Memory management method and related device

By configuring exclusive memory space for the computing unit on the server and setting access permissions, the data security problems caused by shared memory space are solved, and the secure isolation of data storage is achieved.

WO2025139286A1PCT designated stage expired Publication Date: 2025-07-03HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/127017
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2024-10-24
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In the prior art, computing units on the server share memory space, resulting in low data security.

Method used

By managing memory space on the server, configuring exclusive memory space for the first device or virtual instance according to requests, and setting access permissions, only the first device or virtual instance is allowed to perform data reading/writing operations, and isolation of memory space is achieved using the access page table.

Benefits of technology

Improves the security of data storage and ensures that the data in the first memory space is not affected by other devices' operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024127017_03072025_PF_FP_ABST
    Figure CN2024127017_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a memory management method and a related device, which are used for improving the security of data storage. The memory management method is applied to a server. The server is used for managing a memory space. The method comprises: acquiring a first virtual instance on a server or a first request sent by a first application, wherein the first request is used for requesting the use of a memory space that is managed by the server and has a first memory capacity; on the basis of the first memory capacity requested by the first request, configuring, in the memory space managed by the server, a first memory space for the first virtual instance or a first device occupied by the first application, wherein the capacity of the first memory space is greater than or equal to the first memory capacity; and setting an access permission for the first memory space, wherein the access permission indicates that a device performing a data read / write operation on the first memory space is the first virtual instance or the first device.
Need to check novelty before this filing date? Find Prior Art

Description

A memory management method and related device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 26, 2023, with application number 202311825012.3, and invention name “A method for providing secure memory and related equipment”, and the Chinese patent application filed with the State Intellectual Property Office on March 29, 2024, with application number 202410381629.9, and invention name “A memory management method and related equipment”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of computers, and in particular to a memory management method and related devices. Background Art

[0003] With the development of computer technology, servers have more and more functions, and the number and types of computing units on servers are also increasing. How to manage the data required by these computing units during operation has become an urgent problem that needs to be solved.

[0004] In related technical solutions, computing units on a server share a memory space. Since each computing unit stores its own core data in the shared memory space during operation, data security is low.

[0005] Summary of the Invention

[0006] The present application provides a memory management method and related devices for improving the security of data storage.

[0007] In a first aspect, the present application provides a memory management method, which is applied to a server and includes:

[0008] The server is used to manage memory space, specifically, the memory space of a host on the server. The server receives a first request, which is used to request the use of a memory space with a first memory capacity managed by the server. The first request can be issued by a first application running on the server, or by a first virtual instance running on the server. Specifically, the first application runs on a processor included in the server. The first request indicates that the memory capacity to be used is the first memory capacity. Based on this, the server allocates a first memory space from the memory space managed by the server for the first device occupied by the first application, or for the first virtual instance. The capacity of the first memory space is greater than or equal to the first memory capacity to meet the first memory capacity requested by the first request. The server also sets access rights for the first memory space, which indicate that the device that can perform data read / write operations on the first memory space is the first device occupied by the first application, or the first virtual instance. In other words, the first device or the first virtual instance has permission to perform data read / write operations on the first memory space during operation, and the devices that can perform data read / write operations on the first memory space are limited to the first device or the first virtual instance.

[0009] In this application, a first memory space is allocated to a first device or a first virtual instance, and devices with permission to use the first memory space are limited to the first device or the first virtual instance, thereby isolating the first memory space from other memory spaces. Therefore, data used by the first device or the first virtual instance stored in the first memory space will not be affected by operations on other devices, thereby ensuring the security of data storage in the first memory space and thus improving the security of data storage.

[0010] In some optional implementations of the first aspect, the server can set access permissions for the first memory space by establishing an access page table for the first memory space. The access page table includes a first mapping relationship between the physical address of the first device and the physical address of the first memory space, or the access page table includes a second mapping relationship between the physical address of the first virtual instance and the physical address of the first memory space. It is understood that the access page table can implement an address translation function for data read / write operations. Therefore, when the first device initiates a data read / write request to the first memory space, the corresponding physical memory address can be determined in the first memory space based on the physical address of the first device and the access page table, thereby enabling access to the first memory space. Similarly, when the first virtual instance initiates a data read / write request to the first memory space, the corresponding physical memory address can be determined in the first memory space based on the physical address of the first virtual instance and the access page table, thereby enabling access to the first memory space by the first virtual instance. This process also implements the authorization of the first device or the first virtual instance to access the first memory space by the access page table.

[0011] In the present application, the access rights of the first device or the first virtual instance to the first memory space are set by accessing the page table, which provides technical support for the implementation of the technical solution of the present application and improves the feasibility of the technical solution of the present application.

[0012] In some optional implementations of the first aspect, the first virtual instance occupies the second device. That is, the second device is a virtualization module included in the first virtual instance, such as a virtual network card. In embodiments of the present application, memory isolation of the second device can also be implemented. That is, the first memory space requested by the first request can be configured for the second device. In this solution, the aforementioned second mapping relationship is actually a mapping relationship between the physical address of the second device and the physical memory address of the first memory space.

[0013] In some optional implementations of the first aspect, the server receives an access request for a second device, and a physical address corresponding to the access request is not included in an access page table, which means that the second device does not have permission to access the first memory space. The server sends a response message to the second device, indicating that the second device does not have permission to access the first memory space and that the second device does not have permission to perform data read / write operations on the first memory space.

[0014] In this application, the physical address of the second device is not included in the access page table, which means that the second device has no right to access the first memory space, thereby isolating the data in the first memory space from the operations of other devices and ensuring the data storage security of the first memory space.

[0015] In some optional implementations of the first aspect, the first virtual instance includes a virtual machine (VM) or a container running on a server.

[0016] In this application, there are multiple possibilities for the first virtual instance, which enriches the implementation methods and application scenarios of the technical solution of this application and improves the practicality of the technical solution of this application.

[0017] In some optional implementations of the first aspect, the server-managed memory space includes local memory of the server. Allocating a first memory space for the first device occupied by the first virtual instance or the first application in the server-managed memory space based on the first memory capacity requested by the first request includes: if the capacity of the free memory space in the local memory is greater than or equal to the first memory capacity, the server allocating the first memory space for the first device or the first virtual instance from the free memory space in the local memory.

[0018] In some optional implementations of the first aspect, the server-managed memory space includes remote memory, and the remote memory is disposed externally to the server. Allocating a first memory space for the first device occupied by the first virtual instance or the first application in the server-managed memory space based on the first memory capacity requested by the first request includes: if the capacity of the free memory space in the remote memory is greater than or equal to the first memory capacity, the server allocating the first memory space for the first device or the first virtual instance from the free memory space in the remote memory.

[0019] In this application, there are multiple situations for the memory space managed by the server, and there are also multiple possibilities for the first memory space configured for the first device or the first virtual instance. According to the actual application selection, the implementation method and application scenario of the technical solution of this application are enriched, and the flexibility of the technical solution of this application is improved.

[0020] In some optional implementations of the first aspect, the memory space managed by the server includes local memory and remote memory, and the remote memory is set outside the server. According to the first memory capacity requested by the first request, the first memory space is configured for the first device occupied by the first virtual instance or the first application in the memory space managed by the server, including: when the capacity of the free memory space of the local memory and the capacity of the free memory space of the remote memory are both greater than or equal to the first memory capacity, the server has multiple ways to configure the first memory for the first device or the first virtual instance. It can be to select one of the free memory space of the local memory and the remote memory to configure the first memory space for the first device or the first virtual instance, or it can be to configure a mixed first memory space (that is, part of the memory space in the first memory space is included in the free memory space of the local memory, and the other part is included in the free memory space of the remote memory).

[0021] In this application, when the memory space managed by the server includes the local memory and remote memory of the server, the server has multiple ways to configure the first memory space for the first device or the first virtual instance, further enriching the application scenarios of the technical solution of this application.

[0022] In some optional implementations of the first aspect, when the memory space managed by the server includes the local memory and remote memory of the server, and the capacity of the free memory space of the local memory and the capacity of the free memory space of the remote memory are both greater than or equal to the first memory capacity, the server can configure the first memory space for the first device or the first virtual instance according to a preset rule. There are many possibilities for the preset rule, for example, giving priority to memory with a large free memory space, or selecting a memory space of the same type as the most recently configured, or configuring the first memory space in the free memory space of the local memory and the free memory space of the remote memory in proportion, etc., which are not limited to the specific ones here.

[0023] In a second aspect, an embodiment of the present application provides a memory management device, including:

[0024] The transceiver unit is used to obtain a first request sent by a first application or a first virtual instance on the server, where the first request is used to request the use of a memory space with a first memory capacity managed by the server.

[0025] The processing unit is configured to configure, in a memory space managed by the server, a first memory space for the first device or the first virtual instance occupied by the first application based on the first memory capacity requested by the first request, where the capacity of the first memory space is greater than or equal to the first memory capacity, and to set access permissions for the first memory space, where the access permissions indicate that a device performing a data read / write operation on the first memory space is the first device or the first virtual instance.

[0026] The memory management device is used to implement the memory management method shown in the aforementioned first aspect or any possible implementation method of the first aspect. Its beneficial effects are as shown above and will not be repeated here.

[0027] In a third aspect, the present application provides a computer device comprising a processor and a memory, wherein the processor stores instructions. When the instructions stored in the memory are executed on the processor, the method shown in the aforementioned first aspect or any possible implementation of the first aspect is implemented.

[0028] In a fourth aspect, the present application provides a computer-readable storage medium, which stores instructions. When the instructions are executed on a processor, the method shown in the first aspect or any possible implementation of the first aspect is implemented.

[0029] In a fifth aspect, the present application provides a computer program product, which, when executed on a processor, implements the method shown in the aforementioned first aspect or any possible implementation of the first aspect.

[0030] The beneficial effects shown in any one of the third to fifth aspects are similar to those of the first aspect or any possible implementation method of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] FIG1 is a schematic diagram of a system architecture provided by an embodiment of the present application;

[0032] FIG2 is a flow chart of a memory management method provided in an embodiment of the present application;

[0033] FIG3 is a schematic diagram of a memory management method provided in an embodiment of the present application;

[0034] FIG4 is another schematic diagram of the memory management method provided in an embodiment of the present application;

[0035] FIG5 is another schematic diagram of the memory management method provided in an embodiment of the present application;

[0036] FIG6 is another schematic diagram of the memory management method provided in an embodiment of the present application;

[0037] FIG7 is a schematic diagram of the structure of a memory management device provided in an embodiment of the present application;

[0038] FIG8 is a schematic structural diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0039] The embodiments of the present application provide a memory management method and related devices for improving the security of data storage.

[0040] The embodiments of the present application are described below in conjunction with the accompanying drawings. Those skilled in the art will appreciate that, with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0041] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way are interchangeable when appropriate, and this is merely a way of distinguishing objects of the same attributes when describing the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or device comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or devices. In addition, "at least one" refers to one or more, and "a plurality" refers to two or more. "and / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent: the situation where A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0042] First, please refer to FIG1 , which is a schematic diagram of the system architecture provided in the embodiment of the application.

[0043] Optionally, as shown in Figure 1, an application is running on a server processor, and the application may also occupy a device. As shown in Figure 1, the application occupies device 1. The application can also be called a process, and the application occupying device 1 can be understood as the application being bound to device 1.

[0044] Optionally, as shown in Figure 1, a virtual instance can also be run on the server. The virtual instance can also include a device, in which case the device is a virtualized module, such as a virtual network card.

[0045] In the implementation of this application, the server manages memory space, which includes the host's local memory or remote memory located outside the server. In other words, the data in the local memory is stored locally on the server, and the data in the remote memory is stored on a remote server, which can be accessed via the Internet.

[0046] It should be noted that Figure 1 is only a schematic diagram of the system architecture provided in the embodiment of the present application. In actual applications, the server may only include applications or virtual instances, and applications or virtual instances may also manage a larger number of devices, which is not specifically limited here.

[0047] Please refer to FIG2 , which is a flow chart of the memory management method provided in an embodiment of the present application.

[0048] 201. The server obtains a first request sent by a first virtual instance or a first application on the server, where the first request requests use of a memory space with a first memory capacity managed by the server.

[0049] The server receives a first request, and the first request carries an identifier of the first virtual instance or the first device, which is used to indicate that the memory space requested for use by the first request is for use by the first virtual instance or the first device. The identifier of the first virtual instance or the first device is used to uniquely indicate the first virtual instance or the first device, and can be an identifier such as the product serial number (SN) of the first virtual instance or the first device, or the identity document (ID) of the first virtual instance or the first device, and can be set according to the needs of the actual application, and is not limited here. The first request can also carry a first memory capacity, which indicates the size of the memory space requested by the first request.

[0050] There are several possible ways for the server to obtain the first request, which are described below:

[0051] In some optional implementations, the first request is sent by a first application. The first application occupies or manages the first device. The first application calls the driver interface of the first device, so that the kernel of the host in the server binds the ownership of the first device to the first application, thereby realizing the management of the first device by the first application, or in other words, realizing the occupation of the first device by the first application. Then, when processing requests for the first device, the server will only process requests sent by the first application bound to the first device. For requests to the first device sent by other applications, the server will not process them, or will intercept or block these requests. Among them, the application can also be called a process on the bare metal.

[0052] In some optional implementations, the first request is sent by a first virtual instance. The first virtual instance includes a virtual machine or a container. A virtual machine or container refers to a complete computer system with complete hardware system functionality, simulated by software, running in a completely isolated environment. Any work that can be performed on a physical computer can also be performed in a virtual machine.

[0053] In some optional implementations, the first virtual instance may occupy or manage a second device. That is, the virtual instance includes the second device, which is a virtualization module running on the virtual instance. In this case, the memory space requested by the first request sent by the first virtual instance to the server may be allocated to the second device. In this case, the first request carries the device identifier of the second device. The second device identifier is similar to the first device identifier and has multiple possibilities, which will not be detailed here.

[0054] In this application, there are multiple possibilities for the first virtual instance, which enriches the implementation methods and application scenarios of the technical solution of this application and improves the practicality of the technical solution of this application.

[0055] 202. The server configures a first memory space for the first device or the first virtual instance in the memory space managed by the server according to the first memory capacity requested by the first request, and the capacity of the first memory space is greater than or equal to the first memory capacity.

[0056] After receiving the first request, the server allocates the required memory space to the first device or the first virtual instance based on the first memory capacity requested by the first request and the memory space managed by the server. There are multiple possibilities for the memory space managed by the server, and there are also multiple possibilities for the first memory space configured for the first device or the first virtual instance, which are described below:

[0057] In some optional implementations, the memory space managed by the server includes local memory of the server. If the capacity of the local memory is greater than or equal to the first memory capacity, the server allocates the first memory space for the first device or the first virtual instance from free memory space in the local memory. Free memory space refers to memory space that does not store data.

[0058] For example, assuming the first memory capacity is 500MB and the free memory space in the local memory is 600MB, the capacity of the first memory space configured by the server for the first device can be greater than or equal to 500MB, but less than the free memory space in the local memory (600MB). Optionally, the capacity of the first memory space can be set to a certain degree greater than the first memory capacity, for example, to not exceed 1% or 5% of the first memory capacity. The specific parameters can be determined based on actual application needs and are not limited here.

[0059] For example, assuming that the first memory capacity is 500 MB, and if the capacity of the free memory space of the local memory is 500 MB, then the capacity of the first memory space configured by the server for the first device or the first virtual instance is 500 MB.

[0060] In some optional embodiments, the memory space managed by the server includes a remote memory that is external to the server. If the capacity of the free memory space in the remote memory is greater than or equal to the first memory capacity, the server allocates the first memory space for the first device or the first virtual instance from the free memory space in the remote memory.

[0061] It can be understood that the specific implementation of the server configuring the first memory space for the first device or the first virtual instance from the free memory space of the remote memory is similar to the previous configuration of the first memory space for the first device or the first virtual instance from the free memory space of the local memory, and no example is given here.

[0062] In some optional implementations, the memory space managed by the server includes the local memory and remote memory of the server. In this solution, there are multiple implementations of the server configuring the first memory space for the first device or the first virtual instance, which are described below:

[0063] Optionally, a rule may be set to preferentially configure the first memory space for the first device or the first virtual instance from a memory type with a larger capacity of free memory space.

[0064] Exemplarily, if the capacity of the free memory space of the local memory and the capacity of the free memory space of the remote memory are both greater than or equal to the first memory capacity, the first memory space is determined from the free memory space of the local memory and the free memory space of the remote memory, whichever has the larger capacity. For example, if the first memory capacity is 300MB, the free memory space of the local memory is 400MB, and the free memory space of the remote memory is 500MB, the server determines the first memory space from the free memory space of the remote memory. The capacity of the first memory space is greater than or equal to 300MB, and the degree of greater than 300MB can be set. Please refer to the previous description and will not be repeated here.

[0065] Exemplarily, if the capacity of the free memory space of the local memory and the capacity of the free memory space of the remote memory are both smaller than the first memory capacity, then the first memory space determined by the server is included in the free memory space of the local memory and the free memory space of the remote memory. For example, the first memory capacity is 1GB, the free memory space capacity of the local memory is 600MB, and the free memory space capacity of the remote memory is 700MB. Then, the server can determine that 700MB of the first memory space comes from the free memory space of the remote memory, and 324MB comes from the free memory space of the local memory. Optionally, the server can also configure the first memory space in the free memory space of the local memory and the free memory space of the remote memory in proportion.

[0066] Optionally, you can set a rule to give priority to memory spaces of the same type as the most recently configured one.

[0067] Exemplarily, if the capacity of the free memory space in the local memory and the capacity of the free memory space in the remote memory are both greater than or equal to the first memory capacity, the server may select a memory space of the same type as the most recently configured one from the free memory space in the local memory and the free memory space in the remote memory to configure the first memory space. For example, if the first memory capacity is 600MB, the free memory space in the local memory is 700MB, the free memory space in the remote memory is 600MB, and the memory space most recently configured by the server was determined from the local memory space, then the server may determine the first memory space from the free memory space in the local memory.

[0068] Exemplarily, if the capacity of the free memory space of the memory space of the same type as the most recently configured one is smaller than the first memory capacity, then the first memory space determined by the server comes from the free memory space of the local memory and the free memory space of the remote memory. For example, the first memory capacity is 800MB, the free memory space capacity of the local memory is 300MB, the free memory space capacity of the remote memory is 600MB, and the memory space most recently configured by the server is determined from the local memory space. Then the server can determine 300MB from the free memory space of the local memory and set 500MB from the free memory space of the remote memory as the first memory space. Optionally, in this example, the server can also configure the first memory space in the free memory space of the local memory and the free memory space of the remote memory in proportion.

[0069] It is understandable that in actual applications, there may be other ways to configure the first memory space for the first device or the first virtual instance from the memory space managed by the server. As long as it can be ensured that the sum of the capacity of the free memory space of the local memory of the server and the capacity of the free memory space of the remote memory is greater than or equal to the first memory capacity, the first memory space can be successfully configured for the first device or the first virtual instance. The specific implementation method of configuring the first memory space for the first device or the first virtual instance is not limited here.

[0070] In this application, there are multiple situations for the memory space managed by the server, and there are also multiple possibilities for the first memory space configured for the first device or the first virtual instance. According to the actual application selection, the implementation method and application scenario of the technical solution of this application are enriched, and the flexibility of the technical solution of this application is improved.

[0071] 203. The server sets access rights for the first memory space, where the access rights indicate that a device that performs data read / write operations on the first memory space is the first device or the first virtual instance.

[0072] The server sets the access rights of the first memory space by establishing an access page table for the first memory space. Specifically, after determining the first memory space, the server obtains the physical memory address of the first memory space. The access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space. Through the aforementioned mapping relationship, when a request indicating a read / write operation on the data of the first memory space is obtained, it is determined whether the device has the permission to access the first memory space by comparing whether the physical address of the device sending the request is included in the access page table. In addition, the access page table can realize the conversion function of the physical address, so that the request indicating a read / write operation on the data of the first memory space issued by the device with access rights can correspond to the corresponding memory address of the first memory space, thereby realizing access to the first memory space.

[0073] The access page table may be a page table managed by an input / output memory management unit (IOMMU).

[0074] In the present application, the access rights of the first device or the first virtual instance to the first memory space are set by accessing the page table, which provides technical support for the implementation of the technical solution of the present application and improves the feasibility of the technical solution of the present application.

[0075] In some optional implementations, the first virtual instance may occupy or manage the second device. In this case, the first request issued by the first virtual instance may include an identifier of the second device, and the server may further configure the first memory space for the second device based on the first request. Accordingly, the second mapping relationship included in the access page table of the first memory space may be a mapping relationship between the physical address of the second device and the physical memory address of the first memory space.

[0076] In some optional implementations, the server may also receive an access request for a second device. If the physical address corresponding to the access request is not included in the access page table of the first memory space, it indicates that the second device does not have permission to access the first memory space and cannot perform data read / write operations on the first memory space. The server then sends a response message to the second device, indicating that the second device does not have permission to access the first memory space. The second device may be a virtual machine or a bare metal managed device.

[0077] In this application, the physical address of the second device is not included in the access page table, which means that the second device has no right to access the first memory space, thereby isolating the data in the first memory space from the operations of other devices and ensuring the data storage security of the first memory space.

[0078] Based on the foregoing description, it can be seen that in embodiments of the present application, there are various possible devices and types of first memory spaces that are authorized to access the first memory space. Below, some possible examples are described with reference to schematic diagrams. Please refer to Figures 3 to 6, which are schematic diagrams of the memory management method provided in embodiments of the present application.

[0079] It should be noted that, in the embodiments shown in FIG. 3 and FIG. 4 , the server is used as an example to configure the first memory space of the device 1 managed by the application 1 .

[0080] As shown in Figure 3, processor 1 executes step ① to call the software development kit (SDK) interface of the rights management service and sends a first request to the rights management module in the host, requesting that device 1, which is to be managed by application 1, use the memory space managed by the server. The rights management module executes step ② to configure the first memory space for device 1 from the local memory of the server. The rights management module also establishes an access page table indicating the mapping relationship between the physical address of device 1 and the physical memory address of the first memory space to authorize device 1 to access the first memory space. After the configuration is completed, device 1 executes step ③ to apply to the rights management module for access to the first memory space. The rights management module implements device 1's access to the first memory space based on the physical address and access page table applied for by device 1, and performs corresponding data read / write operations.

[0081] Unlike the embodiment shown in FIG3 , in the embodiment shown in FIG4 , the first memory space configured by the server for device 1 is contained in the remote memory. That is, after receiving the first request, the rights management module forwards the first request to the remote memory management module, causing the remote memory management module to determine the first memory space from the server's remote memory and return the physical memory address of the first memory space to the rights management module. The rights management module then creates an access page table that indicates the mapping relationship between device 1's physical address and the physical memory address of the first memory space, thereby authorizing device 1 to access the first memory space.

[0082] In the embodiments shown in Figures 3 and 4, the access rights to the first memory space are limited to device 1. Access to the first memory space by other devices will be intercepted, or access failure will be reported. For applications 1 and 2, when attempting to access the first memory page, the first memory space needs to be mapped to the virtual address space of application 1 or application 2. Due to the access page table of the first memory space, the mapping fails, and application 1 and application 2 have no right to access the first memory space. For device 2, since no access page table is created between the physical address of device 2 and the physical address of the first memory space, the access request of device 2 to the first memory space will be intercepted, resulting in the effect that device 2 has no right to access the first memory space.

[0083] In the embodiments shown in FIG. 5 and FIG. 6 , a virtual machine scenario is used as an example in which a server configures a first memory space for a device 1 managed by a virtual machine 1 .

[0084] As shown in Figure 5, virtual machine 1 calls the SDK interface of the rights management service and sends a first request to the rights management module in the virtual machine management (VMM) layer, requesting that device 1 managed by virtual machine 1 apply for the use of the memory space managed by the server. The rights management module configures the first memory space for device 1 from the local memory of the server. The rights management module also establishes an access page table that indicates the mapping relationship between the physical address of device 1 and the physical memory address of the first memory space to authorize device 1 to access the first memory space. After the configuration is completed, device 1 applies to the rights management module for access to the first memory space. The rights management module implements device 1's access to the first memory space based on the physical address of device 1 and the access page table, and performs corresponding data read / write operations.

[0085] Unlike the embodiment shown in FIG5 , in the embodiment shown in FIG6 , the first memory space configured by the server for device 1 is contained in the remote memory. That is, after receiving the first request, the rights management module forwards the first request to the remote memory management module, causing the remote memory management module to determine the first memory space from the server's remote memory and return the physical memory address of the first memory space to the rights management module. The rights management module then creates an access page table that indicates the mapping relationship between the physical address of device 1 and the physical memory address of the first memory space, thereby authorizing device 1 to access the first memory space.

[0086] In the embodiments shown in Figures 5 and 6, the access rights to the first memory space are limited to device 1, and access to the first memory space by other devices will be intercepted, or access failure will be fed back. For virtual machine 2, when attempting to access the first memory page, a page fault will be triggered and the request will be returned to the VMM layer for processing. Since virtual processor 1 of virtual machine 1 and virtual processor 2 of virtual machine 2 do not have permission to access the first secure memory, the access requests of virtual machine 1 and virtual machine 2 will be intercepted. For device 2, since no access page table is created between the physical address of device 2 and the physical address of the first memory space, the access request of device 2 to the first memory space will be intercepted, thereby achieving the effect that device 2 has no right to access the first memory space.

[0087] In some optional implementations, the server may also update the first memory space. For example, when the capacity of the first memory space cannot meet the usage requirements of the first device or the first virtual instance, the first application or the first virtual instance that manages the first device sends a second request to the server and establishes an access page table for the second memory space. The second memory space indicated by the second request may be a newly added memory space, or a new memory space. The sum of the memory capacity of the newly added memory space and the first memory space meets the usage requirements of the first device or the first virtual instance, and the new memory space is used to replace the first memory space. If the server configures a new memory space, the server may also migrate the data in the original first memory space to the new memory space and delete the access page table of the first memory space.

[0088] In some optional implementations, the first memory space configuration may fail. For example, the capacity of the memory space managed by the server may be less than the memory capacity requested in the first request. In this case, the server returns a message indicating that the memory space configuration failed to the sender of the first request. Optionally, the server may also send a prompt to the sender of the first request, instructing the sender to expand the server's memory space or to clear data on the server to meet actual application needs.

[0089] 7 , which is a schematic diagram of the structure of a memory management device according to an embodiment of the present application. As shown in FIG7 , a memory management device 700 includes a transceiver unit 701 and a processing unit 702 .

[0090] In some optional implementations, the transceiver unit 701 is configured to obtain a first request issued by a first application or a first virtual instance on the server, where the first request is used to request use of a memory space with a first memory capacity managed by the server.

[0091] Processing unit 702 is configured to allocate, in the memory space managed by the server, a first memory space for the first device or the first virtual instance occupied by the first application based on the first memory capacity requested by the first request, where the capacity of the first memory space is greater than or equal to the first memory capacity, and to set access permissions for the first memory space, where the access permissions indicate that the device performing data read / write operations on the first memory space is the first device or the first virtual instance.

[0092] In some optional embodiments, the processing unit 702 is specifically used to set access rights by establishing an access page table for the first memory space, where the access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space.

[0093] In some optional implementations, the transceiver unit 701 is further configured to: obtain an access request for the second device, the physical address corresponding to the access request not being included in the access page table, and send a response message to the second device, the response message indicating that the second device does not have permission to access the first memory space.

[0094] In some optional implementations, the first virtual instance includes a virtual machine or a container running on a server.

[0095] In some optional implementations, the memory space managed by the server includes a local memory of the server. The processing unit 702 is specifically configured to: when the capacity of the free memory space of the local memory is greater than or equal to the first memory capacity, allocate a first memory space for the first device or the first virtual instance from the free memory space of the local memory.

[0096] In some optional implementations, the memory space managed by the server includes remote memory, and the remote memory is located outside the server. Processing unit 702 is specifically configured to, when the capacity of the free memory space in the remote memory is greater than or equal to the first memory capacity, allocate a first memory space for the first device or the first virtual instance from the free memory space in the remote memory.

[0097] In some optional implementations, the memory space managed by the server includes local memory and remote memory of the server. Processing unit 702 is specifically configured to, when the capacity of the free memory space of the local memory and the capacity of the free memory space of the remote memory are both greater than or equal to the first memory capacity, allocate a first memory space for the first device or the first virtual instance from the free memory space of the local memory and / or the free memory space of the remote memory.

[0098] The memory management device is used to execute the operations performed by the server in the embodiments shown in Figures 1 to 6 above, and implement the memory management method provided in the embodiments of the present application. Please refer to the above for details and will not be repeated here.

[0099] Below, the computer device provided in the embodiment of the present application is described. Please refer to Figure 8, which is a structural diagram of the computer device provided in the embodiment of the present application. The computer device 800 includes a processor 801, a memory 802, a communication interface 803 and a bus 804. Among them, the processor 801, the memory 802, the communication interface 803, communicate through the bus 804, and can also achieve communication through other means such as wireless transmission. The memory 802 stores program code, and the processor 801 can call the program code stored in the memory 802 to perform the operations performed by the server in the embodiments shown in Figures 1 to 6 above, thereby implementing the memory management method provided in the embodiment of the present application, which will not be repeated here.

[0100] It should be understood that in the embodiment of the present application, the processor 801 may be a CPU, or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0101] The memory 802 may include a read-only memory and a random access memory, and provides instructions and data to the processor 801. The memory 802 may also include a non-volatile random access memory. For example, the memory 802 may also store device type information.

[0102] The memory 802 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0103] In addition to the data bus, bus 804 may also include a power bus, a control bus, and a status signal bus. However, for clarity, all buses are labeled as bus 804 in the figure. Bus 840 may be a Peripheral Component Interconnect Express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. Bus 840 may be divided into an address bus, a data bus, a control bus, etc.

[0104] The computer device 800 may also include one or more communication interfaces, one or more operating systems, such as Windows Server 2003, Windows Server 2003, Windows Server 2003R ... and Windows Server 2003R. TM , Mac OS X TM , Unix TM ,Linux TM , FreeBSD TM wait.

[0105] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0106] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0107] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0108] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0109] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A memory management method, characterized in that, The method is applied to a server, which is used to manage the memory space. The method includes: Obtaining a first request sent by a first application or a first virtual instance on the server, where the first request is used to request to use the memory space with a first memory capacity managed by the server; Configuring, according to the first memory capacity requested by the first request, a first memory space for a first device occupied by the first application or the first virtual instance in the memory space managed by the server, where the capacity of the first memory space is greater than or equal to the first memory capacity; Setting the access permission of the first memory space, where the access permission indicates that the device for performing data read / write operations on the first memory space is the first device or the first virtual instance.

2. The method according to claim 1, wherein The setting of the access permission of the first memory space includes: Setting the access permission by establishing an access page table of the first memory space, where the access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space.

3. The method according to claim 2, characterized in that The method further includes: Obtaining an access request for a second device, where the physical address corresponding to the access request is not included in the access page table; Sending response information to the second device, where the response information indicates that the second device has no permission to access the first memory space.

4. The method according to any one of claims 1 to 3, characterized in that The first virtual instance includes a virtual machine or a container running on the server.

5. The method according to any one of claims 1 to 4, characterized in that The memory space managed by the server includes the local memory of the server; The configuring, according to the first memory capacity requested by the first request, a first memory space for a first device occupied by the first application or the first virtual instance in the memory space managed by the server includes: When the capacity of the free memory space in the local memory is greater than or equal to the first memory capacity, configuring the first memory space for the first device or the first virtual instance from the free memory space in the local memory.

6. The method according to any one of claims 1 to 4, characterized in that The memory space managed by the server includes a remote memory, and the remote memory is set outside the server; The configuring, according to the first memory capacity requested by the first request, a first memory space for a first device occupied by the first application or the first virtual instance in the memory space managed by the server includes: When the capacity of the free memory space in the remote memory is greater than or equal to the first memory capacity, configuring the first memory space for the first device or the first virtual instance from the free memory space in the remote memory.

7. The method according to any one of claims 1 to 4, characterized in that The memory space managed by the server includes the local memory and the remote memory of the server; The configuring, according to the first memory capacity requested by the first request, a first memory space for a first device occupied by the first application or the first virtual instance in the memory space managed by the server includes: When the capacities of the free memory spaces of the local memory and the remote memory are both greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space of the local memory and / or the free memory space of the remote memory.

8. A memory management device, characterized in that, Including: A transceiver unit, configured to obtain a first request sent by a first application or a first virtual instance on a server, where the first request is used to request to use a memory space with a first memory capacity managed by the server; A processing unit, configured to configure a first memory space for a first device occupied by the first application or the first virtual instance in the memory space managed by the server according to the first memory capacity requested by the first request, where the capacity of the first memory space is greater than or equal to the first memory capacity; The processing unit is further configured to set access permissions for the first memory space, where the access permissions indicate that the device for performing data read / write operations on the first memory space is the first device or the first virtual instance.

9. The device according to claim 8, characterized in that Specifically, the processing unit is configured to set the access permissions by establishing an access page table for the first memory space, where the access page table includes a first mapping relationship between the physical address of the first device and the physical memory address of the first memory space, or includes a second mapping relationship between the physical address of the first virtual instance and the physical memory address of the first memory space.

10. The device according to claim 9, wherein The transceiver unit is further configured to: Obtain an access request for a second device, where the physical address corresponding to the access request is not included in the access page table; Send response information to the second device, where the response information indicates that the second device has no permission to access the first memory space.

11. The device according to any one of claims 8 to 10, characterized in that, The first virtual instance includes a virtual machine or a container running on the server.

12. The device according to any one of claims 8 to 11, characterized in that, The memory space managed by the server includes the local memory of the server; Specifically, the processing unit is configured to: when the capacity of the free memory space of the local memory is greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space of the local memory.

13. The device according to any one of claims 8 to 11, characterized in that The memory space managed by the server includes a remote memory, and the remote memory is disposed outside the server; Specifically, the processing unit is configured to: when the capacity of the free memory space of the remote memory is greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space of the remote memory.

14. The device according to any one of claims 8 to 11, characterized in that, The memory space managed by the server includes the local memory and the remote memory of the server; Specifically, the processing unit is configured to: when the capacities of the free memory spaces of the local memory and the remote memory are both greater than or equal to the first memory capacity, configure the first memory space for the first device or the first virtual instance from the free memory space of the local memory and / or the free memory space of the remote memory.

15. A computer device, characterized in that, including a processor coupled to a memory; Instructions are stored in the memory, which, when run on the processor, cause the computer device to implement the method according to any one of claims 1 to 7.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions, which, when run on a processor, cause the method according to any one of claims 1 to 7 to be implemented.

17. A computer program product, characterized in that, When the computer program product is executed on a computer, the method according to any one of claims 1 to 7 is caused to be implemented.

Citation Information

Patent Citations

  • Memory protection method and system and network interface controller

    CN103488588A

  • Method and device for monitoring memory access behaviors of sample process

    CN110928737A

  • Memory access method, chip, electronic equipment and computer readable storage medium

    CN116136826A

  • Memory management method and device, computer equipment and storage medium

    CN116302491A

  • Computing device with increased resistance against rowhammer attacks

    US20200012600A1