Application execution method and computer program product

By mirroring and loading Android operating systems and applications to trusted virtual machines, operating systems and applications run in the Realm world, the problem of insufficient integrity protection for Android applications in the face of high-permission attacks is solved, and a higher level of isolation and security protection is achieved.

CN119989336APending Publication Date: 2025-05-13BEIJING SANKUAI ONLINE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510112502.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When Android applications face high-privileged attackers, especially opponents with physical device access capabilities, the overall integrity protection of the Android system and application execution environment running on the operating system is insufficient, resulting in the application memory data being easily read or tampered with maliciously, and the existing security mechanism cannot effectively prevent high-privileged attackers.

Method used

By mirroring the operating system framework and applications, generating operating system image files, and modifying the operating system kernel, loading it into the memory area of ​​a trusted virtual machine. The operating system and applications run in the Realm world, providing hardware-level memory encryption and isolation protection.

Benefits of technology

It realizes a higher level of isolation environment for Android applications and operating systems, reduces the attack surface, enhances the protection of sensitive data in the system, improves the security of application operation, and can withstand the threat of high privileges and physical attackers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989336A_ABST
    Figure CN119989336A_ABST
Patent Text Reader

Abstract

The invention provides an application execution method and a computer program product, and relates to the technical field of network security, the application execution method comprises the following steps: mirroring an operating system framework and an operating system application to generate an operating system mirror image file, and modifying an operating system kernel; when the equipment is started, loading the modified operating system kernel and the operating system mirror image file to a memory area of the trusted virtual machine; and after the modified operating system kernel is loaded, configuring the operating system and operating system application to run in the Realm world. The method and the device can realize safe operation of the application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of network security, and in particular to an application execution method and a computer program product. Background Art

[0002] The current security protection mechanism of Android applications mainly relies on the basic isolation and detection measures provided by the operating system and hardware.

[0003] However, when facing attackers with high privileges, especially those with access to physical devices, Android applications run on top of the operating system, and the overall integrity protection of the Android system and application execution environment is insufficient. Applications running on the Android platform store a large amount of sensitive information in memory. However, since the current protection mechanism lacks hardware-level memory encryption support, application memory data can be easily maliciously read or tampered with in the face of physical layer attacks. The current security mechanism of Android devices cannot effectively prevent attackers with system-level or physical device control permissions, and lacks isolation protection against high-privilege attackers, resulting in the inability of applications to run safely. Summary of the invention

[0004] The purpose of the present disclosure is to provide an application execution method and a computer program product, thereby overcoming the problem that applications cannot be run safely due to limitations and defects of related technologies, at least to a certain extent.

[0005] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0006] According to one aspect of the present disclosure, there is provided an application execution method, including: mirroring an operating system framework and an operating system application to generate an operating system image file, and modifying an operating system kernel; when a device is started, loading the modified operating system kernel and the operating system image file into a memory area of ​​a trusted virtual machine; the trusted virtual machine loads the operating system; after the modified operating system kernel is loaded, configuring the operating system and the operating system application to run in a Realm world.

[0007] In an exemplary embodiment of the present disclosure, mirroring the operating system framework and the operating system application to generate the operating system image file includes: modifying the partition table of the operating system framework and modifying the file format used by the temporary file system in the operating system application to generate the operating system image file; wherein the operating system image file can be directly loaded by the operating system kernel; and modifying the attribute information of the operating system kernel.

[0008] In an exemplary embodiment of the present disclosure, the modifying the partition table of the operating system framework includes: modifying the partition table of the operating system framework, and mounting the initialized file system to a root partition in the partition table.

[0009] In an exemplary embodiment of the present disclosure, the modification of the file format used by the temporary file system includes: adding an attribute field in the file header used by the temporary file system so that the temporary files in the temporary file system carry file attribute information; wherein the attribute field is an xattr field, and the file format of the temporary file is a CPIO file format.

[0010] In an exemplary embodiment of the present disclosure, the modifying the attribute information of the operating system kernel includes: adding a function of parsing the temporary file and a function of applying the temporary file to the attribute information of the operating system kernel.

[0011] In an exemplary embodiment of the present disclosure, the method further includes: when the device is started, loading the image files of the operating system and the operating system application into the memory area of ​​the trusted virtual machine, and performing an initial measurement on the image file to obtain a measurement value; and performing verification based on the measurement value to perform integrity verification.

[0012] In an exemplary embodiment of the present disclosure, the operating system application, the operating system framework, and the operating system kernel run in a Realm world and are deployed in the same trusted virtual machine.

[0013] In an exemplary embodiment of the present disclosure, the method further includes: the operating system application and the operating system framework run at a first privilege level of the Realm world; and the operating system kernel runs at a second privilege level of the Realm world.

[0014] In an exemplary embodiment of the present disclosure, the method further includes: adding a function of obtaining a measurement report to the operating system to obtain the measurement report; performing remote attestation or local attestation based on the measurement report; wherein the measurement report includes one or more of the measurement values ​​of the trusted virtual machine, the measurement values ​​of the platform, the measurement values ​​of the operating system, and the measurement values ​​of the operating system image file and the measurement values ​​of the application file.

[0015] According to one aspect of the present disclosure, a computer program product is provided, including a computer program, wherein when the computer program is executed by a processor, the computer program implements any one of the above-mentioned application execution methods.

[0016] In the technical solutions provided in some embodiments of the present disclosure, on the one hand, Android applications and operating systems are run in a protected trusted virtual machine. Through this isolation, the execution environment of the application and the operating system can resist the intrusion of high-privilege attackers, providing a higher-level isolation environment and reducing the attack surface. By providing an Android operating environment in a trusted execution environment Realm, Android applications can run independently of traditional non-secure environments, thereby resisting the threats of high-privilege and physical attackers, and significantly enhancing the protection of sensitive data in the system, improving the security of application operation. On the other hand, by integrating Realm isolation, memory data during application and system operation can be encrypted and protected, which can prevent attackers from stealing or tampering with memory data through physical means, thereby improving the security and confidentiality of data.

[0017] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0019] Figure 1 A flowchart schematically illustrates a method for executing an application according to an embodiment of the present disclosure.

[0020] Figure 2 A schematic diagram of a system architecture for executing an application according to an embodiment of the present disclosure is shown.

[0021] Figure 3 The flowchart of modifying the operating system in the embodiment of the present disclosure is schematically shown.

[0022] Figure 4 The flowchart of the operating system application in the embodiment of the present disclosure is schematically shown.

[0023] Figure 5 The following is a schematic diagram showing the process flow of the application loader in the embodiment of the present disclosure. DETAILED DESCRIPTION

[0024] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as being limited to the examples set forth herein; on the contrary, these embodiments are provided so that the present disclosure will be more comprehensive and complete, and the concepts of the example embodiments are fully conveyed to those skilled in the art. The described features, structures, or characteristics may be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced while omitting one or more of the specific details, or other methods, components, devices, steps, etc. may be adopted. In other cases, known technical solutions are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0025] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0026] With the popularity of mobile devices, Android has become one of the most widely used mobile operating systems in the world, carrying millions of applications, including social, financial, health and other important fields. Currently, Android applications mainly rely on code detection at the application layer and operating system protection to provide certain security protection capabilities. When facing strong attackers, the attacker can attack the entire device and system dimensions, such as through malicious operating systems or simulated hardware platforms, or even control the entire physical device to analyze and modify the application, so stronger security protection measures are needed.

[0027] The most commonly used processor architecture in the Android ecosystem is the Arm (Advanced RISC Machine) architecture. In order to protect the key sensitive data of Android applications, Arm proposed the hardware-level isolation technology TrustZone, which is divided into a secure world and a non-secure world. Through the cooperation of software and hardware, an isolated operating environment is formed in the secure world to prevent unauthorized access. Specifically, TrustZone allows key security functions (such as encryption, authentication, and digital rights management) to run in the secure world, while the daily operations of the application are performed in the non-secure world. Although TrustZone provides basic isolation functions, it has some key limitations: the classification of only secure and non-secure is too rough. With the introduction of more and more use cases that need to be isolated from the operating system, the attack surface is increasing, and vulnerabilities may cause the entire device to be damaged; the TrustZone architecture is relatively static and inflexible, and cannot adapt to dynamic application scenarios. It is also subject to mandatory restrictions by device manufacturers and lacks scalability.

[0028] To address the limitations of TrustZone, Android 13 introduced secure virtualization, namely the Android Virtualization Framework (AVF). The Android virtualization framework proposes a new security model based on the protected KVM (pKVM) technology of the Arm architecture. pKVM not only prevents applications from illegally accessing the host operating system based on virtualization isolation, but also prevents the host system from accessing sensitive running data within the virtual machine system. It enhances the protection of applications and their data through two-way isolation. pKVM does not have hardware mandatory isolation guarantees. Although the virtual machine monitor is implemented with a smaller trusted computing base (Trusted CodeBase, TCB), it still cannot defend against highly privileged attackers. In addition, pKVM does not have a global trusted proof mechanism for the system and applications, making it difficult to maintain integrity during attacks.

[0029] Arm has proposed the Confidential Compute Architecture (CCA) on its latest generation of processors, the Arm v9 processor, and introduced a new hardware isolation domain Realm world to protect third-party applications. Realm is a trusted execution environment in the form of a confidential virtual machine with software-controlled, hardware-enforced isolation, which can protect the confidentiality and integrity of its contents. Although Realm can be dynamically managed by privileged, untrusted system software (such as operating systems and hypervisors), Realm is completely opaque to these software. Arm CCA achieves this isolation through hardware extensions such as RME (Realm Management Extension) and firmware components such as RMM (Realm Management Monitor). Arm CCA also supports remote attestation of Realm, and Realm instances can request a measurement report called a CCA authentication token from RMM. The measurement report contains two parts: one is the measurement of the initial state of Realm and firmware components (including monitors and RMM), and the other is the identity identification of the hardware platform.

[0030] Currently, the security protection mechanism of Android applications mainly relies on the basic isolation and detection measures provided by the operating system and hardware. However, these measures are still significantly insufficient when facing attackers with high privileges, especially those with physical device access capabilities, as shown in the following aspects:

[0031] The overall integrity protection of the Android system and application execution environment is insufficient. Since most of the existing Android application protection mechanisms rely on the integrity of the operating system and the execution environment itself, the integrity of the Android system operation is directly related to the security of the application. Android applications run on top of the operating system and cannot detect the integrity of the operating system and the execution environment. For attackers, modifying the operating system or exploiting operating system vulnerabilities can bypass the application's protection measures, thereby endangering the security of the application. Even though Android 13 introduced virtualization support, it can only provide limited isolation and protection for the operating system. In the face of high-privilege attacks, current protection measures cannot achieve global trusted verification of the system and applications, and it is difficult to ensure that the operating system and applications maintain integrity during attacks.

[0032] Insufficient memory and data protection in the face of physical-level attacks. Applications running on the Android platform store a large amount of sensitive information in memory. However, since the current protection mechanism lacks hardware-level memory encryption support, application memory data can be easily maliciously read or tampered with in the face of physical layer attacks (such as cold start attacks). The existing TrustZone and pKVM do not provide dynamic encryption and protection for application runtime memory, especially when the application and the system are running together, there is a lack of complete isolation and encryption mechanisms, which makes it difficult to effectively protect data when the physical device is controlled.

[0033] Lack of isolation protection against high-privilege attackers. The current security mechanism of Android devices cannot effectively prevent attackers with system-level or physical device control privileges. Even if TrustZone or virtualization technology is used to provide basic isolation protection, the security resources of TrustZone are controlled by hardware manufacturers, and application developers cannot flexibly configure them. There is also a lack of dynamic isolation support during system startup and operation. Existing virtualization technologies (such as pKVM) rely on virtual machine monitors for isolation. This isolation method is also easily breached when facing high-privilege attackers, resulting in threats to system integrity and confidentiality.

[0034] Lack of effective remote attestation mechanism. In application scenarios with high security requirements, remote attestation mechanism becomes an important means to protect application integrity. However, the existing mechanism of the Android system cannot provide continuous verification of the entire operating system and application execution environment. Although TrustZone can provide static verification at startup, it does not provide sufficient support for trustworthy verification during the operation of the operating system. The Android system lacks the ability to perform global and dynamic remote verification of the execution environment, making it impossible to provide the trusted state of the system to remote entities when facing an adversary with physical attack capabilities.

[0035] In the disclosed embodiments, by utilizing the next generation trusted computing technology Arm CCA, the problem that the existing Android system protection mechanism cannot provide secure execution protection for the entire operating system and application execution environment is solved. By combining the technical characteristics of the Android system and Arm CCA based on hardware isolation and integrity measurement, the secure isolation and integrity verification capabilities of the application environment are enhanced. At the same time, the application's anti-attack capabilities are effectively improved through remote attestation and memory encryption technology, making up for the many deficiencies faced by existing technologies in complex mobile application execution protection. A series of key technical issues such as protecting application secure trusted execution and system integrity verification under the Android platform are solved, especially the problem of protecting physical devices from attacks by high-privilege attackers.

[0036] Based on this, some embodiments of the present disclosure provide an application execution method, which can be used to securely execute applications in a Realm world.

[0037] Next, refer to Figure 1 As shown, each step in the application execution method in the embodiment of the present disclosure is described in detail.

[0038] In step S110, the operating system framework and the operating system application are mirrored to generate an operating system image file, and the operating system kernel is modified.

[0039] In some embodiments of the present disclosure, the device may be any type of device as long as it can run an application program, for example, the device may be a smart phone, a tablet computer, or a smart watch, a smart bracelet, etc. The operating system of the device may be an Android system or other types of operating systems, and the Android operating system is used as an example for description. The operating system may include an operating system framework, an operating system application, and an operating system kernel.

[0040] Figure 2 The system architecture for application execution is provided in Figure 2 As shown in , the system architecture 200 may include multiple privilege levels, for example, a first privilege level EL0, a second privilege level EL1, a third privilege level EL2, and a fourth privilege level EL3. Each privilege level may run different components, and the number of components that can be run at each privilege level may be the same or different. Figure 2 As shown in the , the system architecture describes three security states in Arm: Realm world, non-secure world and root world. Based on this, each privilege level can run in the same security state or in different security states.

[0041] Among them, the Root world only exists in the fourth privilege level EL3, and only Arm Trusted Firmware runs in it. Arm Trusted Firmware is responsible for the initialization and basic security configuration of the device, and provides a root of trust for the creation and management of Realm virtual machines.

[0042] The non-secure world contains a virtual machine manager (VMM, such as QEMU) and a virtual machine monitor (Hypervisor, such as Linux KVM) running at the EL2 privilege level. These components are responsible for managing virtualized resources and Realm resources in a non-secure state. They are only responsible for managing Realm virtual machines but cannot directly access resources in Realm virtual machines.

[0043] The RMM runs at the EL2 privilege level of the Realm world, which is responsible for managing the Realm virtual machine and receiving and applying the management policy of the virtual machine monitor. The Realm virtual machine (running at the EL1 and EL0 privilege levels in the Realm world) is what needs to be protected, including the operating system application, the operating system framework, and the operating system kernel. When the operating system is the Android system, the operating system application, the operating system framework, and the operating system kernel are Android applications, AndroidFramework, and Android Kernel respectively.

[0044] refer to Figure 2 As shown in , the system architecture may include a first trusted firmware and a second trusted firmware. The first trusted firmware is Arm Trusted Firmware, and the second trusted firmware is RMM (Realm Management Monitor). The first trusted firmware runs at the fourth privilege level EL3 of the Root world, and the second trusted firmware runs at the third privilege level EL2 of the Realm world. The virtual machine manager (VMM, such as QEMU) in the non-secure world and the virtual machine monitor (Hypervisor, such as Linux KVM) running at the EL2 privilege level jointly manage the Realm virtual machine, such as controlling startup, operation and destruction. The Realm virtual machine runs at the second privilege level EL1 and the first privilege level EL0 in the Realm world, and the Realm virtual machine includes an operating system application, an operating system framework and an operating system kernel. It should be noted that in the operating system, the operating system application, the operating system framework and the operating system kernel can run in the same Realm virtual machine. Among them, the Realm virtual machine refers to a trusted virtual machine, and the trusted virtual machine is used to represent a virtual machine that provides a trusted environment.

[0045] Based on this, the entire operating system and operating system applications run in the Realm world and are deployed in the same Realm virtual machine. For example, the Android kernel, Android framework, and Android applications can be run in the Realm world. Running the operating system and operating system applications in the same Realm virtual machine can ensure that their operation process is not interfered with by external factors. The Realm world can be isolated from other worlds (such as the non-secure world and the secure world), and can also prevent high-privileged attackers from directly accessing or modifying data in the Realm. Among them, different operating system applications can be deployed in different Realm worlds, or different operating system applications can be deployed in the same Realm world.

[0046] By utilizing the isolation protection mechanism provided by Arm CCA, the operating system application and the entire operating system are run in a trusted execution environment Realm to achieve higher integrity and confidentiality protection. By providing an operating system running environment in a trusted execution environment Realm, the operating system application can run independently of the traditional non-secure environment, thereby resisting the threat of high privilege and physical attackers.

[0047] In order to ensure the integrity of the operating system and operating system applications, when the device starts, the operating system loads the first trusted firmware to initialize the hardware resources of the device, and starts the second trusted firmware after completing the hardware resource initialization. Exemplarily, in the initialization phase, when the device starts, the operating system first loads the first trusted firmware Arm TrustedFirmware. The first trusted firmware Arm Trusted Firmware can initialize the hardware resources of the device and configure a secure isolation environment. After completing the hardware resource initialization of the device, the first trusted firmware Arm Trusted Firmware starts the second trusted firmware RMM at the third privilege level EL2.

[0048] It should be noted that when the device starts, the image files corresponding to the entire operating system and the operating system application can be loaded into the memory, and an initial measurement can be performed on them to obtain the initial measurement value. The initial measurement value can be used for subsequent integrity verification. The image file of the operating system application refers to the image file corresponding to the multiple application files that the operating system application depends on. The initial measurement value can be a hash value or other numerical value of the multiple application files that the operating system application depends on. For example, the initial measurement value may include the hash values ​​of the multiple application files, operating system, virtual machine, and platform that the operating system application depends on when the device starts. By performing initial measurements on the multiple application files that the operating system and the application depend on and filling them into the memory, the application execution environment can be effectively prevented from being tampered with and the overall integrity of the operating system can be improved.

[0049] The RMM (Realm Management Monitor) module runs in the third privilege level EL2 of the Realm world, and is responsible for managing the startup of the Realm virtual machine and the configuration of the operating environment and recording the measured values. When the operating system application is started, the measured values ​​can be verified to ensure that the operating system application and its operating environment are complete and not tampered with. Exemplarily, the measured values ​​of all application files that the operating system application depends on, the measured values ​​of the virtual machine, the measured values ​​of the platform, and the measured values ​​of the operating system can be obtained each time the operating system application is loaded. The measured value of each parameter can be further compared with the initial measured value of the parameter obtained when the device is started. When the two are consistent, the operating system application and its operating environment can be considered to be complete and not tampered with. When the two are inconsistent, the operating system application and its operating environment can be considered to be incomplete and may be tampered with. Integrity verification is performed when the operating system and operating system application are started, which can ensure that the operating system and operating system application only run under safe and reliable conditions. This enhanced integrity protection has a significant effect on preventing malicious tampering and ensuring the security of application execution.

[0050] In the disclosed embodiment, the operating system can be mirrored to generate an operating system image file. For example, for an Android system as the operating system, the operating system framework and the operating system application can be mirrored to generate an operating system image file. After all modules of the Android system are compiled, the compiled module files can be packaged. The packaging result is a series of image files, such as system.img, boot.img, ramdisk.img, userdata.img, and recovery.img. These image files can eventually be burned to mobile phones and other devices for operation. Based on this, in the disclosed embodiment, the operating system framework and the operating system application are mirrored to generate an operating system image file, and the obtained operating system image file may include system.img, boot.img, ramdisk.img, userdata.img, and recovery.img, etc., among which ramdisk.img can be a temporary file system initramfs.

[0051] initramfs (Initial RAM Filesystem) is a temporary file system loaded into memory during the system startup process. It is mainly used to initialize and configure the system before mounting the real root file system after the kernel starts. initramfs contains the necessary drivers, tools, and configuration files that help the kernel load and start the system. By including the necessary driver modules, initramfs solves the problem that the kernel cannot access external storage without these drivers. Since different hardware platforms may require different drivers, compiling all drivers into the kernel will make the kernel size large and unnecessary. initramfs improves the compatibility and flexibility of the system by loading drivers on demand.

[0052] In some embodiments, in order to avoid using I / O devices such as hard disks when the operating system is started, and thus relying only on the initialization memory that is counted into the measurement value, it is necessary to mirror the operating system framework Android Framework and the operating system application to obtain an operating system image file. The obtained operating system image file can be directly loaded and mounted by the operating system kernel Android Kernel. In the embodiment of the present disclosure, the operating system image file is used as an image in the initramfs format. During the mirroring process, you can follow Figure 3 The operating system is modified as shown in the figure. The modification process mainly includes the following steps:

[0053] In step S310, the partition table of the operating system framework is modified.

[0054] In step S320, the file format used by the temporary file system in the operating system application is modified.

[0055] In step S330, the attribute information of the operating system kernel is modified.

[0056] The partition table of the operating system framework can be modified to include multiple partitions such as a root partition and a data partition, and further, the file system initialized by the hardware resources can be mounted to the root partition in the partition table. It should be noted that each device has its own partition table, and the partition table of each device can be different.

[0057] When generating an operating system image file, the file format used by the temporary file system initramfs can also be modified. Specifically, the file format used by the temporary file system can be modified to the CPIO file format to facilitate measurement. Exemplarily, an attribute field can be added to the file header of a temporary file in the temporary file system so that the temporary file carries file attribute information through the attribute field. Among them, the attribute field can be an xattr field, and adding an attribute field can enable the temporary file to carry file attribute information such as SELinux labels. Among them, SELinux (Security-Enhanced Linux) is a policy-based access control mechanism. SELinux controls access rights by adding labels (called SELinux labels) to applications and services running on Linux. SELinux labels are used to determine the access rights of processes. Each process and file has a unique SELinux label to determine their access rules.

[0058] In addition, during the image process, the cpio tool used to pack and unpack files can also be modified at the same time. The cpio tool is a tool program used to create and restore backup files. It can add and unpack files in cpio or tar backup files. The modified CPIO file format needs to be followed in the process of generating the temporary file system initramfs. By modifying the operating system, the problem of directly flashing the original image format to the hard disk or permanent storage is avoided, which is convenient for measurement.

[0059] It should be noted that the operating system image file may be generated when the device is started, or may be generated at any appropriate time, which is not specifically limited here.

[0060] In other embodiments, the attribute information of the operating system kernel can also be modified. Exemplarily, the function of parsing temporary files and the function of applying temporary files can be added to the attribute information of the operating system kernel. Since the file format is added to the temporary file, the function of parsing temporary files in the file format and the function of applying temporary files in the file format can be added to the operating system kernel. Among them, parsing temporary files can be understood as reading temporary files in the file format. In the process of parsing the temporary file system initramfs, the xattr file attribute information of each temporary file is parsed and stored at the same time. The xattr file attribute information can be an extended attribute, which is used to provide additional user-defined attributes for the file and is stored in the form of key-value pairs. After SELinux is initialized, the SELinux label information of each file can be applied to start Android's original SELinux-related protection mechanism.

[0061] In step S120, when the device is started, the modified operating system kernel and the operating system image file are loaded into the memory area of ​​the trusted virtual machine, and the trusted virtual machine loads the operating system.

[0062] In the disclosed embodiment, the virtual machine manager VMM uses the virtual machine monitor Linux KVM to call the trusted firmware to create a trusted virtual machine. Exemplarily, the second trusted firmware RMM can be called to create a trusted virtual machine. The trusted virtual machine can be a new Realm virtual machine. After the trusted virtual machine is created, the modified operating system kernel and operating system image file can be loaded into the memory area of ​​the trusted virtual machine. Exemplarily, the operating system kernel that adds the function of parsing temporary files and the function of applying temporary files, as well as the operating system image file generated by modifying the partition table of the operating system framework, the file format used by the temporary file system, and modifying the operating system kernel can be loaded into the memory area of ​​the constructed new Realm virtual machine.

[0063] Furthermore, the second trusted firmware RMM measures the loaded operating system image file and application file to generate an initial measurement value for subsequent integrity verification. This measurement value can be used as part of the measurement report and transmitted to an external verification party through a remote attestation mechanism.

[0064] It should be noted that the disclosed embodiments do not specifically limit the order of creating a new Realm virtual machine and modifying the operating system to generate an operating system image file. For example, a new Realm virtual machine may be created first, and then the operating system may be modified to generate an operating system image file; or the operating system may be modified to generate an operating system image file first, and then a new Realm virtual machine may be created.

[0065] In step S130 , after the modified operating system kernel is loaded, the operating system and operating system applications are configured to run in the Realm world.

[0066] In the disclosed embodiment, after the modified operating system kernel is loaded into the memory area of ​​the trusted virtual machine, the operating system and its operating system applications can run in the Realm world, thereby achieving complete isolation from other execution environments. When the operating system and its operating system applications run in the Realm world, multiple operating system applications can run as a group of applications in one Realm virtual machine, and multiple operating system applications can also run in multiple trusted Realm virtual machines respectively, which is determined according to actual needs.

[0067] When the operating system is applied to the Realm world for application execution, the operating system application and the operating system framework run at the EL0 privilege level of the Realm world, and the operating system kernel runs at the EL1 privilege level, and both run in the Realm world. The operating system application can use the interface API and services provided by the operating system normally and execute safely in an isolated environment. In the Realm state, all data will be encrypted and protected to prevent high-privilege attackers from stealing or tampering with data through physical or memory access methods.

[0068] In some embodiments, reference Figure 4 As shown in , remote attestation or local attestation can be performed according to actual needs. In the embodiment of the present disclosure, the operating system application calls the second trusted firmware RMM through the operating system kernel to generate a measurement report. The measurement report includes the measurement values ​​of the operating system and the platform, and the measurement report may also include the measurement values ​​of the virtual machine, the measurement values ​​of the loaded operating system image file, and the measurement values ​​of the application file. When necessary, the operating system application can send the measurement report to an external remote verification party to verify whether the operating system application and the operating system are in a trusted state. When performing remote attestation, the measurement values ​​in the obtained measurement report can be matched with the corresponding initial measurement values. When the measurement values ​​of all parameters are consistent with the initial measurement values, it can be considered that the operating system application and the operating system are in a trusted state through remote attestation. When the measurement value of any parameter is inconsistent with the initial measurement value of the parameter, it can be considered that the remote attestation has not been passed, and the operating system application and the operating system are not in a trusted state. In addition, the operating system application can also directly save the measurement report locally to realize local verification of the trusted state of the operating system application and the operating system without sending the measurement report to an external remote verification party.

[0069] Through the remote attestation provided by Arm CCA, the system can report the trustworthiness of its operating environment to the remote verifier during operation. By modifying the operating system to add the relevant functions of RSI (Realm Service Interface), the added relevant functions can enable the operating system application to call the second trusted firmware RMM to obtain a measurement report. The measurement report includes the measurement values ​​of the trusted virtual machine (Realm virtual machine), the measurement values ​​of the platform, the measurement values ​​of the operating system, and the measurement values ​​of the operating system image file and the measurement values ​​of the application file. One or more of the measurement reports are used for remote attestation. When performing remote attestation, remote attestation can be performed by verifying whether the measured values ​​of the parameters are consistent. When the measured value of each parameter is consistent with the initial measured value of the parameter, it can be considered to have passed the remote attestation. Remote attestation can ensure that the remote entity has continuous trust in the security status of the system, and can detect the execution of the simulated hardware platform to ensure that it runs on a trusted hardware platform.

[0070] In the disclosed embodiment, the entire operating system and operating system applications are placed in a trusted virtual machine for execution, and multiple security mechanisms such as integrity verification, remote attestation, and memory encryption at device startup are combined to achieve a highly secure Android application and system operating environment that can effectively resist attacks from high-privileged attackers and physical attacks. By utilizing the isolation protection mechanism provided by Arm CCA, Android applications and the entire Android operating system are run in a trusted execution environment Realm to achieve higher integrity and confidentiality protection. By providing an Android operating environment in a trusted execution environment Realm, Android applications can run independently of traditional non-secure environments, thereby resisting the threats of high-privileged and physical attackers.

[0071] In the disclosed embodiment, by running the entire Android environment in the Realm trusted virtual machine, isolation protection and highly secure data protection measures that combine software and hardware are implemented, which can resist high-privilege attackers with physical device access rights. Continuous trusted verification is achieved through a remote attestation mechanism, which significantly improves the security of Android applications and operating systems, and can be applied to security protection in highly sensitive scenarios such as finance, identity authentication, and privacy protection.

[0072] Figure 5 The specific flow chart of the operating system application execution is schematically shown, refer to Figure 5 As shown in , it mainly includes the following steps:

[0073] In step S502, the operating system loads a first trusted firmware Arm Trusted Firmware, and the first trusted firmware initializes hardware resources of the device.

[0074] In step S504, after the hardware resource initialization is completed, the second trusted firmware RMM is started.

[0075] In step S506, a trusted virtual machine is created, where the trusted virtual machine is a new Realm virtual machine.

[0076] In step S508, the modified operating system kernel and operating system image file are loaded into the memory area of ​​the trusted virtual machine.

[0077] In step S510, the RMM measures the loaded operating system image file and application file to generate initial measurement values ​​for integrity verification.

[0078] In step S512, after the operating system kernel is completely loaded, the operating system and its operating system applications run in the Realm world to achieve complete isolation from other execution environments.

[0079] In step S514, the operating system application calls the RMM through the operating system kernel to generate a measurement report, and performs remote certification based on the measurement report.

[0080] The technical solution in the disclosed embodiment provides isolation protection and integrity verification combining software and hardware on the Android platform, and runs the Android application and operating system in a protected trusted virtual machine, which effectively improves the isolation and security of the system. Through this isolation, the execution environment of the application and operating system can resist the intrusion of high-privilege attackers. Even if the attacker obtains the control authority of the physical device, it is difficult to directly affect the application and system running in the isolated environment. Compared with the traditional TrustZone and pKVM solutions, it provides a higher level of isolation environment, reduces the attack surface, and significantly enhances the protection of sensitive data in the system.

[0081] By integrating the isolation of trusted virtual machines, memory data during application and system operation can be encrypted and protected. For highly sensitive application data, such as privacy information in the fields of finance and identity authentication, the dynamic encryption function effectively prevents attackers from stealing or tampering with memory data through physical means, thereby further improving data security and confidentiality.

[0082] By initially measuring the contents that the operating system and applications depend on and filling them into memory, the application execution environment can be effectively prevented from being tampered with, improving the overall integrity of the system. Integrity verification when the system and applications are started can ensure that the operating system and applications run under safe and reliable conditions. This enhanced integrity protection has a significant effect on preventing malicious tampering and ensuring the security of application execution. At the same time, a remote verification mechanism is used to ensure that it runs on a trusted hardware platform.

[0083] The disclosed embodiments effectively make up for the security deficiencies of traditional Android applications when facing high-privilege attacks, provide complete isolation, encryption and remote verification support for Android applications, significantly improve the security and anti-attack capabilities of the system and applications, and meet the protection needs of high-security applications.

[0084] In some embodiments of the present disclosure, an application execution device is provided, which may include: a mirroring module, a loading model, and a running module, wherein:

[0085] The mirroring module is used to mirror the operating system framework and operating system applications, generate operating system image files, and modify the operating system kernel;

[0086] A loading module, used to load the modified operating system kernel and the operating system image file into the memory area of ​​the trusted virtual machine when the device is started; the trusted virtual machine loads the operating system;

[0087] The run module is used to configure the operating system and operating system applications to run in the Realm world after the modified operating system kernel is loaded.

[0088] In an exemplary embodiment of the present disclosure, the image module includes: a partition table modification module, which is used to modify the partition table of the operating system framework and modify the file format used by the temporary file system in the operating system application to generate the operating system image file; wherein the operating system image file can be directly loaded by the operating system kernel; and a kernel modification module, which is used to modify the attribute information of the operating system kernel.

[0089] In an exemplary embodiment of the present disclosure, the partition table modification module includes: a root partition configuration module, which is used to modify the partition table of the operating system framework and mount the initialized file system to the root partition in the partition table.

[0090] In an exemplary embodiment of the present disclosure, the file format modification module includes: an attribute field adding module, which is used to add an attribute field in the file header used by the temporary file system so that the temporary files in the temporary file system carry file attribute information; wherein, the attribute field is an xattr field, and the file format of the temporary file is a CPIO file format.

[0091] In an exemplary embodiment of the present disclosure, the file format modification module includes: an attribute information adding module, which is used to add a function of parsing the temporary file and a function of applying the temporary file in the attribute information of the operating system kernel.

[0092] In an exemplary embodiment of the present disclosure, the device also includes: a measurement module, which is used to load the image files of the operating system and the operating system application into the memory area of ​​the trusted virtual machine when the device is started, and measure the image files to obtain a measurement value; and an integrity verification module, which is used to perform verification based on the measurement value to perform integrity verification.

[0093] In an exemplary embodiment of the present disclosure, the operating system application, the operating system framework, and the operating system kernel run in a Realm world and are deployed in the same trusted virtual machine.

[0094] In an exemplary embodiment of the present disclosure, the device further includes: a first running module, which is used for the operating system application and the operating system framework to run at a first privilege level of the Realm world; and a second running module, which is used for the operating system kernel to run at a second privilege level of the Realm world.

[0095] In an exemplary embodiment of the present disclosure, the device also includes: a measurement report acquisition module, which is used to add a function of obtaining a measurement report to the operating system to call a second trusted firmware to obtain a measurement report; a certification module, which is used to perform remote certification or local certification based on the measurement report; wherein the measurement report includes one or more of the measurement values ​​of the trusted virtual machine, the measurement values ​​of the platform, the measurement values ​​of the operating system, and the measurement values ​​of the operating system image file and the measurement values ​​of the application file.

[0096] It should be noted that the specific details of each part of the above-mentioned application execution device have been described in detail in some implementation methods of the corresponding methods. The undisclosed details can be found in the implementation content of the method part, and will not be repeated here.

[0097] The exemplary embodiment of the present disclosure also provides an electronic device. The electronic device may be the above-mentioned terminal device or the server. Generally, the electronic device may include a processor and a memory, the memory is used to store executable instructions of the processor, and the processor is configured to execute the above-mentioned application execution method by executing the executable instructions. In addition, the electronic device may also include a display for displaying an operation interface.

[0098] Below, an electronic device is exemplarily described in the form of a general-purpose computing device. The electronic device is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0099] Components of the electronic device may include, but are not limited to: the at least one processing unit mentioned above, the at least one storage unit mentioned above, a bus connecting different system components (including the storage unit and the processing unit), and a display unit.

[0100] The storage unit stores a program code, which can be executed by the processing unit, so that the processing unit performs the steps according to various exemplary embodiments of the present disclosure described in the above “Exemplary Method” section of this specification. For example, the processing unit can perform the following steps: Figure 1 Follow the steps shown in .

[0101] The storage unit may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) and / or a cache memory unit, and may further include a read-only memory unit (ROM).

[0102] The storage unit may also include a program / utility having a set (at least one) of program modules, such program modules including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0103] The bus may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0104] The electronic device can also communicate with one or more external devices (such as keyboards, pointing devices, Bluetooth devices, etc.), and can also communicate with one or more devices that enable users to interact with the electronic device, and / or communicate with any device (such as routers, modems, etc.) that enables the electronic device to communicate with one or more other computing devices. This communication can be carried out through an input / output (I / O) interface. In addition, the electronic device can also communicate with one or more networks (such as local area networks (LANs), wide area networks (WANs) and / or public networks, such as the Internet) through a network adapter. As shown in the figure, the network adapter communicates with other modules of the electronic device through a bus. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0105] It should be noted that, in some embodiments of the present disclosure, a computer program product is also provided. The computer program product includes a computer program. When the computer program is executed by a processor, the above method is implemented.

[0106] In one embodiment, the computer program product may be a tangible product containing a computer program, such as a computer-readable storage medium storing a computer program. The readable storage medium may be a storage medium based on electrical, magnetic, optical, electromagnetic, infrared, or other signals, including but not limited to: random access memory (RAM), read-only memory (ROM), magnetic tape, floppy disk, flash memory (Flash), mechanical hard disk (HDD), solid-state drive (SSD), and the like. Exemplarily, the computer program product may be implemented as a non-volatile storage medium storing a computer program, such as a read-only memory, a NAND flash memory, and the like.

[0107] In one embodiment, the computer program product may be an intangible product including a computer program. Exemplarily, the computer program product may be implemented as a virtual digital product, such as a digital file storing an executable file, an installation package, etc. of the computer program.

[0108] The code of the computer program can be written in one or more programming languages. Programming languages ​​such as C language, Java, C++, etc. The program code can be executed entirely on the user computing device, or partially on the user computing device, or as a separate software package, or partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, such as a local area network (LAN), a wide area network (WAN), etc., or can be connected to an external computing device (e.g., an Internet connection provided by an operator).

[0109] The computer program may be carried or transmitted via electrical, magnetic, optical, electromagnetic, infrared, or other signals. The electronic device may convert the signal carrying the computer program into a digital signal, thereby running the computer program. When the computer program is run on an electronic device, its code is used to enable the electronic device to execute (more specifically, the processor of the electronic device may execute) the method steps of various exemplary embodiments of the present disclosure.

[0110] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0111] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing what is disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary technical means in the art that are not disclosed in the present disclosure. The specification and embodiments are to be considered merely as exemplary, and the true scope and spirit of the present disclosure are indicated by the claims.

[0112] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. An application execution method, characterized in that: include: Mirror the operating system framework and operating system applications, generate an operating system image file, and modify the operating system kernel; When the device is started, the modified operating system kernel and the operating system image file are loaded into the memory area of ​​the trusted virtual machine, and the trusted virtual machine loads the operating system; After the modified operating system kernel is loaded, configure the operating system and operating system applications to run in the Realm world.

2. The application execution method according to claim 1, characterized in that: The mirroring of the operating system framework and the operating system application to generate an operating system image file and modifying the operating system kernel includes: Modifying the partition table of the operating system framework and modifying the file format used by the temporary file system in the operating system application to generate the operating system image file; wherein the operating system image file can be directly loaded by the operating system kernel; Modify the attribute information of the operating system kernel.

3. The application execution method according to claim 2, characterized in that: The modifying of the partition table of the operating system framework includes: The partition table of the operating system framework is modified, and the initialized file system is mounted to the root partition of the partition table.

4. The application execution method according to claim 2, characterized in that: The modification of the file format used by the temporary file system in the operating system application includes: Adding an attribute field in a file header used by the temporary file system so that temporary files in the temporary file system carry file attribute information; The attribute field is an xattr field, and the file format of the temporary file is a CPIO file format.

5. The application execution method according to claim 2, characterized in that: The modifying of the attribute information of the operating system kernel includes: A function of parsing the temporary file and a function of applying the temporary file are added to the attribute information of the operating system kernel.

6. The application execution method according to claim 1, characterized in that: The method further comprises: When the device is started, the image files of the operating system and the operating system application are loaded into the memory area of ​​the virtual machine, and the image files are measured to obtain a measurement value; Verification is performed based on the measured values ​​to perform integrity verification.

7. The application execution method according to claim 1, characterized in that: The operating system application, the operating system framework, and the operating system kernel run in the Realm world and are deployed in the same trusted virtual machine.

8. The application execution method according to claim 7, characterized in that: The operating system application and the operating system framework run at a first privilege level of the Realm world; the operating system kernel runs at a second privilege level of the Realm world.

9. The application execution method according to claim 1, characterized in that: The method further comprises: Adding a function of obtaining a measurement report to the operating system to obtain the measurement report; Perform remote certification or local certification based on the measurement report; The measurement report includes one or more of the measurement value of the trusted virtual machine, the measurement value of the platform, the measurement value of the operating system, the measurement value of the operating system image file, and the measurement value of the application file.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the application execution method according to any one of claims 1 to 9 is implemented.