{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/44416"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/44416","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Flexible memory protection for multicore processors","abstract":"A system’s memory access control mechanisms profoundly impact the performance, reliability, security, and composability of the software it runs. Desirable features of an access control mechanism include: the ability to grant arbitrary permissions on any region of memory to any thread in the system; zero-copy sharing between threads with no restrictions on the set of sharers, region granularity, or sharing of pointer-based data structures; time and space overheads dependent only on the fundamental complexity of the access control being requested; and well-defined, hierarchical memory region ownership and permission semantics. The virtual-memory-based access control used in most modern systems, as well as recently proposed enhancements, fall short along one or more of these dimensions. We introduce Lumen, an access control scheme providing security, fault isolation, and efficient shared memory to any number of threads within a single address space. Lumen uses a new concurrent interval skip list (ISL) to scalably maintain and query a set of memory region descriptors containing permissions information. We describe a permissions and ownership system for memory regions that allows safe delegation of privileges between protection domains for sandboxing and software reusability purposes. We describe the LumenCache, which caches region permissions to avoid most ISL lookups. We discuss applications of Lumen in debugging, security, and reliability, and extensions to use Lumen for prefetching, profiling, and user-facing memory management features. Lumen offers scalable, flexible memory access control and the ability to trade off security, system reliability, and performance in a way not possible with existing solutions.","abstract_html":"A system’s memory access control mechanisms profoundly impact the performance, reliability, security, and composability of the software it runs. Desirable features of an access control mechanism include: the ability to grant arbitrary permissions on any region of memory to any thread in the system; zero-copy sharing between threads with no restrictions on the set of sharers, region granularity, or sharing of pointer-based data structures; time and space overheads dependent only on the fundamental complexity of the access control being requested; and well-defined, hierarchical memory region ownership and permission semantics. The virtual-memory-based access control used in most modern systems, as well as recently proposed enhancements, fall short along one or more of these dimensions. We introduce Lumen, an access control scheme providing security, fault isolation, and efficient shared memory to any number of threads within a single address space. Lumen uses a new concurrent interval skip list (ISL) to scalably maintain and query a set of memory region descriptors containing permissions information. We describe a permissions and ownership system for memory regions that allows safe delegation of privileges between protection domains for sandboxing and software reusability purposes. We describe the LumenCache, which caches region permissions to avoid most ISL lookups. We discuss applications of Lumen in debugging, security, and reliability, and extensions to use Lumen for prefetching, profiling, and user-facing memory management features. Lumen offers scalable, flexible memory access control and the ability to trade off security, system reliability, and performance in a way not possible with existing solutions.","abstract_has_math":false,"creators":["Johnson, Matthew"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Patel, Sanjay J."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2013,"date_issued":"2013-05-24T22:15:21Z","date_published":"2013-05-24T22:15:21Z","updated_at":"2026-07-22T22:25:34Z","subjects":["Memory","Multicore","Processor Architecture","Memory Systems","Memory Protection","Data Structures","Concurrency","Virtual Memory"],"languages":["en"],"rights":["Copyright 2013 Matthew R. Johnson"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/44416","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Patel, Sanjay J."]},{"key":"dc:creator","label":"Author","values":["Johnson, Matthew"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2013-05-24T22:15:21Z","2015-05-24T10:01:49Z","2013-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Memory","Multicore","Processor Architecture","Memory Systems","Memory Protection","Data Structures","Concurrency","Virtual Memory"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2013 Matthew R. Johnson"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/44416"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["A system’s memory access control mechanisms profoundly impact the performance, reliability, security, and composability of the software it runs. Desirable features of an access control mechanism include: the ability to grant arbitrary permissions on any region of memory to any thread in the system; zero-copy sharing between threads with no restrictions on the set of sharers, region granularity, or sharing of pointer-based data structures; time and space overheads dependent only on the fundamental complexity of the access control being requested; and well-defined, hierarchical memory region ownership and permission semantics. The virtual-memory-based access control used in most modern systems, as well as recently proposed enhancements, fall short along one or more of these dimensions. We introduce Lumen, an access control scheme providing security, fault isolation, and efficient shared memory to any number of threads within a single address space. Lumen uses a new concurrent interval skip list (ISL) to scalably maintain and query a set of memory region descriptors containing permissions information. We describe a permissions and ownership system for memory regions that allows safe delegation of privileges between protection domains for sandboxing and software reusability purposes. We describe the LumenCache, which caches region permissions to avoid most ISL lookups. We discuss applications of Lumen in debugging, security, and reliability, and extensions to use Lumen for prefetching, profiling, and user-facing memory management features. Lumen offers scalable, flexible memory access control and the ability to trade off security, system reliability, and performance in a way not possible with existing solutions.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2013-04-23T13:54:50Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Johnson_Matthew.pdf: 3746695 bytes, checksum: b1f16da391d49981684b7d0046d030f1 (MD5)","Made available in DSpace on 2013-05-24T22:15:21Z (GMT). No. of bitstreams: 2 Matthew_Johnson.pdf: 3746695 bytes, checksum: b1f16da391d49981684b7d0046d030f1 (MD5) license.txt: 4065 bytes, checksum: 3d6a3fe18b06b2c5e3e9c9d02b7709ea (MD5)","Restriction data tranferred 2014-07-01T11:35:40-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2015-05-24 17:18:31 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (srobbins@illinois.edu) on 2013-05-24T22:18:41Z Item is restricted until 2015-05-24T22:18:31Z","U of I Only Restriction Lifted for Item 44389 on 2015-05-24T10:01:49Z."]},{"key":"dc:title","label":"Title","values":["Flexible memory protection for multicore processors"]}]}],"canonical_facts":{"dc:contributor":["Patel, Sanjay J."],"dc:creator":["Johnson, Matthew"],"dc:date":["2013-05-24T22:15:21Z","2015-05-24T10:01:49Z","2013-05"],"dc:description":["A system’s memory access control mechanisms profoundly impact the performance, reliability, security, and composability of the software it runs. Desirable features of an access control mechanism include: the ability to grant arbitrary permissions on any region of memory to any thread in the system; zero-copy sharing between threads with no restrictions on the set of sharers, region granularity, or sharing of pointer-based data structures; time and space overheads dependent only on the fundamental complexity of the access control being requested; and well-defined, hierarchical memory region ownership and permission semantics. The virtual-memory-based access control used in most modern systems, as well as recently proposed enhancements, fall short along one or more of these dimensions. We introduce Lumen, an access control scheme providing security, fault isolation, and efficient shared memory to any number of threads within a single address space. Lumen uses a new concurrent interval skip list (ISL) to scalably maintain and query a set of memory region descriptors containing permissions information. We describe a permissions and ownership system for memory regions that allows safe delegation of privileges between protection domains for sandboxing and software reusability purposes. We describe the LumenCache, which caches region permissions to avoid most ISL lookups. We discuss applications of Lumen in debugging, security, and reliability, and extensions to use Lumen for prefetching, profiling, and user-facing memory management features. Lumen offers scalable, flexible memory access control and the ability to trade off security, system reliability, and performance in a way not possible with existing solutions.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2013-04-23T13:54:50Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Johnson_Matthew.pdf: 3746695 bytes, checksum: b1f16da391d49981684b7d0046d030f1 (MD5)","Made available in DSpace on 2013-05-24T22:15:21Z (GMT). No. of bitstreams: 2 Matthew_Johnson.pdf: 3746695 bytes, checksum: b1f16da391d49981684b7d0046d030f1 (MD5) license.txt: 4065 bytes, checksum: 3d6a3fe18b06b2c5e3e9c9d02b7709ea (MD5)","Restriction data tranferred 2014-07-01T11:35:40-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2015-05-24 17:18:31 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (srobbins@illinois.edu) on 2013-05-24T22:18:41Z Item is restricted until 2015-05-24T22:18:31Z","U of I Only Restriction Lifted for Item 44389 on 2015-05-24T10:01:49Z."],"dc:identifier":["http://hdl.handle.net/2142/44416"],"dc:language":["en"],"dc:rights":["Copyright 2013 Matthew R. Johnson"],"dc:subject":["Memory","Multicore","Processor Architecture","Memory Systems","Memory Protection","Data Structures","Concurrency","Virtual Memory"],"dc:title":["Flexible memory protection for multicore processors"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:34Z"}