Kernel management method and device based on Hypervisor

Through the Hypervisor-based kernel management method, exception event information of the operating system kernel is obtained and virtual memory measurement is performed, the risk of terminal device hardware resources is solved, the security level is improved, and the safe operation of the operating system kernel is ensured.

CN119989338APending Publication Date: 2025-05-13PRANUS BEIJING TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411839860.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing technology cannot fundamentally eliminate the risk of terminal equipment hardware resources being abused, resulting in the need to improve the security level.

Method used

The kernel management method based on Hypervisor is adopted to obtain exception event information of the operating system kernel, determine the virtual address segment information, and perform virtual memory measurements on the operating system kernel to detect whether the data has been tampered with.

Benefits of technology

It realizes rapid discovery and response to operating system kernel exceptions and tampering behaviors, ensures the safe operation and management of operating system kernels, and thus ensures that the hardware resources of terminal devices are not abused.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989338A_ABST
    Figure CN119989338A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the technical field of terminal security management, and discloses a kernel management method and device based on Hypervisor, and the method comprises the steps: obtaining abnormal event information of an operating system kernel of terminal equipment; determining virtual address field information corresponding to the abnormal event according to the abnormal event information; performing virtual memory measurement on the operating system kernel according to the virtual address field information to obtain a memory measurement result; and determining whether data in the kernel of the operating system is tampered or not according to the memory measurement result. According to the embodiment of the invention, effective detection and protection of data tampering in the kernel of the operating system are realized, and the overall security and system integrity of the terminal equipment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of terminal security management, and in particular to a kernel management method and device based on Hypervisor. Background Art

[0002] Terminal security management technology mainly uses technical means such as identity authentication, access control, and security management to achieve a secure protection environment for the system.

[0003] However, the existing security management mechanism still has the risk of abuse of terminal device hardware resources to a certain extent, and the security level needs to be improved. Summary of the invention

[0004] The embodiment of the present application provides a kernel management method based on Hypervisor to solve the problem that the risk of hardware resources of terminal devices being abused cannot be fundamentally eliminated in the prior art.

[0005] Correspondingly, the embodiment of the present application also provides a Hypervisor-based kernel management method and device to ensure the implementation and application of the above method. In order to solve the above problems, an embodiment of the present application discloses a kernel management method based on Hypervisor, the method comprising: Acquire abnormal event information of an operating system kernel of a terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through a Hypervisor; Determine virtual address segment information corresponding to the abnormal event according to the abnormal event information; wherein the virtual address segment information has a mapping relationship with the physical address segment of the physical memory of the terminal device; According to the virtual address segment information, virtual memory measurement is performed on the operating system kernel to obtain a memory measurement result; Determine whether data in the operating system kernel has been tampered with based on the memory measurement result.

[0006] The embodiment of the present application further discloses a kernel management device based on a Hypervisor, the device comprising: An acquisition module, used to acquire abnormal event information of an operating system kernel of a terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through a Hypervisor; A first processing module, configured to determine virtual address segment information corresponding to the abnormal event according to the abnormal event information; wherein the virtual address segment information has a mapping relationship with a physical address segment of a physical memory of the terminal device; A second processing module is used to perform virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result; The third processing module is used to determine whether the data in the operating system kernel is tampered with according to the memory measurement result.

[0007] An embodiment of the present application also discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, one or more of the methods described in the embodiments of the present application are implemented.

[0008] The embodiments of the present application further disclose a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, one or more methods described in the embodiments of the present application are implemented.

[0009] The embodiments of the present application also disclose a computer program product, including a computer program, which, when executed by a processor, implements one or more of the methods described in the embodiments of the present application.

[0010] The beneficial effects of the technical solution provided by the embodiment of the present application are: The embodiments of the present application can quickly discover and respond to operating system kernel anomalies and tampering behaviors by obtaining abnormal event information of the operating system kernel and performing virtual memory measurement on the physical memory, so as to ensure the safe operation and management of the operating system kernel, and further protect the hardware resources of the terminal device from being abused.

[0011] Additional aspects and advantages of the embodiments of the present application will be partially given in the description below, which will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The above and / or additional aspects and advantages of the present application will become obvious and easily understood from the following description of the embodiments in conjunction with the accompanying drawings.

[0013] Figure 1 It is a schematic diagram of the architecture of a virtualization system according to an embodiment of the present disclosure.

[0014] Figure 2 One of the flowcharts of the Hypervisor-based kernel management method provided in an embodiment of the present application.

[0015] Figure 3 The second flowchart of the Hypervisor-based kernel management method provided in the embodiment of the present application.

[0016] Figure 4A schematic diagram of the structure of a Hypervisor-based kernel management device provided in an embodiment of the present application.

[0017] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0018] The embodiments of the present application are described below in conjunction with the drawings in the present application. It should be understood that the implementation methods described below in conjunction with the drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions of the embodiments of the present application.

[0019] Those skilled in the art will appreciate that, unless specifically stated, the singular forms "one", "an", "said" and "the" used herein may also include plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application refer to that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude the implementation as other features, information, data, steps, operations, elements, components and / or combinations thereof supported by the technical field. It should be understood that when we say that an element is "connected" or "coupled" to another element, the one element may be directly connected or coupled to the other element, or it may refer to that the one element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used here may include wireless connection or wireless coupling. The term "multiple" refers to two or more than two. In view of this, "multiple" may also be understood as "at least two" in the embodiments of the present application. The term "and / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / ", unless otherwise specified, generally indicates that the associated objects before and after are in an "or" relationship.

[0020] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.

[0021] The embodiment of the present application provides a kernel management method based on a Hypervisor. Optionally, the embodiment of the present application can be applied to electronic devices, such as laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), mobile terminals such as vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and devices such as digital TVs and desktop computers. The embodiment of the present application is subsequently introduced with electronic devices as the execution subject, however, this does not constitute a limitation on the embodiment of the present application.

[0022] Figure 1It is a schematic diagram of the architecture of a virtualization system according to an embodiment of the present disclosure.

[0023] like Figure 1 As shown, the virtualization system 100 includes a terminal device 101, a virtual machine monitor (Hypervisor) 102, and a virtual machine 103. Among them, the terminal device 101 is a terminal for users to access the system, which can be a personal computer, a smart phone, a tablet computer, etc. The user operates and accesses through the terminal device. Hypervisor 102 is a virtualization management software located between the hardware and the operating system, and is used to create and manage virtual machines. It provides a virtualized environment so that multiple operating systems and applications can run on the same physical server without interfering with each other. Virtual machine 103 is a virtualized operating system instance running on the Hypervisor. Each virtual machine has its own operating system and application, and is isolated in an independent operating environment and does not interfere with other virtual machines. For example, a user interacts with the system through a terminal device and sends a request. The request arrives at the Hypervisor, and the Hypervisor assigns the request to the corresponding virtual machine for processing according to pre-set policies and rules. After receiving the request, the virtual machine processes it in its own operating system environment and generates a response. The response is returned to the Hypervisor, and the Hypervisor sends the response back to the terminal device to complete the interaction process.

[0024] See also Figure 2 , the method may include the following steps: Step 201, obtaining abnormal event information of an operating system kernel of a terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through a Hypervisor.

[0025] Among them, the application scenarios of the embodiments of the present application are, for example, the operating system kernel management of terminal devices. Optionally, the execution subject of the embodiments of the present application may be a Hypervisor; however, this is only an example of the embodiments of the present application. In other embodiments, the execution subject may also be other devices with corresponding functions, which does not constitute a limitation on the embodiments of the present application. Specifically, a Hypervisor is a software layer or firmware used to create and run multiple virtual machines on top of physical hardware. The operating system kernel runs in a virtual machine virtualized hardware environment and is the core part of the operating system running in the virtual machine. It is responsible for managing the resources and task scheduling inside the virtual machine, and interacting with the physical hardware of the terminal device through the Hypervisor.

[0026] In the Advanced RISC Machine architecture (ARM), privilege levels are called exception levels (EL). The ARMv8 Instruction Set Architecture (ARMv8) defines the following four privilege levels: EL0: User Mode, used to run common applications. It has the lowest permissions and cannot directly access hardware resources.

[0027] EL1: Kernel Mode, used to run the operating system kernel and device drivers. The kernel runs at this level and has full access to hardware resources.

[0028] EL2: Hypervisor Mode, used to run Hypervisor. Hypervisor can manage multiple operating system kernels running in EL1 and provide virtualization support.

[0029] EL3: Secure Monitor Mode, used to run trusted firmware or security monitoring programs. This level is usually used to handle security-critical tasks and provides higher security.

[0030] Among them, the operating system kernel usually runs at the EL1 level in the ARM architecture, and the hypervisor usually runs at the EL2 level in the ARM architecture. The operating system kernel running at the EL1 level has full access to hardware resources without going through other intermediate layers or interfaces, which means that the operating system kernel can directly control the use and configuration of hardware resources, including processors, memory, devices, etc. This direct access and visibility means that the kernel can communicate directly with the hardware when needed and perform various operations without the need for additional permissions or intermediate media.

[0031] The advantage of this visibility and accessibility is that the operating system can manage hardware resources more efficiently and achieve more flexible control and configuration. However, it also brings security risks, because if the operating system kernel is attacked or exploited by malicious programs, the malicious party may directly access and control hardware resources, thus threatening the security of the system.

[0032] In an embodiment of the present application, the Hypervisor obtains abnormal event information of the operating system kernel of the terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through the Hypervisor. The abnormal events of the operating system kernel include abnormal behavior of the operating system kernel. For example, the application running on the operating system kernel is abnormal, the call of the instruction stream in the operating system kernel is abnormal, and the environment variables in the operating system kernel are abnormal. The environment variables in the operating system kernel include global variables and important structure parameters.

[0033] The abnormal event information of the operating system kernel includes the error code of the abnormal event and / or the virtual address segment information of the key part of the operating system kernel related to the abnormal event. The key part of the operating system kernel includes at least one of the monitoring module, the control module, and the environment variable in the operating system kernel. The monitoring module is used to monitor the behavior and environment of the operating system; the control module is used to execute the management strategy for the operating system kernel.

[0034] Among them, a virtual address range usually represents a continuous virtual memory area. This memory segment is defined by a starting address and a size. The range of the virtual address segment can be determined by the starting address and the size. The virtual address segment information provided by the abnormal event refers to the address segment range where the abnormality occurs in the virtual address space. By obtaining the abnormal event information, the embodiment of the present application can promptly discover and respond to abnormal situations in the operating system kernel.

[0035] It should be noted that in a virtualized environment, the operating system kernel is responsible for managing the resource allocation and scheduling of virtual machines. It can dynamically adjust resource allocation according to demand, realize flexible resource utilization and optimization, and improve system performance and efficiency. In addition, the operating system kernel provides an independent operating space for each virtual machine in a virtualized environment, so that virtual machines are isolated from each other, preventing the failure or security vulnerability of one virtual machine from affecting other virtual machines, thereby enhancing the security and stability of the system.

[0036] Step 202: Determine virtual address segment information corresponding to the abnormal event based on the abnormal event information; wherein the virtual address segment information is mapped to the physical address segment of the physical memory of the terminal device.

[0037] In an embodiment of the present application, the operating system kernel includes a virtual address page table for storing the virtual address segments (i.e., linear address spaces) of the key parts of the operating system kernel. The hypervisor includes a physical address page table for storing the physical address segments corresponding to the virtual address segments of the key parts of the operating system kernel. The physical address segment stores the content of the key parts of the operating system kernel. There is a mapping relationship between the virtual address segment information and the physical address segments of the physical memory of the terminal device. Specifically, each entry in the virtual address page table corresponds to the virtual address segment of the key part of the operating system kernel, and the corresponding entry in the physical address page table stores the physical address segments corresponding to these virtual address segments. For example, if the virtual address range of the key part of the operating system kernel is 0x0000 to 0x0FFF, then an entry in the virtual address page table may be: virtual address range 0x0000 - 0x0FFF; the corresponding entry in the physical address page table stores the physical address segment corresponding to this virtual address segment: physical address range 0x8000 - 0x8FFF. Among them, an entry in the virtual address page table corresponds to the virtual address range of a key part of the operating system kernel, and the corresponding entry in the physical address page table stores the physical address range corresponding to this virtual address segment.

[0038] Step 203: Perform virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result.

[0039] It should be noted that memory measurement refers to measuring and evaluating the physical memory in the system to obtain information about memory usage, performance status and resource allocation. In the embodiment of the present application, memory measurement of the operating system kernel can verify the integrity of the data in the physical memory occupied by the operating system kernel.

[0040] In an embodiment of the present application, the Hypervisor performs virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result. Specifically, during the virtual memory measurement process, the Hypervisor obtains the target virtual address segment according to the virtual address segment information. Then, the target physical address segment corresponding to the target virtual address segment is queried according to the physical address page table. The data stored in the target physical address segment is hashed to obtain a hash string. The hash string is compared with the historical hash string to obtain a memory measurement result. Among them, when the comparison result of the hash string and the historical hash string is the same, the memory measurement result is: the integrity of the operating system kernel is "true"; when the comparison result of the hash string and the historical hash string is different, the memory measurement result is: the integrity of the operating system kernel is "false".

[0041] The historical hash string is a hash string stored in the storage medium after the data stored in the target physical address segment is hashed in advance, which can also be called a check value; or a check value stored in the storage medium after the operating system is started and loaded into the memory. The embodiment of the present application can timely detect the tampering or damage of key data of the operating system kernel through virtual memory measurement, and ensure the data integrity of the system kernel.

[0042] Step 204: Determine whether the data in the operating system kernel has been tampered with based on the memory measurement result.

[0043] In an embodiment of the present application, the Hypervisor compares the hash string with the historical hash string to obtain a memory measurement result. If the comparison result is consistent, it means that the content of the key part of the operating system kernel is not destroyed, that is, the integrity exists. If the comparison result is inconsistent, it means that the content of the key part of the operating system kernel is destroyed and the integrity does not exist. The embodiment of the present application confirms that the integrity of the operating system kernel data helps to improve the security of the system, prevent malicious tampering or unauthorized access, and protect the system from attacks.

[0044] The embodiment of the present application realizes effective detection and protection of data tampering in the operating system kernel through the above-mentioned technical means, and improves the overall security and system integrity of the terminal device. Specifically, the embodiment of the present application obtains the abnormal event information of the operating system kernel of the terminal device to help identify potential security threats. According to the abnormal event information obtained, the corresponding virtual address segment information is determined, and by associating the abnormal event with the specific virtual address segment, the abnormal position in the operating system kernel can be accurately located. There is a mapping relationship between the virtual address segment information and the physical memory address segment of the terminal device. Using this mapping relationship, the virtual address segment can be converted into an actual physical memory address segment, providing a basis for subsequent memory measurement. Then, according to the determined virtual address segment information, the operating system kernel is measured for virtual memory to obtain a hash value of a fixed length, that is, a memory measurement result. Finally, according to the memory measurement result, it is determined whether the data in the operating system kernel has been tampered with, by comparing the current memory measurement result with the reference check value calculated in advance and stored securely. If they are consistent, it means that the data is complete, otherwise it indicates that the data may be tampered with. The embodiment of the present application realizes the technical effects of enhanced security, accurate positioning and detection, and data integrity verification through the above-mentioned technical means. By running the operating system kernel in a virtualized environment and using the isolation and monitoring capabilities of the Hypervisor, unauthorized memory access and tampering can be effectively prevented. By determining the virtual address segment based on the abnormal event information and measuring the corresponding physical memory, abnormalities and tampering in the kernel can be accurately detected and located. The kernel data integrity is verified by using hash calculation and checksum comparison methods to ensure that the key data of the operating system kernel has not been tampered with, thereby improving the reliability and security of the system.

[0045] The embodiments of the present application solve the risk of abuse of hardware resources of terminal devices in the prior art. Although the existing terminal security management technology adopts means such as identity authentication, access control, and security management, it cannot fundamentally prevent the risk of kernel data being tampered with. The present application realizes effective protection of kernel data through virtual memory measurement and data integrity verification. Through the use of virtualization technology and Hypervisor, an additional security layer is provided, which can monitor and manage the operation of virtual machines, prevent unauthorized access, and further improve the security of the system. By utilizing the mapping relationship between abnormal event information and virtual address segments, abnormalities and tampering behaviors in the kernel can be accurately located and detected, providing a more effective means of security monitoring. In summary, the embodiments of the present application not only improve the security protection level of terminal devices, but also provide an effective method to monitor and protect the data integrity of the operating system kernel, solving key security issues in the prior art.

[0046] In some embodiments, obtaining abnormal event information of an operating system kernel of a terminal device includes: Receiving a virtualization call (Hypervisor Call, hvc) instruction sent by the operating system kernel, wherein the hvc instruction carries the abnormal event information; or Dynamically measure the operating system kernel to obtain the abnormal event information.

[0047] In an embodiment of the present application, the hypervisor can obtain the abnormal event information of the operating system kernel of the terminal device in two ways. One is that the hypervisor receives the hvc instruction sent by the monitoring module of the operating system kernel, and the hvc instruction carries the abnormal event information. The other is that the hypervisor obtains the abnormal event information of the operating system kernel by dynamic measurement. Among them, dynamic measurement is a method of obtaining abnormal event information by real-time monitoring and analysis of system status. In a virtualized environment, the hypervisor can monitor the behavior of the operating system kernel through dynamic measurement and detect abnormal events in a timely manner.

[0048] In some embodiments, performing virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result includes: Performing a second-order address conversion on the virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; A hash calculation is performed on the data stored in the target physical address segment to obtain a memory measurement result.

[0049] In an embodiment of the present application, under a two-stage address translation mechanism, the operating system kernel includes a virtual address page table for storing virtual address segments (i.e., linear address spaces) of various modules and environment variables of the operating system kernel. The hypervisor includes a physical address page table for storing physical address segments corresponding to various virtual address segments. In an embodiment of the present application, a second-order address translation is performed on the virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel, and then a hash calculation is performed on the data stored in the target physical address segment to obtain a memory measurement result.

[0050] In the embodiment of the present application, the hypervisor implements the mapping of virtual addresses to physical addresses through a secondary address translation mechanism so as to perform virtual memory measurement on the operating system kernel. Through virtual memory measurement, the hypervisor can monitor and verify the integrity of data stored in the operating system kernel.

[0051] In some embodiments, performing hash calculation on the data stored in the target physical address segment to obtain a memory measurement result includes: Performing hash calculation on the data stored in the target physical address segment to obtain a first hash string; Compare the first hash string with the second hash string to obtain a memory measurement result; The second hash string is obtained by the Hypervisor performing a hash calculation on the data stored in the target physical address segment in advance; Or it may be calculated by the operating system when it starts and loads data into memory.

[0052] In the embodiment of the present application, the Hypervisor generally uses a digest algorithm such as MD2, MD4, MD5, SHA1, SHA224, SHA256, SHA384, SM3, etc. during the measurement process. These algorithms can calculate the content in the memory to obtain data of a certain length, that is, a hash value. For example, the data stored in the target physical address segment is hashed to obtain a first hash string. The first hash string is then compared with the second hash string to obtain a memory measurement result. Among them, there are two ways to generate the second hash string as a reference check value (val). One is to pre-calculate the reference check value by the security team or system administrator during the system deployment or initialization phase, and store it securely in the system's storage medium, such as a security chip, a trusted hard disk area, etc. During the measurement process, the Hypervisor or other security monitoring entity will read the reference check value in the storage medium, and then compare the data calculated from the content in the memory with the check value to verify the integrity of the data. The other is that during the system startup phase, the operating system or boot loader is responsible for calculating the reference check value. For example, when the operating system starts and loads data into the memory, the operating system calculates the hash value of the key data in the memory and stores it in a secure location, such as a special storage medium or a trusted memory area. The generated and stored hash value is also used as a reference to verify the integrity of the data during the measurement process. Since this checksum is generated at the initial stage of the operating system startup, the content of the system memory has not been changed at this time, so it can be considered trustworthy.

[0053] In some embodiments, determining whether data in the operating system kernel has been tampered with according to the memory measurement result includes: If the comparison result of the first hash string is consistent with the preset second hash string, it is determined that the data in the operating system kernel has not been tampered with; If the comparison result between the first hash string and the preset second hash string is inconsistent, it is determined that the data in the operating system kernel has been tampered with.

[0054] In the embodiment of the present application, if the comparison result of the first hash string and the second hash string is consistent, it means that the data in the memory is consistent with the preset reference data, and it is determined that the data in the operating system kernel has not been tampered with. If the comparison result of the first hash string and the second hash string is inconsistent, it means that the data in the memory is inconsistent with the reference data, and it is determined that the data in the operating system kernel has been tampered with. Through hash comparison, it is possible to effectively detect whether the data in the operating system kernel has been tampered with, thereby promptly discovering and responding to potential security threats. This helps protect the system from malicious attacks and data tampering.

[0055] In some embodiments, if the comparison result between the first hash string and the preset second hash string is inconsistent, the method further includes: A specified interrupt signal is sent to the operating system kernel to instruct the operating system kernel to perform a corresponding operation according to the specified interrupt signal.

[0056] In this embodiment of the present application, if the comparison result between the first hash string and the preset second hash string is inconsistent, it indicates that the data in the operating system kernel has been tampered with, and the Hypervisor sends a specified interrupt signal to the operating system kernel, instructing the operating system kernel to perform a corresponding operation according to the specified interrupt signal.

[0057] In some embodiments, the method further comprises: Writing the abnormal event information and the memory measurement result into a shared memory; The instructing the operating system kernel to perform a corresponding operation according to the specified interrupt signal includes: Instruct the operating system kernel to obtain the abnormal event information and the memory measurement result from the shared memory in response to the specified interrupt signal, and perform corresponding operations according to the abnormal event information and the memory measurement result.

[0058] In an embodiment of the present application, the Hypervisor sends a specified interrupt signal to the operating system kernel, and writes the information of the abnormal event and the memory measurement result in the shared memory. The shared memory is used for information exchange between the Hypervisor and the operating system kernel control module, and can be a section of register address. The control module of the operating system kernel will respond to the received specified interrupt signal, obtain the information of the abnormal event and the memory measurement result from the shared memory, and the kernel control module implements the corresponding security policy according to the error code and memory measurement result of the abnormal event. By sending an interrupt signal to the kernel and sharing the information of the abnormal event, the system can respond in time when the abnormal event occurs, ensuring rapid processing and repair. Shared memory is used for information exchange between the Hypervisor and the kernel control module, making information transmission more efficient and reliable, and avoiding potential risks caused by untimely information transmission. By timely detecting and responding to abnormal events, and implementing corresponding security policies according to memory measurement results, the overall security of the system is enhanced, which helps to prevent potential attacks and data tampering.

[0059] In some embodiments, the hypervisor obtains the specified interrupt signal registered by the control module through an agreement or the control module of the operating system kernel notifies the hypervisor through an hvc instruction, and the processing function of the interrupt is used to execute the management policy for the operating system kernel. For example, the hypervisor injects the specified interrupt, the operating system kernel responds to the specified interrupt, and jumps to the interrupt processing function entry of the control module to execute a specific management policy.

[0060] In some embodiments, after receiving the virtualization call hvc instruction sent by the operating system kernel, the method further includes: Sending an inter-core interrupt signal to the operating system kernel to instruct a central processing unit (CPU) core to switch to a privilege level of the hypervisor; The operating system kernel is suspended.

[0061] In an embodiment of the present application, after the Hypervisor receives the hvc instruction, it will also initiate an inter-processor interrupt (IPI). Among them, the inter-core interrupt is used to communicate and synchronize between multiple CPU cores. Specifically, the inter-core interrupt traps multiple CPU cores from the EL1 privilege level to the EL2 privilege level. The EL1 privilege level is the privilege level at which the operating system kernel runs, and the EL2 privilege level is the privilege level at which the Hypervisor runs. On the other hand, the inter-core interrupt suspends each operating system kernel and stops the operation of each operating system kernel. This operation can achieve the purpose of protecting the scene and ensure that the state of the operating system kernel does not change when handling abnormal events. By switching multiple CPU cores from the EL1 privilege level to the EL2 privilege level and suspending the operating system kernel, the Hypervisor can protect the running scene of the operating system kernel. This helps to prevent the state of the operating system kernel from being destroyed when handling abnormal events and ensure the stability of the system.

[0062] In some embodiments, the method further comprises: Obtaining target virtual address segment information of the operating system kernel; Performing a second-order address translation on the target virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; The data stored in the target physical address segment is set to a read-only mode.

[0063] In an embodiment of the present application, the hypervisor obtains the target virtual address segment of the key part of the kernel after starting the kernel. Then, based on the target virtual address segment, the corresponding target physical address segment is obtained through the second-order address translation mechanism, and the attribute of the content in the target physical address segment is set to "read-only". The purpose of this setting is to prevent the content of the key part of the kernel from being tampered with by illegal intrusion. An attacker may try to operate on the key part of the kernel, such as modifying its content. Since the physical address segment corresponding to the key part has been set to a read-only attribute, this modification operation cannot be actually implemented, thereby protecting the integrity and security of the kernel.

[0064] As an example, see Figure 3 , Figure 3 An optional implementation of the embodiment of the present disclosure is shown, including the following steps: Step 301, obtaining abnormal event information of an operating system kernel of a terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through a Hypervisor.

[0065] In some embodiments, obtaining abnormal event information of an operating system kernel of a terminal device includes: Receiving a virtualization call hvc instruction sent by the operating system kernel, where the hvc instruction carries the abnormal event information; or Dynamically measure the operating system kernel to obtain the abnormal event information.

[0066] In some embodiments, if all contents in the page table of the key module of the operating system kernel corresponding to the abnormal event are allowed to be read-only, the target virtual address segment information is converted into a second-order address to obtain the target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; the data stored in the target physical address segment is set to read-only mode. If part of the contents in the page table of the key module of the operating system kernel corresponding to the abnormal event are allowed to be written, step 302 is executed.

[0067] Step 302, sending an inter-core interrupt signal to the operating system kernel to instruct the central processing unit CPU core to switch to the privilege level of the hypervisor; The operating system kernel is suspended.

[0068] Step 303: Determine virtual address segment information corresponding to the abnormal event according to the abnormal event information; wherein there is a mapping relationship between the virtual address segment information and the physical address segment of the physical memory of the terminal device.

[0069] In some embodiments, performing virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result includes: Performing a second-order address conversion on the virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; A hash calculation is performed on the data stored in the target physical address segment to obtain a memory measurement result.

[0070] In some embodiments, performing hash calculation on the data stored in the target physical address segment to obtain a memory measurement result includes: Performing hash calculation on the data stored in the target physical address segment to obtain a first hash string; The first hash string is compared with a pre-calculated second hash string to obtain a memory measurement result.

[0071] In some embodiments, determining whether data in the operating system kernel has been tampered with according to the memory measurement result includes: If the comparison result of the first hash string is consistent with the preset second hash string, it is determined that the data in the operating system kernel has not been tampered with; If the comparison result between the first hash string and the preset second hash string is inconsistent, it is determined that the data in the operating system kernel has been tampered with.

[0072] Step 304: If the comparison result between the first hash string and the preset second hash string is inconsistent, a specified interrupt signal is sent to the operating system kernel to instruct the operating system kernel to perform a corresponding operation according to the specified interrupt signal. If the comparison result between the first hash string and the preset second hash string is consistent, the CPU core is instructed to switch back to the original privilege level and the operating system kernel is suspended.

[0073] In some embodiments, the method further comprises: Writing the abnormal event information and the memory measurement result into a shared memory; The instructing the operating system kernel to perform a corresponding operation according to the specified interrupt signal includes: Instruct the operating system kernel to obtain the abnormal event information and the memory measurement result from the shared memory in response to the specified interrupt signal, and perform corresponding operations according to the abnormal event information and the memory measurement result.

[0074] Based on the same principle as the method provided in the embodiment of the present application, the embodiment of the present application also provides a kernel management device based on Hypervisor, such as Figure 4 As shown, the device comprises: Acquisition module 1, used to acquire abnormal event information of the operating system kernel of the terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through a Hypervisor; A first processing module 2 is used to determine virtual address segment information corresponding to the abnormal event according to the abnormal event information; wherein the virtual address segment information has a mapping relationship with the physical address segment of the physical memory of the terminal device; A second processing module 3 is used to perform virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result; The third processing module 4 is used to determine whether the data in the operating system kernel has been tampered with according to the memory measurement result.

[0075] In some embodiments, the acquisition module is specifically used to: Receiving a virtualization call hvc instruction sent by the operating system kernel, where the hvc instruction carries the abnormal event information; or Dynamically measure the operating system kernel to obtain the abnormal event information.

[0076] In some embodiments, the second processing module is specifically used to: Performing a second-order address conversion on the virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; A hash calculation is performed on the data stored in the target physical address segment to obtain a memory measurement result.

[0077] In some embodiments, the second processing module is further specifically configured to: Performing hash calculation on the data stored in the target physical address segment to obtain a first hash string; The first hash string is compared with a pre-calculated second hash string to obtain a memory measurement result.

[0078] In some embodiments, the third processing module is specifically configured to: If the comparison result of the first hash string is consistent with the preset second hash string, it is determined that the data in the operating system kernel has not been tampered with; If the comparison result between the first hash string and the preset second hash string is inconsistent, it is determined that the data in the operating system kernel has been tampered with.

[0079] In some embodiments, if the comparison result between the first hash string and the preset second hash string is inconsistent, the third processing module is further specifically used to: A specified interrupt signal is sent to the operating system kernel to instruct the operating system kernel to perform a corresponding operation according to the specified interrupt signal.

[0080] In some embodiments, the third processing module is further specifically configured to: Writing the abnormal event information and the memory measurement result into a shared memory; Instruct the operating system kernel to obtain the abnormal event information and the memory measurement result from the shared memory in response to the specified interrupt signal, and perform corresponding operations according to the abnormal event information and the memory measurement result.

[0081] In some embodiments, the first processing module is further specifically configured to: Sending an inter-core interrupt signal to the operating system kernel to instruct the central processing unit (CPU) core to switch to the privilege level of the hypervisor; The operating system kernel is suspended.

[0082] In some embodiments, the third processing module is further specifically configured to: Obtaining target virtual address segment information of the operating system kernel; Performing a second-order address translation on the target virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; The data stored in the target physical address segment is set to a read-only mode.

[0083] The Hypervisor kernel management device provided in the embodiment of the present application can achieve Figure 2 To avoid repetition, the various processes implemented in the method embodiment are not described here.

[0084] The hypervisor kernel management device provided in the present application can quickly discover and respond to operating system kernel anomalies and tampering behaviors by obtaining abnormal event information of the operating system kernel and performing virtual memory measurement on the operating system kernel, so as to ensure the safe operation and management of the operating system kernel, thereby ensuring the security of terminal devices and related data.

[0085] The kernel management device of the Hypervisor in the embodiment of the present application can execute the kernel management method of the Hypervisor provided in the embodiment of the present application, and the implementation principle is similar. The actions performed by each module and unit in the kernel management device of the Hypervisor in each embodiment of the present application correspond to the steps in the kernel management method of the Hypervisor in each embodiment of the present application. For the detailed functional description of each module of the kernel management device of the Hypervisor, please refer to the description in the corresponding kernel management method of the Hypervisor shown in the previous text, which will not be repeated here.

[0086] Based on the same principle as the method shown in the embodiment of the present application, the embodiment of the present application also provides an electronic device, which may include but is not limited to: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the hypervisor kernel management method shown in any optional embodiment of the present application by calling the computer program. Compared with the prior art, the hypervisor kernel management method provided by the present application can quickly discover and respond to operating system kernel abnormalities and tampering behaviors by obtaining abnormal event information of the operating system kernel and performing virtual memory measurement on the physical memory, so as to ensure the safe operation and management of the operating system kernel, thereby ensuring the security of terminal devices and related data.

[0087] In an optional embodiment, an electronic device is also provided, such as Figure 5 As shown, Figure 5 The electronic device 5000 shown includes: a processor 5001 and a memory 5003. The processor 5001 and the memory 5003 are connected, such as through a bus 5002. Optionally, the electronic device 5000 may also include a transceiver 5004, which may be used for data interaction between the electronic device and other electronic devices, such as data transmission and / or data reception. It should be noted that in actual applications, the transceiver 5004 is not limited to one, and the structure of the electronic device 5000 does not constitute a limitation on the embodiments of the present application.

[0088] Processor 5001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It may implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of this application. Processor 5001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0089] The bus 5002 may include a path to transmit information between the above components. The bus 5002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The bus 5002 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0090] The memory 5003 may be a ROM (Read Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory) or other types of dynamic storage devices that can store information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, optical disk storage (including compressed optical disk, laser disk, optical disk, digital versatile disk, Blu-ray disk, etc.), magnetic disk storage medium, other magnetic storage devices, or any other medium that can be used to carry or store computer programs and can be read by a computer, without limitation herein.

[0091] The memory 5003 is used to store the computer program for executing the embodiment of the present application, and the execution is controlled by the processor 5001. The processor 5001 is used to execute the computer program stored in the memory 5003 to implement the steps shown in the above method embodiment.

[0092] Among them, electronic devices include but are not limited to: mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The electronic device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0093] An embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps and corresponding contents of the aforementioned method embodiment can be implemented.

[0094] The embodiment of the present application also provides a computer program product, including a computer program, which can implement the steps and corresponding contents of the aforementioned method embodiment when executed by a processor.

[0095] The terms "first", "second", "third", "fourth", "1", "2", etc. (if any) in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than that shown or described in the drawings.

[0096] It should be understood that, although each operation step is indicated by arrows in the flowchart of the embodiment of the present application, the implementation order of these steps is not limited to the order indicated by the arrows. Unless clearly stated herein, in some implementation scenarios of the embodiment of the present application, the implementation steps in each flowchart can be performed in other orders according to demand. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages based on actual implementation scenarios. Some or all of these sub-steps or stages may be executed at the same time, and each sub-step or stage in these sub-steps or stages may also be executed at different times respectively. In different scenarios of execution time, the execution order of these sub-steps or stages may be flexibly configured according to demand, and the embodiment of the present application does not limit this.

[0097] The above is only an optional implementation method for some implementation scenarios of the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the technical concept of the solution of the present application, other similar implementation methods based on the technical ideas of the present application are also within the protection scope of the embodiments of the present application.

Claims

1. A kernel management method based on a virtual machine monitor Hypervisor, characterized in that: include: Acquire abnormal event information of an operating system kernel of a terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through a Hypervisor; Determine virtual address segment information corresponding to the abnormal event according to the abnormal event information; wherein the virtual address segment information has a mapping relationship with the physical address segment of the physical memory of the terminal device; According to the virtual address segment information, virtual memory measurement is performed on the operating system kernel to obtain a memory measurement result; Determine whether data in the operating system kernel has been tampered with based on the memory measurement result.

2. The Hypervisor-based kernel management method according to claim 1, characterized in that: The obtaining of abnormal event information of the operating system kernel of the terminal device includes: Receiving a virtualization call hvc instruction sent by the operating system kernel, where the hvc instruction carries the abnormal event information; or Dynamically measure the operating system kernel to obtain the abnormal event information.

3. The Hypervisor-based kernel management method according to claim 1, characterized in that: The step of performing virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result includes: Performing a second-order address conversion on the virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; A hash calculation is performed on the data stored in the target physical address segment to obtain a memory measurement result.

4. The Hypervisor-based kernel management method according to claim 3, characterized in that: The performing hash calculation on the data stored in the target physical address segment to obtain a memory measurement result includes: Performing hash calculation on the data stored in the target physical address segment to obtain a first hash string; The first hash string is compared with a pre-calculated second hash string to obtain a memory measurement result.

5. The Hypervisor-based kernel management method according to claim 4, characterized in that: The determining, according to the memory measurement result, whether the data in the operating system kernel has been tampered with comprises: If the comparison result of the first hash string is consistent with the preset second hash string, it is determined that the data in the operating system kernel has not been tampered with; If the comparison result between the first hash string and the preset second hash string is inconsistent, it is determined that the data in the operating system kernel has been tampered with.

6. The Hypervisor-based kernel management method according to claim 5, characterized in that: If the comparison result between the first hash string and the preset second hash string is inconsistent, the method further includes: A specified interrupt signal is sent to the operating system kernel to instruct the operating system kernel to perform a corresponding operation according to the specified interrupt signal.

7. The Hypervisor-based kernel management method according to claim 6, characterized in that: The method further comprises: Writing the abnormal event information and the memory measurement result into a shared memory; The instructing the operating system kernel to perform a corresponding operation according to the specified interrupt signal includes: Instruct the operating system kernel to obtain the abnormal event information and the memory measurement result from the shared memory in response to the specified interrupt signal, and perform corresponding operations according to the abnormal event information and the memory measurement result.

8. The Hypervisor-based kernel management method according to claim 2, characterized in that: After receiving the virtualization call hvc instruction sent by the operating system kernel, the method further includes: Sending an inter-core interrupt signal to the operating system kernel to instruct the central processing unit (CPU) core to switch to the privilege level of the hypervisor; The operating system kernel is suspended.

9. The Hypervisor-based kernel management method according to claim 1, characterized in that: The method further comprises: Obtaining target virtual address segment information of the operating system kernel; Performing a second-order address translation on the target virtual address segment information to obtain a target physical address segment corresponding to the virtual address segment in the physical memory occupied by the operating system kernel; The data stored in the target physical address segment is set to a read-only mode.

10. A kernel management device based on Hypervisor, characterized in that: include: An acquisition module, used to acquire abnormal event information of an operating system kernel of a terminal device; wherein the operating system kernel runs in a virtualized hardware environment of a virtual machine and interacts with the terminal device through a Hypervisor; A first processing module, configured to determine virtual address segment information corresponding to the abnormal event according to the abnormal event information; wherein the virtual address segment information has a mapping relationship with a physical address segment of a physical memory of the terminal device; A second processing module is used to perform virtual memory measurement on the operating system kernel according to the virtual address segment information to obtain a memory measurement result; The third processing module is used to determine whether the data in the operating system kernel is tampered with according to the memory measurement result.

11. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the method according to any one of claims 1 to 9 is implemented when the processor executes the program.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.

13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.

Citation Information

Cited By

  • Runtime detection system based on ARM architecture exception level

    CN121598364A