The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 18, 2019

Filed:

Sep. 30, 2016
Applicant:

Intel Corporation, Santa Clara, CA (US);

Inventors:

Rebekah M. Leslie-Hurd, Portland, OR (US);

Francis X. McKeen, Portland, OR (US);

Carlos V. Rozas, Portland, OR (US);

Gilbert Neiger, Hillsboro, OR (US);

Asit K. Mallick, Saratoga, CA (US);

Ittai Anati, Haifa, IL;

Ilya Alexandrovich, Haifa, IL;

Vedvyas Shanbhogue, Austin, TX (US);

Somnath Chakrabarti, Portland, OR (US);

Assignee:

Intel Corporation, Santa Clara, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 3/06 (2006.01); G06F 12/12 (2016.01); G06F 12/0875 (2016.01); G06F 9/455 (2018.01);
U.S. Cl.
CPC ...
G06F 12/12 (2013.01); G06F 3/0604 (2013.01); G06F 3/064 (2013.01); G06F 3/0631 (2013.01); G06F 3/0664 (2013.01); G06F 3/0665 (2013.01); G06F 3/0673 (2013.01); G06F 9/45558 (2013.01); G06F 12/0875 (2013.01); G06F 2009/45583 (2013.01); G06F 2212/1016 (2013.01); G06F 2212/151 (2013.01); G06F 2212/152 (2013.01); G06F 2212/402 (2013.01); G06F 2212/604 (2013.01);
Abstract

Implementations of the disclosure provide for supporting oversubscription of guest enclave memory pages. In one implementation, a processing device comprising a memory controller unit to access a secure enclave and a processor core, operatively coupled to the memory controller unit. The processing device is to identify a target memory page in memory. The target memory page is associated with a secure enclave of a virtual machine (VM). A data structure comprising context information corresponding to the target memory page is received. A state of the target memory page is determined based on the received data structure. The state indicating whether the target memory page is associated with at least one of: a child memory page or a parent memory page of the VM. Thereupon, an instruction to evict the target memory page from the secure enclave is generated based on the determined state.


Find Patent Forward Citations

Loading…