Hypercall-based virtual trusted root construction method and device, medium and product
By establishing a super-call communication channel between the virtual machine and the host machine, and using the VMM for trust chain transmission and legitimacy verification, the security problem of trust chain transmission in the virtualization environment is solved, and efficient and secure trusted computing is achieved.
Patent Information
- Application Number
- CN202510985553.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-11-18
AI Technical Summary
In virtualized environments, existing technologies struggle to securely transfer trust chains, particularly regarding client-side security.
By establishing a communication channel based on supercall between the virtual machine and the host machine, using VMM for mapping transformation and trust chain transmission, and combining trusted root access authorization control unit and legitimacy verification, secure access of the virtual machine to the TPCM module is achieved.
It enables efficient and secure trust chain transmission in virtualized environments, ensuring the trusted computing needs of virtual machines and avoiding the problems of low performance and insufficient security in traditional methods.
Smart Images

Figure CN120973467A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, specifically to a method, device, medium, and product for constructing a virtual root of trust based on supercall. Background Technology
[0002] With the large-scale deployment and application of cloud services, virtualization technology is becoming increasingly widespread, and its security is receiving increasing attention, particularly the security of guest virtual machines (GVMs). Since GVMs can be accessed via remote desktop connections, they are highly vulnerable to external attacks if left unprotected. Current security measures for GVMs include traditional antivirus software, firewalls, and host monitoring. However, these passive security measures are insufficient to address the ever-emerging vulnerabilities and attack methods. Building a proactive, immune-based security system based on trusted computing technology is an effective way to solve virtual machine security problems.
[0003] In related technologies, virtual machines in virtualized environments cannot directly access the host machine's root of trust (TPCM), which prevents the trust chain from being transmitted to the virtual machine, posing a security risk. Existing solutions, such as those using socket client / server architecture to build virtual roots of trust, suffer from low performance and insufficient security. Summary of the Invention
[0004] In view of the above problems, this application provides a method, device, medium and product for constructing a virtual root of trust based on supercall, which solves the problem that traditional methods are difficult to achieve in terms of the security of trust chain transmission under virtual platforms.
[0005] In a first aspect, embodiments of this application provide a method for constructing a virtual trusted root based on a supercall, applied to a virtualization platform, the virtualization platform including a virtual machine and a host machine, the method comprising: Based on the virtual machine, the address corresponding to the shared memory containing the trusted service request is written into the CPU register in the host machine; The virtual machine triggers a trap event in the VMM of the host machine via a hypercall instruction to establish communication between the host machine and the virtual machine; The VMM in the host machine performs mapping and translation through the virtual address of the shared memory to obtain the physical address of the shared memory; The physical address is parsed to determine the input request data transmitted by the virtual machine, and forwarded to the TPCM module in the host machine for processing to obtain the processing result data; The processing result data is written back to the shared memory based on the VMM.
[0006] In some embodiments, the method for constructing a virtual root of trust based on a supercall further includes: Based on the VMM, obtain the code segment triggered by the super call instruction; Perform a hash calculation on the code segment and compare it with the expected value of pre-stored legitimate driver code; If the comparison fails, the super call instruction is ignored and a security log alarm message is generated.
[0007] In some embodiments, a virtual transport channel and a virtual software stack are built inside the virtual machine. A method for building a virtual root of trust based on supercall also includes: Encapsulate trusted service requests based on the virtual software stack and the virtual transmission channel; The encapsulated trusted service request is passed to the VMM via the super call instruction; The encapsulated trusted service request is parsed based on the trap handling code in the VMM, and the TPCM module is invoked.
[0008] In some embodiments, the VMM includes a trusted root access authorization control unit, and a virtual trusted root construction method based on supercall further includes: The Trusted Root Authorization Control Unit monitors the running status of the virtual machine and dynamically authorizes the access permissions of the TPCM module.
[0009] In some embodiments, the step of obtaining the physical address of the shared memory by mapping and translating the virtual address of the shared memory through the VMM in the host machine includes: When a trap event is triggered in the VMM of the host machine, the virtual address of the shared memory in the host machine is determined; The virtual address is mapped and converted to the physical address of the shared memory through the secondary mapping table of the virtualization platform.
[0010] In some embodiments, the method for constructing a virtual root of trust based on a supercall further includes: When the TPCM module starts, it performs a trust measurement on the host machine's hardware devices and startup process; Perform a credibility measurement on the VMM; When the virtual machine starts, a complete trust measurement is performed sequentially on the virtual machine startup process.
[0011] In some embodiments, the method for constructing a virtual root of trust based on a supercall further includes: The virtual trusted root construction method based on supercall is adapted to the ARM v7 architecture, and the supercall instruction is configured to trigger EL2 mode trap.
[0012] Secondly, embodiments of this application provide a computer device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement a virtual trusted root construction method based on supercall as described above.
[0013] Thirdly, embodiments of this application provide a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements one of the above-described methods for constructing a virtual trusted root based on a supercall.
[0014] Fourthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements one of the above-described methods for constructing a virtual trusted root based on a supercall.
[0015] This application provides a method, device, medium, and product for constructing a virtual root of trust based on a hypercall, applied to a virtualization platform. The virtualization platform includes a virtual machine and a host machine. The method for constructing a virtual root of trust based on a hypercall includes: writing the address of shared memory containing a trusted service request into the CPU register of the host machine based on the virtual machine; triggering a trap event of the VMM in the host machine through a hypercall instruction to establish communication between the host machine and the virtual machine; using the VMM in the host machine to perform mapping and conversion of the virtual address of the shared memory to obtain the physical address of the shared memory; parsing the physical address to determine the input request data transmitted by the virtual machine, and forwarding it to the TPCM module in the host machine for processing to obtain the processing result data; and writing the processing result data back to the shared memory based on the VMM. This solves the problem of the virtual machine calling the trusted algorithm of the physical machine's TPCM in a secure manner. By embedding it into the monitoring point of the VMM, trusted control is implemented on the virtualization system, which can meet the trusted application requirements in the virtualization environment. It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0016] The present application will be described in more detail below based on embodiments and with reference to the accompanying drawings.
[0017] Figure 1 This paper illustrates a flowchart of a virtual trusted root construction method based on supercall proposed in one embodiment of this application. Figure 2 A schematic diagram of an exemplary virtualization platform structure proposed in one embodiment of this application is shown; Figure 3 A schematic diagram of an exemplary socket-based virtual root of trust in related technologies is shown. Figure 4 This illustration shows a schematic diagram of an exemplary super-call working principle proposed in one embodiment of this application; Figure 5 This illustration shows a schematic diagram of an exemplary trusted root authorization invocation code according to an embodiment of this application; Figure 6 This illustration shows an exemplary trusted root authorization call according to an embodiment of this application; Figure 7 A schematic diagram of an exemplary trust measurement process proposed in one embodiment of this application is shown; Figure 8 This illustration shows a structural block diagram of a computer device for executing a virtual trusted root construction method based on a super call according to an embodiment of this application; Figure 9 This application illustrates a computer-readable storage medium for storing or carrying a method for constructing a virtual trusted root based on a supercall according to an embodiment of this application. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and are not intended to limit the present invention.
[0019] In existing technologies, trusted computing technology is based on a root of trust. Through step-by-step measurement and trust transfer from firmware, hardware, and operating system to application software, a trust chain is established to build a trusted computing platform. This ensures the platform's trusted startup and operation, endowing it with proactive security protection capabilities. The trusted cryptographic module, as an unconditionally trusted root of trust, possesses high security through physical security design and cryptographic-based logical security design, making it difficult for external parties to crack and obtain sensitive data information within the hardware. According to the trusted computing specification, trusted software is typically divided into two parts: the Trusted Software Stack (TSS) and the trusted application. The TSS is responsible for providing standard trusted service interfaces to upper-layer applications and for accessing the Trusted Platform Module (TPCM), converting interface calls into command requests and returning TPCM computation results.
[0020] In virtualization technology application scenarios, logically, it can be divided into three layers: the infrastructure layer, the virtualization platform layer, and the virtualization application layer. In the infrastructure layer and virtualization platform layer, trusted basic services for the host machine are directly established according to trusted specifications, as shown in the attached figure. Figure 2As shown. However, the situation is different inside a virtual machine. First, a TSS similar to the physical host needs to be built inside the virtual machine, called a vTSS. Due to the isolation protection mechanism between the virtual machine and the host machine, the vTSS cannot directly access the host machine's TDDL layer. This prevents trusted applications in the virtual machine from calling the trusted cryptographic algorithms provided by TPCM, causing the "chain of trust" to be unable to continue to be passed into the virtual machine, and the security of applications within the guest virtual machine cannot be guaranteed. If a hardware-based root of trust is not used, and a software virtualization is used to build a virtual root of trust, the software virtualization inherently lacks the cryptographic algorithm resource segmentation and protection capabilities of hardware emulation. Even if cryptographic resources are protected using encryption methods, they will still be exposed in plaintext in memory during use. The software-built virtual root of trust scheme has significant security vulnerabilities.
[0021] In addition to the above solutions, there is also a client / server (C / S) approach using sockets to build a virtual root of trust. This approach establishes a trusted transmission channel between the virtual machine and the host machine at the virtual network layer via a socket protocol. The host machine provides a trusted socket service. The guest virtual machine actively initiates a trusted root access connection request. After trusted authorization and access verification, network connection is allowed, and the trusted transmission channel is successfully established. The host machine's socket service receives the trusted access request from the virtual machine, forwards the request through the TSS and TDDL layers, and finally sends it to the TPCM module for processing, as shown in the attached diagram. Figure 3 As shown. This solution appears to solve the problem of trusted root access for guest virtual machines under virtualization isolation protection mechanisms. However, the applicant's research found some shortcomings, mainly in three aspects: 1. Socket-based trusted root access relies on relatively heavyweight network layer applications to build the transmission channel. For applications like active trusted measurement, trusted root access needs to be performed during the startup phase (e.g., BIOS), making the method of providing trusted calls using socket services unsuitable. 2. Secondly, this method requires network layer protocols for data exchange and forwarding, and network packets themselves are easily captured and intercepted externally, potentially introducing new security vulnerabilities and risks. 3. Socket protocol transmission adds a protocol parsing process, which reduces trusted computing performance and increases network bandwidth usage. The impact on performance is more pronounced for hash-intensive operations such as encryption / decryption.
[0022] To address the aforementioned technical problems, the applicant, through in-depth analysis of the implementation principles of virtualization technology, proposes a method, device, medium, and product for constructing a virtual root of trust based on super-calls. This solves the problem of the difficulty in achieving security in trust chain transmission under virtual platforms using traditional methods. The method for constructing a virtual root of trust based on super-calls will be described in detail in subsequent embodiments.
[0023] The following describes an application scenario of a virtual trusted root construction method based on super calls provided in the embodiments of this application: Please see Figure 1 , Figure 1 This is a schematic diagram of a virtual root of trust construction method based on supercall provided in this application embodiment. In this embodiment, a virtual root of trust construction method based on supercall can be applied to, for example... Figure 1 The virtualization platform shown and such Figure 8 The computer device 200 shown may include one or more computer devices. Multiple computer devices can transmit information wirelessly and / or via wired means. These multiple computer devices can collaboratively complete a method for constructing a virtual root of trust based on a super-call mechanism. Exemplarily, the computer devices may include computers, mobile terminals, tablets, etc., and this application does not limit them. This application's method for constructing a virtual root of trust based on a super-call mechanism is applied to a virtualization platform, which includes virtual machines and a host machine.
[0024] The following is about Figure 1 The process shown is described in detail. This method for constructing a virtual trusted root based on super calls may include steps S110 to S150.
[0025] S110: Based on the virtual machine, write the address of the shared memory containing the trusted service request to the CPU register in the host machine.
[0026] S120: The virtual machine triggers a trap event in the VMM on the host machine via a hypercall instruction to establish communication between the host machine and the virtual machine.
[0027] S130: Based on the virtual address mapping of shared memory in the host machine's VMM, the physical address of shared memory is obtained.
[0028] In some embodiments, S130 includes S131 to S132.
[0029] S131: When a trap event is triggered in the VMM of the host machine, determine the virtual address of the shared memory in the host machine.
[0030] S132: The virtual address is mapped and converted to the physical address of the shared memory through the secondary mapping table of the virtualization platform.
[0031] S140: Resolve the physical address to determine the input request data passed by the virtual machine, and forward it to the TPCM module in the host machine for processing to obtain the processing result data.
[0032] S150: Based on VMM, write the processing result data back to shared memory.
[0033] In this embodiment, by providing a transmission channel for virtualization to call the physical root of trust through a super call method, the TPCM module on the host machine can be shared with multiple virtual machines for root of trust access, so as to meet the needs of trusted computing applications in virtualization and cloud computing environments.
[0034] In this embodiment, the specific implementation method is as follows: Virtualization technologies can be categorized into two main types: paravirtualization and full virtualization. Paravirtualization is relatively simpler, as the guest operating system is customized, and some CPU instructions that exceed user privileges are replaced or removed during the compilation phase. Products using paravirtualization are less common, primarily because its high degree of customization requirements for passenger systems limits the flexibility of virtualization applications.
[0035] This application focuses on the full virtualization technology. Generally, full virtualization isolation and protection technology mainly solves this problem by adding a spatial dimension to CPU instruction execution and memory access permissions. In other words, it is necessary to restrict some super-privileged instructions (sensitive instructions) executed within the virtual machine, adding the dimension of the running mode. The CPU execution is divided into non-privileged mode and privileged mode.
[0036] In this application, the host operating system and VMM (or Hypervisor) operate in privileged mode, where instruction execution is unrestricted, while the guest virtual machine operates in non-privileged mode, where the execution of some sensitive instructions is restricted. The VMM itself operates in privileged mode, responsible for monitoring or capturing the execution of sensitive instructions within the virtual machine and converting the instructions into other call forms for execution. This ensures that the virtualization isolation mechanism is not compromised and resolves the issue of multiple operating systems competing for CPU resources.
[0037] In addition to the isolation constraints of memory access permissions, existing technologies only require process space protection for a single operating system. However, in a virtualized environment, an additional layer of virtual space protection is needed. Typically, a secondary memory mapping table is used to organize multiple "virtual spaces," and all memory access within the virtual machine is restricted to this logical scope.
[0038] In some embodiments, a method for constructing a virtual root of trust based on a supercall further includes: Encapsulate trusted service requests based on a virtual software stack and virtual transmission channel; The encapsulated trusted service request is passed to the VMM via a super call instruction; The trusted service request is parsed and encapsulated based on the trap handling code in the VMM and then invoked in the TPCM module.
[0039] In this embodiment, analysis of virtualization technology principles reveals that, in non-privileged mode, the virtual machine can transmit messages to the privileged mode VMM. Most virtualization platforms provide special-purpose pseudo-instructions called "super instructions." When a super instruction is called within the virtual machine (this call is called a "super call"), it triggers a VMM trap. The trap calls the trap handling code via a software interrupt. The trap handling code checks the super call behavior and performs the corresponding transaction processing. Using this method, the data buffer memory address is stored in the CPU register beforehand. After triggering the super call, the trap handling code reads the virtual address from the register and then uses a two-level mapping table to look up the physical address corresponding to that virtual address. The data block content corresponding to this physical address is the input data transmitted by the virtual machine. Writing back this data block can also return data to the virtual machine. This method enables the virtual machine to transmit data to and from the host machine. Based on this, a vTDDL layer is established inside the virtual machine to pass data from the TSS call request as a super instruction data stream to the VMM. This involves a lightweight modification to the VMM trap handling code, handling the legality checks of the agreed-upon super call instructions, and processing the data requests passed by vTDDL through the super call. The data requests are then converted into channel transmission requests by the TDDL layer, enabling the trusted root call process of the physical TPCM module within the guest virtual machine, as shown in the appendix. Figure 4 As shown.
[0040] The above call flow applies to both software virtualization and hardware-assisted virtualization modes. Hardware-assisted virtualization technology leverages processor hardware to accelerate the restriction of privileged and non-privileged sensitive instructions and the two-level mapping and translation of virtual memory space, which can greatly improve the efficiency of virtualization execution. In hardware-assisted virtualization, the super call is called VMcall, and when a trap occurs, it's called VMExit. A VMcall call triggers a VMExit hard interrupt from the CPU. The CPU immediately suspends the execution of the virtual machine code in non-privileged mode, switches to privileged mode, and hands over execution to the VMM trap handling code. The VMM can be configured to generate VMExit events using sensitive instructions.
[0041] In this application, considering that most existing C language compilers do not support super instructions, it is necessary to embed assembly code in the driver for specific platforms to implement super calls. To complete data transfer, a shared memory region for reading and writing needs to be allocated in the virtual machine driver. Before the super call, the starting address of this region is stored in the CPU register. In this way, the VMM trap handling code can obtain the virtual address of the shared memory from the register, and after mapping and conversion through the MMC's second-level virtual address table, the physical address of the virtual machine's shared memory can be obtained. Since the VMM itself operates in privileged kernel mode, it can directly access the physical memory data. The VMM handling code obtains the requested data from this physical address, thus basically realizing the data transfer channel between the virtual machine and the VMM.
[0042] In this application, each VMCall call triggers a VMExit, but thanks to hardware-assisted virtualization acceleration, the entire switching process is completed within the CPU, resulting in very fast execution. Through proper design and optimization of the VMM trap handling code, data transmission efficiency is extremely high. Comparing this transmission method with network socket transmission demonstrates a significant performance advantage. Furthermore, while TPCM modules used on single hosts previously only needed to meet the computational demands of that single host, trusted algorithm calls in a virtualized environment require consideration of the number of virtual machines supported by a single server, bandwidth allocation, and the performance of the TPCM module's algorithm computation to meet the actual needs of trusted computing in a virtual environment.
[0043] Considering that the super call in the above embodiments provides an efficient data transmission channel between the virtual machine and the host machine, if the super call instruction is exploited by malicious code, it may pose a certain threat to the security of the host machine.
[0044] In some embodiments, a method for constructing a virtual root of trust based on a supercall further includes: Retrieve the code segment triggered by the super call instruction based on the VMM; Perform a hash calculation on the code segment and compare it with the expected value of pre-stored legitimate driver code; If the comparison fails, the super call instruction is ignored and a security log alarm message is generated.
[0045] In this embodiment of the application, the legality verification process for the super-call trust metric is achieved through the above steps, wherein, as Figure 5As shown, by performing a hash calculation on the driver instruction code that triggers the hypercall within the virtual machine and then comparing it with the expected value of legitimate driver code, the legitimacy of the call can be verified. If an illegal call is found, no action is taken; the call is ignored and a security log alert is generated. This method effectively protects the VMM entity from attacks. Since the VMM runs in privileged kernel mode, it has the authority to obtain the environment in which the CPU is currently executing hypercall instructions and can obtain the instruction code within a specified region through the code segment register. This instruction code is a portion of the hypercall driver's instruction code within the virtual machine, and the hypercall driver code can be extracted in advance as a metric for the expected value.
[0046] In this embodiment, a legality verification technique for super calls is implemented to prevent super calls from being exploited by malicious code and causing new security risks.
[0047] To more concisely implement the construction of a trusted root in a virtualized environment.
[0048] In some embodiments, the VMM includes a trusted root access authorization control unit, and a method for constructing a virtual trusted root based on a super call further includes: The Trusted Root Authorization Control Unit monitors the running status of virtual machines and dynamically authorizes access permissions for TPCM modules.
[0049] In this embodiment, a vTDDL layer is inserted into the traditional TSS->TDDL->TPCM call flow to address the issue of trusted algorithm calls within the virtual machine. A trusted root authorization access unit is provided to securely authorize the virtual machine to access trusted algorithm calls. The trusted root authorization control unit monitors the virtual machine's operation and prevents the virtual machine from accessing the physical trusted root if anomalies are detected. For implementation integrity measurement within the virtual machine, it is necessary to utilize hypercall to construct a virtual transport channel (vTDDL) and a virtual software stack (vTSS) within the virtual machine, as shown in the attached figure. Figure 6 As shown.
[0050] In some embodiments, a method for constructing a virtual root of trust based on a supercall further includes: When the TPCM module starts, it performs a trust measurement on the host machine's hardware devices and startup process; In this embodiment of the application, the startup process of the host machine and the virtual platform is measured to prevent attackers from tampering with the startup process and compromising the virtual machine security mechanism.
[0051] Perform a trust measure on the VMM; In this application embodiment, the trustworthiness of the VMM (Hypervisor) and key virtual machine components is measured to prevent the loading of code with security vulnerabilities or infected by viruses, thus preventing potential security risks. When the virtual machine starts, a complete trust measurement is performed sequentially throughout the virtual machine startup process.
[0052] In this embodiment, when the virtual machine starts, the trustworthiness of the virtual BIOS, the passenger operating system, and the passenger applications are sequentially measured to prevent external attacks from damaging or infecting the virtual machine. A complete trustworthiness measurement process is described.
[0053] In this embodiment, the construction of the trusted chain in the virtualization environment requires the implementation of a trusted extension from the physical root of trust to the virtual machine, ensuring the reliable establishment of security mechanisms in the VMM (Hypervisor) and virtual machine, as shown in the appendix. Figure 7 As shown.
[0054] In some embodiments, a method for constructing a virtual root of trust based on a supercall further includes: The method for constructing a virtual root of trust based on supercall is adapted to the ARM v7 architecture, and the supercall instruction is configured to trigger EL2 mode trapping.
[0055] In this embodiment, the current mainstream direction in the domestic server field is based on ARM architecture, with representative examples such as Phytium's new quad-core processor that conforms to ARM v7 and above standards. This architecture already supports hardware-assisted virtualization technology. The processor has added an EL2 level in terms of mode. The non-privileged level is called the non-security domain and it works in EL0 mode. The privileged level is called the security domain and it runs in EL2 mode. The VMM works in EL2 mode and is protected by the processor.
[0056] In an ARM v7 environment, the processor does not respond to all sensitive instructions or privileged operations; Trap events require prior configuration. Therefore, to implement a high-speed transmission channel based on hypercalls in this architecture, it is necessary to carefully select the appropriate hypercall processor instruction and configure it for Trap events. This is essential for receiving Trap events within the VMM. The method for second-level table memory mapping also differs; refer to relevant ARM v7 technical documentation for details on implementing virtual machine shared memory mapping. The technique proposed in this paper is also applicable to ARM v7 and later processor architectures; however, the hypercall and trap handling code requires a certain amount of adaptation and customization.
[0057] In summary, this application provides a method for constructing a virtual root of trust based on supercall, solving the problem of virtual machines securely invoking the trusted algorithm of the physical machine's TPCM. It continues to use a trusted dual-architecture approach, maintaining the original virtualization platform framework largely unchanged, while hosting a logically relatively independent (implemented as a discrete module) trusted subsystem within the original system. This trusted foundation supports software infrastructure standards. It does not require large-scale modifications to the virtualization platform system, nor does it require the use of less secure socket-based virtual root of trust technology. Instead, it implements trusted control over the virtualization system by embedding it into the VMM's monitoring points. This provides a solution for extending the application of trusted computing in virtualized environments. The virtualized tunneling transmission technology provided in this application is simple, efficient, and feasible, meeting the trusted application requirements in virtualized environments.
[0058] Please see Figure 8 , Figure 8 This application provides a structural block diagram of a computer device 200 that can execute the above-described method for constructing a virtual trusted root based on a supercall. The computer device 200 may be a smartphone, tablet computer, computer, or portable computer.
[0059] The computer device 200 also includes a processor 202 and a memory 204. The memory 204 stores programs that can execute the contents of the foregoing embodiments, and the processor 202 can execute the programs stored in the memory 204.
[0060] The processor 202 may include one or more cores for data processing and message matrix units. The processor 202 connects to various parts of the computer device 200 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 204, and by calling data stored in the memory 204. Optionally, the processor 202 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 202 may integrate one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem / decoder. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem / decoder handles wireless communication. It is understood that the modem / decoder may also be implemented separately through a communication chip, without being integrated into the processor.
[0061] Memory 204 may include random access memory (RAM) or read-only memory (ROM). Memory 204 can be used to store instructions, programs, code, code sets, or instruction sets. Memory 204 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (e.g., instructions for a user to obtain random numbers), instructions for implementing the various method embodiments described below, etc. The data storage area may also store data (e.g., random numbers) created by the terminal during use.
[0062] Computer device 200 may also include a network module and a screen. The network module is used to receive and transmit electromagnetic waves, converting electromagnetic waves into electrical signals and vice versa, thereby enabling communication with communication networks or other devices, such as audio playback devices. The network module may include various existing circuit elements used to perform these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, user identity module (SIM) cards, memory, etc. The network module can communicate with various networks such as the Internet, corporate intranets, and wireless networks, or communicate with other devices via wireless networks. The aforementioned wireless networks may include cellular telephone networks, wireless local area networks, or metropolitan area networks. The screen can display interface content and facilitate data interaction.
[0063] Please refer to Figure 9 , Figure 9 This diagram illustrates a structural block diagram of a computer-readable storage medium according to an embodiment of this application. The computer-readable storage medium 400 stores program code 410, which can be called by a processor to execute the methods described in the above method embodiments.
[0064] The computer-readable storage medium 400 may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium 400 has storage space for program code 410 that performs any of the method steps described above. This program code 410 can be read from or written to one or more computer program products. The program code 410 may be compressed, for example, in a suitable form.
[0065] This application also provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform a virtual root of trust construction method based on a super-call as described in the various optional implementations above.
[0066] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A method for constructing a virtual root of trust based on supercall, characterized in that, Applied to a virtualization platform, which includes virtual machines and a host machine, the method includes: Based on the virtual machine, the address corresponding to the shared memory containing the trusted service request is written into the CPU register in the host machine; The virtual machine triggers a trap event in the VMM of the host machine via a hypercall instruction to establish communication between the host machine and the virtual machine; The VMM in the host machine performs mapping and translation through the virtual address of the shared memory to obtain the physical address of the shared memory; The physical address is parsed to determine the input request data transmitted by the virtual machine, and forwarded to the TPCM module in the host machine for processing to obtain the processing result data; The processing result data is written back to the shared memory based on the VMM.
2. The method for constructing a virtual root of trust based on supercall as described in claim 1, characterized in that, The method further includes: Based on the VMM, obtain the code segment triggered by the super call instruction; Perform a hash calculation on the code segment and compare it with the expected value of pre-stored legitimate driver code; If the comparison fails, the super call instruction is ignored and a security log alarm message is generated.
3. The method for constructing a virtual root of trust based on supercall according to claim 1, wherein a virtual transmission channel and a virtual software stack are constructed internally within the virtual machine, characterized in that, The method further includes: Encapsulate trusted service requests based on the virtual software stack and the virtual transmission channel; The encapsulated trusted service request is passed to the VMM via the super call instruction; The encapsulated trusted service request is parsed based on the trap handling code in the VMM, and the TPCM module is invoked.
4. The method for constructing a virtual root of trust based on a supercall according to claim 1, wherein the VMM is provided with a root of trust access authorization control unit, characterized in that, The method further includes: The Trusted Root Authorization Control Unit monitors the running status of the virtual machine and dynamically authorizes the access permissions of the TPCM module.
5. The method for constructing a virtual trusted root based on supercall according to claim 1, characterized in that, The step of mapping and converting the virtual address of the shared memory through the virtual address in the VMM of the host machine to obtain the physical address of the shared memory includes: When a trap event is triggered in the VMM of the host machine, the virtual address of the shared memory in the host machine is determined; The virtual address is mapped and converted to the physical address of the shared memory through the secondary mapping table of the virtualization platform.
6. The method for constructing a virtual trusted root based on supercall according to claim 4, characterized in that, The method further includes: When the TPCM module starts, it performs a trust measurement on the host machine's hardware devices and startup process; Perform a credibility measurement on the VMM; When the virtual machine starts, a complete trust measurement is performed sequentially on the virtual machine startup process.
7. The method for constructing a virtual root of trust based on supercall according to claim 1, characterized in that, The method further includes: The virtual trusted root construction method based on supercall is adapted to the ARM v7 architecture, and the supercall instruction is configured to trigger EL2 mode trap.
8. A computer device, characterized in that, The computer device includes: a processor and a memory; The memory is used to store computer-executed instructions; The processor is configured to execute computer execution instructions stored in the memory to cause the computer device to operate in order to implement a virtual trusted root construction method based on a supercall as described in any one of claims 1 to 7.
9. A computer storage medium, characterized in that, It includes computer-readable instructions that, when executed, implement a method for constructing a virtual trusted root based on a supercall as described in any one of claims 1 to 7.
10. A computer program product containing instructions that, when run on a computer, cause the computer to perform a method for constructing a virtual trusted root based on a supercall as described in any one of claims 1 to 7.