IP Library › Granted Patent US 12,704,991
Granted Patent B2
US 12,704,991 · App. 17/559,908 · Granted Aug 11, 2026

Circuitry and methods for implementing capability-based compartment switches with descriptors

Inventor: Michael LeMay (Hillsboro, OR)
Assignee: Intel Corporation
G06F3/0655G06F3/0604G06F3/0679G06F9/3818
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,704,991
App. No.
17/559,908
Filed
Dec 22, 2021
Granted
Aug 11, 2026
Kind
B2
Art Unit
2132
USPC
711/154
Abstract

Systems, methods, and apparatuses for implementing capability-based compartment switches with descriptors are described. In certain examples, a hardware processor core comprises a capability management circuit to check a capability for a memory access request, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address range to which the capability authorizes access; a decoder circuit to decode a single instruction into a decoded single instruction, the single instruction comprising one or more fields to indicate a first compartment descriptor that identifies a first capability to a first state element in a first compartment of memory and a second capability to a second state element in the first compartment of the memory, and an opcode to indicate that an execution circuit is to load the first capability from the first compartment descriptor of the memory into a first register to enable the capability management circuit to determine whether a first bounds field of the first capability authorizes an access to the first state element in the first compartment of the memory, and load the second capability from the first compartment descriptor of the memory into a second register to enable the capability management circuit to determine that a second bounds field of the second capability authorizes an access to the second state element in the first compartment of the memory; and the execution circuit to execute the decoded single instruction according to the opcode.

Claims (57)

1 . An apparatus comprising:

a capability management circuit to check a capability for a memory access request, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address range to which the capability authorizes access;

a decoder circuit to decode a single instruction into a decoded single instruction, the single instruction comprising one or more fields to indicate a first compartment descriptor that identifies a first capability to a first state element in a first compartment of memory and a second capability to a second state element in the first compartment of the memory, and an opcode to indicate that an execution circuit is to load the first capability from the first compartment descriptor of the memory into a first register to enable the capability management circuit to determine whether a first bounds field of the first capability authorizes an access to the first state element in the first compartment of the memory, and load the second capability from the first compartment descriptor of the memory into a second register to enable the capability management circuit to determine that a second bounds field of the second capability authorizes an access to the second state element in the first compartment of the memory; and

the execution circuit to execute the decoded single instruction according to the opcode, wherein:

the one or more fields of the single instruction indicate a second compartment descriptor that identifies a third capability to a third state element in a second compartment of the memory and a fourth capability to a fourth state element in the second compartment of the memory; and

the opcode is to further indicate that the execution circuit is to, before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register, store the third capability from the first register into the second compartment descriptor of the memory, and store the fourth capability from the second register into the second compartment descriptor of the memory.

2 . The apparatus of claim 1 , wherein the one or more fields comprise a first compartment descriptor capability that comprises a first compartment descriptor address field of the first compartment descriptor in the memory and a first compartment descriptor bounds field that is to indicate a lower bound and an upper bound of the first compartment descriptor in the memory, and the opcode is to further indicate that the execution circuit is to access the first compartment descriptor in the memory in response to a determination by the capability management circuit that a first compartment descriptor address from the first compartment descriptor address field is within the lower bound and the upper bound from the first compartment descriptor bounds field.

3 . The apparatus of claim 1 , wherein the opcode is to further indicate that the execution circuit is to:

set a busy flag of the second compartment descriptor before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register to stall the load of the first capability from the first compartment descriptor of the memory into the first register, and stall the load of the second capability from the first compartment descriptor of the memory into the second register; and

clear the busy flag in response to completion of the store of the third capability from the first register into the second compartment descriptor of the memory, and the store of the fourth capability from the second register into the second compartment descriptor of the memory.

4 . The apparatus of claim 1 , wherein the opcode is to further indicate that the execution circuit is to clear the first register and the second register before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register.

5 . The apparatus of claim 1 , wherein:

the first compartment descriptor is to store a third set of state elements; and

the opcode is to further indicate that the execution circuit is to load the third set of state elements from the first compartment descriptor into a third set of registers.

6 . The apparatus of claim 5 , wherein the first compartment descriptor comprises a bitmap field to indicate a proper subset of the third set of registers to load the third set of state elements into.

7 . The apparatus of claim 1 , wherein:

the decoder circuit is to decode a second single instruction into a decoded second single instruction, the second single instruction comprising one or more fields to indicate a location of the first compartment descriptor in the memory to store the first capability to the first state element in the first compartment of the memory and the second capability to the second state element in the first compartment of the memory, and an opcode to indicate that the execution circuit is to initialize the memory at the location in a format of a compartment descriptor with space for the first capability and the second capability; and

the execution circuit to execute the decoded second single instruction according to its opcode.

8 . A method comprising:

checking, by a capability management circuit of a processor core, a capability for a memory access request, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address range to which the capability authorizes access;

decoding, by a decoder circuit of the processor core, a single instruction into a decoded single instruction, the single instruction comprising one or more fields to indicate a first compartment descriptor that identifies a first capability to a first state element in a first compartment of memory and a second capability to a second state element in the first compartment of the memory, and an opcode indicating that an execution circuit of the processor core is to load the first capability from the first compartment descriptor of the memory into a first register to enable the capability management circuit to determine whether a first bounds field of the first capability authorizes an access to the first state element in the first compartment of the memory, and load the second capability from the first compartment descriptor of the memory into a second register to enable the capability management circuit to determine that a second bounds field of the second capability authorizes an access to the second state element in the first compartment of the memory; and

executing, by the execution circuit, the decoded single instruction according to the opcode,

wherein:

the one or more fields of the single instruction indicate a second compartment descriptor that identifies a third capability to a third state element in a second compartment of the memory and a fourth capability to a fourth state element in the second compartment of the memory; and

the opcode further indicates that the execution circuit is to, before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register, store the third capability from the first register into the second compartment descriptor of the memory, and store the fourth capability from the second register into the second compartment descriptor of the memory.

9 . The method of claim 8 , wherein the one or more fields comprise a first compartment descriptor capability that comprises a first compartment descriptor address field of the first compartment descriptor in the memory and a first compartment descriptor bounds field that is to indicate a lower bound and an upper bound of the first compartment descriptor in the memory, and the opcode is to further indicate that the execution circuit is to access the first compartment descriptor in the memory in response to a determination by the capability management circuit that a first compartment descriptor address from the first compartment descriptor address field is within the lower bound and the upper bound from the first compartment descriptor bounds field.

10 . The method of claim 8 , wherein the opcode further indicates that the execution circuit is to:

set a busy flag of the second compartment descriptor before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register to stall the load of the first capability from the first compartment descriptor of the memory into the first register, and stall the load of the second capability from the first compartment descriptor of the memory into the second register; and

clear the busy flag in response to completion of the stores of the third capability from the first register into the second compartment descriptor of the memory, and the store of the fourth capability from the second register into the second compartment descriptor of the memory.

11 . The method of claim 8 , wherein the opcode further indicates that the execution circuit is to clear the first register and the second register before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register.

12 . The method of claim 8 , wherein:

the first compartment descriptor stores a third set of state elements; and

the opcode further indicates that the execution circuit is to load the third set of state elements from the first compartment descriptor into a third set of registers.

13 . The method of claim 12 , wherein the first compartment descriptor comprises a bitmap field that indicates a proper subset of the third set of registers to load the third set of state elements into.

14 . The method of claim 8 , further comprising:

decoding, by the decoder circuit, a second single instruction into a decoded second single instruction, the second single instruction comprising one or more fields to indicate a location of the first compartment descriptor in the memory to store the first capability to the first state element in the first compartment of the memory and the second capability to the second state element in the first compartment of the memory, and an opcode to indicate that the execution circuit is to initialize the memory at the location in a format of a compartment descriptor with space for the first capability and the second capability; and

executing, by the execution circuit, the decoded second single instruction according to its opcode.

15 . A non-transitory machine readable medium that stores code that when executed by a machine causes the machine to perform a method comprising:

checking, by a capability management circuit of a processor core, a capability for a memory access request, the capability comprising an address field and a bounds field that is to indicate a lower bound and an upper bound of an address range to which the capability authorizes access;

decoding, by a decoder circuit of the processor core, a single instruction into a decoded single instruction, the single instruction comprising one or more fields to indicate a first compartment descriptor that identifies a first capability to a first state element in a first compartment of memory and a second capability to a second state element in the first compartment of the memory, and an opcode indicating that an execution circuit of the processor core is to load the first capability from the first compartment descriptor of the memory into a first register to enable the capability management circuit to determine that a first bounds field of the first capability authorizes an access to the first state element in the first compartment of the memory, and load the second capability from the first compartment descriptor of the memory into a second register to enable the capability management circuit to determine that a second bounds field of the second capability authorizes an access to the second state element in the first compartment of the memory; and

executing, by the execution circuit, the decoded single instruction according to the opcode,

wherein:

the one or more fields of the single instruction indicate a second compartment descriptor that identifies a third capability to a third state element in a second compartment of the memory and a fourth capability to a fourth state element in the second compartment of the memory; and

the opcode further indicates that the execution circuit is to, before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register, store the third capability from the first register into the second compartment descriptor of the memory, and store the fourth capability from the second register into the second compartment descriptor of the memory.

16 . The non-transitory machine readable medium of claim 15 , wherein the one or more fields comprise a first compartment descriptor capability that comprises a first compartment descriptor address field of the first compartment descriptor in the memory and a first compartment descriptor bounds field that is to indicate a lower bound and an upper bound of the first compartment descriptor in the memory, and the opcode is to further indicate that the execution circuit is to access the first compartment descriptor in the memory in response to a determination by the capability management circuit that a first compartment descriptor address from the first compartment descriptor address field is within the lower bound and the upper bound from the first compartment descriptor bounds field.

17 . The non-transitory machine readable medium of claim 15 ,

wherein the opcode further indicates that the execution circuit is to:

set a busy flag of the second compartment descriptor before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register to stall the load of the first capability from the first compartment descriptor of the memory into the first register, and stall the load of the second capability from the first compartment descriptor of the memory into the second register; and

clear the busy flag in response to completion of the store of the third capability from the first register into the second compartment descriptor of the memory, and the store of the fourth capability from the second register into the second compartment descriptor of the memory.

18 . The non-transitory machine readable medium of claim 15 , wherein the opcode further indicates that the execution circuit is to clear the first register and the second register before the load of the first capability from the first compartment descriptor of the memory into the first register, and the load of the second capability from the first compartment descriptor of the memory into the second register.

19 . The non-transitory machine readable medium of claim 15 , wherein:

the first compartment descriptor stores a third set of state elements; and

the opcode further indicates that the execution circuit is to load the third set of state elements from the first compartment descriptor into a third set of registers.

20 . The non-transitory machine readable medium of claim 19 , wherein the first compartment descriptor comprises a bitmap field that indicates a proper subset of the third set of registers to load the third set of state elements into.

21 . The non-transitory machine readable medium of claim 15 , wherein the method further comprises:

decoding, by the decoder circuit, a second single instruction into a decoded second single instruction, the second single instruction comprising one or more fields to indicate a location of the first compartment descriptor in the memory to store the first capability to the first state element in the first compartment of the memory and the second capability to the second state element in the first compartment of the memory, and an opcode to indicate that the execution circuit is to initialize the memory at the location in a format of a compartment descriptor with space for the first capability and the second capability; and

executing, by the execution circuit, the decoded second single instruction according to its opcode.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2022
From: LEMAY, MICHAEL
To: INTEL CORPORATION
Reel/Frame 058595/0235 →
Continuity (1)
Related Publication 20230195360A1 · Jun 22, 2023
References Cited (154)
US 3794980A · Cogar et al. · 1974 [cited by applicant]
US 3916385A · Parmar et al. · 1975 [cited by applicant]
US 4809160A · Mahon et al. · 1989 [cited by applicant]
US 4821169A · Sites et al. · 1989 [cited by applicant]
US 5287309A · Kai · 1994 [cited by applicant]
US 5499349A · Nikhil et al. · 1996 [cited by applicant]
US 5809564A · Craze et al. · 1998 [cited by applicant]
US 5862400A · Reed et al. · 1999 [cited by applicant]
US 6009503A · Liedtke · 1999 [cited by applicant]
US 6048940A · Blaedel et al. · 2000 [cited by applicant]
US 6128728A · Dowling · 2000 [cited by applicant]
US 6671699B1 · Black et al. · 2003 [cited by applicant]
US 6694450B1 · Kidder et al. · 2004 [cited by applicant]
US 6823433B1 · Barnes et al. · 2004 [cited by applicant]
US 7086088B2 · Narayanan · 2006 [cited by applicant]
US 7401234B2 · Case et al. · 2008 [cited by applicant]
US 7581089B1 · White · 2009 [cited by applicant]
US 8554984B2 · Yano et al. · 2013 [cited by applicant]
US 8595442B1 · James-Roxby et al. · 2013 [cited by applicant]
US 9026866B2 · Balasubramanian · 2015 [cited by applicant]
US 9390031B2 · Durham et al. · 2016 [cited by applicant]
US 9436847B2 · Durham et al. · 2016 [cited by applicant]
US 9501637B2 · Lemay et al. · 2016 [cited by applicant]
US 9652375B2 · Stark · 2017 [cited by examiner]
US 10162694B2 · Stark et al. · 2018 [cited by applicant]
US 11030113B1 · Durham et al. · 2021 [cited by applicant]
US 20020019902A1 · Christie · 2002 [cited by applicant]
US 20030196076A1 · Zabarski et al. · 2003 [cited by applicant]
US 20040031030A1 · Kidder et al. · 2004 [cited by applicant]
US 20040158775A1 · Shibuya et al. · 2004 [cited by applicant]
US 20040221141A1 · Padmanabhan et al. · 2004 [cited by applicant]
US 20050044292A1 · Mckeen · 2005 [cited by applicant]
US 20050193217A1 · Case et al. · 2005 [cited by applicant]
US 20060187941A1 · Andersen · 2006 [cited by applicant]
US 20060256877A1 · Szczepanek et al. · 2006 [cited by applicant]
US 20060256878A1 · Szczepanek et al. · 2006 [cited by applicant]
US 20070055837A1 · Rajagopal et al. · 2007 [cited by applicant]
US 20080209282A1 · Lee et al. · 2008 [cited by applicant]
US 20090271536A1 · Tiennot · 2009 [cited by applicant]
US 20090292977A1 · Bradley et al. · 2009 [cited by applicant]
US 20090320129A1 · Pan et al. · 2009 [cited by applicant]
US 20100115243A1 · Kissell · 2010 [cited by applicant]
US 20100162038A1 · Hulbert et al. · 2010 [cited by applicant]
US 20100293342A1 · Morfey et al. · 2010 [cited by applicant]
US 20120030392A1 · Norden et al. · 2012 [cited by applicant]
US 20120036299A1 · Renno · 2012 [cited by applicant]
US 20120036341A1 · Morfey et al. · 2012 [cited by applicant]
US 20130318322A1 · Shetty et al. · 2013 [cited by applicant]
US 20130326288A1 · Datta et al. · 2013 [cited by applicant]
US 20140115283A1 · Radovic et al. · 2014 [cited by applicant]
US 20140281354A1 · Tkacik et al. · 2014 [cited by applicant]
US 20140283088A1 · Alharbi et al. · 2014 [cited by applicant]
US 20140365742A1 · Patel et al. · 2014 [cited by applicant]
US 20140372698A1 · Lee et al. · 2014 [cited by applicant]
US 20150278516A1 · Caprioli · 2015 [cited by applicant]
US 20160048378A1 · Varma · 2016 [cited by applicant]
US 20160124802A1 · Gabor et al. · 2016 [cited by applicant]
US 20160259682A1 · Stark et al. · 2016 [cited by applicant]
US 20160283300A1 · Stark et al. · 2016 [cited by applicant]
US 20160371139A1 · Stark et al. · 2016 [cited by applicant]
US 20160381050A1 · Shanbhogue et al. · 2016 [cited by applicant]
US 20170177339A1 · Shanbhogue et al. · 2017 [cited by applicant]
US 20170177429A1 · Stark et al. · 2017 [cited by applicant]
US 20170228535A1 · Shanbhogue et al. · 2017 [cited by applicant]
US 20180060250A1 · Hildesheim et al. · 2018 [cited by applicant]
US 20180074715A1 · Farmahini-Farahani et al. · 2018 [cited by applicant]
US 20180253310A1 · Stephens · 2018 [cited by examiner]
US 20190057093A1 · Caulfield · 2019 [cited by examiner]
US 20200004550A1 · Thakker · 2020 [cited by examiner]
US 20200004953A1 · Lemay et al. · 2020 [cited by applicant]
US 20210200546A1 · Lemay et al. · 2021 [cited by applicant]
US 20210294607A1 · Abhishek Raja · 2021 [cited by examiner]
US 20240086579A1 · Ayrapetyan · 2024 [cited by examiner]
EP 0428079A2 · 1991 [cited by applicant]
EP 3885901A1 · 2021 [cited by applicant]
JP 03244054A · 1991 [cited by applicant]
KR 1020080075175A · 2008 [cited by applicant]
WO 2007079011A3 · 2007 [cited by applicant]
European Search Report and Search Opinion, EP App. No. 22205974.3, Mar. 1, 2023, 10 pages. [cited by applicant]
Advisory Action from U.S. Appl. No. 11/323,446, Apr. 17, 2012, 3 pages. [cited by applicant]
Angelo-Oracle. “SPARC M7 Chip-32 cores”, Oracle.com, Aug. 15, 2014. Web. Accessed Dec. 21, 2015. 8 pages. URL: <http://blogs.oracle.com/rajadurai/entry/sparc_m7_chip_32_cores>. [cited by applicant]
Arm, “Arm® Architecture Reference Manual Supplement Morello for A-profile Architecture”, Document No. DDI0606, Document Version: A.j, 2019-2021, 1288 pages. [cited by applicant]
Biin: “CPA Architecture Reference Manual”, 1988, 401 pages. [cited by applicant]
Burow et al., “CUP: Comprehensive User-Space Protection for C/C++”, Session 9: Software Security, ASIACCS'18, Jun. 4-8, 2018, pp. 381-392. [cited by applicant]
Carr et al., “DataShield: Configurable Data Confidentiality and Integrity”, ASIA CCS '17, Apr. 2-6, 2017, pp. 193-204. [cited by applicant]
Chen et al., “Shreds: Fine-grained Execution Units with Private Memory”, IEEE Symposium on Security and Privacy, 2016, pp. 56-71. [cited by applicant]
Cheri, “Capability Hardware Enhanced RISC Instructions (CHERI)”, available online at <https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/>, 2010-2019, 2 pages. [cited by applicant]
Dartmouth, “ELFbac: Runtime Intent-Level ABI-Granular Memory Protection for Linux”, available online at <https://www.cs.dartmouth.edu/~sergey/io/elfbac/>, retrieved on May 1, 2020, 1 page. [cited by applicant]
Duarte, “Memory Translation and Segmentation” Aug. 2008, p. 1-7. [cited by applicant]
Duck et al., “EffectiveSan: Type and Memory Error Detection using Dynamically Typed C/C++”, PLDI'18, Jun. 18-22, 2018, pp. 181-195. [cited by applicant]
Final Office Action from U.S. Appl. No. 11/323,446, Dec. 30, 2011, 18 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 11/323,446, Jan. 17, 2013, 17 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 11/323,446, Jul. 16, 2015, 17 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 11/323,446, Jul. 28, 2014, 16 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 11/323,446, Jul. 7, 2009, 21 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 11/323,446, Oct. 15, 2010, 17 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 11/323,446, Sep. 20, 2013, 14 pages. [cited by applicant]
Final Office action, U.S. Appl. No. 14/752,221, Mar. 7, 2018, 28 pages. [cited by applicant]
Gil et al., “There's a Hole in the Bottom of the C: On the Effectiveness of Allocation Protection”, IEEE Cybersecurity Development (SecDev), Sep. 30-Oct. 2, 2018, 8 pages. [cited by applicant]
Gove, D., et al., “Detecting memory access errors,” Nov. 25, 2015, 17 pages. [cited by applicant]
Gretton-Dann et al., “Arm A-Profile Architecture Developments 2018: Armv8.5-A”, available online at <https://community.arm.com/developer/ip-products/processors/b/processors-ip-blog/posts/arm-a-profile-architecture-2018-… [cited by applicant]
https://courses.cs.washington.edu/courses/cse351/17wi/lectures/CSE351-L02-memory-L17wi.pdfAuthor: Ceze; Title: CSE351:Memory, Data, & Addressing I, Date: Winter, 2017 (Year: 2017). [cited by applicant]
Intel, “Intel 64 and IA-32 Architectures Software Developer's Manual”, vol. 3A, System Programming Guide, Part 1, Order No. 253668-060US, Sep. 2016, 468 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/US2006/048940, Jul. 1, 2008, 8 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2006/048940, Sep. 25, 2007, 15 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2016/063211, Mar. 7, 2017, 11 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2017/012572, Apr. 4, 2017, 13 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US2016/063207, Feb. 27, 2017, 9 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US2016/034364, Sep. 13, 2016, 12 pages. [cited by applicant]
Introduction to SPARC M7 and Silicon Secured Memory (SSM), Retrieved from https://swisdev.oracle.com/_files/What-Is-SSM.html on Jul. 4, 2016, 2 pages. [cited by applicant]
Jeon et a., “HexType: Efficient Detection of Type Confusion Errors for C++”, CCS '17, Session K3: Program Analysis, Oct. 2017, pp. 2373-2387. [cited by applicant]
Kwon et al., “Low-Fat Pointers: Compact Encoding and Efficient Gate-Level Implementation of Fat Pointers for Spatial Safety and Capability-based Security”, Proceedings of the 2013 ACM SIGAC Conference on Computer & Comm… [cited by applicant]
Liljestrand et al., “PAC it up: Towards Pointer Integrity using ARM Pointer Authentication”, Cornell University, Nov. 22, 2018, 21 pages. [cited by applicant]
LogMeln Support, “What is Privilege Separation in SSH?”, available online at <https://web.archive.org/web/20191218064501/https://help.logmein.com/articles/en_US/FAQ/What-is-Privilege-Separation-in-SSH-en1>, Dec. 18, 201… [cited by applicant]
M. Rutland, “ARMv8.3 Pointer Authentication”,, Linux Security Summit, Sep. 14, 2017, 24 slides. [cited by applicant]
Mahon M.J., et al., “Hewlett-Packard Precision Architecture: The Processor,” Hewlett-Packard Journal, Aug. 1986, 19 pages. [cited by applicant]
Mcilroy et al., “Spectre is Here to Stay: An Analysis of Side-Channels and Speculative Execution”, Cornell University, Feb. 15, 2019, pp. 1-26. [cited by applicant]
Menon et al., “Shakti-T: A RISC-V Processor with Light Weight Security Extensions”, Conference: the Hardware and Architectural Support for Security and Privacy, Jun. 25, 2017, 9 pages. [cited by applicant]
Miller, Matt, “Trends, Challenges, and Strategic Shifts in the Software Vulnerability Mitigation Landscape”, Microsoft Security Response Center (MSRC), Feb. 7, 2019, 32 pages. [cited by applicant]
Min R., et al., “Improving Performance of Large Physically Indexed Caches by Decoupling Memory Addresses From Cache Addresses,” IEEE Transactions on Computers, vol. 50, No. 11, Nov. 2001, pp. 1191-1201. [cited by applicant]
Nagarakatte et al., “CETS: Compiler-Enforced Temporal Safety for C”, ISMM'10, Jun. 5-6, 2010, pp. 31-40. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Apr. 23, 2010, 16 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Jan. 15, 2015, 18 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Jun. 22, 2012, 16 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Jun. 7, 2013, 18 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Mar. 15, 2011, 16 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Mar. 20, 2014, 15 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Nov. 5, 2015, 5 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 11/323,446, Oct. 7, 2008, 17 pages. [cited by applicant]
Non-final Office Action, U.S. Appl. No. 14/752,221, May 8, 2017, 23 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/729,358, Sep. 16, 2020, 17 pages. [cited by applicant]
Notice of Allowance from U.S. Appl. No. 11/323,446, Mar. 14, 2016, 5 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/975,840, May 7, 2019, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/729,358, Jul. 6, 2021, 8 pages. [cited by applicant]
Qualcomm, “Pointer Authentication on ARMv8.3: Design and Analysis of the New Software Security Instructions”, Jan. 2017, 12 pages. [cited by applicant]
Rajadurai A., “SPARC M7 Chip—32 cores—Mind Blowing performance,” Oracle Angelo's Soapbox Blog, Aug. 15, 2014, downloaded from https://blogs.oracle.com/rajadurai/sparc-m7-chip-32-cores-mind-blowing-performance-v2 on Aug.… [cited by applicant]
Serebryany et al., “AddressSanitizer: A Fast Address Sanity Checker”, 2012 Usenix Annual Technical Conference, Jun. 13-15, 2012, 10 pages. [cited by applicant]
Serebryany et al., “Memory Tagging And How It Improves C/C++ Memory Safety”, Feb. 2018, 14 pages. [cited by applicant]
Serebryany et al., “Memory Tagging: How It Improves C/C++ Memory Safety” Google, LLVM Developers' Meeting, Oct. 2018, 29 slides. [cited by applicant]
Serebryany, Kostya, “Arm Memory Tagging Extension and How It Improves C/C++ Memory Safety”, available online at <https://www.usenix. org/publications/login/summer2019/serebryany>, Security, vol. 44, No. 2, 2019. 5 pages. [cited by applicant]
Serebryany, Kostya, “Security: ARM Memory Tagging Extension and How It Improves C/C++ Memory Safety”, vol. 44, No. 2, Summer 2019, pp. 12-16. [cited by applicant]
Suh et al., “Secure Program Execution via Dynamic Information Flow Tracking”, ASPLOS'04, Oct. 9-13, 2004, pp. 85-96. [cited by applicant]
T. Nyman et al., “HardScope: Thwarting DOP attacks with Hardware-Assisted Run-time Scope Enforcement”, May 2017, pp. 1-20. [cited by applicant]
The Chromium Projects, “Multi-Process Architecture”, available online at <https://web.archive.org/web/20191030200549/https://www.chromium.org/developers/design-documents/multi-process-architecture>, Oct. 30, 2019, 2 pag… [cited by applicant]
Tsampas et al., “Towards Automatic Compartmentalization of C Programs on Capability Machines”, In Proceedings of the International Conference on Foundations of Computer Science, 2017, 14 pages. [cited by applicant]
Vasilakis et al., “BreakApp: Automated, Flexible Application Compartmentalization”, Network and Distributed Systems Security (NDSS) Symposium, Feb. 18-21, 2018, 15 pages. [cited by applicant]
Watson et al., “An Introduction to CHERI”, University of Cambridge, Computer Laboratory, Technical Report, No. 941, Sep. 2019, 43 pages. [cited by applicant]
Watson et al., “Capability Hardware Enhanced RISC Instructions: CHERI Instruction-Set Architecture (Version 8)”, University of Cambridge, Computer Laboratory, Technical Report, No. 951, Oct. 2020, 590 pages. [cited by applicant]
Watson et al., “Cheri: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization”, IEEE Symposium on Security and Privacy, 2015, pp. 20-37. [cited by applicant]
Watson, “Capsicum: Practical capabilities for UNIX”, USENIX Security, 2010, 17 pages. [cited by applicant]
Wesley et al., “Cornucopia: Temporal Safety for CHERI Heaps”, . In Proceedings of the 41st IEEE Symposium on Security and Privacy, 2020, pp. 1507-1524. [cited by applicant]
Wilkes J., et al., “A Comparison of Protection Lookaside Buffers and the PA-RISC Protection Architecture,” Mar. 1992, Hewlett-Packard, 12 pages. [cited by applicant]
Xia et al., “CHERIvoke: Characterising Pointer Revocation using CHERI Capabilities for Temporal Memory Safety”, MICRO '52, Oct. 2019, pp. 545-557. [cited by applicant]
Intention to Grant, EP App. No. 22205974.3, Mar. 31, 2025, 6 pages. [cited by applicant]