The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Patent No.:

US 7757280 B1

PDF
Full Text
Expired
Date of Patent:
Jul. 13, 2010

Filed:

Jan. 17, 2006
Applicants:

Michael Backes, Thalwil, CH;

Shmuel Ben-yehuda, Haifa, IL;

Jan Leonhard Camenisch, Rueschlikon, CH;

Ton Engbersen, Feusisberg, CH;

Zorik Machulsky, Gesher HaZiv, IL;

Julian Satran, Atlit, IL;

Leah Shalev, Zichron-Yaakov, IL;

Ilan Shimony, Haifa, IL;

Thomas Basil Smith, Iii, Wilton, CT (US);

Michael Waidner, Au, CH;

Inventors:

Michael Backes, Thalwil, CH;

Shmuel Ben-Yehuda, Haifa, IL;

Jan Leonhard Camenisch, Rueschlikon, CH;

Ton Engbersen, Feusisberg, CH;

Zorik Machulsky, Gesher HaZiv, IL;

Julian Satran, Atlit, IL;

Leah Shalev, Zichron-Yaakov, IL;

Ilan Shimony, Haifa, IL;

Thomas Basil Smith, III, Wilton, CT (US);

Michael Waidner, Au, CH;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2006.01); H04L 12/14 (2006.01);
U.S. Cl.
CPC ...
Abstract

A computer-implemented method for protecting a memory is provided. The method includes responsive to a direct memory access (DMA) request received from a consumer for a transaction of data from an IO device to the memory, the request including an IO command and a capability (CAP), generating a cryptographically signed capability (CAPB), forming a credential from CAP and CAPB, appending the credential to the IO command, configuring the IO device according to the credential and the IO command, transmitting the data from the IO device to the memory and prior to allowing execution of the DMA, authenticating that the credential is valid, further includes regenerating CAPB from a key available to an authenticating entity and from the CAP (included in CAPB) and verifying that the memory region information described in the cryptographically signed capability is the same as the requested region that was originally created, and that the cryptographically signed capability encompasses the IO command.


Find Patent Forward Citations

Loading…