Apparatus and method for managing access to data memory based on execution context

By introducing a memory manager and a high-privilege execution environment into the kernel, the kernel's access to data memory is dynamically managed, solving the problem of memory data vulnerability in computing systems and achieving data isolation and enhanced security between kernels.

CN116635855BActive Publication Date: 2026-07-24HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2020-12-20
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In the prior art, the memory data of computing systems is vulnerable to unauthorized access and attacks, especially in multi-core CPU environments. Existing defense mechanisms such as the MMU can be reprogrammed, the implementation of TEE has additional overhead and compatibility issues, and there is a lack of isolation mechanisms for data access between multi-core CPU cores.

Method used

By introducing a memory manager into the kernel, and utilizing a high-privilege execution environment such as a TEE or hypervisor, kernel access to data memory can be dynamically managed, different data contexts can be isolated, and kernel access can be allowed only when necessary, thereby reducing execution overhead and enhancing security.

Benefits of technology

It achieves data isolation between kernels, reduces the risk of unauthorized access and attacks, lowers execution overhead, and improves the security and efficiency of computing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116635855B_ABST
    Figure CN116635855B_ABST
Patent Text Reader

Abstract

An apparatus and method for protecting a data memory are disclosed. The apparatus includes a processor coupled to the data memory. The processor and the data memory are to implement a kernel executing an operating system. The kernel is to execute a memory manager that determines access of the data memory by the kernel. The processor is to provide a high-privilege execution environment managed by the memory manager that controls access of one or more executable codes to one or more portions of the data memory. The kernel is further to support a plurality of data contexts accessible to the one or more executable codes while denying access of the one or more executable codes to data contexts unrelated to the one or more executable codes.
Need to check novelty before this filing date? Find Prior Art