Virtualization security access method and device based on PCIE (Peripheral Component Interface Express) equipment
By dynamically configuring the security policies and levels of virtual machines and memory pages, combined with the security levels of functional modules of PCIE devices, the shortcomings of PCIE virtualization solutions in the existing technology in terms of security and resource isolation are solved, and higher data security and resource isolation are achieved.
Patent Information
- Application Number
- CN202510009500.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-06-06
AI Technical Summary
Existing PCIE virtualization solutions have shortcomings in security and resource isolation, which can easily lead to data breaches and unauthorized access.
By dynamically configuring the security policy of the virtual machine and the security level of the memory page, mapping it with the security level of the functional module of the PCIE device, and controlling the access rights of the memory page according to the preset access policy.
It significantly improves data security and resource isolation effects in multi-user environments, meeting the current security needs of virtualization technology development.
Smart Images

Figure CN120104246A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of virtual machine access, and more specifically, to a method and device for virtualized secure access based on PCIE devices. Background Art
[0002] PCIE devices are directly connected to virtual machines, and TEE and REE are used to achieve secure access. However, the use of TEE and REE means that the security levels cannot be distinguished in detail, and the purpose of setting different security levels for different virtual users cannot be achieved. In the prior art, many people tend to use physical isolation technology, such as allocating data and tasks of different users to independent hardware. This method is intuitive and easy to understand, but it is costly and has low resource utilization. Use software-layer security policies (such as security policies in virtualization hypervisors) to manage resource access. Although this method is flexible, it is often not powerful enough and is vulnerable to attacks. With the rapid development of cloud computing and virtualization technology, shared and multi-tenant environments of PCIE devices are becoming increasingly common. However, existing PCIE virtualization solutions have many deficiencies in security and resource isolation, which can easily lead to data leakage and unauthorized access. Summary of the invention
[0003] In view of the deficiencies in the prior art, the present invention provides a method and apparatus for virtualized secure access based on PCIE devices.
[0004] According to one aspect of the present invention, a method for virtualized secure access based on a PCIE device is provided, comprising:
[0005] Configure security policies for each virtual machine based on the security requirements of the virtual machine and determine the virtual machine security level of each virtual machine;
[0006] Dynamically set the security level of each memory page in the host and determine the memory page security level of each memory page in the host;
[0007] According to the virtual machine security level of each virtual machine, the function module security level of the PCIE device bound to each virtual machine is configured and mapped to determine the security level of each function module;
[0008] According to the preset access policy and the security level of each functional module, the memory pages of the corresponding memory page security level are returned to each virtual machine for access.
[0009] Optionally, according to the security requirements of the virtual machines, a security policy is configured for each virtual machine to determine the virtual machine security level of each virtual machine, including:
[0010] Create multiple virtual machines based on the required number of virtual machines and resource allocation;
[0011] According to the security requirements of each virtual machine, a security policy is configured for each virtual machine to determine the virtual machine security level of each virtual machine.
[0012] Optionally, according to the virtual machine security level of each virtual machine, the function module security level of the PCIE device bound to each virtual machine is configured and mapped to determine the security level of each function module, including:
[0013] When the virtual machine is started, read the configuration file of the virtual machine;
[0014] Based on the configuration file, identify the virtual machine security level of the virtual machine;
[0015] According to the security level of the virtual machine, the security level of the function modules of the PCIE devices bound to each virtual machine is configured and mapped to determine the security level of each function module.
[0016] Optionally, the access strategy includes: accessing memory pages of a corresponding memory page level and accessing memory pages of the corresponding memory page level and below the level.
[0017] Optionally, it also includes:
[0018] Analyze the access records of virtual machines and identify the security risks of virtual machines;
[0019] Adjust the security policy of the virtual machine based on security risks.
[0020] According to another aspect of the present invention, there is provided a device for virtualized secure access based on a PCIE device, comprising:
[0021] A configuration module, configured to configure a security policy for each virtual machine according to the security requirements of the virtual machine and determine the virtual machine security level of each virtual machine;
[0022] A setting module, used to dynamically set the security level of each memory page in the host and determine the memory page security level of each memory page in the host;
[0023] A mapping module is used to configure and map the security level of the function modules of the PCIE devices bound to each virtual machine according to the virtual machine security level of each virtual machine, and determine the security level of each function module;
[0024] The access module is used to return the memory pages of the corresponding memory page security level to each virtual machine for access according to the preset access policy and the security level of each functional module.
[0025] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the storage medium stores a computer program, and the computer program is used to execute the method described in any one of the above aspects of the present invention.
[0026] According to another aspect of the present invention, an electronic device is provided, comprising: a processor; a memory for storing instructions executable by the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any one of the above aspects of the present invention.
[0027] Therefore, the method for virtualized secure access based on PCIE devices provided by the present invention dynamically configures the security level in a virtualized environment based on PCIE, and through fine-grained security management and real-time monitoring, significantly improves the data security and resource isolation effect in a multi-user environment, and meets the security requirements of the current development of virtualization technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:
[0029] Figure 1 It is a flow chart of a method for virtualized secure access based on a PCIE device provided by an exemplary embodiment of the present invention;
[0030] Figure 2 It is a structural diagram of a method for virtualized secure access based on a PCIE device provided by an exemplary embodiment of the present invention;
[0031] Figure 3 It is a structural diagram of a device for virtualized secure access based on a PCIE device provided by an exemplary embodiment of the present invention;
[0032] Figure 4 This is a structure of an electronic device provided by an exemplary embodiment of the present invention. DETAILED DESCRIPTION
[0033] Below, the exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments of the present invention, and it should be understood that the present invention is not limited to the exemplary embodiments described here.
[0034] It should be noted that the relative arrangement of components and steps, the numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present invention unless specifically stated otherwise.
[0035] Those skilled in the art can understand that the terms "first" and "second" in the embodiments of the present invention are only used to distinguish different steps, devices or modules, etc., and neither represent any specific technical meaning nor indicate the necessary logical order between them.
[0036] It should also be understood that, in the embodiments of the present invention, “plurality” may refer to two or more than two, and “at least one” may refer to one, two or more than two.
[0037] It should also be understood that any component, data or structure mentioned in the embodiments of the present invention can generally be understood as one or more, unless explicitly limited or otherwise indicated in the context.
[0038] In addition, the term "and / or" in the present invention is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in the present invention generally indicates that the associated objects before and after are in an "or" relationship.
[0039] It should also be understood that the description of the various embodiments of the present invention focuses on the differences between the various embodiments, and the same or similar aspects thereof can be referenced to each other, and for the sake of brevity, they will not be described one by one.
[0040] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship.
[0041] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.
[0042] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered part of the specification.
[0043] It should be noted that like reference numerals and letters refer to similar items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0044] Embodiments of the present invention can be applied to electronic devices such as terminal devices, computer systems, servers, etc., which can operate with many other general or special computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, servers, etc. include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network personal computers, small computer systems, large computer systems, and distributed cloud computing technology environments including any of the above systems, etc.
[0045] Electronic devices such as terminal devices, computer systems, servers, etc. can be described in the general context of computer system executable instructions (such as program modules) executed by computer systems. Generally, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in a distributed cloud computing environment, where tasks are performed by remote processing devices linked through a communication network. In a distributed cloud computing environment, program modules can be located on local or remote computing system storage media including storage devices.
[0046] Exemplary Methods
[0047] Figure 1 FIG. 1 is a flow chart of a method for virtualized secure access based on a PCIE device provided by an exemplary embodiment of the present invention. This embodiment can be applied to electronic devices, such as Figure 1 As shown, the method 100 for virtualized secure access based on PCIE devices includes the following steps:
[0048] Step 101, configuring a security policy for each virtual machine according to the security requirements of the virtual machine, and determining the virtual machine security level of each virtual machine;
[0049] Step 102, dynamically setting the security level of each memory page in the host, and determining the memory page security level of each memory page in the host;
[0050] Step 103, according to the virtual machine security level of each virtual machine, the function module security level of the PCIE device bound to each virtual machine is configured and mapped to determine the security level of each function module;
[0051] Step 104 , according to the preset access policy and the security level of each functional module, the memory page of the corresponding memory page security level is returned to each virtual machine for access.
[0052] Specifically, in a multi-user environment, different users may share the same physical device. PCIE virtualization security can ensure the data security of each user and prevent sensitive data leakage. Different users may have different security requirements. PCIE virtualization security allows specific security policies to be configured for each user, thereby achieving flexible security management and adapting to various business scenarios.
[0053] In view of this, the present invention provides a method for dynamically configuring different security attributes for each virtual machine and memory in a virtualization environment based on PCIE to achieve effective security isolation. Figure 2 As shown, the system for implementing the method of the present invention includes the following components:
[0054] Virtualization hypervisor: responsible for the creation, management and resource allocation of virtual machines.
[0055] PCIE device: a physical device shared by multiple virtual machines.
[0056] Security policy management module: used to configure and manage the security attributes of virtual machines and memory.
[0057] In one embodiment of the present invention, step 101 includes:
[0058] Dynamic security attribute configuration: Allows administrators to configure specific security policies for each virtual machine based on the security requirements of the virtual machine.
[0059] In one embodiment of the present invention, step 102 includes:
[0060] Memory security attribute management: The security level of each memory page can be set individually, supporting fine-grained access control.
[0061] Security policy application: Select the corresponding security policy based on security requirements, apply it to the virtual machine, and configure the corresponding virtual machine security level, as shown in Table 1.
[0062] In one embodiment of the present invention, step 104 includes:
[0063] Virtual machine startup: When a virtual machine is started, the hypervisor reads its configuration file and identifies the security level of the virtual machine, as shown in Table 1.
[0064] Functional module mapping, mapping the virtual machine's security level to the corresponding PCIE device's functional module, determines the memory page level that the virtual machine can access.
[0065] The present invention also includes:
[0066] Real-time monitoring: The security policy management module monitors the access behavior of virtual machines, records logs and detects abnormal activities.
[0067] Response: Analyze the virtual machine access records, identify potential security risks, and adjust the security policy as needed. Abnormal access behavior refers to the virtual machine accessing a memory page that exceeds its security level. The abnormal access behavior can be recorded. If the abnormal access is normal after analysis, the security level of the virtual machine can be increased or the security level of the memory page can be reduced; if the abnormal access is abnormal after analysis, the security level will not be reset, and the system security policy will remain unchanged. It can achieve the purpose of real-time monitoring and response as needed.
[0068] Table 1
[0069]
[0070] In one embodiment of the present invention, the implementation process of virtual machine access using the method provided by the present invention is as follows:
[0071] In a cloud service provider environment, virtual machines with different security levels are provided to customers. Customer A requires higher security and configures its virtual machine to "high security" mode, allowing access to memory pages with a higher security level. Customer B can be configured to "normal security" mode, allowing access only to memory pages with a low security level. The system dynamically adjusts the access rights of PCIE devices and memory to ensure that each customer's data cannot be accessed by other customers.
[0072] Set the security level of the memory page to 3 levels. The security level of different memory pages is between 0 and 2, which can be set according to actual needs. Among them, the configuration basis of the initial security level of the memory page is based on the design requirements of the system. If the memory page contains sensitive information such as keys and allows a small number of entities to access, set a high-level security permission; if the memory page contains cached data during operation and allows most entities to access, set a low-level security permission.
[0073] A virtual machine with a high security level can access memory pages with a lower security level than its own, while a virtual machine with a low security level cannot access memory pages with a higher security level than its own.
[0074] Each virtual machine can be bound to a function of a PCIE device. Set the security level of client A's virtual machine to 3 and map it to PCIE device function 0, i.e. function module 0. Set the security level of client B's virtual machine to 1 and map it to PCIE device function 1.
[0075] The memory is divided into four areas with different security levels: 0, 1, 2, and 3.
[0076] Client A can access four memory blocks with security levels 0, 1, 2, and 3. Client B can access two memory blocks with security levels 0 and 1. When abnormal access occurs, it will be recorded. The virtual machine program can take the following actions as needed:
[0077] 1. Improve the security level of virtual machines;
[0078] 2. Reduce the security level of memory.
[0079] Secondly, the present invention can use a fixed value matching method to check security access. For example, when the security level of customer A is 3, it can only access the memory space with a security level of 3. When the security level of customer B is 1, it can only access the memory space with a security level of 1. This method has a single security mode and can also achieve the purpose of security isolation. However, users are completely isolated. If customer A wants to access memory of other security levels, he can only set his own security level to the security level of the memory he wants to access. This increases the difficulty of software operation.
[0080] Therefore, the method for virtualized secure access based on PCIE devices provided by the present invention dynamically configures the security level in a virtualized environment based on PCIE, and through fine-grained security management and real-time monitoring, significantly improves the data security and resource isolation effect in a multi-user environment, and meets the security requirements of the current development of virtualization technology.
[0081] Exemplary Devices
[0082] Figure 3 FIG. 1 is a schematic diagram of a structure of a device for virtualized secure access based on a PCIE device provided by an exemplary embodiment of the present invention. Figure 3 As shown, the device 300 includes:
[0083] Configuration module 310, configured to configure security policies for each virtual machine according to the security requirements of the virtual machine and determine the virtual machine security level of each virtual machine;
[0084] A setting module 320, for dynamically setting the security level of each memory page in the host, and determining the memory page security level of each memory page in the host;
[0085] A mapping module 330 is used to configure and map the security level of the function modules of the PCIE devices bound to each virtual machine according to the virtual machine security level of each virtual machine, and determine the security level of each function module;
[0086] The access module 340 is used to return the memory pages of the corresponding memory page security level to each virtual machine for access according to the preset access policy and the security level of each functional module.
[0087] Optionally, the configuration module 310 includes:
[0088] Create a submodule to create multiple virtual machines according to the required number of virtual machines and resource allocation;
[0089] The configuration submodule is used to configure a security policy for each virtual machine and determine the virtual machine security level of each virtual machine according to the security requirements of each virtual machine.
[0090] Optionally, the mapping module 330 includes:
[0091] The reading submodule is used to read the configuration file of the virtual machine when the virtual machine is started;
[0092] An identification submodule, for identifying a virtual machine security level of a virtual machine based on a configuration file;
[0093] The mapping submodule is used to configure and map the security level of the functional modules of the PCIE devices bound to each virtual machine according to the security level of the virtual machine, and determine the security level of each functional module.
[0094] Optionally, the access strategy includes: accessing memory pages of a corresponding memory page level and accessing memory pages of the corresponding memory page level and below the level.
[0095] Optionally, the apparatus 300 further includes:
[0096] An analysis module is used to analyze the access records of virtual machines and identify security risks of virtual machines;
[0097] The adjustment module is used to adjust the security policy of the virtual machine according to the security risks.
[0098] Exemplary Electronic Devices
[0099] Figure 4 This is a structure of an electronic device provided by an exemplary embodiment of the present invention. Figure 4 As shown, the electronic device 40 includes one or more processors 41 and a memory 42 .
[0100] The processor 41 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.
[0101] The memory 42 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 41 may run the program instructions to implement the methods of the software programs of the various embodiments of the present invention described above and / or other desired functions. In one example, the electronic device may also include: an input device 43 and an output device 44, which are interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0102] In addition, the input device 43 may also include, for example, a keyboard, a mouse, etc.
[0103] The output device 44 can output various information to the outside, and can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto.
[0104] Of course, to simplify, Figure 4 Only some of the components related to the present invention in the electronic device are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, the electronic device may further include any other appropriate components according to specific application conditions.
[0105] Exemplary computer program products and computer-readable storage media
[0106] In addition to the above-mentioned methods and devices, an embodiment of the present invention may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to execute the steps of the method according to various embodiments of the present invention described in the above-mentioned "Exemplary Method" section of this specification.
[0107] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of the present invention, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0108] In addition, an embodiment of the present invention may also be a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, enable the processor to execute the steps of the method according to various embodiments of the present invention described in the above “Exemplary Method” section of this specification.
[0109] The computer readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can include, for example, but is not limited to, a system, system or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0110] The basic principle of the present invention is described above in conjunction with specific embodiments. However, it should be pointed out that the advantages, strengths, effects, etc. mentioned in the present invention are only examples and not limitations, and it cannot be considered that these advantages, strengths, effects, etc. must be possessed by each embodiment of the present invention. In addition, the specific details disclosed above are only for the purpose of illustration and facilitation of understanding, rather than limitation, and the above details do not limit the present invention to being implemented by adopting the above specific details.
[0111] Each embodiment in this specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system embodiment, since it basically corresponds to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0112] The block diagrams of the devices, systems, equipment, and systems involved in the present invention are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagram. As will be appreciated by those skilled in the art, these devices, systems, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open words, referring to "including but not limited to", and can be used interchangeably with them. The words "or" and "and" used here refer to the words "and / or" and can be used interchangeably with them, unless the context clearly indicates otherwise. The word "such as" used here refers to the phrase "such as but not limited to", and can be used interchangeably with it.
[0113] The method and system of the present invention may be implemented in many ways. For example, the method and system of the present invention may be implemented by software, hardware, firmware or any combination of software, hardware, firmware. The above order of steps for the method is only for illustration, and the steps of the method of the present invention are not limited to the order specifically described above, unless otherwise specifically stated. In addition, in some embodiments, the present invention may also be implemented as a program recorded in a recording medium, which includes machine-readable instructions for implementing the method according to the present invention. Thus, the present invention also covers a recording medium storing a program for executing the method according to the present invention.
[0114] It should also be noted that in the system, device and method of the present invention, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. The above description of the disclosed aspects is provided to enable any technician in the field to make or use the present invention. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined here can be applied to other aspects without departing from the scope of the present invention. Therefore, the present invention is not intended to be limited to the aspects shown here, but in accordance with the widest range consistent with the principles and novel features disclosed here.
[0115] The above description has been given for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present invention to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.
Claims
1. A method for virtualized secure access based on PCIE devices, characterized in that: include: Configure security policies for each virtual machine based on the security requirements of the virtual machine and determine the virtual machine security level of each virtual machine; Dynamically set the security level of each memory page in the host and determine the memory page security level of each memory page in the host; According to the virtual machine security level of each virtual machine, the function module security level of the PCIE device bound to each virtual machine is configured and mapped to determine the security level of each function module; According to the preset access policy and the security level of each functional module, the memory page of the corresponding memory page security level is returned to each virtual machine for access.
2. The method according to claim 1, characterized in that Configure security policies for each virtual machine based on the security requirements of the virtual machine and determine the virtual machine security level of each virtual machine, including: Create multiple virtual machines based on the required number of virtual machines and resource allocation; According to the security requirements of each virtual machine, a security policy is configured for each virtual machine to determine the virtual machine security level of each virtual machine.
3. The method according to claim 1, characterized in that According to the virtual machine security level of each virtual machine, the function module security level of the PCIE device bound to each virtual machine is configured and mapped to determine the security level of each function module, including: When the virtual machine is started, reading a configuration file of the virtual machine; Based on the configuration file, identifying a virtual machine security level of the virtual machine; According to the virtual machine security level, the function module security level of the PCIE device bound to each virtual machine is configured and mapped to determine the security level of each function module.
4. The method according to claim 1, characterized in that The access strategy includes: accessing memory pages of a corresponding memory page level and accessing memory pages of a corresponding memory page level and below the level.
5. The method according to claim 1, characterized in that Also includes: Analyzing access records of the virtual machine to identify security risks of the virtual machine; The security policy of the virtual machine is adjusted according to the security risk.
6. A device for virtualized secure access based on PCIE devices, characterized in that: include: A configuration module, configured to configure a security policy for each virtual machine according to the security requirements of the virtual machine and determine the virtual machine security level of each virtual machine; A setting module, used to dynamically set the security level of each memory page in the host and determine the memory page security level of each memory page in the host; A mapping module is used to configure and map the security level of the function modules of the PCIE devices bound to each virtual machine, and determine the security level of each function module; The access module is used to return the memory page of the corresponding memory page security level to each virtual machine for access according to the preset access policy and the security level of each functional module.
7. The device according to claim 6, characterized in that Configuration modules, including: Create a submodule to create multiple virtual machines according to the required number of virtual machines and resource allocation; The configuration submodule is used to configure a security policy for each virtual machine according to the security requirements of each virtual machine and determine the virtual machine security level of each virtual machine.
8. The device according to claim 6, characterized in that Mapping modules, including: A reading submodule, used for reading a configuration file of the virtual machine when the virtual machine is started; an identification submodule, configured to identify a virtual machine security level of the virtual machine based on the configuration file; The mapping submodule is used to configure and map the security level of the functional modules of the PCIE devices bound to each virtual machine according to the security level of the virtual machine, and determine the security level of each functional module.
9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program is used to execute the method according to any one of claims 1 to 5.
10. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is used to read the executable instructions from the memory and execute the instructions to implement the method described in any one of claims 1 to 5.