A virtual network communication method and virtual network system for a trusted device
By configuring the virtual network device and PCIe channel on the privacy computing unit side, the problem that the privacy computing unit cannot communicate with the remote service is solved, and transparent communication and low-latency data transmission are realized.
Patent Information
- Application Number
- CN202411897646.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-23
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-12-23
AI Technical Summary
The privacy computing unit cannot communicate directly with the remote service, affecting its use, and the existing gateway service cannot achieve unaware communication and lead to delays in packet transmission.
The virtual network device is configured on the privacy computing unit side, and the data packet is captured and redirected to the host side through the virtual network device, and a high-speed communication link is established with the host side through the PCIe channel to reduce multiple copies of the data packets in the network stack.
It realizes transparent communication between the privacy computing unit and remote services, improves application development flexibility, and reduces communication latency.
Smart Images

Figure CN119341849B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network communication technologies, and particularly relates to a virtual network communication method and a virtual network system for a trusted device. Background Art
[0002] TEE (Trusted Execution Environment), also known as the trusted execution environment, is a secure area isolated from the host system and runs in parallel with the host operating system as an independent environment. TEE technology uses hardware and software to protect data and code, thereby ensuring the confidentiality and integrity of the code and data loaded in the secure area are protected, obtaining stronger security guarantees than the traditional REE (Rich Execution Environment, general execution environment) environment. The trusted applications running in the TEE can access all the functions of the main processor and memory on the platform, and the hardware isolation protects these components from being affected by the user-installed applications running in the main operating system.
[0003] The privacy computing unit (Secure Process Unit, SPU), as a TEE product independent of the host, has its own operating system, memory, and CPU computing resources inside the environment, but has no physical network card, and data cannot flow out from the SPU side. This results in the services inside the SPU being unable to communicate with remote services, thereby affecting the use of the SPU.
[0004] Therefore, the existing technologies still need to be improved. Summary of the Invention
[0005] The technical problem to be solved by this application is to provide a virtual network communication method and a virtual network system for a trusted device in view of the deficiencies of the existing technologies.
[0006] To solve the above technical problem, in the first aspect of this application, a virtual network communication method for a trusted device is provided, which is applied to an electronic device. The electronic device includes a host side and a privacy computing unit side, and a virtual network device is configured inside the privacy computing unit side. The virtual network communication method for the trusted device specifically includes:
[0007] Capturing, by the virtual network device, a first data packet formed on the privacy computing unit side;
[0008] Sending, by the virtual network device, the first data packet to the host side, and forwarding, by the host side, the first data packet to a target network.
[0009] The virtual network communication method of the trusted device, wherein the capturing of the first data packet formed on the trusted execution environment side by the virtual network device specifically includes:
[0010] The application injects the first data packet into the kernel network stack on the privacy computing unit side;
[0011] The virtual network device captures the first data packet by interacting with the kernel network stack on the privacy computing unit side.
[0012] The virtual network communication method of the trusted device, wherein the method further includes:
[0013] Receiving, by the virtual network device, a second data packet from the host side and transmitting the second data packet to the kernel network stack on the privacy computing unit side.
[0014] The virtual network communication method of the trusted device, wherein the method further includes:
[0015] Performing security processing on the first data packet and / or the second data packet by the host side and sending the first data packet and / or the second data packet after security processing.
[0016] The virtual network communication method of the trusted device, wherein the security processing includes performing security processing on the first data packet and / or the second data packet by the host side kernel and / or transmitting the first data packet and / or the second data packet to the user space for performing security processing on the first data packet and / or the second data packet by the application.
[0017] The virtual network communication method of the trusted device, wherein a first PCIe control module is deployed on the privacy computing unit side, a second PCIe control module is deployed on the host side, and both the first PCIe control module and the second PCIe control module communicate with the PCIe channel to form a communication link between the host side and the privacy computing unit side; the communication link is used to transmit the first data packet from the privacy computing unit side to the host side and the second data packet from the host side to the privacy computing unit side.
[0018] A second aspect of the present application provides a virtual network system of a trusted device. The virtual network system of the trusted device includes a host side and a privacy computing unit side, and a virtual network device is configured inside the privacy computing unit side; the virtual network device is used to capture the first data packet formed on the privacy computing unit side, send the first data packet to the host side, and forward the first data packet to the target network through the host side.
[0019] The virtual network system of the trusted device, wherein a first PCIe control module is deployed on the side of the privacy computing unit, and a second PCIe control module is deployed on the host side. Both the first PCIe control module and the second PCIe control module communicate with the PCIe channel to form a communication link between the host side and the privacy computing unit side; the communication link is used to transmit the first data packet from the privacy computing unit side to the host side and the second data packet from the host side to the privacy computing unit side.
[0020] The virtual network system of the trusted device, wherein a virtual device management module is deployed on the side of the privacy computing unit; the virtual device management module is used to redirect the first data packet formed by the interaction between the application program and the kernel network stack on the side of the privacy computing unit to the virtual network device.
[0021] The virtual network system of the trusted device, wherein a host-side security module and / or a user security module is provided on the host side. The host-side security module is used to perform security processing on the second data packet from the remote service, and the user security module is used to transmit the second data packet from the remote service to the user space for the application program to perform security processing on the second data packet.
[0022] Beneficial effects:
[0023] 1. In the present application, the SPU communicates with the external network through a virtual device, and the communication process is transparent to the application program, thereby improving the flexibility of application program development.
[0024] 2. The PCIe channel is used to achieve efficient data transmission between the SPU and the host, reducing multiple copies of the first data packet in the network stack and reducing communication latency.
[0025] 3. The host side performs real-time security processing on the second data packet, ensuring the legality of the second data packet and the security of the system. Description of the drawings
[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0027] Figure 1 It is a principle block diagram of the virtual network system of the trusted device provided by the embodiment of the present application.
[0028] Figure 2 It is a flowchart of the virtual network communication method of the trusted device provided by the embodiment of the present application. Detailed implementation manners
[0029] The embodiments of the present application provide a virtual network communication method and a virtual network system for a trusted device. To make the objectives, technical solutions, and effects of the present application clearer and more explicit, the following further describes the present application in detail with reference to the accompanying drawings and by way of examples. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0030] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the", and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present application means the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups. It should be understood that when we say that an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more of the associated listed items.
[0031] Those skilled in the art of the present technology can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the art to which the present application belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless specifically defined as here.
[0032] It should be understood that the sequence numbers and magnitudes of the steps in this embodiment do not mean the sequence of execution is prior or subsequent. The execution sequence of each process is determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0033] After research, it is found that TEE (Trusted Execution Environment), also known as the trusted execution environment, is a secure area isolated from the host system and runs in parallel with the host operating system as an independent environment. TEE technology uses hardware and software to protect data and code, thereby ensuring the confidentiality and integrity of the code and data loaded in the secure area, and obtaining stronger security guarantees than the traditional REE (Rich Execution Environment) environment. The trusted applications running in the TEE can access all the functions of the main processor and memory on the platform, and the hardware isolation protects these components from the user-installed applications running in the main operating system.
[0034] The privacy computing unit (Secure Process Unit, SPU), as a TEE product independent of the host, has its own operating system, memory, and CPU computing resources inside the environment, but has no physical network card, so data cannot flow out from the SPU side. This results in the inability of the services inside the SPU to communicate with remote services, thereby affecting the use of the SPU.
[0035] Currently, it is forwarded through a gateway service. For example, Nginx, etc. However, the existing gateway services generally only intercept and forward the first IP packet, and do not process the content of the first packet (such as encryption, etc.). And when forwarding the first packet through the gateway service, the application program needs to participate, and it is impossible to achieve communication without the awareness of both parties, which will affect the flexibility of application program development. At the same time, when forwarding the first packet through the gateway service, the first packet needs to be copied multiple times in the network stack, which will cause transmission delay of the first packet.
[0036] To solve the above problems, in the embodiment of the present application, a virtual network device is configured on the privacy computing unit side. The first packet formed on the privacy computing unit side is captured through the virtual network device and redirected to the host side to send the first packet to the host side, and the first packet is forwarded to the target network through the host side. In this way, not only the communication between the privacy computing unit and the remote service is realized, but also when the privacy computing unit communicates with the remote service, the application program does not need to care about the communication between the privacy computing unit and the remote service, and the communication process is transparent to the application program, thereby improving the flexibility of application program development. At the same time, the privacy computing unit side and the host side perform efficient data transmission through the PCIe channel, reducing the multiple copies of the first packet in the network stack and reducing the communication delay.
[0037] The following further illustrates the application content by describing the embodiments in conjunction with the accompanying drawings.
[0038] This embodiment provides a virtual network system for a trusted device, as follows Figure 1 As shown, the virtual network system of the trusted device includes a host, and the host contains one or more SPUs. Each SPU can be an application / server, that is, an SPU application / SPU server. For the convenience of description, here the SPU is denoted as the privacy computing unit side, and the host environment of the host where the SPU is deployed is denoted as the host side. The SPU cannot directly communicate with the remote service. If the SPU needs to communicate with the remote service, it needs to send the first data packet to the host side, and the host side will forward the first data packet to the remote service. Similarly, if the remote service accesses the SPU inside the host side, it also needs to first receive the second data packet sent by the remote service through the host side, and then the host side confirms the SPU side corresponding to the second data packet and sends the second data packet to the SPU side. Of course, when the remote service needs to send the first data packet to the SPU inside the host side, it also needs to first receive the first data packet sent by the remote service through the host side, and then the host side confirms the SPU side corresponding to the first data packet and sends the first data packet to the SPU side. Here, the subsequent description will be given by taking the example of the SPU side sending the first data packet to the remote service and the remote service sending the second data packet to the SPU side.
[0039] As an independent trusted device from the host, the SPU has an operating system, memory, and CPU computing resources inside, but there is no physical network card inside the SPU, so that the first data packet inside the SPU cannot flow from the SPU side to the host side. For this reason, in the embodiment of the present application, a virtual network device (such as a TUN device ( / dev / net / tun), etc.) is configured on the SPU side. The virtual network device is used as a bridge between the kernel network stack on the privacy computing unit side and the PCIe interface, realizing the communication between the SPU side and the host side. That is to say, the virtual network device is used to capture the first data packet on the privacy computing unit side, send the first data packet to the host side, and forward the first data packet to the target network through the host side. At the same time, the virtual network device is also used to receive the second data packet from the host side and transmit the second data packet to the kernel network stack on the privacy computing unit side. By deploying a virtual network device inside the SPU side in the embodiment of the present application, on the one hand, it realizes efficient data interaction between the user state and the kernel state through the interaction between the virtual network device and the kernel network stack on the privacy computing unit side; on the other hand, it realizes the communication between the SPU side and the host side through the virtual network device, realizing efficient transmission inside the host.
[0040] Further, the virtual network device communicates with the kernel network stack, and transmits the first data packet to the virtual network device through the kernel network stack. The first data packet can be formed by an application program within the SPU. That is to say, the application program initiates communication with a remote service and determines the first data packet to be interacted with, and then interacts with the kernel network stack through the Socket API to send the first data packet to the kernel network stack. After receiving the first data packet, the kernel network stack forwards the first data packet to the virtual network device.
[0041] After receiving the first data packet, the virtual network device sends the first data packet to the host side. To avoid communication latency caused by multiple replications of the first data packet within the network stack. In the embodiments of the present application, a high-speed communication channel is established between the virtual network device and the host side through the PCIe channel, and the PCIe channel is used to achieve efficient communication between the virtual network device and the host side. Specifically, as Figure 2 shown, a first PCIe control module (denoted as SpuPcs) is deployed on the SPU side, and a second PCIe control module (denoted as HostPcs) is deployed on the host side. The first PCIe control module and the second PCIe control module establish communication through the PCIe channel to form a communication link between the host side and the privacy computing unit side; the communication link is used to transmit the first data packet from the privacy computing unit side to the host side, and the second data packet from the host side to the privacy computing unit side. That is to say, the first PCIe control module located on the SPU side and the second PCIe control module located on the host side cooperate, and forward the data in the SPU to the host side through the PCIe channel between the two.
[0042] Further, in order to manage the virtual network device, a virtual network device management module (denoted as SpuTun) can also be deployed within the SPU side. The virtual network device management module is used to redirect the first data packet formed by the interaction between the application program and the kernel network stack on the privacy computing unit side to the virtual network device. That is to say, the virtual network device is managed through the virtual network device management module to control the virtual network device to redirect the first data packet from the application program and the second data packet from the host side, thereby realizing network interaction between the kernel state and the user state.
[0043] In one implementation, a host-side management module (denoted as HostTun) can also be set on the host side to manage the first data packet sent to the host side through the virtual network device, so as to inject the first data packet into the kernel network stack on the host side, enabling it to send the first data packet to the target network through the physical network interface on the host side. In addition, a host-side security module (denoted as Netfilter) and / or a user security module (denoted as NFQUEUE) can be deployed on the host side. The host-side security module is used to perform security processing on the second data packet from the remote service and / or the first data packet from the SPU side. The user security module is used to transmit the second data packet and / or the first data packet from the remote service to the user space for security processing of the second data packet and / or the first data packet through an application. This can ensure that all incoming and outgoing second data packets and / or first data packets comply with the system's security policy and prevent unauthorized access.
[0044] Based on the virtual network system of the above-mentioned trusted device, an embodiment of the present application provides a virtual network communication method for a trusted device, as Figure 2 shown, the virtual network communication method for the trusted device specifically includes:
[0045] S10. Capture the first data packet formed on the privacy computing unit side through the virtual network device;
[0046] S20. Send the first data packet to the host side through the virtual network device, and forward the first data packet to the target network through the host side.
[0047] Specifically, the first data packet is for an application in the privacy computing unit side to interact with the target network (i.e., the remote service). That is to say, the application can interact with the remote service through the virtual network device to transmit the first data packet to the remote service, or receive the second data packet sent by the remote service.
[0048] Further, after the application initiates the first data packet, the application will inject the first data packet into the kernel network stack of the SPU side for interaction, and then the virtual network device captures the first data packet of the kernel network stack of the SPU side. Based on this, in one implementation, the capturing of the first data packet formed on the trusted execution environment side through the virtual network device specifically includes:
[0049] S11. The application injects the first data packet into the kernel network stack of the privacy computing unit side;
[0050] S12. The virtual network device captures the first data packet by interacting with the kernel network stack of the privacy computing unit side.
[0051] Specifically, when the kernel network stack on the privacy computing unit side receives the first data packet and the first data packet needs to be sent to a remote service, it redirects the first data packet to the virtual network device so that the virtual network device can capture the first data packet. That is to say, when the kernel network stack on the privacy computing unit side receives the first data packet interacted with by the application and detects the interaction object of the first data packet, when the interaction object is a remote service, it redirects the first data packet and then interacts it with the virtual network device, achieving the goal of using the virtual network device to capture the first data packet in the kernel network stack on the privacy computing unit side that needs to be interacted with the remote service. The application only needs to interact the first data packet with the kernel network stack on the privacy computing unit side without caring about the process of the virtual network device obtaining the first data packet and the process of the virtual network device interacting with the host side.
[0052] After obtaining the first data packet, the virtual network device forwards the first data packet to the host side. Among them, a PCIe channel is established between the virtual network device and the host side, and the virtual network device sends the first data packet to the host side through the PCIe channel, which can reduce the multiple copies of the first data packet in the network stack and reduce the communication delay. Specifically, the virtual network device can be deployed with a first PCIe control module, and the host side is deployed with a second PCIe control module. A PCIe channel is established between the first PCIe control module and the second PCIe control module. The virtual network device sends the first data packet to the first PCIe control module, and the first PCIe control module sends the first data packet to the second PCIe control module through the PCIe channel. The second PCIe module injects the first data packet into the kernel network stack on the host side to transmit the first data packet to the host side. The embodiment of the present application realizes a high-speed communication link between the virtual network device and the grid service on the host side through the PCIe channel to ensure the low-latency transmission of the first data packet. At the same time, the responsibilities of the grid service on the host side are very clear, only responsible for redirecting and routing the first data packet, without involving data processing, encryption or decryption, etc. at the application layer, making the gateway service lightweight and able to process high-throughput first data packets without making any modifications to the data content. Among them, the gateway service can be the physical gateway on the host side, and this physical gateway is responsible for sending the data packet to the external network or receiving the data packet from the external network. The physical network card performs the actual transmission of data through the standard network stack. Before the data packet reaches the physical network card, it is processed by a raw socket for directly operating on the incoming / outgoing data packets to achieve specific customized functions.
[0053] Of course, the first data packet in the SPU can be transmitted to the host side through the virtual network device, or the second data packet from the remote service on the host side can be transmitted to the application through the virtual network device. For this reason, the method further includes:
[0054] Receive a second data packet from the host side through the virtual network device, and transmit the second data packet to the kernel network stack on the privacy computing unit side.
[0055] Specifically, the virtual network device receives the second data packet through the PCIe channel between the virtual network device and the host side. Among them, the second data packet can be a data packet from a remote service. That is to say, after the host side receives the second data packet that needs to be sent to the privacy computing unit side, it will redirect the second data packet, and then transmit the second data packet to the virtual network device through the PCIe channel between the virtual network device and the host side. After receiving the second data packet, the virtual network device injects the second data packet into the kernel network stack on the privacy computing unit side, and then interacts with the application program through the kernel network stack on the privacy computing unit side, realizing the data interaction between the privacy computing unit side and the host side.
[0056] Furthermore, when the kernel network stack on the host side receives the first data packet and / or the second data packet, it can directly send the first data packet and / or the second data packet, or it can first perform security management on the first data packet and / or the second data packet, and then send the first data packet and / or the second data packet after security management. In the embodiment of the present application, the kernel network stack on the host side first performs security management on the first data packet and / or the second data packet, and then sends the first data packet and / or the second data packet after security management. That is to say, the method further includes:
[0057] Perform security processing on the first data packet and / or the second data packet through the host side, and send the first data packet and / or the second data packet after security processing.
[0058] Specifically, the security processing includes performing security processing on the first data packet and / or the second data packet through the host-side kernel and / or transmitting the first data packet and / or the second data packet to the user space for the application to perform security processing on the first data packet and / or the second data packet. In a typical implementation, the security processing includes performing security processing on the first data packet and / or the second data packet through the host-side kernel and transmitting the first data packet and / or the second data packet to the user space for the application to perform security processing on the first data packet and / or the second data packet. Among them, performing security processing on the first data packet and / or the second data packet through the host-side kernel can be filtering and managing the first data packet and / or the second data packet through the Netfilter framework; transmitting the first data packet and / or the second data packet to the user space for the application to perform security processing on the first data packet and / or the second data packet can be transmitting the first data packet and / or the second data packet to the user space for the application to perform in-depth processing, such as security checks, load balancing, etc.
[0059] In the embodiment of the present application, the Netfilter framework is integrated on the host side. The Netfilter framework filters and monitors the data packets entering and / or leaving the SPU according to predefined rules to prevent unauthorized access and potential security threats, ensuring that only authorized first data packets and / or second data packets can enter the system, further guaranteeing the isolation and security of the SPU environment. In addition, the second data packet after passing through the Netfilter framework will also pass the first data packet and / or the second data packet to the user space through NFQUEUE, thereby further improving the security of the first data packet and / or the second data packet.
[0060] In addition, for the transmission process of the first data packet from the virtual network device to the host side and the transmission process of the second data packet from the host side to the virtual network device for the first data packet from the remote service, these two transmission processes are transparent to the applications inside the SPU. The application believes that it directly communicates with the remote service itself without caring about how the first data packet and the second data packet flow between the SPU and the host side, thereby improving the flexibility of application development.
[0061] In summary, this embodiment provides a virtual network communication method and a virtual network system for a trusted device. The method includes configuring a virtual network device on the privacy computing unit side, capturing a first data packet formed on the privacy computing unit side through the virtual network device, redirecting the first data packet to the host side to send the first data packet to the host side, and forwarding the first data packet to the target network through the host side. This not only realizes the communication between the privacy computing unit and the remote service, but also when the privacy computing unit communicates with the remote service, the application program does not need to care about the communication between the privacy computing unit and the remote service, and the communication process is transparent to the application program, thereby improving the flexibility of application program development. At the same time, the privacy computing unit side and the host side perform efficient data transmission through the PCIe channel, reducing the multiple copies of the first data packet in the network stack and reducing the communication delay.
[0062] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A virtual network communication method for a trusted device, characterized in that, Applied to an electronic device, the electronic device includes a host side and a privacy computing unit side. A virtual network device is configured inside the privacy computing unit side. The virtual network device is used as a bridge between the kernel network stack of the privacy computing unit side and the PCIe interface. Through the virtual network device, it interacts with the kernel network stack of the privacy computing unit side to achieve data interaction between the user space and the kernel space, and realizes communication between the privacy computing unit side and the host side through the virtual network device. The specific method for virtual network communication of the trusted device specifically includes: Capture the first data packet formed on the privacy computing unit side through the virtual network device, where the virtual network device is a TUN device; Send the first data packet to the host side through the virtual network device, and forward the first data packet to the target network through the host side; Receive the second data packet from the host side through the virtual network device, and transmit the second data packet to the kernel network stack of the privacy computing unit side, where the host side will perform security processing on the first data packet and / or the second data packet, and send the first data packet and / or the second data packet after security processing; Among them, in order to manage the virtual network device, a virtual network device management module is deployed inside the privacy computing unit side. The virtual network device management module is used to redirect the first data packet formed by the interaction between the application program and the kernel network stack of the privacy computing unit side to the virtual network device; manage the virtual network device through the virtual network device management module to control the virtual network device to redirect the first data packet from the application program and the second data packet from the host side, and realize network interaction between the kernel space and the user space.
2. The virtual network communication method of the trusted device according to claim 1, wherein The capturing of the first data packet formed on the privacy computing unit side through the virtual network device specifically includes: The application program injects the first data packet into the kernel network stack of the privacy computing unit side; The virtual network device captures the first data packet by interacting with the kernel network stack of the privacy computing unit side.
3. The virtual network communication method of the trusted device according to claim 1, characterized in that, The security processing includes performing security processing on the first data packet and / or the second data packet by the host side kernel and / or transmitting the first data packet and / or the second data packet to the user space to perform security processing on the first data packet and / or the second data packet by the application program.
4. The virtual network communication method of a trusted device according to claim 1, characterized in that, A first PCIe control module is deployed on the privacy computing unit side, and a second PCIe control module is deployed on the host side. Both the first PCIe control module and the second PCIe control module communicate with the PCIe channel to form a communication link between the host side and the privacy computing unit side; the communication link is used to transmit the first data packet from the privacy computing unit side to the host side and the second data packet from the host side to the privacy computing unit side.
5. A virtual network system for a trusted device, characterized in that, The virtual network system of the trusted device includes a host side and a privacy computing unit side, and a virtual network device is configured inside the privacy computing unit side; the virtual network device is used as a bridge between the kernel network stack of the privacy computing unit side and the PCIe interface, and interacts with the kernel network stack of the privacy computing unit side through the virtual network device to realize data interaction between the user space and the kernel space, and realizes communication between the privacy computing unit side and the host side through the virtual network device. Specifically, the virtual network device is used to capture the first data packet formed by the privacy computing unit side, send the first data packet to the host side, and forward the first data packet to the target network through the host side, receive the second data packet from the host side through the virtual network device, and transmit the second data packet to the kernel network stack of the privacy computing unit side; the host side is provided with a host side security module and / or a user security module. The host side security module is used to perform security processing on the second data packet from the remote service, and the user security module is used to transmit the second data packet from the remote service to the user space to perform security processing on the second data packet through the application program. Among them, the virtual network device is a TUN device, and in order to manage the virtual network device, a virtual network device management module is deployed inside the privacy computing unit side. The virtual network device management module is used to redirect the first data packet formed by the interaction between the application program and the kernel network stack of the privacy computing unit side to the virtual network device; the virtual network device is managed through the virtual network device management module to control the virtual network device to redirect the first data packet from the application program and the second data packet from the host side to realize network interaction between the kernel space and the user space.
6. The virtual network system of the trusted device according to claim 5, characterized in that, A first PCIe control module is deployed on the privacy computing unit side, and a second PCIe control module is deployed on the host side. Both the first PCIe control module and the second PCIe control module communicate with the PCIe channel to form a communication link between the host side and the privacy computing unit side; the communication link is used to transmit the first data packet from the privacy computing unit side to the host side and the second data packet from the host side to the privacy computing unit side.
Citation Information
Patent Citations
Network communication method and system of trusted equipment, terminal and storage medium
CN118842629A