatus of claim 2 , wherein the CMU is at least partly embodied in hardware of the processor.

4 . The computing apparatus of claim 2 , wherein the CMU is fully embodied in hardware of the processor.

5 . The computing apparatus of claim 1 , wherein the verification engine is operable to identify at least some instructions of the program as safe instructions, and to execute the safe instructions without monitoring the instructions to ensure that they are consistent with the ECD.

6 . The computing apparatus of claim 1 , wherein the second portion of the program comprises unverified instructions.

7 . The computing apparatus of claim 1 , wherein monitoring the second portion of the program comprises comparing an instruction pointer to an ECD control flow.

8 . The computing apparatus of claim 1 , wherein monitoring the second portion of the program comprises comparing address to an ECD control flow.

9 . The computing apparatus of claim 1 , wherein monitoring the second portion of the program comprises comparing a data type to an ECD control flow.

10 . The computing apparatus of claim 1 , wherein receiving the ECD comprises receiving the ECD from a third-party source.

11 . The computing apparatus of claim 1 , wherein the verification engine is further operable to generate the ECD locally.

12 . The computing apparatus of claim 1 , wherein the verification engine is operable to determine that at least some of instructions of the program are not consistent with the ECD, and to act on the determining.

13 . The computing apparatus of claim 10 , wherein acting on the determining comprises throwing an exception.

14 . One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions for providing a monitoring engine operable to:

receive an execution control data (ECD) for a program comprising a plurality of instructions, wherein a first portion of the program is formally proven safe, and wherein a second portion of the program is designated as needing monitoring; and

monitor execution of only the second portion of the program to ensure that it is consistent with the ECD.

15 . The one or more tangible, non-transitory computer-readable storage mediums of claim 14 , wherein the verification engine comprises a correctness monitoring unit (CMU).

16 . The one or more tangible, non-transitory computer-readable storage mediums of claim 15 , wherein the CMU is at least partly embodied in hardware of the processor.

17 . The one or more tangible, non-transitory computer-readable storage mediums of claim 15 , wherein the CMU is fully embodied in hardware of the processor.

18 . The one or more tangible, non-transitory computer-readable storage mediums of claim 14 , wherein the verification engine is operable to identify at least some instructions of the program as safe instructions, and to execute the safe instructions without monitoring the instructions to ensure that they are consistent with the ECD.

19 . The one or more tangible, non-transitory computer-readable storage mediums of claim 14 , wherein monitoring monitoring the second portion of the program comprises identifying at least some of the instructions as unverified instructions.

20 . The one or more tangible, non-transitory computer-readable storage mediums of claim 14 , wherein monitoring the second portion of the program comprises comparing an instruction pointer to an ECD control flow.

21 . The one or more tangible, non-transitory computer-readable storage mediums of claim 14 , wherein monitoring the second portion of the program comprises comparing address to an ECD control flow.

22 . The one or more tangible, non-transitory computer-readable storage mediums of claim 14 , wherein monitoring the second portion of the program comprises comparing a data type to an ECD control flow.

23 . The one or more tangible, non-transitory computer-readable storage mediums of claim 14 , wherein the verification engine is operable to determine that at least some instructions of the program are not consistent with the ECD, and to throw an exception.

24 . A computer-implemented method of providing a monitoring engine, comprising:

receiving an execution control data (ECD) for a program comprising a plurality of instructions, wherein a first portion of the program is formally proven safe, and wherein a second portion of the program is designated as needing monitoring; and

monitoring execution of only the second portion of the program to ensure that it is consistent with the ECD.

25 . The method of claim 24 , further comprising identifying at least some instructions of the program as safe instructions, and to execute the safe instructions without monitoring the instructions to ensure that they are consistent with the ECD.

Assignments (8)
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: MUTTIK, IGOR; BABAYAN, BORIS A.; ERMOLOVICH, ALEXANDER V.; OSTANEVICH, ALEXANDER Y.; ROZHKOV, SERGEY A.
To: MCAFEE, INC.
Reel/Frame 036994/0945 →