IP Library Granted Patent US 12,547,724
Granted Patent B2
US 12,547,724 · App. 17/965,953 · Granted Feb 10, 2026

Firmware guard extension with converged defense engine

Inventor: Shekar Babu Suryanarayana (Bangalore, IN)
Assignee: DELL PRODUCTS L.P.
G06F21/572G06F21/54G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,724
App. No.
17/965,953
Granted
Feb 10, 2026
Kind
B2
Abstract

A system for data protection, comprising an address mapping state machine configured to receive address data and protection data and to generate runtime address data, a firmware extension table coupled to a plurality of adders that are configured to receive data derived from the runtime address data and to output mapped runtime address data and a plurality of external components configured to receive the mapped runtime address data and to utilize the mapped runtime address data for one or more predetermined functions.

Claims (48)

1 . A method for data protection, comprising:

receiving address data and protection data at a dynamic address map enclave [DAME] state machine;

generating runtime address data;

receiving data derived from the runtime address data at a firmware extension table coupled to a plurality of adders;

outputting mapped runtime address data;

receiving the mapped runtime address data at a plurality of external components;

utilizing the mapped runtime address data for one or more predetermined functions; and

remapping a converged defense engine domain memory with pre-map offsets during OS boot to OS runtime memory.

2 . The method of claim 1 further comprising generating memory domain protection type data for use with the runtime address data.

3 . The method of claim 1 further comprising generating isolation policy data for use with the runtime address data.

4 . The method of claim 1 further comprising generating an output to an isolation map.

5 . The method of claim 1 further comprising providing isolation map data to the mapped runtime address data.

6 . The method of claim 1 further comprising:

generating an output to an isolation map; and

providing isolation map data to the mapped runtime address data as a function of an output from an associative set metadata system.

7 . The method of claim 1 further comprising generating indexed address data.

8 . The method of claim 1 further comprising receiving an event queue entry and mapping the event queue entry to a vulnerability.

9 . The method of claim 1 further comprising processing entries for a queue entry mapping to an address range of an index table.

10 . A system for data protection comprising:

one or more processors having code stored in a working memory that cause the one or more processors, when executed, to perform functions of:

receiving address data and protection data at a dynamic address map enclave [DAME] state machine;

generating runtime address data;

receiving data derived from the runtime address data at a firmware extension table coupled to a plurality of adders;

outputting mapped runtime address data;

receiving the mapped runtime address data at a plurality of external components;

utilizing the mapped runtime address data for one or more predetermined functions; and

remapping a converged defense engine domain memory with pre-map offsets during OS boot to OS runtime memory.

11 . The system of claim 10 wherein the code causes the one or more processors to perform the function of generating memory domain protection type data for use with the runtime address data.

12 . The system of claim 10 wherein the code causes the one or more processors to perform the function of generating isolation policy data for use with the runtime address data.

13 . The system of claim 10 wherein the code causes the one or more processors to perform the function of generating an output to an isolation map.

14 . The system of claim 10 wherein the code causes the one or more processors to perform the function of providing isolation map data to the mapped runtime address data.

15 . The system of claim 10 wherein the code causes the one or more processors to perform the function of:

generating an output to an isolation map; and

providing isolation map data to the mapped runtime address data as a function of an output from an associative set metadata system.

16 . The system of claim 10 wherein the code causes the one or more processors to perform the function of generating indexed address data.

17 . The system of claim 10 wherein the code causes the one or more processors to perform the function of receiving an event queue entry and mapping the event queue entry to a vulnerability.

18 . The system of claim 10 wherein the code causes the one or more processors to perform the function of processing entries for a queue entry mapping to an address range of an index table.

19 . A method for data protection, comprising:

receiving address data and protection data at a dynamic address map enclave [DAME] state machine;

generating runtime address data;

receiving data derived from the runtime address data at a firmware extension table coupled to a plurality of adders;

outputting mapped runtime address data;

receiving the mapped runtime address data at a plurality of external components;

utilizing the mapped runtime address data for one or more predetermined functions;

remapping a converged defense engine domain memory with pre-map offsets during OS boot to OS runtime memory;

generating isolation policy data for use with the runtime address data; and

generating an output to an isolation map.

20 . The method of claim 19 further comprising providing isolation map data to the mapped runtime address data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2022
From: SURYANARAYANA, SHEKAR BABU
To: DELL PRODUCTS L.P.
Reel/Frame 061424/0393 →
Continuity (1)
Related Publication 20240126884A1 · Apr 18, 2024
References Cited (19)
US 9679143B2 · Desai · 2017 [cited by examiner]
US 9886833B2 · Noland et al. · 2018 [cited by applicant]
US 10516533B2 · Mannan et al. · 2019 [cited by applicant]
US 10856127B2 · Maier et al. · 2020 [cited by applicant]
US 10917439B2 · Purathepparambil et al. · 2021 [cited by applicant]
US 11472552B2 · Gil et al. · 2022 [cited by applicant]
US 20050094654A1 · Weisler · 2005 [cited by examiner]
US 20130282906A1 · An · 2013 [cited by examiner]
US 20140033268A1 · Julisch · 2014 [cited by examiner]
US 20140115292A1 · Mclachlan · 2014 [cited by examiner]
US 20140237545A1 · Mylavarapu · 2014 [cited by examiner]
US 20140281458A1 · Ravimohan · 2014 [cited by examiner]
US 20190122172A1 · Gil et al. · 2019 [cited by applicant]
US 20200294401A1 · Kerecsen · 2020 [cited by applicant]
US 20200358872A1 · Shribman et al. · 2020 [cited by applicant]
US 20200389469A1 · Litichever et al. · 2020 [cited by applicant]
US 20210356279A1 · Szigeti · 2021 [cited by applicant]
US 20220108007A1 · Zatutschne-Marom · 2022 [cited by examiner]
WO WO2012018525A2 · 2012 [cited by examiner]