A configurable memory device connected to a microprocessor.
The memory recovery system addresses the inefficiencies in cloud computing by using a root of trust processor to prepare memory in the background, reducing downtime and enhancing security through simultaneous recycling and preparation of memory resources.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- ORACLE INT CORP
- Filing Date
- 2024-12-16
- Publication Date
- 2026-04-27
AI Technical Summary
Existing cloud computing systems face significant overhead due to the time-consuming process of data erasure and reconfiguration of memory resources between user transitions, leading to downtime and inefficiencies in resource utilization.
A memory recovery system that utilizes a root of trust processor to prepare a second memory portion in the background while a service processor serves the current user, employing a switch to isolate and swap access between memory portions, enabling simultaneous recycling and preparation of memory for future use.
This approach significantly reduces memory recycling time, allowing immediate access to prepared resources for the next user, enhances security, and minimizes downtime by isolating the preparation process from active user access.
Smart Images

Figure 0007835836000001 
Figure 0007835836000002 
Figure 0007835836000003
Abstract
Description
Background Art
[0001] Cross-reference of related applications This application claims the benefit of U.S. Patent Application No. 16 / 884,002, filed May 26, 2020, entitled "Configurable Memory Device Connected To A Microprocessor", and U.S. Patent Application No. 62 / 853,667, filed May 28, 2019, entitled "Configurable Memory Device Connected To A Microprocessor", and incorporates the above applications by reference herein in their entirety for all purposes as fully set forth herein.
[0002] background Data centers provide a centralized location for consolidating computing and networking equipment so that users can access, consume, and store large amounts of data. For example, in an aggregation of computing systems such as a cloud computing system, common resources such as processors and memory are often configured so that different users can access them in sequence. In such a computing aggregation, rewritable memory, such as flash memory, which can be erased when one user is done using it and rewritten for the next user, is used. For example, when a new user begins accessing cloud resources, a cloud service provider must ensure that the resources are properly configured for subsequent users and that all information from the previous user is made unavailable.
[0003] Depending on the cloud system, a hardware wipe of all memory may be required to protect the integrity of user activity on the cloud. Such data erasure can take considerable time to ensure complete data removal. Further time is spent configuring the memory for reuse by rewriting any startup data. The period during which old data is deleted and cloud resources are reconfigured for the next user represents overhead during which no user can utilize those resources. It is desirable to reduce or minimize the time spent on memory recycling. [Overview of the Initiative]
[0004] overview Implementation examples of the present invention relate to a system for simultaneously recycling memory for future use. In some implementation examples, a device is provided in a collection of computing systems that prepares memory for reuse. The device includes a first memory portion accessible to the first client device of the first user during the first user's usage period. A service processor is coupled to the switch and communicates with the first memory during the usage period. A root of trust processor is coupled to the switch. The root of trust processor is inaccessible to the first client device of the first user during the usage period. The device further includes a second memory portion inaccessible to the first client device of the first user during the first user's usage period. One or more control signals are provided to trigger the root of trust processor to prepare the second memory portion for deployment while the service processor is communicating with the first memory portion. The first and second memory portions may be flash memory.
[0005] In some implementations, the root of trust processor is the second memory. The second memory portion is configured to be prepared by erasing data from previous users of the second memory, such as by restoring it to its original factory state. The root of trust processor may also prepare the second memory portion by reconfiguring it so that it can be used by a second user.
[0006] In some aspects, the device may further include a connector coupled to the root-of-trust processor and the switch. The root-of-trust processor may transmit signals through the connector to instruct the switch to swap access between the service processor and the root-of-trust and the first and second memory portions. In some implementations, the switch may have multiple input lines and multiple output lines.
[0007] Furthermore, in some implementation examples, the method of providing memory for reuse in a cloud computing system includes enabling communication between a root of trust processor and the first memory after a first user has finished accessing the first memory through a service processor in the cloud computing system. The root of trust processor prepares the first memory for future use while the service processor is permitted to communicate with the second memory for access by a second user, and while the root of trust processor is prohibited from communicating with the second memory. A switch signal is generated to trigger the exchange of communication between the service processor and the root of trust and the first and second memories. For example, the root of trust may send the switch signal to a switch component.
[0008] Various implementations and examples of the method are described. For example, the communication exchange may include allowing the service processor to communicate with the first memory, prohibiting the service processor from communicating with the second memory, allowing the root of trust processor to communicate with the second memory, and prohibiting the root of trust processor from communicating with the first memory.
[0009] In some implementation examples, the first user's access to the first memory is terminated when the second user receives a notification through the service processor that the period for which they have access to the second memory has ended.
[0010] In some implementations, the preparation of the first memory may include erasing data from the first user, such as restoring the second memory to its original factory state. The preparation may also include configuring the first memory for subsequent users.
[0011] Furthermore, in some implementation examples, a cloud computing system is provided that has a memory recovery system for simultaneously recycling memory. The cloud computing system includes a service frontend and a recovery backend. The service frontend includes a service processor accessible by the first client device of the first tenant user during the first tenant user's usage period, and a first memory portion accessible by the first client device of the first tenant user during the first tenant user's usage period. The recovery backend includes a second memory portion inaccessible to the first client device of the first tenant user during the first user's usage period, and a root-of-trust processor that prepares the second memory portion for future deployment while the service processor communicates with the first memory portion. The root-of-trust processor is inaccessible to the first client device of the first tenant user. The Ud Computing System further includes a switch coupled to the service frontend and the restore backend. The switch is configured to swap access between the service processor and the root of trust and the first and second memories in response to a switch signal from the root of trust processor.
[0012] In some implementations, the root of trust processor prepares the second memory portion by erasing data from the previous user. Erasing the data may include restoring the second memory portion to its original factory state. The root of trust processor may also prepare the second memory portion by reconfiguring it for use by a second tenant user.
[0013] In some aspects of the cloud computing system described above, the connector is coupled to the root of trust processor and the switch. The root of trust processor may transmit signals through the connector to instruct the switch to swap access between the service processor and the root of trust and the first and second memory portions.
[0014] This disclosure is provided in the drawings for illustrative purposes only, not limitation, and similar reference numbers in these drawings are used to refer to similar elements. [Brief explanation of the drawing]
[0015] [Figure 1a] This is a conceptual diagram illustrating an exemplary environment in which various aspects of a memory recovery system can be implemented, following several implementation examples, and shows reserved memory being prepared for reuse. [Figure 1b] This is a conceptual diagram illustrating an exemplary environment in which various aspects of a memory recovery system can be implemented, following several implementation examples, and shows a state in which prepared reserved memory is being used. [Figure 2] This is a block diagram of an exemplary memory recovery system that incorporates a multiplexer to selectively connect a root-of-trust processing unit and service processor coupled to an operational serial peripheral interface, following several implementation examples. [Figure 3] This is a block diagram of an exemplary memory recovery system that incorporates a crossbar switch to selectively connect a root-of-trust processing unit and a service processor coupled to one of two operational serial peripheral interfaces, following several implementation examples. [Figure 4] Figure 3 is a block diagram of the memory recovery system, showing an example of the pinout of the control circuit in a specific implementation, following several implementation examples. [Figure 5]This is a flowchart illustrating an exemplary method for implementing simultaneous memory recycling using a memory reservation system, following several implementation examples. [Figure 6] These are block diagrams of exemplary computing devices that can be used to implement the memory reservation system shown in Figures 1-4, following several implementation examples. [Modes for carrying out the invention]
[0016] Detailed description of the embodiment This memory recovery system enables a collection of computing systems to prepare inactive rewritable memory for reservation and for future replacement of other memory. This preparation is performed while other memory is active and available for access by users of the computing system. The preparation of the reserved memory portion is isolated from the current users of the active memory portion within the computing system. It runs offline. Memory preparation includes data erasure and reconfiguration. Once the active memory portion is returned, the reserved memory portion can be easily replaced by the memory recovery system. In some implementations, previously active memory can also be recycled and become reserved memory for future reuse.
[0017] In some implementations, a computing device, such as a collection of servers, may integrate this memory recovery system into a cloud computing environment. The computing devices used in a cloud computing system include more memory and more powerful components, such as a robust operating system, than individual client devices, such as workstations. A cloud computing system may include various types of servers, such as bare-metal instances without a hypervisor.
[0018] The service processor is configured to switch to use one of two memory parts, for example, two flash memories. While the service processor is connected to the current memory part and using the current memory part, the root of trust (ROT) processing unit can configure the "inactive" memory part in the background simultaneously with the users present on the server, for example, in a cloud service application. The inactive memory part is prohibited from being connected to the service processor during the preparation stage. When the user exits the server, the cloud infrastructure can "swap" to the memory part that was previously inactive. The simultaneous recycling process of this memory restoration system can bring about a significant acceleration of the server preparation process. The replacement of the memory part is performed using an electrical connection and takes several milliseconds to several seconds until the swap is complete. The computing device accessed by the user is provisioned with clean firmware. The preparation of the reserved memory part executed in the background may include erasing the data from the previous user of the reserved memory part and wiping the reserved memory part clean, for example, restoring it to the factory shipment settings. In some examples, this preparation stage may also include reading the data stored in the reserved memory part and verifying that the bits have not been changed while the previous user was present on the system.
[0019]
[0020] The preparation stage may also include reconfiguring the reserved memory portion for later user use. Reconfiguration may require writing appropriate data to the startup or boot memory to initiate the environment or task of the later user. For example, the root of trust may prepare a fresh software image to be booted on clean flash memory before the prepared memory is passed to the service processor for the next user. The fresh image may be from a previously prepared memory device. Thus, the preparation process can continuously hold any of the memory portions.
[0021] The user referred to in this description, such as an end user, may be any person or entity designated to have available access to a given service processor and active memory device, and the active memory device is preconfigured in response to the user's request. For example, the user may be a tenant of server space in a multi-tenant cloud architecture, where the tenant is isolated and not visible to other tenants of other cloud resources. In some implementations, the user may also be a tenant of a single-tenant cloud system. For example, the user may be a customer currently using a server, such as a customer assigned to the server. The user may be a group of authorized persons, one or more entities, such as a company or a group within a company (including businesses, universities, governments, military, etc.), or an individual.
[0022] A service processor and active memory may be reserved exclusively for the user for the duration of their use, during which the user is entitled to access the allocated computer resources. For example, the use period may begin when the user is granted access to the allocated computer resources, such as a given service processor and associated memory, and end when the user relinquishes the allocated computer resources. The use period may be defined by an agreement with the customer, the duration of a particular project, or the term of employment or contract.
[0023] While features may be described for specific types of resources or operations, such as system flash memory, the features described herein are applicable to other cloud computing resources and operations. Furthermore, while cloud computing is one example of a computing system described in which the memory recovery system may be implemented by the motherboard, this memory recovery system may also be used in other computing environments where memory devices or other electronic hardware are updated in the background. For example, network cards, hard drives, etc., may be updated without interfering with currently running software.
[0024] A memory recovery system may be used to update memory such as memory images that typically take a long time to load due to containing large amounts of data. The update may be performed in the background on a second memory while the first memory is being used by a user of the computer device. The device may then be restarted to load the updated second memory, and both memories are of the same type, such as flash memory. Thus, one memory is not persistent memory, for example, while the other is random-access memory. In addition, a memory recovery system can enable forensic analysis of inactive memory portions if it is suspected that a portion of the memory has been tampered with, for example, by an authorized user.
[0025] It is customary to configure the service processor to carry a single flash memory device for the user. Erasing the flash memory can require considerable downtime, during which the system is inoperable. To compensate for the slow erase / write cycles, some systems attempt to speed up communication with the flash memory by increasing the speed of the physical communication bus between the service processor and the flash memory.
[0026] Another solution being attempted involves logically partitioning the memory used by the service processor, for example, dividing it into two equal parts, and running one part, or half, while updating the other part(s). However, this partitioned memory approach could impose security risks, as the currently running service processor software might be considered untrustworthy once a user becomes present on the server.
[0027] This memory recovery system offers security advantages by isolating the preparation of the reserved memory portion through a switch that restricts access to the reserved memory by the service processor and existing users until the reserved memory is ready to be deployed.
[0028] This memory recovery system significantly reduces the recycling time of computer resources. The next user of a computer resource does not need to wait for the resource to be prepared (e.g., data to be erased) after the previous user has finished using it. By configuring the time-consuming portion of the memory wipe for the next user simultaneously with the service processor accessing separate active memory for the currently existing user, the wipe time experienced during user transitions can be reduced. The Mori Restoration System increases the resilience of server clusters to meet growing customer demand and avoid thousands of potentially offline servers constantly waiting to be recycled.
[0029] In some implementations, two or more physical sections of memory are maintained to reduce the time before the next user can begin using the service processor. While the service processor is being used by the current user, the second section of memory (e.g., flash memory, or other) is accessed by the Root of Trust Processing Unit (ROT). The ROT may be dedicated to jobs such as preparing reserved memory and replacing prepared reserved memory, such as reinstallation. In some implementations, the ROT may include other hardware and firmware that are trusted by being inaccessible to the user. Between user tenancies, the ROT is used to safely wipe any memory used by the service processor.
[0030] In some implementations, ROT or any other type of processing equipment may be used to provide additional functionality. For example, ROT may sanitize, load, and / or validate data for the next user. Then, when it is time for the new user to start operating on the cloud resources, the service processor can communicate with the prepared memory section and begin processing without waiting for the most recently used memory section to be wiped or otherwise configured.
[0031] The usage example shown in Figure 1a illustrates the memory preparation phase in which reserved memory, memory-1 146, is prepared for reuse in the context of the cloud computing system 100. The cloud computing system 100 includes a memory recovery system 110 having a service frontend 122 for computing device-A 120 and a recovery backend 142 for computing device-B 140. According to one implementation example, the memory recovery system 110 is used to access memory-2 via I / O port 128 by a client device 102 of user 104 traversing network 164 via a router (not shown) of the cloud computing system 100. While memory 126 is being accessed, memory -1 = 146 can be prepared.
[0032] Figure 1a shows an instance of a memory recovery system 110, which includes a service front end 122 accessible by a client device 102, having a service processor 124 and memory-2 126. The memory recovery system 110 includes a recovery backend 140 inaccessible to the client device 102, having a ROT processing unit 144 and memory-1 146. The client device may be a variety of heterogeneous devices, such as a desktop, laptop, tablet, smartphone, or thin client.
[0033] In some implementations, computing device-A 120 and computing device-B 140 may be server devices. For example, computing device-A 120 may be a bare-metal type server in which the user can access most of computing device-A 120 except for certain locked-down components. In other implementations, computing device-A Computing device-B 140 is not a separate device, but rather a virtualized machine managed by, for example, Hypervision software. It is thin. In some implementation examples, the server is a large-scale blade server.
[0034] The service processor 124 may be any microprocessor to which the user device 102 can connect and perform functions. For example, in some implementations, the service processor is an Oracle Integra embedded in computing device A 120. This may include a ted Lights Out Manager (ILOM). The server may include various service processors, such as high-performance processors, including Intel XEON® and AMD EPYC® processors. In some implementations, the service processor is a baseboard management controller (BMC). This may include other types of service processors (including general-purpose, custom, bit-slice, or other processors) or processing systems or resources. The BMC may use sensors to monitor the physical status of the server and communicate with the system administrator through a special management connection.
[0035] Switch 160 selectively connects memory-1 146 and memory-2 126 to the ROT and the service processor, respectively. The switch may include various types, such as a multiplexer, a set of switches, or a crossbar switch with multiple input / output lines. The computing system controller 162 may control various aspects of the memory recovery system 110. The controller may send a signal to the ROT to prepare memory-1 146 for deployment. The control signal may trigger the ROT to prepare and configure memory-1 146 while the service processor 124 communicates with memory-2 126.
[0036] In some implementations, one or more switch signals are sent from the ROT to the switch 160 to instruct it to selectively connect or disconnect the ROT and / or service processor to memory-2 126 or memory-1 146. The switch signal may be a single signal for applying or not applying a voltage. In some implementations, the switch signal may be transmitted from the ROT via a virtual wire, a physical wire, or other signal transmission medium. In some implementations, the switch signal may also be transmitted by another source, such as a controller 162. In even more implementations, the switch signal may be a physical component for switching the switch 160.
[0037] For simplicity, Figure 1a shows a single client device 102 and computing devices 120 and 140. The cloud computing system 100 may include a vast collection of computing devices 120 and 140 and have the capability to scale to simultaneously serve many client devices 102 of numerous users 104. In addition, while Figure 1a shows one memory portion being prepared by ROT, in some implementation examples, ROT may prepare multiple reserved memories simultaneously or sequentially for future deployments.
[0038] Cloud computing system 100 is a platform as a service (PaaS) and infrastructure as a service (Iaa). S: infrastructure as a service) and other public services that run various services, The cloud system may be private, virtual private, multi-cloud, or personal cloud system, or a combination thereof. Although the memory recovery system 110 is shown in the context of the cloud computing system 100 in Figure 1a, the memory recovery system 110 may be used with substantially the same components in other computing systems and applications that can benefit from memory swapping with reduced downtime.
[0039] Memory-1 146 and Memory-2 126 may be any rewritable memory suitable for storage and communication with the service processor 124 and the ROT processing unit 144, such as flash memory. Memory-1 146 and Memory-2 126 are typically the same type of rewritable memory, such as flash memory. Note Memory-1 146 and Memory-2 126 are shown as components of computing devices 120 and 140, respectively, but the memory may be located separately from computing devices 120 and 140. For example, Memory-1 146 and Memory-2 126 may be virtualized memory isolated from the servers (computing devices 120 and 140) by a virtualization manager, such as hypervision software.
[0040] In further explanation of the usage example in Figure 1a, Figure 1b shows a swapping phase of the cloud computing system 100 in which a fully prepared memory-1 146 is swapped with memory-2 126 in order to reuse memory-1 146 with the service processor 124. During the swapping phase, switch 160 may receive one or more signals from ROT 144, etc., that trigger switch 160 to change the connection. Through the change in the switch connection, ROT 144 gains communication access to memory-2 126, and service processor 124 loses access to memory-2 126. Similarly, ROT 144 gains communication access to memory-1 Having lost connectivity to 146, the service processor 124 gains communication access to memory-2 126. A new user device 106 of a later user 108, different from the most recent preceding user, can connect to memory-1 146 while memory-2 126 is being prepared for reuse in the background.
[0041] During the replacement phase, ROT can trigger power-off and power-on of hardware hosts, such as servers used by tenant users, to prompt the installation of known firmware. ROT can receive confirmation from the hardware host that the process was executed as expected. The firmware installation preparation and replacement phases are protected against persistent denial of service (PDoS) attacks, or firmware This reduces the risk of firmware-based attacks, such as attempts to embed backdoors in the software to steal data or otherwise render it unusable.
[0042] Some implementations of the memory recovery system 200, as shown in the example in Figure 2, may include a multiplexer switch 202. The service processor (SP) 204 is selectively coupled to the operational serial peripheral interface (OSPI) 208 via the SPI 210 through the multiplexer switch 202 via the serial peripheral interface (SPI) 206. The ROT 214 is selectively coupled to the OSPI 208 via the OSPI 202 through the serial peripheral interface (SPI) 216. The OSPI 208 enables communication with the flash memory system, including memory-1 220 accessed by the ROT 214 and memory-2 222 accessed by the SP 204.
[0043] In some implementations, only certain steps or operations in the preparation phase may need to be pre-configured to save time or provide other beneficial results. Connector 218 may provide a dedicated path for transmitting one or more signals generated by ROT214 to the switch. Connector 218 may also be a virtual wire for coupling ROT214 to the multiplexer switch 202.
[0044] Figure 3 illustrates an example implementation of a memory reservation system 300 for configuring reserved memory, such as memory-1 320, while simultaneously allowing the service processor 304 to access active memory, such as memory-2 322. When the reserved memory is ready, the memory reservation system switches the service processor 304 to the reserved memory, such as memory-1 320, via a crossbar switch 302.
[0045] The crossbar switch 302 controls the ROT314 or SP304 via SPI and The ROT can be selectively connected to either memory-1 320 or memory-2 322 via OSPI1 308 or OSPI2 324. Through the crossbar switch 302, ROT 314 is connected to reserved memory (to memory-1 320 via OSPI1 308, or to memory-2 322 via OSPI2 324), and SP 304 is connected to active memory (to memory-1 320 via OSPI1 308, or to memory-2 322 via OSPI2 324). In some implementations, one or more ROTs and one or more SPs may be connected between two or more memory sections having two or more associated OSPIs. In some implementations, a high-bandwidth bus switch may be used.
[0046] Connector 318 may be a physical or virtual wire for coupling ROT314 to the crossbar switch 302. ROT314 may also send a switch signal to the crossbar switch 302 through connector 318, for example, to trigger the crossbar switch 302 to selectively swap access to OSPI1 308 for memory-1 320 and access to OSPI2 324 for memory-2 322.
[0047] In a particular implementation, each memory portion may be a separate flash memory component or system. In other implementations, the memory portions or partitions may reside within the same physical system, or they may be organized in the background across three or more different memory components (or memory devices, if there are multiple).
[0048] In some implementations, ROT314 may be configured with reserved memory, which may further include loading and measuring OSPI1 308 and / or OSPI2 324. For example, the contents of OSPI1 308 and / or OSPI2 324 may be read and compared to known tolerances.
[0049] In some implementations, the ROT may be given alternating access to both memory-1 320 and memory-2 322 so that the ROT can measure and update OSPI1 308 and OSPI2 324 at a given time. In one implementation, the crossbar switch 302 allows the ROT 314 to control, for example, through signals sent from the ROT 314 via connector 318, whether the ROT 314 is connected to OSPI1 308 or OSPI2 324, and which of the OSPI1 308 or OSPI2 324 devices is connected to the SP 304.
[0050] Figure 4 is a block diagram of exemplary interconnections of possible components in the memory recovery system configuration 400 shown in Figure 3. For example, a high-bandwidth bus switch 402 such as the QS3VH16212 bus-exchange hot switch from Renesas / Integrated Device Technology may be used. Connector 418 provides more I / O by adding an input / output expander such as the Texas Instruments 16-bit I / O expander PCA9555. This may also be the case. In some implementations, a signal expander device may be useful when there is a shortage of physical pins in a particular configuration of the memory recovery system 400. For example, a high-bandwidth bus switch may require additional control bits for additional signals. Other numbers and types of signal expander or signal connector configurations may also be used.
[0051] As described above with respect to Figure 3, the interconnection selectively connects ROT414 through multiple input lines 416, SP404 through multiple output lines 406, and one of the two OSPI devices 408, 424 through multiple lines 410, 412. Includes a switch 402 having pins. OSPI devices 408, 424 enable coupling to their respective memory sections (not shown).
[0052] Figure 5 is a flowchart of an exemplary simultaneous recycling process 500 that automatically prepares and configures used memory for reuse. This simultaneous recycling process is performed by at least some of the components of a memory recovery system (e.g., 110 in Figures 1a and 1b, 200 in Figure 2, or 300 in Figure 3).
[0053] This simultaneous recycling may involve locating a physical medium connected to the host, such as flash memory returned by a previous user. In block 502, an indication is received that the returned memory portion, previously used by a collection of computing resources, such as a cloud computing system, is inactive. This indication may be an internally generated notification, such as from the cloud computing system, that a parameter has been reached that terminates a particular user's access to the returned memory. The termination of use may be the expiration of a particular user's usage period, a warning prohibiting the use of the returned memory, a hardware or software problem with the memory, etc. In some implementations, the indication may be generated by the user device, for example, that the user has terminated their use of the returned memory.
[0054] In block 504, the service processor (e.g., 124 in Figures 1a and 1b, 204 in Figure 2, and 304 in Figure 3) is temporarily denied access to the returned inactive memory. The service processor may be disconnected from the inactive memory by a switch (e.g., 106 in Figures 1a and 1b, 202 in Figure 2, or 302 in Figure 3). The service processor is used by the currently existing user (e.g., 104 in Figures 1a and 1b). In block 506, a user connection is provided so that the SP can access the active memory portion for the client device of the currently existing user. The active memory portion is already prepared and configured for use.
[0055] ROT (e.g., 144 in Figures 1a, 1b, 214 in Figure 2, and 314 in Figure 3) may trigger the switch to change the connection to the memory portion by sending a switch signal. In block 508, a connection is provided so that ROT can access the returned inactive memory portion.
[0056] The ROT can initiate secure erasure by executing an erase command applicable to the type of media. In block 510, data on the returned inactive memory portion is erased by the ROT during the preparation phase. During the preparation phase, physical destruction and logical data erasure processes are used to ensure that no data remains in the recovered memory.
[0057] In some implementations, once the erasure process is complete, ROT can initiate a process to restore the used memory to its initial factory state, reverting it to the factory settings before the initial deployment for the user. ROT can also test the used memory for defects. If defects are detected, the used memory can be flagged for further investigation.
[0058] In block 512, ROT configures inactive memory for users after the service processor. When computing resources, such as a bare-metal compute server instance, are released by a user or service, the hardware undergoes a provisioning process before the returned memory is released into inventory for reallocation. Configuring may include installing and configuring software, including operating systems and applications.
[0059] In decision block 514, it is determined whether the usage period for active memory is still ongoing or has ended. In block 516, if the usage period is still ongoing and the user is still permitted to use the active memory, the prepared active memory portion remains in use, and the inactive memory portion is kept pending for subsequent users in a memory swap. Otherwise, depending on the circumstances, such as when there are no more users or when the memory is found to be too worn for further use, the process may terminate. If the usage period is no longer ongoing and the user is not permitted to continue using the active memory portion, the process returns to block 502 to swap the memory and prepare / configure the recently used memory portion.
[0060] Figure 6 is a block diagram of an exemplary computer device 600, such as a server (e.g., 120 or 140 in Figure 1a or Figure 1b), to be used with the implementation example of the memory recovery system described herein. Computer device 600 may be included in any of the above-described computer devices of a collection of computer devices. Computer device 600 is illustrative and is not intended to limit the scope of the claims. Those skilled in the art will recognize other variations, modifications, and alternatives.
[0061] In one exemplary implementation, computer device 600 includes an I / O interface 610 that can represent a combination of various communication interfaces (e.g., 128 in Figures 1a and 1b). The I / O interface 610 may include a network interface. A network interface typically includes a network interface card, an Ethernet® card, a modem (telephone, satellite, cable, ISDN), and a (asynchronous) digital subscriber line (DSL) unit. Furthermore, the network interface may be physically integrated on the motherboard, a software program such as soft DSL, or otherwise. In some implementations, computer device 600 may use virtual devices instead of physical I / O components.
[0062] Computer device 600 may also include software that enables communication of the I / O interface 610 over network 670, such as HTTP, TCP / IP, RTP / RTSP, Protocol, Wireless Application Protocol (WAP), and IEEE 902.11 Protocol. In addition to and / or instead of this, other communication software and transport protocols, such as IPX or UDP, may be used. Communication network 670 may include any other suitable communication network, such as a local area network, wide area network, wireless network, intranet, internet, private network, public network, switched network, or cloud network. Network 670 may include many interconnected computer systems and any suitable communication links, such as wired links, optical links, satellite, or other wireless communication links, such as Bluetooth®, Wi-Fi, wave propagation links, or any other suitable mechanism for the communication of information. For example, network 670 may communicate with one or more mobile wireless devices 956A-N, such as mobile phones and tablets, via base stations such as wireless transceivers.
[0063] The computer device 600 typically includes computer components such as the processor 650 (service processors 124 and ROT 144 in Figures 1a and 1b) as described above, and memory storage devices such as memory 620 and storage medium 640, such as flash memory as described above. The bus connects the computer components They may be interconnected. In some implementations, the computer device 600 is a server having hard drives (multiple) (e.g., SCSI) and controller cards, a server-compatible processor, a network interface, and memory. While a computer is shown, it will be readily apparent to those skilled in the art that many other hardware and software configurations are suitable for use with the present invention.
[0064] Memory 620 and storage medium 640 are examples of tangible, non-temporary, computer-readable media for storing data, files, and computer programs. Other types of tangible media include disk drives, solid-state drives, floppy disks, optical storage media and barcodes, semiconductor memory such as flash drives, flash memory, random-access or read-only type memory, battery-backed volatile memory, networked storage devices, and cloud storage. Data store 632 may be used to store various types of data, such as user-saved data.
[0065] One or more computer programs, such as application 634, also called a program, software, software application, or code, may also contain instructions that, when executed, perform one or more methods, such as those described herein. Computer programs may be tangibly embodied in an information carrier, such as a computer or a machine-readable medium, for example, in memory 620, a storage device on processor 650, or memory. A machine-readable medium is any computer program product, apparatus, or device used to provide machine instructions or data to a programmable processor.
[0066] Computer device 600 further includes operating system 628. Any operating system 628 that supports failover clustering, such as a server OS, can be used, for example, Linux®, Windows Server (registered trademark), Mac OS, etc. can be used.
[0067] While the descriptions have focused on specific implementation examples, these examples are illustrative and not limiting. For example, circuits or systems that perform the functions described herein may differ significantly from the specific embodiments illustrated herein.
[0068] The routines in a particular implementation can be implemented using any suitable programming language, including C, C++, Java®, assembly language, etc. Different programming techniques, such as procedural or object-oriented programming, can be used. The routines can be executed on a single processor or on multiple processors. Steps, actions, or calculations are presented in a specific order, but this order may be changed in different specific implementations. In some specific implementations, multiple steps indicated herein as sequential can be executed simultaneously.
[0069] Certain embodiments may be implemented in a computer-readable storage medium used by or in connection with an instruction execution system, apparatus, system, or device. Certain embodiments may be implemented in the form of control logic in software, hardware, or a combination of both. The control logic, when executed by one or more processors, may be operable to perform those described in a particular embodiment.
[0070] A particular embodiment uses a programmed general-purpose digital computer These may be implemented by using application-specific integrated circuits, programmable logic devices, field-programmable gate arrays, optical, chemical, biological, quantum, or nanoengineered systems, components, and mechanisms. In general, the functionality of a particular embodiment can be achieved by any means known in the art. Distributed, networked systems, components, and / or circuits may be used. Communication or transfer of data may be by wired, wireless, or any other means.
[0071] Furthermore, it will be understood that one or more of the elements shown in the drawings can be implemented in a more separate or integrated manner, and may even be removed or disabled as necessary for convenience according to a particular application. Implementing a program or code that can be stored on a machine-readable medium so that a computer can perform any of the above methods is also included in the spirit and scope of the present invention.
[0072] In this specification and throughout the appended claims, “a,” “an,” and “the” refer to multiple objects unless otherwise explicitly indicated by the context. Furthermore, in this specification and throughout the appended claims, the meaning of “in” includes both “in” and “on.”
[0073] As described herein, specific embodiments have been described herein, but a range of modifications, changes, and substitutions are intended in the above disclosure, and it will be understood that in some cases, some features of a particular embodiment may be used without corresponding use of other features, without departing from the scope and spirit described above. Therefore, many modifications may be made to adapt the essential scope and spirit to a particular situation or material.
Claims
1. A device for preparing memory for a group of servers, The root of trust processor assigned the task of preparing and deploying memory, A switch that can be operated to be controlled by the root of trust processor to allow a first client device of a first user to access a first memory portion via the server processor of the server group, and to restrict the first client device from accessing the second memory portion while the second memory portion is being prepared, The root of trust processor is configured to prepare the second memory portion by installing data specific to the environment or task of the second user's second client device into the second memory portion while the second memory portion is separated from the server processor. The aforementioned root of trust processor further, To eliminate access to the first memory portion of the first client device, and To provide access to the second memory portion of the second client device via the server processor, A device configured to trigger the aforementioned switch.
2. The apparatus according to claim 1, wherein the root of trust processor further prepares the second memory portion by erasing previous data from a previous user of the second memory portion.
3. The apparatus according to claim 2, wherein erasing the aforementioned previous data includes restoring the second memory portion to its original factory state.
4. The apparatus according to claim 2, wherein installing the data includes the root of trust processor booting a new software image onto the second memory portion after erasing the previous data from the previous user.
5. The apparatus according to any one of claims 1 to 4, wherein installing the data further includes the root of trust processor verifying the installed data for the second client device.
6. The apparatus according to any one of claims 1 to 4, wherein the first memory portion and the second memory portion are of the same type.
7. The apparatus according to any one of claims 1 to 4, wherein the switch includes a crossbar switch having a plurality of input lines and a plurality of output lines.
8. A method for providing memory for reuse using a group of servers, wherein the method is To provide a root of trust processor to which the tasks of memory preparation and deployment are assigned, The root of trust processor triggers a switch to allow the first client device of the first user to access the first memory portion via the server processor of the server group, and to restrict the first client device from accessing the second memory portion while the second memory portion is being prepared. The root of trust processor installs data specific to the environment or task of the second user's second client device into the second memory portion while the second memory portion is separated from the server processor, The switch eliminates access to the first memory portion of the first client device, A method comprising the switch providing access to the second memory portion of the second client device via the server processor.
9. The method according to claim 8, wherein the root of trust processor further prepares the second memory portion by erasing previous data from the previous user of the second memory portion.
10. The method according to claim 9, wherein erasing the aforementioned previous data includes restoring the second memory portion to its original factory state.
11. The method according to claim 9, wherein installing the data includes the root of trust processor booting a new software image onto the second memory portion after erasing the previous data from the previous user.
12. The method according to any one of claims 8 to 11, further comprising the root of trust processor verifying the installed data for the second client device.
13. The method according to any one of claims 8 to 11, wherein the first memory portion and the second memory portion are of the same type.
14. The method according to any one of claims 8 to 11, wherein the switch includes a crossbar switch having a plurality of input lines and a plurality of output lines.
15. A cloud computing system having a group of servers and a memory recovery system for recycling memory, wherein the cloud computing system is A service processor that is accessible to the first client device of the first tenant user during the first usage period, and accessible to the second client device of the second tenant user during the second usage period, During the first usage period, the first memory portion accessible by the first client device of the first tenant user, It comprises a recovery backend, and the recovery backend is The root of trust processor assigned the task of preparing and deploying memory, A switch that can be operated to be controlled by the root of trust processor to allow a first client device of a first user to access a first memory portion via the server processor of the server group, and to restrict the first client device from accessing the second memory portion while the second memory portion is being prepared. The root of trust processor is configured to install data specific to the environment or task of the second user's second client device into the second memory portion while the second memory portion is separated from the server processor. The aforementioned root of trust processor further, To eliminate access to the first memory portion of the first client device, and To provide access to the second memory portion of the second client device via the server processor, A cloud computing system configured to trigger the aforementioned switch.
16. The cloud computing system according to claim 15, wherein the root of trust processor further prepares the second memory portion by erasing previous data from a previous user of the second memory portion.
17. The cloud computing system according to claim 16, wherein erasing the aforementioned previous data includes restoring the second memory portion to its original factory state.
18. The cloud computing system according to claim 16, wherein installing the data includes the root of trust processor booting a new software image onto the second memory portion after erasing the previous data from the previous user.
19. The cloud computing system according to claim 16, wherein installing the data further includes the root of trust processor verifying the installed data for the second client device.
20. The cloud computing system according to any one of claims 15 to 19, wherein the switch includes a crossbar switch having a plurality of input lines and a plurality of output lines.
Citation Information
Patent Citations
Memory device
JP2003256266A
Standby system computer, cluster system, service providing method, and program
JP2012168623A
Stack isolation by a storage network switch
US20150120779A1