A File System Partition Access Control Method Based on ARINC653 Standard
By configuring file system access permissions in the ARINC653 standard operating system, using the partition names of MountPoint, OwnerPartition and ReaderPartition for permission auditing, the permission control problem of multiple partitions when accessing the core operating system file system is solved, and the system reliability and permission management efficiency is improved.
Patent Information
- Application Number
- CN202111633864.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-29
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-12-29
AI Technical Summary
In operating systems that comply with ARINC653 standards, it is difficult to effectively manage the file system access rights control of multiple partitions in the core operating system, which affects system reliability.
By configuring file system access permissions during the device management process of partition operating system, using the partition names of MountPoint, OwnerPartition and ReaderPartition for permission auditing, initializing the file system partition access control check function hook, checking device type and permission tags, and ensuring that only legal partitions can access the file system.
It realizes file system access permission management for different partitions, improves the reliability of the system, prevents illegal access, and ensures the effectiveness of permission management.
Smart Images

Figure CN114444118B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of computer system software, and particularly to a method for controlling access to file system partitions based on the ARINC653 standard. Background Art
[0002] The integrated modular avionics system (IMA) integrates multiple application systems into a computer with high-speed processing capabilities, and improves the energy efficiency of the system through resource sharing. The partitioned operating system is the main embedded real-time operating system adopted by the IMA system. To ensure determinism and robustness, the partitions in the partitioned operating system are isolated from each other in space and time. With the trend of avionics system integration, the partitioned operating system that meets the ARINC653 standard has been widely used in avionics systems.
[0003] At the same time, the file system is the main function used by each partition in the partitioned operating system. In a common IMA system, multiple partitions need to access the file system in the core operating system to perform corresponding operations. Based on the above requirements, if the access permissions of partitions to the file system in the partitioned operating system can be restricted accordingly, the reliability of the system can be improved and it is convenient for users to manage permissions. Summary of the Invention
[0004] In view of this, the embodiments of the present disclosure provide a method for controlling access to file system partitions based on the ARINC653 standard, which solves the problem of permission control when multiple partitions in an operating system that conforms to the ARINC653 standard access the file system in the core operating system. The present invention restricts the access permissions of partitions to the file system during the device management processing in the core layer where the file system of the partitioned operating system is located, improves the reliability of the system, and is convenient for users to manage permissions.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A method for controlling access to file system partitions based on the ARINC653 standard, comprising the following steps:
[0007] (1) The partitioned operating system development environment configuration tool is set according to the Volumes element in the user partition module configuration record, and the MountPoint mount point, the partition name of the OwnerPartition belonging partition, and the partition name of the ReaderPartition reading partition of each Volume volume element are configured. When the integrated project is built, the corresponding configuration record is generated by configuring the project;
[0008] (2) During the initialization of the core operating system, process the Volumes element in the configuration record and convert the attributes of each Volume element into the global volume access control data;
[0009] During device management initialization, if the global volume access control data can be obtained and there is Volume element configuration data, initialize the file system partition access control check function hook;
[0010] (3) In the partition user state, call the device management standard open interface, enter the system state through a system call, the system call handler transfers to the device management open operation, and after finding the corresponding device, perform a check on the file system partition access control check function hook;
[0011] If the hook exists, check whether the device type belongs to a file system type device;
[0012] If so, pass the device control header parameter and the open interface input parameter flags to the file system partition access control check function, enter the file system partition access control check function, and obtain the partition number;
[0013] If the partition number is 1, check whether there is a write permission flag in the input parameter flags,
[0014] If there is, loop through the Volumes elements in the global volume access control data for matching comparison,
[0015] If the volume name matches the device name, check whether the accessed partition is the partition belonging to the OwnerPartition. If so, return SUCCESS, indicating permission to access.
[0016] Further, in step (3), if the hook does not exist, skip the check of the file system partition access control check function hook and directly perform the device management operation.
[0017] Further, in step (3), if it is checked that the device type does not belong to a file system type device, skip the check and directly perform the device management operation.
[0018] Further, in step (3), if the partition number is 0, it represents core operating system access, and return SUCCESS, indicating permission to access.
[0019] Further, in step (3), check whether the accessed partition is the partition belonging to the OwnerPartition. If not, further loop through the partition number records with read permission of the readerPartitionId according to the readerNId. If it is in the record, return SUCCESS.
[0020] Further, according to the readerNId, further loop to check the partition number records with read permissions owned by the readerPartitionId. If it is not in the records, return to the device management standard open interface, and return the Permission denied access permission denial error code and the FAILURE return value.
[0021] Further, the user can configure one or more Volume volume elements. Each Volume volume element contains only one MountPoint mount point. At the same time, there is only one OwnerPartition belonging partition under this Volume volume element, and there can be zero or more ReaderPartition reading partitions.
[0022] Further, the global volume access control data attribute includes the configuration type, the configuration data size, the volume name, the read and write permissions, the partition number records with read permissions, and the valid entries in the partition ID list that can be read accessed.
[0023] The file system partition access control method based on the ARINC653 standard of the present invention solves the problem of permission control when multiple partitions in an operating system compliant with the ARINC653 standard access the file system in the core operating system, facilitates the user to manage the file system access permissions for different partitions, and improves the reliability of the system. Brief Description of the Drawings
[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0025] Figure 1 It is a schematic diagram of the partition access control method for the embodiments of the present invention. Detailed Embodiments
[0026] The embodiments of the present disclosure will be described in detail below with reference to the drawings.
[0027] The following specific examples illustrate the embodiments of the present disclosure. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all embodiments. The present disclosure can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts belong to the scope of protection of the present disclosure.
[0028] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. Additionally, this device and / or this method can be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.
[0029] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure in a schematic manner. The diagrams only show the components related to the present disclosure, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in its actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0030] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0031] The embodiment of the present disclosure provides a file system partition access control method based on the ARINC653 standard, including the following steps:
[0032] (1) The partition operating system development environment configuration tool is set according to the Volumes element in the user partition module configuration record, configuring the MountPoint mount point of each Volume volume element, the partition name of the OwnerPartition belonging partition, and the partition name of the ReaderPartition read partition, and generating the corresponding configuration record when integrating the project to configure the project.
[0033] (2) During the initialization of the core operating system, process the Volumes element in the configuration record and convert the attributes of each Volume element into global volume access control data; during device management initialization, if global volume access control data can be obtained and there is Volume element configuration data, initialize the file system partition access control check function hook.
[0034] (3) In the partition user state, call the device management standard open interface (the input parameters include the file system open address), enter the system state through system calls, the system call handler transfers to the device management open operation, find the corresponding device and then check the file system partition access control check function hook; if the hook does not exist, skip the check of the file system partition access control check function hook and directly perform device management related operations; if the hook exists, check whether the type of the device belongs to a file system type device, if not, otherwise skip the check; if so, pass the device control header parameter and the open interface input parameter flags to the file system partition access control check function, enter the file system partition access control check function, and obtain the partition number; if the partition number is 0, it means that it is a core operating system access and return SUCCESS, indicating permission to access; if the partition number is 1, check whether there is a write permission flag in the input parameter flags, if so, loop through the Volumes elements in the global volume access control data for matching comparison, if the mountPoint, that is, the volume name, matches the device name, then check whether the accessed partition is the partition of the OwnerPartition, if so, return SUCCESS, indicating permission to access; if not, further loop through the partition number records with read permission of the readerPartitionId according to the readerNId, if it is in the record, return SUCCESS.
[0035] Example 1
[0036] This example proposes a file system partition access control method based on the ARINC653 standard. By adding the configuration of file system access permissions to the ARINC653 configuration file, the operating system partition performs permission auditing and control when accessing the file system of the core layer. The technical solutions include:
[0037] Step 101: The user sets the Volumes element in the configuration record, and configures the MountPoint mount point of each Volume element, the partition name of the OwnerPartition to which it belongs, and the partition name of the ReaderPartition for reading.
[0038] It should be noted that the user can configure one or more Volume volume elements. Each Volume volume element contains only one MountPoint mount point. At the same time, there is only one OwnerPartition belonging partition under this Volume volume element, and there can be zero or more ReaderPartition reading partitions. See Table 1 for details; when the integration project is built, the project is configured to generate corresponding configuration records, and when the operating system in the target machine is initialized, it will read the configuration records previously loaded into the target machine.
[0039] Table 1: Volume volume element
[0040] Configuration Item Meaning Remarks Id ID identification of Volume For example, 0, and the serial number is required to be unique MountPoint Mount point In the form of A:, using capital letters, drive letter OwnerPartition Has read and write permissions Unique ReaderPartition Has read permissions Zero or more
[0041] Step 102: During the initialization of the core operating system, process the Volumes element in the configuration record, and convert the attributes of each Volume element into the global volume access control data. Then, when the device management is initialized, if the global volume access control data can be successfully obtained and there is Volume element configuration data, the file system partition access control check function hook is initialized. Otherwise, the file system partition access control check function hook is not initialized.
[0042] The attributes of the global volume access control data include the configuration type, the configuration data size, the volume name, the read-write permission, the partition number record with read permission, and the valid entries in the list of partition IDs that can be read-accessed.
[0043] It should be noted that the items included in the global volume access control data are shown in Table 2.
[0044] Table 2: Global volume access control data
[0045]
[0046]
[0047] Steps 103 to 109 are the processing flow for the user's daily file operations as Figure 1 shown.
[0048] Step 103: In the partition user state, call the device management standard open interface (the input parameters include the file system open address), enter the system state through the system call, the system call handler transfers to the core layer device management open operation, find the corresponding device, and check the file system partition access control check function hook. If the hook exists, enter Step 104; otherwise, skip the check of the partition access control check function hook and directly perform the device management related operations.
[0049] Step 104: Check whether the device belongs to the file system type. If it is, enter Step 105 for checking; otherwise, skip the check and directly perform device management-related operations.
[0050] Step 105: Pass the device control header parameter and the open interface input parameter flags to the file system partition access control check function. Enter the file system partition access control check function, obtain the partition number. If the partition number is 0, it means it is a core operating system access, then return SUCCESS, indicating permission to access; otherwise, enter Step 106.
[0051] Step 106: Check whether there is a write permission flag in the input parameter flags. If there is, perform the check in Step 107; otherwise, directly perform the check in Step 108.
[0052] It should be noted that the write permission flags include O_RDWR, O_WRONLY, O_APPEND, O_CREAT, and O_TRUNC.
[0053] Step 107: Loop through and match the Volumes element in the global volume access control data according to sArincVolumeTblSize. If the mountPoint, i.e., the volume name, matches the device name, check whether the accessed partition is the partition belonging to OwnerPartition. If it is, return SUCCESS; if not, return FAILURE, and finally enter Step 109.
[0054] Step 108: Loop through and match the Volumes element in the global volume access control data according to sArincVolumeTblSize. If the mountPoint, i.e., the volume name, matches the device name, check whether the accessed partition is the partition belonging to OwnerPartition. If it is, return SUCCESS; if not, further loop through the partition number records with read permission of readerPartitionId according to readerNId. If it is in the record, return SUCCESS; if it is still not in the record, return FAILURE, and finally enter Step 109.
[0055] Step 109: Return to the device management standard open interface, judge the return value of the check result. If it is SUCCESS, further perform device management-related operations; otherwise, return the access permission denied error code "Permission denied" and the FAILURE return value.
[0056] It should be noted that in step 102, if the user does not configure any Volume elements in the configuration table, then sArincVolumeTblSize is 0, and the hook function is not initialized during system initialization. When the user calls the device management standard open interface in the partition user state, the device management related operations will be directly performed according to the last step 103.
[0057] Embodiment 2
[0058] This embodiment takes 3 partitions, namely partition 1, partition 2, and partition 3, and 2 volume elements, namely volume C: and volume D: as examples for illustration. The method includes:
[0059] Step 201: The user sets the Volumes element in the configuration record, configures the MountPoint of one Volume volume element as "C:", the OwnerPartition as partition 1, and the ReaderPartition as partition 2 and partition 3; configures the MountPoint of the other Volume volume element as "D:", the OwnerPartition as partition 2, and the ReaderPartition as partition 1 and partition 3;
[0060] Step 202: During the initialization of the core operating system, process the volume C: and volume D: in the Volumes element in the configuration record, convert the attributes of each Volume element into the global volume access control data, and initialize the hook of the file system partition access control check function.
[0061] Step 203: Call the device management standard open interface (with the input parameters C: and O_RDWR) in the partition 1 user state and enter the system state through system calls. The system call handler transfers to the device management open operation, checks the hook of the file system partition access control check function after finding the corresponding device, and enters step 204 for inspection.
[0062] Step 204: Check that the device belongs to a device of the file system type, and enter step 205 for inspection.
[0063] Step 205: Pass the device control header parameter C: and the input parameter flags as O_RDWR to the file system partition access control check function. Enter the file system partition access control check function, obtain the partition number as 1, and enter step 206.
[0064] Step 206: Check whether there is a write permission flag in the input parameter flags, and enter step 207 for inspection.
[0065] Step 207: Loop to find two Volume elements and match and compare the Volume elements in the global volume access control data. The mountPoint name C: matches the device name C:. Check that the partition to which its OwnerPartition belongs is partition 1 and matches the access partition, return SUCCESS, and proceed to step 208.
[0066] Step 208: Return to the device management standard open interface. If the return value of the check result is SUCCESS, further perform relevant device management operations.
[0067] Step 209: In the user state of partition 1, call the device management standard open interface (with the input parameters D: and O_RDWR), enter the system state through a system call. The system call handler transfers to the device management open operation, performs a check on the hook of the file system partition access control check function after finding the corresponding device, and proceeds to step 210 for the check.
[0068] Step 210: Check that the device belongs to the type of file system device, and proceed to step 211 for the check.
[0069] Step 211: Pass the device control header parameter D: and the input parameter flags as O_RDWR to the file system partition access control check function. Enter the file system partition access control check function, obtain the partition number as 1, and proceed to step 212.
[0070] Step 212: Check whether there is a write permission flag in the input parameter flags, and proceed to step 213 for the check.
[0071] Step 213: Loop to find two Volume elements and match and compare the Volume elements in the global volume access control data. The mountPoint name D: matches the device name D:. Check that the partition to which its OwnerPartition belongs is partition 2 and does not match the access partition, return FAILURE, and proceed to step 214.
[0072] Step 214: Return to the device management standard open interface. If the return value of the check result is FAILURE, return the access permission denied error code Permission denied and the FAILURE return value.
[0073] Steps 203 to 208 form an operation loop, and steps 209 to 214 form an operation loop. Similar operation loops are the same for operations in partition 2 and partition 3.
[0074] The present invention provides a file system partition access control method based on the ARINC653 standard, which solves the problem of permission control when multiple partitions compliant with the ARINC653 standard operating system access the file system in the core operating system, facilitates users to manage the file system access permissions for different partitions, and improves the reliability of the system.
[0075] As described above, it is only the specific implementation manner of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present disclosure should be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A file system partition access control method based on the ARINC653 standard, characterized in that, The steps are as follows: (1) Configure the partition operating system development environment tool. Set according to the Volumes element in the user partition module configuration record, configure the MountPoint mount point of each Volume element, the partition name of the OwnerPartition belonging partition, and the partition name of the ReaderPartition reading partition. When integrating the project build, configure the project to generate the corresponding configuration record; (2) During the initialization of the core operating system, process the Volumes element in the configuration record, and convert the attributes of each Volume element into the global volume access control data; During device management initialization, if the global volume access control data can be obtained and there is Volume element configuration data, initialize the file system partition access control check function hook; (3) Call the device management standard open interface in the partition user state, enter the system state through system calls, the system call handler transfers to the device management open operation, and after finding the corresponding device, perform the check of the file system partition access control check function hook; If the hook exists, check whether the device type belongs to a file system type device; If so, pass the device control header parameter and the open interface input parameter flags to the file system partition access control check function, enter the file system partition access control check function, and obtain the partition number; If the partition number is 1, check whether there is a write permission flag in the input parameter flags; If so, loop through the Volumes elements in the global volume access control data for matching comparison; If the volume name matches the device name, check whether the accessed partition is the partition of the OwnerPartition. If so, return SUCCESS, indicating permission to access; In step (3), check whether the accessed partition is the partition of the OwnerPartition. If not, further loop through the partition number records with read permission of the readerPartitionId according to the readerNId. If it is in the record, return SUCCESS; Further loop through the partition number records with read permission of the readerPartitionId according to the readerNId. If it is not in the record, return to the device management standard open interface, and return the Permission denied access permission denial error code and the FAILURE return value.
2. The file system partition access control method based on the ARINC653 standard according to claim 1, wherein In step (3), if the hook does not exist, skip the check of the file system partition access control check function hook and directly perform the device management operation.
3. The file system partition access control method based on the ARINC653 standard according to claim 1, characterized in that, In step (3), if it is checked that the device type does not belong to a file system type device, skip the check and directly perform the device management operation.
4. The file system partition access control method based on the ARINC653 standard according to claim 1, characterized in that In step (3), if the partition number is 0, it means it is a core operating system access, and return SUCCESS, indicating permission to access.
5. The file system partition access control method based on the ARINC653 standard according to claim 1, wherein The user configures one or more Volume elements. Each Volume element contains only one MountPoint, and there is only one OwnerPartition under this Volume element, with zero or more ReaderPartitions.
6. The file system partition access control method based on the ARINC653 standard according to claim 1, characterized in that The global volume access control data attribute includes the configuration type, configuration data size, volume name, read-write permissions, record of partition numbers with read permissions, and valid entries in the list of partition IDs that can be read-accessed.
Citation Information
Patent Citations
Communication handling in integrated modular avionics
CA2408525A1
Multi-partition-oriented GPU access management method
CN110308992A