Tri-level secure separation kernel

    公开(公告)号:US11748484B2

    公开(公告)日:2023-09-05

    申请号:US16747789

    申请日:2020-01-21

    发明人: Arlen Baker

    IPC分类号: G06F21/57 G06F9/455

    摘要: A high assurance kernel executed by a safety certified hypervised system using a separation kernel. The high assurance kernel includes a first level of the separation kernel configured to perform first security features associated with a hypervisor, the first level configured to run on a primary core and a second level of the separation kernel configured to augment the first security features with second security features, the second level implemented on a separate protected component from the primary core, the first level and the second level communicating with one another through a physical separation between the first and second levels. The high assurance kernel may further include a third level of the separation kernel configured as a virtual machine to perform third security features associated with the hypervisor.

    Device, system, and method for adaptive simulation

    公开(公告)号:US11281829B2

    公开(公告)日:2022-03-22

    申请号:US14869495

    申请日:2015-09-29

    IPC分类号: G06F30/33

    摘要: A device, system, and method performs an adaptive simulation. The method performed by a similar includes receiving a release to be incorporated into a user device, the user device being a deployed device. The method includes receiving a profile of the user device, the profile being indicative of settings and usage information of the user device. The method includes generating a simulated user device corresponding to the user device, the simulated user device having a simulated profile corresponding to the profile. The method includes performing, by the simulator, a simulation for the release based upon the simulated user device and the simulated profile.

    Image compression
    3.
    发明授权

    公开(公告)号:US11222427B2

    公开(公告)日:2022-01-11

    申请号:US16176975

    申请日:2018-10-31

    摘要: A device, system, and method performs an image compression. The method includes receiving raw image data of an image and identifying objects in the image as one of a foreground object or a background object. The method includes generating first foreground image data for a first foreground object. The method includes generating first metadata for a first background object. The first metadata indicates a first identity and a first descriptive parameter for the first background object. The first descriptive parameter relates to how the first background object is situated in the image. The method includes generating first background image data for the first background object. The first background image data is empty data. The method includes storing processed image data for the image comprising the first foreground image data, the first metadata, and the first background image data.

    Systems and methods for interrupting latency optimized two-phase spinlock

    公开(公告)号:US11119831B2

    公开(公告)日:2021-09-14

    申请号:US16739445

    申请日:2020-01-10

    IPC分类号: G06F9/52 G06F9/50 G06F9/48

    摘要: Described is a two-phase spinlock that controls access to a resource from a plurality of threads. The two-phase spinlock receives requests from threads to acquire the resource, places the threads in a first queue associated with a first phase of the two-phase spinlock, determines whether at least one of a predetermined number of slots in a second phase of the two-phase spinlock is available and when the slots are unavailable, processes an interrupt served by a select one of the threads based on a number of attempts by the selected thread to enter the second phase.

    Lossy compression for images and signals by identifying regions with low density of features

    公开(公告)号:US10728420B2

    公开(公告)日:2020-07-28

    申请号:US15950919

    申请日:2018-04-11

    发明人: Ionut Popa

    摘要: A device, system, and method perform lossy compression for images and signals by identifying regions with a low density of features. The method performed at a sensor communicatively connected to a receiver includes capturing sensor data. The method includes selecting a position in the sensor data. The method includes determining a local entropy of the position based on an entropy operation that indicates a probability distribution of a plurality of available values. When the local entropy is below a predetermined threshold, the method includes applying a first pre-processing operation to the position that averages features included in the position. The method includes transmitting the pre-processed sensor data corresponding to the position to the receiver.

    Method and system to improve network connection locality on multicore systems

    公开(公告)号:US09894012B2

    公开(公告)日:2018-02-13

    申请号:US14149432

    申请日:2014-01-07

    IPC分类号: H04L12/931 H04L12/26

    CPC分类号: H04L49/00 H04L43/026

    摘要: A method including selecting a prospective local port from a plurality of available local ports for a computing environment; determining a hash value based on the prospective local port, the hash value being further determined based on a hash value determination method of a network interface of the computing environment; determining whether the hash value results in incoming traffic being delivered to a selected one of a plurality of cores of the computing environment; and sending data relating to an application executed by the selected core over the network interface using the prospective local port, if the hash value results in incoming traffic being delivered to the selected core.

    System and method for supporting fast and deterministic execution and simulation in multi-core environments

    公开(公告)号:US09606924B2

    公开(公告)日:2017-03-28

    申请号:US13530802

    申请日:2012-06-22

    申请人: Hakan Zeffer

    发明人: Hakan Zeffer

    IPC分类号: G06F9/30 G06F12/08 G06F11/36

    CPC分类号: G06F12/0842 G06F11/3612

    摘要: The exemplary embodiments described herein relate to supporting fast and deterministic execution and simulation in multi-core environments. Specifically, the exemplary embodiments relate to systems and methods for implementing determinism in a memory system of a multithreaded computer. A exemplary system comprises a plurality of processors within a multi-processor environment, a cache memory within the processor and including metadata, and a hardware check unit performing one of a load check and a store check on the metadata to detect a respective one of a load metadata mismatch and a store metadata mismatch, and invoking a runtime software routine to order memory references upon a detection of one of the load metadata mismatch and the store metadata mismatch.

    Method and System for Enforcing Kernel Mode Access Protection
    10.
    发明申请
    Method and System for Enforcing Kernel Mode Access Protection 审中-公开
    执行内核模式访问保护的方法和系统

    公开(公告)号:US20150331809A1

    公开(公告)日:2015-11-19

    申请号:US14280021

    申请日:2014-05-16

    摘要: A non-transitory computer-readable storage medium storing a set of instructions executable by a processor, the set of instructions, when executed by the processor, causing the processor to perform operations including mapping a memory area storing a segment of code for a kernel of the system during an initialization time of a system. The operations also include executing the segment of code during the initialization time. The operations also include unmapping a portion of the memory area for the kernel after the segment of code has been executed.

    摘要翻译: 一种非暂时的计算机可读存储介质,其存储可由处理器执行的一组指令,所述指令集在由所述处理器执行时,使得所述处理器执行操作,所述操作包括映射存储用于内核的内核的代码段的存储区域 系统在系统的初始化时间内。 这些操作还包括在初始化时间内执行代码段。 这些操作还包括在执行代码段之后,取消映射内核的内存区域的一部分。