IP Library › Granted Patent US 12,299,447
Granted Patent B2
US 12,299,447 · App. 18/484,582 · Granted May 13, 2025

Hardware verification of dynamically generated code

Inventors: Jeffrey E. Gonion (Campbell, CA); Michael D. Snyder (Cedar Park, TX); Filip J. Pizlo (Capitola, CA)
Assignee: Apple Inc.
G06F9/30054G06F9/323G06F9/45516G06F21/53H04L9/0894G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,447
App. No.
18/484,582
Granted
May 13, 2025
Kind
B2
Abstract

In an embodiment, dynamically-generated code may be supported in the system by ensuring that the code either remains executing within a predefined region of memory or exits to one of a set of valid exit addresses. Software embodiments are described in which the dynamically-generated code is scanned prior to permitting execution of the dynamically-generated code to ensure that various criteria are met including exclusion of certain disallowed instructions and control of branch target addresses. Hardware embodiments are described in which the dynamically-generated code is permitted to executed but is monitored to ensure that the execution criteria are met.

Claims (35)

1. A method, comprising:

monitoring, by a monitor circuit of a computer system, a dynamically-generated code sequence being executed in the computer system to ensure that the dynamically-generated code sequence meets one or more execution criteria, wherein the one or more execution criteria specify that a branch target that is outside an execution region of a memory storing the dynamically-generated code sequence is permitted when the branch target is within one of one or more predefined address ranges outside of the execution region;

detecting, by the monitor circuit, a violation of the one or more execution criteria; and

forcing, by the monitor circuit, an exception based on detecting the violation.

2. The method of claim 1 , wherein a set of cryptographic keys is provided to the dynamically-generated code sequence to cryptographically sign one or more target addresses into the dynamically-generated code sequence from an external source.

3. The method of claim 1 , wherein a pair of address ranges adjacent to an address range that corresponds to the execution region are inaccessible to instructions in the dynamically-generated code sequence to prevent direct branch instructions from exiting the execution region.

4. The method of claim 3 , wherein a size of a given address range of the pair of address ranges is based on an extent that is reachable with a given direct branch instruction within the execution region.

5. The method of claim 1 , wherein the one or more execution criteria specify that dynamically-generated code sequences are prohibited from including an unauthenticated indirect branch instruction.

6. The method of claim 1 , wherein the one or more execution criteria include a requirement that a branch target that is outside the execution region is signed with a key that is not accessible to the dynamically-generated code sequence.

7. The method of claim 1 , wherein the execution region is defined by one or more registers of the computer system that are programmable.

8. A processor, comprising:

one or more registers programmable to define an execution region in a memory, wherein dynamically-generated code is stored in the execution region during use; and

a monitor circuit coupled to the one or more registers and configured to:

monitor a dynamically-generated code sequence that is being executed in the processor to ensure that the dynamically-generated code sequence meets one or more execution criteria, wherein the one or more execution criteria specify that a branch target that is outside the execution region is permitted when the branch target is within a predefined address range outside of the execution region; and

cause an exception in the processor based on a detection of a first particular violation of the one or more execution criteria.

9. The processor of claim 8 , wherein the monitor circuit is configured to:

based on a detection of a second particular violation of the one or more execution criteria that pertains to signing a particular pointer, modify an execution of a sign instruction associated with the second particular violation.

10. The processor of claim 8 , wherein the monitor circuit is configured to:

detect an attempt by the dynamically-generated code sequence to access an address within a pair of address ranges adjacent to an address range corresponding to the execution region; and

prevent the access by causing an exception in the processor.

11. The processor of claim 10 , wherein a size of a given address range of the pair of address ranges is based on an extent that is reachable with a direct branch instruction within the execution region.

12. The processor of claim 8 , wherein the one or more execution criteria specify that none of a set of prohibited instructions is present in the dynamically-generated code sequence.

13. The processor of claim 8 , wherein the one or more execution criteria include a requirement that a branch target that is outside the execution region is signed with a key that is not accessible to the dynamically-generated code sequence.

14. The processor of claim 8 , wherein the monitor circuit is configured to:

evaluate a program counter of the processor to determine when the dynamically-generated code sequence is being executed in the processor to ensure that the dynamically-generated code sequence meets one or more execution criteria.

15. A computer system, comprising:

a memory system, wherein a dynamic code execution region is defined in an address range within the memory system, and wherein dynamically-generated code is stored in the dynamic code execution region during use; and

at least one processor that is coupled to the memory system and configured to:

monitor a dynamically-generated code sequence being executed in the computer system to ensure that the dynamically-generated code sequence meets one or more execution criteria, wherein the one or more execution criteria specify that a branch target that is outside the dynamic code execution region is permitted when the branch target is within a predefined address range outside of the dynamic code execution region; and

take an exception based on a detection of a violation of the one or more execution criteria.

16. The computer system of claim 15 , wherein the at least one processor is configured to provide a set of cryptographic keys to the dynamically-generated code sequence to cryptographically sign one or more target addresses into the dynamically-generated code sequence from an external source.

17. The computer system of claim 15 , wherein the at least one processor is configured to enforce the one or more execution criteria on code based on a detection that execution of the code is occurring within the dynamic code execution region.

18. The computer system of claim 15 , wherein the at least one processor is configured to detect an attempt to access within a pair of address ranges adjacent to an address range corresponding to the dynamic code execution region and to prevent the access by taking an exception, and wherein a size of a given address range of the pair of address ranges is based on an extent that is reachable with a direct branch instruction within the dynamic code execution region.

19. The computer system of claim 15 , wherein the one or more execution criteria specify that a branch target that is outside the dynamic code execution region is cryptographically signed with one of a set of one or more cryptographic keys.

20. The computer system of claim 15 , wherein the one or more execution criteria specify that dynamically-generated code sequences are prohibited from including illegal instruction encodings.

Continuity (3)
Continuation 17348565 · Jun 15, 2021
Provisional Application 63108148 · Oct 30, 2020
Related Publication 20240045678A1 · Feb 8, 2024
References Cited (26)
US 8151349B1 · Yee et al. · 2012 [cited by applicant]
US 8850574B1 · Ansel et al. · 2014 [cited by applicant]
US 9390260B2 · Tan et al. · 2016 [cited by applicant]
US 10409600B1 · Sierra et al. · 2019 [cited by applicant]
US 10579806B1 · Pyo et al. · 2020 [cited by applicant]
US 10810305B2 · Zhang et al. · 2020 [cited by applicant]
US 20040250105A1 · Molnar · 2004 [cited by applicant]
US 20050273605A1 · Saha et al. · 2005 [cited by applicant]
US 20090282477A1 · Chen et al. · 2009 [cited by applicant]
US 20110138474A1 · Yee · 2011 [cited by examiner]
US 20120042145A1 · Sehr et al. · 2012 [cited by applicant]
US 20140325239A1 · Ghose · 2014 [cited by applicant]
US 20150007142A1 · Biffle et al. · 2015 [cited by applicant]
US 20170161498A1 · Yavo · 2017 [cited by applicant]
US 20180253549A1 · Yavo · 2018 [cited by applicant]
US 20190102540A1 · Acar et al. · 2019 [cited by applicant]
US 20210203504A1 · Brandt · 2021 [cited by applicant]
CN 104318135B · 2017 [cited by applicant]
CN 107506644A · 2017 [cited by applicant]
CN 111095249A · 2020 [cited by applicant]
WO 2016165446A1 · 2016 [cited by applicant]
WO 202096639A1 · 2020 [cited by applicant]
U.S. Appl. No. 17/348,576, Pizlo et al., filed Jun. 15, 2021. [cited by applicant]
ISRWO, PCT/US2021/057172, mailed Feb. 18, 2022, 11 pages. [cited by applicant]
Office Action from U.S. Appl. No. 13/348,576 mailed Sep. 28, 2022, 7 pages. [cited by applicant]
Notice of Allowance in Chinese Appl. No. 202180073713.9 mailed May 8, 2024, 6 pages. [cited by applicant]