Encryption of executables in computational memory
Abstract
The present invention relates to the encryption of executable instructions in computing memory. The computing memory can traverse an operating system page table in the computing memory to find a page marked as an executable command. In response to finding a page marked as an executable command, the computing memory can determine whether the page marked as an executable command is encrypted. In response to determining that the page marked as an executable instruction is not encrypted, the computing memory can generate a key for the page marked as an executable instruction. The computing memory can use the key to encrypt the page marked as executable.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
25 claims: 8 independent, 17 dependent
- 1A method comprising:traversing an operating system page table in the computing memory by computing memory to find a page marked as an executable command;in response to finding a page marked as an executable command, determining that the label is Whether the page of the executable instruction is encrypted;in response to determining that the page marked as an executable instruction is not encrypted, a key is generated for the page marked as an executable instruction;and the key is used to encrypt the instruction marked as executable This page. 一種方法,其包括: 藉由計算記憶體周遊該計算記憶體中之一作業系統頁面表以尋找標記為可執行指令之一頁面; 回應於尋找到標記為可執行指令之一頁面,判定標記為可執行指令之該頁面是否已加密; 回應於判定標記為可執行指令之該頁面未加密,針對標記為可執行指令之該頁面產生一密鑰;及 使用該密鑰加密標記為可執行指令之該頁面。
- 8A method comprising:traversing an operating system page table in the computing memory by computing memory to find any page marked as an executable command;in response to finding a first page marked as an executable command, determining Whether the first page marked as an executable instruction is encrypted;in response to determining that the first page marked as an executable instruction is not encrypted, a first key is generated for the first page marked as an executable instruction;using the The first key encrypts the first page marked as an executable instruction;in response to finding a second page marked as an executable instruction, it is determined whether the second page marked as an executable instruction is encrypted;in response to the determination mark The second page that is an executable instruction is not encrypted, and a second key is generated for the second page marked as an executable instruction;and the second key is used to encrypt the second page that is marked as an executable instruction. 一種方法,其包括: 藉由計算記憶體周遊該計算記憶體中之一作業系統頁面表以尋找標記為可執行指令之任何頁面; 回應於尋找到標記為可執行指令之一第一頁面,判定標記為可執行指令之該第一頁面是否已加密; 回應於判定標記為可執行指令之該第一頁面未加密,針對標記為可執行指令之該第一頁面產生一第一密鑰; 使用該第一密鑰加密標記為可執行指令之該第一頁面; 回應於尋找到標記為可執行指令之一第二頁面,判定標記為可執行指令之該第二頁面是否已加密; 回應於判定標記為可執行指令之該第二頁面未加密,針對標記為可執行指令之該第二頁面產生一第二密鑰;及 使用該第二密鑰加密標記為可執行指令之該第二頁面。
- 11A non-transitory computer-readable medium that stores instructions executable by computing memory to:determine whether a requested page of the instructions marked as executable in the computing memory is encrypted;in response to determining that the requested page is not encrypted: Store the requested page in the cache area of the computing memory;generate a key;use the key to encrypt the requested page;and replace the requested page and store the encrypted page in the computing memory And in response to determining that the requested page is encrypted: generate a new key;use the new key to re-encrypt the requested page;replace the requested page, and store the re-encrypted page in the computing memory ;And decrypt the requested page and store the decrypted page in the cache area of the computing memory. 一種非暫態電腦可讀媒體,其儲存可由計算記憶體執行之指令以: 判定該計算記憶體中之標記為可執行指令之一經請求頁面是否已加密; 回應於判定該經請求頁面未加密: 將該經請求頁面儲存於該計算記憶體之快取區中; 產生一密鑰; 使用該密鑰加密該經請求頁面;及 取代該經請求頁面,將該已加密頁面儲存於該計算記憶體中;及 回應於判定該經請求頁面已加密: 產生一新密鑰; 使用該新密鑰重新加密該經請求頁面; 取代該經請求頁面,將該重新加密之頁面儲存於該計算記憶體中;及 解密該經請求頁面且將該已解密之頁面儲存於該計算記憶體之該快取區中。
- 12Such as the medium of request 11, wherein the instructions are executable to transfer the requested page or the decrypted page from the cache to a source of the request. 如請求項11之媒體,其中該等指令可執行以將該經請求頁面或該已解密頁面從該快取區傳送至該請求之一來源。
- 14A device comprising:a computing memory;and an operating system page table stored in the computing memory, wherein the operating system page table includes: an indication of whether the respective page is encrypted;for the encrypted A respective key of one of each page;a virtual address corresponding to the respective page;a physical address corresponding to the respective page;and a mark of a type of the respective page;and the computing memory is configured in it To maintain the operating system page table. 一種設備,其包括: 一計算記憶體;及 一作業系統頁面表,其儲存於該計算記憶體中,其中該作業系統頁面表包含: 一各自頁面是否已加密之一指示; 用於已加密之各頁面之一各自密鑰; 對應於該各自頁面之一虛擬位址; 對應於該各自頁面之一實體位址;及 該各自頁面之一類型之一標記;及 其中該計算記憶體經組態以維持該作業系統頁面表。
- 19A device comprising:a computing memory configured to: according to one of the operating system page tables in the computing memory by the computing memory, the response is that the first page is unencrypted and responds Encrypting a first page by marking the first page as an executable command;responding to the second page being unencrypted and responding to the second page being requested and encrypting a second page marked as executable commands;and responding to The third page has been encrypted and is re-encrypted in response to the request of the third page to re-encrypt a third page marked as an executable command. 一種設備,其包括: 一計算記憶體,其經組態以: 根據藉由該計算記憶體對該計算記憶體中之一作業系統頁面表之一周遊,回應於該第一頁面未加密且回應於該第一頁面標記為可執行指令,加密一第一頁面; 回應於該第二頁面未加密且回應於該第二頁面經請求而加密標記為可執行指令之一第二頁面;及 回應於該第三頁面已加密且回應於該第三頁面經請求而重新加密標記為可執行指令之一第三頁面。
- 23Such as the device of request 22, wherein the computing memory is configured to transfer the second page from the cache in response to a subsequent request for the second page. 如請求項22之設備,其中該計算記憶體經組態以回應於對該第二頁面之一隨後請求而自該快取區傳送該第二頁面。
- 25A method, comprising:receiving a request for a page stored in a computing memory;determining whether the requested page has been marked as an executable command in an operating system page table in the computing memory;determining Whether the requested page has been indicated as encrypted in the operating system page table in the computing memory;and in response to determining that the requested page is executable and encrypted: generate a new key;use the new key Re-encrypt the requested page;replace the requested page, store the re-encrypted page in the computing memory;decrypt the requested page and store the decrypted page in the cache of the computing memory ;And send the decrypted requested page from the cache to satisfy the request. 一種方法,其包括: 接收對儲存於一計算記憶體中之一頁面之一請求; 判定該經請求頁面是否已在該計算記憶體中之一作業系統頁面表中被標記為可執行指令; 判定該經請求頁面是否已在該計算記憶體中之該作業系統頁面表中被指示為已加密;及 回應於判定該經請求頁面可執行且已加密: 產生一新密鑰; 使用該新密鑰重新加密該經請求頁面; 取代該經請求頁面,將該重新加密之頁面儲存於該計算記憶體中; 解密該經請求頁面且將該已解密頁面儲存於該計算記憶體之該快取區中;及 自該快取區傳送該已解密經請求頁面以滿足該請求。
Independent claims8
9 paragraphs in 1 section, as filed
Encryption of executable instructions in computing memory
ENCRYPTION OF EXECUTABLES IN COMPUTATIONAL MEMORY
The present invention generally relates to semiconductor memory and methods, and more specifically, the present invention relates to the encryption of executable instructions in computing memory.
Memory devices are usually provided as internal, semiconductor, and integrated circuits in computing devices or other electronic devices. There are many different types of memory, including volatile memory and non-volatile memory. Volatile memory may require power to maintain its data (for example, user data, error data, etc.) and includes random access memory (RAM), dynamic random access memory (DRAM), and synchronous dynamic random access memory (SDRAM) and others. Non-volatile memory can provide persistent data by keeping stored data when it is not powered and can include NAND flash memory, NOR flash memory, read-only memory (ROM), and electrically erasable Programmable ROM (EEPROM), erasable programmable ROM (EPROM) and resistance variable memory (such as phase change random access memory (PCRAM), resistive random access memory (RRAM) and magnetic Resistive random access memory (MRAM), such as spin torque transfer random access memory (STT RAM)) and others. The computing system usually includes a number of processing resources (for example, one or more processors), which can retrieve and execute instructions and store the results of the executed instructions to a suitable location. A processor may include several functional units (for example, referred to herein as functional unit circuits (FUC)), such as arithmetic logic unit (ALU) circuits, floating point unit (FPU) circuits, and/or a combinational logic block, for example , And other executable instructions to perform logical operations on data (for example, one or more operands) (such as "and", "or", "not", "inverse and", "inverse or" and "mutually exclusive or "logic operation). Several components in a computing system may be involved in providing instructions to functional unit circuits for execution. The instructions may be generated by, for example, a processing resource such as a controller and/or host processor. Data (for example, operands on which instructions are executed to perform logical operations) can be stored in a memory array that can be accessed by FUC. Commands and/or data can be retrieved from the memory array and can be serialized and/or buffered before the FUC starts to execute commands on the data. In addition, because different types of operations can be performed in one or more clock cycles through FUC, intermediate results of operations and/or data can also be serialized and/or buffered. In many cases, the processing resources (for example, the processor and/or the associated FUC) can be located outside the memory array, and data can be accessed (for example, via a bus between the processing resource and the memory array) To execute instructions. Data can be moved from the memory array to a register outside the memory array via a bus.
<disclosure></disclosure>
Most modern computer architectures use a register-memory technology in which operations are performed in two separate domains. Logical operations (for example, arithmetic, flow control, and combination operations) are usually performed on a number of register files. Generally, memory operations (for example, loading, storing, etc.) are performed on the memory device. Instructions in the register-memory architecture use register index or memory address to indicate how/where to perform an operation. Computing memory, such as processing in memory (PIM) or processing near memory devices, can be classified as inter-memory devices in the computing architecture taxonomy. In computing memory, both logical operations and memory operations are performed on the memory device in-situ. Instructions in the inter-memory architecture use physical addresses to indicate how/where to perform an operation. Attempts to attack or insert malicious software into a computing system usually include a virus or malware that changes the flow of instructions or instructions executed by the host processor. Some embodiments of the invention use computational memory to encrypt executable instructions (executable instructions, such as host processor instructions). Encryption can be polymorphic to randomize executable instructions, so that an attacker will have to know the encryption state in order to inject malicious software that will have a negative impact on the system. The randomization of executable instructions can obfuscate and/or change executable instructions to create a binary diversity ecosystem, which can reduce and/or eliminate a source of malware and/or system leaks. Any malware that attempts to inject code (for example, binary injection, buffer overflow attack, Morris worm, Code Red, Blaster virus, uniform resource locator (URL) accumulation Vulnerabilities, etc.) will have to understand the underlying instruction set architecture in order to run the code. The present invention relates to the encryption of executable instructions in computing memory. The computing memory can traverse an operating system page table in the computing memory to find a page that is marked as an executable command. In response to finding a page marked as an executable command, the computing memory can determine whether the page marked as an executable command is encrypted. In response to determining that the page marked as an executable command is not encrypted, the computing memory can generate a key for the page marked as an executable command. The computing memory can use the key to encrypt the page marked as executable. Some embodiments of the present invention provide encryption for executable instructions instead of data, which advantageously allows data to be changed, read, written, etc. without an encryption and/or decryption process, and at the same time can be used as a specific attacker. The executable instructions of the target provide protection. Executable instructions are generally referred to herein as executables. In the following detailed description of the present invention, reference is made to the accompanying drawings (which form a part of the present invention, and therein are shown diagrammatically how several embodiments of the present invention can be practiced). These embodiments are described in sufficient detail to enable those of ordinary skill to practice the embodiments of the present invention, and it should be understood that other embodiments are available, and procedures, circuits, and procedures can be made without departing from the scope of the present invention. / Or structural changes. As used herein, the identifiers "M" and "N" (especially for the element symbols in the drawing) indicate that a number of specific features marked as such may be included. As used herein, "a number of" specific things can refer to one or more of these things (for example, a number of memory devices can refer to one or more memory devices). As used herein, the terms "first" and "second" are used to distinguish one feature from another, and do not necessarily imply an order between the features so marked. The figures in this text follow a numbering convention, where the first number corresponds to the figure number of the figure and the remaining figures identify one of the elements or components in the figure. Similar elements or components between different figures can be identified by using similar numbers. For example, 110 may refer to element "10" in FIG. 1, and a similar element may be referred to as 210 in FIG. An element symbol followed by a hyphen and another number or letter can be used to refer to multiple similar elements in a drawing. For example, 240-1 may refer to element 20-1 in FIG. 2 and 240-N may refer to element 40-N which may be similar to element 240-1. These similar elements can usually be referred to without hyphens and additional numbers or letters. For example, the elements 240-1, ..., 240-N may be collectively referred to as 240. As should be appreciated, the elements shown in the various embodiments herein can be added, exchanged, and/or eliminated in order to provide several additional embodiments of the present invention. In addition, it should be understood that the ratios and relative scales of the elements provided in the figures are intended to illustrate certain embodiments of the present invention, and should not be construed as limiting. 1 is a block diagram of a device in the form of a computing system 100 including at least one computing memory system 104 according to several embodiments of the present invention. As used herein, a host 102, a computing memory system 104, a computing memory device 110, a memory array 111 and/or a sensing circuit 124 (including a sense amplifier and a computing circuit) can each be viewed separately It is a "device". The computing system 100 may include a host 102 coupled to a computing memory system 104 that includes a computing memory device 110 (for example, including a memory array 111 and/or sensing circuit 124). The computing memory system 104 can serve as a conventional memory and/or a computing memory. The host 102 may be a host system, such as a personal laptop computer, a desktop computer, a digital camera, a mobile phone or a memory card reader, and various other types of hosts. The host 102 may include a system motherboard and/or backplane and may include several processing resources (for example, one or more processors, microprocessors, or some other types of control circuits), such as a central processing unit (CPU) 106. The CPU 106 may be coupled to the mass storage 114. The mass storage 114 may be a storage device or other media that cannot be directly accessed by the CPU 106, such as a hard disk drive, a solid state disk, an optical disk drive, and may be a non-volatile memory. In some embodiments, the mass storage 114 may be located outside the host 102. The host 102 can be configured with an operating system. The operating system is an executable command (software) that manages hardware resources and provides services for other executable commands (applications) running on the operating system. The operating system can implement a virtual memory system. The CPU 106 may include a translation lookaside buffer (TLB) coupled to 120 and a logic unit 118 of the CPU cache 122. An example of a logic unit 118 is an arithmetic logic unit (ALU), which is a circuit that can perform arithmetic and bitwise logic operations on integer binary numbers. A number of ALUs can be used to act as a floating point unit (FPU) and/or graphics processing unit (GPU). The floating point unit is a circuit that calculates the number of floating points. The graphics processing unit is designed to accelerate output to a display. A circuit for generating the image in the frame buffer. TLB 120 is a cache area for memory management hardware that can be used to improve the speed of virtual address translation. The TLB 120 can be a content addressable memory, where the search index key is a virtual address and the search result is a physical address. As described in more detail with respect to FIGS. 3 to 5, the TLB 120 may include operating system page table entries that map virtual addresses to physical addresses and the operating system page tables may be stored in memory (eg , Memory array 111). The CPU cache 122 may be an intermediate stage (not shown in detail) between the relatively fast register and the relatively slow main memory. The data to be operated by the CPU 106 can be copied to the CPU cache 122 before being placed in a register, where the operation can be affected by the logic unit 118. Although not specifically shown, the CPU cache area 122 may be a multi-level hierarchical cache area. The computing system 100 may include individual integrated circuits, or both the host 102 and the computing memory system 104 may be on the same integrated circuit. The computing system 100 may be, for example, a server system and/or a high-performance computing system and/or a part of the high-performance computing system. Although the example shown in FIG. 1 shows a system with a Von Neumann architecture, the embodiments of the present invention can be implemented in a non-Von Neumann architecture (for example, a Turing machine). The non-Van Neumann architecture may not include one or more components (eg, CPU, ALU, etc.) that are usually associated with a van Neumann architecture. For clarity, the computing system 100 has been simplified to focus on features specifically related to the present invention. The memory array 111 may be a hybrid memory cube (HMC), computing memory, such as a processing in memory random access memory (PIMRAM) array, which may include, for example, a DRAM array , SRAM array, STT One or more of RAM array, PCRAM array, TRAM array, RRAM array, NAND flash array and/or NOR flash array. The memory array 111 may include columns configured to be coupled by access lines (which may be referred to herein as word lines or select lines) and rows coupled by sensing lines (which may be referred to herein as digit lines or data lines) The memory cell. Although a single computing memory device 110 is shown in FIG. 1, the embodiment is not limited thereto. For example, the computing memory system 104 may include several computing memory devices 110 (for example, several memory banks of DRAM cells). The computing memory system 104 may include an address circuit 126 for latching through an input/output "I/O" bus 138 (for example, a data bus and/or address bus) provided through the I/O circuit 130 The address signal (for example, provided to the external ALU circuit and DRAM via the local I/O line and the global I/O line DQ). The address signal can be received and decoded by a column decoder 128 and a row decoder 134 to access the computing memory device 110. Data can be read from the memory array 111 by using the sensing circuit 124 to sense voltage and/or current changes on the sensing line. The sensing circuit 124 can read a page (for example, a row) of data from the memory array 111 and latch the page of data. The I/O circuit 130 can be used for bidirectional data communication with the host 102 via the I/O bus 138. The writing circuit 132 can be used to write data to the computing memory device 110. The controller 108 can decode the signal provided by the control bus 136 from the host 102. These signals may include chip enable signals, write enable signals, and address latch signals for controlling memory operations (including data reading, data writing, and data erasing operations) performed on the computing memory device 110. Signals can also be used to control logical operations performed on the computing memory device 110, including arithmetic, process control, and combination operations, among others. In various embodiments, the controller 108 is responsible for executing instructions from the host 102. The controller 108 can be a state machine, a sequencer, a processor, and/or other control circuits. In some previous methods, data associated with (for example) a logical operation will be read from memory via sensing circuits and via I/O lines (for example, via local I/O lines and/or global I/ O line) and provided to the external ALU circuit. The external ALU circuit may include a number of registers and will use the data (which may be called operands or inputs) to perform logic operations, and the results will be sent back to the array via the I/O line. In contrast, in some embodiments of the present invention, the sensing circuit 124 is configured to perform logical operations on the data stored in the memory array 111 and store the result back to the memory array 111 without enabling coupling One of the I/O lines to the sensing circuit 124 (for example, a local I/O line). Enabling an I/O line may include: enabling (for example, turning on) a gate having a gate coupled to a decoded signal (for example, a row of decoded signals) and a source/drain coupled to the I/O line Transistor. However, the embodiment is not limited to not enabling an I/O line. For example, in some embodiments, the sensing circuit 124 can be used to perform logic operations without enabling the row decode lines of the array; however, in addition to transmitting back to the array 111, the local I/O line(s) can be enabled to A result is sent to a suitable location (for example, to an external register). Therefore, in some embodiments, circuits outside the array 111 and the sensing circuit 124 are not required to perform logic operations. This is because the sensing circuit 124 can operate to use the address space of the memory array 111 to perform logic operations. Use an external processing resource. Therefore, the sensing circuit 124 can be used to supplement and/or replace the external processing resource (or at least the bandwidth consumption of the external processing resource) at least to some extent. The sensing circuit 124 can be formed on the distance from the memory cells of the array. Although not specifically shown, in some embodiments additional peripheral sense amplifiers and/or logic (for example, functional components each storing instructions for execution of a logic function) may be coupled to the sensing circuit 124. The sensing circuit 124 and the peripheral sensing amplifier and logic may cooperate to perform logic operations according to the embodiments described herein. However, in some embodiments, the sensing circuit 124 can be used to perform other logical operations (for example, executing instructions) in addition to the logical operations performed by an external processing resource (for example, the host 102). For example, the host 102 and/or the sensing circuit 124 may be limited to only perform a specific logic operation and/or a specific number of logic operations. An example of the sensing circuit 124 is further described below in conjunction with FIG. 2. For example, in some embodiments, the sensing circuit 124 can include a number of sense amplifiers and a number of computing components, which can include a latch used as an accumulator and can be used (e.g., to be associated with complementary sensing lines)The data) Perform logical operations. Logical operations can include Boolean operations (for example, "AND", "OR", "NOR", "XOR", etc.), combinations of Boolean operations used to perform other mathematical operations, and non-Boolean operations. In some embodiments, the sensing circuit 124 can be used to perform logical operations using data stored in the memory array 111 as input, and store the result of the logical operation back to the memory array 111 without passing through a sensing line address Access transfer (for example, do not trigger a row of decoded signals). Thus, instead of processing resources external to the sensing circuit 124 (for example, by the host CPU 106 and/or other processing circuits located on the computing memory system 104 (such as on the controller 108) or elsewhere (such as ALU circuits) To perform a logical operation and/or in addition to it, the sensing circuit 124 may be used to perform a logical operation. FIG. 2 is a schematic diagram of a part of a computing memory device 210 according to one of several embodiments of the present invention. The computing memory device 210 is similar to the computing memory device 110 shown in FIG. 1. The computing memory device 210 may include a memory array 211 that includes column access lines 242-1, 242-2, 242-3, 242-4, 242-5, 242-6, 242-7,...,242-M and the rows of sensing lines 244-1, 244-2, 244-3, 244-4, 244-5, 244-6, 244-7, 244-8,..., 244- N memory cells 240-1, 240-2, 240-3, 240-4, 240-5, 240-6, 240-7, 240-8,..., 240-N. The memory array 211 is not limited to a specific number of access lines and/or sensing lines, and the use of the terms "row" and "row" does not imply a specific physical structure and/or orientation of the access lines and/or sensing lines . Although not shown, each row of the memory cell can be associated with a pair of corresponding complementary sensing lines. Each row of the memory cell can be coupled to a sensing circuit 224 which can be similar to the sensing circuit 124 shown in FIG. 1. In this example, the sensing circuit includes a number of sensing amplifiers 246-1, 246-2, 246-3, 246-4, 246-5, 246-6, 246-7, 246- coupled to respective sensing lines 244. 8...., 246-N. The sense amplifier 246 is accessed via an access device (for example, a transistor) 250-1, 250-2, 250-3, 250-4, 250-5, 250-6, 250-7, 250-8,..., 250- N is coupled to input/output (I/O) line 254 (For example, a local I/O line). In this example, the sensing circuit also includes a number of computing components 248-1, 248-2, 248-3, 248-4, 248-5, 248-6, 248-7, 248- which are coupled to the respective sensing lines 244. 8....248-N. Row decoding lines 252-1, 252-2, 252-3, 252-4, 252-5, 252-6, 252-7, 252-8,..., 252-N are respectively coupled to the gates of the access device 250 , And can be selectively activated to transmit the data sensed by the respective sense amplifier 246 and/or stored in the respective calculation component 248 to the primary sense amplifier 256. In some embodiments, the computing component 248 may be formed between the memory cell of its corresponding row and/or the distance between the corresponding sensor amplifier 246. In some embodiments, the sensing circuit (for example, the computing component 248 and the sense amplifier 246) is configured to perform a number of logical operations on the elements stored in the array 211. As an example, the first plurality of elements can be stored in a first group of memory cells coupled to a specific access line (for example, access line 242-1) and one of the plurality of sensing lines 244, and the The second plurality of elements are stored in a second group of memory cells coupled to a different access line (for example, access line 242-2) and one of the plurality of sensing lines 244 respectively. Each of the second plurality of elements can be used to perform a logical operation on each element of the first plurality of elements, and the result of the logical operation (for example, as a one-bit vector) can be stored in the coupling to a specific access Line (for example, access line 242-3) and one of several sensing lines 244 in the memory cell of the third group. FIG. 3 is a block flow diagram showing a read or write access according to one of several embodiments of the present invention. Figures 3 to 6 show different flowcharts showing the operation of similar architectures. FIG. 3 includes an illustration of a mass storage device 314 similar to the mass storage 114 described with respect to FIG. 1. The function of the mass storage device 314 is described in more detail with respect to FIG. 4. FIG. 3 includes a CPU 306 similar to the CPU 106 shown in FIG. 1. The CPU 306 is shown as including a logic unit 318, TLB 320 and CPU cache area 322. 3 includes a computing memory system 304. The computing memory system 304 includes an I/O circuit 330, a memory array 311, and a computing memory system cache 312. The computing memory system cache area 312 is described in more detail with respect to FIGS. 5-6. The memory system 304 is similar to the memory system 104 shown in FIG. 1. The memory system 304 is shown as including an operating system page table 316. Although the operating system page table 316 may be stored in the memory array 311, the operating system page table 316 is shown separately for ease of illustration and explanation. Similarly, the calculation memory program 342 can be stored in the memory array 311, but is shown separately to highlight the functional flow described in relation to FIGS. 3-6. The memory system 304 may include an entropy source 340 as described in more detail below. Some embodiments of the present invention enable the CPU 306 and the underlying architecture remain unchanged from the conventional situation of the CPU. However, the computing memory system 304 may operate differently, and/or an operating system of a host may operate differently from the conventional situation. Conventionally, the operating system can maintain an operating system page table. However, according to the present invention, the computing memory system 304 can maintain an operating system page table 316. This is because the computing memory system 304 can encrypt and/or decrypt stored in the memory The page in the body is indicated in the operating system page table and a key can be generated for the encrypted page and stored in the operating system page table. The computing memory system 304 can generate a new key for an encrypted page and re-encrypt the page immediately. The host CPU 306 may include a TLB 320 in its memory hierarchy, but the operating system page table 316 is stored in the memory array 311. Once a page is missing (for example, when loading executable instructions into the memory array 311), the page may need to be loaded from the mass storage 314 and loaded and placed in the reserved area of the physical and virtual memory. The reservation can be managed by the operating system and maintained in the operating system page table 316. The operating system page table 316 can be located in a reserved area of the memory array 311. For example, in an ARM architecture, the ARM memory management unit (MMU) can use the registers TTB0 and TTB1 to point to the operating system page table to allow hardware walking of the table in the case of a page miss. Since the operating system page table 316 is located in the memory array 311, the computing memory system 304 has programmatic access to the structure of the operating system page table 316, which means that the computing memory system 304 can make changes to the operating system page table 316 . The operating system page table 316 may include a number of fields indicating information about the page referred to by the operating system page table 316. These fields may include an encryption instruction field 346, a key field 348, a virtual address field 350, a physical address field 352, a page type field 354, and/or a size field 356 . The encryption indication field 346 can indicate whether the corresponding page is encrypted (for example, by a bit value of 1 for yes, or a bit value of 0 for no). If the corresponding page is encrypted, the key field 348 can store a key of the corresponding page. If the corresponding page is not encrypted, a key may not be stored in the key field 348 for the corresponding page because it will be unnecessary. The virtual address field 350 can store a virtual address corresponding to a page. The physical address field 352 can store a physical address corresponding to the page. The page type field 354 can mark the type of the corresponding page (for example, read "R", write "W", read/write "R/W", or execute "X"). The type of page indicates whether the page stores data or executable commands, among other things. The size field 356 may indicate the size of one of the corresponding pages (for example, 4k). An example of a table is shown in Table 1.<b>surface</b><b>1</b><b>:</b><tables><table><img wi="409" he="114" file="tw201719489a_d0001.tif" alt="" img-content="drawing" img-format="jpg" orientation="portrait" inline="no" /></table></tables>In some embodiments, the operating system page table 316 may not be cached in order to preserve the correlation among the information in the operating system page table 316, the CPU 306, and the memory array 311. The computing memory system 304 can be configured (eg, programmed) to navigate the operating system page table 316 in the memory array 311, for example, to find a page marked as an executable command. For example, the computing memory system 304 may include a computing memory program 342 that can handle the page table 316 of the traveling operating system. The pages referred to in the operating system page table 316 can store data or executable commands. Therefore, a page referred to in the operating system page table 316 can be marked as an executable command by a mark in the page type field 354. Page type read, write, and read/write can mark data pages (a page of stored data) and page type executable commands can mark a page of executable commands (a page of stored executable commands). The computing memory system 304 can be configured to encrypt and/or decrypt executable instructions. For example, the computing memory system 304 may include a computing memory program 342 that can handle encryption and/or decryption of executable instructions. In some embodiments, the computing memory program 342 may be filled in the computing memory system 304 during a page miss period of executable instructions, and/or (e.g., from the CPU 306 performs a cache line refill period) when the executable instruction is read from the computing memory system 304, the encryption and/or decryption of the executable instruction is processed. An indication of whether a page is encrypted can be stored in the encryption indication field 346. In some embodiments, the host operating system can activate the computing memory program 342 in the computing memory system 304 as indicated by the line between the I/O circuit 330 and the computing memory program 342 (eg, at startup). After the computing memory program 342 runs, the responsibility of the host operating system can end with regard to encryption. The computing memory system 304 can include an entropy source 340 that can generate a key and/or be used to generate a key for a page marked as an executable instruction to encrypt the page with the key. The key may be generated based on a random number or near random number generated by the entropy source 340. An example of the entropy source 340 is a phase locked loop (PLL) frequency (e.g., a PLL clock), which can be sampled to generate a number to be used as a key. An example of the entropy source 340 is a serial number associated with the computing memory system 304, which can be sampled to generate one of the inputs to an algorithm that will be used as a key and/or to generate another value Number, the other value can be sampled (or used) to generate a number to be used as a key. An example of an entropy source 340 is a timer, which can be sampled to generate a number to be used as a key. In some embodiments, a key can be generated by a sampled PLL frequency, exclusive OR (XOR) by a sampled sequence number, and XOR by a sampled timer. The computing memory system 304 can be configured to encrypt or re-encrypt pages in the memory array 311 using the unique key generated by the entropy source 340. Other entropy sources and/or combinations of entropy sources can be used to generate a random or nearly random number. As described above, according to the present invention, encryption is not necessary for data reading or writing operations. The computing memory program 442 can grant access to a data page (a page marked as read, write, and/or read/write) in the operating system page table 316, regardless of encryption. Therefore, a data page 358 can be transmitted through the I/O circuit 330 between the memory array 311 and the CPU 306 (for example, via the CPU cache area 322) and stored in the memory array 311 or read from the memory array 311 . For example, in a read/write operation, a virtual memory address (for example, "A") from TLB 320 can be transferred to and from the computing memory system 304 and retrieved from and/or stored in the corresponding write The virtual address field 350 of item 344 in the first table of the data page 358 of. A physical address (for example, "B") corresponding to the virtual address can be retrieved from and/or stored in the physical address field 352 of the first table entry 344. This is extended to item 344 and TLB in Table 1. The line between 320 indicates. Because the transmitted data page 358 is not an executable command, the calculation memory program 342 can be as indicated by the line between the calculation memory program 342 and the first table entry 344 in the encryption instruction of the first table entry 344 The page is marked as unencrypted in field 346 (for example, "0"). The calculation memory program may not store a key in the key field 348 of the first table entry 344 (for example, "N/A") because it corresponds to an unencrypted data page 358. The calculation memory program 342 can store an indication (for example, "R/W") of the data page 358 as an indication of read/write in the page type field 354 and an indication of the page size (for example, "4k") Stored in the size field 356. In Figures 4 to 6, the items in the first table are labeled 444, 544, and 644, respectively. 4 is a block flow diagram showing a new page allocation according to several embodiments of the present invention. FIG. 4 includes a diagram of a large-capacity storage device 414 that includes executable instructions 461. Fig. 4 includes a CPU 406, the CPU 406 includes a logic unit 418, TLB 420 and CPU cache area 422. 4 includes a computing memory system 404, which includes I/O circuit 430, memory array 411, computing memory system cache 412, operating system page table 416, computing memory program 442, and entropy Source 440. The mass storage 414 can store executable instructions 461 for the CPU 406. As indicated by the arrow from the mass storage device 414 through the I/O circuit 430 to the memory array 411, the executable command 461 can be loaded by direct memory access (DMA) from the mass storage device 414 The memory array 411. Initially, the executable instructions 461 from the mass storage device 414 are stored as a plain text executable instruction page 462 in the memory array 411 because they are not encrypted in the mass storage device 414. The computing memory program 442 can generate a second table entry 460 in the operating system page table 416 to correspond to the plain text executable instruction page 462 in the memory array 411. Because the plain text executable instruction page 462 has not been encrypted, the computing memory program 442 can mark the plain text executable instruction page 462 as unencrypted in the encryption indication field 446 of item 460 in the second table (for example, "0") . Similarly, a key (for example, "-") is not stored in the key field 448 of the second table entry 460. Can be from TLB A virtual memory address (for example, "C") of 420 is transmitted to the computing memory system 404 and stored in the virtual address field 450 of the second table entry 460. A physical address (for example, "D") corresponding to the virtual address can be stored in the physical address field 452 of the second table entry 460. This is indicated by the line extending between the second table entry 460 and the TLB 420. As indicated by the line between the calculation memory program 442 and the second table item 460, the calculation memory program can mark the plain text executable command page 462 as an executable command in the type field 454 of the second table item 460 ( For example, "X"). The correspondence between the unencrypted plain text executable instruction page 462 and this instruction is drawn by the line between the memory array 411 and the second table entry 460. The calculation memory program 442 can store an indication of the page size (for example, "4k") in the size field 456. FIG. 5 is a block flow diagram illustrating the encryption of executable instructions according to several embodiments of the present invention. FIG. 5 includes a diagram of a large-capacity storage device 514. As shown in FIG. Fig. 5 includes a CPU 506, and the CPU 506 includes a logic unit 518, TLB 520 and CPU cache area 522. Figure 5 includes a computing memory system 504. The computing memory system 504 includes an I/O circuit 530, a memory array 511, a computing memory system cache 512, an operating system page table 516, a computing memory program 542, and entropy Source 540. In FIG. 4, the executable instruction 461 from the mass storage device 414 is initially stored as a plain text executable instruction 462 in the memory array 411. However, in FIG. 5, the computational memory program 542 can use the entropy source 540 to generate a key of the plain text executable instructions 462 and encrypt the plain text executable instructions 462 into a cipher text executable instruction 564, and execute the cipher text The command 564 is stored back to the memory array 511. Some examples of encryption include Advanced Encryption Standard (AES) (such as AES 128-bit encryption, AES 256-bit encryption, etc.) and Data Encryption Standard (DES), among others. The calculation memory program 542 can delete the second table entry 460 of the plain text executable instruction 462 and generate a third table entry 563 of the ciphertext executable instruction 564. The computing memory program 542 can mark the cipher text executable instruction page 564 as encrypted (for example, "1") in the encryption instruction field 546 of the third table entry 563. This is indicated by the line between the calculation memory program 542 and the item 563 in the third table. The key generated to encrypt the page can be stored in the key field 548 of the third table entry 563 (for example, "XYZ"). This is indicated by the line from the entropy source 540 through the calculation memory program 542 to the key field 548 in the third table entry 563. The virtual memory address in the virtual address field 550 of item 563 in the third table (for example, "C"), the physical address in the physical address field 552 (for example, "D"), and the type field in 554 The type (for example, "X") and the size in the size field 556 (for example, "4k") can remain the same as the second table item 460. However, the embodiment is not limited to this because, for example, The physical address can be changed. The computational memory program 542 can copy the plain text executable instructions 462 before encrypting the plain text executable instructions 462 into cipher text executable instructions 564 (Shown in FIG. 4) and store it as a plain text executable instruction 566 in the cache 512 of the memory system. This is indicated by the line between the computational memory program 542, the ciphertext executable command 564, and the plain text executable command 566. The computing memory system cache 512 can be a non-addressable (eg, secure) area of computing memory (for example, of the computing memory system 504 and/or the memory array 511). The non-addressable computing memory system cache 512 (for example, by a host or DMA device, etc.) can make the plain text executable instructions 566 safe, because an external device (such as a host or DMA device) cannot inject malicious software. The plain text executable instructions 566 in the computing memory system cache 512 can be used to satisfy additional instruction requests from the host and hide some delays that may be caused by the operation of the computing memory program 542. This is illustrated by the line from the plain text executable instruction 566 to the CPU 506. Calculating memory program 542 can travel around the operating system page table 516 (For example, outside of any host operation and/or during the idle time of the computing memory system 504 and/or operating system page table 516) to find pages marked as executable instructions. In some embodiments, the computing memory program 542 may navigate the operating system page table 516 in response to receiving a command from a host associated with a page access (eg, for a requested page). In response to finding a page marked as an executable command, the computing memory program 542 can determine whether the page marked as an executable command is encrypted. It can be determined whether the requested page is encrypted by referring to the operating system page table 516 indicating whether the page is encrypted (for example, by the encryption indication field 546) and whether the page is executable (for example, by the type field 554). In response to determining that the page marked as an executable instruction is not encrypted, the computing memory program 542 can generate a key for the page marked as an executable instruction and use the key to encrypt the page. It can replace the unencrypted page (instead of the requested page in which the encryption operation responds to a request from a host) to store the encrypted page. Finding an unencrypted page marked as an executable instruction can imply that the computing memory system 504 encounters a page error at a certain moment and needs to load a page into the memory array 511. Advantageously, the computing memory program 542 can remedy this by encrypting the page with a uniquely generated key, making it more resilient to injection attacks. In response to determining that the page marked as an executable command is encrypted, the computing memory program 542 may continue to traverse the operating system page table 516 to find an additional page marked as an executable command. In response to finding an additional page marked as an executable command, the computing memory program 542 can determine whether the additional page marked as an executable command is encrypted. If the additional page marked as an executable command has not been encrypted, the computing memory program 542 can generate a different key and use the different key to encrypt the additional page marked as an executable command. The computational memory program 542 can continue to traverse the operating system page table 516 to find any pages marked as executable commands and encrypt those executable commands that are not encrypted. A unique key can be used to encrypt each encrypted page referred to in the encrypted operating system memory table 516, so that each key in the key field 548 of the operating system page table 516 is unique (there are no two key systems identical). In some embodiments, in response to determining that the page marked as an executable command is encrypted, the computing memory program 542 may generate a new key, re-encrypt the requested page with the new key, and replace the requested page and re-encrypt it The pages are stored in the memory array 511. The key field 548 of the requested page can be updated with the new key. The re-encrypted page can be decrypted (using a key) and stored as plain text in the cache area 512 of the memory system. 6 is a block flow diagram illustrating subsequent access to one of an encrypted executable command according to several embodiments of the present invention. FIG. 6 includes a diagram of a large-capacity storage device 614. FIG. 6 includes a CPU 606, and the CPU 606 includes a logic unit 618, a TLB 620 and a CPU cache area 622. FIG. 6 includes a computing memory system 604. The computing memory system 604 includes an I/O circuit 630, a memory array 611, a computing memory system cache 612, an operating system page table 616, a computing memory program 642, and entropy Source 640. The memory array 611 is shown as having ciphertext executable instructions 664 corresponding to the ciphertext executable instructions 564 shown in FIG. 5. In response to a request for a page marked as executable (for example, the ciphertext page 664), the computing memory program 642 can generate a new key (using the entropy source 640) and re-encrypt the marked as executable using the new key Pages of instructions and stores re-encrypted pages of executable instructions instead of pages marked as executable instructions. This is illustrated by the line between the computational memory program 642 and the ciphertext executable instruction 664 and the ciphertext executable instruction 668. The ciphertext executable instruction 668 represents a re-encrypted page marked as an executable instruction. The x-out of the ciphertext executable instruction 664 represents the ciphertext executable instruction 668 stored in place of it. The calculation memory program 642 can delete the third table entry 563 of the ciphertext executable instruction 564 and generate a fourth table entry 665 of the ciphertext executable instruction 668. The computing memory program 642 can mark the ciphertext executable instruction page 668 as encrypted (for example, "1") in the encryption instruction field 646 of the fourth table entry 665. The new key generated to encrypt the page can be stored in the key field 648 of item 665 in the fourth table (for example, "PQR"). This is indicated by the line from the entropy source 640 through the calculation memory program 642 to the key field 648 in the fourth table entry 665. The virtual memory address (for example, "C") in the virtual address field 650 of item 665 in the fourth table, the physical address (for example, "D") in the physical address field 652, and the type field 654 The type (for example, "X") and the size (for example, "4k") in the size field 656 can remain the same as the third table item 563. However, the embodiment is not limited to this, because for example, the entity The address can be changed. Although not specifically shown in FIG. 6, a new page of executable commands can be received (for example, from a host or DMA device) and the computing memory program 642 can generate a new password for the new page (using an entropy source 640). key. The new page can be encrypted by the new key and stored in the memory array 611. The computing memory program 642 can generate a new entry in the operating system page table 616 for the new page, including marking the new page as an executable command and being encrypted. In some embodiments, the computing memory program 642 can decrypt the re-encrypted page (for example, the ciphertext executable instruction 668) and store the decrypted page (for example, as the plain text executable instruction 670) in the computing memory The system cache 612 is used for transfer (for example, to a host or DMA device) to satisfy a request (for a request source). This is illustrated by the line between the computational memory program 642, the plain text executable instruction 670 and the cipher text executable instruction 668, and the line between the plain text executable instruction 670 and the CPU 606. In some embodiments, the decrypted executable instruction or the unencrypted executable instruction is transmitted to a requesting device through the I/O circuit 630 from the computing memory system cache 612 instead of from the memory array 611 to prevent any injected The program code of is sent along with the executable command, because there is no mechanism for injecting the program code into the cache area 612 of the computing memory system. Even if the ciphertext executable instruction in the memory array 611 is injected with malicious code, the decryption of the executable instruction will make the injected code meaningless, because it will not use the same key used to encrypt the executable instruction. An encrypted form of injection. Therefore, the decryption process will reveal malicious code. Executable instructions with leaked malicious code cannot be used for its intended purpose (it can generate an error), and the malicious code will not be executed (for example, it can cause a stop, prefetch abort, or a sharp disconnection of the pipeline), The virus will not spread. Although not specifically shown here, a non-transitory computing device readable medium for storing executable instructions can include all forms of volatile and non-volatile memory, including (by way of example) semiconductor memory devices , DRAM, PIM, HMC, EPROM, EEPROM, flash memory devices, magnetic disks (such as fixed disks, floppy disks and removable disks), other magnetic media (including magnetic tapes), optical media (such as, Compact Disc (CD), Digital Versatile Disc (DVD) and Blu-ray Disc (BD)). The instructions can be supplemented by or incorporated into the ASIC. For example, any one or more of the secondary storage 114, the CPU cache 122, and/or the memory array 111 shown in FIG. 1 may be a non-transitory computing device readable medium. Although specific embodiments have been illustrated and described herein, those of ordinary skill will understand that a configuration calculated to achieve the same result can replace the specific embodiments shown. The present invention is intended to cover adaptations or variations of one or more embodiments of the present invention. It should be understood that the above description has been made in an illustrative manner and not in a restrictive manner. Those skilled in the art will understand the combination of the above-mentioned embodiments and other embodiments not specifically described herein when reviewing the above-mentioned description. The scope of one or more embodiments of the present invention includes other applications in which the above structures and methods are used. Therefore, the scope of one or more embodiments of the present invention should be determined with reference to the scope of the attached patent application together with the full scope of equivalents authorized by the scope of the patent application. In the foregoing embodiments, some features are grouped together in a single embodiment for the purpose of simplifying the present invention. This method of the present invention should not be interpreted as reflecting the following intention: the disclosed embodiments of the present invention must use more features than those explicitly stated in each claim. The fact is, as reflected in the scope of the following patent applications, the subject matter of the invention may be less than all the features of a single disclosed embodiment. Therefore, the scope of the following patent applications is incorporated into the embodiment in this way, in which each claim is taken as an independent embodiment.
<p>100Operating System</p><p>102Host</p><p>104Compute memory system</p><p>106Central Processing Unit (CPU)</p><p>108Controller</p><p>110Compute memory device</p><p>111Memory Array</p><p>114Mass Storage</p><p>118Logic Unit</p><p>120Translation Backup Buffer (TLB)</p><p>122CPU cache area</p><p>124Sensing circuit</p><p>126Address circuit</p><p>128Column Decoder</p><p>130I/O circuit</p><p>132Write circuit</p><p>134line decoder</p><p>136Control bus</p><p>138I/O bus</p><p>210Compute memory device</p><p>211Memory Array</p><p>224Sensing circuit</p><p>240-1 to 240-NMemory cell</p><p>242-1 to 242-MAccess line</p><p>244-1 to 244-NSensing line</p><p>246-1 to 246-NSensing amplifier</p><p>248-1 to 248-NComputer components</p><p>250-1 to 250-NAccess device</p><p>252-1 to 252-Nline decoding line</p><p>254Input/Output Line</p><p>256Secondary sense amplifier</p><p>304Compute memory system</p><p>306Central Processing Unit (CPU)</p><p>311Memory Array</p><p>312Compute memory system cache area</p><p>314 Mass storage device</p><p>316Operating System Page Table</p><p>318Logic Unit</p><p>320Translation Backup Buffer (TLB)</p><p>322CPU cache area</p><p>330I/O circuit</p><p>340Entropy Source</p><p>342Calculation memory program</p><p>344First table item</p><p>346Encryption instruction field</p><p>348Key field</p><p>350Virtual Address Field</p><p>352Physical address field</p><p>354Page type field</p><p>356Size field</p><p>358Data page</p><p>404Compute memory system</p><p>406Central Processing Unit (CPU)</p><p>411Memory Array</p><p>412Compute memory system cache area</p><p>414 Mass storage device</p><p>416Operating System Page Table</p><p>418Logic Unit</p><p>420Translation Backup Buffer (TLB)</p><p>422CPU cache area</p><p>430I/O circuit</p><p>440Entropy Source</p><p>442Calculation memory program</p><p>444First table item</p><p>446Encryption instruction field</p><p>448Key field</p><p>450Virtual address field</p><p>452Physical address field</p><p>454Type field</p><p>456Size field</p><p>460Second table item</p><p>461executable command</p><p>462Plain text executable commands</p><p>504Compute Memory System</p><p>506Central Processing Unit (CPU)</p><p>511Memory Array</p><p>512Compute memory system cache area</p><p>514 Mass storage device</p><p>516Operating System Page Table</p><p>518Logic Unit</p><p>520Translation Backup Buffer (TLB)</p><p>522CPU cache area</p><p>530I/O circuit</p><p>540Entropy Source</p><p>542Calculation memory program</p><p>544First table item</p><p>546Encryption instruction field</p><p>548Key field</p><p>550Virtual address field</p><p>552Physical address field</p><p>554Type field</p><p>556Size field</p><p>563Items in the third table</p><p>564Ciphertext executable instructions</p><p>566Plain text executable commands</p><p>604Compute Memory System</p><p>606Central Processing Unit (CPU)</p><p>611Memory Array</p><p>612Compute memory system cache area</p><p>614 Mass storage device</p><p>616Operating System Page Table</p><p>618Logic Unit</p><p>620Translation Backup Buffer (TLB)</p><p>622CPU cache area</p><p>630I/O circuit</p><p>640Entropy Source</p><p>642Calculation memory program</p><p>644First table item</p><p>646Encryption instruction field</p><p>648Key field</p><p>650Virtual address field</p><p>652Physical address field</p><p>654Type field</p><p>656Size field</p><p>664Ciphertext executable instructions</p><p>665Fourth table item</p><p>668Ciphertext executable commands</p><p>670Plain text executable instructions</p>
FIG. 1 is a block diagram of a device in the form of a computing system including at least one computing memory system according to several embodiments of the present invention. 2 is a schematic diagram of a part of a computing memory device according to one of several embodiments of the present invention. FIG. 3 is a block flow diagram showing a read or write access according to one of several embodiments of the present invention. 4 is a block flow diagram showing a new page allocation according to several embodiments of the present invention. FIG. 5 is a block flow diagram illustrating the encryption of executable instructions according to several embodiments of the present invention. 6 is a block flow diagram illustrating subsequent access to one of an encrypted executable command according to several embodiments of the present invention.
<bio-deposit></bio-deposit>
<sequence-list-text></sequence-list-text>
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| TWI816456B | Cited by | Taiwan Province of China | Examiner |
19 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 14828151 | United States of America | – | |
| 201514828151 | United States of America | A | |
| 201514828151 | United States of America | A | |
| 201514828151 | – | – | – |
| US201514828151 | – | – | – |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| US2017052906A1 | United States of America | A1 | |
| WO2017030745A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201719489AThis record | Taiwan Province of China | A | |
| KR20180030246A | Republic of Korea | A | |
| CN107924367A | China | A | |
| EP3317770A1 | European Patent Office (EPO) | A1 | |
| US9996479B2 | United States of America | B2 | |
| TWI631482B | Taiwan Province of China | B | |
| US2018293179A1 | United States of America | A1 | |
| EP3317770A4 | European Patent Office (EPO) | A4 | |
| KR102059093B1 | Republic of Korea | B1 | |
| EP3317770B1 | European Patent Office (EPO) | B1 | |
| US10691620B2 | United States of America | B2 | |
| US2020320020A1 | United States of America | A1 | |
| EP3726391A1 | European Patent Office (EPO) | A1 | |
| CN107924367B | China | B | |
| EP3726391B1 | European Patent Office (EPO) | B1 | |
| EP4102373A1 | European Patent Office (EPO) | A1 | |
| US11625336B2 | United States of America | B2 |
Numbers
- Publication
- 201719489
- Publication, DOCDB
- 201719489
- Publication, EPODOC
- TW201719489
- Application
- 105125524
- Application, DOCDB
- 105125524
- Application, EPODOC
- TW20165125524
Titles3
- English
- ENCRYPTION OF EXECUTABLES IN COMPUTATIONAL MEMORY
- Chinese
- 計算記憶體中可執行指令之加密
- English
- Encryption of executable instructions in computing memory
Classification
- CPC, 9
- G06F12/1408
- G06F21/79
- G06F12/1009
- G06F2212/1016
- G06F21/126
- G06F2212/1052
- G06F12/1027
- G06F15/7821
- G06F12/0897
- IPC, 2
- G06F21 71
- G11C7 24