Memory data management method, electronic equipment, storage medium and program product

By using step-by-step encryption and red-black tree structure in the memory management system, combined with the page fault exception mechanism, the compatibility and high cost problems of memory data management methods are solved, and memory data management with good compatibility, low cost and controllable performance impact is achieved.

CN120848815AActive Publication Date: 2025-10-28LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511358499.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2025-10-28
Estimated Expiration
2045-09-23

AI Technical Summary

Technical Problem

Existing memory data management methods suffer from poor compatibility, high costs, and significant impact on system performance.

Method used

By traversing the memory space of each process, the physical address of the data to be encrypted is processed using the first key to obtain the first ciphertext, which is then XORed with the data to be encrypted and stored in a red-black tree. Combined with the page fault exception mechanism, step-by-step encryption is achieved, and finally the data is written to the swap area file.

Benefits of technology

It achieves good compatibility with native memory management mechanisms, reduces costs, facilitates large-scale applications, and reduces the impact on system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120848815A_ABST
    Figure CN120848815A_ABST
Patent Text Reader

Abstract

The invention discloses a memory data management method, electronic equipment, a storage medium and a program product, and relates to the technical field of storage, the memory data management method comprises the steps of realizing memory data management based on a native memory management mechanism and a missing page exception mechanism, processing a physical address of to-be-encrypted data by using step-by-step encryption and using a first secret key, and storing the processed physical address in the memory management mechanism; according to the method, the first ciphertext and the to-be-encrypted data are acquired, the exclusive-or operation is performed on the acquired first ciphertext and the to-be-encrypted data, and the acquired second ciphertext is stored in the red-black tree in the memory space, so that the encryption range is expanded, the data security is improved, and the memory space and the addition, deletion and modification performance of the red-black tree are fully utilized. The target second ciphertext needing to be migrated is further encrypted and written into the exchange area file. The method is implemented by pure software and does not depend on specific hardware equipment. The technical problems that compatibility is poor, cost is high, large-scale application is not facilitated, and the influence on system performance is large are solved, and the technical effects that compatibility is good, cost is reduced, large-scale application is facilitated, and the influence on the system performance is reduced are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of storage technology, and in particular to a memory data management method, electronic device, storage medium, and program product. Background Technology

[0002] Current memory data management methods mainly include two types: one is to encrypt and protect memory data on the hardware device responsible for memory management; the other is to encrypt memory data using file data encryption methods.

[0003] However, both memory data management methods have their own drawbacks. First, hardware-based encryption schemes rely on hardware devices, resulting in poor compatibility, high costs, and hindering large-scale applications. Second, file data encryption methods have a significant impact on system performance. Summary of the Invention

[0004] This invention provides a memory data management method, electronic device, storage medium, and program product to at least solve the problems of poor compatibility, high cost, unfavorable large-scale application, and significant impact on system performance in related technologies.

[0005] This invention provides a memory data management method, comprising: Traverse the memory space corresponding to each process to obtain the target memory page that can be encrypted; The data in the target memory page is identified as the data to be encrypted, and the data to be encrypted and its physical address are read. Obtain the first key and the physical address of the data to be encrypted, and process the physical address using the first key to obtain the first ciphertext; Perform an XOR operation on the data to be encrypted and the first ciphertext to obtain the second ciphertext, and store the second ciphertext in a red-black tree; Traverse the red-black tree to obtain the second ciphertext to be written to the swap file, and determine the second ciphertext to be written to the swap file as the target second ciphertext; The target second ciphertext is retrieved from the red-black tree, a second key is obtained, and the target second ciphertext is encrypted using the second key to obtain the third ciphertext; The first ciphertext and the third ciphertext are XORed to obtain the fourth ciphertext, which is then written into the exchange area file.

[0006] The present invention also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of any of the above-described memory data management methods when executing the computer program.

[0007] The present invention also provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of any of the above-described memory data management methods.

[0008] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the above-described memory data management methods.

[0009] This invention achieves better compatibility and stability by implementing memory data management based on native memory management mechanisms and page fault mechanisms, ensuring functional compatibility with native functions. Through step-by-step encryption, the physical address of the data to be encrypted is processed using a first key to obtain the first ciphertext. The data to be encrypted and the first ciphertext are then XORed, and the resulting second ciphertext is stored in a red-black tree in memory. This expands the encryption range, improves data security, and fully utilizes the addition, deletion, and modification capabilities of memory space and the red-black tree. Since data encryption is performed in system memory and this data is frequently accessed, encryption and decryption are also frequent. Therefore, using the XOR algorithm for basic encryption and decryption further encrypts the data, improves performance, and reduces the impact on system and process operation. When the target second ciphertext that needs to be migrated from the red-black tree to the swap file is determined, it is further encrypted and written to the swap file. Implemented purely in software, it is not dependent on specific hardware, resulting in lower costs. Furthermore, by controlling the data to be encrypted, flexible encryption range control is achieved, thus striking a good balance between encryption strength and performance. This results in a dynamic memory encryption method and system that is compatible with native memory management mechanisms, does not depend on specific hardware, and has a controllable performance impact. Therefore, it solves the technical problems of poor compatibility, high cost, unfavorable large-scale applications, and significant impact on system performance, achieving good compatibility, reduced costs, ease of large-scale application, and reduced impact on system performance. Attached Figure Description

[0010] To more clearly illustrate the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 An architecture diagram of a memory data management system provided in an embodiment of the present invention; Figure 2 A flowchart illustrating the implementation of a memory data management method according to an embodiment of the present invention; Figure 3 A flowchart illustrating the implementation of another memory data management method provided in this embodiment of the invention; Figure 4 This is a structural block diagram of a memory data management device provided in an embodiment of the present invention. Detailed Implementation

[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of the present invention.

[0013] It should be noted that, in the description of this invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., used in this invention are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0014] To enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0015] The specific application environment architecture or specific hardware architecture on which the execution of the memory data management method depends is described here.

[0016] See Figure 1 , Figure 1 This is an architecture diagram of a memory data management system provided in an embodiment of the present invention. The memory data management system mainly includes three components: a memory swapping and data encryption component, a red-black tree component for encrypted but not swapped-out memory pages, and a page fault handling and data decryption component.

[0017] The memory swapping and data encryption component is a modified and improved version of the memory swapping function in the original system kernel memory management system. The main difference is the addition of new scanning, swapping, and data encryption functions for dynamic memory pages. Compared to the original memory swapping mechanism, the new scanning algorithm for dynamic memory pages remains unchanged, such as the Least Recently Used (LRU) algorithm, but its conditions are stricter, swapping a wider range of memory pages. This swapping differs from the original swapping; it is a modified swapping mechanism incorporating data encryption, working in conjunction with a red-black tree data structure for encrypted memory pages that have not yet been swapped out. During the swapping process, this part encrypts the data in the target memory page using the first part of the XEX-based Tweaked CodeBook mode with CipherText Stealing (XTS) mode, a symmetric encryption / decryption algorithm. This involves XORing the tweak value with the plaintext data, and then passing the encrypted data to the red-black tree component for storage. The memory swapping logic of the original system kernel memory management component has been moved to the swap file and the encrypted, unswapped memory pages in the red-black tree component. Data that hasn't been accessed for a long time in the red-black tree is swapped out to the swap file, and the second and third parts of the XTS mode encryption operations are performed during this process: "data encryption" and "tweak XOR with ciphertext." This ensures that the data stored in the swap file is also ciphertext. By dividing the XTS mode into two parts, the performance impact of the first part's XOR operation is relatively small, facilitating rapid swapping of memory pages between process memory and the red-black tree, thus reducing the impact on the system. Since disk write performance is relatively poor, the performance bottleneck of the encryption operation is no longer an issue, thereby minimizing the impact on the system. Of course, if the processor's computing performance is excellent, the complete XTS mode encryption and decryption operations can also be performed during the swapping process between system memory and the red-black tree.

[0018] The main function of the encrypted but not swapped-out red-black tree component is to maintain a red-black tree data structure in memory to store memory page information. Based on the needs of the memory swapping and data encryption components, it stores encrypted data swapped out from process memory (i.e., system memory). Subsequently, depending on the requirements, the encrypted data is decrypted and swapped out from the red-black tree into process memory, or further encrypted and migrated to the swap file. The significance of this component lies in the fact that the memory swapping and data encryption components use a more stringent memory page scanning algorithm, resulting in a larger range of data being encrypted and swapped out from process memory. This data is actually accessed and used by processes, and the probability of access is far greater than the data swapped out by the system's native memory swapping mechanism. Without a mechanism to temporarily store encrypted data in memory, all data would need to be read and written from the swap file via disk, requiring both encryption and decryption, which would have a significant impact on system performance. By setting up a red-black tree, this data swapping can occur directly in memory, and the red-black tree data structure improves the performance of CRUD operations, thereby minimizing the impact on data access. Data that hasn't been accessed for a long time and meets the native replacement criteria will still be replaced from the red-black tree to the swap space, thus achieving optimal memory usage. This strikes a good balance between native memory management performance and memory data encryption requirements.

[0019] The page fault handling and data decryption component corresponds to the memory swapping and data encryption component. It is responsible for decrypting encrypted data from the red-black tree and swap file and loading it back into system memory. When data is swapped out of a process's memory, the process can no longer directly access that data. The native operating system's memory management mechanism uses a page fault mechanism to reload data. When a process attempts to access the data, the memory management unit checks if the data is in physical memory. If not, a page fault interrupt is triggered. The processor receives this interrupt, finds and calls the page fault handler based on the exception vector table, and the page fault handler locates the data, loads it from the swap file into memory, and performs related memory management tasks, ultimately enabling the program to access and use the data normally. The page fault handling and data decryption component is a modified and improved version of the page fault handler, enabling it to search the encrypted, unswapped memory pages in the red-black tree component and swap file, find the target data, decrypt it, and load it into the process's memory, allowing it to be accessed and used normally.

[0020] The embodiments of the present invention provide a memory data management method, and the method is described in detail in conjunction with the execution flow of the memory data management method.

[0021] See Figure 2 , Figure 2 The following is a flowchart illustrating an implementation of a memory data management method according to an embodiment of the present invention. The method may include the following steps.

[0022] S201: Traverse the memory space corresponding to each process to obtain the target memory page that can be encrypted.

[0023] During the execution of each process, the memory space corresponding to each process is traversed. This memory space contains the process's code, pre-defined data loaded from the program file, and dynamically generated data during runtime. This data changes dynamically as the program executes, and some data is read and written more frequently than others. Based on the traversal results, the access status of each memory page within each memory space can be determined, and the target memory page for encryption can be located based on the access status of each memory page.

[0024] S202: Identify the data in the target memory page as the data to be encrypted, and read the data to be encrypted and its physical address.

[0025] After obtaining the target memory page that can be encrypted by traversing, the data in the target memory page is identified as the data to be encrypted, and the data to be encrypted and its physical address are read.

[0026] S203: Obtain the first key and use the first key to process the physical address to obtain the first ciphertext.

[0027] After reading the data to be encrypted and its physical address, the first key is obtained. This can be obtained from the Trusted Platform Module (TPM) or by the user pre-defining key data. The first key is then used to process the physical address to obtain the first ciphertext.

[0028] S204: Perform an XOR operation on the encrypted data and the first ciphertext to obtain the second ciphertext, and store the second ciphertext in a red-black tree.

[0029] After processing the physical address of the data to be encrypted using the first key to obtain the first ciphertext, an XOR operation is performed between the data to be encrypted and the first ciphertext to obtain the second ciphertext, which is then stored in a red-black tree. Since data encryption is currently performed in system memory, and this data will be accessed and used frequently, encryption and decryption will also be frequent. Therefore, using the XOR algorithm for basic encryption and decryption not only achieves further encryption of the data but also improves performance and reduces the impact on system and process operation. By storing the second ciphertext in the red-black tree, the process corresponding to the memory space of the target memory page is released.

[0030] S205: Traverse the red-black tree to obtain the second ciphertext to be written to the swap file, and determine the second ciphertext to be written to the swap file as the target second ciphertext.

[0031] After storing the second ciphertext in the red-black tree, traverse the red-black tree to obtain the second ciphertext to be written to the swap file. For example, by traversing the red-black tree, the storage time of each second ciphertext in the red-black tree can be obtained. Based on the storage time, the second ciphertext to be written to the swap file can be selected from each second ciphertext and determined as the target second ciphertext.

[0032] S206: Retrieve the target second ciphertext from the red-black tree, obtain the second key, and use the second key to encrypt the target second ciphertext to obtain the third ciphertext.

[0033] After identifying the second ciphertext to be written to the swap file as the target second ciphertext, the target second ciphertext is retrieved from the red-black tree to obtain the second key. The second key is then used to encrypt the target second ciphertext to obtain the third ciphertext. The second key is used to achieve further encryption of the data.

[0034] S207: XOR the first ciphertext and the third ciphertext to obtain the fourth ciphertext, and write the fourth ciphertext into the exchange area file.

[0035] After encrypting the target second ciphertext using the second key to obtain the third ciphertext, the first and third ciphertexts are XORed to obtain the fourth ciphertext, which is then written to the swap file. By further encrypting the target second ciphertext using the second key during the process of transferring it from the red-black tree to the swap file to obtain the third ciphertext, and then XORing the first and third ciphertexts, the performance bottleneck of this encryption operation can be ignored since the swap file is deployed on the disk, and the disk's write performance is worse than that of process memory. This achieves a good balance between native memory management performance and the need for memory data encryption.

[0036] This invention achieves better compatibility and stability by implementing memory data management based on native memory management mechanisms and page fault mechanisms, ensuring functional compatibility with native functions. Through step-by-step encryption, the physical address of the data to be encrypted is processed using a first key to obtain the first ciphertext. The data to be encrypted and the first ciphertext are then XORed, and the resulting second ciphertext is stored in a red-black tree in memory. This expands the encryption range, improves data security, and fully utilizes the addition, deletion, and modification capabilities of memory space and the red-black tree. Since data encryption is performed in system memory and this data is frequently accessed, encryption and decryption are also frequent. Therefore, using the XOR algorithm for basic encryption and decryption further encrypts the data, improves performance, and reduces the impact on system and process operation. When the target second ciphertext that needs to be migrated from the red-black tree to the swap file is determined, it is further encrypted and written to the swap file. Implemented purely in software, it is not dependent on specific hardware, resulting in lower costs. Furthermore, by controlling the data to be encrypted, flexible encryption range control is achieved, thus striking a good balance between encryption strength and performance. This results in a dynamic memory encryption method and system that is compatible with native memory management mechanisms, does not depend on specific hardware, and has a controllable performance impact. Therefore, it solves the technical problems of poor compatibility, high cost, unfavorable large-scale applications, and significant impact on system performance, achieving good compatibility, reduced costs, ease of large-scale application, and reduced impact on system performance.

[0037] See Figure 3 , Figure 3 The following is a flowchart illustrating another memory data management method provided in an embodiment of the present invention. The method may include the following steps.

[0038] S301: Traverse the memory space corresponding to each process to obtain the idle time corresponding to each memory page in each memory space.

[0039] The idle time for each memory page is pre-recorded in the memory space; the idle time is the duration from the last access to the current time. The memory space corresponding to each process is traversed to obtain the idle time for each memory page in each memory space.

[0040] S302: Determine whether there are memory pages with an idle time exceeding the first preset time. If yes, proceed to step S303; otherwise, return to step S301.

[0041] After traversing the memory space corresponding to each process and obtaining the idle time of each memory page in each memory space, it is determined whether there is a memory page with an idle time exceeding the first preset time. If so, it means that the time since the last access of the memory page has been relatively long, and step S303 is executed. If not, it means that each memory page is accessed relatively frequently, and step S301 is returned to continue polling and monitoring.

[0042] It should be noted that the first preset duration can be set and adjusted according to the actual situation, and the embodiments of the present invention do not limit this.

[0043] S303: Identify memory pages whose idle time exceeds a first preset time as target memory pages.

[0044] When it is determined that there are memory pages with an idle time exceeding the first preset time, the memory pages with an idle time exceeding the first preset time are identified as target memory pages, thereby filtering out target memory pages that can be used for process release.

[0045] S304: Identify the data in the target memory page as the data to be encrypted, and read the data to be encrypted and its physical address.

[0046] S305: Locate the first key from the trusted security platform module, and use the first key to process the physical address to obtain the first ciphertext.

[0047] A trusted security platform module is pre-configured for key storage. After identifying the data in the target memory page as the data to be encrypted and reading the data and its physical address, the first key is retrieved from the trusted security platform module. This first key is then used to process the physical address to obtain the first ciphertext. By retrieving the first key from the trusted security platform module, the module's stronger key protection capabilities are fully utilized, preventing key leakage. Furthermore, its ability to perform encryption and decryption operations improves computational performance and reduces software performance overhead and impact.

[0048] S306: Perform an XOR operation on the encrypted data and the first ciphertext to obtain the second ciphertext, and store the second ciphertext in a red-black tree.

[0049] S307: Obtain the target process memory page table corresponding to the target memory space to which the target memory page belongs.

[0050] Pre-maintain process memory page tables for each memory space, and use these tables to store accessible memory pages within the memory space. After storing the second ciphertext in a red-black tree, retrieve the target process memory page table corresponding to the target memory space to which the target memory page belongs.

[0051] S308: Remove the target memory page from the target process's memory page table.

[0052] After obtaining the target process's memory page table corresponding to the target memory space to which the target memory page belongs, the target memory page is deleted from the target process's memory page table. By promptly deleting the target memory page from the target process's memory page table, effective maintenance of data storage is achieved.

[0053] S309: Traverse the red-black tree to obtain the second ciphertext that has not been accessed for more than the second preset time.

[0054] After storing the second ciphertext in the red-black tree, traverse the red-black tree to obtain the second ciphertext that has not been accessed for more than the second preset time.

[0055] It should be noted that the second preset duration can be set and adjusted according to the actual situation, and the embodiments of the present invention do not limit this.

[0056] The second preset duration can be a reference object for comparing the accumulated unaccessed time since the data was stored in the red-black tree. In this case, there is no size limit for the first and second preset durations. The second preset duration can also be a reference object for comparing the accumulated unaccessed time since the data was stored in memory. In this case, the second preset duration is longer than the first preset duration. By setting the second preset duration as a filtering condition for migrating data to the swap file, the accuracy of data migration is further ensured.

[0057] S310: The second ciphertext that has not been accessed for more than the second preset time period is determined as the second ciphertext to be written to the exchange area file, and the second ciphertext to be written to the exchange area file is determined as the target second ciphertext.

[0058] After traversing the red-black tree and obtaining the second ciphertext that has not been accessed for more than a second preset time, this second ciphertext that has not been accessed for more than the second preset time is identified as the second ciphertext to be written to the swap file, and this second ciphertext to be written to the swap file is identified as the target second ciphertext. By setting a second preset time to filter the second ciphertext to be written to the swap file, timely release of system memory is achieved, allowing for better utilization of system memory.

[0059] S311: Retrieve the target second ciphertext from the red-black tree and search for the second key from the trusted security platform module.

[0060] After identifying the second ciphertext to be written to the exchange area file as the target second ciphertext, the target second ciphertext is retrieved from the red-black tree, and the second key is searched from the trusted security platform module. By searching for the second key from the trusted security platform module, the advantages of its stronger key protection capabilities (avoiding key leakage) and its ability to perform encryption and decryption operations (improving computational performance and reducing software performance overhead and impact) are fully utilized.

[0061] S312: Use the second key to perform symmetric encryption and decryption algorithm on the target second ciphertext to obtain the third ciphertext.

[0062] After retrieving the second key from the trusted security platform module, the target second ciphertext is encrypted using a symmetric encryption / decryption algorithm using the second key to obtain the third ciphertext. By utilizing the encryption operation of the symmetric encryption / decryption algorithm, the advantage of the symmetric encryption / decryption algorithm's minimal performance impact is fully utilized.

[0063] S313: XOR the first ciphertext and the third ciphertext to obtain the fourth ciphertext, and write the fourth ciphertext into the exchange area file.

[0064] In one specific embodiment of the present invention, the method may further include the following steps: Step 1: Parse the received memory access request to obtain the memory page to be accessed; Step 2: Perform a memory page lookup in the process's memory page table corresponding to the memory space to be accessed; Step 3: Determine if the memory page to be accessed has been found. If not, proceed to Step 4; if yes, proceed to Step 5. Step 4: Trigger a page fault interrupt so that the processor can look up the interrupt table in the system kernel and find the page fault handler in the interrupt table. Then, use the page fault handler to decrypt and load the memory page to be accessed. Step 5: Decrypt the memory page to be accessed from the swap file, and load the decrypted data into the memory space to which the memory page to be accessed belongs.

[0065] For ease of description, the five steps mentioned above can be combined for explanation.

[0066] When data access is required, the received memory access request is parsed to obtain the memory page to be accessed. A memory page lookup is performed on the process's memory page table corresponding to the memory space of the memory page to be accessed. If the page is not found, a page fault interrupt is triggered, causing the processor to look up the system kernel's interrupt table based on the page fault interrupt. The page fault handler is then used to decrypt and load the memory page to be accessed. If the page is found, it is decrypted from the swap file, and the decrypted data is loaded into the memory space of the memory page to be accessed. By maintaining compatibility with the original page fault mechanism, when the memory page to be accessed is not found in the process's memory page table, the page fault handler directly searches from the red-black tree and swap file, providing better compatibility and stability and ensuring normal data access.

[0067] In one specific embodiment of the present invention, decrypting and loading the memory page to be accessed using a page fault handler may include the following steps: Step 1: Use the page fault handler to traverse the red-black tree to find the memory page identifier information of the memory page to be accessed; the red-black tree stores the correspondence between each second ciphertext and each memory page identifier information; Step 2: Determine whether the memory page identifier information of the memory page to be accessed is found in the red-black tree. If yes, proceed to step 3; otherwise, proceed to step 4. Step 3: Decrypt the second ciphertext in the memory page to be accessed from the red-black tree, and load the decrypted data into the memory space to which the memory page to be accessed belongs; Step 4: Decrypt the memory page to be accessed from the swap file and load the decrypted data into the memory space to which the memory page to be accessed belongs.

[0068] For ease of description, the four steps above can be combined for explanation.

[0069] The red-black tree stores the correspondence between each second ciphertext and each memory page identifier. When it is determined that the memory page to be accessed is not found in the process's memory page table, the page fault handler traverses the red-black tree to search for the memory page identifier of the memory page to be accessed. It then determines whether the memory page identifier of the memory page to be accessed is found in the red-black tree. If so, the second ciphertext in the memory page to be accessed is decrypted from the red-black tree, and the decrypted data is loaded into the memory space belonging to the memory page to be accessed. If not, the memory page to be accessed is decrypted from the swap file, and the decrypted data is loaded into the memory space belonging to the memory page to be accessed. By pre-storing the correspondence between each second ciphertext and each memory page identifier, and combining this with the addition, deletion, and modification capabilities of the red-black tree, a fast and accurate search for the second ciphertext in the memory page to be accessed is achieved.

[0070] In one specific embodiment of the present invention, decrypting the second ciphertext in the memory page to be accessed from the red-black tree may include the following steps: By reversing the first step of the XOR encryption in the cipherbook pattern of ciphertext theft from the red-black tree, the second ciphertext in the memory page to be accessed is decrypted.

[0071] After finding the memory page identifier information of the memory page to be accessed in the red-black tree, the second ciphertext in the memory page to be accessed is decrypted by reversing the first step of the XOR encryption in the cryptographic book mode with ciphertext theft from the red-black tree. This achieves fast decryption of the second ciphertext in system memory, significantly reducing the impact of the decryption process on system performance.

[0072] In one specific embodiment of the present invention, decrypting the memory page to be accessed from the swap file may include the following steps: The memory page to be accessed is decrypted by executing a complete decryption process from the swap file using a ciphertext-stealing codebook mode.

[0073] If the memory page identifier information for the memory page to be accessed is not found in the red-black tree, the memory page is decrypted from the swap file by executing a complete decryption process in the ciphertext-stealing mode. Since the swap file is deployed on disk, and disk read performance is inferior to process memory, the performance bottleneck of this encryption operation can be ignored, thus achieving a good balance between native memory management performance and the need for memory data decryption.

[0074] In one specific embodiment of the present invention, loading the decrypted data into the memory space of the memory page to be accessed may include the following steps: Step 1: Allocate physical memory for the memory page to be accessed to obtain the target physical memory; Step 2: Migrate the decrypted data to the target physical memory; Step 3: Obtain the virtual address corresponding to the target physical memory; Step 4: Modify the process memory page table based on the virtual address.

[0075] For ease of description, the four steps above can be combined for explanation.

[0076] The process involves allocating physical memory for the memory page to be accessed, obtaining the target physical memory, migrating the decrypted data to the target physical memory, obtaining the virtual address corresponding to the target physical memory, and modifying the process's memory page table based on the virtual address. Through physical memory allocation, data migration, virtual address acquisition, and process memory page table modification, accurate loading of decrypted data into memory is achieved.

[0077] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0078] Embodiments of the present invention also provide a memory data management device.

[0079] See Figure 4 , Figure 4 This is a structural block diagram of a memory data management device provided in an embodiment of the present invention. The device may include: The target memory page acquisition unit 41 is used to traverse the memory space corresponding to each process to obtain the encryptable target memory page. The data reading unit 42 is used to determine the data in the target memory page as the data to be encrypted, and to read the data to be encrypted and its physical address; The first ciphertext acquisition unit 43 is used to acquire the first key and process the physical address using the first key to obtain the first ciphertext; The second ciphertext storage unit 44 is used to perform an XOR operation between the data to be encrypted and the first ciphertext to obtain the second ciphertext, and then store the second ciphertext in a red-black tree. The target second ciphertext determination unit 45 is used to traverse the red-black tree, obtain the second ciphertext to be written to the swap file, and determine the second ciphertext to be written to the swap file as the target second ciphertext; The third ciphertext acquisition unit 46 is used to retrieve the target second ciphertext from the red-black tree, obtain the second key, and use the second key to encrypt the target second ciphertext to obtain the third ciphertext. The fourth ciphertext writing unit 47 is used to XOR the first ciphertext and the third ciphertext to obtain the fourth ciphertext, and then write the fourth ciphertext into the exchange area file.

[0080] This invention achieves better compatibility and stability by implementing memory data management based on native memory management mechanisms and page fault mechanisms, ensuring functional compatibility with native functions. Through step-by-step encryption, the physical address of the data to be encrypted is processed using a first key to obtain the first ciphertext. The data to be encrypted and the first ciphertext are then XORed, and the resulting second ciphertext is stored in a red-black tree in memory. This expands the encryption range, improves data security, and fully utilizes the addition, deletion, and modification capabilities of memory space and the red-black tree. Since data encryption is performed in system memory and this data is frequently accessed, encryption and decryption are also frequent. Therefore, using the XOR algorithm for basic encryption and decryption further encrypts the data, improves performance, and reduces the impact on system and process operation. When the target second ciphertext that needs to be migrated from the red-black tree to the swap file is determined, it is further encrypted and written to the swap file. Implemented purely in software, it is not dependent on specific hardware, resulting in lower costs. Furthermore, by controlling the data to be encrypted, flexible encryption range control is achieved, thus striking a good balance between encryption strength and performance. This results in a dynamic memory encryption method and system that is compatible with native memory management mechanisms, does not depend on specific hardware, and has a controllable performance impact. Therefore, it solves the technical problems of poor compatibility, high cost, unfavorable large-scale applications, and significant impact on system performance, achieving good compatibility, reduced costs, ease of large-scale application, and reduced impact on system performance.

[0081] In one specific embodiment of the present invention, the target memory page acquisition unit 41 may include: The idle duration acquisition sub-unit is used to traverse the memory space corresponding to each process and obtain the idle duration corresponding to each memory page in each memory space. The first judgment subunit is used to determine whether there are memory pages whose idle time exceeds the first preset time. The target memory page determination subunit is used to determine the memory page with an idle time exceeding the first preset time as the target memory page when it is determined that there is a memory page with an idle time exceeding the first preset time. The return execution subunit is used to return to the execution steps of traversing the memory space corresponding to each process when it is determined that there are no memory pages with an idle time exceeding the first preset time.

[0082] In one specific embodiment of the present invention, the second encrypted storage unit 44 may include: The second ciphertext acquisition subunit is used to traverse the red-black tree and obtain the second ciphertext that has not been accessed for more than the second preset time in the red-black tree. The second ciphertext determination subunit is used to determine the second ciphertext that has not been accessed for more than a second preset time period as the second ciphertext to be written into the exchange area file.

[0083] In one specific embodiment of the present invention, the device may further include: The process memory page table acquisition unit is used to acquire the target process memory page table corresponding to the target memory space to which the target memory page belongs after storing the second ciphertext into the red-black tree; The memory page deletion unit is used to delete the target memory page from the target process's memory page table.

[0084] In one specific embodiment of the present invention, the device may further include: The memory page to be accessed unit is used to parse the received memory access request and obtain the memory page to be accessed. The memory page lookup unit is used to perform a memory page lookup in the process memory page table corresponding to the memory space to be accessed. The judgment unit is used to determine whether the memory page to be accessed has been found. The first decryption and loading unit is used to trigger a page fault interrupt when it is determined that the memory page to be accessed cannot be found. This allows the processor to look up the interrupt table of the system kernel based on the page fault interrupt, find the page fault handler in the interrupt table, and use the page fault handler to decrypt and load the memory page to be accessed.

[0085] In one specific embodiment of the present invention, the first decryption and loading unit may include: The memory page identification information lookup subunit is used to traverse the red-black tree to find the memory page identification information of the memory page to be accessed using the page fault exception handler; wherein, the red-black tree stores the correspondence between each second ciphertext and each memory page identification information; The second judgment subunit is used to determine whether the memory page identifier information of the memory page to be accessed can be found in the red-black tree; The first data decryption and loading subunit is used to decrypt the second ciphertext in the memory page to be accessed from the red-black tree when the memory page identifier information of the memory page to be accessed is found in the red-black tree, and load the decrypted data into the memory space to which the memory page to be accessed belongs.

[0086] In one specific embodiment of the present invention, the first data decryption and loading subunit is specifically a unit that decrypts the second ciphertext in the memory page to be accessed by using the reverse operation of the first step of the XOR encryption in the calibration codebook mode with ciphertext stolen from the red-black tree.

[0087] In one specific embodiment of the present invention, the device may further include: The second decryption and loading unit is used to decrypt the memory page to be accessed from the swap file when it is determined that the memory page identification information of the memory page to be accessed is not found in the red-black tree, and to load the decrypted data into the memory space to which the memory page to be accessed belongs.

[0088] In one specific embodiment of the present invention, the second decryption and loading unit is specifically a unit that decrypts the memory page to be accessed from the swap file by executing a complete decryption process of the calibration codebook mode with ciphertext stolen.

[0089] In one specific embodiment of the present invention, the second decryption and loading unit may include: The target physical memory acquisition sub-unit is used to allocate physical memory for the memory page to be accessed, thus obtaining the target physical memory. The data migration subunit is used to migrate the decrypted data to the target physical memory; The virtual address acquisition subunit is used to acquire the virtual address corresponding to the target physical memory; The process memory page table modification subunit is used to modify the process memory page table based on the virtual address.

[0090] In one specific embodiment of the present invention, the first ciphertext acquisition unit 43 is specifically a unit that searches for the first key from the trusted security platform module; The third ciphertext acquisition unit 46 is specifically a unit for retrieving the second key from the trusted security platform module.

[0091] In one specific embodiment of the present invention, the third ciphertext acquisition unit 46 is specifically a unit that performs encryption operations on the target second ciphertext using a symmetric encryption / decryption algorithm with a second key.

[0092] For a description of the features in the embodiment corresponding to the memory data management device, please refer to the relevant description in the embodiment corresponding to the memory data management method, which will not be repeated here.

[0093] Embodiments of the present invention also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above-described embodiments of the memory data management method.

[0094] Embodiments of the present invention also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above-described memory data management method embodiments at runtime.

[0095] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0096] Embodiments of the present invention also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above-described memory data management method embodiments.

[0097] Embodiments of the present invention also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above-described memory data management method embodiments.

[0098] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0099] The present invention has provided a detailed description of a memory data management method, electronic device, storage medium, and program product. Specific examples have been used to illustrate the principles and implementation methods of the invention. The descriptions of these embodiments are only intended to aid in understanding the method and core ideas of the present invention. It should be noted that those skilled in the art can make various improvements and modifications to the present invention without departing from its principles, and these improvements and modifications also fall within the protection scope of the present invention.

Claims

1. A memory data management method, characterized in that, include: Traverse the memory space corresponding to each process to obtain the target memory page that can be encrypted; The data in the target memory page is identified as the data to be encrypted, and the data to be encrypted and its physical address are read. Obtain the first key, and use the first key to process the physical address to obtain the first ciphertext; Perform an XOR operation on the data to be encrypted and the first ciphertext to obtain the second ciphertext, and store the second ciphertext in a red-black tree; Traverse the red-black tree to obtain the second ciphertext to be written to the swap file, and determine the second ciphertext to be written to the swap file as the target second ciphertext; The target second ciphertext is retrieved from the red-black tree, a second key is obtained, and the target second ciphertext is encrypted using the second key to obtain the third ciphertext; The first ciphertext and the third ciphertext are XORed to obtain the fourth ciphertext, which is then written into the exchange area file.

2. The memory data management method according to claim 1, characterized in that, Traverse the memory space corresponding to each process to obtain the target memory pages that can be encrypted, including: Traverse the memory space corresponding to each process to obtain the idle time of each memory page in each memory space; Determine if there are memory pages whose idle time exceeds a first preset time. If so, then the memory page whose idle time exceeds the first preset time is determined as the target memory page; If not, return to the step of traversing the memory space corresponding to each process.

3. The memory data management method according to claim 1, characterized in that, Traversing the red-black tree, the second ciphertext to be written to the swap file is obtained, including: Traverse the red-black tree to obtain the second ciphertext that has not been accessed for more than a second preset time. The second ciphertext that has not been accessed for more than the second preset time period is determined as the second ciphertext to be written to the exchange area file.

4. The memory data management method according to claim 1, characterized in that, After storing the second ciphertext in the red-black tree, the following steps are also included: Obtain the target process memory page table corresponding to the target memory space to which the target memory page belongs; Remove the target memory page from the target process's memory page table.

5. The memory data management method according to claim 4, characterized in that, Also includes: The received memory access request is parsed to obtain the memory page to be accessed; Perform a memory page lookup on the process memory page table corresponding to the memory space to which the memory page to be accessed belongs; Determine whether the memory page to be accessed has been found; If not, a page fault interrupt is triggered, causing the processor to look up the system kernel's interrupt table based on the page fault interrupt, and then find the page fault handler in the interrupt table. The page fault handler is then used to decrypt and load the memory page to be accessed.

6. The memory data management method according to claim 5, characterized in that, The page fault handler is used to decrypt and load the memory page to be accessed, including: The page fault handling procedure is used to traverse the red-black tree to find the memory page identifier information of the memory page to be accessed; wherein, the red-black tree stores the correspondence between each second ciphertext and each memory page identifier information; Determine whether the memory page identifier information of the memory page to be accessed can be found in the red-black tree; If so, the second ciphertext in the memory page to be accessed is decrypted from the red-black tree, and the decrypted data is loaded into the memory space to which the memory page to be accessed belongs.

7. The memory data management method according to claim 6, characterized in that, Decrypting the second ciphertext in the memory page to be accessed from the red-black tree includes: The second ciphertext in the memory page to be accessed is decrypted by reversing the first step of the XOR encryption in the ciphertext-stealing tuning cipherbook mode from the red-black tree.

8. The memory data management method according to claim 6, characterized in that, When it is determined that the memory page identifier information of the memory page to be accessed cannot be found in the red-black tree, the following steps are also included: The memory page to be accessed is decrypted from the swap file, and the decrypted data is loaded into the memory space to which the memory page to be accessed belongs.

9. The memory data management method according to claim 8, characterized in that, Decrypting the memory page to be accessed from the swap file includes: The memory page to be accessed is decrypted from the swap file by performing a complete decryption process using a ciphertext-stealing calibration codebook mode.

10. The memory data management method according to claim 8 or 9, characterized in that, Loading the decrypted data into the memory space of the memory page to be accessed includes: Physical memory allocation is performed on the memory page to be accessed to obtain the target physical memory; The decrypted data is then migrated to the target physical memory. Obtain the virtual address corresponding to the target physical memory; Modify the process memory page table based on the virtual address.

11. The memory data management method according to claim 1, characterized in that, Obtaining the first key and obtaining the second key includes: Locate the first key from the trusted security platform module; The second key is retrieved from the trusted security platform module.

12. The memory data management method according to claim 1, characterized in that, Encrypting the target second ciphertext using a second key includes: The second key is used to perform encryption operations on the target second ciphertext using a symmetric encryption / decryption algorithm.

13. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the memory data management method as described in any one of claims 1 to 12 when executing the computer program.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it implements the steps of the memory data management method as described in any one of claims 1 to 12.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the memory data management method as described in any one of claims 1 to 12.

Citation Information

Patent Citations

  • Order-preserving encryption algorithm based on balanced sort tree storage structure

    CN109495446A

  • Memory management system, leak detection method and storage medium

    CN115617504A

  • Dynamic library loading method and device, computer equipment and storage medium

    CN116225569A

  • Optimizing huge page management

    US20230376423A1

  • Memory management method and module, chip, electronic device, and storage medium

    WO2024044986A1