Invention Grant
- Patent Title: Securing secret data embedded in code against compromised interrupt and exception handlers
-
Application No.: US14550881Application Date: 2014-11-21
-
Publication No.: US10922402B2Publication Date: 2021-02-16
- Inventor: Wei Xu , Alok Nemchand Kataria , Rakesh Agarwal , Martim Carbone
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Patterson + Sheridan, LLP
- Main IPC: G06F21/53
- IPC: G06F21/53 ; G06F13/24

Abstract:
In a computer system operable at more than one privilege level, an interrupt security module handles interrupts without exposing a secret value of a register to virtual interrupt handling code that executes at a lower privilege level than the interrupt security module. The interrupt security module is configured to intercept interrupts generated while executing code at lower privilege levels. Upon receiving such an interrupt, the interrupt security module overwrites the secret value of the register with an unrelated constant. Subsequently, the interrupt security module generates a virtual interrupt corresponding to the interrupt and forwards the virtual interrupt to the virtual interrupt handling code. Advantageously, although the virtual interrupt handling code is able to determine the value of the register and consequently the unrelated constant, the virtual interrupt handling code is unable to determine the secret value.
Public/Granted literature
- US20160147993A1 SECURING SECRET DATA EMBEDDED IN CODE AGAINST COMPROMISED INTERRUPT AND EXCEPTION HANDLERS Public/Granted day:2016-05-26
Information query