Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

654results about "Unauthorized memory use protection" patented technology

Core AI Serving Platform Enhancements

A computer system implements a unified framework integrating an adaptive elastic funnel (AEF) with a convergent intelligence fabric (CIF) for flexible and contextualized multi-agent AI and human collaboration at scale. The system provides a universal multi-modal key-value subsystem for sharing partial computations across agents, implements a hybrid greedy / non-greedy placement strategy for dynamic memory management, orchestrates dynamic computational workflows and tensor workflows using hierarchical tensor-fragment scheduling, enables cross-agent orchestration with policy-based privacy preservation, and incorporates quantum-resistant secure memory enclaves. The architecture supports continuous learning without catastrophic forgetting, compositional reasoning across modalities, and secure task execution in distributed environments. This integration enables unprecedented computational efficiency, secure collaboration, and adaptive intelligence in high-dimensional decision-making environments while supporting incremental adoption through modular interfaces.
Owner:QOMPLX INC

Memory system and storage system managing first and second account information for authentication of first and second accounts

According to one embodiment, a memory system includes a nonvolatile memory and a controller. The controller manages first account information to be used for authentication of a first account and second account information to be used for authentication of a second account. The controller receives third account information from a host device. When the third account information matches the first account information, the controller permits access to at least a partial storage area of the nonvolatile memory based on a request from the host device and transmits first data that includes the second account information to a first memory system.
Owner:KIOXIA CORP

Techniques associated with mapping system memory physical addresses to isolation domains for uniform memory access by a system

PendingUS20260064605A1Memory architecture accessing/allocationMemory adressing/allocation/relocationUniform memory accessAddress decoder
Examples include techniques associated with mapping system memory physical addresses to isolation domains for uniform memory access (UMA) by a system. Examples include mapping separate system memory physical addresses ranges associated with memory devices communicatively coupled with at least one compute die of the system through an input / output (I / O) die of the system. The separate system memory physical addresses to be mapped to isolation domains and address decoder information is generated to indicate the mapping of the separate system memory physical address ranges to the isolation domains.
Owner:INTEL CORP

Privilege level assignments to groups

According to examples, an apparatus may include a memory on which is stored machine-readable instructions that may cause a processor to determine, for each of a plurality of members in a group, a respective least privilege level for a resource and determine, based on the determined respective least privilege levels, a privilege level to be assigned to the group for the resource. The instructions may also cause the processor to assign the determined privilege level to the group for the resource and apply the assigned privilege level to the members of the group for the resource.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and method for trusted execution environment, electronic device and storage medium

The embodiment of the invention provides a trusted execution environment system and method, an electronic device and a storage medium, the system comprises a processor, an enclave protection unit and a memory, the enclave protection unit is connected with the processor and the memory through a data bus, and the processor is used for storing the enclave protection unit in a secure mode. In response to a request message for creating a user enclave sent by the user equipment, creating a corresponding user enclave in the memory, and sending an access address of the user enclave to the user equipment and the enclave protection unit, the user enclave being used for storing encrypted user sensitive data; and the enclave protection unit is used for receiving an access request message sent by the user equipment to the user enclave, and accessing the user enclave according to an access address in the access request message, so that the problems that the TEE capabilities of CPUs of different system architectures are not uniform, a uniform security communication mechanism is lacked and only a solution of software TEE is supported in related technologies can be solved.
Owner:ZTE CORP

A method and apparatus for improving data card security

This invention discloses a method and apparatus for improving the security of data cards, relating to the field of information security, and is invented to enhance the security of information stored in data cards. The method includes: binding a data card inserted into a first terminal to the first terminal; generating a decryption password; when a read / write operation is required on the data card, determining whether a second terminal requiring the read / write operation is the first terminal, and if so, decrypting the data card using the decryption password. This invention is mainly applicable to various data cards.
Owner:YULONG COMPUTER TELECOMM SCI (SHENZHEN) CO LTD

Memory system resource partitioning and monitoring (MPAM) configuration using secure processor

Various embodiments include systems and methods for allocating memory resources in a computing system that includes memory system resource partitioning and monitoring (MPAM) features. The computing system may transition from an MPAM configuration controlled using a CPU to using an MPAM configuration managed by an external entity, such as a CPU co-processor (CPCP). The computing system may centralize MPAM operations, introduce various control modes, and / or notify the autonomous decision process in conjunction with the use of system sensors and parameters.
Owner:QUALCOMM INC

Enabling large frames for secure virtual machines

The computer-implemented methods, computer program products, and computer systems include computer operations that include executing, in a trusted computing environment, a call from a host in an untrusted computing environment, where the call is to determine a status of a large page of memory for use by a secure guest, where the secure guest is managed by the host in the untrusted computing environment. The executing includes determining that all small pages comprising the large page and the large page meet pre-defined security requirements. The executing also includes, based on the determining, setting security properties of the large page and the small pages comprising the large page to enable translation for the large page for a given block of memory of the secure guest. The executing also includes storing in a computing element, a designation identifying the large page as belonging to the secure guest.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

Virtualization-based platform protection technology

A data processing system (DPS) uses platform protection technology (PPT) to protect some or all of the code and data belonging to certain software modules. The PPT may include a virtual machine monitor (VMM) to enable an untrusted application and a trusted application to run on top of a single operating system (OS), while preventing the untrusted application from accessing memory used by the trusted application. The VMM may use a first extended page table (EPT) to translate a guest physical address (GPA) into a first host physical address (HPA) for the untrusted application. The VMM may use a second EPT to translate the GPA into a second HPA for the trusted application. The first and second EPTs may map the same GPA to different HPAs. Other embodiments are described and claimed.
Owner:INTEL CORP

Memory access locking and logging for trusted execution environments

This disclosure describes approaches for securing memory among non-secure / secure processing environments such as in a TrustZone-M processor architecture. An example method of controlling memory access includes: configuring a memory locking service in a computing device having a secure processing environment and a non-secure processing environment, and executing the memory locking service in the secure processing environment; receiving a request with the memory locking service to lock a specified memory region of the computing device, with the specified memory region being associated with the non-secure processing environment; associating the specified memory region with the secure processing environment (e.g., by using a Security Attribution Unit to upgrade the region to secure memory); subsequently, identifying an access attempt to the specified memory region, with the access attempt being received from the non-secure processing environment; and controlling the access attempt to the specified memory region, based on a policy.
Owner:ANALOG DEVICES INC

Electronic device including a storage device and a host device and methods of operation

A storage device for providing a security function may include: a nonvolatile memory device including a Replay Protected Memory Block (RPMB); and a memory controller configured for receiving, from an external host, a command UFS Protocol Information Unit (UPIU) including a host RPMB message, and storing data in the RPMB according to authentication performed using the host RPMB message. The command UPIU may include a basic header segment commonly included in UPIUs transmitted / received between the external host and the memory controller, and the basic header segment may include a data segment length field as information indicating that the host RPMB message has been included in the command UPIU.
Owner:SK HYNIX INC

Personalized interactive communication method and system

An interactive communication apparatus, which connects to a computer, comprises an interactive communication device, having a tag, that is removably placed on or adjacent to an interactive communication device holder, having a sensor, wherein the tag communicates information to the sensor. The interactive communication system enables a user to transfer, store or retrieve information about and / or to a person that is identified with that interactive communication device. Once the interactive communication device is placed on or adjacent to the interactive communication device holder, certain communication applications, which include, photo slideshow, chat, e-mails, music, videos, and RSS feed, launch. The user can terminate the applications by removing the interactive communication device from the interactive communication device holder. The user can access content related to a new person by placing another interactive communication device, that corresponds to the new person, on or adjacent to the interactive communication device holder.
Owner:METTA CONCEPTS

Circuitry and methods for capability informed prefetches

Systems, methods, and apparatuses for implementing capability informed prefetches are described. In certain examples, a hardware processor comprises an execution circuit to execute an instruction that generates a memory access request for an element in memory via a first capability; a capability management circuit to check the first capability for the memory access request, the first capability comprising an address field of the element in the memory, a validity field, and a bounds field that is to indicate a lower bound and an upper bound of a first object to which the first capability authorizes access; a cache; and a prefetch circuit to: prefetch an additional element from the memory to the cache, determine if the additional element is a second capability comprising an address field of a second element in the memory, a validity field, and a bounds field that is to indicate a lower bound and an upper bound of a second object to which the second capability authorizes access, and prefetch the second element from the memory to the cache based on the additional element being the second capability.
Owner:INTEL CORP

Process launch constraints

A kernel of an operating system receives a request from a parent process (e.g., an exec or spawn system call) to launch a child process that executes a binary. The kernel identifies a process-specific launch constraint, which is a precondition for launching the child process. The kernel evaluates the constraint, which can match against any type of system state or variable, including the process's location on disk, protection on disk, and how the process is to be launched. The kernel can then determine whether to launch the child process, thus permitting the child process to be scheduled for execution by the operating system. Launch constraints can be used both for a child process to impose preconditions on the parent process, and vice versa. Launch constraints can be included in the launch request, embedded in the binary, or located elsewhere, such as in a trust cache in kernel memory.
Owner:APPLE INC

Control device, control method, and control program

A simple configuration aims to reduce MCU vulnerabilities. [Solution] The control device 10 includes an MCU 20. The MCU 20 has a CPU 22, a system bus 26, a storage device 28, and an address translation device 24 that translates addresses between the CPU address space of the CPU 22 and the system bus address space of the system bus 26 in accordance with translation rules set in a special function register 24A. The MCU 20 starts up in an unrestricted mode in which all addresses in the CPU address space are available, and after startup, when a predetermined condition is met, it switches to a restricted mode in which only a portion of the addresses in the CPU address space are available. The special function register 24A allows the translation rules to be set and read when in the unrestricted mode, and does not allow the translation rules to be set or read when in the restricted mode.
Owner:KK TOSHIBA +1

Partitioned HVAC controller

In some aspects, the HVAC field device described herein includes: a housing; an HVAC functional device; a non-volatile memory unit including: a first set of computer-executable instructions in a first memory partition configured to execute an operating system; and a second set of computer-executable instructions in a second memory partition configured to execute an application module, wherein the application module is configured to control operation of the HVAC functional device; a volatile memory unit; and at least one processor configured to: execute the operating system in a first memory region of the volatile memory unit and execute the application module in a second memory region of the volatile memory unit, wherein the application module is prevented from accessing the first memory region of the volatile memory unit.
Owner:BELIMO HOLDING AG

Software and hardware combined fine-grained memory protection mechanism

The invention relates to a software and hardware combined fine-grained memory protection mechanism, which realizes high-speed mapping from a physical address to a fine-grained permission label by integrating a metadata search unit and a metadata conversion lookup buffer on a critical path of a processor loading / storage unit. An operating system maintains a multi-level fine-grained permission metadata table in a main memory, and the minimum memory protection granularity is refined to a 64-byte sub-page level. When a processor executes a memory access instruction, address conversion and permission verification are completed in parallel, an access type and a permission label are compared in real time within 1-2 clock periods, and when permission conflicts are detected, high-priority abnormity is triggered immediately, and illegal addresses and fault types are reported accurately. The method supports instruction set extension, buffer overflow protection, multi-level metadata management and user mode and kernel mode differentiated authority control, reduces the influence on the performance of the processor while improving the security of the memory, and is suitable for a computing system with high security and high performance.
Owner:SHAOXIN LABORATORY

Segmented non-contiguous reverse map table

A computing device comprises a processor, a table walker, and a memory storing a segmented reverse map table in multiple non-contiguous portions of the memory. The table walker is configured to translate a virtual memory address specified by a memory access request to a physical memory address associated with the virtual memory address; and provide a requester associated with the memory access request with access to the associated physical memory address in response to an indication at the reverse map table that the requester is authorized to access the associated physical memory address.
Owner:ADVANCED MICRO DEVICES INC +1

CXL device for protecting data using memory encryption and method of operating same

The present disclosure relates to a computing high speed link (CXL) device configured to protect data by using data encryption and a method of operation thereof. An example CXL device includes a volatile memory connected to a plurality of channels; and a CXL controller. The CXL controller includes: a CXL subsystem controller configured to search a key index table for a first key index based on first host data and a first device physical address; and a memory subsystem controller configured to search for at least one first key in a key table based on the first key index, and generate first encrypted data based on the first data, the first device physical address, the at least one first key, and an encryption algorithm.
Owner:SAMSUNG ELECTRONICS CO LTD

Low cost and low latency logical unit erase

A memory control unit of a memory device includes at least one hardware processor; and memory storing instructions that cause the at least one hardware processor to perform operations comprising: generating a scrambler seed and a logical block address (LBA) for a block of write data received by the memory control unit from a host device; generating a flash translation layer (FTL) to map the LBA to a physical address (PA); scrambling the block of data using the scrambler seed; encrypting the scrambler seed, the LBA, and the PA in the FTL using an encryption key; initiating writing a scrambled block of data and encrypted LBA and scrambler seed to a memory array; and decrypting the FTL using an incorrect encryption key in response to an erase command received by the memory control unit from the host device.
Owner:LODESTAR LICENSING GROUP LLC

Method of operating a memory controller, a memory controller and a memory system

The present disclosure provides a method of operating a memory controller, a memory controller, and a memory system, and relates to the technical field of memories. The memory controller includes an Advanced Encryption Standard (AES) engine, a processor, and a first interface, and the memory controller is communicatively connected with a first memory through the first interface. The method includes: in response to the memory controller being powered on, obtaining, by the processor, firmware from the first memory through the first interface, wherein the firmware includes a configuration information ciphertext of a first trusted computing group (TCG); and decrypting, by the AES engine, the configuration information ciphertext of the first TCG based on a first key and a preset decryption algorithm, to obtain a configuration information plaintext of the TCG.
Owner:YANGTZE MEMORY TECH CO LTD

Apparatus and method for managing capabilities

An apparatus is described having processing circuitry for performing operations during which access requests to memory are generated. The processing circuitry generates memory addresses for the access requests using capabilities, where each capability indicates a pointer value and constraining information used to constrain access to memory using memory addresses derived from the pointer value. A marker indication field is stored in association with each capability to provide a marker value used to distinguish between static capabilities used to access statically allocated memory and dynamic capabilities used to access dynamically allocated memory. Capability tracking circuitry maintains a tracking structure providing a tracking field for each of a plurality of memory regions, and the capability tracking circuitry sets the tracking field for a given memory region amongst the plurality of memory regions when at least one capability whose associated marker indication field has a specified marker value is written to the given memory region. The specified marker value indicates that writing of the associated capability to memory is to be tracked by the capability tracking circuitry to facilitate subsequent revocation of that associated capability.
Owner:ARM LTD

Digital device and control method therefor

Disclosed are a digital device and a method for controlling the same. The digital device includes a first memory, a second memory used as a swap space for page data in the first memory, and a controller that controls the page data to be swapped out and written in the second memory, and controls the page data written in the second memory to be swapped into the first memory, wherein the controller prevents a write operation of the page data into the second memory, based on a state of the second memory associated with write of the page data, and allows a read-only operation of the page data written in the second memory.
Owner:LG ELECTRONICS INC

Protected regions management of memory

Apparatuses and methods related to managing regions of memory are described. Managing regions can include verifying whether an access command is authorized to access a particular region of a memory array, which may have some regions that have rules or restrictions governing access (e.g., so-called “protected regions”). The authorization can be verified utilizing a key and a memory address corresponding to the access command. If an access command is authorized to access a region, then a row of the memory array corresponding to the access command can be activated. If an access command is not authorized to access the region, then a row of the memory array corresponding to the access command may not be activated.
Owner:LODESTAR LICENSING GROUP LLC

Encrypted key management

Examples of systems and methods described herein provide for erasing an encrypted key used for data access to a non-volatile memory device. A memory controller may generate an encrypted key for data access to non-volatile memory devices; and, to provide security of data stored on the non-volatile memory devices, the memory controller may store the encrypted key in a local cache of the memory controller. The encrypted key may be erased responsive to losing power or powering down of memory controller. Advantageously, the data stored at the non-volatile memory device may not be accessed when the memory controller (or a computing device implementing the memory controller) loses power. Accordingly, if a malicious actor were to physically remove (or steal) a computing device implementing the memory controller (e.g., a laptop computer), in an attempt to acquire the data, the data stored on the non-volatile memory devices could not be accessed.
Owner:MICRON TECHNOLOGY INC

Region identifier based on instruction fetch address

an instruction fetch circuit (105) that, in response to an instruction fetch address, fetches an instruction associated with the instruction fetch address; a processing circuit (125) that, in response to an instruction, performs an operation dependent on the target memory address when the instruction includes a request specifying a target memory address and the request specifying the target memory address is permitted; and a memory security circuit (135) that, when the instruction includes a request specifying the target memory address, determines a current region identifier based on a predetermined slice of the instruction fetch address, identifies permission information for a request issued in response to an instruction associated with the current region identifier based on the current region identifier, determines whether the request is prohibited based on the permission information, and, in response to determining that the request is prohibited, issues a response to the processing circuit indicating that the request is prohibited.
Owner:ARM LTD

Randomized and safe cache architecture

The present disclosure provides a cache architecture comprising a cache memory having a tag storage and a data storage, a miss status holding register (MSHR) configured to track memory requests where each memory request includes a NoFill field, a safe history buffer (SHB) configured to store safe memory addresses and generate cache line fetch requests based on the stored safe memory addresses, and a cache controller configured to prevent cache fills for memory requests having the NoFill field set, send data to a processor without filling the cache memory when the NoFill field is set, and fill the cache memory with cache lines retrieved by the cache line fetch requests generated by the SHB. The cache architecture provides security against cache timing attacks by decorrelating cache fills from actual memory requests while maintaining performance through the safe history buffer mechanism.
Owner:CORESECURE TECH LLC