IP Library › Granted Patent US 11,055,402
Granted Patent B2
US 11,055,402 · App. 16/142,611 · Granted Jul 6, 2021

Dynamically generated code process sandboxing using authenticated pointers

Inventors: Can Acar (San Diego, CA); Robert Turner (San Diego, CA); Alexander Gantman (Solana Beach, CA)
Assignee: QUALCOMM Incorporated
G06F21/53G06F12/145G06F21/52G06F21/566G06F9/45516G06F2212/1052G06F2221/033G06F2221/2125
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,055,402
App. No.
16/142,611
Granted
Jul 6, 2021
Kind
B2
Abstract

A method is provided for safely executing dynamically generated code to avoid the possibility of an attack in unprotected memory space. Upon ascertaining that dynamically generated code is to be executed, a processing circuit and/or operating system kernel restrict the dynamically generated code to use a first memory region within an unprotected memory space, where the first memory region is distinct (e.g., reserved) from other memory regions used by other processes executed by the processing circuit. A first processing stack is maintained for the dynamically generated code within the first memory region. This first processing stack is separate from a general processing stack used by other processes executed by the processing circuit. A stack pointer is switched/pointed to the first processing stack when the dynamically generated code is executed and the stack pointer is switched/pointed to the general processing stack when the dynamically generated code ends.

Claims (43)

1. A method operational at a processing circuit, comprising:

ascertaining when dynamically generated code is to be executed;

restricting the dynamically generated code to use a first memory region within an unprotected memory space, where the first memory region is distinct from other memory regions used by other processes executed by the processing circuit;

maintaining a first processing stack for the dynamically generated code within the first memory region while the dynamically generated code is being executed, wherein the first processing stack is separate from a general processing stack used by other processes executed by the processing circuit, wherein a stack pointer is switched to the first processing stack when the dynamically generated code is executed and the stack pointer is switched to the general processing stack when the dynamically generated code ends;

triggering a page fault indicator if at least one of a load, store, or branch instruction within the dynamically generated code invokes an address outside the first memory region; and

enforcing all memory access and transfer of control from the first memory region to other memory regions to occur through authenticated pointers while ignoring or disabling all other pointer authentication related instructions.

2. The method of claim 1 , further comprising:

restricting computational instructions used by the dynamically generated code to operate within the first memory region.

3. The method of claim 1 , further comprising:

triggering a page fault indicator if a special or system instruction within the dynamically generated code invokes an address outside the first memory region.

4. The method of claim 1 , wherein restricting the dynamically generated code is performed by at least one of the processing circuit or an operating system kernel operating thereon.

5. The method of claim 1 , wherein return and call instructions comprise an only way to transfer control to the first memory region.

6. The method of claim 1 , wherein the processing circuit is an Advanced Reduced Instruction Set Computer (RISC) Machine (ARM) processor.

7. The method of claim 1 , wherein one or more registers define one or more memory ranges that can be utilized by the dynamically generated code.

8. The method of claim 1 , wherein the first memory region is defined from within writable execution memory regions of a memory device coupled to or integrated within the processing circuit.

9. The method of claim 1 , wherein flags in memory page tables are used to mark all memory pages descending from the first memory region.

10. The method of claim 1 , wherein the dynamically generated code is placed in the first memory region immediately upon being generated by the processing circuit.

11. A processing device, comprising:

a memory device;

a processing circuit coupled to the memory device, the processing circuit configured to:

ascertain when dynamically generated code is to be executed;

restrict the dynamically generated code to use a first memory region within an unprotected memory space of the memory device, where the first memory region is distinct from other memory regions used by other processes executed by the processing circuit;

maintain a first processing stack for the dynamically generated code within the first memory region while the dynamically generated code is being executed, wherein the first processing stack is separate from a general processing stack used by other processes executed by the processing circuit, wherein a stack pointer is switched to the first processing stack when the dynamically generated code is executed and the stack pointer is switched to the general processing stack when the dynamically generated code ends;

trigger a page fault indicator if at least one of a load, store, or branch instruction within the dynamically generated code invokes an address outside the first memory region; and

enforce all memory access and transfer of control from the first memory region to other memory regions to occur through authenticated pointers while ignoring or disabling all other pointer authentication related instructions.

12. The processing device of claim 11 , wherein the processing circuit is further configured to:

restrict computational instructions used by the dynamically generated code to operate within the first memory region;

trigger a page fault indicator if a special or system instruction within the dynamically generated code invokes an address outside the first memory region.

13. The processing device of claim 11 , wherein the processing circuit is an Advanced RISC Machines processor.

14. The processing device of claim 11 , wherein the memory device is integrated within the processing circuit.

15. The processing device of claim 11 , wherein the first memory region is defined from within writable execution memory regions of a memory device coupled to or integrated within the processing circuit.

16. The processing device of claim 11 , wherein the dynamically generated code is placed in the first memory region immediately upon being generated by the processing circuit.

17. A non-transitory processor-readable storage medium having one or more instructions that, when executed by at least one processing circuit, cause the at least one processing circuit to:

ascertain when dynamically generated code is to be executed;

restrict the dynamically generated code to use a first memory region within an unprotected memory space, where the first memory region is distinct from other memory regions used by other processes executed by the processing circuit;

maintain a first processing stack for the dynamically generated code within the first memory region while the dynamically generated code is being executed, wherein the first processing stack is separate from a general processing stack used by other processes executed by the processing circuit, wherein a stack pointer is switched to the first processing stack when the dynamically generated code is executed and the stack pointer is switched to the general processing stack when the dynamically generated code ends;

trigger a page fault indicator if at least one of a load, store, or branch instruction within the dynamically generated code invokes an address outside the first memory region; and

enforce all memory access and transfer of control from the first memory region to other memory regions to occur through authenticated pointers while ignoring or disabling all other pointer authentication related instructions.

18. The non-transitory processor-readable storage medium of claim 17 , further having one or more instructions that, when executed by at least one processing circuit, cause the at least one processing circuit to:

restrict computational instructions used by the dynamically generated code to operate within the first memory region.

19. The non-transitory processor-readable storage medium of claim 17 , further having one or more instructions that, when executed by at least one processing circuit, cause the at least one processing circuit to:

trigger a page fault indicator if a special or system instruction within the dynamically generated code invokes an address outside the first memory region.

20. The non-transitory processor-readable storage medium of claim 17 , wherein restricting the dynamically generated code is performed by at least one of the at least one processing circuit or an operating system kernel operating thereon.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2019
From: ACAR, CAN; TURNER, ROBERT; GANTMAN, ALEXANDER
To: QUALCOMM INCORPORATED
Reel/Frame 048135/0725 →
Continuity (2)
Provisional Application 62566213 · Sep 29, 2017
Related Publication 20190102540A1 · Apr 4, 2019