IP Library › Granted Patent US 12,210,875
Granted Patent B2
US 12,210,875 · App. 18/457,224 · Granted Jan 28, 2025

Security vulnerability mitigation using address space co-execution

Inventors: Amit Shah (Dresden, DE); Jan Hendrik Schoenherr (Dresden, DE); Karimallah Ahmed Mohammed Raslan (Dresden, DE); Marius Hillenbrand (Dresden, DE); Filippo Sironi (Dresden, DE)
Assignee: Amazon Technologies, Inc.
G06F9/3009G06F9/45558G06F9/4881G06F9/5044G06F9/545G06F2009/4557G06F2209/5018
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,210,875
App. No.
18/457,224
Granted
Jan 28, 2025
Kind
B2
Abstract

A first set of instructions, which is provided access to a first address space, is scheduled for execution at a first hardware thread of a processor. Prior to executing an instruction of a second set of instructions, which accesses a second address space, at the first hardware thread, a determination is made that the second address space is accessible from a second hardware thread of the processor.

Claims (43)

1. A computer-implemented method, comprising:

receiving, from a client of a cloud computing environment via one or more programmatic interfaces, an indication that at least a pair of compute instances established on behalf of the client at the cloud computing environment belong to a trusted group of compute instances;

propagating, to one or more hypervisors of respective virtualization hosts of the cloud computing environment, information about the trusted group of compute instances;

executing a hypervisor of the one or more hypervisors on a virtualization host of the respective virtualization hosts, wherein the virtualization host includes a set of processors that implement simultaneous multi-threading (SMT), wherein the hypervisor controls allocation of hardware threads on the set of processors to execute instruction streams of compute instances; and

executing, on the virtualization host, a set of hardware threads on the set or processors allocated to a set of instruction streams of a set of compute instances, including a particular hardware thread of a processor allocated to a first instruction stream of a particular compute instance, wherein the allocations are made based at least in part on the information about the trusted group of compute instances so that trusted compute instances in the trusted group are executed on one or more processors different from one or more processors used to execute untrusted compute instances not in the trusted group, wherein the allocations mitigate one or more co-execution security vulnerabilities associated with execution of the untrusted compute instances and trusted compute instances on a same processor of the virtualization host.

2. The computer-implemented method as recited in claim 1 , wherein the particular compute instance belongs to the trusted group of compute instances, and wherein allocation of the particular hardware thread is based at least in part on determining that a second instruction stream of a compute instance of the trusted group of compute instances is running at another hardware thread of the processor.

3. The computer-implemented method as recited in claim 1 , wherein the particular compute instance does not belong to the trusted group of compute instances, and wherein allocation of the particular hardware thread is based at least in part on determining that a second instruction stream of a compute instance of the trusted group of compute instances is not running at any of the hardware threads of the processor.

4. The computer-implemented method as recited in claim 1 , further comprising:

receiving, from another client of the cloud computing environment, via the one or more programmatic interfaces, an indication that at least a pair of programs executed at a particular computing resource on behalf of the other client belong to a trusted group of programs, wherein the particular computing resource includes an operating system;

propagating, to the operating system, information about the trusted group of programs; and

allocating, by the operating system, based at least in part on the information about the trusted group of programs, a first hardware thread of a first processor of the particular computing resource to execute a first instruction stream of a particular program.

5. The computer-implemented method as recited in claim 4 , wherein the particular program belongs to the trusted group of programs, and wherein allocation of the first hardware thread is based at least in part on determining that a second instruction stream of a program of the trusted group of programs is running at a second hardware thread of the first processor.

6. The computer-implemented method as recited in claim 4 , wherein the particular program does not belong to the trusted group of programs, and wherein allocation of the first hardware thread is based at least in part on determining that a second instruction stream of a program of the trusted group of programs is not running at any of the hardware threads of the first processor.

7. The computer-implemented method as recited in claim 4 , wherein the particular computing resource comprises a non-virtualized host.

8. A system, comprising:

one or more computing devices;

wherein the one or more computing devices include instructions that upon execution on or across one or more processors cause the one or more processors to:

receive, from a client of a cloud computing environment via one or more programmatic interfaces, an indication that at least a pair of compute instances established on behalf of the client at the cloud computing environment belong to a trusted group of compute instances;

propagate, to one or more hypervisors of respective virtualization hosts of the cloud computing environment, information about the trusted group of compute instances;

execute a hypervisor of the one or more hypervisors on a virtualization host of the respective virtualization hosts, wherein the virtualization host includes a set of processors that implement simultaneous multi-threading (SMT), wherein the hypervisor controls allocation of hardware threads on the set of processors to execute instruction streams of compute instances; and

execute, on the virtualization host, a set of hardware threads on the set or processors allocated to a set of instruction streams of a set of compute instances, including a particular hardware thread of a processor allocated to a first instruction stream of a particular compute instance, wherein the allocations are made based at least in part on the information about the trusted group of compute instances so that trusted compute instances in the trusted group are executed on one or more processors different from one or more processors used to execute untrusted compute instances not in the trusted group, wherein the allocations mitigate one or more co-execution security vulnerabilities associated with execution of the untrusted compute instances and trusted compute instances on a same processor of the virtualization host.

9. The system as recited in claim 8 , wherein the particular compute instance belongs to the trusted group of compute instances, and wherein the particular hardware thread is allocated based at least in part on determining that a second instruction stream of a compute instance of the trusted group of compute instances is running at another hardware thread of the processor.

10. The system as recited in claim 8 , wherein the particular compute instance does not belong to the trusted group of compute instances, and wherein the particular hardware thread is allocated based at least in part on determining that a second instruction stream of a compute instance of the trusted group of compute instances is not running at any of the hardware threads of the processor.

11. The system as recited in claim 8 , wherein the one or more computing devices include further instructions that upon execution on or across one or more processors cause the one or more processors to:

receive, from another client of the cloud computing environment, via the one or more programmatic interfaces, an indication that at least a pair of programs executed at a particular computing resource on behalf of the other client belong to a trusted group of programs, wherein the particular computing resource includes an operating system;

propagate, to the operating system, information about the trusted group of programs; and

allocate, by the operating system, based at least in part on the information about the trusted group of programs, a first hardware thread of a first processor of the particular computing resource to execute a first instruction stream of a particular program.

12. The system as recited in claim 11 , wherein the particular program belongs to the trusted group of programs, and wherein the first hardware thread is allocated based at least in part on determining that a second instruction stream of a program of the trusted group of programs is running at a second hardware thread of the first processor.

13. The system as recited in claim 11 , wherein the particular program does not belong to the trusted group of programs, and wherein the first hardware thread is allocated based at least in part on determining that a second instruction stream of a program of the trusted group of programs is not running at any of the hardware threads of the first processor.

14. The system as recited in claim 11 , wherein the particular computing resource comprises a non-virtualized host.

15. One or more non-transitory computer-accessible storage media storing program instructions that when executed on or across one or more processors:

receive, from a client of a cloud computing environment via one or more programmatic interfaces, an indication that at least a pair of compute instances established on behalf of the client at the cloud computing environment belong to a trusted group of compute instances;

propagate, to one or more hypervisors of respective virtualization hosts of the cloud computing environment, information about the trusted group of compute instances;

execute a hypervisor of the one or more hypervisors on a virtualization host of the respective virtualization hosts, wherein the virtualization host includes a set of processors that implement simultaneous multi-threading (SMT), wherein the hypervisor controls allocation of hardware threads on the set of processors to execute instruction streams of compute instances; and

execute, on the virtualization host, a set of hardware threads on the set or processors allocated to a set of instruction streams of a set of compute instances, including a particular hardware thread of a processor allocated to a first instruction stream of a particular compute instance, wherein the allocations are made based at least in part on the information about the trusted group of compute instances so that trusted compute instances in the trusted group are executed on one or more processors different from one or more processors used to execute untrusted compute instances not in the trusted group, wherein the allocations mitigate one or more co-execution security vulnerabilities associated with execution of the untrusted compute instances and trusted compute instances on a same processor of the virtualization host.

16. The one or more non-transitory computer-accessible storage media as recited in claim 15 , wherein the particular compute instance belongs to the trusted group of compute instances, and wherein the particular hardware thread is allocated based at least in part on determining that a second instruction stream of a compute instance of the trusted group of compute instances is running at another hardware thread of the processor.

17. The one or more non-transitory computer-accessible storage media as recited in claim 15 , wherein the particular compute instance does not belong to the trusted group of compute instances, and wherein the particular hardware thread is allocated based at least in part on determining that a second instruction stream of a compute instance of the trusted group of compute instances is not running at any of the hardware threads of the processor.

18. The one or more non-transitory computer-accessible storage media as recited in claim 15 , storing further program instructions that when executed on or across the one or more processors:

receive, from another client of the cloud computing environment, via the one or more programmatic interfaces, an indication that at least a pair of programs executed at a particular computing resource on behalf of the other client belong to a trusted group of programs, wherein the particular computing resource includes an operating system;

propagate, to the operating system, information about the trusted group of programs; and

allocate, by the operating system, based at least in part on the information about the trusted group of programs, a first hardware thread of a first processor of the particular computing resource to execute a first instruction stream of a particular program.

19. The one or more non-transitory computer-accessible storage media as recited in claim 18 , wherein the particular program belongs to the trusted group of programs, and wherein the first hardware thread is allocated based at least in part on determining that a second instruction stream of a program of the trusted group of programs is running at a second hardware thread of the first processor.

20. The one or more non-transitory computer-accessible storage media as recited in claim 18 , wherein the particular program does not belong to the trusted group of programs, and wherein the first hardware thread is allocated based at least in part on determining that a second instruction stream of a program of the trusted group of programs is not running at any of the hardware threads of the first processor.

Continuity (2)
Continuation 16552772 · Aug 27, 2019
Related Publication 20230409321A1 · Dec 21, 2023
References Cited (73)
US 6658447B2 · Cota-Robles · 2003 [cited by applicant]
US 7493436B2 · Blackmore et al. · 2009 [cited by applicant]
US 7698707B2 · Accapadi et al. · 2010 [cited by applicant]
US 7992156B1 · Wang · 2011 [cited by applicant]
US 8136111B2 · Mall et al. · 2012 [cited by applicant]
US 8145797B2 · Floyd · 2012 [cited by applicant]
US 9323552B1 · Adogla · 2016 [cited by examiner]
US 9507540B1 · Adogla · 2016 [cited by examiner]
US 9785557B1 · Frey et al. · 2017 [cited by applicant]
US 11669441B1 · Adogla · 2023 [cited by examiner]
US 20030033510A1 · Dice · 2003 [cited by applicant]
US 20040215932A1 · Burky et al. · 2004 [cited by applicant]
US 20040268325A1 · Moore · 2004 [cited by applicant]
US 20050015702A1 · Shier · 2005 [cited by applicant]
US 20060041735A1 · Hepkin · 2006 [cited by applicant]
US 20080133842A1 · Raikin et al. · 2008 [cited by applicant]
US 20080155536A1 · Levit-Gurevich · 2008 [cited by examiner]
US 20080184240A1 · Franaszek · 2008 [cited by applicant]
US 20080313417A1 · Kim · 2008 [cited by applicant]
US 20100082867A1 · Adachi · 2010 [cited by applicant]
US 20100100934A1 · Mejdrich · 2010 [cited by examiner]
US 20110219447A1 · Horovitz · 2011 [cited by examiner]
US 20110296421A1 · Gschwind et al. · 2011 [cited by applicant]
US 20120222035A1 · Plondke · 2012 [cited by applicant]
US 20130263129A1 · Adachi · 2013 [cited by examiner]
US 20130332778A1 · Spracklen · 2013 [cited by examiner]
US 20140026138A1 · Itou · 2014 [cited by applicant]
US 20140047201A1 · Mehta · 2014 [cited by examiner]
US 20140259117A1 · Wachendorf · 2014 [cited by examiner]
US 20150013008A1 · Lukacs · 2015 [cited by applicant]
US 20150022538A1 · Munshi · 2015 [cited by applicant]
US 20150143055A1 · Guthrie · 2015 [cited by examiner]
US 20150169350A1 · Anand · 2015 [cited by examiner]
US 20150178219A1 · Aslot · 2015 [cited by applicant]
US 20160224509A1 · Moudgill et al. · 2016 [cited by applicant]
US 20160267000A1 · Rose et al. · 2016 [cited by applicant]
US 20160283237A1 · Pardo et al. · 2016 [cited by applicant]
US 20160371123A1 · Zhang et al. · 2016 [cited by applicant]
US 20170093669A1 · Nortman · 2017 [cited by examiner]
US 20170109189A1 · Swidowski et al. · 2017 [cited by applicant]
US 20170177397A1 · Gao · 2017 [cited by examiner]
US 20170212811A1 · Kashnikov · 2017 [cited by applicant]
US 20180011711A1 · Ray et al. · 2018 [cited by applicant]
US 20180137136A1 · Altaparmakov et al. · 2018 [cited by applicant]
US 20180268156A1 · Luo · 2018 [cited by examiner]
US 20180285106A1 · Appu et al. · 2018 [cited by applicant]
US 20180287949A1 · Kumar et al. · 2018 [cited by applicant]
US 20190138720A1 · Grewal et al. · 2019 [cited by applicant]
US 20190196982A1 · Rozas et al. · 2019 [cited by applicant]
US 20200133873A1 · Williams · 2020 [cited by applicant]
US 20200150960A1 · Williams et al. · 2020 [cited by applicant]
US 20200174931A1 · Williams et al. · 2020 [cited by applicant]
US 20200183696A1 · Williams et al. · 2020 [cited by applicant]
US 20200183843A1 · Williams et al. · 2020 [cited by applicant]
US 20200201780A1 · Williams et al. · 2020 [cited by applicant]
US 20200201786A1 · Ouziel · 2020 [cited by applicant]
US 20200301735A1 · Accapadi · 2020 [cited by applicant]
US 20200327367A1 · Ma et al. · 2020 [cited by applicant]
US 20200356409A1 · Williams et al. · 2020 [cited by applicant]
US 20200364375A1 · Bottomley et al. · 2020 [cited by applicant]
US 20200409771A1 · Williams et al. · 2020 [cited by applicant]
Unknown, “Cache speulation Side-Channels”, Whitepaper, Retrieved from https://developer.arm.com/documentation/102816/0205/, dated Jun. 2020, version 2.5, pp. 1-21. [cited by applicant]
Changhee Jung, et al., Adaptive execution techniques for SMT multiprocessor architectures:, PPoPP'05, ACM, Jun. 15-17, 2005, pp. 236-246. [cited by applicant]
Nael Abu-Ghazaleh, et al., “How the Spectre and Meltdown Hacks Really Worked”, Retrieved from https://spectrum.ieee.org/computing/hardware/how-the-spectre-and-meltdown-hacks-really-worked on Jun. 3, 2019, pp. 1-18. [cited by applicant]
Microsoft Tech Community, Hyper-V HyperClear Mitigation for L1 Terminal Fault, Retrieved from https://techcommunity.microsoft.com/t5/Virtualization/Hyper-V-HyperClear-Mitigation-for-L1-Terminal-Fault/ba-p/382429 on Jun.… [cited by applicant]
Deborah T. Marr, et al., “Hyper-Threading Technology Architecture and Microarchitecture”, Intel Technology Journal Q1, 2002, pp. 1-12. [cited by applicant]
Alexander Chartre, KVM Address Space Isolation, Retrieved from https://lwn.net/Articles/788273/ on Jun. 21, 2019, pp. 1-6. [cited by applicant]
Andy Greenberg, “Meltdown Redux: Intel Flaw Lets Siphon Secrets From Millions of PCS”, Retrieved from https://www.wired.com/story/intel-mds-attack-speculative-execution-buffer/ on Jun. 3, 2019, pp. 1-20. [cited by applicant]
Microsoft, “Protect your Windows devices against speculative execution side-channel attacks”, Retrieved from https://support.microsoft.com/en-us/help/4073757/protect-windows-devices-from-speculative-execution-side-chann… [cited by applicant]
Jochen Liedtke, et al., “Lazy Process Switching”, Proceedings Eighth Workshop on Hot Topics in Operating Systems, IEEE, 2001, pp. 13-16. [cited by applicant]
Alexandre Chartre, “LKML: Kernel Address Space Isolation”, Retrieved from https://lkml.org/lkml/2019/7/11/351 on Jul. 20, 2019, pp. 1-5. [cited by applicant]
U.S. Appl. No. 17/936,783, filed Sep. 29, 2022, Nathan Yong Seng Chong, et al. [cited by applicant]
U.S. Appl. No. 16/552,772, filed Aug. 27, 2019, Amit Shah et al. [cited by applicant]