A method, device and storage medium for protecting the integrity of a virtual machine nested page table
By using the hash computing engine to generate message authentication codes and verify their consistency in the memory controller MMU, the problem of insufficient security of virtual machine nested page tables is solved, and effective integrity protection of virtual machine nested page tables is achieved.
Patent Information
- Application Number
- CN202211608740.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-12-14
AI Technical Summary
Existing virtual machine technology cannot effectively ensure the security of virtual machine nested page tables, and malicious virtual machine managers can still tamper with nested page tables.
By implementing the virtual machine nested page table integrity protection method in the memory controller MMU, the hash computing engine is used to generate message authentication code, write data and message authentication code into the memory space, and verify the consistency of message authentication code when reading data to ensure the integrity of the nested page table.
It effectively ensures the security and integrity of the virtual machine's nested page table, prevents malicious tampering, and enhances the virtual machine's ability to isolate the host and other virtual machine memory.
Smart Images

Figure CN116360916B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method, device, storage medium and electronic device for protecting the integrity of a virtual machine nested page table. Background Art
[0002] Virtual machines have the advantages of resource isolation and fast deployment. With the development of cloud technology, most service programs run in virtual machines in the cloud. As the carrier of user data, the data security of virtual machines is increasingly valued.
[0003] In the existing virtual machine technology, the nested page table is used to isolate the memory of virtual machines and the memory of the host, effectively preventing the virtual machine from arbitrarily accessing the memory of the host or other virtual machines. However, a malicious virtual machine manager (VMM) can still tamper with the nested page table, so the security of the virtual machine nested page table cannot be ensured. Summary of the invention
[0004] In view of this, an embodiment of the present invention provides a method, device, storage medium and electronic device for protecting the integrity of a virtual machine nested page table, which can ensure the security of the virtual machine nested page table.
[0005] In a first aspect, an embodiment of the present invention provides a method for protecting the integrity of a virtual machine nested page table, which is applied to a memory controller MMU, and the method includes: receiving a data write request sent by a processor core; the data write request includes data to be written, a first virtual machine physical address GPA to which the data to be written is to be written, and a first address space identifier; wherein the first virtual machine physical address GPA is the virtual machine physical address GPA to be accessed by the data to be written, and the first address space identifier is the address space identifier of the virtual machine to which the data is to be written; sending the data to be written, the first virtual machine physical address GPA, and the first address space identifier to a hash calculation engine, so that the hash calculation engine calculates a first message authentication code according to the data to be written, the first virtual machine physical address GPA, and the first address space identifier; determining the first host physical address HPA to which the data to be written is to be written according to the first virtual machine physical address GPA and the nested page table; writing the data to be written and the first message authentication code into the memory space corresponding to the first host physical address HPA.
[0006] Optionally, after writing the data to be written and the first message authentication code into the memory space corresponding to the first host physical address HPA, the method further includes: receiving a data read request sent by a processor core; the data read request includes a second virtual machine physical address GPA and a second address space identifier; wherein the second virtual machine physical address GPA is the virtual machine physical address GPA to be accessed by the data to be read, and the second address space identifier is the address space identifier of the virtual machine from which the data is to be read; determining the second host physical address HPA of the data to be read according to the second virtual machine physical address GPA and the nested page table; reading data from the memory space corresponding to the second host physical address HPA; sending the read data, the second virtual machine physical address GPA and the second address space identifier to the hash calculation engine, so that the hash calculation engine calculates the second message authentication code according to the read data, the second virtual machine physical address GPA and the second address space identifier; comparing whether the second message authentication code is consistent with the first message authentication code; if the two are inconsistent, determining that the nested page table integrity check has failed.
[0007] Optionally, determining the first host physical address HPA to which the data to be written is to be written based on the first virtual machine physical address GPA and the nested page table includes: determining whether a specified bit of the page table entry in the nested page table where the first virtual machine physical address GPA is located is set based on the first virtual machine physical address GPA; if the specified bit of the page table entry in the nested page table where the first virtual machine physical address GPA is located is set, a page fault exception is triggered.
[0008] Optionally, if the designated bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set, then after triggering the page fault exception, the method further includes: if the page fault exception is triggered for the first time, clearing the designated bit through the first dedicated instruction of the nested page table.
[0009] Optionally, after the designated bit is cleared to zero through the first dedicated instruction of the nested page table, the method further includes: if the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located is modified, then the designated bit is reset through the second dedicated instruction of the nested page table.
[0010] Optionally, if the designated bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set, then after triggering a page fault exception, the method further includes: if the page fault exception is not triggered for the first time, determining that the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located in the nested page table is abnormally modified.
[0011] Optionally, determining the first host physical address HPA to which the data to be written is to be written based on the first virtual machine physical address GPA and the nested page table includes: detecting whether the memory area where the non-last level page table of the nested page table is located belongs to the safe nested page table memory range; if the memory area where the non-last level page table of the nested page table is located does not belong to the safe nested page table memory range, a nested page fault exception is triggered.
[0012] In a second aspect, an embodiment of the present invention provides a virtual machine nested page table integrity protection device, which is arranged in a memory controller MMU, and the device includes: a first receiving module, used to receive a data write request sent by a processor core; the data write request includes data to be written, a first virtual machine physical address GPA to which the data to be written is to be written, and a first address space identifier; wherein the first virtual machine physical address GPA is the virtual machine physical address GPA to be accessed by the data to be written, and the first address space identifier is the address space identifier of the virtual machine to which the data is to be written; a first sending module, used to send the data to be written, the first virtual machine physical address GPA and the first address space identifier to a hash calculation engine, so that the hash calculation engine calculates a first message authentication code according to the data to be written, the first virtual machine physical address GPA and the first address space identifier; a first determining module, used to determine the first host physical address HPA to which the data to be written is to be written according to the first virtual machine physical address GPA and the nested page table; a writing module, writing the data to be written and the first message authentication code into the memory space corresponding to the first host physical address HPA.
[0013] Optionally, the device also includes: a second receiving module, used to receive a data read request sent by the processor core; the data read request includes a second virtual machine physical address GPA and a second address space identifier; wherein the second virtual machine physical address GPA is the virtual machine physical address GPA to be accessed by the data to be read, and the second address space identifier is the address space identifier of the virtual machine to read the data; a second determination module, used to determine the second host physical address HPA of the data to be read according to the second virtual machine physical address GPA and the nested page table; a reading module, used to read data from the memory space corresponding to the second host physical address HPA; a second sending module, used to send the read data, the second virtual machine physical address GPA and the second address space identifier to the hash calculation engine, so that the hash calculation engine calculates the second message authentication code according to the read data, the second virtual machine physical address GPA and the second address space identifier; a comparison module, used to compare whether the second message authentication code is consistent with the first message authentication code; if the two are inconsistent, it is determined that the nested page table integrity check has failed.
[0014] Optionally, the first determination module includes: a determination unit, used to determine whether a specified bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table is set according to the first virtual machine physical address GPA; and a trigger unit, used to trigger a page fault exception if the specified bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table is set.
[0015] Optionally, the device further includes: a clearing module, configured to clear the designated bit to zero by using a first dedicated instruction of the nested page table if the page fault exception is triggered for the first time.
[0016] Optionally, the device also includes: a resetting module, which is used to reset the designated bit through a second dedicated instruction of the nested page table if the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located is modified.
[0017] Optionally, the device also includes: a first trigger module, used to determine that the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located in the nested page table is abnormally modified if the page fault exception is not triggered for the first time.
[0018] Optionally, the device also includes: a detection module, used to detect whether the memory area where the non-last-level page table of the nested page table is located belongs to the safe nested page table memory range; a second trigger module, used to trigger a nested page fault exception if the memory area where the non-last-level page table of the nested page table is located does not belong to the safe nested page table memory range.
[0019] In a third aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement any virtual machine nested page table integrity protection method provided by an embodiment of the present invention.
[0020] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement any of the aforementioned virtual machine nested page table integrity protection methods.
[0021] The virtual machine nested page table integrity protection method, device, storage medium and electronic device provided by the embodiment of the present invention can generate a first message authentication code according to the data to be written, the first virtual machine physical address GPA and the first address space identifier. Then the data to be written and the first message authentication code are written into the memory space corresponding to the first host physical address, which can facilitate the subsequent process to verify whether the nested page table has been tampered with through the first message authentication code, thereby ensuring the integrity of the virtual machine nested page table. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0023] Figure 1 A schematic diagram of a flow chart of a method for protecting the integrity of a nested page table of a virtual machine provided by an embodiment of the present invention;
[0024] Figure 2 A schematic flow chart of another method for protecting the integrity of a nested page table of a virtual machine provided by an embodiment of the present invention;
[0025] Figure 3 A schematic diagram of the structure of a virtual machine nested page table integrity protection device provided by an embodiment of the present invention;
[0026] Figure 4A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0027] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0028] It should be clear that the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0029] In a first aspect, an embodiment of the present invention provides a method for protecting the integrity of a virtual machine nested page table, which is applied to a memory controller. The method may include:
[0030] S11, receiving a data write request sent by the processor core; the data write request includes the data to be written, the first virtual machine physical address (Guest Physical Address, GPA) to which the data to be written is to be written, and the first address space identifier; wherein, the first virtual machine physical address GPA is the virtual machine physical address GPA to be accessed by the data to be written, and the first address space identifier is the address space identifier of the virtual machine to which the data is to be written.
[0031] Specifically, the memory controller is a bus circuit controller used to manage and plan the transmission speed from the memory to the CPU. It can be a separate chip or integrated into the chip. After receiving the data write request sent by the processor core, the memory controller can parse the data to be written, the first virtual machine physical address GPA to which the data to be written is to be written, and the first address space identifier from the data write request. The first address space identifier can be an address space ID (Address Space Identifier, ASID), and different address space IDs can represent the address space of different virtual machines.
[0032] S12, sending the data to be written, the first virtual machine physical address GPA and the first address space identifier to a hash calculation engine, so that the hash calculation engine calculates a first message authentication code according to the data to be written, the first virtual machine physical address GPA and the first address space identifier.
[0033] The message authentication code is a verification mechanism used by both parties of the communication entity, and is a tool to ensure the integrity of the message data. The memory controller can send the data to be written, the first virtual machine physical address GPA and the first address space identifier to the hash calculation engine, and the hash calculation engine can perform a hash operation on the above data to obtain the corresponding message authentication code (i.e., the first message authentication code).
[0034] S13, determining a first host physical address (Host Physical Address, HPA) into which the to-be-written data is to be written according to the first virtual machine physical address GPA and the nested page table.
[0035] The nested page table reflects the correspondence between the virtual machine physical address and the host machine physical address. Therefore, the memory controller can obtain the first host machine physical address corresponding to the first virtual machine physical address by querying the nested page table.
[0036] S14, writing the data to be written and the first message authentication code into the memory space corresponding to the first host physical address HPA.
[0037] In this step, the data to be written and the first message authentication code are written together into the memory space corresponding to the physical address of the first host, so that in the subsequent process, the first message authentication code can be used to verify whether the nested page table has been tampered with, thereby ensuring the integrity of the nested page table of the virtual machine. The integrity of the nested page table refers to the accuracy and reliability of the nested page table, which is used to determine whether the nested page table has been tampered with.
[0038] Optionally, in one embodiment of the present invention, after writing the data to be written and the first message authentication code into the memory space corresponding to the first host physical address HPA (step S14), Figure 2 As shown, the method may further include the following steps:
[0039] S15, receiving a data read request sent by the processor core; the data read request includes a second virtual machine physical address GPA and a second address space identifier; wherein the second virtual machine physical address GPA is the virtual machine physical address GPA to be accessed for data to be read, and the second address space identifier is the address space identifier of the virtual machine to read data.
[0040] In this step, when the processor core needs to verify the integrity of the nested page table, it can send a data read request to the memory controller. After receiving the data read request, the memory controller can parse the second virtual machine physical address and the second address space identifier from the data read request. The second virtual machine physical address GPA represents the physical address of the virtual machine to be accessed, and the second address space identifier represents the address space identifier of the virtual machine to read data. Among them, the second virtual machine physical address is the same as the first virtual machine physical address in the previous text, and the second address space identifier is the same as the first address space identifier in the previous text.
[0041] S16, determining a second host physical address HPA of the data to be read according to the second virtual machine physical address GPA and the nested page table;
[0042] In this step, the memory controller can obtain the second host physical address corresponding to the second virtual machine physical address by searching in the nested page table. The nested page table is the same as the nested page table in the aforementioned step S13.
[0043] S17, reading data from the memory space corresponding to the second host physical address HPA;
[0044] The memory controller can address the second host physical address, and then read corresponding data from the memory space corresponding to the second host physical address.
[0045] S18, sending the read data, the second virtual machine physical address GPA and the second address space identifier to the hash calculation engine, so that the hash calculation engine calculates a second message authentication code according to the read data, the second virtual machine physical address GPA and the second address space identifier;
[0046] In this step, the memory controller may send the read data, the second virtual machine physical address and the second address space identifier to the hash calculation engine, and the hash calculation engine may calculate the second message authentication code corresponding to the above data.
[0047] In the case where the nested page table has not been tampered with, the second host physical address can be obtained according to the second virtual machine physical address, and then the memory data in the memory space corresponding to the second host physical address can be obtained. Since the second virtual machine physical address is the same as the first virtual machine physical address in the previous text, the read memory data is the same as the memory data stored in step S14 in the previous text. Furthermore, after sending the read data, the second virtual machine physical address and the second address space identifier to the hash calculation engine, the second message authentication code calculated by the hash calculation engine must be the same as the first message authentication code stored in the previous step.
[0048] On the contrary, in the case where the nested page table is tampered, the second host physical address obtained according to the second virtual machine physical address is not the same as the first virtual machine physical address in the previous text, so the read memory data is also different from the memory data stored in step S14 in the previous text. Further, after sending the read data, the third virtual machine physical address and the second address space identifier to the hash calculation engine, the second message authentication code calculated by the hash calculation engine must be different from the first message authentication code stored in the previous step.
[0049] S19, comparing the second message authentication code with the first message authentication code to see if they are consistent; if the two are inconsistent, determining that the nested page table integrity check has failed.
[0050] By comparing the second message authentication code with the first message authentication code, if the two are consistent, it can be determined that the nested page table has not been tampered with. If the two are inconsistent, it can be determined that the nested page table has been tampered with, thereby ensuring the integrity of the virtual machine's nested page table.
[0051] Optionally, in one embodiment of the present invention, determining the first host physical address HPA to which the data to be written is to be written based on the first virtual machine physical address GPA and the nested page table (step S13) may include: determining, based on the first virtual machine physical address GPA, whether a specified bit of the page table entry in the nested page table where the first virtual machine physical address GPA is located is set; if the specified bit of the page table entry in the nested page table where the first virtual machine physical address GPA is located is set, a page fault exception is triggered.
[0052] In an embodiment of the present invention, when querying the first host physical address corresponding to the first virtual machine physical address in the nested page table, the page table entry where the first virtual machine physical address is located can be first determined in the nested page table. And further, in the page table entry, it is checked whether a specified bit is set, for example, whether the value of the pending flag is 1. If the specified bit is set, a page fault exception will be triggered, so that in the subsequent process, the memory controller cannot obtain the first host physical address corresponding to the first virtual machine physical address by querying the nested page table, thereby avoiding reading erroneous data.
[0053] Optionally, in one embodiment of the present invention, if the designated bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set, then after triggering the page fault exception, the method may further include: if the page fault exception is triggered for the first time, clearing the designated bit through the first dedicated instruction of the nested page table.
[0054] In the embodiment of the present invention, when the VMM establishes the mapping relationship between each GPA and HPA in the page table entry, it triggers the processor core to set the specified bit (suspend flag bit) to 1, and this is the first time that the specified bit is set to 1. In order to allow the memory controller to write or read data to the memory normally through the nested page table in the subsequent process, the specified bit (suspend flag bit) can be set to 0 by running the first dedicated instruction (PNPT_ACCEPT instruction) of the nested page table.
[0055] Optionally, in one embodiment of the present invention, after the designated bit is cleared to zero through the first dedicated instruction of the nested page table, the method may further include: if the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located is modified, then resetting the designated bit through the second dedicated instruction of the nested page table.
[0056] In an embodiment of the present invention, if the mapping relationship between the virtual machine physical address and the host physical address in the page table entry where the physical address of the first virtual machine is located is maliciously tampered with by the VMM, it will trigger the processor core to reset the suspend flag to 1 through the second dedicated instruction (PNPT_SET instruction) of the nested page table, thereby facilitating the memory controller to trigger a page fault exception when using the nested page table in the subsequent process, thereby avoiding the memory controller using the tampered nested page table to read erroneous data from the memory.
[0057] Optionally, in one embodiment of the present invention, if the designated bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set, then after triggering a page fault exception, the method may further include: if the page fault exception is not triggered for the first time, determining that the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located in the nested page table is abnormally modified.
[0058] In the embodiment of the present invention, since the first page fault exception occurs when the VMM is in the process of establishing the nested page table, and the page fault exception can be eliminated by setting the designated bit (suspend flag bit) to 0 through the first dedicated instruction. Therefore, when the memory controller writes data or reads data through the nested page table, if it is detected that the designated bit is set, since setting the designated bit (suspend flag bit) to 1 must be triggered when the virtual machine manager maliciously tampers with the nested page table, it can be determined that the nested page table has been maliciously tampered with by the virtual machine manager.
[0059] Optionally, in one embodiment of the present invention, determining the first host physical address HPA to which the data to be written is to be written based on the first virtual machine physical address GPA and the nested page table (step S13) may include: detecting whether the memory area where the non-last-level page table of the nested page table is located belongs to the safe nested page table memory range; if the memory area where the non-last-level page table of the nested page table is located does not belong to the safe nested page table memory range, a nested page fault exception is triggered.
[0060] In order to detect whether the nested page table has been tampered with, the secure nested page table memory range can be pre-set through the Basic Input Output System (BIOS).
[0061] In one example, the start address and end address of the safe nested page table memory range can be set in registers. Only nested page table dedicated instructions are allowed to access the safe nested page table memory range, and other types of instructions are not allowed to access it.
[0062] The address pointed to by the non-last-level page table entry is the address of the page table itself. To ensure that all page table entries of the nested page table are within the safe nested page table memory range, the address pointed to by the page table other than the last-level page table can be compared with the start address and end address of the safe nested page table memory range mentioned above to determine whether the nested page table is within the safe nested page table memory range. If it is not within the safe nested page table memory range, it means that the nested page table has been tampered with. When the memory controller uses the nested page table, a page fault exception can be triggered to prevent the memory controller from obtaining incorrect data using the tampered nested page table.
[0063] In a second aspect, an embodiment of the present invention provides a virtual machine nested page table integrity protection device, which is arranged in a memory controller MMU, such as Figure 3 As shown, a virtual machine nested page table integrity protection device 1 may include: a first receiving module 11, used to receive a data write request sent by a processor core; the data write request includes data to be written, a first virtual machine physical address GPA to which the data to be written is to be written, and a first address space identifier; wherein the first virtual machine physical address GPA is a virtual machine physical address GPA to be accessed by the data to be written, and the first address space identifier is an address space identifier of the virtual machine to which the data is to be written; a first sending module 12, used to send the data to be written, the first virtual machine physical address GPA, and the first address space identifier to a hash calculation engine, so that the hash calculation engine calculates a first message authentication code according to the data to be written, the first virtual machine physical address GPA, and the first address space identifier; a first determining module 13, used to determine the first message authentication code according to the first virtual machine physical address GPA
[0064] and nested page tables to determine a first host physical address HPA to which the data to be written is to be written; a writing module 514 writes the data to be written and the first message authentication code into a memory space corresponding to the first host physical address HPA.
[0065] The virtual machine nested page table integrity protection device provided by the embodiment of the present invention can generate a first message authentication code according to the data to be written, the first virtual machine physical address GPA and the first address space identifier. Then the data to be written and the first message authentication code are written into the memory space corresponding to the first host physical address, which can facilitate the subsequent process to verify whether the nested page table has been tampered with through the first message authentication code, thereby ensuring the integrity of the virtual machine nested page table.
[0066] Optionally, in one embodiment of the present invention, the virtual machine nested page table integrity protection device 1 may also include: a second receiving module, used to receive a data read request sent by a processor core; the data read request includes a second virtual machine physical address GPA and a second address space identifier; wherein the second virtual machine physical address GPA is the virtual machine physical address GPA to be accessed by the data to be read, and the second address space identifier is the address space identifier of the virtual machine to read the data; a second determination module, used to determine the second host physical address HPA of the data to be read according to the second virtual machine physical address GPA and the nested page table; a reading module, used to read data from the memory space corresponding to the second host physical address HPA; a second sending module, used to send the read data, the second virtual machine physical address GPA and the second address space identifier to the hash calculation engine, so that the hash calculation engine calculates the second message authentication code according to the read data, the second virtual machine physical address GPA and the second address space identifier; a comparison module, used to compare whether the second message authentication code is consistent with the first message authentication code; if the two are inconsistent, it is determined that the nested page table integrity check fails.
[0067] Optionally, in one embodiment of the present invention, the first determination module 13 may include: a determination unit, used to determine whether a specified bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table is set based on the first virtual machine physical address GPA; and a trigger unit, used to trigger a page fault exception if the specified bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table is set.
[0068] Optionally, in one embodiment of the present invention, the virtual machine nested page table integrity protection device 1 may further include: a clearing module, configured to clear the designated bit to zero through a first dedicated instruction of the nested page table if the page fault exception is triggered for the first time.
[0069] Optionally, in one embodiment of the present invention, the virtual machine nested page table integrity protection device 1 may also include: a resetting module, which is used to reset the designated bit through a second dedicated instruction of the nested page table if the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located is modified.
[0070] Optionally, in one embodiment of the present invention, the virtual machine nested page table integrity protection device 1 may also include: a first trigger module, used to determine that the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located in the nested page table is abnormally modified if the page fault exception is not triggered for the first time.
[0071] Optionally, in one embodiment of the present invention, the virtual machine nested page table integrity protection device 1 may also include: a detection module, used to detect whether the memory area where the non-last-level page table of the nested page table is located belongs to the safe nested page table memory range; a second trigger module, used to trigger a nested page fault exception if the memory area where the non-last-level page table of the nested page table is located does not belong to the safe nested page table memory range.
[0072] In a third aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium has one or more programs, and the one or more programs can be executed by one or more processors to implement any of the virtual machine nested page table integrity protection methods provided in the aforementioned embodiments. The specific execution process of the processor for the above steps and the steps that the processor further executes by running the executable program code can be referred to the description of the aforementioned embodiment, which will not be repeated here.
[0073] In a fourth aspect, an embodiment of the present invention further provides an electronic device, Figure 4 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention, which can implement the present invention Figure 1 The process of the embodiment shown is as follows: Figure 4 As shown, the electronic device may include: a housing 41, a processor 42, a memory 43, a circuit board 44 and a power supply circuit 45, wherein the circuit board 44 is arranged inside the space enclosed by the housing 41, and the processor 42 and the memory 43 are arranged on the circuit board 44; the power supply circuit 45 is used to supply power to various circuits or devices of the electronic device; the memory 43 is used to store executable program codes; the processor 42 runs the program corresponding to the executable program code by reading the executable program code stored in the memory 43, so as to execute the method described in any of the aforementioned method embodiments.
[0074] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0075] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
[0076] In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0077] For the convenience of description, the above device is described by dividing the functions into various units / modules. Of course, when implementing the present invention, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.
[0078] A person skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.
[0079] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for protecting the integrity of a virtual machine nested page table. It is characterized in that Applied to a memory controller MMU, the method comprises: Receive a data write request sent by the processor core; the data write request includes data to be written, a first virtual machine physical address GPA to which the data to be written is to be written, and a first address space identifier; wherein the first virtual machine physical address GPA is a virtual machine physical address GPA to be accessed by the data to be written, and the first address space identifier is an address space identifier of the virtual machine to which the data is to be written; Sending the data to be written, the first virtual machine physical address GPA and the first address space identifier to a hash calculation engine, so that the hash calculation engine calculates a first message authentication code according to the data to be written, the first virtual machine physical address GPA and the first address space identifier; Determine, according to the first virtual machine physical address GPA and the nested page table, a first host physical address HPA into which the to-be-written data is to be written; The data to be written and the first message authentication code are written into the memory space corresponding to the first host physical address HPA.
2. The method for protecting the integrity of a virtual machine nested page table according to claim 1, It is characterized in that After writing the data to be written and the first message authentication code into the memory space corresponding to the first host physical address HPA, the method further includes: Receive a data read request sent by the processor core; the data read request includes a second virtual machine physical address GPA and a second address space identifier; wherein the second virtual machine physical address GPA is a virtual machine physical address GPA to be accessed for data to be read, and the second address space identifier is an address space identifier of the virtual machine to read data; Determine a second host physical address HPA of the data to be read according to the second virtual machine physical address GPA and the nested page table; Reading data from the memory space corresponding to the second host physical address HPA; Send the read data, the second virtual machine physical address GPA and the second address space identifier to the hash calculation engine, so that the hash calculation engine calculates a second message authentication code according to the read data, the second virtual machine physical address GPA and the second address space identifier; Compare the second message authentication code with the first message authentication code to see if they are consistent; if the two are inconsistent, determine that the nested page table integrity check fails.
3. The method for protecting the integrity of a virtual machine nested page table according to claim 1, It is characterized in that The determining, according to the first virtual machine physical address GPA and the nested page table, a first host physical address HPA to which the to-be-written data is to be written comprises: Determine, according to the first virtual machine physical address GPA, whether a designated bit of a page table entry in the nested page table where the first virtual machine physical address GPA is located is set; If the designated bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set, a page fault exception is triggered.
4. The method for protecting the integrity of virtual machine nested page tables according to claim 3, wherein, if a specified bit in the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set, after a page fault exception is triggered, the method further includes: if the page fault exception is triggered for the first time, clear the specified bit through a first special instruction of the nested page table.
5. The method for protecting the integrity of virtual machine nested page tables according to claim 4, wherein, after clearing the specified bit through the first special instruction of the nested page table, the method further includes: if the mapping relationship between the virtual machine physical address GPA in the page table entry where the first virtual machine physical address GPA is located and the host physical address HPA is modified, reset the specified bit through a second special instruction of the nested page table.
6. The method for protecting the integrity of virtual machine nested page tables according to any one of claims 4 to 5, wherein, if a specified bit in the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set, after a page fault exception is triggered, the method further includes: if the page fault exception is not triggered for the first time, determine that the mapping relationship between the virtual machine physical address GPA in the page table entry where the first virtual machine physical address GPA is located in the nested page table and the host physical address HPA has been abnormally modified.
7. The method for protecting the integrity of virtual machine nested page tables according to claim 1, wherein, the step of determining the first host physical address HPA to which the data to be written is to be written according to the first virtual machine physical address GPA and the nested page table includes: detecting whether the memory area where the non-last-level page table of the nested page table is located belongs to the secure nested page table memory range; if the memory area where the non-last-level page table of the nested page table is located does not belong to the secure nested page table memory range, trigger a nested page fault exception.
8. A device for protecting the integrity of virtual machine nested page tables, wherein, it is set in the memory controller MMU, and the device includes: a first receiving module, configured to receive a data writing request sent by a processor core; the data writing request includes data to be written, a first virtual machine physical address GPA to which the data to be written is to be written, and a first address space identifier; wherein, the first virtual machine physical address GPA is the virtual machine physical address GPA that the data to be written is to access, and the first address space identifier is the address space identifier of the virtual machine to which the data is to be written; a first sending module, configured to send the data to be written, the first virtual machine physical address GPA, and the first address space identifier to a hash calculation engine, so that the hash calculation engine calculates a first message authentication code according to the data to be written, the first virtual machine physical address GPA, and the first address space identifier; a first determining module, configured to determine a first host physical address HPA to which the data to be written is to be written according to the first virtual machine physical address GPA and the nested page table; The writing module writes the data to be written and the first message authentication code into the memory space corresponding to the first host physical address HPA.
9. The virtual machine nested page table integrity protection device according to claim 8, It is characterized in that The device also includes: A second receiving module is used to receive a data read request sent by the processor core; the data read request includes a second virtual machine physical address GPA and a second address space identifier; wherein the second virtual machine physical address GPA is a virtual machine physical address GPA to be accessed for data to be read, and the second address space identifier is an address space identifier of the virtual machine to read data; A second determination module, used to determine a second host physical address HPA of the data to be read according to the second virtual machine physical address GPA and the nested page table; A reading module, used to read data from the memory space corresponding to the second host physical address HPA; A second sending module, used to send the read data, the second virtual machine physical address GPA and the second address space identifier to the hash calculation engine, so that the hash calculation engine calculates a second message authentication code according to the read data, the second virtual machine physical address GPA and the second address space identifier; A comparison module is used to compare whether the second message authentication code is consistent with the first message authentication code; if the two are inconsistent, it is determined that the nested page table integrity check fails.
10. The virtual machine nested page table integrity protection device according to claim 8, It is characterized in that The first determining module comprises: A determining unit, configured to determine, according to the first virtual machine physical address GPA, whether a designated bit of a page table entry in the nested page table where the first virtual machine physical address GPA is located is set; The trigger unit is used to trigger a page fault exception if a designated bit of the page table entry where the first virtual machine physical address GPA is located in the nested page table has been set.
11. The virtual machine nested page table integrity protection device according to claim 10, It is characterized in that The device also includes: A clearing module is used to clear the designated bit to zero by using a first dedicated instruction of the nested page table if the page fault exception is triggered for the first time.
12. The virtual machine nested page table integrity protection device according to claim 11, It is characterized in that The device also includes: The resetting module is used to reset the designated bit through the second dedicated instruction of the nested page table if the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located is modified.
13. The virtual machine nested page table integrity protection device according to any one of claims 11 to 12, It is characterized in that The device also includes: The first trigger module is used to determine that the mapping relationship between the virtual machine physical address GPA and the host physical address HPA in the page table entry where the first virtual machine physical address GPA is located in the nested page table is abnormally modified if the page fault exception is not triggered for the first time.
14. The virtual machine nested page table integrity protection device according to claim 8, It is characterized in that The device also includes: A detection module, used to detect whether the memory area where the non-last-level page table of the nested page table is located belongs to the safe nested page table memory range; The second trigger module is used to trigger a nested page fault exception if the memory area where the non-last-level page table of the nested page table is located does not belong to the safe nested page table memory range.
15. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the virtual machine nested page table integrity protection method according to any one of claims 1 to 7.
16. An electronic device, It is characterized in that The electronic device comprises: a shell, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the shell, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the virtual machine nested page table integrity protection method described in any one of claims 1 to 7.
Citation Information
Patent Citations
Memory management method and device of virtual machine, CPU chip and server
CN112099903A
Page access method and page access device, and server
WO2015043376A1