A Communication Method, Device, Equipment and Medium between Jailhouse-Hypervisor and SPM

Through the interaction of SMC and ERET instruction between Jailhouse Hypervisor and SPM, the problem of inefficient SPM communication between Jailhouse Hypervisor and ARM EL3 is solved, efficient information interaction and resource management are achieved, and hardware costs are reduced.

CN119645689BActive Publication Date: 2025-07-08KYLIN CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510181267.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-07-08
Estimated Expiration
2045-02-19

AI Technical Summary

Technical Problem

In the prior art, the lack of efficient and reliable communication methods between Jailhouse Hypervisor and the SPM of ARM EL3 has resulted in inefficient information interaction and resource management between the secure world and the ordinary world, increasing hardware costs.

Method used

By creating a business virtual machine in the ordinary world and converting the authentication request into SMC instructions to send it to SPM, the SPM generates ERET instructions after performing the authentication operation, and implementing information interaction between Jailhouse Hypervisor and SPM; creating a secure virtual machine in the secure world, receiving and processing SMC instructions from Jailhouse Hypervisor, generating ERET instructions for information interaction.

Benefits of technology

实现了Jailhouse Hypervisor与SPM之间的高效鉴权过程,提高了资源隔离和信息交互效率,降低了硬件成本。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119645689B_ABST
    Figure CN119645689B_ABST
Patent Text Reader

Abstract

The present invention relates to a communication method, apparatus, device, and medium between Jailhouse-Hypervisor and SPM. The method includes: creating at least one service virtual machine in the non-secure world; converting an authentication request of a current service program into an SMC instruction and sending the SMC instruction to the SPM, so that the SPM sends the authentication content carried in the SMC instruction to a target authentication program, and generates an ERET instruction after the target authentication program performs an authentication operation according to the authentication content; receiving the ERET instruction from the SPM and sending the authentication result carried in the ERET instruction to the current service program. By using this method, information interaction between Jailhouse Hypervisor and SPM can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer systems, and particularly relates to a communication method, device, equipment and medium between Jailhouse-Hypervisor and SPM. Background Art

[0002] Jailhouse is a semi-virtualized lightweight virtualization solution. Jailhouse focuses on the partitioning of hardware resources rather than the sharing and virtualization of hardware resources, so it can minimize the overhead and latency introduced by virtualization. According to business requirements, Jailhouse can allocate resources such as CPU, memory, device interfaces, and interrupts before running, and ensure the security and independence of resource allocation during operation, realizing the division of a multi-core CPU into multiple independent running environments. Each running environment can run different operating systems and deploy different services.

[0003] The ARM architecture introduced the TrustZone technology, which achieved higher security by dividing the system into a secure world and a normal world. On this basis, the ARM EL3 level allows developers to run a Secure Partition Manager (SPM) at the highest privilege level to manage and coordinate the security functions of the system. The Arm A-profile firmware framework (hereinafter referred to as FF-A) describes a software architecture aimed at achieving the following goals: applying virtualization extensions to isolate software images provided by different vendors; describing interfaces for standardizing communication between various software images, including communication between images in the secure world and the normal world. The main components of Arm FF-A are as follows: a Partition Manager (PM), which is a hypervisor in the normal world and a Secure Partition Manager (SPM) in the secure world. One or more sandbox partitions created by the PM, which can be VMs in the normal world or the secure world. A VM in the secure world is called a Secure Partition (SP).

[0004] The GP standard clearly defines the interfaces provided to Client Applications (CAs) and Trust Applications (TAs) for invocation on the REE (Rich Execution Environment, the business execution environment. Relative to the TEE, it is the traditional server running environment.) side and the TEE (Trusted Execution Environment, a trusted environment based on an isolation mechanism (usually based on a hardware architecture) to protect confidential data, relative to the REE) side, including the function names, functions, parameter descriptions, return values, etc. of the interface functions. During the development of CAs and TAs, it is necessary to follow the interfaces defined by the GP standard to implement communication and data transfer between TAs and CAs.

[0005] In many business scenarios, authentication, certification, and other operations are carried out in the secure world. When Jailhouse is not running, the secure world can only communicate with the only operating system in the normal world. Running only one operating system greatly wastes hardware performance and increases hardware costs.

[0006] After Jailhouse runs, although multiple operating systems can run in the normal world, in the existing technology, there is a lack of an efficient and reliable method for communication between the Jailhouse Hypervisor and the SPM of ARM EL3. This communication is crucial for realizing information interaction and resource management between the secure world and the normal world. Summary of the Invention

[0007] Based on this, in view of the above technical problems, it is necessary to provide a communication method, device, equipment, and medium for Jailhouse-Hypervisor and SPM to realize information interaction between the Jailhouse Hypervisor and the SPM.

[0008] In a first aspect, the present invention provides a communication method for Jailhouse-Hypervisor and SPM, which is applicable to Jailhouse-Hypervisor. The method includes:

[0009] Create at least one business virtual machine in the normal world; the business virtual machine includes an operating system and a business program running on the operating system; there is a unique corresponding authentication program for each business program in the secure world;

[0010] Convert the authentication request of the current business program into an SMC instruction and send the SMC instruction to the SPM, so that the SPM sends the authentication content carried by the SMC instruction to the target authentication program, and an ERET instruction is generated after the target authentication program performs an authentication operation according to the authentication content; the authentication request includes authentication content and a secure virtual machine identifier;

[0011] Receive the ERET instruction from the SPM and send the authentication result carried by the ERET instruction to the current business program.

[0012] In one embodiment, converting the authentication request of the current business program into an SMC instruction and sending the SMC instruction to the SPM includes:

[0013] Receive the HVC instruction generated when the business program calls the TEE driver of its operating system to initiate an authentication request;

[0014] Convert the HVC instruction into an SMC instruction;

[0015] Send the SMC instruction to the SPM.

[0016] In one embodiment, the service program runs on EL0 of the ARM architecture, the operating system of the service virtual machine runs on EL1 of the ARM architecture, and Jailhouse-Hypervisor runs on EL2 of the ARM architecture; sending the authentication result carried by the ERET instruction to the current service program includes:

[0017] Parse the ERET instruction to obtain the authentication result and the service virtual machine identifier;

[0018] Determine the target service virtual machine according to the service virtual machine identifier;

[0019] Switch from EL2 to EL1 through the ERET instruction, and send the authentication result to the TEE driver of the operating system of the target service virtual machine;

[0020] The TEE driver of the operating system switches from EL1 to EL0 through the ERET instruction, and sends the authentication result to the current service program.

[0021] In a second aspect, the present invention provides a communication method between Jailhouse-Hypervisor and SPM, which is applicable to the SPM. The method includes:

[0022] Create at least one secure virtual machine in the secure world; the secure virtual machine includes an operating system and an authentication program running on the operating system; each authentication program has a unique corresponding service program in the normal world;

[0023] Receive the SMC instruction from Jailhouse-Hypervisor, and send the authentication content carried by the SMC instruction to the target authentication program;

[0024] After the target authentication program performs the authentication operation according to the authentication content, send the ERET instruction carrying the authentication result and the service virtual machine identifier to Jailhouse-Hypervisor, so that Jailhouse-Hypervisor sends the authentication result carried by the ERET instruction to the current service program.

[0025] In one embodiment, the authentication program runs on SEL0 of the ARM architecture, the operating system of the secure virtual machine runs on SEL1 of the ARM architecture, and the SPM runs on SEL3 of the ARM architecture; sending the authentication content carried by the SMC instruction to the target authentication program includes:

[0026] Parse the SMC instruction to obtain the authentication content and the authentication virtual machine identifier;

[0027] Determine the target authentication virtual machine according to the authentication virtual machine identifier;

[0028] Through the ERET instruction, switch from SEL3 to SEL1 and send the authentication content to the operating system of the target authentication virtual machine;

[0029] The operating system of the target authentication virtual machine switches from SEL1 to SEL0 through the ERET instruction and sends the authentication content to the target authentication program.

[0030] In one embodiment, after the target authentication program performs an authentication operation according to the authentication content, send an ERET instruction carrying the authentication result to Jailhouse-Hypervisor, including:

[0031] Receive an SMC instruction carrying the authentication result from the target authentication program;

[0032] Parse the SMC instruction to obtain the authentication result;

[0033] Generate an ERET instruction carrying the authentication result;

[0034] Send the ERET instruction carrying the authentication result to Jailhouse-Hypervisor.

[0035] In a third aspect, the present invention also provides a communication device between Jailhouse-Hypervisor and SPM, applicable to Jailhouse-Hypervisor, and the device includes:

[0036] The first creation module is used to create at least one business virtual machine in the normal world;

[0037] The first sending module is used to convert the authentication request of the current service program into an SMC instruction and send the SMC instruction to the SPM, so that the SPM sends the authentication content carried in the SMC instruction to the target authentication program, and generates an ERET instruction after the target authentication program performs an authentication operation according to the authentication content;

[0038] The first receiving module is used to receive the ERET instruction from the SPM and send the authentication result carried in the ERET instruction to the current service program.

[0039] In a fourth aspect, the present invention also provides a communication device between Jailhouse-Hypervisor and SPM, applicable to SPM, and the device includes:

[0040] The second creation module is used to create at least one security virtual machine in the secure world;

[0041] A second receiving module, configured to receive SMC instructions from Jailhouse-Hypervisor and send the authentication content carried in the SMC instructions to a target authentication program;

[0042] A second sending module, configured to, after the target authentication program performs an authentication operation according to the authentication content, send an ERET instruction carrying the authentication result and the service virtual machine identifier to Jailhouse-Hypervisor, so that Jailhouse-Hypervisor sends the authentication result carried in the ERET instruction to the current service program.

[0043] In a fifth aspect, the present invention further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0044] Create at least one service virtual machine in the normal world; the service virtual machine includes an operating system and a service program running on the operating system; each service program has a unique corresponding authentication program in the secure world;

[0045] Convert the authentication request of the current service program into an SMC instruction and send the SMC instruction to the SPM, so that the SPM generates an ERET instruction after sending the authentication content carried in the SMC instruction to the target authentication program and the target authentication program performs an authentication operation according to the authentication content; the authentication request includes authentication content and a secure virtual machine identifier;

[0046] Receive the ERET instruction from the SPM and send the authentication result carried in the ERET instruction to the current service program.

[0047] In a sixth aspect, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:

[0048] Create at least one service virtual machine in the normal world; the service virtual machine includes an operating system and a service program running on the operating system; each service program has a unique corresponding authentication program in the secure world;

[0049] Convert the authentication request of the current service program into an SMC instruction and send the SMC instruction to the SPM, so that the SPM generates an ERET instruction after sending the authentication content carried in the SMC instruction to the target authentication program and the target authentication program performs an authentication operation according to the authentication content; the authentication request includes authentication content and a secure virtual machine identifier;

[0050] Receive the ERET instruction from the SPM and send the authentication result carried in the ERET instruction to the current service program.

[0051] In the above communication method, apparatus, device, and medium between Jailhouse-Hypervisor and SPM, Jailhouse-Hypervisor creates at least one service virtual machine in the normal world, achieving resource isolation; converts the authentication request of the current service program into an SMC instruction and sends the SMC instruction to SPM, so that SPM sends the authentication content carried in the SMC instruction to the target authentication program, and after the target authentication program performs an authentication operation according to the authentication content, generates an ERET instruction, enabling information interaction between Jailhouse-Hypervisor and SPM through the SMC instruction; receives the ERET instruction from SPM and sends the authentication result carried in the ERET instruction to the current service program, thereby completing the authentication process between Jailhouse-Hypervisor and SPM. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] To more clearly illustrate the technical solutions in the embodiments of the present invention or related technologies, the following will briefly introduce the drawings required for describing the embodiments of the present invention or related technologies. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0053] Figure 1 It is a schematic flowchart of the communication method between Jailhouse-Hypervisor and SPM in one embodiment;

[0054] Figure 2 It is an internal structure diagram of a computer device in one embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Many specific details are set forth in the following description to fully understand the present invention, but the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar promotions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0056] In an alternative embodiment, taking Jailhouse-Hypervisor as the execution entity, a communication method between Jailhouse-Hypervisor and SPM is provided. In this embodiment, the method includes the following steps:

[0057] S110, create at least one service virtual machine in the normal world.

[0058] Among them, relative to the secure world, the normal world (also known as the non-secure world) can be understood as a general operating area, where conventional operating systems and application programs run to handle tasks such as daily computing and business logic. The secure world and the normal world are isolated from each other. The secure world can be understood as an area with a higher security level, which is used to handle sensitive operations and security-related tasks, such as encryption tasks and authentication tasks.

[0059] In the normal world, Jailhouse-Hypervisor is used to create and manage business virtual machines in the normal world. A business virtual machine can be understood as a virtual machine used to run specific business software and handle business logic. A business virtual machine may include an operating system and business programs running on the operating system. A business program can be understood as an application program used to implement specific business functions. Each business program has a unique corresponding authentication program in the secure world. An authentication program can be understood as an application program used for verification, such as verifying identity and permissions.

[0060] S120, convert the authentication request of the current business program into an SMC instruction, and send the SMC instruction to the SPM, so that the SPM sends the authentication content carried by the SMC instruction to the target authentication program, and after the target authentication program executes the authentication operation according to the authentication content, an ERET instruction is generated.

[0061] Among them, the SMC (Supervisor Mode Call) instruction is generally used for switching between the normal world and the secure world to execute some operations or tasks that require a higher privilege level. The authentication content can be understood as information used for verification, such as a combination of username and password. The target authentication program can be understood as an authentication program that performs authentication operations according to the authentication content. The ERET (Exception Return) instruction is generally used for switching the privilege level of the processor. In the ARM architecture, the privilege levels in the normal world include: EL0 (application program running level), EL1 (operating system kernel running level), EL2 (virtualization-related running level), and EL3 (highest security privilege level); the privilege levels in the secure world include: SEL0 (basic security level), SEL1 (specific security operation level), SEL2 (security mechanism management level), and SEL3 (highest security control level).

[0062] Optionally, in the normal world of the ARM architecture, business programs can run on EL0, the operating system can run on EL1, and Jailhouse-Hypervisor can run on EL2; in the secure world of the ARM architecture, the authentication program can run on SEL0, the operating system can run on SEL1, and SPM can run on SEL3.

[0063] In an alternative embodiment, converting the authentication request of the current business program into an SMC instruction and sending the SMC instruction to the SPM includes:

[0064] Receiving the HVC instruction generated when the business program calls the TEE driver of its operating system to initiate an authentication request;

[0065] Converting the HVC instruction into an SMC instruction;

[0066] Sending the SMC instruction to the SPM.

[0067] Exemplarily, in the ARM architecture, for the business program CA1 on the business virtual machine VM0 in the normal world:

[0068] CA1 on EL0 will call the TEE driver (Trusted Execution Environment driver) in GuestOS1 (the operating system where CA1 is located) running on EL1 to initiate an authentication request. Specifically, the TEE driver can send an authentication request to the Jailhouse-Hypervisor on EL2 through the ARM HVC assembly instruction;

[0069] After receiving the HVC instruction, the Jailhouse-Hypervisor will forward the authentication request to the SPM running on EL3 through the ARM assembly instruction SMC, thereby switching the execution of the program to the secure world.

[0070] S130, receiving the ERET instruction from the SPM and sending the authentication result carried by the ERET instruction to the current business program.

[0071] In an alternative embodiment, sending the authentication result carried by the ERET instruction to the current business program includes:

[0072] Parsing the ERET instruction to obtain the authentication result and the business virtual machine identifier;

[0073] Determining the target business virtual machine according to the business virtual machine identifier;

[0074] Switch from EL2 to EL1 via the ERET instruction and send the authentication result to the TEE driver of the operating system of the target service virtual machine;

[0075] The TEE driver of the operating system switches from EL1 to EL0 via the ERET instruction and sends the authentication result to the current service program.

[0076] Among them, the service virtual machine identifier can be understood as the identifier information used to match the target service virtual machine.

[0077] In this embodiment, Jailhouse-Hypervisor creates at least one service virtual machine in the normal world, achieving resource isolation; converts the authentication request of the current service program into an SMC instruction and sends the SMC instruction to the SPM, so that the SPM sends the authentication content carried by the SMC instruction to the target authentication program, and after the target authentication program performs the authentication operation according to the authentication content, an ERET instruction is generated, enabling information interaction between Jailhouse-Hypervisor and the SPM through the SMC instruction; receives the ERET instruction from the SPM and sends the authentication result carried by the ERET instruction to the current service program, thereby completing the authentication process between Jailhouse-Hypervisor and the SPM.

[0078] In an alternative embodiment, with the SPM as the execution entity, a communication method between Jailhouse-Hypervisor and the SPM is provided. In this embodiment, the method includes the following steps:

[0079] S210, create at least one secure virtual machine in the secure world.

[0080] Among them, the secure virtual machine (also known as the secure partition) can be understood as a virtual machine used to process sensitive data and perform critical security operations.

[0081] S220, receive the SMC instruction from Jailhouse-Hypervisor and send the authentication content carried by the SMC instruction to the target authentication program.

[0082] In an alternative embodiment, sending the authentication content carried by the SMC instruction to the target authentication program includes:

[0083] Parse the SMC instruction to obtain the authentication content and the authentication virtual machine identifier;

[0084] Determine the target authentication virtual machine according to the authentication virtual machine identifier;

[0085] Switch from SEL3 to SEL1 via the ERET instruction and send the authentication content to the operating system of the target authentication virtual machine;

[0086] The operating system of the target authentication virtual machine switches from SEL1 to SEL0 via the ERET instruction and sends the authentication content to the target authentication program.

[0087] Among them, the authentication virtual machine identifier can be understood as the identifier information used to match the target authentication virtual machine. It should be noted that the ERET instruction cannot directly return from EL3 to EL0 because, according to the ARM exception level design, the processor needs to perform a hierarchical context switch through EL1 or EL2 to ensure that each exception level has the opportunity to handle tasks such as exceptions and status recovery.

[0088] Exemplarily, in the ARM architecture, for the authentication program TA1 on the secure virtual machine SP0 in the secure world:

[0089] The SPM will parse the SMC instruction from the Jailhouse-Hypervisor and determine the specific authentication content (e.g., request type) for the target authentication virtual machine (SP0);

[0090] Enter the TEE OS (the operating system where TA1 is located) in SEL1 through the arm assembly instruction ERET, and then enter SEL0 through ERET again, so as to send the authentication content to TA1;

[0091] TA1 can perform an authentication operation based on the authentication content and obtain an authentication result.

[0092] S230, after the target authentication program performs an authentication operation based on the authentication content, send the ERET instruction carrying the authentication result and the business virtual machine identifier to the Jailhouse-Hypervisor, so that the Jailhouse-Hypervisor sends the authentication result carried by the ERET instruction to the current business program.

[0093] In an alternative embodiment, sending the ERET instruction carrying the authentication result to the Jailhouse-Hypervisor includes:

[0094] Receive the SMC instruction carrying the authentication result from the target authentication program;

[0095] Parse the SMC instruction to obtain the authentication result;

[0096] Generate an ERET instruction carrying the authentication result;

[0097] Send the ERET instruction carrying the authentication result to the Jailhouse-Hypervisor.

[0098] In this embodiment, the SPM creates at least one secure virtual machine in the secure world, achieving resource isolation; receives SMC instructions from the Jailhouse-Hypervisor and sends the authentication content carried in the SMC instructions to the target authentication program, enabling the SPM to interact with the Jailhouse-Hypervisor; after the target authentication program performs an authentication operation based on the authentication content, it sends an ERET instruction carrying the authentication result and the business virtual machine identifier to the Jailhouse-Hypervisor, so that the Jailhouse-Hypervisor sends the authentication result carried in the ERET instruction to the current business program, thereby completing the authentication process between the Jailhouse-Hypervisor and the SPM.

[0099] In an alternative embodiment, as Figure 1 shown, a communication method between the Jailhouse-Hypervisor and the SPM is provided. In this embodiment, the method includes the following steps:

[0100] S301, the service program CA1 on VM0 calls the TEE driver in GuestOS1 on EL1.

[0101] S302, the TEE driver in GuestOS1 on El1 issues an authentication request to the Jailhouse-Hypervisor on El2 through ARM HVC assembly instructions;

[0102] S303, after receiving the HVC instruction, the Jailhouse-Hypervisor forwards the authentication request to the SPM on EL3 through the ARM assembly instruction SMC, completing the switch of program execution to the secure world.

[0103] S304, the SPM parses the SMC instruction from the Jailhouse-Hypervisor and determines the specific request type and the target security partition (SP0).

[0104] S305, the SPM enters the TEE OS in SEL1 through the arm assembly instruction ERET, and then enters SEL0 through ERET, and sends the request type to SP0.

[0105] S306, the authentication program TA1 in SP0 authenticates CA1.

[0106] S307, sends the authentication result to the SPM through the SMC instruction.

[0107] In S308, the SPM directly sends the authentication result to the Jailhouse-Hypervisor in the normal world via the ERET instruction.

[0108] In S309, the Jailhouse-Hypervisor parses the ERET instruction from the SPM to determine the authentication result and the target service virtual machine (VM0).

[0109] In S310, the Jailhouse-Hypervisor sends the authentication result to the corresponding VM0 via the ERET instruction, which is received by the TEE driver in VM0.

[0110] In S311, the TEE driver in VM0 sends the authentication result to the corresponding CA program (CA1) via the ERET instruction, thus completing a complete authentication process.

[0111] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0112] Based on the same inventive concept, an embodiment of the present invention further provides a communication device between the Jailhouse-Hypervisor and the SPM for implementing the communication method between the Jailhouse-Hypervisor and the SPM involved above. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the communication device between the Jailhouse-Hypervisor and the SPM provided below can refer to the limitations on the method in the above text, and will not be elaborated here.

[0113] In an exemplary embodiment, a communication between the Jailhouse-Hypervisor and the SPM is provided, which is applicable to the Jailhouse-Hypervisor and includes: a first creation module, a first sending module, and a first receiving module, where:

[0114] The first creation module is used to create at least one service virtual machine in the non-secure world.

[0115] The first sending module is used to convert the authentication request of the current service program into an SMC instruction and send the SMC instruction to the SPM, so that the SPM sends the authentication content carried in the SMC instruction to the target authentication program, and generates an ERET instruction after the target authentication program performs the authentication operation according to the authentication content.

[0116] The first receiving module is used to receive the ERET instruction from the SPM and send the authentication result carried in the ERET instruction to the current service program.

[0117] In one embodiment, the first sending module includes: a first receiving unit, which is used to receive the HVC instruction generated when the service program calls the TEE driver of its operating system to initiate an authentication request; a first conversion unit, which is used to convert the HVC instruction into an SMC instruction; a first sending unit, which is used to send the SMC instruction to the SPM.

[0118] In one embodiment, the first receiving module includes: a first parsing unit, which is used to parse the ERET instruction to obtain the authentication result and the service virtual machine identifier; a first determining unit, which is used to determine the target service virtual machine according to the service virtual machine identifier; a second sending unit, which is used to switch from EL2 to EL1 through the ERET instruction and send the authentication result to the TEE driver of the operating system of the target service virtual machine; a third sending unit, which is used to switch from EL1 to EL0 through the ERET instruction by the TEE driver of the operating system and send the authentication result to the current service program.

[0119] In an exemplary embodiment, a communication between Jailhouse-Hypervisor and SPM is provided, which is applicable to the SPM and includes: a second creation module, a second receiving module and a second sending module, where:

[0120] The second creation module is used to create at least one secure virtual machine in the secure world;

[0121] The second receiving module is used to receive the SMC instruction from Jailhouse-Hypervisor and send the authentication content carried in the SMC instruction to the target authentication program;

[0122] The second sending module is used to send the ERET instruction carrying the authentication result and the service virtual machine identifier to Jailhouse-Hypervisor after the target authentication program performs the authentication operation according to the authentication content, so that Jailhouse-Hypervisor sends the authentication result carried in the ERET instruction to the current service program.

[0123] In one embodiment, the second receiving module includes: a second parsing unit configured to parse the SMC instruction to obtain the authentication content and the authentication virtual machine identifier; a second determining unit configured to determine a target authentication virtual machine according to the authentication virtual machine identifier; a fourth sending unit configured to switch from SEL3 to SEL1 through an ERET instruction and send the authentication content to the operating system of the target authentication virtual machine; and a fifth sending unit configured to enable the operating system of the target authentication virtual machine to switch from SEL1 to SEL0 through an ERET instruction and send the authentication content to the target authentication program.

[0124] In one embodiment, the second sending module includes: a second receiving unit configured to receive an SMC instruction carrying an authentication result from the target authentication program; a third parsing unit configured to parse the SMC instruction to obtain the authentication result; a first generating unit configured to generate an ERET instruction carrying the authentication result; and a sixth sending unit configured to send the ERET instruction carrying the authentication result to the Jailhouse-Hypervisor.

[0125] Each module in the above device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of a processor in a computer device in the form of hardware, or stored in a memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0126] In an exemplary embodiment, a computer device is provided, and its internal structural diagram can be as Figure 2 shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for communicating with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a communication method between the Jailhouse-Hypervisor and the SPM.

[0127] Those skilled in the art can understand thatFigure 2 The structure shown is only a block diagram of some structures related to the present invention, and does not constitute a limitation on the computer device to which the present invention is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different component layout.

[0128] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0129] Create at least one business virtual machine in the normal world; the business virtual machine includes an operating system and a business program running on the operating system; each business program has a unique corresponding authentication program in the secure world;

[0130] Convert the authentication request of the current business program into an SMC instruction, and send the SMC instruction to the SPM, so that the SPM sends the authentication content carried by the SMC instruction to the target authentication program, and an ERET instruction is generated after the target authentication program performs an authentication operation according to the authentication content; the authentication request includes authentication content and a secure virtual machine identifier;

[0131] Receive the ERET instruction from the SPM, and send the authentication result carried by the ERET instruction to the current business program.

[0132] In an embodiment, when the processor executes the computer program, the following steps are further implemented:

[0133] Receive the HVC instruction generated when the business program calls the TEE driver of its operating system to initiate an authentication request;

[0134] Convert the HVC instruction into an SMC instruction;

[0135] Send the SMC instruction to the SPM.

[0136] In an embodiment, when the processor executes the computer program, the following steps are further implemented:

[0137] Parse the ERET instruction to obtain the authentication result and the business virtual machine identifier;

[0138] Determine the target business virtual machine according to the business virtual machine identifier;

[0139] Switch from EL2 to EL1 through the ERET instruction, and send the authentication result to the TEE driver of the operating system of the target business virtual machine;

[0140] The TEE driver of the operating system uses the ERET instruction to switch from EL1 to EL0 and sends the authentication result to the current service program.

[0141] In one embodiment, when the processor executes the computer program, the following steps are also implemented:

[0142] Create at least one secure virtual machine in the secure world; the secure virtual machine includes an operating system and an authentication program running on the operating system; each authentication program has a unique corresponding service program in the normal world;

[0143] Receive the SMC instruction from the Jailhouse-Hypervisor and send the authentication content carried by the SMC instruction to the target authentication program;

[0144] After the target authentication program performs the authentication operation according to the authentication content, send the ERET instruction carrying the authentication result and the service virtual machine identifier to the Jailhouse-Hypervisor, so that the Jailhouse-Hypervisor sends the authentication result carried by the ERET instruction to the current service program.

[0145] In one embodiment, when the processor executes the computer program, the following steps are also implemented:

[0146] Parse the SMC instruction to obtain the authentication content and the authentication virtual machine identifier;

[0147] Determine the target authentication virtual machine according to the authentication virtual machine identifier;

[0148] Use the ERET instruction to switch from SEL3 to SEL1 and send the authentication content to the operating system of the target authentication virtual machine;

[0149] The operating system of the target authentication virtual machine uses the ERET instruction to switch from SEL1 to SEL0 and sends the authentication content to the target authentication program.

[0150] In one embodiment, when the processor executes the computer program, the following steps are also implemented:

[0151] Receive the SMC instruction carrying the authentication result from the target authentication program;

[0152] Parse the SMC instruction to obtain the authentication result;

[0153] Generate an ERET instruction carrying the authentication result;

[0154] Send the ERET instruction carrying the authentication result to the Jailhouse-Hypervisor.

[0155] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0156] Create at least one business virtual machine in the normal world; the business virtual machine includes an operating system and business programs running on the operating system; each business program has a unique corresponding authentication program in the secure world;

[0157] Convert the authentication request of the current business program into an SMC instruction, and send the SMC instruction to the SPM, so that the SPM sends the authentication content carried by the SMC instruction to the target authentication program, and an ERET instruction is generated after the target authentication program performs an authentication operation according to the authentication content; the authentication request includes authentication content and a secure virtual machine identifier;

[0158] Receive the ERET instruction from the SPM, and send the authentication result carried by the ERET instruction to the current business program.

[0159] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0160] Receive the HVC instruction generated when the business program calls the TEE driver of its operating system to initiate an authentication request;

[0161] Convert the HVC instruction into an SMC instruction;

[0162] Send the SMC instruction to the SPM.

[0163] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0164] Parse the ERET instruction to obtain the authentication result and the business virtual machine identifier;

[0165] Determine the target business virtual machine according to the business virtual machine identifier;

[0166] Switch from EL2 to EL1 through the ERET instruction, and send the authentication result to the TEE driver of the operating system of the target business virtual machine;

[0167] The TEE driver of the operating system switches from EL1 to EL0 through the ERET instruction, and sends the authentication result to the current business program.

[0168] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0169] Create at least one secure virtual machine in the secure world; the secure virtual machine includes an operating system and an authentication program running on the operating system; each authentication program has a unique corresponding business program in the normal world;

[0170] Receive an SMC instruction from the Jailhouse-Hypervisor, and send the authentication content carried in the SMC instruction to the target authentication program;

[0171] After the target authentication program performs an authentication operation according to the authentication content, send an ERET instruction carrying the authentication result and the business virtual machine identifier to the Jailhouse-Hypervisor, so that the Jailhouse-Hypervisor sends the authentication result carried in the ERET instruction to the current business program.

[0172] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0173] Parse the SMC instruction to obtain the authentication content and the authentication virtual machine identifier;

[0174] Determine the target authentication virtual machine according to the authentication virtual machine identifier;

[0175] Through the ERET instruction, switch from SEL3 to SEL1, and send the authentication content to the operating system of the target authentication virtual machine;

[0176] The operating system of the target authentication virtual machine switches from SEL1 to SEL0 through the ERET instruction, and sends the authentication content to the target authentication program.

[0177] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0178] Receive an SMC instruction carrying the authentication result from the target authentication program;

[0179] Parse the SMC instruction to obtain the authentication result;

[0180] Generate an ERET instruction carrying the authentication result;

[0181] Send the ERET instruction carrying the authentication result to the Jailhouse-Hypervisor.

[0182] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided by the present invention can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided by the present invention can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0183] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope recorded in the present invention.

[0184] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent for the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the appended claims.

Claims

1. A communication method between Jailhouse-Hypervisor and SPM, characterized in that Applicable to Jailhouse - Hypervisor, the method includes: Create at least one business virtual machine in the normal world; the business virtual machine includes an operating system and business programs running on the operating system; each business program has a unique corresponding authentication program in the secure world; Convert the authentication request of the current business program into an SMC instruction and send the SMC instruction to the SPM, so that the SPM sends the authentication content carried by the SMC instruction to the target authentication program, and an ERET instruction is generated after the target authentication program performs an authentication operation according to the authentication content; the authentication request includes authentication content and a secure virtual machine identifier; converting the authentication request of the current business program into an SMC instruction and sending the SMC instruction to the SPM includes: receiving an HVC instruction generated when the business program calls the TEE driver of its operating system to initiate an authentication request; converting the HVC instruction into an SMC instruction; sending the SMC instruction to the SPM; Receive the ERET instruction from the SPM and send the authentication result carried by the ERET instruction to the current business program; The business program runs on EL0 of the ARM architecture, the operating system of the business virtual machine runs on EL1 of the ARM architecture, and Jailhouse - Hypervisor runs on EL2 of the ARM architecture; sending the authentication result carried by the ERET instruction to the current business program includes: Parse the ERET instruction to obtain the authentication result and the business virtual machine identifier; Determine the target business virtual machine according to the business virtual machine identifier; Switch from EL2 to EL1 through the ERET instruction and send the authentication result to the TEE driver of the operating system of the target business virtual machine; The TEE driver of the operating system switches from EL1 to EL0 through the ERET instruction and sends the authentication result to the current business program.

2. A communication method between Jailhouse-Hypervisor and SPM, characterized in that, Applicable to SPM, the method includes: Create at least one secure virtual machine in the secure world; the secure virtual machine includes an operating system and authentication programs running on the operating system; each authentication program has a unique corresponding business program in the normal world; the authentication program runs on SEL0 of the ARM architecture, the operating system of the secure virtual machine runs on SEL1 of the ARM architecture, and SPM runs on SEL3 of the ARM architecture; sending the authentication content carried by the SMC instruction to the target authentication program includes: Parse the SMC instruction to obtain the authentication content and the authentication virtual machine identifier; Determine the target authentication virtual machine according to the authentication virtual machine identifier; Switch from SEL3 to SEL1 through the ERET instruction and send the authentication content to the operating system of the target authentication virtual machine; The operating system of the target authentication virtual machine switches from SEL1 to SEL0 through the ERET instruction and sends the authentication content to the target authentication program; Receive SMC instructions from the Jailhouse-Hypervisor and send the authentication content carried by the SMC instructions to the target authentication program; After the target authentication program performs an authentication operation based on the authentication content, send an ERET instruction carrying the authentication result and the business virtual machine identifier to the Jailhouse-Hypervisor, so that the Jailhouse-Hypervisor sends the authentication result carried by the ERET instruction to the current business program. After the target authentication program performs an authentication operation based on the authentication content, sending an ERET instruction carrying the authentication result to the Jailhouse-Hypervisor includes: Receive an SMC instruction carrying the authentication result from the target authentication program; Parse the SMC instruction to obtain the authentication result; Generate an ERET instruction carrying the authentication result; Send the ERET instruction carrying the authentication result to the Jailhouse-Hypervisor.

3. A communication device between Jailhouse-Hypervisor and SPM, characterized in that, Applicable to the Jailhouse-Hypervisor, the device includes: The first creation module is used to create at least one business virtual machine in the normal world; The first sending module is used to convert the authentication request of the current business program into an SMC instruction and send the SMC instruction to the SPM, so that the SPM generates an ERET instruction after sending the authentication content carried by the SMC instruction to the target authentication program and the target authentication program performs an authentication operation based on the authentication content; converting the authentication request of the current business program into an SMC instruction and sending the SMC instruction to the SPM includes: receiving the HVC instruction generated when the business program calls the TEE driver of its operating system to initiate an authentication request; converting the HVC instruction into an SMC instruction; sending the SMC instruction to the SPM; The first receiving module is used to receive the ERET instruction from the SPM and send the authentication result carried by the ERET instruction to the current business program; The business program runs on EL0 of the ARM architecture, the operating system of the business virtual machine runs on EL1 of the ARM architecture, and the Jailhouse-Hypervisor runs on EL2 of the ARM architecture; sending the authentication result carried by the ERET instruction to the current business program includes: Parse the ERET instruction to obtain the authentication result and the business virtual machine identifier; Determine the target business virtual machine according to the business virtual machine identifier; Switch from EL2 to EL1 through the ERET instruction and send the authentication result to the TEE driver of the operating system of the target business virtual machine; The TEE driver of the operating system switches from EL1 to EL0 through the ERET instruction and sends the authentication result to the current business program.

4. A communication device between Jailhouse-Hypervisor and SPM, characterized in that, Applicable to the SPM, the device includes: The second creation module is used to create at least one secure virtual machine in the secure world; The second receiving module is used to receive SMC instructions from Jailhouse-Hypervisor and send the authentication content carried by the SMC instructions to the target authentication program; the authentication program runs on SEL0 of the ARM architecture, the operating system of the secure virtual machine runs on SEL1 of the ARM architecture, and the SPM runs on SEL3 of the ARM architecture; the second receiving module includes: a second parsing unit for parsing the SMC instructions to obtain the authentication content and the authentication virtual machine identifier; a second determination unit for determining the target authentication virtual machine according to the authentication virtual machine identifier; a fourth sending unit for switching from SEL3 to SEL1 through the ERET instruction and sending the authentication content to the operating system of the target authentication virtual machine; a fifth sending unit for the operating system of the target authentication virtual machine to switch from SEL1 to SEL0 through the ERET instruction and send the authentication content to the target authentication program; The second sending module is used to send an ERET instruction carrying the authentication result and the service virtual machine identifier to Jailhouse-Hypervisor after the target authentication program performs an authentication operation according to the authentication content, so that Jailhouse-Hypervisor sends the authentication result carried by the ERET instruction to the current service program; The second sending module includes: a second receiving unit for receiving an SMC instruction carrying the authentication result from the target authentication program; a third parsing unit for parsing the SMC instruction to obtain the authentication result; a first generating unit for generating an ERET instruction carrying the authentication result; a sixth sending unit for sending the ERET instruction carrying the authentication result to Jailhouse-Hypervisor.

5. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 2 are implemented.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 2 are implemented.

Citation Information

Patent Citations

  • Vulnerability detection method and device

    CN113868673A

  • ARM (Advanced RISC Machines) TrustZone architecture for realizing secure world Jailhouse virtualization

    CN119201351A

  • Method and system for guiding jailhome to start based on authentication

    CN119396537A