Automatic library operating system internal-external isolation method
Through automated detection and configuration file division isolation domains, combined with program analysis and placeholder conversion, the security isolation problem between Unikernel system micro-libraries is solved, and the automation and security of internal and external isolation of the library operating system is realized, reducing the cost and error rate of manual settings.
Patent Information
- Application Number
- CN202510471210.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-07-22
AI Technical Summary
Unikernel's single-core feature leads to a lack of isolation between system micro-stores, which has security problems, and it is difficult for the existing technology to automatically implement permission calculation and variable allocation for internal and external isolation of library operating systems, resulting in high cost of manual setup and error-prone.
By automatically detecting and marking variables and functions that potentially need to set isolation permissions, dividing isolation domains based on configuration files, using program analysis and placeholder conversion, automated permission calculation and variable allocation are realized, ensuring the security and efficiency of internal and external isolation.
It realizes secure isolation within the library operating system, and supports the security of external VMFUNC access, reducing the cost and error rate of manual settings, and improving the automation of system isolation.
Smart Images

Figure CN120353539A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of system security isolation, and particularly relates to an in-out isolation method for an automated library operating system. Background Art
[0002] The representative implementation of the library operating system, Unikernel, is a very promising technology in the cloud service deployment scenario. Unikernel (single-address operating system) generates a virtual machine image with a single address space and only retains the kernel modules required by the application. Therefore, Unikernel avoids the user-kernel state switch, has high execution efficiency, and at the same time has a small image size, making it suitable for scenarios such as Serverless (serverless computing) and microservice deployment.
[0003] However, the single-core characteristic of Unikernel results in a lack of isolation between system micro-libraries, which may lead to potential security problems. To solve this problem, existing work introduces the Memory Protection Key mechanism to artificially divide the library operating system into several isolation domains. The security isolation domain division of the system micro-libraries is determined by means of a configuration file. Private variables are stored in their respective isolation domains, and shared variables are stored in the public access domain, thereby achieving secure isolation between micro-libraries.
[0004] In addition, as a virtual machine, the communication between Unikernels will cause VM-Exit, resulting in high overhead. Intel provides VMFUNC to achieve efficient EPT switching, which can accelerate the communication between two virtual machines without the need for VM-Exit, and is more suitable for scenarios with complex call chains in the cloud service scenario.
[0005] However, applying the security isolation library operating system implemented based on MPK to the cloud service scenario has the following problems:
[0006] 1. What MPK implements is the isolation within the library operating system. VMFUNC allows the CPU of the caller to directly access the memory address of the callee. To restrict the access behavior of the caller, it is necessary to limit the memory space it can access to achieve secure isolation between systems. The goals of in-system and inter-system isolation are different, and there is a conflict in the isolation scope, so it is necessary to distinguish the isolation behaviors of the two.
[0007] 2. When the two isolation behaviors appear simultaneously, it is unrealistic to manually calculate the permissions of the isolation variables. Because there are a large number of micro-libraries in the library operating system, there are a large number of variables in the micro-libraries. At the same time, the micro-libraries have different combinations and different isolation domain placement modes, and an automated isolation mechanism needs to be implemented.
[0008] 3. The calculation of permissions and the allocation of memory addresses in Problem 2 rely on the placeholders in the micro-library. The placeholders will be replaced after the method of system isolation placement is determined, and variables will be automatically allocated to the corresponding address spaces during the compilation and startup phases. Since there are a large number of variables in the system micro-library, it is unrealistic to manually label these variables. Summary of the Invention
[0009] The present invention provides an internal-external isolation method for an automated library operating system, which ensures the secure isolation of the micro-library inside the library operating system, and at the same time ensures that the external VMFUNC can securely access the data inside the library operating system, solves the permission conflicts between the two settings of internal-external isolation, and reduces the cost of manual permission settings.
[0010] The present invention provides an internal-external isolation method for an automated library operating system, including the following steps:
[0011] Step 1: Analyze the system micro-library, automatically detect and mark all variables that potentially need to set isolation permissions and functions involved in cross-domain calls, providing a basis for subsequent permission calculation and isolation;
[0012] Step 2: Initialize the composition of the micro-library of the library operating system based on the configuration file, divide the protection domains shared inside the system and the functions allowed for external access, and clarify the isolation boundaries between the inside and outside of the system;
[0013] Step 3: According to the variables and functions marked in Step 1 and the configuration file in Step 2, automatically calculate the variable permissions and perform placeholder conversion, determine the permission levels of the variables and the functions for cross-domain execution, and implement automatic allocation of permissions and isolation settings;
[0014] Step 4: At the system initialization and startup stage, according to the variable permissions determined in Step 3, allocate the variables to the corresponding memory spaces, implement the isolation inside the system, and provide a secure remote service interface for external access;
[0015] Step 5: When an external caller initiates a remote access through VMFUNC, through permission checking and the division of the access stack, ensure that the external access can only access the variables isolated between systems, and at the same time ensure the memory access security of the callee, and implement the isolation outside the system.
[0016] The present invention also provides an internal-external isolation device for an automated library operating system, including a memory and one or more processors. The memory stores executable code, and when the one or more processors execute the executable code, it is used to implement the internal-external isolation method of the automated library operating system.
[0017] The present invention also provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it is used to implement the in-out isolation method of the automated library operating system.
[0018] In summary of the above steps, the caller realizes lightweight access to the callee, while preventing the security leakage problem of the callee due to the complete exposure of the memory space to the caller.
[0019] Compared with the prior art, the present invention has the following excellent effects:
[0020] The automated in-out isolation mechanism of the library operating system provided by the present invention explicitly distinguishes the internal isolation of the library operating system from the inter-library operating system isolation in the case of using VMFUNC for the library operating system supporting internal isolation, ensuring data security.
[0021] The placeholder automatic annotation mechanism based on program analysis provided by the present invention solves the manual inspection cost of placeholder annotation for implementing permission isolation, and avoids the costs of manual annotation omission and debugging.
[0022] The permission automatic calculation method based on program analysis provided by the present invention avoids the manual costs, omission problems, and debugging problems caused by manually calculating permissions in the case of changes in the security isolation configuration of the library operating system and changes in the functions allowing external VMFUNC access. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 It is an architecture diagram of an automated in-out isolation technology method for a library operating system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0025] Automatic placeholder annotation: In order to implement the security isolation of the library operating system, placeholders need to be added to cross-domain functions and cross-domain variables for subsequent permission calculation. This process only needs to be executed once after the micro-library implementation is completed.
[0026] Based on the algorithm of program analysis, all potential variables that need to set isolation permissions and functions involved in cross-domain calls are automatically detected in the system micro-library. The placeholder is used for permission calculation when the subsequent system micro-library is assembled into the library operating system, determining whether these variables are cross-domain.
[0027] In this embodiment, first, it is assumed that no isolation policy is set for all system micro-libraries, and the micro-libraries are integrated with the system for compilation to obtain the compilation intermediate result LLVM IR. Static analysis of the program can be performed based on LLVM IR. clang is the program source code, which can be directly parsed through the Coccinelle tool.
[0028] [1-1] For cross-domain functions, in this embodiment, first, all functions F defined in the micro-library are counted define , and for each function F define,i its function implementation is scanned.
[0029] [1-2] In this embodiment, all functions included in the function implementation of F define,i are defined as F impl . If there is an implemented function indicating that the function implementation is not defined in this micro-library, this embodiment defines this function f as a potential cross-domain function. The set composed of all functions f in this system micro-library is defined as f cross,temp .
[0030] [1-3] For cross-domain variables, this embodiment determines that variables allocated on the heap and global variables are potential cross-domain variables. Specifically, in this embodiment, the Coccinelle tool is used to identify global variables called by all cross-domain functions and variables allocated through malloc-related functions and record them as potential cross-domain variables S share,temp , and placeholder identifiers are marked for potential cross-domain variables.
[0031] The placeholder annotation is a prerequisite for permission calculation and automatic isolation. Through this method, this embodiment completes Figure 1 item ②, and obtains the placeholders in item ③. This embodiment significantly reduces the manual inspection cost of placeholder annotation and avoids the costs of manual annotation omission and debugging.
[0032] 2. Callee initialization based on the configuration file: Determine the micro-library composition of the library operating system, divide the library functions into domains (shared within the system), and functions allowed to be accessed by external VMFUNC (shared between systems).
[0033] In this embodiment, by defining a configuration file, the number of isolation domains of the system is determined. Then, the micro-libraries that make up the library operating system are placed in the corresponding isolation domains to achieve micro-library isolation within the system. At the same time, the functions accessible by VMFUNC are declared to be used to subsequently restrict the function range and variable protection accessible by the caller, so as to achieve isolation between library operating systems. Such as Figure 1 the configuration file constraint in item ③.
[0034] Specifically, for the in-memory database application Redis, the main component libraries include libc, liblwip, libnewlib, and libredis. In this embodiment, two domains are divided, and the system core libraries libc, lib-lwip, and lib-newlib are placed in domain 0, and the third-party library lib-redis is placed in domain 1, thus realizing the isolation between the core library and the third-party library.
[0035] The Redis application composed of the library operating system is mainly provided as a third-party service application. In this embodiment, the remote data read operations SET and GET can be used as functions that allow external VMFUNC access. Therefore, it is necessary to further restrict the variables associated with SET and GET subsequently to achieve isolation between library operating systems.
[0036] [2-1] The user declares multiple protection domains, such as domain 0 and domain 1, in the configuration file, and each domain is isolated using the Intel Memory Protection Key (MPK). A library operating system consists of multiple system micro-libraries. In this embodiment, libraries that trust each other are placed in one protection domain, and those that do not trust each other are placed in different domains.
[0037] [2-2] The user declares the functions accessible by VMFUNC and the system micro-libraries where these functions are located in the configuration file for subsequent access permission checks and cross-domain access.
[0038] 3. Placeholder transformation: Based on the settings in the configuration file and static analysis of the program, the variable permissions are automatically calculated and placeholder transformation is performed. The result of the placeholder transformation determines whether a function needs to execute across domains, and the permission levels of the variables are private, shared within the system, and shared between systems.
[0039] In this embodiment, Figure 1 the above steps are completed in ③ of this embodiment. By means of static analysis, the private variable S within the domain private , the shared variable S between domains intra , the shared variable S between library operating systems inter and the shared S between the two both are found. The division of variable permissions determines the corresponding memory spaces that these variables will be allocated to by the library operating system after startup.
[0040] [3-1] For cross-domain functions, in this embodiment, all the component micro-libraries in the configuration file are scanned. For the set of potential cross-domain functions F cross,temp obtained in step (1) in one of the micro-libraries, if the cross-domain function is defined in the same domain, then from the set of potential cross-domain functions Fcross,temp Remove from it to obtain the final cross-domain function set F cross For F cross add a gate nested modifier to the function so that the function can achieve stack space switching and MPK permission switching during cross-domain execution.
[0041] [3-2] The present invention uses Coccinelle to find the potential cross-domain function set F cross Variables associated with it in the potential shared variable set S share,temp In this embodiment, it is denoted as the shared variable set S within the library operating system intra .
[0042] [3-3] The present invention performs function call graph analysis based on the results of LLVM (Low Level Virtual Machine) IR (Intermediate Representation), and performs a breadth-first search of function calls with the functions allowed to be accessed by VMFUNC as the root nodes. For the variables in S involved in the functions on the call graph, they are denoted as the shared variables S between library operating systems share,temp . inter .
[0043] [3-4] For the common variables in the shared variable set S within the library operating system and the shared variable set S between library operating systems, in this embodiment, it is denoted as S intra = S inter ∩S both At the same time, S intra and S inter both remove S intra from them. For the remaining S inter variables that are not in S both , S both , and S intra as well as S inter , they are saved as the private domain variable set and denoted as S share,temp pr i va t e . .
[0044] 4. System initialization and startup: According to the variable permissions determined by the result of placeholder conversion, allocate the permissions of the corresponding variables to the corresponding memory spaces to achieve mutual isolation. Then provide remote access services as the callee.
[0045] [4-1] During the startup phase, the system divides separate memory space addresses for each protection domain, as well as intra-share and inter-share variables within the system. The allocation of all global variables and heap variables is performed at the corresponding addresses.
[0046] [4-2]MPK supports at most 16 protection domains, indexed from 0 to 15. For the variables private within each domain, the present invention reserves protection domains 0 to 11 for the private domains to store data. The private data within each protection domain is stored in the corresponding protection domain. Domain 12 is reserved as a buffer area for VMFUNC access, and domains 13 to 15 are respectively used to store S intra , S inter and S both .
[0047] 5. Remote access: The service caller uses VMFUNC for remote access (VMFUNC access cannot directly transmit parameters and needs to rely on shared memory to achieve lightweight access). Through permission check constraints, it is ensured that external access can only access the variables isolated between corresponding systems. At the same time, a separate access stack is divided to ensure the memory access security of the callee.
[0048] [5-1] First, allocate a buffer on the shared memory of the host machines of the caller and the callee for passing in the function name of the access and the corresponding parameters.
[0049] [5-2] The caller saves the register state, initiates a VMFUNC access jump to the EPT of the callee, and enters domain 12 reserved for VMFUNC access.
[0050] [5-3] The callee parses the access function name and parameters from the buffer.
[0051] [5-4] Call the dynamic gate, obtain the protection domain id where the target function is located based on the library where the target function is located, switch from domain 12 to the corresponding domain id, and at the same time provide a separate thread id to achieve secure cross-domain access of the external caller.
[0052] [5-5] Save the execution result to the buffer.
[0053] [5-6] Restore the register state saved in [5-2], and switch back to the EPT of the caller through VMFUNC.
[0054] [5-7] Copy the execution result from the buffer and release the buffer in the shared memory.
[0055] The embodiment of the present invention also provides an in-out isolation device for an automated library operating system, which includes a memory and one or more processors. Executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement the in-out isolation method for the automated library operating system. Taking software implementation as an example, as a logically meaningful device, it is formed by reading the corresponding computer program instructions in the non-volatile memory into the memory and running them through the processor of any device with data processing capabilities where it is located. In terms of hardware, in addition to the processor, memory, network interface, and non-volatile memory, any device with data processing capabilities where the device in the embodiment is located usually includes other hardware according to the actual functions of the device with data processing capabilities, which will not be elaborated here.
[0056] The embodiment of the present invention also provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it is used to implement the in-out isolation method for the automated library operating system. The computer-readable storage medium can be an internal storage unit of any device with data processing capabilities described in any of the foregoing embodiments, such as a hard disk or memory. The computer-readable storage medium can also be any device with data processing capabilities, such as a plug-in hard disk, a Smart Media Card (SMC), an SD card, a Flash Card, etc. equipped on the device. Further, the computer-readable storage medium can also include both an internal storage unit of any device with data processing capabilities and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and can also be used to temporarily store the data that has been output or will be output.
[0057] The above are only the embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, various changes and modifications can be made to the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.
Claims
1. An internal-external isolation method for an automated library operating system, characterized in that, It includes the following steps: Step 1: Analyze the system micro-library, automatically detect and mark all variables that potentially need to set isolation permissions and functions involving cross-domain calls, providing a basis for subsequent permission calculation and isolation; Step 2: Initialize the micro-library composition of the library operating system based on the configuration file, divide the protection domains shared within the system and the functions allowed for external access, and clarify the isolation boundaries between the inside and outside of the system; Step 3: According to the variables and functions marked in Step 1 and the configuration file in Step 2, automatically calculate the variable permissions and perform placeholder conversion, determine the permission levels of the variables and the functions for cross-domain execution, and implement automatic permission allocation and isolation settings; Step 4: At the system initialization startup stage, according to the variable permissions determined in Step 3, allocate the variables to the corresponding memory spaces, implement isolation within the system, and provide a secure remote service interface for external access; Step 5: When an external caller initiates a remote access through VMFUNC, through permission checking and the division of the access stack, ensure that external access can only access the variables isolated between systems, and at the same time ensure the memory access security of the callee, implementing isolation outside the system.
2. The method for internal-external isolation in an automated library operating system according to claim 1, wherein In the said Step 1, the specific method for analyzing the system micro-library includes: Count all the defined functions in the micro-library, and scan the function implementation of each function. If the function called in the function implementation is not defined in this micro-library, mark this function as a potentially cross-domain function; Use the Coccinelle tool to identify all the global variables called by cross-domain functions and the variables allocated through functions related to malloc, and mark them as potentially cross-domain variables.
3. The automated library operating system internal-external isolation method according to claim 1, wherein In the said Step 2, the specific method for initializing the micro-library composition of the library operating system based on the configuration file includes: The user declares multiple protection domains in the configuration file, and each protection domain is isolated using MPK; Place the libraries that trust each other in the same protection domain, and place the libraries that do not trust each other in different protection domains; Declare in the configuration file the functions allowed for external VMFUNC access and the system micro-library where they are located.
4. The automated library operating system internal-external isolation method according to claim 1, wherein, In the said Step 3, the specific method for automatically calculating variable permissions and performing placeholder conversion includes: Scan all the composed micro-libraries in the configuration file, and remove the functions defined in the same protection domain from the set of potentially cross-domain functions; Use the Coccinelle tool to find the variables in the set of potentially shared variables associated with the set of potentially cross-domain functions, and record them as the set of shared variables within the library operating system; Based on the results of the LLVM IR, perform function call graph analysis, and perform breadth-first search with the functions allowed for VMFUNC access as the root nodes to determine the set of shared variables between library operating systems; For the common variables in the set of shared variables within the library operating system and the set of shared variables between library operating systems, remove them from both sets and save them as a separate set of shared variables.
5. The method for internal-external isolation of an automated library operating system according to claim 1, characterized in that, In the said Step 4, the specific method for allocating the permissions of the corresponding variables to the corresponding memory spaces according to the variable permissions determined by the result of placeholder conversion includes: During the startup phase, the system assigns separate memory space addresses for each protection domain and for shared variables within the system and between systems; The allocation of all global variables and heap variables is carried out at the corresponding addresses; Protection domains 0 to 11 are reserved for private domains to store data, domain 12 is reserved as a buffer area for VMFUNC access, and domains 13 to 15 are respectively used to store different sets of shared variables.
6. The automated library operating system internal-external isolation method according to claim 5, characterized in that, In step 5, the specific method for an external caller to initiate a remote access through VMFUNC includes: Allocate a buffer on the shared memory of the caller and callee's host machines for passing in the function name and corresponding parameters of the access; The caller saves the register state, initiates a VMFUNC access jump to the callee's EPT, and enters domain 12 reserved for VMFUNC access; The callee parses the access function name and parameters from the buffer, calls the dynamic gate, obtains the protection domain id where the target function is located based on the library where the target function is located, switches from domain 12 to the corresponding domain id, and at the same time provides a separate thread id to achieve secure cross-domain access for the external caller; Save the execution result to the buffer, restore the register state saved in the caller, switch back to the caller's EPT through VMFUNC, copy the execution result from the buffer, and release the buffer in the shared memory.
7. The automated library operating system internal-external isolation method according to claim 2, characterized in that In step 1, when analyzing the system micro-library, static analysis of the program is carried out based on LLVM IR to determine potential cross-domain functions and variables.
8. The automated library operating system internal-external isolation method according to claim 6, characterized in that In step 5, through permission check constraints, it is ensured that external access can only access the variables isolated between corresponding systems. At the same time, a separate access stack is divided to ensure the memory access security of the callee.
9. An in-out isolation device for an automated library operating system, comprising a memory and one or more processors, wherein executable code is stored in the memory, and is characterized in that, When the one or more processors execute the executable code, it is used to implement the in-out isolation method of the automated library operating system according to any one of claims 1-8.
10. A computer-readable storage medium having a program stored thereon, characterized in that, When the program is executed by the processor, it is used to implement the in-out isolation method of the automated library operating system according to any one of claims 1-8.