IP Library Granted Patent US 8,972,746
Granted Patent B2
US 8,972,746 · App. 12/972,406 · Granted Mar 3, 2015

Technique for supporting multiple secure enclaves

Inventors: Simon P. Johnson (Beaverton, OR); Uday R. Savagaonkar (Portland, OR); Vincent R. Scarlata (Beaverton, OR); Francis X. McKeen (Portland, OR); Carlos V. Rozas (Portland, OR)
Assignee: Intel Corporation
G06F12/1466G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,972,746
App. No.
12/972,406
Granted
Mar 3, 2015
Kind
B2
Abstract

A technique to enable secure application and data integrity within a computer system. In one embodiment, one or more secure enclaves are established in which an application and data may be stored and executed.

Claims (14)

1. A system comprising:

hardware logic to generate a platform-level key to provide for a secure enclave corresponding to a plurality of processors, wherein the platform-level key is to be derived from a plurality of processor-level keys corresponding to the plurality of processors, wherein each of the plurality of processors is to store a plurality of package-unique symmetric keys (PUSKs) and a plurality of package-specific asymmetric keys (PASKs), and wherein the secure enclave is to be executed from an enclave page cache in which data is to be protected using access control mechanisms to be provided by at least one processor of the plurality of processors having an instruction set architecture including a plurality of secure enclave instructions.

2. The system of claim 1 , Wherein the plurality of processors is contained within a plurality of processor packages.

3. The system of claim 1 , wherein the plurality of processors is contained within a single processor package.

4. A method comprising:

generating, by hardware logic, a multi-package secure enclave key, common to a plurality of processors;

storing the multi-package secure enclave key;

storing a package-unique symmetric key (PUSK) into the plurality of processors to be

used in a multi-package secure enclave, and

creating a plurality of package-specific asymmetric keys (PASKs) for each of the plurality of processors,

wherein a secure enclave is to be executed from an enclave page cache in which data is to

be protected using access control mechanisms to be provided by at least one processor of

the plurality of processors having an instruction set architecture including a plurality of

secure enclave instructions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2012
From: JOHNSON, SIMON P.; SAVAGAONKAR, UDAY R.; SCARLATA, VINCENT R.; MCKEEN, FRANCIS X.; ROZAS, CARLOS V.
To: INTEL CORPORATION
Reel/Frame 028972/0695 →
Continuity (1)
Related Publication 20120159184A1 · Jun 21, 2012