Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

4results about How to "Reduce performance overhead" patented technology

A container isolation and hardening method and system based on confined eBPF technology

ActiveCN120872480BImprove isolation safetyFlexible and stable security isolationDigital data protectionInternal/peripheral component protectionOperating systemReliability engineering
This invention belongs to the field of computer security technology and relates to a container isolation and hardening method and system based on restricted eBPF technology. The method mainly includes: constructing an eBPF program capable of hardening container security isolation; attaching the eBPF program to kernel hook points; triggering the eBPF program and executing corresponding security protection logic when the kernel executes a critical point on a specific path; constructing a two-level eBPF function permission restriction model based on eBPF program granularity and eBPF helper function granularity; and using this two-level eBPF function permission restriction model to restrict the eBPF functions of the container, enabling the secure use of eBPF technology in container isolation and hardening scenarios. This invention improves the security of container environment isolation while ensuring that eBPF technology itself is not maliciously exploited, making eBPF technology more adaptable to container environments and enhancing its flexibility and security at the container level.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

A method for preventing covert communication in ARM platform caches based on noise loading injection

ActiveCN119835020Bimprove securityReduce performance overheadSecuring communicationCovert communicationDynamic monitoring
This invention discloses a method for defending against cached covert communication on an ARM platform based on noise loading injection. Due to the expanding attack surface of TEEs and the vulnerabilities of TrustZone technology in microarchitectural isolation, cached covert communication has become possible. This invention adds a defense mechanism against cached covert communication based on TrustZone technology, designing a cached covert communication defense architecture based on noise loading injection. Based on this architecture, a dynamic monitoring mechanism, a strategy optimization mechanism, and a noise injection mechanism are proposed. The dynamic monitoring mechanism monitors system security and system performance. The strategy optimization mechanism generates the optimal noise injection strategy and calculates the noise injection frequency and intensity in real time. The noise injection mechanism loads data to resist cached covert communication. This defense method improves the security of the original architecture and achieves low performance overhead, balancing system security and performance.
Owner:BEIJING UNIV OF TECH

Methods, apparatus, storage media and electronic devices for projection processing of virtual objects

This disclosure provides a method, apparatus, computer-readable storage medium, and electronic device for processing the projection of virtual objects, relating to the field of computer technology. The method includes: in response to a controlled virtual object entering an indoor game scene, acquiring first position information of the controlled virtual object in the indoor game scene and second position information of a specified pseudo-light source in the indoor game scene; determining the projection position and projection angle of the controlled virtual object in the indoor game scene based on the first and second position information; displaying a projection decal at the projection position and according to the projection angle in the indoor game scene to simulate the projection of the controlled virtual object in the indoor game scene; wherein the projection decal is generated by rendering based on scene information in the indoor game scene and a specified projection material. This disclosure improves the realism of virtual object projection and enhances the user experience.
Owner:NETEASE (HANGZHOU) NETWORK CO LTD

An operating system security authentication and key management method based on post-quantum signature

PendingCN122160130AEffectively resist quantum computing attacksGuaranteed long-term securityKey distribution for secure communicationMultiple keys/algorithms usageOperational systemOperating system security
The application discloses a kind of based on post-quantum signature operating system security authentication and key management method, belong to operating system security and quantum security technical field, including the following steps, establish the three-layer security architecture model based on hardware trust root-post-quantum signature chain-mixed key management;Operating system security authentication is carried out based on three-layer security architecture model;After security authentication passes, the whole life cycle management of post-quantum key is executed to generate key, and in the process, the way of hardware isolation and encryption protection is used to ensure that key is not leaked, traceable and controllable;Post-quantum signature and the post-quantum key obtained in the above step are deployed to the operating system and terminal equipment that have passed security authentication, the application uses the above method, realizes operating system full-scene anti-quantum security authentication, guarantees the safety of the whole life cycle of key, realizes the smooth compatibility with existing traditional cryptographic system, reduces migration cost, improves the overall security level of operating system.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD