Method, apparatus, device and storage medium for direct storage access of virtual machine

By mapping the physical addresses in the virtual machine's direct storage access request to the address range allocated to its use, limiting the access range of the DMA device, solving the problem of virtual machines illegally accessing physical memory and improving security and isolation.

CN119441074BActive Publication Date: 2025-05-27BEIJING INSTITUTE OF OPEN SOURCE CHIP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510044887.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-27
Estimated Expiration
2045-01-10

AI Technical Summary

Technical Problem

The virtual machine illegally accesses physical memory resources through the DMA device, causing security risks.

Method used

By mapping the first physical address in the direct storage access request issued by the virtual machine to the direct storage access device to the second physical address actually allocated to the virtual machine for use, and causing the direct storage access device to perform the direct storage access operation according to the second physical address, the physical memory accessible by the DMA device is restricted from being in the physical memory allocated to the virtual machine.

Benefits of technology

It avoids the virtual machine maliciously using the direct storage access device to access memory resources that do not belong to the virtual machine, ensuring isolation between virtual machines, thereby improving the security of the target device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119441074B_ABST
    Figure CN119441074B_ABST
Patent Text Reader

Abstract

The present application provides a direct storage access method, device, equipment and storage medium for a virtual machine. The virtual machine is deployed on a target device. The method includes: receiving, by a target device in the target device, a direct storage access request sent by the virtual machine; the direct storage access request includes a first physical address for a direct storage access operation; determining a second physical address matching the first physical address according to an address mapping relationship between physical addresses in a pre-configured first address range and physical addresses in a second address range; the first address range includes an address range not allocated for use by the virtual machine; the second address range is an address range allocated for use by the virtual machine; performing, by the target device, a direct storage access operation on the memory according to the second physical address, and sending the result of the direct storage access to the virtual machine. The process of the present application can implement restrictions on direct storage access operations and ensure the isolation of virtual machines in the target device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of virtual machines, and particularly to a method, apparatus, electronic device, and computer-readable storage medium for direct storage access of a virtual machine. Background Art

[0002] To improve the utilization rate of the Central Processing Unit (CPU) of a system, Direct Memory Access (DMA) devices are becoming increasingly popular.

[0003] A DMA device can directly access the physical memory resources of a computer system. For example, data stored in the DMA device can be directly transferred to the physical memory of the computer system without passing through the CPU; in a computer system including a virtual machine, the DMA device corresponding to the virtual machine will execute the requests of the virtual machine and perform DMA operations.

[0004] However, in theory, a DMA device can access any physical memory, and a virtual machine does not issue requests according to the addresses of the physically allocated memory. Therefore, a virtual machine can use the DMA device to access physical memory resources that do not belong to the virtual machine, that is, illegally access physical memory resources, posing a security risk. Summary of the Invention

[0005] Embodiments of this application provide a method, apparatus, electronic device, and computer-readable storage medium for direct storage access of a virtual machine to at least solve the problem of illegal access to physical memory resources by a virtual machine through a DMA device in related technologies.

[0006] In a first aspect, embodiments of this application provide a method for direct storage access of a virtual machine. The virtual machine is deployed on a target device. The method includes:

[0007] Receiving, by a target device in the target device, a direct storage access request sent by the virtual machine; the direct storage access request includes a first physical address for a direct storage access operation; the target device is a device with direct storage access function, and the first physical address belongs to a first address range; the first address range includes an address range not allocated for use by the virtual machine;

[0008] Determining, according to an address mapping relationship between physical addresses in a pre-configured first address range and physical addresses in a second address range, a second physical address that matches the first physical address; the second address range is an address range allocated for use by the virtual machine;

[0009] Through the target device, perform a direct memory access operation according to the second physical address, and send the result of the direct memory access to the virtual machine.

[0010] In a second aspect, an embodiment of the present application provides a direct memory access device for a virtual machine, where the virtual machine is deployed on a target device, and the device includes:

[0011] A receiving module: configured to receive a direct memory access request sent by the virtual machine through a target device in the target device; the direct memory access request includes a first physical address for a direct memory access operation; the target device is a device with a direct memory access function, and the first physical address belongs to a first address range; the first address range includes an address range not allocated for use by the virtual machine;

[0012] A mapping module: configured to determine a second physical address that matches the first physical address according to an address mapping relationship between physical addresses of a pre-configured first address range and physical addresses of a second address range; the second address range is an address range allocated for use by the virtual machine;

[0013] An execution module: configured to perform a direct memory access operation on the memory according to the second physical address through the target device, and send the result of the direct memory access to the virtual machine.

[0014] In a third aspect, an embodiment of the present application further provides an electronic device, including a processor;

[0015] A memory for storing executable instructions of the processor;

[0016] Wherein, the processor is configured to execute the instructions to implement the method of the first aspect.

[0017] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, enabling the electronic device to execute the method of the first aspect.

[0018] In the embodiments of the present application, by mapping the first physical address in the direct storage access request sent by the virtual machine to the direct storage access device to the second physical address actually allocated for use by the virtual machine, and enabling the direct storage access device to perform a direct storage access operation according to the second physical address, the physical memory accessible by the direct storage access device is restricted to the physical memory allocated to the virtual machine, so that the direct storage access is restricted, and the virtual machine is prevented from using the direct storage access device to access the memory resources that do not belong to the virtual machine; by preventing the virtual machine from using the direct storage access device to access the physical memory occupied by other virtual machines, the isolation between virtual machines is ensured, thereby improving the security of the target device.

[0019] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically illustrates the specific embodiments of the present application. Brief Description of the Drawings

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0021] Figure 1 It is a flowchart of steps of a direct storage access method for a virtual machine provided by an embodiment of the present application;

[0022] Figure 2 It is another flowchart of steps of a direct storage access method for a virtual machine provided by an embodiment of the present application;

[0023] Figure 3 It is a block diagram of a direct storage access device for a virtual machine provided by an embodiment of the present application;

[0024] Figure 4 It is a block diagram of an electronic device provided by an embodiment of the present invention;

[0025] Figure 5 It is a block diagram of another electronic device of another embodiment of the present invention. Detailed Description of the Embodiments

[0026] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0027] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, the term "and / or" in the specification and claims is used to describe the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. In the embodiments of the present application, the term "multiple" refers to two or more, and other quantifiers are similar.

[0028] Figure 1 , is a step flowchart of a direct storage access method for a virtual machine provided by an embodiment of the present application. The virtual machine is deployed on a target device, such as Figure 1 shown, the method may include:

[0029] Step 101, receiving, by a target device in the target device, a direct storage access request sent by the virtual machine; the direct storage access request includes a first physical address for direct storage access operations; the target device is a device with direct storage access function, and the first physical address belongs to a first address range; the first address range includes an address range not allocated for use by the virtual machine.

[0030] The embodiments of the present application may be based on the fifth-generation Reduced Instruction Set Computer (RISC-V) architecture. The RISC-V architecture is an open-source architecture that can be used to build a computer system including a virtual machine; the target device may be an RISC-V-based embedded system. In the target device, multiple virtual computer systems, that is, multiple virtual machines, may be deployed. Exemplarily, the virtual computer system may be Linux.

[0031] The target device further includes a target device, and the target device has a direct memory access function, that is, the target device includes a DMA device. Exemplarily, the DMA device may include peripheral devices such as a hard disk drive and a network adapter, or may also include peripheral interfaces that support the DMA function such as a Serial Peripheral Interface (SPI), an Inter-Integrated Circuit (IIC), a Universal Asynchronous Receiver / Transmitter (UART), and an Analog-to-Digital Converter (ADC); the virtual machine will use the DMA device to perform DMA operations during operation.

[0032] Since the physical address ranges recognized by the virtual machine, that is, the first address range and the physical address range actually allocated to the virtual machine, and the second address range are not the same, the virtual machine does not send a request instruction to the DMA device according to the physical address range actually allocated to the virtual machine. Also, because the DMA device can theoretically directly access any physical memory of the target device, this causes the virtual machine to be able to access the physical memory not allocated to itself through the DMA device, and the virtual machine cannot be fully isolated from the actual physical computer system, resulting in security risks; for a target device with multiple virtual machines deployed, the virtual machine can access the physical memory owned by other virtual machines through the DMA device, affecting the security of the target device.

[0033] Exemplarily, the available physical address range in the memory is 0x001fffff - 0x00600000; the second address range allocated to the virtual machine is 0x00400000 - 0x00600000, and the first address range recognized by the virtual machine is 0x001fffff - 0x003ffffff. The virtual machine will send a request instruction to the DMA device according to 0x001fffff - 0x003ffffff.

[0034] Exemplarily, the electronic and electrical architecture of an automobile evolves from a distributed architecture to a centralized architecture, which is manifested by the integration of multiple original scattered electronic components into one controller. The target device in the embodiments of the present application can be used as the controller of the automobile, and multiple virtual machines can be deployed on the controller to respectively execute different types of tasks on the automobile. If a virtual machine related to automobile safety, such as a virtual machine for executing chassis control tasks, and a virtual machine for ordinary operation feedback, such as a virtual machine for executing seat adjustment tasks, are running simultaneously on the controller, in the above situation, it is necessary to ensure that the virtual machine for executing seat adjustment tasks cannot access the physical memory resources of the virtual machine for executing chassis control tasks. For example, it is not allowed to rewrite the data in the memory allocated to the virtual machine for executing chassis control tasks; for a scenario like an automobile with high safety requirements, it is necessary to ensure the isolation of virtual machines in the target device, otherwise it will pose a safety hazard to the target device and the vehicle where it is located.

[0035] Furthermore, the method for direct storage access of the virtual machine provided in the embodiments of the present application is implemented in the Rust language; the Rust language is a system programming language focusing on security and has a memory safety mechanism. Rust ensures the safety of memory and threads through the ownership model and type system, enabling it to eliminate memory-related errors during compilation and having performance close to that of C or C++. Implementing the method for direct storage access of the virtual machine through Rust can reduce the memory safety problems of the virtual machine and the target device where it is located, and further improve the isolation of virtual machines in the target device.

[0036] Step 102: Determine the second physical address matching the first physical address according to the address mapping relationship between the physical addresses in the pre-configured first address range and the physical addresses in the second address range; the second address range is the address range allocated for use by the virtual machine.

[0037] According to the address mapping relationship between the physical addresses of the first address range and the second address range, the first physical addresses are mapped one by one to the second physical addresses. The second physical addresses belong to the second address range, and the second address range is the address range actually allocated for the virtual machine to use. By mapping the first physical addresses to the second physical addresses, the physical memory accessed by the DMA device is restricted to the second addresses. Each virtual machine treats the physical memory allocated to itself as a new physical memory, so the virtual machine does not send request instructions to the DMA device according to the second address range. Through the pre-configured address mapping relationship, the first physical addresses in the request instructions sent by the virtual machine to the DMA device can be converted into the second physical addresses included in the second address range. For a virtual machine with static partitioning, its second address range is fixed and allocated to the virtual machine when the virtual machine is created. Therefore, after the address mapping relationship is configured, it will not change dynamically and does not need to be continuously maintained. It can be used immediately, which is convenient for the target device to operate continuously and stably. For the DMA device, the address mapping relationship restricts the address range of the physical memory it accesses, avoiding illegal physical memory access by the virtual machine through the DMA device.

[0038] Exemplarily, the first physical address is 0x001fffff. According to the address mapping relationship between the first address range 0x001fffff - 0x003ffffff and the second address range 0x00400000 - 0x00600000, the obtained second physical address after mapping is 0x00400000.

[0039] Exemplarily, the conversion of the first physical address and the second physical address according to the address mapping relationship can be performed by software, such as a virtual machine monitor. The virtual machine runs on the virtual machine monitor, and its behavior is managed and controlled by the virtual machine monitor. Through the virtual machine monitor, software constraints on the physical address accessed by the DMA device can be achieved.

[0040] Step 103: Through the target device, perform a direct memory access operation on the memory according to the second physical address, and send the result of the direct memory access to the virtual machine.

[0041] After mapping the first physical addresses to the second physical addresses, the target device, i.e., the DMA device, performs a DMA operation on the memory according to the second physical addresses. Since the second physical addresses belong to the second address range, and the second address range is the physical address range allocated to the virtual machine, the DMA device will perform a DMA operation within the physical address range allocated to the virtual machine. On the one hand, it realizes the direct memory access of the virtual machine, and on the other hand, it ensures that the behavior of the virtual machine will not exceed the physical memory resources allocated to the virtual machine.

[0042] Exemplarily, the DMA operation may include directly copying data from the DMA device to the memory, directly transferring and copying data from the memory to the DMA device, copying data from a certain address segment in the memory to another address segment in the memory, etc. It can be understood that directly copying data from the DMA device to the memory is equivalent to completing the data reading operation in the DMA device; the data copied from the DMA device to the memory is modified in the memory and then copied back from the memory to the DMA device, which is equivalent to completing the data overwriting operation in the DMA device.

[0043] After the copy task in the DMA operation is completed, the DMA device that executes the DMA operation will return an interrupt signal to the virtual machine, and the virtual machine responds to the interrupt signal and processes the end of the DMA operation, including returning the result of the direct memory access to the virtual machine.

[0044] Exemplarily, the first physical address in the DMA request is 0x001fffff, the mapped second physical address is 0x00400000, and the DMA operation is the read operation of the c file in the DMA device, that is, the DMA device will directly copy the data of the c file to the corresponding area of 0x00400000 in the physical memory to implement the reading of the c file.

[0045] In the embodiment of the present application, by mapping the first physical address in the direct memory access request sent by the virtual machine to the direct memory access device to the second physical address actually allocated for the virtual machine to use, and enabling the direct memory access device to perform the direct memory access operation according to the second physical address, the physical memory accessible by the direct memory access device is restricted to the physical memory allocated to the virtual machine, so that the direct memory access is restricted, and the virtual machine is prevented from maliciously using the direct memory access device to access the memory resources that do not belong to the virtual machine; by making the virtual machine unable to use the direct memory access device to access the physical memory occupied by other virtual machines, the isolation between virtual machines is ensured, thereby improving the security of the target device.

[0046] Figure 2 , is another step flowchart of the direct memory access of the virtual machine provided by the embodiment of the present application. The virtual machine is deployed on a target device, such as Figure 2 shown, the method may include:

[0047] Step 201, when creating the virtual machine, save the page table in the memory through the virtual machine monitor; the page table is used to save the address mapping relationship between the physical addresses in the first address range and the physical addresses in the second address range. The first address range includes the address range not allocated for the virtual machine to use, and the second address range is the address range allocated for the virtual machine to use.

[0048] When creating and deploying a virtual machine on a target device, the page table is stored in the memory of the target device through a virtual machine monitor; the address mapping relationship between the physical addresses in the first address range and the physical addresses in the second address range is stored in the page table. This data structure of the page table is stored in the memory of the target device when the virtual machine is created. When the virtual machine is about to perform a DMA operation on the first physical address in the first address range through a DMA device, the address mapping relationship is read from the page table in the memory to complete the conversion from the first physical address to the second physical address.

[0049] Exemplarily, for a target device based on RISC-V, the virtual machine monitor may include hvisor, BaoHypervisor.

[0050] Optionally, the page table used in the process of mapping the virtual physical address of the virtual machine to the actual physical address of the virtual machine is the same page table.

[0051] When the virtual machine is running, in order to prevent the virtual machine from directly accessing the actual physical memory, it is necessary to first convert the virtual address of the virtual machine into the virtual physical address of the virtual machine (i.e., the guest physical address, GPA), and then convert the virtual physical address of the virtual machine into the actual physical address of the virtual machine (i.e., the host physical address, HPA). The actual physical address of the virtual machine is the physical address actually allocated to the virtual machine. The virtual physical address of the virtual machine is converted into the actual physical address of the virtual machine through a one-to-one mapping. It can be understood that in the process of mapping the virtual physical address of the virtual machine to the actual physical address of the virtual machine, compared with the process of mapping the first physical address to the second physical address, the range of the first address range is the same as the range of the virtual physical address of the virtual machine, and the range of the second address range is the same as the range of the actual physical address of the virtual machine. Therefore, the virtual physical address of the virtual machine is equivalent to the first physical address, and the actual physical address of the virtual machine is equivalent to the second physical address; thus, the same page table can be shared between the DMA device and the virtual machine. On the one hand, through the address mapping relationship in the page table, the physical memory accessible by the DMA device can be restricted to the physical memory allocated to the virtual machine to ensure the isolation of the virtual machine. On the other hand, the same page table is used in the above two mapping processes, which avoids the duplication of the page table, is not only convenient for implementation and management, but also saves physical memory.

[0052] Step 202: Receive a direct storage access request sent by the virtual machine through the target device in the target device; the direct storage access request includes a first physical address for a direct storage access operation; the target device is a device with a direct storage access function, and the first physical address belongs to the first address range.

[0053] This step has been described in the above step 101 and will not be elaborated here.

[0054] Step 203: Obtain the address mapping relationship saved in the page table from the memory through the input / output memory management unit; the target device includes the input / output memory management unit, and the input / output memory management unit is arranged between the target device and the memory of the target device.

[0055] In the embodiments of the present application, the entire process of obtaining the address mapping relationship and performing the conversion from the first physical address to the second physical address according to the address mapping relationship can be executed by setting a hardware input / output memory management unit (Input / Output Memory Management Unit, IOMMU) between the DMA device and the memory; in some embodiments, the above process can be executed by the virtual machine monitor, but frequent entry into the virtual machine monitor will bring certain time overhead, that is, obtaining the address mapping relationship in software form and performing the change from the first physical address to the second physical address according to the address mapping relationship will affect the real-time performance of the target device; directly obtaining the address mapping relationship and performing the address mapping change through the IOMMU hardware has a faster execution speed compared to the pure software implementation method, and can keep the time consumption of the above process at a relatively low level; for a target device such as an embedded system, setting the IOMMU can ensure the real-time performance of the target device.

[0056] IOMMU is a memory management unit (MMU) that connects a direct memory access-capable input / output bus (DMA-capable I / O BUS) to the main memory (Main memory). In some computer systems, IOMMU is also called the system memory management unit (System Memory Manage Unit, SMMU); since IOMMU connects to the DMA-capable I / O BUS, IOMMU can aggregate the scattered first physical addresses in multiple DMA requests into a continuous first physical address, and more quickly achieve the conversion from the first physical address to the second physical address.

[0057] Furthermore, the hardware driver of IOMMU is implemented in the Rust language, and the Rust language has a memory safety mechanism, which can improve the security of the computer system where IOMMU is located.

[0058] Optionally, there is at least one target device; step 202 may include:

[0059] Sub-step 2031: According to the device identifier of the target device, control the input / output memory management unit to obtain the device context of the target device in the device directory table; the device directory table is used to store the device context of each device, each target device has a unique device identifier, and the device context is used to store the device parameters related to the address mapping relationship; the device directory table includes a single-level device directory table.

[0060] Since there can be more than one target device on a target equipment, and different target devices may access different physical memory areas. To ensure that the first physical address in the DMA operation of different target devices can be correctly mapped to their respective matching second physical addresses, each target equipment has a data structure called Device Context (DC). DC can be used to store the device parameters related to the operation of the target device, including the device parameters related to the address mapping relationship. Through DC, a page table can be specified for the target equipment; the DCs of multiple target devices are stored in a data structure called the device directory table. The device directory table is stored in the memory of the target equipment when the target equipment is started. When a virtual machine is created, the device context of the target device related to the virtual machine is stored in the device directory table by the virtual machine monitor.

[0061] Through the unique device identifier of each device, the IOMMU can find the DC of the target device performing the DMA operation in the device directory table, obtain the device parameters related to the address mapping relationship in the DC, and obtain the page table through at least a part of these device parameters.

[0062] Optionally, the target device includes a platform device and a PCI device / PCIe device; the device identifier of the platform device is specified when the platform device is connected to the target equipment, and the device identifier of the PCI device / PCIe device is specified by the BDF number of the PCI device / PCIe device; the platform device includes non-PCI devices / PCIe devices installed when the target equipment leaves the factory, and the PCI device / PCIe device includes devices that conform to the PCI / PCIe standard.

[0063] The device identifier is used to uniquely specify a device. In the embodiments of the present application, the target device includes a platform device and a PCI device / PCIe device. For these two types of devices, the device identifier can be specified in different ways.

[0064] For platform devices, i.e., non-PCI devices / PCIe devices installed on the target device at the time of factory shipment, such as interfaces like SPI, IIC, UART, ADC, etc., they are assigned fixed device identifiers when connected to the target device at the factory. Since platform devices generally cannot be separated from the target device after leaving the factory, fixed device identifiers can be configured for them.

[0065] For PCI devices / PCIe devices, i.e., devices compliant with the Peripheral Component Interconnect Express / Peripheral Component Interconnect Express (PCI / PCIe) standard, such as network adapters, hard disk drives, etc., these devices connected to the target device have unique Bus, Device, Function (BDF) numbers, that is, the BDF numbers respectively include the bus number, device number, and function number. The combination of these three numbers can identify a specific PCI / PCIe device, so it can be used as a device identifier.

[0066] Sub-step 2032: Obtain the starting physical address of the page table in the device context.

[0067] Sub-step 2033: Read the address mapping relationship stored in the page table in the memory according to the starting physical address.

[0068] Sub-steps 2032 - 2033 describe the process of obtaining the address mapping relationship based on the device context. The device context includes the base address of the page table of the target device, that is, the starting physical address of the page table in the memory. When creating a virtual machine, the page table is saved into the memory, and its position in the memory does not change dynamically. Therefore, once the starting physical address of the page table is determined, the complete page table can be read from the starting physical address in the memory of the target device, and further the complete address mapping relationship can be obtained.

[0069] Step 204: Obtain the first physical address through the input / output memory management unit.

[0070] Step 205: Through the input / output memory management unit, determine the second physical address that matches the first physical address according to the address mapping relationship between the physical addresses in the pre-configured first address range and the physical addresses in the second address range.

[0071] Steps 204 - 205 describe the process of converting the first physical address to the second physical address through the IOMMU. By using the IOMMU, a hardware component, to perform the conversion from the first physical address to the second physical address, the direct memory access operation of the DMA device is restricted. This ensures that the DMA device can only access the physical memory resources allocated to the virtual machine. Compared with a pure software implementation method such as a virtual machine monitor, the conversion process from the first physical address to the second physical address can be completed more quickly, guaranteeing the isolation of the virtual machine in the target device and the real-time performance of the target device.

[0072] For the case where the target device is an embedded system, restricting the direct memory access operation of the DMA device through the IOMMU is an optimal solution that takes into account both isolation and real-time performance.

[0073] Exemplarily, for the application scenario of an automobile, the automobile has a controller, which is equivalent to the target device in the embodiments of the present application. If a virtual machine related to vehicle safety, such as a virtual machine for performing chassis control tasks, and a virtual machine for ordinary operation feedback, such as a virtual machine for performing seat adjustment tasks, are running simultaneously on the controller. In such a case, simply ensuring the isolation between the two virtual machines is not enough; although the conversion from the virtual physical address of the virtual machine to the actual physical address of the virtual machine can ensure that the virtual machine does not directly access illegal memory, it cannot guarantee that the virtual machine indirectly accesses illegal memory through the DMA device on the controller, thus damaging the stability of the system. Although the virtual machine monitor can prevent the virtual machine from indirectly accessing illegal memory through the DMA device on the controller, it will introduce a longer time overhead. For a scenario like an automobile that has high requirements for real-time performance, a longer time overhead means a higher security risk, which is unacceptable.

[0074] By introducing the IOMMU hardware and using the method provided in the embodiments of the present application, when the target device on the controller performs a DMA operation, the target device can only access the physical memory allocated to the corresponding virtual machine, guaranteeing the isolation between the virtual machines on the controller. At the same time, the IOMMU does not introduce significant time overhead, enabling the controller of the automobile to complete related tasks within an acceptable time, guaranteeing the real-time performance of the controller. For the application scenario of an automobile, converting the first physical address to the second physical address through the IOMMU ensures both the real-time performance of the controller in the automobile and the isolation between the virtual machines in the controller, further guaranteeing the safety of the automobile.

[0075] Step 206: Through the target device, perform a direct memory access operation on the memory according to the second physical address, and send the result of the direct memory access to the virtual machine.

[0076] This step has been described in step 103 above and will not be elaborated here.

[0077] Optionally, after step 205, it may further include:

[0078] Step 207: When the first physical address cannot be mapped to the second physical address one by one according to the address mapping relationship, a page fault warning is issued, and the virtual machine monitor is controlled to take over the direct storage access operation.

[0079] Since in the embodiment of the present application, the process of mapping the first physical address to the second physical address and the process of mapping the virtual physical address to the actual physical address of the virtual machine can share the same page table, the exceptions in the process of mapping the first physical address to the second physical address in the embodiment of the present application can be captured and processed during the process of mapping the virtual physical address to the actual physical address of the virtual machine. Among them, when the first physical address is not mapped to the second physical address by the page table, that is, when the first physical address cannot be mapped to the second physical address one by one according to the address mapping relationship, a page fault (Guest Page Fault) is triggered, a corresponding warning is issued, and the virtual machine monitor is notified to take over the DMA operation of the DMA device, that is, to enter the virtual machine monitor to handle the exception.

[0080] Optionally, step 207 may include:

[0081] Sub-step 2071: Control the virtual machine monitor to end the operation of the virtual machine.

[0082] After creating a virtual machine and configuring the page table, the page table no longer changes dynamically, and the address mapping relationship is pre-configured. If a page fault is triggered due to DMA during the subsequent operation of the virtual machine, it indicates that there is a malicious program in the virtual machine. To ensure the security of the target device, the virtual machine monitor can directly end the operation of the corresponding virtual machine.

[0083] In the embodiment of the present application, by mapping the first physical address in the direct storage access request sent by the virtual machine to the direct storage access device to the second physical address actually allocated for the virtual machine to use, and enabling the direct storage access device to perform the direct storage access operation according to the second physical address, the physical memory accessible by the direct storage access device is restricted to the physical memory allocated to the virtual machine, so that the direct storage access is restricted, avoiding the malicious use of the direct storage access device by the virtual machine to access the memory resources that do not belong to the virtual machine; by preventing the virtual machine from using the direct storage access device to access the physical memory occupied by other virtual machines, the isolation between virtual machines is ensured, thereby improving the security of the target device.

[0084] Figure 3It is a block diagram of a direct storage access device 30 for a virtual machine provided by an embodiment of the present application. The virtual machine is deployed on a target device. The device 30 includes:

[0085] A receiving module 301: configured to receive a direct storage access request sent by the virtual machine through a target device in the target device; the direct storage access request includes a first physical address for a direct storage access operation; the target device is a device with direct storage access function, and the first physical address belongs to a first address range; the first address range includes an address range allocated for use by the virtual machine;

[0086] A mapping module 302: configured to determine a second physical address matching the first physical address according to an address mapping relationship between physical addresses of a first address range and physical addresses of a second address range configured in advance; the second address range is an address range allocated for use by the virtual machine;

[0087] An execution module 303: configured to perform a direct storage access operation on the memory according to the second physical address through the target device, and send the result of the direct storage access to the virtual machine.

[0088] Optionally, the address mapping relationship is stored in a page table, and the page table is the same page table used in the process of mapping the virtual physical address of the virtual machine to the actual physical address of the virtual machine.

[0089] Optionally, the target device includes an input / output memory management unit, and the input / output memory management unit is arranged between the target device and the memory. The mapping module 302 may include:

[0090] An obtaining sub-module: configured to obtain the first physical address through the input / output memory management unit;

[0091] A mapping execution sub-module: configured to determine a second physical address matching the first physical address through the input / output memory management unit according to an address mapping relationship between physical addresses of a first address range and physical addresses of a second address range configured in advance.

[0092] Optionally, the target device includes an input / output memory management unit, and the input / output memory management unit is arranged between the target device and the memory. The device 30 further includes:

[0093] A page table initialization module: configured to save the page table in the memory through a virtual machine monitor when creating the virtual machine;

[0094] Mapping acquisition module: used to obtain the address mapping relationship saved in the page table from the memory through the input / output memory management unit.

[0095] Optionally, the mapping acquisition module may include:

[0096] Device context acquisition unit: used to control the input / output memory management unit to obtain the device context of the target device in the device directory table according to the device identifier of the target device; the device directory table is used to save the device context of each device, each target device has a unique device identifier, and the device context is used to save the device parameters related to the address mapping relationship; the device directory table includes a single-level device directory table.

[0097] Starting physical address acquisition unit: used to obtain the starting physical address of the page table in the device context.

[0098] Mapping acquisition unit: used to read the address mapping relationship stored in the page table in the memory according to the starting physical address.

[0099] Optionally, the target device includes a platform device and a PCI device / PCIe device; the device identifier of the platform device is specified when the platform device accesses the target device, and the device identifier of the PCI device / PCIe device is specified by the BDF number of the PCI device / PCIe device; the platform device includes non-PCI devices / PCIe devices installed when the target device leaves the factory, and the PCI device / PCIe device includes devices that conform to the PCI / PCIe standard.

[0100] Optionally, device 30 may further include:

[0101] Exception module: used to issue a page fault exception warning and control the virtual machine monitor to take over the direct storage access operation when the first physical address cannot be mapped to the second physical address one by one according to the address mapping relationship.

[0102] Optionally, the exception module may include:

[0103] Stop sub-module: used to control the virtual machine monitor to end the operation of the virtual machine.

[0104] In the embodiments of the present application, by mapping the first physical address in the direct storage access request sent by the virtual machine to the direct storage access device to the second physical address actually allocated for the virtual machine to use, and enabling the direct storage access device to perform the direct storage access operation according to the second physical address, the physical memory accessible by the direct storage access device is restricted to the physical memory allocated to the virtual machine, so that the direct storage access is restricted, avoiding malicious use of the direct storage access device by the virtual machine to access the memory resources that do not belong to the virtual machine; by preventing the virtual machine from using the direct storage access device to access the physical memory occupied by other virtual machines, the isolation between virtual machines is ensured, thereby enhancing the security of the target device.

[0105] For the apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference may be made to the partial description of the method embodiments.

[0106] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the various embodiments may be referred to each other.

[0107] Regarding the apparatus in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here in detail.

[0108] The embodiments of the present application provide a direct storage access device for a virtual machine, including a memory, and more than one program, where the more than one program is stored in the memory and is configured to be executed by more than one processor. The more than one program includes those for performing the methods described in the above one or more embodiments.

[0109] Figure 4 It is a block diagram of an electronic device 400 shown according to an exemplary embodiment. For example, the electronic device 400 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0110] Referring to Figure 4 , the electronic device 400 may include one or more of the following components: a processing component 402, a memory 404, a power component 406, a multimedia component 408, an audio component 410, an input / output (I / O) interface 412, a sensor component 414, and a communication component 416.

[0111] The processing component 402 generally controls the overall operation of the electronic device 400, such as operations associated with display, telephone calls, data communication, camera operations, and recording operations. The processing component 402 may include one or more processors 420 to execute instructions to complete all or part of the steps of the above methods. In addition, the processing component 402 may include one or more modules to facilitate the interaction between the processing component 402 and other components. For example, the processing component 402 may include a multimedia module to facilitate the interaction between the multimedia component 408 and the processing component 402.

[0112] The memory 404 is used to store various types of data to support the operation of the electronic device 400. Examples of such data include instructions for any application or method operating on the electronic device 400, contact data, phone book data, messages, pictures, multimedia, and the like. The memory 404 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disks, or optical disks.

[0113] The power component 406 provides power to various components of the electronic device 400. The power component 406 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device 400.

[0114] The multimedia component 408 includes a screen that provides an output interface between the electronic device 400 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can not only sense the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operations. In some embodiments, the multimedia component 408 includes a front camera and / or a rear camera. When the electronic device 400 is in an operating mode, such as a shooting mode or a multimedia mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0115] The audio component 410 is used to output and / or input audio signals. For example, the audio component 410 includes a microphone (MIC) that is used to receive external audio signals when the electronic device 400 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signal can be further stored in the memory 404 or sent via the communication component 416. In some embodiments, the audio component 410 further includes a speaker for outputting audio signals.

[0116] The I / O interface 412 provides an interface between the processing component 402 and a peripheral interface module, and the peripheral interface module may be a keyboard, a click wheel, buttons, etc. These buttons may include, but are not limited to: a home button, a volume button, a start button, and a lock button.

[0117] The sensor component 414 includes one or more sensors for providing status assessments of various aspects of the electronic device 400. For example, the sensor component 414 can detect the on / off state of the electronic device 400, the relative positioning of components, such as the display and keypad of the electronic device 400. The sensor component 414 can also detect a change in the position of the electronic device 400 or a component of the electronic device 400, the presence or absence of user contact with the electronic device 400, the orientation or acceleration / deceleration of the electronic device 400, and the temperature change of the electronic device 400. The sensor component 414 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 414 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 414 can further include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0118] The communication component 416 is used to facilitate communication between the electronic device 400 and other devices in a wired or wireless manner. The electronic device 400 can access a wireless network based on a communication standard, such as WiFi, a carrier network (such as 2G, 3G, 4G, or 5G), or a combination thereof. In an exemplary embodiment, the communication component 416 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 416 further includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0119] In an exemplary embodiment, the electronic device 400 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for implementing the method provided by the embodiments of the present application.

[0120] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 404 including instructions, and the above instructions can be executed by a processor 420 of the electronic device 400 to complete the above method. For example, the non-transitory storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0121] Figure 5 FIG. 500 is a block diagram of an electronic device 500 shown according to an exemplary embodiment. For example, the electronic device 500 may be provided as a server. Referring to Figure 5 FIG. 500, the electronic device 500 includes a processing component 522, which further includes one or more processors, and memory resources represented by a memory 532 for storing instructions executable by the processing component 522, such as application programs. The application programs stored in the memory 532 may include one or more modules each corresponding to a set of instructions. In addition, the processing component 522 is configured to execute instructions to perform the method provided by the embodiments of the present application.

[0122] The electronic device 500 may further include a power supply component 526 configured to perform power management of the electronic device 500, a wired or wireless network interface 550 configured to connect the electronic device 500 to a network, and an input / output (I / O) interface 558. The electronic device 500 may operate based on an operating system stored in the memory 532, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSD TM, or the like.

[0123] The embodiments of the present application also provide a computer program product including a computer program, and the computer program implements the method described in the above embodiments when executed by a processor.

[0124] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the application disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only to be considered exemplary, and the true scope and spirit of the present application are pointed out by the following claims.

[0125] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.

Claims

1. A method for direct storage access of a virtual machine, characterized in that: The virtual machine is deployed on a target device, and the method includes: receiving a direct storage access request issued by the virtual machine through a target device in the target apparatus; the direct storage access request includes a first physical address for a direct storage access operation; the target device is a device having a direct storage access function, the first physical address belongs to a first address range; the first address range includes an address range not allocated to the virtual machine for use; Determine a second physical address matching the first physical address according to a preconfigured address mapping relationship between a physical address in a first address range and a physical address in a second address range; the second address range is an address range allocated to the virtual machine for use; A direct storage access operation is performed on the memory according to the second physical address through the target device, and a result of the direct storage access is sent to the virtual machine.

2. The method according to claim 1, characterized in that The address mapping relationship is stored in a page table, and the page table is the same as the page table used in the process of mapping the virtual physical address of the virtual machine to the actual physical address of the virtual machine.

3. The method according to claim 1, characterized in that The target device includes an input / output memory management unit, and the input / output memory management unit is arranged between the target device and the memory; according to a pre-configured one-to-one address mapping relationship between physical addresses in a first address range and physical addresses in a second address range, determining a second physical address matching the first physical address includes: Acquire the first physical address through the input / output memory management unit; The input / output memory management unit determines a second physical address that matches the first physical address according to a preconfigured address mapping relationship between physical addresses in the first address range and physical addresses in the second address range.

4. The method according to claim 1, characterized in that: The target device includes an input / output memory management unit, and the input / output memory management unit is arranged between the target device and the memory; The address mapping relationship is stored in a page table; The method further comprises: When creating the virtual machine, storing the page table in the memory through a virtual machine monitor; Before the step of mapping the first physical addresses to matching second physical addresses one by one according to the pre-configured address mapping relationship, the method further comprises: The address mapping relationship stored in the page table is obtained from the memory through the input / output memory management unit.

5. The method according to claim 4, characterized in that The target device has at least one; the step of obtaining the address mapping relationship stored in the page table from the memory through the input / output memory management unit includes: According to the device identifier of the target device, the input / output memory management unit is controlled to obtain the device context of the target device in the device directory table; the device directory table is used to store the device context of each device, each target device has a unique device identifier, and the device context is used to store device parameters related to the address mapping relationship; the device directory table includes a single-level device directory table; Obtaining a starting physical address of the page table in the device context; The address mapping relationship stored in the page table is read in the memory according to the starting physical address.

6. The method according to claim 5, characterized in that The target device includes a platform device and a PCI device / PCIe device; the device identifier of the platform device is specified when the platform device is connected to the target device, and the device identifier of the PCI device / PCIe device is specified by the BDF number of the PCI device / PCIe device; the platform device includes a non-PCI device / PCIe device equipped with the target device when it leaves the factory, and the PCI device / PCIe device includes a device that complies with the PCI / PCIe standard.

7. The method according to claim 1, characterized in that The method further comprises: In the case where the first physical address cannot be mapped one-to-one to the second physical address according to the address mapping relationship, a page fault exception alarm is issued, and the virtual machine monitor is controlled to take over the direct storage access operation.

8. The method according to claim 7, characterized in that The controlling the virtual machine monitor to take over the direct storage access operation includes: The virtual machine monitor is controlled to terminate the operation of the virtual machine.

9. A direct storage access device for a virtual machine, characterized in that: The virtual machine is deployed on a target device, and the apparatus comprises: A receiving module: used for receiving a direct storage access request issued by the virtual machine through a target device in the target equipment; the direct storage access request includes a first physical address for a direct storage access operation; the target device is a device with a direct storage access function, the first physical address belongs to a first address range; the first address range includes an address range that is not allocated to the virtual machine for use; A mapping module: used to determine a second physical address matching the first physical address according to a pre-configured address mapping relationship between a physical address in a first address range and a physical address in a second address range; the second address range is an address range allocated to the virtual machine for use; An execution module is used to perform a direct storage access operation on the memory according to the second physical address through the target device, and send the result of the direct storage access to the virtual machine.

10. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that: When the instructions in the computer storable medium are executed by a processor of an electronic device, the electronic device is enabled to perform the method as claimed in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Process monitoring method and device

    CN109583190A

  • Memory protection unit in a virtual processing environment

    US20140108701A1