Issued patents

  1. 12,705,057 (2026): Circuitry and methods for implementing capabilities using narrow registers

  2. 12,704,991 (2026): Circuitry and methods for implementing capability-based compartment switches with descriptors

  3. 12,669,947 (2026): Memory safety with single memory tag per allocation

  4. 12,657,122 (2026): Circuitry and methods for implementing non-redundant metadata storage addressed by bounded capabilities

  5. 12,639,072 (2026): Reducing instrumentation code bloat and performance overheads using a runtime call instruction

  6. 12,585,757 (2026): Technologies for object-oriented memory management with extended segmentation

  7. 12,579,078 (2026): Speculating object-granular key identifiers for memory safety

  8. 12,504,891 (2025): Zero-redundancy tag storage for bucketed allocators

  9. 12,487,822 (2025): Apparatus, computer-readable medium, and method for reducing bounds checking overhead by instrumenting pointer arithmetic

  10. 12,481,502 (2025): Cryptographic computing with context information for transient side channel security

  11. 12,373,356 (2025): Fast key ID switching via extended paging for cryptographic intra-process isolation

  12. 12,360,689 (2025): Efficient caching and queueing for per-allocation non-redundant metadata

  13. 12,346,463 (2025): Pointer based data encryption

  14. 12,321,467 (2025): Cryptographic computing isolation for multi-tenancy and secure software components

  15. 12,306,998 (2025): Stateless and low-overhead domain isolation using cryptographic computing

  16. 12,282,567 (2025): Cryptographic computing using encrypted base addresses and used in multi-tenant environments

  17. 12,277,234 (2025): Cryptographic computing in multitenant environments

  18. 12,253,958 (2025): System for address mapping and translation protection

  19. 12,216,922 (2025): Updating encrypted security context in stack pointers for exception handling and tight bounding of on-stack arguments

  20. 12,182,317 (2024): Region-based deterministic memory safety

  21. 12,093,182 (2024): Typed store buffers for hardening store forwarding

  22. 12,050,701 (2024): Cryptographic isolation of memory compartments in a computing environment

  23. 12,045,174 (2024): Tagless implicit integrity with multi-perspective pattern search

  24. 12,032,486 (2024): Transient side-channel aware architecture for cryptographic computing

  25. 12,019,733 (2024): Compartment isolation for load store forwarding

  26. 12,019,562 (2024): Cryptographic computing including enhanced cryptographic addresses

  27. 12,008,374 (2024): Cryptographic enforcement of borrow checking

  28. 11,972,126 (2024): Data relocation for inline metadata

  29. 11,960,375 (2024): Apparatus and method for pausing processor trace for efficient analysis

  30. 11,954,045 (2024): Object and cacheline granularity cryptographic memory integrity

  31. 11,940,927 (2024): Technologies for memory tagging

  32. 11,922,220 (2024): Function as a service (FaaS) system enhancements

  33. 11,841,939 (2023): Technologies for object-oriented memory management with extended segmentation

  34. 11,838,418 (2023): Protection of keys and sensitive data from attack within microprocessor architecture

  35. 11,836,094 (2023): Cryptographic data objects page conversion

  36. 11,829,488 (2023): Pointer based data encryption

  37. 11,829,299 (2023): Technologies for execute only transactional memory

  38. 11,822,644 (2023): Technologies for object-oriented memory management with extended segmentation

  39. 11,797,678 (2023): Memory scanning methods and apparatus

  40. 11,789,737 (2023): Capability-based stack protection for software fault isolation

  41. 11,784,786 (2023): Mitigating security vulnerabilities with memory allocation markers in cryptographic computing systems

  42. 11,782,826 (2023): Security check systems and methods for memory allocations

  43. 11,782,716 (2023): Hardware apparatuses, methods, and systems for individually revocable capabilities for enforcing temporal memory safety

  44. 11,768,931 (2023): Technologies for object-oriented memory management with extended segmentation

  45. 11,741,018 (2023): Apparatus and method for efficient process-based compartmentalization

  46. 11,734,199 (2023): Enforcing memory operand types using protection keys

  47. 11,711,201 (2023): Encoded stack pointers

  48. 11,704,297 (2023): Collision-free hashing for accessing cryptographic computing metadata and for cache expansion

  49. 11,681,793 (2023): Technologies for object-oriented memory management with extended segmentation

  50. 11,669,625 (2023): Data type based cryptographic computing

  51. 11,630,920 (2023): Memory tagging for side-channel defense, memory safety, and sandboxing

  52. 11,620,391 (2023): Data encryption based on immutable pointers

  53. 11,580,035 (2023): Fine-grained stack protection using cryptographic computing

  54. 11,575,504 (2023): Cryptographic computing engine for memory load and store units of a microarchitecture pipeline

  55. 11,562,063 (2023): Encoded inline capabilities

  56. 11,531,750 (2022): Installing and manipulating a secure virtual machine image through an untrusted hypervisor

  57. 11,436,161 (2022): System for address mapping and translation protection

  58. 11,429,580 (2022): Collision-free hashing for accessing cryptographic computing metadata and for cache expansion

  59. 11,416,624 (2022): Cryptographic computing using encrypted base addresses and used in multi-tenant environments

  60. 11,416,414 (2022): Technologies for execute only transactional memory

  61. 11,409,662 (2022): Apparatus and method for efficient process-based compartmentalization

  62. 11,403,234 (2022): Cryptographic computing using encrypted base addresses and used in multi-tenant environments

  63. 11,392,492 (2022): Memory management apparatus and method for compartmentalization using linear address metadata

  64. 11,360,876 (2022): Apparatus and method for pausing processor trace for efficient analysis

  65. 11,354,423 (2022): Cryptographic isolation of memory compartments in a computing environment

  66. 11,321,469 (2022): Microprocessor pipeline circuitry to support cryptographic computing

  67. 11,250,165 (2022): Binding of cryptographic operations to context or speculative execution restrictions

  68. 11,222,127 (2022): Processor hardware and instructions for SHA3 cryptographic operations

  69. 11,216,366 (2022): Security check systems and methods for memory allocations

  70. 11,188,639 (2021): System, method and apparatus for automatic program compartmentalization

  71. 11,171,983 (2021): Techniques to provide function-level isolation with capability-based security

  72. 11,163,569 (2021): Hardware apparatuses, methods, and systems for individually revocable capabilities for enforcing temporal memory safety

  73. 11,144,479 (2021): System for address mapping and translation protection

  74. 11,080,401 (2021): Memory scanning methods and apparatus

  75. 11,036,850 (2021): Technologies for object-oriented memory management with extended segmentation

  76. 11,030,113 (2021): Apparatus and method for efficient process-based compartmentalization

  77. 10,884,952 (2021): Enforcing memory operand types using protection keys

  78. 10,860,709 (2020): Encoded inline capabilities

  79. 10,795,997 (2020): Hardened safe stack for return oriented programming attack mitigation

  80. 10,785,028 (2020): Protection of keys and sensitive data from attack within microprocessor architecture

  81. 10,769,272 (2020): Technology to protect virtual machines from malicious virtual machine managers

  82. 10,706,164 (2020): Crypto-enforced capabilities for isolation

  83. 10,642,752 (2020): Auxiliary processor resources

  84. 10,642,711 (2020): Apparatus and method for pausing processor trace for efficient analysis

  85. 10,628,613 (2020): Cryptographic operations for secure page mapping in a virtual machine environment

  86. 10,558,582 (2020): Technologies for execute only transactional memory

  87. 10,515,023 (2019): System for address mapping and translation protection

  88. 10,503,664 (2019): Virtual machine manager for address mapping and translation protection

  89. 10,453,114 (2019): Selective sharing of user information based on contextual relationship information, such as to crowd-source gifts of interest to a recipient

  90. 10,452,848 (2019): Memory scanning methods and apparatus

  91. 10,324,863 (2019): Protected memory view for nested page table access by virtual machine guests

  92. 10,318,733 (2019): Techniques for detecting malware with minimal performance degradation

  93. 10,235,301 (2019): Dynamic page table edit control

  94. 10,216,522 (2019): Technologies for indirect branch target security

  95. 10,157,277 (2018): Technologies for object-oriented memory management with extended segmentation

  96. 10,152,612 (2018): Cryptographic operations for secure page mapping in a virtual machine environment

  97. 10,104,122 (2018): Verified sensor data processing

  98. 10,061,918 (2018): System, apparatus and method for filtering memory access logging in a processor

  99. 10,007,784 (2018): Technologies for control flow exploit mitigation using processor trace

  100. 9,954,950 (2018): Attestable information flow control in computer systems

  101. 9,858,411 (2018): Execution profiling mechanism

  102. 9,830,162 (2017): Technologies for indirect branch target security

  103. 9,817,976 (2017): Techniques for detecting malware with minimal performance degradation

  104. 9,805,194 (2017): Memory scanning methods and apparatus

  105. 9,792,222 (2017): Validating virtual address translation by virtual machine monitor utilizing address validation structure to validate tentative guest physical address and aborting based on flag in extended page table requiring an expected guest physical address in the address validation structure

  106. 9,710,393 (2017): Dynamic page table edit control

  107. 9,703,703 (2017): Control of entry into protected memory views

  108. 9,665,373 (2017): Protecting confidential data with transactional processing in execute-only memory

  109. 9,501,637 (2016): Hardware shadow stack support for legacy guests

  110. 9,335,943 (2016): Method and apparatus for fine grain memory protection

  111. 9,124,635 (2015): Verified sensor data processing

  112. 8,458,791 (2013): Hardware-implemented hypervisor for root-of-trust monitoring and control of computer system

  113. 7,774,411 (2010): Secure electronic message transport protocol

Published patent applications

  1. 19/253,812: EFFICIENT TAG CHECKING FOR DYNAMICALLY REPEATING MEMORY ACCESSES

  2. 19/003,528: MONITORING MEMORY TAG LOAD PERFORMANCE

  3. 18/977,277: CONSERVING INSTRUCTION ENCODING SPACE AND MINIMIZING CODE SIZE FOR MEMORY OPERATIONS USING PREFIX BITS TO DISTINGUISH LOAD AND STORE TAG CHECKS

  4. 19/253,814: SELECTIVELY CONTROLLABLE MEMORY TAG CHECKING

  5. 18/900,705: MEMORY SAFETY USING CRYPTOGRAPHIC ENTROPY TAGGING

  6. 18/900,258: INCREASING DATA-DEPENDENT MEMORY PREFETCHER ACCURACY USING MEMORY METADATA

  7. 18/759,355: CRYPTOGRAPHIC ADDRESS PREFETCH CIRCUITRY AND METHODS

  8. 18/622,896: CRYPTOGRAPHIC INITIALIZATION STATE TRACKING FOR DETECTION OF UNINITIALIZED MEMORY READS

  9. 18/616,889: CIRCUITRY AND METHODS FOR LINEAR MEMORY ACCESS CONTROL TABLE SWITCHING FOR FINE GRAIN COMPARTMENTALIZATION

  10. 18/946,869: CAPABILITY-BASED MEMORY ACCESS CONTROL FOR GRAPHICS PROCESSORS AND ACCELERATORS

  11. 18/619,267: CONCEPT FOR GENERATING A CRYPTOGRAPHIC ADDRESS OF A FIELD OF AN OBJECT

  12. 18/401,107: PROCESSORS, METHODS, SYSTEMS, AND INSTRUCTIONS TO USE DATA OBJECT EXTENT INFORMATION IN POINTERS TO INFORM PREDICTORS

  13. 18/346,221: INSTRUCTION PREFIX ENCODING FOR CRYPTOGRAPHIC COMPUTING CAPABILITY DATA TYPES

  14. 18/525,220: INTEGRITY CHECK VALUE TRIPWIRES FOR SPATIAL AND TEMPORAL MEMORY SAFETY

  15. 18/948,099: REGION-BASED DETERMINISTIC MEMORY SAFETY

  16. 18/343,718: CIRCUITRY AND METHODS FOR CRYPTOGRAPHICALLY ENFORCING CONTROL-FLOW INTEGRITY

  17. 18/346,222: EXPLICIT INTEGRITY CHECK VALUE INITIALIZATION

  18. 18/478,882: MEMORY SAFETY USING TAG CHECKING INSTRUCTIONS AND ISLANDS OF TAGS IN LINE WITH BUCKETED DATA

  19. 18/194,553: MULTI-KEY MEMORY ENCRYPTION PROVIDING EFFICIENT ISOLATION FOR MULTITHREADED PROCESSES

  20. 18/194,086: CIRCUITRY AND METHODS FOR IMPLEMENTING FORWARD-EDGE CONTROL-FLOW INTEGRITY (FECFI) USING ONE OR MORE CAPABILITY-BASED INSTRUCTIONS

  21. 17/953,186: TEMPORAL INFORMATION LEAKAGE PROTECTION MECHANISM FOR CRYPTOGRAPHIC COMPUTING

  22. 17/936,011: DETERMINISTIC ADJACENT OVERFLOW DETECTION FOR SLOTTED MEMORY POINTERS

  23. 17/949,353: USER-LEVEL EXCEPTION-BASED INVOCATION OF SOFTWARE INSTRUMENTATION HANDLERS

  24. 18/499,133: POINTER BASED DATA ENCRYPTION

  25. 17/849,351: CONTROL FLOW INTEGRITY TO PREVENT POTENTIAL LEAKAGE OF SENSITIVE DATA TO ADVERSARIES

  26. 17/848,142: IMPLICIT MEMORY CORRUPTION DETECTION FOR CONDITIONAL DATA TYPES

  27. 17/791,000: CRYPTOGRAPHIC COMPUTING IN MULTITENANT ENVIRONMENTS

  28. 17/947,072: UPDATING ENCRYPTED SECURITY CONTEXT IN STACK POINTERS FOR EXCEPTION HANDLING AND TIGHT BOUNDING OF ON-STACK ARGUMENTS

  29. 17/357,963: REGION-BASED DETERMINISTIC MEMORY SAFETY

  30. 17/696,330: RATCHET POINTERS TO ENFORCE BYTE-GRANULAR BOUNDS CHECKS ON MULTIPLE VIEWS OF AN OBJECT

  31. 17/699,593: CRYPTOGRAPHIC DATA OBJECTS PAGE CONVERSION

  32. 17/693,748: GENERATING ENCRYPTED CAPABILITIES WITHIN BOUNDS

  33. 17/682,997: COMPILER-DIRECTED SELECTION OF OBJECTS FOR CAPABILITY PROTECTION

  34. 17/576,533: MICROPROCESSOR PIPELINE CIRCUITRY TO SUPPORT CRYPTOGRAPHIC COMPUTING

  35. 17/561,828: PROCESS OBJECT RE-KEYING DURING PROCESS CREATION IN CRYPTOGRAPHIC COMPUTING

  36. 17/560,363: HARDENING CPU PREDICTORS WITH CRYPTOGRAPHIC COMPUTING CONTEXT INFORMATION

  37. 17/559,385: DATA OBLIVIOUS CRYPTOGRAPHIC COMPUTING

  38. 17/346,757: TECHNOLOGIES FOR OBJECT-ORIENTED MEMORY MANAGEMENT WITH EXTENDED SEGMENTATION

  39. 17/346,812: TECHNOLOGIES FOR OBJECT-ORIENTED MEMORY MANAGEMENT WITH EXTENDED SEGMENTATION

  40. 17/314,349: TECHNOLOGY TO CONTROL SYSTEM CALL INVOCATIONS WITHIN A SINGLE ADDRESS SPACE

  41. 17/133,734: ENFORCING MEMORY OPERAND TYPES USING PROTECTION KEYS

  42. 16/585,964: HARDWARE FOR ELIDING SECURITY CHECKS WHEN DEEMED SAFE DURING SPECULATIVE EXECUTION

  43. 16/862,022: MEMORY WRITE FOR OWNERSHIP ACCESS IN A CORE

  44. 15/721,553: Installing and manipulating a secure virtual machine image through an untrusted hypervisor

  45. 15/713,573: Methods and arrangements to determine physical resource assignments

  46. 15/966,358: TECHNOLOGIES FOR CONTROL FLOW EXPLOIT MITIGATION USING PROCESSOR TRACE

  47. 16/040,193: System, method and apparatus for automatic program compartmentalization

  48. 15/273,286: Access control

  49. 15/201,018: Regulating control transfers for execute-only code execution