Direct storage access and command data transmission method, device and related equipment

By including the virtual machine ID in the DMA request of the DMA device, and using IOMMU to combine the host physical address and virtual machine ID, the problem that the DMA device cannot directly transmit encrypted memory data is solved, and efficient encrypted memory data transmission and data security guarantee are achieved.

CN114238185BActive Publication Date: 2025-05-23HYGON INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111561726.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-20
Publication Date
2025-05-23
Estimated Expiration
2041-12-20

AI Technical Summary

Technical Problem

Under secure virtualization technology, since the data in the encrypted memory space of the encrypted virtual machine exists in the form of ciphertext, DMA devices cannot directly and efficiently transmit data with the encrypted memory space.

Method used

By including the virtual machine ID in the DMA request of the DMA device, and combining the host physical address with the virtual machine ID with the input and output memory management unit (IOMMU) to form a target HPA, thereby controlling the memory controller to encrypt/decrypt and transmit data to the encrypted memory based on the corresponding key.

Benefits of technology

It realizes direct and efficient data transmission between DMA devices and encrypted memory space, avoiding the process of encrypted virtual machines that need to be decrypted first and then stored in ordinary memory, improving DMA transmission efficiency and ensuring data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238185B_ABST
    Figure CN114238185B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention provides a direct storage access and command data transmission method, device and related equipment. When the direct storage access method issues a DMA command to a DMA device, it simultaneously sends a virtual machine identifier corresponding to the encrypted virtual machine, so that when the DMA device performs data transmission with the encrypted memory, the IOMMU can combine the HPA obtained by IO page table conversion with the virtual machine identifier to form a new target HPA, so that the memory controller can call the key corresponding to the virtual machine identifier based on the virtual machine identifier in the target HPA, encrypt / decrypt data and transmit data on the encrypted memory page corresponding to the HPA, so that the DMA device and the encrypted memory space can achieve the purpose of direct and efficient data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of virtual machine technology, and in particular to a direct storage access and command data transmission method, device and related equipment. Background Art

[0002] DMA (Direct Memory Access) technology is an interface technology that enables external devices connected to the host to exchange data directly with the physical memory without going through the CPU. Under secure virtualization technology, since the data in the encrypted memory space of the encrypted virtual machine exists in ciphertext form, DMA devices cannot directly and efficiently transmit data with the encrypted memory space.

[0003] Therefore, how to provide an improvement plan to provide a basis for DMA devices to directly and efficiently transfer data with encrypted memory space has become a technical problem that technical personnel in this field urgently need to solve. Summary of the invention

[0004] In view of this, an embodiment of the present invention provides a direct storage access and command data transmission method, apparatus and related equipment to provide a basis for a DMA device to directly and efficiently perform data transmission with an encrypted memory space.

[0005] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions:

[0006] A direct storage access method is applied to an input-output memory management unit (IOMMU), the method comprising:

[0007] Obtain a DMA request of a direct memory access (DMA) device, wherein the DMA request includes a virtual machine identifier;

[0008] Determine the host physical address HPA of the memory data to be accessed by the DMA request;

[0009] Combining the HPA with the virtual machine identifier to form a target HPA;

[0010] The target HPA is used to control a memory controller so that the memory controller encrypts / decrypts data and transmits data on the encrypted memory corresponding to the HPA based on a key corresponding to the virtual machine identifier.

[0011] Optionally, the virtual machine identifier is set in the GPA of the memory that the DMA request needs to access, and determining the host physical address HPA of the memory that the DMA request needs to access includes:

[0012] Get the GPA of the memory to be accessed in the DMA request;

[0013] Removing the virtual machine identifier in the GPA;

[0014] Based on the GPA after removing the virtual machine ID, find the corresponding HPA.

[0015] Optionally, an encryption identifier is set in the GPA of the memory data that the DMA request needs to access, and the step of removing the virtual machine identifier in the GPA also includes: removing the encryption identifier in the GPA.

[0016] Optionally, combining the HPA with the virtual machine identifier to form a target HPA includes:

[0017] Extracting the virtual machine identifier from the GPA;

[0018] The virtual machine identifier is set in the HPA to form a target HPA.

[0019] Optionally, extracting the virtual machine identifier from the GPA further includes: extracting the encryption identifier from the GPA;

[0020] The step of setting the virtual machine identifier in the HPA further includes: setting the encryption identifier in the HPA.

[0021] The embodiment of the present invention further provides a direct storage access method, which is applied to a direct storage access DMA device, comprising:

[0022] Receiving a DMA command, wherein the DMA command includes a virtual machine identifier;

[0023] In response to the DMA command, a DMA request is sent to an input / output memory management unit IOMMU; the DMA request includes the virtual machine identifier, so that the memory controller encrypts / decrypts data and transmits data on the encrypted memory to be accessed based on a key corresponding to the virtual machine identifier;

[0024] When the memory controller responds to the DMA request to perform data transmission of the encrypted memory, the data transmitted by the memory controller is received.

[0025] Optionally, in the DMA request, the virtual machine identifier is set in the client physical address GPA of the memory that the DMA device needs to access.

[0026] Optionally, before the step of sending a DMA request to an input / output memory management unit IOMMU in response to the DMA command, the step further includes:

[0027] Build a secure channel for transmitting command data.

[0028] Optionally, the step of constructing a secure channel for transmitting command data includes:

[0029] Receiving a first ciphertext, where the first ciphertext is encrypted by a public key generated by a device driver using a chip public key;

[0030] Decrypting the first ciphertext using the chip private key to obtain the public key generated by the device driver;

[0031] Generate channel key information;

[0032] Encrypting the channel key information with the public key obtained by decryption to form a second ciphertext;

[0033] The second ciphertext is sent to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by it, obtains the channel key information, and forms a secure channel with encryption protection.

[0034] Optionally, the receiving the first ciphertext is specifically receiving a secure channel creation command, and the secure channel creation command includes the first ciphertext.

[0035] Optionally, after the step of receiving the DMA command and before the step of sending a DMA request to an input / output memory management unit IOMMU in response to the DMA command, the method further includes:

[0036] The DMA command is decrypted based on the channel key information of the secure channel.

[0037] Optionally, after the step of receiving the data transmitted by the memory controller, the step further includes:

[0038] Based on the context identifier of the transmitted data, the transmitted data is stored in an on-chip memory corresponding to the context identifier.

[0039] The embodiment of the present invention further provides a direct storage access method, which is applied to a device driver, comprising:

[0040] After the encrypted virtual machine generates a direct memory access DMA command, obtaining a virtual machine identifier corresponding to the DMA command;

[0041] Setting the virtual machine identifier in a DMA command;

[0042] A DMA command carrying the virtual machine identifier is sent to the DMA device.

[0043] Optionally, after obtaining the DMA command and before obtaining the virtual machine identifier corresponding to the DMA command, the method further includes:

[0044] Get the security status of the virtual machine that generated the DMA command;

[0045] When the virtual machine that generates the DMA command is an encrypted virtual machine, the step of obtaining the virtual machine identifier corresponding to the DMA command is performed.

[0046] Optionally, obtaining the virtual machine identifier corresponding to the DMA command is specifically, reading the virtual machine identifier stored in a model specific register, where the model specific register corresponds to the encrypted virtual machine that generates the DMA command.

[0047] Optionally, obtaining the virtual machine identifier corresponding to the DMA command includes:

[0048] Sending a virtual machine identification acquisition request to the encryption virtual machine, so that the encryption virtual machine can securely call the virtual machine identification in the security processor;

[0049] Get the virtual machine identifier obtained by the encrypted virtual machine security call.

[0050] Optionally, the DMA command includes a client physical address GPA of the memory that the DMA device needs to access, and setting the virtual machine identifier in the DMA command specifically includes setting the virtual machine identifier in the client physical address GPA.

[0051] Optionally, the step of setting the virtual machine identifier in the DMA command further includes setting an encryption identifier in the DMA command, wherein the encryption identifier is used to indicate whether the memory to be accessed in the DMA command is encrypted memory.

[0052] Optionally, the DMA command includes a client physical address GPA for transmitting memory data to the DMA device, and setting an encryption identifier in the DMA command specifically includes setting the encryption identifier in the client physical address GPA.

[0053] Optionally, before sending the DMA command with the virtual machine identifier to the DMA device, the method further includes:

[0054] Building a secure channel for transmitting command data;

[0055] The step of sending the DMA command with the virtual machine identifier to the DMA device includes:

[0056] Encrypting the DMA command based on the channel key information of the secure channel to form encrypted command data;

[0057] The encrypted command data is sent to a DMA device.

[0058] Optionally, the step of constructing a secure channel for transmitting command data includes:

[0059] Generate matching public and private keys;

[0060] Obtain a chip public key of the DMA device, and encrypt the generated public key using the chip public key to form a first ciphertext;

[0061] Sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext;

[0062] receiving the second ciphertext;

[0063] The second ciphertext is decrypted using a private key to obtain the channel key information, so as to form a secure channel with encryption protection.

[0064] Optionally, sending the first ciphertext to the DMA device includes:

[0065] Send a secure channel creation command, where the secure channel creation command includes the first ciphertext.

[0066] The embodiment of the present invention further provides a command data transmission method, which is applied to a device driver and includes:

[0067] Constructing a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism;

[0068] Encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data;

[0069] The encrypted command data is sent.

[0070] Optionally, the data transmission channel between the device driver and the direct memory access DMA device further includes a boot channel, and the boot channel is transmitted in plain text; after the step of building a secure channel for transmitting command data and before the step of encrypting the command data to be transmitted based on the channel key information of the secure channel, the step further includes:

[0071] Determine whether the resource accessed by the command data to be transmitted by the device driver is a secure resource;

[0072] When the resource accessed by the command data to be transmitted by the device driver is a secure resource, the step of executing the channel key information based on the secure channel, encrypting the command data to be transmitted, and forming encrypted command data; when the resource accessed by the command data to be transmitted by the device driver is not a secure resource, sending the command data through the boot channel.

[0073] Optionally, after determining whether the resource accessed by the command data sent by the device driver is a secure resource, before encrypting the command data to be transmitted based on the channel key information of the secure channel and forming the encrypted command data, it also includes determining whether the command data to be transmitted includes a read command;

[0074] If yes, it is determined that an access error occurs; if no, the step of encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data is executed.

[0075] Optionally, the step of constructing a secure channel for transmitting command data includes:

[0076] Receiving a first ciphertext, where the first ciphertext is encrypted by a public key generated by a device driver using a chip public key;

[0077] Decrypting the first ciphertext using the chip private key to obtain the public key generated by the device driver;

[0078] Generate channel key information;

[0079] Encrypting the channel key information with the public key obtained by decryption to form a second ciphertext;

[0080] The second ciphertext is sent to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by it, obtains the channel key information, and forms a secure channel with encryption protection.

[0081] Optionally, the receiving the first ciphertext is specifically receiving a secure channel creation command, and the secure channel creation command includes the first ciphertext.

[0082] Optionally, the channel key information includes a channel key, and at least one or more of an integrity key, an initial vector, and a rotation value.

[0083] Optionally, the channel key information includes a channel key, an integrity key, an initial vector and a rotation value;

[0084] The step of encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data includes:

[0085] Encrypt the command data to be transmitted using the channel key to obtain encrypted ciphertext;

[0086] The integrity verification ciphertext is calculated using the integrity key, the encrypted ciphertext and the rotation value;

[0087] The encrypted ciphertext and the integrity verification ciphertext are used as the encrypted command data.

[0088] The embodiment of the present invention further provides a command data transmission method, which is applied to a direct memory access DMA device, comprising:

[0089] Constructing a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism;

[0090] Get encrypted command data;

[0091] The encrypted command data is decrypted based on the channel key information of the secure channel to obtain command data.

[0092] Optionally, the step of constructing a secure channel for transmitting command data includes:

[0093] Generate matching public and private keys;

[0094] Obtain a chip public key of the DMA device, and encrypt the generated public key using the chip public key to form a first ciphertext;

[0095] Sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext;

[0096] receiving the second ciphertext;

[0097] The second ciphertext is decrypted using a private key to obtain the channel key information, so as to form a secure channel with encryption protection.

[0098] Optionally, the channel key information includes a channel key, and at least one or more of an integrity key, an initial vector, and a rotation value.

[0099] Optionally, the channel key information includes a channel key, an integrity key, an initial vector and a rotation value; the encryption command data includes an encrypted ciphertext and an integrity verification ciphertext;

[0100] The decrypting the encrypted command data based on the channel key information of the secure channel to obtain the command data comprises:

[0101] Verify the integrity verification ciphertext using the integrity key, the encrypted ciphertext and the rotation value;

[0102] If the verification is successful, the encrypted ciphertext is decrypted using the channel key to obtain the command data.

[0103] Optionally, after the step of decrypting the encrypted command data to obtain the command data, the step further includes:

[0104] Based on the context identifier in the command data, an on-chip memory is allocated for the corresponding command.

[0105] Optionally, allocating on-chip memory for a corresponding command based on a context identifier in the command data includes:

[0106] The current context identifier and the on-chip memory allocated thereto are updated in the identifier record table, wherein the identifier record table is used to record the corresponding relationship between the context identifier and the on-chip memory allocated thereto.

[0107] Optionally, after allocating on-chip memory for a corresponding command based on the context identifier in the command data, the method further includes:

[0108] Based on the context identifier in the command data, the command data is stored in an on-chip memory corresponding to the context identifier.

[0109] An embodiment of the present invention further provides a direct storage access device, comprising:

[0110] A request acquisition module, used for acquiring a DMA request of a direct memory access DMA device, wherein the DMA request includes a virtual machine identifier;

[0111] An address determination module, used for determining a host physical address HPA of memory data to be accessed by the DMA request;

[0112] An address forming module, used to combine the HPA with the virtual machine identifier to form a target HPA;

[0113] The data transmission module is used to control the memory controller by using the target HPA so that the memory controller encrypts / decrypts data and transmits data to the encrypted memory corresponding to the HPA based on the key corresponding to the virtual machine identifier.

[0114] An embodiment of the present invention further provides a direct storage access device, comprising:

[0115] A command receiving module, used for receiving a DMA command, wherein the DMA command includes a virtual machine identifier;

[0116] A request sending module, configured to send a DMA request to an input / output memory management unit IOMMU in response to the DMA command; the DMA request includes the virtual machine identifier, so that the memory controller encrypts / decrypts data and transmits data for the encrypted memory to be accessed based on a key corresponding to the virtual machine identifier;

[0117] The data receiving module is used to receive data transmitted by the memory controller when the memory controller responds to the DMA request to transmit data of the encrypted memory.

[0118] An embodiment of the present invention further provides a direct storage access device, comprising:

[0119] An identification acquisition module, used for acquiring a virtual machine identification corresponding to a direct memory access DMA command after the encrypted virtual machine generates the DMA command;

[0120] An identification setting module, used for setting the virtual machine identification in a DMA command;

[0121] The command sending module is used to send the DMA command with the virtual machine identifier to the DMA device.

[0122] The embodiment of the present invention further provides a command data transmission device, comprising:

[0123] A third channel construction module is used to construct a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism;

[0124] An encrypted command forming module, used for encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data;

[0125] The encrypted command sending module is used to send the encrypted command data.

[0126] The embodiment of the present invention further provides a command data transmission device, comprising:

[0127] A fourth channel construction module is used to construct a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism;

[0128] An encrypted command acquisition module, used to acquire encrypted command data;

[0129] The command decryption module is used to decrypt the encrypted command data based on the channel key information of the secure channel to obtain command data.

[0130] An embodiment of the present invention further provides an input-output memory management unit (IOMMU), wherein the IOMMU is configured to execute the direct storage access method provided by the embodiment of the present invention.

[0131] An embodiment of the present invention further provides a direct storage access DMA device, wherein the DMA device is configured to execute the direct storage access method provided by the embodiment of the present invention, and / or execute the command data transmission method provided by the embodiment of the present invention.

[0132] Optionally, the DMA device includes a cryptographic coprocessor, and the cryptographic coprocessor is used to provide encryption and decryption services and digest calculation services for the DMA device.

[0133] An embodiment of the present invention also provides an electronic device, comprising an input-output memory management unit provided by an embodiment of the present invention, a direct storage access DMA device provided by an embodiment of the present invention, and a device driver, wherein the device driver is configured to execute the direct storage access method provided by an embodiment of the present invention, and / or execute the command data transmission method provided by an embodiment of the present invention.

[0134] The embodiment of the present invention provides a direct storage access and command data transmission method, device and related equipment. When the method sends a DMA command to a DMA device, a virtual machine identifier corresponding to the encrypted virtual machine is sent at the same time, so that when the DMA device performs data transmission with the encrypted memory, the IOMMU can combine the HPA obtained by IO page table conversion with the virtual machine identifier to form a new target HPA, so that the memory controller can call the key corresponding to the virtual machine identifier based on the virtual machine identifier in the target HPA, encrypt / decrypt data and transmit data on the encrypted memory page corresponding to the HPA, so that the DMA device and the encrypted memory space can achieve the purpose of direct and efficient data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0135] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0136] Figure 1 Virtualization technology architecture for cloud service scenarios;

[0137] Figure 2 It is an optional architecture for cloud hosts;

[0138] Figure 3 A schematic diagram of an optional virtualization technology architecture provided for an embodiment of the present invention;

[0139] Figure 4 An optional flow chart of a direct storage access method provided by an embodiment of the present invention;

[0140] Figure 5 An optional MSR structure diagram provided for an embodiment of the present invention;

[0141] Figure 6 An optional flow chart of a secure call of a virtual machine identifier provided by an embodiment of the present invention;

[0142] Figure 7 An example diagram of an optional GPA format provided by an embodiment of the present invention;

[0143] Figure 8 An optional flow chart of step S15 provided in an embodiment of the present invention;

[0144] Fig. 9 An optional flow chart of step S16 provided in an embodiment of the present invention;

[0145] Fig.10 An example diagram of an optional HPA format provided by an embodiment of the present invention;

[0146] Fig.11 A schematic diagram of an optional structure of a DMA device provided in an embodiment of the present invention;

[0147] Fig.12 An optional flow chart of a command data transmission method provided by an embodiment of the present invention;

[0148] Fig.13 Another optional flow chart of the command data transmission method provided by the embodiment of the present invention;

[0149] Fig.14 An optional process for establishing a secure channel between a DMA device and a device driver of an encrypted virtual machine provided in an embodiment of the present invention;

[0150] Fig.15 An example diagram of a context structure provided by an embodiment of the present invention;

[0151] Fig.16 An optional block diagram of a direct storage access device provided by an embodiment of the present invention;

[0152] Fig.17 Another optional block diagram of a direct storage access device provided by an embodiment of the present invention;

[0153] Fig.18 Another optional block diagram of the direct storage access device provided by the embodiment of the present invention;

[0154] Fig.19 An optional block diagram of a command data transmission device provided by an embodiment of the present invention;

[0155] Fig. 20 Another optional block diagram of the command data transmission device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0156] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0157] With the development of cloud services, virtualization technology has been more and more widely used in cloud service scenarios. Virtualization technology allows users to deploy business systems on cloud hosts in the form of virtual machines, thereby reducing their own operating costs.

[0158] To prevent the host operating system of the cloud host from obtaining the memory data in the virtual machine and ensure the security of user cloud computing, refer to Figure 1 In the virtualization technology architecture of the cloud service scenario shown in the figure, the memory data of the virtual machine can be stored after encryption. Among them, the virtual machine VM (Virtual Machine) runs on the host operating system host OS and the virtual machine manager VMM (Virtual Machine Monitor), and the corresponding memory data can be encrypted / decrypted by the encryption engine (such as the SM4 national standard packet encryption engine) and stored in the memory DRAM of the cloud host after encryption.

[0159] To further ensure the independence of data between virtual machines, different virtual machines have different keys. Figure 1 For example, the virtual machine corresponding to asid=1 has key 1, the virtual machine corresponding to asid=2 has key 2, and so on, the virtual machine n corresponding to asid=n has key n, where asid (Address Space ID) is used to indicate the virtual machine identifier of the virtual machine, and different virtual machines have different asids.

[0160] Specifically, during the operation of the virtual machine, the hardware marks the code and data corresponding to the virtual machine based on the virtual machine identifier. During the encryption / decryption process of the memory data, the encryption engine determines the key of the virtual machine based on the virtual machine identifier, and further encrypts / decrypts the memory data based on the key.

[0161] In the cloud host, not all virtual machines perform encryption / decryption of memory data, and not all memory data executes the encryption / decryption process. For the sake of convenience, the embodiment of the present invention refers to the virtual machine that assigns the key as an encrypted virtual machine, and the virtual machine that does not assign the key as a normal virtual machine; at the same time, the memory that stores encrypted memory data is called encrypted memory, and the memory that stores unencrypted memory data is called normal memory. It should be noted that the virtual machine generated by the national standard encrypted secure virtualization technology is a CSV VM, where CSV stands for China Secure Virtualization, a national standard secure virtualization technology.

[0162] In order to improve the operating efficiency of the system and reduce the load of the CPU (Central Processing Unit), DMA devices can be further deployed on the cloud host to realize direct data exchange between DMA and physical memory. The DMA device can be understood as a device that can realize the DMA function. Accordingly, in the embodiments of the present invention, hard disks, GPUs (Graphic Processor Units), FPGAs (Field Programmable Gate Arrays) and other devices that can realize the DMA function can be understood as DMA devices. Taking the DMA device as a GPU as an example, refer to Figure 2 An optional architecture of a cloud host is shown, wherein the cloud host includes: a CPU SOC (CPU system on chip), a GPU and a memory.

[0163] CPU SOC can be understood as a chip equipped with a CPU. In addition to the CPU, the chip can also be equipped with a hardware structure that assists the operation of the CPU. The host operating system (host OS) runs on the CPU SOC, and the encrypted virtual machine runs on the host operating system.

[0164] The encrypted virtual machine can interact with the real GPU device through the pre-configured virtual GPU device. Specifically, when the resources of the GPU device need to be used, the GPU driver and / GPU runtime library are called to access the GPU device, thereby controlling the GPU device to execute corresponding commands.

[0165] The CPU SOC connects to the GPU device through the MMIO (memory mapped io) interface and injects commands into the command buffer in the GPU through MMIO.

[0166] A DMA module for implementing DMA function can be set in the GPU, and the IOMMU (Input / Output Memory Management Unit) in the CPU SOC can be used to realize the transmission of memory data.

[0167] In the CPU SOC, the cryptographic processor encrypts the memory data and stores it in the encrypted memory of the memory. However, when the host operating system is connected to the DMA device, since the data in the encrypted memory space of the encrypted virtual machine exists in the form of ciphertext, the DMA device cannot directly obtain the memory data it needs (that is, the original memory data of the virtual machine, which can be understood here as the memory data before encryption or after the ciphertext is decrypted). Instead, the encrypted virtual machine needs to first decrypt the ciphertext and copy it to the ordinary memory, and then the DMA device copies the memory data from the ordinary memory to the DMA device.

[0168] Based on the above situation, the embodiment of the present invention considers sending a virtual machine identifier corresponding to the encrypted virtual machine at the same time when issuing a DMA command to the DMA device, so that when the DMA device performs data transmission with the encrypted memory, the IOMMU can combine the HPA obtained by converting the IO page table with the virtual machine identifier to form a new target HPA, so that the memory controller can call the key corresponding to the virtual machine identifier based on the virtual machine identifier in the target HPA, encrypt / decrypt data and transmit data on the encrypted memory page corresponding to the HPA, so that the DMA device and the encrypted memory space can achieve the purpose of direct and efficient data transmission.

[0169] Based on this idea, an embodiment of the present invention provides an improved direct storage access method, so that during the direct storage access process, the IOMMU can configure the virtual machine identifier of the encrypted virtual machine in the data item of the DMA device, so that the DMA device can directly and efficiently encrypt / decrypt and transmit data with the encrypted memory space, thereby improving the transmission efficiency of DMA.

[0170] The direct storage access method provided by the embodiment of the present invention is described in detail below.

[0171] In an optional implementation, Figure 3 FIG. 4 shows a schematic diagram of an optional virtualization technology architecture provided by an embodiment of the present invention, such as Figure 3 As shown, the virtualization technology architecture is implemented based on secure virtualization technology, and may specifically include: CPU SOC, GPU devices and memory.

[0172] Among them, the basic introduction of CPU SOC, GPU device and memory can refer to the description of the corresponding parts in the previous text. The following will further explain the improved functions and relationships of these components in the embodiments of the present invention; it is worth noting that in the embodiments of the present invention, the device driver (i.e., GPU driver) in the encrypted virtual machine supports the asid query function, and the IOMMU supports the IO page table function with asid.

[0173] In an embodiment of the present invention, Figure 3A security processor is also provided in the technical architecture shown, which is used to configure a corresponding key for the memory of the encrypted virtual machine and mark it with the virtual machine identifier asid of the encrypted virtual machine, so that the cryptographic processor encrypts and decrypts the memory data based on the virtual machine identifier asid;

[0174] In addition, the memory manager MMU is computer hardware responsible for processing the CPU's memory access requests. Its functions include virtual memory management, memory protection, etc. Virtual memory management mainly includes the construction of page tables, the conversion of virtual machine virtual addresses (GuestVirtual Address, GVA) to host physical addresses (Host Physical Address, HPA), etc. For example, in the process of building the page table of the encrypted virtual machine, the memory manager establishes a virtual page table gPT and a nested page table nPT for the encrypted virtual machine based on the command of the virtual machine manager VMM. Among them, in an optional example, in the established nested page table nPT, the client physical address GPA can carry a virtual machine identifier asid.

[0175] based on Figure 3 The optional architecture shown, in an optional implementation, Figure 4 An optional flow chart of a direct storage access method provided by an embodiment of the present invention is shown, Figure 4 As shown, the process may include:

[0176] Step S10: After the encrypted virtual machine generates a DMA command, the device driver obtains a virtual machine identifier corresponding to the DMA command;

[0177] It is understandable that after the encrypted virtual machine generates a DMA command, it will call the device driver to access the DMA device. After the device driver encrypted virtual machine generates a DMA command, it can obtain the DMA command, thereby obtaining the virtual machine identifier corresponding to the DMA command.

[0178] The virtual machine identifier corresponding to the DMA command refers to the virtual machine identifier of the virtual machine that generates the DMA command. In this example, after obtaining the DMA command, the virtual machine that generates the DMA command can be determined based on the DMA command, and then the virtual machine identifier of the virtual machine that generates the DMA command can be obtained.

[0179] It should be noted that, in a cloud host, the virtual machines may include only encrypted virtual machines, or may include both ordinary virtual machines and encrypted virtual machines. Based on the DMA of encrypted memory data of an encrypted virtual machine in an embodiment of the present invention, when the virtual machines include both ordinary virtual machines and encrypted virtual machines, the security status of the virtual machine that generates the DMA command is further determined, and then it can be determined whether the virtual machine that generates the DMA command is an encrypted virtual machine. Therefore, when the virtual machine that generates the DMA command is an encrypted virtual machine, the step of obtaining the virtual machine identifier corresponding to the DMA command is performed.

[0180] In an optional example, the virtual machine identifier may be read from a model specific register (Model Specific Register, MSR) corresponding to the encrypted virtual machine.

[0181] The model-specific register is used to store the asid of the encrypted virtual machine. The security processor has read and write permissions to the MSR. The encrypted virtual machine can only read the asid stored in the MSR. Correspondingly, the device driver in the encrypted virtual machine can only read the MSR. During the startup phase of the encrypted virtual machine, the security processor is responsible for writing the asid into the MSR. An optional MSR structure can be referenced Figure 5 As shown, due to the length limit of asid, bits 0-8 can be used for asid, and the remaining space can be reserved space.

[0182] In another optional example, the device driver can also securely call the asid in the security processor through the encrypted virtual machine. Figure 6 In the optional flow chart of the virtual machine identification security call shown, step S10 may include:

[0183] Step S101: The device driver sends a virtual machine identification acquisition request to the encrypted virtual machine, so that the encrypted virtual machine can safely call the virtual machine identification in the security processor;

[0184] Correspondingly, after receiving the virtual machine identification acquisition request, the encrypted virtual machine securely calls the virtual machine identification in the security processor, thereby obtaining the virtual machine identification corresponding to the encrypted virtual machine.

[0185] Step S102: The device driver obtains the virtual machine identifier obtained by securely calling the encrypted virtual machine.

[0186] By obtaining the virtual machine identifier of the encrypted virtual machine, the issued DMA command carries the virtual machine identifier, so that encryption and decryption of memory data to be accessed can be achieved based on the virtual machine identifier.

[0187] Continue to refer Figure 4, executing step S11, the device driver sets the virtual machine identifier in the DMA command;

[0188] By setting the virtual machine identifier in the DMA command, the subsequent DMA process can implement decryption of memory data based on the virtual machine identifier.

[0189] The DMA command includes the client physical address GPA of the memory to be accessed to indicate the location of the memory to be accessed. The access described in this example includes reading and writing data. In an optional example, the virtual machine identifier can be set in the client physical address GPA in the DMA command. Figure 7 An optional GPA format example diagram is shown, wherein bits 48 to 56 of the GPA may be defined as virtual machine identification bits, and the virtual machine identification may be set in the virtual machine identification bits, thereby setting a corresponding virtual machine identification in the GPA.

[0190] In a further optional example, an encryption identifier c-bit may also be set in the DMA command to indicate whether the memory to be accessed in the DMA command is encrypted memory. Specifically, it may be defined that when the encryption identifier is a first value (e.g., c-bit is 1), it indicates that the memory to be accessed by the DMA device is encrypted memory, and when the encryption identifier is a second value (e.g., c-bit is 0), it indicates that the memory to be accessed by the DMA device is ordinary memory.

[0191] Accordingly, in the DMA command, the encryption flag can be set in the client physical address GPA of the memory that the DMA device needs to access. Figure 7 An example diagram of the GPA format is shown, in which bit 47 of the GPA can be defined as an encryption identification bit, and the encryption identification can be set in the encryption identification bit, thereby setting a corresponding encryption identification in the GPA.

[0192] Continue to refer Figure 4 , executing step S12, the device driver sends a DMA command with the virtual machine identifier to the DMA device;

[0193] After the virtual machine identifier is set, the DMA command can be sent to the DMA device. Correspondingly, the DMA device can receive the DMA command.

[0194] Continue to refer Figure 4 , executing step S13, the DMA device sends a DMA request to the IOMMU in response to the DMA command;

[0195] The DMA request includes the virtual machine identifier, so that the memory controller encrypts / decrypts data and transmits data on the encrypted memory to be accessed based on the key corresponding to the virtual machine identifier;

[0196] The virtual machine identifier can be obtained by parsing the DMA command, and when generating the DMA request, the virtual machine identifier is set in the DMA request. Alternatively, in an optional example, considering that in the DMA request generated based on the DMA command, the address information corresponding to the memory data to be accessed must be set in the DMA request. Therefore, when the virtual machine identifier is set in the GPA, the DMA request can be generated and sent directly based on the original process without having to specifically execute the step of setting the virtual machine identifier in the DMA request.

[0197] Step S14, the IOMMU obtains a DMA request from the DMA device;

[0198] The DMA request includes a virtual machine identifier, so that encryption / decryption of data on the encrypted memory to be accessed is achieved based on the virtual machine identifier.

[0199] Continue to refer Figure 4 , executing step S15, the IOMMU determines the host physical address HPA of the memory data to be accessed by the DMA request;

[0200] After obtaining the DMA request, the IOMMU may determine the HPA corresponding to the DMA request. In an optional implementation, the IOMMU may obtain the HPA corresponding to the DMA request by searching an IO page table.

[0201] It is understandable that the IOMMU needs to look up the IO page table based on the GPA of the memory data to be accessed in the DMA request, so as to obtain the HPA corresponding to the GPA.

[0202] When the virtual machine identifier is set in the GPA, the IOMMU can remove the virtual machine identifier in the GPA and then perform the corresponding HPA search process. Figure 8 The optional flow chart of step S15 shown in FIG. 1 includes:

[0203] Step S150, obtaining the GPA of the memory to be accessed in the DMA request;

[0204] Step S151, removing the virtual machine identifier in the GPA;

[0205] The removal may include clearing the corresponding information to zero (mask).

[0206] Step S152: based on the GPA after removing the virtual machine identifier, search for the corresponding HPA.

[0207] It should be noted that, in the process of removing the virtual machine identifier in the GPA in step S151, if the GPA also includes an encryption identifier, step S151 will also remove the encryption identifier in the GPA.

[0208] In addition, it is understandable that when the search for the HPA fails, a page fault may be generated, so that the host operating system allocates physical memory for the GPA and updates the IO page table.

[0209] Continue to refer Figure 4 , executing step S16, the IOMMU combines the HPA with the virtual machine identifier to form a target HPA;

[0210] After determining the virtual machine identifier corresponding to the HPA, the IOMMU may combine the HPA with the virtual machine identifier to form a new target HPA. The IOMMU may use the target HPA to implement data encryption / decryption and data transmission between the DMA device and the encrypted memory page corresponding to the HPA.

[0211] Wherein, the virtual machine identifier can be obtained from the DMA request. When the virtual machine identifier is set in the GPA of the memory data to be accessed by the DMA request, refer to Fig. 9 An optional flow chart of step S16 is shown, where step S16 may include:

[0212] Step S160, extracting the virtual machine identifier from the GPA;

[0213] Specifically, the virtual machine identifier can be extracted based on the virtual machine identifier bit preset in the GPA. When an encryption identifier is also set in the GPA of the memory to be accessed by the DMA request, this step can also include extracting the encryption identifier (c-bit) in the GPA.

[0214] Step S161: Set the virtual machine identifier in the HPA to form a target HPA.

[0215] The format of the HPA can be found in Fig.10 As shown in the example diagram of the HPA format, bits 48 to 56 of the HPA may be defined as virtual machine identification bits, and the virtual machine identification may be set in the virtual machine identification bits;

[0216] When an encryption identifier is also set in the GPA of the memory data to be accessed by the DMA request, this step may also simultaneously include setting the encryption identifier in the HPA.

[0217] Specifically, refer to Fig.10 In the example diagram of the HPA format shown, the 47th bit of the HPA can be defined as an encryption identification bit, and the encryption identification can be set in the encryption identification bit. Fig.10 The structure of the target HPA shown is only exemplary, and embodiments of the present invention may also adopt target HPA in other structural forms that can combine HPA, asid and c-bit.

[0218] Continue to refer Figure 4 , executing step S17, the IOMMU uses the target HPA to control the memory controller, so that the memory controller encrypts / decrypts data and transmits data on the encrypted memory corresponding to the HPA based on the key corresponding to the virtual machine identifier;

[0219] After obtaining the target HPA, the IOMMU can use the target HPA to control the memory controller, so that the memory controller encrypts / decrypts and transmits data in the encrypted memory corresponding to the HPA based on the key bound to the virtual machine identifier, thereby realizing direct and efficient data transmission between the DMA device and the encrypted memory, avoiding the need for the encrypted virtual machine to first decrypt the data in the encrypted memory and then store it in the ordinary memory space, thereby improving the transmission efficiency of DMA.

[0220] Optionally, the IOMMU may send the target HPA to the memory controller, so that the memory controller performs data encryption / decryption and data transmission in the encrypted memory corresponding to the HPA based on the key bound to the virtual machine identifier; in a more specific optional implementation, the data transmission of the DMA device in the encrypted memory page corresponding to the HPA can be divided into the process of writing data and reading data. It can be understood that since the encrypted memory page is in an encrypted state, when writing data, the data needs to be encrypted with the key of the encrypted virtual machine and then written into the encrypted memory page. When reading data, the data in the encrypted memory page needs to be decrypted with the key of the encrypted virtual machine and then read out;

[0221] In one example, when writing data, the memory controller can parse the target HPA after obtaining the target HPA. After determining that the c-bit in the target HPA is the first value, the memory controller can call the key bound to the asid, encrypt the data, and write it to the encrypted memory page corresponding to the HPA in the target HPA; when reading data, the memory controller can parse the target HPA after obtaining the target HPA. After determining that the c-bit in the target HPA is the first value, the memory controller can read the encrypted data from the encrypted memory page corresponding to the HPA in the target HPA, use the key bound to the asid to decrypt the read encrypted data, and pass it to the DMA device.

[0222] It can be understood that the DMA device is a peripheral device of the host, assisting the host in storing and processing data. Figure 3 As shown, taking the DMA device as a GPU device as an example, the GPU device can provide additional computing power services for the virtual machine, especially when performing AI (Artificial Intelligence) model calculations, the GPU device can be used as an AI accelerator card to provide an independent data processing device for the AI ​​model.

[0223] Specifically, when the GPU device assists in AI data processing, the AI ​​model can be started in the encrypted virtual machine, the GPU runtime library and GPU driver can be called, and the command data of the AI ​​model (such as model loading commands, memory copy commands, etc.) can be injected into the command buffer in the GPU device. The GPU device further copies the model data of the AI ​​model from the memory to the on-chip memory of the GPU device based on the DMA module, and runs calculations on the AI ​​model based on the data in the on-chip memory. After the operation, the calculation results are copied to the memory through the DMA module.

[0224] Based on the aforementioned embodiments of the present invention, when the memory is an encrypted memory, data encryption / decryption and data transmission can be performed based on the direct storage access method provided in the aforementioned embodiments of the present invention, thereby directly and efficiently transmitting data with the encrypted memory space.

[0225] However, if the data processing environment of the DMA device (eg, GPU device) remains open and accepts command data sent by the host in plain text, the host operating system may spy on and tamper with the commands injected into the DMA device, resulting in data leakage.

[0226] In view of this, in order to ensure the data security of the DMA device, an embodiment of the present invention further provides a DMA device that supports command data encryption transmission function. By establishing a secure channel between the DMA device and the device driver in the host, based on the fact that the device driver is a virtual device inside the encrypted virtual machine, its data will not be obtained by the host operating system, thereby realizing encrypted transmission of command data between the DMA device and the device driver, thereby ensuring the data security of the DMA device.

[0227] Specifically, refer to Fig.11 The schematic diagram of the optional structure of the DMA device shown is a GPU, which is further provided with a cryptographic coprocessor for providing encryption and decryption services (such as sm4 / aes algorithms), digest calculation services (such as sm3 / sha3 algorithms), etc. for the DMA device. The cryptographic coprocessor is internally fixed with a chip private key, which does not allow any device other than the cryptographic coprocessor to read.

[0228] In an embodiment of the present invention, a secure channel between the DMA device and the device driver of the encrypted virtual machine can be established based on the above-mentioned DMA device, and based on the channel key information of the secure channel, the command data sent by the host can be transmitted, thereby creating a closed trusted environment for the DMA device and ensuring the data security of the device.

[0229] based on Figure 3 and Fig.11 The optional architecture shown, in an optional implementation, Fig.12 An optional flow chart of the command data transmission method provided by an embodiment of the present invention is shown, Fig.12 As shown, the process may include:

[0230] Step S20: The device driver and the DMA device construct a secure channel for transmitting command data;

[0231] The secure channel can realize data transmission based on the data encryption and decryption mechanism, so that the data can be transmitted in the form of ciphertext during the data transmission process, thereby improving the security of data transmission. Accordingly, the secure channel performs data transmission based on the data encryption and decryption mechanism.

[0232] Step S22: The device driver encrypts the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data;

[0233] After the secure channel is constructed, the channel key information of the secure channel can be obtained, so that the command data can be encrypted based on the channel key information to ensure the transmission security of the command data.

[0234] Step S24: The device driver sends encrypted command data to the DMA device.

[0235] After the device driver sends the encrypted command data to the DMA device, the DMA device can obtain the encrypted command data accordingly.

[0236] Step S26: The DMA device decrypts the encrypted command data based on the channel key information of the secure channel to obtain the command data.

[0237] After the secure channel is constructed, the channel key information of the secure channel can be obtained, so that the encrypted command data can be decrypted based on the channel key information to obtain the corresponding command data.

[0238] It can be seen that in an embodiment of the present invention, a secure channel can be established between a DMA device and a host (such as a device driver of an encrypted virtual machine), and command data sent by the host can be transmitted based on the secure channel. This can create a closed trusted environment for the DMA device to ensure data security of the device.

[0239] When the command data does not need to be or cannot be transmitted through the secure channel, it can be transmitted in plain text through the original MMIO interface. For the sake of distinction, the channel for plain text transmission through the MMIO interface can be called a boot channel. In the embodiment of the present invention, the access command to the non-secure resource of the device can be transmitted through the boot channel, and the access command to the secure resource of the device can be transmitted through the secure channel.

[0240] Specifically, Fig.13 Another optional flow chart of the command data transmission method provided by the embodiment of the present invention is shown as follows: Fig.13 As shown, after the device driver executes step S20 and before executing step S22, the following may be further included:

[0241] Step S21, the device driver determines whether the resource accessed by the command data to be transmitted is a secure resource;

[0242] Specifically, it is possible to determine whether the accessed resource is a secure resource based on the address information in the command data to be transmitted, or it is possible to determine whether the accessed resource is a secure resource based on the encryption identifier in the command data to be transmitted. The address information in the command data to be transmitted or the encryption identifier in the command data to be transmitted can indicate whether the accessed resource is a secure resource, so that the execution process of the subsequent steps can be determined based on the judgment result.

[0243] Specifically, when the resource accessed by the command data to be transmitted by the device driver is a secure resource, step S22 is executed; when the resource accessed by the command data to be transmitted by the device driver is not a secure resource, step S23 is executed.

[0244] Step S23: The device driver sends the command data through the guide channel.

[0245] The command data is transmitted in plain text in the guide channel, so that the command data can be sent directly.

[0246] In another optional example, the boot channel can transmit, for example, secure channel creation commands, device information query commands, etc., and the secure channel can transmit, for example, device memory allocation-related commands, device kernel code loading, data copy (e.g., DMA) commands, etc.

[0247] It can be understood that after obtaining the corresponding command data, the DMA device (such as a GPU device) can process the data internally and execute data transmission through the DMA module. Therefore, in an embodiment of the present invention, the security channel can be set to only support the transmission of command data of write commands, and not support the transmission of command data of read commands. Specifically, on the device driver side, after step S21 and before step S22, it can be further determined whether the command data to be transmitted includes a read command. If so, it is determined that an access error occurs. If not, step S22 is executed.

[0248] In a further optional example, the GPU device also includes a command processor for encrypting / decrypting data using a cryptographic coprocessor.

[0249] Specifically, refer to Fig.14 The optional process of establishing a secure channel between a DMA device and a device driver of an encrypted virtual machine shown in the figure may include:

[0250] Step S200: The device driver generates matching public and private keys;

[0251] The public key and the private key are also called a key pair, which are used to encrypt and decrypt data. Specifically, the key pair can be generated based on the national secret SM2.

[0252] Step S201: The device driver obtains a chip public key of the DMA device, and encrypts the generated public key using the chip public key to form a first ciphertext;

[0253] The chip public key can be obtained based on the boot channel, and the generated public key can be further encrypted based on the chip public key, so that the channel key generated by the GPU device can be encrypted and transmitted based on the public key.

[0254] Step S202: The device driver sends the first ciphertext to the DMA device;

[0255] The device driver may send a secure channel creation command to the GPU through a boot channel, and the secure channel creation command may include the first ciphertext, thereby implementing the sending of the first ciphertext.

[0256] Correspondingly, the DMA device may receive the first ciphertext, or the DMA device may receive a secure channel creation command, which may include the first ciphertext.

[0257] Step S203: The DMA device decrypts the first ciphertext using the chip private key to obtain the public key generated by the device driver;

[0258] The DMA device can use the chip private key to decrypt the first ciphertext, and then obtain the public key generated by the device driver.

[0259] Step S204, the DMA device generates channel key information;

[0260] The channel key information is used to encrypt and decrypt command data transmitted through a secure channel, so that the corresponding command data is encrypted and transmitted through the secure channel. The channel key information at least includes a channel encrypt key (CEK), and in other optional examples, the channel key information may further include at least one or more of a channel integrity key (CIK), an initialization vector (IV), and a round value.

[0261] The channel key is used to encrypt command data, the integrity key is used to verify the integrity of data, and the initial vector and round value are used as parameters in the integrity calculation to participate in the corresponding integrity calculation. The round value is a variable value that can be increased by 1 after each calculation to resist replay attacks.

[0262] Step S205: The DMA device encrypts the channel key information with the public key obtained by decryption to form a second ciphertext;

[0263] Wherein, when the channel key information is generated, the channel key information is transmitted by encryption to ensure data security of the channel key information.

[0264] In a further optional example, the chip private key may be further used to sign the second ciphertext to further improve the data security of the second ciphertext.

[0265] Step S206: The DMA device sends the second ciphertext to the device driver;

[0266] After the second ciphertext is generated, the second ciphertext is sent to the device driver, so that the device driver obtains the channel key information of the secure channel based on the information in the ciphertext.

[0267] In the optional example, the second ciphertext is the second ciphertext signed by the chip private key, and accordingly, the second ciphertext signed by the chip private key is sent to the device driver.

[0268] Correspondingly, the device driver can receive the second ciphertext.

[0269] Step S207: The device driver uses the private key to decrypt the second ciphertext and obtain the channel key information to form a secure channel with encryption protection.

[0270] After receiving the second ciphertext, the device driver may use the private key to decrypt the second ciphertext, thereby obtaining the channel key information and forming a secure channel with encryption protection.

[0271] It is understandable that after obtaining the channel key information, the command data that needs to be transmitted through the secure channel can be encrypted based on the channel key information and then transmitted to the DMA device, thereby improving the security of the command data.

[0272] In the optional example, the second ciphertext is the second ciphertext signed by the chip private key. Accordingly, this step can use the chip public key to verify the second ciphertext, and then perform decryption of the second ciphertext after the verification is passed to ensure the data security of the second ciphertext.

[0273] Correspondingly, when using the secure channel to transmit DMA commands, after setting the virtual machine identifier in the DMA command in step S11, step S12 further encrypts the DMA command based on the channel key information of the secure channel to form encrypted command data, and then sends the encrypted command data to the DMA device.

[0274] Accordingly, when the secure channel is used to transmit a DMA command, after the DMA device receives the encrypted command data, it is further necessary to decrypt the encrypted command data to obtain the DMA command. Specifically, after receiving the DMA command, the DMA command can be further decrypted based on the channel key information of the secure channel, and then in step S13, a DMA request is sent in response to the DMA command.

[0275] In an optional example, the channel key information may include: channel encrypt key (CEK), channel integrity key (CIK), initialization vector (IV), round value. When encrypting the command data to be transmitted in step S22, the command data to be transmitted can be encrypted based on the channel key information. Specifically, the command data to be transmitted can be encrypted using the channel key CEK to obtain an encrypted ciphertext, and the integrity verification ciphertext can be calculated using CIK, encrypted ciphertext, and round value. The encrypted ciphertext and the integrity verification ciphertext are used as the encrypted command data. The integrity verification ciphertext can be a summary MAC calculated by CIK, encrypted ciphertext, and round value. Among them, the round value is increased by 1 each time the calculation is performed.

[0276] Specifically, during the transmission of the DMA command, the command data may be a DMA command. Accordingly, the DMA command encryption may be specifically performed by encrypting the DMA command using a channel key CEK to obtain an encrypted ciphertext, and using the CIK, the encrypted ciphertext, and a round value to calculate an integrity verification ciphertext, and using the encrypted ciphertext and the integrity verification ciphertext as the encrypted command data.

[0277] In an optional example, when decrypting the encrypted command data in step S26, the encrypted command data can be decrypted based on the channel key information. Specifically, the integrity verification ciphertext is verified using CIK, encrypted ciphertext, and round value. After the verification is passed, the encrypted ciphertext is decrypted using the channel key CEK to obtain the command data. The integrity verification can be a summary MAC calculated by CIK, encrypted ciphertext, and round value, and the calculated MAC is compared with the integrity verification ciphertext. If they are consistent, the verification is passed. If they are inconsistent, the verification fails. Correspondingly, the round value on the DMA device side is increased by 1 after each calculation.

[0278] Specifically, during the transmission of the DMA command, the command data may be a DMA command. Accordingly, the DMA command is decrypted based on the channel key information, specifically, the integrity verification ciphertext is verified using CIK, encrypted ciphertext, and round value, and after the verification is passed, the encrypted ciphertext is decrypted using the encrypted channel key CEK to obtain the DMA command.

[0279] It should be noted that the same DMA device may be assigned to different encrypted virtual machines. Accordingly, when constructing a secure channel, different encrypted virtual machines have different device drivers. Different secure channels can be constructed based on different device drivers, thereby ensuring the isolation of data between different encrypted virtual machines and improving data security.

[0280] It can be understood that different encrypted virtual machines correspond to different commands, and different commands have different contexts (context), and thus correspond to different context identifiers (context id). Therefore, a secure channel can be constructed based on the context identifier (context id) in the command data, and different secure channels can be constructed based on different context identifiers, thereby ensuring the isolation of data between different encrypted virtual machines and improving data security.

[0281] In an optional example, to further ensure the isolation of data in the GPU, an on-chip memory management module (graphic memory ownership management, GMOM) may be set in the GPU device to configure different memory pages for different commands, thereby avoiding data access between different commands.

[0282] It can be understood that different commands have different contexts (context), and thus correspond to different context identifiers (context id). Therefore, isolating the on-chip memory based on the context identifier (context id) in the command data can avoid mutual access to memory data and improve data security.

[0283] In an optional example, after obtaining the corresponding command data, on-chip memory can be allocated for the corresponding command based on the context identifier in the command data, and a piece of memory can be allocated in the on-chip memory of the GPU to store the context identifier to which the GPU on-chip memory belongs. The context identifier in the command data obtained by the GPU can be compared with the context identifier corresponding to the on-chip memory accessed by the command data, and when the two context identifiers are consistent, the corresponding access is performed. For example, when a DMA device receives data transmitted by a memory controller, the transmitted data can be stored in the on-chip memory of the DMA device based on the context identifier of the transmitted data. Among them, the context identifier to which the GPU on-chip memory belongs can be recorded in an identifier record table.

[0284] When the GPU allocates on-chip memory, the current context id and the memory allocated thereto are updated in the identification record table; when the GPU releases on-chip memory, the context id field on the identification record table where the memory is located is cleared.

[0285] After the corresponding on-chip memory is allocated, the command data can be stored in the on-chip memory corresponding to the context identifier based on the context identifier of the command data. When performing DMA data transmission, the transmitted data can be stored in the on-chip memory corresponding to the context identifier based on the context identifier of the transmitted data. The context identifier corresponds to the on-chip memory.

[0286] refer to Fig.15 As shown in the context structure example diagram, the context at least includes the physical address of the root page table (graphic page table addr) and the context identifier (context id) corresponding to the context.

[0287] In an optional example, the channel descriptor corresponding to the context stores the physical address of the root page table, so that the corresponding root page table can be obtained according to the physical address of the root page table, and the root page table can be queried to obtain the video memory physical address VHPA corresponding to the video memory virtual address VHVA in the command data. Then, GMOM can query the corresponding context id based on the video memory physical address VHPA and compare it with the context id in the command data, so as to determine that the two context identifiers are consistent, and execute the corresponding command when the two context identifiers are consistent.

[0288] The above describes multiple implementation schemes provided by the embodiments of the present invention. The various optional methods introduced in the implementation schemes can be combined and cross-referenced with each other without conflict, thereby extending a variety of possible implementation schemes, which can all be considered as implementation schemes disclosed and open in the embodiments of the present invention.

[0289] The following introduces the direct storage access device provided in the embodiment of the present invention from the perspective of IOMMU. The direct storage access device described below can be considered as a functional module that the IOMMU needs to set up in order to implement the direct storage access method provided in the embodiment of the present invention. The content of the direct storage access device described below can be referenced to the content of the method described above.

[0290] In an optional implementation, Fig.16 FIG. 4 shows an optional block diagram of a direct storage access device provided by an embodiment of the present invention, wherein the direct storage access device can be applied to an IOMMU, such as Fig.16 As shown, the direct storage access device may include:

[0291] A request acquisition module 300, used to acquire a DMA request of a direct memory access DMA device, wherein the DMA request includes a virtual machine identifier;

[0292] An address determination module 310, configured to determine a host physical address HPA of memory data to be accessed by the DMA request;

[0293] An address forming module 320, configured to combine the HPA with the virtual machine identifier to form a target HPA;

[0294] The data transmission module 330 is used to control the memory controller by using the target HPA, so that the memory controller encrypts / decrypts data and transmits data on the encrypted memory corresponding to the HPA based on the key corresponding to the virtual machine identifier.

[0295] Optionally, the virtual machine identifier is set in the GPA of the memory that the DMA request needs to access, and the address determination module 310 is used to determine the host physical address HPA of the memory that the DMA request needs to access, including:

[0296] Get the GPA of the memory to be accessed in the DMA request;

[0297] Removing the virtual machine identifier in the GPA;

[0298] Based on the GPA after removing the virtual machine ID, find the corresponding HPA.

[0299] Optionally, an encryption identifier is set in the GPA of the memory data to be accessed by the DMA request, and the address determination module 310 is used to remove the virtual machine identifier in the GPA, and further includes: removing the encryption identifier in the GPA.

[0300] Optionally, the address forming module 320 is used to combine the HPA with the virtual machine identifier to form a target HPA, including:

[0301] Extracting the virtual machine identifier from the GPA;

[0302] The virtual machine identifier is set in the HPA to form a target HPA.

[0303] Optionally, the address forming module 320, used to extract the virtual machine identifier from the GPA, further includes: extracting the encryption identifier from the GPA;

[0304] The address forming module 320 is used to set the virtual machine identifier in the HPA, and further includes: setting the encryption identifier in the HPA.

[0305] The direct storage access device provided in the embodiment of the present invention is introduced below from the perspective of a DMA device. The direct storage access device described below can be considered as a functional module that a DMA device needs to set up in order to implement the direct storage access method provided in the embodiment of the present invention. The content of the direct storage access device described below can be referenced in correspondence with the content of the method described above.

[0306] In an optional implementation, Fig.17 Another optional block diagram of a direct storage access device provided by an embodiment of the present invention is shown. The direct storage access device can be applied to a DMA device, such as Fig.17 As shown, the direct storage access device may include:

[0307] A command receiving module 400, configured to receive a DMA command, wherein the DMA command includes a virtual machine identifier;

[0308] A request sending module 410 is used to send a DMA request to an input / output memory management unit IOMMU in response to the DMA command; the DMA request includes the virtual machine identifier, so that the memory controller encrypts / decrypts data and transmits data for the encrypted memory to be accessed based on the key corresponding to the virtual machine identifier;

[0309] The data receiving module 420 is used to receive data transmitted by the memory controller when the memory controller responds to the DMA request to transmit data of the encrypted memory.

[0310] Optionally, in the DMA request, the virtual machine identifier is set in the client physical address GPA of the memory that the DMA device needs to access.

[0311] Optionally, the direct storage access device further includes:

[0312] The first channel building module 430 is used to build a secure channel for transmitting command data.

[0313] Optionally, the first channel building module 430 is used to build a secure channel for transmitting command data, including:

[0314] Receiving a first ciphertext, where the first ciphertext is encrypted by a public key generated by a device driver using a chip public key;

[0315] Decrypting the first ciphertext using the chip private key to obtain the public key generated by the device driver;

[0316] Generate channel key information;

[0317] Encrypting the channel key information with the public key obtained by decryption to form a second ciphertext;

[0318] The second ciphertext is sent to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by it, obtains the channel key information, and forms a secure channel with encryption protection.

[0319] Optionally, the first channel construction module 430 is used to receive a first ciphertext, specifically, to receive a secure channel creation command, where the secure channel creation command includes the first ciphertext.

[0320] Optionally, the direct storage access device further includes:

[0321] The command decryption module 440 is used to decrypt the DMA command based on the channel key information of the secure channel.

[0322] Optionally, the direct storage access device further includes:

[0323] The data storage module 450 is configured to store the transmitted data in an on-chip memory corresponding to the context identifier based on the context identifier of the transmitted data.

[0324] The direct storage access device provided in the embodiment of the present invention is introduced below from the perspective of the device driver. The direct storage access device described below can be considered as a functional module that the device driver needs to set in order to implement the direct storage access method provided in the embodiment of the present invention. The content of the direct storage access device described below can be referenced to the content of the method described above.

[0325] In an optional implementation, Fig.18 1 shows another optional block diagram of a direct storage access device provided by an embodiment of the present invention, the direct storage access device can be applied to a device driver, such as Fig.18 As shown, the direct storage access device may include:

[0326] The identification acquisition module 500 is used to obtain the virtual machine identification corresponding to the direct memory access DMA command after the encryption virtual machine generates the DMA command;

[0327] An identification setting module 510, used to set the virtual machine identification in the DMA command;

[0328] The command sending module 520 is used to send the DMA command with the virtual machine identifier to the DMA device.

[0329] Optionally, the identification acquisition module 500 is further used to:

[0330] Get the security status of the virtual machine that generated the DMA command;

[0331] When the virtual machine that generates the DMA command is an encrypted virtual machine, the step of obtaining the virtual machine identifier corresponding to the DMA command is performed.

[0332] Optionally, the identification acquisition module 500 is used to obtain the virtual machine identification corresponding to the DMA command, specifically, to read the virtual machine identification stored in a model-specific register, where the model-specific register corresponds to the encrypted virtual machine that generates the DMA command.

[0333] Optionally, the identifier acquisition module 500 is used to acquire the virtual machine identifier corresponding to the DMA command, including:

[0334] Sending a virtual machine identification acquisition request to the encryption virtual machine, so that the encryption virtual machine can securely call the virtual machine identification in the security processor;

[0335] Get the virtual machine identifier obtained by the encrypted virtual machine security call.

[0336] Optionally, the DMA command includes the client physical address GPA of the memory that the DMA device needs to access, and the identifier setting module 510 is used to set the virtual machine identifier in the DMA command, specifically, to set the virtual machine identifier in the client physical address GPA.

[0337] Optionally, the identifier setting module 510 is further used to set an encryption identifier in a DMA command, where the encryption identifier is used to indicate whether the memory to be accessed in the DMA command is an encrypted memory.

[0338] Optionally, the DMA command includes a client physical address GPA for transmitting memory data to the DMA device, and the identifier setting module 510 is further used to set an encryption identifier in the DMA command, specifically, to set the encryption identifier in the client physical address GPA.

[0339] Optionally, the direct storage access device further includes:

[0340] A second channel building module 530, used to build a secure channel for transmitting command data;

[0341] The command sending module 520 is used to send the DMA command with the virtual machine identifier to the DMA device, including:

[0342] Encrypting the DMA command based on the channel key information of the secure channel to form encrypted command data;

[0343] The encrypted command data is sent to a DMA device.

[0344] Optionally, the second channel building module 530 is used to build a secure channel for transmitting command data, including:

[0345] Generate matching public and private keys;

[0346] Obtain a chip public key of the DMA device, and encrypt the generated public key using the chip public key to form a first ciphertext;

[0347] Sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext;

[0348] receiving the second ciphertext;

[0349] The second ciphertext is decrypted using a private key to obtain the channel key information, so as to form a secure channel with encryption protection.

[0350] Optionally, the second channel construction module 530, used to send the first ciphertext to the DMA device, includes:

[0351] Send a secure channel creation command, where the secure channel creation command includes the first ciphertext.

[0352] The command data transmission device provided in the embodiment of the present invention is introduced below from the perspective of the device driver. The command data transmission device described below can be considered as a functional module that the device driver needs to set up in order to implement the command data transmission method provided in the embodiment of the present invention. The content of the command data transmission device described below can be referenced in correspondence with the content of the method described above.

[0353] In an optional implementation, Fig.19 FIG. 1 shows an optional block diagram of a command data transmission device provided by an embodiment of the present invention, wherein the command data transmission device can be applied to a device driver, such as Fig.19 As shown, the command data transmission device may include:

[0354] A third channel construction module 600 is used to construct a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism;

[0355] The encrypted command forming module 610 is used to encrypt the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data;

[0356] The encrypted command sending module 620 is used to send the encrypted command data.

[0357] Optionally, the data transmission channel between the device driver and the direct memory access DMA device further includes a guide channel, and the guide channel is transmitted in plain text; the command data transmission device further includes:

[0358] The resource determination module 630 is used to determine whether the resource accessed by the command data to be transmitted by the device driver is a secure resource;

[0359] When the resource accessed by the command data to be transmitted by the device driver is a secure resource, the encryption command forming module 610 encrypts the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data; when the resource accessed by the command data to be transmitted by the device driver is not a secure resource, the command data is sent through the boot channel.

[0360] Optionally, the command data transmission device further includes:

[0361] A command determination module 640 is used to determine whether the command data to be transmitted includes a read command;

[0362] If yes, it is determined that an access error occurs. If no, the encryption command forming module 610 encrypts the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data.

[0363] Optionally, the third channel building module 600 is used to build a secure channel for transmitting command data, including:

[0364] Receiving a first ciphertext, where the first ciphertext is encrypted by a public key generated by a device driver using a chip public key;

[0365] Decrypting the first ciphertext using the chip private key to obtain the public key generated by the device driver;

[0366] Generate channel key information;

[0367] Encrypting the channel key information with the public key obtained by decryption to form a second ciphertext;

[0368] The second ciphertext is sent to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by it, obtains the channel key information, and forms a secure channel with encryption protection.

[0369] Optionally, the third channel construction module 600 is used to receive a first ciphertext, specifically, to receive a secure channel creation command, where the secure channel creation command includes the first ciphertext.

[0370] Optionally, the channel key information includes a channel key, and at least one or more of an integrity key, an initial vector, and a rotation value.

[0371] Optionally, the channel key information includes a channel key, an integrity key, an initial vector and a rotation value;

[0372] The encrypted command forming module 610 is used to encrypt the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data, including:

[0373] Encrypt the command data to be transmitted using the channel key to obtain encrypted ciphertext;

[0374] The integrity verification ciphertext is calculated using the integrity key, the encrypted ciphertext and the rotation value;

[0375] The encrypted ciphertext and the integrity verification ciphertext are used as the encrypted command data.

[0376] The command data transmission device provided in the embodiment of the present invention is introduced below from the perspective of the DMA device. The command data transmission device described below can be considered as a functional module that the DMA device needs to set up in order to implement the command data transmission method provided in the embodiment of the present invention. The content of the command data transmission device described below can be referenced to the content of the method described above.

[0377] In an optional implementation, Fig. 20 Another optional block diagram of the command data transmission device provided by the embodiment of the present invention is shown, and the command data transmission device can be applied to a DMA device, such as Fig. 20 As shown, the command data transmission device may include:

[0378] A fourth channel construction module 700 is used to construct a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism;

[0379] The encryption command acquisition module 710 is used to acquire encryption command data;

[0380] The command decryption module 720 is used to decrypt the encrypted command data based on the channel key information of the secure channel to obtain command data.

[0381] Optionally, the fourth channel building module 700 is used to build a secure channel for transmitting command data, including:

[0382] Generate matching public and private keys;

[0383] Obtain a chip public key of the DMA device, and encrypt the generated public key using the chip public key to form a first ciphertext;

[0384] Sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext;

[0385] receiving the second ciphertext;

[0386] The second ciphertext is decrypted using a private key to obtain the channel key information, so as to form a secure channel with encryption protection.

[0387] Optionally, the channel key information includes a channel key, and at least one or more of an integrity key, an initial vector, and a rotation value.

[0388] Optionally, the channel key information includes a channel key, an integrity key, an initial vector and a rotation value; the encryption command data includes an encrypted ciphertext and an integrity verification ciphertext;

[0389] The command decryption module 720 is used to decrypt the encrypted command data based on the channel key information of the secure channel to obtain the command data, including:

[0390] Verify the integrity verification ciphertext using the integrity key, the encrypted ciphertext and the rotation value;

[0391] If the verification is successful, the encrypted ciphertext is decrypted using the channel key to obtain the command data.

[0392] Optionally, the command data transmission device further includes:

[0393] The memory allocation module 730 is used to allocate on-chip memory to the corresponding command based on the context identifier in the command data.

[0394] Optionally, the memory allocation module 730 is used to allocate on-chip memory to the corresponding command based on the context identifier in the command data, including:

[0395] The current context identifier and the on-chip memory allocated thereto are updated in the identifier record table, wherein the identifier record table is used to record the corresponding relationship between the context identifier and the on-chip memory allocated thereto.

[0396] Optionally, the command data transmission device further includes:

[0397] The command data storage module 740 is configured to store the command data to an on-chip memory corresponding to the context identifier based on the context identifier in the command data.

[0398] An embodiment of the present invention further provides an IOMMU, which can be configured to execute the direct storage access method from the IOMMU perspective provided in the embodiment of the present invention. The specific content can be referred to the description of the corresponding part above, and will not be further introduced here.

[0399] An embodiment of the present invention also provides a DMA device, which can be configured to execute the direct storage access method from the perspective of the DMA device provided in the embodiment of the present invention, or the command data transmission method from the perspective of the DMA device provided in the embodiment of the present invention. The specific content can be referred to the description of the corresponding part above, and will not be further elaborated here.

[0400] An embodiment of the present invention further provides an electronic device, such as a cloud host, which may include the above-mentioned IOMMU, DMA device and device driver, and the device driver may be configured to execute the direct storage access method from the device driver perspective provided by the embodiment of the present invention, or the command data transmission method from the device driver perspective provided by the embodiment of the present invention. The optional structure of the electronic device may be as follows: Figure 3 As shown, no further introduction is given here.

[0401] Although the embodiments of the present invention are disclosed above, the present invention is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the scope defined by the claims.

Claims

1. A direct storage access method, It is characterized in that Applicable to the input and output memory management unit IOMMU, including: Obtain a DMA request for direct storage access to a DMA device, the DMA request including a virtual machine identifier; wherein the DMA request is obtained based on a DMA device responding to a DMA command, and the DMA command is transmitted to the DMA device through a secure channel for transmitting command data; the DMA device receives a first ciphertext, the first ciphertext is encrypted by a public key generated by a chip public key for a device driver, the first ciphertext is decrypted using a chip private key to obtain a public key generated by the device driver, channel key information is generated, the channel key information is encrypted using the decrypted public key to form a second ciphertext, the second ciphertext is sent to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by the device driver, obtains the channel key information, and forms a secure channel with encryption protection; Determine the host physical address HPA of the memory data to be accessed by the DMA request; Combining the HPA with the virtual machine identifier to form a target HPA; The target HPA is used to control a memory controller so that the memory controller encrypts / decrypts data and transmits data on the encrypted memory corresponding to the HPA based on a key corresponding to the virtual machine identifier.

2. The method according to claim 1, It is characterized in that The virtual machine identifier is set in the GPA of the memory required to be accessed by the DMA request, and the determining of the host physical address HPA of the memory required to be accessed by the DMA request includes: Get the GPA of the memory to be accessed in the DMA request; Removing the virtual machine identifier in the GPA; Based on the GPA after removing the virtual machine ID, find the corresponding HPA.

3. The method according to claim 2, It is characterized in that An encryption identifier is set in the GPA of the memory data to be accessed by the DMA request, and the step of removing the virtual machine identifier in the GPA further includes: removing the encryption identifier in the GPA.

4. The method according to claim 3, It is characterized in that The combining the HPA with the virtual machine identifier to form a target HPA includes: Extracting the virtual machine identifier from the GPA; The virtual machine identifier is set in the HPA to form a target HPA.

5. The method according to claim 4, It is characterized in that The extracting the virtual machine identifier in the GPA further includes: extracting the encryption identifier in the GPA; The step of setting the virtual machine identifier in the HPA further includes: setting the encryption identifier in the HPA.

6. A direct storage access method, It is characterized in that Applicable to direct memory access DMA devices, including: Receiving a DMA command, wherein the DMA command includes a virtual machine identifier; Constructing a secure channel for transmitting command data, including: receiving a first ciphertext, the first ciphertext being encrypted by a public key generated by a chip public key for a device driver; decrypting the first ciphertext using a chip private key to obtain the public key generated by the device driver; generating channel key information; encrypting the channel key information using the decrypted public key to form a second ciphertext; sending the second ciphertext to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by the device driver, obtains the channel key information, and forms a secure channel with encryption protection; In response to the DMA command, a DMA request is sent to an input / output memory management unit IOMMU; the DMA request includes the virtual machine identifier, so that the memory controller encrypts / decrypts data and transmits data on the encrypted memory to be accessed based on a key corresponding to the virtual machine identifier; When the memory controller responds to the DMA request to perform data transmission of the encrypted memory, the data transmitted by the memory controller is received.

7. The method according to claim 6, It is characterized in that In the DMA request, the virtual machine identifier is set in the client physical address GPA of the memory that the DMA device needs to access.

8. The method according to claim 6, It is characterized in that The receiving the first ciphertext specifically includes receiving a secure channel creation command, wherein the secure channel creation command includes the first ciphertext.

9. The method according to claim 6, It is characterized in that After the step of receiving the DMA command and before the step of sending a DMA request to the input / output memory management unit IOMMU in response to the DMA command, the method further includes: The DMA command is decrypted based on the channel key information of the secure channel.

10. The method according to claim 6, It is characterized in that After the step of receiving the data transmitted by the memory controller, the method further includes: Based on the context identifier of the transmitted data, the transmitted data is stored in an on-chip memory corresponding to the context identifier.

11. A direct storage access method, It is characterized in that Applicable to device drivers, including: After the encrypted virtual machine generates a direct memory access DMA command, obtaining a virtual machine identifier corresponding to the DMA command; Setting the virtual machine identifier in a DMA command; Constructing a secure channel for transmitting command data, including: generating matching public keys and private keys; obtaining a chip public key of a DMA device, and encrypting the generated public key with the chip public key to form a first ciphertext; sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext; receiving the second ciphertext; decrypting the second ciphertext with a private key to obtain the channel key information, so as to form a secure channel with encryption protection; A DMA command carrying the virtual machine identifier is sent to the DMA device.

12. The method according to claim 11, It is characterized in that After obtaining the DMA command and before obtaining the virtual machine identifier corresponding to the DMA command, the method further includes: Get the security status of the virtual machine that generated the DMA command; When the virtual machine that generates the DMA command is an encrypted virtual machine, the step of obtaining the virtual machine identifier corresponding to the DMA command is performed.

13. The method according to claim 11, It is characterized in that The obtaining of the virtual machine identifier corresponding to the DMA command is specifically to read the virtual machine identifier stored in a model specific register, where the model specific register corresponds to the encrypted virtual machine that generates the DMA command.

14. The method according to claim 11, It is characterized in that The obtaining the virtual machine identifier corresponding to the DMA command includes: Sending a virtual machine identification acquisition request to the encryption virtual machine, so that the encryption virtual machine can securely call the virtual machine identification in the security processor; Get the virtual machine identifier obtained by the encrypted virtual machine security call.

15. The method according to claim 11, It is characterized in that The DMA command includes the client physical address GPA of the memory that the DMA device needs to access, and setting the virtual machine identifier in the DMA command specifically includes setting the virtual machine identifier in the client physical address GPA.

16. The method according to claim 11, It is characterized in that The step of setting the virtual machine identifier in the DMA command also includes setting an encryption identifier in the DMA command, where the encryption identifier is used to indicate whether the memory to be accessed in the DMA command is encrypted memory.

17. The method according to claim 16, It is characterized in that The DMA command includes a client physical address GPA for transmitting memory data to the DMA device, and setting the encryption identifier in the DMA command specifically includes setting the encryption identifier in the client physical address GPA.

18. The method according to claim 11, It is characterized in that The step of sending the DMA command with the virtual machine identifier to the DMA device includes: Encrypting the DMA command based on the channel key information of the secure channel to form encrypted command data; The encrypted command data is sent to a DMA device.

19. The method according to claim 11, It is characterized in that The sending the first ciphertext to the DMA device includes: Send a secure channel creation command, where the secure channel creation command includes the first ciphertext.

20. A command data transmission method, It is characterized in that Applicable to device drivers, including: Constructing a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism; the constructing a secure channel for transmitting command data includes: generating a matching public key and a private key; obtaining a chip public key of a DMA device, and encrypting the generated public key with the chip public key to form a first ciphertext; sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext; receiving the second ciphertext; decrypting the second ciphertext with a private key to obtain the channel key information, so as to form a secure channel with encryption protection; Encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data; The encrypted command data is sent.

21. The method according to claim 20, It is characterized in that The data transmission channel between the device driver and the direct memory access DMA device also includes a boot channel, and the boot channel is transmitted in plain text; after the step of constructing a secure channel for transmitting command data, before the step of encrypting the command data to be transmitted based on the channel key information of the secure channel, it also includes: Determine whether the resource accessed by the command data to be transmitted by the device driver is a secure resource; When the resource accessed by the command data to be transmitted by the device driver is a secure resource, the step of executing the channel key information based on the secure channel, encrypting the command data to be transmitted, and forming encrypted command data; when the resource accessed by the command data to be transmitted by the device driver is not a secure resource, sending the command data through the boot channel.

22. The method according to claim 21, It is characterized in that After determining whether the resource accessed by the command data sent by the device driver is a secure resource, before encrypting the command data to be transmitted based on the channel key information of the secure channel to form the encrypted command data, it also includes determining whether the command data to be transmitted includes a read command; If yes, it is determined that an access error occurs; if no, the step of encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data is executed.

23. The method according to claim 20, It is characterized in that The channel key information includes a channel key, and at least one or more of an integrity key, an initial vector, and a round value.

24. The method according to claim 23, It is characterized in that The channel key information includes a channel key, an integrity key, an initial vector and a rotation value; The step of encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data includes: Encrypt the command data to be transmitted using the channel key to obtain encrypted ciphertext; The integrity verification ciphertext is calculated using the integrity key, the encrypted ciphertext and the rotation value; The encrypted ciphertext and the integrity verification ciphertext are used as the encrypted command data.

25. A command data transmission method, It is characterized in that Applicable to direct memory access DMA devices, including: Constructing a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism; the constructing a secure channel for transmitting command data comprises: receiving a first ciphertext, wherein the first ciphertext is encrypted by a public key generated by a chip public key for a device driver; decrypting the first ciphertext using a chip private key to obtain a public key generated by the device driver; generating channel key information; encrypting the channel key information using the decrypted public key to form a second ciphertext; sending the second ciphertext to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by the device driver, obtains the channel key information, and forms a secure channel with encryption protection; Get encrypted command data; The encrypted command data is decrypted based on the channel key information of the secure channel to obtain command data.

26. The method according to claim 25, It is characterized in that The channel key information includes a channel key, and at least one or more of an integrity key, an initial vector, and a round value.

27. The method according to claim 26, It is characterized in that The channel key information includes a channel key, an integrity key, an initial vector and a rotation value; the encryption command data includes an encrypted ciphertext and an integrity verification ciphertext; The decrypting the encrypted command data based on the channel key information of the secure channel to obtain the command data comprises: Verify the integrity verification ciphertext using the integrity key, the encrypted ciphertext and the rotation value; If the verification is successful, the encrypted ciphertext is decrypted using the channel key to obtain the command data.

28. The method according to claim 25, It is characterized in that After the step of decrypting the encrypted command data to obtain the command data, the method further includes: Based on the context identifier in the command data, an on-chip memory is allocated for the corresponding command.

29. The method according to claim 28, It is characterized in that The allocating on-chip memory for the corresponding command based on the context identifier in the command data includes: The current context identifier and the on-chip memory allocated thereto are updated in the identifier record table, wherein the identifier record table is used to record the corresponding relationship between the context identifier and the on-chip memory allocated thereto.

30. The method according to claim 28, It is characterized in that After allocating on-chip memory for the corresponding command based on the context identifier in the command data, the method further includes: Based on the context identifier in the command data, the command data is stored in an on-chip memory corresponding to the context identifier.

31. A direct storage access device, It is characterized in that include: Request acquisition module, configured to acquire a DMA request of a direct memory access (DMA) device, where the DMA request includes a virtual machine identifier; wherein, the DMA request is obtained based on the DMA device's response to a DMA command, and the DMA command is transmitted to the DMA device through a secure channel for transmitting command data; the DMA device receives a first ciphertext, which is encrypted by a public key generated by a chip public key for a device driver, decrypts the first ciphertext using a chip private key to obtain the public key generated by the device driver, generates channel key information, encrypts the channel key information using the decrypted public key to form a second ciphertext, and sends the second ciphertext to the device driver so that the device driver decrypts the second ciphertext based on the private key it generates to obtain the channel key information, thereby forming a secure channel with encryption protection; Address determination module, configured to determine the host physical address (HPA) of the memory data to be accessed by the DMA request; Address formation module, configured to combine the HPA with the virtual machine identifier to form a target HPA; Data transmission module, configured to control a memory controller using the target HPA, so that the memory controller performs data encryption / decryption and data transmission on the encrypted memory corresponding to the HPA based on the key corresponding to the virtual machine identifier.

32. A direct memory access device, characterized in that, it includes: Command reception module, configured to receive a DMA command, where the DMA command includes a virtual machine identifier; First channel construction module, configured to construct a secure channel for transmitting command data, including: receiving a first ciphertext, which is encrypted by a public key generated by a chip public key for a device driver; decrypting the first ciphertext using a chip private key to obtain the public key generated by the device driver; generating channel key information; encrypting the channel key information using the decrypted public key to form a second ciphertext; sending the second ciphertext to the device driver so that the device driver decrypts the second ciphertext based on the private key it generates to obtain the channel key information, thereby forming a secure channel with encryption protection; Request sending module, configured to, in response to the DMA command, send a DMA request to an input / output memory management unit (IOMMU); the DMA request includes the virtual machine identifier, so that the memory controller performs data encryption / decryption and data transmission on the encrypted memory to be accessed based on the key corresponding to the virtual machine identifier; Data reception module, configured to receive the data transmitted by the memory controller when the memory controller responds to the DMA request for data transmission of the encrypted memory.

33. A direct memory access device, characterized in that, it includes: Identifier acquisition module, configured to acquire the virtual machine identifier corresponding to the DMA command after an encrypted virtual machine generates a direct memory access (DMA) command; Identifier setting module, configured to set the virtual machine identifier in the DMA command; The second channel construction module is used to construct a secure channel for transmitting command data, including: generating matching public keys and private keys; obtaining a chip public key of a DMA device, and encrypting the generated public key with the chip public key to form a first ciphertext; sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext; receiving the second ciphertext; decrypting the second ciphertext with a private key to obtain the channel key information, so as to form a secure channel with encryption protection; The command sending module is used to send the DMA command with the virtual machine identifier to the DMA device.

34. A command data transmission device, It is characterized in that include: The third channel construction module is used to construct a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism; constructing a secure channel for transmitting command data includes: generating a matching public key and a private key; obtaining a chip public key of a DMA device, and encrypting the generated public key with the chip public key to form a first ciphertext; sending the first ciphertext to the DMA device so that the DMA device generates channel key information, and encrypts the channel key information based on the public key obtained by decryption to form a second ciphertext; receiving the second ciphertext; decrypting the second ciphertext with a private key to obtain the channel key information, so as to form a secure channel with encryption protection; An encrypted command forming module, used for encrypting the command data to be transmitted based on the channel key information of the secure channel to form encrypted command data; The encrypted command sending module is used to send the encrypted command data.

35. A command data transmission device, It is characterized in that include: A fourth channel construction module is used to construct a secure channel for transmitting command data, wherein the secure channel realizes data transmission based on a data encryption and decryption mechanism; the construction of a secure channel for transmitting command data includes: receiving a first ciphertext, wherein the first ciphertext is encrypted by a public key generated by a device driver using a chip public key; decrypting the first ciphertext using a chip private key to obtain a public key generated by the device driver; generating channel key information; encrypting the channel key information using the decrypted public key to form a second ciphertext; sending the second ciphertext to the device driver, so that the device driver decrypts the second ciphertext based on the private key generated by the device driver, obtains the channel key information, and forms a secure channel with encryption protection; An encrypted command acquisition module, used to acquire encrypted command data; The command decryption module is used to decrypt the encrypted command data based on the channel key information of the secure channel to obtain command data.

36. An input-output memory management unit IOMMU, It is characterized in that The IOMMU is configured to execute the direct memory access method according to any one of claims 1 to 5.

37. A direct memory access DMA device, It is characterized in that The DMA device is configured to execute the direct storage access method according to any one of claims 6 to 10, and / or to execute the command data transmission method according to any one of claims 25 to 30.

38. The apparatus according to claim 37, It is characterized in that The DMA device includes a cryptographic coprocessor, and the cryptographic coprocessor is used to provide encryption and decryption services and digest calculation services for the DMA device.

39. An electronic device, It is characterized in that It comprises an input-output memory management unit as described in claim 36, a direct memory access DMA device as described in any one of claims 37-38, and a device driver, wherein the device driver is configured to execute the direct memory access method as described in any one of claims 11-19, and / or execute the command data transmission method as described in any one of claims 20-24.

Citation Information

Patent Citations

  • Information configuration method, direct storage access method and related devices

    CN112433817A

  • Data processing method, migration method of secure virtual machine, related device and architecture

    CN113342473A