IP Library › Granted Patent US 7,757,280
Granted Patent B2
US 7,757,280 · App. 11/333,066 · Granted Jul 13, 2010

Method and system for memory protection and security using credentials

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,757,280
App. No.
11/333,066
Granted
Jul 13, 2010
Kind
B2
Abstract

A computer-implemented method for protecting a memory is provided. The method includes responsive to a direct memory access (DMA) request received from a consumer for a transaction of data from an IO device to the memory, the request including an IO command and a capability (CAP), generating a cryptographically signed capability (CAPB), forming a credential from CAP and CAPB, appending the credential to the IO command, configuring the IO device according to the credential and the IO command, transmitting the data from the IO device to the memory and prior to allowing execution of the DMA, authenticating that the credential is valid, further includes regenerating CAPB from a key available to an authenticating entity and from the CAP (included in CAPB) and verifying that the memory region information described in the cryptographically signed capability is the same as the requested region that was originally created, and that the cryptographically signed capability encompasses the IO command.

Claims (18)

1. A computer-implemented method for protecting a memory, said method comprising:

responsive to a direct memory access (DMA) request received from a consumer for a transaction of data from an IO device to said memory, said request including an IO command and a capability (CAP), generating a cryptographically signed capability (CAPB);

forming a credential from CAP and CAPB;

appending said credential to said IO command;

configuring said IO device according to said credential and said IO command;

transmitting said data from said IO device to the memory; and

prior to allowing execution of said DMA, authenticating that said credential is valid, wherein said step of authenticating further comprises:

regenerating CAPB from a key available to an authenticating entity and from said CAP (included in CAPB); and

verifying that the memory region information described in said cryptographically signed capability is the same as said requested region that was originally created, and that said cryptographically signed capability encompasses said IO command.

2. A computer software product, including a computer-readable medium in which computer program instructions are stored, which instructions, when read by a computer, cause the computer to perform a method for protecting a memory, said method comprising:

responsive to a direct memory access (DMA) request received from a consumer for a transaction of data from an IO device to said memory, said request including an IO command and a capability (CAP), generating a cryptographically signed capability (CAPB);

forming a credential from CAP and CAPB;

appending said credential to said IO command;

configuring said IO device according to said credential and said IO command;

transmitting said data from said IO device to the memory; and

prior to allowing execution of said DMA, authenticating that said credential is valid, wherein said step of authenticating further comprises:

regenerating CAPB from a key available to an authenticating entity and from said CAP (included in CAPB); and

verifying that the memory region information described in said cryptographically signed capability is the same as said requested region that was originally created, and that said cryptographically signed capability encompasses said IO command.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2006
From: BACKES, MICHAEL; BEN-YEHUDA, SHMUEL; CAMENISCH, JAN LEONHARD; ENGBERSEN, TON; MACHULSKY, ZORIK; SATRAN, JULIAN; SHALEV, LEAH; SHIMONY, ILAN; SMITH III, THOMAS BASIL; WAIDNER, MICHAEL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 017126/0483 →
Continuity (1)
Related Publication 20070169172A1 · Jul 19, 2007