A Hardware Memory Encryption System Based on RISC-V Architecture and Its Applications
By extending the instruction set and introducing key management modules in the RISC-V architecture, the problems of restricted encryption areas and insufficient key storage in the existing hardware memory encryption technology are solved, and multi-key management and full-process encryption transmission are realized, which improves memory data security.
Patent Information
- Application Number
- CN202310027782.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-09
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2043-01-09
AI Technical Summary
The existing hardware memory encryption technology has problems such as limited encryption area, limited number of key storage, high performance overhead in encryption area, and failure to support full-process encryption transmission.
Based on the RISC-V architecture, the instruction set is extended, setcbit, setkybit, datats and accdatats are introduced, combined with the key management module and the encryption and decryption engine, and the LRU replacement strategy and Cuckoo Hash algorithm are used to realize multi-key management and full-process encrypted transmission.
The encryption area is expanded, and efficient management of unlimited key count is realized. It supports the encrypted transmission of memory data throughout the process, improving memory data security.
Smart Images

Figure CN115994389B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of hardware memory security, and more specifically, relates to a hardware memory encryption system based on the RISC-V architecture and its applications. Background Art
[0002] To prevent the risk of memory data leakage caused by attacks on memory devices' software and hardware, the industry and academia generally encrypt memory data. Encryption methods are mainly divided into hardware encryption and software encryption.
[0003] Currently, there are many mature hardware memory encryption technologies in the academic and industrial fields. The MKTME technology developed by Intel is a multi-key full memory encryption technology. It uses the upper bits of the physical address as the keyID and supports encrypting memory with multiple keys. It encrypts when writing to memory and decrypts when reading from memory, thus preventing data from being stolen under complex offline attacks. Its structure and function are simple, and other security features can be superimposed on the architecture, and it also has good software compatibility. The Penglai developed by a Chinese team is based on the open-source RISC-V architecture, uses the PMP / sPMP functional module to provide enclave functions, and is based on the openSBI open-source supervision interface. Encryption can be completed without modifying the hardware. It uses the hardware TVM function to perform fine-grained isolation at the 4KB page level between untrusted hosts and enclaves, improving the scalability of the memory encryption system.
[0004] However, some problems still exist. Existing hardware memory encryption technologies such as Intel's MKTME technology and AMD's SEV technology encrypt memory at the page granularity, while SGX and Trustzone can only encrypt limited block areas, and the encrypted areas are restricted. Secondly, existing hardware memory encryption technologies only support a small number of keys. Encryption technologies such as Intel's MKTME technology and AMD's SME technology have a small number of available encrypted areas, which may result in high performance overhead. The trusted key storage area of Intel's MKTME technology is only 32k, and the identifier of each key table is between 4-15 bits. Key storage will occupy the free bits of the existing physical address, posing a risk of memory data leakage. In addition, existing hardware memory encryption systems do not support end-to-end encrypted data transmission.
[0005] Therefore, how to efficiently achieve memory data security protection is the direction that the current hardware memory encryption system urgently needs to improve. Summary of the Invention
[0006] Aiming at the defects and improvement requirements of the existing technology, the present invention provides a hardware memory encryption system based on the RISC-V architecture and its applications, aiming to propose a hardware memory encryption system to more efficiently protect the security of memory data.
[0007] To achieve the above object, according to one aspect of the present invention, there is provided a hardware memory encryption system based on the RISC-V architecture, including: a key management module, an encryption / decryption engine, a transmission module, and a programming interface set based on the RISC-V architecture; wherein,
[0008] The instruction set of the RISC-V architecture is extended to include two instructions, setcbit and setkybit, for memory encryption. Through the programming interface, the key management module can be used to call the instructions setcbit and setkybit to respectively set the encryption flag bit and key number of the applied memory space, thereby setting the memory space as an encrypted space;
[0009] When the key management module performs key management, it is divided into two parts: key storage and key acquisition. Among them, the on-chip memory key storage method is adopted, the LRU replacement policy is used to maintain the on-chip buffer, and the Cuckoo HashKey Table is used as the memory key table;
[0010] The instruction set of the RISC-V architecture is further extended to include two instructions, datats and accdatats, for memory data transmission. By configuring the programming interface, the transmission module can call the instructions datats and accdatats to respectively send and receive memory data.
[0011] Furthermore, the key management module is also used to, according to the user request, call the setkybit and setcbit instructions to restore the key number and encryption flag bit of the memory page to be released to the default values, thereby setting the memory space as a non-encrypted space; and notify the operating system to release the memory space through the Free method, thereby releasing the encrypted memory space.
[0012] Furthermore, the RV64 R-type instruction format is adopted to design the definition methods of the instructions genky, setky, setcbit, setkybit, datats, and accdatats, specifically as follows:
[0013] The method for defining the genky instruction is: define that the instruction has no write-back result and does not require reading operands;
[0014] The method for defining the setky instruction is: define that the instruction has no write-back result and requires reading the operand rs1, and the value of the operand rs1 is the virtual address of the shared key;
[0015] The method for defining the setcbit instruction is as follows: Define that the instruction has no write-back result. The instruction needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the virtual passenger plane page to be set.
[0016] The method for defining the setkybit instruction is as follows: Define that the instruction has no write-back result. The instruction needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the virtual passenger plane page to be set.
[0017] The method for defining the datats instruction is as follows: Define that the instruction has no write-back result. The instruction needs to read the operands rs1 and rs2. The value of the operand rs1 is the virtual address of the memory to be transferred, and the value of the operand rs2 is the virtual address of the target information structure.
[0018] The method for defining the accdatats instruction is as follows: Define that the instruction has no write-back result. The instruction needs to read the operands rs1 and rs2. The value of the operand rs1 is the virtual address of the data to be received, and the value of the operand rs2 is the virtual address of the passenger plane information structure.
[0019] Furthermore, the way for the key management module to perform key management is as follows:
[0020] Use a buffer to store the keys of some virtual machines or processes. First, access the buffer. If the key does not exist, look it up in the memory key table. If it still does not exist, generate a key and store it; when the process is destroyed, clear all the keys corresponding to this process.
[0021] Furthermore, the instruction set of the RISC-V architecture is extended and also includes two instructions, genky and setky, for memory encryption. The genky instruction is used to enable the key management module to generate a default key for the user process; the setky instruction is used for the user to specify a private key.
[0022] The specific way for the key management module to perform key management is as follows:
[0023] S1. Use a buffer to store the keys of some virtual machines or processes corresponding to the most recently used memory pages;
[0024] S2. After being triggered, obtain the virtual machine number, process number, core number, key number, and encryption flag bit of the current memory page where the data to be encrypted / decrypted is located through a trusted channel. Determine the target key according to the key number, virtual machine number, process number, core number, and the applied memory space address, and judge whether the target key is in the buffer; if so, directly transmit the target key to the encryption / decryption engine; if not, go to step S3; where the key number is the number of the default key or the number of the private key;
[0025] S3: Determine whether the number of keys evicted to the in-memory key table is 0; if so, go to step S8; if not, go to step S4;
[0026] S4: Determine whether the target key is in the in-memory key table; if so, transmit the target key to the encryption / decryption engine and go to step S5; if not, go to step S8;
[0027] S5: Determine whether there is free storage space in the buffer; if so, go to step S7; if not, go to step S6;
[0028] S6: Use the LRU policy to find the least recently used key, algorithmically encrypt the least recently used key with the key generated by the trusted platform module, evict it to the in-memory key table, increment the eviction key counter by one, and go to step S7;
[0029] S7: Insert the target key into the buffer;
[0030] S8: Raise an error to the user.
[0031] Furthermore, after inserting the target key into the buffer, the key management module is further configured to:
[0032] Encrypt the eviction pending key K-e with the key generated by the trusted platform module through the encryption / decryption engine and insert K-e into the in-memory key table, where the in-memory key table is a Cuckoo Hash Key Table constructed and managed by the key management module.
[0033] The present invention also provides a method for performing memory encryption transmission by using a hardware memory encryption system based on the RISC-V architecture as described above, embedding the hardware memory encryption system into a computer system, where the encryption / decryption engine and the key management module in the hardware memory encryption system are provided in the memory controller of the computer system and perform the following steps:
[0034] After the computer system is powered on and the hardware memory encryption system completes self-check, and when the user applies for an encrypted memory space, through the programming interface, the key management module in the hardware memory encryption system calls the instructions setcbit and setkybit to set the encryption flag bit and key number of the applied memory space respectively, thereby setting the memory space as an encrypted space; after receiving the trigger signal from the processor of the computer system to control the memory controller to read data from or write data to the memory, obtain the virtual machine number, process number, core number, key number, and encryption flag bit of the current memory page where the data is located through the trusted channel; determine whether the data needs to be encrypted according to the encryption flag bit; if not, directly send the data out of the memory controller, if so, based on the key number, the virtual machine number, the process number, the core number, and the address of the encrypted space, perform a key access, obtain the target key and distribute it to the encryption and decryption engine in the hardware memory encryption system;
[0035] The encryption and decryption engine encrypts and decrypts the data according to the key and delivers the data to the memory controller;
[0036] When the transmission module in the hardware memory encryption system receives an instruction request for data transmission and passes the security verification, it calls the instructions datats and accdatats to send and receive memory data respectively, realizing the whole-process encrypted transmission.
[0037] Further, the implementation method of sending memory data is as follows:
[0038] When the computer system initiates a data transmission request to the remote server and receives the transmission public key and identity information sent by the remote server, the encryption and decryption engine encrypts a triple structure using the transmission key. The triple structure is in the order of: VMID-VPIDcore-KeyID information of the data to be transmitted, the key, and the page table entry where the data to be transmitted is located; the computer system sends the triple structure and the memory data to be transmitted to the remote server, where VMID-VPIDcore-KeyID represents the virtual machine number and process number of the corresponding page and the key number used.
[0039] Further, the specific implementation method of sending memory data is as follows:
[0040] (1) The computer system sends a local data transfer request according to msg = tS0||randN0||size: IDA||cla||PB||sigB(msg)||msg, where the || symbol represents the concatenation of strings, msg represents the local data transfer request information, tS0 represents the timestamp information, randN0 represents a random number, size represents the size of the data to be transferred, cla represents the operation type, representing virtual machine migration or data transfer, PB represents the public key generated by the computer system's transfer module, and sigB(msg) is a function whose function is to sign msg using the private key generated by the transfer module;
[0041] (2) After the computer system receives the identity string IDA||sigK(randN0)||EPB(rVMID||rPID) sent by the remote server, the transfer module verifies IDA||sigK(randN0); if the verification is successful, it sends EPK(sk)||SM4SK(sigB(H(KT))||M to the remote server, where sk is the random session key generated by the computer system for this transfer, EPK(sk) represents the local computer system encrypting sk using the public key of the remote device, SM4SK() represents encryption using the session key, KT represents VMID||VPIDcore||Key0||Key1, and SM3(M) represents calculating the check value of KT using the SM3 algorithm; among them, the identity string IDA||sigK(randN0)||EPB(rVMID||rPID) is obtained by the remote server looking up the device code IDA pre-added to its approved list and verifying: verPB(sigB) = msg, where verPB(sigB) is a function whose function is for the remote server to verify the signature of msg using PB. If the verification is successful, it is configured according to cla and sent to the computer system as the identity string; where K represents the private key under the AC certificate system of the remote server, sigK(randN0) represents the signature returned by the remote server using the private key for the random number randN0, rVMID represents the number of the target virtual machine on the remote server, rPID represents the number of the target process on the remote server, and EPB() is a function representing SM2 encryption of rVMID||rPID using PB;
[0042] (3) After the remote server successfully obtains the sk and KT information, it sends an Ack signal to the computer system, where the Ack signal represents the key in-place confirmation signal;
[0043] (4) The computer system sends Mc after receiving the Ack signal, where Mc represents the encrypted memory data.
[0044] The present invention also provides a computer system, which incorporates a hardware memory encryption system based on the RISC-V architecture as described above, for executing the method of memory encryption transmission as described above.
[0045] Generally speaking, through the above technical solutions conceived by the present invention, the following beneficial effects can be achieved:
[0046] The present invention proposes a hardware memory encryption system based on the RISC-V architecture, which improves the existing hardware memory encryption solutions and more effectively protects the security of memory data. First, the present invention proposes to extend the RISC-V instruction set, use the newly added instructions to create a memory security space management method, convert the general memory into an encrypted space, and increase the encrypted area; secondly, design a multi-key eviction scheme, implement the LRU replacement strategy in the memory field, and apply the Cuckoo Hash algorithm to achieve unlimited number of keys and high efficiency in key acquisition; in addition, adopt the above-mentioned protocol-authorized memory data transmission scheme to realize the whole-process encrypted transmission of memory data between local and remote ends, which is the first implementation in the existing memory encryption solutions. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is an architecture model diagram of the hardware memory encryption system based on the RISC-V architecture and the national cryptography algorithm in the embodiment of the present invention;
[0048] Figure 2 It is a schematic flow diagram of encrypting and decrypting memory when reading and writing data by the hardware memory encryption system based on the RISC-V architecture and the national cryptography algorithm in the embodiment of the present invention;
[0049] Figure 3 It is a schematic diagram of the custom instruction encoding of the hardware memory encryption system based on the RISC-V architecture and the national cryptography algorithm in the embodiment of the present invention;
[0050] Figure 4 It is a schematic diagram of the Cuckoo Hash Key Table Entry of the hardware memory encryption system based on the RISC-V architecture and the national cryptography algorithm in the embodiment of the present invention;
[0051] Figure 5 It is the memory data encryption method of the hardware memory encryption system based on the RISC-V architecture and the national cryptography algorithm in the embodiment of the present invention;
[0052] Figure 6 It is a schematic flow diagram of the memory data transmission scheme of the hardware memory encryption system based on the RISC-V architecture and the national cryptography algorithm in the embodiment of the present invention;
[0053] Figure 7It is a schematic architecture diagram of the encryption engine module in the hardware memory encryption system based on the RISC-V architecture and national cryptographic algorithms in the embodiments of the present invention;
[0054] Figure 8 It is a schematic architecture diagram of the key manager in the hardware memory encryption system based on the RISC-V architecture and national cryptographic algorithms in the embodiments of the present invention. Detailed implementation manners
[0055] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0056] Embodiment 1
[0057] A hardware memory encryption system based on the RISC-V architecture includes: a key management module, an encryption and decryption engine, a transmission module, and a programming interface set based on the RISC-V architecture; wherein,
[0058] The instruction set of the RISC-V architecture is extended to include two instructions, setcbit and setkybit, for memory encryption. Through the programming interface, the key management module can be used to call the instructions setcbit and setkybit to respectively set the key number and encryption flag bit of the applied memory space, so as to set the memory space as an encrypted space;
[0059] When the key management module performs key management, it is divided into two parts: key storage and key acquisition. Among them, the on-chip memory key storage method is adopted, the LRU replacement strategy is used to maintain the on-chip buffer, and the Cuckoo Hash KeyTable is used as the memory key table;
[0060] The instruction set of the RISC-V architecture is further extended to include two instructions, datats and accdatats, for memory data transmission. Through the programming interface, the transmission module can call the instructions datats and accdatats to respectively send and receive memory data.
[0061] As a preferred implementation, the above key management module is further used to, according to a user request, call the setky and setcbit instructions to restore the key number and encryption flag bit of the memory page to be released to default values, so as to restore the memory space to a non-encrypted space; and through the Free method, notify the operating system to release the memory space, so as to release the encrypted memory space.
[0062] That is, to implement the functions of memory data transfer and virtual machine migration, the system has made appropriate extensions to the original RISC-V instruction set, and innovatively added six instructions, namely genky, setky, setcbit, setcbit, datats, and accdatats. As a preferred implementation, using the RV64 R-type instruction format, the definition methods of the instructions genky, setky, setcbit, setkybit, datats, and accdatats are designed as follows:
[0063] The method for defining the genky instruction is: define that the instruction has no write-back result and does not need to read operands;
[0064] The method for defining the setky instruction is: define that the instruction has no write-back result and needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the shared key;
[0065] The method for defining the setcbit instruction is: define that the instruction has no write-back result and needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the virtual passenger plane page to be set;
[0066] The method for defining the setkybit instruction is: define that the instruction has no write-back result and needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the virtual passenger plane page to be set;
[0067] The method for defining the datats instruction is: define that the instruction has no write-back result and needs to read the operands rs1 and rs2. The value of the operand rs1 is the virtual address of the memory to be transferred, and the value of the operand rs2 is the virtual address of the target information structure;
[0068] The method for defining the accdatats instruction is: define that the instruction has no write-back result and needs to read the operands rs1 and rs2. The value of the operand rs1 is the virtual address of the data to be received, and the value of the operand rs2 is the virtual address of the passenger plane information structure.
[0069] For a more specific definition method, as Figure 3 shown, this embodiment gives the following example:
[0070] (1) Definition of intervals: The QUADRANT interval from bit 0 to bit 1 of the instruction represents the instruction length types that can be identified; the interval from bit 2 to bit 6 of the instruction is the instruction opcode OPCODE, which is used to select the EXTOPT instruction group; the FUNCT3 interval from bit 12 to bit 14 of the instruction is the function encoding interval, which is used to define the specific instruction for transferring memory data; the OPTN interval from bit 20 to bit 24 of the instruction is the function encoding interval, which is used to define the specific instruction for memory encryption; the EXTOPT interval from bit 25 to bit 31 of the instruction represents the extended opcode identifier;
[0071] (2) According to the interval definition, the genky instruction used to generate a key for the encrypted memory space is defined as:
[0072] Let QUADRANT = 0x11, indicating that the instruction length type that can be identified is 17; OPCODE = 0x1d, that is, the EXTOPT instruction group is adopted; OPTN = 0x0, that is, this value is encoded as the genky instruction; EXTOPT = 0x0, that is, this value-encoded instruction is an instruction for memory encryption;
[0073] The setky instruction used to import the user key for the current process is defined as:
[0074] Let QUADRANT = 0x11, indicating that the instruction length type that can be identified is 17; OPCODE = 0x1d, that is, the EXTOPT instruction group is adopted; OPTN = 0x1, that is, this value is encoded as the setky instruction; EXTOPT = 0x0, that is, this value-encoded instruction is an instruction for memory encryption; RD can use any RISC-V general-purpose register;
[0075] The setcbit instruction used to set the specified page as an encrypted page is defined as:
[0076] Let QUADRANT = 0x11, indicating that the instruction length type that can be identified is 17; OPCODE = 0x1d, that is, the EXTOPT instruction group is adopted; OPTN = 0x2, that is, this value is encoded as the setcbit instruction; EXTOPT = 0x0, that is, this value-encoded instruction is an instruction for memory encryption;
[0077] The setkybit instruction used to set the specified page as a user-key encrypted page is defined as:
[0078] Let QUADRANT = 0x11, indicating that the instruction length type that can be identified is 17; OPCODE = 0x1d, that is, the EXTOPT instruction group is adopted; OPTN = 0x3, that is, this value is encoded as the setkybit instruction; EXTOPT = 0x0, that is, this value-encoded instruction is an instruction for memory encryption;
[0079] Define the datats instruction for transmitting the specified data of the current process to the specified target as:
[0080] Let QUADRANT = 0x11, indicating that the instruction length type can be identified as 17; OPCODE = 0x1d, that is, the EXTOPT instruction group is adopted; FUNCT3 = 0x0, that is, this value is encoded as the datats instruction; EXTOPT = 0x1, that is, this value encodes the instruction as an instruction for transmitting memory; RD and RS1 can use any RISC-V general-purpose register;
[0081] Define the accdatats instruction for receiving the data of the specified target into the specified area of the current process as:
[0082] Let QUADRANT = 0x11, indicating that the instruction length type can be identified as 17; OPCODE = 0x1d, that is, the EXTOPT instruction group is adopted; FUNCT3 = 0x2, that is, this value is encoded as the accdatats instruction; EXTOPT = 0x1, that is, this value encodes the instruction as an instruction for transmitting memory;
[0083] Among them, the EXTOPT instruction group is an instruction group composed of the instructions genky, setky, setcbit, setkybit, datats, and accdatats.
[0084] Using the above instructions, the key management module configured in the system of this embodiment can execute a new memory encryption space management method: by setting the key number and encryption flag bit, the general memory space is changed into an encrypted space, expanding the number of encrypted areas. Preferably, the specific methods for applying for encrypted memory and releasing encrypted memory are:
[0085] Through the Malloc method, apply for a general memory space from the operating system, call the setky instruction and the setcbit instruction to set the key number and encryption flag bit of the memory page, so as to set the memory space as an encrypted space, and then return the memory space address to the user, thereby providing an encrypted memory space to the user. In addition, the present invention provides a method for releasing encrypted memory. Call the setky instruction and the setcbit instruction to restore the encryption bit and key identification bit of the memory page to the default value, so as to set the memory space as a non-encrypted space, and notify the operating system to release the memory space through the Free method, thereby releasing the encrypted memory space.
[0086] After applying for encrypted memory, the key management module also needs to obtain encryption / decryption keys for accessing encrypted memory data. To address the issue of limited key storage capacity, the present invention adopts an on-chip memory storage method and an LRU replacement strategy. To efficiently obtain keys, the present invention refers to the design concept of the Cuckoo Hash Page Table and provides an implementation method applying the Cuckoo Hash Key Table. The specific steps for the key management module to access the corresponding key are as follows:
[0087] Generally, a small buffer buffer1 is used to store keys of some virtual machines or processes. First, the buffer is accessed. If the key does not exist, it is searched in the memory key table. If it still does not exist, a key is generated and stored. When a process is destroyed, the manager will clear all keys corresponding to that process.
[0088] Among them, LRU is a commonly used replacement method. In addition, the Cuckoo Hash Key Table can achieve multi-way key lookup at the minimum cost.
[0089] Further preferably, the instruction set of the above RISC-V architecture is extended and further includes two instructions, genky and setky, for memory encryption. The genky instruction is used to enable the key management module to generate a default key for a user process; the setky instruction is used for the user to specify a private key. As Figure 8 shown, the specific way for the above key management module to manage keys is as follows:
[0090] S1. Use a buffer to store keys of some virtual machines or processes corresponding to the most recently used memory pages;
[0091] S2. Upon being triggered, obtain the virtual machine number, process number, core number, key number, and encryption flag bit of the current memory page where the data to be encrypted / decrypted is located through a trusted channel. Determine the target key according to the key number, virtual machine number, process number, core number, and the applied memory space address, and judge whether the target key is in the buffer; if so, directly transmit the target key to the encryption / decryption engine; if not, go to step S3; where the key number is the number of the default key or the number of the private key;
[0092] S3: Judge whether the number of keys evicted to the memory key table is 0; if so, go to step S8; if not, go to step S4;
[0093] S4: Judge whether the target key is in the memory key table; if so, transmit the target key to the encryption / decryption engine and go to step S5; if not, go to step S8;
[0094] S5: Determine whether there is free storage space in the buffer; if yes, go to step S7; if no, go to step S6;
[0095] S6: Use the LRU policy to find the least recently used key, encrypt the least recently used key with the key generated by the trusted platform module using an algorithm, evict it to the memory key table, increment the eviction key counter by one, and go to step S7;
[0096] S7: Insert the target key into the buffer;
[0097] S8: Raise an error to the user.
[0098] Preferably, after inserting the target key into the buffer, the above key management module is further configured to: encrypt the pending eviction key K-e with the key generated by the trusted platform module using the encryption and decryption engine, and insert K-e into the memory key table, where the memory key table is a Cuckoo Hash Key Table constructed and managed by the key management module.
[0099] The buffer finds the least recently used key through the LRU policy and evicts it from the buffer for replacement. The main process of the Cuckoo Hash Key Table Entry is as Figure 4 shown. The Valid bit indicates whether the key row is valid. The VMID and PID respectively represent the virtual machine number and process number corresponding to the key row. The internalKey stores the key generated by the key manager, and the externalKey stores the key specified by the user. The key generated by the trusted platform module (TPM) is stored in the one-time programmable (OTP) memory inside the platform and is encrypted, with high security and cannot be obtained by other software and hardware.
[0100] Embodiment 2
[0101] A method for performing memory encryption transmission using the hardware memory encryption system described in Embodiment 1 based on the RISC-V architecture, specifically: embedding the hardware memory encryption system into a computer system, where the encryption and decryption engine and the key management module in the hardware memory encryption system are set in the memory controller of the computer system, and as Figure 1 and Figure 2 shown, perform the following steps:
[0102] After the computer system is powered on and the hardware memory encryption system completes self-check, the key management module in the hardware memory encryption system calls the instructions setcbit and setkybit to set the key number and encryption flag bit of the applied memory space respectively, so as to set the memory space as an encrypted space; after receiving the trigger signal that the processor of the computer system controls the memory controller to read data from or write data to the memory, obtain the virtual machine number, process number, core number, key number and encryption flag bit of the current memory page where the data is located through a trusted channel; determine whether the data needs to be encrypted according to the encryption flag bit; if not, directly send the data out of the memory controller, if so, perform a key access based on the key number, virtual machine number, process number, core number and the address of the encrypted space, obtain the target key and distribute it to the encryption and decryption engine;
[0103] The encryption and decryption engine in the hardware memory encryption system encrypts and decrypts the data using a software algorithm based on the key and sends the data out of the memory controller;
[0104] When the transmission module in the hardware memory encryption system receives an instruction request for data transmission and passes the security verification, it calls the datats and accdatats instructions to send and receive memory data respectively, realizing the whole-process encrypted transmission.
[0105] That is, the operation of a hardware memory encryption system based on the RISC-V architecture described in Embodiment 1 mainly includes the following steps:
[0106] S1. When the processor reads or writes data from / to the memory, the key management module accesses the key corresponding to the page and distributes the corresponding key to the encryption and decryption engine, and the encryption and decryption engine encrypts and decrypts the data using the SM4 algorithm; regarding the memory data encryption method, as Figure 5 shown, the architecture of the encryption and decryption engine module is as Figure 7 shown.
[0107] S2. When the local server receives an instruction request of ReqMigration and passes the verification, it calls the RecvMigration instruction to transmit the local encrypted data to the remote end, realizing the whole-process encrypted transmission.
[0108] In step S2, the KeyID bit is used to identify which key corresponds to the process. A process can have at most two keys. The KeyID defaults to 0, indicating the storage of the transparent key generated by the key management module, and the KeyID being 1 indicates the storage of the key given by the user.
[0109] Further, to enable communication between processes, the user can set the same key (or not encrypt) for the shared pages of the processes that need to share memory. In step S1 of the present embodiment, instructions for memory encryption and data transmission are added on the basis of the RISC-V architecture, and available programming interfaces are provided. The specific form and function description of the API are as follows:
[0110] (1)void*encryptedMalloc(
[0111] bool enc,
[0112] size_t size,
[0113] boolext,
[0114] unsigned char*extKey)
[0115] Used to apply for memory space and call the instructions setcbit and setkybit to set the C-bit and KeyID-bit of the corresponding memory page to the corresponding values respectively. The parameter enc indicates whether the applied memory space needs to be encrypted. If it is true, it needs to be encrypted and the value of the C-bit is set to 1; otherwise, it is not encrypted and the value of the C-bit is set to 0. The parameter size is the size of the applied memory space. The parameter ext indicates whether to use a specified key for encryption. If it is true, a specified key is used, the value of the KeyID-bit is set to 1, and the instruction setky is called to import the specified key for the current process; otherwise, the key generated by the key manager is used and the value of the KeyID-bit is set to 0. The parameter extKey points to the user-specified key. Since the channel for inputting the key is not necessarily secure, it is generally not recommended to use the specified key for encrypting private memory, but for encrypting the shared coexistence between processes. If the user repeatedly uses this function in the same process and uses two or more specified keys (i.e., extKey), the system throws an error.
[0116] (2)void encryptedFree(
[0117] void*p,
[0118] bool enc)
[0119] Used to release the memory space applied for by encryptedMalloc. The parameter p points to the memory space to be released. The parameter enc indicates whether the space has been encrypted. If it is true, it has been encrypted; otherwise, it has not been encrypted.
[0120] (3)void DataTrans(
[0121] void*p,
[0122] size_t size,
[0123] void* dstOpt)
[0124] Used to initiate memory data transmission and call the instruction dataTransmission for transmission. The parameter p points to the starting position of the memory data to be transmitted; the parameter size is the size of the data; dstOpt points to a target information structure migDest. The structure migDest contains 5 elements: ipv4 represents the ipv4 address of the target host, port represents the port number of the target host, nvmid represents the target virtual machine number of the target host, npid represents the target process number in the target host, and size represents the size of the memory data to be transmitted.
[0125] (4)void AccDataTrans(
[0126] void* p,
[0127] void* IDA)
[0128] Used to receive memory data transmission and call the instruction dataTransmission for reception. The parameter p points to the storage address for receiving data; the parameter IDA points to the identification code of the source to be received (a machine code that uniquely identifies a hardware device).
[0129] In steps S1 and S2, to implement the functions of memory data transmission and virtual machine migration, the system makes appropriate extensions under the original RISC-V instruction set and innovatively adds six instructions, namely genky, setky, setcbit, setcbit, datats, accdatats. Their definition methods and function descriptions are the same as those in Embodiment 1 and will not be elaborated here.
[0130] Preferably, the memory data transmission scheme authorized by the above protocol realizes the whole-process memory data encryption transmission module. Specifically, as Figure 6 shown, the implementation method of sending memory data is:
[0131] When the computer system initiates a data transmission request to the remote server and receives the transmission public key and identity information sent by the remote server, the encryption and decryption engine encrypts a triple structure using the transmission key. The triple structure is in the order of: VMID-VPIDcore-KeyID information of the data to be transmitted, the key, and the page table entry where the data to be transmitted is located. The computer system sends the triple structure and the memory data to be transmitted to the remote server, where VMID-VPIDcore-KeyID represents the virtual machine number, process number, and key number used for the corresponding page. The remote server redeploys the virtual machine according to the triple.
[0132] Further preferably, the specific implementation manner of sending the memory data is as follows:
[0133] (1) The computer system sends a local data transmission request according to msg = tS0||randN0||size: IDA||cla||PB||sigB(msg)||msg, where the || symbol represents string concatenation, msg represents the local data transmission request information, tS0 represents the timestamp information, randN0 represents a random number, size represents the size of the transmitted data, cla represents the operation type, representing virtual machine migration or data transmission, PB represents the public key generated by the computer system transmission module, and sigB(msg) is a function whose function is to sign msg using the private key generated by the computer system transmission module;
[0134] (2) After the remote server looks up the device code IDA pre-added to its approved list and verifies: verPB(sigB) = msg, where verPB(sigB) is a function whose function is for the remote server to verify the signature of msg using PB; if the verification is successful, perform configurations such as memory allocation according to cla; send the identity string IDA||sigK(randN0)||EPB(rVMID||rPID) to the computer system; where K represents the private key of the remote server under the AC certificate system, sigK(randN0) represents the signature returned by the remote server using the private key for the random number randN0, rVMID represents the number of the target virtual machine on the remote server, rPID represents the number of the target process on the remote server, and EPB() is a function representing SM2 encryption of rVMID||rPID using PB;
[0135] (4) The computer sends EPK(sk)||SM4SK(sigB(H(KT))||M to the remote server. The computer system generates a random session key sk for this transmission and sends EPKL(sk)||SM4SK(sigL(SM3(M)))||M, where EPK(sk) represents the local computer system encrypting sk using the public key of the remote device, SM4SK() represents encryption using the session key, KT represents VMID||VPIDcore||Key0||Key1, and SM3(M) represents calculating the check value of KT using the SM3 algorithm.
[0136] (5) After receiving the Ack signal from the remote server, the computer system sends Mc, where the Ack signal represents the key-in-place confirmation signal and Mc represents the encrypted memory data.
[0137] Generally speaking, the present invention is first based on the open-source instruction set architecture of RISC-V. The RISC-V instruction set architecture is open-source and has the advantages of low power consumption, low cost, strong scalability, security and reliability, small area, and simplicity compared with the Intel x86 and ARM architectures. Using the RISC-V architecture, developers do not have to purchase expensive architecture licenses and can independently modify the instruction set, define functional modules, patch vulnerabilities and updates, reducing code density and development difficulty. In the present invention, the RISC-V architecture is used to expand six system instructions on the basis of the original instruction set, realizing the functions of memory data encryption and decryption and memory data transmission. Secondly, the present invention realizes software-transparent multi-key encryption. Currently, memory encryption schemes that support multiple keys, such as Intel's MKTME, only support a limited number of keys, resulting in a waste of hardware resources. To solve this problem, the present invention designs a multi-key eviction scheme, implements the LRU replacement strategy in the memory field, and applies the Cuckoo Hash Key Table: Keys that exceed the on-chip storage capacity of the CPU are encrypted by the internal CPU key through the encryption engine and stored in the reserved area of the DDR memory. This scheme realizes the complete transparency of the keys to other software and hardware. At the same time, since cold-boot attackers cannot obtain the internal CPU key, it can also resist cold-boot attacks. In addition, the present invention's scheme supports data transmission, and existing memory encryption schemes do not support memory data transmission schemes. Nowadays, various technologies such as cloud services and memory pooling are constantly developing, and memory interconnection and heterogeneous pooling have become hotspots. To adapt to and solve the data security transmission under memory encryption, the present invention designs a software-transparent memory data transmission scheme: The local program calls the transmission instruction, uses the SM2 national cryptography algorithm, and transmits the page data and keys through the transmission module. The remote end is also responsible for decryption by the transmission module, without the participation of third-party software. Using this scheme can reduce the software development cost on the one hand and also reduce the security risks from third-party software on the other hand.
[0138] Embodiment III
[0139] A computer system is embedded with a hardware memory encryption system based on the RISC-V architecture described in Embodiment I and is used to execute the method of memory encryption transmission described in Embodiment II.
[0140] The related technical solutions are the same as those in Embodiment I and Embodiment II and will not be elaborated here.
[0141] Those skilled in the art can easily understand that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A hardware memory encryption system based on the RISC-V architecture, characterized in that, Including: A key management module, an encryption / decryption engine, a transmission module, and a programming interface set based on the RISC-V architecture; among them, The instruction set of the RISC-V architecture is extended to include two instructions, setcbit and setkybit, for memory encryption. Through the programming interface, the key management module can be used to call the instructions setcbit and setkybit to respectively set the encryption flag bit and key number of the applied memory space, thereby setting the memory space as an encrypted space; When performing key management, the key management module is divided into two parts: key storage and key acquisition. Among them, the on-chip memory key storage method is adopted, and the LRU replacement policy is used to maintain the on-chip buffer, and the Cuckoo Hash KeyTable is used as the memory key table; The instruction set of the RISC-V architecture is extended to also include two instructions, datats and accdatats, for memory data transmission. By configuring the programming interface, the transmission module can call the instructions datats and accdatats to respectively send and receive memory data; Among them, using the RV64 R-type instruction format, the definition methods of the instructions genky, setky, setcbit, setkybit, datats, and accdatats are designed as follows: The method of defining the genky instruction is: define that the instruction has no write-back result and the instruction does not need to read operands; The method of defining the setky instruction is: define that the instruction has no write-back result and the instruction needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the shared key; The method of defining the setcbit instruction is: define that the instruction has no write-back result and the instruction needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the virtual guest page to be set; The method of defining the setkybit instruction is: define that the instruction has no write-back result and the instruction needs to read the operand rs1, and the value of the operand rs1 is the virtual address of the virtual guest page to be set; The method of defining the datats instruction is: define that the instruction has no write-back result and the instruction needs to read the operands rs1 and rs2, the value of the operand rs1 is the virtual address of the memory to be transmitted, and the value of the operand rs2 is the virtual address of the target information structure; The method of defining the accdatats instruction is: define that the instruction has no write-back result and the instruction needs to read the operands rs1 and rs2, the value of the operand rs1 is the virtual address of the data to be received, and the value of the operand rs2 is the virtual address of the guest information structure.
2. The hardware memory encryption system according to claim 1, wherein The key management module is also used to, according to the user request, call the setkybit and setcbit instructions to restore the key number and encryption flag bit of the memory page to be released to the default values, thereby setting the memory space as a non-encrypted space; and through the Free method, notify the operating system to release this memory space, thereby releasing the encrypted memory space.
3. The hardware memory encryption system according to claim 1, characterized in that, The way the key management module performs key management is: Use a buffer to store the keys of some virtual machines or processes. First, access the buffer. If the key does not exist, look it up in the memory key table. If it still does not exist, generate a key and store it. When a process is destroyed, all the keys corresponding to that process are cleared.
4. The hardware memory encryption system according to claim 3, wherein The instruction set of the RISC-V architecture is extended and also includes two instructions, genky and setky, for memory encryption. The genky instruction is used to make the key management module generate a default key for a user process; the setky instruction is used for the user to specify a private key. The specific way for the key management module to manage keys is as follows: S1: Use a buffer to store the keys of some virtual machines or processes corresponding to the most recently used memory pages. S2: After being triggered, obtain the virtual machine number, process number, core number, key number, and encryption flag bit of the current memory page where the data to be encrypted / decrypted is located through a trusted channel. Determine the target key based on the key number, virtual machine number, process number, core number, and the applied memory space address, and judge whether the target key is in the buffer. If so, directly transmit the target key to the encryption / decryption engine; if not, go to step S3. Among them, the key number is the number of the default key or the number of the private key. S3: Judge whether the number of keys evicted to the memory key table is 0. If so, go to step S8; if not, go to step S4. S4: Judge whether the target key is in the memory key table. If so, transmit the target key to the encryption / decryption engine and go to step S5; if not, go to step S8. S5: Judge whether there is free storage space in the buffer. If so, go to step S7; if not, go to step S6. S6: Use the LRU strategy to find the least recently used key, encrypt the least recently used key with the key generated by the trusted platform module using an algorithm, evict it to the memory key table, increment the evicted key counter by one, and go to step S7. S7: Insert the target key into the buffer. S8: Send an error prompt to the user.
5. The hardware memory encryption system according to claim 4, characterized in that, After inserting the target key into the buffer, the key management module is also used for: Use the key generated by the trusted platform module through the encryption / decryption engine to encrypt the pending evicted key K-e and insert K-e into the memory key table, where the memory key table is a Cuckoo HashKey Table constructed and managed by the key management module.
6. A method for performing memory encryption transmission using a hardware memory encryption system based on the RISC-V architecture as described in any one of claims 1 to 5, characterized in that, Embed the hardware memory encryption system into the computer system, where the encryption / decryption engine and the key management module in the hardware memory encryption system are set in the memory controller of the computer system and perform the following steps: After the computer system is powered on and the hardware memory encryption system completes self-check, and when the user applies for an encrypted memory space through the programming interface, the key management module in the hardware memory encryption system calls the instructions setcbit and setkybit to set the encryption flag bit and key number of the applied memory space respectively, so as to set the memory space as an encrypted space; after receiving the trigger signal from the processor of the computer system to control the memory controller to read data from or write data to the memory, obtain the virtual machine number, process number, core number, key number, and encryption flag bit of the memory page where the data is located through the trusted channel; determine whether the data needs to be encrypted according to the encryption flag bit; if not, directly send the data out of the memory controller, if so, based on the key number, the virtual machine number, the process number, the core number, and the address of the encrypted space, perform a key access, obtain the target key and distribute it to the encryption and decryption engine in the hardware memory encryption system; The encryption and decryption engine encrypts and decrypts the data according to the key and delivers the data to the memory controller; When the transmission module in the hardware memory encryption system receives an instruction request for data transmission and passes the security verification, it calls the instructions datats and accdatats to perform the sending and receiving of memory data respectively, realizing full-process encrypted transmission.
7. The method according to claim 6, wherein The implementation method of sending memory data is as follows: When the computer system initiates a data transmission request to the remote server and receives the transmission public key and identity information sent by the remote server, the encryption and decryption engine encrypts a triple structure using the transmission public key. The triple structure is in the order of: VMID-VPIDcore-KeyID information of the space where the memory data to be transmitted is located, the key, and the page table entry of the memory data to be transmitted; the computer system sends the triple structure and the memory data to be transmitted to the remote server, where VMID-VPIDcore-KeyID represents the virtual machine number, process number, and key number used by the corresponding page.
8. The method according to claim 7, wherein The specific implementation method of sending memory data is as follows: (1) The computer system sends a local data transmission request according to msg = tS0||randN0||size: IDA||cla||PB||sigB(msg)||msg, where the || symbol represents the concatenation of strings, msg represents the local data transmission request information, tS0 represents the timestamp information, randN0 represents a random number, size represents the size of the transmitted data, cla represents the operation type, representing virtual machine migration or data transmission, PB represents the public key generated by the transmission module of the computer system, and sigB(msg) is a function whose function is to sign msg using the private key generated by the transmission module; (2) After the computer system receives the identity string IDA||sigK(randN0)||EPB(rVMID||rPID) sent by the remote server, the transmission module verifies IDA||sigK(randN0); if the verification is successful, it sends EPK(sk)||SM4SK(sigB(H(KT))||M to the remote server, where sk is the random session key generated by the computer system for this transmission, EPK(sk) represents that the local computer system encrypts sk using the public key of the remote device, SM4SK() represents encryption using the session key, KT represents VMID||VPIDcore||Key0||Key1, and SM3(M) represents calculating the verification value of KT using the SM3 algorithm; among them, the identity string IDA||sigK(randN0)||EPB(rVMID||rPID) is obtained by the remote server by looking up the device code IDA pre-added to its approved list and verifying: verPB(sigB)=msg, where verPB(sigB) is a function whose function is for the remote server to verify the signature of msg using PB. If the verification is successful, it is configured according to cla and is the identity string sent to the computer system; where K represents the private key under the AC certificate system of the remote server, sigK(randN0) represents the signature returned by the remote server using the private key for the random number randN0, rVMID represents the number of the target virtual machine on the remote server, rPID represents the number of the target process on the remote server, and EPB() is a function representing SM2 encryption of rVMID||rPID using PB. (3) After the remote server successfully obtains the sk and KT information, it sends an Ack signal to the computer system, where the Ack signal represents a key-in-place confirmation signal. (4) The computer system sends Mc after receiving the Ack signal, where Mc represents the encrypted memory data.
9. A computer system, characterized in that, A hardware memory encryption system based on the RISC-V architecture as described in any one of claims 1 to 5 is embedded for performing the memory encryption transmission method as described in any one of claims 6 to 8.
Citation Information
Patent Citations
Processor and method for clearing translation backup buffer area by specified key identification code
CN114064518A
Method and apparatus for multi-key total memory encryption based on dynamic key derivation
US20210200880A1