IP Library Granted Patent US 12,373,217
Granted Patent B2
US 12,373,217 · App. 17/932,883 · Granted Jul 29, 2025

Indirect branch predictor storing encrypted branch information fields

Inventors: Jeffry E. Gonion (Campbell, CA); Ian D. Kountanis (Santa Clara, CA); Conrado Blasco (Sunnyvale, CA); Steven Andrew Myers (San Jose, CA); Yannick L. Sierra (San Francisco, CA)
Assignee: Apple Inc.
G06F9/3844G06F9/30029G06F9/3861G06F9/45533G06F21/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,217
App. No.
17/932,883
Granted
Jul 29, 2025
Kind
B2
Abstract

A system and method for efficiently protecting branch prediction information. In various embodiments, a computing system includes at least one processor with a branch predictor storing branch target addresses and security tags in a table. The security tag includes one or more components of machine context. When the branch predictor receives a portion of a first program counter of a first branch instruction, and hits on a first table entry during an access, the branch predictor reads out a first security tag. The branch predictor compares one or more components of machine context of the first security tag to one or more components of machine context of the first branch instruction. When there is at least one mismatch, the branch prediction information of the first table entry is not used. Additionally, there is no updating of any branch prediction training information of the first table entry.

Claims (40)

1. An apparatus, comprising:

a table comprising circuitry, wherein the table comprises a plurality of table entries configured to store branch prediction information; and

branch prediction circuitry configured to:

generate an encrypted value, based at least in part on a program counter corresponding to a branch instruction;

combine, using encryption circuitry, the encrypted value with a branch target address of the branch instruction to generate an encrypted branch target address; and

store the encrypted branch target address in an entry of the table.

2. The apparatus as recited in claim 1 , wherein the branch prediction circuitry is configured to store machine context information corresponding to the branch instruction in the entry.

3. The apparatus as recited in claim 2 , wherein the branch prediction circuitry is configured to store the machine context information as a security tag in a security tag field of the entry.

4. The apparatus as recited in claim 2 , wherein the branch prediction circuitry is further configured generate the machine context information based at least in part on one or more of an exception level, virtual machine identifier, privilege mode, process identifier, and a program counter.

5. The apparatus as recited in claim 2 , wherein the branch prediction circuitry is configured to:

detect a hit on the entry in the table, responsive to a first branch instruction; and

prevent use of branch prediction information in the entry by the first branch instruction, responsive to a mismatch between at least a portion of a machine context of the first branch instruction and machine context information stored in the entry.

6. The apparatus as recited in claim 5 , wherein the apparatus is configured to generate an exception responsive to the mismatch.

7. The apparatus as recited in claim 5 , wherein the branch prediction circuitry is configured to allow use of the branch prediction information in the entry by the first branch instruction, responsive to a match between the machine context of the first branch instruction and the machine context information stored in the entry.

8. The apparatus as recited in claim 7 , wherein the branch prediction circuitry is configured to update branch prediction training information stored in the entry, responsive to the match between the machine context of the first branch instruction and the machine context information stored in the entry.

9. A method, comprising:

generating an encrypted value, based at least in part on a program counter corresponding to a branch instruction;

combining the encrypted value with a branch target address of the branch instruction to generate an encrypted branch target address; and

storing the encrypted branch target address in an entry of a table.

10. The method as recited in claim 9 , further comprising storing machine context information corresponding to the branch instruction in the entry.

11. The method as recited in claim 10 , further comprising storing the machine context information as a security tag in a security tag field of the entry.

12. The method as recited in claim 10 , further comprising generating the machine context information based at least in part on one or more of an exception level, virtual machine identifier, privilege mode, process identifier, and a program counter.

13. The method as recited in claim 10 , further comprising:

detecting a hit on the entry in the table, responsive to a first branch instruction; and

preventing use of branch prediction information in the entry by the first branch instruction, responsive to a mismatch between at least a portion of a machine context of the first branch instruction and machine context information stored in the entry.

14. The method as recited in claim 13 , further comprising generating an exception responsive to the mismatch.

15. The method as recited in claim 13 , further comprising allowing use of the branch prediction information in the entry by the first branch instruction, responsive to a match between the machine context of the first branch instruction and the machine context information stored in the entry.

16. The method as recited in claim 15 , further comprising updating branch prediction training information stored in the entry, responsive to the match between the machine context of the first branch instruction and the machine context information stored in the entry.

17. A processor, comprising:

instruction fetch circuitry configured to fetch instructions for execution;

execution circuitry configured to execute instructions fetched by the instruction fetch circuitry; and

branch prediction circuitry configured to:

generate an encrypted value, based at least in part on a program counter corresponding to a branch instruction;

combine, using encryption circuitry, the encrypted value with a branch target address of the branch instruction to generate an encrypted branch target address; and

store the encrypted branch target address in an entry of a table.

18. The processor as recited in claim 17 , wherein the branch prediction circuitry is configured to store machine context information corresponding to the branch instruction in the entry.

19. The processor as recited in claim 18 , wherein the branch prediction circuitry is configured to:

detect a hit on the entry in the table, responsive to a first branch instruction; and

prevent use of branch prediction information in the entry by the first branch instruction, responsive to a mismatch between at least a portion of a machine context of the first branch instruction and machine context information stored in the entry.

20. The processor as recited in claim 19 , wherein the branch prediction circuitry is configured to allow use of the branch prediction information in the entry by the first branch instruction, responsive to a match between the machine context of the first branch instruction and the machine context information stored in the entry.

Continuity (2)
Continuation 16220488 · Dec 14, 2018
Related Publication 20230010948A1 · Jan 12, 2023
References Cited (14)
US 5935241A · Shiell et al. · 1999 [cited by applicant]
US 6212629B1 · McFarland et al. · 2001 [cited by applicant]
US 8762694B1 · Zou et al. · 2014 [cited by applicant]
US 8955111B2 · Glew et al. · 2015 [cited by applicant]
US 10037288B2 · Guim et al. · 2018 [cited by applicant]
US 11449343B2 · Gonion et al. · 2022 [cited by applicant]
US 20150268957A1 · Bonanno et al. · 2015 [cited by applicant]
US 20180365015A1 · Lee et al. · 2018 [cited by applicant]
US 20190042263A1 · Sukhomlinov et al. · 2019 [cited by applicant]
US 20190163902A1 · Reid et al. · 2019 [cited by applicant]
US 20190166158A1 · Grocutt et al. · 2019 [cited by applicant]
US 20190227802A1 · Kessler · 2019 [cited by examiner]
US 20190303161A1 · Nassi · 2019 [cited by examiner]
US 20200057641A1 · Leenstra et al. · 2020 [cited by applicant]