Security control method and device for virtual machine and storage medium

By intercepting and securely verifying the access requests of virtual machine to virtual device status data in the kernel state component of the virtual machine manager, the problem of virtual device status data being easily tampered with is solved, reducing the security risks of virtual machines.

CN119960893AActive Publication Date: 2025-05-09HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202311474684.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-07
Publication Date
2025-05-09
Estimated Expiration
2043-11-07

AI Technical Summary

Technical Problem

Virtual device status data is vulnerable to attacks and tampered with in the user's state memory address space, resulting in an increase in the security risk of virtual machines.

Method used

Secure verification is performed by intercepting the virtual machine's access request to the virtual device status data in the kernel-state component of the virtual machine manager. If the verification is passed, the access request is forwarded to the user-state component for response.

Benefits of technology

Effectively prevent virtual device status data from being tampered with, reduce the security risks of virtual machines, and ensure that virtual machines access the untampered virtual device status data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119960893A_ABST
    Figure CN119960893A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a security control method and device for a virtual machine and a storage medium. In the embodiment of the invention, when a kernel mode component in a virtual machine manager intercepts an access request which is sent by any virtual machine on a host machine and aims at virtual equipment state data, the kernel mode component carries out security verification on the virtual equipment state data pointed by the access request, and after the virtual equipment state data passes the security verification, the virtual equipment state data is sent to the host machine. The kernel mode component transfers the access request to the user mode component in the virtual machine manager, and then the user mode component responds to the access request. Therefore, whether the virtual equipment state data stored in the memory address space of the user mode is tampered or not can be found in time, and after the tampering problem is found, access control is carried out in the kernel mode in time, so that the virtual machine is prevented from accessing the tampered virtual equipment state data, and the security risk of the virtual machine is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud computing technology, and in particular to a method, device and storage medium for secure management and control of a virtual machine. Background Art

[0002] In virtualization technology, in order to better support the operation of virtual machines, various required virtual peripherals are usually simulated for virtual machines and provided to the virtual machines for use. These virtual peripherals may include virtual keyboards, virtual mice, and various virtual bus PCI (Peripheral Component Interconnect) devices.

[0003] At present, the state data of virtual devices is generally stored in the user-state memory address space. Since memory leaks or abnormal memory access are more likely to occur in the user-state memory address space, the state data of virtual devices is vulnerable to attacks and tampering, which in turn brings greater security risks to the virtual machine. Summary of the invention

[0004] Multiple aspects of the present application provide a virtual machine security management method, device and storage medium to reduce the security risks of the virtual machine.

[0005] The embodiment of the present application provides a method for security management and control of a virtual machine, which is applicable to a kernel state component included in a virtual machine manager running on a host machine, wherein the virtual machine manager also includes a user state component, and the method includes:

[0006] In the case of intercepting an access request for virtual device state data issued by any virtual machine on the host machine, performing a security check on the virtual device state data pointed to by the access request;

[0007] If the virtual device state data passes the security check, the access request is forwarded to the user state component, so that the user state component responds to the access request.

[0008] The embodiment of the present application also provides a physical device, including a memory and a processor, wherein a virtual machine manager runs in the processor, and the virtual machine manager includes a user state component and a kernel state component;

[0009] The memory is used to store one or more computer instructions;

[0010] The processor is coupled to the memory and the communication component, and is used to execute the one or more computer instructions to execute the aforementioned virtual machine security management and control method.

[0011] An embodiment of the present application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the aforementioned virtual machine security management and control method.

[0012] In the embodiment of the present application, when the kernel state component in the virtual machine manager intercepts an access request for virtual device state data issued by any virtual machine on the host machine, the kernel state component will perform a security check on the virtual device state data pointed to by the access request, and only after it passes the security check will the kernel state component transfer the access request to the user state component in the virtual machine manager, and then the user state component can respond to the access request. In this way, it can be timely discovered whether the virtual device state data stored in the user state memory address space has been tampered with, and after the tampering problem is discovered, access control is timely performed in the kernel state to prevent the virtual machine from accessing the tampered virtual device state data, thereby reducing the security risk of the virtual machine. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0014] Figure 1a A flowchart of a method for security control of a virtual machine provided by an exemplary embodiment of the present application;

[0015] Figure 1b A logical diagram of a method for security management and control of a virtual machine provided by an exemplary embodiment of the present application;

[0016] Figure 2a A flowchart of another virtual machine security management method provided by an exemplary embodiment of the present application;

[0017] Figure 2b A logical diagram of another virtual machine security management and control method provided by an exemplary embodiment of the present application;

[0018] Figure 3 A logical schematic diagram of a preferred solution provided for an exemplary embodiment of the present application;

[0019] Figure 4a A flowchart of another method for security control of a virtual machine provided by an exemplary embodiment of the present application;

[0020] Figure 4b A logical diagram of another virtual machine security control method provided by an exemplary embodiment of the present application;

[0021] Figure 5a A flowchart of another method for security control of a virtual machine provided by an exemplary embodiment of the present application;

[0022] Figure 5b A logical diagram of another virtual machine security control method provided by an exemplary embodiment of the present application;

[0023] Figure 6 A schematic diagram of the structure of a physical device provided for an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0025] With the development of IO virtualization technology, in virtualization scenarios, in order to improve the IO performance in virtual machines, various required virtual peripherals are usually simulated for virtual machines through IO virtualization technology. As introduced in the background technology, the types of these virtual peripherals are various, and can be virtual keyboards, virtual mice, and various virtual PCI devices. For ease of description, these virtual peripherals used in virtual machines will be described as virtual devices in the following text.

[0026] Like hardware peripherals, each virtual device also has a device state. Device state refers to the state data configured in the configuration space of the virtual device. The device state is used to record the state of the configuration space and / or registers of the virtual device at a certain moment. The virtual machine can read and write the device state of the virtual device to realize the performance perception, function configuration and action enabling of the virtual device. In addition, like hardware peripherals, in IO virtualization technology, it is also necessary to save the virtual device state data in real time. Since virtual devices do not have storage hardware like hardware peripherals, the virtual device state data is usually stored in the physical memory of the host machine. In order to support the isolation mechanism of virtual machines in CPU virtualization technology, the virtual device state data usually needs to be stored in the user state memory address space, and the virtual device state data involved in different virtual machines are usually isolated.

[0027] The inventors found during the research that since memory leaks or abnormal memory access are more likely to occur in the user-mode memory address space, the virtual device state data is vulnerable to attack and tampering. However, the virtual machine cannot perceive this, which causes the virtual machine to read and write the tampered virtual device state data as usual, which in turn causes the related processes in the virtual machine to be attacked, which will bring greater security risks to the virtual machine.

[0028] To this end, this embodiment proposes a virtual machine security management method, and proposes to reduce the security risks brought to the virtual machine by ensuring the security of virtual device state data. Therefore, how to ensure the security of virtual device state data becomes the focus of this embodiment. This embodiment provides a new technical concept to ensure the security of virtual device state data.

[0029] This embodiment proposes a method for the security management and control of virtual machines, which can be applied to the virtual machine manager running on the host machine. Among them, the virtual machine manager (Virtual Machine Manager, VMM) can be regarded as an actual operating system, which is used to establish and maintain a framework for managing virtual machines. The virtual device mentioned in this embodiment is a virtual I / O device created by the VMM and provided to the virtual machine (specifically the guest operating system Guest OS) for I / O access. The guest operating system can only observe the virtual devices belonging to it, and all I / O accesses of the guest operating system can only be sent to its own virtual devices. Then the virtual machine manager can obtain the access request of the guest operating system from the virtual device, and then complete the real I / O access.

[0030] The inventor discovered during the research that the virtual machine manager usually includes a user-mode component and a kernel-mode component. Among them, the user-mode component is usually used to process tasks related to the user mode, such as QEMU (quick emulator) components, etc.; while the kernel-mode component is usually used to process tasks related to the kernel mode, such as KVM (Kernel-based Virtual Machine) components, etc. The tasks processed by the user-mode component may include but are not limited to creating a virtual machine, allocating addresses from the virtual address space occupied by the virtual machine manager as the physical address of the virtual machine, and simulating the required virtual devices for the virtual machine, etc., which are not exhaustively listed here. The kernel-mode component provides a series of interfaces to the user-mode component, through which the user-mode component can control various aspects of the virtual machine, such as the number of CPUs, memory layout, operation, etc.; the kernel-mode component is also used to process privileged instructions issued in the virtual machine, which are usually those that may affect the entire host machine, such as IO requests occurring in the virtual machine, etc.

[0031] In this embodiment, it is proposed that the user state component and the kernel state component cooperate with each other to ensure the security of the virtual device state data.

[0032] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.

[0033] Figure 1a A flowchart of a method for security management and control of a virtual machine is provided as an exemplary embodiment of the present application. Figure 1b A logical diagram of a virtual machine security control method provided by an exemplary embodiment of the present application. Figure 1a , the method may include:

[0034] Step 100: When the kernel state component intercepts an access request for virtual device state data from any virtual machine on the host machine, the kernel state component performs a security check on the virtual device state data pointed to by the access request;

[0035] Step 101: If the virtual device state data passes the security check, the kernel state component transfers the access request to the user state component;

[0036] Step 102: The user mode component responds to the access request.

[0037] In step 100, when any virtual machine on the host issues an access request for virtual device state data, a kernel-mode component may intercept such access request. It is worth noting that the access request in this embodiment may include a write request and a read request, so when any virtual machine on the host issues a write request or a read request for virtual device state data, it may be intercepted by the kernel-mode component.

[0038] refer to Figure 1b In this embodiment, the virtual machine can be essentially regarded as a process managed by a user-mode component. Therefore, when an access request for virtual device state data is issued in the virtual machine, it will be first perceived by the user-mode component. However, since the access request for virtual device state data belongs to the privileged instruction mentioned above, this type of access request can be accurately intercepted by the kernel-mode component.

[0039] For this type of access request, the kernel-mode component will forward it to the user-mode component for processing after identifying the privilege reason (which can be understood as the intention of the access request).

[0040] refer to Figure 1b In this embodiment, it is proposed that before forwarding such access request to the user-mode component for processing, the kernel-mode component performs a security check on the virtual device state data pointed to by the intercepted access request.

[0041] The virtual device state data pointed to by the access request refers to the virtual device state data stored in the user state memory address space mentioned above. It should be understood that the virtual device state data pointed to by the access request may have been tampered with in the user state memory address space. Based on step 100, in this embodiment, a security check can be completed in the kernel state for the virtual device state data to be accessed to determine whether the virtual device state data has been tampered with.

[0042] In addition, it is worth noting that the kernel state component has the ability to access the user state memory address space, so it can read the virtual device state data required to be accessed from the user state memory address space without any obstacles, and then perform security verification. In practical applications, for example, the kernel state component can initiate an address mapping instruction to the user state component so that the user state component returns the host virtual address (Host Virtual Address, HVA) mapped to the access address in the access request (usually the client physical address GPA, Guest Physical Address), and then the kernel state component can read the required virtual device state data from the physical memory of the host machine based on the page table in the host machine (recording the mapping relationship between the host virtual address HVA-host physical address HPA). Of course, this is only an exemplary reading method, and the present embodiment is not limited to this.

[0043] Continue to refer Figure 1a In step 101, if the virtual device state data passes the security check, the kernel state component transfers the access request to the user state component. That is, after the kernel state component performs a security check on the virtual device state data to be accessed according to step 100, it will transfer the access request to the user state component only when it is determined that the virtual device state data has not been tampered with. This ensures the security of the access request for the virtual device state data transferred to the user state component.

[0044] refer to Figure 1a In step 102, the user mode component may respond to the access request.

[0045] As mentioned above, in this embodiment, the access request may be a write request or a read request. Therefore, the response operation performed by the user-mode component based on the access request may at least include writing the accessed virtual device state data according to the write request and reading the accessed virtual device state data according to the read request. In addition, it should be understood that the user-mode component is usually also configured with operation functions associated with various types of device state values. In this embodiment, the response operation performed by the user-mode component based on the access request may also include performing simulation operations according to the operation functions associated with the device state values ​​after the read / write operation to realize the virtual machine's use requirements for the virtual device. The simulation operations here may include, but are not limited to, interrupt enable, DMA space application, device function configuration, and device function perception, etc., which are not exhaustive here.

[0046] In summary, in this embodiment, when the kernel state component in the virtual machine manager intercepts an access request for virtual device state data issued by any virtual machine on the host machine, the kernel state component will perform a security check on the virtual device state data pointed to by the access request, and only after it passes the security check will the kernel state component transfer the access request to the user state component in the virtual machine manager, and then the user state component can respond to the access request. In this way, it can be timely discovered whether the virtual device state data stored in the user state memory address space has been tampered with, and after the tampering problem is discovered, access control is timely performed in the kernel state to prevent the virtual machine from accessing the tampered virtual device state data, thereby reducing the security risk of the virtual machine.

[0047] Figure 2a A flowchart of another virtual machine security management method provided as an exemplary embodiment of the present application. Figure 2b A logical diagram of another virtual machine security management method provided by an exemplary embodiment of the present application. Figure 2a , the method may include:

[0048] Step 200: When the kernel state component intercepts an access request for virtual device state data from any virtual machine on the host machine, the kernel state component searches for verification data configured for the virtual device state data from the kernel state memory address space;

[0049] Step 201: The kernel state component performs security verification on the virtual device state data based on the verification data;

[0050] Step 202: If the virtual device state data passes the security check, the kernel state component transfers the access request to the user state component;

[0051] Step 203: The user mode component responds to the access request.

[0052] Among them, step 202-step 203 can refer to the relevant description in the previous embodiment, and will not be repeated here. In this embodiment, based on step 200 and step 201, an implementation method for performing security verification on the virtual device state data to be accessed is provided. This implementation method can be applied to the previous or subsequent embodiments, and combined with various implementation methods provided therein to form various technical solutions of different ranges.

[0053] refer to Figure 2b In this embodiment, the kernel-mode component maintains corresponding verification data in the kernel-mode memory address space for each virtual device state data stored in the user-mode address space.

[0054] Based on this, reference Figure 2a In step 200, when the kernel state component intercepts an access request for virtual device state data from any virtual machine on the host machine, the kernel state component can search for verification data configured for the virtual device state data from the kernel state memory address space. Among them, the verification data provided in this embodiment is located in the kernel state memory address space. The verification data is used as a basis for security verification. That is, the kernel state component can evaluate whether the virtual device state data in the user state memory address space has been tampered with based on the verification data.

[0055] The user state memory address space and kernel state memory address space in this embodiment are defined on the basis of memory virtualization technology. Based on the memory virtualization base technology, there are concepts of virtual address VA (Virtual Address) and physical address PA (Physical Address) in both the virtual machine and the host machine, namely, the guest virtual address GVA (Guest Virtual Address) and the guest physical address GPA (Guest Physical Address), as well as the host virtual address HVA (Host Virtual Address) and the host physical address HPA (Host Physical Address). Among them, the virtual machine manager can usually be regarded as a process in the host machine, so a section of address space can be allocated to the virtual machine manager from the host virtual address space as the virtual address space occupied by the virtual machine manager. Further, the user state memory address space and the kernel state memory address space can also be divided from the virtual address space occupied by the virtual machine manager. Among them, the kernel state component in the virtual machine manager has access rights to the user state memory address space and the kernel state memory address space, while the user state component only has access rights to the user state memory address space. In addition, a typical task of the user-mode component mentioned above is to allocate an address from the virtual address space occupied by the virtual machine manager as the physical address of the virtual machine, that is, to allocate an address from the user-mode memory address space of the virtual machine manager as the physical address GPA of the virtual machine.

[0056] Based on this, reference Figure 2b In this embodiment, the kernel state component can apply for address space from the kernel state memory address space for storing verification data. In practical applications, corresponding verification data can be configured in the kernel state memory address space for each virtual device used in different virtual machines in the user state memory address space, so as to support separate verification of a single virtual device in a single virtual machine and improve the accuracy of verification.

[0057] In addition, in this embodiment, the kernel state component can also configure the pointing relationship between the access address in the access request for the virtual device state data and the verification data stored in the kernel state memory address space, so that the kernel state component can accurately find the verification data for security verification according to the access address in the access request for the virtual device state data. This pointing relationship can be a pointing relationship between addresses (such as GPA pointing to HVA), so that the kernel state component can find the storage location of the verification data in the kernel state memory address space according to this pointing relationship. Of course, it can also be a pointing relationship between an address and a data identifier (such as GPA pointing to a data identifier), so that the kernel state component can accurately hit the verification data in the kernel state memory address space according to the data identifier. It should be understood that these are only exemplary, and the implementation scheme of the kernel state hitting the verification data in this embodiment is not limited to this, and no more examples are given here.

[0058] On this basis, reference Figure 2a In step 201, the kernel state component may perform security verification on the virtual device state data based on the verification data. Since the verification data is located in the kernel state memory address space, there is no risk of tampering, thus providing a secure and stable verification basis for the security verification process of the kernel state component.

[0059] Furthermore, in this embodiment, the content and format of the verification data are not limited. Figure 3 A logical diagram of a preferred solution provided for an exemplary embodiment of the present application. Figure 3 In a preferred implementation, the verification data may include mirror data configured for the virtual device state data. In this embodiment, the mirror data is used to record the untampered value corresponding to the data item in the virtual device state data. It should be understood that the untampered value is the value that the virtual device state data should have if it has not been attacked. That is, the mirror data in this embodiment is equivalent to a copy of the virtual device state data stored in the user-state memory address space, but this copy is not a simple copy of the virtual device state data stored in the user-state memory address space, but will present the original appearance of the virtual device state data stored in the user-state memory address space, that is, the data value that should be possessed if it has not been tampered with.

[0060] In this embodiment, a variety of solutions can be used to ensure that the image data records the untampered values ​​corresponding to the data in the virtual device state data. A preferred solution is provided below. For ease of description, the solution is described by taking the target virtual device used by the target virtual machine in the host as an example, wherein the target virtual device can be any virtual device used in the target virtual machine, and the target virtual machine can be any virtual machine running on the host. It should be understood that other virtual devices can also use the same solution to obtain corresponding image data.

[0061] In the preferred solution: the user state component can create an initial value of the virtual device state data for the target virtual device in the user state memory address space; the kernel state component can copy a copy of the initial value of the virtual device state data of the target virtual device in the kernel state memory address space as the initial value of the mirror data, so that for the target virtual device, the initial value of the virtual device state data in the user state memory address space and the initial value of the mirror data in the kernel state memory address space are consistent. Among them, the initial value of the virtual device state is assumed by default to have not been tampered with. In this way, the user state memory address space and the kernel state memory address space have the same data initial value for the target virtual device. On this basis, the kernel state component can use the initial value of the mirror data as the starting point, and in the kernel state memory address space, according to each write request that accesses the target virtual device and passes the security check, sequentially perform write operations to obtain the untampered value corresponding to the data item in the virtual device state data in the mirror data corresponding to the target virtual device.

[0062] That is, in the preferred solution, in the kernel memory address space, a write operation is performed on the relevant mirror data in synchronization with and consistent with the virtual device state data in the user memory address space, so that, if the virtual device state data in the user memory address space is not tampered with, the state data of the same virtual device in the same virtual machine in the user memory address space and the kernel memory address space will remain consistent. However, if the virtual device state data in the user memory address space is tampered with, the mirror data corresponding to it in the kernel memory address space will not be synchronously tampered with.

[0063] Based on this, in step 201, the process of performing security verification on the virtual device state data based on the verification data can be specifically implemented as follows: the kernel state component reads the virtual device state data from the user state memory address space; and determines whether the virtual device state data is consistent with its corresponding mirror data. If the virtual device state data is consistent with its corresponding mirror data, it is determined that the virtual device state data has passed the security verification. On the contrary, if the virtual device state data is inconsistent with its corresponding mirror data, it is determined that the virtual device state data has not passed the security verification.

[0064] Moreover, based on this solution, it is ensured that the image data records the untampered value corresponding to the data item in the virtual device state data. Figure 3 If it is determined in step 201 that the virtual device state data has passed the security check, in addition to executing the aforementioned steps 202 and 203, in the case where the access request is a write request, after the user state component completes the write operation on the virtual device state data according to the current write request that has passed the security check, the kernel state component can perform a write operation on the mirror data corresponding to the virtual device state data according to the write request. The mirror data after the write operation is completed will be used as verification data when the next write request occurs for the virtual device state data. That is, the mirror data when the write operation is completed will be consistent with the corresponding virtual device state data obtained in the user state memory address space after the user state component responds to the write request. In this way, the mirror data will always record the latest untampered value corresponding to the corresponding virtual device state data.

[0065] In summary, in this embodiment, it is proposed to configure corresponding verification data for the virtual device state data in the user state memory address space in the kernel state memory address space, and the kernel state component uses the verification data as a basis to perform security verification on the virtual device state data pointed to by the intercepted access request for the virtual device state data, so that access control for such access requests can be completed in the kernel state. Further, in this embodiment, a preferred verification data form---mirror data is also proposed, and the mirror data is used to record the untampered value that the corresponding virtual device state data should have. In this way, the kernel state component can determine whether the virtual device state data in the user state memory address space has been tampered with by comparing the virtual device state data in the user state memory address space with the corresponding mirror data in the kernel state memory address space, thereby effectively improving the accuracy of the security verification.

[0066] It is worth noting that the implementation method of performing security verification on the virtual device state data to be accessed provided in this embodiment is optional, and this embodiment supports the use of other implementation methods to implement the implementation method of performing security verification on the virtual device state data to be accessed. For example, the user-mode component can generate a hash verification value for the virtual device state data each time after completing a write operation on the virtual device state data, and store it in the kernel-mode memory address space; the kernel-mode memory address space can use the hash verification value as verification data to perform security verification on the virtual device state data. No more examples of implementation methods are given here.

[0067] Figure 4a A flowchart of another virtual machine security control method provided as an exemplary embodiment of the present application. Figure 4b A logical diagram of another virtual machine security control method provided by an exemplary embodiment of the present application. Figure 4a , the method may include:

[0068] Step 400: When the kernel state component intercepts an access request for virtual device state data from any virtual machine on the host machine, the kernel state component performs a security check on the virtual device state data pointed to by the access request;

[0069] Step 401: If the virtual device state data passes the security check, the kernel state component transfers the access request to the user state component;

[0070] Step 402: The user state component responds to the access request;

[0071] Step 403: If the virtual device state data fails the security check, the kernel state component intercepts the access request and performs exception processing on the access request.

[0072] Among them, steps 400 to 402 can refer to the relevant descriptions in the previous embodiment, and will not be repeated here. In this embodiment, a processing solution is provided based on step 403 when the virtual device state data fails the security check. This processing solution can be applied to the previous or subsequent embodiments, combined with various implementation methods provided therein, to form various technical solutions of different ranges.

[0073] refer to Figure 4aIn step 403, if the virtual device state data fails the security check, the kernel state component will no longer forward the currently intercepted access request to the user state component. In this way, the access request for the virtual device state data that fails the security check will not be able to reach the user state component. Accordingly, in this embodiment, even if the attacker tampers with the virtual device state data in the user state memory address space, since the access request initiated for the tampered virtual device state data has been blocked in the kernel state in this embodiment, this attack method can no longer achieve the purpose of attacking the virtual machine.

[0074] In addition, in step 402, it is proposed that the kernel-mode component performs exception processing on access requests that fail the security check.

[0075] This embodiment supports multi-dimensional exception handling. Several exemplary exception handling dimensions are provided below.

[0076] In an exemplary solution, if the virtual device state data fails the security check, the kernel state component may return a response failure notification to the virtual machine that issued the access request. The format of the response failure notification can be set as needed. For example, it may be some meaningless status values, or for another example, it may be a status code used to characterize a hardware error in the virtual device, etc. No further examples are given here, and this embodiment does not limit this. In addition, the method for issuing the response failure notification is not limited here. For example, the response failure notification may be passed to the user state component, and the user state component may serve as the response result of the access request, etc. No further examples are given here. Through exception handling in this dimension, the virtual machine can be informed that the response to the access request it issued has failed.

[0077] refer to Figure 4b In an exemplary solution, if the virtual device state data fails to pass the security check, the kernel state component can isolate the virtual device pointed to by the access request in the virtual machine. In this exemplary solution, it is proposed that when it is found that the virtual device state data fails to pass the security check, the kernel state component actively isolates the relevant virtual device.

[0078] Here, the process of isolating the virtual device pointed to by the access request can be: the kernel state component sends a pull-out instruction for the virtual device to the user state component; the user state component responds to the pull-out instruction and pulls the virtual device out of the virtual machine. In actual applications, the user state component can perform hot-plug control on the virtual device in the virtual machine. Here, the user state component pulls out the relevant virtual device from the virtual machine. It should be understood that the virtual device after being pulled out is no longer visible to the virtual machine, and the virtual machine usually does not issue an access request for the virtual device state of the isolated virtual device. However, considering that in special circumstances, there may also be subsequent access requests for the virtual device state data of the isolated virtual device issued in the virtual machine, for this purpose, the kernel state component can record the identification and other information of the isolated virtual device for each virtual machine respectively, so that when the kernel state component intercepts the access request for the virtual device state data of the isolated virtual device, it can directly return a response failure notification to the corresponding virtual machine and no longer need to perform the aforementioned security verification operation. That is, the access request for the virtual device state data initiated by the isolated virtual device will be directly rejected by the kernel state component without security verification.

[0079] It should be understood that the above isolation scheme is only exemplary, and this embodiment may also adopt other isolation schemes. For example, the kernel state component may maintain an access control table for virtual devices, in which the access control mode corresponding to each virtual device is recorded. For the virtual devices that need to be isolated, their corresponding access control mode may be recorded as "isolated". When the kernel state component subsequently intercepts a virtual device status data access request initiated for the isolated virtual device again, it may directly reject such access request, thereby achieving isolation of the virtual device. No more examples of isolation schemes are given here.

[0080] Based on the exception handling of this dimension, the scope of exception handling can be reduced to the granularity of virtual devices, and it is no longer necessary to perform exception handling on the entire virtual machine. In other words, in the event of such a security risk, it is not necessary to shut down the virtual machine to avoid the risk, but to isolate the relevant virtual devices. Other virtual devices in the virtual machine can be used normally, and of course, the entire virtual machine is also in normal operation. This can effectively reduce the scope of abnormal impact and ensure the operation of the virtual machine.

[0081] In addition, it should be understood that the above exception handling dimensions are only exemplary, and the present embodiment is not limited thereto. Moreover, multiple exception handling dimensions can be combined with each other, that is, multiple dimensions of exception handling operations can be implemented simultaneously, and the combination scheme is not described in detail here.

[0082] Accordingly, in this embodiment, when the virtual device state data fails the security check, the kernel state component no longer forwards the corresponding access request to the user state component, but the kernel state component directly handles the access request. This can effectively improve the efficiency of handling access requests that fail the security check.

[0083] Figure 5a A flowchart of another virtual machine security control method provided as an exemplary embodiment of the present application. Figure 5b A logical diagram of another virtual machine security control method provided by an exemplary embodiment of the present application. Figure 5a , the method may include:

[0084] Step 500: When the kernel state component intercepts an access request for virtual device state data from any virtual machine on the host machine, the kernel state component performs a security check on the virtual device state data pointed to by the access request;

[0085] Step 501: If the virtual device state data fails the security check, the kernel state component repairs the virtual device state data in the user state memory address space based on the check data in the kernel state memory address space;

[0086] Step 502: After the repair is completed, the kernel state component transfers the access request to the user state component;

[0087] Step 503: The user mode component responds to the access request.

[0088] Among them, step 500 and step 503 can refer to the relevant description in the previous embodiment, and will not be repeated here. In this embodiment, based on step 501 and step 502, a processing solution is provided when the virtual device state data fails the security check. This processing solution can be applied to the previous or subsequent embodiments, combined with various implementation methods provided therein, to form various technical solutions of different ranges.

[0089] and Figure 4a The processing scheme provided in the illustrated embodiment is different. In this embodiment, based on the processing scheme provided in step 501 and step 502, the kernel state component no longer directly handles the access request that currently fails the security check. Instead, the kernel state component performs the modification operation on the virtual device state data and then returns to the normal access request processing process. That is, after the repair is completed, the access request that currently fails the security check will be transferred to the user state component for processing.

[0090] As mentioned above, the verification data is used as the basis for security verification of kernel-mode components. Therefore, based on the verification data, the virtual device state data in the user-mode memory address space can be repaired to the state before tampering.

[0091] refer to Figure 5b , in response to the mirror data proposed in the above-mentioned embodiment, in step 501, if the verification data includes the mirror data configured for the virtual device state data, the kernel state component can overwrite the virtual device state data in the user state memory address space based on the corresponding mirror data in the kernel state memory address space. Since the mirror data records the untampered value corresponding to the data item in the virtual device state data, after the overwriting operation implemented by the kernel state component, the virtual device state data in the user state memory address space can be restored to the state before being tampered.

[0092] It should be understood that in step 501, appropriate repair means may be used according to the content form of the verification data. For example, in the case where the verification data mentioned in the above embodiment includes a hash check value configured for the virtual device state data, the kernel state component may perform reverse hashing on the virtual device state data based on the hash check value to restore the value of the data item in the virtual device state data. No further examples of repair means are given here.

[0093] On this basis, in step 502, after the repair is completed, the kernel state component can transfer the access request to the user state component. After the repair is completed, the virtual device state data in the user state memory address space has been restored to its original state before being tampered with. Therefore, in this embodiment, it is considered that the security risk has been eliminated, and it is proposed to continue to return to the normal access request processing process.

[0094] Here, in this embodiment, the kernel state component may no longer need to perform security verification on the repaired virtual device state data; of course, security verification may be performed again, and this embodiment does not limit this.

[0095] Accordingly, in this embodiment, by repairing the virtual device state data, the response success rate of access requests to the virtual device state data can be effectively improved, thereby reducing the failure probability of the virtual machine, and further effectively improving the stability and reliability of the virtual machine.

[0096] The inventor discovered during the research process that after the repair is completed and the kernel-mode component transfers the access request to the user-mode component, the problem of access failure may still occur. The reason for this problem is roughly that due to tampering, other data items related to the device state may also have changed. Therefore, even if the repair is completed, the device is essentially still in a faulty state, which leads to the problem of access failure after the user-mode component responds to the corresponding access request. For this reason, in this embodiment, the kernel-mode component can support receiving isolation instructions from the outside. In this way, after discovering that the access request fails, the virtual machine user can initiate an isolation instruction to the kernel-mode component for the virtual device executed by the access request.

[0097] After receiving the isolation instruction, the kernel state component can isolate the corresponding virtual device. For the specific technical details of isolation, please refer to the description in the previous article, and will not be repeated here. However, it should be understood that Figure 4a The isolation operation in the illustrated embodiment is actively initiated by the kernel-mode component, whereas the isolation operation in this embodiment is passively initiated by the kernel-mode component in response to an external instruction.

[0098] Accordingly, in this embodiment, when the virtual device state data fails to pass the security check, the kernel state component attempts to repair the virtual device state data that fails the security check, and returns to the normal access request handling process after the repair, so that the current access request can be transferred to the user state component normally. This can effectively reduce the number of abnormal responses to access requests in the virtual machine, thereby improving the stability and reliability of the virtual machine. Moreover, safeguards are proposed for situations where normal responses are still not possible after repair, that is, when the repair is ineffective, the corresponding virtual device is isolated. Isolation can minimize the abnormal range of the virtual machine and ensure the work efficiency of the virtual machine.

[0099] It should be noted that in some of the processes described in the above embodiments and the accompanying drawings, multiple operations appearing in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel, and the serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel.

[0100] Figure 6 A schematic diagram of a physical device structure provided by an exemplary embodiment of the present application. Figure 6 As shown, the physical device may include: a memory 60 and a processor 61, a virtual machine manager 62 runs in the processor 61, and the virtual machine manager 62 includes a user state component 63 and a kernel state component 64;

[0101] The memory is used to store one or more computer instructions;

[0102] The processor is coupled to the memory and is configured to execute one or more computer instructions for:

[0103] In the case where the kernel state component intercepts an access request for virtual device state data issued by any virtual machine on the host machine, the kernel state component performs a security check on the virtual device state data pointed to by the access request;

[0104] If the virtual device state data passes the security check, the kernel state component transfers the access request to the user state component 63;

[0105] The user mode component 63 responds to the access request.

[0106] In an optional embodiment, when performing security verification on the virtual device state data pointed to by the access request, the kernel state component 64 may be used to:

[0107] The kernel state component searches for verification data configured for the virtual device state data from the kernel state memory address space;

[0108] A security check is performed on the virtual device state data based on the check data.

[0109] In an optional embodiment, the verification data includes mirror data configured for the virtual device state data, and when the kernel state component 64 performs security verification on the virtual device state data based on the verification data, it can be used to:

[0110] Reading the virtual device state data from the user state memory address space;

[0111] Determining whether the virtual device state data is consistent with its corresponding mirror data;

[0112] The mirror data is used to record the untampered value corresponding to the data item in the virtual device state data.

[0113] In an optional embodiment, for a target virtual device in a target virtual machine, an initial value of the virtual device state data created by the user state component 63 in the user state memory address space is consistent with an initial value of the image data created by the kernel state component in the kernel state memory address space, and the kernel state component 64 may also be used to:

[0114] Taking the initial value of the mirror data as a starting point, in the kernel state memory address space, in accordance with each write request that accesses the target virtual device and passes the security check, write operations are performed in sequence to obtain an untampered value corresponding to a data item in the virtual device state data in the mirror data corresponding to the target virtual device;

[0115] The target virtual device is any virtual device used by the target virtual machine.

[0116] In an optional embodiment, when the access request is a write request, the kernel mode component 64 may also be used to:

[0117] After the user state component completes the write operation on the virtual device state data according to the write request, write the mirror data corresponding to the virtual device state data according to the write request;

[0118] The mirror data after the write operation is completed is used as verification data when the next write request occurs for the virtual device state data.

[0119] In an optional embodiment, the kernel mode component 64 may also be used to:

[0120] If the virtual device state data fails the security check, the access request is intercepted and an exception process is performed on the access request.

[0121] In an optional embodiment, when performing exception processing on the access request, the kernel state component 64 may be used to:

[0122] A response failure notification is returned to the virtual machine that issued the access request.

[0123] In an optional embodiment, when performing exception processing on the access request, the kernel mode component may be used to:

[0124] The virtual device pointed to by the access request in the virtual machine is isolated.

[0125] In an optional embodiment, the kernel mode component 64 may also be used to:

[0126] If the virtual device state data fails the security check, repairing the virtual device state data in the user state memory address space based on the check data in the kernel state memory address space;

[0127] After the repair is completed, the kernel state component transfers the access request to the user state component 63 and subsequent operations are performed.

[0128] In an optional embodiment, when the kernel state component 64 repairs the virtual device state data in the user state memory address space based on the verification data in the kernel state memory address space, it can be specifically used to:

[0129] If the verification data includes mirror data configured for the virtual device state data, overwriting the virtual device state data in the user state memory address space based on the mirror data in the kernel state memory address space;

[0130] The mirror data is used to record the untampered value corresponding to the data item in the virtual device state data.

[0131] In an optional embodiment, the kernel mode component 64 may also be used to:

[0132] After the repair is completed, if an isolation instruction for the virtual device pointed to by the access request is received, the virtual device pointed to by the access request is isolated.

[0133] In an optional embodiment, when isolating the virtual device pointed to by the access request, the kernel state component 64 may be specifically used to:

[0134] A removal instruction for the virtual device is issued to the user state component 63, so that the user state component 63 removes the virtual device from the virtual machine in response to the removal instruction.

[0135] Further, if Figure 6 As shown, the physical device also includes other components such as a communication component 65 and a power supply component 66. Figure 6 Only some components are shown schematically, which does not mean that the physical device only includes Figure 6 Components shown.

[0136] It is worth noting that the technical details in the above-mentioned embodiments of the physical device can refer to the relevant description in the aforementioned method embodiment. In order to save space, they will not be repeated here, but this should not cause loss of the protection scope of this application.

[0137] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed, can implement the steps performed in the above method embodiment.

[0138] Above Figure 6The memory in the computer is used to store computer programs and can be configured to store various other data to support operations on the computing platform. Examples of such data include instructions for any application or method operating on the computing platform, contact data, phone book data, messages, pictures, videos, etc. The memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0139] Above Figure 6 The communication component in is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G / LTE, 5G and other mobile communication networks, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.

[0140] Above Figure 6 The power supply component in the device provides power to various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device where the power supply component is located.

[0141] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0142] The present application is described with reference to the flowchart and / or block diagram of the method, device (system) and computer program product according to the embodiment of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, and the combination of the process and / or box in the flowchart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for realizing the function specified in one process or multiple processes in the flowchart and / or one box or multiple boxes in the block diagram.

[0143] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0144] These computer program instructions may also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0145] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0146] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0147] The above is only the embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.

Claims

1. A virtual machine security management and control method, characterized in that: The method is applicable to a kernel state component included in a virtual machine manager running on a host machine, wherein the virtual machine manager also includes a user state component, and the method includes: In the case of intercepting an access request for virtual device state data issued by any virtual machine on the host machine, performing a security check on the virtual device state data pointed to by the access request; If the virtual device state data passes the security check, the access request is forwarded to the user state component, so that the user state component responds to the access request.

2. The method according to claim 1, characterized in that Performing a security check on the virtual device state data pointed to by the access request includes: Searching for verification data configured for the virtual device state data from the kernel state memory address space; A security check is performed on the virtual device state data based on the check data.

3. The method according to claim 2, characterized in that The verification data includes mirror data configured for the virtual device state data, and performing security verification on the virtual device state data based on the verification data includes: Reading the virtual device state data from the user state memory address space; Determining whether the virtual device state data is consistent with its corresponding mirror data; The mirror data is used to record the untampered value corresponding to the data item in the virtual device state data.

4. The method according to claim 3, characterized in that For a target virtual device in a target virtual machine, an initial value of virtual device state data created by the user state component in the user state memory address space is consistent with an initial value of image data created by the kernel state component in the kernel state memory address space, and the method further includes: Taking the initial value of the mirror data as a starting point, in the kernel state memory address space, in accordance with each write request that accesses the target virtual device and passes the security check, write operations are performed in sequence to obtain an untampered value corresponding to a data item in the virtual device state data in the mirror data corresponding to the target virtual device; The target virtual device is any virtual device used by the target virtual machine.

5. The method according to any one of claims 3 or 4, characterized in that: In the case where the access request is a write request, the method further includes: After the user state component completes the write operation on the virtual device state data according to the write request, write the mirror data corresponding to the virtual device state data according to the write request; The mirror data after the write operation is completed is used as verification data when the next write request is made to the virtual device state data.

6. The method according to claim 1, characterized in that Also includes: If the virtual device state data fails the security check, the access request is intercepted and an exception process is performed on the access request.

7. The method according to claim 6, characterized in that Performing exception processing on the access request, including: A response failure notification is returned to the virtual machine that issued the access request.

8. The method according to claim 6, characterized in that The kernel state component performs exception processing on the access request, including: The virtual device pointed to by the access request in the virtual machine is isolated.

9. The method according to claim 2, characterized in that: The method further comprises: If the virtual device state data fails the security check, repairing the virtual device state data in the user state memory address space based on the check data in the kernel state memory address space; After the repair is completed, the access request is transferred to the user mode component and subsequent operations are performed.

10. The method according to claim 9, characterized in that Repairing the virtual device state data in the user state memory address space based on the verification data in the kernel state memory address space includes: If the verification data includes mirror data configured for the virtual device state data, overwriting the virtual device state data in the user state memory address space based on the mirror data in the kernel state memory address space; The mirror data is used to record the untampered value corresponding to the data item in the virtual device state data.

11. The method according to claim 9, characterized in that The method further comprises: After the repair is completed, if an isolation instruction for the virtual device pointed to by the access request is received, the virtual device pointed to by the access request is isolated.

12. The method according to claim 8 or 11, characterized in that: Isolating the virtual device pointed to by the access request includes: A removal instruction for the virtual device is issued to the user state component, so that the user state component removes the virtual device from the virtual machine in response to the removal instruction.

13. A physical device, characterized in that It includes a memory and a processor, wherein a virtual machine manager runs in the processor, and the virtual machine manager includes a user state component and a kernel state component; The memory is used to store one or more computer instructions; The processor is coupled to the memory and is used to execute the one or more computer instructions to execute the security management and control method of the virtual machine according to any one of claims 1 to 12.

14. A computer-readable storage medium storing computer instructions, characterized in that: When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the virtual machine security management and control method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Virtualization security management method, device of running kernel driver and storage medium

    CN109324873A

  • Memory management method and device of virtual machine and electronic equipment

    CN114880074A

  • Network access security protection method and device, electronic equipment and storage medium

    CN115292005A

  • System and Method for Enforcing Security Policies in a Virtual Environment

    US20110047542A1

  • Micro-virtualization architecture for threat-aware microvisor deployment in a node of a network environment

    US20150199532A1