Systems and methods for hiding operating system kernel data in system management mode memory to thwart user mode side-channel attacks
摘要:
Systems and methods are provided that may be implemented to hide operating system kernel data in system management mode memory. An information handling system includes a system memory, central processing unit (CPU), and Basic Input Output System (BIOS). The CPU is operable in a system management mode and is programmable to specify an SMM region of the system memory that is only accessible when the CPU is operating in the SMM. The BIOS is programmed to save kernel data from a non-SMM region of the system memory to the SMM region and then clear the kernel data from the non-SMM region in response to an operating system (OS) generating a system management interrupt (SMI) and to restore the kernel data to the non-SMM region of the system memory from the SMM region in response to the OS generating a SMI.
信息查询
0/0