US2023030961A1PendingUtilityA1

Virtualization-based platform protection technology

Assignee: INTEL CORPPriority: Jun 15, 2015Filed: Sep 30, 2022Published: Feb 2, 2023
Est. expiryJun 15, 2035(~8.9 yrs left)· nominal 20-yr term from priority
G06F 21/53G06F 9/45558G06F 12/109G06F 12/023G06F 12/145G06F 2212/151G06F 9/485G06F 21/57G06F 2221/2149G06F 12/1491G06F 2009/45583G06F 2009/45587G06F 2212/651G06F 12/1009G06F 21/60G06F 21/51G06F 2212/1052G06F 9/45545
68
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A data processing system (DPS) uses platform protection technology (PPT) to protect some or all of the code and data belonging to certain software modules. The PPT may include a virtual machine monitor (VMM) to enable an untrusted application and a trusted application to run on top of a single operating system (OS), while preventing the untrusted application from accessing memory used by the trusted application. The VMM may use a first extended page table (EPT) to translate a guest physical address (GPA) into a first host physical address (HPA) for the untrusted application. The VMM may use a second EPT to translate the GPA into a second HPA for the trusted application. The first and second EPTs may map the same GPA to different HPAs. Other embodiments are described and claimed.

Claims

exact text as granted — not AI-modified
1 .- 16 . (canceled) 
     
     
         17 . A method comprising:
 generating, by a data processing system, a secret cookie value (SCV) for a trusted application to run on top of an operating system (OS) in a virtual machine (VM);   saving, by the data processing system, the SCV to a platform protection technology (PPT) data structure associated with the trusted application;   patching, by the data processing system, the SCV into trampoline code that provides for transferring control from an untrusted application to the trusted application;   determining, by the data processing system and in response to the untrusted application calling the trusted application and before allowing the trusted application to execute, whether the trampoline code and the PPT data structure contain matching SCVs; and   allowing, by the data processing system, the trusted application to execute only if the trampoline code and the PPT structure contain matching SCVs.   
     
     
         18 . The method of  claim 17 , wherein the PPT comprises trusted interrupt service routines (ISRs) and the trusted ISRs comprises a trusted application (TA)-enter ISR,
 switching, by the TA-enter ISR, the data processing system from an untrusted memory view associated with the untrusted application to a trusted memory view associated with the trusted application; and   determining, by the TA-enter ISR, whether the trampoline code and the PPT data structure contain matching SCV s.   
     
     
         19 . The method of  claim 17 , wherein the PPT data structure associated with the trusted application resides outside of the VM. 
     
     
         20 . A data processing system comprising:
 one or more processors; and   one or more memory devices coupled to the one or more processors, the one or more processors to:   generate a secret cookie value (SCV) for a trusted application to run on top of an operating system (OS) in a virtual machine (VM);   save the SCV to a platform protection technology (PPT) data structure associated with the trusted application;   patch the SCV into trampoline code that provides for transferring control from an untrusted application to the trusted application;   determine, in response to the untrusted application calling the trusted application and before allowing the trusted application to execute, whether the trampoline code and the PPT data structure contain matching SCVs; and   allow the trusted application to execute only if the trampoline code and the PPT structure contain matching SCVs.   
     
     
         21 . The data processing system of  claim 20 , wherein the PPT comprises trusted interrupt service routines (ISRs) and the trusted ISRs comprises a trusted application (TA)-enter ISR, and wherein the plurality of instructions, when executed, further cause the data processing system to:
 switch, by the TA-enter ISR, the data processing system from an untrusted memory view associated with the untrusted application to a trusted memory view associated with the trusted application; and   determine, by the TA-enter ISR, whether the trampoline code and the PPT data structure contain matching SCV s.   
     
     
         22 . The data processing system of  claim 20 , wherein the PPT data structure associated with the trusted application resides outside of the VM. 
     
     
         23 . An apparatus comprising:
 one or more processors to:   generate a secret cookie value (SCV) for a trusted application to run on top of an operating system (OS) in a virtual machine (VM);   save the SCV to a platform protection technology (PPT) data structure associated with the trusted application;   patch the SCV into trampoline code that provides for transferring control from an untrusted application to the trusted application;   determine, in response to the untrusted application calling the trusted application and before allowing the trusted application to execute, whether the trampoline code and the PPT data structure contain matching SCVs; and   allow the trusted application to execute only if the trampoline code and the PPT structure contain matching SCVs.   
     
     
         24 . The apparatus of  claim 23 , wherein the PPT comprises trusted interrupt service routines (ISRs) and the trusted ISRs comprises a trusted application (TA)-enter ISR, and wherein the plurality of instructions, when executed, further cause the data processing system to:
 switch, by the TA-enter ISR, the data processing system from an untrusted memory view associated with the untrusted application to a trusted memory view associated with the trusted application; and   determine, by the TA-enter ISR, whether the trampoline code and the PPT data structure contain matching SCV s.   
     
     
         25 . The apparatus of  claim 23 , wherein the PPT data structure associated with the trusted application resides outside of the VM. 
     
     
         26 . A computer-readable medium having stored thereon instructions which, when executed, cause a computing device to perform operations comprising:
 generating a secret cookie value (SCV) for a trusted application to run on top of an operating system (OS) in a virtual machine (VM);   saving the SCV to a platform protection technology (PPT) data structure associated with the trusted application;   patching, the SCV into trampoline code that provides for transferring control from an untrusted application to the trusted application;   determining, in response to the untrusted application calling the trusted application and before allowing the trusted application to execute, whether the trampoline code and the PPT data structure contain matching SCVs; and   allowing the trusted application to execute only if the trampoline code and the PPT structure contain matching SCVs.   
     
     
         27 . The computer-readable medium of  claim 26 , wherein the PPT comprises trusted interrupt service routines (ISRs) and the trusted ISRs comprises a trusted application (TA)-enter ISR,
 switching, by the TA-enter ISR, the data processing system from an untrusted memory view associated with the untrusted application to a trusted memory view associated with the trusted application; and   determining, by the TA-enter ISR, whether the trampoline code and the PPT data structure contain matching SCV s.   
     
     
         28 . The computer-readable medium of  claim 26 , wherein the PPT data structure associated with the trusted application resides outside of the VM.

Join the waitlist — get patent alerts

Track US2023030961A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.