Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

116 results about "Memory protection" patented technology

Memory protection is a way to control memory access rights on a computer, and is a part of most modern instruction set architectures and operating systems. The main purpose of memory protection is to prevent a process from accessing memory that has not been allocated to it. This prevents a bug or malware within a process from affecting other processes, or the operating system itself. Protection may encompass all accesses to a specified area of memory, write accesses, or attempts to execute the contents of the area. An attempt to access unowned memory results in a hardware fault, called a segmentation fault or storage violation exception, generally causing abnormal termination of the offending process. Memory protection for computer security includes additional techniques such as address space layout randomization and executable space protection.

Solid state disk management system and data processing method

The invention discloses a solid state disk management system and a data processing method, and relates to the technical field of solid state disk management. Flexible task scheduling and resource management are provided through a lightweight operating system module, and a computing task program defined by a user is supported to be dynamically loaded; edge computing or machine learning operators are efficiently executed in combination with a programmable hardware processing unit and a DMA channel of the computing acceleration engine module, the data preloading module is utilized to predict and preload data to DDR based on LBA access history, access delay is reduced, an NVMe protocol is expanded by means of the task unloading interface module, host task issuing and result returning are achieved, and the data processing efficiency is improved. And hardware-level memory protection is ensured through the security isolation module, so that the data calculation processing capacity of the solid state disk is remarkably improved, localized calculation tasks such as edge calculation and machine learning are supported, mass data transmission is effectively reduced, and bus and network loads are relieved.
Owner:HUIJU ELECTRONICS (DONGGUAN) IND CO LTD

Automatic memory protection method and device, computer equipment and storage medium

The invention relates to an automatic memory protection method and device, computer equipment and a storage medium, and the automatic memory protection method comprises the steps: responding to a real-time memory read-write instruction, and determining a target memory address corresponding to the memory read-write instruction; determining a pre-stored tag value corresponding to the target memory address and an actual tag value currently embedded in a memory block pointed by the target memory address; and when it is detected that the pre-stored tag value is not matched with the actual tag value, stopping a memory operation associated with the memory read-write instruction. Through the method and the device, the problem that the data-oriented attack cannot be effectively prevented is solved, the data-oriented attack is effectively prevented, and the memory security and the system operation efficiency are improved.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1

Memory management method, device and equipment and computer readable storage medium

The invention discloses a memory management method, device and equipment and a computer readable storage medium. The method comprises the following steps: when a mapping request exists, determining a target I / O virtual address corresponding to the mapping request and triggering an application identity identifier of the mapping request; detecting whether the target I / O virtual address is associated with the application identity label or not; and if yes, establishing mapping between the target I / O virtual address and the corresponding memory physical address. According to the method and the device, the memory protection capability of the equipment can be enhanced on a system without IOMMU (Input / Output Management Unit); and the complexity of hardware design can be reduced on a system with an IOMMU, and the hardware cost is reduced.
Owner:SIENGINE TECH CO LTD

Heterogeneous trusted execution environment architecture construction method and device and processor

The invention relates to a heterogeneous trusted execution environment architecture construction method and device, and the method comprises the following steps: constructing a tensor analyzer which is located in a memory control unit of a central processing unit of a heterogeneous trusted execution environment architecture; and providing memory protection with uniform tensor granularity for data interaction between the neural network processor of the heterogeneous trusted execution environment architecture and the central processing unit through the tensor analyzer.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Static trusted execution environment for inter-architecture processor program compatibility

Computer-implemented methods and associated hardware for static trusted execution environment for inter-architecture processor program compatibility are disclosed herein. A device (e.g., a Reduced Instruction Set Computing-Five (RISC-V) device), may emulate a static trusted execution environment (e.g., ARM TrustZone) using physical memory protection (PMP). A regular world may have access to only a portion of an address space of the device, while a secure world may have access to the full address space. A secure world identifier (SWID) may be stored in a configuration status register (CSR) only accessible by a mode (e.g., machine mode). When an entry is added to a translation lookaside buffer (TLB), the SWID may be added as part of a tag to differentiate secure world entries from regular world entries.
Owner:TENSTORRENT USA INC

Task stack protection method and device, electronic equipment, chip and medium

The invention provides a task stack protection method and device, electronic equipment, a chip and a medium, and relates to the technical field of computer security. The task stack protection method comprises the following steps: in response to starting of an operating system, initializing a memory protection unit; based on the memory protection unit, the first task is removed from a stack protection memory area, the stack protection memory area is a stack top space of a task stack memory area of an operating system memory, and the first task is a process or a thread operated by an operating system in the stack protection memory area; setting attributes of a stack protection memory area of a second task, the second task being a task executed after the first task and being an active task; and moving the second task into the stack protection memory area. Through the technical scheme provided by the invention, the problem that the task stack protection of the memory area by the memory protection unit is unsafe and unreliable is solved, and the safety and reliability of the task stack protection of the memory area by the memory protection unit are improved.
Owner:SHANGHAI LIXIANG AUTOMOBILE CO LTD

Protecting execution environments within domains

There is provided an apparatus that includes processing circuitry for performing processing in one of a fixed number of at least two domains. One of those domains is subdivided into a variable number of execution environments and memory protection circuitry uses a key input to perform encryption or decryption on the data of a memory access request issued to a memory address from within a current one of the domains. The key input is different for each of the domains and for each of the execution environments, the key input for each of the domains is fixed at boot time of the apparatus, and the key input for each of the execution environments is dynamic.
Owner:ARM LTD

Maintenance operations across subdivided memory domains

An apparatus is provided in which processing circuitry performs processing in one of a fixed number of at least two domains. One of the domains is subdivided into a variable number of execution environments one of which is a management execution environment configured to manage the execution environments. Memory protection circuitry defines a point of encryption after at least one unencrypted storage circuit of a memory hierarchy and before at least one encrypted storage circuit of the memory hierarchy. The at least one encrypted storage circuitry uses a key input to perform encryption or decryption on the data of a memory access request issued from within a current one of the domains. The key input is different for each of the domains and for each of the execution environments and the management execution environment is configured to inhibit issuing a maintenance operation to the at least one encrypted storage circuit of the memory hierarchy.
Owner:ARM LTD

User interrupt event callback mechanism implementation method

The invention discloses a user interrupt event callback mechanism implementation method, which adopts an implementation method of combining user interrupt event callback caused by hardware interrupt and conventional task scheduling, after system hardware interrupt occurs, kernel interrupt processing codes construct a user mode code running environment, and a user mode is switched to run a user event callback function, so that the user interrupt event callback is realized. After the execution of the user event callback function is finished, the system environment before the execution of the user event callback function is recovered through an undefined instruction falling into a kernel; and when all the user callback event functions are executed, falling into the kernel through the undefined instruction again, and recovering an instruction execution stream before the interruption event occurs by utilizing the stack frame information reserved when the interruption is entered. According to the method, an emergency processing mechanism with determined delay is realized, the constructed interrupt event callback function runs in a user space, and the method has the functions of shielding low-priority interrupt and protecting a memory, is low in overhead, simple to implement and easy to adapt to various processors, and has a good application prospect.
Owner:NANJING PANENG TECHNOLOGY DEVELOPMENT CO LTD

Hardware virtual machine for controlling access to physical memory space

A system controls access to a physical address (PA) space. The system includes multiple system resources addressable within the PA space, and multiple processing circuits executing multiple virtual machines (VMs). A given region of the PA space is dedicated to addressing the VMs. The system also includes multiple memory management units (MMUs) coupled to corresponding processing circuits. A given MMU is operative to translate a virtual address indicated in an access request from a processing circuit into a requested PA that is accessible by the processing circuit according to a configurable setting of the given MMU. The system further includes multiple memory protection units (MPUs). A given MPU, which is coupled to a target system resource allocated with the requested PA, is operative to grant or deny the request based on information indicating whether the requested PA is accessible to a requesting VM executed on the processing circuit.
Owner:MEDIATEK INC

Brushing method for flashing Bootloader software

The invention belongs to the technical field of program updating, and particularly relates to a method for flashing Bootloader software, which comprises the following steps of: judging the validity of an application program by an operation starting manager, judging the validity of a programming mark if the application program is valid, and skipping to the operation of the application program if the programming mark is invalid; flashing the software of the second version of the boot loader and the effective copy mark into the flash area, and resetting the micro-control unit; the application program judges whether the copy effective mark is effective or not, if yes, the software of the second-version boot loader is copied to the position where the software of the first-version boot loader is located, after copying is completed, the copy effective mark is removed, and the software of the second-version boot loader is copied. And starting a memory protection unit preset by the micro-control unit to perform write access protection of all memories except for using the EEPROM, and enabling the application program to wait for other tasks. According to the method, the problem that the brick is damaged due to power failure when the power failure occurs in the process of flashing the Bootloader by running the APP is solved.
Owner:领科汇智科技有限公司 +1

Container memory access control method and device, electronic equipment and medium

The embodiment of the invention relates to the technical field of memory management, and provides a container memory protection method and device, electronic equipment and a medium. A pointer authentication code is embedded into a pointer to be accessed to obtain an authentication pointer with authentication information, and the pointer authentication code is generated according to the pointer and context information of the first access request; extracting a pointer authentication code from the authentication pointer, and verifying the authentication pointer based on the pointer authentication code; and when the verification is passed, temporarily inserting a mapping item which allows access to the memory of the target container in an expansion page table allocated for the target container, and performing access control on the memory of the target container through the mapping item. Consequently, container memory protection with light weight and low performance influence is achieved.
Owner:BEIJING UNIV OF POSTS & TELECOMM +2

Memory protection method and device, equipment and storage medium

The invention discloses a memory protection method and device, equipment and a storage medium, and relates to the technical field of computers. The method comprises the following steps: receiving a memory access request initiated by a first kernel of an operating system, wherein the memory access request is used for requesting to access a first region of a memory; according to the memory access request, kernel-level barrier check is executed on the first kernel to obtain a first check result, and the kernel-level barrier check is used for determining whether the first kernel has the access permission of the first area or not; under the condition that the first check result is that the first kernel has the access permission of the first area, executing token permission check on the first kernel to obtain a second check result; and under the condition that the second check result is that the first kernel has the effective authorization token corresponding to the first area, executing an access operation on the first area according to the memory access request. According to the method, memory protection is realized, and the security of memory access is improved.
Owner:KYLIN CORP

Methods and apparatuses for kernel and task isolation

An embodiment of the present application provides a method and apparatus for kernel and task isolation. By adding a separate trusted base to a computer system, the trusted base is independent of the kernel and tasks, and the trusted base, tasks, and kernel each have independent memory. The tasks and the kernel cannot access each other's memory. When task scheduling is required, the trusted base configures the memory protection device according to the memory switching configuration information stored in the memory of the trusted base. By configuring the memory protection device, the memory access boundary can be switched from the kernel's memory to the task's memory, or from the task's memory to the kernel's memory. The access to the memory of the task and the kernel is achieved through the switching of the memory boundary, thereby ensuring the security of the task and the kernel.
Owner:YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Method for ensuring heap memory space safety of embedded system, and embedded system using same

A method for ensuring heap memory space security of an embedded system, according to some embodiments of the present invention, may comprise the steps of: receiving a source code; generating an instrumentation code for the source code; compiling the instrumentation code and executing a program; setting a plurality of memory protection units for a heap area; and performing memory boundary checking before performing a read / write command included in the program, wherein the step of performing the memory boundary checking can include the steps of: using a base pointer and a pointer for the read / write command, and specifying one of the plurality of memory protection units by using the base pointer; and using the base pointer and the pointer so as to determine whether to exceed the heap size for the specified memory protection unit.
Owner:PUSAN NAT UNIV IND UNIV COOPERATION FOUND

Software and hardware combined fine-grained memory protection mechanism

The invention relates to a software and hardware combined fine-grained memory protection mechanism, which realizes high-speed mapping from a physical address to a fine-grained permission label by integrating a metadata search unit and a metadata conversion lookup buffer on a critical path of a processor loading / storage unit. An operating system maintains a multi-level fine-grained permission metadata table in a main memory, and the minimum memory protection granularity is refined to a 64-byte sub-page level. When a processor executes a memory access instruction, address conversion and permission verification are completed in parallel, an access type and a permission label are compared in real time within 1-2 clock periods, and when permission conflicts are detected, high-priority abnormity is triggered immediately, and illegal addresses and fault types are reported accurately. The method supports instruction set extension, buffer overflow protection, multi-level metadata management and user mode and kernel mode differentiated authority control, reduces the influence on the performance of the processor while improving the security of the memory, and is suitable for a computing system with high security and high performance.
Owner:SHAOXIN LABORATORY

Static Trusted Execution Environment for Inter-Architecture Processor Program Compatibility

Computer-implemented methods and associated hardware for static trusted execution environment for inter-architecture processor program compatibility are disclosed herein. A device (e.g., RISC-V), may emulate a static trusted execution environment (e.g., ARM TrustZone) using physical memory protection (PMP). A regular world may have access to only a portion of an address space of the device, while a secure world may have access to the full address space. A secure world identifier (SWID) may be a configuration status register (CSR) only accessible by a mode (e.g., machine mode). When an entry is added to a translation lookaside buffer (TLB), the SWID may be added as part of a tag to differentiate secure world entries from regular world entries.
Owner:TENSTORRENT USA INC

Enforcement of attestation of read-only protected memory during attestation validity period

Enforcing attestation of read-only protected memory during attestation validity period. A client computer system identifies a change in a read-only protected memory protection status for a software component loaded at the client computer system. The client computer system then determines that a validity time period of an attestation report is unexpired. The attestation report comprises one or more attested properties, including one or more read-only memory protection (ROMP) attested properties for the software component. The client computer system also determines that at least one ROMP attested property for the software component is no longer valid due to the change in the read-only protected memory protection status for a software component. Based on the at least one ROMP attested property for the software component being no longer valid, the client computer system initiates a remedial action to prevent interaction of the software component with a relying party computer system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Static trusted execution environment for inter-architecture processor program compatibility

Computer-implemented methods and associated hardware for static trusted execution environment for inter-architecture processor program compatibility are disclosed herein. A device (e.g., RISC-V), may emulate a static trusted execution environment (e.g., ARM TrustZone) using physical memory protection (PMP). A regular world may have access to only a portion of an address space of the device, while a secure world may have access to the full address space. A secure world identifier (SWID) may be a configuration status register (CSR) only accessible by a mode (e.g., machine mode). When an entry is added to a translation lookaside buffer (TLB), the SWID may be added as part of a tag to differentiate secure world entries from regular world entries.
Owner:TENSTORRENT USA INC

Multi-key cryptographic memory protection

In one embodiment, an apparatus comprises a processor to execute instruction(s), wherein the instructions comprise a memory access operation associated with a memory location of a memory. The apparatus further comprises a memory encryption controller to: identify the memory access operation; determine that the memory location is associated with a protected domain, wherein the protected domain is associated with a protected memory region of the memory, and wherein the protected domain is identified from a plurality of protected domains associated with a plurality of protected memory regions of the memory; identify an encryption key associated with the protected domain; perform a cryptography operation on data associated with the memory access operation, wherein the cryptography operation is performed based on the encryption key associated with the protected domain; and return a result of the cryptography operation, wherein the result is to be used for the memory access operation.
Owner:INTEL CORP

Storage systems and data protection methods

PendingJP2026110040AControl storeEngineering
During writeback in the storage system, this prevents logs from accumulating in the queue that stores the logs of cache memory updates. [Solution] Each of the multiple storage controllers is equipped with a first memory protection method that generates logs related to the writing and updating of data in memory, stores them in a memory queue, retrieves the logs from the queue, and writes them to a non-volatile storage medium. When the storage controller protects data in memory using the first memory protection method, it controls the execution of a first process that stores logs in the queue and a second process that retrieves logs from the queue and writes them to the storage medium, according to the capacity of the logs stored in the queue.
Owner:HITACHI VANTARA LTD

Memory access method, memory protection unit, system on chip, and storage medium

The application discloses a memory access method, a memory protection unit, a system on chip and a storage medium, and belongs to the chip technical field. The method is applied to the memory protection unit, the memory protection unit comprises at least one arbitration node, a plurality of input / output bridges and a plurality of checkers, the arbitration node is arranged between the plurality of input / output bridges and the plurality of checkers, and the method comprises the following steps: receiving a memory access request sent by an external device through an input / output bridge and sending the memory access request to the arbitration node; determining a target checker from the plurality of checkers according to traffic information of the plurality of checkers through the arbitration node, and forwarding the memory access request to the target checker; checking the memory access permission of the external device through the target checker, obtaining a checking result, and returning the checking result to the input / output bridge through the arbitration node; and the checking result is used to represent whether the external device passes the permission check. The application can solve the problem that the existing physical memory input / output protection method is low in efficiency.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

Implementation method, device, module and system of firmware trusted platform module based on RISC-V architecture

The present invention utilizes a firmware trusted platform module implemented by the PMP memory protection mechanism in the architecture to solve the problems of implementation complexity and the need for additional hardware support in the current firmware TPM solution under the RISC-V architecture. The method includes the following modules: (1) NVRAM secure memory module using the PMP mechanism: Based on the RISC-V instruction set, its privileged architecture and physical memory protection (PMP) technology are used to implement memory isolation, divide multiple memory areas and configure different access rights. In this way, the security of the memory is guaranteed from the hardware perspective, and at the same time, DRAM latency PUF is used to generate reversible keys, avoiding the security risks of key storage. PMP technology is further used to control access to Flash devices, so that NVRAM data can be securely encrypted and stored and effectively protected. (2) RISC-V architecture rollback attack defense module: Modify some TPM command semantics and use NVRAM to maintain the number of error attempts to deal with the problems that TPM may face, such as rollback attacks and lack of a secure clock.
Owner:WUHAN UNIV

Memory vulnerability repairing method, computer device and readable storage medium

ActiveCN120910872APlatform integrity maintainanceOperating systemMemory protection unit
The invention provides a vulnerability repair method of a memory, a computer device and a readable storage medium, the method comprises the following steps: obtaining an exception type corresponding to hardware exception trigger information, if the exception type is exception of a memory protection unit, obtaining information of a fault address recorded by a fault address register; if the exception type is breakpoint exception, inquiring information of a breakpoint address triggering the breakpoint exception; querying address information of the repair function from the vulnerability modification mapping table; obtaining a first vulnerability type of a vulnerability corresponding to the current abnormal condition, if the first vulnerability type is a function-level vulnerability, extracting a function parameter from a push register, and calling a repair function; if the first vulnerability type is an instruction-level vulnerability, analyzing a vulnerability instruction and calling a repair function; and executing the called repair function. The invention further provides a computer device and a readable storage medium for implementing the method. According to the method, bug repair is realized by multiplexing the original memory protection unit and the breakpoint module of the processor.
Owner:CORE TREND (ZHUHAI) TECH CO LTD

A secure starting method of MCU with fusion function safety

The application belongs to the chip security technical field, and particularly relates to a kind of MCU safety starting method of fusion function safety, by burning and verifying the security boot program and firmware program of main and redundant starting surface in factory environment, the safety and reliability of starting process are ensured.The security and reliability of starting process are ensured by burning and verifying the security boot program and firmware program of main and redundant starting surface in factory environment, and memory protection and privilege / user mode protection mechanism, reset counter fault detection mechanism and starting surface switching fault recovery logic are particularly emphasized, which effectively improves the security of system.The method solves the problem that CMAC check code cannot be dynamically updated in the prior art, while supporting clearing the corresponding hash value during firmware update, and realizing dynamic updating of trust chain.The application realizes the collaborative enhancement of functional safety and information security, and adapts to the ASIL-B and above grade functional safety requirements of vehicle-mounted MCU.
Owner:SHENZHEN ROADROVER TECH

Method and computing system capable of enhancing memory protection

This invention provides a method and computing system capable of enhancing memory protection related to the operating system kernel, thereby ensuring system security. The computing system provided by this invention may include: a processor configured to execute a guest virtual machine (VM), wherein an operating system (OS) runs on the guest VM, and an application (APP) runs on the OS. The kernel of the OS includes: a protection service module configured to receive at least one virtual address and first size information sent by a client of the APP; and a memory management unit (MMU) manager. The computing system further includes a virtual machine manager configured to receive the at least one virtual address and the first size information sent by the protection service module. The computing system also includes a host VM, which includes: a protection manager configured to receive and obtain a physical address array and second size information based on the at least one virtual address and the first size information to protect memory allocated by the kernel of the OS.
Owner:MEDIATEK INC

A memory protection unit, an electronic device, and an access monitoring method

The present application discloses a memory protection unit, an electronic device, and an access monitoring method, relating to the technical field of access control. The memory protection unit is configured to receive an access signal sent by an access unit when the access unit needs to access memory; after determining that the main controller in the access unit has valid access and determining that the access unit is restricted from accessing memory based on the access signal sent by the access unit, send a bus exception signal to the main controller, so that the main controller performs exception access processing after receiving the bus exception signal. Since the bus exception signal is not affected by the interrupt enable and the interrupt signal, the main controller can quickly receive the bus exception signal; the time delay from when the main controller receives the bus exception signal to when it enters the bus exception handling program is short, so as to perform exception access processing in a timely manner.
Owner:ACTIONS ZHUHAI TECH CO

Enforcement of attestation of read-only protected memory during attestation validity period

Enforcing attestation of read-only protected memory during attestation validity period. A client computer system identifies a change in a read-only protected memory protection status for a software component loaded at the client computer system. The client computer system then determines that a validity time period of an attestation report is unexpired. The attestation report comprises one or more attested properties, including one or more read-only memory protection (ROMP) attested properties for the software component. The client computer system also determines that at least one ROMP attested property for the software component is no longer valid due to the change in the read-only protected memory protection status for a software component. Based on the at least one ROMP attested property for the software component being no longer valid, the client computer system initiates a remedial action to prevent interaction of the software component with a relying party computer system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Physical memory protection table item screening device, processor and method

The invention discloses a physical memory protection table item screening device, a processor and a method, and belongs to the technical field of computers. A matching module in the physical memory protection table item screening device is configured to judge whether a physical address carried by an access request is within a memory area address range defined by each of a plurality of PMP table items or not according to an address matching mode so as to determine at least one matched PMP table item matched with the physical address; the screening module is configured to screen out a target PMP table item with the minimum corresponding memory area address range from the matched PMP table items when at least one matched PMP table item exists, and the target PMP table item is used for checking the operation authority of the access request. By taking the PMP table item with the minimum corresponding memory area address range in the plurality of PMP table items as the target PMP table item, the permission error under the condition of area overlapping of the PMP table items is effectively avoided.
Owner:BEIJING ESWIN COMPUTING TECH CO LTD

Sandbox-based electric power agent process isolation protection method and system

The invention discloses a sandbox-based electric power agent process isolation protection method and system, and relates to the technical field of electric power agent process isolation protection, and the method comprises the following steps: obtaining power frequency time sequence data of an electric power system, extracting a frequency fluctuation curve to construct a first query sequence, screening the sequence through a DTW algorithm, and obtaining a reference sequence; frequency feature vectors are constructed for Fourier transform, and a granularity matrix is generated; inputting the granularity matrix into a multi-objective optimization function, and evaluating the memory allocation granularity by adopting an NSGA-III algorithm; dividing a process memory space into a plurality of isolation regions according to an evaluation result, and optimizing the memory capacity of each region by using a quantum annealing algorithm to obtain an optimal capacity; and deploying the optimal capacity to a memory protection unit to form an isolation barrier, and integrating the isolation barrier to a sandbox to realize security isolation. According to the method, the problem that the memory allocation granularity and capacity are not matched in the traditional process isolation is solved, and the problems of micro-granularity memory attacks such as cross-region access and cache injection are avoided.
Owner:HEFEI D2S INFORMATION TECH CO LTD