IP Library Granted Patent US 11,928,058
Granted Patent B1
US 11,928,058 · App. 17/965,762 · Granted Mar 12, 2024

Computing data and instructions at immutable points

Inventors: Dale Weston Reese (Boise, ID); Matthew Ryan Waltz (Boise, ID); Jay Takeji Hirata (Meridian, ID); Andrew James Weiler (Nampa, ID); Nathan Charles Chrisman (Nampa, ID); Claude Harmon Garrett, V (Meridian, ID)
Assignee: IDAHO SCIENTIFIC LLC
G06F12/0802G06F2212/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,928,058
App. No.
17/965,762
Granted
Mar 12, 2024
Kind
B1
Abstract

An apparatus comprising a CPU core configured to execute instructions and consume data. The apparatus includes a memory configured to store the instructions and the data. A memory protection shim is coupled to the CPU core and the memory. The memory protection shim is configured to perform transformations over digital blocks to perform at least one of authentication or decryption of the digital blocks received from the memory. The memory protection shim is coupled to the CPU core in a fashion that prevents egress of the digital blocks or ingress of other external digital blocks between the memory protection shim and the CPU core.

Claims (29)

1. An apparatus comprising:

a CPU core configured to execute instructions and consume data;

a memory configured to store the instructions and the data; and

a memory protection shim coupled to the CPU core and the memory, wherein the memory protection shim is configured to perform transformations over digital blocks, the digital blocks comprising at least one of the data or the instructions, to perform at least one of authentication or decryption of the digital blocks received from the memory, and wherein the memory protection shim is coupled to the CPU core in a fashion that prevents egress of the digital blocks or ingress of other external digital blocks between the memory protection shim and the CPU core.

2. The apparatus of claim 1 , wherein the memory protection shim is coupled to the CPU core via a bus that logically separates instructions and data.

3. The apparatus of claim 1 , wherein the memory protection shim is coupled to the CPU core via physically separated instruction and data busses.

4. The apparatus of claim 1 , wherein the memory protection shim is coupled to the CPU core in a fashion that prevents egress of the digital blocks or ingress of the other external digital blocks between the memory protection shim and the CPU core by the memory protection shim being coupled directly to a Level 1 cache directly built into the CPU core and to a Level 2 cache external to the CPU core, but included in an integrated fashion with the CPU core.

5. The apparatus of claim 4 , wherein the CPU core, the memory protection shim, and the Level 2 cache are implemented in an integrated fashion on a same silicon die.

6. The apparatus of claim 4 , wherein the CPU core, the memory protection shim, and the Level 2 cache are implemented in an integrated fashion in a same semiconductor package.

7. The apparatus of claim 1 , wherein the memory protection shim is implemented in a package external to a package for the CPU core.

8. The apparatus of claim 1 , wherein the memory protection shim is coupled to the CPU core in a fashion that prevents egress of the digital blocks or ingress of the other external digital blocks between the memory protection shim and the CPU core by the memory protection shim being configured to perform the transformations over the digital blocks temporally proximate to when the digital blocks are requested from CPU core.

9. An apparatus comprising:

a memory protection shim configured to be coupled to a CPU core and memory, wherein the CPU core is configured to execute instructions and consume data and wherein the memory is configured to store the instructions and the data;

wherein the memory protection shim is configured to perform transformations over digital blocks, the digital blocks comprising at least one of the data or the instructions, to perform at least one of authentication or decryption of the digital blocks received from the memory; and

wherein the memory protection shim is configured to be coupled to the CPU core in a fashion that prevents egress of the digital blocks or ingress of other external digital blocks between the memory protection shim and the CPU core.

10. The apparatus of claim 9 , wherein the memory protection shim is configured to be coupled to the CPU core via a bus that logically separates instructions and data.

11. The apparatus of claim 9 , wherein the memory protection shim is configured to be coupled to the CPU core via physically separated instruction and data busses.

12. The apparatus of claim 9 , wherein the memory protection shim is configured to be coupled to the CPU core in a fashion that prevents egress of the digital blocks or ingress of the other external digital blocks between the memory protection shim and the CPU core by the memory protection shim being configured to be coupled directly to a Level 1 cache directly built into the CPU core and to a Level 2 cache external to the CPU core.

13. The apparatus of claim 9 , wherein the memory protection shim is implemented in a semiconductor package external to a semiconductor package for the CPU core.

14. The apparatus of claim 9 , wherein the memory protection shim is configured to be coupled to the CPU core in a fashion that prevents egress of the digital blocks or ingress of the other external digital blocks between the memory protection shim and the CPU core by the memory protection shim being configured to perform the transformations over the digital blocks temporally proximate to when the digital blocks are requested from CPU core.

15. A method of consuming data in a secure fashion, the method comprising:

at a memory protection shim coupled to a CPU core configured to execute instructions and consume data and a memory configured to store the instructions and the data, receiving a digital block from the memory;

performing one or more transformations over the digital block, the digital block comprising at least one of the data or the instructions, to perform at least one of authentication or decryption of the digital blocks received from the memory; and

as a result of authentication or decryption, providing the digital block to the CPU core in a fashion that prevents egress of the digital blocks or ingress of other external digital blocks between the memory protection shim and the CPU core.

16. The method of claim 15 , wherein the memory protection shim receives the digital block via a bus that logically separates instructions and data.

17. The method of claim 15 , wherein the memory protection shim receives the digital block via at least one of a physically separated instruction or data bus.

18. The method of claim 15 , wherein the memory protection shim prevents egress of the digital blocks or ingress of the other external digital blocks between the memory protection shim and the CPU core by the memory protection shim being coupled directly to a Level 1 cache directly built into the CPU core and to a Level 2 cache external to the CPU core, but included in an integrated fashion with the CPU core.

19. The method of claim 15 , wherein providing the digital block to the CPU core comprises the memory protection shim providing the digital block from a package external to a package for the CPU core.

20. The method of claim 15 , wherein the memory protection shim prevents egress of the digital blocks or ingress of the other external digital blocks between the memory protection shim and the CPU core by the memory protection shim performing the transformations over the digital blocks temporally proximate to when the digital blocks are requested from CPU core.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2026
From: IDAHO SCIENTIFIC LLC
To: GENERAL DYNAMICS MISSION SYSTEMS,
Reel/Frame 073779/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2023
From: GARRETT, CLAUDE HARMON, V
To: IDAHO SCIENTIFIC LLC
Reel/Frame 065218/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2022
From: REESE, DALE WESTON; WALTZ, MATTHEW RYAN; HIRATA, JAY TAKEJI; WEILER, ANDREW JAMES; CHRISMAN, NATHAN CHARLES; GARRETT, CLAUDE HARMON, V
To: IDAHO SCIENTIFIC LLC
Reel/Frame 061500/0050 →
Continuity (1)
Continuation 17942936 · Sep 12, 2022