Safe data processing method and device
By dynamically switching modes between processing cores and using control circuits to coordinate thread pause and recovery, the balance problem of SMT technology between system security and performance is solved, and the efficient operation of secure data processing is achieved.
Patent Information
- Application Number
- CN202080002516.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-30
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2040-04-30
AI Technical Summary
When the prior art uses synchronous multithreading (SMT) technology, it is difficult to both reduce attack risks and maintain system performance, and the user configuration scheme is poorly applicable or the user experience is poor.
By dynamically switching modes between processing cores, and using control circuits to coordinate processing core pause and restore threads, data processing in safe mode is realized, avoiding the complete shutdown of SMT function and maintaining system performance.
On the basis of supporting SMT functions, it improves system security, reduces attack risks, and maintains system performance. It is suitable for a variety of processor architectures, including CPUs in Intel and ARM architectures.
Smart Images

Figure CN116097221B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of secure data, and particularly to a secure data processing method and device. Background Art
[0002] Simultaneous multithreading (SMT, also known as synchronous multithreading) technology means that the central processing unit (CPU) of an architecture executes multiple threads in parallel on the physical or logical cores of the central processing unit (CPU). These multiple threads can share physical resources to improve system performance and reduce power consumption. However, the time-sharing multiplexing of shared resources between multiple processing cores causes time differences in accessing shared resources, which in turn makes it vulnerable to attacks and leads to the leakage of sensitive information.
[0003] Currently, several methods have been proposed to reduce the risk of SMT attacks, but they all have various defects. For example, turning off the SMT function to reduce the attack risk, but the technical advantages of SMT cannot be utilized, resulting in a decline in system performance. Re-enabling the SMT function requires a large delay, such as restarting the system. Another example is that the user determines whether to enable SMT by themselves, but this solution is only applicable to products where the user can modify the software configuration, such as a computer, and is not applicable to products where the user cannot modify the software configuration, such as a mobile phone. The applicability is poor, and this solution requires the user to have corresponding technical knowledge to accurately configure SMT, resulting in a poor user experience. Another example is to eliminate the code that may leak sensitive information, that is, to change the process of processing sensitive information in the code to the form of "constant-time" code. However, when the data stream related to sensitive information is long, this solution will result in false negatives or false positives of the code of sensitive information, and the code corresponding to sensitive information is also huge, making this solution difficult to implement. Another example is to divide the physical resources of the CPU according to logical cores, allocate physical resources separately for each logical core, and prohibit one logical core from accessing the physical resources of other logical cores to reduce the attack risk. Similar to the above solution of turning off the SMT function, this solution also cannot utilize the technical advantages of SMT, resulting in a decline in system performance.
[0004] In summary, the above solutions cannot meet the requirements of both reducing the attack risk and utilizing the technical advantages of SMT. Summary of the Invention
[0005] Embodiments of this application provide a secure data processing method and device, which can improve system security and reduce the attack risk on the basis of supporting the SMT function. To achieve the above objective, this application adopts the following technical solutions.
[0006] In a first aspect, a secure data processing method is provided. The secure data processing method includes: a first processing core executing a first thread in a normal mode, a second processing core executing a second thread in the normal mode, the first processing core pausing the execution of the first thread when it needs to switch to a secure mode, the first processing core instructing the second processing core to pause the execution of the second thread, and then the second processing core pausing the execution of the second thread according to the instruction of the first processing core, and the first processing core switching from the normal mode to the secure mode to process first information. It should be noted that this application does not limit the order of the first processing core pausing the execution of the first thread and the first processing core instructing the second processing core to pause the execution of the second thread.
[0007] Based on the secure data processing method described in the first aspect, when the processing core does not need to switch to the secure mode to process information, each processing core executes its corresponding thread in the normal mode, leveraging the advantages of multi-threading to improve system performance. When one of the processing cores needs to switch to the secure mode, it instructs the other processing cores to pause the execution of the corresponding threads. For example, if the first processing core needs to switch to the secure mode, it instructs the second processing core to pause the execution of the second thread, which can eliminate the risk of other processing cores maliciously exploiting the shared resource race condition to launch attacks when one processing core processes the first information in the secure mode, thereby improving system security. In addition, this solution does not require completely turning off the SMT function, improving system performance.
[0008] In a possible design, the first processing core instructing the second processing core to pause the execution of the second thread may include: the first processing core sending a first instruction message to a control circuit, and the control circuit sending a second instruction message to the second processing core in response to the first instruction message, where the second instruction message is used to instruct the second processing core to pause the execution of the second thread. That is, the first processing core can send information that it needs to switch to the secure mode to the control circuit so that the control circuit instructs the second processing core to pause the execution of the second thread.
[0009] Optionally, the control circuit may include: a secure mode synchronization module or an interrupt controller.
[0010] In a possible design, after the second processing core pauses the execution of the second thread according to the instruction of the first processing core, the secure data processing method may further include: the second processing core switching to the secure mode, or entering a first low-power state in the normal mode to reduce power consumption.
[0011] Optionally, after the second processing core switches to the secure mode, the secure data processing method may further include: the second processing core enters the second low-power state in the secure mode, or processes second information in the secure mode. That is to say, after the second processing core switches to the secure mode, it can enter the second low-power state to reduce the system power consumption, or process the second information that it needs to process. At this time, the second information may be different from the first information, or after being merged with the first processing core into a single core, the second information can be processed. At this time, the second information may be the same as the first information, that is, the merged single core processes the first information that the first processing core needs to process.
[0012] In a possible design, after the first processing core switches from the normal mode to the secure mode to process the first information, the secure data processing method may further include: the first processing core exits the secure mode, the first processing core triggers the second processing core to resume executing the second thread, the first processing core resumes executing the first thread, and the second processing core resumes executing the second thread according to the trigger of the first processing core.
[0013] That is to say, after the first processing core finishes processing the first information in the secure mode, it can exit the secure mode, continue to execute the first thread in the normal mode, and trigger the second processing core to resume executing the second thread, so as to continue to take advantage of the system's multi-threading. It should be noted that this application does not limit the order of the first processing core triggering the second processing core to resume executing the second thread and the first processing core resuming executing the first thread.
[0014] In a possible design, before the first processing core exits the secure mode, the secure data processing method may further include: the first processing core clears the traces of processing the first information in the secure mode, that is, the first processing core can clear the usage traces remaining in the shared hardware resources after processing the first information in the secure mode, so as to further improve the system security. Similarly, if the second processing core processes the second information in the secure mode, then before the second processing core exits the secure mode, the second processing core can clear the usage traces remaining in the shared hardware resources after processing the second information in the secure mode, so as to further improve the system security.
[0015] Optionally, the first processing core and the second processing core may be physical cores or logical cores.
[0016] In a second aspect, a secure data processing device is provided. The secure data processing device includes a first processing core and a second processing core. Among them, the first processing core is used to execute the first thread in the normal mode, pause executing the first thread when it needs to switch to the secure mode, instruct the second processing core to pause executing the second thread, and switch from the normal mode to the secure mode to process the first information. The second processing core is used to execute the second thread in the normal mode and pause executing the second thread according to the instruction of the first processing core.
[0017] In a possible design, the secure data processing device may further include a control circuit. Among them, the first processing core is further configured to send first indication information to the control circuit, and the control circuit is configured to send second indication information to the second processing core in response to the first indication information, where the second indication information is used to instruct the second processing core to suspend the execution of the second thread.
[0018] Optionally, the control circuit includes: a secure mode synchronization module or an interrupt controller.
[0019] In a possible design, the second processing core is further configured to switch to the secure mode after suspending the execution of the second thread according to the instruction of the first processing core, or enter the first low-power state in the normal mode.
[0020] In a possible design, the second processing core is further configured to enter the second low-power state in the secure mode, or process the second information in the secure mode after the second processing core switches to the secure mode.
[0021] In a possible design, the first processing core is further configured to: after switching from the normal mode to the secure mode to process the first information, exit the secure mode, trigger the second processing core to resume the execution of the second thread, and resume the execution of the first thread. The second processing core is further configured to resume the execution of the second thread according to the trigger of the first processing core.
[0022] In a possible design, the first processing core is further configured to erase the traces of processing the first information in the secure mode before exiting the secure mode.
[0023] Optionally, the first processing core and the second processing core may be physical cores or logical cores.
[0024] It should be noted that the secure data processing device described in the second aspect may be a processor. In addition, the technical effects of the secure data processing device described in the second aspect may refer to the technical effects of the secure data processing method described in any implementation manner of the first aspect, which will not be elaborated here.
[0025] In a third aspect, a secure data processing device is provided. The secure data processing device includes a first processing module and a second processing module. Among them, the first processing module is used to implement the functions of the first processing core involved in any possible implementation manner in the first aspect, and the second processing module is used to implement the functions of the second processing core involved in any possible implementation manner in the first aspect.
[0026] In a possible design, the secure data processing device may further include a control module. Among them, the control module may be used to implement the functions of the control circuit involved in any possible implementation manner in the first aspect.
[0027] In a possible design, the security data processing device described in the third aspect may further include a storage module, which may be a memory. The storage module is used to store program instructions and data for implementing the functions involved in any possible implementation manner in the first aspect. When the first processing module, the second processing module, and the control module execute the program or instructions, the security data processing device described in the third aspect can execute the security data processing method described in the first aspect.
[0028] Optionally, the security data processing device described in the third aspect may further include a transceiver module. The transceiver module may be a transceiver circuit or an input / output port, and the transceiver module can be used to implement the transceiver functions involved in any possible implementation manner in the first aspect. The transceiver module may include a receiving module and a transmitting module. The specific implementation manner of the transceiver module in this application is not specifically limited.
[0029] It should be noted that the security data processing device described in the third aspect may be a processor. One or more of the above modules may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions. When any of the above modules is implemented by software, the software exists in the form of computer program instructions and is stored in the memory. In addition, the technical effects of the security data processing device described in the third aspect can refer to the technical effects of the security data processing method described in any implementation manner in the first aspect, which will not be elaborated here.
[0030] In a fourth aspect, a security data processing system is provided, and the security data processing system includes the security data processing device described in the second aspect or the third aspect.
[0031] In a fifth aspect, a computer-readable storage medium is provided. The computer-readable storage medium includes a computer program or instructions. When the computer program or instructions run on a computer, the computer is caused to execute the security data processing method described in any possible implementation manner in the first aspect. The computer includes a first processing core and a second processing core.
[0032] In a sixth aspect, a computer program product is provided. The computer program product includes: a computer program or instructions. When the computer program or instructions run on a computer, the computer is caused to execute the security data processing method described in any possible implementation manner in the first aspect. The computer includes a first processing core and a second processing core. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is a schematic diagram of the architecture of the security data processing system provided by the embodiment of this application;
[0034] Figure 2 Schematic flowchart of the security data processing method provided by an embodiment of this application Figure 1 ;
[0035] Figure 3 Schematic structure diagram of the security data processing device provided by an embodiment of this application Figure 1 ;
[0036] Figure 4 Schematic flowchart of the security data processing method provided by an embodiment of this application Figure 2 ;
[0037] Figure 5 Schematic flowchart of the security data processing method provided by an embodiment of this application Figure 3 ;
[0038] Figure 6 Schematic structure diagram of the security data processing device provided by an embodiment of this application Figure 2 ;
[0039] Figure 7 Schematic structure diagram of the security data processing device provided by an embodiment of this application Figure 3 . Detailed implementation manners
[0040] Next, the technical solutions in this application will be described in conjunction with the accompanying drawings. In this application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item)" or similar expressions thereof refer to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple.
[0041] This application will present various aspects, embodiments, or features around a system that may include multiple devices, components, modules, etc. It should be understood and clear that each system may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. In addition, combinations of these solutions may also be used.
[0042] In addition, in the embodiments of the present application, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present application should not be construed as being more preferred or more advantageous than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner.
[0043] Figure 1 FIG. is a schematic architecture diagram of a security data processing system applicable to the security data processing method provided in the embodiments of the present application. To facilitate understanding of the embodiments of the present application, first, Figure 1 Taking the architecture of the security data processing system shown in as an example, the architecture of the security data processing system applicable to the embodiments of the present application is described in detail. The security data processing system may be a CPU of the Intel architecture using SMT technology, or a CPU of the ARM architecture using SMT technology, or other CPUs using SMT technology. It should be noted that the solutions in the embodiments of the present application can also be applied to security data processing systems of other architectures. Of course, in this embodiment, the CPU is taken as an example for introduction, but the present solution is not limited thereto, but can be extended to other types of processors.
[0044] As Figure 1 shown, the security data processing system includes a hardware layer and a software layer. Among them, the hardware layer may include a first processing core and a second processing core. It can be understood that the solution of the present application may include more processing cores, and only two processing cores are taken as an example for introduction in subsequent embodiments. Optionally, the hardware layer may further include a control circuit. The software layer may include a rich execution environment (REE, also known as a rich execution environment), a trusted execution environment (TEE), and a security processing core scheduling module. Among them, the REE environment may be referred to as a normal mode or a non-secure mode, including an Android or Windows environment, the TEE environment may be referred to as a secure mode, and the security processing core scheduling module may include: an active processing core scheduling module, an idle processing core scheduling module, and a security processing core synchronization control module.
[0045] Next, each component of the hardware layer of the security data processing system is specifically introduced. Among them, the first processing core executes the first thread, and the second processing core executes the second thread. Optionally, the security data processing system may include more than two processing cores, and the more than two processing cores may all execute their respective corresponding threads in the REE environment. The present application does not limit this. Optionally, the first processing core may include a first synchronization circuit, and the second processing core may include a second synchronization circuit. The specific implementation manners of the first synchronization circuit and the second synchronization circuit may refer to S203 below and will not be elaborated here.
[0046] The control circuit can be used to implement communication and interaction between processing cores, such as implementing inter-process communication. Specifically, the control circuit receives an event sent by a processing core that the processing core needs to switch to the TEE environment, and triggers other processing cores to pause or resume the execution of corresponding threads, without completely turning off the SMT mode, but allowing other processing cores to pause work or resume again when SMT is enabled. Exemplarily, the control circuit can be used to implement the first processing core instructing the second processing core to pause or resume the execution of the second thread. Optionally, the control circuit may include a security mode synchronization module or an interrupt controller ( Figure 1 not shown in the figure), and the specific implementation manner of the security mode synchronization module or the interrupt controller can refer to S203 described below, which will not be elaborated here.
[0047] The software modules included in the software layer of the secure data processing system will be specifically introduced below. Among them, the non-trusted execution environment can also be called the rich execution environment, and the processing core can execute corresponding threads in the non-trusted execution environment. For example, the first processing core executes the first thread in the non-trusted execution environment, and the second processing core executes the second thread in the non-trusted execution environment.
[0048] The trusted execution environment is isolated from the non-trusted execution environment and can be used for the protection of sensitive information. The processing core can execute security service codes in the trusted execution environment, such as fingerprint verification, identity authentication, etc.
[0049] The active processing core scheduling module can be used to schedule the processing core that actively requests to switch from the REE environment to the TEE environment to enter the TEE environment. For example, when the first processing core needs to switch from the REE environment to the TEE environment, the code of the active processing core scheduling module is executed to switch to the TEE environment.
[0050] The idle processing core scheduling module can be used to schedule other processing cores other than the processing core that actively requests to switch to the TEE environment to switch to the TEE environment. For example, if the first processing core is the processing core that actively requests to switch to the TEE environment, the second processing core can execute the code of the idle processing core scheduling module to enter the TEE environment.
[0051] The secure processing core synchronization control module is a driver for the control circuit in the hardware layer and can trigger the control circuit to generate corresponding actions. For example, triggering the control circuit to instruct the second processing core to pause the execution of the second thread. This solution does not require completely turning off the SMT mode, but allows the second processing core to pause work or resume later when SMT is enabled.
[0052] It should be understood that Figure 1 only a simplified schematic diagram shown for easy understanding, and the architecture schematic diagram of the secure data processing system may also include other components / units, Figure 1 not shown in the figure. The following will be combined withFigures 2 - 5 Specifically describe the security data processing method provided by the embodiments of this application.
[0053] Figure 2 The flow chart of the security data processing method provided by the embodiments of this application Figure 1 . This security data processing method can be applicable to Figure 1 the communication between components in the hardware layer shown in Figure 2 As shown, this security data processing method includes the following steps: S201, the first processing core executes the first thread in the normal mode, and the second processing core executes the second thread in the normal mode. Optionally, the normal mode can be Figure 1 the REE environment shown in , and the normal mode can also be called the non-secure mode. The REE environment is a general operating environment, and the processing core can execute the corresponding thread in the REE environment. Optionally, the first processing core and the second processing core can be physical cores or logical cores.
[0054] Next, introduce the physical core and the logical core in combination with Figure 3 . The security data processing method provided by the embodiments of this application can be applied to a security data processing device. Figure 3 The structural schematic diagram of the security data processing device provided by the embodiments of this application Figure 1 .
[0055] As Figure 3 shown, the security data processing device may include one or more physical cores, such as physical core 0 and physical core 1. Each physical core may include one or more logical cores, such as logical core 0 and logical core 1. Among them, each physical core may include physical resources, that is, the corresponding circuit hardware core. Specifically, the physical resources may include at least one of the following: level 1 instruction cache (L1 Instruction Cache), level 1 data cache (L1 data cache), cache bank, translation lookaside buffer (TLB), vector unit, load / store buffer, port connection, etc. The logical cores included in the physical core can share the physical resources. For example, logical core 0 and logical core 1 can share the physical resources of the physical core, which can improve system performance and reduce power consumption. It should be understood that Figure 3 is only a simplified schematic diagram for easy understanding, and other components / units may also be included in the structural schematic diagram of this security data processing device, Figure 3 which are not drawn in . The specific definition of the logical core can refer to the description of the prior art.
[0056] S202, when the first processing core needs to switch to the secure mode, it pauses the execution of the first thread. Optionally, the secure mode can be Figure 1 the TEE environment shown in Figure 1 , where fingerprint verification, authentication, etc. can be performed in the TEE environment. That is, when the first thread needs to use the TEE service, the first processing core invokes the secure monitor call (SMC) instruction through the first thread, thereby determining that the first processing core needs to switch to the secure mode and pausing the first thread that is executing in the normal mode.
[0057] S203, the first processing core instructs the second processing core to pause the execution of the second thread. It should be noted that when the second processing core needs to switch to the secure mode, it can first pause the execution of the first thread and then instruct the second processing core to pause the execution of the second thread. Or, when the second processing core needs to switch to the secure mode, it can first instruct the second processing core to pause the execution of the second thread and then pause the execution of its own first thread. That is, this application does not limit the order of S202 and S203 above.
[0058] In a possible design, the above S203, where the first processing core instructs the second processing core to pause the execution of the second thread, may include the following steps 1 to 2.
[0059] Step 1, the first processing core sends a first indication message to the control circuit. Optionally, the first indication message can be used to indicate that the first processing core needs to switch to the secure mode. Or, the first indication message can be used to indicate that the second processing core pauses the execution of the second thread.
[0060] That is, the first processing core can send the actions it will perform to the control circuit for the control circuit to determine the following second indication message. Or, the first processing core can directly send the indication message for the second processing core to the control circuit according to its own state, and the control circuit directly forwards the indication message of the first processing core for the second processing core, that is, the following second indication message is the same as the first indication message at this time.
[0061] Step 2, the control circuit sends a second indication message to the second processing core in response to the first indication message. Optionally, the second indication message can be used to indicate that the second processing core pauses the execution of the second thread. Optionally, the second indication message can include a synchronization signal, or a secure interrupt, or a non-secure interrupt. Among them, the synchronization signal can be used to indicate that the second processing core switches to the secure mode, the secure interrupt can be used to indicate that the second processing core switches to the secure mode, and the non-secure interrupt can be used to indicate that the second processing core enters the first low-power state in the normal mode. In the first low-power state, the power consumption of the second processing core is lower than the power consumption of the second processing core in the normal working state.
[0062] Further, the control circuit may include: a security mode synchronization module or an interrupt controller. Taking the security mode synchronization module as an example, in a possible design solution, step S203 where the first processing core instructs the second processing core to suspend the execution of the second thread may include the following steps three to four.
[0063] Step three, the first processing core sends first indication information to the security mode synchronization module. Optionally, for the specific implementation manner of the first indication information, reference may be made to the above step one, which will not be elaborated here. Specifically, the security mode synchronization module may be used to trigger other processing cores to switch to the security mode when one processing core needs to or has switched to the security mode. For example, if the first processing core needs to or has switched to the security mode, it triggers the second processing core to switch to the security mode.
[0064] Step four, in response to the first indication information, the security mode synchronization module sends second indication information to the second processing core. Optionally, the second indication information may be a synchronization signal. For the specific implementation manner of the second indication information, reference may be made to the above step two, which will not be elaborated here.
[0065] It should be noted that the methods of switching the security mode include synchronous switching and asynchronous switching. Among them, the method in which a processing core enters the security mode through the SMC instruction and exits the security mode through an exception instruction is called synchronous switching. The method in which a processing core enters the security mode through an external interrupt or exception is called asynchronous switching. The TrustZone technology can support both synchronous switching and asynchronous switching, while the Intel SGX technology only supports synchronous switching.
[0066] Specifically, Figure 2 For the shown security data processing method, with the support of the security mode synchronization module at the hardware layer, the solution for the first processing core to switch to the security mode has a short delay, low performance overhead, and reduced attack risk. This solution is also applicable to the scenarios of synchronous switching to the security mode and asynchronous switching to the security mode, and can thus protect the TEE environments of the TrustZone technology and the Intel SGX technology and reduce the attack risk.
[0067] Further, any of the above processing cores may further include a synchronization circuit. For example, the first processing core may further include a first synchronization circuit, and the second processing core may further include a second synchronization circuit. Specifically, the first synchronization circuit may be used to actively send first indication information to the security mode synchronization module when the first processing core needs to switch from the normal mode to the security mode. The second synchronization circuit may be used to trigger the second processing core to suspend the execution of the corresponding thread when receiving the second indication information.
[0068] It should be noted that Figure 2The security data switching method shown is illustrated by taking the first processing core actively switching to the secure mode as an example. It should be understood that if the second processing core actively switches to the secure mode, the second processing core can execute Figure 2 the functions of the first processing core in the security data switching method shown, and the first processing core can execute Figure 2 the functions of the second processing core in the security data switching method shown. Similarly, the second synchronization circuit can execute Figure 2 the functions of the first synchronization circuit in the security data switching method shown, and the first synchronization circuit can execute Figure 2 the functions of the second synchronization circuit in the security data switching method shown.
[0069] Furthermore, in a possible design scheme, for the above S203, the first processing core instructing the second processing core to suspend the execution of the second thread may include the following steps five to six. Step five, the first synchronization circuit of the first processing core sends a first indication message to the secure mode synchronization module. For the specific implementation manner of the first indication message, reference may be made to the above step one, which will not be elaborated here.
[0070] Step six, in response to the first indication message, the secure mode synchronization module sends a second indication message to the second synchronization circuit of the second processing core. Optionally, the second indication message can be used to instruct the second processing core to suspend the execution of the second thread. Optionally, the second indication message can be a synchronization signal. For the specific implementation manner of the second indication message, reference may be made to the above step two, which will not be elaborated here.
[0071] That is to say, the synchronization circuit can monitor the event of the corresponding processing core switching to the secure mode and send the event to the secure mode synchronization module, so that the secure mode synchronization module instructs other processing cores to suspend the execution of the threads, and can also be used to receive the indication message of suspending the execution of the thread sent by the secure mode synchronization module to trigger the corresponding processing core to suspend the execution of the corresponding thread.
[0072] Taking the interrupt controller as an example, in another possible design scheme, for the above S203, the first processing core instructing the second processing core to suspend the execution of the second thread may include the following steps seven to eight. Step seven, the first processing core sends a first indication message to the interrupt controller. For the specific implementation manner of the first indication message, reference may be made to the above step one, which will not be elaborated here.
[0073] Specifically, the interrupt controller can be used to generate an inter-processor interrupt (IPI). One processing core can send an interrupt to other processing cores through the interrupt controller. The interrupt controller can include components such as a data bus buffer, a read / write circuit, and a register.
[0074] Step 8, the interrupt controller sends a second indication message to the second processing core in response to the first indication message. Optionally, the second indication message may be a secure interrupt or a non-secure interrupt. For the specific implementation of the second indication message, please refer to Step 2 above and will not be elaborated here.
[0075] It should be noted that Figure 2 the secure data processing method shown is applicable to the scenario of asynchronously switching to the secure mode with the support of the interrupt controller at the hardware layer, which can protect the TEE environment of the TrustZone technology and reduce the attack risk.
[0076] S204, the second processing core suspends the execution of the second thread according to the indication of the first processing core. In a possible design, after the second processing core suspends the execution of the second thread according to the indication of the first processing core, Figure 2 the secure data processing method shown may further include: the second processing core switches to the secure mode, or the second processing core enters the first low-power state in the normal mode.
[0077] Further, in a possible design, the above-mentioned second processing core switching to the secure mode may include the following Steps 9 to 11. Step 9, the second processing core receives a second indication message from the secure mode synchronization module. Optionally, the second indication message may be a synchronization signal, and the synchronization signal may be used to indicate the second processing core to switch to the secure mode. Step 10, the second processing core suspends the execution of the second thread. Step 11, the second processing core switches to the secure mode.
[0078] In another possible design, the above-mentioned second processing core switching to the secure mode may include the following Steps 12 to 14. Step 12, the second processing core receives a second indication message from the interrupt controller. Optionally, the second indication message may be a secure interrupt, and the secure interrupt may be used to indicate the second processing core to switch to the secure mode. Step 13, the second processing core suspends the execution of the second thread. Step 14, the second processing core switches to the secure mode.
[0079] That is to say, both the secure mode synchronization module and the interrupt controller can indicate the second processing core to enter the secure mode. In this way, the attack risk brought by the second processing core when the first processing core processes the first information in the secure mode can be eliminated, thereby improving the system security.
[0080] In a possible design, for the second processing core to enter the first low-power state in the normal mode, the following steps 15 to 17 may be included. Step 15, the second processing core receives second indication information from the interrupt controller. Optionally, the second indication information may be a non-secure interrupt, and the non-secure interrupt may be used to indicate that the second processing core enters the first low-power state in the normal mode. Step 16, the second processing core pauses the execution of the second thread. Step 17, the second processing core enters the first low-power state in the normal mode.
[0081] That is to say, the interrupt controller can indicate to enter the first low-power state in the normal mode. In this way, the attack risk brought by the second processing core when the first processing core processes the first information in the secure mode can be eliminated, thereby improving the system security.
[0082] S205, the first processing core switches from the normal mode to the secure mode to process the first information. Optionally, the first information may include sensitive information such as username, key, user data, system critical data, etc., and this embodiment is not limited thereto.
[0083] In a possible design, after the second processing core switches to the secure mode, Figure 2 the secure data processing method shown in may further include: S206, the second processing core enters the second low-power state in the secure mode, or the second processing core processes the second information in the secure mode. Wherein, the second information may include sensitive information such as username, key, user data, system critical data, etc., and the power consumption of the second processing core in the second low-power state is lower than that in the normal working state of the second processing core. It should be noted that the second information may be the same as the first information or different from the first information.
[0084] Taking the second information being the same as the first information as an example, after the second processing core switches to the secure mode, the second processing core can be merged with the first processing core into a single core to process the second information. This single core has higher performance than the first processing core, can improve the secure data processing efficiency, and further improve the system performance. In this scheme, the second information may be the same as the first information, that is, the merged single core is used to process the first information.
[0085] Taking the second information being different from the first information as an example, if the second processing core needs to enter the secure mode to process the second information it needs to process, after the second processing core switches to the secure mode, it can process the second information it needs to process.
[0086] Further, after the above S205, the first processing core switches from the normal mode to the secure mode to process the first information, Figure 2The security data processing method shown may further include the following S207 to S210. S207, the first processing core exits the security mode. That is, after the first processing core finishes processing the first information in the security mode, it exits the security mode and returns to the normal mode.
[0087] S208, the first processing core triggers the second processing core to resume executing the second thread. Optionally, in S208, before the first processing core triggers the second processing core to resume executing the second thread, the first processing core may trigger the second processing core to exit the security mode or the first low-power state in the normal mode.
[0088] It should be noted that the first processing core may first exit the security mode and then trigger the second processing core to exit the security mode or the first low-power state in the normal mode. Or, the first processing core may first trigger the second processing core to exit the security mode or the first low-power state in the normal mode and then exit the security mode. This application does not limit this.
[0089] S209, the first processing core resumes executing the first thread. It should be noted that the first processing core may first trigger the second processing core to resume executing the second thread and then resume executing the first thread. Or, the first processing core may first resume executing the first thread and then trigger the second processing core to resume executing the second thread. This application does not limit the order of the first processing core triggering the second processing core to resume executing the second thread and resuming executing the first thread.
[0090] S210, the second processing core resumes executing the second thread according to the trigger of the first processing core. That is, after the first processing core finishes processing the first information in the security mode, it may exit the security mode, continue to execute the first thread in the normal mode, and trigger the second processing core to resume executing the second thread, continuing to utilize the system multi-threading advantage.
[0091] In a possible design, before the first processing core exits the security mode in the above S207, Figure 2 the security data processing method shown may further include: the first processing core clears the traces of processing the first information in the security mode. In this way, after the first processing core finishes processing the first information, it can clear the usage traces remaining in the shared hardware resources during the processing of the first information in the security mode. For example, the traces may include caches, page table caches, or translation lookaside buffers occupied by the processed information. The clearing actions include operations such as random number overwriting and formatting, which can further improve system security.
[0092] In a possible design, before the second processing core exits the security mode, Figure 2The secure data processing method shown in may further include: the second processing core clears the traces of processing the second information in the secure mode. That is to say, if the second processing core processes the second information in the secure mode, before the second processing core exits the secure mode, the second processing core may clear the usage traces left in the shared hardware resources by processing the second information in the secure mode. For example, the clearing actions include operations such as random number overwriting and formatting, further improving the system security.
[0093] The above Figure 2 Taking the interaction between components at the hardware layer as an example, the secure data processing method provided in the embodiments of the present application is described in detail. Next, taking the interaction between the hardware layer and the software layer as an example, the secure data processing method provided in the embodiments of the present application is described in detail.
[0094] Figure 4 Flow schematic of the secure data processing method provided in the embodiments of the present application Figure 2 . The secure data processing method can be applicable to Figure 1 the interaction shown in between the hardware layer and the software layer and between each module in the software layer. As Figure 4 shown, the secure data processing method includes the following steps: S401, the first processing core executes the first thread, and the second processing core executes the second thread. That is to say, the first processing core executes the first thread in the normal mode, and the second processing core executes the second thread in the normal mode.
[0095] Optionally, the normal mode may be Figure 1 the REE environment shown in . The normal mode may also be referred to as the non-secure mode. The REE environment is a general operating environment, and the processing core may execute the corresponding thread in the REE environment. Optionally, the first processing core and the second processing core may be physical cores or logical cores. The specific implementation manners of the physical core and the logical core may refer to the above S201 and will not be elaborated here.
[0096] S402, the first processing core executes a switching instruction to call the active processing core scheduling module. Optionally, the switching instruction may be an SMC instruction. That is to say, the first processing core executes the SMC instruction to execute the code of the active processing core scheduling module, so that the active processing core scheduling module schedules the first processing core to switch to the secure mode to process the first information. Optionally, the secure mode may be Figure 1 the TEE environment shown in , and fingerprint verification, identity authentication, etc. can be performed in the TEE environment.
[0097] In S403, the first processing core executes the code of the active processing core scheduling module and sends a first indication message to invoke the security processing core synchronization control module. Optionally, the control circuit may include: a security mode synchronization module or an interrupt controller. The specific implementation manners of the control circuit, the first indication message, and the second indication message may refer to the above S203 and will not be elaborated herein. In a possible design solution, the first processing core may include a first synchronization circuit, and the second processing core may include a second synchronization circuit.
[0098] For the above S403, where the first processing core executes the code of the active processing core scheduling module and sends a first indication message to invoke the security processing core synchronization control module, it may include the following steps twenty-two to twenty-three. Step twenty-two, the first processing core executes the code of the active processing core scheduling module, triggering the first synchronization circuit to send a first indication message to invoke the security processing core synchronization control module. Step twenty-three, the security processing core synchronization control module triggers the security mode synchronization module at the hardware layer to send a second indication message to the second synchronization circuit of the second processing core. Among them, the second indication message may be a synchronization signal.
[0099] It should be noted that Figure 4 The security data processing method shown is applicable to both the scenario of synchronously switching to the security mode and the scenario of asynchronously switching to the security mode with the support of the security mode synchronization module at the hardware layer. Furthermore, it can protect the TEE environment of TrustZone technology and Intel SGX technology, reducing the attack risk.
[0100] In another possible design solution, for the above S403, where the first processing core executes the code of the active processing core scheduling module and sends a first indication message to invoke the security processing core synchronization control module, it may include the following steps twenty-four to twenty-five. Step twenty-four, the first processing core executes the code of the active processing core scheduling module and sends a first indication message to invoke the security processing core synchronization control module. Step twenty-five, the security processing core synchronization control module triggers the interrupt controller to send a second indication message to the second processing core. Among them, the second indication message may be a security interrupt.
[0101] It should be noted that Figure 4 The security data processing method shown is applicable to the scenario of asynchronously switching to the security mode with the support of the interrupt controller at the hardware layer, can protect the TEE environment of TrustZone technology, and reduce the attack risk.
[0102] S404. The control circuit sends second indication information to the second processing core. In a possible design, the second processing core may include a second synchronization circuit. The step S404 where the control circuit sends second indication information to the operating second processing core may include: The security processing core synchronization control module triggers the security mode synchronization module at the hardware layer to send the second indication information to the second synchronization circuit of the second processing core. The second indication information may be a synchronization signal.
[0103] In another possible design, the second processing core does not include a second synchronization circuit. The step S404 where the control circuit sends second indication information to the operating second processing core may include: The security processing core synchronization control module triggers the interrupt controller to send the second indication information to the second processing core. The second indication information may be a security interrupt.
[0104] S405. The second processing core suspends the execution of the second thread and executes the code of the idle processing core scheduling module. In a possible design, the second processing core includes a second synchronization circuit. The step S405 where the second processing core suspends the execution of the second thread and executes the code of the idle processing core scheduling module may include: The second processing core suspends the execution of the second thread and executes the code of the idle processing core scheduling module according to the second indication information received by the second synchronization circuit, so as to schedule the second processing core to switch to the security mode.
[0105] In another possible design, the second processing core does not include a second synchronization circuit. The step S405 where the second processing core suspends the execution of the second thread and executes the code of the idle processing core scheduling module may include: The second processing core suspends the execution of the second thread and executes the code of the idle processing core scheduling module to schedule the second processing core to switch to the security mode.
[0106] S406. The second processing core switches to the security mode according to the scheduling of the idle processing core scheduling module. S407. The idle processing core scheduling module sends third indication information to call the security processing core synchronization control module.
[0107] Optionally, the third indication information may be used to indicate that the second processing core has switched to the security mode. That is to say, notify the control circuit that the second processing core has switched to the security mode, and trigger the control circuit to call the active processing core scheduling module to schedule the first processing core to switch to the security mode.
[0108] S408. The control circuit responds to the third indication information and sends fourth indication information to call the active processing core scheduling module. Optionally, the fourth indication information may be used to indicate that the second processing core has switched to the security mode, or to indicate that the active processing core scheduling module schedules the first processing core to switch from the normal mode to the security mode to process the first information.
[0109] S409. The first processing core switches from the normal mode to the secure mode according to the scheduling of the active processing core scheduling module to process the first piece of information. Optionally, for the specific implementation of the first piece of information, reference may be made to S205 above, which will not be elaborated here.
[0110] S410. The second processing core enters the second low-power state in the secure mode or processes the second piece of information according to the scheduling of the idle processing core scheduling module. Optionally, for the specific implementation of the second piece of information, reference may be made to S205 above, which will not be elaborated here.
[0111] S411. The first processing core sends the fifth indication information to invoke the secure processing core synchronization control module. The fifth indication information can be used to indicate that the first processing core has completed processing the first piece of information. That is to say, the first processing core sends the fifth indication information to invoke the secure processing core synchronization control module, triggering the first processing core to invoke the active processing core scheduling module and triggering the second processing core to invoke the idle processing core scheduling module.
[0112] Optionally, before the first processing core sends the fifth indication information to invoke the secure processing core synchronization control module in S411 above, the first processing core can clear the traces of processing the first piece of information in the secure mode to further improve data security.
[0113] S412. In response to the fifth indication information, the control circuit sends the sixth indication information to invoke the active processing core scheduling module and sends the seventh indication information to invoke the idle processing core scheduling module. Optionally, the sixth indication information can be used to indicate triggering the first processing core to resume executing the first thread, and the seventh indication information can be used to indicate triggering the second processing core to resume executing the second thread. That is to say, it indicates that the first processing core and the second processing core resume executing their respective corresponding threads to continue leveraging the multi-thread advantage of the system.
[0114] S413. The first processing core exits the secure mode according to the scheduling of the active processing core scheduling module and resumes executing the first thread, and the second processing core exits the secure mode according to the scheduling of the idle processing core scheduling module and resumes executing the second thread. Optionally, before the second processing core exits the secure mode according to the scheduling of the idle processing core scheduling module and resumes executing the second thread in S413 above, the second processing core can clear the traces of processing the second piece of information in the secure mode to further improve data security.
[0115] Figure 5 is the flowchart of the secure data processing method provided by the embodiment of the present application Figure 3 . This secure data processing method can be applicable to Figure 1 the interaction between the first processing core, the second processing core, the interrupt controller and the software layer shown in the figure. The second indication information is a non-secure interrupt. As Figure 5As shown, the security data processing method includes the following steps: S501, the first processing core executes the first thread, and the second processing core executes the second thread. That is to say, the first processing core executes the first thread in the normal mode, and the second processing core executes the second thread in the normal mode. Optionally, the normal mode can be the Figure 1 REE environment shown in Figure 1 . The normal mode can also be referred to as the non-secure mode. The REE environment is a general running environment, and the processing core can execute the corresponding thread in the REE environment. Optionally, the first processing core and the second processing core can be physical cores or logical cores. The specific implementation manners of the physical core and the logical core can refer to the above S201, which will not be elaborated here.
[0116] S502, the first processing core executes a switching instruction to call the active processing core scheduling module. Optionally, the switching instruction can be an SMC instruction. That is to say, the first processing core executes the SMC instruction to execute the code of the active processing core scheduling module, so that the active processing core scheduling module schedules the first processing core to switch to the secure mode to process the first information. Optionally, the secure mode can be the Figure 1 TEE environment shown in Figure 1 , where fingerprint verification, authentication, etc. can be performed in the TEE environment.
[0117] S503, the first processing core executes the code of the active processing core scheduling module and sends a first indication message to call the secure processing core synchronization control module. In a possible design solution, for the above S503, where the first processing core executes the code of the active processing core scheduling module and sends a first indication message to call the secure processing core synchronization control module, it can include the following steps twenty-six to twenty-seven. Step twenty-six, the first processing core executes the code of the active processing core scheduling module and sends a first indication message to call the secure processing core synchronization control module. Step twenty-seven, the secure processing core synchronization control module triggers the interrupt controller to send a second indication message to the second processing core. Among them, the second indication message can be a non-secure interrupt. Optionally, the non-secure interrupt can be used to indicate that the second processing core enters the first low-power state in the normal mode.
[0118] It should be noted that Figure 5 the security data processing method shown in Figure 5 , with the support of the interrupt controller at the hardware layer, is applicable to the scenario of asynchronously switching to the secure mode, can protect the TEE environment of the TrustZone technology, and reduce the attack risk.
[0119] S504, the interrupt controller sends second indication information to the second processing core. It should be noted that different from S404 above where the control circuit sends second indication information to the second processing core and when the control circuit is the interrupt controller, the second indication information is a secure interrupt, in S504 the second indication information is a non-secure interrupt. Among them, a secure interrupt is non-maskable in normal mode, and a non-secure interrupt is maskable in normal mode.
[0120] S505, the second processing core suspends the execution of the second thread and enters the first low-power state in normal mode. In this way, the second processing core suspends the execution of the second thread and enters the first low-power state in normal mode, which can eliminate the attack risk brought by the second processing core when the first processing core processes the first information in secure mode, thereby improving system security.
[0121] S506, the interrupt controller sends eighth indication information to invoke the active processing core scheduling module. Optionally, the eighth indication information can be used to indicate that the second processing core has entered the first low-power state in normal mode. That is to say, the interrupt controller sends the eighth indication information to trigger the interrupt controller to invoke the active processing core scheduling module to schedule the first processing core to switch to secure mode.
[0122] S507, the first processing core switches from normal mode to secure mode to process the first information according to the scheduling of the active processing core scheduling module. Optionally, the specific implementation manner of the first information can refer to S205 above and will not be elaborated here.
[0123] S508, the first processing core sends ninth indication information to invoke the secure processing core synchronization control module. Among them, the ninth indication information can be used to indicate that the first processing core has processed the first information. That is to say, the first processing core can send the ninth indication information to invoke the secure processing core synchronization control module to trigger the interrupt controller to invoke the active processing core scheduling module.
[0124] Optionally, before the first processing core sends the ninth indication information to invoke the secure processing core synchronization control module in S508 above, the first processing core can clear the traces of processing the first information in secure mode to further improve data security.
[0125] S509, the interrupt controller in response to the ninth indication information sends tenth indication information to invoke the active processing core scheduling module. Optionally, the tenth indication information can be used to indicate triggering the first processing core to resume the execution of the first thread.
[0126] S510, the first processing core exits the secure mode according to the scheduling of the active processing core scheduling module and resumes the execution of the first thread. The second processing core exits the first low-power state according to the scheduling of the secure processing core synchronization control module and resumes the execution of the second thread. In this way, after the first processing core finishes processing the first information in the secure mode, the first processing core and the second processing core resume the execution of their respective corresponding threads and continue to leverage the system's multi-threaded advantages.
[0127] Based on Figure 2 , Figure 4 , Figure 5 For the secure data processing method described in any one of the above, when the processing core does not need to switch to the secure mode to process information, each processing core executes its corresponding thread in the normal mode, leveraging the multi-threaded advantage to improve system performance. When one of the processing cores needs to switch to the secure mode, it instructs the other processing cores to suspend the execution of their corresponding threads. For example, if the first processing core needs to switch to the secure mode, it instructs the second processing core to suspend the execution of the second thread. This can eliminate the risk that other processing cores maliciously exploit the shared resource race condition to launch attacks when one processing core processes the first information in the secure mode, thereby improving system security. In addition, this solution does not require completely turning off the SMT function, improving system performance.
[0128] The above has Figures 2 - 5 detailed the secure data processing method provided by the embodiments of the present application. The following will Figures 6 - 7 detail the secure data processing device provided by the embodiments of the present application.
[0129] Figure 6 is the structural schematic Figure 2 of the secure data processing device provided by the embodiments of the present application. This secure data processing device can be applied to Figure 1 the secure data processing system shown in Figure 2 , Figures 4 - 5 and execute any one of the secure data processing methods shown in Figure 6 . For the sake of simplicity,
[0130] As Figure 6 shown, the secure data processing device 600 includes a first processing core 601 and a second processing core 602. Among them, the first processing core 601 is used to execute the first thread in the normal mode. The second processing core 602 is used to execute the second thread in the normal mode. The first processing core 601 is further used to suspend the execution of the first thread when it needs to switch to the secure mode. The first processing core 601 is further used to instruct the second processing core 602 to suspend the execution of the second thread. The second processing core 602 is further used to suspend the execution of the second thread according to the instruction of the first processing core 601. The first processing core 601 is further used to switch from the normal mode to the secure mode to process the first information.
[0131] In a possible design, the secure data processing device 600 may further include a control circuit 603. Among them, the first processing core 601 is further configured to send first indication information to the control circuit 603. The control circuit 603 is configured to send second indication information to the second processing core 602 in response to the first indication information, and the second indication information is used to instruct the second processing core 602 to suspend the execution of the second thread. Optionally, the control circuit 603 includes: a secure mode synchronization module or an interrupt controller ( Figure 6 not shown in the figure).
[0132] In a possible design, the second processing core 602 is further configured to switch to the secure mode after suspending the execution of the second thread according to the indication of the first processing core 601, or enter the first low-power state in the normal mode. In a possible design, the second processing core 602 is further configured to enter the second low-power state in the secure mode, or process the second information in the secure mode after the second processing core 602 switches to the secure mode.
[0133] In a possible design, the first processing core 601 is further configured to exit the secure mode after switching from the normal mode to the secure mode to process the first information. The first processing core 601 is further configured to trigger the second processing core 602 to resume the execution of the second thread. The first processing core 601 is further configured to resume the execution of the first thread. The second processing core 602 is further configured to resume the execution of the second thread according to the trigger of the first processing core 601.
[0134] In a possible design, the first processing core 601 is further configured to clear the traces of processing the first information in the secure mode before exiting the secure mode. Similarly, if the second processing core 602 processes the second information in the secure mode, the second processing core 602 is further configured to clear the usage traces of processing the second information remaining in the shared hardware resources before exiting the secure mode, so as to improve the system security.
[0135] Optionally, the first processing core 601 and the second processing core 602 may be physical cores or logical cores. It should be noted that the secure data processing device 600 may be a processor. In addition, the technical effects of the secure data processing device 600 may refer to Figure 2 , Figures 4 - 5 the technical effects of the secure data processing method described in any one of the implementation manners, which will not be elaborated here.
[0136] Figure 7 is a schematic structural diagram of the secure data processing device provided by the embodiment of the present application Figure 3 . This secure data processing device can be applied to Figure 1 the secure data processing system shown in Figure 2 ,Figures 4 - 5 The security data processing method shown in any one of Figure 7 For the sake of convenience of description, only the main components of the security data processing device are shown.
[0137] As Figure 7 shown, the security data processing device 700 includes a first processing module 701 and a second processing module 702. Among them, the first processing module 701 is used to implement the functions of the first processing core involved in the above method embodiments, and the second processing module 702 is used to implement the functions of the second processing core involved in the above method embodiments.
[0138] In a possible design, the security data processing device 700 may further include a control module 703. Among them, the control module 703 can be used to implement the functions of the control circuit involved in the above method embodiments.
[0139] Optionally, the security data processing device 700 may further include a storage module ( Figure 7 not shown in the figure), the storage module may be a memory, and the storage module can be used to store program instructions and data for implementing the functions involved in the above method embodiments. When the first processing module 701, the second processing module 702, and the control module 703 execute the program or instructions, the security data processing device 700 can execute Figure 2 , Figures 4 - 5 the security data processing method shown in any one of
[0140] Optionally, the security data processing device 700 may further include a transceiver module ( Figure 7 not shown in the figure). The transceiver module may be a transceiver circuit or an input / output port, and the transceiver module can be used to implement the transceiver functions involved in the above method embodiments. The transceiver module may include a receiving module and a sending module. The specific implementation manner of the transceiver module in this application is not specifically limited.
[0141] It should be noted that the security data processing device 700 may be a processor. One or more of the above modules may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions. When any of the above modules is implemented by software, the software exists in the form of computer program instructions and is stored in the memory. In addition, the technical effects of the security data processing device 700 can refer to Figure 2 , Figures 4 - 5 the technical effects of the security data processing method described in any one of the implementation manners, and will not be elaborated here.
[0142] The embodiments of this application provide a security data processing system, and the security data processing system includes the security data processing device described above.
[0143] An embodiment of the present application provides a computer-readable storage medium, which includes a computer program or instruction; when the computer program or instruction runs on a computer, the computer is caused to execute the security data processing method described in the foregoing method embodiment, and the computer includes a first processing core and a second processing core.
[0144] An embodiment of the present application provides a computer program product, including a computer program or instruction, when the computer program or instruction runs on a computer, the computer is caused to execute the security data processing method described in the foregoing method embodiment, and the computer includes a first processing core and a second processing core.
[0145] It should be understood that the processor designed in the embodiment of the present application may be the central processing unit (CPU) mentioned in the previous embodiment, or the processor may also be other general-purpose processors, digital signal processors (DSPs), processors in application specific integrated circuits (ASICs), processors in field programmable gate arrays (FPGAs). The processor may further include other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The previous embodiment mainly takes the CPU as an example for introduction, but is not used to limit the present solution.
[0146] It should also be understood that the memory in the embodiments of the present application may be a volatile memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0147] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more collections of available media. The available media may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium may be a solid-state drive.
[0148] It should be understood that the term "and / or" in this text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this text generally represents an "or" relationship between the preceding and following associated objects, but it may also represent an "and / or" relationship, and specific understanding can be made by referring to the context before and after.
[0149] It should be understood that in various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not imply the sequence of execution. The execution sequence of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0150] Those of ordinary skill in the art can realize that the units or modules and algorithm steps of each example described in combination with the embodiments disclosed in this text can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0151] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units or modules described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0152] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above division of units or modules is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or modules can be combined or integrated into another system, or some units or modules can be omitted, or their corresponding functions are not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or units / modules can be in an electrical, mechanical, or other form.
[0153] The units / modules described as separate components may or may not be physically separated. The components displayed as units / modules may or may not be physical units / modules, that is, they can be located in one place, or they can be distributed to multiple network units / modules. Some or all of the units / modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0154] In addition, in each embodiment of the present application, each functional unit / module can be integrated into one processing unit / module, or each unit / module can exist physically alone, or two or more units / modules can be integrated into one unit / module.
[0155] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A secure data processing method, characterized in that, The method includes: The first processing core executes a first thread in the normal mode; The second processing core executes a second thread in the normal mode; When the first processing core needs to switch to the secure mode, it pauses the execution of the first thread; The first processing core instructs the second processing core to pause the execution of the second thread; The second processing core pauses the execution of the second thread according to the instruction of the first processing core; The first processing core switches from the normal mode to the secure mode to process first information; Wherein, the first processing core and the second processing core are included in the hardware layer.
2. The secure data processing method according to claim 1, wherein The first processing core instructing the second processing core to pause the execution of the second thread includes: The first processing core sends first instruction information to the control circuit; The control circuit sends second instruction information to the second processing core in response to the first instruction information, and the second instruction information is used to instruct the second processing core to pause the execution of the second thread.
3. The security data processing method according to claim 2, wherein The control circuit includes: a secure mode synchronization module or an interrupt controller.
4. The security data processing method according to any one of claims 1-3, characterized in that, After the second processing core pauses the execution of the second thread according to the instruction of the first processing core, the method further includes: The second processing core switches to the secure mode, or enters a first low-power state in the normal mode.
5. The security data processing method according to claim 4, wherein, After the second processing core switches to the secure mode, the method further includes: The second processing core enters a second low-power state in the secure mode, or processes second information in the secure mode.
6. The security data processing method according to any one of claims 1-3, characterized in that, After the first processing core switches from the normal mode to the secure mode to process first information, the method further includes: The first processing core exits the secure mode; The first processing core triggers the second processing core to resume the execution of the second thread; The first processing core resumes the execution of the first thread; The second processing core resumes the execution of the second thread according to the trigger of the first processing core.
7. The security data processing method according to claim 6, wherein Before the first processing core exits the secure mode, the method further includes: The first processing core clears the traces of processing first information in the secure mode.
8. The secure data processing method according to any one of claims 1-3, characterized in that, The first processing core and the second processing core are physical cores or logical cores.
9. A secure data processing device, characterized in that, The secure data processing device includes a first processing core and a second processing core, wherein, The first processing core is used to execute a first thread in the normal mode, pause the execution of the first thread when it needs to switch to the secure mode, instruct the second processing core to pause the execution of the second thread, and switch from the normal mode to the secure mode to process first information; The second processing core is used to execute the second thread in the normal mode and pause the execution of the second thread according to the instruction of the first processing core; wherein, the first processing core and the second processing core are included in the hardware layer.
10. The secure data processing device according to claim 9, wherein, The secure data processing device further includes a control circuit, wherein, the first processing core is further used to send first instruction information to the control circuit; The control circuit is used to send second instruction information to the second processing core in response to the first instruction information, and the second instruction information is used to instruct the second processing core to pause the execution of the second thread.
11. The secure data processing device according to claim 10, wherein The control circuit includes: a security mode synchronization module or an interrupt controller.
12. The secure data processing device according to any one of claims 9-11, characterized in that the second processing core is further configured to switch to the security mode after pausing the execution of the second thread according to the instruction of the first processing core, or enter a first low-power state in the normal mode.
13. The secure data processing device according to claim 12, characterized in that the second processing core is further configured to enter a second low-power state in the security mode or process second information in the security mode after the second processing core switches to the security mode.
14. The secure data processing device according to any one of claims 9-11, characterized in that the first processing core is further configured to: after switching from the normal mode to the security mode to process first information, exit the security mode, trigger the second processing core to resume executing the second thread, and resume executing the first thread; the second processing core is further configured to resume executing the second thread according to the trigger of the first processing core.
15. The secure data processing device according to claim 14, characterized in that the first processing core is further configured to clear the traces of processing first information in the security mode before exiting the security mode.
16. The secure data processing device according to any one of claims 9-11, characterized in that The first processing core and the second processing core are physical cores or logical cores.
17. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a computer program or instruction, which, when running on a computer, causes the computer to execute the secure data processing method according to any one of claims 1-8, and the computer includes the first processing core and the second processing core.
18. A computer program product, characterized in that, The computer program product includes: a computer program or instruction, which, when running on a computer, causes the computer to execute the secure data processing method according to any one of claims 1-8, and the computer includes the first processing core and the second processing core.
Citation Information
Patent Citations
Trusted execution environment cache isolation method and device, electronic equipment and storage medium
CN109947666A