A memory mapping and data management method, system and storage medium
Patent Information
- Application Number
- CN202111145588.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-28
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2041-09-28
AI Technical Summary
如果攻击者利用用户态或启动阶段等的数据传输,就极容易访问内存中的其他数据区域从而实现攻击,其中危险的攻击甚至可以实现数据的越权访问和篡改,例如在系统启动时和启动后,对于BOOT参数的访问和修改等,又由于现有的内存架构和系统架构的设计和检查机制,很少能及时发现该类的攻击
[0050]1、启动时和启动后,如需要修改boot的参数,必须提供有效的验证码,该验证码在制作启动image时由md5算法产生;该方法能够限制知悉该验证码的人数,同时减少了非法访问的可能性。类似于手机银行使用短信验证码采取的第三方验证方式。
Smart Images

Figure CN113849430B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer storage security, and in particular to a method, system, and storage medium for memory mapping and data management. Background Technology
[0002] In conventional operating systems and computer architectures, memory design and usage mostly focus on storage efficiency, ease of data access, and overall design compactness. These designs often result in little to no encapsulation or effective access management of the entire memory data, or only limited encapsulation for specific compilations. In actual system operation, especially during the system startup phase, data access is almost unrestricted and unprotected, and data in memory can be accessed arbitrarily without any checks.
[0003] The data storage areas in memory are primarily designed for ease of access and compactness, with little consideration given to the security of accessing different types of data. If an attacker exploits data transfers during user mode or startup, they can easily access other data areas in memory to carry out an attack. Dangerous attacks can even result in unauthorized access and data tampering, such as accessing and modifying BOOT parameters during and after system startup. Furthermore, due to the design and detection mechanisms of existing memory and system architectures, such attacks are rarely detected in a timely manner. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention proposes a memory mapping and data management method, system, and apparatus. Specifically, this invention provides the following technical solutions:
[0005] On one hand, the present invention provides a memory mapping and data management method, the method comprising:
[0006] S1. Based on the differences in usage scenarios, the memory is divided into multiple regions, including the boot region, system region, share region, and user region;
[0007] S2. Set access control attributes for the multiple regions;
[0008] In the boot area, writing and reading data are only allowed to be performed by users with specified permissions, and when reading data, the destination address is a specified area in the system area;
[0009] The system area contains a converter layer, which uses a hash algorithm to manage the addresses for reading and writing data.
[0010] The share area serves as a temporary mapping area for data interaction between the user area and the system area;
[0011] The user area is used for access by the OS and user space;
[0012] S3. Based on the request, perform data access and control for the corresponding area.
[0013] Preferably, in step S2, the permission settings in the boot area include:
[0014] It is able to access the boot image verification code, which serves as the unique access key to the boot image; the boot image verification code is preferably generated using MD5 encryption.
[0015] During system startup, after verification via CAPTCHA, the user has direct read and write permissions; after system startup, after verification via CAPTCHA, the user has shared read and shared write permissions.
[0016] Preferably, in step S2, when modifying the boot parameters in the boot area, the name of the parameter to be modified is first determined, the corresponding storage address is found based on the name of the parameter to be modified, and the validity of the parameter value to be modified is checked.
[0017] Secondly, after the validity check passes, the parameter values to be modified are written to the backup area. Once all parameter values to be modified have been modified, the current parameter area is set as the new backup area, the backup area is set as the valid parameter area, and a restart is performed.
[0018] Preferably, when a restart fails, after a timeout, the new backup area is swapped with the valid parameter area, and the reason for the restart failure is displayed.
[0019] Preferably, in the boot area, the specified destination address for reading is a specified area in the system area, which is achieved in the following way:
[0020] The destination address can be specified by accessing the verification code via boot; or
[0021] Set the external interface of the specified area to the name of the saved variable. When reading, read the name of the saved variable into the shared area and then display it through the console to ensure that the destination address is the specified area.
[0022] Preferably, the converter layer is established as follows:
[0023] A hash table covering the entire memory is established, the hash table is stored at the beginning of the system area, and is established after the memory is initialized;
[0024] After the hash table is created, only read permissions are retained, and write permissions are canceled.
[0025] Preferably, in the share area, a user flag and a system flag are set;
[0026] When data is sent from the system area to the user area, the target address of the user area and the data to be sent are written to the share area, and the user flag is set to 1; when a thread finds that the user flag is set to 1, it writes the data to be sent from the share area to the target address of the user area, and clears the user flag to 0.
[0027] When data is sent from the user area to the system area, the target address of the system area and the data to be sent are written to the share area, and the system flag is set to 1. When the thread finds that the system flag is set to 1, it checks whether the address in the share area is within the writable range and whether the data to be sent is valid. If both are true, the data to be sent in the share area is written to the target address of the system area, and the system flag is cleared to 0.
[0028] On the other hand, the present invention also provides a memory mapping and data management system, which includes memory, a control module, and an encryption module;
[0029] The memory is divided into multiple regions, including a boot region, a system region, a share region, and a user region.
[0030] In the boot area, writing and reading data are only allowed to be performed by users with specified permissions, and when reading data, the destination address is a specified area in the system area;
[0031] The system area contains a converter layer, which uses a hash algorithm to manage the addresses for reading and writing data.
[0032] The share area serves as a temporary mapping area for data interaction between the user area and the system area;
[0033] The user area is used for access by the OS and user space;
[0034] The control module is used to control the determination of access to data in the memory;
[0035] The encryption module is used to generate verification codes. These codes can be generated using an existing encryption method, or, depending on security requirements, by combining multiple encryption algorithms.
[0036] Preferably, in the boot area, the settings for specified permissions include:
[0037] It can access the boot image verification code, which serves as the unique access key to the boot image; the boot image verification code is generated by the encryption module.
[0038] The boot area is configured such that, during the system startup phase, after verification via a verification code, it has direct read and write permissions; and after system startup, after verification via a verification code, it has shared read and shared write permissions.
[0039] Preferably, when modifying boot parameters in the boot area, the control module determines the name of the parameter to be modified, finds the corresponding storage address based on the name of the parameter to be modified, and performs a validity check on the value of the parameter to be modified.
[0040] After the validity check passes, the control module sends a write command to write the parameter values to be modified to the backup area of the boot area. After all the parameter values to be modified have been modified, the current parameter area is set as the new backup area, and the backup area is set as the valid parameter area. By swapping the functions of the backup area and the parameter area, the waste of storage area can be effectively reduced, and data backup and recovery can be achieved more conveniently.
[0041] After completing the above tasks, the control module executes the system restart command.
[0042] Preferably, in the converter layer, a hash table is established at the beginning of the system area, and the hash table is established after memory initialization;
[0043] The hash table addresses cover the entire memory, and after its creation, only read permissions are retained, while write permissions are cancelled.
[0044] Preferably, to ensure the security of data transmission between different storage areas, a user flag bit, a system flag bit, a share to user area, and a share to system area are set in a separately established share area;
[0045] The user flag bit is used to identify whether the data in the user share area meets the sending requirements; the system flag bit is used to identify whether the data in the system share area meets the sending requirements.
[0046] The share to user area is used to store the data to be sent to the user area and the target address of the user area;
[0047] The share to system area is used to store data that is to be sent to the system area and the target address of the system area.
[0048] In another aspect, the present invention also provides a computer-readable storage medium storing a computer program that controls a memory device to perform the memory mapping and data management method as described above.
[0049] Compared with the prior art, the present invention has at least the following advantages:
[0050] 1. During and after startup, if boot parameters need to be modified, a valid verification code must be provided. This verification code is generated using the MD5 algorithm when creating the boot image. This method limits the number of people who can know the verification code and reduces the possibility of unauthorized access. It is similar to the third-party verification method used by mobile banking with SMS verification codes.
[0051] 2. Indirect address access during the Boot phase means that modification requires knowing the valid parameter name and cannot be done through direct memory address access. In other words, only personnel familiar with the system can modify the parameters, thus limiting the possibility of unauthorized access. Attached Figure Description
[0052] Figure 1 This is a memory structure block diagram according to an embodiment of the present invention;
[0053] Figure 2 This is a flowchart illustrating the method implementation of an embodiment of the present invention. Detailed Implementation
[0054] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the figures. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0055] In one specific embodiment, combined with Figure 1 , Figure 2 As shown, the preferred embodiment of the present invention can be implemented in the following manner:
[0056] Step 1: Divide the memory into boot, system, share, and user regions according to different usage scenarios;
[0057] The Boot area is used to meet the memory requirements of the boot loader stage when the chip starts up, and stores the data segment in the boot code as well as the data generated during runtime;
[0058] The System area serves as the management area for the operating system, storing runtime data for the operating system.
[0059] The User area stores data that is used during application runtime.
[0060] The Share area stores temporary data when the operating system and applications interact.
[0061] Step 2: Set different access control attributes for each area according to its security level; access control attributes can be, for example, direct read, direct write, shared write, shared read, etc.
[0062] Step 3: Boot area. Data writing operations are only allowed by specific users, meaning only users with specified permissions can perform this operation, and the data to be written is controlled by a specified algorithm. Here, the specified algorithm can be, for example, the MD5 encryption algorithm, or other encryption algorithms to further ensure the security of data operations.
[0063] In a more preferred embodiment, a specific writer (i.e., a person with designated permissions) can be configured as follows to ensure the security of data operations in the corresponding area:
[0064] (1) You need to know the verification code of the boot image in advance. The verification code is generated by an algorithm such as MD5 when the boot image is generated and serves as the unique access key of the boot image.
[0065] (2) During the system startup phase, after obtaining the verification code, you can have direct read and direct write permissions. After the system starts up, after obtaining the verification code, you can have shared read and shared write permissions.
[0066] (3) If it is necessary to modify the boot parameters, the modifier must first know the name of the parameter to be modified. When modifying, the modifier must first find the corresponding storage address by the name of the parameter to be modified, and perform a validity check on the parameter value, such as the corresponding MD5 check. Only after passing the check will the data be written to the backup area. After all the data has been modified, the current parameter area is set as the new backup area, the backup area is set as the valid parameter area, and then the system restarts. If the startup fails, after the watchdog timeout, the current valid parameter area and the backup area (referring to the new backup area) are swapped, and the failure is indicated as being caused by parameter errors.
[0067] Step 4: In the boot area, data reading can only be controlled by a specific user, meaning only users with specified permissions can perform this operation, and the destination address for data reading must be a region specified in the system.
[0068] In a more preferred embodiment, control of a specified area can be achieved in at least two ways: 1. Specifying the destination address by accessing the boot verification code; 2. The external interface of the area can be set to store the name of a variable. When a read operation is performed, the name of the stored variable is first read into the share area and then displayed through the console, instead of being displayed directly from the stored address. This way, data can be read into the specified area.
[0069] Step 5: In the system area, a converter layer is built inside, and a hash algorithm is used to manage the addresses for reading and writing data within this layer;
[0070] The purpose of establishing an internal converter layer is to shield the data from its specific memory address, preventing malicious access to that address. In a preferred embodiment, the converter layer can be established by creating a hash table whose address covers the entire memory space. In a more preferred embodiment, the minimum address bits of each item in the hash table are 10, which is in megabytes (M). This hash table is stored at the beginning of the system area memory. The table is created after memory initialization, and after creation, only read permissions are retained, while write permissions are removed.
[0071] Step 6: The share area is a temporary mapping area used for data exchange between the user and the system;
[0072] To ensure adequate protection of data access in this solution, a shared area is set up as a temporary mapping area for data interaction between the system and the user in specific scenarios, such as when the system needs to access user data and the user needs to access system data. The shared area is preferably implemented in the following way:
[0073] 1. When data is sent from system to user: the target address and the data to be written in user are written to the share area, and the flag is set to 1. The user running thread keeps querying the flag. When it finds that the flag is 1, it writes the data set in the share area to the target address and clears the flag to 0.
[0074] 2. When data from user is sent to system: The target address in system and the data to be written are written to the shared area, and the flag is set to 1. The system running thread keeps querying the flag. After finding that the value is 1, it checks whether the address in the shared area is within the writable range and whether the data to be written is a valid value. If both are true, the data is written to the corresponding address and the flag is cleared to 0.
[0075] Step 7: User zone, which can be accessed by the OS and user-mode users.
[0076] Step 8: After the above settings are completed, data access and control for the corresponding area will be performed based on the request.
[0077] Combined again Figure 1 In another specific embodiment, the solution of the present invention can also be implemented through a memory mapping and data management system, which includes memory, a control module, and an encryption module;
[0078] like Figure 1 As shown, the memory is divided into multiple regions, including the boot region, system region, share region, and user region. Of course, other module regions can also be set up within the memory regions to execute other corresponding functions of the entire system.
[0079] In the boot area, writing and reading data are only allowed to be performed by users with specified permissions, and when reading data, the destination address is a specified area in the system area;
[0080] The system area contains a converter layer, which uses a hash algorithm to manage the addresses for reading and writing data.
[0081] The share area serves as a temporary mapping area for data interaction between the user area and the system area;
[0082] The user area is used for access by the OS and user space (i.e., user access);
[0083] The control module is used to control the determination of access to data in the memory;
[0084] The encryption module is used to generate verification codes. These codes can be generated using an existing encryption method, or, depending on security requirements, by combining multiple encryption algorithms.
[0085] Preferably, in the boot area, the settings for specified permissions include:
[0086] It can access the boot image verification code, which serves as the unique access key to the boot image; the boot image verification code is generated by the encryption module.
[0087] The boot area is configured such that, during the system startup phase, after verification via a verification code, it has direct read and write permissions; and after system startup, after verification via a verification code, it has shared read and shared write permissions.
[0088] Preferably, when modifying boot parameters in the boot area, the control module determines the name of the parameter to be modified, finds the corresponding storage address based on the name of the parameter to be modified, and performs a validity check on the value of the parameter to be modified.
[0089] After the validity check passes, the control module sends a write command to write the parameter values to be modified to the backup area of the boot area. After all the parameter values to be modified have been modified, the current parameter area is set as the new backup area, and the backup area is set as the valid parameter area. By swapping the functions of the backup area and the parameter area, the waste of storage area can be effectively reduced, and data backup and recovery can be achieved more conveniently.
[0090] After completing the above tasks, the control module executes the system restart command.
[0091] Preferably, in the converter layer, a hash table is established at the beginning of the system area, and the hash table is established after memory initialization; more preferably, the minimum address of each item in the hash table is 10 bits, that is, in megabytes (M).
[0092] The hash table addresses cover the entire memory, and after its creation, only read permissions are retained, while write permissions are cancelled.
[0093] Preferably, to ensure the security of data transmission between different storage areas, a user flag bit, a system flag bit, a share to user area, and a share to system area are set in a separately established share area;
[0094] The user flag bit is used to identify whether the data in the user share area meets the sending requirements; the system flag bit is used to identify whether the data in the system share area meets the sending requirements.
[0095] In a more preferred embodiment, whether the data in the share area meets the requirements can be configured as follows:
[0096] (1) When data is sent from the system to the user: check whether the target address and the data to be written in the user area have been written to the share area. If the writing has been completed, set the user flag to 1.
[0097] (2) When data is sent from user to system: check whether the target address in the system area and the data to be written have been written to the share area. If the writing is completed, set the system flag to 1. In a more preferred embodiment, if the system running thread keeps querying the system flag and finds that the value is 1, it performs further checks—checking whether the address in the share area is within the writable range and whether the written data is a valid value. If both are true, the data is written to the corresponding address, and the flag is cleared to 0. At this point, the data writing operation is complete.
[0098] The share to user area is used to store data that is about to be sent to the user area and the target address of the user area;
[0099] The share to system area is used to store data that is about to be sent to the system area and the target address of the system area.
[0100] In addition, the solution of the present invention can also be implemented by a computer program or a storage medium that can carry a computer program, so as to execute the memory mapping and data management method given in the embodiments of the present invention.
[0101] Alternatively, the solution of the present invention can also be implemented by an electronic device, which can be equipped with or carried by the memory mapping and data management system listed in the present invention, and the device can also be equipped with, for example, a display, input devices, etc., to facilitate the realization of the device's functions.
[0102] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0103] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A memory mapping and data management method, characterized in that, The method includes: S1. Based on the differences in usage scenarios, the memory is divided into multiple regions, including the boot region, system region, share region, and user region; S2. Set access control attributes for the multiple regions; In the boot area, writing and reading data are only allowed to be performed by users with specified permissions, and when reading data, the destination address of the data read is a specified area in the system area; The system area contains a converter layer, which uses a hash algorithm to manage the addresses for reading and writing data. The share area serves as a temporary mapping area for data interaction between the user area and the system area; The user area is used for access by the OS and user space; S3. Based on the request, perform data access and control for the corresponding area; In S2, when modifying the boot parameters in the boot area, the name of the parameter to be modified is first determined, the corresponding storage address is found based on the name of the parameter to be modified, and the validity of the parameter value to be modified is checked. Secondly, after the validity check passes, the parameter values to be modified are written to the backup area. Once all the parameter values to be modified have been modified, the current parameter area is set as the new backup area, the backup area is set as the valid parameter area, and a restart is performed. In the boot area, the destination address to be read is specified in the system area, which is achieved in the following way: The destination address can be specified by accessing the verification code via boot; or Set the external interface of the specified area to the name of the saved variable. When reading, read the name of the saved variable into the shared area and then display it through the console to ensure that the destination address is the specified area. In step S2, the settings for specified permissions in the boot area include: It can access the boot image verification code, which serves as the unique access key to the boot image. During system startup, after verification via CAPTCHA, the user has direct read and write permissions; after system startup, after verification via CAPTCHA, the user has shared read and shared write permissions.
2. The method according to claim 1, characterized in that, When a reboot fails, after a timeout, the new backup area and the valid parameter area will be swapped, and the reason for the reboot failure will be displayed.
3. The method according to claim 1, characterized in that, The converter layer is established as follows: A hash table covering the entire memory is established, the hash table is stored at the beginning of the system area, and is established after the memory is initialized; After the hash table is created, only read permissions are retained, and write permissions are canceled.
4. The method according to claim 1, characterized in that, In the shared area, the user flag and system flag are set; When data is sent from the system area to the user area, the target address of the user area and the data to be sent are written to the share area, and the user flag bit is set to 1; when a thread finds that the user flag bit is set to 1, it writes the data to be sent from the share area to the target address of the user area, and clears the user flag bit to 0. When data is sent from the user area to the system area, the target address of the system area and the data to be sent are written to the share area, and the system flag is set to 1. When the thread finds that the system flag is set to 1, it checks whether the address in the share area is within the writable range and whether the data to be sent is valid. If both are true, the data to be sent in the share area is written to the target address of the system area, and the system flag is cleared to 0.
5. A memory mapping and data management system, characterized in that, The system includes a memory, a control module, and an encryption module; The memory is divided into multiple regions, including a boot region, a system region, a share region, and a user region. In the boot area, writing and reading data are only allowed to be performed by users with specified permissions, and when reading data, the destination address of the data read is a specified area in the system area; The system area contains a converter layer, which uses a hash algorithm to manage the addresses for reading and writing data. The share area serves as a temporary mapping area for data interaction between the user area and the system area; The user area is used for access by the OS and user space; The control module is used to control the determination of access to data in the memory; The encryption module is used to generate verification codes; In the boot area, when modifying boot parameters, the name of the parameter to be modified is first determined, the corresponding storage address is found based on the name of the parameter to be modified, and the validity of the parameter value to be modified is checked. Secondly, after the validity check passes, the parameter values to be modified are written to the backup area. Once all the parameter values to be modified have been modified, the current parameter area is set as the new backup area, the backup area is set as the valid parameter area, and a restart is performed. In the boot area, the destination address to be read is specified in the system area, which is achieved in the following way: The destination address can be specified by accessing the verification code via boot; or Set the external interface of the specified area to the name of the saved variable. When reading, read the name of the saved variable into the shared area and then display it through the console to ensure that the destination address is the specified area. In the boot area, the specified permissions settings include: It can access the boot image verification code, which serves as the unique access key to the boot image. During system startup, after verification via CAPTCHA, the user has direct read and write permissions; after system startup, after verification via CAPTCHA, the user has shared read and shared write permissions.
6. A computer-readable storage medium, characterized in that, The storage medium stores a computer program that controls the memory device to execute the memory mapping and data management method according to any one of claims 1-4.
Citation Information
Patent Citations
Cloud computing system and method and device for controlling user permission through quadratic mapping of cloud computing system
CN103716412A
Flushbonding CPU for information safety
CN1545023A