USRE40405EExpiredUtility

Method and apparatus for securing executable programs against copying

Assignee: RICOH KKPriority: Apr 18, 1995Filed: Oct 7, 1999Granted: Jun 24, 2008
Est. expiryApr 18, 2015(expired)· nominal 20-yr term from priority
G06F 2221/2107G06F 21/123
46
PatentIndex Score
15
Cited by
14
References
93
Claims

Abstract

A secure system for executing program code in an insecure environment while making it impossible, or at least impractical, to determine how to copy the program code and associated data is provided. A program memory contains encrypted program data and security circuitry contained within an integrated circuit is provided for decrypting the program data as it is needed by a processor. A portion of the processing steps which would be done by the processor in an insecure system is performed in this secure system within the secure circuitry using portions of the decrypted program data which are not provided to the processor. Program data is parsed it out based on a proper request to the security chip from the processor. A key value stored in volatile memory is used in the decrypting process and the volatile memory is positioned on the integrated circuit such that its contents are lost before a chip peel provides access to the volatile memory.

Claims

exact text as granted — not AI-modified
1. An apparatus for executing a secure program in a computer system, wherein the ability to make workable copies of the secure program from the computer system is inhibited, the apparatus comprising:
 a program memory in which the secure program data is stored in an encrypted form;  
 a security chip coupled to the program memory, the security chip comprising:  
 means for decrypting portions of the secure program into a clear portion and a remainder portion;  
 means for providing the clear portion to memory locations accessible by a processor; and  
 remainder memory for storing the remainder portion of the secure program, the remainder memory not directly accessible by the processor;  
 means for requesting subsets of the remainder portion for use by the processor; and  
 means, within the security chip, for checking that the requested subset is within a valid predetermined set of requested subsets dependent on a stored state for the processor.  
 
     
     
       2. The apparatus of  claim 1 , wherein the secure program stored in the program memory is stored with the clear portion and the remainder portion stored separately. 
     
     
       3. The apparatus of  claim 1 , wherein the remainder portion is a set of branch instructions of the secure program. 
     
     
       4. The apparatus of  claim 3 , wherein the security chip further includes means for caching branch statements based on recently executed branches. 
     
     
       5. The apparatus of  claim 1 , wherein the means for decrypting portions of the secure program is configured with a decryption key. 
     
     
       6. The apparatus of  claim 5 , wherein the decryption key is stored in a volatile memory. 
     
     
       7. The  An apparatus of  claim 6 ,  for executing a secure program in a computer system, wherein the ability to make workable copies of the secure program from the computer system is inhibited, the apparatus comprising:
   a program memory in which the secure program data is stored in an encrypted form;    
   a security chip coupled to the program memory, the security chip comprising:      means for decrypting portions of the secure program into a clear portion and a remainder portion, wherein the means for decrypting portions of the secure program is configured with a decryption key, wherein the decryption key is stored in a volatile memory, and  wherein the volatile memory is distributed over the security chip, the security chip further comprising overlying circuitry which overlies and obscures at least a part of the volatile memory;    
   means for providing the clear portion to memory locations accessible by a processor; and    
   remainder memory for storing the remainder portion of the secure program, the remainder memory not directly accessible by the processor;    
   means for requesting subsets of the remainder portion for use by the processor; and    
   means, within the security chip, for checking that the requested subset is within a valid predetermined set of requested subsets dependent on a stored state for the processor .  
 
     
     
       8. The apparatus of  claim 7 , wherein the overlying circuitry is coupled to a power source for the volatile memory such that the removal of the overlying circuitry removes the power to the overlying circuitry. 
     
     
       9. The apparatus of  claim 1 , further comprising:
 clocking means, within the security chip, for determining a rate of instruction execution of the processor; and  
 timing response means for rejecting processor requests when the clocking means determines that the rate is outside a range of normal operation for the processor.  
 
     
     
       10. The apparatus of  claim 1 , further comprising a data decompressor for decompressing the secure program after decryption, wherein the secure program is compressed before encryption. 
     
     
       11. The  An apparatus of  claim 10 ,  for executing a secure program in a computer system, wherein the ability to make workable copies of the secure program from the computer system is inhibited, the apparatus comprising:
   a program memory in which the secure program data is stored in an encrypted form;    
   a security chip coupled to the program memory, the security chip comprising:      means for decrypting portions of the secure program into a clear portion and a remainder portion;        means for providing the clear portion to memory locations accessible by a processor; and        remainder memory for storing the remainder portion of the secure program, the remainder memory not directly accessible by the processor;      
   means for requesting subsets of the remainder portion for use by the processor;    
   means, within the security chip, for checking that the requested subset is within a valid predetermined set of requested subsets dependent on a stored state for the processor; and    
   a data decompressor for decompressing the secure program after decryption, wherein the secure program is compressed before encryption,  wherein the decompressor is an entropy decoder.  
 
     
     
       12. The apparatus of  claim 1 , further comprising:
 checksum means, within the security chip, for determining a checksum of bus accesses on a processor bus; and  
 checksum response means for rejecting processor requests when the checksum does not match a predetermined checksum for those bus accesses.  
 
     
     
       13. The  An apparatus of  claim 1 ,  further comprising for executing a secure program in a computer system, wherein the ability to make workable copies of the secure program from the computer system is inhibited, the apparatus comprising:
   a program memory in which the secure program data is stored in an encrypted form;    
   a security chip coupled to the program memory, the security chip comprising:      means for decrypting portions of the secure program into a clear portion and a remainder portion;        means for providing the clear portion to memory locations accessible by a processor; and        remainder memory for storing the remainder portion of the secure program, the remainder memory not directly accessible by the processor;      
   means for requesting subsets of the remainder portion for use by the processor;    
   means, within the security chip, for checking that the requested subset is within a valid predetermined set of requested subsets dependent on a stored state for the processor; and    
 a data scrambler for reordering data elements of the secure program according to a reversible and deterministic pattern determined by a key value, wherein the secure program is reordered by the inverse of the data scrambler before being placed in the program memory.  
 
     
     
       14. The apparatus of  claim 13 , wherein the data scrambler comprises a plurality of first-in, first-out buffers. 
     
     
       15. The apparatus of  claim 13 , wherein the reversible and deterministic pattern is generated by reference to the output of a pseudorandom number generator. 
     
     
       16. The  An apparatus of  claim 1 ,  for executing a secure program in a computer system, wherein the ability to make workable copies of the secure program from the computer system is inhibited, the apparatus comprising:
   a program memory in which the secure program data is stored in an encrypted form;    
   a security chip coupled to the program memory, the security chip comprising:      means for decrypting portions of the secure program into a clear portion and a remainder portion,  wherein the means for decrypting portions of the secure program operates based on the key value and the output of a pseudorandom number generator;      means for providing the clear portion to memory locations accessible by a processor; and        remainder memory for storing the remainder portion of the secure program, the remainder memory not directly accessible by the processor;      
   means for requesting subsets of the remainder portion for use by the processor; and    
   means, within the security chip, for checking that the requested subset is within a valid predetermined set of requested subsets dependent on a stored state for the processor .  
 
     
     
       17. The apparatus of  claim 1 , further comprising means for altering the operation of the security chip and the program flow of the secure program when said means for checking detects that the requested subset is not within the valid predetermined set of subsets, whereby the altered operation causes a negative effect on the program flow or operation. 
     
     
       18. The apparatus of  claim 17 , wherein the means for altering is a means for halting the processor. 
     
     
       19. An apparatus for encrypting program data to prevent unauthorized copying, comprising:
 a branch separator for extracting branch statements from the program data;  
 a compressor for compressing the extracted branch statements and a remainder of the program data to form compressed data; and  
 an encryptor for encrypting the compressed data.  
 
     
     
       20. An apparatus for encrypting program data to prevent unauthorized copying, comprising:
 a branch separator for extracting branch statements from the program data comprising:  
 means for automatically generating checksum data representing checksums of program data; and  
 means for automatically generating timing information used to assess timing of program data processing;  
 a compressor for compressing the extracted branch statements, a remainder of the program data, the checksum data, and the timing information, to form compressed data; and  
 an encryptor for encrypting the compressed data.  
 
     
     
       21. A method of executing a secure program to prevent copying of the secure program in a usable form from information acquired over an insecure processor bus, the usable form being a copy which replaces the functionality of the original, comprising the steps of :
 accepting a request from a processor over the insecure processor bus for a block of program data, the block of program data including at least one of one or more program instructions or one or more program data elements;  
 decrypting, in a secure manner, the block of program data into a clear portion and a remainder portion;  
 providing the clear portion to the processor over the insecure processor bus; and  
 accepting requests from the processor over the insecure processor bus for elements of the remainder portion;  
 checking that the request is consistent with the state of the processor and previous requests;  
 processing the requests from the processor for elements of the remainder portion; and  
 responding to the requests with request responses, wherein the request responses do not contain enough information content to recreate the remainder portion with substantially less computational effort than required to create said remainder portion.  
 
     
     
       22. The method of  claim 21 , further comprising the steps of :
 separating a program into the clear portion and the remainder portion to form a secure program; and  
 encrypting the secure program prior to placing the secure program into an insecure memory.  
 
     
     
       23. The method of  claim 22 , wherein the step of  separating is a step of  a program into the clear portion and the remainder portion to form a secure program includes separating branch instructions of the program from other instructions of the program. 
     
     
       24. The method of  claim 21 , wherein the step of  decrypting is performed with a decryption key. 
     
     
       25. The method of  claim 24 , further comprising the step of  storing the decryption key in a volatile memory. 
     
     
       26. The  A method of  claim 25 , further comprising the steps of:  of executing a secure program to prevent copying of the secure program in a usable form from information acquired over an insecure processor bus, the usable form being a copy which replaces the functionality of the original, comprising the steps of:
   accepting a request from a processor over the insecure processor bus for a block of program data, the block of program data including at least one of one or more program instructions or one or more program data elements;    
   decrypting, in a secure manner, the block of program data into a clear portion and a remainder portion, wherein the decrypting is performed with a decryption key;    
   storing the decryption key in a volatile memory;   
 providing a power source to the volatile memory;  
 covering the volatile memory with a circuit such that the power source is removed from the volatile memory when the circuit is disturbed and the circuit shields the volatile memory from probing;  
   providing the clear portion to the processor over the insecure processor bus;    
   accepting requests from the processor over the insecure processor bus for elements of the remainder portion;    
   checking that the request is consistent with the state of the processor and previous requests;    
   processing the requests from the processor for elements of the remainder portion; and    
   responding to the requests with request responses, wherein the request responses do not contain enough information content to recreate the remainder portion with substantially less computational effort than required to crate said remainder portion .  
 
     
     
       27. The method of  claim 21 , further comprising the step of  checking a rate of instruction execution of the processor prior to providing a request response. 
     
     
       28. The method of  claim 21 , further comprising the step of  decompressing the secure program after decryption, wherein the secure program is compressed before encryption. 
     
     
       29. The method of  claim 21 , further comprising the steps of :
 determining a checksum of bus accesses on a processor bus;  
 comparing the checksum to a precalculated checksum for a set of instructions of the secure program which are executed under normal operation; and  
 preventing the unobstructed operation of the secure program when the checksum and the precalculated checksum differ.  
 
     
     
       30. The  A method of  claim 21 , further comprising the steps of:  of executing a secure program to prevent copying of the secure program in a usable form from information acquired over an insecure processor bus, the usable form being a copy which replaces the functionality of the original, comprising:
   accepting a request from a processor over the insecure processor bus for a block of program data, the block of program data including at least one of one or more program instructions or one or more program data elements;    
   decrypting, in a secure manner, the block of program data into a clear portion and a remainder portion;    
   providing the clear portion to the processor over the insecure processor bus;    
   accepting requests from the processor over the insecure processor bus for elements of the remainder portion;    
   checking that the request is consistent with the state of the processor and previous requests;    
   processing the requests from the processor for elements of the remainder portion;    
   responding to the requests with request responses, wherein the request responses do not contain enough information content to recreate the remainder portion with substantially less computational effort than required to create said remainder portion;   
 scrambling an order of data elements of the secure program according to a reversible and deterministic pattern determined by a key value prior to storage in an insecure memory; and  
 descrambling the order of the data elements upon proper request of the processor.  
 
     
     
       31. The method of  claim 30 , wherein the step of  scrambling comprises a step of  generating a pseudorandom number used to form the reversible and deterministic pattern. 
     
     
       32. The method for encrypting a program to prevent unauthorized copying, comprising the steps of :
 separating program code according to sequences of non-branch instructions and branch instructions;  
 compressing the nonbranch instructions to form a first set of compressed data;  
 compressing the branch instructions to form a second set of compressed data; and  
 encrypting the first and second sets of compressed data.  
 
     
     
       33. An apparatus for executing a secure program in an insecure computer system, wherein the ability to make workable copies of the secure program during execution of the secure program using the insecure computer system is inhibited, a workable copy being a copy which replaces the functionality of the original secure program, the apparatus comprising:
 a program memory in which the secure program,  data is stored in an encrypted form;  
 a security chip coupled between the program memory and adapted to be coupled to a processor over an accessible processor bus, the security chip comprising:  
 means for decrypting portions of the secure program into a clear portion and a remainder portion;  
 means for providing the clear portion to memory locations accessible by the processor; and  
 remainder memory for storing the remainder portion of the secure program, the remainder memory not directly accessible by the processor except via the security chip;  
 means for requesting subsets of the remainder portion for use by the processor; and  
 means, within the, security chip, for checking that the requested subset is within a valid predetermined set of requested subsets given a stored state for the processor.  
 
     
     
       34. A method of executing a secure program comprising:
   receiving a first request for program information having a plurality of instructions;        determining if the first request is proper;        sending a first subset of requested program information if the request is proper;        maintaining information regarding a second subset of the requested program information, the second subset relating to at least one instruction in the requested program information not included in the first subset;        receiving a second request corresponding to an instruction of the requested program information not in the first subset; and        sending information corresponding to the instruction to allow continued execution of the program information as if the instruction had been included in the first subset.     
     
     
       35. The method defined in  claim 34  wherein receiving the first request comprises receiving a pointer to a compressed data set. 
     
     
       36. The method defined in  claim 35  wherein the pointer comprises an ID associated with the compress data set whose creation occurred at time of encryption. 
     
     
       37. The method defined in  claim 34  further comprising preventing continued execution of the program in a manner that the program was originally designed to be executed if the first request is determined to be improper. 
     
     
       38. The method defined in  claim 37  wherein preventing continued operation comprises halting program execution. 
     
     
       39. The method defined in  claim 37  wherein preventing continued operation comprises altering program flow. 
     
     
       40. The method defined in  claim 37  wherein preventing continued operation comprises causing degradation of program execution performance. 
     
     
       41. A method for executing a secure program comprising:
   receiving a first request for program information having a plurality of instructions;        determining if the first request is proper;        sending a first subset of requested program information if the request is proper;        maintaining information regarding a second subset of the requested program information, the second subset relating to at least one instruction in the requested program information not included in the first subset;        receiving a second request corresponding to an instruction of the requested program information not in the first subset; and        sending information corresponding to the instruction to allow continued execution of the program information as if the instruction had been included in the first subset; and        preventing continued execution of the program in a manner that the program was originally designed to be executed if the first request is determined to be improper, wherein preventing continued operation comprises erasing a portion of the program stored in memory.     
     
     
       42. The method defined in  claim 34  further comprising accessing the requested program information from memory. 
     
     
       43. The method defined in  claim 42  further comprising translating at least a portion of the requested program information. 
     
     
       44. The method defined in  claim 42  further comprising decrypting the requested program information. 
     
     
       45. The method defined in  claim 34  further comprising separating the requested program information between the first subset and a second subset. 
     
     
       46. The method defined in  claim 34  wherein maintaining information regarding a second subset comprises storing a branch table with information relating to execution of the at least one instruction. 
     
     
       47. The method defined in  claim 34  wherein maintaining information regarding a second subset comprises storing checksum information relating to execution of instructions in the requested program information. 
     
     
       48. The method defined in  claim 34  wherein maintaining information regarding a second subset comprises storing timing information relating to execution of instructions in the requested program information. 
     
     
       49. The method defined in  claim 34  wherein receiving the second request comprises receiving a branch request. 
     
     
       50. The method defined in  claim 49  further comprising determining if the branch request is proper. 
     
     
       51. The method defined in  claim 50  further comprising halting execution of instructions in the program information if the branch request is improper. 
     
     
       52. The method defined in  claim 34  wherein the instruction information comprises a branch address. 
     
     
       53. An apparatus for executing a secure program comprising:
   means for receiving a first request for program information having a plurality of instructions;        means for determining if the first request is proper;        means for sending a first subset of requested program information if the request is proper;        means for maintaining information regarding a second subset of the requested program information, the second subset relating to at least one instruction in the requested program information not included in the first subset;        means for receiving a second request corresponding to an instruction of the requested program information not in the first subset; and        means for sending information corresponding to the instruction to allow continued execution of the program information as if the instruction had been included in the first subset.     
     
     
       54. The apparatus defined in  claim 53  wherein the means for receiving the first request comprises means for receiving a pointer to a compressor data set. 
     
     
       55. The apparatus defined in  claim 54  wherein the pointer comprises an ID associated with the compress data set whose creation occurred at time of encryption. 
     
     
       56. The apparatus defined in  claim 53  further comprising means for preventing continued execution of the program in a manner that the program was originally designed to be executed if the first request is determined to be improper. 
     
     
       57. The apparatus defined in  claim 53  further comprising means for accessing the requested program information from memory. 
     
     
       58. The apparatus defined in  claim 57  further comprising means for translating at least a portion of the requested program information. 
     
     
       59. The apparatus defined in  claim 57  further comprising means for decrypting the requested program information. 
     
     
       60. The apparatus defined in  claim 53  further comprising means for separating the requested program information between the first subset and a second subset. 
     
     
       61. The apparatus defined in  claim 53  wherein the means for maintaining information regarding a second subset comprises means for storing a branch table with information relating to execution of the at least one instruction. 
     
     
       62. The apparatus defined in  claim 53  wherein the means for maintaining information regarding a second subset comprises means for storing checksum information relating to execution of instructions in the requested program information. 
     
     
       63. The apparatus defined in  claim 53  wherein the means for maintaining information regarding a second subset comprises means for storing timing information relating to execution of instructions in the requested program information. 
     
     
       64. The apparatus defined in  claim 53  wherein the means for receiving the second request comprises means for receiving a branch request. 
     
     
       65. The apparatus defined in  claim 64  further comprising means for determining if the branch request is proper. 
     
     
       66. The apparatus defined in  claim 65  further comprising means for halting execution of instructions in the program information if the branch request is improper. 
     
     
       67. The apparatus defined in  claim 53  wherein the instruction information comprises a branch address. 
     
     
       68. An article of manufacture comprising one or more recordable media having executable instructions stored thereon which, when executed by a system, cause the processor to:
   receive a first request for program information having a plurality of instructions;        determine if the first request is proper;        send a first subset of requested program information if the request is proper;        maintain information regarding a second subset of the requested program information, the second subset relating to at least one instruction in the requested program information not included in the first subset;        receive a second request corresponding to an instruction of the requested program information not in the first subset; and        send information corresponding to the instruction to allow continued execution of the program information as if the instruction had been included in the first subset.     
     
     
       69. An apparatus for executing a secure program comprising:
   an input to receive a first request for program information having a plurality of instructions;        a processing unit to determine if the first request is proper and to send a first subset of requested program information if the request is proper;        a memory to store information regarding a second subset of the requested program information, the second subset relating to at least one instruction in the requested program information not included in the first subset; and        wherein the input receives a second request corresponding to an instruction of the requested program information not in the first subset, and, in response thereto, the processing unit access the memory and sends information corresponding to the instruction and generated in response to the memory access to allow continued execution of the program information as if the instruction had been included in the first subset.     
     
     
       70. The apparatus defined in  claim 69  wherein the input receives a pointer to a compressed data set, the pointer comprising an ID associated with the compress data set whose creation occurred at time of encryption. 
     
     
       71. The apparatus defined in  claim 69  wherein the processing unit prevents continued execution of the program in a manner that the program was originally designed to be executed if the first request is determined to be improper. 
     
     
       72. The apparatus defined in  claim 69  wherein the processing unit accesses the program from memory and translates at least a portion of the requested program information. 
     
     
       73. The apparatus defined in  claim 69  wherein the processing unit accesses the program from memory and decrypts the requested program information. 
     
     
       74. The apparatus defined in  claim 69  wherein the processing unit separates the requested program information between the first subset and a second subset. 
     
     
       75. The apparatus defined in  claim 69  wherein the memory stores information regarding a second subset comprises means for storing a branch table with information relating to execution of the at least one instruction. 
     
     
       76. The apparatus defined in  claim 69  wherein the memory stores information regarding a second subset comprises means for storing checksum information relating to execution of instructions in the requested program information. 
     
     
       77. The apparatus defined in  claim 69  wherein the memory stores information regarding a second subset comprises means for storing timing information relating to execution of instructions in the requested program information. 
     
     
       78. The apparatus defined in  claim 69  wherein the second request comprises a branch request. 
     
     
       79. The apparatus defined in  claim 78  wherein the processing unit determines if the branch request is proper and sends a branch address if the branch request is proper. 
     
     
       80. A method for a processor to execute a program comprising:
   generating a first request for program information;        receiving a portion of the program information requested;        executing instructions in the received program information, including        generating a second request if program information encountered during execution corresponds to an instruction of a first type that must be executed to continue execution of the program yet is not included in the received program information;        receiving non - instruction data in response to the second request; and        operating on the non - instruction data to continue execution of the program as if the instruction had been executed by the processor.     
     
     
       81. An apparatus for executing a program comprising:
   means for generating a first request for program information;        means for receiving a portion of the program information requested; and        means for executing instructions in the received program information, including:      means for generating a second request if program information encountered during execution corresponds to an instruction of a first type that must be executed to continue execution of the program yet is not included in the received program information;        means for receiving non - instruction data in response to the second request; and        means for operating on the non - instruction data to continue execution of the program as if the instruction had been executed by the processor.       
     
     
       82. An article of manufacture comprising one or more recordable media with executable instructions stored thereon which, when executed by a system, cause the system to:
   generate a first request for program information;        receive a portion of the program information requested; and        execute instructions in the received program information by generating a second request if program information encountered during execution corresponds to an instruction of a first type that must be executed to continue execution of the program yet is not included in the received program information;        receiving non - instruction data in response to the second request; and        operating on the non - instruction data to continue execution of the program as if the instruction had been executed by the processor.     
     
     
       83. A method of executing a secure program comprising:
   providing a first portion of a program to a processor over an insecure processor bus;        accepting a request from the processor over the insecure processor bus for elements of a second portion of the program not included in the first portion of the program needed to continue execution of the program;        determining whether the request is consistent with expected processor state and any previous requests;        processing the request from the processor for elements of the second portion of the program; and        sending a response to the request to enable continued execution of the program by the processor without the processor executing an instruction in the second portion of the program.     
     
     
       84. The method defined in  claim 83  wherein the response comprises a branch address. 
     
     
       85. The method defined in  claim 83  wherein the response comprises a branch address to which the processor jumps so that the processor doesn't execute the branch instruction that would have caused the processor to perform such a jump. 
     
     
       86. An apparatus for executing a secure program comprising:
   means for providing a first portion of a program to a processor over an insecure processor bus;        means for accepting a request from the processor over the insecure processor bus for elements of a second portion of the program not included in the first portion of the program needed to continue execution of the program;        means for determining whether the request is consistent with expected processor state and any previous requests;        means for processing the request from the processor for elements of the second portion of the program; and        means for sending a response to the request to enable continued execution of the program by the processor without the processor executing an instruction in the second portion of the program.     
     
     
       87. The apparatus defined in  claim 86  wherein the response comprises a branch address. 
     
     
       88. The apparatus defined in  claim 86  wherein the response comprises a branch address to which the processor jumps so that the processor doesn't execute the branch instruction that would have caused the processor to perform such a jump. 
     
     
       89. An article of manufacture comprising one or more recordable media with executable instructions stored thereon which, when executed by a system, cause the system to:
   provide a first portion of a program to a processor over an insecure processor bus;        accept a request from the processor over the insecure processor bus for elements of a second portion of the program not included in the first portion of the program needed to continue execution of the program;        determine whether the request is consistent with expected processor state and any previous requests;        process the request from the processor for elements of the second portion of the program if the request is determined to be consistent; and        send a response to the request to enable continued execution of the program by the processor without the processor executing an instruction in the second portion of the program.     
     
     
       90. An apparatus for executing a secure program in cooperation with a processor, the apparatus comprising:
   a memory;        a processing unit coupled to the memory and the input, wherein the processing unit provides a first portion of a program to the processor over an insecure processor bus;        an input to accept a request from the processor over the insecure processor bus for elements of a second portion of the program not included in the first portion of the program needed to continue execution of the program, and        wherein the processing unit determines whether the request is consistent with expected processor state and any previous requests and processes the request for elements of the second portion of the program if the request is consistent, and thereafter sends a response to the request to enable continued execution of the program by the processor without the processor executing an instruction in the second portion of the program.     
     
     
       91. The apparatus defined in  claim 90  wherein the response comprises a branch address. 
     
     
       92. The apparatus defined in  claim 90  wherein the response comprises a branch address to which the processor jumps so that the processor doesn't execute the branch instruction that would have caused the processor to perform such a jump. 
     
     
       93. An apparatus for executing a program in a computer system, the apparatus comprising:
   a program memory to store the program data in a secure manner;        a security chip coupled to the program memory, the security chip comprising:      means for providing a first portion of the program data to memory locations accessible by a processor; and        a memory for storing a second portion of the program data not included in the first portion, the memory not directly accessible by the processor;          means for requesting subsets of the second portion of the program data for use by the processor; and        means, within the security chip, for determining whether the request is proper based on stored processor state information and for providing information that allows continued execution of instructions in the program data even though the processor does not execute each of the instruction itself.

Join the waitlist — get patent alerts

Track USRE40405E — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.