Security Isolation Method, Storage Medium, Device and Apparatus Based on Software Sandbox
A software-based sandboxing method segregates storage spaces using MPUs to manage access permissions, addressing the high cost of hardware-based isolation for embedded systems, enhancing security and reducing hardware needs.
Patent Information
- Application Number
- CN202111613830.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-27
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-12-27
AI Technical Summary
In existing embedded devices, the cost of hardware-based security isolation solutions is high, which is difficult for low-end devices to bear, and the demand for security protection levels is not high, the existing technology cannot effectively reduce hardware costs.
By dividing storage space at the software level and adopting a software sandbox method, it provides independent storage space for operating systems and applications, and uses MPU to configure special permissions and storage tables to achieve secure isolation and reduce dependence on hardware devices.
On the premise of meeting the security isolation, the requirements of hardware equipment are reduced, the isolation cost is reduced, and data security and isolation effect are improved.
Smart Images

Figure CN114266038B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of embedded systems, and particularly relates to a security isolation method, a storage medium, a device and a device based on a software sandbox. Background Art
[0002] In the field of embedded systems, there are more and more requirements for security protection and isolation. Basically, the security isolation solutions provided by chip hardware are used, which are mainly divided into the following two situations:
[0003] With the help of a highly secure independent SE chip, in general, for scenarios with extremely high requirements for security protection, the SE is an independent hardware chip that runs secure computing independently and can provide high-security protection for private information;
[0004] For medium security requirements, the security protection and non-security software are integrated into the same chip. Generally, the practice is to divide different access rights to resources and assign different privilege levels to the software running in the system. Through different privilege levels and access rights restrictions, some important private information is protected from being accessed, leaked or tampered with, so as to achieve the purpose of security protection.
[0005] However, the security isolation method based on the hardware solution has limitations. The hardware costs of the SE solution technology and the chip integrating the security isolation technology are relatively high. The actual situation is that the MCU controllers used in a large number of existing low-end embedded devices still use low-performance chips without the above-mentioned hardware security protection technology due to cost and actual security requirements; from the perspective of security requirements, some embedded device usage scenarios require security protection, but the security protection level does not need to reach a very high security level.
[0006] Therefore, in order to address the above situation, a new security isolation technology based on a software sandbox is provided. Summary of the Invention
[0007] The present application provides a security isolation method, a storage medium, a device and a device based on a software sandbox, which reasonably divide and isolate the storage space, provide independent storage spaces for the operating system and different applications, reduce the requirements for hardware devices on the premise of meeting security isolation, and reduce the isolation cost to a certain extent.
[0008] In a first aspect, the present application provides a security isolation method based on a software sandbox, and the method includes the following steps:
[0009] Create an operating system storage space corresponding to an operating system, configure special permissions for the operating system using the MPU, and set that the operating system storage space allows special permission access;
[0010] Create an application storage space corresponding to the application, and use the MPU to set the application storage space as the permitted access range corresponding to the application;
[0011] Allocate a first entry storage table to the operating system, where the first entry storage table records the storage address range of the operating system storage space and the set value of the storage address range within the MPU;
[0012] Allocate a second entry storage table to the application, where the second entry storage table records the storage address range of the application storage space and the set value of the storage address range within the MPU; wherein,
[0013] The operating system storage space and different application storage spaces are independent of each other;
[0014] The operating system storage space provides storage resources for the operation of the operating system;
[0015] The application storage space provides storage resources for the operation of the application.
[0016] Furthermore, the method further includes the following steps:
[0017] Use the MPU to configure special permissions for a preset SVC instruction;
[0018] The application reads the first entry storage table based on a preset SVC instruction, accesses the operating system storage space, and calls a preset function of the operating system.
[0019] Furthermore, when the application needs to perform data interaction with other applications, the method further includes the following steps:
[0020] The first application calls a preset system function and sends a first interaction message to the operating system;
[0021] The operating system receives the first interaction message and forwards it to the corresponding second application;
[0022] The second application receives and responds to the first interaction message, generating a first feedback message;
[0023] The second application calls a preset system function and feeds back the first feedback message to the operating system;
[0024] The operating system receives the first feedback message and forwards it to the first application.
[0025] Furthermore, the method further includes the following steps:
[0026] Configure the application storage space corresponding to the application to prohibit the application storage space corresponding to other applications.
[0027] Further, the method further includes the following steps:
[0028] When the application starts at least two threads, based on the application storage space corresponding to the application, allocate storage resources for the corresponding threads.
[0029] Further, the method further includes the following steps:
[0030] Configure an interrupt function in the operating system, and configure a corresponding interrupt function call interface for the application;
[0031] Bind the interrupt function call interface to the second entry storage table of the corresponding application.
[0032] Further, the method further includes the following steps:
[0033] Before calling the interrupt function, back up the set value of the application in the MPU in the current state to obtain an MPU set value backup;
[0034] According to the second entry storage table of the application at the time of registration, reset the set value of the MPU;
[0035] Call and execute the interrupt function, and restore the set value in the MPU according to the MPU set value backup.
[0036] In a second aspect, the present application provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the security isolation method based on a software sandbox mentioned in the first aspect are implemented.
[0037] In a third aspect, the present application provides a device, the device includes a memory, a processor, and a computer program stored on the memory and running on the processor, and when the processor executes the computer program, the steps of the security isolation method based on a software sandbox mentioned in the first aspect are implemented.
[0038] In a fourth aspect, the present application provides a security isolation device based on a software sandbox, the device includes:
[0039] A storage space allocation module, which is used to create an operating system storage space corresponding to an operating system, and is also used to create an application storage space corresponding to an application;
[0040] A storage table allocation module, which is used to allocate a first entry storage table to the operating system, and is also used to allocate a second entry storage table to the application;
[0041] An MPU, which is used to configure special permissions for the operating system, set that the storage space of the operating system allows access with special permissions, and is also used to set the application storage space to the allowed access range corresponding to the application; wherein,
[0042] The first entry storage table records the storage address range of the operating system storage space and the set value within the MPU for the storage address range;
[0043] The second entry storage table records the storage address range of the application storage space and the set value within the MPU for the storage address range;
[0044] The operating system storage space and different application storage spaces are independent of each other;
[0045] The operating system storage space provides storage resources for the operation of the operating system;
[0046] The application storage space provides storage resources for the operation of the application.
[0047] The beneficial effects brought by the technical solution provided in this application include:
[0048] This application starts from the software level, reasonably divides and isolates the storage space, provides independent storage spaces for the operating system and different applications, and in the form of a software sandbox, reduces the requirements for hardware devices while meeting the premise of security isolation, and reduces the isolation cost to a certain extent. Description of the Drawings
[0049] Term Explanation:
[0050] SE: Secure Element, secure component;
[0051] MCU: Microcontroller Unit, microcontroller;
[0052] SVC: Super Visor Call, system management call;
[0053] ARM: Advanced RISC Machines, ARM processor;
[0054] CPU: Central Processing Unit, central processing unit;
[0055] RAM: Random Access Memory, random access memory;
[0056] NVM: Non-volatile Memory, fixed memory, non-volatile memory;
[0057] MPU: Memory Protection Unit, memory protection unit.
[0058] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0059] Figure 1 It is the flowchart of the steps of the security isolation method based on software sandbox provided in the embodiments of the present application;
[0060] Figure 2 It is the principle framework diagram of the security isolation method based on software sandbox provided in the embodiments of the present application;
[0061] Figure 3 It is the schematic diagram of the interaction between applications in the security isolation method based on software sandbox provided in the embodiments of the present application;
[0062] Figure 4 It is the structural block diagram of the security isolation device based on software sandbox provided in the embodiments of the present application. Specific implementation manners
[0063] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.
[0064] The following will further elaborate on the embodiments of the present application in conjunction with the accompanying drawings.
[0065] The embodiments of the present application provide a security isolation method, storage medium, device, and apparatus based on software sandbox. Starting from the software level, the storage space is reasonably divided and isolated to provide independent storage spaces for the operating system and different applications. In the form of a software sandbox, while meeting the requirements of security isolation, the requirements for hardware devices are reduced, and the isolation cost is reduced to a certain extent.
[0066] To achieve the above technical effects, the overall idea of the present application is as follows:
[0067] A security isolation method based on software sandbox, the method comprising the following steps:
[0068] S1. Create an operating system storage space corresponding to an operating system, configure special permissions for the operating system using the MPU, and set that the operating system storage space allows special permission access;
[0069] S2. Create an application storage space corresponding to an application, and use the MPU to set the application storage space as the allowed access range corresponding to the application;
[0070] S3. Allocate a first entry storage table to the operating system, the first entry storage table recording the storage address range of the operating system storage space and the set value within the MPU of the storage address range;
[0071] S4. Allocate a second entry storage table to the application, the second entry storage table recording the storage address range of the application storage space and the set value within the MPU of the storage address range; wherein,
[0072] The operating system storage space and different application storage spaces are independent of each other;
[0073] The operating system storage space provides storage resources for the operation of the operating system;
[0074] The application storage space provides storage resources for the operation of the application.
[0075] The following further elaborates on the embodiments of the present application with reference to the accompanying drawings.
[0076] In a first aspect, referring to Figures 1 to 3 as shown, the embodiments of the present application provide a security isolation method based on software sandbox, the method comprising the following steps:
[0077] S1. Create an operating system storage space corresponding to an operating system, configure special permissions for the operating system using the MPU, and set that the operating system storage space allows special permission access;
[0078] S2. Create an application storage space corresponding to an application, and use the MPU to set the application storage space as the allowed access range corresponding to the application;
[0079] S3. Allocate a first entry storage table to the operating system, the first entry storage table recording the storage address range of the operating system storage space and the set value within the MPU of the storage address range;
[0080] S4. Allocate a second entry storage table to the application, the second entry storage table recording the storage address range of the application storage space and the set value within the MPU of the storage address range; wherein,
[0081] The operating system storage space and different application storage spaces are independent of each other;
[0082] The operating system storage space provides storage resources for the operation of the operating system;
[0083] The application storage space provides storage resources for the operation of the application.
[0084] It should be noted that in the embedded field, there are more and more requirements for security protection and isolation. Basically, the security isolation solutions provided by chip hardware are used. The specific situations are as follows:
[0085] A highly secure independent SE chip is adopted. Generally, in scenarios with extremely high requirements for security protection, the SE is an independent hardware chip that runs secure computing independently and can provide high-security protection for private information.
[0086] For medium security requirements, the security protection and non-security software are integrated into the same chip. Generally, the practice is to divide different access rights for resources and assign different privilege levels to the software running in the system. Through different privilege levels and access rights restrictions, some important private information is protected from being accessed, leaked, or tampered with, so as to achieve the purpose of security protection.
[0087] At the current stage of technical means, typical solutions are as follows;
[0088] The TrustZone technology proposed by ARM. The ARM chip adopting the TrustZone technology provides isolation between the secure and non-secure environments at the hardware level. Based on what the hardware provides, a logically secure operating environment is constructed, which can run some trusted secure operating systems or secure service codes. The secure environment and the non-secure environment are completely isolated logically and achieve independent operation in virtual logic through hardware, thus realizing the isolation between the secure environment and the non-secure environment.
[0089] When using a dual-core CPU for task security isolation, one secure core has the permission to access all resources of the chip, and one non-secure core only has the permission to access some resources, realizing the isolation between the secure environment and the non-secure environment.
[0090] However, there are limitations in the security isolation method based on the hardware solution. The hardware costs of the SE solution technology and the chips integrating the security isolation technology are relatively high.
[0091] The actual situation is that the MCU controllers used in a large number of existing low-end embedded devices still use low-performance chips without the above-mentioned hardware security protection technology due to cost and actual security requirements considerations;
[0092] In terms of security requirements, the usage scenarios of some embedded devices require security protection, but the security protection level does not need to reach a very high level.
[0093] Based on the limitations of the current technical means described above, in the embodiments of the present application, starting from the software level, the storage space is reasonably divided and isolated to provide independent storage spaces for the operating system and different applications. In the form of a software sandbox, while meeting the requirements of security isolation, the requirements for hardware devices are reduced, and the isolation cost is reduced to a certain extent.
[0094] Furthermore, the security isolation method based on the software sandbox further includes the following steps:
[0095] Use the MPU to configure special permissions for a preset SVC instruction;
[0096] The application reads the first entry storage table based on the preset SVC instruction, accesses the operating system storage space, and calls the preset function of the operating system.
[0097] Since the application does not have special permissions, it cannot directly access some system registers provided by the chip, cannot modify the application's permissions to privileged-level permissions in the application code, nor modify the settings of the protection segments in the MPU registers. Therefore, it cannot obtain access permissions to resources outside the permitted range;
[0098] Therefore, the application needs to call the functions provided by the operating system through the SVC instruction. Since the SVC instruction has entered the privileged level, it can read the first entry storage table of the operating system, enable access to the operating system resources on the current MPU setting, and then call the system function for processing;
[0099] Before returning from the SVC, close the permission to access the operating system resources, and restore the application to non-privileged mode for execution after returning to the application.
[0100] It should be noted that both the input and output of the system function call are transmitted using the preset shared RAM segment.
[0101] Furthermore, when the application needs to perform data interaction with other applications, the security isolation method based on the software sandbox further includes the following steps:
[0102] The first application calls a preset system function and sends a first interaction message to the operating system;
[0103] The operating system receives the first interaction message and forwards it to the corresponding second application;
[0104] The second application receives and responds to the first interaction message, generating a first feedback message;
[0105] The second application invokes a preset system function to feedback the first feedback message to the operating system;
[0106] The operating system receives the first feedback message and forwards it to the first application.
[0107] In this way, data interaction between applications can be avoided, further enhancing data security.
[0108] Furthermore, the security isolation method based on software sandbox further includes the following steps:
[0109] Configure the application storage space corresponding to the application to be prohibited from being accessed by the application storage spaces corresponding to other applications.
[0110] Furthermore, the security isolation method based on software sandbox further includes the following steps:
[0111] When the application starts at least two threads, based on the application storage space corresponding to the application, allocate storage resources for the corresponding threads;
[0112] And record the situation of allocating storage resources for the corresponding threads, that is, the corresponding storage addresses, in the second entry storage table.
[0113] With such settings, the storage addresses of the application can be further refined, enabling further security isolation of the storage resources in the application.
[0114] Furthermore, the security isolation method based on software sandbox further includes the following steps:
[0115] Configure an interrupt function within the operating system and configure a corresponding interrupt function call interface for the application;
[0116] Bind the interrupt function call interface to the second entry storage table of the corresponding application.
[0117] Furthermore, the security isolation method based on software sandbox further includes the following steps:
[0118] Before invoking the interrupt function, back up the set value of the application in the MPU in the current state to obtain an MPU set value backup;
[0119] According to the second entry storage table of the application at the time of registration, reset the set value of the MPU;
[0120] Invoke and execute the interrupt function, and restore the set value in the MPU according to the MPU set value backup.
[0121] It should be noted that, based on the technical solution of this application, all interrupt handling is processed by the interrupt function of the operating system, thereby further enhancing the reliability of security isolation.
[0122] Specifically, the operating system storage space and the application storage space include a CODE space, a RAM space, an NVM storage space, and a shared RAM area; among them,
[0123] The CODE space is a specially divided space for storing code;
[0124] That is, the CODE space of the operating system storage space stores the code of the operating system;
[0125] The CODE space of the application system storage space stores the code of the application system.
[0126] The embodiment of this application is specifically based on an MCU chip. The MCU chip has an MPU protection function, which can implement the protection of memories (mainly memory and peripheral registers), making the software more robust and reliable. Before use, it must be programmed according to needs. The MPU can improve the reliability of the system and can specifically perform the following functions:
[0127] Prevent user application programs from destroying the data used by the operating system;
[0128] Prevent one task from accessing the data area of other tasks, thereby separating the tasks;
[0129] The critical data area can be set to read-only, fundamentally eliminating the possibility of being damaged;
[0130] Detect unexpected memory accesses, such as stack overflow and array out-of-bounds;
[0131] The MPU can set the range, size, and access permissions of multiple domains;
[0132] In addition, other access attributes of the memory regions can also be set through the MPU, such as whether to buffer, whether to cache, etc.
[0133] Some embedded chips (such as ARM cores like Cortex M3, M4, etc.) provide two operating levels, privileged level and unprivileged level. The code running at the privileged level can access all storage spaces (except for the spaces prohibited by the MPU setting), and some chip core registers cannot be accessed under the unprivileged level, such as system control registers, interrupt control registers, MPU control registers, and tick clock registers.
[0134] In actual implementation, based on the method of the embodiment of this application, an embedded software system can be designed. The specific situation is as follows:
[0135] The access permission of the MPU - set storage space is configured to allow privileged - level access and prohibit non - privileged - level access. The privileged - level access corresponds to the SVC mode. Functions configured by the operating system can be called by the application through instructions in the SVC mode. The operating system creates an entry storage table for itself, storing the MPU - set values that allow access to the resource segments used by the operating system.
[0136] The application runs at the non - privileged level. The operating system creates an entry storage table for each application. The entry table stores multiple storage - space range segments that this application is allowed to access. The storage - space access segments include the CODE space, the RAM space (including the stack space), the NVM storage space, and the shared RAM area. The storage space where this entry table is located belongs to the kernel resources.
[0137] The application can start one or more threads. During the context switch of the thread entering the application, the operating system reads the storage - space segments allowed to be accessed from the entry storage table of the application, and modifies the MPU settings according to the allowed resource range. Other resources that are not allowed to be accessed are set to prohibit read - write access. When the application runs, it can only access the resource segments allowed to be accessed set in the MPU. When the application directly accesses other prohibited resource segments, an exception will be triggered.
[0138] It should be noted that since the application runs at the non - privileged level, it cannot directly access some system registers provided by the chip, cannot modify its own permission to the privileged level in the application code, or modify the protection segments in the MPU register, and cannot obtain the access permission to resources outside the allowed range.
[0139] Therefore, the application can only call the system functions provided by the operating system through the SVC instruction. Since it has entered the privileged - level permission, it can read the operating - system entry table, enable the access to the operating - system resources on the current MPU settings, and then call the system function for processing.
[0140] Close the permission to access the operating - system resources. After returning to the application, it resumes execution in the non - privileged mode. The input and output of the function call are passed using the shared RAM segment.
[0141] In addition, all interrupt handling is performed by the interrupt functions of the operating system. The operating system provides a system call interface for the application to register interrupt handling. When registering, the system automatically binds the callback function registered by the application to the entry table of the application.
[0142] Before calling the application's interrupt handling function in the interrupt handling function of the operating system, back up the current MPU settings, modify the current operating mode to non-privileged level, reset the MPU according to the application entry table value at registration, call the registered interrupt callback function of the application, and restore the MPU settings according to the backup before exiting the interrupt.
[0143] The technical solution of the embodiment of the present application can be implemented on the current mainstream real-time multitasking operating system, and can also be implemented on the non-multitasking embedded system code.
[0144] In a second aspect, an embodiment of the present application provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the security isolation method based on a software sandbox mentioned in the first aspect are implemented.
[0145] In a third aspect, an embodiment of the present application provides a device, which includes a memory, a processor, and a computer program stored on the memory and running on the processor. When the processor executes the computer program, the steps of the security isolation method based on a software sandbox mentioned in the first aspect are implemented.
[0146] In a fourth aspect, as shown in Figure 4 An embodiment of the present application provides a security isolation device based on a software sandbox. The security isolation device based on a software sandbox includes:
[0147] A storage space allocation module, which is used to create an operating system storage space corresponding to an operating system, and is also used to create an application storage space corresponding to an application;
[0148] A storage table allocation module, which is used to allocate a first entry storage table to the operating system, and is also used to allocate a second entry storage table to the application;
[0149] An MPU, which is used to configure special permissions for the operating system, set that the operating system storage space allows special permission access, and is also used to set the application storage space as the allowed access range corresponding to the application; where
[0150] The first entry storage table records the storage address range of the operating system storage space and the setting value of the storage address range in the MPU;
[0151] The second entry storage table records the storage address range of the application storage space and the setting value of the storage address range in the MPU;
[0152] The operating system storage space and different application storage spaces are independent of each other;
[0153] The operating system storage space provides storage resources for the operation of the operating system;
[0154] The application storage space provides storage resources for the operation of the application.
[0155] In the embodiments of the present application, starting from the software level, the storage space is reasonably divided and isolated to provide independent storage spaces for the operating system and different applications. In the form of a software sandbox, on the premise of meeting security isolation, the requirements for hardware devices are reduced, and the isolation cost is reduced to a certain extent.
[0156] Further, the MPU is also used to configure special permissions for a preset SVC instruction;
[0157] Based on this technical means, the application can read the first entry storage table based on the preset SVC instruction, access the operating system storage space, and call the preset function of the operating system.
[0158] Based on the technical solution of the embodiments of the present application, when the application needs to perform data interaction with other applications, the following operations are specifically included:
[0159] The first application calls a preset system function and sends a first interaction message to the operating system;
[0160] The operating system receives the first interaction message and forwards it to the corresponding second application;
[0161] The second application receives and responds to the first interaction message and generates a first feedback message;
[0162] The second application calls a preset system function and feeds back the first feedback message to the operating system;
[0163] The operating system receives the first feedback message and forwards it to the first application.
[0164] Further, the MPU is also used to configure the application storage space corresponding to the application to be prohibited from being accessed by the application storage spaces corresponding to other applications.
[0165] Further, when the application starts at least two threads, the storage space allocation module is also used to allocate storage resources for the corresponding threads based on the application storage space corresponding to the application.
[0166] Further, the device also includes an interrupt execution module, which is used to configure an interrupt function in the operating system and configure a corresponding interrupt function call interface for the application;
[0167] The interrupt execution module is further configured to bind the interrupt function call interface to the second entry storage table of the corresponding application.
[0168] Furthermore, the MPU is further configured to back up the set value of the MPU in the current state of the application before the interrupt execution module calls the interrupt function to perform an interrupt operation on the corresponding application, so as to obtain an MPU set value backup;
[0169] The MPU is further configured to reset the set value of the MPU according to the second entry storage table of the application during registration;
[0170] The MPU is further configured to, after the interrupt execution module calls and executes the interrupt function and completes the interrupt operation, restore the set value of the MPU according to the MPU set value backup.
[0171] Specifically, the operating system storage space and the application storage space include a CODE space, a RAM space, an NVM storage space, and a shared RAM area; where
[0172] The CODE space is a specially allocated space for storing code;
[0173] That is, the CODE space of the operating system storage space stores the code of the operating system;
[0174] The CODE space of the application system storage space stores the code of the application system.
[0175] It should be noted that in this application, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0176] The above are only specific embodiments of the present application, enabling those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but rather will be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A security isolation method based on software sandbox, characterized in that, The method includes the following steps: Create an operating system storage space corresponding to an operating system, configure special permissions for the operating system using the MPU, and set the operating system storage space to allow access with special permissions; Create an application storage space corresponding to an application, and use the MPU to set the application storage space as the allowed access range corresponding to the application; Allocate a first entry storage table to the operating system, where the first entry storage table records the storage address range of the operating system storage space and the set value of the storage address range within the MPU; Allocate a second entry storage table to the application, where the second entry storage table records the storage address range of the application storage space and the set value of the storage address range within the MPU; wherein, The operating system storage space and different application storage spaces are independent of each other; The operating system storage space provides storage resources for the operating system during operation; The application storage space provides storage resources for the application during operation.
2. The security isolation method based on software sandbox as claimed in claim 1, wherein The method further includes the following steps: Configure special permissions for a preset SVC instruction using the MPU; The application reads the first entry storage table based on the preset SVC instruction, accesses the operating system storage space, and calls a preset function of the operating system.
3. The security isolation method based on software sandbox according to claim 1, wherein When the application needs to perform data interaction with other applications, the method further includes the following steps: The first application calls a preset system function and sends a first interaction message to the operating system; The operating system receives the first interaction message and forwards it to the corresponding second application; The second application receives and responds to the first interaction message, generating a first feedback message; The second application calls a preset system function and feeds back the first feedback message to the operating system; The operating system receives the first feedback message and forwards it to the first application.
4. The security isolation method based on software sandbox according to claim 1, characterized in that, The method further includes the following steps: Configure the application storage space corresponding to the application to be prohibited from being accessed by the application storage spaces corresponding to other applications.
5. The security isolation method based on software sandbox according to claim 1, characterized in that The method further includes the following steps: When the application starts at least two threads, based on the application storage space corresponding to the application, allocate storage resources for the corresponding threads.
6. The security isolation method based on software sandbox according to claim 1, wherein The method further includes the following steps: Configure an interrupt function within the operating system, and configure a corresponding interrupt function call interface for the application; Bind the interrupt function call interface to the second entry storage table of the corresponding application.
7. The security isolation method based on software sandbox according to claim 6, characterized in that, The method further includes the following steps: Before calling the interrupt function, back up the set value of the MPU in the current state of the application to obtain an MPU set value backup; Reset the set value of the MPU according to the second entry storage table when the application is registered; Call and execute the interrupt function, and restore the set value in the MPU according to the MPU set value backup.
8. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7 above.
9. An apparatus, the apparatus comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that: When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7 above.
10. A security isolation device based on a software sandbox, characterized in that, The device includes: A storage space allocation module, which is used to create an operating system storage space corresponding to an operating system, and is also used to create an application storage space corresponding to an application; A storage table allocation module, which is used to allocate a first entry storage table to the operating system, and is also used to allocate a second entry storage table to the application; An MPU, which is used to configure special permissions for the operating system, and set that the operating system storage space allows special permission access, and is also used to set the application storage space as the allowed access range corresponding to the application; wherein, The first entry storage table records the storage address range of the operating system storage space and the set value of the storage address range in the MPU; The second entry storage table records the storage address range of the application storage space and the set value of the storage address range in the MPU; The operating system storage space and different application storage spaces are independent of each other; The operating system storage space provides storage resources for the operation of the operating system; The application storage space provides storage resources for the operation of the application.
Citation Information
Patent Citations
Shared library isolation protection method and system based on hardware virtualization technology
CN107102888A
System and method
CN112749397A