Invention Grant
- Patent Title: Using a call gate to prevent secure sandbox leakage
- Patent Title (中): 使用呼叫门防止安全沙箱泄漏
-
Application No.: US13045339Application Date: 2011-03-10
-
Publication No.: US08528083B2Publication Date: 2013-09-03
- Inventor: Paton Lewis
- Applicant: Paton Lewis
- Applicant Address: US CA San Jose
- Assignee: Adobe Systems Incorporated
- Current Assignee: Adobe Systems Incorporated
- Current Assignee Address: US CA San Jose
- Agency: Wolfe-SBMC
- Main IPC: G06F21/22
- IPC: G06F21/22 ; G06F17/00 ; G06F9/445

Abstract:
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for enveloping a thread of execution within an IDT-based secure sandbox. In one aspect, embodiments of the invention provide that a request is received from an application, the request being generated using an application programming interface of a device driver. After the request is received a call gate descriptor for a call gate is added to a segment descriptor table for the application. The call gate descriptor specifies: (a) that the call gate can be called from a first privilege level of the application; and (b) that the call gate requests a second privilege level higher that the first privilege level. A call gate selector for the call gate descriptor is provided to the application in response to the request.
Public/Granted literature
- US20130167222A1 USING A CALL GATE TO PREVENT SECURE SANDBOX LEAKAGE Public/Granted day:2013-06-27
Information query