Securing secret data embedded in code against compromised interrupt and exception handlers
Abstract
In a computer system operable at more than one privilege level, an interrupt security module handles interrupts without exposing a secret value of a register to virtual interrupt handling code that executes at a lower privilege level than the interrupt security module. The interrupt security module is configured to intercept interrupts generated while executing code at lower privilege levels. Upon receiving such an interrupt, the interrupt security module overwrites the secret value of the register with an unrelated constant. Subsequently, the interrupt security module generates a virtual interrupt corresponding to the interrupt and forwards the virtual interrupt to the virtual interrupt handling code. Advantageously, although the virtual interrupt handling code is able to determine the value of the register and consequently the unrelated constant, the virtual interrupt handling code is unable to determine the secret value.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method of securing secret values stored in registers in a computer system, the method comprising:
intercepting, by a first process executing at a first privilege level, a first interrupt or exception that is targeted to be handled by a second process executing instructions at a second privilege level lower than the first privilege level, the instructions including a move instruction that sets a register to a secret value by moving an immediate value in the move instruction into the register, wherein the first interrupt or exception is triggered during execution of the instructions; in response to the intercepting, overwriting, by the first process, the secret value stored in the register with a value; and after the overwriting, forwarding, by the first process, the first interrupt or exception to the second process for handling of the first interrupt or exception by the second process.
2 . The method of claim 1 ,
wherein the registers in the computer system include a subset of the registers that further includes the register and other registers, the other registers containing secret values, and further comprising, in response to the intercepting, overwriting, by the first process, the secret values stored in the other registers with one or more values while retaining values stored in the registers that are not included in the subset.
3 . The method of claim 1 , wherein the instructions further comprise one or more instructions for comparing content of the register to the value.
4 . The method of claim 3 , wherein the instructions further comprise one or more instructions for executing confidential code, and wherein the second process interprets the register including the value as a trigger to re-execute the instructions.
5 . The method of claim 3 , wherein the value comprises a predetermined erasure constant.
6 . The method of claim 1 , further comprising:
intercepting a second interrupt; determining that the second interrupt is disabled; identifying an instruction that is affected by the second interrupt; and causing the instruction that is affected by the second interrupt to execute at the first privilege level without forwarding the second interrupt for handling at the second privilege level.
7 . The method of claim 1 , wherein the value is a random number.
8 . A computer system comprising:
registers; and at least one processor configured to:
intercept, by a first process executing at a first privilege level, a first interrupt or exception that is targeted to be handled by a second process executing instructions at a second privilege level lower than the first privilege level, the instructions including a move instruction that sets a register to a secret value by moving an immediate value in the move instruction into the register, wherein the first interrupt or exception is triggered during execution of the instructions;
in response to the intercepting, overwrite, by the first process, the secret value stored in the register with a value; and
after the overwriting, forward, by the first process, the first interrupt or exception to the second process for handling of the first interrupt or exception by the second process.
9 . The computer system of claim 8 ,
wherein the registers in the computer system include a subset of the registers that further includes the register and other registers, the other registers containing secret values, and wherein the at least one processor is further configured to, in response to the intercepting, overwrite, by the first process, the secret values stored in the other registers with one or more values while retaining values stored in the registers that are not included in the subset.
10 . The computer system of claim 8 , wherein the instructions further comprise one or more instructions for comparing content of the register to the value.
11 . The computer system of claim 10 , wherein the instructions further comprise one or more instructions for executing confidential code, and wherein the second process interprets the register including the value as a trigger to re-execute the instructions.
12 . The computer system of claim 10 , wherein the value comprises a predetermined erasure constant.
13 . The computer system of claim 8 , wherein the at least one processor is further configured to:
intercept a second interrupt; determine that the second interrupt is disabled; identify an instruction that is affected by the second interrupt; and cause the instruction that is affected by the second interrupt to execute at the first privilege level without forwarding the second interrupt for handling at the second privilege level.
14 . The computer system of claim 8 , wherein the value is a random number.
15 . A non-transitory computer readable medium comprising instructions, that when executed by a computer system, cause the computer system to perform a method of securing secret values stored in registers in the computer system, the method comprising:
intercepting, by a first process executing at a first privilege level, a first interrupt or exception that is targeted to be handled by a second process executing instructions at a second privilege level lower than the first privilege level, the instructions including a move instruction that sets a register to a secret value by moving an immediate value in the move instruction into the register, wherein the first interrupt or exception is triggered during execution of the instructions; in response to the intercepting, overwriting, by the first process, the secret value stored in the register with a value; and after the overwriting, forwarding, by the first process, the first interrupt or exception to the second process for handling of the first interrupt or exception by the second process.
16 . The non-transitory computer readable medium of claim 15 ,
wherein the registers in the computer system include a subset of the registers that further includes the register and other registers, the other registers containing secret values, and wherein the method further comprises, in response to the intercepting, overwriting, by the first process, the secret values stored in the other registers with one or more values while retaining values stored in the registers that are not included in the subset.
17 . The non-transitory computer readable medium of claim 15 , wherein the instructions further comprise one or more instructions for comparing content of the register to the value.
18 . The non-transitory computer readable medium of claim 17 , wherein the instructions further comprise one or more instructions for executing confidential code, and wherein the second process interprets the register including the value as a trigger to re-execute the instructions.
19 . The non-transitory computer readable medium of claim 17 , wherein the value comprises a predetermined erasure constant.
20 . The non-transitory computer readable medium of claim 15 , wherein the method further comprises:
intercepting a second interrupt; determining that the second interrupt is disabled; identifying an instruction that is affected by the second interrupt; and causing the instruction that is affected by the second interrupt to execute at the first privilege level without forwarding the second interrupt for handling at the second privilege level.Join the waitlist — get patent alerts
Track US2021124824A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.