Security Container Isolation Method and Device Based on MIPS64 Instruction Set

Through QEMU-KVM hardware virtualization technology and module optimization, a virtual machine with MIPS64 instruction set is created, and secure container isolation based on MIPS64 instruction set is realized, which solves the problem that the existing technology cannot adapt to the Loongson CPU of the MIPS64 instruction set, and provides an independent and secure container operation environment.

CN114253655BActive Publication Date: 2025-07-29DIANKEYUN (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011017106.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-24
Publication Date
2025-07-29
Estimated Expiration
2040-09-24

AI Technical Summary

Technical Problem

It is difficult for the prior art to realize a secure and strongly isolated container operating environment on a container platform based on the MIPS64 instruction set. Illegal users can use permission vulnerabilities to attack, and the existing secure container technical solutions cannot adapt to the Loongson CPU of the MIPS64 instruction set.

Method used

Using QEMU-KVM hardware virtualization technology, combining QEMU and KVM modules, we create a virtual machine containing the MIPS64 instruction set core, integrate virtualization tool interfaces and I/O components, optimize the module components of the container runtime, and realize the independent operating environment of each container.

Benefits of technology

The MIPS64 instruction set platform is a secure and strongly isolated container operation environment, which improves the security level of the container, dynamically adjusts resource configuration, and ensures the independent and safe operation of applications in the container.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114253655B_ABST
    Figure CN114253655B_ABST
Patent Text Reader

Abstract

The present invention provides a security container isolation method and device based on the MIPS64 instruction set. The method includes the following steps: Select a node for the service to be deployed based on the workload deployment information from the user terminal and the cluster load status. The workload deployment information includes the name and / or address of the container image used by the workload; Create a virtual machine that supports hardware acceleration and includes a MIPS64 instruction set kernel on the node of the service to be deployed by using QEMU-KVM, and start the virtual machine by using the physical machine kernel. Both the physical machine kernel and the virtual machine kernel include a basic communication component, a container runtime-related module component, and a kernel-based virtualization module; Load the container runtime in the virtual machine kernel and the physical machine kernel. The container runtime in the physical machine kernel integrates a virtualization tool interface and an I / O component. The present invention runs the container at a higher security level, creates an independent and secure strong isolation running environment for the application programs in the container, and provides a higher security level for business applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing, specifically to the underlying method for running containers in a container cloud platform, and particularly to a secure container isolation method and device based on the MIPS64 instruction set. Background Art

[0002] Container technology is an indispensable part of the development of the cloud industry in recent years. Applying container technology services to a cloud computing platform gives rise to container cloud platform technology. Container technology is a lightweight operating system layer virtualization technology relying on kernel modules. The core of container technology is to group and partition available resources such as computing, storage, and network in the operating system, enabling applications to run independently in each resource group.

[0003] To complete resource partitioning and control, container technology mainly relies on two major working mechanisms at the kernel layer: namespaces (used for virtual isolation of user space and allocating independent system resources) and control groups (i.e., Linux ControlGroup, used to manage and control the behavior of processes using resources in a grouped manner). This working mode of container technology allows each application to have its own isolated environment and also enables the reuse of basic functional components at the bottom layer of the operating system. This isolation method is essentially a weak isolation mechanism formed by resource slicing in the kernel state of the operating system and resource restriction in the user state. Although the working mechanism of containers is simple and efficient, in some scenarios, there will be serious security risks, and illegal users can use privilege - type vulnerabilities in the physical machine kernel to operate on container applications that do not belong to that user. Therefore, for some special scenarios, special means are needed to strengthen the running environment of containers to improve their security level and prevent illegal users from damaging the container running environment and the applications inside.

[0004] In the traditional working mode, the method for running containers based on the MIPS64 instruction set is as Figure 1 shown, and correspondingly, the basic infrastructure for running containers based on the MIPS64 instruction set is as Figure 2 shown. The main work of this architecture is to adapt to the container runtime based on the MIPS64 instruction set. The container runtime communicates directly with the operating system kernel of the physical machine to obtain and allocate various resources required for each container, and then creates and manages the running state of the containers. Therefore, essentially, each container shares the kernel functions of the host. According to the Figure 2 shown architecture, once a user in a container uses illegal means or program vulnerabilities to obtain permissions outside its container environment, they can directly communicate with the container runtime or even the kernel of the physical machine and implement a destructive attack from the inside.

[0005] Container security technology is a complete technical solution to ensure the integrity of containers. Currently, on container platforms based on the x86 instruction set, there are different secure container technology solutions, such as Google's sandbox container technology gVisor and the open-source strong isolation container runtime Kata, etc. These technologies are implemented for the mainstream instruction set x86 and can be directly used on Intel product lines. Although these solutions have different specific implementations, their main idea is to build a sandboxed runtime environment for the operation of each container, and each container is located in its own independent sandbox to ensure that the hardware resources used by each container application are completely independent and do not affect each other. Such an implementation solution poses strict functional support and technical requirements for both the kernel and the hardware architecture. Therefore, even open-source technology solutions are difficult to apply outside of platforms that do not natively support them.

[0006] Since the MIPS64 instruction set is mainly supported and used by the domestic CPU LoongArch, global advanced technologies do not consider adapting to the MIPS64 instruction set when being implemented; moreover, optimization work related to instruction sets usually does not consider non-mainstream instruction set architectures. Therefore, these secure container technology solutions used on x86 instruction set container platforms cannot be used on LoongArch CPUs based on the MIPS64 instruction set.

[0007] Therefore, how to implement a complete and strongly isolated secure container technology solution for servers using the MIPS64 instruction set is an urgent problem to be solved. Summary of the Invention

[0008] In view of the problems existing in the prior art, embodiments of the present invention provide a secure container isolation method and device based on the MIPS64 instruction set to eliminate or improve one or more defects existing in the prior art.

[0009] The technical solution of the present invention is as follows:

[0010] A secure container isolation method based on the MIPS64 instruction set, the method includes the following steps:

[0011] Select a node for the service to be deployed based on the workload deployment information from the user terminal and the cluster load status, where the workload deployment information includes: the name / and or address of the container image used by the workload;

[0012] Create a virtual machine containing a virtual machine kernel on the node for the service to be deployed using QEMU-KVM, and start the virtual machine using the physical machine kernel, where both the physical machine kernel and the virtual machine kernel include: a basic communication component, a container runtime related module component, and a KVM module;

[0013] Load a container runtime in the virtual machine kernel to start the container by using the container runtime;

[0014] Send the container running information in the virtual machine back to the container runtime on the physical machine kernel through network transmission, where the container runtime on the physical machine kernel integrates a virtualization tool interface and an I / O component.

[0015] Optionally, the QEMU-KVM includes a trimmed QEMU and a KVM (Kernel-based Virtual Machine) module. The trimmed QEMU has some or all of the modules other than the modules related to the basic core hardware resource simulation mechanism trimmed off, and the KVM module is used to improve the running efficiency of the MIPS64 instruction set in the virtual machine.

[0016] Optionally, before selecting a node for deploying the workload, the method further includes: compiling QEMU from source code for the container cloud platform, trimming the functional modules of QEMU, and adding a kernel-based virtualization module KVM.

[0017] Optionally, before loading the virtual machine kernel, the method further includes the following steps: modifying the kernel configuration file before the virtual machine kernel is compiled; adding container runtime-related modules; encapsulating the container runtime module in the virtual machine kernel.

[0018] Optionally, the step of encapsulating the container runtime module in the virtual machine kernel includes: encapsulating the container runtime components into the first process of the kernel; the step of loading the container runtime by using the kernel of the created virtual machine includes: running the first process and loading the container runtime after the virtual machine kernel is initialized; the method further includes: transmitting a container image specified by a user to the virtual machine and running an application in the container image.

[0019] Optionally, the method further includes: obtaining the running status and resource overhead of the container from within the virtual machine by using the I / O component and the network component; dynamically adjusting the occupancy configuration of CPU, memory, and / or network resources of the virtual machine based on the resource overhead of the container by using the virtualization tool interface.

[0020] In the embodiment of the present invention, the workload deployment information further includes the name of the workload and the namespace to which the workload is to be incorporated; both the physical machine kernel and the virtual machine kernel are kernels that support hardware virtualization of the MIPS64 instruction set.

[0021] Optionally, the runtime-related module components include: 9P file system module, network block storage device module, fair group scheduling module, Remote Direct Memory Access (RDMA) controller, control group (cgroup) scheduling module, Advanced Configuration and Power Interface module for PCI devices, CompactPCI bus module, ipset framework module, virtual network module, virtual network card module, cgroup scheduling module based on network traffic classification, network hierarchical service scheduling module, module providing element addition and deletion functions for the ipset module, network filter tracking module, general host controller for PCI devices, and fact group policy scheduler.

[0022] Optionally, the modules trimmed from the trimmed QEMU include some or all of the following modules: avx2 module, bluez module, brlapi module, bzip2 module, cocoa module, curses module, dmg module, gtk module, libiscsi module, libusb module, linux-aio module, qom-cast-debug module, sdl module, seccomp module, smartcard module, spice module, tpm module, usb-redir module, vnc module, vnc-jpeg module, vnc-png module, vnc-sasl module, vte module, whpx module, xen module, and xen-pci-passthrough module.

[0023] On the other hand, the present invention also provides a security container isolation device based on the MIPS64 instruction set. The device includes a processor and a memory. Computer instructions are stored in the memory, and the processor is configured to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the device implements the steps of the method described above.

[0024] On the other hand, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described above are implemented.

[0025] The security container isolation method and device based on the MIPS64 instruction set of the present invention can run containers at a higher security level, create an independent and secure strong isolation running environment for the application programs in the containers, and provide a higher security level for business applications.

[0026] Additional advantages, objects, and features of the present invention will be partly set forth in the description which follows, and in part will become obvious to those having ordinary skill in the art upon examination of the following, or may be learned from practice of the present invention. The objects and other advantages of the present invention may be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings.

[0027] Those skilled in the art will understand that the objects and advantages that can be achieved by the present invention are not limited to those specifically described above, and the above and other objects that the present invention can achieve will be more clearly understood from the following detailed description. Brief Description of the Drawings

[0028] The drawings described herein are for further understanding of the present invention, form a part of this application, and do not limit the present invention.

[0029] Figure 1 It is a schematic diagram of the operation method of traditional containers on the LoongArch platform.

[0030] Figure 2 It is a framework schematic diagram of traditional container technology on the LoongArch platform.

[0031] Figure 3 It is a schematic diagram of the operation method of secure containers on the LoongArch platform based on the MIPS64 instruction set in an embodiment of the present invention.

[0032] Figure 4 It is a framework schematic diagram of secure container technology on the LoongArch platform based on the MIPS64 instruction set in an embodiment of the present invention.

[0033] Figure 5 It is a flowchart schematic diagram of the secure container isolation method based on the MIPS64 instruction set in an embodiment of the present invention.

[0034] Figure 6 It is a flowchart schematic diagram of the secure container isolation method based on the MIPS64 instruction set in another embodiment of the present invention. Detailed Description of the Embodiments

[0035] To make the objects, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with the embodiments and the drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but do not limit the present invention.

[0036] Here, it should also be noted that in order to avoid obscuring the present invention with unnecessary details, only the structures and / or processing steps closely related to the solution of the present invention are shown in the drawings, and other details less related to the present invention are omitted.

[0037] It should be emphasized that when the term "comprising / including" is used herein, it refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.

[0038] The secure container technology proposed by the present invention is mainly aimed at the MIPS64 instruction set container cloud platform (hereinafter referred to as the container cloud platform or Loongson platform for short), and secures the container technology in terms of access rights and infrastructure.

[0039] The secure container operation mode of the container cloud platform based on the MIPS64 instruction set provided by the embodiments of the present invention is as Figure 3 shown, and the framework of the secure container technology of the corresponding container cloud platform is as Figure 4 shown. As Figure 3 and Figure 4 shown, the kernel functions of virtual machines are no longer shared among the containers on the same physical machine, and each container has an independent virtual machine kernel supported by hardware virtualization technology. These independent kernels supporting the containers can be the same or different. They only need to meet some common requirements.

[0040] The virtualization technology adopted in container technology can be divided into software virtualization technology and hardware virtualization technology. The most prominent open-source tool representative of software virtualization technology is QEMU, which enables the system and applications to run on virtual hardware (isomorphic or non-isomorphic instruction sets) by means of CPU instruction translation. Hardware virtualization mainly combines the underlying implementation of the operating system and the hardware functions of the CPU to achieve high-performance virtualization. Its typical technical representatives include KVM, XEN, and Intel VT. Hardware virtualization technology requires that the same instruction set as the physical machine must be used in the virtual environment. In the embodiments of the present invention, the adopted virtualization technology is a combination of software virtualization and hardware virtualization, that is, the QEMU-KVM virtualization framework is used, and the KVM technology is used to improve the CPU operation efficiency in the virtual machine. Under this framework, it is required that the containers running on this platform use the MIPS64 instruction set.

[0041] In the embodiments of the present invention, in order to implement the secure container technology architecture as Figure 4 shown, at least the following three levels are transformed: (1) transforming the physical machine kernel; (2) transforming the virtual machine kernel; (3) transforming the container runtime to integrate the virtualization tool interface and input / output components (I / O components) in the container runtime. In addition, the virtualization tool QEMU is trimmed and the KVM module is added to further improve the running efficiency of the container. The following will elaborate on these aspects of the transformation.

[0042] I. Transformation of the physical machine kernel

[0043] In the embodiments of the present invention, the software virtualization tool used is QEMU. QEMU is an open-source simulator and virtual machine manager, and QEMU mainly provides two functions: one is as a user-mode simulator, using the dynamic code translation mechanism to execute code different from the host architecture. The other is as a virtual machine monitor, simulating the entire system, using other VMMs (Xen, KVM, etc.) to utilize the virtualization support provided by the hardware to create virtual machines close to the performance of the host.

[0044] Since this method adopts the QEMU-KVM hardware virtualization technology, there are basic module configuration requirements for the physical machine kernel. The basic components of the physical machine kernel include the following parts: core hardware drivers (such as memory / hard disk / network card / display / keyboard and mouse, etc.); basic hardware resource management programs; permission management components; process (individual program) management components and basic communication components, etc. In the embodiments of the present invention, in order to be compatible with the characteristics of container operation and satisfy the requirements that the containers in the virtual machine and the physical machine can quickly share resources and exchange data, the KVM module and some module components on which the container runtime depends are supplemented in the kernel module. The module components on which the container runtime depends may include: 9P file system module components, network block storage device module components, fair group scheduling module, CPU dynamic frequency control module, ipset framework module, virtual network module, virtual network card module, hardware virtualization acceleration module, cgroup scheduling module based on network traffic classification, network hierarchical service scheduling module, module providing element addition and deletion functions for the ipset module, tracking module of the network filter netfilter, and fact group policy scheduler, etc. Table 1 is the module components supplemented in the physical machine kernel for the security container isolation method based on the MIPS64 instruction set according to the present invention.

[0045] Table 1. Kernel module completion list of the physical machine system

[0046]

[0047]

[0048] The kernel modules listed in Table 1 originally existed in the operating system of the virtual machine. The present invention supplements them to the physical kernel, and the specific implementation of each module will not be described in detail. As shown in Table 1, to complete the supplementation of the modules listed above, the modules can be supplemented by modifying the configuration file before compiling the physical kernel. It should be noted that this kernel runs on the Loongson CPU, and its kernel source code must use a version that supports Loongson. The following Table 2 is an example of the configuration file.

[0049] Table 2. Example of the virtual machine kernel configuration file

[0050]

[0051]

[0052] In the above kernel configuration, y indicates that the compiled result is embedded in the kernel boot file, and m indicates that the compiled result is placed as a module file in the packaged and compressed file of the kernel module. After introducing the compilation work of the above modules into the physical machine kernel, the configured software virtualization software QEMU can directly start the virtual machine using the kernel file.

[0053] II. Container Runtime Integrated with Virtualization Tool Interface

[0054] In order to achieve complete isolation and non-interference of the running environments of each container, in the embodiments of the present invention, before starting a container, the container runtime needs to create a virtual machine for the container to be started and start a kernel (virtual machine kernel) containing the container runtime in the virtual machine to achieve complete independence of the basic running environment of each container. Therefore, in order to add the function of creating a virtual machine and starting a customized kernel to the original workflow of the container cloud platform, the embodiments of the present invention integrate a virtualization tool interface in the container runtime of the physical machine and implement three main functions in the virtualization tool interface: 1) Create a virtual machine and start the corresponding kernel before starting the container; 2) During the running process of the virtual machine and the container, support dynamic adjustment of the virtual machine kernel and memory resources to adapt to the elastic resource adjustment of the container; 3) Shut down the virtual machine when the container stops running.

[0055] Therefore, in the container runtime on the MIPS64 platform, the code is adjusted, and while adding the virtualization tool interface, the CPU and memory scheduling methods on the MIPS64 platform are supplemented to dynamically adjust the resource allocation of the virtual machine in cooperation with the elastic scaling function of the container without stopping the applications or services in the container.

[0056] In addition, an input / output component (I / O component) is additionally added to the modified container runtime for communicating with the kernel in the virtual machine and performing data exchange. There are mainly two means of data exchange: 1) Local data sharing, using the 9P file system to share the file content on the physical machine disk between the virtual machine and the physical machine; 2) Network data sharing, using the NetFilter module or the VHOST communication module to connect the network communication between the virtual machine and the physical machine. These modules are simple to implement, have concentrated functions, and can meet the scenario requirements, only bringing very small resource overhead.

[0057] Container technology does not natively support the MIPS64 instruction set (LoongArch) platform. Therefore, to implement the present invention, first, adaptation work is carried out, and then secure container technology is extended and generated. An example of this adaptation work is as follows:

[0058] 1) Adapt two versions of Docker 18.09.9 and 19.03 on the MIPS64 instruction set (LoongArch) platform, and at the same time adapt the Kubernetes 1.15 version. Among them, Docker includes two tools, runc and containerd.

[0059] runc and containerd are two basic tools for container runtimes. The basic functions of these two tools are basically the same, but the calling interfaces and logics are different. These two tools are used to directly start container images. From the perspective of the overall solution of the container ecosystem, the most commonly used tool is docker (its underlying call selects one of runc and containerd or supports both). However, docker only solves the problem of using container technology on a single machine. It is not easy to use docker in a distributed environment or a cluster. Therefore, in order to use container technology in a distributed environment or a cloud environment, the Kubernetes (k8s) solution emerged. Kubernetes can be said to be the foundation of all current container cloud platforms, and almost all container products of manufacturers are expanded on this basis.

[0060] 2) The container cloud platform, an extension on top of Kubernetes. To achieve the implementation of secure containers, adjustments are required. The most core part is to add virtualization tool interfaces and I / O component interfaces in the containerd component, so that containerd can use these interfaces to control virtual machines.

[0061] 3) Virtualization tool interface: containerd can directly start containers, but a virtual machine needs to be created before starting a secure container. Therefore, the present invention implants the control interface of the virtualization tool (QEMU) in containerd. By adding code, containerd can create and delete virtual machines, and modify the resource occupancy (CPU, storage, network) during the operation of the virtual machine.

[0062] 4) I / O component: As the basic component of the container runtime, containerd needs to monitor the running status of containers in real time. Normally, containers running locally on a physical machine can directly obtain the running status and resource consumption of the containers using the local file interface of containerd. After using secure container technology, the running status and resource consumption of the containers are in the virtual machine. Therefore, this part of the data needs to be passed back from the virtual machine to containerd. Since containerd itself does not support data access in the virtual machine, it is necessary to increase the access ability of the physical machine and virtual machine data interaction interface through the I / O component to achieve the purpose of monitoring the running status of containers in real time.

[0063] III. Transformation of the Virtual Machine Kernel

[0064] The secure container technology of the present invention adds a dedicated virtual machine kernel to each container in the ordinary container running method. To avoid unnecessary performance losses, the embodiments of the present invention streamline and transform the dedicated virtual machine kernel module to minimize the redundant computing and storage resource overhead as much as possible. At the same time, due to the use of hardware virtualization technology, the virtual machine kernel and the physical machine kernel need to be consistent in the selection of some modules responsible for communication and data interaction. On the other hand, a complete container runtime is already running on the physical machine to manage and schedule the containers. Therefore, a simplified container runtime that can ensure the smooth execution of the containers needs to be embedded in the virtual machine kernel.

[0065] Since the actual running environment of the container is in the virtual machine, the virtual machine kernel module also needs to include the basic modules relied on by the container runtime. In the process of implementing the present invention, the inventors found that some module components relied on by the container runtime were missing in the kernel used by Loongson. Therefore, the embodiments of the present invention supplemented the kernel module of the virtual machine. The list of specific kernel modules supplemented in the virtual kernel is shown in Table 3 below.

[0066] Table 3. Kernel Module Completion List of the Virtual Machine System

[0067]

[0068]

[0069] After supplementing the kernel modules relied on by the container runtime in the virtual machine kernel, a simple container runtime can be encapsulated in the virtual machine kernel. More specifically, the present invention encapsulates the container runtime components (such as libcontainer) into the first process of the kernel. The first process is the first process started by the kernel, and its main function is to manage and schedule other processes. In the prior art, if a complete operating system is started, the first step is to load the kernel into the memory, run the first process, and then start other programs supporting the operating system. Therefore, after the present invention embeds the container runtime into the first process, the first process can include a complete container running environment. Combining with the existing process management function, the container image can be run relying on the first process, and the application programs packaged in the image can be started. The first process then manages and monitors the containers. At the same time, the first process can also use the I / O component to interact with the physical machine to help the application programs in the container obtain the required data and enable the container runtime on the physical machine to monitor and manage the containers in the virtual machine.

[0070] IV. Tailoring of the Virtual Machine Manager (QEMU)

[0071] The software virtualization tool used in the present invention is QEMU. QEMU is an open-source emulator and virtual machine manager, which mainly provides two functions. One is to act as a user-mode emulator, using the dynamic code translation mechanism to execute code different from the host architecture. The other is to act as a virtual machine monitor, simulating the entire system, using other VMMs (such as Xen, KVM, etc.) to utilize the virtualization support provided by the hardware to create virtual machines close to the performance of the host.

[0072] The functional structure of the existing software virtualization tool QEMU is relatively complex. In the embodiments of the present invention, only the most basic core hardware resource simulation of QEMU is required. Therefore, in the present invention, in order to improve its runtime performance, in addition to modifying the code during the compilation of QEMU to adapt to the Loongson CPU (based on MIPS64 instructions), QEMU is also customized and trimmed. The so-called "trimming" refers to functional streamlining and / or individual function optimization, retaining the hardware simulation functions of the CPU, memory, storage, instruction translation mechanism, and network, and disabling the simulation components and functional modules that are not required in the container cloud platform scenario, thereby improving the running efficiency of QEMU itself. The list of modules trimmed in QEMU is shown in Table 4.

[0073] Table 4. List of modules trimmed in QEMU

[0074] Module Name Function Description avx2 Advanced Vector Extensions Instruction Support bluez Bluetooth Function Emulation brlapi Braille Terminal Support bzip2 Compression Function Support cocoa iOS Mac Foundation Framework Support curses curses Graphics Output Module dmg DMG Image Module gtk Display Output Module Implemented Using GTK Framework libiscsi iSCSI Device Bus Module libusb USB Device Bus Module linux-aio Asynchronous I / O Module qom-cast-debug QEMU Object Model Debugging Function sdl Display Output Module Implemented Using SDL Framework seccomp Secure Computing Mode Support smartcard Smart Card Module spice spice Graphics Transfer Protocol Support tpm Trusted Platform Module usb-redir usb Peripheral Redirection Module vnc vnc Graphics Transfer Protocol Support vnc-jpeg vnc Graphics Transfer Protocol Support vnc-png vnc Graphics Transfer Protocol Support vnc-sasl vnc Graphics Transfer Protocol Support vte Virtual Terminal Environment Support whpx Windows Hypervisor Platform Hardware Acceleration Module xen xen Para-virtualization Acceleration Module xen-pci-passthrough pci Device Passthrough Technology Support

[0075] The trimmed modules listed in Table 4 are only examples. Based on the module composition of QEMU, there may also be fewer modules. Of course, there may also be more modules. The trimmed QEMU is intended to retain the KVM module and the modules related to the basic core hardware resource simulation mechanism while trimming other parts or all of the modules. Among them, in order to make full use of the hardware virtualization technology, some functional modules are added during the QEMU configuration process, and the list is shown in Table 5.

[0076] Table 5. List of modules added in QEMU

[0077] Module Name Function Description cap-ng Network Acceleration Module kvm Kernel-based Virtualization Module Support (Hardware Virtualization Acceleration Module) rbd Remote Block Device Access Module (Remote Storage Device Access Optimization) virtfs Virtual File System Support (Local Disk Access Optimization Based on Hardware Virtualization) malloc-trim Solid State Drive (SSD) Performance Optimization Instruction Support

[0078] The QEMU adopted in the present invention is compiled using the source code of Loongson. During compilation, the purpose of function trimming of QEMU can be achieved by modifying the parameters of the compilation command. For example, the parameter of the compilation command of the module can be modified to "disable" to indicate the disabling of the module or "enable" to indicate the enabling of the module.

[0079] The following is to implement the secure container isolation method based on the MIPS64 instruction set of the present invention based on the above-transformed architecture. This method can be implemented in the Loongson container cloud platform (referred to as the Loongson platform or container cloud platform) that adopts the MIPS64 instruction set.

[0080] Figure 5 The flowchart of the secure container isolation method based on the MIPS64 instruction set in an embodiment of the present invention is shown. As Figure 5 shown, the method includes the following steps:

[0081] Step S510: Select a node for the service to be deployed based on the workload deployment information from the user terminal and the cluster load status.

[0082] Users of the container cloud platform can log in to the container cloud platform, enter the cluster management page with deployment permissions, and enter the workload deployment page by inputting a service deployment request (such as clicking the "Service Deployment" button on the cluster management page).

[0083] Users fill in the workload deployment information on the deployment interface. The workload deployment information may include: a) the name of the workload; and b) the name and / or address of the container image used by the workload, and may also include c) the namespace to which the workload is to be incorporated. In addition, more information may also be included. The name or address of the container image is used to locate the container image and let the system know where to download the image file. The namespace is a means of container permission management, and containers in the same namespace are more convenient in terms of data exchange, network communication, etc.

[0084] In the embodiment of the present invention, there is also a "Secure Container" option on the deployment interface. For example, there is a button "Secure Container" below the name column. By clicking this button to select the secure container mode, it means enabling the secure container technology; clicking the button "Secure Container" again to cancel the selection of the secure container mode means using the ordinary container running mode without enabling the secure container technology.

[0085] After the workload deployment information filled in by the user and the selection result of the secure container mode are completed, they can be transmitted to the container cloud platform, and the container cloud platform then selects the node (physical machine) used to deploy the workload according to the cluster load status.

[0086] Step S520: In the secure container mode, use QEMU-KVM adapted to the MIPS64 instruction set to create a virtual machine on the node of the service to be deployed, which includes a kernel that supports hardware acceleration and includes the MIPS64 instruction set, and start the virtual machine using the physical machine kernel.

[0087] Among them, both the physical machine kernel and the virtual machine kernel include: basic communication components, container runtime related module components, and kernel-based virtualization modules. In addition, the physical machine kernel and the virtual machine kernel also include: basic hardware resource managers, permission management components, and process management components.

[0088] More specifically, if the secure container technology is enabled, the container cloud platform will start a virtual machine on the node where the service to be deployed is located, then download the container image from the filled address to the physical machine, and share it with the virtual machine through the 9P file system.

[0089] Alternatively, if the secure container technology is not enabled, the container cloud platform will directly start the container on the physical machine according to the normal container startup process.

[0090] Step S530, in the secure container mode, the container cloud platform uses the virtual machine kernel to load the container runtime to start the container using the container runtime.

[0091] By embedding the container runtime in the virtual machine kernel, after loading the container runtime, the user-specified container image can be independently and quickly run in the virtual machine kernel, thus not relying on a large operating system and improving the deployment efficiency.

[0092] Step S540, the container cloud platform starts the container in the virtual machine and returns the container runtime information back to the container runtime on the physical machine through network transmission.

[0093] The page service returns to the service list page, and the container runtime on the physical machine collects the runtime information of each container and displays it on the page.

[0094] In the prior art, the resources of the container are pre-allocated, and the resources cannot be dynamically adjusted and re-allocated after the container runs in the virtual machine. In the embodiments of the present invention, the container runtime integrates a virtualization tool interface and I / O components, and the user-specified container image runs independently and quickly in the virtual machine kernel. In this way, the I / O components can be used to obtain the runtime status and resource overhead of the container from the virtual machine, and the virtualization tool interface can be used to dynamically adjust the occupancy configuration of the virtual machine for CPU, memory, and / or network resources based on the resource overhead of the container. The virtualization tool interface can implement the creation and deletion of the virtual machine, as well as the modification of its resource occupancy (CPU, storage, network) during the operation of the virtual machine.

[0095] For the customers of the CAS Cloud container cloud platform, whether the secure container technology is enabled or not, in the normal operation process, only need to click the "Secure Container" button, and other processes are transparent to the user.

[0096] The operating method of secure containers on MIPS64 (LoongArch) physical machines in the container cloud platform implemented by the present invention modifies the physical machine kernel, container runtime, virtualization tool QEMU, and virtual machine kernel, enabling each container to have an independent kernel environment as support and optimizing its operating efficiency. At the same time, no modification is required for container images based on the MIPS64 instruction set.

[0097] The secure container isolation method and device based on the MIPS64 instruction set in the embodiments of the present invention have at least the following beneficial technical effects:

[0098] 1) A complete strong isolation secure container operating environment is implemented on the MIPS64 instruction set (LoongArch) platform.

[0099] 2) The intermediate links are optimized to improve the container operating performance on the virtual kernel as much as possible.

[0100] 3) The container operating status and resource usage overhead in the virtual machine are passed through to the container cloud platform, enabling the platform to directly monitor and manage the containers inside the virtual machine.

[0101] 4) The resource occupancy of the virtual machine can be dynamically adjusted.

[0102] As can be seen above, different from the operation of ordinary containers, the present invention enables computers based on the MIPS64 instruction set (LoongArch) to run containers at a higher security level, creating an independent and secure strong isolation operating environment for the application programs inside the containers and providing a higher security level for business applications. Moreover, the container images can run stably and smoothly in an independent kernel without modification.

[0103] As shown in FIG. 6, it is a schematic flowchart of the operating method of heterogeneous instruction set containers in the container cloud platform according to another embodiment of the present invention. As Figure 6 shown, the operating method includes the following steps:

[0104] Step S61, the user of the container cloud platform logs in to the container cloud platform.

[0105] Step S62, the user of the container cloud platform enters the cluster management page with deployment permissions, clicks the "Service Deployment" button, and enters the workload deployment page.

[0106] Step S63, the user of the container cloud platform fills in the workload deployment information and uploads it to the container cloud platform. This information at least includes required fields, such as: a) the name of the workload; b) the name and / or address of the container image used by the workload; c) the namespace to which the workload is to be incorporated. At the same time, the user can also select the "Secure Container" mode on the workload deployment page and upload it to the container cloud platform.

[0107] Step S64, the container cloud platform receives the workload deployment information filled in by the user and starts to deploy the workload. It selects the nodes to be used for deploying the workload according to the cluster load status, then obtains the CPU type of the nodes (such as LoongArch type), and further looks up the container image that can run on the corresponding nodes from the image repository based on the CPU type of the nodes and the name or address of the container image.

[0108] Step S65, the container cloud platform confirms whether the name or address of the container image is correct based on the lookup result. If it is incorrect, it executes Step S73 to prompt the user that the image does not exist, and further executes Step S74 to return to the "Service Deployment" page. If the name or address of the container image is correct, it executes Step S66.

[0109] Step S66, the container cloud platform downloads the container image from the image repository.

[0110] Step S67, determine whether to start a secure container. If yes, enter Step S69; if not, enter Step S68.

[0111] Step S68, the container cloud platform directly starts the container on the physical machine according to the normal container startup process and continues until entering Step S72, where the operation terminates or the user actively shuts down or stops the workload.

[0112] Step S69, create a virtual machine to run a customized kernel.

[0113] More specifically, it may include:

[0114] 1) Start QEMU-KVM on the selected node to build a virtual machine based on the MIPS64 instruction set;

[0115] 2) Load the MIPS64 kernel with the container runtime already packaged in the virtual machine;

[0116] 3) After the kernel initialization, run the first process, start the virtual machine, and load the container runtime.

[0117] Step S70, the container cloud platform shares the container image with the virtual machine. For example, it transfers the container image specified by the user into the virtual machine using the 9P file system.

[0118] Step S71, run the application or service program in the container image in the virtual machine until the operation terminates or the user actively shuts down or stops the workload (Step S72).

[0119] Meanwhile, the container cloud platform can send the container runtime information back to the container runtime on the physical machine through network transmission.

[0120] During the operation of a container, the I / O component can be utilized to obtain the running status and resource overhead of the container from the virtual machine, and the virtualization tool interface can be used to dynamically adjust the occupancy configuration of the virtual machine for CPU, memory, and / or network resources based on the resource overhead of the container. The virtualization tool interface can also implement the creation and deletion of virtual machines.

[0121] Based on the above-mentioned secure container isolation method based on the MIPS64 instruction set, containers are run at a higher security level, creating an independent and secure strong isolation running environment for the applications within the containers and providing a higher security level for business applications.

[0122] Correspondingly, the present invention also provides a secure container isolation device based on the MIPS64 instruction set. The device includes a processor and a memory. Computer instructions are stored in the memory, and the processor is configured to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the device implements the steps of the method described above.

[0123] The present invention also relates to a storage medium on which computer program code can be stored. When the program code is executed, various embodiments of the method of the present invention can be implemented. The storage medium can be a tangible storage medium, such as an optical disc, random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of tangible storage medium known in the technical field.

[0124] It should be clear that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present invention.

[0125] Those of ordinary skill in the art should understand that the various exemplary components, systems, and methods described in connection with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Specifically, whether to implement in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, and so on. When implemented in software, the elements of the present invention are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or a communication link. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.

[0126] It should also be noted that the exemplary embodiments mentioned in the present invention describe some methods or systems based on a series of steps or devices. However, the present invention is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, can be different from the order in the embodiments, or several steps can be executed simultaneously.

[0127] In the present invention, the features described and / or illustrated for one embodiment can be used in the same or a similar manner in one or more other embodiments, and / or combined with the features of other embodiments or replace the features of other embodiments.

[0128] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, various changes and modifications can be made to the embodiments of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention should be included within the protection scope of the present invention.

Claims

1. A security container isolation method for a container cloud platform based on the MIPS64 instruction set, characterized in that, The method includes the following steps: Select a node for the service to be deployed based on the workload deployment information from the user terminal and the cluster load status, where the workload deployment information includes: the name or address of the container image used by the workload; Create a virtual machine containing the virtual machine kernel on the node for the service to be deployed, and start the virtual machine using the physical machine kernel, where both the physical machine kernel and the virtual machine kernel include: a basic communication component, a container runtime related module component, and a KVM module; Load the container runtime in the virtual machine kernel to start the container using the container runtime; Transmit the container runtime information in the virtual machine back to the container runtime on the physical machine kernel through network transmission, where the container runtime on the physical machine kernel integrates a virtualization tool interface and an I / O component.

2. The method according to claim 1, characterized in that, The QEMU-KVM includes a trimmed QEMU and a KVM module, and the trimmed QEMU has some or all of its modules removed except for the modules related to the basic core hardware resource simulation mechanism.

3. The method according to claim 2, wherein Before selecting a node for deploying the workload, the method further includes: Compile QEMU from source code for the container cloud platform, trim the functional modules of QEMU, and introduce the KVM module.

4. The method according to claim 2, wherein Before loading the virtual machine kernel, the method further includes the following steps: Modify the kernel configuration file before the virtual machine kernel is compiled; Add container runtime related modules; Encapsulate the container runtime module in the virtual machine kernel.

5. The method according to claim 4, wherein The step of encapsulating the container runtime module in the virtual machine kernel includes: encapsulating the container runtime components into the first process of the kernel; The step of loading the container runtime in the virtual machine kernel includes: after the virtual machine kernel is initialized, running the first process to load the container runtime; The method further includes: transmitting the container image specified by the user to the virtual machine and running the application in the container image.

6. The method according to claim 1, wherein The method further includes: Obtain the running status and resource overhead of the container from within the virtual machine using the I / O component and the network component; Dynamically adjust the occupancy configuration of the virtual machine for CPU, memory, and / or network resources based on the resource overhead of the container using the virtualization tool interface.

7. The method according to claim 1 or 2, wherein the workload deployment information further includes the name of the workload and the namespace to which the workload is to be incorporated; the physical machine kernel and the virtual machine kernel are kernels that support hardware virtualization of the MIPS64 instruction set.

8. The method according to claim 1, wherein The runtime-related module components include: 9P file system module, network block storage device module, fair group scheduling module, RDMA controller, cgroup scheduling module, advanced configuration and power interface module for PCI devices, CompactPCI bus module, ipset framework module, virtual network module, virtual network card module, cgroup scheduling module based on network traffic classification, network hierarchical service scheduling module, module providing element addition and deletion functions for the ipset module, network filter tracking module, general host controller for PCI devices, and fact group policy scheduler.

9. The method according to claim 2, characterized in that, The modules trimmed from the trimmed QEMU include some or all of the following modules: avx2 module, bluez module, brlapi module, bzip2 module, cocoa module, curses module, dmg module, gtk module, libiscsi module, libusb module, linux-aio module, qom-cast-debug module, sdl module, seccomp module, smartcard module, spice module, tpm module, usb-redir module, vnc module, vnc-jpeg module, vnc-png module, vnc-sasl module, vte module, whpx module, xen module, and xen-pci-passthrough module.

10. A secure container isolation device for a container cloud platform based on the MIPS64 instruction set. The device includes a processor and a memory, and is characterized in that, Computer instructions are stored in the memory, and the processor is configured to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the device implements the steps of the method according to any one of claims 1-9.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Processor extensions for execution of secure embedded containers

    CN104375890A

  • Heterogeneous hybrid cloud computing system

    CN107979620A