VIRTUAL MACHINE SYSTEM, CONFIDENTIAL INFORMATION PROTECTION METHOD, AND CONFIDENTIAL INFORMATION PROTECTION PROGRAM
    1.
    发明申请
    VIRTUAL MACHINE SYSTEM, CONFIDENTIAL INFORMATION PROTECTION METHOD, AND CONFIDENTIAL INFORMATION PROTECTION PROGRAM 有权
    虚拟机系统,机密信息保护方法和机密信息保护计划

    公开(公告)号:US20140020086A1

    公开(公告)日:2014-01-16

    申请号:US14008785

    申请日:2013-02-20

    IPC分类号: G06F21/30

    摘要: A virtual machine system that restricts use of confidential information only to the case where an authentication has resulted in success. The virtual machine system includes first virtual machine, second virtual machine, and hypervisor. The first virtual machine includes: storage unit storing confidential information; and authentication unit configured to perform authentication and notify the hypervisor of result of the authentication. The second virtual machine uses virtual device that is virtualized storage device. When having received authentication result indicating authentication success from the authentication unit, the hypervisor enables the second virtual machine to access, as substance of the virtual device, storage area storing the confidential information, and when not having received the authentication result indicating the authentication success from the authentication unit, the hypervisor disables the second virtual machine from accessing the storage area storing the confidential information.

    摘要翻译: 仅在身份验证已成功的情况下才限制使用机密信息的虚拟机系统。 虚拟机系统包括第一虚拟机,第二虚拟机和管理程序。 第一虚拟机包括:存储机密信息的存储单元; 以及认证单元,被配置为执行认证,并将所述认证结果通知所述管理程序。 第二个虚拟机使用虚拟化设备,即虚拟化存储设备。 当从认证单元接收到表示认证成功的认证结果时,管理程序使第二虚拟机能够作为虚拟设备的实体访问存储机密信息的存储区域,并且当没有接收到表示认证成功的认证结果时 认证单元,管理程序禁用第二虚拟机访问存储机密信息的存储区域。

    VIRTUAL COMPUTER SYSTEM, CONTROL METHOD FOR VIRTUAL COMPUTER SYSTEM, CONTROL PROGRAM FOR VIRTUAL COMPUTER SYSTEM, AND INTEGRATED CIRCUIT
    2.
    发明申请
    VIRTUAL COMPUTER SYSTEM, CONTROL METHOD FOR VIRTUAL COMPUTER SYSTEM, CONTROL PROGRAM FOR VIRTUAL COMPUTER SYSTEM, AND INTEGRATED CIRCUIT 有权
    虚拟计算机系统,虚拟计算机系统的控制方法,虚拟计算机系统的控制程序和集成电路

    公开(公告)号:US20130117745A1

    公开(公告)日:2013-05-09

    申请号:US13810024

    申请日:2012-03-30

    IPC分类号: G06F9/455

    摘要: When a process judging unit 109 judges that a target process is a protected process 101, a key judging unit 111 judges whether a target key that is a key generated by a key generating unit 108 is a first key or a second key. When the key judging unit 111 judges that the target key is the first key, a VM communication managing unit 112 notifies the target process of a memory ID of a protected memory region 121 corresponding to the first key. When the process judging unit 109 judges that the target process is an unprotected process, a key transforming unit 110 transforms the target key from the first key to the second key based on the key transformation rule. An HV communication managing unit 105 notifies the target process of a memory ID of an unprotected memory region 122 corresponding to the second key.

    摘要翻译: 当处理判断单元109判断目标处理是被保护处理101时,密钥判断单元111判断作为密钥生成单元108生成的密钥的目标密钥是第一密钥还是第二密钥。 当密钥判断单元111判断为目标密钥是第一密钥时,VM通信管理单元112向目标处理通知对应于第一密钥的受保护存储器区域121的存储器ID。 当处理判断单元109判断目标处理是不受保护的处理时,密钥变换单元110基于密钥变换规则将目标密钥从第一密钥转换为第二密钥。 HV通信管理单元105向目标处理通知对应于第二密钥的未受保护的存储区域122的存储器ID。

    Virtual computer system having a first virtual computer that executes a protected process, a second virtual computer that executes an unprotected process, and a hypervisor that controls the first and second virtual computers
    4.
    发明授权
    Virtual computer system having a first virtual computer that executes a protected process, a second virtual computer that executes an unprotected process, and a hypervisor that controls the first and second virtual computers 有权
    具有执行受保护处理的第一虚拟计算机的虚拟计算机系统,执行未受保护处理的第二虚拟计算机以及控制第一和第二虚拟计算机的管理程序

    公开(公告)号:US09032401B2

    公开(公告)日:2015-05-12

    申请号:US13810024

    申请日:2012-03-30

    IPC分类号: G06F9/455 G06F12/14 G06F21/10

    摘要: When a process judging unit judges that a target process is a protected process, a key judging unit judges whether a target key that is a key generated by a key generating unit is a first key or a second key. When the key judging unit judges that the target key is the first key, a VM communication managing unit notifies the target process of a memory ID of a protected memory region corresponding to the first key. When the process judging unit judges that the target process is an unprotected process, a key transforming unit transforms the target key from the first key to the second key based on the key transformation rule. An HV communication managing unit notifies the target process of a memory ID of an unprotected memory region corresponding to the second key.

    摘要翻译: 当处理判断单元判定目标处理是受保护处理时,密钥判断单元判断作为密钥生成单元生成的密钥的目标密钥是第一密钥还是第二密钥。 当密钥判断单元判定目标密钥是第一密钥时,VM通信管理单元向目标处理通知对应于第一密钥的受保护存储器区域的存储器ID。 当处理判断单元判断目标处理是不受保护的处理时,密钥变换单元基于密钥变换规则将目标密钥从第一密钥转换为第二密钥。 HV通信管理单元向目标处理通知对应于第二密钥的未受保护的存储区域的存储器ID。

    Generating child virtual machine to execute authorized application with reduced risk of malware attack
    6.
    发明授权
    Generating child virtual machine to execute authorized application with reduced risk of malware attack 有权
    生成子虚拟机执行授权应用程序,降低恶意软件攻击的风险

    公开(公告)号:US09460270B2

    公开(公告)日:2016-10-04

    申请号:US13807202

    申请日:2012-02-21

    摘要: When a predetermined application program becomes the target of execution on a virtual machine that is currently being executed, the virtual machine that is currently being executed is designated as a parent virtual machine, and a child virtual machine to execute the predetermined application program is generated by forking. The generated child virtual machine is configured not to execute any application program other than the predetermined application program. The parent virtual machine executes a dummy application program instead of the predetermined application program.

    摘要翻译: 当预定应用程序成为当前正在执行的虚拟机上的执行目标时,当前正在执行的虚拟机被指定为父虚拟机,并且通过以下方式生成执行预定应用程序的子虚拟机: 分叉 生成的子虚拟机被配置为不执行除了预定应用程序之外的任何应用程序。 父虚拟机执行虚拟应用程序而不是预定的应用程序。

    VIRTUAL COMPUTER SYSTEM, VIRTUAL COMPUTER CONTROL METHOD, VIRTUAL COMPUTER CONTROL PROGRAM, AND SEMICONDUCTOR INTEGRATED CIRCUIT
    7.
    发明申请
    VIRTUAL COMPUTER SYSTEM, VIRTUAL COMPUTER CONTROL METHOD, VIRTUAL COMPUTER CONTROL PROGRAM, AND SEMICONDUCTOR INTEGRATED CIRCUIT 有权
    虚拟计算机系统,虚拟计算机控制方法,虚拟计算机控制程序和半导体集成电路

    公开(公告)号:US20130097603A1

    公开(公告)日:2013-04-18

    申请号:US13807202

    申请日:2012-02-21

    IPC分类号: G06F21/00 G06F9/455

    摘要: When a predetermined application program becomes the target of execution on a virtual machine that is currently being executed, the virtual machine that is currently being executed is designated as a parent virtual machine, and a child virtual machine to execute the predetermined application program is generated by forking. The generated child virtual machine is configured not to execute any application program other than the predetermined application program. The parent virtual machine executes a dummy application program instead of the predetermined application program.

    摘要翻译: 当预定应用程序成为当前正在执行的虚拟机上的执行目标时,当前正在执行的虚拟机被指定为父虚拟机,并且通过以下方式生成执行预定应用程序的子虚拟机: 分叉 生成的子虚拟机被配置为不执行除了预定应用程序之外的任何应用程序。 父虚拟机执行虚拟应用程序而不是预定的应用程序。

    Virtual machine control device, virtual machine control method, computer-readable recording medium, and integrated circuit
    8.
    发明授权
    Virtual machine control device, virtual machine control method, computer-readable recording medium, and integrated circuit 有权
    虚拟机控制装置,虚拟机控制方法,计算机可读记录介质和集成电路

    公开(公告)号:US09304789B2

    公开(公告)日:2016-04-05

    申请号:US13883452

    申请日:2012-08-03

    IPC分类号: G06F9/455 G06F1/32 G06F9/48

    摘要: A pseudo task generation requester 200 generates a request for generating a pseudo task 283 indicating that a certain one of CPUs is in an use state, and notifies a second OS 125 of the generation request, in the case where a task to be processed by a first virtual machine 110 is assigned to the one CPU, but a task to be processed by a second virtual machine 120 is not assigned to the one CPU. A pseudo task finishing requester 206 finishes the pseudo task 283 when a task in the first virtual machine 110 is finished with respect to the CPU to which the pseudo task 283 is assigned.

    摘要翻译: 伪任务生成请求器200生成用于生成指示CPU中的某个CPU处于使用状态的伪任务283的请求,并且在第二OS 125通知由第一OS 125处理的任务的情况下生成生成请求 第一虚拟机110被分配给一个CPU,但是由第二虚拟机120处理的任务未分配给一个CPU。 当第一虚拟机110中的任务相对于分配有伪任务283的CPU完成时,伪任务完成请求器206完成伪任务283。

    Stripping knife
    9.
    发明授权
    Stripping knife 有权
    剥线刀

    公开(公告)号:US09132036B2

    公开(公告)日:2015-09-15

    申请号:US12597384

    申请日:2008-04-25

    CPC分类号: A61F9/0133 A61B17/3211

    摘要: [Problems] To ensure the sharpness of a stripping knife whereby a part of a living tissue is incised and stripped while preventing a cut along the thickness direction.[Means for Solving Problems] A stripping knife (A) having a plate-shaped blade (3) having an edge (1) around the periphery, a shank (5) connected to the blade (3), and a handle (7) holding the shank (5) in the integrated state, wherein the blade (3) is composed of the edge (1) formed at the front end and a guide face (2) which is formed between the edge (1) and the front face (3b) of the connected plate constituting the blade (3) and brought into contact with the surface (13) of the remaining tissue.

    摘要翻译: [问题]为了确保剥离刀的清晰度,由此一边活动组织被切开并剥离,同时防止沿着厚度方向的切割。 解决问题的手段具有围绕周边具有边缘(1)的板状刀片(3)的剥离刀(A),连接到刀片(3)的柄(5)和手柄(7) 将所述柄(5)保持在一体状态,其中所述刀片(3)由形成在所述前端的边缘(1)和形成在所述边缘(1)和所述前表面 (3)的连接板(3b)并与其余组织的表面(13)接触。

    Multiprocessor control apparatus for controlling a plurality of processors sharing a memory and an internal bus and multiprocessor control method and multiprocessor control circuit for performing the same
    10.
    发明授权
    Multiprocessor control apparatus for controlling a plurality of processors sharing a memory and an internal bus and multiprocessor control method and multiprocessor control circuit for performing the same 有权
    用于控制共享存储器的多个处理器和内部总线的多处理器控制装置和多处理器控制方法以及用于执行该处理器的多处理器控制电路

    公开(公告)号:US08489862B2

    公开(公告)日:2013-07-16

    申请号:US12663932

    申请日:2008-06-05

    IPC分类号: G06F15/00 G06F15/76

    摘要: An object of the invention is to reduce the electric power consumption resulting from temporarily activating a processor requiring a large electric power consumption, out of a plurality of processors. A multiprocessor system (1) includes: a first processor (141) which executes a first instruction code; a second processor (151) which executes a second instruction code, a hypervisor (130) which converts the second instruction code into an instruction code executable by the first processor (141); and a power control circuit (170) which controls the operation of at least one of the first processor (141) and the second processor (151). When the operation of the second processor (151) is suppressed by the power control circuit (170), the hypervisor (130) converts the second instruction code into the instruction code executable by the first processor (141), and the first processor (141) executes the converted instruction code.

    摘要翻译: 本发明的一个目的是减少由多个处理器中暂时激活需要大功率消耗的处理器所产生的电力消耗。 多处理器系统(1)包括:执行第一指令代码的第一处理器(141) 执行第二指令代码的第二处理器(151),将第二指令代码转换成可由第一处理器(141)执行的指令代码的管理程序(130); 以及控制第一处理器(141)和第二处理器(151)中的至少一个的操作的功率控制电路(170)。 当由功率控制电路(170)抑制第二处理器(151)的操作时,管理程序(130)将第二指令代码转换为可由第一处理器(141)执行的指令代码,第一处理器(141) )执行转换的指令代码。