Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

2144 results about "Virtual machine" patented technology

In computing, a virtual machine (VM) is an emulation of a computer system. Virtual machines are based on computer architectures and provide functionality of a physical computer. Their implementations may involve specialized hardware, software, or a combination.

Virtual machine operation management system based on RISC-V architecture

The invention relates to the technical field of virtualization management, in particular to a virtual machine operation management system based on RISC-V. The system comprises an instruction set mapping module, a resource scheduling optimization module, a virtual machine monitoring integration module, an operation tuning update module and an operation configuration distribution module. According to the method, by analyzing the operation instruction of the virtual machine and combining the RISC-V underlying characteristics, accurate instruction mapping is achieved, the processing efficiency and accuracy are remarkably improved, the performance loss and conversion delay caused by too high abstraction level of a traditional virtual machine on the instruction level are overcome, the optimal allocation scheme is screened, the resource utilization rate and the system response speed are effectively improved, and the system performance is improved. The operation state and performance indexes of the virtual machine are integrated, anomaly detection and resource recovery are embedded, system stability and effective resource reutilization are ensured, basic configuration is continuously and incrementally updated, operation configuration refinement and automatic management and updating are achieved, the overall operation efficiency and management flexibility are improved, and the manual intervention cost is reduced.
Owner:WUHAN COMPUTING ECOLOGY TECH CO LTD

Ai-agent based system and method for real-time multilingual and context-aware linguistic transformation in telecommunications

A system and method for real-time or near real-time multilingual language transformation in telecommunications environments using distributed artificial intelligence (Al). The system includes at least one processor configured to instantiate a plurality of Al agents, each corresponding to a user in a communication session, and to manage their operation via an Al-agent runtime adapter comprising a microkernel agent manager and a virtual machine layer. A language model abstraction layer enables access to language models and Al algorithm libraries through publish-subscribe interfaces. The system supports contextual transformation of speech based on user profile data such as sentiment, emotional tone, and cultural background. Execution can occur on telecommunication-class switches, edge devices, or general-purpose computing hardware. Al agents operate asynchronously, access shared or private memory, and produce personalized, bidirectional linguistic output. The architecture supports secure, scalable deployment across heterogeneous devices and networks.
Owner:CUNNINGHAM CHERYL

Mechanical arm control system and control method based on embedded virtual machine architecture

The invention provides a mechanical arm control system and control method based on an embedded virtual machine architecture. A real-time operating system and a non-real-time operating system are deployed on the same embedded board card; the non-real-time operating system transmits control words of all the drivers to a driver communication module deployed on the real-time operating system through a control queue based on the received control request, and the driver communication module transmits state data of all the drivers to the non-real-time operating system through a state queue; and the motion planning module deployed on the non-real-time operating system transmits the generated position data to the driver communication module through the position queue according to a preset control period, and issues the control word and the position data to the driver through the driver communication module. By the adoption of the method, the problems that a non-real-time operating system is interrupted, communication stability is poor due to multi-task resource preemption, control response is slow, state coverage is caused by jitter of the non-real-time operating system, and a mechanical arm is stuck due to position transmission jitter can be solved.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS +1

Sidecar system and method for responding to computing system outage

A system and a method for responding to an outage of a computing system use a sidecar computing system and an event manager. The computing system is operatively connected to multiple user devices by a first network. The sidecar computing system includes a processor, a non-transitory storage device and multiple virtual machines, wherein computer-readable instructions are stored in the storage device. A second network operatively connected to the sidecar computing system and the sidecar computing system is deactivated when the computing system is operating. The event manager communicates with the computing system through the first network and the sidecar computing system through the second computer network, wherein the event manager activates the sidecar computing system to operate in an outage mode when the computing system has an outage.
Owner:TRUIST BANK

Memory data swapping method, memory data swap-out method, memory data swap-in method, and memory data swapping system

Disclosed in the present invention are a memory data swapping method, a memory data swap-out method, a memory data swap-in method, and a memory data swapping system. The memory data swapping method comprises: controlling a host machine to switch from running a host machine operating system to running a virtual machine operating system; during running of the virtual machine operating system on the host machine, acquiring a memory swap request, wherein the memory swap request is used for requesting to swap memory data between a physical memory of the host machine and a back-end storage medium corresponding to the host machine; in response to the memory swap request, determining a task swap category corresponding to the memory data; and for the memory data, executing a swap task, corresponding to the task swap category, between the physical memory of the host machine and the back-end storage medium. The present invention solves the technical problem of great memory swap limitation.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Disaster recovery resource scheduling method and device based on heterogeneous cloud environment

The invention discloses a disaster recovery resource scheduling method and device based on a heterogeneous cloud environment, and the method comprises the steps: constructing a multi-dimensional resource portrait model and a cross-cloud network topological graph in the heterogeneous cloud environment, and generating a standardized resource vector set and a topological affinity scoring matrix; aggregating the local SLA default risk prediction model of each cloud node through federated learning, and performing fine tuning through transfer learning to obtain a global prediction model; calculating load fluctuation entropy based on the SLA constraint template and real-time load data, and inputting the load fluctuation entropy into a global model to predict and obtain an SLA default probability set; constructing and solving a dynamic weight multi-objective optimization function to obtain an optimal takeover cloud node list and a migration strategy identifier set; a target cloud node and a migration strategy are determined through SLA simulation verification, and an adaptive execution adapter is called to complete virtual machine incremental snapshot migration or cross-cloud arrangement deployment of containerized services. According to the invention, intelligent and automatic scheduling of disaster recovery resources is realized, and the fault takeover speed and the cross-cloud resource utilization rate are improved.
Owner:SHENZHEN SHUCUN TECH CO LTD

Computer resource dynamic allocation management method based on cloud computing

The invention belongs to the field of computer resource management, particularly relates to a computer resource dynamic allocation management method based on cloud computing, and aims to solve the problems of locality of a decision view angle and hysteresis of a time dimension in related technologies. The method comprises the following steps: acquiring the resource utilization rate of each virtual machine in a cloud environment, wherein the resource utilization rate comprises a historical resource utilization rate and a real-time resource utilization rate; according to the resource utilization rate, predicting a resource demand of each virtual machine in a future preset time period; determining a resource competition conflict according to the predicted resource demand, and constructing a resource competition graph model; mapping the resource competition graph model into a non-cooperative game model; and determining a scheduling scheme in the cloud environment based on the non-cooperative game model, and executing a resource allocation operation according to the scheduling scheme. According to the method, potential conflicts can be identified and scheduled before resource competition actually occurs, and performance reduction caused by insufficient resources is reduced.
Owner:TIANJIN YINGXIN TECH CO LTD

Efficient file recovery from tiered cloud snapshots

A file system in a user space partition of virtual memory may be mounted by a computing device that runs a virtual machine which includes a set of storage disks. The file system in user space may then expose one or more virtual files associated with one or more storage disks that correspond to one or more loop devices configured to map files of the virtual machine to the one or more virtual files. The computing device may then receive a request to read a data block stored at the virtual machine and may identify a file and corresponding virtual file that stores the requested data block based on a set of metadata provided by the loop devices. The computing device may then determine the location of the data block stored at the virtual machine, and may read the data block from the determined location.
Owner:RUBRIK INC

Attestable deepfake detection and / or prevention

Implementations are described herein for detecting deepfakes in digital media while preserving the privacy of the source computing device. In various implementations, sensor fingerprints and / or security tokens that signal software-introduced alterations, e.g., introduced by hardware abstraction layers (HALs) or virtual machines (VMs) may be utilized to detect such deepfakes. These signals may be used, separately and / or in combination, for various purposes, such as flagging digital content to a user as being a deepfake, preventing or blocking receipt and / or playback of digital content deemed to be a deepfake, allowing an end user to disable aspect(s) (e.g., layers) of digital content that are determined to be synthetic, etc.
Owner:GDM HOLDING LLC

Cluster self-discovery method suitable for cloud server cipher machine

The invention relates to the technical field of information security, in particular to a cluster self-discovery method suitable for a cloud server cipher machine, which comprises the following steps: when physical equipment of the cloud server cipher machine leaves a factory, a certificate management module generates an equipment certificate and a root CA certificate in combination with an enterprise CA system, and stores the equipment certificate and the root CA certificate; after the virtual cipher machine is created and started, the key management service module combines with the certificate management module to generate a virtual machine certificate, and stores the virtual machine certificate, the storage device certificate and the root CA certificate together; the cluster management service module enables the master node of the virtual cipher machine to discover the slave node of the virtual cipher machine in the same network domain through UDP broadcast, and executes three-level verification on the slave node of the virtual cipher machine from three aspects of an equipment certificate, a virtual machine certificate and an authentication signature; and the virtual cipher machine master node synchronizes the cluster master key to the virtual cipher machine slave node passing verification. According to the invention, hierarchical identity isolation and verification of the cloud server cipher machine host and the virtual cipher machine can be realized, and the security of cluster self-discovery and authentication stages is ensured.
Owner:山东三未信安信息科技有限公司

Network security functions for dynamic construction and programmatic placement

A system and method are provided for placing network functions among respective locations in a network. The locations at which the network functions are placed can be nodes and network devices within the network. These nodes can be selected, e.g., based on which network devices have available capacity and or specialized hardware (e.g., accelerator sin a data processing units (DPUs)) that is optimized for particular network functions. The network functions can include an inline network function that is provisioned directly in a data plane of one of the network devices (e.g., in-lined directly in a hardware offload device without a virtual machine and without a container). The decision of where to place the network functions can be based on a performance metric (e.g., representing available computational / memory resources at the network nodes) and / or a network-function metric (e.g., representing consumed computational / memory resources by the network functions) to improve system performance.
Owner:CISCO TECHNOLOGY INC

Embedded system resource allocation method and system based on hardware virtualization

The invention discloses an embedded system resource allocation method and system based on hardware virtualization. The method comprises the following steps: deploying a Type-1 virtual machine monitor system on a multi-core processor hardware platform supporting virtualization extension; the Type-1 virtual machine monitor carries out virtualization, resource partitioning and security isolation on hardware resources, and creates operation system execution environment'domain 'partitions zoneG and zoneR. A universal operating system is deployed in a zoneG domain partition to take charge of a high-computing-power computing task, and a real-time operating system is deployed in a zoneR to take charge of a real-time computing task. Low-delay inter-core communication between a real-time operating system and a general operating system is realized based on an OpenAMP protocol, and data is transmitted through a shared memory and an interrupt mechanism; according to the requirements of real-time tasks and non-real-time tasks, a Type-1 virtual machine monitor dynamically adjusts a resource allocation strategy, and the priority and deadline of the real-time tasks are ensured.
Owner:NARI INFORMATION & COMM TECH

Secure key injection method and system

The invention discloses a secure key injection method and system, which are applied to electronic equipment with a rich execution environment and a secure virtual machine environment, and the method comprises the following steps: receiving a key injection request in the rich execution environment, and loading and starting the secure virtual machine environment; forwarding the key injection request to a secure virtual machine environment; generating a key pair in the secure virtual machine environment, and sending a public key certificate and an identity certificate of the key pair to a key management background through a rich execution environment; the key management background returns response data after verification is passed, and the response data is forwarded to the secure virtual machine environment through the rich execution environment; verifying the response data in the secure virtual machine environment; and after the verification is passed, storing the to-be-injected key material in the response data in the secure virtual machine environment. According to the invention, end-to-end security protection of the key material is realized through dual-environment cooperation, and the anti-attack capability and the data confidentiality of the injection process are effectively improved.
Owner:FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD

Server virtualization integration system and method

The invention relates to the technical field of server resource scheduling, in particular to a server virtualization integration system and method. The method comprises the following steps: executing a multi-dimensional reference pressure test on each NUMA node in a physical server cluster to generate physical node performance data; monitoring a virtual machine cache event of a tenant virtual machine in real time by utilizing the virtualization management platform, and determining tenant load snapshot data; evaluating the matching degree between the remote memory access demand of the virtual machine and the node localization supply capability according to the tenant load snapshot data, determining an optimal host migration target, and starting real-time migration of the virtual machine by the virtualization management platform to obtain a server migration integration process; and monitoring an abnormal state after migration in real time according to a server migration integration process so as to realize secondary forced scheduling integration request processing. According to the method, the optimal matching between the virtual machine and the physical node in the server is realized, the resource utilization efficiency is improved, and the cross-NUMA access overhead is reduced.
Owner:HEBEI JITONG ROAD&BRIDGE CONSTRUCT CO LTD

Method, device, equipment and medium for virtual machine to access cloud platform management network

The application discloses a method, device and equipment for a virtual machine to access a cloud platform management network and a medium, the method comprising: creating a first virtual bridge interworking with a business network on a physical node of a cloud platform; creating a virtual management network interworking with a management network on the physical node based on the first virtual bridge; connecting a virtual machine on the physical node with the virtual management network and configuring a default route when the virtual machine accesses the management network, so that the virtual machine can access the management network based on the virtual management network. The method provided by the application enables the virtual machine to access the cloud platform management network without changing the physical isolation of the cloud platform management network and the business network.
Owner:ANCHAO CLOUD SOFTWARE CO LTD

Interactive document editing canvas method and device

The invention discloses an interactive document editing canvas method, which comprises the following steps of: establishing a data-view mapping relation directly driven by a Vue2 responsive system between a canvas container and an element array, any addition, deletion and modification operation aiming at the node description data set can be instantly and accurately reflected to the style and attribute of the corresponding DOM child node without manual intervention, so that element positioning, rendering and follow-up editing are completed in the same technical action, the delay and inconsistency risk caused by frequent and direct operation of a real DOM in a traditional scheme is eliminated, and the operation efficiency is improved. The interaction fluency, the layout intuition and the system maintainability are obviously improved; by means of a virtual DOM mechanism of Vue2, batch diff is carried out and then submitted to a real DOM in a unified mode, the number of rearrangement and redrawing times of a browser is reduced, CPU and memory occupation is further reduced, and the canvas still keeps smooth response even in the scene with dense elements and frequent updating.
Owner:CHINESE PEOPLES LIBERATION ARMY INFORMATION SUPPORT CORPS ENGINEERING UNIVERSITY

Network security functions for dynamic construction and programmatic placement

A system and method are provided for placing network functions among respective locations in a network. The locations at which the network functions are placed can be nodes and network devices within the network. These nodes can be selected, e.g., based on which network devices have available capacity and or specialized hardware (e.g., accelerator sin a data processing units (DPUs)) that is optimized for particular network functions. The network functions can include an inline network function that is provisioned directly in a data plane of one of the network devices (e.g., in-lined directly in a hardware offload device without a virtual machine and without a container). The decision of where to place the network functions can be based on a performance metric (e.g., representing available computational / memory resources at the network nodes) and / or a network-function metric (e.g., representing consumed computational / memory resources by the network functions) to improve system performance.
Owner:CISCO TECHNOLOGY INC

Implementation architecture and implementation method for virtual machine to use DPU function and computing device

The invention provides an implementation architecture and implementation method for a virtual machine to use a DPU function and computing device.The implementation architecture is based on a DPU on which at least one function device is mounted and a host configured with the DPU, the implementation architecture comprises a virtual machine monitor, a DPU device aggregation layer and a DPU driving module, the virtual machine monitor comprises a DPU device simulation layer, and the DPU device aggregation layer comprises a DPU device aggregation layer and a DPU driving module; the DPU equipment simulation layer interacts with the DPU equipment aggregation layer; the DPU device aggregation layer interacts with the DPU driving module so as to provide the DPU and the hardware layer function of the function device mounted on the DPU for the DPU device simulation layer; and the DPU driving module is used for driving the DPU and the function equipment mounted on the DPU, and providing a use interface of the DPU and a use interface of the function equipment mounted on the DPU for the DPU equipment polymerization layer. According to the technical scheme, management and configuration can be simplified, the actual hardware function is decoupled from the equipment layer, and the management flexibility is improved.
Owner:SHENZHEN JAGUAR MICROSYSTEMS CO LTD

Data contract-oriented strategy real-time compiling and consistency hot deployment method and system

The invention belongs to the technical field of computer data security, and particularly relates to a data contract-oriented strategy real-time compiling and consistency hot deployment method and system.The method comprises the steps that according to a strategy input by a user, strategy definition and standardized representation are based on formalized semantics, and a data contract-oriented strategy is compiled in real time; constructing a strategy abstract syntax tree with complete semantic information; inputting the abstract syntax tree into a multi-stage compilation optimization pipeline, and generating a high-performance intermediate representation (IR) code by using a cost model driven optimization decision mechanism; a policy distribution architecture based on a publishing-subscribing model is adopted, and an improved Gossip protocol and a Paxos atomic submission algorithm are combined to realize distributed consistency synchronization and real-time hot deployment of a policy; and efficient and safe execution of the strategy is realized through a register type micro virtual machine and a self-adaptive execution mode. The problems that in the prior art, execution performance has bottleneck, strategy updating is delayed, complex strategy supporting capacity is weak, and cluster strategy consistency is difficult to guarantee are solved.
Owner:山东腾安信息科技有限公司

Server hybrid deployment and management system based on virtualization technology

The invention relates to the technical field of computer server resource management and network virtualization, and particularly discloses a server hybrid deployment and management system based on a virtualization technology, which comprises a uniform resource abstraction layer, a global resource sensing and modeling unit, a strategy-driven intelligent arrangement engine and a heterogeneous resource execution adapter. The uniform resource abstraction layer performs standardized abstraction on a physical server, a virtual machine and a container; the global resource sensing and modeling unit integrates the resource data and constructs a global resource model; a strategy-driven intelligent arrangement engine performs multi-objective optimization solution based on strategies and constraints to generate a scheduling scheme; the heterogeneous resource execution adapter translates the scheme into bottom executable atomic operations. According to the invention, unified management and intelligent cooperative scheduling of heterogeneous computing resources are realized, and the resource utilization efficiency and the system automation level are improved.
Owner:SHANGHAI PUSAI INTELLIGENT TECHNOLOGY CO LTD

Application upgrading method and device, equipment, terminal, storage medium and program

The embodiment of the invention discloses an application upgrading method and device, equipment, a terminal, a storage medium and a program.The method is applied to an operation system of a WebAssembly virtual machine and comprises the steps that a first upgrading instruction initiated by a to-be-upgraded application is received; the first upgrading instruction comprises application data retention indication information of the to-be-upgraded application; obtaining an old-version application corresponding to the to-be-upgraded application and an application data object of the old-version application according to application data retention indication information included in the first upgrading instruction, and storing application data in the application data object of the old-version application; receiving a second upgrading instruction initiated by the to-be-upgraded application; and recovering the application data in the application data object of the old-version application to the application data object of the new-version application corresponding to the old-version application according to the second upgrading instruction. According to the technical scheme provided by the embodiment of the invention, the application upgrading flexibility in the operation system of the WebAssembly virtual machine can be improved.
Owner:BEIJING TONGFANG MICROELECTRONICS

Cloud computing task scheduling method, device and system based on deep reinforcement learning

The invention discloses a cloud computing task scheduling method, device and system based on deep reinforcement learning, and the method comprises the steps: carrying out the preprocessing of a task, and obtaining the priority of the task; the task with the highest priority is selected according to the priorities of the tasks, partition selection is converted into a Markov decision process, the Markov decision process is executed through a first D3QN agent, and the tasks are distributed to corresponding virtual machine partitions; and converting task scheduling into a Markov decision process, and executing the Markov decision process through the second D3QN intelligent agent to distribute the tasks to the corresponding virtual machines so as to realize task scheduling. A task scheduling model is designed, task scheduling is regarded as a packing problem by the model, and resource requirements of tasks and execution capability of heterogeneous virtual machines are considered at the same time. Meanwhile, reduction of task completion time and maintenance of load balance of a cluster environment are taken as optimization objectives, so that multi-objective optimization of task scheduling is realized.
Owner:WUHAN UNIV

Multi-architecture chip compatible localized cloud platform virtualization method

The invention discloses a multi-architecture chip compatible localized cloud platform virtualization method, which is suitable for a localized cloud computing environment constructed by taking a localized CPU (Central Processing Unit) as a core. Comprising the following steps: when a plurality of domestic CPUs and compatible architecture information are collected at a bottom layer of a domestic cloud platform, establishing a unified hardware abstract model; constructing a virtualization compatibility layer on a domestic cloud platform virtual machine monitor; designing a cross-architecture virtual device agent module, and redirecting a domestic peripheral driver; and a unified scheduling and security isolation strategy is constructed, and efficient cooperation and trusted operation of the multi-architecture virtual machine under the localized cloud platform is realized. According to the method, instruction-level compatibility and unified operation environment construction of the heterogeneous chip in the localized cloud platform are realized, and the performance and stability of cross-architecture migration of the virtual machine are remarkably improved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD

ARM processor-oriented microkernel operating system confidential computing environment construction method

The invention relates to an operating system environment construction technology, and discloses an ARM (Advanced RISC Machines) processor-oriented micro-kernel operating system confidential computing environment construction method, which is characterized in that a hierarchical system architecture is constructed, a virtual machine monitor and a confidential domain management monitor are decoupled at an ARM exception level EL2, and the virtual machine monitor and the confidential domain management monitor run in mutually isolated address spaces. The RMM is used as an independent module for dynamic loading, a management mechanism of a confidential computing domain is specially used, and the Hypervisor is only responsible for strategy scheduling, so that the defect that the Hypervisor is bloated in function in a traditional scheme is overcome. According to the method, the RMM is loaded through the security startup process during startup, the confidential virtual machine is dynamically created during running, mirror image security verification, memory encryption and other mechanisms are integrated, and finally the security domain is destroyed after the application is finished. The method has the advantages that a flexible and safe confidential computing environment conforming to the minimum privilege principle is provided for the microkernel system, and the method is particularly suitable for embedded scenes with high safety requirements such as the Internet of Things and industrial control.
Owner:CHENGDU TIANRUAN TECHNOLOGY CO LTD

Byte code function retrieval method and device of Ethereum virtual machine and computer equipment

The invention relates to a byte code function retrieval method and device of an Ethereum virtual machine and computer equipment, and the method comprises the following steps: processing all byte codes in a byte code library of the Ethereum virtual machine to obtain all byte code functions; calculating a first similarity between the to-be-retrieved natural language query content and all byte code functions based on a pre-trained byte code retriever; inputting the natural language query content into a preset large model to generate a code language function corresponding to the intelligent contract function; calculating a second similarity between the code language function and all byte code functions based on a pre-trained specific retriever; and retrieving a target byte code function corresponding to the natural language query content according to the first similarity and the second similarity. Through the method and the device, the problem of low retrieval accuracy in related technologies is solved, the accurate target byte code function is retrieved on the basis of the first similarity and the second similarity, and then the retrieval recall rate and the retrieval accuracy are enhanced.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY

Firmware management engine for integrated system memory management and firmware provisioning

Methods, systems, and devices for providing firmware management using a firmware management engine of a cloud computing system are described. The firmware management engine supports using a hot-plugged memory (e.g., Compute Express Link (CXL) pooled memory) to temporarily migrate system memory (e.g., Central Processing Unit (CPU) local memory or CXL attached memory) of a server node, while performing firmware management operations (e.g., a firmware update) on the server node. The hot-plugged memory can be CXL pooled memory that is a shared at a rack level, the CXL pooled memory can be used to store system memory data of system memory while updating and activating new memory initialization firmware code. A virtual machine associated with the server node stays operational temporarily using the hot-plugged memory. Firmware management is performed on a server node while virtual machines associated with the server node and the system memory of the server node remain operational.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method for managing updates to a distributed network independent of hardware

A system and method for performing rolling updates of distributed applications in a software-defined network environment. An application manager coordinates deployment of updated versions of fxDeviceApp and fxCloudApp components to isolated execution environments on distinct network elements, such as edge devices and cloud-based containers or virtual machines. During the update process, the system establishes secure communication tunnels between the updated components using a virtual messaging fabric, verifies the integrity of the updated components before activation, and maintains service continuity by activating the new versions only after successful validation. The original application instances are decommissioned after the updated components are fully operational. The system supports dynamic scaling of execution environments based on load conditions, policy-governed update concurrency and ordering, coordinated deployment across multiple zones, automatic rollback on failure, and audit logging of deployment events. These mechanisms enable secure, resilient, and minimally disruptive application lifecycle management in distributed and programmable networking environments.
Owner:EDGE NETWORKING SYST LLC

NVMe storage array virtualization device based on FPGA

The invention discloses an NVMe storage array virtualization device based on an FPGA (Field Programmable Gate Array), which is characterized in that single I / O (Input / Output) virtualization (SR-IOV) is realized in the FPGA, and a plurality of NVMe virtual functions which can be directly accessed by a virtual machine are externally provided; mapping from a virtual volume logic address to a physical storage address is completed in hardware, striping management and RAID verification calculation are carried out on a plurality of NVMe solid state disks at the rear end, and storage resource pooling is achieved; the partial reconfigurable characteristic of the FPGA is utilized, I / O scheduling, data compression and prefetching strategies are dynamically adjusted, and the adaptability and performance efficiency of the system are improved. Hardware unloading of the whole I / O path is completed in the FPGA, intervention of a host CPU is not needed, delay is remarkably reduced, the throughput capacity is improved, service quality isolation and elastic expansion in a multi-tenant environment are supported, and an effective technical path is provided for constructing a next-generation high-performance and low-delay storage infrastructure.
Owner:CHINA SHIPBUILDING IND CORP NO 723 RESEARCH INSTITUTE

Full-automatic penetration testing method based on large language model

The invention discloses a full-automatic penetration testing method based on a large language model, and relates to the field of network security. The method comprises the following six core steps: 1) constructing a host asset model through multi-source data acquisition, integrating Shodan, Fofa and eagle map platform data, and performing LLM verification; 2) calling an NVD database to identify vulnerabilities, and secondarily verifying CVE validity by using LLM; 3) dynamically disassembling the penetration task based on a collaborative penetration decision tree (SPDT), and fusing ATTamp; guiding task planning by a CK technology and tactics map; (4) a multi-agent engine is adopted to execute a command, three interaction modes of Browser-use / CLI / GUI are supported, a Kali virtual machine is connected through an SSH to execute command line operation, and a graphical tool is driven based on a multi-mode model; according to the method, the problem that the automation degree of traditional penetration testing is low is solved, and the full-process automation of the penetration testing is achieved.
Owner:SICHUAN UNIV

Method and apparatus for passthrough of pcie device to virtual machine, and related device

A method and an apparatus for passthrough of a PCIe device to a virtual machine, and a related device are disclosed and may be applied to a computing device whose hardware resources are partitioned into an REE side and a TEE side. The computing device (300) includes a first PCIe device, and the TEE side includes the virtual machine. The method includes the following operations: A processor of the computing device (300) obtains a first instruction on the REE side, where the first instruction instructs to configure passthrough of the first PCIe device to the virtual machine on the TEE side. Then, the processor configures, on the TEE side, passthrough of the first PCIe device to the virtual machine according to the first instruction.
Owner:HUAWEI TECH CO LTD