検索に戻る
案件記録

TRUSTED EXECUTION MEMORY PROTECTION USING AN ACCESS CONTROL DATA STRUCTURE AND A SPECIAL ACCESS CONTROL DATA CACHE IN HARDWARE

発明審査中
20請求項 · 3 独立
§ Ⅰ

案件概要

発明者

Gideon Gerzon; Chaimy Stern; Arie Aharon

IPC分類

G6F 21/52

CPC分類

G6F21/52G6F2221/33

Techniques for trusted execution memory protection using an access control data structure and a special access control data cache in a memory management circuit are described. In certain examples, a computer system includes a memory; a hardware processor core to implement a trust domain manager to manage one or more hardware isolated virtual machines as a respective trust domain with a region of protected memory of the memory; and a memory management circuit coupled between the hardware processor core and the memory, wherein the memory management circuit is to: include a set secure memory transaction bit with a first memory access request by the one or more hardware isolated virtual machines for the region of protected memory of the respective trust domain, allow the first memory access request by the one or more hardware isolated virtual machines for the region of protected memory of the respective trust domain in response to the set secure memory transaction bit, and the memory management circuit is to further: allow a second memory access request, generated externally from the one or more hardware isolated virtual machines, for the region of protected memory of the respective trust domain in response to a secure memory transaction bit of the second memory access request not being set, and an entry in an access control data structure for a memory page for the second memory access request having a secure memory attribute bit not being set, and deny the second memory access request, generated externally from the one or more hardware isolated virtual machines, for the region of protected memory of the respective trust domain in response to the secure memory transaction bit of the second memory access request not being set, and the entry in the access control data structure for the memory page for the second memory access request having the secure memory attribute bit being set.

原文(中国語)

Techniques for trusted execution memory protection using an access control data structure and a special access control data cache in a memory management circuit are described. In certain examples, a computer system includes a memory; a hardware processor core to implement a trust domain manager to manage one or more hardware isolated virtual machines as a respective trust domain with a region of protected memory of the memory; and a memory management circuit coupled between the hardware processor core and the memory, wherein the memory management circuit is to: include a set secure memory transaction bit with a first memory access request by the one or more hardware isolated virtual machines for the region of protected memory of the respective trust domain, allow the first memory access request by the one or more hardware isolated virtual machines for the region of protected memory of the respective trust domain in response to the set secure memory transaction bit, and the memory management circuit is to further: allow a second memory access request, generated externally from the one or more hardware isolated virtual machines, for the region of protected memory of the respective trust domain in response to a secure memory transaction bit of the second memory access request not being set, and an entry in an access control data structure for a memory page for the second memory access request having a secure memory attribute bit not being set, and deny the second memory access request, generated externally from the one or more hardware isolated virtual machines, for the region of protected memory of the respective trust domain in response to the secure memory transaction bit of the second memory access request not being set, and the entry in the access control data structure for the memory page for the second memory access request having the secure memory attribute bit being set.

外部リソース