System and non-transitory machine readable medium for application protection

CN115828229BActive Publication Date: 2026-09-25MEDIATEK INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210817900.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-06-26
Filing Date
2022-07-12
Publication Date
2026-09-25
Estimated Expiration
2042-07-12

AI Technical Summary

Technical Problem

系统可能包括多个主(primary)虚拟机(Virtual Machine,VM),这些主虚拟机可能被安排为对APP进行APP保护,系统可能无法确认每个APP保护对应的主VM,这将影响系统的安全性

Benefits of technology

[0006]如上所述,本发明实施例通过主机虚拟机代替管理模块实施对应用保护的验证,由此可减少系统成本并增加系统性能。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115828229B_ABST
    Figure CN115828229B_ABST
Patent Text Reader

Abstract

The application provides a system and a non-transient machine readable medium for application protection. The embodiments of the application can reduce system cost and increase system performance. The system for application protection comprises a processor configured to execute a guest virtual machine, a host virtual machine, a management module and a host computer virtual machine. The guest virtual machine runs at least one application, and an application protection with an identification of the at least one application is downloaded to the guest virtual machine. The management module comprises an installation service module configured to receive the application protection from the guest virtual machine and copy to the host virtual machine, and a starting module configured to start the application protection. The host computer virtual machine is configured to verify the application protection through the identification and generate a verification result, acquire the identification from the host virtual machine according to the verification result, and generate a starting command to the starting module according to the identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of calculator technology, and more specifically, to a technical solution for application protection. Background Technology

[0002] For Android high-level operating systems (OS) running multiple applications (APPs), multiple APP protections (e.g., protection policies) corresponding to these APPs can be downloaded from the cloud, and a management module can be configured to provide a dynamic APP protection loading mechanism to perform verification, loading, and enforcement on the APP. However, some problems may arise. The system may require an additional secure operating system or have the management module itself perform verification on the APP, which will increase costs and reduce system performance. The system may include multiple primary Virtual Machines (VMs), which may be assigned to protect APPs. The system may not be able to identify the primary VM corresponding to each APP protection, which will affect system security. Therefore, there is an urgent need for a novel APP protection system that verifies APPs through APP identification (ID) and binds them to primary VMs based on the ID. Summary of the Invention

[0003] The present invention provides a system for application protection and a non-transitory machine-readable medium for storing program code. Implementing embodiments of the present invention can reduce system costs and increase system performance.

[0004] The present invention provides a system for application protection, comprising: a processor configured to execute a guest virtual machine, at least one host virtual machine, a management module, and a host virtual machine; wherein at least one application runs on the guest virtual machine, and at least one application protection having at least one identifier of the at least one application is downloaded to the guest virtual machine; wherein the management module comprises: an installation service module configured to receive the at least one application protection having the at least one identifier from the guest virtual machine, and copy the at least one application protection to the at least one host virtual machine according to an installation service command; and a startup module configured to start the at least one application protection copied to the at least one host virtual machine according to a startup instruction; wherein the host virtual machine is configured to: receive at least one installation command from the guest virtual machine, and generate an installation service command for the installation service module according to the at least one installation command; verify the at least one application protection using the at least one identifier and generate at least one verification result; obtain the at least one identifier from the at least one host virtual machine according to the at least one verification result; and generate a startup command for the startup module according to the at least one identifier.

[0005] This invention provides a non-transitory machine-readable medium for storing program code, wherein when the program code is loaded and executed by a processor, the program code instructs the processor to execute a guest virtual machine, at least one host virtual machine, a management module, and a host virtual machine; wherein at least one application runs on the guest virtual machine, and at least one application protection having at least one identifier of the at least one application is downloaded to the guest virtual machine; wherein the management module includes: an installation service module configured to receive the at least one application protection having the at least one identifier from the guest virtual machine, and copy the at least one application protection to the at least one host virtual machine according to an installation service command; and a startup module configured to start the at least one application protection copied to the at least one host virtual machine according to a startup instruction; wherein the host virtual machine is configured to: receive at least one installation command from the guest virtual machine, and generate an installation service command to the installation service module according to the at least one installation command; verify the at least one application protection using the at least one identifier and generate at least one verification result; obtain the at least one identifier from the at least one host virtual machine according to the at least one verification result; and generate a startup command to the startup module according to the at least one identifier.

[0006] As described above, the embodiments of the present invention implement application protection verification by replacing the management module with a host virtual machine, thereby reducing system costs and increasing system performance. Attached Figure Description

[0007] Figure 1 This is a schematic diagram of an electronic device 10 according to an embodiment of the present invention.

[0008] Figure 2 This is a schematic diagram of a system 20 for APP protection according to an embodiment of the present invention.

[0009] Figure 3 This is a schematic diagram of a system 30 for APP protection according to another embodiment of the present invention.

[0010] Figure 4 This is a schematic diagram of a system 40 for APP protection according to another embodiment of the present invention.

[0011] Figure 5 This is a schematic diagram of a system 50 for APP protection according to an embodiment of the present invention. Detailed Implementation

[0012] Certain terms are used in the specification and claims to refer to specific modules. Those skilled in the art will understand that hardware manufacturers may use different names to refer to the same module. This specification and claims do not distinguish modules by differences in name, but rather by differences in function. The terms "comprising" and "including" used throughout the specification and claims are open-ended and should be interpreted as "comprising but not limited to." "Substantially" or "approximately" means that within an acceptable margin of error, those skilled in the art can solve the technical problem and substantially achieve the technical effect within a certain margin of error. Furthermore, the terms "coupled" or "coupled" herein include any direct and indirect electrical connection means. Therefore, if a first device is described as coupled to a second device, it means that the first device can be directly electrically connected to the second device, or indirectly electrically connected to the second device through other devices or connection means. The following description is a preferred mode for carrying out the invention and is intended to illustrate the spirit of the invention rather than to limit the scope of protection of the invention. The scope of protection of the invention shall be determined by the appended claims.

[0013] The following description represents the preferred embodiments of the present invention. These descriptions are intended to illustrate the general principles of the invention and not to limit it. The scope of protection of the present invention should be determined based on the claims of the invention.

[0014] Figure 1 This is a schematic diagram of an electronic device 10 according to an embodiment of the present invention. By way of example and not limitation, the electronic device 10 may be a portable device, such as a smartphone or tablet computer. The electronic device 10 may include a processor 12 and a storage device 14. The processor 12 may be a single-core processor or a multi-core processor. The storage device 14 is a non-transitory machine-readable medium for storing calculator program code (PROG). The processor 12 is equipped with the ability to implement software. The calculator program code PROG may include multiple software modules. Therefore, when loaded and executed by the processor 12, the calculator program code PROG instructs the processor 12 to perform specified functions of the software modules. The electronic device 10 can be considered as a calculator system using a calculator program product, which includes a calculator-readable medium containing the calculator program code PROG. The system for app protection provided by the present invention can be implemented in the electronic device 10. For example, the system for app protection may include software-based functions implemented by the calculator program code PROG running on the processor 12.

[0015] Figure 2 This is a schematic diagram of a system 20 for APP protection according to an embodiment of the present invention. Figure 2As shown, system 20 may include a processor (e.g., Figure 1 The processor 12 shown is configured to execute software modules including: a guest virtual machine (VM) 200, a management module 210, a primary VM 220, and a host VM 230. In this embodiment, APP A can run on the guest VM 200 and can download an APP protection (e.g., a protection policy, for simplicity) with the identifier (ID) of APP A from the cloud 202. Figure 2 (marked as "APP A protection") to customer VM200 (for simplicity, in) Figure 2 (The text is marked as "Download"). Note that other information that can identify APP A (e.g., APP A's signature) can be used instead of the ID.

[0016] As an example, an Android operating system with a Linux kernel may run on a guest VM 200, where the guest 201 (APP A) may send an installation command I_CMD for APP A protection to the host VM 230. The management module 210 may include an installation service module 212 and a launch module 214. The installation service module 212 can be used to receive APP A protection from the guest VM 200 (for simplicity, in...). Figure 2 The code is marked "Received" and copies APP A protection to the primary VM 220 according to the installation service command IS_CMD (for simplicity, in...). Figure 2 The installation service command IS-CMD can be used to instruct the installation service module 212 to copy APP A protection to the primary VM 220. The startup module 214 can be used to start the APP A protection copied to the primary VM 220 according to the startup command L_CMD (for simplicity, in...). Figure 2 (Marked as "Startup" in the middle).

[0017] The host VM 230 can be used to ensure the legitimacy of the host VM 220 for the system 20, and may include an ID list 231 and an installation management module 232, wherein the ID of APP A may be included in the ID list 231. The installation management module 232 can be used to receive the installation command I_CMD from the guest VM 200, and generate an installation service command IS_CMD to the installation service module 212 in the management module 210 according to the installation command I_CMD, so as to trigger the installation service module 212 to copy the protection of APP A to the host VM 220. In addition, the installation management module 232 may include an ID management module 233 and an activated ID module 234. The ID management module 233 can be used to verify the protection of APP A through the ID of APP A in the ID list 231 (for simplicity, in Figure 2 The ID management module 233 can generate the ID of APP A in the ID list 231 through an algorithm, key category or whitelist, and can determine whether the ID protected by APP A is valid through the ID of APP A in the generated ID list 231 to generate the verification result. However, the present invention is not limited to this.

[0018] Subsequently, in response to the verification result indicating that the ID of APP A is valid, the activated ID module 234 in the installation management module 232 can be used to obtain (that is, the host VM 200 provides the ID of APP A to the activated ID module 234; for simplicity, in) Figure 2 The system records the activated ID (i.e., the ID of APP A) and generates a startup command L_CMD in the startup module 214 of the management module 210 based on the ID of APP A to start the protection of APP A. Since the verification of APP protection is performed by the host VM 230, the corresponding functional tasks of the management module 210 can be offloaded, thereby reducing costs and increasing the performance of the system 20. Note that when APP A is loaded onto the guest VM 200, the host VM 220 is simultaneously loaded onto the processor, and when APP A is unloaded from the guest VM 200, the host VM 220 is simultaneously unloaded from the processor. Furthermore, when APP A stops running on the guest VM 200 (i.e., the protection of APP A is no longer needed), the host VM 220 can release the protection of APP A. In other words, when APP A starts running on the guest VM 200, the protection of APP A can be copied to the host VM 220. In this way, the storage space of the system 20 can be significantly saved.

[0019] Figure 3 This is a schematic diagram of a system 30 for app protection according to another embodiment of the present invention. Figure 3 As shown, system 30 may include a processor (e.g., Figure 1The processor 12 shown is configured to execute software modules including: guest virtual machines (VMs) 300, a management module 310, multiple primary VMs (e.g., two primary VMs 320 and 321), and a host VM 330. The management module 310 may include an installation service module 312 and a startup module 314, the host VM 330 may include an ID list 331 and an installation management module 332, and the installation management module 332 may include an ID management module 333 and an activated ID module 334. In this embodiment, two apps (i.e., APP A and APP B) can run on the client VM 300. An app with the ID of APP A and used for app protection of APP A, and another app with the ID of APP B and used for app protection of APP B (hereinafter referred to as "APP A protection" and "APP B protection" respectively) can be downloaded from the cloud 302 to the client VM 300. The main VM 320 and main VM 321 can serve as the locations for executing APP A protection and APP B protection, respectively. For simplicity, similar descriptions to other embodiments are omitted here.

[0020] In this embodiment, the installation command I_CMD may include a first installation command F_I_CMD sent by client 301 of APP A and a second installation command S_I_CMD sent by client 303 of APP B. The first installation command F_I_CMD can be used to trigger the installation service module 312 to copy the protection of APP A to the main VM 320 through the installation service command IS_CMD generated by the host VM 330 (more specifically, the installation management module 332). The second installation command S_I_CMD can be used to trigger the installation service module 312 to copy the protection of APP B to the main VM 321 through the installation service command IS_CMD generated by the host VM 330 (more specifically, the installation management module 332).

[0021] It should be noted that the number of apps running on the client VM 300 and the corresponding number of master VMs in system 30 can vary depending on actual design considerations. In specific implementations, any system with multiple master VMs protected by multiple apps, each corresponding to multiple IDs of multiple apps running on the client VM, will fall within the scope of protection of this invention. Furthermore, when an app (e.g., app A or app B) is loaded onto the client VM 300, the corresponding master VM (e.g., master VM 320 or master VM 321) will be loaded onto the processor simultaneously, and when an app (e.g., app A or app B) is unloaded from the client VM 300, the corresponding master VM (e.g., master VM 320 or master VM 321) will be unloaded from the processor simultaneously. When an application (e.g., APP A or APP B) stops running on the guest VM 300, it means that the corresponding application protection (e.g., APP A protection or APP B protection) is no longer needed. The primary VM (e.g., primary VM 320 or primary VM 321) corresponding to the no longer needed application protection can then release the no longer needed application protection (e.g., APP A protection or APP B protection). In other words, when an application (e.g., APP A or APP B) starts running on the guest VM 300, an application protection (e.g., APP A protection or APP B protection) can be copied to the primary VM corresponding to that application protection (e.g., primary VM 320 or primary VM 321). For brevity, similar descriptions to those in other embodiments are omitted here.

[0022] Figure 4 This is a schematic diagram of a system 40 for APP protection according to another embodiment of the present invention. Figure 4 As shown, system 40 may include a processor (e.g., Figure 1The processor 12 shown is configured to execute software modules, including a guest VM 400, a management module 410, a host VM 420, and a master VM 430. The management module 410 may include an installation service module 412 and a startup module 414. The master VM 430 may include an ID list 431 and an installation management module 432, and the installation management module 432 may include an ID management module 433 and an activated ID module 434. In this embodiment, two apps (i.e., APP A and APP B) may run on the guest VM 400. An app protection for APP A with an ID of APP A and another app protection for APP B with an ID of APP B (hereinafter referred to as "APP A protection" and "APP B protection," respectively) may be downloaded from the cloud 302 to the guest VM 300, with the master VM 420 serving as the location for executing APP A protection and APP B protection. For simplicity, similar descriptions to other embodiments are omitted here. Furthermore, the IDs of APPA and APPB can be included in ID list 431.

[0023] Figure 4 The system 40 shown and Figure 3 The difference between system 30 and system 40 is that system 40 may include only one master VM 420, which corresponds to both APP A protection and APP B protection. It should be noted that the number of APPs running on the guest VM 400 can vary depending on actual design considerations. In practice, any system with a master VM corresponding to multiple APP protections will fall within the scope of this invention, wherein the APP protections have IDs for multiple APPs running on the guest VM.

[0024] Furthermore, when an application (e.g., application A or application B) stops running on the guest VM 400, the master VM 420 will release the corresponding application protection (e.g., application A protection or application B protection). In other words, when an application (e.g., application A or application B) starts running on the guest VM 400, the corresponding application protection (e.g., application A protection or application B protection) can be copied to the master VM 420. For example, when application A stops running on the guest VM 400 and application B starts running on the guest VM 400, the master VM 420 will release application A protection, and application B protection can be copied to the master VM 420. For the sake of brevity, similar descriptions to other embodiments are omitted here.

[0025] Figure 5This is a schematic diagram of a system 50 for app protection according to an embodiment of the present invention, wherein system 50 includes a communication proxy. Figure 5 As shown, system 50 may include a processor (e.g., Figure 1 The processor 12 shown is configured to execute software modules, including: a guest VM 500, a management module 510, a host VM 520, and a host VM 530. The management module 510 may include an installation service module and a startup module 512, a communication agent 514, and a protection management module (e.g., a Real-Time Kernel Protection (RKP) module, or a user library protection module) 516. The host VM 530 may include an ID list 531 and an installation management module 532, and the installation management module 532 may include an ID management module 533 and an activated ID module 534. Figure 2 Compared to the management module 210 in the system 20 shown, the management module 510 may further include a communication agent 514 and a protection management module 516. The activated ID module 534 can also be used to establish a specific channel between the activated ID module 534 and the communication agent 514 to register the activated ID (i.e., the ID of APP A) to the communication agent 514 (for simplicity, in...). Figure 5 (Marked as "Registration ID" in the middle).

[0026] Communication agent 514 can be used to receive the ID of APP A sent by the activated ID module 534 in the installation management module 532, and perform communication between the master VM 520 and the management module 510 based on the ID of APP A. Protection management module 516 can be used to configure the protection settings of APP A (SAFETY_APP A_COMMAND) sent by the master VM 520 through communication agent 514 according to the APP A protection setting command. Figure 5 The communication agent 514, labeled "SAC", manages and configures security protection modules (such as MMU (Memory Management Unit) and / or MPU (Memory Protection Unit)). Additionally, the communication agent 514 can also be used to bind the master VM 520 to the management module 510, and only the master VM with the ID APP A can communicate with the management module 510 through the communication agent 514. For example, only the master VM with the ID APP A can send the APP A protection setting command SAFETY_APPA_COMMAND to the protection management module 516 through the communication agent 514 to manage and configure the security protection modules (such as MMU and / or MPU) according to the APP A protection setting command SAFETY_APPA_COMMAND.

[0027] It is worth noting that this embodiment focuses on the design of the system 50 for APP protection and the communication agent 514. The operation of the protection management module 516 is well known to those skilled in the art, so the details of the protection management module 516 will not be described in the specification of this invention.

[0028] In summary, in the system for APP protection according to this invention, since the verification of APP protection can be performed by the host VM, the corresponding functions in the management module can be removed, thereby reducing system costs and increasing system performance. When an APP stops or starts running on a client VM, the APP protection with the corresponding APP ID can be released from or copied to the host VM, which greatly saves system storage space. Furthermore, in some embodiments, since only the host VM with the APP ID can communicate with the management module through a communication agent, system security can be guaranteed.

[0029] While the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the scope of the invention. Any person skilled in the art can make some modifications and refinements without departing from the spirit and scope of the invention. Therefore, the scope of protection of the present invention shall be determined by the claims.

Claims

1. A system for application protection, characterized in that, include: A processor configured to execute a guest virtual machine, at least one host virtual machine, a management module, and a host virtual machine; At least one application is running on the guest virtual machine, and at least one application protection having at least one identifier of the at least one application is downloaded to the guest virtual machine; This management module includes: The installation service module is configured to receive at least one application protection having the at least one identifier from the guest virtual machine, and copy the at least one application protection to the at least one master virtual machine according to the installation service command; and The startup module is configured to initiate, upon startup instruction, the at least one application protection copied to the at least one master virtual machine; A communication agent is configured to receive at least one identifier sent by the host virtual machine and to bind the at least one host virtual machine to the management module; The host virtual machine is configured as follows: Receive at least one installation command from the client virtual machine, and generate an installation service command for the installation service module based on the at least one installation command; The at least one application protection is verified by the at least one identifier and at least one verification result is generated; Based on the at least one verification result, obtain the at least one identifier from the at least one main virtual machine; and A startup command is generated for the startup module based on at least one identifier.

2. The system as described in claim 1, characterized in that, The communication agent is further configured as follows: Communication is performed between the at least one master virtual machine and the management module based on the at least one identifier.

3. The system as described in claim 1, characterized in that, An application runs on a guest virtual machine, and the at least one host virtual machine includes a host virtual machine corresponding to an application protection having the identifier of the application.

4. The system as described in claim 3, characterized in that, When an application is loaded onto or unloaded from a guest virtual machine, the corresponding master virtual machine is simultaneously loaded onto or unloaded from the processor.

5. The system as described in claim 3, characterized in that, When an application stops running on the guest virtual machine, the corresponding master virtual machine releases the application protection that has the application's identifier.

6. The system as described in claim 3, characterized in that, When an application starts running on the guest virtual machine, the application protection with the application's identifier is copied to the host virtual machine.

7. The system as described in claim 1, characterized in that, Multiple applications run on the guest virtual machine, and the at least one master virtual machine includes multiple master virtual machines, each of which corresponds to multiple application protections with the identifiers of the multiple applications.

8. The system as described in claim 7, characterized in that, When the first application in the plurality of applications is loaded onto or unloaded from the guest virtual machine, the first master virtual machine protected by the first application with the identifier of the first application is simultaneously loaded onto or unloaded from the processor.

9. The system as described in claim 7, characterized in that, When the first application among the multiple applications stops running on the guest virtual machine, the first master virtual machine with the identifier of the first application releases the first application protection.

10. The system as described in claim 7, characterized in that, When the first application among the multiple applications starts running on the guest virtual machine, the first application protection with the identifier of the first application is copied to the first master virtual machine corresponding to the first application protection.

11. The system as claimed in claim 1, characterized in that, Multiple applications run on the guest virtual machine, and the at least one master virtual machine includes a master virtual machine that corresponds to multiple application protections with the identifiers of the multiple applications.

12. The system as claimed in claim 11, characterized in that, When the first application among the multiple applications stops running on the guest virtual machine, the master virtual machine releases application protection with the identifier of the first application.

13. The system as described in claim 11, characterized in that, When the first application among the multiple applications starts running on the guest virtual machine, the application protection with the identifier of the first application is copied to the master virtual machine.

14. A non-transitory machine-readable medium for storing program code, characterized in that, When the program code is loaded and executed by the processor, the program code instructs the processor to execute the guest virtual machine, at least one master virtual machine, management module, and host virtual machine; At least one application is running on the guest virtual machine, and at least one application protection having at least one identifier of the at least one application is downloaded to the guest virtual machine; This management module includes: The installation service module is configured to receive at least one application protection having the at least one identifier from the guest virtual machine, and copy the at least one application protection to the at least one master virtual machine according to the installation service command; and The startup module is configured to initiate, upon startup instruction, the at least one application protection copied to the at least one master virtual machine; A communication agent is configured to receive at least one identifier sent by the host virtual machine and to bind the at least one host virtual machine to the management module; The host virtual machine is configured as follows: Receive at least one installation command from the client virtual machine, and generate an installation service command for the installation service module based on the at least one installation command; The at least one application protection is verified by the at least one identifier and at least one verification result is generated; Based on the at least one verification result, obtain the at least one identifier from the at least one main virtual machine; and A startup command is generated for the startup module based on at least one identifier.

15. The non-transient machine-readable medium as claimed in claim 14, characterized in that, The communication agent is further configured as follows: Communication is performed between the at least one master virtual machine and the management module based on the at least one identifier.

16. The non-transient machine-readable medium as claimed in claim 14, characterized in that, An application runs on a guest virtual machine, and the at least one host virtual machine includes a host virtual machine corresponding to an application protection having the identifier of the application.

17. The non-transient machine-readable medium as claimed in claim 14, characterized in that, Multiple applications run on the guest virtual machine, and the at least one master virtual machine includes multiple master virtual machines, each of which corresponds to multiple application protections with the identifiers of the multiple applications.

18. The non-transient machine-readable medium as claimed in claim 14, characterized in that, Multiple applications run on guest virtual machines, and the at least one master virtual machine includes a master virtual machine that corresponds to multiple application protections with the identifiers of the multiple applications.

Citation Information

Patent Citations

  • Device with a secure virtual machine

    CN101755269A

  • Systems and methods for listening policies for virtual servers of an appliance

    CN102771086A