Protected Mode

Descriptor tables, selectors, protection rings.

Darshan N
Updated: 19 March 2026
10 min read

When the 80286 processor was introduced, one of its most important architectural additions was Protected Mode. Unlike Real Mode where any program can access any memory location, Protected Mode introduces hardware-enforced memory protection that prevents one process from corrupting another. This feature is the foundation of all modern multitasking operating systems.

Understanding Protected Mode is essential for GATE aspirants because it covers descriptor tables, selectors, segmentation, and protection rings, all of which are core topics in the modern processors section of the microprocessors syllabus.

Protected Mode Memory Access OverviewSegmentSelectorDescriptor Table(GDT or LDT)Segment Descriptor(Base, Limit, DPL)PhysicalAddressProtection RingsRing 0KernelRing 1OS ServicesRing 2Device DriversRing 3User ProgramsInner rings have higher privilege; Ring 0 has full hardware access
Figure 1: Protected Mode address translation via descriptor tables and four-level privilege ring structure.

Core Concept: What Protected Mode Does

In Real Mode, a logical address is computed as Segment Register x 16 + Offset. Any program can write any physical address, which makes it impossible to isolate programs from each other. Protected Mode changes this completely by treating the segment register not as a base address value but as a selector that points to a descriptor table entry.

A selector is a 16-bit value where bits 15 to 3 are the descriptor index, bit 2 is the Table Indicator (TI = 0 for Global Descriptor Table, TI = 1 for Local Descriptor Table), and bits 1 to 0 represent the Requested Privilege Level (RPL). This selector is used to locate a descriptor in either the GDT or LDT, which contains the actual base address, segment limit, and access rights.

Descriptor Tables

The Global Descriptor Table (GDT) is a system-wide table stored in memory whose base address and size are stored in the GDTR register. Each entry in the GDT is an 8-byte segment descriptor that contains a 32-bit segment base address, a 20-bit segment limit, granularity bit, descriptor privilege level (DPL), and various type bits indicating whether the segment is code, data, or system.

The Local Descriptor Table (LDT) is a per-process descriptor table. Each process can have its own LDT, which allows the operating system to give each process a private memory map. The LDT base and limit are stored in the LDTR register. When TI = 1 in a selector, the processor uses LDTR to locate the LDT and finds the descriptor at the given index.

Protection Rings

Protected Mode defines four privilege levels called rings, numbered 0 to 3. Ring 0 is the most privileged and is used by the OS kernel. Ring 3 is the least privileged and is used by user applications. Rings 1 and 2 are available for OS services and device drivers, though most modern operating systems like Linux and Windows use only Ring 0 (kernel) and Ring 3 (user space).

The CPU enforces protection by comparing the Current Privilege Level (CPL) stored in the lower 2 bits of the CS register with the Descriptor Privilege Level (DPL) in the segment descriptor. A program running at Ring 3 cannot access a descriptor with DPL = 0. Any such violation triggers a General Protection Fault (GPF), which is exception 13 in x86 architecture.

Mathematical Expression

In Protected Mode, the linear (physical) address is computed by adding the 32-bit segment base address from the descriptor to the 32-bit effective offset. The condition for a valid access is that the offset must be less than or equal to the segment limit. If the granularity bit G = 1, the limit is scaled by 4096 (page granularity), allowing segments up to 4 GB. If G = 0, the limit is in bytes with a maximum of 1 MB.

Example
Given:
Segment Descriptor Base = 0x00400000
Segment Limit = 0x0009FFFF (G=0, byte granularity)
Effective Offset = 0x00050000

Why this formula applies:
In Protected Mode, physical address = base + offset if offset <= limit.

Formula:
Physical Address = Segment Base + Effective Offset
Condition: Effective Offset <= Segment Limit

Substitution:
Physical Address = 0x00400000 + 0x00050000
Check: 0x00050000 <= 0x0009FFFF ? YES

Calculation:
= 0x00450000

Final Answer: Physical Address = 0x00450000 (valid access, no protection fault).
Exam Tip: In GATE, remember that the segment register in Protected Mode is a SELECTOR (index into descriptor table), not a base address. The actual base is in the descriptor. RPL and DPL comparison is how ring protection is enforced.
Segment Descriptor Format (8 bytes)Base[31:24] + FlagsAccess Byte + Limit[19:16]Base [23:16]Base [15:0]Byte 7-6Byte 5-4Byte 3Bytes 1-0Limit[15:0] is in Bytes 0-1 of lower DWORD (not shown above for brevity)Access Byte FieldsP (Present):1 = segment is valid in memoryDPL [2 bits]:Descriptor Privilege Level (0=kernel, 3=user)Selector Format (16-bit segment register in Protected Mode)Bits [15:3]:Descriptor Index (which entry in GDT or LDT)Bit [2] TI:0 = GDT, 1 = LDTBits [1:0] RPL:Requested Privilege LevelPhysical Address = Descriptor Base + Effective Offset (if Offset within Limit)Protection fault (GPF) raised if CPL > DPL or offset exceeds limit
Figure 2: Segment descriptor format and selector structure showing how protection and address translation work in Protected Mode.
  • Protected Mode converts segment registers into selectors pointing to GDT or LDT descriptor entries.
  • Each 8-byte descriptor contains 32-bit base, 20-bit limit, DPL, and type fields.
  • GDT is system-wide; LDT is per-process. Addresses stored in GDTR and LDTR registers.
  • Protection rings: Ring 0 (kernel, most privileged) to Ring 3 (user, least privileged).
  • CPU compares CPL with DPL; violation triggers General Protection Fault (exception 13).

Quick Revision

  • Protected Mode introduced in 80286; enhanced with 32-bit support in 80386.
  • Selector = 13-bit index + TI bit + 2-bit RPL. TI=0 uses GDT, TI=1 uses LDT.
  • Descriptor has base address, limit, DPL (privilege), present bit, and type bits.
  • Physical Address = Descriptor Base + Offset (if Offset <= Limit).
  • Ring 0 = kernel (full privilege), Ring 3 = user programs (restricted access).
  • GPF (exception 13) is raised on privilege violation or out-of-limit access.
  • Exam trap: Segment register in Protected Mode is NOT a base address; it is a table index selector.

Protected Mode Quiz

Test your understanding of x86 protected mode, descriptor tables, selectors, and privilege rings.

Question 1 of 3

Q1.In x86 protected mode, a segment selector stored in a segment register contains a 13-bit index, a TI bit, and a 2-bit RPL field. What does the TI bit specify?