CN1628284B - 用于处理安全异常的方法与系统 - Google Patents
用于处理安全异常的方法与系统 Download PDFInfo
- Publication number
- CN1628284B CN1628284B CN028290593A CN02829059A CN1628284B CN 1628284 B CN1628284 B CN 1628284B CN 028290593 A CN028290593 A CN 028290593A CN 02829059 A CN02829059 A CN 02829059A CN 1628284 B CN1628284 B CN 1628284B
- Authority
- CN
- China
- Prior art keywords
- security
- security exception
- register
- exception
- sem
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Lifetime
Links
- 238000000034 method Methods 0.000 title claims abstract description 39
- 238000012545 processing Methods 0.000 title description 3
- 230000007257 malfunction Effects 0.000 claims 2
- 238000012544 monitoring process Methods 0.000 claims 1
- 238000010586 diagram Methods 0.000 description 12
- 230000007246 mechanism Effects 0.000 description 11
- 230000004044 response Effects 0.000 description 9
- 238000013519 translation Methods 0.000 description 9
- 230000014616 translation Effects 0.000 description 9
- 230000008859 change Effects 0.000 description 8
- 230000011218 segmentation Effects 0.000 description 6
- 230000006870 function Effects 0.000 description 5
- 230000008569 process Effects 0.000 description 5
- 230000009471 action Effects 0.000 description 3
- 230000005540 biological transmission Effects 0.000 description 3
- 238000006243 chemical reaction Methods 0.000 description 3
- 238000004891 communication Methods 0.000 description 3
- 230000004048 modification Effects 0.000 description 3
- 238000012986 modification Methods 0.000 description 3
- 230000003287 optical effect Effects 0.000 description 3
- 230000001419 dependent effect Effects 0.000 description 2
- 230000004913 activation Effects 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000003139 buffering effect Effects 0.000 description 1
- 238000004364 calculation method Methods 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000018109 developmental process Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000007689 inspection Methods 0.000 description 1
- 239000013307 optical fiber Substances 0.000 description 1
- 230000002093 peripheral effect Effects 0.000 description 1
- 230000011664 signaling Effects 0.000 description 1
- 239000007787 solid Substances 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/46—Multiprogramming arrangements
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/53—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2153—Using hardware token as a secondary aspect
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Quality & Reliability (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (4)
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US10/161,500 | 2002-05-31 | ||
US10/161,500 US7451324B2 (en) | 2002-05-31 | 2002-05-31 | Secure execution mode exceptions |
PCT/US2002/040219 WO2003102770A1 (en) | 2002-05-31 | 2002-12-17 | Secure execution mode exceptions |
Publications (2)
Publication Number | Publication Date |
---|---|
CN1628284A CN1628284A (zh) | 2005-06-15 |
CN1628284B true CN1628284B (zh) | 2013-04-24 |
Family
ID=29583455
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN028290593A Expired - Lifetime CN1628284B (zh) | 2002-05-31 | 2002-12-17 | 用于处理安全异常的方法与系统 |
Country Status (7)
Country | Link |
---|---|
US (1) | US7451324B2 (zh) |
EP (1) | EP1509843A1 (zh) |
JP (1) | JP2005528690A (zh) |
KR (1) | KR100992611B1 (zh) |
CN (1) | CN1628284B (zh) |
AU (1) | AU2002361717A1 (zh) |
WO (1) | WO2003102770A1 (zh) |
Families Citing this family (19)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7334123B2 (en) * | 2003-05-02 | 2008-02-19 | Advanced Micro Devices, Inc. | Computer system including a bus bridge for connection to a security services processor |
US7784063B2 (en) * | 2004-01-09 | 2010-08-24 | Hewlett-Packard Development Company, L.P. | Method and apparatus for system caller authentication |
US7617534B1 (en) | 2005-08-26 | 2009-11-10 | Symantec Corporation | Detection of SYSENTER/SYSCALL hijacking |
US7685638B1 (en) | 2005-12-13 | 2010-03-23 | Symantec Corporation | Dynamic replacement of system call tables |
US8572729B1 (en) * | 2006-01-30 | 2013-10-29 | Mcafee, Inc. | System, method and computer program product for interception of user mode code execution and redirection to kernel mode |
US8214296B2 (en) * | 2006-02-14 | 2012-07-03 | Microsoft Corporation | Disaggregated secure execution environment |
EP1881404A1 (fr) * | 2006-07-20 | 2008-01-23 | Gemplus | Procédé de protection dynamique des données lors de l'exécution d'un code logiciel en langage intermédiaire dans un appareil numérique |
GB2478733B (en) | 2010-03-15 | 2013-08-14 | Advanced Risc Mach Ltd | Apparatus and method for handling exception events |
US9507937B2 (en) * | 2012-03-30 | 2016-11-29 | Intel Corporation | Reporting malicious activity to an operating system |
US9298911B2 (en) * | 2013-03-15 | 2016-03-29 | Intel Corporation | Method, apparatus, system, and computer readable medium for providing apparatus security |
US20160048679A1 (en) * | 2014-08-18 | 2016-02-18 | Bitdefender IPR Management Ltd. | Systems And Methods for Exposing A Current Processor Instruction Upon Exiting A Virtual Machine |
CN106569904A (zh) * | 2015-10-09 | 2017-04-19 | 中兴通讯股份有限公司 | 一种信息存储方法和装置、及服务器 |
US10146606B2 (en) * | 2016-04-06 | 2018-12-04 | Dell Products, Lp | Method for system debug and firmware update of a headless server |
CN106454914A (zh) * | 2016-11-10 | 2017-02-22 | 邦彦技术股份有限公司 | 一种ims的大批量业务出现异常的定位方法及装置 |
US11783064B2 (en) * | 2017-07-10 | 2023-10-10 | Intel Corporation | Techniques to provide hardware enforced protection environment for a system management mode |
CN107807870B (zh) * | 2017-10-30 | 2021-04-27 | 郑州云海信息技术有限公司 | 一种存储服务器主板掉电保护功能的测试方法和系统 |
CN109787777B (zh) * | 2017-11-10 | 2020-04-03 | 北京金山云网络技术有限公司 | 一种网卡模式切换方法、装置、电子设备及存储介质 |
CN112269597B (zh) * | 2020-10-23 | 2023-03-24 | 中国人民解放军战略支援部队信息工程大学 | 处理器指令异常行为检测方法及系统 |
US11797713B2 (en) | 2020-12-16 | 2023-10-24 | International Business Machines Corporation | Systems and methods for dynamic control of a secure mode of operation in a processor |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5684948A (en) * | 1995-09-01 | 1997-11-04 | National Semiconductor Corporation | Memory management circuit which provides simulated privilege levels |
US5937186A (en) * | 1994-03-24 | 1999-08-10 | International Business Machines Corporation | Asynchronous interrupt safing of prologue portions of computer programs |
Family Cites Families (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5784631A (en) * | 1992-06-30 | 1998-07-21 | Discovision Associates | Huffman decoder |
US5369770A (en) | 1992-11-02 | 1994-11-29 | Microsoft Corporation | Standardized protected-mode interrupt manager |
US5535397A (en) | 1993-06-30 | 1996-07-09 | Intel Corporation | Method and apparatus for providing a context switch in response to an interrupt in a computer process |
US6957332B1 (en) * | 2000-03-31 | 2005-10-18 | Intel Corporation | Managing a secure platform using a hierarchical executive architecture in isolated execution mode |
US6792499B1 (en) * | 2000-11-14 | 2004-09-14 | Cypress Semiconductor Corp. | Dynamic swapping of memory bank base addresses |
US6697959B2 (en) * | 2000-12-20 | 2004-02-24 | Bull Hn Information Systems Inc. | Fault handling in a data processing system utilizing a fault vector pointer table |
US6725362B2 (en) * | 2001-02-06 | 2004-04-20 | Intel Corporation | Method for encoding an instruction set with a load with conditional fault instruction |
-
2002
- 2002-05-31 US US10/161,500 patent/US7451324B2/en active Active
- 2002-12-17 EP EP02797355A patent/EP1509843A1/en not_active Ceased
- 2002-12-17 AU AU2002361717A patent/AU2002361717A1/en not_active Abandoned
- 2002-12-17 JP JP2004509788A patent/JP2005528690A/ja active Pending
- 2002-12-17 WO PCT/US2002/040219 patent/WO2003102770A1/en active Application Filing
- 2002-12-17 CN CN028290593A patent/CN1628284B/zh not_active Expired - Lifetime
- 2002-12-17 KR KR1020047019413A patent/KR100992611B1/ko not_active IP Right Cessation
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5937186A (en) * | 1994-03-24 | 1999-08-10 | International Business Machines Corporation | Asynchronous interrupt safing of prologue portions of computer programs |
US5684948A (en) * | 1995-09-01 | 1997-11-04 | National Semiconductor Corporation | Memory management circuit which provides simulated privilege levels |
Also Published As
Publication number | Publication date |
---|---|
US7451324B2 (en) | 2008-11-11 |
EP1509843A1 (en) | 2005-03-02 |
AU2002361717A1 (en) | 2003-12-19 |
KR20040111714A (ko) | 2004-12-31 |
WO2003102770A1 (en) | 2003-12-11 |
JP2005528690A (ja) | 2005-09-22 |
KR100992611B1 (ko) | 2010-11-08 |
US20030226022A1 (en) | 2003-12-04 |
CN1628284A (zh) | 2005-06-15 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN1628284B (zh) | 用于处理安全异常的方法与系统 | |
US6823433B1 (en) | Memory management system and method for providing physical address based memory access security | |
US6854039B1 (en) | Memory management system and method providing increased memory access security | |
US8051301B2 (en) | Memory management system and method providing linear address based memory access security | |
KR102116571B1 (ko) | 가상 머신을 나가자 마자 현재 프로세서 명령의 결과를 노출하기 위한 시스템 및 방법 | |
US11748457B2 (en) | Systems and methods for policy linking and/or loading for secure initialization | |
US7424709B2 (en) | Use of multiple virtual machine monitors to handle privileged events | |
US7380049B2 (en) | Memory protection within a virtual partition | |
US10496462B2 (en) | Providing instructions to facilitate detection of corrupt stacks | |
CN102906720B (zh) | 启用/禁用计算环境的适配器 | |
CN101952807A (zh) | 管理计算环境的多个可分页客户端对存储装置的使用 | |
US10114971B2 (en) | Interlinking routines with differing protections using stack indicators | |
US10248482B2 (en) | Interlinking modules with differing protections using stack indicators | |
US7426644B1 (en) | System and method for handling device accesses to a memory providing increased memory access security | |
KR20040101332A (ko) | 구획된 보안을 위한 입/출력 허가 비트맵 | |
US20170192834A1 (en) | Providing instructions to protect stack return addresses in a hardware managed stack architecture | |
WO2014122554A1 (en) | Key-based data security management | |
Allievi et al. | Windows internals, part 2 | |
EP0619899A1 (en) | Software control of hardware interruptions | |
JP7349437B2 (ja) | メモリ・アクセスにおける保護タグ・チェックの制御 | |
WO2023034586A1 (en) | Systems and methods for on-demand loading of metadata | |
US11216280B2 (en) | Exception interception | |
CN117222990A (zh) | 用于使用能力约束对存储器的访问的技术 | |
US20240354412A1 (en) | Systems and methods for on-demand loading of metadata | |
Meade | Microsoft, Inc. Windows NT Workstation and Server |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
ASS | Succession or assignment of patent right |
Owner name: GLOBALFOUNDRIES SEMICONDUCTORS CO., LTD Free format text: FORMER OWNER: ADVANCED MICRO DEVICES CORPORATION Effective date: 20100721 |
|
C41 | Transfer of patent application or patent right or utility model | ||
COR | Change of bibliographic data |
Free format text: CORRECT: ADDRESS; FROM: CALIFORNIA STATE, THE USA TO: GRAND CAYMAN ISLAND, BRITISH CAYMAN ISLANDS |
|
TA01 | Transfer of patent application right |
Effective date of registration: 20100721 Address after: Grand Cayman, Cayman Islands Applicant after: GLOBALFOUNDRIES Inc. Address before: California, USA Applicant before: ADVANCED MICRO DEVICES, Inc. |
|
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20210310 Address after: California, USA Patentee after: Lattice chip (USA) integrated circuit technology Co.,Ltd. Address before: Greater Cayman Islands, British Cayman Islands Patentee before: GLOBALFOUNDRIES Inc. |
|
TR01 | Transfer of patent right | ||
CX01 | Expiry of patent term | ||
CX01 | Expiry of patent term |
Granted publication date: 20130424 |