IP Library › Granted Patent US 12,443,713
Granted Patent B2
US 12,443,713 · App. 18/595,244 · Granted Oct 14, 2025

Systems and methods for defending against side channel attacks to speculative execution of processor pipeline instructions

Inventors: Hithesh Hassan Lepaksha (Hyderabad, IN); Darshan Kumar Nandanwar (Bangalore, IN); Kartik Gunvantbhai Desai (Savarkundla, IN); Sagar Bamashetti (Chadchan, IN)
Assignee: QUALCOMM Incorporated
G06F21/566G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,713
App. No.
18/595,244
Granted
Oct 14, 2025
Kind
B2
Abstract

A method includes executing a first pointer authentication instruction, including a first pointer authentication code, on a pointer in a speculative path of a pipeline. The method also includes determining whether the first pointer authentication code for the pointer fails. The method further includes determining whether the first pointer authentication code for the pointer differs from a previous pointer authentication code for the pointer in response to the first pointer authentication code failing. The method still further includes incrementing a failure counter in response to determining that the first pointer authentication code for the pointer failed and that the first pointer authentication code for the pointer differs from the previous pointer authentication code for the pointer. The method additionally includes determining whether the failure counter is greater than a threshold value and performing a defensive action in response to the failure counter being greater than the threshold value.

Claims (49)

1. A method, comprising:

executing a first pointer authentication instruction on a pointer in a speculative path of a pipeline, the first pointer authentication instruction including a first pointer authentication code;

determining whether the first pointer authentication code for the pointer fails;

determining whether the first pointer authentication code for the pointer differs from a previous pointer authentication code for the pointer in response to the first pointer authentication code failing;

incrementing a failure counter in response to determining that the first pointer authentication code for the pointer failed and that the first pointer authentication code for the pointer differs from the previous pointer authentication code for the pointer;

determining whether the failure counter is greater than a threshold value; and

performing a defensive action in response to the failure counter being greater than the threshold value.

2. The method of claim 1 , in which the defensive action comprises delaying execution of the pipeline by an amount of time corresponding to a failed pointer authentication in response to the failure counter having a first value that is lower than a second value.

3. The method of claim 1 , in which the defensive action comprises:

performing, in response to the failure counter having a second value that is higher than a first value, an instruction not associated with the pointer over a period of time that corresponds to a successful pointer authentication, the instruction producing a result; and

discarding the result without committing the result to a data cache.

4. The method of claim 3 , in which the defensive action further comprises discarding all instruction data loaded in the pipeline.

5. The method of claim 1 , in which the defensive action comprises:

increasing a response latency between the pipeline and a cache; and

refusing a further pointer authentication via the speculative path in response to the failure counter having a third value that is higher than a second value and a first value.

6. The method of claim 1 , further comprising setting the failure counter to zero when the first pointer authentication code was successful.

7. The method of claim 1 , in which the threshold value is based on a quantity of failed pointer authentications in a specified period of time.

8. An apparatus, comprising:

at least one memory; and

at least one processor coupled to the at least one memory, the at least one processor configured to:

execute a first pointer authentication instruction on a pointer in a speculative path of a pipeline, the first pointer authentication instruction including a first pointer authentication code;

determine whether the first pointer authentication code for the pointer fails;

determine whether the first pointer authentication code for the pointer differs from a previous pointer authentication code for the pointer in response to the first pointer authentication code failing;

increment a failure counter in response to determining that the first pointer authentication code for the pointer failed and that the first pointer authentication code for the pointer differs from the previous pointer authentication code for the pointer;

determine whether the failure counter is greater than a threshold value; and

perform a defensive action in response to the failure counter being greater than the threshold value.

9. The apparatus of claim 8 , in which the at least one processor is configured to perform the defensive action by delaying execution of the pipeline by an amount of time corresponding to a failed pointer authentication in response to the failure counter having a first value that is lower than a second value.

10. The apparatus of claim 8 , in which the at least one processor is configured to perform the defensive action by performing, in response to the failure counter having a second value that is higher than a first value, an instruction not associated with the pointer over a period of time that corresponds to a successful pointer authentication, the instruction producing a result; and discarding the result without committing the result to a data cache.

11. The apparatus of claim 10 , in which the at least one processor is configured to perform the defensive action by discarding all instruction data loaded in the pipeline.

12. The apparatus of claim 8 , in which the at least one processor is configured to perform the defensive action by increasing a response latency between the pipeline and a cache; and refusing a further pointer authentication via the speculative path in response to the failure counter having a third value that is higher than a second value and a first value.

13. The apparatus of claim 8 , in which the at least one processor is further configured to set the failure counter to zero when the first pointer authentication code was successful.

14. The apparatus of claim 8 , in which the threshold value is based on a quantity of failed pointer authentications in a specified period of time.

15. An apparatus, comprising;

means for executing a first pointer authentication instruction on a pointer in a speculative path of a pipeline, the first pointer authentication instruction including a first pointer authentication code;

means for determining whether the first pointer authentication code for the pointer fails;

means for determining whether the first pointer authentication code for the pointer differs from a previous pointer authentication code for the pointer in response to the first pointer authentication code failing;

means for incrementing a failure counter in response to determining that the first pointer authentication code for the pointer failed and that the first pointer authentication code for the pointer differs from the previous pointer authentication code for the pointer;

means for determining whether the failure counter is greater than a threshold value; and

means for performing a defensive action in response to the failure counter being greater than the threshold value.

16. The apparatus of claim 15 , in which the means for performing the defensive action comprises means for delaying execution of the pipeline by an amount of time corresponding to a failed pointer authentication in response to the failure counter having a first value that is lower than a second value.

17. The apparatus of claim 15 , in which the means for performing the defensive action comprises:

means for performing, in response to the failure counter having a second value that is higher than a first value, an instruction not associated with the pointer over a period of time that corresponds to a successful pointer authentication, the instruction producing a result;

means for discarding the result without committing the result to a data cache; and

means for discarding all instruction data loaded in the pipeline.

18. The apparatus of claim 15 , in which the means for performing the defensive action comprises:

means for increasing a response latency between the pipeline and a cache; and

means for refusing a further pointer authentication via the speculative path in response to the failure counter having a third value that is higher than a second value and a first value.

19. The apparatus of claim 15 , further comprising means for setting the failure counter to zero when the first pointer authentication code was successful.

20. The apparatus of claim 15 , in which the threshold value is based on a quantity of failed pointer authentications in a specified period of time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2024
From: LEPAKSHA, HITHESH HASSAN; NANDANWAR, DARSHAN KUMAR; DESAI, KARTIK GUNVANTBHAI; BAMASHETTI, SAGAR
To: QUALCOMM INCORPORATED
Reel/Frame 066813/0771 →
Continuity (1)
Related Publication 20250278489A1 · Sep 4, 2025
References Cited (11)
US 6081887A · Steely, Jr. · 2000 [cited by examiner]
US 9177153B1 · Perrig · 2015 [cited by examiner]
US 10409600B1 · Sierra · 2019 [cited by examiner]
US 20020073301A1 · Kahle · 2002 [cited by examiner]
US 20180107823A1 · Samadani · 2018 [cited by examiner]
US 20200073669A1 · Clouqueur · 2020 [cited by examiner]
US 20200082070A1 · Semeria · 2020 [cited by examiner]
US 20240086526A1 · Iles · 2024 [cited by examiner]
US 20250094567A1 · Pape · 2025 [cited by examiner]
WO WO2025124522A1 · 2025 [cited by examiner]
Carlson, Trevor “A Next-Generation Side-Channel Detector for General-Purpose Processors”, Department of Computer Science, National University of Singapore, p. 1-2 (Year: 2023). [cited by examiner]