IP Library Granted Patent US 12,373,213
Granted Patent B2
US 12,373,213 · App. 17/461,563 · Granted Jul 29, 2025

Hardware enforcement of boundaries on the control, space, time, modularity, reference, initialization, and mutability aspects of software

Inventor: Daniel Shawcross Wilkerson (Berkeley, CA)
Assignee: WHOLE SKY TECHNOLOGIES COMPANY
G06F9/3005G06F8/51G06F9/30054G06F9/323G06F9/34G06F9/5044G06F12/0882G06F12/1009G06F12/14G06F21/52G06F21/54
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,213
App. No.
17/461,563
Granted
Jul 29, 2025
Kind
B2
Abstract

Modifications to existing computer hardware, compiler changes or source-to-source transforms performed during the software build process, and a collection of libraries and modifications to existing standard system software and libraries. The invention allows a program author to enforce various kinds of locality of causality in software to provide enforcement of boundaries for the following aspects of a computer program: control, space, time, modularity, reference, initialization, and mutability. Where these properties do not suffice to guarantee a property at static time, dynamic checks may be added and the constraints on control flow prevent such dynamic checks from being avoided by the program.

Claims (56)

1. A method for regulating an execution of a program on a computer, said method comprising:

providing said computer with an absolute-pointer, said absolute-pointer comprising a target-address and an object-id, said target-address comprising a target address data-page-index and a target address data-page-offset,

providing said computer with data addresses, said data addresses comprising a data address data-page-index and a data address data-page-offset, some of said data addresses comprising data,

annotating some of said data-page indexes with a data-page meta-datum, at least one of said data-page meta-datum comprising a page-class-id,

annotating at least one of said page-class-ids with a page-class-meta-datum using a page-class-id-map,

annotating at least one page-class-meta-datum with a map-object-metadata-table, said map-object-metadata-table annotating said object-id with an object-metadatum comprised of metadata,

providing at least one said object-metadatum with an object-start and an object-length,

providing said computer with a memory-access instruction which accesses data at said target-address through said absolute-pointer,

when a memory-access instruction attempts to access data at said target-address through said absolute-pointer, performing the following steps:

finding said data-page meta-datum annotated onto said target address data-page-index,

finding said page-class-id of said data-page meta-datum,

finding said page-class-meta-datum annotated onto said page-class-id using said page-class-id-map,

finding said map-object-metadata-table annotated onto said page-class-meta-datum,

finding said object-metadatum annotated by said map-object-metadata-table onto said object-id of said absolute-pointer,

finding said object-start and said object-length of said object-metadatum,

computing an object-end as a sum of said object-start and said object-length,

checking if said target-address of said absolute-pointer is greater than or equal to said object-start,

if said target-address of said absolute-pointer is not greater than or equal to said object-start, raising a fault,

if said target-address of said absolute pointer is greater than or equal to said object start, checking if said target-address of said absolute-pointer plus an access-width is less than or equal to said object-end,

if said target-address of said absolute-pointer plus said access-width is not less than or equal to said object-end, raising a fault.

2. The method of claim 1 , the method further comprising: providing said absolute-pointer with a page-overflow-flag, when a memory-access instruction attempts to access data at said target-address through said absolute-pointer, further performing the following steps:

checking if said page-overflow-flag of said absolute-pointer is set to true,

if said page-overflow-flag of said absolute-pointer is set to true, computing an effective target address data-page-index as a value of said target address data-page-index minus one,

if said page-overflow-flag of said absolute-pointer is not set to true, putting an effective target address data-page-index to be said value of said target address data-page-index,

when finding said data-page meta-datum, instead finding said data-page meta-datum annotated onto said effective target address data-page-index,

finding said page-class-id of said data-page meta-datum,

finding said page-class-meta-datum annotated onto said page-class-id using said page-class-id-map,

finding said map-object-metadata-table annotated onto said page-class-meta-datum,

finding said object-metadatum annotated by said map-object-metadata-table onto said object-id of said absolute-pointer,

finding said object-start and said object-length of said object-metadatum,

computing said object-end as the sum of said object-start and said object-length,

checking if said target-address of said absolute-pointer is greater-than-or-equal-to said object-start,

if said target-address of said absolute-pointer is not greater-than-or-equal-to said object-start, raising a fault,

if said target-address of said absolute-pointer is greater-than-or-equal-to said object-start, checking if said target-address of said absolute-pointer plus said access-width is less-than-or-equal-to said object-end,

if said target-address of said absolute-pointer plus said access-width is not less-than-or-equal-to said object-end, raising a fault.

3. The method of claim 1 , the method further comprising:

providing said absolute-pointer with a sub-object-id,

annotating at least one said page-class-meta-datum with a map-sub-object-metadata-table,

using at least one said map-sub-object-metadata-table to annotate said object-id with a sub-object-metadata-table,

using at least one said sub-object-metadata-table to annotate said sub-object-id with a sub-object-metadatum-memory,

providing at least one said data-page meta-datum with a page-sub-object-id-absolute-base,

providing at least one said sub-object-metadatum-memory with a sub-object-offset from said object-start and a sub-object-length,

when a memory-access instruction attempts to access data at said target-address through said absolute-pointer, further performing the following steps:

finding said data-page meta-datum annotated onto said target address data-page-index,

finding said page-class-id of said data-page meta-datum,

finding said page-class-meta-datum annotated onto said page-class-id using said page-class-id-map,

finding said map-sub-object-metadata-table annotated onto said page-class-meta-datum,

finding said sub-object-metadata-table annotated by said map-sub-object-metadata-table onto said object-id of said absolute-pointer,

computing an absolute sub-object-id as the sum of said sub-object-id of said absolute-pointer and said page-sub-object-absolute-base annotated onto said data-page meta-datum annotated onto said target address data-page-index,

finding said sub-object-metadatum-mem annotated by said sub-object-metadata-table onto said absolute sub-object-id,

computing a sub-object-start as the sum of said object-start of said object-metadatum and said sub-object-offset-from-object-start of said sub-object-metadatum-memory,

computing a sub-object-end as the sum of said sub-object-start and said sub-object-length of said sub-object-metadatum-memory,

checking if said target-address of said absolute-pointer is greater-than-or-equal-to said sub-object-start,

if said target-address of said absolute-pointer is not greater-than-or-equal-to said sub-object-start, raising a fault,

checking if said target-address of said absolute-pointer plus said access-width is less-than-or-equal-to said sub-object-end,

if said target-address of said absolute-pointer plus said access-width is not less-than-or-equal-to said sub-object-end, raising a fault.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2025
From: WILKERSON, DANIEL SHAWCROSS
To: WHOLE SKY TECHNOLOGIES COMPANY
Reel/Frame 071532/0478 →
Continuity (4)
Continuation In Part PCTUS2020029406 · Apr 22, 2020
Provisional Application 63071934 · Aug 28, 2020
Provisional Application 62837145 · Apr 22, 2019
Related Publication 20210389946A1 · Dec 16, 2021
References Cited (81)
US 4408274A · Wheatley et al. · 1983 [cited by applicant]
US 4434464A · Suzuki et al. · 1984 [cited by applicant]
US 4442484A · Childs et al. · 1984 [cited by applicant]
US 4525780A · Bratt et al. · 1985 [cited by applicant]
US 4701846A · Ikeda et al. · 1987 [cited by applicant]
US 5075842A · Lai · 1991 [cited by applicant]
US 5075845A · Lai et al. · 1991 [cited by applicant]
US 5075848A · Lai et al. · 1991 [cited by applicant]
US 5157777A · Lai et al. · 1992 [cited by applicant]
US 5563843A · Fackenthal et al. · 1996 [cited by applicant]
US 5627987A · Nozue et al. · 1997 [cited by applicant]
US 5845129A · Wendorf et al. · 1998 [cited by applicant]
US 5890189A · Nozue et al. · 1999 [cited by applicant]
US 5892944A · Fukumoto et al. · 1999 [cited by applicant]
US 6542919B1 · Wendorf et al. · 2003 [cited by applicant]
US 6615340B1 · Wilmot · 2003 [cited by applicant]
US 6854039B1 · Strongin et al. · 2005 [cited by applicant]
US 6873993B2 · Charlesworth et al. · 2005 [cited by applicant]
US 6941473B2 · Etoh et al. · 2005 [cited by applicant]
US 7134050B2 · Wenzel · 2006 [cited by applicant]
US 7197502B2 · Feinsmith · 2007 [cited by applicant]
US 7287140B1 · Asanovic et al. · 2007 [cited by applicant]
US 7467272B2 · Genty et al. · 2008 [cited by applicant]
US 7584461B2 · Plum · 2009 [cited by applicant]
US 7882318B2 · Savagaonkar et al. · 2011 [cited by applicant]
US 7917710B2 · Freeman et al. · 2011 [cited by applicant]
US 8136091B2 · Erlingsson et al. · 2012 [cited by applicant]
US 8364910B2 · Wilkerson et al. · 2013 [cited by applicant]
US 8495036B2 · Calder et al. · 2013 [cited by applicant]
US 9524163B2 · Godard et al. · 2016 [cited by applicant]
US 9569612B2 · Wilkerson et al. · 2017 [cited by applicant]
US 9747218B2 · Godard et al. · 2017 [cited by applicant]
US 9934166B2 · Wilkerson et al. · 2018 [cited by applicant]
US 9935975B2 · Wilkerson et al. · 2018 [cited by applicant]
US 10678700B2 · Godard et al. · 2020 [cited by applicant]
US 11797398B2 · Sutherland et al. · 2023 [cited by applicant]
US 20020123981A1 · Baba et al. · 2002 [cited by applicant]
US 20030120888A1 · Huang · 2003 [cited by examiner]
US 20030172246A1 · Tessarolo · 2003 [cited by applicant]
US 20080222397A1 · Wilkerson et al. · 2008 [cited by applicant]
US 20120102268A1 · Smith et al. · 2012 [cited by applicant]
US 20120151184A1 · Wilkerson et al. · 2012 [cited by applicant]
US 20120198139A1 · Tanaka et al. · 2012 [cited by applicant]
US 20120255001A1 · Sallam · 2012 [cited by applicant]
US 20130205285A1 · Pizlo · 2013 [cited by applicant]
US 20130283017A1 · Wilkerson · 2013 [cited by examiner]
US 20140201422A1 · Tseng et al. · 2014 [cited by applicant]
US 20140258635A1 · Hong et al. · 2014 [cited by applicant]
US 20160094552A1 · Durham · 2016 [cited by examiner]
US 20160147811A1 · Eluri et al. · 2016 [cited by applicant]
US 20180278714A1 · Das · 2018 [cited by applicant]
US 20200073822A1 · Wallach · 2020 [cited by examiner]
US 20210182390A1 · Winterrowd · 2021 [cited by examiner]
US 20210200546A1 · Lemay · 2021 [cited by examiner]
GB 2576506A · 2020 [cited by examiner]
JP 07006095A · 1995 [cited by applicant]
JP H8077023 · 1996 [cited by applicant]
JP 2000322260A · 2000 [cited by applicant]
JP 2003296128A · 2003 [cited by applicant]
JP 2019505052A · 2019 [cited by applicant]
Robert Wahbe, Steven Lucco, Thomas E. Anderson, Susan L Graham “Efficient Software-Based Fault Isolation”, ACM SIGOPS Operating Systems Review, Dec. 1993, vol. 27, No. 5, pp. 203-216. [cited by applicant]
Warg et al., Rounding pointers: type safe capabilities with C++ meta programming, Oct. 2011, 5 pages. [cited by applicant]
Witchel et al. “Mondrian Memory Protection”; ACM SIGPLAN Notices; vol. 37Issue 10pp. 304-316; Oct. 2002. [cited by applicant]
[Dhawan-2015] “Architectural Support for Software-Defined Metadata Processing”, Udit Dhawan and Catalin Hritcu and Nikos Vasilakis and Raphael Rubin and Silviu Chiricescu and Jonathan M. Smith and Thomas F. Knight and J… [cited by applicant]
[EKO-1995]: Dawson R. Engler, M. Frans Kaashoek, James O'Toole “Exokemel: An Operating System Architecture for Application-Level Resource Management”, Symposium on Operating Systems Principles, 1995, pp. 251-266. [cited by applicant]
[Lamport-1979] L. Lamport. “How to make a multiprocessor computer that correctly executes multiprocess programs”. Computers, IEEE Transactions on, 100(9):690-691, 1979. [cited by applicant]
[OSSNMS-1992]: T. Okamoto, H. Segawa, S. H. Shin, H. Nozue, Ken-Ichi Maeda, M. Saito, “A Micro-Kernel Architecture for Next Generation Processors”, Proceedings of the Workshop on Micro-kernels and Other Kernel Architect… [cited by applicant]
[WCA-2002]: Emmett Witchel, Josh Cates, Krste Asanovic, “Mondrian Memory Protection”, ASPLOS-X: Proceedings of the 10th international conference on Architectural support for programming languages and operating systems, … [cited by applicant]
[WS-1992]: John Wilkes, Bart Sears, “A comparison of Protection Lookaside Buffers and the PA-RISC protection architecture”, HP Laboratories Technical Report HPL-92-55, Mar. 1992, pp. 1-11. [cited by applicant]
“The Intel iAPX 432”—“Capability-based Computer Systems”, chapter 9, pp. 159-186, Henry M. Levy, Digital Press, 1984. [cited by applicant]
Bennet Yee, David Sehr, Gregory Dardyk, J. Bradley Chen, Robert Muth, Tavis Ormandy, Shiki Dkasaka, Neha Narula, Nicholas Fullagar, “Native Client: A Sandbox for Portable, Untrusted x86 Native code,” sp, pp. 79-93, 2009… [cited by applicant]
Bojinov et al., Address space randomization for mobile devices, Jun. 2011, 11 pages. [cited by applicant]
Nicholas P. Carter, Stephen W. Keckler, William J. Dally. “Hardware Support for Fast Capability-based Addressing”, ASPLOS-VI Proceedings—Sixth International Conference on Architectural Support for Programming Languages … [cited by applicant]
E.J. Koldinger, J.S. Chase, S.J. Eggers, “Architectural Support for Single Address Space Operating Systems”, Architectural Support for Programming Languages and Operating Systems (ASPLOS) V, pp. 175-186, 1992. [cited by applicant]
Hertz et al. “Quantifying the Performance of Garbage Collection vs. Explicit Memory Management”; SIGPLAN Not.,40 (10):313-326, 2005. [cited by applicant]
Intel, “Intel Itanium Architecture Software Developer's Manual, vol. 2: System Architecture”, Revision 2.3, May 2010, pp. 2:59-2:60, pp. 2:564-2:565. [cited by applicant]
Intel, “Intel Itanium Architecture Software Developer's Manual, vol. 3: Intel Itanium Instruction Set Reference”, Revision 2.3, May 2010, p. 3:29, p. 3:53. [cited by applicant]
International Search Report for PCT/US2020/29406 dated Jul. 17, 2020. [cited by applicant]
Jeffrey S. Chase, Henry M. Levy, Michael J. Feeley, Edward D. Lazowska, “Sharing and Protection in a Single-Address-Space Operating System”, ACM Transactions on Computer Systems 1994, vol. 12, No. 4, pp. 271-307. [cited by applicant]
Joe Devietti, Colin Blundell, Milo M. K. Martin, Steve Zdancewic. “HardBound: Architectural Support for Spatial Safety of the C Programming Language”, ASPLOS-XIIII Proceedings—Thirteenth International Conference on Arch… [cited by applicant]
Nagarakette et al., WatchdogLite: Hardware-Accelerated Compiler-Based Pointer Checking, Feb. 2014, 10 pages. [cited by applicant]
Cited By (1)
US 12,693,982