US2021117343A1PendingUtilityA1
Enforcing memory operand types using protection keys
Est. expirySep 30, 2036(~10.2 yrs left)· nominal 20-yr term from priority
G06F 2212/1052G06F 12/1466G06F 21/566G06F 12/1009G06F 21/53G06F 2221/034
65
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Enforcing memory operand types using protection keys is generally described herein. A processor system to provide sandbox execution support for protection key rights attacks includes a processor core to execute a task associated with an untrusted application and execute the task using a designated page of a memory; and a memory management unit to designate the page of the memory to support execution of the untrusted application.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A processor system to provide sandbox execution support for protection key rights attacks, the processor system comprising:
a processor core to execute a task associated with an untrusted application, the processor core to execute the task using a designated page of a memory; and a a memory management unit, coupled to the processor core, the memory management unit to designate the page of the memory to support execution of the untrusted application, the memory management unit comprising: a storage unit to store a page table entry associated with a page of the memory, the page table entry including a protection key field that identifies a location of a protection key right (PKR) entry and a field that enables a trusted PKR update page of the memory; and a PKR register including the PKR entry, the PKR entry including a set of bits; and wherein the memory management unit to, in response to a request to clear a bit of the set of bits of the PKR, generate a page fault in response to the request originating in a page other than the trusted PKR update page of the memory.
2 . The processor system of claim 1 , wherein the memory management unit to, in response to the field that enables the trusted PKR update page enable being set, retrieve, from a register, an identifier of the trusted PKR update page.
3 . The processor system of claim 2 , wherein the register is a control register.
4 . The processor system of claim 1 , wherein the memory management unit to allow access to the trusted PKR update page via a branch from the page of the memory to support execution of the untrusted application in response to the branch being an ENDBRANCH instruction.
5 . The processor system of claim 1 , wherein the processor core to deny access to the trusted PKR update page via a branch from the page of the memory to support execution of the untrusted application in response to the branch landing on an instruction other than an ENDBRANCH instruction.
6 . The processor system of claim 1 , wherein the processor core to operate in a 64-bit mode to execute the untrusted application.
7 . At least one machine-readable medium including instructions to provide sandbox execution support for protection key rights attacks, which when executed by a machine, cause the machine to:
execute a task; store a page table entry associated with a page of a memory, the page table entry including a protection key field that identifies a location of a protection key rights (PKR) entry, the PKR entry including an entry to disable access for a plurality of effective segments; and in response to a request for access to a page of a memory, deny access to the page of the memory based on an operand having an effective segment attribute matching one of the plurality of effective segments in the PKR entry.
8 . The at least one machine-readable medium of claim 7 , further including instructions, which when executed by a machine, cause the machine to:
categorize operands having effective segments different from all of the plurality of effective segments in the PKR entry into a first stack; categorize operands having effective segments that match one of the plurality of effective segments in the PKR entry into a second stack; allow access to a page of a memory for operands in the first stack; and deny access to a page of the memory for operands in the second stack.
9 . The at least one machine-readable medium of claim 8 , wherein the PKR entry of the PKR register further includes a stack operation enable (SOE) bit, wherein the at least one machine-readable medium further including instructions, which when executed by a machine, cause the machine to deny access to a page of a memory for operands on the first stack while the SOE bit is set.
10 . The at least one machine-readable medium of claim 8 , further including instructions, which when executed by a machine, cause the machine to:
set the SOE bit of the PKR entry; set an access disable bit of the PKR entry; and only allow access to a page of a memory for operands that have an effective segment equal to a first type while the SOE bit is set.
11 . The at least one machine-readable medium of claim 8 , wherein the first type of the effective stack segment is a segment stack (SS).Join the waitlist — get patent alerts
Track US2021117343A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.