IP Library › Granted Patent US 12,619,556
Granted Patent B2
US 12,619,556 · App. 18/629,390 · Granted May 5, 2026

Security vulnerability mitigation using hardware-supported context-dependent address space hiding

Inventors: Nathan Yong Seng Chong (Ponte Vedra, FL); Karimallah Ahmed Mohammed Raslan (Leander, TX)
Assignee: Amazon Technologies, Inc.
G06F12/1491G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,556
App. No.
18/629,390
Granted
May 5, 2026
Kind
B2
Abstract

A system, method and processor that mitigates security vulnerabilities using context-dependent address space hiding. In some embodiments, a hardware mechanism allows a more-privileged software component managing multiple less-privileged software components to blind itself against “out-of-context” less-privileged software components. The hardware mechanism can allow the more-privileged software component to dynamically hide a portion of the more-privileged address space related to the “out-of-context” less-privileged software components, based on knowledge of the “in-context” less-privileged software component. A context register is set with a value from which an address range, within the address space of the more-privileged software component, can be determined, where the address range is associated with a first less-privileged software component can be determined. When the more-privileged software component attempts to access data from other less-privileged software components, it is prevented from accessing such data, based at least in part on the context register.

Claims (76)

1 . A device, comprising:

one or more hardware registers; and

address translation circuitry configured to translate, for memory access instructions, addresses in a virtual address space to addresses in a physical address space for accessing physical memory, wherein the virtual address space comprises a plurality of portions of different privilege levels including a lower privilege level and a higher privilege level, and wherein to translate an address in the virtual address space for a memory access, the address translation circuitry is configured to:

determine whether to apply context dependent memory access security;

responsive to a determination to apply context dependent memory access security, determine, based on contents of the one or more hardware registers, whether the address in the virtual address space is within a subset of one or more portions of the virtual address space of the lower privilege level;

responsive to a determination the address in the virtual address space is within the subset of the one or more portions of the virtual address space of the lower privilege level, allow translation of the address in the virtual address space to an address in the physical address space; and

responsive to a determination the address in the virtual address space is not within the subset of the one or more portions of the virtual address space of the lower privilege level, block the memory access.

2 . The device of claim 1 , wherein to translate the address in the virtual address space for the memory access, the address translation circuitry is configured to:

responsive to a determination to not apply context dependent memory access security, allow translation of the address in the virtual address space to the address in the physical address space.

3 . The device of claim 1 , further comprising:

one or more hardware execution units configured to execute program instructions for a more-privileged software component and a plurality of less-privileged software components, wherein the more-privileged software component has a higher memory access privilege than respective memory access privileges of the plurality of less-privileged software components, and wherein the more-privileged software component is configured to perform management tasks on behalf of the plurality of less-privileged software components using management data at one or more portions of a virtual address space to which the more-privileged software component has access according to the higher memory access privilege.

4 . The device of claim 3 , wherein to translate the address in the virtual address space for the memory access, the address translation circuitry is configured to:

determine whether the address in the virtual address space is within another one or more portions of the virtual address space used by the more-privileged software component; and

responsive to a determination that the address in the virtual address space is not within the other one or more portions of the virtual address space, allow translation of the address in the virtual address space to an address in the physical address space;

wherein to determine whether the address in the virtual address space is within the subset of the one or more portions of the virtual address space is responsive to the determination to apply context dependent memory access security and responsive to the determination that the address in the virtual address space is within the other one or more portions of the virtual address space used by the more-privileged software component.

5 . The device of claim 3 , wherein to translate the address in the virtual address space for the memory access, the address translation circuitry is configured to:

determine whether the address in the virtual address space is within another one or more portions of the virtual address space used by the more-privileged software component; and

responsive to a determination that the address in the virtual address space is not within the other one or more portions of the virtual address space, allow translation of the address in the virtual address space to an address in the physical address space;

wherein to determine whether to apply the context dependent memory access security is responsive to the determination that the address in the virtual address space is within the other one or more portions of the virtual address space used by the more-privileged software component.

6 . The device of claim 3 , wherein the one or more hardware registers comprise:

a first hardware register for storing location information for the one or more portions of the virtual address space used by the more-privileged software component; and

a second hardware register for storing an identifier for one of the plurality of less-privileged software components for which the more-privileged software component is to perform a management task, wherein the identifier maps to a subset of the one or more portions of the virtual address space;

wherein the determination to apply context dependent memory access security is based on contents of the first and second hardware registers.

7 . The device of claim 6 , wherein the one or more hardware registers further comprise a third hardware register for storing a fixed size of subsets of the one or more portions of the virtual address space, including the subset, used by the more-privileged software component to store the management data for performing the management tasks on behalf of individual less-privileged software components of the plurality of less-privileged software components, and wherein to determine whether the address in the virtual address space is within the subset of the one or more portions of the virtual address space, the address translation circuitry is further configured to:

determine a beginning virtual address, of the subset of the one or more portions of the virtual address space, by multiplying the third register with the second register and adding a result of the multiplication to the first register;

determine an ending virtual address by adding the second register to the beginning virtual address; and

determine whether the address in the virtual address space is between the beginning virtual address and the ending virtual address.

8 . A system, comprising:

one or more processors individually comprising:

one or more hardware registers; and

address translation circuitry configured to translate, for memory access instructions, addresses in a virtual address space to addresses in a physical address space for accessing physical memory, wherein the virtual address space comprises a plurality of portions of different privilege levels including a lower privilege level and a higher privilege level, and wherein to translate an address in the virtual address space for a memory access, the address translation circuitry is configured to:

determine whether to apply context dependent memory access security;

responsive to a determination to apply context dependent memory access security, determine, based on contents of the one or more hardware registers, whether the address in the virtual address space is within a subset of one or more portions of the virtual address space of the lower privilege level;

responsive to a determination the address in the virtual address space is within the subset of the one or more portions of the virtual address space of the lower privilege level, allow translation of the address in the virtual address space to an address in the physical address space; and

responsive to a determination the address in the virtual address space is not within the subset of the one or more portions of the virtual address space of the lower privilege level, block the memory access.

9 . The system of claim 8 , wherein to translate the address in the virtual address space for the memory access, the address translation circuitry is configured to:

responsive to a determination to not apply context dependent memory access security, allow translation of the address in the virtual address space to the address in the physical address space.

10 . The system of claim 8 , wherein the one or more processors further individually comprise:

one or more hardware execution units configured to execute program instructions for a more-privileged software component and a plurality of less-privileged software components, wherein the more-privileged software component has a higher memory access privilege than respective memory access privileges of the plurality of less-privileged software components, and wherein the more-privileged software component is configured to perform management tasks on behalf of the plurality of less-privileged software components using management data at one or more portions of a virtual address space to which the more-privileged software component has access according to the higher memory access privilege.

11 . The system of claim 10 , wherein to translate the address in the virtual address space for the memory access, the address translation circuitry is configured to:

determine whether the address in the virtual address space is within another one or more portions of the virtual address space used by the more-privileged software component; and

responsive to a determination that the address in the virtual address space is not within the other one or more portions of the virtual address space, allow translation of the address in the virtual address space to an address in the physical address space;

wherein to determine whether the address in the virtual address space is within the subset of the one or more portions of the virtual address space is responsive to the determination to apply context dependent memory access security and responsive to the determination that the address in the virtual address space is within the other one or more portions of the virtual address space used by the more-privileged software component.

12 . The system of claim 10 , wherein to translate the address in the virtual address space for the memory access, the address translation circuitry is configured to:

determine whether the address in the virtual address space is within another one or more portions of the virtual address space used by the more-privileged software component; and

responsive to a determination that the address in the virtual address space is not within the other one or more portions of the virtual address space, allow translation of the address in the virtual address space to an address in the physical address space;

wherein to determine whether to apply the context dependent memory access security is responsive to the determination that the address in the virtual address space is within the other one or more portions of the virtual address space used by the more-privileged software component.

13 . The system of claim 10 , wherein the one or more hardware registers comprise:

a first hardware register for storing location information for the one or more portions of the virtual address space used by the more-privileged software component; and

a second hardware register for storing an identifier for one of the plurality of less-privileged software components for which the more-privileged software component is to perform a management task, wherein the identifier maps to a subset of the one or more portions of the virtual address space;

wherein the determination to apply context dependent memory access security is based on contents of the first and second hardware registers.

14 . The system of claim 13 , wherein the one or more hardware registers further comprise a third hardware register for storing a fixed size of subsets of the one or more portions of the virtual address space, including the subset, used by the more-privileged software component to store the management data for performing the management tasks on behalf of individual less-privileged software components of the plurality of less-privileged software components, and wherein to determine whether the address in the virtual address space is within the subset of the one or more portions of the virtual address space, the address translation circuitry is further configured to:

determine a beginning virtual address, of the subset of the one or more portions of the virtual address space, by multiplying the third register with the second register and adding a result of the multiplication to the first register;

determine an ending virtual address by adding the second register to the beginning virtual address; and

determine whether the address in the virtual address space is between the beginning virtual address and the ending virtual address.

15 . A method, comprising:

translating, in address translation circuitry of a processor on behalf of memory access instructions addresses in a virtual address space to addresses in a physical address space for accessing physical memory, wherein the virtual address space comprises a plurality of portions of different privilege levels including a lower privilege level and a higher privilege level, and wherein translating an address in the virtual address space for a memory access comprises:

determining whether to apply context dependent memory access security;

responsive to determining to apply context dependent memory access security, determining, based on contents of one or more hardware registers, whether the address in the virtual address space is within a subset of one or more portions of the virtual address space of the lower privilege level;

responsive to determining the address in the virtual address space is within the subset of the one or more portions of the virtual address space of the lower privilege level, allowing translation of the address in the virtual address space to an address in the physical address space; and

responsive to determining the address in the virtual address space is not within the subset of the one or more portions of the virtual address space of the lower privilege level, blocking the memory access.

16 . The method of claim 15 , wherein translating the address in the virtual address space for the memory access comprises:

responsive to determining to not apply context dependent memory access security, allowing translation of the address in the virtual address space to the address in the physical address space.

17 . The method of claim 15 , further comprising executing program instructions for a more-privileged software component and a plurality of less-privileged software components, wherein the more-privileged software component has a higher memory access privilege than respective memory access privileges of the plurality of less-privileged software components, and wherein the more-privileged software component is configured to perform management tasks on behalf of the plurality of less-privileged software components using management data at one or more portions of a virtual address space to which the more-privileged software component has access according to the higher memory access privilege.

18 . The method of claim 17 , wherein translating the address in the virtual address space for the memory access comprises:

determining whether the address in the virtual address space is within another one or more portions of the virtual address space used by the more-privileged software component; and

responsive to a determining that the address in the virtual address space is not within the other one or more portions of the virtual address space, allowing translation of the address in the virtual address space to an address in the physical address space;

wherein determining whether the address in the virtual address space is within the subset of the one or more portions of the virtual address space is performed responsive to determining to apply context dependent memory access security and responsive to determining that the address in the virtual address space is within the other one or more portions of the virtual address space used by the more-privileged software component.

19 . The method of claim 17 , wherein translating the address in the virtual address space for the memory access comprises:

determining whether the address in the virtual address space is within another one or more portions of the virtual address space used by the more-privileged software component; and

responsive to determining that the address in the virtual address space is not within the other one or more portions of the virtual address space, allowing translation of the address in the virtual address space to an address in the physical address space;

wherein determining whether to apply the context dependent memory access security is performed responsive to determining that the address in the virtual address space is within the other one or more portions of the virtual address space used by the more-privileged software component.

20 . The method of claim 17 , wherein determining whether the address in the virtual address space is within the subset of the one or more portions of the virtual address space comprises:

determining a beginning virtual address, of the subset of the one or more portions of the virtual address space, by multiplying a third register with a second register and adding a result of the multiplication to a first register, the first hardware register storing location information for the one or more portions of the virtual address space used by the more-privileged software component, the second hardware register storing an identifier for one of the plurality of less-privileged software components for which the more-privileged software component is to perform a management task, wherein the identifier maps to a subset of the one or more portions of the virtual address space and the third hardware register storing a fixed size of subsets of the one or more portions of the virtual address space, including the subset, used by the more-privileged software component to store the management data for performing the management tasks on behalf of individual less-privileged software components of the plurality of less-privileged software components;

determining an ending virtual address by adding the second register to the beginning virtual address; and

determining whether the address in the virtual address space is between the beginning virtual address and the ending virtual address.

Continuity (2)
Continuation 17936783 · Sep 29, 2022
Related Publication 20240256470A1 · Aug 1, 2024
References Cited (80)
US 6658447B2 · Cota-Robles · 2003 [cited by applicant]
US 7493436B2 · Blackmore et al. · 2009 [cited by applicant]
US 7698707B2 · Accapadi et al. · 2010 [cited by applicant]
US 7992156B1 · Wang · 2011 [cited by applicant]
US 8136111B2 · Mall et al. · 2012 [cited by applicant]
US 8145797B2 · Floyd · 2012 [cited by applicant]
US 9286105B1 · Levchenko · 2016 [cited by applicant]
US 9323552B1 · Adogla · 2016 [cited by applicant]
US 9507540B1 · Adogla · 2016 [cited by applicant]
US 9785557B1 · Frey · 2017 [cited by applicant]
US 9971909B2 · Mittal · 2018 [cited by examiner]
US 11593169B2 · Chisnall · 2023 [cited by applicant]
US 11669441B1 · Adogla · 2023 [cited by applicant]
US 11782713B1 · Shah · 2023 [cited by applicant]
US 11977496B1 · Chong et al. · 2024 [cited by applicant]
US 20030033510A1 · Dice · 2003 [cited by applicant]
US 20040215932A1 · Burky · 2004 [cited by applicant]
US 20040268325A1 · Moore · 2004 [cited by applicant]
US 20050015702A1 · Shier · 2005 [cited by applicant]
US 20060041735A1 · Hepkin · 2006 [cited by applicant]
US 20080133842A1 · Raikin · 2008 [cited by applicant]
US 20080155536A1 · Levit-Gurevich · 2008 [cited by applicant]
US 20080184240A1 · Franaszek · 2008 [cited by applicant]
US 20080313417A1 · Kim · 2008 [cited by applicant]
US 20100082867A1 · Adachi · 2010 [cited by applicant]
US 20100100934A1 · Mejdrich · 2010 [cited by applicant]
US 20110219447A1 · Horovitz · 2011 [cited by applicant]
US 20110296421A1 · Gschwind · 2011 [cited by applicant]
US 20120222035A1 · Plondke · 2012 [cited by applicant]
US 20130263129A1 · Adachi · 2013 [cited by applicant]
US 20130332778A1 · Spracklen · 2013 [cited by applicant]
US 20140026138A1 · Itou · 2014 [cited by applicant]
US 20140047201A1 · Mehta · 2014 [cited by applicant]
US 20140259117A1 · Wachendorf · 2014 [cited by applicant]
US 20150013008A1 · Lukacs · 2015 [cited by applicant]
US 20150022538A1 · Munshi · 2015 [cited by applicant]
US 20150143055A1 · Guthrie · 2015 [cited by applicant]
US 20150169350A1 · Anand · 2015 [cited by applicant]
US 20150178219A1 · Aslot · 2015 [cited by applicant]
US 20160224509A1 · Moudgill · 2016 [cited by applicant]
US 20160267000A1 · Rose · 2016 [cited by applicant]
US 20160283237A1 · Pardo · 2016 [cited by applicant]
US 20160371123A1 · Zhang · 2016 [cited by applicant]
US 20170093669A1 · Nortman · 2017 [cited by applicant]
US 20170109189A1 · Swidowski · 2017 [cited by applicant]
US 20170177397A1 · Gao · 2017 [cited by applicant]
US 20170212811A1 · Kashnikov · 2017 [cited by applicant]
US 20180011711A1 · Ray · 2018 [cited by applicant]
US 20180129525A1 · Hong · 2018 [cited by examiner]
US 20180137136A1 · Altaparmakov · 2018 [cited by applicant]
US 20180268156A1 · Luo · 2018 [cited by applicant]
US 20180285106A1 · Appu · 2018 [cited by applicant]
US 20180287949A1 · Kumar · 2018 [cited by applicant]
US 20190138720A1 · Grewal · 2019 [cited by applicant]
US 20190196982A1 · Rozas · 2019 [cited by applicant]
US 20200133873A1 · Williams · 2020 [cited by applicant]
US 20200150960A1 · Williams · 2020 [cited by applicant]
US 20200174931A1 · Williams · 2020 [cited by applicant]
US 20200183696A1 · Williams · 2020 [cited by applicant]
US 20200183843A1 · Williams · 2020 [cited by applicant]
US 20200201780A1 · Williams · 2020 [cited by applicant]
US 20200201786A1 · Ouziel · 2020 [cited by applicant]
US 20200301735A1 · Accapadi · 2020 [cited by applicant]
US 20200327367A1 · Ma · 2020 [cited by applicant]
US 20200356409A1 · Williams · 2020 [cited by applicant]
US 20200364375A1 · Bottomley · 2020 [cited by applicant]
US 20200409771A1 · Williams · 2020 [cited by applicant]
US 20230205562A1 · Basak · 2023 [cited by applicant]
US 20230409321A1 · Shah et al. · 2023 [cited by applicant]
Changhee Jung, et al., Adaptive execution techniques for SMT multiprocessor architectures:, PPoPP'05, ACM, Jun. 15-17, 2005, pp. 236-246. [cited by applicant]
Nael Abu-Ghazaleh, et al., “How the Spectre and Meltdown Hacks Really Worked”, Retrieved from https://spectrum.ieee.org/computing/hardware/how-the-spectre-and-meltdown-hacks-really-worked on Jun. 3, 2019, pp. 1-18. [cited by applicant]
Microsoft Tech Community, Hyper-V HyperClear Mitigation for L1 Terminal Fault, Retrieved from https://techcommunity.microsoft.com/t5/Virtualization/Hyper-V-HyperClear-Mitigation-for-L1-Terminal-Fault/ba-p/382429 on Jun.… [cited by applicant]
Deborah T. Marr, et al., “Hyper-Threading Technology Architecture and Microarchitecture”, Intel Technology Journal Q1, 2002, pp. 1-12. [cited by applicant]
Alexander Chartre, KVM Address Space Isolation, Retrieved from https://lwn.net/Articles/788273/ on Jun. 21, 2019, pp. 1-6. [cited by applicant]
Andy Greenberg, “Meltdown Redux: Intel Flaw Lets Siphon Secrets From Millions of PCs”, Retrieved from https://www.wired.com/story/intel-mds-attack-speculative-execution-buffer/ on Jun. 3, 2019, pp. 1-20. [cited by applicant]
Microsoft, “Protect your Windows devices against speculative execution side-channel attacks”, Retrieved from https://support.microsoft.com/en-us/help/4073757/protect-windows-devices-from-speculative-execution-side-chann… [cited by applicant]
Jochen Liedtke, et al., “Lazy Process Switching”, Proceedings Eighth Workshop on Hot Topics in Operating Systems, IEEE, 2001, pp. 13-16. [cited by applicant]
Alexandre Chartre, “LKML: Kernel Address Space Isolation”, Retrieved from https://lkml.org/lkml/2019/7/11/351 on Jul. 20, 2019, pp. 1-5. [cited by applicant]
Unknown, “Cache speulation Side-Channels”, Whitepaper, Retrieved from https://developer.arm.com/documentation/102816/0205/, dated Jun. 2020, version 2.5, pp. 1-21. [cited by applicant]
U.S. Appl. No. 17/936,783, filed Sep. 29, 2022, Nathan Yong Seng Chong, et al. [cited by applicant]