Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

68 results about "Memory safety" patented technology

Memory safety is the state of being protected from various software bugs and security vulnerabilities when dealing with memory access, such as buffer overflows and dangling pointers. For example, Java is said to be memory-safe because its runtime error detection checks array bounds and pointer dereferences. In contrast, C and C++ allow arbitrary pointer arithmetic with pointers implemented as direct memory addresses with no provision for bounds checking, and thus are termed memory-unsafe.

AI large model security all-in-one machine and security channel establishment method and device

The invention discloses an AI large model security all-in-one machine and a security channel establishment method and device, and relates to the technical field of multi-party security computing. The AI large model security all-in-one machine comprises a security processor and a physical memory module; the security all-in-one machine is provided with a plurality of trusted execution environments (TEE), different TEEs have different secret keys used for memory encryption and decryption and serve as memory secret keys, the memory secret keys of the TEEs are generated by a memory encryption module of a security processor based on a hardware trusted root of the security processor, and different memory spaces which are independently used are distributed to different TEEs on a physical memory module; an AI large model application is installed on each TEE, and data generated by the AI large model application is encrypted, written and decrypted and read in the memory space allocated for the TEE by the memory security module by using the memory key corresponding to the TEE. By adopting the scheme, the data security for localized deployment of the AI large model is improved.
Owner:HUAKONG TSINGJIAO INFORMATION SCI BEIJING LTD

Automatic memory protection method and device, computer equipment and storage medium

The invention relates to an automatic memory protection method and device, computer equipment and a storage medium, and the automatic memory protection method comprises the steps: responding to a real-time memory read-write instruction, and determining a target memory address corresponding to the memory read-write instruction; determining a pre-stored tag value corresponding to the target memory address and an actual tag value currently embedded in a memory block pointed by the target memory address; and when it is detected that the pre-stored tag value is not matched with the actual tag value, stopping a memory operation associated with the memory read-write instruction. Through the method and the device, the problem that the data-oriented attack cannot be effectively prevented is solved, the data-oriented attack is effectively prevented, and the memory security and the system operation efficiency are improved.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1

Computer systems, methods, and devices for analyzing exploitability of memory safety vulnerabilities

The present disclosure provides a method for analyzing exploitability of memory safety vulnerabilities in binary programs. The method includes identifying potential vulnerabilities within a binary program, performing a baseline analysis to detect potential Return-Oriented Programming (ROP) chains, applying a memory safety mitigation technology to the binary program, performing a protected analysis after applying the memory safety mitigation technology to detect potential ROP chains, comparing results of the baseline analysis and the protected analysis, and generating a report quantifying an impact of the memory safety mitigation technology on exploitability of the identified vulnerabilities. The method enables assessment of the effectiveness of memory safety mitigation techniques in reducing the risk of exploitation, providing valuable insights for improving software security throughout the development lifecycle.
Owner:RUNSAFE SECURITY INC

Software and hardware combined fine-grained memory protection mechanism

The invention relates to a software and hardware combined fine-grained memory protection mechanism, which realizes high-speed mapping from a physical address to a fine-grained permission label by integrating a metadata search unit and a metadata conversion lookup buffer on a critical path of a processor loading / storage unit. An operating system maintains a multi-level fine-grained permission metadata table in a main memory, and the minimum memory protection granularity is refined to a 64-byte sub-page level. When a processor executes a memory access instruction, address conversion and permission verification are completed in parallel, an access type and a permission label are compared in real time within 1-2 clock periods, and when permission conflicts are detected, high-priority abnormity is triggered immediately, and illegal addresses and fault types are reported accurately. The method supports instruction set extension, buffer overflow protection, multi-level metadata management and user mode and kernel mode differentiated authority control, reduces the influence on the performance of the processor while improving the security of the memory, and is suitable for a computing system with high security and high performance.
Owner:SHAOXIN LABORATORY

Tag-non-preserving write operation

An apparatus includes memory access type determining circuitry to: determine whether a given write operation specifying a target address is to be a tag-non-preserving write operation; and memory access circuitry to: trigger, in response to determining that the given write operation is to be the tag-non-preserving write operation, a memory system to process the tag-non-preserving write operation specifying the target address, the tag-non-preserving write operation indicating that, following completion of the tag-non-preserving write operation, the memory system is not required to preserve a current value of a memory safety check tag associated with the target address.
Owner:ARM LTD

Memory safety self-checking circuit and method, chip and memory safety circuit

The embodiment of the invention discloses a memory security self-checking circuit and method, a chip and a memory security circuit. The memory security self-checking circuit comprises a random number generator, a random address generation module, a first address output selector, a first memory, a second memory, a self-checking module and a decryption circuit, the output end of the random number generator is connected with the first input end of the random address generation module, and the output end of the random address generation module is connected with the first input end of the first address output selector; the output end of the first address output selector is connected with the input end of the first memory and the input end of the second memory; the output end of the first memory is connected with the input end of the self-checking module, and the output end of the self-checking module is used for providing a result flag bit obtained by checking the self-checking data for the control circuit; the output end of the second memory is connected with the input end of the decryption circuit. The security of the chip is improved, and important programs and data related to the chip are protected.
Owner:GUANGZHOU ZHONO ELECTRONICS TECH CO LTD

Method for driving interrupt controller based on rust language

The invention relates to the technical field of underlying software of a computer system, in particular to an interrupt controller driving method based on a rust language, which comprises the steps of unified hardware abstract interface, strong type interrupt number management, thread safe interrupt distribution, multi-version GIC automatic identification, virtual interrupt mapping, multi-core load balancing and virtualization support. According to the method, a memory security mechanism and a type system of a Rust language are utilized, unified, safe and efficient driving of GICv2 / v3 / v4 under an Arm64 architecture is achieved, memory security defects in traditional C language driving are effectively eliminated, and system reliability and performance under a multi-core and virtualization scene are improved.
Owner:HUNAN ZETIAN ZHIHANG ELECTRONIC TECH CO LTD

Memory management method and apparatus

The application discloses a memory management method and device, relates to the technical field of heterogeneous computing, and comprises the following steps: obtaining a memory allocation request of a device, and searching for a page-locked memory block corresponding to the memory allocation request to allocate the memory block to the corresponding device; receiving a request for releasing the memory block, identifying a device computing flow associated with the memory block, and recording a synchronization event for each computing flow; storing the recorded synchronization event and metadata of the memory block in a to-be-processed event queue; querying whether an event in the to-be-processed event queue is completed; and when it is queried that a specific event is completed, recycling the corresponding memory block to an idle memory pool, so that the technical problem that in the related art, high-cost memory management function calls are too frequent, performance is low, and it is difficult to cooperate with device asynchronous operation, and data competition and errors are easily caused is solved, and the technical effect that the efficiency of memory allocation and the overall throughput of a system are greatly improved under the premise of ensuring memory safety is achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Hardware revocation engine for temporal memory safety

A hardware revocation engine for invalidating a pointer, that refers to a deallocated object, from memory in a memory constrained system. The hardware revocation engine has a revocation pipeline coupled to a pipeline of a main processor of the memory constrained system. The revocation pipeline shares access to memory with the main pipeline, the revocation pipeline comprising at least a first stage and a subsequent second stage. In a first cycle of the revocation pipeline, the first stage of the revocation pipeline loads a first pointer-sized value from the memory. In a second cycle: the second stage checks whether the first loaded pointer-sized value is a pointer referring to deallocated memory. In a third cycle: in response to the outcome of the check indicating that the first loaded pointer-sized value is a pointer referring to deallocated memory, the first stage invalidates the first pointer-sized value.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A method for mixed construction of Rust, C and assembly based on an embedded operating system

PendingCN122285007ATaking into account reuseTaking into account scalabilityEmbedded operating systemTerm memory
This invention relates to a hybrid Rust, C, and assembly code construction method based on an embedded operating system, belonging to the field of embedded operating systems. This invention utilizes Rust's External Function Interface (FFI) and the "staticlib" and "rlib" code classes supported by the Rust compiler to align the Rust library API with the APIs of the C and assembly libraries in the embedded operating system. This aligns the Rust code with the relocatable files that can be recognized by the embedded operating system, guiding the build system to link the Rust library with the C and assembly libraries to form the final embedded operating system executable file. This invention can link Rust components with C and assembly components to form a single executable file, fully utilizing Rust's type safety and memory safety features to improve the overall security and reliability of the system, while also considering the reuse and expansion of existing code libraries.
Owner:BEIJING INST OF COMP TECH & APPL

Memory security violation detection method and device, computer equipment and storage medium

The embodiment of the invention provides a memory security violation detection method and device, computer equipment and a storage medium. A magic number is inserted in advance for a red area and a released memory area in a memory allocated by each application program. The method comprises the following steps: determining whether a magic number is stored in a target memory object of a specified application program or not; the target memory object is a section of continuous memory in which memory security violation may occur in a heap region, a stack region or a global region; under the condition that the magic number is stored in the target memory object, determining whether the target memory object is accessible or not; and under the condition that the target memory object is inaccessible, determining that the memory security violation exists. The shadow memory class is not directly queried to determine whether the memory security is violated, but whether the magic number is stored in the target memory object is determined firstly, and whether the target memory object is accessible is determined only when the magic number exists, so that the extra runtime overhead during the running of the specified application program can be reduced, and the memory security of the specified application program is improved. And the resource utilization efficiency is improved.
Owner:SHENZHEN UNIV

Method, device and equipment for randomizing executable and linkable format file structure

The invention relates to the field of computers, and provides an executable linkable format file structure randomization method, device and equipment, and the method comprises the steps: converting an executable linkable format file into an LLVM intermediate representation document; performing structural body randomization processing on the LLVM intermediate representation document to obtain a randomized LLVM intermediate representation document; and recompiling the randomized LLVM intermediate representation document into a target file with a randomized structural body layout, and generating the target file into an executable and linkable format file through a link and outputting the executable and linkable format file. According to the method and the device, the problem that structural body internal storage layout randomization cannot be directly carried out on the binary executable file in the prior art is solved, automatic randomization processing is carried out on the structural body in the ELF file through LLVM intermediate representation under the condition that source codes are not needed, and the internal storage safety and the anti-attack capability of a program are enhanced.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Data processing apparatus with a revocation entity for temporal memory safety

Each memory location of a main memory (140) is associated with a respective tag bit indicating whether a respective value stored at the respective memory location is a pointer. A revocation entity (135) invalidates one or more pointers referring to one or more deallocated objects in the main memory. The revocation entity is arranged between a memory interconnect (130) and the main memory, and implements a revocation operation, comprising loading a value from a current memory location of the main memory, and overwriting the tag bit associated with the current memory location of the main memory, if the loaded value is a pointer referring to a deallocated object. The revocation entity detects store operations of a main processor (120) to the main memory and aborts the revocation operation, if during the revocation operation a store operation to the current memory location of the main memory is detected.
Owner:SCI SEMICONDUCTOR LTD

Hardware memory access control method, software isolation domain construction method and device

The application provides a hardware memory access control method, a software isolation domain construction method and equipment, and relates to the technical field of computer architecture and memory security. The method comprises the following steps: configuring a bit identifier for a memory page; configuring a running state bit identifier in a processor, wherein the running state bit identifier represents the authority level of a current execution context; when the processor executes a memory access operation, the hardware checks the relationship between the running state bit identifier and the bit identifier of a target memory page according to a preset lattice order rule to obtain a checking result; and when the checking result indicates that the authority of the running state bit identifier is higher than the authority of the bit identifier of the target memory page, the processor is allowed to access the target memory. Through real-time checking of the authority identifier based on the lattice order relationship by the hardware, efficient and scalable fine-grained memory access control is achieved.
Owner:TSINGHUA UNIVERSITY

Method for performing a dynamic memory safety analysis of a program containing specific sentences

The application relates to a method for performing memory safety dynamic analysis on a program containing specific sentences. The method comprises the following steps: selecting a project directory or a single source code file to be instrumented; preprocessing the source code, replacing macro calls with the content in the macro definition, and commenting out the original macro call; generating a symbol table and an abstract syntax tree of the source code by using a compiler; traversing all nodes in the abstract syntax tree, performing static analysis on the source code, and modifying the source code for sentences that cannot be processed, and then re-instrumenting the source code; traversing all nodes in the abstract syntax tree, performing different instrumentations on the source code according to different node types, compiling the instrumented project directory or file by using a compiler, generating an executable file on a target system, and running the executable file, performing memory error detection on the program containing specific sentences, and reporting the position of the source code corresponding to the error. The method avoids the problems of instrumentation failure and the failure of correctly compiling the program after instrumentation.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Communication method and device, computer readable storage medium and chip

The invention provides a communication method and device, a computer readable storage medium and a chip, and relates to the technical field of automatic driving. The communication method is applied to the computer system, the computer system comprises a first subsystem and a second subsystem, the security level of the first subsystem is higher than that of the second subsystem, the first subsystem comprises a memory access checker, and the method comprises the following steps: the memory access checker receives a memory access request from a memory access initiator, and determining whether the security level of the memory to be accessed by the memory access initiator is matched with the security level of the memory access initiator according to pre-configured memory security level division information, and allowing the memory access initiator to access the memory address when the security level of the memory address is matched with the security level of the memory access initiator. According to the method and the device, different subsystems of the computer system can be well isolated.
Owner:YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Hardware revocation engine for temporal memory safety

A hardware revocation engine for invalidating a pointer, that refers to a deallocated object, from memory in a memory constrained system. The hardware revocation engine has a revocation pipeline coupled to a pipeline of a main processor of the memory constrained system. The revocation pipeline shares access to memory with the main pipeline, the revocation pipeline comprising at least a first stage and a subsequent second stage. In a first cycle of the revocation pipeline, the first stage of the revocation pipeline loads a first pointer-sized value from the memory. In a second cycle: the second stage checks whether the first loaded pointer-sized value is a pointer referring to deallocated memory. In a third cycle: in response to the outcome of the check indicating that the first loaded pointer-sized value is a pointer referring to deallocated memory, the first stage invalidates the first pointer-sized value.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Memory safety management apparatus and method of operating system

The application relates to the technical field of memory management, in particular to a memory safety management device and method of an operating system. The device comprises a memory management module, a data safety module, an authority management module, a log system module and an exception processing module; when the memory management module allocates memory for a program, space record information is simultaneously allocated, including data verification information; after writing data is completed, the data safety module verifies the data of the whole memory to generate a unique signature of the data, and writes the signature into the data verification information; when accessing the memory data, the data safety module generates a unique signature of the memory data and compares the signature with the signature in the data verification information; if the signatures are consistent, the memory access can be normally carried out; if the signatures are inconsistent, the memory access is terminated, and the exception processing module is informed. The application can avoid abnormal memory access, solve the hidden danger of memory protection, avoid memory out-of-bound access and improve the safety of memory protection.
Owner:GUANGZHOU JINQILI INFORMATION TECH CO LTD

Cache component pointer analysis method based on static analysis

The invention discloses a method for analyzing a pointer of a swan Mongolia ArkTS cache component based on static analysis, which comprises the following steps of: screening AppStorage-related APIs (Application Program Interface) through three-address code semantic modeling, constructing a bidirectional synchronous strong connected component by adopting a reverse backflow edge, and blocking unidirectional synchronous reverse propagation based on freezing constraint, so as to achieve the purpose of analyzing the pointer of the swan Mongolia ArkTS cache component. And realizing cross-component data stream accurate tracking by combining a dynamic pointer assignment graph and an accessibility algorithm. According to the method, the false alarm rate of pointer analysis is reduced from 20% to 5%, the accuracy rate of memory leak detection reaches 98%, the analysis efficiency is improved by 40%-60%, the method is compatible with an OpenHarmony tool chain, and the problems of memory security and optimization under an ArkTS response type synchronization mechanism are solved.
Owner:BEIHANG UNIV

A program verification metadata export method and device and a deterministic execution environment

The application discloses a program verification metadata export method and device and a deterministic execution environment, and belongs to the field of compiling technology and formal verification. The method comprises the following steps: marking the pointer ownership state in the source code through attribute annotation; extracting the ownership conversion information and generating the structured metadata during compiling; and outputting the metadata to the special section of the compiling product, so that the memory safety of the program can be verified independently by directly reading the metadata by an external system. In order to make the exported metadata complete and inferable, a deterministic running environment composed of zero global state context, full-link memory management, capability token and deterministic execution suite is provided. In the application, specific attribute annotations in the source code are identified during the compiling process, the pointer ownership state conversion information and the function formal contract are generated into the structured metadata with a predefined binary format, and are written into the special metadata section of the target file (such as an ELF). In this way, the processing of the internal semantics of the program is changed from being internally digested and reformed by the compiler to being actively and standardized output to the external system, so that the technical obstacle that the program semantics information cannot be directly and reliably acquired by the external AI or verification tool is solved.
Owner:彭钟广

Lightweight pointer security method for preventing wild pointer in embedded software and corresponding system

The invention discloses a lightweight pointer security method for preventing a wild pointer by embedded software and a corresponding system, which are used for solving the problems of complex prevention and high overhead of the wild pointer in the prior art. The invention discloses a lightweight pointer safety method for preventing a wild pointer of embedded software. The method comprises the following steps: initializing a pointer registry when the embedded software is started; the pointer registry is used for storing a security pointer registry structural body, and the security pointer registry structural body comprises a 4-byte original pointer, a 1-byte pointer state and a 1-byte pointer permission; according to the pointer application, judging whether an unoccupied position exists in the pointer registry or not; if yes, allocating a memory, recording in the pointer registry, and meanwhile, returning a security pointer structure containing a 4-byte original pointer and a 2-byte registry index position; otherwise, returning an invalid security pointer structure. According to the lightweight solution for preventing the wild pointer in the embedded communication system, efficient memory security management is realized through pointer packaging and a registry mechanism.
Owner:THE 20TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORP

Operating system kernel design method and device based on trust domain extension

The invention discloses an operating system kernel design method and device based on trust domain extension, and the method comprises the steps: obtaining a Rust-TPM library and a Rust-IMA library which are constructed based on a Rust language, and reducing security vulnerabilities and improving the reliability of codes through the security attribute of Rust; according to the method, an Asterias-IMA kernel is obtained on the basis of a Rust-TPM (Trusted Platform Module) library and a Rust-IMA library, and security vulnerabilities can be effectively reduced by the system kernel realized through Rust; the kernel is deployed on the Intel trust domain extension to obtain the kernel based on the trust domain extension, and the security of the system is enhanced by means of the isolation effect of the Intel trust domain extension. According to the method, the integrity measurement architecture function is realized again by utilizing the memory security characteristics of Rust and trust domain extension, so that the security of an operating system is greatly improved.
Owner:SOUTHERN UNIVERSITY OF SCIENCE AND TECHNOLOGY

A program detection method, system and electronic device

An embodiment of the present invention provides a program detection method, system and electronic device. The method includes: parsing the source code of a target program based on a package manager to determine an intermediate intermediate representation corresponding to the source code; analyzing the intermediate intermediate representation to construct a control flow graph; performing fixed-point iteration analysis on the target program based on the control flow graph to determine state data corresponding to each function in the target program, and integrating the state data into global data; performing at least one of memory safety detection, concurrent safety detection and numerical safety detection on the global data, and generating a detection result. The embodiments of the present invention can improve the detection efficiency of Rust programs, reduce the false positive rate, and improve the detection accuracy.
Owner:LOONGSON TECH CORP

Physical memory protection method, electronic device, computer readable medium and computer program product

PendingCN122634677APhysical addressTerm memory
The present disclosure provides a physical memory protection method, an electronic device, a computer readable medium and a computer program product. The method is applied to an MMU lookup unit. In an address conversion process, a page table mapping granularity determined by a page table check and a security protection granularity determined by a security check are obtained. In response to the security protection granularity being smaller than the page table mapping granularity, a first valid page size is set as the security protection granularity, and a downgrade flag is generated. A first address mapping relationship including the downgrade flag is generated, and the first address mapping relationship is stored in an MMU storage unit. The downgrade flag is used to trigger a security check on a memory access request based on the security protection granularity when the memory access request hits an entry with the downgrade flag in the MMU storage unit. In the embodiment of the present disclosure, the physical address interval involved in each memory access can be subjected to a security check, eliminating the protection blind area caused by the mismatch of the granularity, and enhancing the memory security of the system.
Owner:BEIJING LIRUI MICROELECTRONICS TECHNOLOGY CO LTD

Hardware-assisted isolated execution of eBPF programs

ActiveCN119106415BKeep memory safeSolving pointer leaksPlatform integrity maintainanceProgram/content distribution protectionJust-in-time compilationSoftware engineering
This invention proposes a hardware-assisted isolated execution method for eBPF programs, comprising: acquiring the eBPF program to be executed; setting all data pages accessed in the eBPF program to non-privileged pages; issuing all memory access instructions in the eBPF program as non-privileged access instructions through just-in-time (JIT) compilation to obtain the program to be executed; running the program to be executed in kernel mode EL1 of the server operating system to obtain the execution result; and during the execution of the program to be executed, the non-memory access instructions in the program to be executed run at the kernel mode EL1 privilege level, and the memory access instructions in the program to be executed are non-privileged access instructions, which are run at the user mode EL0 non-privileged level. By setting the memory of the eBPF program to non-privileged pages, the eBPF program still runs at a privileged level, but is issued with non-privileged memory access instructions. Since the kernel memory is set to privileged pages, the eBPF program cannot access them, thereby ensuring kernel memory safety.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Marked memory conflict optimization method, device and equipment based on heap cluster randomization

The invention relates to the technical field of computer memory security, in particular to a heap cluster randomization-based marked memory conflict optimization method, device and equipment, and the method comprises the following steps: judging whether a heap cluster memory management requirement exists or not; if the heap cluster memory management requirement exists, performing layering processing on a plurality of preset heap cluster units based on a preset layering randomization memory layout strategy to obtain a current layering result; and based on the current layering result, according to a life cycle management strategy corresponding to the heap cluster memory management requirement, carrying out allocation operation, reuse operation or recovery operation on the plurality of heap cluster units. Therefore, through the heap cluster randomization layout and the hierarchical mark allocation strategy, the problems of probabilistic mark conflicts and the like existing in marked memory security protection in the related technology are solved, and the probabilistic detection capability of memory abnormal behaviors is improved.
Owner:WUHAN UNIV

Memory management method and device

The embodiment of the invention discloses a memory management method and device which are used for improving the memory utilization efficiency of a cloud platform. The method comprises the steps that the computing device receives a memory management request sent by a first entity, the memory management request is used for managing a secure memory, the secure memory is a memory area allocated to the trusted execution environment, and the first entity comprises a secure application program or a secure side part of the application program. And determining an idle secure memory based on the memory management request, the idle secure memory for expanding a memory space of a non-secure memory, the non-secure memory comprising a memory region allocated to a second entity for access, the second entity comprising a non-secure application or a non-secure side portion of the application. And responding to a memory access request corresponding to the second entity based on the idle secure memory.
Owner:HUAWEI TECH CO LTD +1