IP Library › Granted Patent US 12,541,582
Granted Patent B2
US 12,541,582 · App. 18/167,744 · Granted Feb 3, 2026

Function call authentication for program flow control

Inventors: Miguel Cristian Young de la Sota (Cambridge, MA); Mehmet Alphan Ulusoy (Framingham, MA)
Assignee: Google LLC
G06F21/33G06F9/30101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,582
App. No.
18/167,744
Granted
Feb 3, 2026
Kind
B2
Abstract

This document discloses aspects of function call authorization for program flow control. In some aspects, a processor encounters a first instruction to initiate or call a function. The processor compares an immediate value of a second instruction at an entry point of the function to a function call authorization value stored in a register. In response to the immediate value of the second instruction matching the function call authorization value stored in the register the process transfers control flow to the function. Alternatively, if the values do not match, an exception or fault may be raised to halt execution of the function or other code. By so doing, these and other aspects of function call authorization may prevent fault injection attacks, execution of unauthorized instructions, or access to sensitive data.

Claims (55)

1 . A method comprising:

encountering a first instruction to call a function, the first instruction comprising a branch instruction or a jump instruction configured to call the function;

comparing an immediate value of a second instruction at an entry point of the function to a function call authorization value stored in a register, the second instruction comprising a landing pad instruction of the function, access to the register storing the function call authorization value limited to:

a first function call authorization instruction to set the function call authorization value;

a second function call authorization instruction to read the function call authorization value stored in the register; and

a third function call authorization instruction to clear the function call authorization value from the register; and

transferring control flow to the function in response to the immediate value of the second instruction matching the function call authorization value stored in the register.

2 . The method as recited in claim 1 , wherein function call authorization value comprises a function call authorization token stored in the register.

3 . The method as recited in claim 2 , wherein:

the register in which the function call authorization token comprises a register that is not part of the RISC a reduced instruction set computer (RISC) register file.

4 . The method as recited in claim 1 , wherein the function comprises a function that accesses sensitive information or operates on sensitive information.

5 . The method as recited in claim 1 , further comprising:

before encountering the first instruction to call the function, accessing the register to set the function call authorization value stored in the register.

6 . The method as recited in claim 1 , further comprising:

executing a first portion of code of the function;

comparing an immediate value of a third instruction at an intermediate point of the function to the function call authorization value stored in a register; and

executing a second portion of the code of the function in response to the immediate value of the third instruction matching the function call authorization value stored in the register; or

ceasing execution of the function in response to the immediate value of the third instruction not matching the function call authorization value stored in the register.

7 . The method as recited in claim 1 , further comprising:

obtaining a return address from the function from a call stack; and

returning from the function to the return address obtained from the call stack.

8 . The method as recited in claim 1 , further comprising:

prior to returning from the function, clearing the function call authorization value stored in the register.

9 . The method as recited in claim 1 , further comprising:

prior to executing code that includes the first instruction and the second instruction:

determining the immediate value for the second instruction, the immediate value associated with the function to enable function call authorization; and

adding, to code of the function, code of the second instruction that includes the immediate value.

10 . An integrated circuit comprising:

a register configured to store a function call authorization value, access to the register limited to a first function call authorization instruction to set the function call authorization value, a second function call authorization instruction to read the function call authorization value stored in the register, and a third function call authorization instruction to clear the function call authorization value from the register; and

a processor configured to execute instructions to implement a function call authorization code module, the function call authorization code module configured to:

encounter a first instruction to call a function, the first instruction comprising a branch instruction or a jump instruction configured to call the function;

compare an immediate value of a second instruction at an entry point of the function to the function call authorization value stored in the register, the second instruction comprising a landing pad instruction of the function; and

transfer control flow to the function in response to the immediate value of the second instruction matching the function call authorization value stored in the register.

11 . The integrated circuit as recited in claim 10 , wherein function call authorization value comprises a function call authorization token stored in the register.

12 . The integrated circuit as recited in claim 11 , wherein:

the register in which the function call authorization token comprises a register that is not part of a reduced instruction set computer (RISC) register file.

13 . The integrated circuit as recited in claim 10 , wherein the function comprises a function that accesses sensitive information or operates on sensitive information.

14 . The integrated circuit as recited in claim 10 , wherein the function call authorization code module is further configured to:

before encountering the first instruction to call the function, access the register to set the function call authorization value.

15 . An integrated circuit comprising:

a register configured to store a function call authorization token;

a hardware-based call stack; and

a processor configured to execute instructions to implement a function call authorization module, the function call authorization module configured to:

access the register to set the function call authorization token, access to the register limited to a first function call authorization instruction to set the function call authorization token, a second function call authorization instruction to read the function call authorization token stored in the register, and a third function call authorization instruction to clear the function call authorization token from the register;

encounter an instruction to call a function, the instruction comprising a branch instruction or a jump instruction configured to call the function;

compare an immediate value of a landing pad instruction at an entry point of the function to the function call authorization token stored in the register;

transfer control flow to the function in response to the immediate value of the landing pad instruction matching the function call authorization token stored in the register;

obtain a return address from the function from the hardware-based call stack; and

return from the function to the return address obtained from the hardware-based call stack.

16 . The integrated circuit as recited in claim 15 , wherein the landing pad instruction comprises an only entry point of the function and the processor is further configured to raise a fault responsive to an attempt to enter the function at any other point.

17 . The integrated circuit as recited in claim 15 , wherein the function call authorization module is further configured to:

prior to returning from the function, clearing the function call authorization token stored in the register.

18 . The integrated circuit as recited in claim 15 , further comprising a memory storing code of the function and multiple other functions and wherein the function and multiple other functions are each configured to use different respective function call authorization tokens.

19 . The integrated circuit as recited in claim 15 , the register configured to store a function call authorization token comprises a limited-access register that is not part of a reduced instruction set computer (RISC) register file.

20 . The integrated circuit as recited in claim 16 , wherein the function comprises a function that accesses sensitive information or operates on sensitive information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2023
From: YOUNG DE LA SOTA, MIGUEL CRISTIAN; ULUSOY, MEHMET ALPHAN
To: GOOGLE LLC
Reel/Frame 062676/0975 →
Continuity (2)
Provisional Application 63267965 · Feb 14, 2022
Related Publication 20230259603A1 · Aug 17, 2023
References Cited (54)
US 5923883A · Tanaka · 1999 [cited by examiner]
US 7284116B2 · Jourdan · 2007 [cited by examiner]
US 8712039B2 · Ebeid et al. · 2014 [cited by applicant]
US 8769637B2 · Janzen · 2014 [cited by applicant]
US 10911221B2 · Hutter et al. · 2021 [cited by applicant]
US 20020144236A1 · Beer et al. · 2002 [cited by applicant]
US 20040181684A1 · Hong et al. · 2004 [cited by applicant]
US 20060259744A1 · Matthes · 2006 [cited by examiner]
US 20080178010A1 · Vaterlaus et al. · 2008 [cited by applicant]
US 20080184016A1 · Erlingsson · 2008 [cited by examiner]
US 20090141887A1 · Yap et al. · 2009 [cited by applicant]
US 20090282393A1 · Costa et al. · 2009 [cited by applicant]
US 20100146624A1 · Meyer et al. · 2010 [cited by applicant]
US 20130159791A1 · Fabrice et al. · 2013 [cited by applicant]
US 20130166514A1 · Schultz · 2013 [cited by applicant]
US 20150113640A1 · Krten et al. · 2015 [cited by applicant]
US 20150186251A1 · Friedler et al. · 2015 [cited by applicant]
US 20170024559A1 · Hughes · 2017 [cited by examiner]
US 20180082057A1 · LeMay · 2018 [cited by examiner]
US 20210264020A1 · LeMay · 2021 [cited by examiner]
US 20220374415A1 · Boling · 2022 [cited by examiner]
US 20220414218A1 · Torvik · 2022 [cited by examiner]
US 20240422005A1 · Sukhomlinov et al. · 2024 [cited by applicant]
US 20250007948A1 · Sota et al. · 2025 [cited by applicant]
CN 110471924 · 2019 [cited by applicant]
CN 112632476 · 2021 [cited by applicant]
JP 2001282106A · 2001 [cited by applicant]
JP 2018088147A · 2018 [cited by applicant]
JP 2022541057A · 2022 [cited by applicant]
WO 2020076555A1 · 2020 [cited by applicant]
WO 2023063924 · 2023 [cited by applicant]
WO 2023091803 · 2023 [cited by applicant]
Abadi, et al., “Control-Flow Integrity—Principles, Implementations, and Applications”, Nov. 2005, 14 pages. [cited by applicant]
Amar, “An Armful of CHERIs”, Retrieved at: https://msrc-blog.microsoft.com/2022/01/20/an_armful_of_cheris/, Jan. 20, 2022, 10 pages. [cited by applicant]
“International Preliminary Report on Patentability”, Application No. PCT/US2021/054431, Apr. 16, 2024, 8 pages. [cited by applicant]
“International Preliminary Report on Patentability”, Application No. PCT/US2022/071360, May 2, 2024, 8 pages. [cited by applicant]
“International Search Report and Written Opinion”, Application No. PCT/US2021/054431, Jul. 1, 2022, 11 pages. [cited by applicant]
“International Search Report and Written Opinion”, Application No. PCT/US2022/071360, Jul. 27, 2022, 11 pages. [cited by applicant]
Almahdi, Ismail, “HMAC-SHA384-VHDL/ HMACSHA384_ISMAIL.vhd”, Retrieved at: https://github.com/ismailalmahdi/HMAC-SHA384-VHDL/blob/master/HMACSHA384ISMAIL.vhd—on Jun. 21, 2022, 10 pages. [cited by applicant]
Arias, Dan, “Hashing in Action: Understanding bcrypt”, Feb. 25, 2021, 19 pages. [cited by applicant]
Arnautov, et al., “ControlFreak: Signature Chaining to Counter Control Flow Attacks”, Sep. 28, 2015, 10 pages. [cited by applicant]
Aumasson, et al., “SPHINCS—Submission to the NIST post-quantum project, v.3 Contents”, Oct. 1, 2020, 62 pages. [cited by applicant]
Berthet, et al., “An Area-Efficient SPHINCS Post-Quantum Signature Coprocessor”, Jun. 17, 2021, pp. 180-187. [cited by applicant]
Bjoern, Kerler, “opencl_Brute/pbkdf2.cl”, Retrieved from https://github.com/KenChen-Xeniro/opencl_brute/blob/master/ Library/worker/generic/pbkdf2.cl—on Jun. 21, 2022, 5 pages. [cited by applicant]
De Clercq, et al., “A survey of Hardware-based Control Flow Integrity (CFI)”, Jul. 31, 2017, 27 pages. [cited by applicant]
De Clercq, et al., “SOFIA: Software and Control Flow Integrity Architecture”, Apr. 28, 2016, 6 pages. [cited by applicant]
Lalande, et al., “Software Countermeasures for Control Flow Integrity of Smart Card C Codes”, Jan. 1, 2014, pp. 200-217. [cited by applicant]
Werner, et al., “Protecting the Control Flow of Embedded Processors Against Fault Attacks”, Mar. 10, 2016, pp. 161-176. [cited by applicant]
“Foreign Office Action”, JP Application No. 2024-529608, May 7, 2025, 4 pages. [cited by applicant]
“Foreign Office Action”, JP Application No. 2024-520759, May 7, 2025, 7 pages. [cited by applicant]
“Foreign Office Action”, IN Application No. 202447039928, Jul. 25, 2025, 7 pages. [cited by applicant]
“Foreign Office Action”, JP Application No. 2024529608, Oct. 7, 2025, 4 pages. [cited by applicant]
“Foreign Office Action”, KR Application No. 10-2024-7017716, Nov. 24, 2025, 10 pages. [cited by applicant]
“Non-Final Office Action”, U.S. Appl. No. 18/711,527, filed Nov. 21, 2025, 9 pages. [cited by applicant]