Trusted execution environment security enhancement method and system, electronic equipment and medium

By creating instance domains in a trusted execution environment and leveraging PKRU register management permissions, security vulnerabilities caused by resource sharing in hardware enclave technology are solved, significantly enhancing the security and reliability of the enclave.

CN120012122APending Publication Date: 2025-05-16CHANGSHA SEMICON TECH & APPL INNOVATION RES INST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411860028.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When existing hardware enclave technology protects sensitive data and computing tasks, there are security vulnerabilities caused by resource sharing. Attackers can destroy the integrity of the isolated environment by abusing PKRU registers or executing non-privileged instructions, resulting in leaks of sensitive data.

Method used

By creating an instance domain in a trusted execution environment and setting up a memory domain and instruction set domain for it, using the PKRU register to manage the permissions of the instance domain, fine-grained memory and instruction resource isolation is achieved.

Benefits of technology

Effectively enhance the security and reliability of the enclave, preventing attackers from breaking security boundaries through resource sharing, and ensuring the confidentiality and integrity of sensitive data and computing tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure HDA0005192971560000011
    Figure HDA0005192971560000011
  • Figure HDA0005192971560000012
    Figure HDA0005192971560000012
  • Figure HDA0005192971560000021
    Figure HDA0005192971560000021
Patent Text Reader

Abstract

The invention provides a trusted execution environment security enhancement method and system, electronic equipment and a medium. The method comprises the following steps: creating a trusted execution environment; creating an instance domain for the component needing to be isolated, and setting a memory domain and an instruction set domain for the instance domain; different lock keys are distributed to the trusted execution environment memory at the page entry level, and different access keys are distributed to the memory domain; the current instance domain applies for a memory access request, and the memory domain key of the instance domain is compared with the accessed page table entry lock key; if the matching fails, judging that the access is illegal; if matching succeeds, checking instruction set domain instruction permission and register permission; and if the instruction authority and the register authority pass the check, indicating that the current instance domain does not exceed the authority. According to the method, a single virtual address space model and a coarse-grained instruction set management model of a traditional trusted execution environment are expanded into a composite multi-domain model based on a page table key and an instruction set bitmap, so that the enclave security and reliability are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of confidential computing and integrated circuit design information security technology, and in particular, relates to a trusted execution environment security enhancement method, system, electronic device and medium. Background Art

[0002] As the core component responsible for data processing in the hardware system, the performance and security of the processor directly affect the reliable operation of the entire system. Data security can be divided into three main aspects of protection: storage state, transmission state, and operation state. Compared with data security protection technologies in storage state and transmission state, such as firewalls, security gateways, and security databases, which have made significant progress, the security protection technology of operation state data is still relatively weak, becoming an important shortcoming in the current research field. How to effectively ensure the security of operation state data from the underlying processor architecture to the entire hardware system level has become a research hotspot in academia and industry, and is also one of the core problems that need to be solved in the national information security work. The design of a new security architecture around processor vulnerabilities can significantly improve the security of the entire system, thereby effectively responding to potential threats. This is of great strategic significance for national information security. In-depth research in this field can not only provide theoretical basis and technical support for the high reliability of processors, but also lay a solid foundation for building a new generation of information technology security system. By promoting the innovation of processor security architecture, it is expected to comprehensively improve the risk resistance of information systems in the future and provide stronger protection for network security in key areas of the country.

[0003] Hardware Enclave is a hardware-based security isolation technology, whose core goal is to protect sensitive data and computing tasks in a specific area from external interference or malicious attacks through a hardware-supported isolation environment. This technology is widely used in a variety of processor architectures, such as Intel SGX, AMD SEV, ARM TrustZone, and RISC-V Keystone, so that the confidentiality and integrity of sensitive code and data can be ensured when running on untrusted operating systems and hypervisors. However, although hardware enclave technology provides unprecedented security guarantees, it also introduces new security challenges and attack surfaces.

[0004] Research has shown that attackers can abuse the resources of hardware enclaves in a variety of ways to leak confidential data. For example, by abusing the PKRU register or executing unprivileged WRMSR instructions, attackers can compromise the integrity of the isolated environment. In addition, memory management vulnerabilities within the enclave may also become an entry point for attackers, leading to the leakage of sensitive data. Current hardware typically only provides coarse-grained access control for enclave resources, such as enclaves sharing common register files with non-enclave environments. This sharing mechanism provides attackers with the opportunity to use carefully crafted payloads to launch attacks through register resources, thereby causing "re-entrancy" vulnerabilities. Such vulnerabilities may allow malicious code to invade isolated enclaves and undermine their security.

[0005] In addition, the existing resource isolation mechanism still has limitations in dealing with these threats. Current methods mainly focus on memory isolation, such as extending the SDK (Software Development Kit) of SGX (Intel Software Guard Extensions) to securely merge MPK (Memory Protection Key), but MPK can only control the read and write permissions of the corresponding memory, but cannot control the execution permissions. Therefore, MPK-based work cannot control the execution permissions of the isolation domain. They put all the codes of the isolation domain in the initial domain and grant execution permissions to the code of the initial domain. At the same time, new instructions and registers will be added during the implementation process. Once these instructions and registers are controlled, memory isolation will be threatened. As a result, attackers can break through the security boundaries of the enclave by exploiting instruction or register sharing. Others use nested enclave technology to expand the traditional single protection domain and support fine-grained hierarchical security isolation by accommodating multiple internal enclaves in an external enclave. This method can also break through the security boundary through instructions and registers. You can also check the permissions of instructions through control flow integrity. This method is often based on compiler technology to check in advance, which has a large overhead, cannot provide fine-grained control over instructions and registers, and cannot manage newly added third-party libraries.

[0006] With the rapid development of Trusted Execution Environment (TEE) technology, the application scenarios of hardware enclaves in processing highly sensitive data are increasing, but their security risks are also becoming more prominent. The potential threat of attackers stealing data through hardware enclaves is becoming more serious, further highlighting the urgency of researching and improving the security of enclave technology. Summary of the invention

[0007] The purpose of the present invention is to address the deficiencies in the prior art and provide a trusted execution environment security enhancement method, system, electronic device and medium to enhance the security and reliability of the trusted execution environment.

[0008] In order to achieve the above object, the technical solution adopted by the present invention is:

[0009] A method for enhancing security of a trusted execution environment includes the following processes:

[0010] The secure monitor creates a trusted execution environment, which includes enclaves;

[0011] The enclave creates an instance domain for the component that needs to be isolated. The enclave sets the memory domain and instruction set domain for the instance domain. The instance domain has memory permissions and instruction set permissions, which are controlled by the memory domain and instruction set domain respectively. The enclave assigns lock keys to page table entries and assigns access-allowed keys to the memory domain. The instruction and register read and write permissions allowed by the instruction set domain are set.

[0012] The current instance domain applies for a memory access request, and the memory management unit matches the memory domain key of the current instance domain with the lock key of the page table entry;

[0013] If the hot key of the current instance domain fails to match the lock key of the target memory domain, the memory management unit matches all the permission keys of the instance domain with the lock key at the target virtual address being accessed; if all the permission keys of the instance domain still fail to match the lock key of the target memory domain, it is determined to be an illegal access;

[0014] If the hot key of the current instance domain matches the lock key of the target memory domain, or all the permission keys owned by the instance domain match the lock key of the target memory domain and the permission key in the PKRU register is updated, the instruction set domain instruction permission check is further performed; if the instruction set domain to which the current instance domain belongs allows the execution of the current instruction, and the instruction of the target memory domain displays the read-write control status register, the register access permission is checked;

[0015] If the instruction set domain to which the current instance domain belongs does not allow the execution of the current instruction, or the register access permission check fails, an exception is triggered;

[0016] If the register access permission check passes, or the instruction set domain to which the current instance domain belongs allows the execution of the current instruction and the instruction of the target memory domain does not display the read / write control status register, it indicates that the current instance domain has not exceeded the permission and the program execution flow is executed normally.

[0017] The present invention extends the single virtual address space model of the traditional trusted execution environment into a multi-domain model based on page table keys, realizes page table level isolation, does not require physical continuous memory, reduces the complexity of the trusted computing base, and improves the security of the trusted execution environment; the present invention uses the method of managing instance domains by PKRU registers, combines the memory domain with the instruction set domain, and can manage the resources in the enclave in a fine-grained manner.

[0018] Furthermore, the PKRU register includes multiple permission keys, the number of the current instance domain, and the number of the instruction set domain to which the current instance domain belongs; the first permission key corresponds to the private memory domain of the instance domain, and the remaining permission keys correspond to the shared memory domain.

[0019] By caching the implementation domain permissions in registers, the efficiency of isolation checking is optimized, further improving the isolation performance of the trusted execution environment.

[0020] Furthermore, both the hot key and the permission key include a multi-bit key value and a 1-bit write flag; the permission key of the current instance domain and the lock key of the target memory domain have the same key value, and the write flag of the hot key is set to 1, and an instruction permission check is performed.

[0021] Furthermore, the instruction permission check includes: indexing the instruction permission bitmap according to the permission number of the instruction set domain to determine the execution permission of the current instance domain to the instruction set domain.

[0022] Furthermore, the register access permission check includes: indexing a register permission bitmap according to the number of the control status register to determine the read and write permissions of the instruction set domain to which the current instance domain belongs to the control status register.

[0023] Furthermore, the instruction permission bitmap and the register permission bitmap are set in a cache area of ​​the instruction set checking unit.

[0024] Furthermore, an instruction permission bitmap template is set in the cache area of ​​the instruction set check unit, and the instruction permission bitmap is managed through the instruction permission bitmap template; the instruction permission bitmap template is compared with the instruction permission bitmap, and if the difference value between the instruction permission bitmap template and the instruction permission bitmap is less than or equal to a threshold value, the security monitor loads the difference value and restores the instruction permission bitmap through the permission bitmap template and the difference value.

[0025] Speed ​​up the updating and loading process of permission bitmaps by compressing the throughput of loading permission bitmaps.

[0026] Based on the same inventive concept, the present invention also provides a trusted execution environment security enhancement system, including a memory check unit, an instruction set check unit, an initial domain unit, a security monitor unit and an instance domain unit;

[0027] Memory check unit: responsible for checking the memory access rights of the instance domain;

[0028] Instruction set check unit: responsible for checking instruction permissions and register access permissions in the instance domain;

[0029] Initial domain unit: used to manage instance domains, memory domains, memory domain lock keys, PKRU registers, and initialize enclaves;

[0030] Security monitor unit: responsible for storing domain bitmaps, providing privileged target interface library interfaces, and initializing the trusted execution environment;

[0031] Instance domain unit: Instance domain permissions are restricted by both the memory domain and the instruction set domain.

[0032] Based on the same inventive concept, the present invention also provides an electronic device, including:

[0033] one or more processors;

[0034] A memory having one or more programs stored thereon, which, when executed by the one or more processors, enables the one or more processors to implement the steps of the trusted execution environment security enhancement method.

[0035] Based on the same inventive concept, the present invention also provides a computer-readable storage medium storing a computer program, which implements the steps of the trusted execution environment security enhancement method when executed by a processor.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] The present invention expands the single virtual address space model and coarse-grained instruction set management model of the traditional trusted execution environment into a composite multi-domain model based on page table keys and instruction set bitmaps, which can manage memory resources with a minimum granularity of 4Kb, manage the execution of each instruction, and the read and write permissions of each register; comprehensively manage enclave resources, and greatly enhance the security and reliability of the enclave. The present invention uses the method of managing instance domains with PKRU registers, combines the memory domain with the instruction set domain, and can manage the resources in the enclave in a fine-grained manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 A schematic diagram of an embodiment of the present invention;

[0039] Figure 2 A schematic diagram of a trusted execution environment security enhancement system of the present invention;

[0040] Figure 3 It is a schematic diagram of the PKRU register structure of the present invention;

[0041] Figure 4A schematic diagram of a flow chart of checking memory access rights of an instance domain according to a virtual address according to the present invention;

[0042] Figure 5 It is a schematic diagram of the ISA resource isolation method based on the permission bitmap of the present invention;

[0043] Figure 6 A schematic diagram of an IRDID register structure of the present invention;

[0044] Figure 7 A schematic diagram of a permission bitmap updating method of the present invention;

[0045] Figure 8 It is a schematic diagram of the page table entry structure of the present invention. DETAILED DESCRIPTION

[0046] The present invention will be described in detail below in conjunction with the embodiments. It should be noted that the embodiments and features of the embodiments of the present invention can be combined with each other without conflict. For the convenience of description, if the words "upper", "lower", "left" and "right" appear in the following, they only indicate that the upper, lower, left and right directions are consistent with the drawings themselves, and do not limit the structure.

[0047] Example

[0048] like Figure 1 The trusted execution environment security enhancement method based on the RISC-V architecture of this embodiment includes the following process:

[0049] Step 1: Initialize the Trusted Execution Environment

[0050] The secure monitor (SM) creates a trusted execution environment, the operating system loads the trusted program binary file, the secure monitor performs trusted authentication, and switches to the enclave entry to complete the trusted execution environment initialization.

[0051] The Trusted Execution Environment (TEE) consists of trusted hardware, a secure monitor, and an enclave.

[0052] Trusted hardware is a CPU package built by a trusted vendor that contains a standard RISC-V core and a root of trust (TCB) that is compatible with the specific TEE system. The hardware also contains optional features such as cache partitioning, memory encryption, cryptographically secure random sources, etc. The security monitor supports these optional features through platform-specific plugins.

[0053] The RISC-V architecture is an instruction set architecture, similar to the X86 architecture and the ARM architecture, including a basic instruction set and an extended instruction set.

[0054] The Secure Monitor is an M-mode software with a small root of trust. The SM provides interfaces to manage the enclave lifecycle and leverage platform specific features. The Secure Monitor performs most of the security guarantees of the TEE, ensuring isolation between the enclave and the untrusted operating system.

[0055] An enclave is an environment isolated from the untrusted operating system and other enclaves. Each enclave has an independent physical memory area that only the enclave itself and the SM can access. An enclave consists of a user-level enclave application (eapp) and a management-level runtime.

[0056] An enclave application (eapp) is a user-level application that executes in an enclave. You can build a custom eapp from scratch, or run an existing RISC-V executable in a TEE.

[0057] The runtime is S-mode software, responsible for implementing functions such as system calls, trap processing, and virtual memory management.

[0058] Trusted program binaries are applications that run in a trusted execution environment and are provided by users, who can use the trusted execution environment to protect their programs.

[0059] Step 2: Initialization of the Trusted Execution Environment Security Enhancement System

[0060] The Enclave entry code (the Enclave entry code is the SDK code provided by TEE) is responsible for initializing the Trusted Execution Environment Security Enhancement System. The entry code creates independent instruction set domains and memory domains for components that need to be isolated, assigns a dedicated key to each memory domain, and binds the page table entries corresponding to the memory domain to the corresponding keys. The instruction set domain and the memory domain respectively control the instruction execution permissions and memory read and write ranges and permissions of the isolated components. After completing the initialization of the Trusted Execution Environment Security Enhancement System, jump to the entry code of the trusted program.

[0061] Step 3: Memory access request processing

[0062] After initialization, the processor obtains the code to be executed through memory access. The processor uses the memory management unit (MMU) to convert the virtual address to the physical address. When the MMU captures a memory request, it sends the instance domain identity information of the memory access request and its hot key.

[0063] Step 4: Memory access exception handling

[0064] The newly added memory check unit in the MMU determines whether the memory access request violates the isolation rule. The memory check unit checks whether the hot key matches the lock key of the target address (that is, the key of the page table entry corresponding to the memory domain, corresponding to Figure 8 The Pkey part in the address field matches the Pkey part in the address field. If the match succeeds, it indicates that the access is legal, and the instruction and register permission check continues. If the match fails, an illegal access exception signal is triggered, and the arbitration post-processing module is called.

[0065] Step 5: Memory arbitration post-processing

[0066] The arbitration post-processing module (belonging to the memory check unit) performs further checks based on the matching results. If the match fails, read the key stored in the trusted memory and verify whether the key set of the current instance domain matches the target address lock key: if the match is successful, update the "hot" key and continue the instruction and register permission check; if the match fails, it is judged as a serious isolation access violation and an abnormal signal is fed back.

[0067] Step 6: Command Access Arbitration

[0068] When memory arbitration is passed, the processor loads the target instruction (the target instruction refers to the instruction read by accessing the target memory domain) into the pipeline. During the pipeline execution phase, the instruction set check unit verifies whether the target instruction is allowed to be executed in the instruction set domain to which the current instance domain belongs: if execution is allowed, the register access rights are further checked; if not, an exception is triggered.

[0069] Step 7: Register Access Rights Arbitration

[0070] After instruction access arbitration, if the instruction involves the Control and Status Register (CSR), the access rights of the Control and Status Register need to be checked. The permission bitmap is indexed according to the register number to determine the read and write permissions of the register in the current instruction set domain: if the permission check passes, the instruction is allowed to execute; if the check fails, a hardware exception is triggered, indicating that the instruction or register usage permissions are violated.

[0071] The trusted execution environment security enhancement system (enclave security enhancement architecture) of this embodiment is as follows: Figure 2 As shown, the system adopts the above method and mainly includes a memory check unit, an instruction set check unit, an initial domain unit, a security monitor unit and an instance domain unit;

[0072] Memory check unit: responsible for checking the memory access rights of the instance domain;

[0073] Instruction set (ISA) check unit: responsible for checking instruction permissions and register permissions in the instance domain;

[0074] Initial domain unit: used to manage instance domains, memory domains, memory domain lock keys, PKRU registers, and initialize enclaves;

[0075] Security Monitor Unit: responsible for storing domain bitmaps, providing privileged target interface library (SBI) interfaces, and initializing the trusted execution environment;

[0076] Instance domain unit: The permissions of the instance domain (the area where the program actually runs) are restricted by both the memory domain and the instruction set domain.

[0077] The instance domain permissions of the instance domain unit are restricted by the memory domain and the instruction set domain. The instance domain information is stored in the PKRU (Protection Keys for User-space Register) register, and its structure is as follows: Figure 3 As shown, it is managed by a small handler of the initial domain (when the program is first executed, the provided entry code will be executed. The functions in it will be responsible for creating the initial domain. The initial domain manages some data structures, that is, manages the data structures used by other domains and protects its own data through keys. These are all handled in the entry code. After the initialization is completed, it jumps to the user's code execution). The 64-bit PKRU register can contain 4 "hot" permission keys, which is completely sufficient for fine-grained domains. The first permission key is used as a private memory domain of the instance domain, and the remaining three can be used for shared memory domains or other private memory domains. In addition to the 10-bit key value, each permission key also has a write flag bit. Only when the key value and the write flag position are 1 at the same time, the corresponding memory domain allows the instance domain to perform write operations, thereby realizing read-only sharing of memory. PKRU also reserves the ID field representing the current instance domain and the ISA_ID field representing the instruction set domain to which the current instance domain belongs. The former is used for exception handling when a PKRU miss occurs (the 4 permission keys in the PKRU do not match the lock key), and the latter is used to determine whether the instruction set domain needs to be switched when switching domains. The highest bit is reserved and is not used for any valid purpose.

[0078] The PKRU register is a user-mode control status register that can be read and written through standard RISC-V CSR instructions. Its management is the responsibility of the initial domain. When a domain switch occurs, the initial domain is responsible for refreshing the PKRU register and filling in the new PKRU value.

[0079] Domain switching provides clear switching permissions and well-defined entry points (call gates) to prevent cross-domain control flow transfer attacks. Information on all entry functions needs to be registered in the initial domain. The caller applies to the initial domain to call the function of another domain. The initial domain will wrap the caller's return entry and the callee's entry function into a call gate and generate a unique ID for each to ensure a credible and unforgeable call gate. The wrapper code has the same type signature as the target entry function, so there is no need to reorder parameters or return values.

[0080] Cross-domain calls and returns need to go through a call gate. The initial domain provides the call gate ID and information indicating whether it is a call or a return. The initial domain is responsible for deciding whether to allow the call or return (based on the registration information in the previous paragraph) and performing a switch to the target domain.

[0081] The PKRU registers can prevent unauthorized changes to the protection key policy. In principle, the control status registers in user mode can be configured through standard CSR instructions at all privilege levels. However, it is guaranteed that only the trusted initial domain can configure the PKRU registers, and other domains do not have read and write permissions to the PKRU registers. This is restricted by the instruction set domain bound to each instance domain. The instruction set domain can restrict the access rights of other instance domains to the PKRU registers except the initial domain.

[0082] The memory check unit is responsible for checking the memory access rights of the instance domain. The process is as follows: Figure 4 As shown, the implementation process is:

[0083] 1. When a memory access occurs, the memory check unit accesses the TLB or page table to query the memory domain lock key corresponding to the virtual address;

[0084] 2. The memory check unit requests the CPU to return the authority key owned by PKRU;

[0085] 3. The memory check unit checks whether the permission key owned by the current instance domain contains the lock key corresponding to the virtual address.

[0086] When a memory access occurs, the primary task of the memory check unit is to verify the memory domain lock key of the virtual address. Specifically, the memory check unit will first query the translation lookaside buffer (TLB) to determine whether the memory domain lock key corresponding to the virtual address has been cached. If the query result is a TLB hit (TLB is a hardware module in the MMU that accelerates the translation of virtual addresses to physical addresses. A TLB hit indicates that the page table entry is cached in the TLB and there is no need to access the page table in the memory), the lock key is directly obtained and the next step is performed; if a TLB miss occurs, the memory check unit will load the corresponding page table information from the memory and perform a page table traversal. During the page table traversal process, the memory check module locates the corresponding page table entry based on the virtual address and extracts the lock key information from the entry. Through this mechanism, the memory check unit can ensure that the virtual address and the lock key are accurately matched at the page table level, thereby providing support for the subsequent memory access permission verification.

[0087] When the memory check unit requests the CPU to return the hot key owned by the current instance domain, it needs to access the PKRU register of the initial domain management to obtain the permission key. PKRU is accessed through the standard CSR instructions of all permission levels to obtain the permission key of the memory domain. First, check whether the corresponding key value is 0. If it is not 0, it is the memory domain permission owned by the current instance domain. Then check the write flag. If the flag is 0, the memory domain corresponding to the permission key is read-only sharing; if the flag is 1, the instance domain can write to the memory domain.

[0088] The memory check unit checks whether the permission key owned by the current instance domain contains the lock key corresponding to the virtual address. If not, the memory check unit issues an exception, and the exception will be delegated to the initial domain in the user state for processing. The exception indicates that there is no lock key for the current memory address in the register cache. At this time, a memory request needs to be issued to query the complete key managed by the initial domain to see whether the current instance domain has the lock key for the memory address. The exception information is written to the exception-related registers in the user state (including the address where the exception occurred and the target permission key), and then the CPU will jump to the exception handler in the initial domain for execution. The initial domain will read the instance domain ID field in the PKRU to index the structure that manages the instance domain information, and find out whether it has the target permission key. If the search is successful, the PKRU register cache is replaced, and the eviction strategy adopts the LRU strategy. After writing the PKRU register, it returns to the place where the exception occurred and re-executes; if the search fails, it means that a real illegal access exception has occurred. The entire exception handling is captured by the hardware and directly delegated to the initial domain exception handler in the user state for execution. It is transparent to the user and does not need to fall into the kernel.

[0089] The instruction set check unit (ISA check unit) is responsible for checking the instruction and register access rights in the instance domain. Its structure is as follows Figure 5 As shown in the figure, the check of the instruction set domain is performed by the ISA check unit in the pipeline. Since it is necessary to determine whether each instruction executed in the instance domain has permission, the check is performed in the pipeline to easily obtain all the information of the currently executed instruction. Figure 5 As shown, a new module called the instruction set check unit is introduced before the execution stage of the pipeline. The instruction set check unit obtains the unique identification, encoding, and attributes of the currently executed instruction from the pipeline, and can also obtain the source register and target register information carried by the instruction. For registers, only the control status register (CSR) carried by the CSR instruction is concerned. In addition, the instruction set check unit can also directly obtain the permission number value of the current instruction set domain stored in the IRDID register, thereby determining the corresponding instruction permission bitmap.

[0090] For instruction checking, the instruction set check unit indexes the permission bitmap through the unique identifier of the instruction and obtains feedback of 1 or 0, indicating whether the instruction is allowed or not. If a feedback of 0 is obtained, the instruction set check unit will generate a hardware exception and feedback to the security monitor that instruction abuse has occurred after the execution phase. Register access rights will only be checked if the instruction check passes and the current instruction shows that the CSR is used. Implicit CSR modifications or CSR changes caused by side effects are not checked, but this goal can be achieved by further restricting CSR changes in the ISA domain. Register access rights checking is similar to instruction permission checking. The register permission bitmap is indexed by the register number to determine the read and write permissions of the register in the instruction set domain of the current instance domain.

[0091] IRDID (Instruction and Register Domain ID) register, its structure is as follows Figure 6As shown, it is used to store the permission number of the instruction set domain to which the current context (all status information of the currently running program, including ISA resources) belongs. Different from the ISA_ID field in the PKRU register, the value stored in the IRDID register represents the permission number information of the ISA domain of the current context, while the ISA_ID field in the PKRU register represents the ISA_ID to which the domain ID belongs. When a domain (domain refers to the domain name system in the computer field) is executed, the ISA_ID field value in its PKRU is the same as the permission number value of the ISA domain stored in the IRDID register. The lowest bit of the IRDID register is the control bit. When the control bit is turned off (set to 0), the check of the ISA domain is turned off to eliminate the impact on other programs (such as the impact on untrusted programs). The IRDID register is an M-mode register and can only be managed by the secure monitor. When switching to the enclave, the secure monitor sets the control bit of the IRDID register to 1, and when switching out of the enclave, the control bit of the IRDID register is set to 0. For security reasons, the IRDID register is not a standard CSR and cannot be operated through CSR read and write instructions. A dedicated M-mode instruction mIRDID (modify IRDID) is provided to perform read, write and modification.

[0092] RISC-V provides three privilege modes. Machine mode (M mode) has the highest privilege and is responsible for interacting with hardware. Only machine mode can access and configure physical memory protection registers. Physical memory access in other modes will be restricted by the physical memory protection mechanism. The security monitor works in this mode. All memory accesses in this mode use physical addresses. Supervisor mode (S mode) is usually a privileged mode that provides support for the operating system. The host operating system and runtime run in this mode. User mode is the mode in which regular applications without any privileges run. All applications run in this mode.

[0093] ISABuffer optimization and reuse. The ISA check unit obtains the permission number value of the current ISA domain stored in the IRDID register from the pipeline, and finds the corresponding permission bitmap from the memory of the security monitor. This will cause all instructions in the CPU pipeline to be converted into memory-type instructions (because each instruction requires additional memory access to obtain the permission bitmap in the memory), which will cause great performance overhead. This embodiment draws on the design of the Load Store Queue (LSQ) and embeds several independent cache areas (ISABuffer) in the ISA check unit to cache the permission bitmap.

[0094] Each ISA Buffer stores a permission bitmap of an ISA domain, and its structure is as follows Figure 5 As shown, the instruction permission bitmap and register permission bitmap are stored therein respectively. The inspection of instructions and registers will search for permission bits in their respective permission bitmaps through instruction index and register index.

[0095] The initial domain unit is used to manage instance domains, memory domains, and memory domain lock keys, and initialize the enclave security enhancement architecture. During enclave startup, the security monitor creates a special ISA permission domain for the entire enclave space based on user-defined requirements. Code executed in this ISA permission domain will not be checked by the ISA check unit, that is, by default, the ISA check unit is turned off and will not affect the execution of code outside the enclave.

[0096] After the enclave is started, the small handler in the initial domain needs to be initialized first to assign a permission key to private data. The small handler manages all permission keys to ensure that permission keys are not assigned repeatedly. Subsequently, different instance domains will be created and assigned their own private hot keys to achieve mutual isolation. Different instance domains can also have the hot key of a certain memory domain at the same time to achieve memory area sharing. Although you can apply to the small handler to create an instance domain at runtime, there is no conflict between instance domains. The small handler does not force the permissions of different instance domains to be mutually exclusive, that is, different instance domains can have hot keys with different read and write permissions for the same memory domain.

[0097] The security monitor module is responsible for storing the domain bitmap and providing the SBI interface to initialize the trusted execution environment. In the small handler, a field representing the ISA domain is reserved for the identifier of each instance domain. The ISA domain number of the initial domain is 0. By default, the ISA domain number of other newly created instance domains is 1. When creating a domain, you can use flags to specify whether a new restricted ISA domain needs to be allocated to the current instance domain. If necessary, an SBI call request is issued to the privileged layer. The SM creates a new ISA domain according to the security rules and returns a unique ISA domain number. It can be seen that different instance domains can be under the same ISA domain or under different ISA domains, so specific instruction and register resource access control can be implemented for specific instance domains.

[0098] In addition, permission bitmap templates are used to manage instruction permission bitmaps to speed up the updating and loading process of permission bitmaps. For example, the ISA check unit wants to load the permission bitmap of the target ISA domain into the hardware cache Buffer. The ISA check unit will first trigger an exception. The exception is passed to the final stage in the pipeline, and the CPU will jump to the exception handler in the security monitor to execute. The security monitor captures a load buffer exception and compares the permission bitmap of the target ISA domain with the permission bitmap template. If the difference value does not exceed the threshold, the security monitor will only load the difference value into a register. After the security monitor is loaded, the CPU returns to the address where the exception occurs to continue execution. At this time, the ISA check unit reads the difference value from the register and restores the permission bitmap of the target ISA domain with reference to the permission bitmap template. The process is as follows: Figure 7 As shown in the figure, by compressing the throughput of the load permission bitmap and passing small difference values ​​through registers, the refresh and load process of ISABuffer has a significant performance improvement.

[0099] Through the above method and system, this embodiment effectively improves the security of the enclave based on RISC-V TEE and meets the high isolation requirements in multiple scenarios.

[0100] The trusted execution environment security enhancement method and system for the RISC-V architecture proposed in this embodiment is intended to provide stronger security protection through the refined isolation of memory and instruction resources. First, the system adopts a mechanism based on memory virtual address keys to divide the memory into multiple independent memory domains. A lock key is set for each memory domain. The memory management unit (MMU) captures access requests from the memory domain and determines whether the access complies with the isolation rules by comparing the hot key of the instance domain with the lock key of the target memory domain. If the comparison fails, it is considered that there is an isolation violation, and an arbitration output signal is constructed through the MMU. The arbitration output signal is processed by the arbitration post-processing module in the MMU. The module determines whether to trigger the update process of the memory execution key based on the arbitration result. If the permission check of the memory domain passes, the instruction set permission check stage is entered. In the instruction permission check, the instruction permission bitmap is first used to verify whether the current instruction is allowed to be executed in the ISA domain to which it belongs. If the instruction check passes and involves the use of the control status register (CSR), the register access rights are further checked. At this time, the system confirms the read and write permissions of the current ISA domain to the target register based on the register permission bitmap. If any of the above check links fails, the system will immediately trigger a hardware exception to prevent illegal operations from occurring, thereby ensuring fine-grained isolation of ISA and memory resources and enhancing the security of the enclave architecture.

[0101] The SDK of SGX is extended to merge MPK securely. However, MPK can only control the read and write permissions of the corresponding memory, but cannot control the execution permissions. Therefore, the work based on MPK cannot control the execution permissions of the isolation domain (instance domain). They put all the codes of the isolation domain in the initial domain and grant execution permissions to the codes of the initial domain. At the same time, new instructions and registers will be added during the implementation process. Once these instructions and registers are controlled, memory isolation will be threatened. As a result, attackers can break through the security boundaries of the enclave by exploiting instruction or register sharing.

[0102] The nested enclave technology is used to expand the traditional single protection domain. By accommodating multiple internal enclaves in an external enclave, fine-grained hierarchical security isolation is supported. This method can also break through security boundaries through instructions and registers.

[0103] Instruction permissions are checked through control flow integrity. This method is often based on compiler technology to check in advance, which has high overhead, cannot provide fine-grained control over instructions and registers, and cannot manage newly added third-party libraries.

[0104] The fine-grained memory resource and ISA resource isolation method and system of this embodiment can manage memory resources with a minimum granularity of 4Kb, manage the execution of each instruction, and the read and write permissions of each register. It fully manages enclave resources and greatly enhances the security and reliability of the enclave.

[0105] Compared with the prior art, the advantages of the method in this embodiment are reflected in the following aspects:

[0106] 1. Multi-domain isolation model based on page table keys. By extending the single virtual address space model of the traditional trusted execution environment (TEE) program to a multi-domain model based on page table keys, page table-level isolation is achieved without the need for physical continuous memory, reducing the complexity of the trusted computing base and significantly improving the security of the TEE. In addition, the page table entries are expanded, and reserved bits are used to manage memory domain lock keys (such as Figure 8 ). At the same time, by caching isolation permissions in registers, the efficiency of isolation checks is optimized, further improving the isolation performance of TEE.

[0107] 2. ISA domain management mechanism. Through the buffer+cache ISA domain management method, fine-grained management of each instruction execution and register reading and writing is achieved, while reducing hardware performance overhead. In addition, the permission bitmap template of the black and white list mechanism is introduced to simplify the traditional full user-defined permission management to a template-based configuration mode. Users can adjust the default blacklist and whitelist configurations, but after the system (enclave) is started, the black and white lists will be solidified as permission bitmap templates. During the template refresh process, if the changed part does not exceed the set threshold, the security monitor only loads the difference value and completes the permission bitmap recovery by referring to the permission bitmap template. Through differentiated processing of the permission bitmap and register transmission of small-scale data, the throughput of permission bitmap loading is significantly reduced, and the performance of permission refresh and loading is greatly optimized.

[0108] The instructions and registers used in the existing vulnerabilities are analyzed in advance, and the instructions and registers that have not been attacked are preset as whitelists, indicating that their use is allowed.

[0109] 3. Instance domain management mechanism. The method of managing instance domains using PKRU registers combines the memory domain with the ISA domain to manage resources within the enclave in a fine-grained manner. In addition, a write flag is added, which can be flexibly configured to facilitate memory management of the instance domain; reserved bits are reserved to provide more possibilities for subsequent management of instance domains.

[0110] Another embodiment of the present invention provides an electronic device, including:

[0111] one or more processors;

[0112] A memory stores one or more programs, and when the one or more programs are executed by one or more processors, the one or more processors implement the steps of the trusted execution environment security enhancement method.

[0113] In some implementations, the memory may be a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk memory.

[0114] In some other implementations, the processor may be a central processing unit (CPU), a digital signal processor (DSP), or other general-purpose processors of various types, which are not limited herein.

[0115] Another embodiment of the present invention provides a computer-readable storage medium storing a computer program, which implements the steps of the trusted execution environment security enhancement method when the computer program is executed by a processor.

[0116] The contents explained in the above embodiments should be understood as these embodiments are only used to more clearly illustrate the present invention, and are not used to limit the scope of the present invention. After reading the present invention, various equivalent forms of modifications to the present invention by those skilled in the art all fall within the scope defined by the claims attached to this application.

Claims

1. A method for enhancing security of a trusted execution environment, characterized in that: The process includes: The secure monitor creates a trusted execution environment, which includes enclaves; The enclave creates an instance domain for the component that needs to be isolated. The enclave sets the memory domain and instruction set domain for the instance domain. The instance domain has memory permissions and instruction set permissions, which are controlled by the memory domain and instruction set domain respectively. The enclave assigns lock keys to page table entries and assigns access-allowed keys to the memory domain. Set the instructions and register read and write permissions allowed in the instruction set domain; The current instance domain applies for a memory access request, and the memory management unit matches the memory domain key of the current instance domain with the lock key of the page table entry; If the hot key of the current instance domain fails to match the lock key of the target memory domain, the memory management unit matches all the permission keys of the instance domain with the lock key at the target virtual address being accessed; if all the permission keys of the instance domain still fail to match the lock key of the target memory domain, it is determined to be an illegal access; If the hot key of the current instance domain matches the lock key of the target memory domain, or all the permission keys owned by the instance domain match the lock key of the target memory domain and the permission key in the PKRU register is updated, the instruction set domain instruction permission check is further performed; if the instruction set domain to which the current instance domain belongs allows the execution of the current instruction, and the instruction of the target memory domain displays the read-write control status register, the register access permission is checked; If the instruction set domain to which the current instance domain belongs does not allow the execution of the current instruction, or the register access permission check fails, an exception is triggered; If the register access permission check passes, or the instruction set domain to which the current instance domain belongs allows the execution of the current instruction and the instruction of the target memory domain does not display the read / write control status register, it indicates that the current instance domain has not exceeded the permission and the program execution flow is executed normally.

2. The trusted execution environment security enhancement method according to claim 1, characterized in that: The PKRU register includes multiple permission keys, the number of the current instance domain, and the number of the instruction set domain described by the current instance domain; the first permission key corresponds to the private memory domain of the instance domain, and the remaining permission keys correspond to the shared memory domain.

3. The trusted execution environment security enhancement method according to claim 2, characterized in that: Both the hot key and the permission key include a multi-bit key value and a 1-bit write flag. When the key value of the permission key of the current instance domain is the same as the key value of the lock key of the target memory domain, and the write flag of the hot key is set to 1, an instruction permission check is performed.

4. The trusted execution environment security enhancement method according to claim 1, characterized in that: The instruction permission check includes: indexing the instruction permission bitmap according to the permission number of the instruction set domain, and determining the execution permission of the current instance domain to the instruction set domain.

5. The trusted execution environment security enhancement method according to claim 1, characterized in that: The register access permission check includes: indexing the register permission bitmap according to the number of the control status register, and determining the read and write permissions of the instruction set domain to which the current instance domain belongs to the control status register.

6. The trusted execution environment security enhancement method according to claim 4 or 5, characterized in that: The instruction permission bitmap and the register permission bitmap are set in the buffer area of ​​the instruction set check unit.

7. The trusted execution environment security enhancement method according to claim 6, characterized in that: An instruction permission bitmap template is set in the cache area of ​​the instruction set check unit, and the instruction permission bitmap is managed through the instruction permission bitmap template; the instruction permission bitmap template is compared with the instruction permission bitmap, and if the difference value between the instruction permission bitmap template and the instruction permission bitmap is less than or equal to a threshold value, the security monitor loads the difference value and restores the instruction permission bitmap through the permission bitmap template and the difference value.

8. A trusted execution environment security enhancement system, characterized in that: It includes a memory check unit, an instruction set check unit, an initial domain unit, a security monitor unit and an instance domain unit; Memory check unit: responsible for checking the memory access rights of the instance domain; Instruction set check unit: responsible for checking instruction permissions and register access permissions in the instance domain; Initial domain unit: used to manage instance domains, memory domains, memory domain lock keys, PKRU registers, and initialize enclaves; Security monitor unit: responsible for storing domain bitmaps, providing privileged target interface library interfaces, and initializing the trusted execution environment; Instance domain unit: Instance domain permissions are restricted by both the memory domain and the instruction set domain.

9. An electronic device, characterized in that: include: one or more processors; A memory having one or more programs stored thereon, which, when the one or more programs are executed by the one or more processors, enables the one or more processors to implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer program is stored therein, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.