Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

234 results about "User space" patented technology

A modern computer operating system usually segregates virtual memory into kernel space and user space. Primarily, this separation serves to provide memory protection and hardware protection from malicious or errant software behaviour.

Capturing and using application-level data to monitor a compute environment

An illustrative method includes receiving, by a data platform configured to monitor the compute environment, runtime workload data collected by an agent deployed to the compute environment, wherein the runtime workload data comprises user space data collected from a user space of the compute environment and kernel space data collected from a kernel space of the compute environment. The method further includes performing, by the data platform, a monitoring operation based on the user space data and the kernel space data of the runtime workload data.
Owner:FORTINET INC

Linux access control system based on attributes

The invention provides a Linux access control system based on attributes, and relates to the technical field of data access control. The system comprises a system monitor module, a data interaction module and a decision unit. The system monitor module collects attributes from a kernel and a user space and writes the attributes into the data interaction module; the access decision unit compiles the access control strategy into an eBPF program and mounts the eBPF program to a corresponding hook; executing the kernel to the hook, and triggering an eBPF program; an eBPF program queries a Flow rule; matching the attribute with the Flow rule, and if the matching is successful, executing a corresponding action; if all the Flow rules fail to match, executing a default action; the system can be expanded during operation, and can be loaded or unloaded based on dynamic loading characteristics and strategies of the eBPF program and the eBPF program during operation of the system, so that the problem that a kernel needs to be compiled in a traditional LSM scheme is solved; the method does not intrude the kernel, is completely based on an eBPF program, does not modify a kernel source code, and can guarantee the stability and compatibility.
Owner:SICHUAN UNIV

Containerized agent for monitoring container activity in a compute environment

A containerized agent that is deployed to a compute node of a compute environment and that executes in both user space and kernel space of the compute node is disclosed. The containerized agent collects data associated with a first container entity that is deployed to the compute node and that executes only in the user space of the compute node such that the first container entity is isolated from other entities executing in the user space of the compute node. The containerized agent also provides the collected data associated with the first container entity to a data platform that is monitoring the cloud compute environment using the containerized agent. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

File retrieval method and device, equipment and storage medium

The invention discloses a file retrieval method and device, equipment and a storage medium, and relates to the technical field of data retrieval, and the method comprises the steps that a user mode space responds to a file retrieval instruction received at the current moment, a target retrieval strategy corresponding to the file retrieval instruction is determined, and an event filtering strategy is updated to a kernel mode space; the kernel mode space obtains a target file operation event from all file operation events captured at the current moment based on the updated event filtering strategy; and the user mode space determines metadata information of a target file corresponding to the target file operation event, updates the mixed index database based on the metadata information, and then retrieves in the updated mixed index database based on the target retrieval strategy and the file retrieval instruction to obtain a file retrieval result. According to the method, the purposes of real-time updating of the metadata information of the file system and efficient retrieval of multiple retrieval dimensions are achieved, the efficient file retrieval requirement is met, and the file retrieval efficiency is improved.
Owner:BEIJING LINX SOFTWARE CORP

Hardware accelerator and data handling method

The invention relates to the technical field of chips, and discloses a hardware accelerator and a data handling method, the hardware accelerator comprises a doorbell processing module, a descriptor cache module and at least one DMA engine module; wherein a target engine module in the at least one DMA engine module is configured to read a target descriptor from effective descriptors in the descriptor cache module and analyze the target descriptor to obtain a source address field, a source address space identifier, a destination address field and a destination address space identifier, and carrying the target data block in the first user space to the second user space based on the source address field, the source address space identifier, the destination address field and the destination address space identifier, wherein the effective descriptor is read from a descriptor ring in the first user space through the doorbell processing module and is written into the descriptor cache module. Therefore, through cooperative work of all the modules, full-hardware acceleration of user mode data carrying is completed, and therefore the data carrying efficiency is remarkably improved.
Owner:PHYTIUM TECH CO LTD

PCIe-based DMA data zero copy processing method and system

The invention relates to the technical field of data acquisition, and discloses a PCIe-based DMA data zero copy processing method and system. The method is applied to a zero copy processing system, and comprises a HOST module for distributing a physical DMA buffer area and mapping a physical address of the DMA buffer area to a logically continuous virtual address space; the HOST module is used for constructing a preset descriptor queue and sending a head address of the queue to the FPGA module; the FPGA module receives the initial address of the queue through a PCIe interface, analyzes a descriptor, and writes DMA data with a preset transmission length into a sub DMA buffer area of the HOST module; and the HOST module monitors the state of the DMA buffer area and adopts a dynamic flow control mechanism to adjust the data transmission rate of the FPGA module according to the state. According to the method provided by the embodiment of the invention, the physical DMA buffer area is mapped to the logically continuous virtual address space, and the application program can directly access the DMA data in the user space without copying through the middle of a kernel, so that zero-copy access is realized, the data processing delay is reduced, and the data transmission efficiency is improved.
Owner:SUZHOU YIGE TECH CO LTD

Intelligent backboard interaction method supporting terminal interconnection, medium and intelligent backboard

The invention discloses an intelligent backboard interaction method supporting terminal interconnection, a medium and an intelligent backboard. The intelligent backboard interaction method comprises the following steps: collecting user space motion data to generate a space-time trajectory sequence and binding a user identity label, segmenting a multi-user shooting action data stream in real time, extracting dynamic association features and combining sphere trajectory data to construct a multi-dimensional feature matrix; inputting the matrix into a distributed intention understanding engine, and fusing voice, a touch event and historical data to generate an interactive decision instruction; a dynamic content generation module is driven according to the instruction, a training difficulty coefficient and a tactical matching degree are calculated in real time, and a multi-terminal cooperative control signal is output; and aggregating multi-user and sphere state feedback data, and continuously adjusting a collaborative strategy of a shooting action evaluation standard, a multi-user confrontation rule and terminal display content. According to the method, accurate distinguishing and collaborative intention understanding of multi-user actions are realized, and the training individuation level and the self-adaptive real-time control capability of multi-user interaction are effectively improved.
Owner:FUJIAN MIRACLE SPORTS TECH CO LTD

Electric power intelligent equipment-oriented trusted execution environment construction method, system, equipment and medium

The invention discloses a trusted execution environment construction method, system, equipment and medium for electric power intelligent equipment, and relates to the technical field of electric power intelligent equipment monitoring, and the method comprises the following steps: carrying out Hash measurement on a to-be-detected area in an operating system kernel, carrying out comparison based on a preset reference value, and monitoring the consistency of kernel static data and codes; performing list management and integrity verification on the system kernel module, and identifying illegal loading, unloading or tampering behaviors; monitoring a kernel module event, sensing the change of the life cycle of the module and dynamically triggering a verification mechanism; performing Hash verification on an execution file of the specified user space process, and identifying process-level illegal replacement or injection behaviors; and updating the trusted measurement database based on a detection result, and executing log recording, alarming and blocking strategy response. The method does not depend on a chip, a virtualization platform or hardware extension, realizes security monitoring only through a software means, and is suitable for an embedded terminal with limited resources.
Owner:NARI INFORMATION & COMM TECH

Asynchronous communication-based file system client kernel mode and user mode communication method

The invention provides a file system client kernel mode and user mode communication method based on asynchronous communication. According to the asynchronous communication-based file system client kernel mode and user mode communication method provided by the embodiment of the invention, the context switching overhead of communication between the user mode and the kernel mode can be reduced, the data transmission throughput is improved, the resource utilization rate is optimized through dynamic queue management, and the problem of performance bottleneck in a high-concurrency scene is effectively solved.
Owner:JINAN INSPUR DATA TECH CO LTD

Graphic processor simulation method, simulator, device, equipment and storage medium

The invention discloses a graphics processor simulation method, a simulator, a device, electronic equipment and a storage medium, and belongs to the technical field of simulation. Loading a target system call simulator for simulating the target graphics processor; the target system call simulator comprises a user space simulation layer, a graphics processor simulation layer and a graphics drive simulation layer connected with the graphics processor simulation layer and the user space simulation layer; and running a target program in the user space simulation layer, and directly sending a graphic system call generated in the running process of the target program to the graphic drive simulation layer, so that the graphic drive simulation layer transmits a corresponding GPU instruction set to the graphic processor simulation layer based on the graphic system call, and executes the GPU instruction set through the graphic drive simulation layer. Therefore, the software and hardware of the corresponding graphics processor can be simulated by calling the simulator through the lightweight target system, and the simulation precision of the graphics processor can be improved under the condition of ensuring relatively high simulation efficiency.
Owner:LOONGSON TECH CORP

Transparent virtual machine monitoring method for cloud security

The invention discloses a transparent virtual machine monitoring method for cloud security. The method comprises the following steps: S1, activating and stopping an LBR and a PMU; s2, integrity verification and user space interaction; s3, performing hardware configuration and interrupt processing; s4, performing double mapping on the kernel cache and the user space; and S5, user space interaction and CFI verification are carried out. Real-time monitoring and integrity verification of the control flow of the kernel of the virtual machine are achieved by ingeniously utilizing the hardware characteristics of a modern processor, control flow hijacking attacks are effectively resisted on the premise that normal operation of the virtual machine is not affected, and the safety of the kernel of the virtual machine in the cloud computing environment is improved.
Owner:ANHUI NORMAL UNIV

Heterogeneous processor-oriented deep neural network reasoning task dynamic scheduling method and system

The invention discloses a heterogeneous processor-oriented deep neural network reasoning task dynamic scheduling method and system, and belongs to the technical field of computer systems. The method comprises the steps that a DNN model is converted into a computational graph in a user space, and the computational graph is divided into a plurality of fine-grained micro-tasks through key path analysis; monitoring resource states of the CPU and the GPU in a kernel space in real time; dynamically selecting an optimal processor for each microtask in a kernel layer based on a cost model comprising execution time, queue length and utilization rate; and executing the micro-task on the corresponding processor according to a scheduling result, and triggering cross-processor task dynamic migration when detecting that the load is unbalanced, including context storage, data transmission and execution recovery. The system adopts a user space and kernel space collaborative architecture to realize the method. Through fine-grained division, kernel-level real-time scheduling and a dynamic migration mechanism, the reasoning efficiency, the resource utilization rate and the system stability of the heterogeneous system under a complex load are effectively improved.
Owner:EAST CHINA NORMAL UNIV

Process interception method and device and electronic equipment

The embodiment of the invention provides a process interception method and device and electronic equipment. The method comprises the following steps: a kernel space receives a process protection list sent by a user space by utilizing a virtual file system interface; wherein the process protection list comprises a process identifier of at least one to-be-protected process; the kernel space obtains a process termination request; wherein the process termination request is used for requesting to terminate a target process, and the target process is a process entity scheduled by an operating system; under the condition that the kernel space determines that the request type of the process termination request is a preset request, determining a matching relationship between the target process and a process protection list based on a target process identifier of the target process; and when the matching relationship indicates that the process identifier of the at least one to-be-protected process in the process protection list comprises the target process identifier, the kernel space intercepts the process termination request. By the adoption of the method, the important process can be effectively prevented from being terminated due to malicious or misoperation, and the safety and stability of the system are improved.
Owner:XFUSION DIGITAL TECH CO LTD

Resource management method and device, electronic equipment and storage medium

The invention provides a resource management method and device, electronic equipment and a storage medium, the method is applied to the field of terminals, and the method comprises the following steps: in a multi-user operating system, responding to a system resource management instruction received by a performance optimization main program in a main user space; the method comprises the steps of determining first resource use data of a main user space based on a performance optimization main program, calling a performance optimization agent process based on the performance optimization main program, determining second resource use data of a sub-user space, and optimizing system resources of a multi-user operating system based on the first resource use data and the second resource use data. Therefore, one-stop management of multi-user system resources is achieved, the response speed and efficiency of the whole system are improved, and resource consumption is reduced.
Owner:GREAT WALL MOTOR CO LTD

Context-sensitive token-bucket rate limiting in eBPF

The present disclosure provides techniques for context-sensitive token-bucket rate limiting. A processing device obtains, in a kernel space of an operating system (OS), a message comprising a unique process identifier (UPID) and a message type. The processing device determines whether to send the message from the kernel space to a user space of the OS based on at least one of: the UPID, the message type, or a token count and a discrete time unit in an entry in a data structure in the kernel space. The processing device processes the message based on the determination of whether to send the message from the kernel space to the user space.
Owner:CROWDSTRIKE

Systems and methods for testing sandboxed in-kernel programs

Systems and methods for testing sandboxed in-kernel programs are provided. A method of testing a program includes: obtaining a Berkeley Packet Filter (BPF) program to test; obtaining a test to run on the BPF program; performing the test on the BPF program for a plurality of Linux kernels and reporting a result of performing the test on the BPF program for a plurality of Linux kernels. This enables a generic testing solution for black box testing of BPF programs. The embodiments can integrate with existing testing suites and frameworks and can integrate into CI / CD pipelines. Some embodiments allow testing using any kernel from user space. Host kernel testing of BPF programs is enabled by a developer using the developer's own workstation and version of the Linux kernel. Guest kernel testing of BPF programs is enabled using specific kernel versions by providing the framework a specification of the target kernel environment.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

File processing method, file system in user space, device, and computer program product

Provided in the embodiments of the present disclosure are a file processing method, a file system in user space, a device, and a computer program product. The file processing method is applied to a file system in user space, wherein the user state file system comprises a file system process and a file system in user space (fuse) process which is in communication connection with the file system process. The file processing method comprises: a fuse process acquiring a file processing request; the fuse process caching the file processing request, wherein the fuse process comprises a caching request queue used for caching the file processing request; and when a file system process exits, the fuse process determining a request processing state of the file processing request to be a suspension state, such that a file processing link where the fuse process is located maintains a normal state. In the embodiment, when a file system process exits, a fuse process may cache a file processing request, thereby ensuring the normal operation of a user process.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

RPA mouse and keyboard control method and system for Wayland desktop

The invention belongs to the technical field of computer man-machine interaction and automatic control, and particularly relates to an RPA mouse and keyboard control method and system for a Wayland desktop. The method comprises the following steps: S1, creating and registering a virtual input device supporting mouse and keyboard functions in a user space by accessing a virtual input device interface provided by an operating system kernel; s2, current activity display output is detected, and screen resolution information is obtained; s3, the server program monitors a preset local Unix domain socket path for receiving a control instruction from the client; s4, the client sends a control request to the local Unix domain socket path in a structured format, and the server receives and analyzes the control request; s5, the server side maps the analyzed control request into a corresponding kernel input event sequence according to the operation type; meanwhile, by writing event data into the virtual input device, an input event is injected into the system so as to simulate a control operation on the graphic desktop.
Owner:浙江实在智能科技有限公司

Real-time data transfer scheme from limited power embedded systems

Distributed fiber optic sensing (DFOS) / distributed acoustic sensing (DAS) that illustrate inventive techniques—applicable to all embedded systems—that deliver high-bandwidth traffic from a DFOS system to a cloud or other processing resources in real-time, employ firmware that operates at a register-transfer level and writes data repeatedly into the embedded host memory directly—without software intervention after initial configuration. This technique advantageously enables the use of the relatively large host memory to compensate for any software jitter. Preferably configured, the firmware employs only a small buffer to compensate for a transaction and host-memory arbitration latency. A second dedicated thread sends out data from the user space buffer to a cloud, or a connected server. Remote procedures that are executed on a remote system (a computer, network of computers, or cloud), receive data transmitted from the embedded system, and perform further processing as necessary.
Owner:NEC LABORATORIES AMERICA INC

Policy-driven kernel extension security

A computer-implemented method (CIM), according to one embodiment, includes receiving, at a kernel space of a data processing system, from a user space, a policy, a kernel extension code, and metadata associated with the kernel extension code. The metadata describes at least one type of attachment point in the kernel space, and the policy includes an allowlist and a blocklist of metadata for the attachment points. The method further includes validating the metadata against the policy, and performing an integrity measurement on the kernel extension code. In response to a determination that the metadata is validated against the policy and the integrity measurement is verified, the kernel extension code is loaded in the kernel space.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Systems and methods for container based multiple operating system delivery with limited ram

Systems and methods for using containers in computing devices (e.g., IOT devices, etc.) to host multiple operating system (OS) user spaces that share the same kernel may include a computing device configured to intelligently and dynamically switch the currently active container to another container in response to detecting a trigger, event, or condition on the computing device. The computing device may also dynamically activate or deactivate all or portions of one or more memories of the computing device based on the characteristics and / or workload of the currently active container.
Owner:QUALCOMM INC

Kernel-level heterogeneous collaborative AI reasoning method, device and equipment and storage medium

The invention discloses a kernel-level heterogeneous collaborative AI reasoning method and device, equipment and a storage medium, and relates to the field of AI reasoning acceleration. When the KDS receives a reasoning request submitted by a user space, generating a cross-device plan list according to a global system resource state and issuing the cross-device plan list to the HCEE; the HCEE drives the corresponding target execution equipment according to the task execution sequence, reads the data information from the UCMP, or restores intermediate / result data reasoned and output by the target execution equipment; after reasoning of the plan list is completed, the kernel space triggers an event notification mechanism, and a user process of the user space is awakened; and the user process directly reads the reasoning result from the UCMP. According to the scheme, deep collaboration of task scheduling, memory management and equipment execution is realized on a Linux kernel level, the problems of high overhead, resource islands, memory redundant copy, extensive scheduling granularity and the like of a user mode reasoning framework system are solved, and end-to-end low-delay, high-throughput and high-energy-efficiency AI reasoning acceleration is realized.
Owner:STORAGEX TECH INC +1

Migrating ransomware activity of an operating system by monitoring from user space

Ransomware activity in operating systems can be mitigated by monitoring from user space. For example, a computing environment can generate an affinity score indicating a likelihood of ransomware activity associated with an operating system based on a first set of system calls detected from a user space of the operating system within a first time window. The computing environment can buffer one or more write operations from the first set of system calls during a second time window based on the affinity score. The computing environment can update the affinity score based on a second set of system calls detected from the user space of the operating system within the second time window. The computing environment can block execution of the one or more write operations based on the updated affinity score exceeding a predefined threshold.
Owner:RED HAT INC

User interrupt event callback mechanism implementation method

The invention discloses a user interrupt event callback mechanism implementation method, which adopts an implementation method of combining user interrupt event callback caused by hardware interrupt and conventional task scheduling, after system hardware interrupt occurs, kernel interrupt processing codes construct a user mode code running environment, and a user mode is switched to run a user event callback function, so that the user interrupt event callback is realized. After the execution of the user event callback function is finished, the system environment before the execution of the user event callback function is recovered through an undefined instruction falling into a kernel; and when all the user callback event functions are executed, falling into the kernel through the undefined instruction again, and recovering an instruction execution stream before the interruption event occurs by utilizing the stack frame information reserved when the interruption is entered. According to the method, an emergency processing mechanism with determined delay is realized, the constructed interrupt event callback function runs in a user space, and the method has the functions of shielding low-priority interrupt and protecting a memory, is low in overhead, simple to implement and easy to adapt to various processors, and has a good application prospect.
Owner:NANJING PANENG TECHNOLOGY DEVELOPMENT CO LTD

User space file system, file operation method and computing equipment

The invention discloses a user space file system, a file operation method and computing equipment, and belongs to the technical field of computers. The user space file system is applied to the computing device, the computing device comprises a shared memory, the user space file system comprises a kernel module and a user space daemon process, the kernel module runs in a kernel mode, and the user space daemon process runs in a user mode. The kernel module and the user space daemon process can access the shared memory so as to realize bidirectional communication between a user mode and a kernel mode. According to the user space file system, the user mode and the kernel mode can share the same memory, and then messages and data in the memory can be shared, so that frequent switching and data copying between the user mode and the kernel mode can be reduced, the overhead and time delay of file access are reduced, and the performance of the user space file system is improved.
Owner:HUAWEI TECH CO LTD

Determination of user operations at a data processing system

Methods are described for determining user operations at a data processing system. In one example, an agent is established at the data processing system that has access to data indicating, for each of multiple user space applications, an association between (i) a set of multiple calls by the user space application to one or more software functions and (ii) a specific operation of the user space application. A set of calls by a given user space application to one or more software functions is received by the agent. It is determined that the set of calls are characteristic of a specific operation of the given user space application by processing the set of calls based on the data. One or both of generating a report regarding the specific operation and influencing functioning of the given user space application are then performed.
Owner:FORTINET INC

System and method for observing encrypted traffic in JAVA applications using ebpf and JAVA agent

A method for observing encrypted traffic in Java applications using eBPF and Java Agent is disclosed. The method includes providing the eBPF program to capture to capture encrypted data from kernel-level read and write operations, and / or Transfer Layer Security (TLS) generated key. The method also includes providing a Java agent to instrument functions involved in TLS key generation and to extract session secrets. Further, the method includes facilitating the Java agent to write session secrets to a non-persistent storage medium, such that the eBPF program reads session secrets from the non-persistent storage medium. Thereafter, the method includes providing a user-space program to receive the encrypted data and session secrets from the eBPF program and decrypt the data for analyzing and tracing the Java application.
Owner:HARNESS INC

System management method and device, vehicle and storage medium

The invention provides a system management method and device, a vehicle and a storage medium, relates to the technical field of computers, and is used for solving the problem of abnormal restart of a system. The system management method is applied to an operating system, a user space of the operating system comprises a first process, and a first thread lock and a second thread lock are arranged in the first process; the method comprises the steps that under the condition that a target event is monitored, the state of a first thread lock is obtained, under the condition that the state of the first thread lock is a non-locking state, a first shared resource is accessed to process the target event, and the target event is a storage event related to pluggable storage equipment; and acquiring the state of the second thread lock under the condition that the monitoring event of the first process is monitored, and restarting the operating system under the condition that the state of the second thread lock is determined to be a deadlock state.
Owner:ZHAOQING XIAOPENG NEW ENERGY INVESTMENT CO LTD

GPU equipment isolation and mounting method and device, equipment and storage medium

The invention relates to a GPU equipment isolating and mounting method and device, equipment and a storage medium, and relates to the field of artificial intelligence chips. The method comprises the following steps: CPU equipment in computer equipment acquires a GPU resource request submitted by a user through a job scheduling system, determines target GPU equipment from candidate GPU equipment based on the GPU resource request so as to allocate the target GPU equipment to the user, and assigns the target GPU equipment to a visible environment variable defined by a manufacturer of the target GPU equipment; and calling the user space container system through a container arrangement tool of the job scheduling system, so that the user space container system creates a container according to the visible environment variable, analyzes the visible environment variable to obtain target GPU equipment, and mounts the target GPU equipment into the container. By adopting the method, the flexibility and efficiency of GPU resource management can be improved.
Owner:SHANGHAI BIREN TECH CO LTD