IP Library › Granted Patent US 10,102,380
Granted Patent B2
US 10,102,380 · App. 13/802,272 · Granted Oct 16, 2018

Method and apparatus to provide secure application execution

Inventors: Francis X. McKeen (Portland, OR); Carlos V. Rozas (Portland, OR); Uday R. Savagaonkar (Portland, OR); Simon P. Johnson (Beaverton, OR); Vincent Scarlata (Beaverton, OR); Michael A. Goldsmith (Lake Oswego, OR); Ernie Brickell (Hillsboro, OR); Jiang Tao Li (Beaverton, OR); Howard C. Herbert (Phoenix, AZ); Prashant Dewan (Hillsboro, OR); Stephen J. Tolopka (Portland, OR); Gilbert Neiger (Portland, OR); David Durham (Beaverton, OR); Gary Graunke (Hillsboro, OR); Bernard Lint (Mountain View, CA); Don A. Van Dyke (Rescue, CA); Joseph Cihula (Hillsboro, OR); Stalinselvaraj Jeyasingh (Beaverton, OR); Stephen R. Van Doren (Portland, OR); Dion Rodgers (Hillsboro, OR); John Garney (Portland, OR); Asher Altman (Bedford, MA)
Assignee: Intel Corporation
G06F21/60G06F21/53G06F21/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,102,380
App. No.
13/802,272
Granted
Oct 16, 2018
Kind
B2
Abstract

A technique to enable secure application and data integrity within a computer system. In one embodiment, one or more secure enclaves are established in which an application and data may be stored and executed.

Claims (12)

1. A processor comprising:

execution circuitry to perform at least a first instruction to move protected data between an enclave page cache (EPC) and a second storage area during execution of a program accessing the protected data, wherein the program is to run in a protected mode, wherein the execution of first instruction is to add a page to a secure enclave and the first instruction is to include an address of a data structure used as a parameter to EPC-management instructions and an address of a destination in the EPC.

2. The processor of claim 1 , wherein a security map (SMAP) is to help ensure the integrity of the program when the program is stored in a hard disk drive or protected memory.

3. The processor of claim 1 , wherein the first instruction is to be executed in a non-kernel privilege level.

4. The processor of claim 3 , wherein the secure enclave is not initialized.

5. The processor of claim 3 , wherein secure enclave is initialized.

6. A computer-implemented method comprising:

performing at least a first instruction to move protected data between an enclave page cache (EPC) and a second storage area during execution of a program accessing the protected data, wherein the program is to run in a protected mode, wherein the execution of first instruction is to add a page to a secure enclave and the first instruction is to include an address of a data structure used as a parameter to EPC-management instructions and an address of a destination in the EPC.

7. The computer-implemented method of claim 6 , wherein a security map (SMAP) is used to help ensure the integrity of the program when the program is stored in a hard disk drive or protected memory.

8. The computer-implemented method of claim 6 , wherein the first instruction is to be executed in a non-kernel privilege level.

9. The computer-implemented method of claim 8 , wherein the secure enclave is not initialized.

10. The computer-implemented method of claim 8 , wherein secure enclave is initialized.

Continuity (3)
Continuation 13527547 · Jun 19, 2012
Continuation In Part PCTUS2009069212 · Dec 22, 2009
Related Publication 20130198853A1 · Aug 1, 2013
Cited By (3)
US 12,242,393 US 12,657,287 US 12,699,768