Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

40 results about "Privilege level" patented technology

A privilege level in the x86 instruction set controls the access of the program currently running on the processor to resources such as memory regions, I/O ports, and special instructions. There are 4 privilege levels ranging from 0 which is the most privileged, to 3 which is least privileged. Most modern operating systems use level 0 for the kernel/executive, and use level 3 for application programs. Any resource available to level n is also available to level 0..n, so the privilege levels are "rings". It is not necessary to use all four privilege levels. Existing software that was designed to use only one or two levels of privilege can simply ignore the other levels offered by the 80386 and later processors. A one-level system should use privilege level zero; a two-level system should use privilege levels zero and three. Here level zero is called the Supervisor mode while level three is User mode. All versions of Windows below Windows XP use only the two-level system. The real mode programs in 8086 are executed at level 0 whereas virtual mode in 8086 executes all programs at level 3.

Debugging system and debugging method of RISC-V architecture

The invention discloses a debugging system and a debugging method of an RISC-V architecture, and relates to the field of processor debugging, the debugging system comprises a debugging host, a transport layer interface, a debugging module, a debugging logic module in a processor core and a monitoring module, and all the components are in communication connection in sequence. According to the invention, by supporting an RV32 / RV64 double-word-length processor, being compatible with a U / S / M full privilege level operation mode and adapting to various mainstream open-source RISC-V cores and self-defined cores, compared with the existing scheme only supporting a single architecture variant, the method does not need to reconstruct debugging logic for different core types, reduces the core adaptation cost, does not need to customize a debugging instruction or a tool chain process, and has the advantages that the debugging efficiency is improved, and the debugging cost is reduced. Through the register and protocol standardization, the method has high compatibility, and the cross-platform debugging cost is reduced.
Owner:WUHAN COMPUTING ECOLOGY TECH CO LTD

Privilege level assignments to groups

According to examples, an apparatus may include a memory on which is stored machine-readable instructions that may cause a processor to determine, for each of a plurality of members in a group, a respective least privilege level for a resource and determine, based on the determined respective least privilege levels, a privilege level to be assigned to the group for the resource. The instructions may also cause the processor to assign the determined privilege level to the group for the resource and apply the assigned privilege level to the members of the group for the resource.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Memory preserved warm reset mechansim

An apparatus is disclosed. The apparatus comprises one or more processors to receive a request to trigger a system management interrupt (SMI), execute policy shim code to enforce access control policy in a first privilege level and dispatch the SMI to shield code to enforce the access security policy to perform a system management mode (SMM) and execute the shield code to perform the SMM, including retrieving an operating system (OS) memory preserved warm reset (MPWR) context, saving the context and issuing a warm reset.
Owner:INTEL CORP

ACCESS PERMISSIONS FOR STORAGE AREAS

A control unit (300) comprising the following: a control unit memory (120) with a configuration register (124) for defining an operating mode of the control unit (300) and a lock register (122) for storing a lock indicator, wherein, immediately after authorization information has been set during a system initialization event, the lock indicator in the lock register (122) is set to a value indicating whether at least part of the authorization information can be changed or not, and set up a controller (302) to: to receive a request for access to a first memory area of ​​a memory (308) from a request device (306) separate from the control unit (300); in response to the request to access authorization information, which contains a multitude of entries corresponding to different memory areas (110-1 to 110-n) of the memory (308), each entry of the multitude of entries comprising a multitude of indicators, the indicators comprising: a first indicator that can assume an active value, representing an execution access mode in which instructions are retrieved from the respective memory area for execution, a second indicator that can assume an active value representing a privileged access mode in which access to the respective memory area is permitted if the requester has a privileged level; and a third indicator representing a read or write mode on a memory area; and Based on the occurrence of the system initialization event and according to the metadata of the request and the authorization information, to determine whether access to the content in the first storage area is allowed.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and apparatus for constructing a permission topology structure based on least privilege

ActiveCN120850316BDigital data protectionOther databases indexingGraph operationsPublic interface
This application provides a method and apparatus for constructing a permission topology structure based on the lowest privilege level. The method includes: obtaining a non-public interface path template by structured parsing and classifying request data from an identity management platform and performing parameterized substitution; establishing a mapping relationship between the non-public interface path template and a preset identity management platform permission model to obtain a non-public interface parameter structure; merging the non-public interface parameter structure with an existing interface parameter structure to obtain a centralized interface parameter structure; under the lowest privilege role, starting from the initial node of the centralized interface parameter structure according to the task scheduling engine and graph operation model, performing a multi-hop breadth traversal along member relationships, role bindings, and permission operation paths to determine the corresponding permission graph; performing fine-grained dependency extraction on the permission graph; updating the permission graph according to the dependency relationships; and determining the corresponding permission topology structure. This application can improve the security and management efficiency of the identity and access management platform.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Timestamp synchronization method and apparatus across operating levels, chip, network interface card, device, medium and program product

The application relates to a timestamp synchronization method and device across running levels, a chip, a network interface card, equipment, a medium and a program product. The method comprises the following steps: obtaining a first value of a clock cycle count recorded by a system counter since system startup, wherein the same system counter is used by firmware and an application program running at different running levels; in the case that a timestamp synchronization completion flag exists in shared memory, obtaining a second value and a first local timestamp saved by the application program from the shared memory; and obtaining a second local timestamp based on the first value, the second value and the first local timestamp. The method can realize accurate timestamp synchronization of different privilege levels.
Owner:HANGZHOU YUNBAO CHUANGXIN INTELLIGENT TECHNOLOGY CO LTD +1

Master security device, operator device, client security device, operation authority setting method, computer-readable storage medium, and security system

To provide a master security device capable of setting operation authority including an access right without a password.SOLUTION: A master security device according to an embodiment comprises an input interface, a memory, a processor, and an output interface. The input interface inputs operator identification information associated with operator device identification information. The memory stores the operator identification information. The processor generates verifiable credentials including an operation permission level including access rights to a client security device and device identification information for the client security device. The output interface outputs the tombstones to the operator device based on the operator identification information.SELECTED DRAWING: Figure 1
Owner:KK TOSHIBA

Cross-running-level timestamp synchronization method and device, chip, network interface card, equipment, medium and program product

ActiveCN121193362ATime-division multiplexTimestampingPrivilege level
The invention relates to a cross-running-level timestamp synchronization method, a cross-running-level timestamp synchronization device, a chip, a network interface card, equipment, a medium and a program product. The method comprises the following steps: acquiring a first value recorded by a system counter and counted by a clock cycle started by a system, and operating firmware and an application program at different operating levels using the same system counter; under the condition that a timestamp synchronization completion mark exists in a shared memory, obtaining a second value and a first local timestamp saved by the application program from the shared memory; and obtaining a second local timestamp based on the first value, the second value and the first local timestamp. By adopting the method, accurate synchronization of timestamps of different privilege levels can be realized.
Owner:HANGZHOU YUNBAO CHUANGXIN INTELLIGENT TECHNOLOGY CO LTD +1

A Design Method for a RISC-V AIA Interrupt-Configured Multi-Privilege Level IMSIC Controller

PendingCN122132085ANext instruction address formationPrivilege levelHardware register
This invention discloses a design method for a RISC-V AIA interrupt-configurable multi-privilege-level IMSIC controller, comprising: setting a programmable configuration register MS_CUT_CFG in the IMSIC to dynamically allocate interrupt file resources for machine mode (M-mode) and supervisor mode (S-mode) at runtime; controlling the allocation ratio of the actual physical storage space of interrupt files in machine mode (M-mode) and supervisor mode (S-mode) through the configuration register MS_CUT_CFG to achieve dynamic reuse of interrupt file resources; physically sharing the same hardware register array for the interrupt enable register group (IE) and interrupt suspend register group (IP) of machine mode (M-mode) and supervisor mode (S-mode); and mapping suspended but executable interrupt requests to the corresponding privilege level and submitting them to the processor core through an interrupt arbitration circuit based on the current value of the configuration register. This invention overcomes the limitations of the static resource configuration strategy for IMSIC interrupt files, significantly enhancing the flexibility and dynamic scenario adaptability of RISC-V AIA interrupt applications.
Owner:NAT INNOVATION INST OF DEFENSE TECH PLA ACAD OF MILITARY SCI

Lightweight function running method and system for server-unaware computing scenarios

The application provides a lightweight function running method and system for a server-unaware computing scene, and the method comprises the following steps: providing a communication primitive for fast cold start of an isolated environment and high-performance intermediate data transmission; for a server-unaware function computing workflow scene, a runtime is provided as a new software stack architecture; the function and the underlying runtime relied by the function are all deployed in the same CPU privilege level and address space for cold start operation; a library operating system with a workflow granularity is used to provide underlying runtime services for the function, and a memory-safe language is used to provide memory isolation and sharing; and an on-demand loading mechanism is implemented for the library operating system. The application solves the technical problems of slow cold start of an isolated environment, poor intermediate data transmission performance, large cold start range and high cost, and poor flexibility of memory isolation and sharing.
Owner:THE ACAD OF TIANJIN UNIV HEFEI

Virtual machine running system, method, processor and electronic device

This disclosure provides a virtual machine runtime system, method, processor, and electronic device, relating to the field of virtual machine technology. The system includes: a virtual machine monitor, which runs at a first exception level and is used to create virtual machines using a virtualization environment provided by a microkernel, and to handle interrupt events associated with the virtual machines according to notifications from the microkernel; a virtual machine, which runs at a second exception level; and a microkernel, which runs at a third exception level and is used to provide the necessary virtualization environment for the virtual machine monitor to create the virtual machines, and to intercept interrupt events associated with the virtual machines and notify the virtual machine monitor to handle the interrupt events; the privilege levels of the first exception level, the second exception level, and the third exception level increase sequentially. This disclosure aims to solve the problems of centralized privileges and high resource consumption in existing virtual machine runtime systems.
Owner:PHYTIUM TECH CO LTD

Agent Transition Allowability Based on Current Privilege Level

A processor circuit is configured to receive, while a current software agent is executing in a current execution mode, an indication of an execution mode transition that attempts to change an execution mode index from a current value indicative of the current execution mode to a new value indicative of a new execution mode. The processor circuit is configured to access, based on the current privilege level, particular execution mode transition information in a storage circuit to determine whether the execution mode transition is allowed. The processor circuit is configured to determine, based on particular execution mode transition information, whether to update the current value indicative of the current execution mode. The processor is further configured to update the current value indicative of the current execution mode based on a determination that the execution mode transition is permitted.
Owner:APPLE INC

System and methods for Input / Output device emulation

A system is disclosed for Input / Output (I / O) device emulation that allows a service provider to configure and enforce a policy for software access to some or all I / O resources in a platform. I / O device emulation enables service providers to protect their platforms from malicious guest software that may be executed on associated platforms that has direct access to I / O resources in case of bare-metal servers, escalates the privilege level from guest to host in case of hosted-Virtual Machine servers, or escalates the privilege level from guest to System Management Mode in case of either bare-metal servers or hosted-Virtual Machine servers. The technology enables service providers to protect their platforms from malicious guest software running on their platforms that either has direct access to legacy I / O and memory mapped I / O resources. In one illustrative example, the platform may include a microprocessor.
Owner:SDG LOGIC INC

Method and system for executing security critical applications

A method of executing a security critical application (150) on a hardware platform (100) is presented. The method comprises: executing a virtual machine monitoring program (120) having a monitoring component (130) for a security critical application (150) on a hardware platform (100); instantiating at least one virtual machine (140) by a privilege level of the virtual machine monitoring program (120) hardware platform that is lower than the privilege level of the virtual machine monitoring program (120); a list of one or more predefined actions is provided that, when executed by the processor core (112a, 112b), have relevance to the integrity and / or operation of the safety critical application (150). The method further comprises instructing, by the virtual machine monitoring program (120), the processor core (112a, 112b) to divert the control flow towards a respective handler (132) in the monitoring component (130) for the action to be performed when the action to be performed is about to be performed on the list; and executing at least the security critical application (150) over the guest operating system (142) in the at least one virtual machine (140). Further, a check of whether the action is allowed or not allowed may be performed, and / or at least one preparation for the action to be performed may be performed.
Owner:ELEKTROBIT AUTOMOTIVE GMBH

A system call method and apparatus

A system call method and device, the method comprising: a kernel of a first virtual machine receiving an interrupt instruction of a first process, the first process running in a user space of a second virtual machine, the kernel of the first virtual machine running in a kernel space of the second virtual machine, the second virtual machine being configured to provide a running environment of the first virtual machine, at this time, a CPU switching from a user state to a kernel state; the kernel of the first virtual machine mapping a first address associated with the interrupt instruction to a second address, the kernel of the first virtual machine executing the interrupt instruction based on the second address, obtaining an interrupt processing result, and sending the interrupt processing result to the first process, at this time, the CPU switching from the kernel state to the user state. Therefore, in the process of the first virtual machine calling the system, the CPU only needs to switch between the kernel state and the user state twice, thereby reducing the privilege level overhead, the context switching overhead, and the resource consumption of the CPU.
Owner:HUAWEI TECH CO LTD

System and methods for input / output device emulation

PendingUS20260086834A1Software simulation/interpretation/emulationOutput deviceSystem Management Mode
A system is disclosed for Input / Output (I / O) device emulation that allows a service provider to configure and enforce a policy for software access to some or all I / O resources in a platform. I / O device emulation enables service providers to protect their platforms from malicious guest software that may be executed on associated platforms that has direct access to I / O resources in case of bare-metal servers, escalates the privilege level from guest to host in case of hosted-Virtual Machine servers, or escalates the privilege level from guest to System Management Mode in case of either bare-metal servers or hosted-Virtual Machine servers. The technology enables service providers to protect their platforms from malicious guest software running on their platforms that either has direct access to legacy I / O and memory mapped I / O resources. In one illustrative example, the platform may include a microprocessor.
Owner:SDG LOGIC INC

HyperVHE virtual machine system and method based on ZVM

The invention relates to the technical field of virtual machines, and particularly discloses a HyperVHE virtual machine system based on a ZVM, which runs on an ARM processor and comprises a host operating system running at an EL2 privilege level; the ZVM runs at an EL2 privilege level, cooperatively runs with the host operating system at the same level, shares control authority, and realizes distribution and management of resources and interrupts through a predefined interface; the at least one guest operating system runs at an EL1 privilege level, and access control, memory isolation and interrupt forwarding of the guest operating system are taken over by the ZVM; wherein the kernel of the host operating system is subjected to EL2 privilege level transformation. By adopting the technical scheme of the invention, the system can run in an ARMv8.0 architecture, and has the advantages of higher real-time performance and light weight.
Owner:HUNAN UNIV

Hardware-assisted isolated execution of eBPF programs

ActiveCN119106415BKeep memory safeSolving pointer leaksPlatform integrity maintainanceProgram/content distribution protectionJust-in-time compilationSoftware engineering
This invention proposes a hardware-assisted isolated execution method for eBPF programs, comprising: acquiring the eBPF program to be executed; setting all data pages accessed in the eBPF program to non-privileged pages; issuing all memory access instructions in the eBPF program as non-privileged access instructions through just-in-time (JIT) compilation to obtain the program to be executed; running the program to be executed in kernel mode EL1 of the server operating system to obtain the execution result; and during the execution of the program to be executed, the non-memory access instructions in the program to be executed run at the kernel mode EL1 privilege level, and the memory access instructions in the program to be executed are non-privileged access instructions, which are run at the user mode EL0 non-privileged level. By setting the memory of the eBPF program to non-privileged pages, the eBPF program still runs at a privileged level, but is issued with non-privileged memory access instructions. Since the kernel memory is set to privileged pages, the eBPF program cannot access them, thereby ensuring kernel memory safety.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Mechanism to limit out-of-compliance intra-die communication

PendingUS20260187260A1Computer networkEngineering
An apparatus, method and system to implement a mechanism to limit out-of-compliance intra-die communication. A receiver receives a packet directed to a component on a die or a package containing the die. A logic circuit evaluates attributes of the packet based on a number of criteria and a privilege level associated with the component that is a target of the packet, wherein the logic circuit is to: when the attributes of the packet meet the number of criteria, evaluate a packet privilege level to access the component to the privilege level associated with the component and grant, substitute or downgrade the packet privilege level to access the component; and when one or more attributes of the packet does not meet the number of criteria, reject the packet.
Owner:INTEL CORP

Memory Dump using Hardware Security Mechanism

A device includes multiple registers, multiple hardware-implemented Privilege Level Indicators (PLIs), and one or more circuits. The registers are to store respective values. The PLIs are to specify privilege levels for accessing the respective registers. The one or more circuits are to perform a secure memory dump operation including (i) checking the PLIs of one or more of the registers and (ii) outputting the values of the registers that are permitted for outputting according to the respective PLIs.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Method and system for executing security critical applications

A method of executing a security critical application (130) on a hardware platform (100) is proposed. The method comprises: executing a virtual machine hypervisor (115) on the hardware platform (100); instantiating an execution environment (120) by the virtual machine hypervisor (115); executing an operating system having a kernel (125, 125a) in the execution environment (120); executing, in an execution environment (120), the security critical application (130) on the operating system at a privilege level that is lower than a privilege level of the kernel (125, 125a); executing system call instructions of the kernel (125, 125a) by the security-critical application (130), the system call instructions transferring a control flow to a primary handler (127) in the kernel (125, 125a) for the purpose of calling functions provided by the kernel (125, 125a) by a specific intended system call; further transferring, by the processor core (112a, 112b), the control flow to a secondary processing program (119) in the virtual machine hypervisor (115); passing, by the secondary handler (119), the intended system call to a supervisory component (150); and checking, by the supervision component (150), the operation to be performed by the intended system call against a predetermined set of rules in order to allow or disallow the system call.
Owner:ELEKTROBIT AUTOMOTIVE GMBH

Multicore architecture and virtual machines

A computer system having a multi-kernel architecture comprising multiple operating system microkernels is described. The computer system comprises multiple processing cores, a memory comprising multiple private memory regions and a shared memory region, and multiple compute nodes each comprising one or more processing cores and further comprising one of the multiple operating system microkernels and an associated user space for non-kernel operations, wherein only the operating system microkernels run at the highest privilege level of the one or more processing cores of the compute nodes. Each of the multiple compute nodes has an associated private memory region from the multiple private memory regions for use by the operating system microkernel of the each of the multiple compute nodes, and for non-kernel operations, each of the multiple compute nodes accesses the shared memory region. Associated methods and computer systems are also described.
Owner:NEUTRAL LLC

Apparatus and method for protecting shared objects

An apparatus is provided for protecting the privacy of shared objects and helping to prevent the loss of these software assets by loading the shared objects into the user memory of a trusted execution environment. The shared objects have encrypted segments and metadata. A decryption request is sent to the trusted execution environment, and the encrypted segments are decrypted based on the metadata and a predetermined platform key to produce a decrypted segment. The decrypted segment is written to the shared object. A request to lock the shared object is sent, locking or setting the memory occupied by the shared object to execution-only. The locking of the memory region occupied by the decrypted shared object maps the memory region to be unreadable and unwritable by all applications executing at a first privilege level and by the operating system kernel executing at a second privilege level.
Owner:HUAWEI TECH CO LTD

A method and system for building a virtual machine monitor secure execution environment

The application discloses a virtual machine monitor security execution environment construction method and system. The method is as follows: removing the host OS and virtual machine monitor runtime code from the trusted computing base TCB, and constructing a simple security monitor on the CPU privilege level of the host; removing the privilege permission of the host OS to obtain a reduced-privilege host OS; using the simple security monitor to instantiate a Bid-Enclave instance for each virtual machine on the host to carry the virtual machine monitor runtime; and executing a bidirectional isolation strategy between the reduced-privilege host OS and the instance and between different instances; dividing I / O processing into a control plane and a data plane; using the reduced-privilege host OS to process the control plane and auditing by the simple security monitor; and under the supervision of the simple security monitor, establishing a protected direct memory access channel between the instance and a PCIe SR-IOV virtual function or an analog device queue to access the data plane.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Integrated-circuit memory dump using hardware security mechanism

A device includes multiple registers, multiple hardware-implemented Privilege Level Indicators (PLIs), and one or more circuits. The registers are to store respective values. The PLIs are to specify privilege levels for accessing the respective registers. The one or more circuits are to perform a secure memory dump operation including (i) checking the PLIs of one or more of the registers and (ii) outputting the values of the registers that are permitted for outputting according to the respective PLIs.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Method and system for executing a safety-critical application

A method of executing a safety-critical application (150) on a hardware platform (100) is proposed. The method includes executing, on the hardware platform (100), a hypervisor (120) with a monitoring component (130) for the safety-critical application (150), instantiating, by the hypervisor (120), at least one virtual machine (140) on a lower privilege level of the hardware platform than a privilege level of the hypervisor (120), providing a list of one or more predefined actions that, when executed by the processor core (112a, 112b), have a relevancy for an integrity and / or a functioning of the safety-critical application (150). The method further includes instructing, by the hypervisor (120), the processor core (112a, 112b) to when about to execute a to-be-performed action on the list, divert the control flow towards a respective handler (132) for this to-be-performed action in the monitoring component (130), and executing, in the at least one virtual machine (140), at least the safety-critical application (150) on top of a guest operating system (142). Further, a check whether to allow or disallow the action can be performed and / or at least one preparation for the to-be-performed action may be performed.
Owner:ELEKTROBIT AUTOMOTIVE GMBH

Technologies for object-oriented memory management with extended segmentation

Technologies for memory management with memory protection extension include a computing device having a processor with one or more protection extensions. The processor may load a logical address including a segment base, effective limit, and effective address and generate a linear address as a function of the logical address with the effective limit as a mask. The processor may switch to a new task described by a task state segment extension. The task state extension may specify a low-latency segmentation mode. The processor may prohibit access to a descriptor in a local descriptor table with a descriptor privilege level lower than the current privilege level of the processor. The computing device may load a secure enclave using secure enclave support of the processor. The secure enclave may load an unsandbox and a sandboxed application in a user privilege level of the processor. Other embodiments are described and claimed.
Owner:INTEL CORP

Apparatus and method for fine-grained user mode control of read performance monitor counters

Apparatus and methods for fine-grained user mode control of read performance monitor counters are disclosed. An apparatus for managing access to a performance counter. For example, one embodiment of a processor includes a plurality of cores to execute first program code at a first privilege level and second program code at a second privilege level higher than the first privilege level, a core of the plurality of cores including a performance monitoring circuit including a plurality of performance counter control registers, the plurality of performance counters are used for indicating events to be counted by the corresponding plurality of performance counters; and a processor control register to store a global control value to indicate whether the first program code is permitted to read values from the corresponding plurality of performance counters; wherein each performance counter control register is to store a counter-by-counter control value to indicate whether a first program code executing at a first privilege level is permitted to read a corresponding value from a respective performance counter regardless of the global control value.
Owner:INTEL CORP

Apparatus and method for fine grain user mode control for reading performance monitor counters

An apparatus for managing access to performance counters. one embodiment of a processor comprises: a plurality of cores to execute first program code at a first privilege level and second program code at a second privilege level higher than the first privilege level, a core of the plurality of cores comprising: performance monitoring circuitry including a plurality of performance counter control registers to indicate events to be counted by a corresponding plurality of performance counters; and a processor control register to store a global control value to indicate whether the first program code is permitted to read values from the corresponding plurality of performance counters; wherein each performance counter control register is to store a per-counter control value to indicate whether the first program code executed at the first privilege level is permitted to read a corresponding value from a respective performance counter, regardless of the global control value.
Owner:INTEL CORP

Execution mode transition allowability based on current privilege level

A processor circuit is configured to receive, while a current software agent is executing in a current execution mode, an indication of an execution mode transition that attempts to change an execution mode index from a current value indicative of the current execution mode to a new value indicative of a new execution mode. The processor circuit is configured to access, based on the current privilege level, particular execution mode transition information in a storage circuit to determine whether the execution mode transition is allowed. The processor circuit is configured to determine, based on particular execution mode transition information, whether to update the current value indicative of the current execution mode. The processor is further configured to update the current value indicative of the current execution mode based on a determination that the execution mode transition is permitted.
Owner:APPLE INC +1