Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

104 results about "User space" patented technology

A modern computer operating system usually segregates virtual memory into kernel space and user space. Primarily, this separation serves to provide memory protection and hardware protection from malicious or errant software behaviour.

Linux access control system based on attributes

The invention provides a Linux access control system based on attributes, and relates to the technical field of data access control. The system comprises a system monitor module, a data interaction module and a decision unit. The system monitor module collects attributes from a kernel and a user space and writes the attributes into the data interaction module; the access decision unit compiles the access control strategy into an eBPF program and mounts the eBPF program to a corresponding hook; executing the kernel to the hook, and triggering an eBPF program; an eBPF program queries a Flow rule; matching the attribute with the Flow rule, and if the matching is successful, executing a corresponding action; if all the Flow rules fail to match, executing a default action; the system can be expanded during operation, and can be loaded or unloaded based on dynamic loading characteristics and strategies of the eBPF program and the eBPF program during operation of the system, so that the problem that a kernel needs to be compiled in a traditional LSM scheme is solved; the method does not intrude the kernel, is completely based on an eBPF program, does not modify a kernel source code, and can guarantee the stability and compatibility.
Owner:SICHUAN UNIV

Process interception method and device and electronic equipment

The embodiment of the invention provides a process interception method and device and electronic equipment. The method comprises the following steps: a kernel space receives a process protection list sent by a user space by utilizing a virtual file system interface; wherein the process protection list comprises a process identifier of at least one to-be-protected process; the kernel space obtains a process termination request; wherein the process termination request is used for requesting to terminate a target process, and the target process is a process entity scheduled by an operating system; under the condition that the kernel space determines that the request type of the process termination request is a preset request, determining a matching relationship between the target process and a process protection list based on a target process identifier of the target process; and when the matching relationship indicates that the process identifier of the at least one to-be-protected process in the process protection list comprises the target process identifier, the kernel space intercepts the process termination request. By the adoption of the method, the important process can be effectively prevented from being terminated due to malicious or misoperation, and the safety and stability of the system are improved.
Owner:XFUSION DIGITAL TECH CO LTD

RPA mouse and keyboard control method and system for Wayland desktop

The invention belongs to the technical field of computer man-machine interaction and automatic control, and particularly relates to an RPA mouse and keyboard control method and system for a Wayland desktop. The method comprises the following steps: S1, creating and registering a virtual input device supporting mouse and keyboard functions in a user space by accessing a virtual input device interface provided by an operating system kernel; s2, current activity display output is detected, and screen resolution information is obtained; s3, the server program monitors a preset local Unix domain socket path for receiving a control instruction from the client; s4, the client sends a control request to the local Unix domain socket path in a structured format, and the server receives and analyzes the control request; s5, the server side maps the analyzed control request into a corresponding kernel input event sequence according to the operation type; meanwhile, by writing event data into the virtual input device, an input event is injected into the system so as to simulate a control operation on the graphic desktop.
Owner:浙江实在智能科技有限公司

Real-time data transfer scheme from limited power embedded systems

Distributed fiber optic sensing (DFOS) / distributed acoustic sensing (DAS) that illustrate inventive techniques—applicable to all embedded systems—that deliver high-bandwidth traffic from a DFOS system to a cloud or other processing resources in real-time, employ firmware that operates at a register-transfer level and writes data repeatedly into the embedded host memory directly—without software intervention after initial configuration. This technique advantageously enables the use of the relatively large host memory to compensate for any software jitter. Preferably configured, the firmware employs only a small buffer to compensate for a transaction and host-memory arbitration latency. A second dedicated thread sends out data from the user space buffer to a cloud, or a connected server. Remote procedures that are executed on a remote system (a computer, network of computers, or cloud), receive data transmitted from the embedded system, and perform further processing as necessary.
Owner:NEC LABORATORIES AMERICA INC

Kernel-level heterogeneous collaborative AI reasoning method, device and equipment and storage medium

The invention discloses a kernel-level heterogeneous collaborative AI reasoning method and device, equipment and a storage medium, and relates to the field of AI reasoning acceleration. When the KDS receives a reasoning request submitted by a user space, generating a cross-device plan list according to a global system resource state and issuing the cross-device plan list to the HCEE; the HCEE drives the corresponding target execution equipment according to the task execution sequence, reads the data information from the UCMP, or restores intermediate / result data reasoned and output by the target execution equipment; after reasoning of the plan list is completed, the kernel space triggers an event notification mechanism, and a user process of the user space is awakened; and the user process directly reads the reasoning result from the UCMP. According to the scheme, deep collaboration of task scheduling, memory management and equipment execution is realized on a Linux kernel level, the problems of high overhead, resource islands, memory redundant copy, extensive scheduling granularity and the like of a user mode reasoning framework system are solved, and end-to-end low-delay, high-throughput and high-energy-efficiency AI reasoning acceleration is realized.
Owner:STORAGEX TECH INC +1

User-space parallel access channel for traditional filesystem using CAPI technology

User process to directly access a file in a file system. A user process first opens a file in the file system for access. In the process of opening the file, a file handle for the file is returned to the user process by an operating system kernel. The user process then makes a read request to a special function unit for one or more blocks of the file in the file system using the file handle. In response, the special function unit, which is coupled to the processor, bypasses the operating system kernel and returns the requested data directly to the user process. A write by the user process may be refused by the computer system or allowed on a selective basis based on a flag in a file system inode corresponding to the block.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Track user linking method and device based on graph edge weight optimization and storage medium

The invention relates to the technical field of trajectory data mining and identity recognition, in particular to a trajectory user linking method and device based on graph edge weight optimization and a storage medium. The model is composed of a local graph representation learning module fused with grid semantics, a global relation graph representation learning module of adaptive edge weight, a layered space-time attention network and a track user link module. The method comprises the following steps: carrying out gridding processing on an anonymous track, extracting hierarchical semantic embedding of POI categories, and constructing a local space graph and a global relation graph; introducing a semantic consistency coefficient into the local graph to re-calibrate an edge weight, and dynamically modeling an interaction relationship between tracks and between users and tracks in the global graph through a self-adaptive edge weight learning mechanism; fusing local space-time features and global interaction representation through a layered space-time attention network; and finally, the features are projected to the user space for matching, so that the accuracy and robustness of the track user link are remarkably improved.
Owner:CHINA UNIV OF MINING & TECH

Method for monitoring and enforcing secure policies in a device

A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

Product personalized recommendation method and system based on multi-source data fusion

The invention discloses a product personalized recommendation method and system based on multi-source data fusion. The method comprises the following steps: acquiring multi-dimensional behavior data of a user, associating financial product attributes with user spatio-temporal characteristics to construct a product association map, fusing multi-source semantic information, and performing noise elimination to generate a unified semantic vector; after reaching the standard, extracting time sequence interaction information to construct a deep customization preference vector, analyzing a sub-graph semantic coincidence degree to obtain semantic analysis strength, and generating a cross-scene association path identification potential preference point set; screening the core preference subsets to obtain a recommendation list, and matching the user motivation components to determine a final recommendation result. According to the method, accurate personalized recommendation driven by multi-source data can be realized, and high-quality recommendation requirements of deep customization and cross-scene adaptation in a complex scene are met.
Owner:SUZHOU ZHONGDIHANG INFORMATION TECH CO LTD

Data read / write method, system, and apparatus, computing device, and storage medium

PCT designated stageWO2026144711A1Computer hardwareEngineering
Embodiments of the present disclosure provide a data read / write method, system, and apparatus, a computing device, and a storage medium. The data read / write method comprises: receiving, by means of an asynchronous I / O layer, a data read / write request sent from a user space, and storing the data read / write request in a request queue; when the asynchronous I / O layer determines that the data read / write request is of a pass-through type, sending the data read / write request to a driver layer; and parsing the data read / write request by means of the driver layer, and sending request information of the data read / write request to a target processing end device for read / write processing. The data read / write request sent from the user space is received by means of the asynchronous I / O layer, and is sent to the driver layer after the data read / write request is determined to be of the pass-through type, thereby reducing context switching and data copying overhead, and improving the processing efficiency of I / O operations. The request is parsed at the driver layer and sent to the processing end device for read / write processing, thereby optimizing the scheduling of I / O tasks, reducing disk addressing time and I / O latency, and improving overall performance and system stability.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Method and apparatus for optimizing server system interrupts, device and medium

Disclosed are a method and apparatus for optimizing server system interrupts, a device and a medium, which relate to the field of servers. The method is applied to a server system, and comprises: when a peripheral driver of a kernel space monitors an interrupt request signal sent by a hardware peripheral, reading a hardware event queue in the hardware peripheral, so as to acquire a target hardware event in the hardware event queue; then, converting the target hardware event into a target software event by using the peripheral driver, and writing the target software event into a preset global event queue; reading the target software event in the global event queue by means of a user space, and forwarding the target software event to a corresponding target service process by means of the user space, such that the target service process processes the target. In this way, by using hardware interrupt coalescing and software event coalescing techniques, this solution may not only reduce the interrupt processing overhead, but also reduce the processor utilization.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Method for accessing system-on-chip (SOC) memory from user space

The present disclosure is directed to a method for accessing memory. The method includes mapping an address space for the memory to an address space for a kernel space. The method includes mapping the address space for the memory to an address space for a user space using the kernel space. The method includes accessing the memory via the address space for the kernel space and the address space for the user space.
Owner:QUALCOMM INC

External display screen driving method and system based on Android system

PendingCN121349391ADigital output to display deviceColor graphicsLinux kernel
The invention relates to an external display screen driving method and system based on an Android system, an external display screen is connected with Android equipment through a low-speed serial interface, and the method comprises the steps that S1, a Native layer initialization function is called through a JNI interface on an Android application layer; s2, an LVGL graphic library is loaded on a Native layer; s3, registering and adapting external display screen hardware of the low-speed serial interface through a display driving interface of the LVGL graphics library; s4, executing a color space conversion algorithm on the Native layer, and converting color graphic data output by the LVGL graphic library into color format data suitable for the target external display screen; and S5, transmitting the converted display data to an external display screen through a device driving interface of the Linux kernel. According to the method, the lightweight LVGL graphics library is integrated into the Android application through the JNI technology, and the display screen connected through the low-speed serial interface is directly driven in the user space, so that the efficient and flexible display driving is realized under the condition that the source code of the Android system is not modified, and the multi-screen different display function is supported.
Owner:SHANGHAI SIMCOM LTD

User login auditing method, device and equipment, medium and product

The invention discloses a user login auditing method, device and equipment, a medium and a product. The method comprises the following steps: mounting an extension packet filter program to a target trigger point related to user login; under the condition that the target trigger point is triggered, acquiring a system call event of the target trigger point through the extension packet filter program, and transmitting to-be-audited event data associated with the system call event to a login audit daemon process of a user space; and performing user login auditing based on the to-be-audited event data through the login auditing daemon process, and generating a user login auditing result. According to the scheme, the system call event is acquired through the extension packet filter program mounting to perform user login auditing, so that the event call can be monitored in real time, and the real-time performance is high; the auditing process does not depend on log files, and the log tampering risk is avoided; kernel source codes, system configuration and the like do not need to be modified, the original authentication process and system stability are not influenced, the invasiveness is low, and the compatibility is high.
Owner:SHANGHAI JIACHE INFORMATION TECH CO LTD

Data management method and device, equipment, medium and program product

The invention provides a data management method which can be applied to the technical field of big data. The data management method is executed in a user space file system and comprises the steps that an operation request for a first logic path file is received through a virtual file system, and the operation request is from a user program; the operation request is routed to a kernel driver, a callback function corresponding to the operation request is called, and the callback function is registered by a user program; on the basis of the callback function, a pre-established metadatabase is inquired, metadata corresponding to the first logic path is obtained, and the metadata at least comprises the mapping relation between the logic path and the physical path; and executing an operation corresponding to the operation request based on the metadata. The invention further provides a data management device and equipment, a storage medium and a program product.
Owner:NAT ASTRONOMICAL OBSERVATORIES CHINESE ACAD OF SCI

File input and output proxy method and system compatible with general kernel mirror image specification

PendingCN121560392AVersion controlBootstrappingParallel computingCode refactoring
The invention relates to a file input and output proxy method and system compatible with a general kernel mirror image specification, and the method comprises the steps: providing an interface compatible layer consistent with VFS operation in a kernel space, converting a file operation request into a Netlink protocol message, sending the Netlink protocol message to a user space for execution, maintaining the original calling semantics through a synchronous coordination mechanism, and carrying out the operation of the Netlink protocol message; according to the method, the GKI specification requirement can be met by zero modification of the drive code, the problem of large-scale code reconstruction in the process of smoothly migrating the Android system to the GKI specification is effectively solved, and the development workload and the risk of introducing new defects are reduced.
Owner:MOBIIOT TECH (NINGBO) CO LTD

File operation method of user space file system and user space file system

The application discloses a file operation method of a user space file system and the user space file system, and the method comprises the following steps: a virtual file system receives a file operation request for a target file in the user space file system sent by an application program, and sends the file operation request to a target drive module corresponding to the user space file system; the target drive module starts an extended filter, so as to call a plug-in function corresponding to the file operation request to perform corresponding file operation on an underlying file system, and update shared data areas in a kernel according to an operation result; and a user space daemon obtains a data update result from the shared data areas, and sends the data update result to the application program. According to the technical scheme of the application, the data interaction frequency between the user space and the kernel can be effectively reduced, and the system overhead is reduced.
Owner:GUANGDONG TONGXIN SOFTWARE CO LTD

Vehicle event processing method and device, vehicle, equipment and medium

The embodiment of the invention provides a vehicle event processing method and device, a vehicle, equipment and a medium, and the method comprises the steps: obtaining a directed acyclic graph corresponding to an event when the event of an intelligent driving system is triggered; the directed acyclic graph defines tasks corresponding to the events and a dependency relationship between the tasks; calling the user space program to load the kernel space program to the kernel space; the kernel space program and the user space program communicate through a kernel mapping table, and a scheduling strategy for tasks is set in the kernel space program; sending the directed acyclic graph to a directed acyclic graph scheduling process; calling a directed acyclic graph scheduling process to load a kernel space program; and scheduling the task according to the directed acyclic graph and the scheduling strategy. According to the embodiment of the invention, the event processing efficiency of the intelligent driving system can be improved.
Owner:SHANGHAI LIXIANG AUTOMOBILE CO LTD

Kernel bypass for iscsi and nvme / TCP applications

Techniques for host devices to offload iSCSI and NVMe / TCP data plane processing for data plane traffic to a NIC, and for the NIC to perform the data plane traffic processing in hardware. Traditionally, network protocol stacks have been implemented within the kernel of an operating system of a computing device. In light of this, iSCSI and NVMe / TCP user space applications running on host devices interact with a kernel of an operating system using system calls in order to send network traffic. However, the system calls, TCP / IP processing, and data copying required when communicating via the kernel increases CPU utilization as well as I / O latency. Techniques described herein include configuring the host device to enable kernel bypass for data path traffic for iSCSI and NVMe / TCP user space applications, and a NIC may include hardware configured to perform the iSCSI and NVMe / TCP processing for iSCSI and NVMe / TCP connections.
Owner:SPEEDNIC LLC

Data monitoring method, device and system

The invention provides a data monitoring method, device and system, and relates to the technical field of computers. The method comprises the following steps: intercepting a system call event in a kernel space of an operating system to capture a data packet transmitted between specified components through a network; checking the state of the plurality of protocol monitoring switches to determine a currently enabled protocol monitoring switch; identifying the application protocol type of the data packet by using an identification strategy matched with the currently started protocol monitoring switch; analyzing the data packet by using an analyzer matched with the application protocol type to obtain an analysis result; generating structured monitoring data according to an analysis result; and sending the structured monitoring data to the user space. By means of the method, self-adaptive monitoring can be efficiently and accurately conducted on network communication data of multiple application protocols, and the universality and expandability of data monitoring are improved.
Owner:JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD

Data transmission method and device, computer equipment, chip and chip module

The invention relates to a data transmission method and device, computer equipment, a chip and a chip module, relates to the technical field of computers, and can effectively improve the network sharing quality of the computer equipment. The computer equipment comprises a baseband chip and further comprises a target chip deployed with virtual network equipment, and the virtual network equipment is connected with a kernel space and a user space; the method comprises the following steps: acquiring a first data packet from a kernel space based on virtual network equipment; the first data packet is obtained by packaging data provided by a first application program in the user space; and transmitting the first data packet to a second application program in the user space based on the virtual network device, calling a preset communication interface by the second application program, and sending the first data packet to the baseband chip from the target chip, so as to perform network transmission on the first data packet through the baseband chip.
Owner:SPREADTRUM SEMICON(CHENGDU) CO LTD

Efficient usage of writebooster buffer in preserve user space mode

In a flash memory device, portions of a write buffer may be merged into a user space logical unit based on a measurement of write buffer usage. In a Universal Flash Storage (UFS) device configured with the WriteBooster feature, the write buffer may be a WriteBooster buffer. When it is determined that a user space logical unit has become full, then the write buffer usage may be determined. Portions of the write buffer that are least used or have the longest remaining lifetime may be preferentially merged into the user space logical unit.
Owner:QUALCOMM INC

Behavior perception and access control method during SQLite database operation based on eBPF

The invention discloses a behavior perception and access control method during SQLite database operation based on eBPF, belongs to the technical field of computer system security, and aims to solve the problem that the existing scheme depends too much on application layer logic or the protection of a hardware layer is not practical. The system is composed of the following three logic modules which work cooperatively to form a closed loop: a kernel probe module which deploys an eBPF program on a kernel key path and is responsible for capturing an original event and executing forced interception; and the strategy decision module runs in a user space, receives the audit event reported by the kernel, carries out deep analysis, carries out risk judgment according to an existing strategy, and generates a dynamic control strategy. And the data interaction module is used as a safe communication bridge between the kernel and the user mode. The method is independent of application integrity, and fine-grained auditing and interception can be carried out on SQLite operation in a kernel layer. The method does not depend on whether the logic of an application layer is sound or not, and even if the application is broken, high-risk behaviors such as data stealing can still be effectively blocked.
Owner:BEIJING UNIV OF TECH

High-speed network data distribution and transmission device and method based on DPDK

The invention discloses a high-speed network data distribution and transmission device and method based on DPDK. The high-speed network data distribution and transmission device comprises a case suite and a computing board. The case suite receives multi-path optical fiber radar data and forwards the multi-path optical fiber radar data to the corresponding computing board through the switching board. And the computing board runs a DPDK data transmission program, bypasses a Linux kernel protocol stack, directly acquires data from a network card driver in a user space, and analyzes a user-defined control word behind a UDP protocol header. According to a data type flag in the control word, guiding the data to an IDLE or READY state annular queue; and managing the state switching of the data memory block between the double queues according to the transmission state flag, and scheduling the memory block through a double-buffer mechanism to complete the distribution and convergence of the data. The zero-copy high-speed transmission of the user mode is realized, the problems of low bandwidth, more packet loss and large jitter of the traditional communication mode are effectively solved, and the transmission efficiency and the real-time performance are remarkably improved.
Owner:西安超越申泰信息科技有限公司

Method and apparatus for handling risk events in encrypted traffic

This application discloses a method and apparatus for handling risk events in encrypted traffic. The method includes: synchronously collecting network modality data and host modality data through an eBPF program assembly with multiple function entry points pre-deployed in the Linux kernel to obtain collected network events; transmitting the network events to a user-space receiver via the Perf Buffer data transmission mechanism to append a global high-precision timestamp and host identifier to the network events to obtain network traffic; generating a comprehensive risk score for the network events based on the network traffic, combined with a pre-trained bimodal deep learning model and a cross-modal attention fusion module; and triggering an alarm and writing the network event as a risk event into a graph database when the comprehensive risk score exceeds a preset threshold. Using this application, lateral movement attacks can be effectively detected and defended, improving the accuracy of encrypted risk detection and enabling users to gain a more comprehensive understanding of attack behavior, thereby enabling more effective attack analysis and response.
Owner:HANGZHOU WEIMING XINKE TECH CO LTD +1

Input method switching method and related device

The invention provides an input method switching method and a related device, when an electronic device determines that an input focus is located in an application interface of a first user space, a first input method corresponding to the first user space is automatically called, the first input method can correct content input by a user through cloud service, and the user experience is improved. Therefore, the candidate word matched with the corrected content is displayed, and the accuracy of the candidate word is improved. And when the electronic equipment determines that the input focus is switched to the application interface of the second user space, automatically calling a second input method corresponding to the second user space. And the second input method does not upload the content input by the user to the cloud, so that the privacy security of the user is ensured when the electronic equipment runs in the parallel space. Moreover, the user does not need to manually switch the online mode and the offline mode of the input method in the whole process, so that the operation complexity of switching the input method is reduced, and the user experience is improved.
Owner:HONOR DEVICE CO LTD

Disaggregated computing for distributed confidential computing environment

An apparatus to facilitate disaggregated computing for a distributed confidential computing environment is disclosed. The apparatus includes one or more processors to: provide a remote GPU middleware layer to act as a proxy for an application stack on a client platform that is separate from the remote server platform, wherein the remote GPU middleware layer comprises is to expose an abstraction of the remote GPU to userspace components of a remote GPU stack, the userspace components running on the client machine; communicate with a kernel mode driver of the one or more processors to cause the host memory to be allocated for data structures used to communicate commands between the client and the remote GPU; and invoke the kernel mode driver to submit a workload generated by the application stack, the workload submitted for processing by the remote GPU using the data structures allocated in the host memory.
Owner:INTEL CORP

File protection method, device, system and equipment, storage medium and program product

The embodiment of the invention provides a file protection method, device and system, equipment, a storage medium and a program product, and relates to the technical field of computing security. The file protection method comprises the following steps: in response to an access request of a user process to a file in a kernel space, loading a file access strategy based on an extended Berkley data packet filter eBPF, performing security check on the access request based on the file access strategy, and releasing or intercepting the access request according to a security check result; wherein the file access strategy is that the security service module of the user space receives the file access strategy from the server side and sends the file access strategy to the file security module, and the file security module stores the file access strategy in the kernel space in advance based on the eBPF. The technical scheme provided by the embodiment of the invention is relatively high in universality and security for various kernel versions.
Owner:ALIBABA CLOUD COMPUTING CO LTD