System for executing program using virtual machine monitor and method of controlling the system
    1.
    发明授权
    System for executing program using virtual machine monitor and method of controlling the system 有权
    使用虚拟机监视器执行程序的系统和控制系统的方法

    公开(公告)号:US08327438B2

    公开(公告)日:2012-12-04

    申请号:US12127901

    申请日:2008-05-28

    IPC分类号: H04L29/06

    CPC分类号: G06F21/53

    摘要: A system for executing a program using a virtual machine monitor and a method of controlling the system are provided. The system includes a virtual machine monitor which divides an operating system (OS) into at least one root domain and a plurality of domains having different trust levels, and a trust-management module which is included in the at least one root domain and which periodically measures the trust level of an application program currently being executed in the plurality of domains. The virtual machine monitor executes the application program in one of the domains based on the trust level of the application program.

    摘要翻译: 提供了一种使用虚拟机监视器执行程序的系统和控制系统的方法。 该系统包括虚拟机监视器,其将操作系统(OS)划分为至少一个根域和具有不同信任级别的多个域,以及信任管理模块,其被包括在所述至少一个根域中,并且周期性地 测量当前正在多个域中执行的应用程序的信任级别。 虚拟机监视器根据应用程序的信任级别执行其中一个域中的应用程序。

    SYSTEM FOR EXECUTING PROGRAM USING VIRTUAL MACHINE MONITOR AND METHOD OF CONTROLLING THE SYSTEM
    2.
    发明申请
    SYSTEM FOR EXECUTING PROGRAM USING VIRTUAL MACHINE MONITOR AND METHOD OF CONTROLLING THE SYSTEM 有权
    使用虚拟机监视器执行程序的系统和控制系统的方法

    公开(公告)号:US20090165133A1

    公开(公告)日:2009-06-25

    申请号:US12127901

    申请日:2008-05-28

    IPC分类号: G06F21/00

    CPC分类号: G06F21/53

    摘要: A system for executing a program using a virtual machine monitor and a method of controlling the system are provided. The system includes a virtual machine monitor which divides an operating system (OS) into at least one root domain and a plurality of domains having different trust levels, and a trust-management module which is included in the root domain and periodically measures the trust level of an application program currently being executed in the OS. The virtual machine monitor executes the application program in one of the domains in consideration of the trust level of the application program. The method includes dividing an OS into at least a root domain and a plurality of domains having different trust levels by using a virtual machine monitor, enabling the root domain to periodically measure the trust level of an application program currently being executed in the OS, and executing the application program in one of the domains according to the trust level of the application program.

    摘要翻译: 提供了一种使用虚拟机监视器执行程序的系统和控制系统的方法。 该系统包括将操作系统(OS)划分成至少一个根域和具有不同信任级别的多个域的虚拟机监视器,以及包括在根域中并且周期性地测量信任级别的信任管理模块 当前正在OS中执行的应用程序。 考虑到应用程序的信任级别,虚拟机监视器在其中一个域中执行应用程序。 该方法包括通过使用虚拟机监视器将OS划分成至少根域和具有不同信任级别的多个域,使得根域能够周期性地测量当前在OS中执行的应用程序的信任级别,以及 根据应用程序的信任级别在其中一个域中执行应用程序。

    Method and system for securely sharing content
    3.
    发明授权
    Method and system for securely sharing content 有权
    安全地共享内容的方法和系统

    公开(公告)号:US08275884B2

    公开(公告)日:2012-09-25

    申请号:US12333692

    申请日:2008-12-12

    CPC分类号: G06F21/606

    摘要: A method and apparatus for securely sharing content are provided, which can securely share the content without allowing access by unauthorized third parties. The method of securely sharing content includes a first domain, which has content that requires security among a plurality of domains logically generated on a hardware platform, sharing the content with at least one second domain, and if the second domain intends to write the content in a region in which writing is not permitted, preventing the writing of the content.

    摘要翻译: 提供了一种用于安全地共享内容的方法和装置,其可以安全地共享内容,而不允许未授权的第三方访问。 安全地共享内容的方法包括第一域,其具有需要在硬件平台上逻辑生成的多个域之间的安全性的内容,与至少一个第二域共享内容,以及如果第二域旨在将内容写入 不允许写入的区域,阻止写入内容。

    BOOTING APPARATUS AND METHOD USING SNAPSHOT IMAGE
    6.
    发明申请
    BOOTING APPARATUS AND METHOD USING SNAPSHOT IMAGE 有权
    BOOTING设备和使用SNAPSHOT图像的方法

    公开(公告)号:US20120131320A1

    公开(公告)日:2012-05-24

    申请号:US13187732

    申请日:2011-07-21

    IPC分类号: G06F9/06

    CPC分类号: G06F9/4401 G06F9/4406

    摘要: Provided are a booting apparatus and method using a snapshot image. A snapshot image may be divided into a plurality of blocks. Each of the blocks may be stored in a nonvolatile memory in a compressed or non-compressed format. The snapshot image may be incrementally loaded in units of the blocks during booting. The loading and decompression of the blocks may be performed in parallel.

    摘要翻译: 提供了使用快照图像的启动装置和方法。 快照图像可以被划分成多个块。 每个块可以以压缩或非压缩格式存储在非易失性存储器中。 快照图像可以在引导期间以块为单位递增加载。 块的加载和解压缩可以并行执行。

    APPARATUS AND METHOD FOR GENERATING A BOOT IMAGE THAT IS ADJUSTABLE IN SIZE
    7.
    发明申请
    APPARATUS AND METHOD FOR GENERATING A BOOT IMAGE THAT IS ADJUSTABLE IN SIZE 有权
    用于生成可调整大小的引导图像的装置和方法

    公开(公告)号:US20120089825A1

    公开(公告)日:2012-04-12

    申请号:US13178029

    申请日:2011-07-07

    IPC分类号: G06F9/00

    CPC分类号: G06F9/4418

    摘要: A technique for reducing a size of a snapshot boot image by adjusting a structure of the snapshot boot image based on an analysis of a computing system. In addition, according to the technique, the overriding portions of a snapshot based boot image may be loaded first in consideration of a time of use of the system, and therefore a boot time can be reduced.

    摘要翻译: 一种通过基于计算系统的分析调整快照启动映像的结构来减小快照引导映像的大小的技术。 此外,根据该技术,考虑到系统的使用时间,可以首先加载基于快照的引导映像的重写部分,因此可以减少引导时间。

    SYSTEM AND METHOD FOR PROTECTING DATA INFORMATION STORED IN STORAGE
    8.
    发明申请
    SYSTEM AND METHOD FOR PROTECTING DATA INFORMATION STORED IN STORAGE 有权
    用于保护存储中存储的数据信息的系统和方法

    公开(公告)号:US20080263676A1

    公开(公告)日:2008-10-23

    申请号:US12017580

    申请日:2008-01-22

    IPC分类号: H04L9/32

    摘要: A system and method are provided for protecting data information stored in a storage medium. The system includes a memory unit which is divided into a plurality of storage regions in which data information is stored; a domain unit which includes a plurality of OS domains, which are access subjects, and loads the data information stored in the storage regions that are accessed by the OS domains; and a control unit which controls access of the domain unit to the memory unit.

    摘要翻译: 提供了一种用于保护存储在存储介质中的数据信息的系统和方法。 该系统包括:存储单元,被分成多个存储数据信息的存储区域; 包括作为访问对象的多个OS域的域单元,并且加载存储在由OS域访问的存储区域中的数据信息; 以及控制单元,其控制域单元对存储器单元的访问。

    Real-time performance apparatus and method for controlling virtual machine scheduling in real-time

    公开(公告)号:US09792137B2

    公开(公告)日:2017-10-17

    申请号:US13246929

    申请日:2011-09-28

    IPC分类号: G06F9/46 G06F9/455

    摘要: A virtualization apparatus is provided. The virtualization apparatus includes a plurality of virtual machines (VMs), a process scheduler configured to schedule processes to be executed on the respective virtual machines, a virtual machine monitor (VMM) configured to provide each of the virtual machine with a virtualized execution environment, a virtual machine scheduler configured to schedule the virtual machines to run in the virtual machine monitor, and a synchronization unit configured to synchronize a process schedule time which is scheduled by the process scheduler and a virtual machine schedule time which is scheduled by the virtual machine scheduler, or to change the virtual machine schedule time in consideration of the process schedule time.