IP Library Granted Patent US 11,977,760
Granted Patent B1
US 11,977,760 · App. 18/244,060 · Granted May 7, 2024

Secure data and instruction loading

Inventors: Andrew James Weiler (Nampa, ID); Nathan Charles Chrisman (Nampa, ID); Claude Harmon Garrett, V (Meridian, ID); Dale Weston Reese (Boise, ID); Matthew Ryan Waltz (Boise, ID); Jay Takeji Hirata (Meridian, ID)
Assignee: IDAHO SCIENTIFIC LLC
G06F3/064G06F3/0623G06F3/0673
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,977,760
App. No.
18/244,060
Granted
May 7, 2024
Kind
B1
Abstract

Securely loading digital blocks into memory for consumption by a processor. A method includes, at a memory protection shim, receiving a digital block and a manifest for the digital block. The manifest includes a transformation key for the digital block. The transformation key is configured to be used for at least one of validating the digital block or decrypting the digital block. The manifest is encrypted. The method further includes decrypting the manifest to obtain the transformation keys. The method further includes using the transformation keys to perform at least one of validating or decrypting the digital block. The method further includes retransforming the digital block using a memory protection shim ephemeral key to perform at least one of creating an authentication tag or encrypting the digital block. The method further includes storing the retransformed digital block in memory.

Claims (37)

1. A method for securely loading digital blocks into memory for consumption by a processor, the method comprising:

at a memory protection shim, receiving a digital block and a manifest for the digital block, wherein the manifest comprises a transformation key for the digital block, the transformation key configured to be used for at least one of validating the digital block or decrypting the digital block, and wherein the manifest is encrypted;

at the memory protection shim, decrypting the manifest to obtain the transformation key;

at the memory protection shim, using the transformation key to perform at least one of validating or decrypting the digital block;

at the memory protection shim, retransforming the digital block using a memory protection shim ephemeral key to perform at least one of creating an authentication tag or encrypting the digital block; and

storing the retransformed digital block in memory.

2. The method of claim 1 , wherein storing the retransformed digital block in the memory comprises storing the retransformed digital block in a same location in the memory from which the digital block was received.

3. The method of claim 1 , wherein using the transformation key to perform at least one of validating or decrypting the digital block comprises validating a virtual memory address location for the digital block.

4. The method of claim 1 , wherein retransforming the digital block comprises adding a physical address location to the authentication tag.

5. The method of claim 1 , wherein decrypting the manifest comprises decrypting the manifest using a private key of a public key/private key pair, where a public key of the public key/private key pair was used to encrypt the manifest.

6. The method of claim 5 , wherein the public key/private key pair is created on a per hardware manufacturer basis.

7. The method of claim 5 , wherein the public key/private key pair is created on a per hardware device basis.

8. A non-transitory physical computer-readable medium comprising computer executable instructions that when executed by one or more processors causes the one or more processors to perform the following:

at a memory protection shim, receiving a digital block and a manifest for the digital block, wherein the manifest comprises a transformation key for the digital block, the transformation key configured to be used for at least one of validating the digital block or decrypting the digital block, and wherein the manifest is encrypted;

at the memory protection shim, decrypting the manifest to obtain the transformation key;

at the memory protection shim, using the transformation key to perform at least one of validating or decrypting the digital block;

at the memory protection shim, retransforming the digital block using a memory protection shim ephemeral key to perform at least one of creating an authentication tag or encrypting the digital block; and

storing the retransformed digital block in memory.

9. The non-transitory physical computer-readable medium of claim 8 , wherein storing the retransformed digital block in the memory comprises storing the retransformed digital block in a same location in the memory from which the digital block was received.

10. The non-transitory physical computer-readable medium of claim 8 , wherein using the transformation key to perform at least one of validating or decrypting the digital block comprises validating a virtual memory address location for the digital block.

11. The non-transitory physical computer-readable medium of claim 8 , wherein retransforming the digital block comprises adding a physical address location to the authentication tag.

12. The non-transitory physical computer-readable medium of claim 8 , wherein decrypting the manifest comprises decrypting the manifest using a private key of a public key/private key pair, where a public key of the public key/private key pair was used to encrypt the manifest.

13. The non-transitory physical computer-readable medium of claim 12 , wherein the public key/private key pair is created on a per hardware manufacturer basis.

14. The non-transitory physical computer-readable medium of claim 12 , wherein the public key/private key pair is created on a per hardware device basis.

15. A computing system comprising:

one or more processors; and

one or more computer-readable media coupled to the one or more processors, the computer-readable media comprising computer executable instructions that when executed by one or more processors causes the one or more processors to perform the following:

at a memory protection shim, receiving a digital block and a manifest for the digital block, wherein the manifest comprises a transformation key for the digital block, the transformation key configured to be used for at least one of validating the digital block or decrypting the digital block, and wherein the manifest is encrypted;

at the memory protection shim, decrypting the manifest to obtain the transformation key;

at the memory protection shim, using the transformation key to perform at least one of validating or decrypting the digital block;

at the memory protection shim, retransforming the digital block using a memory protection shim ephemeral key to perform at least one of creating an authentication tag or encrypting the digital block; and

storing the retransformed digital block in memory.

16. The computing system of claim 15 , wherein storing the retransformed digital block in the memory comprises storing the retransformed digital block in a same location in the memory from which the digital block was received.

17. The computing system of claim 15 , wherein using the transformation key to perform at least one of validating or decrypting the digital block comprises validating a virtual memory address location for the digital block.

18. The computing system of claim 15 , wherein retransforming the digital block comprises adding a physical address location to the authentication tag.

19. The computing system of claim 15 , wherein decrypting the manifest comprises decrypting the manifest using a private key of a public key/private key pair, where a public key of the public key/private key pair was used to encrypt the manifest.

20. The computing system of claim 19 , wherein the public key/private key pair is created on a per hardware manufacturer basis or on a per hardware device basis.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2026
From: IDAHO SCIENTIFIC LLC
To: GENERAL DYNAMICS MISSION SYSTEMS,
Reel/Frame 073779/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: WEILER, ANDREW JAMES; CHRISMAN, NATHAN CHARLES; GARRETT, CLAUDE HARMON, V; REESE, DALE WESTON; WALTZ, MATTHEW RYAN; HIRATA, JAY TAKEJI
To: IDAHO SCIENTIFIC LLC
Reel/Frame 065377/0115 →