IP Library Patent Application 18194086
Patent Application
App. No. 18/194,086

CIRCUITRY AND METHODS FOR IMPLEMENTING FORWARD-EDGE CONTROL-FLOW INTEGRITY (FECFI) USING ONE OR MORE CAPABILITY-BASED INSTRUCTIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/194,086
Abstract

Techniques for implementing forward-edge control-flow integrity (FECFI) using capability instructions in a hardware processor are described. In certain examples, a hardware processor (e.g., core) includes a capability management circuit to check a capability for a memory access request for a memory, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address space to which the capability authorizes access; a decoder circuit to decode a single instruction into a decoded single instruction, the single instruction comprising: a first capability to indicate a first call table comprising a respective entry for each of a plurality of functions of a first type, a field to indicate a first offset of a first entry for a first function requested for execution, and an opcode to indicate the capability management circuit is to perform a first check that the first offset is within a lower bound and an upper bound of the first capability and a second check that the first offset is a permitted offset for the entries in the first call table, and in response to the first check and the second check both passing, cause an execution circuit to execute the first function; and the execution circuit to execute the decoded single instruction according to the opcode.

Claims (38)

1 . An apparatus comprising:

a capability management circuit to check a capability for a memory access request for a memory, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address space to which the capability authorizes access;

a decoder circuit to decode a single instruction into a decoded single instruction, the single instruction comprising:

a first capability to indicate a first call table comprising a respective entry for each of a plurality of functions of a first type,

a field to indicate a first offset of a first entry for a first function requested for execution, and

an opcode to indicate the capability management circuit is to perform a first check that the first offset is within a lower bound and an upper bound of the first capability and a second check that the first offset is a permitted offset for the entries in the first call table, and in response to the first check and the second check both passing, cause an execution circuit to execute the first function; and

the execution circuit to execute the decoded single instruction according to the opcode.

2 . The apparatus of claim 1 , wherein the execution circuit is to, in response to the second check indicating that the first offset is not the permitted offset, cause the single instruction to fault.

3 . The apparatus of claim 2 , wherein the execution circuit is to, in response to the first check indicating that the first offset is beyond the lower bound or the upper bound of the first capability, cause the single instruction to fault.

4 . The apparatus of claim 3 , wherein the execution circuit is to, in response to a third check indicating that a validity tag of the first capability is not set, cause the single instruction to fault.

5 . The apparatus of claim 1 , wherein an object type field of the first capability is to indicate the first capability is for a call table type of object.

6 . The apparatus of claim 1 , wherein a prefix of the first capability is to indicate the first capability is for a call table type of object.

7 . The apparatus of claim 1 , wherein the first entry in the first call table comprises a second capability for the first function in the memory, and the opcode is to indicate that the execution circuit is to cause the capability management circuit to perform a third check that the first function is authorized by the second capability for execution, and in response to the first check, the second check, and the third check all passing, cause the execution circuit to execute the first function.

8 . A method comprising:

checking, by a capability management circuit of a processor, a capability for a memory access request for a memory, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address space to which the capability authorizes access;

decoding, by a decoder circuit of the processor, a single instruction into a decoded single instruction, the single instruction comprising:

a first capability to indicate a first call table comprising a respective entry for each of a plurality of functions of a first type,

a field to indicate a first offset of a first entry for a first function requested for execution, and

an opcode to indicate the capability management circuit is to perform a first check that the first offset is within a lower bound and an upper bound of the first capability and a second check that the first offset is a permitted offset for the entries in the first call table, and in response to the first check and the second check both passing, cause an execution circuit to execute the first function; and

executing, by the execution circuit, the decoded single instruction according to the opcode.

9 . The method of claim 8 , wherein, in response to the second check indicating that the first offset is not the permitted offset, the executing causes the single instruction to fault.

10 . The method of claim 9 , wherein, in response to the first check indicating that the first offset is beyond the lower bound or the upper bound of the first capability, the executing causes the single instruction to fault.

11 . The method of claim 10 , wherein, in response to a third check indicating that a validity tag of the first capability is not set, the executing causes the single instruction to fault.

12 . The method of claim 8 , wherein an object type field of the first capability is to indicate the first capability is for a call table type of object.

13 . The method of claim 8 , wherein a prefix of the first capability is to indicate the first capability is for a call table type of object.

14 . The method of claim 8 , wherein the first entry in the first call table comprises a second capability for the first function in the memory, and the opcode is to indicate that the capability management circuit is to perform a third check that the first function is authorized by the second capability for execution, and in response to the first check, the second check, and the third check all passing, cause the execution circuit to execute the first function.

15 . A non-transitory machine-readable medium that stores code that when executed by a machine causes the machine to perform a method comprising:

checking, by a capability management circuit of a processor, a capability for a memory access request for a memory, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address space to which the capability authorizes access;

decoding, by a decoder circuit of the processor, a single instruction into a decoded single instruction, the single instruction comprising:

a first capability to indicate a first call table comprising a respective entry for each of a plurality of functions of a first type,

a field to indicate a first offset of a first entry for a first function requested for execution, and

an opcode to indicate the capability management circuit is to perform a first check that the first offset is within a lower bound and an upper bound of the first capability and a second check that the first offset is a permitted offset for the entries in the first call table, and in response to the first check and the second check both passing, cause an execution circuit to execute the first function; and

executing, by the execution circuit, the decoded single instruction according to the opcode.

16 . The non-transitory machine-readable medium of claim 15 , wherein, in response to the second check indicating that the first offset is not the permitted offset, the executing causes the single instruction to fault.

17 . The non-transitory machine-readable medium of claim 16 , wherein, in response to the first check indicating that the first offset is beyond the lower bound or the upper bound of the first capability, the executing causes the single instruction to fault.

18 . The non-transitory machine-readable medium of claim 15 , wherein an object type field of the first capability is to indicate the first capability is for a call table type of object.

19 . The non-transitory machine-readable medium of claim 15 , wherein a prefix of the first capability is to indicate the first capability is for a call table type of object.

20 . The non-transitory machine-readable medium of claim 15 , wherein the first entry in the first call table comprises a second capability for the first function in the memory, and the opcode is to indicate that the capability management circuit is to perform a third check that the first function is authorized by the second capability for execution, and in response to the first check, the second check, and the third check all passing, cause the execution circuit to execute the first function.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2026
From: INTEL CORPORATION
To: INTEL PRODUCTS IP LLC
Reel/Frame 075991/0981 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2023
From: CONSTABLE, SCOTT D.; LEMAY, MICHAEL
To: INTEL CORPORATION
Reel/Frame 063279/0024 →