IP Library › Granted Patent US 12,592,962
Granted Patent B2
US 12,592,962 · App. 18/410,717 · Granted Mar 31, 2026

Dynamic cloud workload reallocation based on active security exploits in dynamic random access memory (DRAM)

Inventor: Phani Bhushan Avadhanam (San Diego, CA)
Assignee: Oracle International Corporation
H04L63/1466G06F12/1458G06F21/55G06F21/79G06F2212/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,962
App. No.
18/410,717
Granted
Mar 31, 2026
Kind
B2
Abstract

The present embodiments relate to identifying and mitigating memory bit flips in a cloud infrastructure service. The cloud infrastructure service can provide a monitoring system to monitor low level memory space to detect bit flips by the DRAM instances in the cloud infrastructure service. The bit flips detected in various DRAM computing instances can be processed to verify that the bit flips are sustained (e.g., and possibly relating to a Rowhammer attack) rather than transitory bit flips occurring in DRAM computing devices. Responsive to validating a set of bit flips at one or more computing instances, workloads associated with the affected computing instances can be migrated to other computing instances in the cloud infrastructure service.

Claims (62)

1 . A method, comprising:

processing, for one or more computing instances in a cloud infrastructure service, a set of memory rows to identify one or more bit flips in the one or more computing instances;

validating at least a subset of the one or more computing instances as comprising sustained bit flips based at least in part on the one or more bit flips identified in the one or more computing instances; and

responsive to validating the subset of the one or more computing instances as comprising sustained bit flips:

migrating one or more computing resources residing on the subset of one or more validated computing instances to one or more corresponding nodes in the cloud infrastructure service.

2 . The method of claim 1 , further comprising:

updating a cloud scheduler to redirect processing requests from the subset of one or more validated computing instances to the one or more corresponding nodes.

3 . The method of claim 1 , further comprising:

generating a bitmap for a computing instance of the one or more computing instances, the bitmap comprising a set of one or more bit flips identified in the computing instance,

wherein the computing instance is validated as comprising sustained bit flips by processing the bitmap.

4 . The method of claim 3 , further comprising:

obtaining an immutable image for the computing instance; and

modifying the immutable image to generate a modified image for the computing instance,

wherein processing the bitmap comprises:

comparing the bitmap for the computing instance to the modified image for the computing instance.

5 . The method of claim 1 , wherein validating at least the subset of the one or more computing instances as comprising sustained bit flips comprises:

applying an exponential mathematical equation to a bit flip of the one or more bit flips to generate a value; and

determining that the bit flip is a sustained bit flip based at least in part on analyzing the value.

6 . The method of claim 5 , wherein the value is a cumulative sum of a floating-point number or a decimal-point number.

7 . The method of claim 1 , wherein the method is performed by a cloud infrastructure node.

8 . A system, comprising:

at least one device including a hardware processor; and

the system being configured to perform operations comprising:

processing, for one or more computing instances in a cloud infrastructure service, a set of memory rows to identify one or more bit flips in the one or more computing instances;

validating at least a subset of the one or more computing instances as comprising sustained bit flips based at least in part on the one or more bit flips identified in the one or more computing instances; and

responsive to validating the subset of the one or more computing instances as comprising sustained bit flips:

migrating one or more computing resources residing on the subset of one or more validated computing instances to one or more corresponding nodes in the cloud infrastructure service.

9 . The system of claim 8 , wherein the operations further comprise:

updating a cloud schedule to redirect processing requests from the subset of one or more validated computing instances to the one or more corresponding nodes.

10 . The system of claim 8 , wherein the operations further comprise:

generating a bitmap for a computing instance of the one or more computing instances, the bitmap comprising a set of one or more bit flips identified in the computing instance,

wherein the computing instance is validated as comprising sustained bit flips by processing the bitmap.

11 . The system of claim 10 , wherein the operations further comprise:

obtaining an immutable image for the computing instance; and

modifying the immutable image to generate a modified image for the computing instance,

wherein processing the bitmap comprises:

comparing the bitmap for the computing instance to the modified image for the computing instance.

12 . The system of claim 8 , wherein validating at least the subset of the one or more computing instances as comprising sustained bit flips comprises:

applying an exponential mathematical equation to a bit flip of the one or more bit flips to generate a value; and

determining that the bit flip is a sustained bit flip based at least in part on analyzing the value,

wherein the value is a cumulative sum of a floating-point number or a decimal-point number.

13 . The system of claim 8 , wherein validating a computing instance is associated with a Rowhammer attack.

14 . One or more non-transitory computer-readable media comprising instructions that, when executed by one or more hardware processors, causes performance of operations comprising:

processing, for one or more computing instances in a cloud infrastructure service, a set of memory rows to identify one or more bit flips in the one or more computing instances;

validating at least a subset of the one or more computing instances as comprising sustained bit flips based at least in part on the one or more bit flips identified in the one or more computing instances; and

responsive to validating the subset of the one or more computing instances as comprising sustained bit flips:

migrating one or more computing resources residing on the subset of one or more validated computing instances to one or more corresponding nodes in the cloud infrastructure service.

15 . The one or more non-transitory computer-readable media of claim 14 , wherein the operations further comprise:

updating a cloud scheduler to redirect processing requests from the subset of one or more validated computing instances to the one or more corresponding nodes.

16 . The one or more non-transitory computer-readable media of claim 14 , wherein the operations further comprise:

generating a bitmap for a computing instance of the one or more computing instances, the bitmap comprising a set of one or more bit flips identified in the computing instance,

wherein the computing instance is validated as comprising sustained bit flips by processing the bitmap.

17 . The one or more non-transitory computer-readable media of claim 16 , wherein the operations further comprise:

obtaining an immutable image for the computing instance; and

modifying the immutable image to generate a modified image for the computing instance,

wherein processing the bitmap comprises:

comparing the bitmap for the computing instance to the modified image for the computing instance.

18 . The one or more non-transitory computer-readable media of claim 14 , wherein validating at least the subset of the one or more computing instances as comprising sustained bit flips comprises:

applying an exponential mathematical equation to a bit flip of the one or more bit flips to generate a value; and

determining that the bit flip is a sustained bit flip based at least in part on analyzing the value.

19 . The one or more non-transitory computer-readable media of claim 18 , wherein the value is a cumulative sum of a floating-point number or a decimal-point number.

20 . The one or more non-transitory computer-readable media of claim 14 , wherein the one or more computing instances comprise dynamic random access memory (DRAM) memory cells.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: AVADHANAM, PHANI BHUSHAN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 066110/0624 →
Continuity (2)
Continuation 17463488 · Aug 31, 2021
Related Publication 20240146764A1 · May 2, 2024
References Cited (16)
US 9329930B2 · Ingalls · 2016 [cited by examiner]
US 10169577B1 · Sobel · 2019 [cited by examiner]
US 11902323B2 · Avadhanam · 2024 [cited by examiner]
US 20200012600A1 · Konoth · 2020 [cited by examiner]
US 20200380130A1 · Purushotham · 2020 [cited by examiner]
US 20210064459A1 · Ramasamy · 2021 [cited by examiner]
US 20210349995A1 · Qureshi · 2021 [cited by examiner]
US 20210382798A1 · Ganesan · 2021 [cited by examiner]
US 20210406384A1 · Jin · 2021 [cited by examiner]
US 20220115057A1 · Pope · 2022 [cited by examiner]
US 20220156159A1 · Wang · 2022 [cited by examiner]
US 20220262428A1 · Bains · 2022 [cited by examiner]
US 20220291837A1 · Shao · 2022 [cited by examiner]
US 20220413959A1 · Sethumadhavan · 2022 [cited by examiner]
WO WO2019070195A1 · 2019 [cited by examiner]
Yang et al.; “An Effective and Scalable VM Migration Strategy to Mitigate Cross-VM Side-Channel Attacks in Cloud”, Apr. 2019, China Communications, pp. 151-171. (Year: 2019). [cited by examiner]