Detection of return oriented programming attacks
    1.
    发明授权
    Detection of return oriented programming attacks 有权
    检测面向回程的编程攻击

    公开(公告)号:US09582663B2

    公开(公告)日:2017-02-28

    申请号:US14960709

    申请日:2015-12-07

    申请人: Intel Corporation

    摘要: In one embodiment, a processor includes at least one execution unit and Return Oriented Programming (ROP) detection logic. The ROP detection logic may determine a ROP metric based on a plurality of control transfer events. The ROP detection logic may also determine whether the ROP metric exceeds a threshold. The ROP detection logic may also, in response to a determination that the ROP metric exceeds the threshold, provide a ROP attack notification.

    摘要翻译: 在一个实施例中,处理器包括至少一个执行单元和返回定向编程(ROP)检测逻辑。 ROP检测逻辑可以基于多个控制传送事件来确定ROP度量。 ROP检测逻辑还可以确定ROP度量是否超过阈值。 ROP检测逻辑还可以响应于ROP度量超过阈值的确定,提供ROP攻击通知。

    Secure provisioning of secret keys during integrated circuit manufacturing

    公开(公告)号:US09742563B2

    公开(公告)日:2017-08-22

    申请号:US13631512

    申请日:2012-09-28

    申请人: Intel Corporation

    IPC分类号: H04L9/00 H04L9/08 H04L9/32

    CPC分类号: H04L9/0866 H04L9/3278

    摘要: A method, of an aspect, includes challenging a set of Physically Unclonable Function (PUF) cells, of an integrated circuit device, and receiving a set of PUF bits from the PUF cells in response. A PUF key is generated based on the set of PUF bits. An encryption of the PUF key with an embedded key is output from the integrated circuit device. The integrated circuit device receives an encryption of a fuse key with the PUF key. Fuses of the integrated circuit device are programmed with at least one of the fuse key and the received encryption of the fuse key with the PUF key. Other methods, apparatus, and systems are also disclosed.

    Fuse attestation to secure the provisioning of secret keys during integrated circuit manufacturing
    4.
    发明授权
    Fuse attestation to secure the provisioning of secret keys during integrated circuit manufacturing 有权
    保险丝证明在集成电路制造期间确保秘密密钥的供应

    公开(公告)号:US08885819B2

    公开(公告)日:2014-11-11

    申请号:US13728375

    申请日:2012-12-27

    申请人: Intel Corporation

    摘要: Embodiments of an invention for fuse attestation to secure the provisioning of secret keys during integrated circuit manufacturing are disclosed. In one embodiment, an apparatus includes a storage location, a physically unclonable function (PUF) circuit, a PUF key generator, an encryption unit, and a plurality of fuses. The storage location is to store a configuration fuse value. The PUF circuit is to provide a PUF value. The PUF key generator is to generate a PUF key based on the PUF value. The encryption unit is to encrypt the configuration fuse value using the PUF key. The PUF key and the configuration fuse value are to be provided to a key server. The key server is to determine that the configuration fuse value indicates that the apparatus is a production component, and, in response, provide a fuse key to be stored in the plurality of fuses.

    摘要翻译: 公开了用于在集成电路制造期间确保秘密密钥供应的熔丝证明的发明的实施例。 在一个实施例中,一种装置包括存储位置,物理上不可克隆功能(PUF)电路,PUF密钥发生器,加密单元和多个保险丝。 存储位置是存储配置熔丝值。 PUF电路提供PUF值。 PUF密钥生成器基于PUF值生成PUF密钥。 加密单元使用PUF密钥加密配置熔丝值。 PUF键和配置保险丝值将提供给密钥服务器。 密钥服务器是确定配置熔丝值表示该设备是生产部件,并且作为响应,提供要存储在多个保险丝中的熔丝钥匙。

    Detection Of Return Oriented Programming Attacks
    6.
    发明申请
    Detection Of Return Oriented Programming Attacks 审中-公开
    检测面向回程的编程攻击

    公开(公告)号:US20160085966A1

    公开(公告)日:2016-03-24

    申请号:US14960709

    申请日:2015-12-07

    申请人: Intel Corporation

    IPC分类号: G06F21/55 G06F9/30

    摘要: In one embodiment, a processor includes at least one execution unit and Return Oriented Programming (ROP) detection logic. The ROP detection logic may determine a ROP metric based on a plurality of control transfer events. The ROP detection logic may also determine whether the ROP metric exceeds a threshold. The ROP detection logic may also, in response to a determination that the ROP metric exceeds the threshold, provide a ROP attack notification.

    摘要翻译: 在一个实施例中,处理器包括至少一个执行单元和返回定向编程(ROP)检测逻辑。 ROP检测逻辑可以基于多个控制传送事件来确定ROP度量。 ROP检测逻辑还可以确定ROP度量是否超过阈值。 ROP检测逻辑还可以响应于ROP度量超过阈值的确定,提供ROP攻击通知。

    Detection of return oriented programming attacks
    8.
    发明授权
    Detection of return oriented programming attacks 有权
    检测面向回程的编程攻击

    公开(公告)号:US09223979B2

    公开(公告)日:2015-12-29

    申请号:US13664532

    申请日:2012-10-31

    申请人: Intel Corporation

    IPC分类号: G06F21/50 G06F21/56

    摘要: In one embodiment, a processor includes at least one execution unit and Return Oriented Programming (ROP) detection logic. The ROP detection logic may determine a ROP metric based on a plurality of control transfer events. The ROP detection logic may also determine whether the ROP metric exceeds a threshold. The ROP detection logic may also, in response to a determination that the ROP metric exceeds the threshold, provide a ROP attack notification.

    摘要翻译: 在一个实施例中,处理器包括至少一个执行单元和返回定向编程(ROP)检测逻辑。 ROP检测逻辑可以基于多个控制传送事件来确定ROP度量。 ROP检测逻辑还可以确定ROP度量是否超过阈值。 ROP检测逻辑还可以响应于ROP度量超过阈值的确定,提供ROP攻击通知。

    Integrated circuits having accessible and inaccessible physically unclonable functions
    9.
    发明授权
    Integrated circuits having accessible and inaccessible physically unclonable functions 有权
    集成电路具有可访问和无法访问的物理不可克隆功能

    公开(公告)号:US08928347B2

    公开(公告)日:2015-01-06

    申请号:US13631634

    申请日:2012-09-28

    申请人: Intel Corporation

    IPC分类号: H03K19/00 H03K19/003

    摘要: An integrated circuit substrate of an aspect includes a plurality of exposed electrical contacts. The integrated circuit substrate also includes an inaccessible set of Physically Unclonable Function (PUF) cells to generate an inaccessible set of PUF bits that are not accessible through the exposed electrical contacts. The integrated circuit substrate also includes an accessible set of PUF cells to generate an accessible set of PUF bits that are accessible through the exposed electrical contacts. Other apparatus, methods, and systems are also disclosed.

    摘要翻译: 一方面的集成电路基板包括多个暴露的电触点。 集成电路基板还包括不可接近的物理不可克隆功能(PUF)单元组,以生成不能通过暴露的电触点访问的不可访问的PUF位集合。 集成电路基板还包括可访问的PUF单元组,以产生可通过暴露的电触点访问的可访问的PUF位组。 还公开了其他装置,方法和系统。