IP Library › Granted Patent US 12,608,479
Granted Patent B2
US 12,608,479 · App. 18/164,705 · Granted Apr 21, 2026

Secure initial program load (IPL) code loading attributes facility

Inventors: Louis P. Gomes (Poughkeepsie, NY); Peter Oberparleiter (Dettenhausen, DE)
Assignee: International Business Machines Corporation
G06F21/575G06F21/54G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,608,479
App. No.
18/164,705
Granted
Apr 21, 2026
Kind
B2
Abstract

A method, system, and computer program product are provided for preventing malicious code injection during Initial Program Load (IPL). A secure code loading attributes block (SCLAB) is appended to a variable sized signed binary code component to generate a combined component. The variable sized signed binary code component is Operating System (OS) code for an initial program load (IPL) process. The SCLAB comprises contents that include a length field, an identifier, flag fields, a load program status word (PSW) and a load address. The combined component is digitally signed. During IPL, the unsigned component table entries associated with the signed component are verified against the SCLAB contents.

Claims (41)

1 . A method, comprising:

appending a secure-code-loading-attributes block (SCLAB) to a variable sized signed binary code component to generate a combined component, wherein the variable sized signed binary code component is Operating System (OS) code for an initial program load (IPL) process, and wherein the SCLAB comprises contents including a length field, an identifier, flag fields, a load program status word (PSW) and a load address,

signing the combined component using a private key, and

verifying the signed combined component during the IPL.

2 . The method of claim 1 , wherein the verifying further comprises:

decrypting, by a system boot loader, a signature of the variable sized signed binary code component and a signature of the SCLAB using a public key, wherein a signature mismatch terminates the IPL;

based on a signature match, validating the SCLAB contents; and

based on the SCLAB contents being valid, continuing the IPL.

3 . The method of claim 1 , wherein the length field specifies the length of the SCLAB, the SCLAB begins immediately following the signed binary code component, and wherein a start of the SCLAB is determined by subtracting from an end of a variable size signed binary code component address.

4 . The method of claim 1 , wherein the flag fields comprise a first flag indicating override PSW, wherein when the first flag indicating override PSW is set, a load PSW in the SCLAB is used to start the OS code instead of a PSW specified in an unsigned component table entry.

5 . The method of claim 1 , wherein the flag fields comprise a second flag indicating override load address, wherein when the second flag indicating override load address is set, a load address in the SCLAB is used instead of the load address specified in an unsigned component table entry.

6 . The method of claim 1 , wherein the SCLAB contents are set during building the variable sized signed binary code component, and wherein a mismatch of the SCLAB contents to SCLAB contents during the IPL process terminates the IPL.

7 . The method of claim 1 , wherein the contents in the SCLAB control a load location and a start address in memory without modifying the variable sized signed binary code component.

8 . A computer program product, the computer program product comprising a non-transitory tangible storage device having program code embodied therewith, the program code executable by a processor of a computer to perform a method, the method comprising:

appending a secure-code-loading-attributes block (SCLAB) to a variable sized signed binary code component to generate a combined component, wherein the variable sized signed binary code component is Operating System (OS) code for an initial program load (IPL) process, and wherein the SCLAB comprises contents including a length field, an identifier, flag fields, a load program status word (PSW) and a load address;

signing the combined component using a private key; and

verifying the signed combined component against the SCLAB contents during the IPL.

9 . The computer program product of claim 8 , wherein the verifying further comprises:

decrypting, by a system boot loader, a signature of the variable sized signed binary code component and a signature of the SCLAB using a public key, wherein a signature mismatch terminates the IPL;

based on a signature match, validating the SCLAB contents; and

based on the SCLAB contents being valid, continuing the IPL.

10 . The computer program product of claim 8 , wherein the length field specifies the length of the SCLAB, the SCLAB begins immediately following the signed binary code component, and wherein a start of the SCLAB is determined by subtracting from an end of a variable size signed binary code component address.

11 . The computer program product of claim 8 , wherein the flag fields comprise a first flag indicating override PSW, wherein when the first flag indicating override PSW is set, a load PSW in the SCLAB is used to start the OS code instead of a PSW specified in an unsigned component table entry.

12 . The computer program product of claim 8 , wherein the flag fields comprise a second flag indicating override load address, wherein when the second flag indicating override load address is set, a load address in the SCLAB is used instead of the load address specified in an unsigned component table entry.

13 . The computer program product of claim 8 , wherein the SCLAB contents are set during building the variable sized signed binary code component, and wherein a mismatch of the SCLAB contents to SCLAB contents during the IPL process terminates the IPL.

14 . The computer program product of claim 8 , wherein the contents in the SCLAB control a load location and a start address in memory without modifying the variable sized signed binary code component.

15 . A computer system, comprising:

one or more processors;

a memory coupled to at least one of the processors;

a set of computer program instructions stored in the memory and executed by at least one of the processors in order to perform actions of:

appending a secure-code-loading-attributes block (SCLAB) to a variable sized signed binary code component to generate a combined component, wherein the variable sized signed binary code component is Operating System (OS) code for an initial program load (IPL) process, and wherein the SCLAB comprises contents including a length field, an identifier, flag fields, a load program status word (PSW) and a load address;

signing the combined component using a private key; and

verifying the signed combined component against the SCLAB contents during the IPL.

16 . The computer system of claim 15 , wherein the verifying further comprises:

decrypting, by a system boot loader, a signature of the variable sized signed binary code component and a signature of the SCLAB using a public key, wherein a signature mismatch terminates the IPL;

based on a signature match, validating the SCLAB contents; and

based on the SCLAB contents being valid, continuing the IPL.

17 . The computer system of claim 15 , wherein the length field specifies the length of the SCLAB, the SCLAB begins immediately following the signed binary code component, and wherein a start of the SCLAB is determined by subtracting from an end of a variable size signed binary code component address.

18 . The computer system of claim 15 , wherein the flag fields comprise a first flag indicating override PSW, wherein when the first flag indicating override PSW is set, a load PSW in the SCLAB is used to start the OS code instead of a PSW specified in an unsigned component table entry.

19 . The computer system of claim 15 , wherein the flag fields comprise a second flag indicating override load address, wherein when the second flag indicating override load address is set, a load address in the SCLAB is used instead of the load address specified in an unsigned component table entry.

20 . The computer system of claim 15 , wherein the SCLAB contents are set during building the variable sized signed binary code component, and wherein a mismatch of the SCLAB contents to SCLAB contents during the IPL process terminates the IPL.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2023
From: GOMES, LOUIS P.; OBERPARLEITER, PETER
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062597/0463 →
Continuity (1)
Related Publication 20240265108A1 · Aug 8, 2024
References Cited (12)
US 10615989B2 · Kreft · 2020 [cited by applicant]
US 10902126B2 · Sutton · 2021 [cited by applicant]
US 11374773B2 · Kreft · 2022 [cited by applicant]
US 11500787B2 · Wei · 2022 [cited by examiner]
US 20180260569A1 · Sutton · 2018 [cited by examiner]
US 20200342111A1 · Gomes · 2020 [cited by examiner]
US 20250124156A1 · Beecham · 2025 [cited by examiner]
Disclosed Anonymouly, “Security layer to prevent access to file system objects from malicious code,” IP.com, Aug. 10, 2005, 3 pages, IP.com No. IPCOM000126911D, Retrieved from the Internet: <URL: https://priorart.ip.com… [cited by applicant]
Disclosed Anonymously, “ETL Stage for Malicious Code Neutralization,” IP.com, Apr. 12, 2021, 4 pages, IP.com No. IPCOM000265448D, Retrieved from the Internet: <URL: https://priorart.ip.com/IPCOM/000265448>. [cited by applicant]
Disclosed Anonymously, “Vulnerability Scanning when Inserting Code,” IP.com, Jun. 15, 2022, 6 pages, IP.com No. IPCOM000270210D, Retrieved from the Internet <URL: https://priorart.ip.com/IPCOM/000270210>. [cited by applicant]
Faisina, et al., “Grab 'n Run: Secure and Practical Dynamic Code Loading for Android Applications,” ACSAC '15 [conference], Dec. 7-11, 2015, 10 pages, Los Angeles, CA, ACM 978-1-4503-3682-6/15/12, DOI: 10.1145/2818000.2… [cited by applicant]
Unknown Author, “Malicious Code,” Cyber Awareness Challenge 2022 [unclassified], 2022, 2 pages, Retrieved from the Internet: <URL: https://dl.dod.cyber.mil/wp-content/uploads/tmn/online/disa_cac_2022_final_web/pdf/DISA_… [cited by applicant]