Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

18 results about "Memory protection" patented technology

Memory protection is a way to control memory access rights on a computer, and is a part of most modern instruction set architectures and operating systems. The main purpose of memory protection is to prevent a process from accessing memory that has not been allocated to it. This prevents a bug or malware within a process from affecting other processes, or the operating system itself. Protection may encompass all accesses to a specified area of memory, write accesses, or attempts to execute the contents of the area. An attempt to access unowned memory results in a hardware fault, called a segmentation fault or storage violation exception, generally causing abnormal termination of the offending process. Memory protection for computer security includes additional techniques such as address space layout randomization and executable space protection.

Storage systems and data protection methods

PendingJP2026110040AControl storeEngineering
During writeback in the storage system, this prevents logs from accumulating in the queue that stores the logs of cache memory updates. [Solution] Each of the multiple storage controllers is equipped with a first memory protection method that generates logs related to the writing and updating of data in memory, stores them in a memory queue, retrieves the logs from the queue, and writes them to a non-volatile storage medium. When the storage controller protects data in memory using the first memory protection method, it controls the execution of a first process that stores logs in the queue and a second process that retrieves logs from the queue and writes them to the storage medium, according to the capacity of the logs stored in the queue.
Owner:HITACHI VANTARA LTD

Method and computing system capable of enhancing memory protection

This invention provides a method and computing system capable of enhancing memory protection related to the operating system kernel, thereby ensuring system security. The computing system provided by this invention may include: a processor configured to execute a guest virtual machine (VM), wherein an operating system (OS) runs on the guest VM, and an application (APP) runs on the OS. The kernel of the OS includes: a protection service module configured to receive at least one virtual address and first size information sent by a client of the APP; and a memory management unit (MMU) manager. The computing system further includes a virtual machine manager configured to receive the at least one virtual address and the first size information sent by the protection service module. The computing system also includes a host VM, which includes: a protection manager configured to receive and obtain a physical address array and second size information based on the at least one virtual address and the first size information to protect memory allocated by the kernel of the OS.
Owner:MEDIATEK INC

A memory out-of-bounds detection method, device, medium and program product

This invention relates to the field of chip technology and discloses a method, device, medium, and program product for memory out-of-bounds detection. The method includes: obtaining the operator semantics and input parameters corresponding to a target operator, and generating initial address attribute entries based on the operator semantics and input parameters; obtaining the computing core corresponding to the target operator, and storing each initial address attribute entry in a fine-grained memory protection unit corresponding to the computing core; and performing memory out-of-bounds detection on memory access requests of the computing core based on each initial address attribute entry to obtain the detection result. By pre-deriving the address attribute entries corresponding to the target operator based on the operator semantics and input parameters, adding a fine-grained memory protection unit for storing the address attribute entries, and implementing real-time memory out-of-bounds detection of memory access requests based on the address attribute entries, efficient and accurate memory out-of-bounds detection under a memory pool mechanism can be achieved, ensuring memory data security.
Owner:SHANGHAI SUIYUAN TECH CO LTD

A control logic runtime verification and security recovery method for embedded real-time systems

PendingCN122308328AOperational systemSafety property
This invention discloses a method for runtime verification and safety recovery of control logic in embedded real-time systems, relating to the fields of embedded real-time control and functional safety technology. This invention constructs an independent safety monitoring layer outside the operating system kernel, defines runtime contracts containing safety invariance and timing logic constraints for critical control tasks, and performs real-time contract verification through periodic data collection. When a contract violation is detected, a layered recovery mechanism is initiated according to fault levels, including output clamping, task rollback and restart, and algorithm degradation switching. A memory protection unit is used to achieve spatiotemporal isolation protection for tasks. This invention achieves non-intrusive real-time monitoring and hierarchical safety recovery of critical control tasks, improving the functional safety and operational stability of embedded real-time systems. The monitoring overhead is controllable and does not affect real-time system scheduling, making it widely applicable to safety-critical scenarios such as vehicle control and industrial robots.
Owner:CHINA YANGTZE POWER

Dynamic scheduling method and system for physical memory protection mechanism under RISC-V architecture

The application provides a dynamic scheduling method and system of a physical memory protection mechanism under a RISC-V architecture, and relates to the technical field of computers, and comprises the following steps: S1, accessing application memory under the dynamic scheduling support of the physical memory protection mechanism; and S2, maintaining the current effective application memory access permission configuration by using an LRU algorithm.The application can greatly reduce the probability of updating the PMP configuration and improve the running efficiency of the application.
Owner:SHANGHAI TRUSTKERNEL INFORMATION TECH CO LTD

Memory protection

Apparatuses and methods for memory protection are disclosed. A memory protection apparatus is interposed between a system cache and a memory system. The apparatus comprises encryption circuitry, which encrypts data item in dependence on encryption metadata and decrypts encrypted data items in dependence on the encryption metadata. In response to a change in a metadata item of the encryption metadata, when no cached copy of an affected data item is currently in the system cache, the affected data item is retrieved from the memory system, re-encrypted using the updated metadata item and returned to the memory system. When there is a cached copy, in dependence on update control data, the copy is retrieved from the system cache, encrypted using the updated metadata item and written out to the memory system.
Owner:ARM LTD

Method and system for modular loading of firmware based on hardware abstraction layer

The application provides a kind of hardware abstraction layer-based firmware modular loading method and system, it is related to computer technology field, first activate hardware abstraction layer service when system initialization, provide uniform operation interface for upper layer, read firmware module list from system security storage area, parse target loading module dependency graph, obtain the encrypted signature target module firmware image in order, verify signature and compare integrity by hardware abstraction layer service call cryptographic service engine, after successful verification, load module to specified memory protection area and register interface, continuously monitor module hardware resource access request during operation, suspend module and trigger safety isolation and hot update process when detecting exception or receiving update signal.The application improves system portability, security and maintainability.
Owner:GUOXINYUN (SHANGHAI) INTELLIGENT INFORMATION TECH CO LTD

Method and apparatus for detecting stack overflow using physical memory protection function

PCT designated stageWO2026147133A1Parallel computingTerm memory
The present disclosure relates to a stack overflow detection method performed by a processor including a memory protection address register and a memory protection configuration register, and the method may comprise the steps of: detecting access to a first memory access address value located outside a stack area of a first execution unit on the basis of a first memory protection address register value of the first execution unit recorded in the memory protection address register; comparing the first memory access address value with a first memory protection address value of the first execution unit; and performing stack overflow detection on the basis of a result of comparing the first memory access address value with the first memory protection address value of the first execution unit.
Owner:RTST CO LTD

An ECU-guided dynamic self-healing system, method, and device based on vehicle diagnostic communication protocol and physical perception.

PendingCN122309225AMicrocontrollerIn vehicle
This invention relates to the field of ECU management technology, and discloses an ECU boot dynamic self-healing system, method, and device based on vehicle diagnostic communication protocols and physical sensing. The key technical features include a microcontroller, non-volatile memory, a memory protection unit, and a power supply voltage detection unit. The microcontroller runs a boot protection module, a logic evolution module, a dynamic driving unit, and a snapshot management and power-down hardening unit. The boot protection module is used for power-on priority startup, reading snapshot status, performing fault self-healing, and resuming interrupted data transfer. The logic evolution module is used to execute the main business of the bootloader program. The dynamic driving unit is loaded into the running memory and used to perform erase / write operations on the updatable boot area, updating the snapshot information in the running memory in real time during the flashing process. The power supply voltage detection unit is used to trigger power-down processing. The snapshot management and power-down hardening unit is used to respond to power-down signals and write snapshot information to the snapshot storage area.
Owner:NANJING CHUHANG TECH CO LTD

Adaptive memory protection method and device for dynamically adjusting three-mode redundancy voting frequency

ActiveCN121455701BTerm memoryDependability
This invention belongs to the field of computer technology and proposes an adaptive memory protection method and apparatus for dynamically adjusting the voting frequency of triple modular redundancy (TMR). It involves creating and initializing a management structure for critical data, which includes three data copy pointers to manage three copies of the critical data. The method monitors system status parameters related to the critical data in real time or periodically, including system load rate and the historical error rate of data inconsistencies in historical voting. Based on the monitored system status parameters, it dynamically adjusts the voting frequency strategy for performing a two-out-of-three voting operation on the three data copies. Following the voting frequency strategy, it performs the corresponding two-out-of-three voting operation on the three data copies. This invention can dynamically adjust the voting frequency of TMR based on system load and historical error rate, thereby significantly optimizing system performance and reducing power consumption while ensuring memory reliability.
Owner:KYLIN CORP

Method, system, and circuit for memory protection unit configuration and content generation

System, method, and circuitry for generating content for a programmable computing device based on user-selected memory regions. Contiguous regions that share memory access attributes are merged, interleaved contiguous regions that share at least one nested attribute are defined into combined regions, and remaining regions are defined as separate independent regions. A memory protection unit (MPU) region size closest to a size of each defined region is identified. If the start address of each region aligns with the address structure of the MPU region size, then those regions are assigned to MPU regions having the MPU region size; otherwise, another MPU size that aligns with the size of the regions is selected and those regions are assigned to MPU regions having that size. Content is generated to configure settings of MPU regions of the programmable computing device for the merged contiguous regions, the combined region, and the independent regions.
Owner:STMICROELECTRONICS (GRAND OUEST) SAS

Kernel hardware access driver system based on signature-verified script virtual machine

PendingCN122365539AComputer architectureBit field
This invention relates to the field of Windows kernel driver technology, specifically to a kernel hardware access driver system based on a signature verification script virtual machine. It includes a driver framework module, a bytecode integrity verification module, a script virtual machine module, and a hardware access primitive module. The bytecode integrity verification module performs a byte-by-byte constant-duration comparison of the message authentication code signature of the loaded bytecode to resist timing side-channeling. The hardware access primitive module, during compilation for the ARM64 architecture, stores a first stub array and a second stub array generated by compiling constant expression functions in a read-only executable section, and directly uses the instruction word bit field as the array subscript index for access. This invention supports hot-swapping of driver functions and dynamic access to any ARM64 system register under the constraints of non-writable and executable memory protection.
Owner:JIANGXIA INFORMATION TECH (HUIZHOU) CO LTD

System and method for controlling access to physical address space

A system for controlling access to a physical address (PA) space includes multiple processing circuits executing multiple virtual machines (VMs), multiple system resources addressable within the memory management unit space, multiple memory management units (MMUs) coupled to corresponding processing circuits, and multiple memory protection units (MPUs). A given region of the physical address space is dedicated to addressing the multiple VMs. A given memory management unit translates a virtual address indicated by a request processing circuit in an access request into a requested physical address, which can be accessed by the request processing circuit according to configurable settings of the given memory management unit. A given memory protection unit coupled to a target system resource allocated the requested physical address grants or denies the access request based on sideband signals included in page table entries used for virtual-to-physical address translation by the multiple memory management units.
Owner:MEDIATEK INC

System and method for controlling access to physical address space

A system for controlling access to a physical address (PA) space includes a plurality of processing circuits executing a plurality of virtual machines (VMs), a plurality of system resources addressable within the PA space, a plurality of memory management units (MMUs) coupled to corresponding processing circuits, and a plurality of memory protection units (MPUs). A given region of the PA space is dedicated to addressing the plurality of VMs. A given MMU translates a virtual address indicated in an access request from a requesting processing circuit into a requested PA that is accessible by the requesting processing circuit according to a configurable setting of the given MMU. A given MPU coupled to a target system resource allocated with the requested PA grants or denies the access request according to a sideband signal that is included in a page table entry utilized by the plurality of MMUs for virtual-to-physical address translation.
Owner:MEDIATEK INC

Storage system and data protection method

Each of a plurality of storage controllers includes a first memory protection scheme in which logs related to the writing and updating of data in memory are generated and stored in an in-memory queue and in which the logs are extracted from the queue and written to a non-volatile storage medium. When the data in the memory is to be protected using the first memory protection scheme, the storage controller controls, according to the capacity of the logs stored in the queue, the execution of a first process for storing logs in the queue and a second process for extracting logs from the queue and writing the logs to the storage medium.
Owner:HITACHI VANTARA LTD

An intelligent distribution network terminal heterogeneous core information partition interaction method

PendingCN122332343AShardAlgorithm
This application provides a method for information partitioning and interaction between heterogeneous cores in a smart distribution network terminal, comprising: summarizing target partitions with merging feasibility and their corresponding adjacent partitions to form a grouped partition set; extracting actual boundary addresses from the grouped partition set, optimizing the partition merging sequence based on the constraint relationship between fragmentation ratio and isolation granularity by progressively deducing the boundary address combination of each partition, and determining the boundary address of the merged new partition; obtaining the boundary address of the merged new partition, updating the alignment configuration of the physical memory protection area through the RISC-V side region protection unit, and obtaining the updated shared memory partition structure based on the boundary definition requirements of the RISC-V side hardware; evaluating the adjustment effect by comparing the address space utilization under the updated shared memory partition structure with the original address space utilization, extracting the read / write security boundary of the dual cores, and reallocating the virtual and physical address mapping of the interactive information partitions to obtain the partition configuration.
Owner:GUANGZHOU JOINT INSPECTION & CERTIFICATION TECHNOLOGY DEVELOPMENT SERVICES CO LTD