Access method for shared memory and related apparatus

By dividing shared memory into memory segments with different permissions and assigning corresponding permissions to processes, the problem of insufficient data security in shared memory is solved, and efficient and reliable communication between processes is achieved.

WO2025103005A1PCT designated stage expired Publication Date: 2025-05-22HUAWEI TECH CO LTD

Patent Information

Application Number
PCT/CN2024/122600
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-14
Filing Date
2024-09-30
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

In the business scenario of shared memory, the existing technology is difficult to effectively ensure the security of data, resulting in unintentional or malicious data modifications between business processes, which leads to process operation errors or crashes.

Method used

By dividing shared memory into multiple memory segments with different permissions and giving different permissions to different processes, processes with high permissions can normally access high or low permissions memory segments, while low permission processes need to undergo security detection when accessing high permissions memory segments.

Benefits of technology

This method effectively guarantees the security of data in shared memory, improves the reliability of process operation, and improves the communication efficiency between processes by reducing unnecessary security detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024122600_22052025_PF_FP_ABST
    Figure CN2024122600_22052025_PF_FP_ABST
Patent Text Reader

Abstract

An access method for a shared memory, for use in achieving the access of a shared memory in an electronic device. In the method, the shared memory is divided into a plurality of memory segments corresponding to different permissions, and different permissions are given to different processes, such that processes having high permissions can normally access the memory segments corresponding to the high permissions or low permissions, and processes having the low permissions need to be subjected to security detection when accessing the memory segments corresponding to the high permissions, thereby ensuring the security of data in the shared memory, and improving the reliability of process operation. In addition, the processes having the high permissions do not need to be subjected to security detection when accessing the memory segments having the low permissions, and the process having the low permissions need to be subjected to security detection only when accessing the memory segments having the high permissions, thereby greatly reducing the security detection needed to be executed by the processes during cross-permission memory access, and improving the communication efficiency between the processes.
Need to check novelty before this filing date? Find Prior Art

Description

A shared memory access method and related device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 14, 2023, with application number 202311519242.7 and application name “A method for accessing a shared memory and related devices”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of computer technology, and in particular to a method for accessing a shared memory and related devices. Background Art

[0003] Shared memory, as the most efficient inter-process communication method, is widely used in complex business scenarios within the information and communications technology (ICT) field, such as databases and enterprise resource planning (ERP). For multiple processes sharing the same shared memory, data written by any one process can be quickly accessed by the other processes, enabling efficient inter-process communication.

[0004] Generally, to facilitate management and improve efficiency, the shared memory management component usually pre-applies to the operating system for a larger block of shared memory, and then performs secondary management and allocation, thereby reducing the performance impact caused by the business process falling into kernel state when frequently requesting and releasing shared memory.

[0005] However, applying for shared memory uniformly for different business processes brings certain security risks. That is, since the entire shared memory is accessible to all business processes, data can be easily modified unintentionally or maliciously between business processes, causing business processes to run incorrectly or even crash.

[0006] Summary of the Invention

[0007] This application provides a shared memory access method that can ensure the security of data in the shared memory and improve the reliability of process operation.

[0008] In a first aspect, the present application provides a method for accessing a shared memory, which is applied to implement access to a shared memory in an electronic device. The method comprises: first, when a first process and a second process access the shared memory, obtaining a first access request from the first process and a second access request from the second process, wherein the first access request is used to request access to a first address in the shared memory, and the second access request is used to request access to a second address in the shared memory. The shared memory requested to be accessed by the first process and the second process includes a plurality of memory segments, and the plurality of memory segments respectively correspond to different access permissions. For example, the plurality of memory segments include a first memory segment and a second memory segment, the access permission corresponding to the first memory segment is low permission, and the access permission corresponding to the second memory segment is high permission.

[0009] Then, in response to the first process's access rights being no less than the access rights corresponding to the memory segment to which the first address belongs, the first access request is executed. Specifically, the processes running in the electronic device that are capable of accessing the shared memory are also configured with corresponding access rights to indicate the memory segments in the shared memory that the processes can normally access. Since the access rights configured for the first process (i.e., the first process's access rights) are no less than the access rights corresponding to the memory segment to which the first address to which the first process is requesting access belongs, it can be confirmed that the first process can normally access the first address in the shared memory, thereby executing the first access request.

[0010] Moreover, in response to the fact that the access rights of the second process are lower than the access rights corresponding to the memory segment to which the second address belongs, it can be determined that the second process does not have the normal permission to access the second address, and then a security check is performed on the second access request to trigger the execution of the second access request when the second access request passes the security check.

[0011] In this solution, by dividing shared memory into multiple memory segments corresponding to different permissions and assigning different permissions to different processes, processes with high permissions can normally access memory segments corresponding to high or low permissions, while processes with low permissions are required to undergo security checks when accessing memory segments corresponding to high permissions. This ensures the security of data in shared memory and improves the reliability of process operation. In addition, since high-privileged processes do not need to undergo security checks when accessing low-privileged memory segments, security checks are only required when low-privileged processes access high-privileged memory segments. This significantly reduces the number of security checks required for processes to access memory across permissions, improving the efficiency of communication between processes.

[0012] In one possible implementation, the access rights of the first process are the same as the access rights corresponding to the memory segment to which the second address belongs. For example, both the access rights of the first process and the access rights corresponding to the memory segment to which the second address belongs are high privileged. The access rights of the second process are the same as the access rights corresponding to the memory segment to which the first address belongs. For example, both the access rights of the second process and the access rights corresponding to the memory segment to which the first address belongs are low privileged. Furthermore, the access rights of the first process are higher than the access rights of the second process.

[0013] That is to say, the memory segments to which the first process and the second address belong both correspond to high permissions, while the memory segments to which the second process and the first address belong correspond to low permissions. In this way, when the first process with high permissions accesses the first address corresponding to low permissions, even if the permissions corresponding to the first address are not the same as the permissions of the first process, the first process can access the first address normally without performing security checks, thereby reducing the number of security checks performed when the process accesses the shared memory across permissions and improving the efficiency of inter-process communication. When the second process with low permissions accesses the second address corresponding to the high permissions, it is necessary to perform security checks on the access request of the second process to avoid illegal tampering with the shared memory, ensure the security of the data in the shared memory, and improve the reliability of process operation.

[0014] In one possible implementation, the method further includes: obtaining a third access request from the second process, the third access request being used to request a first address in the shared memory; and executing the third access request in response to the access rights of the second process being not less than the access rights corresponding to the memory segment to which the first address belongs.

[0015] In one possible implementation, after obtaining any one of the first access request and the second access request, a mapping relationship is obtained, which is used to indicate the correspondence between the process and the memory segment in the shared memory. The target memory segment corresponding to the target process includes one or more memory segments whose corresponding access rights are not higher than the access rights of the target process, and the target process is any process recorded in the mapping relationship. In other words, the mapping relationship indicates the correspondence between the various processes created in the electronic device and the memory segments, and the memory segment corresponding to each process is the memory segment that the process can access normally. For any process, if the mapping relationship indicates that there is a correspondence between the process and a certain memory segment, it means that the access rights of the process are not lower than the access rights corresponding to the memory segment, so the process can access the memory segment normally without undergoing security detection.

[0016] After obtaining the mapping relationship, it can be determined based on the mapping relationship that the access rights of the first process are not lower than the access rights corresponding to the memory segment to which the first address belongs, and that the access rights of the second process are lower than the access rights corresponding to the memory segment to which the second address belongs.

[0017] In this solution, by using a mapping relationship to indicate the correspondence between the process and the memory segment, the access rights of the process and the corresponding access rights of the memory segment can be quickly obtained by querying the mapping relationship, thereby determining whether it is necessary to perform security checks on the access requests of the process, thereby improving the processing efficiency of the access requests of the process.

[0018] In one possible implementation, the mapping between the target process and the target memory segment is generated when the target process is created. That is, during the operation of the electronic device, each time the electronic device creates a process that requires shared memory, a mapping between the process and the memory segment is generated. This allows the electronic device to quickly determine the memory segments in the shared memory that each process can normally access.

[0019] In one possible implementation, since the memory address targeted by the process is usually a virtual address, the above-mentioned mapping relationship can be specifically used to record the correspondence between the process and the virtual address segment, and the recorded virtual address segment has a correspondence with the memory segment in the shared memory.

[0020] Since the address in the access request obtained from the process is a virtual address, this solution records the correspondence between the virtual address segment and the memory segment in the shared memory in the mapping relationship, and can quickly determine whether the process's access request needs to perform security checks based on the virtual address obtained in the access request, thereby improving the efficiency of determining whether the access request needs to perform security checks.

[0021] In a possible implementation, the mapping relationship is recorded in a page table, that is, the mapping relationship is stored in the memory as part of the page table. The page table is used to record the correspondence between the virtual address and the physical address in the shared memory.

[0022] Since it is necessary to query the page table to obtain the physical address corresponding to the virtual address in the access request during the execution of the access request, by recording the mapping relationship in the page table, two pieces of information can be obtained by querying the page table once, namely, the physical address corresponding to the virtual address and whether the process has the normal permission to access the physical address corresponding to the virtual address, thereby improving the efficiency of the process accessing shared memory.

[0023] In one possible implementation, a target function may be pre-configured in the operating system, and when a security check needs to be performed on the second access request, the target function may be called to perform a security check on the second access request. In this way, after the second access request passes the security check of the target function, the second process may switch to a security domain with higher access rights, thereby enabling access to the second address with higher access rights. The target function may be pre-written by the administrator and configured in the operating system, and may enable security checks to be performed on the access request based on various detection strategies, thereby achieving security checks at a finer granularity. For example, the target function may specifically determine whether the second access request is legal based on which threads or coroutines and other fine-grained components in the second process the second access request originates from, and the operations carried by the second access request (such as data read operations or data write operations) performed on the accessed second address.

[0024] In a possible implementation, if the second access request passes the security check, triggering execution of the second access request;

[0025] Alternatively, if the second access request fails the security check, the second access request is denied.

[0026] A second aspect of the present application provides a shared memory access device, including: an acquisition module, used to obtain a first access request from a first process and a second access request from a second process, the first access request is used to request access to a first address in the shared memory, and the second access request is used to request access to a second address in the shared memory, the shared memory includes multiple memory segments, and the multiple memory segments correspond to different access rights; a processing module, used to execute the first access request in response to the access right of the first process being not less than the access right corresponding to the memory segment to which the first address belongs; the processing module is also used to perform a security check on the second access request in response to the access right of the second process being less than the access right corresponding to the memory segment to which the second address belongs, so as to trigger the execution of the second access request when the second access request passes the security check.

[0027] In one possible implementation, the access rights of the first process are the same as the access rights corresponding to the memory segment to which the second address belongs, the access rights of the second process are the same as the access rights corresponding to the memory segment to which the first address belongs, and the access rights of the first process are higher than the access rights of the second process.

[0028] In one possible implementation, the acquisition module is further used to obtain a third access request from the second process, where the third access request is used to request the first address in the shared memory; the processing module is further used to execute the third access request in response to the access rights of the second process being no less than the access rights corresponding to the memory segment to which the first address belongs.

[0029] In one possible implementation, the acquisition module is further used to obtain a mapping relationship, which is used to indicate the correspondence between the process and the memory segment in the shared memory, wherein the target memory segment corresponding to the target process includes one or more memory segments whose corresponding access rights are not higher than the access rights of the target process, and the target process is any process recorded in the mapping relationship; the processing module is further used to determine, based on the mapping relationship, that the access rights of the first process are not lower than the access rights corresponding to the memory segment to which the first address belongs, and that the access rights of the second process are lower than the access rights corresponding to the memory segment to which the second address belongs.

[0030] In a possible implementation, in the mapping relationship, the correspondence between the target process and the target memory segment is generated when the target process is created.

[0031] In a possible implementation, the mapping relationship is specifically used to record the correspondence between the process and the virtual address segment, and the virtual address segment has a correspondence with the memory segment in the shared memory.

[0032] In a possible implementation, the mapping relationship is recorded in a page table, which is used to record the correspondence between the virtual address and the physical address in the shared memory.

[0033] In a possible implementation, the processing module is further configured to call a target function to perform a security check on the second access request, where the target function is a preset function.

[0034] In a possible implementation, the processing module is further configured to: trigger execution of the second access request if the second access request passes the security check; or refuse execution of the second access request if the second access request fails the security check.

[0035] A third aspect of the present application provides a shared memory access device, which may include a processor coupled to a memory, wherein the memory stores program instructions. When the program instructions stored in the memory are executed by the processor, the method of the first aspect or any implementation of the first aspect is implemented. For details of the steps in each possible implementation of the first aspect performed by the processor, please refer to the first aspect and will not be repeated here.

[0036] In a fourth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer-readable storage medium is run on a computer, the computer executes the method of any implementation of the first aspect.

[0037] A fifth aspect of the present application provides a circuit system, the circuit system including a processing circuit, and the processing circuit is configured to execute a method of any implementation manner of the above-mentioned first aspect.

[0038] The sixth aspect of the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the method of any implementation manner of the first aspect.

[0039] The seventh aspect of the present application provides a chip system, which includes a processor for supporting a server or a feature screening device to implement the functions involved in any implementation of the first aspect, for example, processing the data and / or information involved in the above method. In one possible design, the chip system also includes a memory for storing program instructions and data necessary for the server or feature screening device. The chip system can be composed of a chip, or it can include a chip and other discrete devices.

[0040] The beneficial effects of the second to seventh aspects mentioned above can be referred to the introduction of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] FIG1 is a schematic diagram of an isolation domain switching provided by an embodiment of the present application;

[0042] FIG2 is a schematic structural diagram of an electronic device 101 provided in an embodiment of the present application;

[0043] FIG3 is a method for accessing a shared memory provided in an embodiment of the present application;

[0044] FIG4 is a schematic diagram of different processes accessing shared memory according to an embodiment of the present application;

[0045] FIG5 is a schematic diagram of configuring access permissions for different memory segments in a shared memory in a scenario provided by an embodiment of the present application;

[0046] FIG6 is a schematic diagram of configuring access permissions for different memory segments in a shared memory in another scenario provided by an embodiment of the present application;

[0047] FIG7 is a schematic diagram of a memory segment in a shared memory provided in an embodiment of the present application;

[0048] FIG8 is a schematic diagram of establishing a correspondence between a process and a virtual address segment according to an embodiment of the present application;

[0049] FIG9 is a schematic structural diagram of a shared memory access device provided in an embodiment of the present application;

[0050] FIG10 is a schematic structural diagram of an electronic device provided in an embodiment of the present application;

[0051] FIG11 is a schematic diagram of the structure of a computer-readable storage medium provided in an embodiment of the present application. DETAILED DESCRIPTION

[0052] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments.

[0053] The terms "first," "second," "third," "fourth," and so on (if any) in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that shown or described herein.

[0054] In addition, the terms "comprises" and "having" and any variations thereof are intended to cover a non-exclusive inclusion. For example, a process, method, system, product or apparatus that includes a series of steps or elements is not necessarily limited to those steps or elements expressly listed but may include other steps or elements not expressly listed or inherent to such process, method, product or apparatus.

[0055] To facilitate understanding, some technical terms involved in the embodiments of this application are first introduced below.

[0056] (1) Shared memory

[0057] Shared memory refers to a large amount of memory accessible by different central processing units (CPUs) in a multiprocessor computer system. It is typically used for communication between multiple processes and is the fastest way to achieve inter-process communication. Specifically, when one process writes data to shared memory, the data is immediately visible to other processes sharing the shared memory.

[0058] (2) Process

[0059] A process is a computer program's execution of a specific set of data. It is the basic unit of system resource allocation and the foundation of operating system architecture. In early process-oriented computer architectures, processes were the basic execution entity of programs; in modern thread-oriented computer architectures, processes are containers for threads. A program is a description of instructions, data, and their organization, while a process is the entity of the program.

[0060] (3)Threads

[0061] A thread is the smallest unit of computation that an operating system can schedule. It is contained within a process and is the actual unit of operation within that process. A thread is a single, sequential flow of control within a process. A process can have multiple threads running concurrently, each executing different tasks in parallel.

[0062] (4) Subroutines

[0063] In computer science, a subroutine, also known as a subprogram, is a section of code within a larger program, consisting of one or more blocks of statements. A subroutine is responsible for completing a specific task and operates independently from the rest of the code.

[0064] (5) Coroutine

[0065] Coroutines are similar to subroutines in that they are also program components. Compared to subroutines, coroutines are more general and flexible, but they are not as widely used in practice.

[0066] (6) Register

[0067] Registers are high-speed memory components within the CPU with limited storage capacity. Simply put, registers are small storage areas within the CPU used to temporarily store data involved in calculations and their results. Compared to computer memory, registers have much higher read and write speeds, allowing data to be transferred between registers very quickly.

[0068] (7) Virtual address (VA)

[0069] A virtual address is the address of a storage unit in a computer architecture as seen by an application. Virtual addresses are often different from the physical addresses of storage units and require an address translator to convert virtual addresses into physical addresses (PA).

[0070] Simply put, a virtual address is usually an address generated by the CPU in a computer when an application is running; a physical address is a real address in physical memory.

[0071] (8) Page Table

[0072] A page table is a special data structure used to record the mapping relationship between virtual addresses and physical addresses. Generally, in a computer, the memory management unit (MMU) can convert between virtual addresses and physical addresses by querying the page table.

[0073] (9) Application Programming Interface (API)

[0074] An API is essentially a set of predefined functions (i.e., a collection of functions) that allows applications and developers to access a set of routines based on a piece of software or hardware without having to access the source code or understand the details of the internal workings.

[0075] In related technologies, the method of uniformly applying for shared memory for different business processes brings certain security risks. That is, since the entire shared memory is accessible to all business processes, it is easy for unintentional or malicious data modifications to occur between business processes, causing business processes to run incorrectly or even crash.

[0076] To achieve inter-process isolation, one possible approach is to partition a block of shared memory into multiple isolation domains, with each domain corresponding to a different process. A process can normally access data in its own isolation domain; however, when accessing data in other isolation domains, the process must pass specific security checks before accessing the data.

[0077] For example, please refer to Figure 1, which is a schematic diagram of an isolation domain switching provided by an embodiment of the present application. As shown in Figure 1, it is assumed that the shared memory is divided into isolation domain 1, isolation domain 2 and isolation domain 3, and each isolation domain has a corresponding process. In this way, when the process corresponding to any isolation domain needs to access data in other isolation domains, isolation domain switching is required, that is, security detection is performed on the behavior of the process accessing other isolation domains, thereby generating a higher isolation domain switching cost and reducing the communication efficiency between processes. Specifically, when the process corresponding to isolation domain 1 accesses data in isolation domain 3, a switch from isolation domain 1 to isolation domain 3 will occur, that is, all access requests issued by the process corresponding to isolation domain 1 to isolation domain 3 need to undergo security detection; similarly, when the process corresponding to isolation domain 3 accesses data in isolation domain 1, a switch from isolation domain 3 to isolation domain 1 will occur, that is, all access requests issued by the process corresponding to isolation domain 3 to isolation domain 1 also need to undergo security detection.

[0078] Based on this, the present application provides a method for accessing shared memory. By dividing the shared memory into multiple memory segments corresponding to different permissions and assigning different permissions to different processes, a process with high permissions can normally access the memory segments corresponding to high permissions or low permissions, while a process with low permissions needs to undergo security checks when accessing the memory segments corresponding to high permissions, thereby ensuring the security of the data in the shared memory and improving the reliability of process operation. In addition, since a process with high permissions does not need to undergo security checks when accessing a memory segment with low permissions, a security check is only required when a process with low permissions accesses a memory segment with high permissions. This greatly reduces the security checks that need to be performed when a process accesses memory across permissions, thereby improving the efficiency of communication between processes.

[0079] For ease of understanding, the following describes a device to which the shared memory access method provided in an embodiment of the present application is applied.

[0080] Please refer to Figure 2, which is a schematic diagram of the structure of an electronic device 101 provided in an embodiment of the present application. As shown in Figure 2, the electronic device 101 to which the shared memory access method provided in an embodiment of the present application is applied includes a processor 103, which is coupled to a system bus 105. The processor 103 can be one or more processors, each of which can include one or more processor cores. A display adapter (video adapter) 107 can drive a display 109, which is coupled to the system bus 105. The system bus 105 is coupled to an input / output (I / O) bus via a bus bridge 111. An I / O interface 115 is coupled to the I / O bus. The I / O interface 115 communicates with various I / O devices, such as an input device 117 (e.g., a touch screen), an external memory 121 (e.g., a hard disk, floppy disk, optical disk, or USB flash drive), a multimedia interface, etc., a transceiver 123 (capable of sending and / or receiving radio communication signals), a camera 155 (capable of capturing still and dynamic digital video images), and an external USB port 125. Optionally, the interface connected to the I / O interface 115 may be a USB interface.

[0081] The processor 103 may be any conventional processor, including a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, or a combination thereof. Alternatively, the processor may be a dedicated device such as an ASIC.

[0082] Electronic device 101 can communicate with software deployment server 149 via network interface 129. Exemplarily, network interface 129 is a hardware network interface, such as a network card. Network 127 can be an external network, such as the Internet, or an internal network, such as Ethernet or a virtual private network (VPN). Alternatively, network 127 can be a wireless network, such as a WiFi network or a cellular network.

[0083] The hard drive interface 131 is coupled to the system bus 105. The hard drive interface is connected to the hard drive 133. The internal memory 135 is coupled to the system bus 105. The data running in the internal memory 135 may include the operating system (OS) 137 of the electronic device 101, the application 143, and the scheduler.

[0084] The operating system consists of a shell 139 and a kernel 141. Shell 139 is an interface between the user and the operating system's kernel. The shell is the outermost layer of the operating system. The shell manages the interaction between the user and the operating system: it waits for user input, interprets user input to the operating system, and processes various operating system output.

[0085] The kernel 141 consists of the parts of the operating system that manage memory, files, peripherals, and system resources. The kernel 141 directly interacts with the hardware. The operating system kernel typically runs processes and provides inter-process communication, CPU time slice management, interrupts, memory management, and I / O management.

[0086] For example, please refer to Figure 3, which illustrates a method for accessing shared memory provided in an embodiment of the present application. As shown in Figure 3, the method for accessing shared memory provided in this embodiment includes the following steps 301-303. Furthermore, the method for accessing shared memory provided in this embodiment can be applied to an electronic device including shared memory, specifically, to an operating system of the electronic device or a software component within the operating system.

[0087] Step 301, obtain a first access request from a first process and a second access request from a second process, the first access request is used to request access to a first address in a shared memory, and the second access request is used to request access to a second address in the shared memory, the shared memory includes multiple memory segments, and the multiple memory segments correspond to different access permissions.

[0088] In this embodiment, when a process needs to access data in shared memory, it generates a corresponding access request to access the data in the shared memory. Specifically, after a first process generates a first access request and a second process generates a second access request, an operating system in the electronic device can obtain the first access request and the second access request. The operating system may obtain the first access request first and then the second access request; or the operating system may obtain the second access request first and then the first access request. This embodiment does not limit the order in which the first access request and the second access request are obtained.

[0089] For the first access request and the second access request, the first access request and the second access request are both used to request access to an address in the shared memory, and the addresses requested to be accessed by the first access request and the second access request are different, that is, the first address and the second address are different. In addition, the shared memory is pre-divided into multiple memory segments (for example, two or more memory segments), each of the multiple memory segments corresponds to a unique access permission, and different memory segments in the multiple memory segments correspond to different access permissions. For example, the multiple memory segments include a first memory segment and a second memory segment, the access permission corresponding to the first memory segment is low permission, and the access permission corresponding to the second memory segment is high permission.

[0090] It should be noted that for any of the multiple memory segments, the memory segment can be composed of one or more consecutive memory addresses. If a memory segment consists of one consecutive memory address, the memory addresses included in the memory segment are continuous. If a memory segment consists of multiple consecutive memory addresses, the multiple memory addresses are separated, that is, the memory addresses included in the memory segment are not completely continuous.

[0091] Step 302 : In response to the access rights of the first process being no less than the access rights corresponding to the memory segment to which the first address belongs, executing the first access request.

[0092] In this embodiment, processes running on the electronic device that are able to access the shared memory are also configured with corresponding access permissions to indicate the memory segments in the shared memory that the processes can normally access. Specifically, in this embodiment, the access permissions configured for the first process (i.e., the access permissions of the first process) are not lower than the access permissions corresponding to the memory segment to which the first address requested by the first process belongs. Therefore, it can be confirmed that the first process can normally access the first address in the shared memory, thereby executing the first access request.

[0093] For example, the first process has a high access permission, while the memory segment to which the first address belongs has a low access permission. Since the first process has a higher access permission than the memory segment to which the first address belongs, the first process has normal access permission to the first address and can therefore execute the first access request.

[0094] The first access request may also carry an operation to be performed on the accessed first address, such as a data read operation or a data write operation. In the process of executing the first access request, the data in the first address may be read or new data may be written to the first address according to the instruction of the first access request.

[0095] Step 303 : In response to the access rights of the second process being lower than the access rights corresponding to the memory segment to which the second address belongs, a security check is performed on the second access request, so as to trigger execution of the second access request when the second access request passes the security check.

[0096] In this embodiment, the access rights configured for the second process are lower than the access rights corresponding to the memory segment to which the second address to which the second process is requesting access belongs. Therefore, it can be determined that the second process does not have normal access rights to the second address, thereby triggering a security check on the second access request. Thus, the second access request is only executed if it passes the security check. If it fails the security check, the second access request is rejected.

[0097] That is, when a process with high privileges requests an address in a memory segment with the same or lower privileges, the process can access the address in the memory segment normally. When a process with low privileges requests an address in a memory segment with high privileges, the process cannot access the address in the memory segment normally. Instead, it needs to undergo security checks to confirm whether the process's access behavior is safe before it can determine whether the process's access behavior is allowed.

[0098] In this solution, by dividing shared memory into multiple memory segments corresponding to different permissions and assigning different permissions to different processes, processes with high permissions can normally access memory segments corresponding to high or low permissions, while processes with low permissions are required to undergo security checks when accessing memory segments corresponding to high permissions. This ensures the security of data in shared memory and improves the reliability of process operation. In addition, since high-privileged processes do not need to undergo security checks when accessing low-privileged memory segments, security checks are only required when low-privileged processes access high-privileged memory segments. This significantly reduces the number of security checks required for processes to access memory across permissions, improving the efficiency of communication between processes.

[0099] The security check performed on the second access request may specifically be based on a pre-configured detection policy to detect the legitimacy of the second access request to confirm whether executing the second access request will have a negative impact on the shared memory. For example, the process of detecting the second access request based on the pre-configured detection policy may specifically be based on the source of the second access request (such as which threads or coroutines in the second process the second access request originates from) and the operation carried by the second access request to be performed on the accessed second address (such as a data read operation or a data write operation), to determine whether the second access request is legitimate.

[0100] In one possible implementation, a target function may be pre-configured in the operating system, and when a security check needs to be performed on the second access request, the security check can be performed on the second access request by calling the target function. In this way, after the second access request passes the security check of the target function, the second process can switch to a security domain with higher access rights, thereby being able to access the second address with higher access rights. There are many ways to implement the target function. For example, the target function may be an application programming interface (API) pre-configured in the operating system. Furthermore, the implementation logic of the target function (i.e., the detection strategy included in the target function) may be determined according to the actual business scenario, and this embodiment does not specifically limit this.

[0101] In one possible example, the access rights of the first process are the same as the access rights corresponding to the memory segment to which the second address belongs. For example, both the access rights of the first process and the access rights corresponding to the memory segment to which the second address belongs are high privileged. The access rights of the second process are the same as the access rights corresponding to the memory segment to which the first address belongs. For example, both the access rights of the second process and the access rights corresponding to the memory segment to which the first address belongs are low privileged. Furthermore, the access rights of the first process are higher than the access rights of the second process.

[0102] In simple terms, the memory segments to which the first process and the second address belong both correspond to high permissions, while the memory segments to which the second process and the first address belong correspond to low permissions. In this way, when a first process with high permissions accesses a first address corresponding to a low permission, even if the permission corresponding to the first address is not the same as the permission of the first process, the first process can still access the first address normally without performing security checks, thereby reducing the number of security checks performed when a process accesses shared memory across permissions and improving the efficiency of inter-process communication. When a second process with low permissions accesses a second address corresponding to a high permission, it is necessary to perform a security check on the access request of the second process to avoid illegal tampering with the shared memory, ensure the security of the data in the shared memory, and improve the reliability of process operation.

[0103] In addition, when the access permission corresponding to the memory segment accessed by the second process is lower than or equal to the access permission of the second process, the second process can achieve normal access to the memory segment without the need to perform security checks.

[0104] For example, in the above method, the operating system may also receive a third access request from the second process, the third access request being for the first address in the shared memory. Since the access rights of the second process are equal to the access rights corresponding to the memory segment to which the first address belongs, the third access request may be executed in response to the second process's access rights being no less than the access rights corresponding to the memory segment to which the first address belongs.

[0105] For example, please refer to Figure 4, which is a schematic diagram illustrating different processes accessing shared memory according to an embodiment of the present application. As shown in Figure 4, the shared memory includes a first memory segment and a second memory segment. The access permission corresponding to the first memory segment is low-privileged, while the access permission corresponding to the second memory segment is high-privileged. Furthermore, the access permission of the first process is high-privileged, while the access permission of the second process is low-privileged.

[0106] Then, when the first process accesses the shared memory, since the access rights of the first process are higher than the access rights corresponding to the first memory segment, and the access rights of the first process are equal to the access rights corresponding to the second memory segment, the first process can normally access the addresses in the first memory segment and the second memory segment.

[0107] When the second process accesses the shared memory, because the second process's access rights are equal to the access rights corresponding to the first memory segment, the second process can normally access addresses in the first memory segment. Furthermore, because the second process's access rights are lower than the access rights corresponding to the second memory segment, when the second process requests access to addresses in the second memory segment, it must first undergo a security check and can only access addresses in the second memory segment if it passes the security check.

[0108] The above describes how to implement process access to shared memory in the shared memory access method provided by this embodiment. To facilitate understanding, the following describes how to implement configuration of access rights to memory segments in shared memory in conjunction with specific scenarios.

[0109] In a possible example, please refer to Figure 5, which is a schematic diagram of configuring access permissions for different memory segments in a shared memory under a scenario provided by an embodiment of the present application. As shown in Figure 5, in scenario 1, during the operation of the first process and the second process, the first process will frequently access addresses in the second memory segment, and occasionally access addresses in the first memory segment. For example, during the process of the first process accessing the shared memory, the number of times the address in the second memory segment is accessed accounts for 90% of the total number of times the shared memory is accessed, and the number of times the address in the first memory segment is accessed accounts for 10% of the total number of times the shared memory is accessed. The second process will frequently access addresses in the first memory segment, and occasionally access addresses in the second memory segment. For example, during the process of the second process accessing the shared memory, the number of times the address in the first memory segment is accessed accounts for 95% of the total number of times the shared memory is accessed, and the number of times the address in the second memory segment is accessed accounts for 5% of the total number of times the shared memory is accessed.

[0110] Furthermore, in scenario 1, the first process is a highly secure process, while the second process is a less secure process. That is, the first process is highly secure and is less likely to illegally tamper with shared memory, while the second process is less secure and may be more susceptible to shared memory tampering.

[0111] Therefore, in scenario 1, the access permission corresponding to the second memory segment frequently accessed by the high-security first process can be configured as high, and the access permission of the first process can be configured as high, thereby ensuring that the first process can normally access the addresses in the second memory segment without undergoing security checks. Furthermore, the access permission corresponding to the first memory segment frequently accessed by the low-security second process can be configured as low, and the access permission of the second process can be configured as low, thereby ensuring that the second process can normally access the addresses in the first memory segment.

[0112] Because the first process's access rights are higher than those of the first memory segment, the first process can access addresses in the first memory segment normally without undergoing security checks, thereby ensuring the efficiency of the first process, which has a higher security rating, when occasionally accessing the first memory segment. Because the second process's access rights are lower than those of the second memory segment, the second process must undergo security checks when accessing addresses in the second memory segment. Only after passing the security checks can it access the second memory segment, effectively ensuring the security of the data in the second memory segment.

[0113] In another possible example, please refer to Figure 6, which is a schematic diagram of configuring access permissions for different memory segments in a shared memory under another scenario provided by an embodiment of the present application. As shown in Figure 6, in scenario 2, during the operation of the first process and the second process, the first process will frequently access addresses in the first memory segment and addresses in the second memory segment. For example, during the process of the first process accessing the shared memory, the number of times the address in the second memory segment is accessed accounts for 45% of the total number of times the shared memory is accessed, and the number of times the address in the first memory segment is accessed accounts for 55% of the total number of times the shared memory is accessed. The second process will frequently access addresses in the first memory segment and occasionally access addresses in the second memory segment. For example, during the process of the second process accessing the shared memory, the number of times the address in the first memory segment is accessed accounts for 95% of the total number of times the shared memory is accessed, and the number of times the address in the second memory segment is accessed accounts for 5% of the total number of times the shared memory is accessed.

[0114] Therefore, in scenario 1, the access permission corresponding to the second memory segment frequently accessed by the first process can be configured as high, and the access permission of the first process can be configured as high, thereby ensuring that the first process can normally access the addresses in the second memory segment without undergoing security checks. In addition, the access permission corresponding to the first memory segment frequently accessed by both the first and second processes can be configured as low, and the access permission of the second process can be configured as low, thereby ensuring that the second process can normally access the addresses in the first memory segment.

[0115] Because the first process's access rights are higher than those of the first memory segment, the first process can access addresses in the first memory segment normally without undergoing security checks, thereby ensuring the efficiency of the first process when frequently accessing the first memory segment. Because the second process's access rights are lower than those of the second memory segment, the second process must undergo security checks when occasionally accessing addresses in the second memory segment. Only after passing the security checks can it access the second memory segment, effectively ensuring the security of the data in the second memory segment.

[0116] The above describes how to configure the access rights of memory segments in shared memory and the access rights of each process in some specific business scenarios. In actual applications, different configuration methods can be adopted according to the actual business scenarios, and this embodiment does not specifically limit this.

[0117] It should be noted that the above description of the shared memory access method provided by this embodiment uses the example of a shared memory including two memory segments (i.e., a first memory segment and a second memory segment). In actual applications, the shared memory may also be divided into three or more memory segments with different access permissions. This embodiment does not specifically limit the number of memory segments included in the shared memory. In addition, the number of processes configured with the same access permissions in the electronic device may also be one or more.

[0118] For example, please refer to Figure 7, which is a schematic diagram of a memory segment in a shared memory provided in an embodiment of the present application. As shown in Figure 7, the shared memory includes at least memory segment 1, memory segment 2, and memory segment 3. Moreover, the access permission corresponding to memory segment 1 is high permission, the access permission corresponding to memory segment 2 is medium permission, and the access permission corresponding to memory segment 3 is low permission. In addition, the shared memory may also include other memory segments with corresponding access permissions lower than that of memory segment 3, which will not be described in detail here. Moreover, in the scenario shown in Figure 7, the electronic device includes one or more processes with high permission (i.e., processes with high permission), and these processes with high permission can normally access all memory segments in the shared memory. The electronic device includes one or more processes with medium permission (i.e., processes with medium permission), and these processes with medium permission can normally access other memory segments in the shared memory except memory segment 1, i.e., processes with medium permission only need to perform security checks when accessing memory segment 1. The electronic device also includes one or more processes with low-privilege access rights (i.e., processes with low privileges). These processes with low privileges can normally access other memory segments in the shared memory except memory segment 1 and memory segment 2, that is, processes with low privileges need to perform security checks when accessing memory segment 1 and memory segment 2.

[0119] In the above embodiment, a process is described for determining whether a security check is required for an access request issued by a process based on the access permissions of the process and the access permissions corresponding to the memory segments accessed by the process. To facilitate understanding, the following describes how to implement the determination of the access permissions of a process and the access permissions corresponding to the memory segments accessed by the process.

[0120] In the embodiment shown in FIG. 3 , after receiving either the first access request or the second access request, a mapping relationship can be obtained. The mapping relationship indicates the correspondence between processes and memory segments in the shared memory. Taking the target process in the mapping relationship as an example, the target process is any process recorded in the mapping relationship, and the target memory segment corresponding to the target process includes one or more memory segments whose corresponding access rights are no higher than the access rights of the target process. In other words, the mapping relationship indicates the correspondence between various processes created in the electronic device and memory segments, and the memory segment corresponding to each process is the memory segment that the process can normally access. For any process, if the mapping relationship indicates a correspondence between the process and a memory segment, it means that the process's access rights are no lower than the access rights corresponding to the memory segment, and therefore the process can normally access the memory segment without undergoing security checks. Conversely, if the mapping relationship does not indicate a correspondence between the process and a memory segment, it means that the process's access rights are lower than the access rights corresponding to the memory segment, and therefore the process needs to undergo security checks before it can access the memory segment.

[0121] After obtaining the mapping relationship, it can be determined that the access rights of the first process are not lower than the access rights corresponding to the memory segment to which the first address belongs, based on the correspondence between the first process and the memory segment to which the first address belongs indicated in the mapping relationship; and based on the fact that the mapping relationship does not indicate the correspondence between the second process and the memory segment to which the second address belongs, it can be determined that the access rights of the second process are lower than the access rights corresponding to the memory segment to which the second address belongs.

[0122] Optionally, in the above-mentioned mapping relationship, the correspondence between the target process and the target memory segment is generated when the target process is created. That is to say, during the operation of the electronic device, each time the electronic device creates a process that needs to use shared memory, it will generate a correspondence between the process and the memory segment, so that it can quickly determine the memory segment in the shared memory that each process can normally access. For example, in the process of creating a process by the electronic device, the creation of the process can be achieved through a pre-configured interface. The interface can determine the memory segment that the process can normally access based on the type of process to be created, and then generate a correspondence between the process and the memory segment, and allocate unused memory to the process in the memory segment that can be normally accessed, thereby achieving the creation of the process.

[0123] Optionally, since the memory address targeted by the process is usually a virtual address, the above mapping relationship can be specifically used to record the correspondence between the process and the virtual address segment, and the recorded virtual address segment has a correspondence with the memory segment in the shared memory.

[0124] Specifically, the address operated by the process (for example, the address indicated by the process in the access request) is usually a virtual address, and the virtual address has a corresponding relationship with the physical address on the memory. When executing the access request initiated by the process, it is often necessary to convert the virtual address indicated in the access request into a physical address before the operation can be performed on the data at the corresponding address in the memory. Since the address in the access request obtained from the process is a virtual address, this embodiment records the correspondence between the virtual address segment and the memory segment in the shared memory in the mapping relationship, and can quickly determine whether the access request of the process needs to perform security detection based on the virtual address obtained in the access request, thereby improving the efficiency of determining whether the access request needs to perform security detection.

[0125] In this embodiment, the above-mentioned mapping relationship can be stored in a variety of ways.

[0126] Optionally, the above-mentioned mapping relationship can be recorded in a page table, that is, the mapping relationship is stored in the memory as part of the page table. The page table was originally used to record the correspondence between the virtual address and the physical address in the shared memory. In the case of recording the mapping relationship in the page table, the page table can be used to simultaneously record the correspondence between the virtual address and the physical address in the shared memory and the correspondence between the process and the virtual address segment. For example, in the page table, for any virtual address corresponding to the shared memory, the physical address and process corresponding to the virtual address can be recorded.

[0127] In this way, since it is necessary to query the page table to obtain the physical address corresponding to the virtual address in the access request during the execution of the access request, by recording the mapping relationship in the page table, two pieces of information can be obtained by querying the page table once, namely the physical address corresponding to the virtual address and whether the process has the normal permission to access the physical address corresponding to the virtual address, thereby improving the efficiency of the process accessing the shared memory. Specifically, after obtaining the virtual address in the access request, the process and physical address corresponding to the virtual address can be queried in the page table; if the process corresponding to the virtual address includes the process that generates the access request, it means that the current process has the normal permission to access the memory segment, and there is no need to perform a security check, and then the access request is executed based on the physical address corresponding to the virtual address; if the process corresponding to the virtual address does not include the process that generates the access request, it means that the current process does not have the normal permission to access the memory segment, and a security check needs to be performed. After the security check passes, the access request is executed based on the physical address corresponding to the virtual address.

[0128] Optionally, the above mapping relationship may also be stored in a specific location in the memory, so that components in the operating system can quickly confirm the access rights of the process and the memory segment by accessing the memory.

[0129] For example, please refer to Figure 8, which is a schematic diagram of establishing a correspondence between a process and a virtual address segment provided by an embodiment of the present application. As shown in Figure 8, the mmap_base in the mm_struct structure of the operating system kernel can control the base address of the virtual address allocation. Therefore, by controlling the base address of the allocated virtual address, multiple virtual address segments can be obtained, and each virtual address segment corresponds to a memory segment. For example, in Figure 8, three virtual address segments can be obtained. The virtual address range of the first virtual address segment is 0x0000 0000 0000 0000-0x0000 7FFF FFFF FFFF; the virtual address range of the second virtual address segment is 0x0000 7FFF FFFF FFFF-0x0000 FFFF FFFF FFFF; and the virtual address range of the third virtual address segment is 0x0000 FFFF FFFF FFFF-0x0007 FFFF FFFF FFFF. Furthermore, the physical addresses corresponding to the virtual addresses in the first virtual address segment in shared memory constitute memory segment 1, and the access rights corresponding to memory segment 1 are low permissions; the physical addresses corresponding to the virtual addresses in the second virtual address segment in shared memory constitute memory segment 2, and the access rights corresponding to memory segment 2 are medium permissions; the physical addresses corresponding to the virtual addresses in the third virtual address segment in shared memory constitute memory segment 3, and the access rights corresponding to memory segment 3 are high permissions. Therefore, after determining the memory segment corresponding to each virtual address segment and the access rights corresponding to each memory segment, the access rights corresponding to the virtual address segment can be determined, and then the correspondence between processes and virtual addresses can be established based on the access rights of each process.

[0130] Specifically, when the operating system kernel creates process 1, the operating system kernel determines that the access permission of process 1 is high permission, and can determine that process 1 can access memory segment 1-memory segment 3 corresponding to the 1st virtual address segment-3rd virtual address segment, and then records the correspondence between process 1 and the 1st virtual address segment-3rd virtual address segment in the mapping relationship, that is, process 1 corresponds to 0x0000 0000 0000 0000-0x0007 FFFF FFFF FFFF.

[0131] When the operating system kernel creates process 2, the operating system kernel determines that the access permission of process 2 is medium, and can determine that process 2 can access memory segment 1-memory segment 2 corresponding to the first virtual address segment and the second virtual address segment, and then records the correspondence between process 2 and the first virtual address segment-the second virtual address segment in the mapping relationship, that is, process 2 corresponds to 0x0000 0000 0000 0000-0x0000 FFFF FFFF FFFF.

[0132] When the operating system kernel creates process 3, the operating system kernel determines that the access permission of process 3 is low, and can determine that process 3 can access memory segment 1 corresponding to the first virtual address segment, and then records the correspondence between process 3 and the first virtual address segment in the mapping relationship, that is, process 3 corresponds to 0x0000 0000 0000 0000-0x0000 7FFF FFFF FFFF.

[0133] The above describes in detail the method provided by the embodiment of the present application. Next, the device provided by the embodiment of the present application for executing the above method will be introduced.

[0134] Please refer to Figure 9, which is a schematic diagram of the structure of a shared memory access device provided in an embodiment of the present application. As shown in Figure 9, the shared memory access device includes: an acquisition module 901, which is used to acquire a first access request from a first process and a second access request from a second process, the first access request being used to request access to a first address in the shared memory, and the second access request being used to request access to a second address in the shared memory, the shared memory including multiple memory segments, each of which corresponds to a different access permission; a processing module 902, which is used to execute the first access request in response to the access permission of the first process being not less than the access permission corresponding to the memory segment to which the first address belongs; the processing module 902 is also used to perform a security check on the second access request in response to the access permission of the second process being less than the access permission corresponding to the memory segment to which the second address belongs, so as to trigger the execution of the second access request when the second access request passes the security check.

[0135] In one possible implementation, the access rights of the first process are the same as the access rights corresponding to the memory segment to which the second address belongs, the access rights of the second process are the same as the access rights corresponding to the memory segment to which the first address belongs, and the access rights of the first process are higher than the access rights of the second process.

[0136] In one possible implementation, the acquisition module 901 is also used to obtain a third access request from the second process, where the third access request is used to request the first address in the shared memory; the processing module 902 is also used to execute the third access request in response to the access rights of the second process being no less than the access rights corresponding to the memory segment to which the first address belongs.

[0137] In one possible implementation, the acquisition module 901 is further used to obtain a mapping relationship, which is used to indicate the correspondence between the process and the memory segment in the shared memory, wherein the target memory segment corresponding to the target process includes one or more memory segments whose corresponding access rights are not higher than the access rights of the target process, and the target process is any process recorded in the mapping relationship; the processing module 902 is further used to determine, based on the mapping relationship, that the access rights of the first process are not lower than the access rights corresponding to the memory segment to which the first address belongs, and that the access rights of the second process are lower than the access rights corresponding to the memory segment to which the second address belongs.

[0138] In a possible implementation, in the mapping relationship, the correspondence between the target process and the target memory segment is generated when the target process is created.

[0139] In a possible implementation, the mapping relationship is specifically used to record the correspondence between the process and the virtual address segment, and the virtual address segment has a correspondence with the memory segment in the shared memory.

[0140] In a possible implementation, the mapping relationship is recorded in a page table, which is used to record the correspondence between the virtual address and the physical address in the shared memory.

[0141] In a possible implementation, the processing module 902 is further configured to call a target function to perform a security check on the second access request, where the target function is a preset function.

[0142] In a possible implementation, the processing module 902 is further configured to: trigger execution of the second access request if the second access request passes the security check; or refuse execution of the second access request if the second access request fails the security check.

[0143] Please refer to Figure 10, which is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. As shown in Figure 10, the electronic device 1000 can be specifically manifested as a mobile phone, a tablet, a laptop computer, an intelligent wearable device, a server, etc., which is not limited here. Specifically, the electronic device 1000 includes: a receiving module 1001, a sending module 1002, a processor 1003 and a memory 1004 (wherein the number of processors 1003 in the electronic device 1000 can be one or more, and Figure 10 takes one processor as an example), wherein the processor 1003 may include an application processor 10031 and a communication processor 10032. In some embodiments of the present application, the receiving module 1001, the sending module 1002, the processor 1003 and the memory 1004 may be connected via a bus or other means.

[0144] The memory 1004 may include a read-only memory and a random access memory, and provides instructions and data to the processor 1003. A portion of the memory 1004 may also include non-volatile random access memory (NVRAM). The memory 1004 stores processor and operation instructions, executable modules, or data structures, or subsets or extended sets thereof. The operation instructions may include various operation instructions for implementing various operations.

[0145] Processor 1003 controls the operation of the electronic device. In specific applications, the various components of the electronic device are coupled together via a bus system. In addition to a data bus, the bus system may also include a power bus, a control bus, and a status signal bus. However, for clarity, all bus systems are referred to as a bus system in the figure.

[0146] The method disclosed in the above embodiment of the present application can be applied to the processor 1003, or implemented by the processor 1003. The processor 1003 can be an integrated circuit chip with signal processing capabilities. During the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor 1003 or an instruction in the form of software. The above processor 1003 can be a general-purpose processor, a digital signal processor (DSP), a microprocessor or a microcontroller, and can further include an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, and discrete hardware components.

[0147] The processor 1003 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 1004, and the processor 1003 reads the information in the memory 1004 and completes the steps of the above method in combination with its hardware.

[0148] Receiving module 1001 can be used to receive input digital or character information and generate signal input related to the relevant settings and function control of the electronic device. Transmitting module 1002 can be used to output digital or character information through the first interface; transmitting module 1002 can also be used to send instructions to the disk group through the first interface to modify the data in the disk group; transmitting module 1002 can also include a display device such as a display screen.

[0149] The electronic device provided in the embodiments of the present application may specifically be a chip, and the chip includes: a processing unit and a communication unit. The processing unit may be, for example, a processor, and the communication unit may be, for example, an input / output interface, a pin, or a circuit. The processing unit may execute computer-executable instructions stored in the storage unit so that the chip in the execution device executes the method described in the above embodiment. Optionally, the storage unit is a storage unit in the chip, such as a register, a cache, etc. The storage unit may also be a storage unit located outside the chip in the wireless access device, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.

[0150] Please refer to Figure 11, which is a schematic diagram of the structure of a computer-readable storage medium provided in an embodiment of the present application. The present application also provides a computer-readable storage medium. In some embodiments, the method disclosed in Figure 3 above can be implemented as computer program instructions encoded in a machine-readable format on a computer-readable storage medium or on other non-transitory media or products.

[0151] 11 schematically illustrates a conceptual partial view of an example computer-readable storage medium including a computer program for executing a computer process on a computing device, arranged in accordance with at least some embodiments presented herein.

[0152] In one embodiment, computer readable storage medium 1100 is provided using signal bearing medium 1101. Signal bearing medium 1101 may include one or more program instructions 1102 that, when executed by one or more processors, may provide the functionality or portions of the functionality described above with respect to FIG.

[0153] In some examples, signal bearing medium 1101 may include computer readable medium 1103 such as, but not limited to, a hard drive, compact disk (CD), digital video disk (DVD), digital tape, memory, ROM or RAM, and the like.

[0154] In some embodiments, the signal-bearing medium 1101 may include a computer-recordable medium 1104, such as, but not limited to, a memory, a read / write (R / W) CD, a R / W DVD, or the like. In some embodiments, the signal-bearing medium 1101 may include a communication medium 1105, such as, but not limited to, a digital and / or analog communication medium (e.g., a fiber optic cable, a waveguide, a wired communication link, a wireless communication link, or the like). Thus, for example, the signal-bearing medium 1101 may be communicated via a wireless form of the communication medium 1105 (e.g., a wireless communication medium conforming to the IEEE 802.X standard or other transmission protocol).

[0155] The one or more program instructions 1102 may be, for example, computer-executable instructions or logic-implemented instructions. In some examples, the computing device may be configured to provide various operations, functions, or actions in response to the program instructions 1102 communicated to the computing device via one or more of computer-readable media 1103, computer-recordable media 1104, and / or communication media 1105.

[0156] It should also be noted that the device embodiments described above are merely illustrative, in which the units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided in this application, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.

[0157] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general hardware, and of course can also be implemented by special hardware including application-specific integrated circuits, special CPUs, special memories, special components, etc. In general, all functions performed by computer programs can be easily implemented with corresponding hardware, and the specific hardware structures used to implement the same function can also be various, such as analog circuits, digital circuits or special circuits, etc. However, for the present application, software program implementation is a better implementation method in most cases. Based on such an understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a readable storage medium, such as a computer's floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk or optical disk, etc., and includes a number of instructions to enable a computer device (which can be a personal computer, training equipment, or network equipment, etc.) to execute the methods of each embodiment of the present application.

[0158] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a computer program product.

[0159] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, training equipment or data center to another website, computer, training equipment or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a training equipment, data center, etc. that includes one or more available media integrations. Available media can be magnetic media, (e.g., floppy disk, hard disk, tape), optical media (e.g., DVD), or semiconductor media (e.g., solid-state drive (SSD)), etc.

Claims

1. A method for accessing a shared memory, characterized in that: include: Obtaining a first access request from a first process and a second access request from a second process, wherein the first access request is used to request access to a first address in a shared memory, and the second access request is used to request access to a second address in the shared memory, wherein the shared memory includes a plurality of memory segments, and the plurality of memory segments respectively correspond to different access permissions; In response to the access rights of the first process being no less than the access rights corresponding to the memory segment to which the first address belongs, executing the first access request; In response to the access rights of the second process being lower than the access rights corresponding to the memory segment to which the second address belongs, a security check is performed on the second access request to trigger execution of the second access request when the second access request passes the security check.

2. The method according to claim 1, characterized in that The access rights of the first process are the same as the access rights corresponding to the memory segment to which the second address belongs, the access rights of the second process are the same as the access rights corresponding to the memory segment to which the first address belongs, and the access rights of the first process are higher than those of the second process.

3. The method according to claim 1 or 2, characterized in that: The method further comprises: Obtaining a third access request from the second process, where the third access request is used to request the first address in the shared memory; In response to the access rights of the second process being no less than the access rights corresponding to the memory segment to which the first address belongs, executing the third access request.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: Obtaining a mapping relationship, the mapping relationship being used to indicate a correspondence between a process and a memory segment in the shared memory, wherein a target memory segment corresponding to a target process includes one or more memory segments whose corresponding access rights are not higher than the access rights of the target process, and the target process is any one of the processes recorded in the mapping relationship; Based on the mapping relationship, it is determined that the access rights of the first process are not lower than the access rights corresponding to the memory segment to which the first address belongs, and that the access rights of the second process are lower than the access rights corresponding to the memory segment to which the second address belongs.

5. The method according to claim 4, characterized in that In the mapping relationship, the corresponding relationship between the target process and the target memory segment is generated when the target process is created.

6. The method according to claim 4 or 5, characterized in that: The mapping relationship is specifically used to record the corresponding relationship between the process and the virtual address segment, and the virtual address segment has a corresponding relationship with the memory segment in the shared memory.

7. The method according to any one of claims 4 to 6, characterized in that: The mapping relationship is recorded in a page table, and the page table is used to record the corresponding relationship between the virtual address and the physical address in the shared memory.

8. The method according to any one of claims 1 to 7, characterized in that: The performing security detection on the second access request includes: A target function is called to perform security detection on the second access request, where the target function is a preset function.

9. The method according to any one of claims 1 to 8, characterized in that: The method further comprises: If the second access request passes the security check, triggering execution of the second access request; Alternatively, if the second access request fails the security check, the second access request is refused to be executed.

10. A shared memory access device, characterized in that: include: an acquisition module, configured to acquire a first access request from a first process and a second access request from a second process, wherein the first access request is used to request access to a first address in a shared memory, and the second access request is used to request access to a second address in the shared memory, wherein the shared memory includes a plurality of memory segments, and the plurality of memory segments respectively correspond to different access permissions; a processing module, configured to execute the first access request in response to the access right of the first process being not less than the access right corresponding to the memory segment to which the first address belongs; The processing module is further used to perform a security check on the second access request in response to the access rights of the second process being lower than the access rights corresponding to the memory segment to which the second address belongs, so as to trigger the execution of the second access request when the second access request passes the security check.

11. The device according to claim 10, characterized in that The access rights of the first process are the same as the access rights corresponding to the memory segment to which the second address belongs, the access rights of the second process are the same as the access rights corresponding to the memory segment to which the first address belongs, and the access rights of the first process are higher than those of the second process.

12. The device according to claim 10 or 11, characterized in that The acquisition module is further used to acquire a third access request from the second process, where the third access request is used to request the first address in the shared memory; The processing module is further configured to execute the third access request in response to the access rights of the second process being not less than the access rights corresponding to the memory segment to which the first address belongs.

13. The device according to any one of claims 10 to 12, characterized in that: The acquisition module is further used to acquire a mapping relationship, wherein the mapping relationship is used to indicate a corresponding relationship between a process and a memory segment in the shared memory, wherein the target memory segment corresponding to the target process includes one or more memory segments whose corresponding access rights are not higher than the access rights of the target process, and the target process is any one of the processes recorded in the mapping relationship; The processing module is further used to determine, based on the mapping relationship, that the access rights of the first process are not lower than the access rights corresponding to the memory segment to which the first address belongs, and that the access rights of the second process are lower than the access rights corresponding to the memory segment to which the second address belongs.

14. The device according to claim 13, characterized in that In the mapping relationship, the corresponding relationship between the target process and the target memory segment is generated when the target process is created.

15. The device according to claim 13 or 14, characterized in that The mapping relationship is specifically used to record the corresponding relationship between the process and the virtual address segment, and the virtual address segment has a corresponding relationship with the memory segment in the shared memory.

16. The device according to any one of claims 13 to 15, characterized in that: The mapping relationship is recorded in a page table, and the page table is used to record the corresponding relationship between the virtual address and the physical address in the shared memory.

17. The device according to any one of claims 10 to 16, characterized in that: The processing module is further used to call a target function to perform security detection on the second access request, and the target function is a preset function.

18. The device according to any one of claims 10 to 17, characterized in that: The processing module is further used for: If the second access request passes the security check, triggering execution of the second access request; Alternatively, if the second access request fails the security check, the second access request is refused to be executed.

19. A shared memory access device, characterized in that: The device comprises a memory and a processor; the memory stores codes, the processor is configured to execute the codes, and when the codes are executed, the device executes the method according to any one of claims 1 to 9.

20. A computer storage medium, characterized in that The computer storage medium stores instructions, which, when executed by a computer, cause the computer to implement the method of any one of claims 1 to 9.

Citation Information

Patent Citations

  • Shared memory access method and related device

    CN120011095A

  • Method for accessing shared memory

    CN105760217A

  • Memory access and allocation method, memory controller and system

    CN110554911A

  • Memory sharing method and device, electronic equipment and storage medium

    CN111813584A

  • Method and device for managing and controlling authority of shared memory

    CN116775324A

Cited By

  • Simulation method, device, equipment, medium and product

    CN120197569A

  • Cross-domain communication method and system based on capability token, and readable storage medium

    CN121333770A