Code Protection Architecture With Secure Heterogeneous Acceleration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software code protection solutions suffer from insufficient computing power due to limited utilization of hardware resources, particularly when integrating encryption and hardware isolation technologies, and face challenges in ensuring data security during heterogeneous acceleration.

Innovation Solution

The solution involves configuring a heterogeneous acceleration resource directly for the code protection system, utilizing a heterogeneous acceleration device without intermediation by the host, and employing a heterogeneous acceleration module and driving module to execute tasks, ensuring data security through identity confirmation and secure memory access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a code protection solution combines encryption technology and hardware isolation technology to provide an independent virtual runtime environment, then data security is improved, but computing power is insufficient

Engineering Contradiction:
Improvedata securityVSAvoidcomputing power
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a gatekeeper as an intermediary component between the virtual runtime environment and the host system. The gatekeeper manages access to hardware resources and coordinates communication between the protected code and external systems, enabling the code protection system to utilize host resources while maintaining security isolation. This resolves the contradiction by allowing secure data protection through the gatekeeper's mediation while improving computing power through controlled resource access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The code protection system is designed to perform multiple functions: it provides encryption for data confidentiality, hardware isolation for security, and through the gatekeeper mechanism, enables access to heterogeneous computing resources. This multi-functionality allows the system to maintain strong security protections while simultaneously improving computing power by leveraging various host resources including CPU, GPU, and other acceleration devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If heterogeneous acceleration resources are integrated into the code protection system, then computing power is improved, but data security during heterogeneous acceleration becomes challenging

Engineering Contradiction:
Improvecomputing powerVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the access to heterogeneous acceleration resources through the gatekeeper architecture. The gatekeeper divides resource access into controlled operations, managing data flow between the protected virtual environment and external acceleration devices. This segmentation allows computing power to be improved through heterogeneous resources while data security is maintained by isolating sensitive operations within the protected environment and controlling what data leaves the secure boundary.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gatekeeper serves as a security intermediary that mediates all interactions between the code protection system and heterogeneous acceleration resources. It validates operations, controls data flow, and ensures that security policies are enforced during heterogeneous acceleration. This intermediary mechanism enables the system to leverage powerful external resources while preventing security breaches, thus resolving the contradiction between improved computing power and maintained data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4394628B1Code protection system and method, virtual system architecture, chip and electronic device
Publication Date: 2025.12.03 HYGON INFORMATION TECH CO LTD
  • EP4394628B1 patent drawingFigure 1
  • EP4394628B1 patent drawingFigure 2
  • EP4394628B1 patent drawingFigure 3

AI summary

The present disclosure provides a code protection system, a method, a virtual system architecture, a chip, and an electronic device, and the system includes: a heterogeneous acceleration resource configured for the code protection system, in which the heterogeneous acceleration resource is configured to execute a code execution task of a piece of software, and the code execution task includes running code of the software and/or accessing data of the software; a heterogeneous acceleration module, which is configured to allocate the code execution task to the heterogeneous acceleration resource configured for the code protection system; and a heterogeneous acceleration driving module, which is configured to drive the heterogeneous acceleration resource configured, to execute the code execution task allocated. The embodiments of the present disclosure are capable of enhancing the computing power of code protection solutions.