IP Library › Granted Patent US 11,176,243
Granted Patent B2
US 11,176,243 · App. 16/585,373 · Granted Nov 16, 2021

Processor extensions to protect stacks during ring transitions

Inventors: Vedvyas Shanbhogue (Austin, TX); Jason W. Brandt (Austin, TX); Ravi L. Sahita (Beaverton, OR); Barry E. Huntley (Hillsboro, OR); Baiju V. Patel (Portland, OR); Deepak K. Gupta (Hillsboro, OR)
Assignee: Intel Corporation
G06F21/52G06F3/0622G06F3/0637G06F3/0673G06F9/30101G06F9/30134G06F9/461G06F12/1491G06F2212/1052G06F2221/033G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,176,243
App. No.
16/585,373
Granted
Nov 16, 2021
Kind
B2
Abstract

A processor implementing techniques for processor extensions to protect stacks during ring transitions is provided. In one embodiment, the processor includes a plurality of registers and a processor core, operatively coupled to the plurality of registers. The plurality of registers is used to store data used in privilege level transitions. Each register of the plurality of registers is associated with a privilege level. An indicator to change a first privilege level of a currently active application to a second privilege level is received. In view of the second privilege level, a shadow stack pointer (SSP) stored in a register of the plurality of registers is selected. The register is associated with the second privilege level. By using the SSP, a shadow stack for use by the processor at the second privilege level is identified.

Claims (13)

1. An apparatus comprising:

at least one data storage location to store one or more shadow stack pointer (SSP), wherein each SSP is associated with a privilege level; and

execution circuitry, operatively coupled to the at least one data storage location, to:

receive an indication to change a first privilege level associated with a currently active application to a second privilege level;

select, in view of the second privilege level, a stored SSP stored in the at least one data storage location; and

identify, using the selected SSP, a shadow stack for use at the second privilege level.

2. The apparatus of claim 1 , wherein the shadow stack is to be used for control transfer operations.

3. The apparatus of claim 2 , wherein the shadow stack is separate and different than a data stack.

4. The apparatus of claim 1 , wherein the SSP is to point to a current top of the shadow stack.

5. The apparatus of claim 1 , wherein the indication to change the first privilege level is a result of an interrupt.

6. The apparatus of claim 1 , wherein the indication to change the first privilege level is a result of a call to an interrupt handler.

7. The apparatus of claim 1 , wherein the indication to change the first privilege level is a result of a call to an exception handler.

8. The apparatus of claim 1 , wherein a token associated with the shadow stack is to be verified by the execution circuitry.

Continuity (2)
Continuation 15016068 · Feb 4, 2016
Related Publication 20200089871A1 · Mar 19, 2020
Cited By (2)
US 12,229,453 US 12,562,918