RISC-V processor-oriented practical confidential virtual machine architecture implementation method and equipment
By introducing a security monitor and time-division multiplexing CPU mode on the RISC-V processor, combined with trap delegation control and three-level memory management, the hardware compatibility, flexibility and scalability issues of the confidential virtual machine architecture on the RISC-V platform are solved, and a secure and efficient confidential virtual machine architecture is realized, which is suitable for high-performance cloud computing environments.
Patent Information
- Application Number
- CN202510821596.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-10-14
AI Technical Summary
The existing RISC-V platform lacks a secure, efficient and flexible confidential virtual machine architecture, cannot run on commercial processors, and has problems with insufficient hardware compatibility, flexibility and scalability.
A practical confidential virtual machine architecture for RISC-V processors is designed. Physical memory protection is configured through a security monitor to implement time-division multiplexing CPU mode. Trap delegation control and three-level hierarchical memory management are adopted, combined with a separate memory sharing mechanism to ensure security and flexibility.
A secure, efficient, flexible and scalable confidential virtual machine architecture is implemented on commercial RISC-V processors, supporting large-scale concurrent virtual machine deployment, reducing context switching overhead, and improving data privacy and security.
Smart Images

Figure CN120780404A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer security, and particularly relates to a confidential virtual machine (CVM) technology based on a RISC-V processor, aiming to improve the data confidentiality and integrity of a virtual machine in an untrusted environment, and being suitable for a cloud computing platform. BACKGROUND
[0002] With the increase of data leakage and privacy infringement events, trusted execution environment (TEE) technology has become increasingly important due to its powerful hardware isolation features. In TEE technology, a confidential virtual machine (CVM) takes a virtual machine as an execution abstraction, providing higher compatibility and practicality compared to process-based TEE technology (such as Intel SGX) [1].
[0003] Currently, mainstream chip manufacturers have proposed their own confidential virtual machine architectures, such as AMD SEV [2], Intel TDX [3], and ARM CCA [4]. Similarly, major cloud service providers such as Amazon AWS, Microsoft Azure, and Google Cloud have also integrated confidential virtual machines to provide secure and privacy-focused services for tenants with confidential workloads.
[0004] With the expansion of RISC-V in various computing fields, confidential virtual machines on RISC-V have also received increasing attention and adoption. RISC-V initially established its presence in low-performance Internet of Things (IoT) devices, taking advantage of its open-source architecture and flexibility to support a wide range of applications. However, RISC-V is now moving beyond its traditional focus, making significant progress in high-performance cloud computing environments that require powerful, secure, and efficient solutions. This evolution has driven the growing demand for confidential virtual machine technology, as data privacy and secure computing are being prioritized in these high-performance computing environments.
[0005] However, there is still a lack of practical confidential virtual machine architecture on current RISC-V platforms. Prominent RISC-V TEE architectures such as Sanctum [5], Keystone [6], and Penglai [7] all use process-level abstraction, requiring modification of user applications to be compatible with their TEEs. In contrast, confidential virtual machine architectures designed for RISC-V platforms face hardware compatibility issues. For example, CURE [8] and VirTEE [9] provide VM enclaves capable of running confidential virtual machines, but they rely on custom hardware and cannot run on commercial RISC-V processors. Another confidential virtual machine extension (CoVE) proposed by the RISC-V TEE task group (AP-TEE TG)
[10] is still under development. Considering the long time delay from design to actual adoption of hardware security primitives, the availability of CoVE in the near future is still uncertain.
[0006] In addition to hardware compatibility, current confidential virtual machine architectures on RISC-V platforms also lack flexibility and scalability. In terms of flexibility, CURE and VirTEE implement region-based memory isolation, requiring the physical addresses of memory isolation regions to be contiguous. This design makes it difficult to meet the flexible memory isolation needs of confidential virtual machines, making dynamic expansion difficult and leading to significant memory fragmentation. In terms of scalability, due to the resource limitations of security primitives extended by custom hardware, CURE and VirTEE can only support 13 concurrent VM enclaves, making it difficult to meet the large-scale concurrency needs of cloud platforms.
[0007] Therefore, the present application aims to solve the following problem: Can a secure, efficient, and flexible confidential virtual machine architecture be designed to run on commercial RISC-V processors?
[0008] Related literature: [1] V. Costan and S. Devadas, “Intel sgx explained,” CryptologyePrint Archive, 2016. [2] A. Sev-Snp, “Strengthening vm isolation with integrity protectionand more,” White Paper, January, vol. 53, pp. 1450–1465, 2020. [3] Intel Corporation, “Intel Trust Domain Extensions (intel TDX) whitepaper,” 2024, accessed: 2024-11-20. [Online]. Available: https: / / www.intel.com / content / dam / develop / external / us / en / documents / tdx-whitepaper-final9-17.pdf [4] X. Li, X. Li, C. Dall, R. Gu, J. Nieh, Y. Sait, and G. Stockwell, “Design and verification of the arm confidential compute architecture,” in 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22), 2022, pp. 465–484. [5] V. Costan, I. Lebedev, and S. Devadas, “Sanctum: Minimal hardware extensions for strong software isolation,” in 25th USENIX Security Symposium (USENIX Security 16), 2016, pp. 857–874. [6] D. Lee, D. Kohlbrenner, S. Shinde, K. Asanovi ́c, and D. Song, “Keystone: An open framework for architecting trusted execution environments,” in Proceedings of the Fifteenth European Conference on Computer Systems, 2020, pp. 1–16. [7] E. Feng, X. Lu, D. Du, B. Yang, X. Jiang, Y. Xia, B. Zang, and H. Chen, “Scalable memory protection in the penglai enclave,” in 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI 21), 2021, pp. 275-294. [8] R. Bahmani, F. Brasser, G. Dessouky, P. Jauernig, M. Klimmek, A.-R. Sadeghi, and E. Stapf, “Cure: A security architecture with customizable and resilient enclaves,” in 30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 1073-1090. [9] J. Wang, P. Mahmoody, F. Brasser, P. Jauernig, A.-R. Sadeghi, D. Yu, D. Pan, and Y. Zhang, “Virtee: A full backward-compatible tee with native live migration and secure i / o,” in Proceedings of the 59th ACM / IEEE Design Automation Conference, 2022, pp. 241-246.
[10] R. Sahita, V. Shanbhogue, A. Bresticker, A. Khare, A. Patra, S. Ortiz, D. Reid, and R. Kanwal, “Cove: Towards confidential computing on risc-v platforms,” in Proceedings of the 20th ACM International Conference on Computing Frontiers, 2023, pp. 315–321. SUMMARY The present application aims to solve the technical problem of how to build a secure, efficient, flexible and scalable confidential virtual machine architecture on existing commercial RISC-V processors without relying on additional hardware security extensions.
[0009] The technical solution of the present application provides a practical confidential virtual machine architecture implementation method for RISC-V processors, including the following processes: A secure monitor running in machine mode is configured to protect physical memory, isolate and establish a secure memory pool in normal memory; The CPU is divided into normal mode and confidential virtual machine mode by time division multiplexing; A short-path confidential virtual machine mode is implemented based on trap delegation control, which only requires one privilege level switch to complete mode conversion; A secure vCPU structure is created in the secure memory to store the confidential virtual machine register state, and a shared vCPU structure is established in the Hypervisor to quickly exchange state information with the secure monitor; A three-level hierarchical memory management structure is constructed, the first level directly allocates memory pages through vCPU page cache, the second level allocates secure memory blocks through a bidirectional circular linked list, and the third level extends the secure memory pool through the Hypervisor; A separate memory sharing mechanism is implemented, which divides the confidential virtual machine's guest physical address space into private address space and shared address space, and the private address space page table is managed independently by the secure monitor, while the shared address space page table is managed by the Hypervisor and the secure monitor in coordination.
[0010] Moreover, the secure monitor dynamically adjusts the PMP configuration register permissions when performing mode switching, ensuring that the Hypervisor cannot access the secure memory pool in normal mode.
[0011] Further, a load-first-check-later mechanism is established for vCPU state protection and update, after loading the register state from the shared vCPU structure, the SM performs integrity check on the register value to defend against TOCTOU attacks.
[0012] Further, in the three-level hierarchical memory management structure, the secure memory blocks are managed by a bidirectional circular linked list, and when the vCPU page cache is exhausted, a new secure memory block is allocated from the head of the linked list and associated with the vCPU.
[0013] Further, the split memory sharing mechanism specifically includes the following settings, The mapping of the private address space is configured and protected by the security monitor in the secure memory pool, and is mapped to the secure memory region; The mapping of the shared address space is jointly managed by the Hypervisor and the SM, and is only mapped to the normal memory region; The security monitor performs security check on the shared memory mapping request submitted by the Hypervisor, and prohibits it from pointing to the secure memory.
[0014] Further, an I / O physical memory protection mechanism is also configured to prevent malicious devices from attacking the secure memory region through direct memory access.
[0015] Further, the short-path confidential virtual machine mode is implemented through trap delegation control, and interrupt and exception events that can be handled by the confidential virtual machine are delegated to the VS mode kernel of the confidential virtual machine for processing, and interrupt and exception events that cannot be handled are directly taken over and processed by the security monitor.
[0016] On the other hand, the present application also provides an electronic device comprising a memory, a processor and a computer program stored on the memory and executable on the processor, wherein the processor implements the above-mentioned RISC-V processor-oriented utility confidential virtual machine architecture implementation method when executing the program.
[0017] On the other hand, the present application also provides a non-transitory computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the above-mentioned RISC-V processor-oriented utility confidential virtual machine architecture implementation method.
[0018] On the other hand, the present application also provides a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the above-mentioned RISC-V processor-oriented utility confidential virtual machine architecture implementation method.
[0019] The present application proposes a practical confidential virtual machine architecture for commercial RISC-V processors, which can be implemented without additional hardware security extensions. The architecture introduces a security monitor (SM) to divide the CPU into normal mode and confidential virtual machine mode through time division multiplexing, and adopts a short path design based on trap delegation control, which only needs one privilege level switching to complete mode conversion. The present application protects the virtual CPU state by combining the mechanisms of secure vCPU and shared vCPU, and realizes flexible and scalable memory isolation through the combination of physical memory protection (PMP) and paging technology, overcoming the limitation of the number of traditional PMP entries. In addition, the present application adopts a three-level hierarchical memory management structure and a separate memory sharing mechanism to ensure efficient memory management and flexible sharing. The evaluation results show that the architecture can effectively guarantee the security, flexibility and scalability of the confidential virtual machine, and provides a solid security guarantee for RISC-V platforms in high-performance cloud computing environments.
[0020] Compared with the prior art, the present application is innovative in terms of hardware compatibility (no additional hardware security extensions), security (centralized management of security resources by security monitor), flexibility (support for non-contiguous physical memory allocation), scalability (support for large-scale concurrent confidential virtual machine deployment), and efficiency (reduction of context switching and memory management overhead). BRIEF DESCRIPTION OF DRAWINGS
[0021] Figure 1 is the system design architecture diagram of the embodiment of the present application.
[0022] Figure 2 is the hierarchical confidential virtual machine memory management scheme of the embodiment of the present application. DETAILED DESCRIPTION
[0023] The technical solutions of the present application will be described in detail below in combination with the drawings and embodiments.
[0024] Embodiment one The embodiment provides a practical confidential virtual machine architecture implementation method for a RISC-V processor, and realizes the confidential virtual machine architecture based on a commercial RISC-V processor, including: a security monitor (SM) running in a machine mode (M Mode) and used for managing the life cycle and resources of the confidential virtual machine; an isolated execution mode realized through time division multiplexing, including a normal mode (Normal Mode) and a confidential virtual machine mode (CVM Mode); a short-path confidential virtual machine mode based on trap delegation control, reducing the privilege level switching overhead; a vCPU state protection and update mechanism combined with a secure vCPU and a shared vCPU; a flexible and expandable memory isolation scheme combined with a physical memory protection (PMP) and a paging mechanism; a three-level hierarchical memory management structure, including a vCPU page cache, a secure memory block linked list and an extended secure memory pool; and a separated memory sharing mechanism, which divides the address space of the confidential virtual machine into a private and a shared area.
[0025] The security monitor (SM) configures a physical memory protection (PMP) to establish a secure memory pool in a normal memory, and dynamically adjusts a PMP configuration register permission when an execution mode is switched, so that the Hypervisor cannot access the secure memory pool in the normal mode (Normal Mode).
[0026] As Figure 1As shown, the present application provides a confidential virtual machine system architecture based on RISC-V architecture, which is divided into five main levels: physical hardware layer (HW), machine mode layer (M), management supervision mode layer (HS), virtual supervision mode layer (VS) and virtual user mode layer (VU), and contains a non-virtualized user mode layer (U), the whole system supports two running modes of normal mode and confidential virtual machine mode, and the trusted switching and resource isolation control between the two modes are realized through the security monitor running in the highest privilege level M mode. In the physical hardware layer (HW), the system relies on security mechanisms such as PMP (physical memory protection), IOPMP (I / O physical memory protection) and Root of Trust (Root of Trust) to realize strong isolation and access control of computing resources and I / O devices, while providing hardware virtualization support for multi-level page table conversion and guest context management. In the machine mode layer (M), the security monitor is run as the smallest trusted computing base of the system, which has the ability of unified management and isolation of confidential virtual machines, including: confidential virtual machine mode switching, confidential virtual machine trap processing, confidential virtual machine memory isolation and management, and confidential virtual machine lifecycle management and other function modules. The security monitor provides the start, suspension, destruction and other control capabilities of the confidential virtual machine to the upper layer Hypervisor through the ECALL interface, while supporting the provision of measurement reports, platform random numbers and other services to the confidential virtual machine, enhancing the verifiability and confidentiality of the platform. In the management supervision mode layer (HS), the traditional host operating system kernel is run, containing vCPU scheduler, KVM virtualization subsystem, device driver and file system module, which is mainly responsible for scheduling and managing virtual machine running resources, but cannot access the internal state of the confidential virtual machine. The U mode layer runs user-mode emulator programs such as QEMU to provide virtual peripheral support for virtual machines. In the virtualization mode, the confidential virtual machine runs in VS (virtual supervision mode) and VU (virtual user mode), the virtual machine kernel is in VS mode, and the confidential application is in VU mode, each confidential virtual machine instance (such as confidential virtual machine 1 and confidential virtual machine 2 in the figure) is created and isolated by the security monitor, and the underlying hardware security primitives are used to ensure the invisibility and tamper resistance of its vCPU and memory; relatively, the ordinary virtual machine runs in the same virtualization environment, but does not have the same level of security isolation protection. The above system architecture realizes soft and hard collaborative confidential virtualization on a trusted hardware foundation, has the advantages of strong controllability, strong isolation and flexible deployment, and is especially suitable for cloud multi-tenant, data privacy protection and high-security computing scenarios. The architecture uses existing RISC-V hardware security primitives such as physical memory protection PMP, trap delegation mechanism and virtualization extensions to build a confidential virtual machine environment. The specific implementation scheme is as follows: In order to support the running of confidential virtual machines, the present application divides the running mode into normal mode and confidential virtual machine mode. The state switching between the two modes is realized through the security monitor.
[0027] Normal mode is responsible for running non-trusted parts, including hypervisor, upper applications and normal virtual machines. Hypervisor runs in HS mode, including vCPU scheduler, device driver, file system and KVM, etc. At the same time, QEMU, a hardware virtualization platform, runs in U mode to provide simulation device support for confidential virtual machines.
[0028] Confidential virtual machine mode is used to run confidential virtual machines and is in virtualization mode. The kernel of the confidential virtual machine runs in VS mode, and the confidential application runs in VU mode. The implementation and protection of the confidential virtual machine mode depend on the security monitor, which runs in the highest privilege level M mode as the trusted computing base of the system. The security monitor constructs the confidential virtual machine mode through the security primitives (such as PMP, IOPMP, trap delegation, etc.) provided by the underlying hardware, and ensures that the vCPU and memory of the confidential virtual machine are securely isolated and protected. In addition, the security monitor is also responsible for the memory management of the confidential virtual machine mode, including the allocation, recycling and sharing of secure memory.
[0029] To support the cooperation between the normal mode and the confidential virtual machine mode, the security monitor provides different ECALL interfaces (environment call interface). The hypervisor in the normal mode controls the life cycle of the confidential virtual machine through these interfaces, such as initialization, running and pausing operations. At the same time, the confidential virtual machine in the confidential virtual machine mode can obtain its measurement report and platform random number functions through the ECALL interface, further enhancing the security and reliability of the system.
[0030] Embodiment two On the basis of the implementation method of the practical confidential virtual machine architecture for the RISC-V processor provided in embodiment one, a short-path confidential virtual machine mode scheme is further proposed, and the implementation manner is as follows: Through the design based on the virtual security processor, the CPU is divided into normal mode and protected confidential virtual machine mode through time-sharing multiplexing. Unlike existing schemes, the present application concentrates the execution state switching and security management into the security monitor (SM), and only one security monitor privilege level switching is required to realize the switching between the confidential virtual machine mode and the normal mode, thereby reducing the overhead of twice privilege level conversion in the traditional architecture.
[0031] In order to avoid the security risks (such as sensitive register state leakage) caused by the lack of a secure hypervisor, the present application introduces a trap delegation control mechanism to transfer the processing right of the related trap to the security monitor. The specific criteria are as follows: For the trap that can be processed by the confidential virtual machine, it is proxied to the VS mode and processed by the kernel of the confidential virtual machine. For unprocessable traps, ensure that the execution flow directly enters the security monitor, which is responsible for processing.
[0032] The trap represents the interrupt and exception of the RISC-V platform. The interrupt that the confidential virtual machine can process includes the virtual manager software interrupt, the virtual manager time interrupt and the virtual manager external interrupt. The exception that the confidential virtual machine can process includes the page error exception, the VU mode user call exception, the breakpoint exception, the illegal instruction exception, etc.
[0033] Through this design, the application not only improves the context switching efficiency, but also ensures the security of the confidential virtual machine.
[0034] Embodiment three On the basis of the implementation method of the utility confidential virtual machine architecture for the RISC-V processor provided in embodiment one, in order to accelerate the state transmission between the confidential virtual machine vCPU state and the Hypervisor, a vCPU state protection and update mechanism combining a secure vCPU and a shared vCPU is further provided: a secure vCPU structure allocated in the secure memory managed by the SM is used to store the register state of the confidential virtual machine; a shared vCPU structure established in the Hypervisor is used to quickly exchange state information between the SM and the Hypervisor; and a load-after-check mechanism is used to defend against the TOCTOU attack of the attacker.
[0035] The vCPU state protection and update mechanism is specifically described as follows: Security: the application allocates memory space in the security monitor to construct a secure vCPU structure, ensuring the security of the general register and control register state of the confidential virtual machine vCPU; Efficiency: a shared vCPU structure is established on the Hypervisor to quickly exchange the vCPU state between the Hypervisor and the security monitor.
[0036] When switching between the confidential virtual machine mode and the normal mode, the security monitor stores the register state in the secure vCPU or the shared vCPU according to the exception or interrupt type. For example, when the confidential virtual machine exits due to the load instruction, the security monitor stores the Trap related register state in the shared vCPU, so as to facilitate the Hypervisor to analyze and obtain the target register value; and other registers are stored in the secure vCPU to ensure state isolation and protection.
[0037] To prevent TOCTOU attacks (attacks exploiting the time difference between system security checks and resource usage), the present application will perform security checks on the register values of the shared vCPU state after loading it, thereby ensuring that it is not tampered with by a malicious Hypervisor.
[0038] Embodiment Four On the basis of the RISC-V processor-oriented practical confidential virtual machine architecture implementation method provided in Embodiment One, a flexible and scalable memory isolation technical solution combining PMP and paging mechanism is further proposed.
[0039] The present application adopts a memory isolation solution combining PMP and paging, solving the problems of flexibility and scalability of memory isolation. The security monitor configures PMP to establish a secure memory pool, and dynamically adjusts access permissions during mode switching. The memory isolation between confidential virtual machines is realized through a two-level page table, and IOPMP is used to defend against DMA attacks, thereby ensuring the security of the memory. The specific implementation is as follows: PMP isolation: memory isolation between confidential virtual machine mode and normal mode is realized through PMP primitives. The security monitor divides a region in the Normal memory (normal memory) into a secure memory pool of the confidential virtual machine by configuring PMP, ensuring that the confidential virtual machine is protected when accessing the secure memory.
[0040] Paging isolation: memory isolation between confidential virtual machines is ensured through a Stage-2 page table. The security monitor allocates mapped memory for the confidential virtual machine, ensuring that its memory is not shared with other confidential virtual machines. At the same time, the security monitor manages the page table of the confidential virtual machine to prevent interference by the Hypervisor. The Stage-2 page table is a second-stage page table.
[0041] In addition, to prevent DMA attacks initiated by malicious devices, the present application uses IOPMP to protect the memory pool and control device access, i.e., sets up an IOPMP protection mechanism to prevent malicious devices from attacking the secure memory area through direct memory access (DMA). At the same time, the security monitor configures a dedicated page table for the confidential virtual machine, avoiding tampering with the page table of the confidential virtual machine by the Hypervisor. In specific implementation, the security monitor can configure the page table of the confidential virtual machine in the secure memory pool to prevent page table attacks by untrusted Hypervisors.
[0042] Embodiment Five On the basis of the RISC-V processor-oriented practical confidential virtual machine architecture implementation method provided in Embodiment One, a hierarchical confidential virtual machine memory management solution is further proposed, which uses a bidirectional circular linked list to manage secure memory blocks.
[0043] The application provides a multi-level secure memory management method and system for a confidential virtual machine (CVM), aiming to improve memory allocation efficiency, guarantee memory security, and support on-demand dynamic expansion. In the scheme, a virtual CPU (vCPU) of the confidential virtual machine serves as a driving core of memory demand, and gradually acquires required secure memory resources through a three-stage allocation strategy. The secure memory resource division structure is divided into multiple levels, as shown in Figure 2
[0044] Secure memory structure initialization: After a privileged software (such as a Hypervisor) registers part of a physical memory region as secure memory, a security monitor (Security Monitor) is responsible for dividing the region into a plurality of secure memory blocks according to a preset size (such as 2MB) and organizing the secure memory blocks into a double-linked list structure, so as to realize efficient memory block allocation. The secure memory blocks can be further subdivided into a plurality of memory pages of a fixed size, for page allocation by an upper layer. To realize dynamic adjustment, the application allows the secure memory pool to be dynamically expanded from normal memory when necessary, to cope with memory pressure.
[0045] The memory allocation process is divided into the following three stages: First-stage allocation: page cache allocation In a normal memory usage scenario, memory pages are preferentially allocated from a page cache (Page Cache) bound to a vCPU of the confidential virtual machine. When a page fault occurs, an unallocated memory page is directly taken from the page cache of the vCPU and returned. This stage has the lowest latency and completely avoids the performance overhead generated by interaction with the Hypervisor.
[0046] If the memory pages in the page cache are exhausted, second-stage allocation is triggered.
[0047] Second-stage allocation: secure block allocation If the page cache is insufficient to support the current page fault request, the security monitor allocates a new secure memory block from the head of the double-linked list and hangs the secure memory block in the page cache structure of the vCPU that triggered the page fault, thereby expanding the local cache capacity. This operation is still completed under the control of the security monitor, avoiding entering the normal privileged state.
[0048] If the secure block allocation is also exhausted, third-stage allocation is entered.
[0049] Third-stage allocation: dynamic expansion When the system detects that the secure memory pool resource is about to be exhausted, the security monitor initiates a dynamic expansion request through the interface with the Hypervisor to allocate a part of the physical memory from the system normal memory, convert it into a new secure memory block, and append it to the tail of the secure memory pool linked list to realize on-demand expansion.
[0050] Through the three-stage allocation process and the linked list organization mechanism proposed in the application, the memory allocation operation has constant complexity O(1), and the combination of vCPU local cache significantly reduces the page fault delay and context switching overhead, ensuring high-performance operation in the confidential computing scenario. In addition, through the dynamic expansion capability of the secure memory pool, the elastic deployment and operation of multiple instances of CVM are effectively supported, improving the utilization rate and maintainability of the overall resources.
[0051] In specific implementation, after introducing the hierarchical memory management structure, a three-level allocation strategy including vCPU page cache, secure memory block and extended secure memory pool is formed. After the privileged user registers the continuous physical memory to the security monitor, the security monitor divides the memory segment into secure memory blocks (preferably with a recommended default size of 256KB) and manages them through a double-linked list, thereby realizing efficient memory allocation. In this design, after the privileged user registers the physical memory as a secure memory to the security monitor, the security monitor divides the memory into multiple secure memory blocks according to the preset size, forms a double-linked list, and allocates the secure memory blocks in the linked list from the head of the list first.
[0052] Embodiment six On the basis of the implementation method of the utility confidential virtual machine architecture for the RISC-V processor provided in Embodiment One, a separate memory sharing mechanism is further proposed. Unlike the traditional mixed management of private and shared address spaces, the entire address space of the confidential virtual machine is statically divided into two parts according to the highest address bit: the high address space is the shared address space, and the low address space is the private address space. The size of the shared memory area is configured when the confidential virtual machine starts, and the two parts do not overlap in the address space and cannot be dynamically switched. Based on this division, independent management mechanisms are designed for the private and shared address spaces.
[0053] Specifically, the scheme establishes a secure page table for the private address space, which is maintained by the SM, ensures that all mappings point to secure memory regions, and uses the large page mechanism to improve performance. For the shared address space, the Hypervisor maintains a shared page table to realize the mapping of normal memory. When the confidential virtual machine accesses shared memory and a page fault occurs, the SM determines that it is shared memory through the highest address bit and forwards the page fault information to the Hypervisor, which allocates normal memory and registers the mapping information to the SM. Before the confidential virtual machine runs, the SM checks the mapping information passed by the Hypervisor to prevent malicious mapping of shared memory to secure memory. After the check passes, the SM establishes the corresponding mapping. It is worth noting that the scheme uses page granularity management for shared memory to ensure flexibility in allocation and prohibit the execution permission of shared memory to prevent potential malicious code execution.
[0054] The embodiment is specifically designed as follows: The system divides the GPA address space of the CVM into a private region (highest bit = 0) and a shared region (highest bit = 1) according to the highest bit: Private address space: The private address space mapping of the confidential virtual machine is maintained by the security monitor to ensure the security of its memory. Shared address space: The shared address space mapping of the confidential virtual machine is maintained by the Hypervisor and the SM, where the Hypervisor is responsible for page allocation, and the SM is responsible for security check and page table establishment, which together realize the memory sharing between the CVM and the Hypervisor.
[0055] Wherein, CVM represents the confidential virtual machine, and GPA represents the guest physical address.
[0056] In this design, by separating the private and shared address spaces and configuring independent management mechanisms for them, the flexibility and efficiency of shared memory allocation are significantly improved while ensuring the security of the private memory of the confidential virtual machine.
[0057] In specific implementation, the method proposed by the technical scheme of the present application can be automatically run by a person skilled in the art using computer software technology, and the system device of the method, such as a computer readable storage medium storing the corresponding computer program of the technical scheme of the present application and a computer device including the running of the corresponding computer program, should also be within the protection scope of the present application.
[0058] The following embodiment describes the electronic device provided by the present application, and the electronic device described below can be correspondingly referred to the RISC-V processor-oriented practical confidential virtual machine architecture implementation method described above.
[0059] The electronic device can include a processor, a communications interface, a memory, and a communications bus, wherein the processor, the communications interface, and the memory complete mutual communication through the communications bus. The processor can invoke a logical instruction in the memory to execute the utility secret virtual machine architecture implementation method for the RISC-V processor, mainly including the software processing part in the above steps.
[0060] In addition, the logical instruction in the memory described above can be realized in the form of a software functional unit and sold or used as an independent product, and can be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, includes several instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0061] On the other hand, the embodiment of the present application also provides a computer program product, the computer program product includes a computer program, the computer program can be stored on a non-transitory computer readable storage medium, when the computer program is executed by a processor, the computer can execute the software processing part in the utility secret virtual machine architecture implementation method for the RISC-V processor provided by the above-mentioned method.
[0062] In another aspect, the embodiment of the present application also provides a non-transitory computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the software processing part in the utility secret virtual machine architecture implementation method for the RISC-V processor provided by the above-mentioned method.
[0063] The device embodiments described above are only schematic, wherein the units described as separate components can or can not be physically separated, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0064] Those skilled in the art can clearly understand the technical solutions of the various embodiments from the above description of the embodiments, and the various embodiments can be implemented by means of software with the necessary general hardware platforms, and of course, can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that makes a contribution, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0065] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, rather than limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for some technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A practical confidential virtual machine architecture implementation method for RISC-V processor, characterized in that: The following processes are included: Configure physical memory protection through a security monitor running in machine mode, isolating and establishing a secure memory pool in normal memory; The CPU is divided into normal mode and confidential virtual machine mode through time division multiplexing; Implementing short-path confidential virtual machine mode based on trapping delegation control, requiring only one privilege level switch to complete the mode transition; Create a secure vCPU structure in secure memory to store confidential virtual machine register states, and establish a shared vCPU structure in the hypervisor for quickly exchanging state information with the security monitor; A three-level hierarchical memory management structure is built. The first level directly allocates memory pages through the vCPU page cache, the second level allocates secure memory blocks through a bidirectional circular linked list, and the third level expands the secure memory pool through the hypervisor. A separate memory sharing mechanism is implemented to divide the client physical address space of the confidential virtual machine into private address space and shared address space. The private address space page table is managed independently by the security monitor, while the shared address space page table is managed collaboratively by the hypervisor and the security monitor.
2. The method for implementing a practical confidential virtual machine architecture for a RISC-V processor according to claim 1, characterized in that: The security monitor dynamically adjusts the PMP configuration register permissions when performing mode switching to ensure that the hypervisor cannot access the secure memory pool in normal mode.
3. The method for implementing a practical confidential virtual machine architecture for a RISC-V processor according to claim 1, characterized in that: A load-first-then-check mechanism is established for vCPU state protection and update. After loading the register state from the shared vCPU structure, the SM performs integrity check on the register value to defend against TOCTOU attacks.
4. The method for implementing a practical confidential virtual machine architecture for a RISC-V processor according to claim 1, characterized in that: In the three-level hierarchical memory management structure, secure memory blocks are managed through a bidirectional circular linked list. When the vCPU page cache is exhausted, a new secure memory block is allocated from the head of the linked list and associated with the vCPU.
5. The method for implementing a practical confidential virtual machine architecture for a RISC-V processor according to claim 1, characterized in that: The separate memory sharing mechanism specifically includes the following settings: The mapping of the private address space is configured and protected by the security monitor in the secure memory pool and mapped to the secure memory area; The mapping of the shared address space is managed jointly by the Hypervisor and the SM and is only mapped to the normal memory area; The security monitor performs security checks on shared memory mapping requests submitted by the hypervisor and prohibits them from pointing to secure memory.
6. The method for implementing a practical confidential virtual machine architecture for a RISC-V processor according to claim 1, characterized in that: It also includes configuring I / O physical memory protection mechanisms to prevent malicious peripherals from attacking secure memory areas through direct memory access.
7. The method for implementing a practical confidential virtual machine architecture for a RISC-V processor according to claim 1, characterized in that: The short-path confidential virtual machine mode is implemented by trapping into delegation control. Interrupts and exceptions that can be handled by the confidential virtual machine are delegated to its VS mode kernel for processing, while interrupts and exceptions that cannot be handled are directly taken over and processed by the security monitor.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, it implements the practical confidential virtual machine architecture implementation method for the RISC-V processor as described in any one of claims 1 to 7.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the practical confidential virtual machine architecture implementation method for a RISC-V processor as described in any one of claims 1 to 7.
10. A computer program product comprising a computer program, characterized in that: When the computer program is executed by a processor, it implements the practical confidential virtual machine architecture implementation method for a RISC-V processor as described in any one of claims 1 to 7.