Method for deploying containerized protocols on very small devices

    公开(公告)号:US11875167B2

    公开(公告)日:2024-01-16

    申请号:US17209100

    申请日:2021-03-22

    申请人: Nubix, Inc.

    摘要: A method includes: accessing a set of hardware parameters characterizing an embedded device; identifying a set of supported container functions based on the set of hardware parameters; accessing a selection of container functions; identifying a set of selected container functions based on the selection of container functions and the set of supported container functions; generating a hardware abstraction layer (HAL) including a set of libraries supporting the set of selected container functions; generating a container runtime environment (CRE) configured to execute, at the embedded device, a containerized application via the HAL, the containerized application including the set of selected container functions; installing the HAL and the CRE onto the embedded device; installing the containerized application onto the embedded device via the CRE; and at the embedded device, executing the containerized application via the CRE and the HAL.

    CIRCUITRY AND METHODS FOR IMPLEMENTING MICRO-CONTEXT BASED TRUST DOMAINS

    公开(公告)号:US20230315648A1

    公开(公告)日:2023-10-05

    申请号:US17709867

    申请日:2022-03-31

    申请人: Intel Corporation

    发明人: David M. Durham

    摘要: Systems, methods, and apparatuses for implementing micro-context based trust domains are described. In one example, a system includes a hardware processor core to implement a trust domain manager to manage one or more hardware isolated virtual machines as a respective trust domain with a region of protected memory, and assign a micro-context identification value, that is not readable by privileged system code that is to execute on the hardware processor core, to each granule of a plurality of granules of physical memory of the protected memory (e.g., where a granule is a proper subset of a page of memory relating to a single object in memory); and a memory management circuit coupled between the hardware processor core and the physical memory, wherein the memory management circuit is to prevent data in the protected memory having a first micro-context identification value from being accessed by code based on the code having a different micro-context identification value.

    METHOD FOR CONFIGURING ADDRESS TRANSLATION RELATIONSHIP, AND COMPUTER SYSTEM

    公开(公告)号:US20230281135A1

    公开(公告)日:2023-09-07

    申请号:US18314999

    申请日:2023-05-10

    摘要: A method for configuring an address translation relationship is disclosed. The method is applied to a computer system. A rich execution environment REE and a trusted execution environment TEE are deployed in the computer system, a virtual machine VM and a virtual machine manager VMM are deployed in the REE, and a secure partition SP and a secure partition manager SPM are deployed in the TEE. The method includes: The VMM transfers a first address translation relationship to the SPM. The first address translation relationship includes an address translation relationship from an intermediate physical address IPA allocated to the VM to a physical address PA, so that the SPM performs IPA-to-PA address translation based on the first address translation relationship when transmitting data from the SP to the VM. The PA is a memory address. The method simplifies a process in which the SPM establishes an IPA-to-VA address mapping relationship.