IP Library Granted Patent US 9,870,466
Granted Patent B2
US 9,870,466 · App. 14/866,928 · Granted Jan 16, 2018

Hardware-enforced code paths

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,870,466
App. No.
14/866,928
Granted
Jan 16, 2018
Kind
B2
Abstract

There is disclosed in one example, a computing apparatus, including: first one or more logic elements providing a code module, the code module comprising a member having a branching policy designating either a public or private member; second one or more logic elements providing a policy engine, operable to: receive a first branch instruction to the member; determine that the branch instructions does not meet the policy; and take a security action. There is also disclosed a method of providing a policy engine, and a computer-readable medium having stored thereon executable instructions for providing a policy engine.

Claims (31)

1. A computing apparatus, comprising:

first one or more logic elements, including at least a hardware logic element, comprising a module providing executable code including a cryptographically signed private routine having a public entry point, the public entry point configured to be accessible by an unprivileged process, the private routine having associated therewith a branching policy comprising a requirement that entry to the private routine be from a signed entry point; and

second one or more logic elements, including at least a hardware logic element, comprising a policy engine, operable to:

receive a first branching instruction to the private routine;

determine that the first branching instruction is not a signed entry point for the private routine, comprising a branch check selected from predictive branch checking, comprising evaluating the branching policy before branching, and reactive branch checking, comprising evaluating the branching policy after branching; and

take a security action.

2. The computing apparatus of claim 1 , wherein the module further comprises a public routine, and wherein the policy engine is further operable to receive a second branching instruction from an external source to the module, and allow the second branching instruction to execute.

3. The computing apparatus of claim 1 , wherein the policy engine is further operable to receive a third branching instruction to the private routine, determine that the third branching instruction comes from an authorized source internal to the module, and allow the third branching instruction to execute.

4. The computing apparatus of claim 1 , wherein the policy engine is implemented within a trusted execution environment (TEE).

5. The computing apparatus of claim 1 , wherein the security action comprises throwing an exception.

6. The computing apparatus of claim 1 , wherein the branching policy comprises a private routine designation.

7. The computing apparatus of claim 1 , wherein the branching policy comprises a public routine designation.

8. The computing apparatus of claim 1 , wherein the policy engine is implemented at least partly in processor hardware.

9. The computing apparatus of claim 1 , wherein the policy engine is implemented at least partly in a hypervisor or memory controller.

10. The computing apparatus of claim 1 , wherein determining that the first branching instruction is not a signed entry point for the private routine comprises determining that a calling procedure of the first branching instruction does not include a call-to marker for the routine.

11. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions for providing a policy engine, operable to:

execute a module providing executable code, including a cryptographically signed private routine having a public entry point, the public entry point configured to be accessible by an unprivileged process, the private routine having associated therewith a branching policy comprising a requirement that entry to the private routine be from a signed entry point;

receive a first branching instruction to the private routine;

determine that the first branching instruction is not a signed entry point for the private routine, comprising a branch check selected from predictive branch checking, comprising evaluating the branching policy before branching, and reactive branch checking, comprising evaluating the branching policy after branching; and

take a security action.

12. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein the module further comprises a public routine, and wherein the policy engine is further operable to receive a second branching instruction from an external source to the public routine, and allow the second branching instruction to execute.

13. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein the branching policy comprises a private routine designation.

14. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein the branching policy comprises a public routine designation.

15. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , comprising processor hardware instructions or microcode.

16. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , comprising a hypervisor or memory controller.

17. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein determining that the first branching instruction is not a signed entry point for the private routine comprises determining that a calling procedure of the first branching instruction does not include a call-to marker for the routine.

18. A computer-implemented method of providing a policy engine for branching instructions, comprising:

executing a module providing executable code, including a cryptographically signed private routine having a public entry point, the public entry point configured to be accessible by an unprivileged process, the private routine having associated therewith a branching policy comprising a requirement that entry to the private routine be from a signed entry point;

receiving a first branching instruction to the private routine;

determining that the first branching instruction is not a signed entry point for the private routine, comprising a branch check selected from predictive branch checking, comprising evaluating the branching policy before branching, and reactive branch checking, comprising evaluating the branching policy after branching; and

taking a security action.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2016
From: WOODWARD, CARL D.; MANKIN, JENNIFER ELIGIUS; BENNETT, JEREMY
To: MCAFEE, INC.
Reel/Frame 037810/0850 →