Communication method and apparatus for virtualized data isolation

CN117294423BActive Publication Date: 2026-09-25BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310988167.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-07
Publication Date
2026-09-25
Estimated Expiration
2043-08-07

AI Technical Summary

Technical Problem

但是,这样往往会存在性能问题,不适用于同一台物理机上两台虚拟设备,进行短时间内、大量数据量的通信

Benefits of technology

[0057]本申请提供一种虚拟化数据隔离的通信方法及装置,所述方法不需要经过网络协议栈,也不需要经过虚拟或真实的网卡,而是直接在物理机上进行内存数据的传输和通信,能够满足同一台物理机上两台虚拟设备短时间内大量数据量的通信。本方案通中的专用通信区域是通过物理机的PCIe接口映射出来的,从链路上保证了只有通信双方可以访问,安全性更好。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117294423B_ABST
    Figure CN117294423B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a communication method and device for virtualized data isolation, and belongs to the technical field of information security. The method comprises the following steps: a physical machine initializes and allocates a shared memory to be mapped to a virtual machine; a first virtual machine and a second virtual machine perform communication key negotiation based on the shared memory, and obtain a negotiated communication key; the physical machine uses the address conversion function of PCIe to map the address of a region in DDR physical memory to the first virtual machine, and uses the address of the region as a special communication region address; the first virtual machine transmits the encrypted special communication region address to the second virtual machine; the second virtual machine decrypts the special communication region address, and constructs a special communication region with the first virtual machine based on the decrypted special communication region address; and the second virtual machine communicates with the first virtual machine based on the constructed special communication region. The method can meet the communication of a large amount of data between two virtual devices on the same physical machine within a short time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically to a virtualized data isolation communication method, a virtualized data isolation communication device, a machine-readable storage medium, and a processor. Background Technology

[0002] In recent years, with the rapid development of the Internet, it has been embedded into people's lives in every aspect, from food and clothing to housing and transportation. The emergence of cloud servers has further changed the way society works and the business model.

[0003] Protecting the private information of each user on cloud servers has become a crucial aspect of cloud security. Effectively isolating information between devices and between users to ensure data security in the cloud has become a key concern for cloud services.

[0004] Existing technologies typically emphasize the emulation and isolation of virtual devices within cloud servers. Communication between two virtual devices on a cloud server is usually treated as different independent network hosts, communicating via common network protocols and virtual or physical network interface cards (NICs). However, this often leads to performance issues and is unsuitable for communication of large amounts of data within a short period between two virtual devices on the same physical machine. Summary of the Invention

[0005] The purpose of this invention is to provide a virtualized data isolation communication method and apparatus. The method does not require a network protocol stack or a virtual or real network card, but directly transmits and communicates memory data on the physical machine, which can meet the communication of a large amount of data between two virtual devices on the same physical machine in a short period of time.

[0006] To achieve the above objectives, a first aspect of this application provides a virtualized data isolation communication method for communication between virtual machines in a virtual network, wherein the virtual machines reside on the same physical machine, the method comprising:

[0007] The physical machine initializes and allocates shared memory mappings to the virtual machine; the shared memory includes a communication area, a public key storage area, and a communication key factor storage area.

[0008] The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain the negotiated communication key.

[0009] The physical machine uses the address translation function of PCIe to map the address of a region in DDR physical memory to the first virtual machine, and uses the address of the region as the address of a dedicated communication region.

[0010] The first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine;

[0011] The second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0012] The second virtual machine constructs a dedicated communication area with the first virtual machine based on the decrypted dedicated communication area address, and communicates with the first virtual machine based on the constructed dedicated communication area.

[0013] Optionally, the first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain a negotiated communication key, including:

[0014] The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory using an asymmetric encryption algorithm to obtain a negotiated communication key. The negotiated communication key includes a negotiated first communication key and a negotiated second communication key, wherein the negotiated first communication key is generated by the first virtual machine and the negotiated second communication key is generated by the second virtual machine.

[0015] Optionally, the first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine, including:

[0016] The first virtual machine uses the negotiated first communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

[0017] Optionally, the second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address, including:

[0018] The second virtual machine uses the negotiated second communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0019] Optionally, the first virtual machine and the second virtual machine negotiate a communication key using an asymmetric encryption algorithm based on the shared memory to obtain a negotiated communication key, including:

[0020] For the first virtual machine:

[0021] The first virtual machine randomly generates a first communication key factor;

[0022] The first communication key factor is encrypted using the public key of the second virtual machine to obtain the ciphertext of the first communication key factor.

[0023] The first communication key factor ciphertext is signed using the private key of the first virtual machine to obtain the signed first communication key factor ciphertext.

[0024] The ciphertext of the first communication key factor after signing is placed in the storage area corresponding to the communication key factor.

[0025] Optionally, the first virtual machine and the second virtual machine negotiate a communication key using an asymmetric encryption algorithm based on the shared memory to obtain a negotiated communication key, including:

[0026] For the second virtual machine:

[0027] The second virtual machine randomly generates a second communication key factor;

[0028] The second communication key factor is encrypted using the public key of the first virtual machine to obtain the ciphertext of the second communication key factor.

[0029] The second communication key factor ciphertext is signed using the private key of the second virtual machine to obtain the signed second communication key factor ciphertext.

[0030] The ciphertext of the signed second communication key factor is placed in the storage area corresponding to the communication key factor.

[0031] Optionally, for the second virtual machine, it also includes:

[0032] The first communication key factor ciphertext after signing is obtained from the storage area corresponding to the communication key factor;

[0033] The first virtual machine's public key is used to verify the signature of the first communication key factor ciphertext, and the verified first communication key factor ciphertext is obtained.

[0034] The private key of the second virtual machine is used to decrypt the ciphertext of the first communication key factor after signature verification to obtain the decrypted first communication key factor.

[0035] The decrypted first communication key factor and the second communication key factor are concatenated to generate the negotiated second communication key.

[0036] Optionally, for the first virtual machine, it also includes:

[0037] The signed second communication key factor ciphertext is obtained from the storage area corresponding to the communication key factor;

[0038] The public key of the second virtual machine is used to verify the signature of the second communication key factor ciphertext, and the verified second communication key factor ciphertext is obtained.

[0039] The private key of the first virtual machine is used to decrypt the ciphertext of the verified second communication key factor to obtain the decrypted second communication key factor.

[0040] The first communication key factor and the decrypted second communication key factor are concatenated to generate the negotiated first communication key.

[0041] A second aspect of this application provides a virtualized data isolation communication device for communication between virtual machines in a virtual network, wherein the virtual machines reside on the same physical machine, and the device includes:

[0042] A memory allocation unit is used to enable the physical machine to initialize and allocate shared memory mapped to the virtual machine; the shared memory includes a communication area, a public key storage area, and a communication key factor storage area.

[0043] A key negotiation unit is used to enable the first virtual machine and the second virtual machine to negotiate a communication key based on the shared memory, and obtain a negotiated communication key.

[0044] Address translation unit, used to enable the physical machine to use the PCIe address translation function to map the address of a region in DDR physical memory to the first virtual machine, and use the address of the region as the address of a dedicated communication region;

[0045] An encryption unit is used to enable the first virtual machine to use the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine;

[0046] The decryption unit is used to enable the second virtual machine to use the negotiated communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0047] A dedicated communication unit is used to enable the second virtual machine to construct a dedicated communication area with the first virtual machine based on the decrypted dedicated communication area address, and to communicate with the first virtual machine based on the constructed dedicated communication area.

[0048] Optionally, the first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain a negotiated communication key, including:

[0049] The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory using an asymmetric encryption algorithm to obtain a negotiated communication key. The negotiated communication key includes a negotiated first communication key and a negotiated second communication key, wherein the negotiated first communication key is generated by the first virtual machine and the negotiated second communication key is generated by the second virtual machine.

[0050] Optionally, the first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine, including:

[0051] The first virtual machine uses the negotiated first communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

[0052] Optionally, the second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address, including:

[0053] The second virtual machine uses the negotiated second communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0054] A third aspect of this application provides a processor configured to perform the aforementioned virtualized data isolation communication method.

[0055] A fourth aspect of this application provides a machine-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the aforementioned virtualized data isolation communication method.

[0056] Compared with the prior art, the above-mentioned technical solution of the present invention has the following beneficial effects:

[0057] This application provides a virtualized data isolation communication method and apparatus. The method does not require a network protocol stack or a virtual or physical network card; instead, it directly transmits and communicates memory data on the physical machine, enabling communication of large amounts of data between two virtual devices on the same physical machine within a short period. The dedicated communication area in this solution is mapped from the physical machine's PCIe interface, ensuring that only the communicating parties can access it, thus enhancing security.

[0058] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0059] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:

[0060] Figure 1 The illustration shows a flowchart of a virtualized data isolation communication method according to an embodiment of this application;

[0061] Figure 2This illustration schematically shows the relationship between memory regions and virtual machines according to embodiments of this application;

[0062] Figure 3 This schematically illustrates a system startup flowchart according to an embodiment of the present application;

[0063] Figure 4 This illustration schematically shows the initialization process of a physical machine system and a virtual machine system according to an embodiment of this application;

[0064] Figure 5 This illustration schematically shows a diagram of the internal storage structure of shared memory according to an embodiment of this application;

[0065] Figure 6 This illustration schematically shows the internal structure of the communication area of ​​a virtual machine according to an embodiment of this application;

[0066] Figure 7 This illustration schematically shows a key factor ciphertext region storage structure according to an embodiment of this application;

[0067] Figure 8 This illustration schematically shows a timing diagram for confirming the initial communication status between the two communicating parties according to an embodiment of this application;

[0068] Figure 9 A schematic diagram illustrating a communication timing sequence according to an embodiment of this application is shown.

[0069] Figure 10 A schematic block diagram of a communication device with virtualized data isolation according to an embodiment of this application is shown. Detailed Implementation

[0070] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for illustration and explanation of the embodiments of this application and are not intended to limit the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0071] It should be noted that if the embodiments of this application involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, features defined with "first" or "second" may explicitly or implicitly include at least one of those features. Furthermore, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.

[0072] PCIe is short for PCI-Express (Peripheral Component Interconnect Express). It is an internal bus and a computer expansion bus standard. It is a high-speed serial, high-bandwidth expansion bus, usually used on the motherboard to connect peripherals such as graphics cards, solid-state drives, capture cards, and wireless network cards.

[0073] ATU (Address Translation Unit): Address translation unit.

[0074] DDR (Double Data Rate Synchronous Dynamic Random Access Memory): Double data rate synchronous dynamic random access memory.

[0075] Figure 1 A schematic flowchart illustrating a communication method for virtualized data isolation according to an embodiment of this application is shown. Figure 1 As shown in one embodiment of this application, a virtualized data isolation communication method is provided. This embodiment mainly illustrates the application of this method to two virtual machines on the same physical machine in a virtual network, including the following steps:

[0076] Step 110: The physical machine initializes and allocates shared memory mappings to the virtual machine; the shared memory includes a communication area, a public key storage area, and a communication key factor storage area.

[0077] Specifically, a physical machine is a device that actually hosts resources, such as a server or PC. A virtual machine is a device created using virtualization functionality, relying on a physical machine. Initialization is initiated by the physical machine system, and the resources needed for subsequent virtual machine construction, such as memory, hard disk storage space, and hardware devices, all reside on the physical machine. Then, the physical machine allocates and maps these resources onto the virtual machine.

[0078] Figure 2This illustration schematically shows the relationship between memory regions and virtual machines according to embodiments of this application, such as... Figure 2 As shown, there are N virtual machines on the same physical machine. The shared memory of the physical machine after initialization is used by the virtual machines, which then publish their own device public keys, communication key factors, and other information.

[0079] Figure 3 This schematically illustrates a system startup flowchart according to an embodiment of the present application, such as... Figure 3 As shown, the process includes the following steps: 1. Initialization of the physical machine system and the virtual machine system; 2. Negotiation of communication keys between the two virtual machine communication parties; 3. Confirmation of the initial communication status; 4. Entering the business communication state.

[0080] Figure 4 This illustration schematically shows the initialization process of a physical machine system and a virtual machine system according to embodiments of this application, such as... Figure 4 As shown, the physical machine initializes and builds virtual machine resources, allocates and initializes memory mapping to the virtual machine, the virtual machine synchronously lays out key distribution, the virtual machine generates a key and publishes a public key, then obtains the public keys of other virtual machines, preprocesses communication key factors based on the obtained public keys, and finally publishes the preprocessed communication key factors and the preprocessed communication key factors obtained from other devices.

[0081] Figure 5 This illustration schematically shows a diagram of the internal storage structure of shared memory according to an embodiment of this application, such as... Figure 5 As shown, the shared memory includes: a communication area, a public key storage area, a communication key factor storage area, and a reserved area.

[0082] Figure 6 This illustration schematically shows the internal structure of the communication area of ​​a virtual machine according to an embodiment of this application, such as... Figure 6 As shown, the communication area of ​​this device includes: peer device 1 area, peer device 2 area, ..., peer device N area. "This device" refers to this virtual machine, and "peer device" refers to other virtual machines besides this one. That is, the communication area of ​​each virtual machine includes the communication areas of all other virtual machines except this one. In the entire system, assuming there are N virtual machine devices, there will be N communication areas as shown. Figure 6 The structure shown is as follows. Each virtual machine corresponds to a structure like this. Figure 6 The communication area is shown. The communication area is used in the following scenarios: when a peer virtual machine communicates with this virtual machine, it places the communication command in the communication area of ​​this virtual machine corresponding to the peer device; when this virtual machine replies to a message, it also places the communication command in the communication area of ​​the peer virtual machine corresponding to this virtual machine.

[0083] Each virtual machine generates its own public key. The public key published by the virtual machine is stored in a public key storage area. To prevent malicious tampering of the virtual machine's public key, eavesdropping technology can be used. Every modification to the public key must be confirmed by the virtual machine to which the public key belongs; only after confirmation can the modification be completed. Typically, the virtual machine itself modifies its own public key.

[0084] Figure 7 This illustration schematically shows a key factor ciphertext region storage structure according to an embodiment of this application, such as... Figure 7 As shown, the key factor ciphertext area of ​​this device includes: peer device 1 key factor area, peer device 2 key factor area, ... peer device N key factor area. "This device" refers to this virtual machine, and "peer device" refers to other virtual machines besides this virtual machine. That is, the communication key factor storage area (i.e., key factor ciphertext area) of each virtual machine contains the key factor areas of other virtual machines besides this virtual machine.

[0085] Step 120: The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain the negotiated communication key.

[0086] Specifically, the first virtual machine and the second virtual machine negotiate a communication key based on the shared memory using an asymmetric encryption algorithm to obtain a negotiated communication key; the negotiated communication key includes: a negotiated first communication key and a negotiated second communication key, wherein the negotiated first communication key is generated by the first virtual machine and the negotiated second communication key is generated by the second virtual machine.

[0087] Specifically, the negotiated first communication key and the negotiated second communication key are numerically equal.

[0088] Specifically, since asymmetric encryption algorithms (public-key encryption algorithms) are much slower than symmetric encryption, this embodiment uses a public-key encryption algorithm to securely share and negotiate a symmetric encryption communication key. When transmitting data, a symmetric encryption algorithm is used. The communication key factor serves as a factor in the negotiated key, used by both virtual machine communication parties to negotiate the symmetric encryption key for communication.

[0089] Specifically, for a virtual machine about to communicate, the process of generating, preprocessing, and publishing its key factor is as follows:

[0090] Generate communication key factor: Randomly generate a 16-byte random number and use this random number as the communication key factor;

[0091] Preprocessing key factors: Encrypt the communication key factors using the public key of the peer virtual machine, and then sign them using the private key of the local virtual machine;

[0092] Release key factor: Place the signed ciphertext of the communication key factor in the storage area corresponding to the communication key factor.

[0093] In the above process, both parties in the communication virtual machine device have completed the key factor publication. The following steps will then complete the communication key negotiation between the two parties:

[0094] After initialization, virtual machine devices can access the communication key factor area of ​​the peer virtual machine through shared memory, and obtain the signed ciphertext of the communication key factor between the peer and the local device.

[0095] The signature is verified using the public key of the peer virtual machine, and the communication key factor is obtained by decrypting the ciphertext of the communication key factor using the private key of the local virtual machine.

[0096] The communication key factors of both parties are concatenated using the local communication key factor and the remote communication key factor to obtain the communication key between them. Specifically, the communication key factors of the initiating party are concatenated in the order of initiating party first and responding party last, so that both parties can obtain the same communication key, that is, the negotiated first communication key and the negotiated second communication key are equal in value.

[0097] Step 130: The physical machine uses the address translation function of PCIe to map the address of a region in the DDR physical memory to the first virtual machine, and uses the address of the region as the address of the dedicated communication region.

[0098] Specifically, the dedicated communication area is allocated by the physical machine when the virtual machine initiating communication requests a memory block. After learning the address of the memory block, the requesting virtual machine uses the negotiated communication key obtained in step 120 to encrypt the address of the memory block and then transmits it to the virtual machine that wants to establish communication. Because the address of the memory block is encrypted before being transmitted to the peer virtual machine, only the two communicating virtual machines can read and recognize it. Through the management of the physical machine and virtual machine systems, each virtual machine has its own accessible memory space. For addresses temporarily mapped by PCIe, virtual machines without access rights cannot access them by adding an offset to the base address.

[0099] Step 140: The first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

[0100] Specifically, the first virtual machine uses the negotiated first communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

[0101] Step 150: The second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address.

[0102] Specifically, the second virtual machine uses the negotiated second communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0103] Specifically, the negotiated first communication key is generated by the first virtual machine, and the negotiated second communication key is generated by the second virtual machine. The negotiated first communication key and the negotiated second communication key are numerically equal, and this communication key is used as the key for symmetric encryption and decryption when the two communicating parties transmit data.

[0104] Step 160: The second virtual machine constructs a dedicated communication area with the first virtual machine based on the decrypted dedicated communication area address, and communicates with the first virtual machine based on the constructed dedicated communication area.

[0105] Figure 8 This schematically illustrates a timing diagram for confirming the initial communication status between the two communicating parties according to an embodiment of this application, such as... Figure 8 As shown:

[0106] The initiating end (first virtual machine) encrypts the initialization command containing data area information using a communication key and places it in the initialization memory corresponding to the responding end (second virtual machine); wherein, the data area information includes the address of a dedicated communication area;

[0107] The responding end (second virtual machine) decrypts the received ciphertext containing the address of the private communication area, maps the decrypted private communication area address to the specified area, constructs the private communication area, and puts the string "OK" into the private communication area;

[0108] The initiating end (the first virtual machine) continuously polls the dedicated communication area to confirm that the dedicated communication area can successfully read data. Once the "OK" message is successfully obtained in the dedicated communication area, it indicates that the construction of the dedicated communication area is complete.

[0109] Figure 9 A schematic diagram illustrating a communication timing sequence according to an embodiment of this application is shown, such as... Figure 9 As shown:

[0110] After the initiating end (first virtual machine) completes the data address mapping, it notifies the responding end of the communication operation command containing data area information through the dedicated communication area; wherein, the data area information includes the address of the dedicated communication area for this purpose;

[0111] After the responding end (second virtual machine) receives the communication operation command, it maps the dedicated communication area to the responding end;

[0112] The responding end (second virtual machine) obtains the data transmitted by the initiating end from the dedicated communication area;

[0113] After the responding end (second virtual machine) finishes executing the communication operation command, it stores the command result in the dedicated communication area for this operation.

[0114] The initiating end (the first virtual machine) continuously polls the dedicated communication area, reads the command results from the dedicated communication area, and completes the communication.

[0115] The virtualized data isolation communication method provided in this embodiment has the following advantages:

[0116] Higher performance: This solution's communication data does not need to pass through the network protocol stack, nor does it require data encapsulation and decapsulation. It can directly communicate in memory according to the specified data packet format. Furthermore, this solution's communication data does not need to pass through a virtual or physical network card; instead, it directly transmits and communicates memory data on the physical machine.

[0117] Enhanced security: Because the communication data in this solution is transmitted directly within the physical machine's memory without passing through the external network, the accessible scope is relatively small. This solution has a complete communication protocol, and all communication processes are encrypted. The dedicated communication area in this solution is mapped through the physical machine's PCIe interface, ensuring that only the communicating parties can access it from the link layer. Other virtual devices are physically isolated at the PCIe link layer.

[0118] Communication protocols can be more flexible: because network data packets have specific transmission protocols and must communicate according to the specified protocols, custom network protocols usually require the cooperation of various network hardware and must be compatible with the protocols of the same and lower layers. As a result, implementing new network application protocols is quite difficult. However, this solution provides a completely independent memory area, and the users are limited to the two parties of the communication protocol, without involving more software and hardware environments. Therefore, it is very convenient to implement various communication protocols.

[0119] This application enables a more powerful cloud server-side virtual device communication solution. It features high performance, strong security, and greater flexibility, and can be applied to many scenarios involving cloud server-side virtual device communication.

[0120] Figure 1 This is a flowchart illustrating a communication method for virtualized data isolation in one embodiment. It should be understood that, although... Figure 1The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 1 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0121] In one embodiment, such as Figure 10 As shown, a virtualized data isolation communication device is provided, comprising: a memory allocation unit, a key negotiation unit, an address translation unit, an encryption unit, a decryption unit, and a dedicated communication unit, wherein:

[0122] The memory allocation unit 210 is used to enable the physical machine to initialize and allocate shared memory mapped to the virtual machine; the shared memory includes a communication area, a public key storage area, and a communication key factor storage area.

[0123] The key negotiation unit 220 is used to enable the first virtual machine and the second virtual machine to negotiate a communication key based on the shared memory, and obtain the negotiated communication key.

[0124] Address translation unit 230 is used to enable the physical machine to use the PCIe address translation function to map the address of a region in DDR physical memory to the first virtual machine, and to use the address of the region as the address of a dedicated communication region.

[0125] The encryption unit 240 is used to enable the first virtual machine to use the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine;

[0126] The decryption unit 250 is used to enable the second virtual machine to use the negotiated communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0127] The dedicated communication unit 260 is used to enable the second virtual machine to construct a dedicated communication area with the first virtual machine based on the decrypted dedicated communication area address, and to communicate with the first virtual machine based on the constructed dedicated communication area.

[0128] Optionally, the first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain a negotiated communication key, including:

[0129] The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory using an asymmetric encryption algorithm to obtain a negotiated communication key. The negotiated communication key includes a negotiated first communication key and a negotiated second communication key, wherein the negotiated first communication key is generated by the first virtual machine and the negotiated second communication key is generated by the second virtual machine.

[0130] Optionally, the first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine, including:

[0131] The first virtual machine uses the negotiated first communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

[0132] Optionally, the second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address, including:

[0133] The second virtual machine uses the negotiated second communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0134] The virtualized data isolation communication device includes a processor and a memory. The memory allocation unit, key negotiation unit, address translation unit, encryption unit, decryption unit, and dedicated communication unit are all stored in the memory as program units. The processor executes the program units stored in the memory to implement the corresponding functions.

[0135] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and data isolation communication methods can be virtualized by adjusting kernel parameters.

[0136] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0137] This invention provides a storage medium on which a program is stored, which, when executed by a processor, implements the virtualized data isolation communication method.

[0138] This invention provides a processor for running a program, wherein the program executes the virtualized data isolation communication method during runtime.

[0139] This invention provides a device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps:

[0140] Step 110: The physical machine initializes and allocates shared memory mappings to the virtual machine; the shared memory includes a communication area, a public key storage area, and a communication key factor storage area.

[0141] Step 120: The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain the negotiated communication key.

[0142] Step 130: The physical machine uses the address translation function of PCIe to map the address of a region in the DDR physical memory to the first virtual machine, and uses the address of the region as the address of the dedicated communication region.

[0143] Step 140: The first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

[0144] Step 150: The second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address.

[0145] Step 160: The second virtual machine constructs a dedicated communication area with the first virtual machine based on the decrypted dedicated communication area address, and communicates with the first virtual machine based on the constructed dedicated communication area.

[0146] Optionally, the first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain a negotiated communication key, including:

[0147] The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory using an asymmetric encryption algorithm to obtain a negotiated communication key. The negotiated communication key includes a negotiated first communication key and a negotiated second communication key, wherein the negotiated first communication key is generated by the first virtual machine and the negotiated second communication key is generated by the second virtual machine.

[0148] Optionally, the first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine, including:

[0149] The first virtual machine uses the negotiated first communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

[0150] Optionally, the second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address, including:

[0151] The second virtual machine uses the negotiated second communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

[0152] Optionally, the first virtual machine and the second virtual machine negotiate a communication key using an asymmetric encryption algorithm based on the shared memory to obtain a negotiated communication key, including:

[0153] For the first virtual machine:

[0154] The first virtual machine randomly generates a first communication key factor;

[0155] The first communication key factor is encrypted using the public key of the second virtual machine to obtain the ciphertext of the first communication key factor.

[0156] The first communication key factor ciphertext is signed using the private key of the first virtual machine to obtain the signed first communication key factor ciphertext.

[0157] The ciphertext of the first communication key factor after signing is placed in the storage area corresponding to the communication key factor.

[0158] Optionally, the first virtual machine and the second virtual machine negotiate a communication key using an asymmetric encryption algorithm based on the shared memory to obtain a negotiated communication key, including:

[0159] For the second virtual machine:

[0160] The second virtual machine randomly generates a second communication key factor;

[0161] The second communication key factor is encrypted using the public key of the first virtual machine to obtain the ciphertext of the second communication key factor.

[0162] The second communication key factor ciphertext is signed using the private key of the second virtual machine to obtain the signed second communication key factor ciphertext.

[0163] The ciphertext of the signed second communication key factor is placed in the storage area corresponding to the communication key factor.

[0164] Optionally, for the second virtual machine, it also includes:

[0165] The first communication key factor ciphertext after signing is obtained from the storage area corresponding to the communication key factor;

[0166] The first virtual machine's public key is used to verify the signature of the first communication key factor ciphertext, and the verified first communication key factor ciphertext is obtained.

[0167] The private key of the second virtual machine is used to decrypt the ciphertext of the first communication key factor after signature verification to obtain the decrypted first communication key factor.

[0168] The decrypted first communication key factor and the second communication key factor are concatenated to generate the negotiated second communication key.

[0169] Optionally, for the first virtual machine, it also includes:

[0170] The signed second communication key factor ciphertext is obtained from the storage area corresponding to the communication key factor;

[0171] The public key of the second virtual machine is used to verify the signature of the second communication key factor ciphertext, and the verified second communication key factor ciphertext is obtained.

[0172] The private key of the first virtual machine is used to decrypt the ciphertext of the verified second communication key factor to obtain the decrypted second communication key factor.

[0173] The first communication key factor and the decrypted second communication key factor are concatenated to generate the negotiated first communication key.

[0174] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0175] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0176] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0177] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0178] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0179] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0180] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0181] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0182] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A virtualized data isolation communication method, characterized in that, For communication between virtual machines in a virtual network, wherein the virtual machines reside on the same physical machine, the method includes: The physical machine initializes and allocates shared memory mappings to the virtual machine; the shared memory includes a communication area, a public key storage area, and a communication key factor storage area. The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain the negotiated communication key. The physical machine uses the address translation function of PCIe to map the address of a region in DDR physical memory to the first virtual machine, and uses the address of the region as the address of a dedicated communication region. The first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine; The second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address. The second virtual machine constructs a dedicated communication area with the first virtual machine based on the decrypted dedicated communication area address, and communicates with the first virtual machine based on the constructed dedicated communication area.

2. The virtualized data isolation communication method according to claim 1, characterized in that, The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain a negotiated communication key, including: The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory using an asymmetric encryption algorithm to obtain a negotiated communication key. The negotiated communication key includes a negotiated first communication key and a negotiated second communication key, wherein the negotiated first communication key is generated by the first virtual machine and the negotiated second communication key is generated by the second virtual machine.

3. The virtualized data isolation communication method according to claim 2, characterized in that, The first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine, including: The first virtual machine uses the negotiated first communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

4. The virtualized data isolation communication method according to claim 3, characterized in that, The second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address, including: The second virtual machine uses the negotiated second communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

5. The virtualized data isolation communication method according to claim 2, characterized in that, The first virtual machine and the second virtual machine negotiate a communication key using an asymmetric encryption algorithm based on the shared memory, and obtain the negotiated communication key, including: For the first virtual machine: The first virtual machine randomly generates a first communication key factor; The first communication key factor is encrypted using the public key of the second virtual machine to obtain the ciphertext of the first communication key factor. The first communication key factor ciphertext is signed using the private key of the first virtual machine to obtain the signed first communication key factor ciphertext. The ciphertext of the first communication key factor after signing is placed in the storage area corresponding to the communication key factor.

6. The virtualized data isolation communication method according to claim 5, characterized in that, The first virtual machine and the second virtual machine negotiate a communication key using an asymmetric encryption algorithm based on the shared memory, and obtain the negotiated communication key, including: For the second virtual machine: The second virtual machine randomly generates a second communication key factor; The second communication key factor is encrypted using the public key of the first virtual machine to obtain the ciphertext of the second communication key factor. The second communication key factor ciphertext is signed using the private key of the second virtual machine to obtain the signed second communication key factor ciphertext. The ciphertext of the signed second communication key factor is placed in the storage area corresponding to the communication key factor.

7. The virtualized data isolation communication method according to claim 6, characterized in that, For the second virtual machine, it also includes: The first communication key factor ciphertext after signing is obtained from the storage area corresponding to the communication key factor; The first virtual machine's public key is used to verify the signature of the first communication key factor ciphertext, and the verified first communication key factor ciphertext is obtained. The private key of the second virtual machine is used to decrypt the ciphertext of the first communication key factor after signature verification to obtain the decrypted first communication key factor. The decrypted first communication key factor and the second communication key factor are concatenated to generate the negotiated second communication key.

8. The virtualized data isolation communication method according to claim 7, characterized in that, For the first virtual machine, it also includes: The signed second communication key factor ciphertext is obtained from the storage area corresponding to the communication key factor; The public key of the second virtual machine is used to verify the signature of the second communication key factor ciphertext, and the verified second communication key factor ciphertext is obtained. The private key of the first virtual machine is used to decrypt the ciphertext of the verified second communication key factor to obtain the decrypted second communication key factor. The first communication key factor and the decrypted second communication key factor are concatenated to generate the negotiated first communication key.

9. A virtualized data isolation communication device, characterized in that, For communication between virtual machines in a virtual network, wherein the virtual machines reside on the same physical machine, the device includes: A memory allocation unit is used to enable the physical machine to initialize and allocate shared memory mapped to the virtual machine; the shared memory includes a communication area, a public key storage area, and a communication key factor storage area. A key negotiation unit is used to enable the first virtual machine and the second virtual machine to negotiate a communication key based on the shared memory, and obtain a negotiated communication key. Address translation unit, used to enable the physical machine to use the PCIe address translation function to map the address of a region in DDR physical memory to the first virtual machine, and to use the address of the region as the address of a dedicated communication region; An encryption unit is used to enable the first virtual machine to use the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine; The decryption unit is used to enable the second virtual machine to use the negotiated communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address. A dedicated communication unit is used to enable the second virtual machine to construct a dedicated communication area with the first virtual machine based on the decrypted dedicated communication area address, and to communicate with the first virtual machine based on the constructed dedicated communication area.

10. The virtualized data isolation communication device according to claim 9, characterized in that, The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory to obtain a negotiated communication key, including: The first virtual machine and the second virtual machine negotiate a communication key based on the shared memory using an asymmetric encryption algorithm to obtain a negotiated communication key. The negotiated communication key includes a negotiated first communication key and a negotiated second communication key, wherein the negotiated first communication key is generated by the first virtual machine and the negotiated second communication key is generated by the second virtual machine.

11. The virtualized data isolation communication device according to claim 10, characterized in that, The first virtual machine uses the negotiated communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine, including: The first virtual machine uses the negotiated first communication key to encrypt the dedicated communication area address and transmit it to the second virtual machine.

12. The virtualized data isolation communication device according to claim 11, characterized in that, The second virtual machine uses the negotiated communication key to decrypt the encrypted private communication area address to obtain the decrypted private communication area address, including: The second virtual machine uses the negotiated second communication key to decrypt the encrypted private communication area address and obtain the decrypted private communication area address.

13. A processor, characterized in that, A communication method configured to perform virtualized data isolation as described in any one of claims 1 to 8.

14. A machine-readable storage medium storing instructions thereon, characterized in that, When executed by a processor, this instruction causes the processor to be configured to perform the virtualized data isolation communication method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method and device for assisting communication between virtual machines

    CN101819564A

  • Communication establishment method and system

    CN115914136A