TW201719489A

Encryption of executables in computational memory

Abstract

The present invention relates to the encryption of executable instructions in computing memory. The computing memory can traverse an operating system page table in the computing memory to find a page marked as an executable command. In response to finding a page marked as an executable command, the computing memory can determine whether the page marked as an executable command is encrypted. In response to determining that the page marked as an executable instruction is not encrypted, the computing memory can generate a key for the page marked as an executable instruction. The computing memory can use the key to encrypt the page marked as executable.

TW201719489A, drawing sheet 1
Sheet 1 of 1

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

25 claims: 8 independent, 17 dependent

  1. 1
    A method comprising:traversing an operating system page table in the computing memory by computing memory to find a page marked as an executable command;in response to finding a page marked as an executable command, determining that the label is Whether the page of the executable instruction is encrypted;in response to determining that the page marked as an executable instruction is not encrypted, a key is generated for the page marked as an executable instruction;and the key is used to encrypt the instruction marked as executable This page. 一種方法,其包括: 藉由計算記憶體周遊該計算記憶體中之一作業系統頁面表以尋找標記為可執行指令之一頁面; 回應於尋找到標記為可執行指令之一頁面,判定標記為可執行指令之該頁面是否已加密; 回應於判定標記為可執行指令之該頁面未加密,針對標記為可執行指令之該頁面產生一密鑰;及 使用該密鑰加密標記為可執行指令之該頁面。
  2. 8
    A method comprising:traversing an operating system page table in the computing memory by computing memory to find any page marked as an executable command;in response to finding a first page marked as an executable command, determining Whether the first page marked as an executable instruction is encrypted;in response to determining that the first page marked as an executable instruction is not encrypted, a first key is generated for the first page marked as an executable instruction;using the The first key encrypts the first page marked as an executable instruction;in response to finding a second page marked as an executable instruction, it is determined whether the second page marked as an executable instruction is encrypted;in response to the determination mark The second page that is an executable instruction is not encrypted, and a second key is generated for the second page marked as an executable instruction;and the second key is used to encrypt the second page that is marked as an executable instruction. 一種方法,其包括: 藉由計算記憶體周遊該計算記憶體中之一作業系統頁面表以尋找標記為可執行指令之任何頁面; 回應於尋找到標記為可執行指令之一第一頁面,判定標記為可執行指令之該第一頁面是否已加密; 回應於判定標記為可執行指令之該第一頁面未加密,針對標記為可執行指令之該第一頁面產生一第一密鑰; 使用該第一密鑰加密標記為可執行指令之該第一頁面; 回應於尋找到標記為可執行指令之一第二頁面,判定標記為可執行指令之該第二頁面是否已加密; 回應於判定標記為可執行指令之該第二頁面未加密,針對標記為可執行指令之該第二頁面產生一第二密鑰;及 使用該第二密鑰加密標記為可執行指令之該第二頁面。
  3. 11
    A non-transitory computer-readable medium that stores instructions executable by computing memory to:determine whether a requested page of the instructions marked as executable in the computing memory is encrypted;in response to determining that the requested page is not encrypted: Store the requested page in the cache area of the computing memory;generate a key;use the key to encrypt the requested page;and replace the requested page and store the encrypted page in the computing memory And in response to determining that the requested page is encrypted: generate a new key;use the new key to re-encrypt the requested page;replace the requested page, and store the re-encrypted page in the computing memory ;And decrypt the requested page and store the decrypted page in the cache area of the computing memory. 一種非暫態電腦可讀媒體,其儲存可由計算記憶體執行之指令以: 判定該計算記憶體中之標記為可執行指令之一經請求頁面是否已加密; 回應於判定該經請求頁面未加密: 將該經請求頁面儲存於該計算記憶體之快取區中; 產生一密鑰; 使用該密鑰加密該經請求頁面;及 取代該經請求頁面,將該已加密頁面儲存於該計算記憶體中;及 回應於判定該經請求頁面已加密: 產生一新密鑰; 使用該新密鑰重新加密該經請求頁面; 取代該經請求頁面,將該重新加密之頁面儲存於該計算記憶體中;及 解密該經請求頁面且將該已解密之頁面儲存於該計算記憶體之該快取區中。
  4. 12
    Such as the medium of request 11, wherein the instructions are executable to transfer the requested page or the decrypted page from the cache to a source of the request. 如請求項11之媒體,其中該等指令可執行以將該經請求頁面或該已解密頁面從該快取區傳送至該請求之一來源。
  5. 14
    A device comprising:a computing memory;and an operating system page table stored in the computing memory, wherein the operating system page table includes: an indication of whether the respective page is encrypted;for the encrypted A respective key of one of each page;a virtual address corresponding to the respective page;a physical address corresponding to the respective page;and a mark of a type of the respective page;and the computing memory is configured in it To maintain the operating system page table. 一種設備,其包括: 一計算記憶體;及 一作業系統頁面表,其儲存於該計算記憶體中,其中該作業系統頁面表包含: 一各自頁面是否已加密之一指示; 用於已加密之各頁面之一各自密鑰; 對應於該各自頁面之一虛擬位址; 對應於該各自頁面之一實體位址;及 該各自頁面之一類型之一標記;及 其中該計算記憶體經組態以維持該作業系統頁面表。
  6. 19
    A device comprising:a computing memory configured to: according to one of the operating system page tables in the computing memory by the computing memory, the response is that the first page is unencrypted and responds Encrypting a first page by marking the first page as an executable command;responding to the second page being unencrypted and responding to the second page being requested and encrypting a second page marked as executable commands;and responding to The third page has been encrypted and is re-encrypted in response to the request of the third page to re-encrypt a third page marked as an executable command. 一種設備,其包括: 一計算記憶體,其經組態以: 根據藉由該計算記憶體對該計算記憶體中之一作業系統頁面表之一周遊,回應於該第一頁面未加密且回應於該第一頁面標記為可執行指令,加密一第一頁面; 回應於該第二頁面未加密且回應於該第二頁面經請求而加密標記為可執行指令之一第二頁面;及 回應於該第三頁面已加密且回應於該第三頁面經請求而重新加密標記為可執行指令之一第三頁面。
  7. 23
    Such as the device of request 22, wherein the computing memory is configured to transfer the second page from the cache in response to a subsequent request for the second page. 如請求項22之設備,其中該計算記憶體經組態以回應於對該第二頁面之一隨後請求而自該快取區傳送該第二頁面。
  8. 25
    A method, comprising:receiving a request for a page stored in a computing memory;determining whether the requested page has been marked as an executable command in an operating system page table in the computing memory;determining Whether the requested page has been indicated as encrypted in the operating system page table in the computing memory;and in response to determining that the requested page is executable and encrypted: generate a new key;use the new key Re-encrypt the requested page;replace the requested page, store the re-encrypted page in the computing memory;decrypt the requested page and store the decrypted page in the cache of the computing memory ;And send the decrypted requested page from the cache to satisfy the request. 一種方法,其包括: 接收對儲存於一計算記憶體中之一頁面之一請求; 判定該經請求頁面是否已在該計算記憶體中之一作業系統頁面表中被標記為可執行指令; 判定該經請求頁面是否已在該計算記憶體中之該作業系統頁面表中被指示為已加密;及 回應於判定該經請求頁面可執行且已加密: 產生一新密鑰; 使用該新密鑰重新加密該經請求頁面; 取代該經請求頁面,將該重新加密之頁面儲存於該計算記憶體中; 解密該經請求頁面且將該已解密頁面儲存於該計算記憶體之該快取區中;及 自該快取區傳送該已解密經請求頁面以滿足該請求。