Memory management method and related equipment

By managing memory space in the server and setting access permissions, the data security problem caused by the sharing of memory space by computing units is solved, and the isolation of memory space and the security of data storage is improved.

CN120217420APending Publication Date: 2025-06-27HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410381629.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-26
Filing Date
2024-03-29
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

On the server, the computing unit shares memory space, resulting in low data security.

Method used

By managing memory space in the server, allocating isolated memory space for each application or virtual instance, and setting access permissions by accessing the page table, ensuring that only authorized devices or virtual instances can access their allocated memory space.

Benefits of technology

Isolation of memory space is achieved, preventing the operation of other devices or virtual instances from being affected, and improving the security of data storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217420A_ABST
    Figure CN120217420A_ABST
Patent Text Reader

Abstract

The invention provides a memory management method and related equipment, which are used for improving the security of data storage. The memory management method is applied to the server, the server is used for managing memory space, the method comprises the steps that a first request sent by a first virtual instance or a first application on the server is obtained, and the first request is used for requesting to use the memory space which is managed by the server and has first memory capacity. According to the first memory capacity requested by the first request, a first memory space is configured for first equipment occupied by the first virtual instance or the first application in the memory space managed by the server, and the capacity of the first memory space is larger than or equal to the first memory capacity. And setting an access permission of the first memory space, wherein the access permission indicates that the equipment for performing data reading / writing operation on the first memory space is the first virtual instance or the first equipment.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application titled "A Method for Providing Secure Memory and Related Devices" with an application number of 202311825012.3, filed with the China National Intellectual Property Administration on December 26, 2023. The entire content of this Chinese patent application is incorporated herein by reference. Technical Field

[0002] This application relates to the field of computers, and particularly to a memory management method and related devices. Background Art

[0003] With the development of computer technology, servers have more and more functions, and the number and types of computing units on servers are also increasing. How to manage the data required by these computing units during operation has become an urgent problem to be solved.

[0004] In related technical solutions, the computing units on the server share the memory space. Since each computing unit stores its respective core data in this memory space during operation, and this memory space is shared, the security of the data is not high. Summary of the Invention

[0005] This application provides a memory management method and related devices for improving the security of data storage.

[0006] In a first aspect, this application provides a memory management method, which is applied to a server. The method includes:

[0007] The server is used to manage the memory space, specifically, it can manage the memory space of the host on the server. The server obtains a first request, which is used to request to use the memory space with a first memory capacity managed by the server. The first request can be issued by a first application running on the server or a first virtual instance running on the server. Further, the first application runs on the processor included in the server. The first request indicates that the memory capacity to be used is the first memory capacity. Based on this, the server configures a first memory space from the memory space managed by the server for the first device occupied by the first application or for the first virtual instance. Among them, the capacity of the first memory space is greater than or equal to the first memory capacity to meet the first memory capacity requested by the first request. The server also sets the access permission of the first memory space. The access permission indicates that the device for performing data read / write operations on the first memory space is the first device occupied by the first application or the first virtual instance. That is to say, the first device or the first virtual instance has the right to perform data read / write operations on the first memory space during operation, and the device for performing data read / write operations on the first memory space is limited to the first device or the first virtual instance.

[0008] In this application, a first memory space is allocated for a first device or a first virtual instance, and it is set that the devices with permission to access the first memory space are limited to the first device or the first virtual instance, thereby achieving the isolation of the first memory space from other memory spaces. Then, the data used by the first device or the first virtual instance stored in the first memory space will not be affected by the operations of other devices, ensuring the security of data storage in the first memory space, that is, improving the security of data storage.

[0009] In some optional implementation manners of the first aspect, the server can set the access permission of the first memory space by establishing an access page table for the first memory space. Among them, the access page table includes a first mapping relationship between the physical address of the first device and the physical address of the first memory space, or the access page table includes a second mapping relationship between the physical address of the first virtual instance and the physical address of the first memory space. It can be understood that the access page table can implement the address conversion function of data read / write operations. Then, when the first device initiates a data read / write request to the first memory space, according to the physical address of the first device and the access page table, the corresponding physical memory address can be determined in the first memory space to achieve access to the first memory space. Similarly, when the first virtual instance initiates a data read / write request to the first memory space, according to the physical address of the first virtual instance and the access page table, the corresponding physical memory address can be determined in the first memory space to achieve access of the first virtual instance to the first memory space. This process also realizes the authorization of the access page table for the first device or the first virtual instance to access the first memory space.

[0010] In this application, setting the access permission of the first device or the first virtual instance to the first memory space by the access page table provides technical support for the implementation of the technical solution of this application and improves the feasibility of the technical solution of this application.

[0011] In some optional implementation manners of the first aspect, the first virtual instance occupies a second device, that is to say, the second device is a virtualization module included in the first virtual instance, such as a virtual network card, etc. In the embodiments of this application, memory isolation of the second device can also be achieved, that is, the first memory space applied for by the first request can be configured for the second device. In this solution, the aforementioned second mapping relationship is actually a mapping relationship between the physical address of the second device and the physical memory address of the first memory space.

[0012] In some alternative implementations of the first aspect, the server receives an access request for a second device, and the physical address corresponding to the access request is not included in the access page table, which means that the second device has no right to access the first memory space. The server sends response information to the second device, and the response information indicates that the second device has no permission to access the first memory space, and the second device has no permission to perform data read / write operations on the first memory space.

[0013] In this application, the physical address of the second device is not included in the access page table, which means that the second device has no right to access the first memory space, thus realizing the operation isolation between the data in the first memory space and other devices and ensuring the data storage security of the first memory space.

[0014] In some alternative implementations of the first aspect, the first virtual instance includes a virtual machine (VM) or a container running on the server.

[0015] In this application, there are various possibilities for the first virtual instance, enriching the implementation methods and application scenarios of the technical solution of this application and enhancing the practicability of the technical solution of this application.

[0016] In some alternative implementations of the first aspect, the memory space managed by the server includes the local memory of the server. According to the first memory capacity requested by the first request, configure a first memory space for the first device occupied by the first virtual instance or the first application in the memory space managed by the server, including: when the capacity of the free memory space in the local memory is greater than or equal to the first memory capacity, the server configures a first memory space for the first device or the first virtual instance from the free memory space in the local memory.

[0017] In some alternative implementations of the first aspect, the memory space managed by the server includes a remote memory, and the remote memory is set outside the server. According to the first memory capacity requested by the first request, configure a first memory space for the first device occupied by the first virtual instance or the first application in the memory space managed by the server, including: when the capacity of the free memory space in the remote memory is greater than or equal to the first memory capacity, the server configures a first memory space for the first device or the first virtual instance from the free memory space in the remote memory.

[0018] In this application, there are various situations for the memory space managed by the server, and there are also various possibilities for the first memory space configured for the first device or the first virtual instance. It can be selected according to the actual application, enriching the implementation methods and application scenarios of the technical solution of this application and enhancing the flexibility of the technical solution of this application.

[0019] In some alternative implementations of the first aspect, the memory space managed by the server includes local memory and remote memory, and the remote memory is set outside the server. According to the first memory capacity requested by the first request, configure the first memory space for the first device or the first virtual instance occupied by the first application in the memory space managed by the server, including: when the capacity of the free memory space in the local memory and the capacity of the free memory space in the remote memory are both greater than or equal to the first memory capacity, the server has multiple ways to configure the first memory for the first device or the first virtual instance. It can be to select one of the free memory space in the local memory and the remote memory to configure the first memory space for the first device or the first virtual instance, or configure a mixed first memory space (that is, part of the memory space in the first memory space is included in the free memory space of the local memory, and the other part is included in the free memory space of the remote memory).

[0020] In this application, when the memory space managed by the server includes the local memory and the remote memory of the server, the server has multiple ways to configure the first memory space for the first device or the first virtual instance, further enriching the application scenarios of the technical solution of this application.

[0021] In some alternative implementations of the first aspect, when the memory space managed by the server includes the local memory and the remote memory of the server, and the capacity of the free memory space in the local memory and the capacity of the free memory space in the remote memory are both greater than or equal to the first memory capacity, the server can configure the first memory space for the first device or the first virtual instance according to a preset rule. Among them, there are multiple possibilities for the preset rule. For example, preferentially select the memory with a large free memory space, or select the memory space with the same configuration type as the most recent configuration, or configure the first memory space in the free memory space of the local memory and the free memory space of the remote memory according to a ratio, etc. The specific details are not limited here.

[0022] In a second aspect, an embodiment of this application provides a memory management device, including:

[0023] A transceiver unit, configured to obtain a first request sent by a first application or a first virtual instance on the server, where the first request is used to request to use a memory space with a first memory capacity managed by the server.

[0024] A processing unit, configured to configure a first memory space for a first device or a first virtual instance occupied by the first application in the memory space managed by the server according to the first memory capacity requested by the first request, where the capacity of the first memory space is greater than or equal to the first memory capacity. Set the access permission of the first memory space, and the access permission indicates that the device for performing data read / write operations on the first memory space is the first device or the first virtual instance.

[0025] The memory management device is used to implement the memory management method shown in the foregoing first aspect or any possible implementation manner in the first aspect. Its beneficial effects are as shown above and will not be elaborated here.

[0026] In a third aspect, the present application provides a computer device, including a processor and a memory. The processor stores instructions, and when the instructions stored in the memory run on the processor, the method shown in the foregoing first aspect or any possible implementation manner in the first aspect is implemented.

[0027] In a fourth aspect, the present application provides a computer-readable storage medium, in which instructions are stored. When the instructions run on a processor, the method shown in the foregoing first aspect or any possible implementation manner in the first aspect is implemented.

[0028] In a fifth aspect, the present application provides a computer program product. When the computer program product is executed on a processor, the method shown in the foregoing first aspect or any possible implementation manner in the first aspect is implemented.

[0029] The beneficial effects shown in any one of the third aspect to the fifth aspect are similar to those in the first aspect or any possible implementation manner in the first aspect, and will not be elaborated here. Description of the Drawings

[0030] Figure 1 It is a schematic diagram of the system architecture provided by an embodiment of the present application;

[0031] Figure 2 It is a flowchart of the memory management method provided by an embodiment of the present application;

[0032] Figure 3 It is a schematic diagram of the memory management method provided by an embodiment of the present application;

[0033] Figure 4 It is another schematic diagram of the memory management method provided by an embodiment of the present application;

[0034] Figure 5 It is another schematic diagram of the memory management method provided by an embodiment of the present application;

[0035] Figure 6 It is another schematic diagram of the memory management method provided by an embodiment of the present application;

[0036] Figure 7 It is a schematic diagram of the structure of the memory management device provided by an embodiment of the present application;

[0037] Figure 8 It is a schematic diagram of the structure of the computer device provided by an embodiment of the present application. Detailed Embodiments

[0038] Embodiments of the present application provide a method for memory management and related devices, which are used to improve the security of data storage.

[0039] The embodiments of the present application will be described below with reference to the accompanying drawings. As can be known to those of ordinary skill in the art, with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0040] Terms such as "first" and "second" in the specification, claims and above-mentioned drawings of the present application are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing the embodiments of the present application. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not necessarily have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices. In addition, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item) of the following" or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c may be single or multiple.

[0041] First, please refer to Figure 1 , Figure 1 which is a schematic diagram of the system architecture provided by the embodiments of the application.

[0042] Optionally, as shown in Figure 1 , an application is running on the server processor, and the application can also occupy a device. As shown in Figure 1 , the application occupies device 1. Among them, the application can also be called a process. The application occupying device 1 can be understood as the application being bound to device 1.

[0043] Optionally, as shown in Figure 1 , virtual instances can also run on the server. The virtual instances can also include devices. At this time, the device is a virtualized module, such as a virtual network card, etc.

[0044] In the implementation of this application, the server manages the memory space, which includes the local memory of the host or the remote memory set outside the server. That is to say, the storage location of the data in the local memory is on the local server, and the storage location of the data in the remote memory is on the remote server. The remote memory can be accessed through the Internet.

[0045] It should be noted that Figure 1 This is only a schematic diagram of the system architecture provided by the embodiments of this application. In actual applications, the server may only include applications or virtual instances, and the applications or virtual instances can also manage a larger number of devices. The specific details are not limited here.

[0046] Please refer to Figure 2 , Figure 2 which is a schematic flow diagram of the memory management method provided by the embodiments of this application.

[0047] 201. The server obtains a first request sent by a first virtual instance or a first application on the server. The first request requests to use the memory space managed by the server with a first memory capacity.

[0048] The server receives the first request. The first request carries the identifier of the first virtual instance or the first device, which is used to indicate that the memory space applied for by the first request is for the first virtual instance or the first device. Among them, the identifier of the first virtual instance or the first device is used to uniquely indicate the first virtual instance or the first device, and it can be the product serial number (SN) of the first virtual instance or the first device, the identity document (ID) of the first virtual instance or the first device, etc. The identifier can be set according to the actual application needs, and the specific details are not limited here. The first request may also carry the first memory capacity, and the first memory capacity indicates the size of the memory space applied for by the first request.

[0049] There are many possible ways for the server to obtain the first request, which are described separately below:

[0050] In some alternative embodiments, the first request is sent by the first application. The first application occupies or manages the first device. The first application calls the driver interface of the first device, so that the kernel of the host in the server binds the ownership of the first device to the first application, realizing the management of the first device by the first application, or in other words, realizing the occupation of the first device by the first application. Then, when the server processes the request for the first device, it will only process the request sent by the first application bound to the first device, and will not process, intercept, or block the requests for the first device sent by other applications. Among them, an application can also be called a process on a bare machine.

[0051] In some alternative embodiments, the first request is sent by a first virtual instance. The first virtual instance includes a virtual machine or a container. Herein, a virtual machine or a container refers to a complete computer system with complete hardware system functions simulated by software and running in a completely isolated environment. Whatever work can be completed on a physical computer can be implemented in a virtual machine.

[0052] In some alternative embodiments, the first virtual instance may occupy or manage a second device. That is to say, the virtual instance includes the second device, and the second device is a virtualization module running on the virtual instance. In this case, the memory space requested by the first request sent by the first virtual instance to the server may be for the use of the second device. At this time, the identifier of the second device is carried in the first request. The identifier of the second device is similar to that of the first device and has various possibilities, which will not be elaborated here.

[0053] In this application, there are various possibilities for the first virtual instance, which enriches the implementation manners and application scenarios of the technical solution of this application and improves the practicability of the technical solution of this application.

[0054] 202. The server configures a first memory space for the first device or the first virtual instance in the memory space managed by the server according to the first memory capacity requested by the first request, and the capacity of the first memory space is greater than or equal to the first memory capacity.

[0055] After obtaining the first request, the server allocates the required memory space for the first device or the first virtual instance according to the first memory capacity requested by the first request and the memory space managed by the server. There are various possibilities for the memory space managed by the server, and there are also various possibilities for the first memory space configured for the first device or the first virtual instance. The following will be described separately:

[0056] In some alternative embodiments, the memory space managed by the server includes the local memory of the server. Then, when the capacity of the local memory is greater than or equal to the first memory capacity, the server configures a first memory space for the first device or the first virtual instance from the free memory space in the local memory. Herein, the free memory space refers to the memory space that does not store data.

[0057] Exemplarily, assume that the first memory capacity is 500 MB. If the capacity of the free memory space in the local memory is 600 MB, then the capacity of the first memory space configured by the server for the first device can be greater than or equal to 500 MB, but less than the capacity of the free memory space in the local memory, which is 600 MB. Optionally, the degree to which the capacity of the first memory space is greater than the first memory capacity can be set. For example, it can be set that the capacity of the first memory space does not exceed 1% or 5% of the first memory capacity. The specific parameters can be determined according to the actual application needs and will not be limited herein.

[0058] Exemplarily, assume that the first memory capacity is 500 MB. If the capacity of the free memory space in the local memory is 500 MB, then the capacity of the first memory space configured by the server for the first device or the first virtual instance is 500 MB.

[0059] In some alternative embodiments, the memory space managed by the server includes remote memory, which is set outside the server. Then, when the capacity of the free memory space in the remote memory is greater than or equal to the first memory capacity, the server configures the first memory space for the first device or the first virtual instance from the free memory space in the remote memory.

[0060] It can be understood that the specific implementation of the server configuring the first memory space for the first device or the first virtual instance from the free memory space in the remote memory is similar to the previous case of configuring the first memory space for the first device or the first virtual instance from the free memory space in the local memory, and no examples will be given here.

[0061] In some alternative embodiments, the memory space managed by the server includes the local memory and remote memory of the server. In this solution, there are multiple implementation ways for the server to configure the first memory space for the first device or the first virtual instance, which will be described separately below:

[0062] Optionally, rules can be set to preferentially configure the first memory space for the first device or the first virtual instance from the memory type with a larger capacity of the free memory space.

[0063] Exemplarily, if the capacity of the free memory space in the local memory and the capacity of the free memory space in the remote memory are both greater than or equal to the first memory capacity, then among the free memory space in the local memory and the free memory space in the remote memory, the first memory space is determined from the free memory space with a larger capacity. For example, if the first memory capacity is 300 MB, the capacity of the free memory space in the local memory is 400 MB, and the capacity of the free memory space in the remote memory is 500 MB, then the server determines the first memory space from the free memory space in the remote memory. Among them, the capacity of the first memory space is greater than or equal to 300 MB, and the degree of exceeding can be set. Refer to the previous description and will not be elaborated here.

[0064] Exemplarily, if the capacities of the free memory spaces of the local memory and the remote memory are both less than the first memory capacity, then the first memory space determined by the server is included in the sum of the free memory spaces of the local memory and the remote memory. For example, the first memory capacity is 1GB, the capacity of the free memory space of the local memory is 600MB, and the capacity of the free memory space of the remote memory is 700MB. Then, the server can determine that 700MB in the first memory space comes from the free memory space of the remote memory and 324MB comes from the free memory space of the local memory. Optionally, the server can also configure the first memory space proportionally in the free memory spaces of the local memory and the remote memory.

[0065] Optionally, rules can be set to preferentially select a memory space with the same configuration type as the most recent one.

[0066] Exemplarily, if the capacities of the free memory spaces of the local memory and the remote memory are both greater than or equal to the first memory capacity, the server can select a memory space with the same configuration type as the most recent one from the free memory spaces of the local memory and the remote memory to configure the first memory space. For example, the first memory capacity is 600MB, the capacity of the free memory space of the local memory is 700MB, the capacity of the free memory space of the remote memory is 600MB, and the memory space configured by the server most recently is determined from the local memory space. Then the server determines the first memory space from the free memory space of the local memory.

[0067] Exemplarily, if the capacity of the free memory space of the memory space with the same configuration type as the most recent one is less than the first memory capacity, then the first memory space determined by the server comes from the free memory spaces of the local memory and the remote memory. For example, the first memory capacity is 800MB, the capacity of the free memory space of the local memory is 300MB, the capacity of the free memory space of the remote memory is 600MB, and the memory space configured by the server most recently is determined from the local memory space. Then the server can determine 300MB from the free memory space of the local memory and set 500MB in the free memory space of the remote memory as the first memory space. Optionally, in this example, the server can also configure the first memory space proportionally in the free memory spaces of the local memory and the remote memory.

[0068] It can be understood that in practical applications, there can be other ways to configure the first memory space for the first device or the first virtual instance from the memory space managed by the server. As long as it can be ensured that the sum of the free memory space of the local memory of the server and the free memory space of the remote memory is greater than or equal to the first memory capacity, the first memory space can be successfully configured for the first device or the first virtual instance. The specific implementation method of configuring the first memory space for the first device or the first virtual instance is not limited herein.

[0069] In this application, there are various situations for the memory space managed by the server, and there are also various possibilities for the first memory space configured for the first device or the first virtual instance. It can be enriched according to the selection of actual applications, which enriches the implementation methods and application scenarios of the technical solution of this application and improves the flexibility of the technical solution of this application.

[0070] 203. The server sets the access permission for the first memory space, and the access permission indicates that the device for performing data read / write operations on the first memory space is the first device or the first virtual instance.

[0071] The server sets the access permission for the first memory space by establishing an access page table for the first memory space. Specifically, after the server determines the first memory space, it obtains the physical memory address of the first memory space. The access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space. Through the foregoing mapping relationship, when a request for reading / writing data to the first memory space is obtained, it is determined whether the device has the permission to access the first memory space by comparing whether the physical address of the device sending the request is included in the access page table. In addition, the access page table can implement the physical address conversion function, so that a request for reading / writing data to the first memory space sent by a device with access permission can be corresponding to the corresponding memory address of the first memory space to achieve access to the first memory space.

[0072] Among them, the access page table can be a page table managed by an input / output memory management unit (IOMMU).

[0073] In this application, setting the access permission for the first device or the first virtual instance to the first memory space provides technical support for the implementation of the technical solution of this application and improves the feasibility of the technical solution of this application.

[0074] In some alternative embodiments, the first virtual instance may occupy or manage the second device. Then, the first request sent by the first virtual instance may include the identifier of the second device, and the server may also configure a first memory space for the second device based on the first request. Correspondingly, the second mapping relationship included in the access page table of the first memory space may be the mapping relationship between the physical address of the second device and the physical memory address of the first memory space.

[0075] In some alternative embodiments, the server may also obtain an access request for the second device. When the physical address corresponding to the access request is not included in the access page table of the first memory space, it indicates that the second device has no permission to access the first memory space and cannot perform data read / write operations on the first memory space. Then the server sends response information to the second device, and the response information indicates that the second device has no permission to access the first memory space. Among them, the second device may be a virtual machine or a device managed by a bare machine.

[0076] In this application, the physical address of the second device is not included in the access page table, which means that the second device has no right to access the first memory space, thereby realizing the operation isolation between the data in the first memory space and other devices and ensuring the data storage security of the first memory space.

[0077] Based on the foregoing description, it can be seen that in the embodiments of this application, there are various possibilities for the device that has the right to access the first memory space and the type of the first memory space. Next, some possible examples will be described with reference to the schematic diagrams. Please refer to Figures 3 to 6 , Figures 3 to 6 All are schematic diagrams of the memory management method provided by the embodiments of this application.

[0078] It should be noted that in Figure 3 and Figure 4 In the illustrated embodiments, the example of the server configuring the first memory space for device 1 managed by application 1 is used.

[0079] Such as Figure 3As shown, the processor 1 executes step ① to call the software development kit (SDK) interface of the permission management service, and sends a first request to the permission management module in the host, requesting to apply for the use of the memory space managed by the server for device 1 managed by application 1. The permission management module executes step ② to configure a first memory space for device 1 from the local memory of the server. The permission management module also establishes an access page table indicating the mapping relationship between the physical address of device 1 and the physical memory address of the first memory space, so as to authorize device 1 to access the first memory space. After the configuration is completed, device 1 executes step ③ to apply to the permission management module for accessing the first memory space. The permission management module realizes the access of device 1 to the first memory space according to the physical address applied by device 1 and the access page table, and executes the corresponding data read / write operation.

[0080] different from Figure 3 the embodiment shown, in Figure 4 the embodiment shown, the first memory space configured by the server for device 1 is included in the remote memory. That is to say, after receiving the first request, the permission management module forwards the first request to the remote memory management module, so that the remote memory management module determines the first memory space from the remote memory of the server, and returns the physical memory address of the first memory space to the permission management module. The permission management module then establishes an access page table indicating the mapping relationship between the physical address of device 1 and the physical memory address of the first memory space, so as to authorize device 1 to access the first memory space.

[0081] In Figure 3 and Figure 4 the embodiment shown, the access permission of the first memory space is limited to device 1, and the access of other devices to the first memory space will be intercepted, or access failure will be reported. For application 1 and application 2, when attempting to access the first memory page, it is necessary to map the first memory space to the virtual address space of application 1 or application 2. Limited by the access page table of the first memory space, this mapping fails, and application 1 and application 2 have no right to access the first memory space. For device 2, since there is no access page table created for the physical address of device 2 and the physical address of the first memory space, the access request of device 2 to the first memory space will be intercepted, achieving the effect that device 2 has no right to access the first memory space.

[0082] In Figure 5 and Figure 6 the embodiment shown, in the virtual machine scenario, the server configures the first memory space for device 1 managed by virtual machine 1 as an example.

[0083] Such as Figure 5As shown, virtual machine 1 calls the SDK interface of the permission management service and sends a first request to the permission management module in the virtual machine management (VMM) layer. The request is to apply for the use of the memory space managed by the server for device 1 managed by virtual machine 1. The permission management module configures a first memory space for device 1 from the local memory of the server. The permission management module also establishes an access page table indicating the mapping relationship between the physical address of device 1 and the physical memory address of the first memory space to authorize device 1 to access the first memory space. After the configuration is completed, device 1 applies to the permission management module to access the first memory space. The permission management module realizes the access of device 1 to the first memory space according to the physical address of device 1 and the access page table, and performs corresponding data read / write operations.

[0084] Different from Figure 5 the embodiment shown, in Figure 6 the embodiment shown, the first memory space configured by the server for device 1 is included in the remote memory. That is to say, after receiving the first request, the permission management module forwards the first request to the remote memory management module, so that the remote memory management module determines the first memory space from the remote memory of the server and returns the physical memory address of the first memory space to the permission management module. The permission management module then establishes an access page table indicating the mapping relationship between the physical address of device 1 and the physical memory address of the first memory space to authorize device 1 to access the first memory space.

[0085] In Figure 5 and Figure 6 the embodiment shown, the access permission of the first memory space is limited to device 1, and the access of other devices to the first memory space will be intercepted, or an access failure will be reported. For virtual machine 2, when attempting to access the first memory page, a page fault will be triggered and returned to the VMM layer for processing. Since the virtual processor 1 of virtual machine 1 and the virtual processor 2 of virtual machine 2 do not have permission to access the first secure memory, the access requests of virtual machine 1 and virtual machine 2 will be intercepted. For device 2, since the access page table of the physical address of device 2 and the physical address of the first memory space is not created, the access request of device 2 to the first memory space will be intercepted, achieving the effect that device 2 has no right to access the first memory space.

[0086] In some alternative embodiments, the server may also update the first memory space. For example, when the capacity of the first memory space cannot meet the usage requirements of the first device or the first virtual instance, the first application or the first virtual instance that manages the first device sends a second request to the server and establishes an access page table for the second memory space. The second memory space indicated by the second request may be a newly added memory space or a new memory space. The sum of the memory capacities of the newly added memory space and the first memory space meets the usage requirements of the first device or the first virtual instance, and the new memory space is used to replace the first memory space. If the server configures a new memory space, the server may also migrate the data in the original first memory space to the new memory space and delete the access page table of the first memory space.

[0087] In some alternative embodiments, there may also be a situation where the configuration of the first memory space fails. For example, the capacity of the memory space managed by the server is less than the memory capacity requested by the first request. In this case, the server returns a memory space configuration failure to the sender of the first request. Optionally, the server may also send a prompt message to the sender of the first request, and the prompt message indicates to expand the memory space of the server or prompt to clean the data in the server to meet the actual application needs.

[0088] Next, please refer to Figure 7 , Figure 7 which is a schematic structural diagram of the memory management device provided in the embodiments of the present application. As Figure 7 shown, the memory management device 700 includes a transceiver unit 701 and a processing unit 702.

[0089] In some alternative embodiments, the transceiver unit 701 is configured to obtain a first request sent by a first application or a first virtual instance on the server, and the first request is used to request to use a memory space with a first memory capacity managed by the server.

[0090] The processing unit 702 is configured to configure a first memory space for the first device or the first virtual instance occupied by the first application in the memory space managed by the server according to the first memory capacity requested by the first request, and the capacity of the first memory space is greater than or equal to the first memory capacity. Set the access permission of the first memory space, and the access permission indicates that the device for performing data read / write operations on the first memory space is the first device or the first virtual instance.

[0091] In some alternative embodiments, the processing unit 702 is specifically configured to set the access permission by establishing an access page table for the first memory space. The access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space.

[0092] In some alternative embodiments, the transceiver unit 701 is further configured to: obtain an access request for a second device, where the physical address corresponding to the access request is not included in the access page table. Send response information to the second device, where the response information indicates that the second device does not have permission to access the first memory space.

[0093] In some alternative embodiments, the first virtual instance includes a virtual machine or a container running on a server.

[0094] In some alternative embodiments, the memory space managed by the server includes the local memory of the server. The processing unit 702 is specifically configured to: when the capacity of the free memory space in the local memory is greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space in the local memory.

[0095] In some alternative embodiments, the memory space managed by the server includes a remote memory, and the remote memory is set outside the server. The processing unit 702 is specifically configured to: when the capacity of the free memory space in the remote memory is greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space in the remote memory.

[0096] In some alternative embodiments, the memory space managed by the server includes the local memory and the remote memory of the server. The processing unit 702 is specifically configured to: when the capacity of the free memory space in the local memory and the capacity of the free memory space in the remote memory are both greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space in the local memory and / or the free memory space in the remote memory.

[0097] The memory management device is used to execute the operations performed by the server in the foregoing Figures 1 to 6 illustrated embodiments to implement the memory management method provided in the embodiments of the present application. For details, refer to the foregoing illustration and will not be elaborated here.

[0098] Next, the computer device provided in the embodiments of the present application will be described. Please refer to Figure 8 , Figure 8 which is a schematic structural diagram of the computer device provided in the embodiments of the present application. The computer device 800 includes a processor 801, a memory 802, a communication interface 803, and a bus 804. Among them, the processor 801, the memory 802, and the communication interface 803 communicate through the bus 804, and can also implement communication through other means such as wireless transmission. The memory 802 stores program codes, and the processor 801 can call the program codes stored in the memory 802 to execute the foregoing Figures 1 to 6The operations performed by the server in the illustrated embodiments implement the memory management method provided in the embodiments of the present application, which will not be elaborated here.

[0099] It should be understood that in the embodiments of the present application, the processor 801 may be a CPU, and the processor 801 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0100] The memory 802 may include a read-only memory and a random access memory, and provide instructions and data to the processor 801. The memory 802 may also include a non-volatile random access memory. For example, the memory 802 may also store information about the device type.

[0101] The memory 802 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0102] In addition to including a data bus, the bus 804 may also include a power bus, a control bus, a status signal bus, etc. However, for the sake of clear illustration, various buses are labeled as bus 804 in the figure. The bus 840 may be a Peripheral Component Interconnect Express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a Compute Express Link (CXL), a Cache-Coherent Interconnect for Accelerators (CCIX), etc. The bus 840 may be divided into an address bus, a data bus, a control bus, etc.

[0103] The computer device 800 may also include one or more communication interfaces and one or more operating systems, such as Windows Server TM , Mac OS X TM , Unix TM , Linux TM , FreeBSD TM , etc.

[0104] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0105] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other may be through some interfaces, and the indirect couplings or communication connections of the devices or units may be in electrical, mechanical, or other forms.

[0106] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0107] In addition, each functional unit in various embodiments of the present application may be integrated into one processing unit, may exist physically alone for each unit, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0108] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

Claims

1. A memory management method, characterized in that: The method is applied to a server, and the server is used to manage memory space. The method includes: Obtaining a first request issued by a first application or a first virtual instance on a server, wherein the first request is used to request to use a memory space with a first memory capacity managed by the server; According to the first memory capacity requested by the first request, configuring a first memory space for the first device or the first virtual instance occupied by the first application in the memory space managed by the server, wherein the capacity of the first memory space is greater than or equal to the first memory capacity; An access right is set for the first memory space, where the access right indicates that a device that performs a data read / write operation on the first memory space is the first device, or the first virtual instance.

2. The method according to claim 1, characterized in that The step of setting the access permission of the first memory space includes: The access permission is set by establishing an access page table of the first memory space, wherein the access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space.

3. The method according to claim 2, characterized in that The method further comprises: Obtaining an access request for a second device, wherein a physical address corresponding to the access request is not included in the access page table; Send response information to the second device, where the response information indicates that the second device does not have permission to access the first memory space.

4. The method according to any one of claims 1 to 3, characterized in that The first virtual instance includes a virtual machine or a container running on the server.

5. The method according to any one of claims 1 to 4, characterized in that The memory space managed by the server includes the local memory of the server; The configuring a first memory space for a first device or a first virtual instance occupied by the first application in a memory space managed by the server according to the first memory capacity requested by the first request includes: When the capacity of the free memory space of the local memory is greater than or equal to the first memory capacity, the first memory space is configured for the first device or the first virtual instance from the free memory space of the local memory.

6. The method according to any one of claims 1 to 4, characterized in that The memory space managed by the server includes a remote memory, and the remote memory is arranged outside the server; The configuring a first memory space for a first device or a first virtual instance occupied by the first application in a memory space managed by the server according to the first memory capacity requested by the first request includes: When the capacity of the free memory space of the remote memory is greater than or equal to the first memory capacity, the first memory space is configured for the first device or the first virtual instance from the free memory space of the remote memory.

7. The method according to any one of claims 1 to 4, characterized in that The memory space managed by the server includes the local memory and remote memory of the server; The configuring a first memory space for a first device or a first virtual instance occupied by the first application in a memory space managed by the server according to the first memory capacity requested by the first request includes: When the capacity of the free memory space of the local memory and the capacity of the free memory space of the remote memory are both greater than or equal to the first memory capacity, the first memory space is configured for the first device or the first virtual instance from the free memory space of the local memory and / or the free memory space of the remote memory.

8. A memory management device, characterized in that: include: A transceiver unit, configured to obtain a first request issued by a first application or a first virtual instance on a server, wherein the first request is used to request to use a memory space having a first memory capacity managed by the server; a processing unit, configured to configure a first memory space for the first device or the first virtual instance occupied by the first application in the memory space managed by the server according to the first memory capacity requested by the first request, wherein the capacity of the first memory space is greater than or equal to the first memory capacity; The processing unit is further used to set access rights for the first memory space, where the access rights indicate that a device that performs data read / write operations on the first memory space is the first device, or the first virtual instance.

9. The device according to claim 8, characterized in that The processing unit is specifically used to set the access permission by establishing an access page table of the first memory space, wherein the access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space.

10. The device according to claim 9, characterized in that The transceiver unit is further used for: Obtaining an access request for a second device, wherein a physical address corresponding to the access request is not included in the access page table; Send response information to the second device, where the response information indicates that the second device does not have permission to access the first memory space.

11. The device according to any one of claims 8 to 10, characterized in that The first virtual instance includes a virtual machine or a container running on the server.

12. The device according to any one of claims 8 to 11, characterized in that The memory space managed by the server includes the local memory of the server; The processing unit is specifically used to: when the capacity of the free memory space of the local memory is greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space of the local memory.

13. The device according to any one of claims 8 to 11, characterized in that The memory space managed by the server includes a remote memory, and the remote memory is arranged outside the server; The processing unit is specifically used to: when the capacity of the free memory space of the remote memory is greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space of the remote memory.

14. The device according to any one of claims 8 to 11, characterized in that The memory space managed by the server includes the local memory and remote memory of the server; The processing unit is specifically used to: when the capacity of the free memory space of the local memory and the capacity of the free memory space of the remote memory are both greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space of the local memory and / or the free memory space of the remote memory.

15. A computer device, characterized in that: comprising a processor coupled to a memory; Instructions are stored in the memory, and when the instructions are executed on the processor, the computer device implements the method according to any one of claims 1 to 7.

16. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed on a processor, the method according to any one of claims 1 to 7 is implemented.

17. A computer program product, characterized in that When the computer program product is executed on a computer, the method according to any one of claims 1 to 7 is implemented.