Invention Grant
US09398019B2 Verifying caller authorization using secret data embedded in code
有权
使用嵌入代码中的秘密数据验证来电者授权
- Patent Title: Verifying caller authorization using secret data embedded in code
- Patent Title (中): 使用嵌入代码中的秘密数据验证来电者授权
-
Application No.: US14500779Application Date: 2014-09-29
-
Publication No.: US09398019B2Publication Date: 2016-07-19
- Inventor: Rakesh Agarwal
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Patterson & Sheridan LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F9/455

Abstract:
In a computer system operable at more than one privilege level, confidential code is securely customized to use secret data to establish a code protection domain without disclosing the secret data to a managing operating system. In operation, a security module executes at a higher privilege level than both the managing operating system and the confidential code. After the managing operating system loads the executable of the confidential code, the security module injects the secret data directly into an authorization instruction and a verification instruction included in the confidential code and then sets both the authorization instruction and the verification instruction as executable-only. As the confidential code executes at the assigned privilege level, the authorization instruction and the verification instruction use the secret data to distinguish between unauthorized and authorized execution of the confidential code.
Public/Granted literature
- US20160044041A1 VERIFYING CALLER AUTHORIZATION USING SECRET DATA EMBEDDED IN CODE Public/Granted day:2016-02-11
Information query