Process-based virtualization system for executing secure application processes
By introducing a process-based virtualization system into the computer system and using firmware to execute secure applications independently of the operating system, the problem of fragile execution of secure applications in the prior art is solved, and effective isolation between secure applications and non-secure applications and overall security improvement of the system is achieved.
Patent Information
- Application Number
- CN202080093368.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-01-24
- Filing Date
- 2020-12-10
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2040-12-10
AI Technical Summary
Existing container managers rely on operating systems, resulting in fragile execution of secure applications and making it difficult to effectively isolate secure applications from non-secure applications.
By introducing a process-based virtualization system into the computer system, the firmware is used to execute secure applications independently of the operating system, and the second memory component is used to store and execute secure application code to ensure isolation between secure applications and non-secure applications.
Isolation and protection of secure applications is achieved to prevent potential security vulnerabilities, improve the overall security of the system, while seamlessly integrating with existing systems.
Smart Images

Figure CN114945900B_ABST
Abstract
Description
Background Art
[0001] The present invention relates to the field of digital computer systems, and more particularly, to a process-based virtualization system.
[0002] Container managers such as Docker are a set of coupled software-as-a-service and platform-as-a-service products that use operating system-level virtualization to develop and deliver software in packages called containers. However, due to the container's dependence on the operating system in which the container is deployed, the execution of the container can be fragile. Summary of the invention
[0003] Various embodiments provide methods of executing secure applications, process-based virtualization systems, and computer program products. Advantageous implementations are also described. The embodiments of the present invention may be freely combined with each other if they are not mutually exclusive.
[0004] In one aspect, the present invention relates to a process-based virtualization system, comprising: a computer-readable storage medium (or machine-readable medium), wherein a first memory component of the computer-readable storage medium is configured to be accessed by an operating system (OS), secure applications and non-secure applications, and firmware of the process-based virtualization system, and wherein a second memory component of the computer-readable storage medium is configured to be accessed by the firmware and the secure application but not by the OS and not by the non-secure application, the data processing unit is configured to operate in a first operating mode using the OS to execute non-secure applications, and the data processing unit is configured to operate in a second operating mode using the firmware to execute the secure application, thereby using the second memory component to execute application code of the secure application.
[0005] In one aspect, the present invention relates to a method, comprising: providing a computer-readable storage medium, wherein a first memory component of the computer-readable storage medium is configured to be accessed by an OS, a secure application and a non-secure application, and a firmware, and wherein a second memory component of the computer-readable storage medium is configured to be accessed by the firmware and the secure application but not by the OS and not by the non-secure application, providing a data processing unit, wherein the data processing unit is configured to operate in a first operating mode using the OS to execute a non-secure application, and configuring the data processing unit to operate in a second operating mode using the firmware to execute the secure application, thereby using the second memory component to execute application code of the secure application.
[0006] On the other hand, the present invention relates to a computer program product comprising a computer-readable storage medium having a computer-readable program code embodied therewith, wherein the computer-readable program code is configured to implement all the steps of the method according to the aforementioned embodiments.
[0007] In addition, any component of the present invention can be deployed, managed, serviced, etc. by a service provider that provides process-based virtualization in a computer system. Embodiments of the present invention also provide and include related systems, methods and / or program products. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] These and other features of the present invention will be more readily understood from the following detailed description of the various aspects of the invention taken in conjunction with the accompanying drawings.
[0009] Embodiments of the invention are explained in more detail below, by way of example only, with reference to the accompanying drawings, in which:
[0010] Figure 1A is a block diagram of an example process-based virtualization system in accordance with the inventive subject matter.
[0011] Figure 1B is a block diagram of an example process-based virtualization system in accordance with the inventive subject matter.
[0012] Figure 2 is a machine state table according to an example of the present invention.
[0013] Figure 3A is a flow chart of a method for executing a security application according to an example of the inventive subject matter.
[0014] Figure 3B A diagram illustrating first and second memory components of an example process-based virtualization system according to the inventive subject matter.
[0015] Figure 3C A diagram illustrating first and second memory components of an example process-based virtualization system according to the inventive subject matter.
[0016] Figure 4 is a flow chart of a method for executing a security application according to an example of the inventive subject matter.
[0017] Figure 5 is a flow chart of a method for executing a security application according to an example of the inventive subject matter.
[0018] Fig. 6A A data structure illustrating an address translation tree for a process-based virtualization system according to an example of the inventive subject matter is described.
[0019] Figure 6BA data structure illustrating an address translation tree for a process-based virtualization system according to an example of the inventive subject matter is described.
[0020] Figure 6C A diagram showing a data processing unit according to an example of the inventive subject matter.
[0021] Fig.6D A flow chart illustrating an example address translation process according to the inventive subject matter is described. DETAILED DESCRIPTION
[0022] Detailed embodiments of the present invention are disclosed herein with reference to the accompanying drawings. In the accompanying drawings, the same reference numerals represent the same elements. It should be understood that the disclosed embodiments are only potential embodiments of the present invention and may take different forms. In addition, each example given in conjunction with various embodiments is intended to be illustrative rather than restrictive. In addition, the drawings are not necessarily drawn to scale, and some features may be enlarged to show the details of specific components. Therefore, the specific structural and functional details disclosed herein should not be interpreted as limiting, but are merely representative bases for teaching those skilled in the art to adopt the present invention in different ways.
[0023] References in the specification to "one embodiment", "an embodiment", "an exemplary embodiment", etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment may necessarily include the particular feature, structure, or characteristic. In addition, such phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in conjunction with an embodiment, it is considered to be within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in conjunction with other embodiments (whether or not explicitly described).
[0024] The description of different embodiments of the present invention will be given for the purpose of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein are selected to best explain the principles of the embodiments, practical applications, or technical improvements to the technology found in the marketplace, or to enable those of ordinary skill in the art to understand the embodiments disclosed herein.
[0025] The code under the open source operating system is freely available for anyone to view and modify. However, this may expose computer systems running such OSs with usually millions of lines of code to potential security vulnerabilities. Specifically, processes that rely on the OS (such as instances of containers) may be exposed to security vulnerabilities because they are isolated only by software concepts such as namespaces and control groups (also known as cgroups). The subject matter of the present invention can enable a computer system / firmware to be independent of the OS and use hardware to execute the process of a secure application in a secure manner to isolate the secure application from other applications. The secure application process is different from the non-secure application process. For example, the address space is set for the secure application by the firmware instead of the OS. In addition, the firmware controls the execution of the secure application instead of the OS. However, untrusted applications can run under the control of the OS. This may be particularly advantageous because the number of secure applications is generally much smaller than the number of non-secure applications due to the effort required to implement secure applications. Therefore, adapting the system to secure applications can protect access to data while still seamlessly integrating with existing systems. For example, compared to the OS, the firmware can have much fewer lines of code because it only needs to use the encrypted data of the secure application to complete tasks that the OS cannot complete.
[0026] The inventive subject matter may provide transparent execution of processes to a user of a process-based virtualization system. That is, the user may not see the difference between the execution of his / her secure application and a non-secure application. A process may be an instance of a computer program being executed. A secure application process may be an instance of a secure application being executed. A non-secure application process may be an instance of a non-secure application being executed. Secure applications and non-secure applications may be defined by the user, for example, a user may define an application as a secure application or a non-secure application.
[0027] A process-based virtualization system may be, for example, a container-based virtualization system. A process-based virtualization system may be a computer system. A process-based virtualization system may implement operating system-level virtualization. OS-level virtualization may be enabled by the kernel of a process-based virtualization system, which allows the existence of multiple isolated namespaces. A container may be one of such namespaces. A container may include an application and all the parts it requires, such as libraries and other dependencies. A container manager may be installed in a process-based virtualization system to manage (e.g., create, delete, start, etc.) containers. The container manager may be, for example, Docker or LXC. If a container is running in a virtual machine (VM) including a client OS in a process-based virtualization system, OS-level virtualization may be client OS-level virtualization. In another example, in the case where a process-based virtualization system does not include a virtual machine, OS-level virtualization may be host OS-level virtualization.
[0028] According to one embodiment, the firmware is configured to: receive a system call from a process (e.g., named 'scall' for clarity of description), the system call indicating that a security application is stored in an encrypted format in a first memory component (the first memory component stores the encrypted security application), upon receiving the system call, configure the data processing unit to operate in a second operating mode, copy or transfer the encrypted security application in the second memory component and decrypt the copied or transferred security application in the second memory component, set an address translation structure to enable access to data in the second memory component and the first memory component through the decrypted security application, and execute the decrypted security application, wherein the execution includes using the address translation structure to access the second memory component.
[0029] The process sending scall can be a non-safe application process of a non-safe application. The system call scall of the non-safe application process can point to the safety application in the first memory component. For example, the system call scall of the non-safe application process can point to the integrity-protected code portion and the encryption-protected code portion of the safety application in the first memory component. Because the code of the loaded safety application is encrypted and integrity-protected, a system call scall can be made from the safety portion. The firmware can copy the integrity-protected code portion and the encryption-protected code portion to the second memory component. Decryption and integrity checks can be completed in the second memory component. If those checks pass (or succeed), the code of the safety application can be executed as a safety process. In another example, the safety application can be part of a safety container, wherein the process sending scall can be part of the safety container. For example, the system call scall can be sent by the library OS of the safety container. In a further example, the process sending scall can be part of a safety VM (SVM). The safety application process can directly point to the decrypted and integrity-checked code in the second memory component.
[0030] According to one embodiment, the firmware is configured to: receive a process initialization system call from a process, the call indicating that the security application is stored in an encrypted format in a first memory component, upon receiving the process initialization system call, configure the data processing unit to operate in a second operating mode, transfer or copy the encrypted security application to a second memory component, then decrypt the transferred or copied security application in the second memory component, and set an address translation structure for allowing the decrypted security application to access data in the second memory component and the first memory component. The address translation structure can be set so that the decrypted security application can use the library OS call. The process that sends the initialization system call can be a non-security application process that is a non-security application.
[0031] The execution of the security application process can be enabled by an initialization phase and a security application execution phase. This embodiment can enable the initialization phase. During the initialization phase, the firmware can set up memory and / or interfaces that can be used by the security application when executing. Separating the initialization phase from the security application execution phase can enable the security application to be executed without changing the code of the security application. During the security application execution phase, the decryption of the input data of the security application and the encryption of the output data of the security application can be completed by library OS calls, so that the input or output data can be read or stored in the first memory component. The data processing unit can be in a first security state (as described herein) in the initialization phase and in a second security state in the security application execution phase.
[0032] According to one embodiment, the address translation structure includes a partition table and a security process table for a security process, and the partition table and the security process table are stored in a second memory component, wherein setting the address translation structure includes: adding a partition entry to the partition table, the added partition entry pointing to the security process table; and adding a process entry to the security process table, the process entry being associated with a security application process of a security application, the added process entry pointing to a security application address translation tree, and the security application address translation tree is configured to enable conversion of an effective address into a physical address of the second memory component.
[0033] The safe application transformation tree can be a single-level partition-range radix transformation tree, an example of which is shown in Fig.6D The number is 624. The added process entry can enable the page directory and page table of the secure application address translation tree to be located.
[0034] According to one embodiment, the firmware is configured to: further receive an address indicating a storage location of the encrypted security application in the first memory component, with which to perform the decryption and the copying.
[0035] Transferring the instructions of the secure application from the first memory component to the second memory component can prevent access to the instructions in the second memory component by, for example, the OS and non-secure applications. This may also be advantageous because it can enable seamless integration of the subject matter of the invention with existing systems. For example, the secure application is started in the first memory component as any other application.
[0036] The received address may be, for example, a received process initialization system call or a part of a received system call (scall).
[0037] According to one embodiment, an unencrypted secure application is associated with a hash value indicative of the content of the secure application, and the firmware is further configured to perform an integrity check of the unencrypted content of the secure application with the hash value. If the integrity check succeeds, decryption and copying are performed. The integrity check may include determining whether the hash value still represents the current content of the secure application. If it does, decryption and copying may be performed. In an alternative embodiment, the integrity check is performed simultaneously with the decryption. If the integrity check passes, the decryption succeeds, otherwise the decryption fails.
[0038] This embodiment can further increase the security aspect of the inventive subject matter, since it can prevent access to the code of the security application even before the security application is started to be executed. This can, for example, prevent malicious modification of the security application before it is executed by the firmware.
[0039] According to one embodiment, a data processing unit comprises a partition table, the partition table being indexed by a logical process identifier (LPID), the partition table comprising an entry pointing to a secure process table, wherein the entry is indexed by a fixed value, the secure process table being indexed by a secure process identifier (SPID), the data processing unit further comprising a secure register comprising a value of the SPID of a secure application process, the secure application process being configured to identify the secure process table using the fixed value, and to use / read a value stored in the secure register to perform an address translation using an entry of the secure process table associated with the read value of the security register, the read value being the SPID value stored in the security register.
[0040] The fixed value may be a reserved effective LPID, ie, effLPID='FFF'x.
[0041] The secure process table is a table maintained by the firmware that describes the processes in memory. Indexing the secure process table by the SPID of the secure process can further enhance the security aspects of the subject matter of the present invention, because the secure process can be assigned an ID that can only be accessed by the firmware and the secure application process itself. For example, the SPID is used to find the memory table associated with the secure application process. The memory table is located in the secure memory (the second memory component) and can only be accessed by the firmware (and the address translation hardware). The location in the memory table is accessible to the secure application process and the firmware. If the secure application process is running in secure mode (the second operating mode), the hardware is allowed to utilize the memory table.
[0042] According to one embodiment, after setting the translation structure, the firmware is further configured to: receive an application start system call from a process, the application start system call including an address; upon receiving the application start system call, execute the decrypted secure application, the execution including using the address translation structure to access the second memory component. This embodiment can implement a secure application execution phase. The process sending the application start system call can be a non-secure application process.
[0043] According to one embodiment, the data processing unit has at least two security states in the second operating mode, the first of the two security states being a firmware state in which the data processing unit allows the execution of firmware, and the second of the two security states being a secure application process state in which the data processing unit allows the execution of secure application processes.
[0044] According to one embodiment, the data processing unit is configured to switch to the first security state upon receiving a process initialization system call or an interrupt request, and to switch to the second security state upon receiving an application start system call.
[0045] In case of receiving a (single) system call scall, the data processing unit is configured to transfer or copy the security application to the secure memory (second memory component) when receiving the system call (scall), or is configured to receive an interrupt request and allow the process to start or resume execution in the second security state when setting the conversion structure. If the encryption or integrity check of the security application fails, the execution of the security process cannot be started.
[0046] According to one embodiment, a data processing unit includes a machine status register (MSR), the MSR includes a security bit, the security bit is set to a first value to indicate that the data processing unit operates in a first operating mode, and wherein the security bit is set to a second value to indicate that the data processing unit operates in a second operating mode. For example, when the data processing unit operates in the first operating mode, data written to the computer-readable storage medium is written to the first memory component, and when the data processing unit operates in the second operating mode, the computer-readable storage medium is configured to enable access to the data to the first memory component and the second memory component.
[0047] According to one embodiment, a secure application process is an executable instance of a container that includes a secure application.
[0048] According to one embodiment, the container runs in a virtual machine of a process-based virtualization system.
[0049] Figure 1A1 is a block diagram of a process-based virtualization system 100 according to an example of the subject matter of the present invention. The process-based virtualization system 100 includes a host operating system (hypervisor) 110, firmware 120, hardware 130, a secure virtual machine (SVM) 140, and a VM 150. The hardware 130 may, for example, include a data processing unit (e.g., a processor core) according to an example of the subject matter of the present invention. The components of the process-based virtualization system 100 may be interconnected via a network (not shown) (e.g., a local area network (LAN), a wide area network (WAN) (such as the Internet), or a combination of both), and include wired, wireless, or fiber optic connections. The process-based virtualization system 100 may be a desktop computer, a laptop computer, a dedicated computer server, or any other computer system known in the art. In some embodiments, the process-based virtualization system 100 may represent a computer system that utilizes cluster computers and components to act as a single seamless resource pool when accessed through a network. For example, such an embodiment may be used in data centers, cloud computing, storage area networks (SANs), wide area networks (WANs), and network attached storage (NAS) applications. Generally speaking, the computing systems described herein represent an electronic device or combination of electronic devices capable of executing machine-readable program instructions according to examples of the present subject matter.
[0050] Hypervisor 110 represents system software such as a virtual machine monitor (VMM) configured to manage, create, and execute SVM 140 and VM 150. Hypervisor 110 may be an untrusted system software component. Hypervisor 110 may be configured to access and manage a first memory component of a computer-readable storage medium of system 100.
[0051] Firmware 120 represents a trusted system software component configured to provide control, monitoring, and manipulation of data performed by trusted hardware 130. In this embodiment, firmware 120 manages a second memory component of a computer-readable storage medium of the system. In addition, each SVM 140 and secure container (or secure application) can be assigned to the second memory component. Firmware 120 operates in ultravisor mode, which is a privileged level above the hypervisor 110 mode. The ultravisor may refer to firmware. In ultravisor mode, firmware 120 is configured to control a regular partition-wide address translation mechanism in conjunction with hardware 130 for maintaining separation between the first and second memory components. In addition, firmware 120 is configured to maintain separation of each SVM 140 and the secure container within the second memory component ( Figure 3B and 3C 1 shows example contents of the first and second memory components. For example, the second memory component is configured to be accessed by the firmware and the secure application. The second memory component is configured so that the second memory component is not accessed by the OS and the non-secure application.
[0052] Hardware 130 mechanisms may be used to invoke firmware 120 whenever a transition between two memory components occurs, thereby enabling firmware 120 to ensure that the state of a process in one memory component is properly isolated from the state of a process in another memory component.
[0053] Subsystems of the process-based virtualization system 100 (not shown) can interact with the process-based virtualization system 100 memory independently of hardware 130 components such as processors. These subsystems can be modified so that all untrusted devices (e.g., input / output (I / O) devices) cannot access the second memory component. Subsystem data that is secure and used by secure applications can be stored in the first memory component in an encrypted format. In addition, the firmware 120 operating in the hypervisor mode can transfer or copy the encrypted data to the second memory component and decrypt it. In another example, the hardware can encrypt / decrypt under the instruction of the firmware 120. The secure data in the second memory component can be encrypted and a secure hash can be added before being stored in the hypervisor 110 / VM 150 memory domain (i.e., the first memory component). Thereafter, the encrypted data can be paged out to disk storage by the hypervisor 110. Therefore, data and state information related to the SVM 140 and the secure container may not be in plain text format outside the second memory component and is protected by the integrity of the secure hash.
[0054] Hardware 130 represents hardware components for system 100. In this embodiment, an SMF-enabled processor (e.g., a data processing unit may be an SMF-enabled processor) is included in hardware 130 and has a set of asymmetric keys and may have associated symmetric keys for protecting security data processed by SVM 140 and / or security applications.
[0055] SVM 140 is similar to VM 150. In addition, SVM 140 and security applications can be packaged for SMF with security data encrypted with the target processor's public SMF key. The private SMF key can be protected by a trusted platform module (TPM) and only becomes available when the correct firmware 120 is loaded during boot. In this embodiment, a trusted entity that manufactures and distributes SMF-enabled processors can issue a certificate for its public key.
[0056] The SVM can implement secure execution of applications running inside the SVM. To this end, the SVM trusts a given OS (e.g., client OS 160) rather than a hypervisor. However, if the OS is untrusted, the application running inside the conventional VM may need to be protected. That is, the secure application does not trust both the OS and the hypervisor 110 (if present). The subject matter of the present invention can enable protection of such applications. Each of the VMs and SVMs of the process-based virtualization system 100 can, for example, enable containers, where these containers can be secure containers and / or unsecure containers. The secure container represents a secure application, such as a banking operation. For example, VM 150 includes a container manager 170 for developing, delivering, installing, and executing containers 180A-N, which is executed at least in part by the client operating system 160, and the container represents a combination of container 180A and secure container 180N in this article. Note that there is another set of containers, represented here as container 180B, which includes a copy of the application and library operating system included in container 180A. In contrast, secure container 180N includes a secure version of the application and a secure library operating system. As used herein, the secure version of the application and the secure library operating system of the secure container 180N have a higher level of security when compared to the versions of the application and library operating system found in the container 180A and the container 180B. The container manager 170 may be, for example, Docker or LXC. The containers in the containers 180A-N may be created using the container manager 170. The container may, for example, include the application and the required libraries. The secure container 180N may include a secure application that may perform secure library calls for accessing data in the first and second memory components.
[0057] Container manager 170 can, for example, be configured to receive a container image for instantiation, installation, and / or execution in client operating system 160. For example, the container image can be a Docker image obtained from a container repository (such as a Docker registry). For example, a container image can be a read-only template with instructions for creating a container. Using the container image, containers 180A-N can be instantiated by container manager 170 to execute as one or more processes in client operating system 160.
[0058] The process-based virtualization system 100 enables virtualization using containers running within a VM.
[0059] Figure 1B is a block diagram of an example process-based virtualization system 190 in accordance with the inventive subject matter.
[0060] The process-based virtualization system 190 includes a main operating system (OS) 195, firmware 196, and hardware 197, as shown in FIG. Figure 1AHardware 197 may, for example, include a data processing unit (eg, a processor core) according to an example of the inventive subject matter.
[0061] The process-based virtualization system 190 provides virtualization using only containers, eg, without using VMs (ie, without a hypervisor).
[0062] The process-based virtualization system 190 can enable containers. The container can be a secure container and / or an unsecure container. For example, the process-based virtualization system 190 includes a container manager 191 for developing, delivering, installing, and executing containers 192A-N, which is executed at least in part by a host operating system (OS) 195. It should be understood that, similar to containers 180A and 180B, containers 192A and 192B include copies of application and library operating systems. Further, similar to secure container 180N, secure container 192N includes a more secure version of the application and library operating system. Container manager 191 can be, for example, Docker or LXC. Container manager 191 can be used to create containers in containers 192A-N.
[0063] Figure 2 is a table of bits from an MSR indicating a machine state of a data processing unit according to an example of the inventive subject matter. Different machine states are provided for first and second operating modes. In this example, a typical first operating mode 210 is extended with a second operating mode using an MSR(S) bit 220, which is, for example, a security bit.
[0064] In the first operating mode 210, the data processing unit can have four different machine states 251-254. Each of the four machine states 251-254 enables access to data and resources of the data processing unit for corresponding components such as the hypervisor 110 and non-secure applications. For example, if the MSR (S) bit 220 is set to 0, untrusted applications and the hypervisor 110 can be operated. In the case where the data processing unit is part of the process-based virtualization system 100, the state 252 is associated with the hypervisor 110, and in the case where the data processing unit is part of the process-based virtualization system 190, the state 252 is associated with the host OS 195. In order to simplify the description, the state 252 is referred to as the hypervisor state here.
[0065] If the MSR(S) bit 220 is set to 1, the second operating mode 210 may be active. For example, for a security application, the MSR(S) bit 220 is set to 1. In the second operating mode, the data processing unit may have machine states 241-244. At least two states 241-242 may be used to implement the execution of the security application. In order for the executed security application (e.g., in VM 150) to operate unchanged, two states are supported with the MSR(S) bit 220 equal to 1.
[0066] Each machine state in machine states 241-244 and 251-254 can be defined by a corresponding combination of values of a set of bits of MSR. The set of bits can be maintained / set, for example, by firmware. The set of bits includes a security bit. The set of bits can also include an MSR (HV) bit and an MSR (PR) bit. In the second operating mode, the firmware state (or super shielding state) is defined by setting the MSR (S) bit 220, the MSR (HV) bit 230, and the MSR (PR) bit 240 to 1, 1, and 0, respectively. In order to execute a secure application, the MSR (PR) bit can be flipped so that the data processing unit is in state 0b111. Therefore, in the absence of a code change of the code of the secure application, when the hypervisor state 252 would otherwise be entered, the firmware can maintain control instead of the hypervisor 110 (or host OS 195). This enables the security data and state information to be saved and cleared before the firmware takes control of the hypervisor 110 (or host OS 195). The state transition from the firmware state to the hypervisor state may be performed by resetting the MSR(S) bit 220 to 0 by the firmware return of the interrupt double word instruction. This provides an example implementation and those skilled in the art may implement alternative equivalent mechanisms.
[0067] The data processing unit can be configured to switch or convert between states 241-244 and 251-254 to allow components associated with the state it switches to to access data. For example, in state 241 (MSR(S, HV, PR)=0b111), a secure application can be executed and can be allowed to access data stored in secure memory. The hardware 130 can be configured so that only the firmware can set the MSR(S) bit. In order for the firmware 120 to control the transition between the secure state and the non-secure state and ensure the security of the SVM or secure process / container, it controls the MSR(S) bit, or receives control at any time when the state is automatically changed by the hardware.
[0068] Figure 3A is a flow chart of a method for implementing execution of a secure application. The secure application may, for example, be part of a secure container 180N. Figure 1A or Figure 1B The invention implements the execution of a secure application process in a system, but is not limited to this implementation manner.
[0069] In step 301, the data processing unit may be configured to operate in the second operating mode. By setting the security bit to 1. Step 301 may be performed, for example, when a process initialization system call or another system call (e.g., named scall) from a given process is received by the firmware 120. The given process may be a process of a non-secure application. The firmware 120 may, for example, set the security bit MSR (S) so that the data processing unit can operate in the second operating mode.
[0070] The received process initialization system call (or received scall) may point to an encrypted file containing a secure application in a secure container 180N in an encrypted format in a first memory component. Figure 3B and 3C The example contents of the first and second memory components of the process-based virtualization systems 100 and 190 are shown respectively. The first memory component of the process-based virtualization system 100 (referred to herein as conventional memory 310A) includes an encrypted secure application and secure library operating system 302, VM 150 (which may include a docker engine), client OS 160, and a secure container in an encrypted format. The first memory component 310B of the process-based virtualization system 190 includes a container manager 191, a host OS 195, and a secure container in an encrypted format using the operating system 302 including encrypted and secure applications and libraries.
[0071] In step 303, firmware 120 moves the encrypted secure application into the second memory component. In step 304, firmware 120 may decrypt the secure application. In one example, the firmware may perform an integrity check on the decrypted secure application. The integrity check may be performed using a hash associated with the unencrypted contents of the secure application. Ensure that nothing has been changed in the code (e.g., flipped bits). If the integrity check fails, the transition to the secure process / container fails and the second memory component is cleared before returning. In this case, steps 305-307 are not performed. Figure 3B As shown, the second storage component 312A (which is the secure storage of the process-based virtualization system 100) includes a conversion: a radix tree 309, a firmware 120 with effLPID=FFF, and a secure container 308 including a secure application and a secure library OS in an unencrypted format. The second storage component 312A may further include an SVM 140 in an unencrypted format. Figure 3B As shown, a second memory component of the process-based virtualization system 190 (referred to herein as secure memory 312B) includes a transformation: a radix tree 309, firmware 196, and a secure container 308, which includes a secure container in an unencrypted format.
[0072] In step 305, the firmware 120 establishes a conversion structure in the second memory component to enable the secure application to access the data in the second memory component. The conversion structure may include: Fig.6D The partition table and process table shown. This setting can be performed by creating a new entry in the partition table pointing to the secure process table. For example, an entry can also be added to the secure process table that associates the secure application with the transition tree. The radix tree of the secure process range, such as Figure 3B and 3C Translation: Radix tree 309. That is, the firmware 120 has a partition table and uses the translation tree to establish address translation. For example, the second memory components 312A and 312B of the process-based virtualization systems 100 and 190 can store the secure application address translation tree.
[0073] In one example, Figure 3A The method may further include step 307 of starting the security application. In one example, in response to receiving an application start system call after receiving a process initialization system call, the starting of the security application may be performed. That is, steps 301 to 305 may be performed in response to the received process initialization system call, and step 307 may be performed in response to the received application start system call. In another example, steps 301 to 307 may be performed in response to other received system calls (scall).
[0074] Figure 4 is a flow chart of a method for executing a secure application.For example, the secure application may be part of a container, such as a container included in secure container 180N.
[0075] In step 401, the firmware 120 may receive an application start system call from a process of a non-secure application. The application start system call includes an address indicating a secure application address translation tree.
[0076] After receiving the application start system call, the firmware 120 may execute the security application in step 403. The execution of the security application includes accessing the second memory component using the security application address translation tree.
[0077] Figure 5 is a flowchart of a method for executing a secure container, such as a container included in secure container 180N.
[0078] In step 501, a system call (eg, ucall) of level lev=2 may be received. The system call is received to start a secure application of a secure container. The system call may be received when the data processing unit is in firmware state 0b110.
[0079] In step 503, the security application may be started (eg, using the urfid or hrifd instruction). The execution of the security application may be performed in the state MSR (S, HV, PR) = 0b111.
[0080] Interrupts caused or triggered by the security application may be handled as described with reference to steps 505 to 509. For example, if the security application requires an OS-enabled operation (e.g., for reading data from a disk), then in step 505, the data processing unit may switch to state 242 ((MSR(S, HV, PR)=0b110). In state 242, the firmware may manage OS operations on behalf of the security application. In order to keep the number of lines of code in the firmware limited, the firmware may use the OS in order to perform the requested security application operations. The firmware may switch the data processing unit to a given state that allows the OS to perform operations in steps 507-509. When the security application is Figure 1A In the case of a portion of a process-based virtualization system 100, the given state is state 254; in the case of a security application being Figure 1B In the case of a portion of a process-based virtualization system 190, the given state is state 252. The requested operation data may be encrypted before being stored in, for example, a first memory component. For example, the data may be provided or (pre)stored in an encrypted format on disk so that they can be requested by a security application. After the operation is completed, the data processing unit switches again to firmware state 242. When the OS completes the operation, if it chooses to resume the security application, it returns to firmware 120, which will resume the secure state 0b111 (241) and pass control to the security application. The firmware may, for example, pre-process the requested data or the result of the operation before switching to state 241 so that the security application continues to execute with the pre-processed data. The pre-processing may, for example, include encryption of output data of the security application or decryption of input data of the security application. Interrupts that are not associated with the security application and received when the security application is executed may be securely reflected to the OS.
[0081] In one example, the data processing unit may switch from state 241 0b111 to state 242 0b110 in step 505. The data processing unit may switch from state 242 0b110 to the hypervisor state in steps 507 and 509 to enable the host OS to process interrupts.
[0082] Figures 6A to 6D A data component enabling access to data stored in a second memory component according to an example of the inventive subject matter is shown. Fig. 6A and 6BData structures 601 and 610 are shown illustrating different states of a data processing unit for different received effective addresses. Data structures 601 and 610 indicate which translation tree may be used for a given received effective address (EA) of process-based virtualization systems 100 and 190, respectively.
[0083] Data structures 601 and 610 can be described as tables with cells, where each cell is defined by a pair of different values of two variables V1 and V2. Variable V1 refers to the value of the two first bits of the effective address as indicated in the first column of the data structure, and variable V2 refers to the value of the MSR (S, HV, PR) bits. The inventive subject matter uses the two first bits of the effective address to define the state of the data processing unit associated with each different value of V1.
[0084] Each cell of the data structure indicates two registers that contain the values of two identifiers. The two identifiers are a process identifier and a logical partition identifier (or VM identifier). For example, if the received address is in quadrant 0 (i.e., EA(0:1)=00) and MSR(S,HV,PR)=0b111, then the corresponding cell indicates a named register (e.g., SPIDR) from which the identifier of the process (sending the given address) and the identifier of the logical partition in which the process is running are converted. The address translation mechanism uses the contents of the indicated registers and the values of the logical partition identifiers as shown in the following example. Fig.6D The partition table shown is used to translate the given address (if the process is running in the correct mode).
[0085] The value of the MSR(S,HV,PR) bits can be obtained from Figure 6C 615. The MSR register may, for example, be part of an instruction sequencing unit (ISU) 616 of the data processing unit 615. In addition, the register indicated in the cell of the data structure, such as SPIDR, may be, for example, Figure 6C Part of the load store unit (LSU) / memory management unit (MMU) 617 of the data processing unit shown in .
[0086] like Fig.6D As shown in Fig. 6A and Figure 6B The values of the two registers in each cell of the data structure 601 can be used as indices of the partition table controlled by the firmware so that the conversion can be performed. For example, for a secure container, the two indices can enable the use of Fig.6D The partition scoped tree shown in is used to translate a given address.
[0087] like Fig.6DAs shown in , partition table 620 includes one entry for each logical partition ID. Each entry in partition table 620 references a corresponding process table. For example, an entry indexed by a logical partition ID equal to FFF may point to a process table such as Fig.6D The security process table 621 shown in FIG. Also, the entry indexed by the logical partition ID equal to 0 can point to the following: Fig.6D The conventional process table 622 shown in FIG. 6 is a conventional process table 622 shown in FIG. The secure process table 621 includes an entry for each secure process and is indexed by the secure process ID. Each entry in the secure process table 621 points to the location of the page directory and page table of the conversion tree 623. The conversion tree 623 can be as follows: Fig.6D The transformation tree 623 can be used to transform the partition range shown in FIG. Fig.6D Received effective address shown in . For example, the origin of the highest order translation table in the hierarchical translation table of the translation tree 623, such as provided by an entry of a secure process table associated with a secure application process. The effective address is used to index into each table of the hierarchical translation table to determine the origin address of the next table to locate, for example, a page table entry (PTE) having the address of a page of physical memory.
[0088] Some embodiments provide one or more of a method, a computer system, and a computer program product for process-based virtualization. At least one such embodiment includes granting an operating system, a secure application, a non-secure application, and firmware of a process-based virtualization system access to a first memory component of a computer-readable storage medium, wherein the firmware and the secure application are permitted to access a second memory component of the computer-readable storage medium, and the operating system and the non-secure application are prohibited from accessing the second memory component. An embodiment includes modifying a data processing unit to operate in a first operating mode so that the data processing unit executes a non-secure application with the operating system. An embodiment includes modifying a data processing unit to operate in a second operating mode so that the data processing unit executes a secure application with the firmware, and uses the second memory component to execute application code of the secure application.
[0089] At least one such embodiment includes receiving a system call from a process, wherein the system call indicates that a security application is being stored in an encrypted format in a first memory component. At least one such embodiment includes modifying a data processing unit to operate in a second operating mode in response to receiving the system call. At least one such embodiment includes copying the encrypted security application in a second memory component. At least one such embodiment includes decrypting the security application in the second memory component. At least one such embodiment includes generating an address translation structure that provides access by the decrypted security application to data in the second memory component and the first memory component. At least one such embodiment includes executing the decrypted security application so that the second memory component is accessed using the address translation structure.
[0090] At least one such embodiment includes firmware including program instructions for performing a method. The method includes receiving a process initialization system call from a process, the process initialization system call indicating that a security application is being stored in an encrypted format in a first memory component. The method includes responding to the receipt of the process initialization system call. The method includes configuring a data processing unit to operate in a second operating mode. The method includes copying the encrypted security application in a second memory component. The method includes decrypting the security application in the second memory component. The method includes generating an address translation structure that authorizes the decrypted security application to access data in the second memory component and the first memory component.
[0091] In at least one embodiment, the address translation structure includes a partition table and a secure process table. In at least one embodiment, the partition table and the secure process table are stored in a second memory component. In at least one embodiment, generating the address translation structure includes adding (i) a partition entry pointing to the secure process table and (ii) a process entry associated with a secure application process of the secure application to the partition table, wherein the process entry points to a secure application address translation tree that enables translation of an effective address to a physical address.
[0092] At least one embodiment includes firmware including program instructions for performing a method. The method includes receiving an address indicating a storage location of a security application in a first memory component. The method includes using the address to copy an encrypted security application and decrypting the security application.
[0093] In at least one embodiment, the encrypted security application is associated with a hash value associated with the content of the encrypted security application.In at least one embodiment, a method that may be performed by firmware includes performing an integrity check on the encrypted security application using the hash value.
[0094] In at least one embodiment, the address translation structure includes a partition table and a secure process table, wherein the partition table is indexed by a logical process identifier. In at least one embodiment, the partition table includes an entry pointing to the secure process table, wherein the entry pointing to the secure process table is indexed by a fixed value. In at least one embodiment, the secure process table is indexed by the secure process identifier. In at least one embodiment, the data processing unit includes a security register, the security register including the value of the secure process identifier of the secure application process of the secure application. In at least one embodiment, the secure application process identifies the secure process table using the fixed value, and uses the value stored in the security register to perform an address translation using the entry of the secure process table associated with the value of the security register.
[0095] At least one embodiment includes firmware including program instructions for performing a method. The method includes determining that a translation structure has been created. The method includes receiving an application start system call from the process. The method includes: upon receiving the application start system call, executing a decrypted secure application by accessing a second memory component using the address translation structure.
[0096] In at least one embodiment, the data processing unit includes at least a first security state and a second security state in the second operating mode. In at least one embodiment, the first security state includes a firmware state in which the data processing unit allows the execution of firmware, and the second security state includes a secure application process state in which the data processing unit allows the execution of secure applications.
[0097] In at least one embodiment, the method includes switching to a first security state in response to receiving a process initialization system call or an interrupt request. In at least one embodiment, the method includes switching to a second security state in response to receiving an application start system call.
[0098] In at least one embodiment, the data processing unit includes a set of bits whose values indicate first and second security states.
[0099] In at least one embodiment, the data processing unit includes a machine status register, wherein the set of bits includes a machine status register bit indicating an operating mode of the data processing unit, a machine status register bit indicating a hypervisor state, and a machine status register bit indicating a privileged state or a problem state of the machine status register.
[0100] In at least one embodiment, the data processing unit includes a machine state register including a security bit, wherein setting the security bit to a first value causes the data processing unit to operate in a first operating mode, and setting the security bit to a second value causes the data processing unit to operate in a second operating mode. In at least one embodiment, in the first operating mode, the data processing unit writes data written to the computer-readable storage medium to the first memory component. In at least one embodiment, in the second operating mode, the computer-readable storage medium is modified to access data included in the first memory component and the second memory component.
[0101] In at least one embodiment, a security application process of a security application is an executable instance of a container that includes the security application. In at least one embodiment, the container executes within a virtual machine of a process-based virtualization system.
[0102] The present invention may be a system, method and / or computer program product of any possible degree of technical detail integration. The computer program product may include a computer-readable storage medium having computer-readable program instructions thereon for causing a processor to execute various aspects of the present invention.
[0103] Computer readable storage medium can be a tangible device that can retain and store instructions for use by instruction execution devices. Computer readable storage medium can be, for example but not limited to, electronic storage device, magnetic storage device, optical storage device, electromagnetic storage device, semiconductor storage device or any suitable combination of the above. A non-exhaustive list of more specific examples of computer readable storage medium includes the following: portable computer disk, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanical encoding device such as punch card or protruding structure in the groove with instructions recorded thereon, and any suitable combination of the above. Computer readable storage medium as used herein should not be interpreted as transient signal itself, such as radio wave or other free propagating electromagnetic wave, electromagnetic wave propagated by waveguide or other transmission medium (for example, light pulse passing through fiber optic cable) or electrical signal emitted by wire.
[0104] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network), or downloaded to an external computer or external storage device. The network can include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in a computer-readable storage medium in the corresponding computing / processing device.
[0105] The computer-readable program instructions for performing the operation of the present invention can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, configuration data of integrated circuits, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages (such as Smalltalk, C++, etc.) and process programming languages (such as "C" programming languages or similar programming languages). The computer-readable program instructions can be executed completely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer, partially on the remote computer, or completely on the remote computer or server. In the latter case, the remote computer can be connected to the user's computer through any type of network (including local area network (LAN) or wide area network (WAN)), or can be connected to an external computer (for example, using an Internet service provider through the Internet). In some embodiments, the electronic circuit including, for example, a programmable logic circuit, a field programmable gate array (FPGA) or a programmable logic array (PLA) can be executed by using the state information of the computer-readable program instructions to personalize the electronic circuit to perform computer-readable program instructions, so as to perform various aspects of the present invention.
[0106] The present invention is described with reference to the flowchart and / or block diagram of the method, device (system) and computer program product according to the embodiment of the present invention. It should be understood that each frame of the flowchart and / or block diagram and the combination of frames in the flowchart and / or block diagram can be implemented by computer-readable program instructions.
[0107] These computer-readable program instructions can be provided to a processor of a computer or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device create a device for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, which causes the computer, programmable data processing device, and / or other equipment to work in a specific manner, so that the computer-readable storage medium in which the instructions are stored includes a manufactured product containing instructions for implementing aspects of the functions / actions specified in one or more boxes of the flowchart and / or block diagram.
[0108] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device, so that a series of operational steps are performed on the computer, other programmable apparatus, or other device to produce computer-implemented processing, so that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / actions specified in or in multiple boxes in the flowchart and / or block diagram.
[0109] The flow chart and block diagram in the accompanying drawings show the architecture, function and operation of the possible implementation of the system, method and computer program product according to different embodiments of the present invention. To this end, each box in the flow chart or block diagram may represent a module, segment or part of an instruction, which includes one or more executable instructions for implementing a specified logical function. In some alternative implementations, the function marked in the box may not occur in the order marked in the figure. For example, the two boxes shown in succession can actually be completed as a step, and are executed simultaneously, substantially simultaneously, in a partially or completely overlapping manner in time, or the boxes can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of each box in the block diagram and / or flow chart, can be implemented with a dedicated hardware-based system that performs a specified function or action or performs a combination of dedicated hardware and computer instructions.
Claims
1. A computer system for process-based virtualization, the computer system include: one or more computer processors; at least one computer-readable storage medium, the at least one computer-readable storage medium itself not being a transient signal; as well as Program instructions stored on the at least one computer-readable storage medium, the program instructions being executable by at least one of the one or more computer processors to cause the at least one computer processor to perform a method comprising: Granting an operating system, a secure application, a non-secure application, and firmware of a process-based virtualization system access to a first memory component of a computer-readable storage medium, wherein the firmware and the secure application are permitted to access a second memory component of the computer-readable storage medium, and the operating system and the non-secure application are prohibited from accessing the second memory component; modifying a data processing unit to operate in a first operating mode such that the data processing unit executes the non-secure application using the operating system; and modifying the data processing unit to operate in a second operating mode such that the data processing unit executes the security application using the firmware and executes application code of the security application using the second memory component, Wherein, the firmware includes: program instructions for receiving from a process a process initialization system call instructing the security application to store in an encrypted format in the first memory component; program instructions for configuring the data processing unit to operate in a second operating mode in response to receiving the process initialization system call; program instructions for copying the encrypted secure application in a second memory component and decrypting the secure application in the second memory component; and Program instructions for generating an address translation structure that grants the decrypted security application access to data in the second memory component and the first memory component.
2. The system according to claim 1, in, The firmware includes: program instructions for receiving a system call from a process, wherein the system call indicates that the security application is being stored in an encrypted format in a first memory component; program instructions for modifying the data processing unit to operate in a second operating mode in response to receiving the system call; program instructions for copying the encrypted security application in a second memory component; program instructions for decrypting the secure application in the second memory component; program instructions for generating an address translation structure that provides access by the decrypted security application to data in the second memory component and the first memory component; and Program instructions for executing the decrypted security application to access a second memory component using the address translation structure.
3. The system according to claim 1, in, The address translation structure includes a partition table and a security process table, wherein the partition table and the security process table are stored in a second memory component, and wherein generating the address translation structure includes adding (i) a partition entry pointing to the security process table and (ii) a process entry associated with the security application process of the security application to the partition table, wherein the process entry points to a security application address translation tree that enables conversion of an effective address into a physical address.
4. The system according to claim 1, wherein the firmware include: for receiving program instructions indicating an address of a storage location of the security application in the first memory component; as well as Program instructions for using the address to copy the encrypted security application and to decrypt the security application.
5. The system according to claim 1, in, The encrypted security application is associated with a hash value associated with content of the encrypted security application, and wherein the firmware includes program instructions for performing an integrity check of the encrypted security application using the hash value.
6. The system according to claim 1, in, The address translation structure includes a partition table and a security process table, wherein the partition table is indexed by a logical process identifier; wherein the partition table includes entries pointing to the security process table, wherein the entries pointing to the security process table are indexed by a fixed value, wherein the security process table is indexed by a security process identifier, wherein the data processing unit includes a security register, wherein the security register includes the value of a security process identifier of a security application process of the security application, wherein the security application process uses the fixed value to identify the security process table, and uses the value stored in the security register to perform address translation of an entry of the security process table associated with the value of the security register.
7. The system according to claim 1, wherein the firmware include: program instructions for determining that the conversion structure has been created; receiving a program instruction from the process for the application to initiate a system call; as well as Program instructions for executing the decrypted secure application upon receiving the application start system call by accessing a second memory component using the address translation structure.
8. The system according to claim 1, in, The data processing unit includes at least a first security state and a second security state in the second operating mode, wherein the first security state includes a firmware state in which the data processing unit enables execution of the firmware, and the second security state includes a security application process state in which the data processing unit enables execution of the security application.
9. The system according to claim 8, wherein the data processing unit include: Program instructions for switching to a first security state in response to receiving a process initialization system call or an interrupt request, and switching to a second security state in response to receiving an application start system call.
10. The system according to claim 8, in, The data processing unit includes a set of bits, the values of which indicate a first security state and a second security state.
11. The system according to claim 10, in, The data processing unit includes a machine status register, wherein the set of bits includes a machine status register bit indicating an operating mode of the data processing unit, a machine status register bit indicating a hypervisor state, and a machine status register bit indicating a privileged state or a problem state of the machine status register.
12. The system according to claim 1, in: (i) the data processing unit comprises a machine state register, the machine state register comprising a security bit, wherein the security bit being set to a first value causes the data processing unit to operate in a first operating mode, and wherein the security bit being set to a second value causes the data processing unit to operate in a second operating mode; (ii) in a first operating mode, the data processing unit writes data written to the computer-readable storage medium to a first memory component; as well as (iii) in a second operating mode, the computer-readable storage medium is modified to access data included in the first memory component and the second memory component.
13. The system according to claim 1, in, The security application process of the security application is an executable instance of a container that includes the security application.
14. The system according to claim 13, in, The container executes within a virtual machine of the process-based virtualization system.
15. A method for process-based virtualization, the method include: granting, by at least one computer processor, an operating system, a secure application, a non-secure application, and firmware of a process-based virtualization system access to a first memory component of a computer-readable storage medium, wherein the firmware and the secure application are permitted to access a second memory component of the computer-readable storage medium, and the operating system and the non-secure application are prohibited from accessing the second memory component; modifying, by the at least one computer processor, a data processing unit to operate in a first operating mode such that the data processing unit executes the non-secure application using the operating system; and modifying, by the at least one computer processor, the data processing unit to operate in a second operating mode such that the data processing unit executes the security application using the firmware and executes application code of the security application using a second memory component, Wherein, the method comprises: receiving, by the at least one computer processor, a process initialization system call from a process, the process initialization system call instructing the secure application to be stored in an encrypted format in a first memory component; configuring, by the at least one computer processor in response to receiving the process initialization system call, the data processing unit to operate in a second operating mode; copying, by the at least one computer processor, the encrypted security application in a second memory component and decrypting the security application in the second memory component; and An address translation structure is generated, by the at least one computer processor, that grants the decrypted security application access to data in the second memory component and the first memory component.
16. The method according to claim 15, wherein include: receiving, by the at least one computer processor, a system call from a process, wherein the system call indicates that the security application is being stored in an encrypted format in a first memory component; modifying, by the at least one computer processor in response to receiving the system call, the data processing unit to operate in a second operating mode; copying, by the at least one computer processor, the encrypted security application in a second memory component; decrypting, by the at least one computer processor, the secure application in the second memory component; generating, by the at least one computer processor, an address translation structure that provides access by the decrypted security application to data in the second memory component and the first memory component; and The decrypted security application is executed by the at least one computer processor to cause a second memory component to be accessed using the address translation structure.
17. The method according to claim 15, in, The address translation structure includes a partition table and a security process table, wherein the partition table and the security process table are stored in a second memory component, and wherein generating the address translation structure includes adding (i) a partition entry pointing to the security process table and (ii) a process entry associated with the security application process of the security application to the partition table, wherein the process entry points to a security application address translation tree that enables conversion of an effective address into a physical address.
18. A computer program product for process-based virtualization, the computer program product comprising a computer-readable storage medium having program instructions embodied therein, in, The computer-readable storage medium itself is not a transient signal, and the program instructions can be executed by a device to enable the device to perform the method as claimed in any one of claims 15 to 17.
Citation Information
Patent Citations
Hardware based isolation for secure execution of virtual machines
US20190034666A1