IP Library › Granted Patent US 8,108,905
Granted Patent B2
US 8,108,905 · App. 11/553,008 · Granted Jan 31, 2012

System and method for an isolated process to control address translation

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,108,905
App. No.
11/553,008
Granted
Jan 31, 2012
Kind
B2
Abstract

A system, method, and computer-usable medium for an isolated process to control address translation. According to a preferred embodiment of the present invention, an isolation region that is accessible only to a first processing unit in a data processing system is created. A loader is executed to load a secure process in the isolation region. If the secure process is determined to be allowed to issue real mode direct memory access commands, real mode direct memory access commands are enabled to allow the secure process to issue non-translated direct memory access commands.

Claims (19)

1. A method for verifying an operating system image utilized to boot a data processing system has not been altered since the booting of said data processing system, said method comprising:

partitioning a local store unit within an attached processor element into a general access region and an isolation region, wherein said isolation region is accessible only to an attached processor unit within said attached processor element of a data processing system having a main processor unit and a system memory;

executing a loader to load a secure process in said isolation region, wherein said secure process is a system monitor;

determining if said secure process is allowed to use real mode direct memory access commands; and

in response to a determination that said secure process is allowed to use real mode direct memory access commands, enabling real mode direct memory access commands to allow said secure process to issue non-translated direct memory access commands to verify an operating system image utilized to boot said data processing system has not been altered since booting of said data processing system.

2. The method of claim 1 , wherein said method further includes authenticating said loader.

3. The method of claim 1 , wherein said enabling real mode direct memory access commands further includes enabling a configuration bit readable by the said secure process, wherein said configuration bit enables a set of special DMA command opcodes for real mode direct memory access.

4. The method of claim 1 , wherein said method further includes booting said data processing system utilizing said operating system image.

5. The method of claim 1 , wherein said method further includes in response to loading said secure process, loading and executing an application within said isolated region.

6. A data processing system comprising:

a main processing unit;

a system memory;

an attached processor element coupled to said main processing unit and said system memory, wherein said attached processor element includes an attached processor unit, a local store unit and a load/exit state machine, wherein said local store unit includes a general access section and an isolated section, wherein said isolated section is accessible only to said attached processor unit, wherein said load/exit state machine

determines if a secure process is allowed to use real mode direct memory access commands after said secure process has been loaded in said isolated section, wherein said secure process is a system monitor loaded in said isolated section via a loader; and

in response to a determination that said secure process is allowed to use real mode direct memory access commands, enables real mode direct memory access commands to allow a system monitor within said isolated section to issue non-translated direct memory access commands to verify an operating system image utilized to boot said data processing system has not been altered since booting said data processing system.

7. The data processing system of claim 6 , wherein said system monitor performs a system monitor function.

8. The data processing system of claim 6 , wherein said real mode direct memory access commands are enabled via a configuration bit readable by said secure process, wherein said configuration bit enables a set of special command opcodes for real mode direct memory access.

9. The data processing system of claim 6 , wherein said data processing system is boot by utilizing an operating system image.

10. The data processing system of claim 6 , wherein said attached processor unit executes an application within said isolated section.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2006
From: JOHNS, CHARLES R.; SHIMIZU, KANNA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 018437/0973 →
Continuity (1)
Related Publication 20080104711A1 · May 1, 2008