Method, system, terminal and medium for secure use of virtual devices across bus domains
The control bridge realizes security state management in virtual PC I e devices across the bus domain, which solves the problem that virtual devices are difficult to ensure safety when used, and ensures the effectiveness of the devices in security and ordinary computing tasks.
Patent Information
- Application Number
- CN202410548989.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-06
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-05-06
AI Technical Summary
The prior art is difficult to ensure security when using virtual PC Ie devices across the bus domain, especially when borrowed devices cannot be used for secure computing, resulting in data leakage.
The control bridge realizes security state management. After powering on, the control bridge enters the initialization state. After completing the identity authentication and obtaining the communication key, the data output to the device lender bus is encrypted and the input data is decrypted.
Ensure that the virtual device can be used for ordinary computing tasks or for secure computing tasks to ensure the security of computing tasks.
Smart Images

Figure CN118673496B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of device virtualization, and in particular, to a method, system, terminal, and medium for securely using virtual devices across bus domains. Background Art
[0002] PCIe device virtualization typically involves simulating and managing physical PCIe devices in a virtual machine environment within a single PCIe bus domain. Virtualizing PCIe devices allows virtual machines to access and use these devices as if they were directly connected to the virtual machine.
[0003] Currently, for PCIe devices across PCIe bus domains (two or more host systems), access interfaces such as interrupts, BARs, and DMA execution can be exposed to each other through PCIe NTB (Non-Transparent Bridge). However, it is difficult to ensure the security of virtual PCIe devices across bus domains during use, especially when borrowed devices cannot be used for secure computing, resulting in data leakage.
[0004] Therefore, the prior art still needs to be improved and enhanced. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a method, system, terminal, and medium for securely using virtual devices across bus domains in view of the above-mentioned deficiencies of the prior art. The technical solutions adopted by the present invention are as follows:
[0006] In a first aspect, the present invention provides a method for securely using virtual devices across bus domains, where the method includes:
[0007] When the control bridge powers on, it enters the initialization state, and after completing the initialization, the control bridge enters the available state;
[0008] After receiving the start security task instruction, the control bridge enters the authentication state, and in the authentication state, the identity authentication of the control bridge is performed and a communication key is obtained;
[0009] Enter the running security task state, and based on the communication key, the control bridge encrypts all data output to the device lender's bus and decrypts all data input from the device lender's bus.
[0010] In one implementation, the method further includes:
[0011] After receiving the start non-security task instruction, enter the running non-security task state;
[0012] In the running non-security task state, the control bridge stops using any security functions.
[0013] In one implementation, after the control bridge is powered on, it enters the initialization state. After the initialization is completed, the control bridge enters the available state, including:
[0014] Complete the trusted boot, where the trusted boot includes: checking necessary parameters, and if there is firmware or software, measuring the firmware and software;
[0015] After the trusted boot is successful, establish a boot flag and ensure that the connected virtual devices are normally reset;
[0016] The connection bridge obtains the authentication public key from the control bridge, and when the boot flag is valid and the initialization completion instruction is received, the control bridge enters the available state.
[0017] In one implementation, perform the identity authentication of the control bridge in the authentication state and obtain the communication key, including:
[0018] The device borrower completes the identity authentication of the control bridge through the connection bridge using the remote authentication method or the identity discrimination method;
[0019] The device borrower requests a security status report from the control bridge through the connection bridge;
[0020] After receiving the request for the security status report, the control bridge locks the security-related configuration parameters, and uses the authentication private key to sign the security status report with the locked parameters as part of the security status report and sends it to the device borrower.
[0021] In one implementation, perform the identity authentication of the control bridge in the authentication state and obtain the communication key, including:
[0022] After receiving the security status report, the device borrower verifies the signature using the authentication public key of the control bridge;
[0023] After the signature verification passes, evaluate the security status report to determine whether the control bridge is in a secure state;
[0024] Obtain the communication key according to the request of the device borrower.
[0025] In one implementation, obtaining the communication key according to the request of the device borrower includes:
[0026] The device borrower and the control bridge jointly negotiate the communication key;
[0027] Or,
[0028] The communication key is directly distributed by the equipment borrower, and the equipment borrower encrypts the communication key using the authentication public key of the control bridge.
[0029] In one implementation, the method further includes:
[0030] If an error occurs in any state other than the initialization state, the control bridge enters the error handling state;
[0031] Collect error information in the error handling state and update the error status information in the control bridge;
[0032] After completing the collection and update of the error status information, the control bridge returns to the initialization state.
[0033] In a second aspect, an embodiment of the present invention further provides a virtual device secure usage system across bus domains. Among them, the system is applied to the virtual device secure usage method across bus domains in the above technical solution. The system includes: an equipment borrower, an equipment lender, a connection bridge, and a control bridge. The equipment borrower includes a virtual device, the equipment lender includes a virtualized device, the connection bridge is used to connect the buses corresponding to the equipment borrower and the equipment lender respectively, and the control bridge is used to connect the virtualized device to the bus of the equipment lender. Among them, the control bridge includes:
[0034] An initialization module, configured to enter the initialization state when the control bridge is powered on, and after completing the initialization, the control bridge enters the available state;
[0035] An identity authentication module, configured to enter the authentication state after receiving the start security task instruction. In the authentication state, perform the identity authentication of the control bridge and obtain the communication key;
[0036] A data encryption and decryption module, configured to enter the running security task state. Based on the communication key, the control bridge encrypts all data output to the bus of the equipment lender and decrypts all data input from the bus of the equipment lender.
[0037] In a third aspect, an embodiment of the present invention further provides a terminal. Among them, the terminal includes a memory, a processor, and a virtual device secure usage program across bus domains stored in the memory and executable on the processor. When the processor executes the virtual device secure usage program across bus domains, it implements the steps of the virtual device secure usage method in any one of the above solutions.
[0038] Fourthly, an embodiment of the present invention further provides a computer-readable storage medium, on which a virtual device secure usage program across bus domains is stored. When the virtual device secure usage program across bus domains is executed by a processor, the steps of the virtual device secure usage method across bus domains described in any one of the above solutions are implemented.
[0039] Beneficial effects: Compared with the prior art, the present invention provides a virtual device secure usage method across bus domains. First, when the control bridge is powered on, it enters the initialization state, and after completing the initialization, the control bridge enters the available state. Then, after receiving the start security task instruction, the control bridge enters the authentication state, and in the authentication state, the identity authentication of the control bridge is performed and a communication key is obtained. Entering the running security task state, based on the communication key, the control bridge encrypts all data output to the device lender bus and decrypts all data input from the device lender bus. The present invention realizes security state management through the control bridge, enabling the virtual device to be used for ordinary computing tasks and also for security computing tasks, ensuring the security of computing tasks. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 It is a flowchart of a preferred embodiment of the virtual device secure usage method across bus domains provided by an embodiment of the present invention.
[0041] Figure 2 It is a structural diagram of the virtual device secure usage system across bus domains provided by an embodiment of the present invention.
[0042] Figure 3 It is a finite state model diagram of the virtual device secure usage method across bus domains provided by an embodiment of the present invention.
[0043] Figure 4 It is a principle block diagram of a terminal provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] To make the objectives, technical solutions and effects of the present invention clearer and more definite, the following further describes the present invention in detail with reference to the accompanying drawings and by way of examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0045] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the", and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present invention means the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more of the associated listed items.
[0046] Those skilled in the art of the present technology can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the field to which the present invention belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless specifically defined as here.
[0047] This embodiment provides a method for secure use of virtual devices across bus domains. Based on the method of this embodiment, security state management is achieved through a control bridge, enabling the virtual devices to be used for ordinary computing tasks and also for secure computing tasks, ensuring the security of computing tasks.
[0048] As Figure 1 As shown in, the method for secure use of virtual devices across bus domains of this embodiment can be applied to terminals and also to servers. Specifically, the method for secure use of virtual devices across bus domains of this embodiment includes the following steps:
[0049] Step S100: When the control bridge is powered on, it enters the initialization state, and after completing the initialization, the control bridge enters the available state;
[0050] Step S200: After receiving the start secure task instruction, the control bridge enters the authentication state, and in the authentication state, the identity authentication of the control bridge is performed, and a communication key is obtained;
[0051] Step S300: Enter the running secure task state. Based on the communication key, the control bridge encrypts all data output to the device lender bus and decrypts all data input from the device lender bus.
[0052] Specifically in implementation, this embodiment provides a system for secure use of virtual devices across bus domains, asFigure 2 As shown, the system includes: a device borrower, a device lender, a connection bridge, and a control bridge. The device borrower includes virtual devices, and the device lender includes virtualized devices. The connection bridge is used to connect the buses respectively corresponding to the device borrower and the device lender, and the control bridge is used to connect the virtualized device to the bus of the device lender. In this embodiment, the connection bridge is a PCIe non-transparent bridge, which appears as a PCIe EP (Endpoint) in both the PCIe buses of the device borrower and the device lender. The EP of the device borrower in this embodiment is called EP0, and the EP of the device lender is called EP1. One end of the control bridge in this embodiment is connected to the PCIe bus of the device lender, and the other end is connected to the virtualized device, and it has the functions of both a PCIe transparent bridge and a non-transparent bridge. As a transparent bridge, it does not change the PCIe bus topology of the device lender and ensures the normal use of the virtualized device in the device lender. As a non-transparent bridge, when the device borrower uses the virtualized device, it can further process and control the PCIe data entering and leaving the virtualized device, such as implementing security state management in this embodiment.
[0053] Combined with Figure 3 As shown, after the control bridge is powered on, it automatically enters the initialization state. The trusted boot is completed, including: checking necessary parameters, and if there is firmware or software, measuring the firmware and software. Then, after the trusted boot is successful, a startup flag (Startup flag) is established, and it is ensured that the connected virtualized device is normally reset, which can be specifically achieved through the hard reset, logical reset of PCIe or power on / off of the control device to implement the reset. The connection bridge obtains the authentication public key from the control bridge, and when the startup flag is valid and the initialization completion instruction is received, the control bridge enters the available state.
[0054] Further, after the control bridge enters the available state, if a non-secure task start instruction is received, it enters the non-secure task running state. At this time, the control bridge cannot use any security functions, such as identity authentication, data encryption and decryption, traffic control, etc. When a non-secure task stop instruction is received, it enters the initialization state. If a secure task start instruction is received, the control bridge enters the authentication state. In the authentication state, the identity authentication of the control bridge is performed and a communication key is obtained. Specifically, the identity authentication is completed by the equipment borrower. If the connection bridge is integrated in the equipment borrower, it can also be automatically completed by the connection bridge. The identity authentication in this embodiment includes a remote authentication method or an identity verification method. Therefore, the equipment borrower can choose the remote authentication method to determine whether the identity of the control bridge is legal; the equipment borrower can also choose to complete it by the industry-recognized identity verification method, such as the national standard GB / T 15843.3-2016. Of course, in some implementation methods, the two methods of remote authentication and identity verification can also be combined to more accurately implement the identity authentication of the control bridge.
[0055] Next, the equipment borrower requests a security status report from the control bridge through the connection bridge; after receiving the request for the security status report, the control bridge locks the security-related configuration parameters, including but not limited to: virtual device information, connection bridge EP1 address information, control registers, etc. Then, the locked parameters are used as part of the security status report, and the security status report is signed using the authentication private key and sent to the equipment borrower. After receiving the security status report, the equipment borrower verifies the signature using the authentication public key of the control bridge. After the signature verification passes, the security status report is evaluated to determine whether the control bridge is in a secure state.
[0056] Further, the control bridge obtains a communication key according to the request of the equipment borrower. Specifically, the communication key can be jointly negotiated by the equipment borrower and the control bridge, such as using the DH algorithm, the SM2 key exchange protocol, etc.; or the equipment borrower directly distributes the communication key. At this time, the equipment borrower uses the authentication public key of the control bridge to encrypt the communication key. After successfully obtaining the communication key, the control bridge enters the secure task running state. Based on the communication key, the control bridge encrypts all data output to the equipment lender's bus and decrypts all data input from the equipment lender's bus. The encryption and decryption algorithms in this embodiment can use the authenticated encryption working mode (such as: GCM) to achieve the control of the data stream. When a secure task stop instruction is received, the control bridge enters the initialization state.
[0057] Further, if an error occurs in any state other than the initialization state, the control bridge enters the error handling state; in the error handling state, error information is collected and the error status information in the control bridge is updated; after the collection and update of the error status information are completed, the control bridge returns to the initialization state.
[0058] It can be seen that in this embodiment, security means are added through the connection bridge and the control bridge, enabling the borrowed device to be used for secure computing as well. And through security state management, the borrowed device can also be used for general computing.
[0059] Based on the above embodiments, the present invention further provides a secure usage system for virtual devices across bus domains, as Figure 2 shown in the figure. The system includes: a device borrower, a device lender, a connection bridge, and a control bridge. The device borrower includes virtual devices, and the device lender includes virtualized devices. The connection bridge is used to connect the buses respectively corresponding to the device borrower and the device lender, and the control bridge is used to connect the virtualized device to the bus of the device lender. Specifically, the control bridge at least includes: an initialization module, an identity authentication module, and a data encryption and decryption module. The initialization module is used to enter the initialization state when the control bridge is powered on, and after the initialization is completed, the control bridge enters the available state. The identity authentication module is used to enter the authentication state after receiving the instruction to start a security task, perform the identity authentication of the control bridge in the authentication state, and obtain a communication key. The data encryption and decryption module is used to enter the running security task state, and based on the communication key, the control bridge encrypts all data output to the bus of the device lender and decrypts all data input from the bus of the device lender.
[0060] The functional principles of the various modules in the secure usage system for virtual devices across bus domains in this embodiment are the same as the functions to be achieved in the method steps in the above embodiments, and will not be elaborated here.
[0061] Based on the above embodiments, the present invention further provides a terminal, and the principle block diagram of the terminal can be as Figure 4 shown in the figure. The terminal may include one or more processors 100 ( Figure 4 only one is shown in the figure), a memory 101, and a computer program 102 stored in the memory 101 and executable on one or more processors 100, for example, a secure usage program for virtual devices across bus domains. When one or more processors 100 execute the computer program 102, each step in the embodiment of the method for secure usage of virtual devices across bus domains can be implemented. Or, when one or more processors 100 execute the computer program 102, the functions of the various modules / units in the embodiment of the method for secure usage of virtual devices across bus domains can be implemented, and no limitation is made here.
[0062] In one embodiment, the so-called processor 100 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0063] In one embodiment, the memory 101 may be an internal storage unit of the electronic device, such as the hard disk or memory of the electronic device. The memory 101 may also be an external storage device of the electronic device, such as a plug-in hard disk equipped on the electronic device, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. Further, the memory 101 may also include both the internal storage unit and the external storage device of the electronic device. The memory 101 is used to store computer programs and other programs and data required by the terminal. The memory 101 may also be used to temporarily store data that has been output or is to be output.
[0064] Those skilled in the art can understand that Figure 4 the principle block diagram shown in
[0065] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, operational database, or other medium used in the embodiments provided by the present invention can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0066] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or equivalently replace some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for securely using a virtual device across bus domains, characterized in that: The method comprises: When the control bridge is powered on, it enters the initialization state, and after completing the initialization, the control bridge enters the usable state; After receiving the instruction to start the safety task, the control bridge enters the authentication state, performs identity authentication of the control bridge in the authentication state, and obtains the communication key; Entering into the running safety task state, based on the communication key, the control bridge encrypts all data output to the device lender bus and decrypts all data input from the device lender bus; After receiving the command to start the non-safety task, it enters the running non-safety task state; When running a non-safety task, the control bridge stops using any safety function; When the control bridge is powered on, it enters the initialization state, and after the initialization is completed, the control bridge enters the usable state, including: Complete the trusted boot, wherein the trusted boot includes: checking necessary parameters, and if firmware or software exists, measuring the firmware and software; After the trusted boot is successful, a boot flag is established and the connected virtual device is ensured to be reset normally. The reset method includes hard reset of PCIe, logical reset or power on and off of the control device. The connection bridge obtains the authentication public key from the control bridge, and after the startup flag is valid and the initialization completion instruction is received, the control bridge enters an available state; The step of performing identity authentication of the control bridge in the authentication state and obtaining a communication key includes: The equipment borrower completes the identity authentication of the control bridge by remote authentication or identity authentication through the connection bridge; The equipment borrower requests a safety status report from the control bridge through the connection bridge; After receiving the request for the security status report, the control bridge locks the security-related configuration parameters, uses the locked parameters as part of the security status report, signs the security status report with the authentication private key, and sends it to the device borrower; The step of performing identity authentication of the control bridge in the authentication state and obtaining a communication key includes: After receiving the security status report, the equipment borrower uses the control bridge's authentication public key to verify the signature; After the signature verification is passed, the safety status report is evaluated to determine whether the control bridge is in a safe state; Obtaining the communication key according to the request of the device borrower; The obtaining of the communication key according to the request of the device borrower includes: The device borrower and the control bridge jointly negotiate the communication key; or, The communication key is directly distributed by the equipment borrower, and the equipment borrower encrypts the communication key using the authentication public key of the control bridge; The method further comprises: If an error occurs in any state except the initialization state, the control bridge enters the error handling state; Collecting error information in the error processing state and updating error state information in the control bridge; After completing the collection and update of the error status information, the control bridge returns to the initialization state.
2. A cross-bus domain virtual device secure use system, characterized in that: The system is applied to the method for securely using a virtual device across bus domains as described in claim 1 above, and the system comprises: a device borrower, a device lender, a connection bridge and a control bridge, the device borrower comprises a virtual device, the device lender comprises a virtualized device, the connection bridge is used to connect the buses corresponding to the device borrower and the device lender respectively, and the control bridge is used to connect the bus of the virtualized device and the bus of the device lender, wherein the control bridge comprises: The initialization module is used to enter the initialization state when the control bridge is powered on, and after the initialization is completed, the control bridge enters the usable state; The identity authentication module is used to control the bridge to enter an authentication state after receiving an instruction to start a safety task, perform identity authentication of the control bridge in the authentication state, and obtain a communication key; The data encryption and decryption module is used to enter the running safety task state, and based on the communication key, the control bridge encrypts all data output to the device lender bus and decrypts all data input from the device lender bus.
3. A terminal, characterized in that: The terminal includes a memory, a processor, and a cross-bus domain virtual device safe use program stored in the memory and executable on the processor. When the processor executes the cross-bus domain virtual device safe use program, the steps of the cross-bus domain virtual device safe use method as described in claim 1 are implemented.
4. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a program for safely using a virtual device across bus domains. When the program for safely using a virtual device across bus domains is executed by a processor, the steps of the method for safely using a virtual device across bus domains as described in claim 1 are implemented.
Citation Information
Patent Citations
Heterogeneous computing system and resource processing method based on heterogeneous computing system
CN116527257A
METHOD TO USE PCIe DEVICE RESOURCES BY USING UNMODIFIED PCIe DEVICE DRIVERS ON CPUs IN A PCIe FABRIC WITH COMMODITY PCI SWITCHES
US20160098372A1