An apparatus with a kernel architecture based on the PKS system
By dividing user areas and security areas in the computer system, and using the interaction between the TEE module and the UEFI module, the security and performance problems caused by computing and secure sharing resources in the prior art are solved, real-time protection and high-performance secure computing are achieved.
Patent Information
- Application Number
- CN202210258947.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-16
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-03-16
AI Technical Summary
In the existing computer system, computing and security share the same set of resources, resulting in unknown computing risks that allow attackers to obtain legal permissions or bypass security software protection. The dual-architecture external security architectures are weak and cannot obtain the computing space status in real time.
Using a kernel architecture based on PKS system, by dividing user areas and secure areas in dual architecture processors, non-secure computing and secure computing are divided into different spaces, and through the interaction between TEE module and UEFI module, the computing space status is obtained in real time for protection.
Real-time acquisition of the computed space status for protection is achieved, avoiding the problems of few security space functions and weak performance, and enhancing the security and performance of the system.
Smart Images

Figure CN114707140B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly to an apparatus based on the kernel architecture of the PKS system. Background Art
[0002] In the existing computer system, computing and security are in the same space, sharing the same set of computing resources, memory, and I / O resources. This enables security software to obtain the computing state and implement protection. However, unknown computing risks may allow attackers to obtain legitimate permissions or bypass the protection of security software. The dual architecture with security externalized adopted in the industry often has few functions and weak performance in the security space, unable to obtain the computing space state in real time and provide timely and in-depth protection.
[0003] Therefore, how to provide a secure and reliable kernel architecture based on the PKS system is a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide an apparatus based on the kernel architecture of the PKS system, which can obtain the computing space state in real time for protection, avoiding the few functions and weak performance of the security space caused by the dual architecture with security externalized. The specific scheme is as follows:
[0005] The user area in the dual-architecture processor is used to call the operating system security module LSM to provide functions for security software to hook sub to uniformly manage software hooking, and allocate operating resources for the hooked security software;
[0006] The security area in the dual-architecture processor is used to, when receiving a resource access request, call the TEE module to perform security verification and signature on the code loaded into the kernel. If the verification and signature pass, the code loaded into the kernel is run; wherein, the permission of the security area is higher than that of the user area;
[0007] The UEFI module located in the user area is used to perform trusted measurement on the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot.
[0008] Optionally, the user area and the security area are divided by configuring relevant registers based on the PSPA specification, and a custom protocol handshake and transmission of the data packet to be transmitted are performed in the manner of shared memory.
[0009] Optionally, the user area is further used for:
[0010] Dynamically perform private key signature on the code to be loaded into the kernel processed by the eBPF loader and send it to the TEE module, so that the TEE module verifies the signature of the code to be loaded into the kernel with the private key and then runs it.
[0011] Optionally, the trusted measurement of the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot includes:
[0012] Trusted-measure the UEFI firmware by calling the TEE module and start the UEFI firmware after determining that the UEFI firmware is trusted;
[0013] Use the UEFI firmware to traverse the motherboard devices to obtain relevant hardware information;
[0014] Trusted-measure the hardware information by calling the TEE module, and if it is trusted, perform trusted boot.
[0015] Optionally, before trusted-measuring the hardware information by calling the TEE module, it further includes:
[0016] Determine whether the trusted measurement is the first measurement;
[0017] If so, generate a corresponding whitelist according to the first measurement result, so that the dynamically calculated hash value is matched with the whitelist during subsequent measurement processes;
[0018] If the match is successful, determine that the measurement result is trusted;
[0019] If the match fails, skip and continue to boot or report an error and prevent booting.
[0020] Optionally, after using the UEFI firmware to traverse the motherboard devices to obtain relevant hardware information, it further includes:
[0021] Split the hard disk partition table data in the traversed hardware information;
[0022] Send the split data to the TEE module in batches, so that the TEE module measures the obtained batch data.
[0023] Optionally, splitting the hard disk partition table data in the traversed hardware information includes:
[0024] Split the hard disk partition table data in the traversed hardware information to obtain multiple data packets in units of the shared memory size.
[0025] Optionally, the TEE module is the only module with FLASH physical read and write functions.
[0026] Optionally, the device with a kernel architecture based on the PKS system further includes:
[0027] The heterogeneous computing unit is used to receive the mounted security software sent by the TEE module to perform heterogeneous computing processing on the mounted security software.
[0028] Optionally, the TEE module is further used to configure the secure memory according to the configuration instruction of the user area.
[0029] In this application, the device with a kernel architecture based on the PKS system includes a user area, a secure area, and a UEFI module in a dual-architecture processor. Among them, the user area is used to call the operating system security module LSM to provide functions for security software hooking sub to uniformly manage software hooking, and to allocate operating resources for the mounted security software; the secure area is used to, when a resource access request is obtained, call the TEE module to perform security verification and signature on the code loaded into the kernel. If the verification and signature pass, the code loaded into the kernel is run; among them, the permission of the secure area is higher than that of the user area; the UEFI module is used to perform trusted measurement on the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot. It can be seen that the kernel architecture of this application separates non-secure computing and secure computing into different spaces by dividing the user area and the secure area. At the same time, based on the interaction between the TEE module and the UEFI module, the computing space status can be obtained in real time for protection, avoiding the few functions and weak performance of the secure space caused by using a dual-architecture with an external security device. Description of the Drawings
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0031] Figure 1 It is a device diagram of a kernel architecture based on the PKS system provided by this application;
[0032] Figure 2 It is a schematic diagram of specific internal interactions of the architecture provided by this application. Detailed Embodiments
[0033] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0034] The existing computer system integrates computing and security in the same space, sharing the same set of computing resources, memory, and I / O resources. This enables security software to obtain the computing state and implement protection. However, unknown computing risks may allow attackers to obtain legitimate permissions or bypass the protection of security software. The commonly used dual-architecture with external security often has limited functions and weak performance in the security space, unable to obtain the computing space state in real time and provide timely and in-depth protection. To address the above technical deficiencies, this application provides a device based on the kernel architecture of the PKS system. By dividing the user area and the security area, non-secure computing and secure computing belong to different spaces. At the same time, based on the interaction between the TEE module and the UEFI module, the computing space state can be obtained in real time for protection, avoiding the problems of limited functions and weak performance in the security space caused by the dual-architecture with external security.
[0035] Figure 1 This is a diagram of a device based on the kernel architecture of the PKS system provided by an embodiment of this application. Refer to Figure 1 As shown, the device based on the kernel architecture of the PKS system includes the user area and the security area in the dual-architecture processor, the UEFI module, and the TEE module, where:
[0036] The user area in the dual-architecture processor is used to call the operating system security module LSM to provide functions for security software to hook sub-functions for unified management and control of software hooking, and to allocate operating resources for the hooked security software;
[0037] The security area in the dual-architecture processor is used to, when a resource access request is received, call the TEE module to perform security verification and signature on the code loaded into the kernel. If the verification and signature pass, the code loaded into the kernel is run; among them, the permission of the security area is higher than that of the user area;
[0038] The UEFI module is used to perform trusted measurement on the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot.
[0039] The PKS system is a green, open, and shared technical architecture and ecological system. "P" represents the Feiteng processor (PHYTIUM), "K" represents the Kylin operating system (KYLIN), and "S" represents the ability to inject security. The processor and operating system in this embodiment are both the processor and operating system under the PKS system, establishing a dual-processor architecture that combines computing and security protection, and creating an immune mode based on trusted computing. On this basis, the user area in the dual-architecture processor is used to call the operating system security module LSM to provide functions for security software to hook on, so as to uniformly manage software hooking, and allocate operating resources for the hooked security software. The security area in the dual-architecture processor is used to, when a resource access request is obtained, call the TEE module to perform security verification and signature on the code loaded into the kernel. If the verification and signature pass, the code loaded into the kernel will be run; among them, the permission of the security area is higher than that of the user area.
[0040] On this basis, the user area is also used to dynamically perform private key signature on the code to be loaded into the kernel processed by the eBPF loader and then send it to the TEE module, so that the TEE module can perform verification and signature on the code to be loaded into the kernel with private key signature and then run it. Based on the LINUX kernel LSM security mechanism (security module) and eBPF, Kylin OS provides interface functions for security software to hook on to limit and avoid conflicts or security risks caused by security software directly writing LSM-class data structures. In addition, when the eBPF loader dynamically loads code into the kernel, the TEE module will perform security verification and signature on it to ensure that the source is legal and correct.
[0041] In this embodiment, the processor CPU is divided into a user area and a security area to obtain a dual-architecture processor. The security area space is divided inside the same processor CPU, physically isolating the user area space, I / O space, and memory space. The division method is software-defined. According to the ArmV8 TrustZone and Feiteng PSPA architecture principles, the permission of the security area is higher than that of the user area, that is, the security area can see the user area, and the user area cannot see the security area, which can not only achieve isolation but also achieve powerful high-performance monitoring. And it is safer inside the same chip without changing the motherboard.
[0042] In this embodiment, the isolation can be software-defined configured, that is, the user area and the security area are divided by configuring relevant registers based on the PSPA specification. In addition, a shared memory method is adopted between the user area and the security area to perform custom protocol handshaking and transmission on the data packets to be transmitted. The communication mechanism between the TEE module and the OS kernel corresponding to the user area adopts the shared memory method, custom protocol handshaking and transmission, including the packet header, packet tail, and handshake signal of the data to be transmitted. At the same time, the SMC (ArmV8) Monitor soft call method or the IRQ interrupt method can be used. The OS corresponding to the user area can also send the program to be run in the TEE module to the TEE module after private key signature through the communication channel, and run in the space of the TEE module after passing the signature verification of the TEE module.
[0043] In this embodiment, the UEFI module is located in the user area and is used to perform trusted measurement on the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot. Specifically, refer to Figure 2 as shown. The UEFI firmware complies with international relevant standards and architectures, and adds trusted boot and firmware security protection functions. The specific trusted boot process is as follows: call the TEE module to perform trusted measurement on the UEFI firmware and start the UEFI firmware after determining that the UEFI firmware is trusted; use the UEFI firmware to traverse the motherboard devices to obtain relevant hardware information; call the TEE module to perform trusted measurement on the hardware information, and if it is trusted, perform trusted boot. It should be noted that in this embodiment, the TEE module is generally triggered by PBF to perform trusted measurement on the UEFI firmware. Before that, it is also necessary to determine whether the trusted measurement is the first measurement. If so, a corresponding whitelist is generated according to the first measurement result, so that the dynamically calculated hash value is matched with the whitelist in the subsequent measurement process; if the match is successful, the measurement result is determined to be trusted; if the match fails, skip and continue to start or report an error and prevent the start. That is, the UEFI firmware traverses the motherboard devices (drivers such as buses, boards, and bridges) and sends the data code to the TEE module to calculate the hash. If it is the first measurement, the whitelist is generated by default. From the second time on, the dynamically calculated hash is compared with the whitelist. If it is correct, start. If any one is incorrect, it can be skipped and continued to start or reported an error and prevented from starting according to the user's pre-configuration.
[0044] Further, after the traversed hardware information, the hard disk partition table data in the traversed hardware information can be split, and then the split data is sent to the TEE module in batches, so as to use the TEE module to measure the obtained batched data. Preferably, the hard disk partition table data can be split into data packets with the size of the shared memory as the unit, and then passed to the TEE module in batches for measurement, so as to realize the trustworthiness of the hard disk partition table boot process. That is, after the hard disk partition table data in the traversed hardware information is split, a plurality of data packets with the size of the shared memory as the unit are obtained.
[0045] In this embodiment, the TEE module is the only module with the physical read and write function of FLASH. It cooperates with the user area and the security area to complete the physical read and write of the FLASH chip where the UEFI firmware is located. The physical read and write function of FLASH is placed in the TEE module, and all other modules in the system do not have the FLASH read and write function, so as to realize the anti-firmware attack of the system. At the same time, it can prevent Bootkit and firmware viruses, and realize some functions of Trusted Computing 3.0. In addition, on the one hand, the TEE module completes operations in the isolated space to meet the trusted environment; on the other hand, it stores key data, keys, security policies and security controls in the isolated space, which is an important means of protecting against memory attacks and firmware attacks. The TEE and the OS are different address spaces. The TEE module is the logical space address, and the UEFI firmware is the physical space address. The UEFI plays a role in mapping the logical address to the physical address, which is convenient for the TEE module to be truly and securely configured at the underlying physical level. The mapping methods include driver programs, UEFI data structures, etc.
[0046] It can be understood that the TEE module runs in the isolated space of the security area, and can directly implement the security attributes of the memory and the security configuration of the heterogeneous computing unit while communicating with other modules. In this embodiment, the secure memory and the heterogeneous computing unit belong to the same module, and are also part of the device with the kernel architecture based on the PKS system. The TEE module is also used to configure the secure memory according to the configuration instructions in the user area. The heterogeneous computing unit can also be called xPU, including accelerators such as GPU, FPGA intelligent network card, etc., which are used to receive the mounted security software sent by the TEE module to perform heterogeneous computing processing on the mounted security software. That is, the secure memory receives the configuration from the OS to the TEE module according to the user configuration, the TEE module configures the secure memory, and the code of the xPU received from the OS can complete the execution of the security software on the xPU. Specifically, refer to Figure 2 as shown.
[0047] It can be seen that the device with the kernel architecture based on the PKS system in the embodiments of the present application includes the user area and the security area in the dual-architecture processor, and the UEFI module. Among them, the user area is used to call the operating system security module LSM to provide functions for security software to hook sub to uniformly manage software hooking, and to allocate operating resources for the hooked security software; the security area is used to call the TEE module to perform security verification and signature on the code loaded into the kernel when a resource access request is obtained. If the verification and signature pass, the code loaded into the kernel is run; among them, the permission of the security area is higher than that of the user area; the UEFI module is used to perform trusted measurement on the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot. The kernel architecture of the embodiments of the present application divides the non-secure computing and the secure computing into different spaces by dividing the user area and the security area. At the same time, based on the interaction between the TEE module and the UEFI module, the computing space status can be obtained in real time for protection, avoiding the few security space functions and weak performance caused by using the dual-architecture with external security.
[0048] The various embodiments in this specification are described in a progressive manner. The key point of each embodiment is the difference from other embodiments. The same or similar parts between the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0049] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0050] The above has introduced in detail the device with the kernel architecture based on the PKS system provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. An apparatus based on the kernel architecture of the PKS system, characterized in that, it includes: The user area in the dual-architecture processor is used to call the operating system security module LSM to provide functions for security software hooking sub to uniformly manage software hooking, and allocate operating resources for the hooked security software; The security area in the dual-architecture processor is used to, when a resource access request is obtained, call the TEE module to perform security verification and signature on the code loaded into the kernel. If the verification and signature pass, the code loaded into the kernel is run; among them, the permission of the security area is higher than that of the user area; The UEFI module located in the user area is used to perform trusted measurement on the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot; The performing trusted measurement on the UEFI firmware and the operating system through interaction with the TEE module to achieve trusted boot includes: Performing trusted measurement on the UEFI firmware by calling the TEE module and starting the UEFI firmware after determining that the UEFI firmware is trusted; Using the UEFI firmware to traverse the motherboard devices to obtain relevant hardware information; Performing trusted measurement on the hardware information by calling the TEE module. If it is trusted, perform trusted boot; After using the UEFI firmware to traverse the motherboard devices to obtain relevant hardware information, it further includes: Splitting the hard disk partition table data in the traversed hardware information; Sending the split data in batches to the TEE module to use the TEE module to measure the obtained batch data.
2. The apparatus based on the kernel architecture of the PKS system according to claim 1, characterized in that, The user area and the security area are divided by configuring relevant registers based on the PSPA specification, and a custom protocol handshake and transmission of the data packet to be transmitted are performed in the way of shared memory.
3. The apparatus based on the kernel architecture of the PKS system according to claim 1, characterized in that, The user area is further used for: Dynamically performing private key signature on the code to be loaded into the kernel processed by the eBPF loader and then sending it to the TEE module, so that the TEE module runs after verifying the signature of the code to be loaded into the kernel with the private key.
4. The apparatus based on the kernel architecture of the PKS system according to claim 1, characterized in that, Before performing trusted measurement on the hardware information by calling the TEE module, it further includes: Judging whether the trusted measurement is the first measurement; If so, generating a corresponding whitelist according to the first measurement result, so that the dynamically calculated hash value is matched with the whitelist during the subsequent measurement process; If the match is successful, the measurement result is determined to be trusted; If the match fails, skip and continue to start or report an error and prevent the start.
5. The apparatus based on the kernel architecture of the PKS system according to claim 1, characterized in that, The splitting the hard disk partition table data in the traversed hardware information includes: Split the hard disk partition table data in the traversed hardware information to obtain multiple data packets in units of shared memory size.
6. The device based on the kernel architecture of the PKS system according to any one of claims 1 to 5, characterized in that the TEE module is the only module with the physical read and write function of FLASH.
7. The device based on the kernel architecture of the PKS system according to any one of claims 1 to 5, characterized in that further comprising: a heterogeneous computing unit, configured to receive the mounted security software sent by the TEE module, so as to perform heterogeneous computing processing on the mounted security software.
8. The device based on the kernel architecture of the PKS system according to any one of claims 1 to 5, characterized in that the TEE module is further configured to configure the secure memory according to the configuration instruction of the user area.
Citation Information
Patent Citations
A trusted computing software integrity measurement system and method
CN113919004A