Binary translation method and device, electronic equipment and readable storage medium

By checking the access instruction in the binary translation process and generating the target inspection instruction, the security problem of the client platform accessing the target platform binary translator is solved, and the security of the binary translation process and the isolation of the target platform resource data is improved.

CN120255955APending Publication Date: 2025-07-04LOONGSON TECH CORP
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510253389.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

During the existing binary translation process, the source program of the client platform can access the binary translator of the target platform, resulting in parameter leakage or data corruption, reducing the security of the binary translation process.

Method used

During the binary translation process, the memory access instruction is checked and the target inspection instruction is generated. The memory access operation is only performed when the target memory access address does not fall within the preset address constraint range. The preset address constraint range includes the memory area in the target platform that is not allowed to memory access.

Benefits of technology

It improves the security of the binary translation process and the security of the target platform resource data, ensuring the isolation of resource data in the target platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120255955A_ABST
    Figure CN120255955A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a binary translation method and device, electronic equipment and a readable storage medium, in the process of performing binary translation on a binary file of a source platform, if a current instruction is a memory access instruction, based on corresponding target address information after performing binary translation on the current instruction, the memory access instruction is accessed to the source platform; determining a target access address corresponding to the target platform; based on the target memory access address, generating a binary translated target check instruction corresponding to the current instruction; executing the target checking instruction to perform address checking on the target memory access address, and executing a target memory access operation corresponding to the current instruction under the condition that the target memory access address does not belong to a preset address constraint range; the preset address constraint range comprises a memory area which does not allow the target check instruction to access in the target platform. On the premise of ensuring the binary translation performance, the security of the binary translation process and the security and isolation of the resource data in the target platform are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and in particular, to a binary translation method, apparatus, electronic device, and readable storage medium. Background Art

[0002] With the development of computer architectures, different processor architectures often adopt different Instruction Set Architectures (ISAs). Instruction set architectures can be divided into RISC (Reduced Instruction Set Computer) instruction set architectures and CISC (Complex Instruction Set Computing) instruction set architectures. CISC instruction set architectures such as x86, and RISC instruction set architectures such as ARM and LoongArch. Binary translation can convert a source program running on a platform with one instruction set architecture (referred to as the GUEST platform) into a target program running on another platform with a different instruction set architecture (referred to as the HOST platform).

[0003] In related technologies, during binary translation by a binary translator, the binary file of the client platform and the executable file corresponding to the binary translator of the target platform are located in the same user-mode address space and share the same page table information. The source program of the client platform can access the executable file corresponding to the binary translator. At this time, if the source program of the client platform maliciously attacks the binary translator of the target platform, it may lead to parameter leakage or data damage, reducing the security of the binary translation process. Summary of the Invention

[0004] To overcome the problems existing in related technologies, the present invention provides a binary translation method, apparatus, electronic device, and readable storage medium.

[0005] In a first aspect, the present invention provides a binary translation method applied to a binary translator. The method includes:

[0006] During the process of binary translating the binary file of the source platform, if the current instruction is a memory access instruction, based on the target address information corresponding to the binary translation of the current instruction, determine the target memory access address corresponding to the target platform;

[0007] Based on the target memory access address, generate a target check instruction after binary translation corresponding to the current instruction;

[0008] Execute the target check instruction to perform an address check on the target memory access address, and perform the target memory access operation corresponding to the current instruction when the target memory access address does not belong to the preset address constraint range; the preset address constraint range includes the memory areas in the target platform where the target check instruction is not allowed to perform memory access.

[0009] In a second aspect, the present invention provides a binary translation device, which is applied to a binary translator. The device includes:

[0010] A first determination module, configured to, during the process of binary translation of a binary file of a source platform, if the current instruction is a memory access instruction, determine the target memory access address corresponding to the target platform based on the target address information corresponding to the binary translation of the current instruction;

[0011] A first generation module, configured to generate a target check instruction after binary translation corresponding to the current instruction based on the target memory access address;

[0012] A first check module, configured to execute the target check instruction to perform an address check on the target memory access address, and perform the target memory access operation corresponding to the current instruction when the target memory access address does not belong to the preset address constraint range; the preset address constraint range includes the memory areas in the target platform where the target check instruction is not allowed to perform memory access.

[0013] In a third aspect, the present invention provides an electronic device, including: a processor, a memory, and a computer program stored on the memory and executable on the processor, wherein the processor, when executing the program, implements the binary translation method according to any one of the first aspects above.

[0014] In a fourth aspect, the present invention provides a readable storage medium, when the instructions in the storage medium are executed by the processor of an electronic device, enabling the electronic device to execute the steps in the binary translation method according to any one of the embodiments in the first aspect above.

[0015] In an embodiment of the present invention, during the process of binary translation of a binary file of a source platform, if the current instruction is a memory access instruction, based on the target address information corresponding to the binary translation of the current instruction, determine the target memory access address corresponding to the target platform; based on the target memory access address, generate a target check instruction after binary translation corresponding to the current instruction; execute the target check instruction to perform an address check on the target memory access address, and when the target memory access address does not belong to the preset address constraint range, perform the target memory access operation corresponding to the current instruction; the preset address constraint range includes the memory area in the target platform where the target check instruction is not allowed to perform memory access. In this way, by generating a target check instruction after binary translation corresponding to the current instruction and changing the translation method during the binary translation of the memory access instruction, it is possible to perform an address check on the memory access address before performing the target memory access operation. Only when the target memory access address does not belong to the preset address constraint range, perform the target memory access operation corresponding to the current instruction, thereby avoiding malicious access to the data within the preset address constraint range by the binary file of the source platform, and improving the security of the binary translation process, as well as the security and isolation of the resource data in the target platform while ensuring the performance of the binary translation. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0017] Figure 1 is a flowchart of the steps of a binary translation method provided by an embodiment of the present invention;

[0018] Figure 2 is a schematic diagram of an instruction structure provided by an embodiment of the present invention;

[0019] Figure 3 is a schematic diagram of a process address space provided by an embodiment of the present invention;

[0020] Figure 4 is a schematic diagram of a file loading provided by an embodiment of the present invention;

[0021] Figure 5 is a schematic diagram of an original translation result and a target translation result provided by an embodiment of the present invention;

[0022] Figure 6 is a schematic diagram of the execution of a target check instruction provided by an embodiment of the present invention;

[0023] Figure 7It is a specific step flowchart of a binary translation method provided by an embodiment of the present invention;

[0024] Figure 8 It is a structural diagram of a binary translation device provided by an embodiment of the present invention;

[0025] Figure 9 It is a structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners

[0026] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0027] Binary translation can be used to solve the problem of application programs running across instruction set architectures at the binary level. Specifically, binary translation technology can convert an instruction sequence in one instruction set architecture into an instruction sequence in another instruction set architecture. In other words, binary translation technology can enable a source program of one architecture to run in a program of another architecture. For example, binary translation can translate an instruction sequence in the x86 instruction set architecture into an instruction sequence in the arm instruction set architecture (such as arm64), and vice versa. Binary translation includes static translation and dynamic translation. Static translation is to translate the binary program A on the source platform before it is executed, so as to translate the binary program A into a binary program file B on the target platform. Dynamic translation is to translate the executed instructions when the binary program is running. The exception handling method of the embodiments of the present invention can be applied to dynamic translation or static translation. In the static translation scenario, the translation result obtained in one translation can be used multiple times; in the dynamic translation scenario, translation is performed in units of basic blocks (Translation Block, TB), and a basic block generally ends with a control flow change instruction (such as jump, function call, etc.).

[0028] In the embodiments of the present invention, the source program (source code) refers to the program to be binary-translated, and the source program can be any type of application program. The source platform refers to the machine platform on which the source program can run. In some embodiments, the source platform can also be referred to as the guest platform (GUEST platform) or the guest machine. The processor of the source platform can be a processor based on the first instruction set architecture. The first instruction set architecture can be, for example, the x86 instruction set architecture or the arm instruction set architecture (such as arm64). The source program is a program developed based on the first instruction set architecture. Therefore, the source program can run normally on the source platform. The target platform is the machine platform on which the source program is desired to be ported. In some embodiments, the target platform can also be referred to as the host platform (HOST platform) or the host machine. The processor of the target platform can be a processor based on the second instruction set architecture. The second instruction set architecture is different from the first instruction set architecture. For example, the first instruction set architecture is the x86 instruction set architecture and the second instruction set architecture is the arm instruction set architecture. Another example is that the first instruction set architecture is the arm instruction set architecture and the second instruction set architecture is the x86 instruction set architecture. The source program can run on the source platform using the source binary code. The source binary code is code based on the first instruction set architecture. If it is desired to run the source program on the target platform, the source binary code needs to be translated into target binary code (target code) by a binary translator. The target binary code is code based on the second instruction set architecture, so that the target binary code can be run on the target platform.

[0029] Figure 1 is a flowchart of the steps of a binary translation method provided by an embodiment of the present invention. As Figure 1 shown, the method may include:

[0030] Step 101, during the process of binary-translating the binary file of the source platform, if the current instruction is a memory access instruction, determine the target memory access address corresponding to the target platform based on the target address information corresponding to the binary translation of the current instruction.

[0031] In an embodiment of the present invention, during the binary translation of a binary file of a source platform by a binary translator, the binary file is divided into basic blocks for binary translation. If a memory access instruction is included in a basic block, when the current instruction being translated is a memory access instruction, the current instruction is binary-translated to obtain the target address information corresponding to the current instruction after binary translation. Herein, the current instruction may be a memory access instruction generated by an operating system or other application programs in the source platform, such as a load instruction or a store instruction. The target address information may include the target address offset and the target base address corresponding to the target platform after binary translation of the current instruction. When the current instruction is a memory access instruction, the current instruction indicates the memory access address where a target memory access operation needs to be performed. For example, the current instruction may include a base address register and an address offset register for indicating the base address and the address offset. The binary translator binary-translates the base address and the address offset indicated by the current instruction, and translates them into a target address offset and a target base address that match the target instruction set architecture of the target platform. Exemplarily, according to the instruction set architecture of the target platform, the base address and the address offset indicated by the current instruction corresponding to the source platform can be equivalently translated into a target address offset and a target base address corresponding to the target platform through operations such as direct mapping, simulation, or replacement.

[0032] Based on the target address offset and the target base address corresponding to the binary translation, the target memory access address corresponding to the target platform can be determined. Exemplarily, a target addition instruction can be generated, and based on the target addition instruction, the target address offset is added to the target base address to obtain the target memory access address. Herein, the target memory access address is the equivalent memory access address of the memory access address corresponding to the current instruction in the source platform on the target platform. Depending on the differences such as the instruction set architectures of the target platform and the source platform, the target memory access address corresponding to the target platform after translation may be the same as or different from the memory access address corresponding to the source platform. Exemplarily, assuming the target base address is 0x1000 and the target address offset is 0x4, the target memory access address may be 0x1000 + 0x4 = 0x1004.

[0033] It can be understood that if the addressing mode of the current instruction is the direct addressing mode, the memory access address indicated by the current instruction can be directly translated into a target memory access address that matches the target instruction set architecture of the target platform; if the memory access address of the current instruction needs to be obtained through calculation, a target addition instruction can be generated first, and the target memory access address is determined based on the target address offset and the target base address. That is to say, whether a target addition instruction needs to be generated before the target check instruction is determined based on the addressing mode of the current instruction, and the embodiments of the present invention do not limit this.

[0034] Step 102: Generate a target check instruction after binary translation corresponding to the current instruction based on the target memory access address.

[0035] In an embodiment of the present invention, a target check instruction corresponding to a target platform is generated based on a target memory access address. The target check instruction may be a memory access instruction with an address boundary check function obtained after binary translation of the current instruction. The target check instruction is used to indicate that an address check is first performed on the target memory access address to be accessed before performing a target memory access operation, and the target memory access operation is only performed when the address constraint range is met. Specifically, the instruction format of the target check instruction may be determined according to the instruction set architecture of the target platform. And based on the instruction format of the target check instruction, the target memory access address is filled into the corresponding field of the instruction to generate the target check instruction.

[0036] Exemplarily, as Figure 2 shown, in the related art, after binary translation of the current instruction, a general memory access instruction (General Load Instruction) corresponding to the target platform is obtained. The general memory access instruction may include a first opcode, a second register of the target platform for storing data to be written or storing data after reading data during memory access, a base address register, and an offset address. Among them, the register included in the general memory access instruction is the register identifier. Specifically, based on the first opcode in the general memory access instruction, the operation type to be performed (such as a read operation or a write operation) is determined. The base address register and the offset address are read, and the base address in the base address register is added to the offset address to obtain the actual memory address to be accessed. If the opcode indicates a read operation, data is read from the calculated memory address and stored in the register of the target platform; if the opcode indicates a write operation, the CPU writes the data in the register of the target platform to the calculated memory address.

[0037] In the embodiment of the present invention, after binary translation of the current instruction, a target check instruction corresponding to the current instruction is generated. The target check instruction (Load Instruction with Address Check) may include a second opcode, an address check register, a target register, and a second register. Among them, the registers included in the target check instruction are the register identifiers; the first opcode is different from the second opcode, the start address and the end address corresponding to the preset address constraint range are stored in the address check register, the preset address constraint range is the specific range for instruction address check, the target memory access address is stored in the target register, and the second register is the register for storing the data to be written when the target check instruction performs memory access after the address check is passed or the register for storing the data after reading the data. In this way, the embodiment of the present invention not only adjusts the operands of the instruction after binary translation, but also redefines the opcode of the instruction. By replacing the ordinary memory access instruction with the target check instruction, fast and dynamic address security check can be achieved during the data memory access operation on the target platform.

[0038] Step 103, execute the target check instruction to perform an address check on the target memory access address, and perform the target memory access operation corresponding to the current instruction when the target memory access address does not belong to the preset address constraint range; the preset address constraint range includes the memory area in the target platform where the target check instruction is not allowed to perform memory access.

[0039] In the embodiment of the present invention, based on the target check instruction, an address check is performed on the target memory access address to determine whether the target memory access address meets the preset address constraint range. When the target memory access address does not belong to the preset address constraint range, it indicates that the target memory access address is allowed to be accessed by the memory access instruction after binary translation, and then the target memory access operation corresponding to the current instruction can be executed. Among them, the target memory access operation indicated by the current instruction may include a data loading operation or a data storage operation. After the current instruction is equivalently translated into a target check instruction corresponding to the target platform, the memory access operation type corresponding to the target check instruction is the same as the memory access operation type corresponding to the current instruction.

[0040] To avoid the program on the source platform from accessing sensitive data or critical resources on the target platform, a preset address constraint range can be set in advance. The preset address constraint range can be a protected memory area or a memory range prohibited from access, including the memory areas in the target platform where the instructions after binary translation are not allowed to access memory, such as sensitive data, operating system kernel code, or other resources that need to be protected. Specifically, it includes an address constraint upper limit and an address constraint lower limit. Only when the memory access address does not belong to the preset address constraint range, the memory access operation is allowed. It can be understood that the preset address constraint range can be set according to requirements. For example, the preset address constraint range can be the address range of the operating system kernel space in the memory area of the target platform, or the address range of the executable file corresponding to the binary translator stored in the memory area of the target platform.

[0041] When the target memory access address does not belong to the preset address constraint range, according to the target memory access address indicated by the target check instruction, perform the target memory access operation corresponding to the current instruction. For example, read the data in the target memory access address and load the data into the target register indicated by the target check instruction.

[0042] In summary, in the embodiments of the present invention, during the process of binary translation of the binary file on the source platform, if the current instruction is a memory access instruction, based on the target address information corresponding to the binary translation of the current instruction, determine the target memory access address corresponding to the target platform; based on the target memory access address, generate a binary translated target check instruction corresponding to the current instruction; execute the target check instruction to perform an address check on the target memory access address, and when the target memory access address does not belong to the preset address constraint range, perform the target memory access operation corresponding to the current instruction; the preset address constraint range includes the memory areas in the target platform where the target check instruction is not allowed to access memory. In this way, by generating a binary translated target check instruction corresponding to the current instruction and changing the translation method during the binary translation of the memory access instruction, it is possible to perform an address check on the memory access address before performing the target memory access operation, and only perform the target memory access operation corresponding to the current instruction when the target memory access address does not belong to the preset address constraint range, thereby avoiding the malicious access of the binary file on the source platform to the data within the preset address constraint range, and improving the security of the binary translation process, as well as the security and isolation of the resource data in the target platform while ensuring the binary translation performance.

[0043] Optionally, the embodiments of the present invention may further include the following steps:

[0044] Step 201, when the target memory access address belongs to the preset address constraint range, do not perform the target memory access operation and trigger an exception event.

[0045] In an embodiment of the present invention, when the target memory access address belongs to a preset address constraint range, it indicates that the target memory access address is a memory area that is not allowed to be accessed. Then, the target memory access operation is not executed, and an exception event for the target check instruction is triggered. At the same time, it is necessary to configure in the kernel a processing logic for processing the exception event. For example, after the exception event is triggered, an exception flag is set in a specified register.

[0046] In an embodiment of the present invention, when the target memory access address does not meet the preset address constraint range, the target memory access operation is not executed, and an exception event is triggered, which can prevent a program on the source platform from accessing a memory area where memory access is not allowed, ensuring the security of the resources corresponding to the target memory access address.

[0047] Optionally, an embodiment of the present invention may further include the following steps:

[0048] Step 301: Determine the process address space corresponding to the target file based on the file format of the target file; the target file includes the executable file corresponding to the binary translator and the binary file corresponding to the source platform, and the process address space corresponding to the target file includes the first process address space corresponding to the executable file and the second process address space corresponding to the binary file.

[0049] In an embodiment of the present invention, if it is necessary to run a binary translator on the target platform for binary translation, the executable file corresponding to the binary translator needs to be loaded into the memory of the target platform for execution. At the same time, in order to use the binary translator to perform binary translation on the binary file of the source platform, the binary file of the source platform needs to be loaded onto the target platform. Usually, the executable file corresponding to the binary translator and the binary file of the source platform are loaded into the same process address space. Loading the executable file corresponding to the binary translator and the binary file of the source platform into the same process address space means loading these two programs into the operating system memory space of the target platform and enabling them to interact within the same process. This approach is usually for more efficient binary translation and execution. By placing the executable file corresponding to the binary translator and the binary file of the source platform in the same process address space, the overhead of inter-process communication can be reduced, and the efficiency of translation and execution can be improved. Further, in the scenario of dynamic translation, binary translation needs to be performed while the program corresponding to the source platform is running. Placing the executable file corresponding to the binary translator and the binary file of the source platform within the same process can more conveniently implement dynamic translation, so that the translator can access and modify the execution code of the binary file of the source platform in real time.

[0050] Determine the process address space corresponding to the target file based on the file format of the target file. Among them, the target file includes the executable file corresponding to the binary translator and the binary file corresponding to the source platform. The file format of the target file defines the structure of the file, including program code, data segment, symbol table, relocation information, dependency library list, etc. For example, the file format of the target file can be the PE (Portable Executable) format or EXEC format in the Windows system, the ELF (Executable and Linkable Format) format in the Linux system, etc. The process address space corresponding to the target file includes the first process address space corresponding to the executable file and the second process address space corresponding to the binary file. The executable file corresponding to the binary translator refers to the program file used to execute the binary translation task. This program file usually contains a series of algorithms and logics for converting the binary code on the source platform into the code that can be executed on the target platform. The binary file corresponding to the source platform refers to the original binary program that needs to be executed on the target platform. For example, the binary file corresponding to the source platform can represent an operating system or an application program.

[0051] According to the differences in the file formats of the target files, different methods for determining the process address space will be corresponding. The process address space corresponding to the target file can be the memory space used to load and store the target file. For example, the first process address space corresponding to the executable file is used to load and store the executable file, and the second process address space corresponding to the binary file is used to load and store the binary file.

[0052] Optionally, step 301 may include the following steps:

[0053] Step 401, when the file format of the target file is the first format, determine the process address space corresponding to the target file based on the free address space in the target platform.

[0054] In an embodiment of the present invention, when the file format of the target file is the first format, based on the free address space in the target platform, the process address space corresponding to the target file is determined. Herein, the first format may be a file format with position independence, that is, no address information is specified in this file format. For example, it is the PIE (Position-Independent Executable) format. When the file format of the target file is the first format, since no address information is specified in the target file, such as the process address space corresponding to file loading, the process address space corresponding to the target file can be determined based on the free address space in the target platform. Exemplarily, when the operating system loads a target file in the first format, it can obtain the free address space in the target platform and randomly allocate an address space that meets the storage size requirement of the target file in the free address space. For example, the operating system usually selects a continuous and large enough free memory block to place the PIE file for loading and storing the target file.

[0055] Step 402, when the file format of the target file is the second format, obtain the target address space indicated by the target file, and determine the target address space as the process address space corresponding to the target file.

[0056] In an embodiment of the present invention, when the file format of the target file is the second format, obtain the target address space indicated by the target file, and determine the target address space as the process address space corresponding to the target file. Herein, the second format may be a file format with specific address information specified, such as the EXEC format. When the file format of the target file is the second format, the target address space indicated by the target file can be directly obtained, and this target address space is used as the process address space for loading and storing the target file.

[0057] After determining the first process address space corresponding to the executable file and the second process address space corresponding to the binary file, load the executable file correspondingly into the first process address space, and load the binary file correspondingly into the second process address space. Exemplarily, the process of loading an executable file or a binary file into memory can be divided into the following steps: mapping the segment data of the file to the corresponding process address space area, resolving dynamic linking and relocation, initializing the heap and stack, and jumping to the program entry point for execution, etc. Taking the target file in the ELF format as an example, the first process address space and the second process address space after loading can be as Figure 3 shown.

[0058] Exemplarily, a linker is a program that can link one or more object files (which contain machine code and information available to the linker) generated by a compiler or assembler, as well as library files, into an executable file. During this process, the linker allocates process address spaces for the files. Therefore, when the file format of the executable file or binary file is in the PIE format, the operating system and the linker can allocate the corresponding process address space for the executable file or binary file from the free address space. For example, it can be determined based on the joint decision of the operating system and the linker which part of the address space the executable file or binary file is to be loaded into. Specifically, the operating system is responsible for allocating the process address space for the process, while the linker ensures that the program can run correctly in these address spaces by generating position-independent code. When the file format of the executable file or binary file is in the EXEC format, the target address space indicated in the executable file or binary file can be obtained and determined as the process address space corresponding to the target file, so that the executable file or binary file can be loaded into the target address space.

[0059] In a possible implementation, when the file formats of both the executable file and the binary file are in the PIE format, the executable file corresponding to the binary translator can be loaded into a relatively high address in the memory area of the target platform, and the binary file corresponding to the source platform can be loaded into a relatively low address in the memory area corresponding to the same process, as Figure 4 shown.

[0060] In the embodiments of the present invention, according to the different file formats of the executable file or binary file, the process address space corresponding to the executable file or binary file can be flexibly determined to adapt to the diverse file formats of the target files and ensure that the executable file or binary file can be loaded into a suitable process address space.

[0061] Optionally, step 101 may include the following steps:

[0062] Step 501, based on the register mapping rule of the target platform, determine the target address offset corresponding to the address offset indicated by the current instruction and the target base address corresponding to the base address indicated by the current instruction; the target address information includes the target address offset and the target base address.

[0063] In the embodiments of the present invention, different platform architectures have different register mapping situations. When performing binary translation, based on the instruction set architecture of the target platform, the register mapping rules of the target platform are obtained to ensure that the registers in the source platform can be correctly mapped to the registers in the target platform. The register mapping rules of the target platform describe how to correspond the memory addresses or input / output addresses in the target platform to the registers of the processor or other hardware modules. Parse the current instruction to determine the address offset and base address indicated by the current instruction. Based on the register mapping rules of the target platform, determine the target address offset and target base address in the target platform corresponding to the address offset and base address indicated by the current instruction. Exemplarily, the address offset and base address indicated by the current instruction can be converted into the target address offset and target base address based on operations such as displacement, addition, or multiplication.

[0064] Step 502: Based on the target addition instruction, perform an addition calculation on the target address offset and the target base address to obtain the target memory access address.

[0065] In the embodiments of the present invention, based on the target addition instruction, an addition calculation is performed on the target address offset and the target base address to obtain the target memory access address. Among them, the target memory access address is the equivalent memory access address on the target platform of the memory access address corresponding to the current instruction in the source platform. Exemplarily, the target address offset and the target base address are stored in register A and the base address register of the target platform respectively. The target addition instruction can be used to add the target address offset stored in register A to the base address register, so as to calculate the actual target memory access address.

[0066] Taking the addressing mode of the current instruction being calculated based on the base address and offset to obtain the memory access address as an example, after the original binary translation of the current instruction (Guest Load), the obtained original translation result includes: the target position (Load Dest) in the target platform where the data is loaded or stored, the base address (Address) corresponding to the target platform after binary translation, and the address offset (Offset) corresponding to the target platform after binary translation. Correspondingly, based on the binary translation method provided by the embodiments of the present invention, the target translation result obtained after binary translation of the current instruction (Guest Load) includes the target memory access address obtained by performing an addition calculation on the target base address and the target address offset based on the target addition instruction, the preset address constraint range (LoadCheck Dest), and the position (Address) in the target platform where the data is loaded or stored. Exemplarily, the original translation result and the target translation result can be as Figure 5 shown.

[0067] In a possible implementation, the target memory access address corresponding to the memory access address indicated by the current instruction can be directly determined based on the register mapping rule of the target platform. Exemplarily, the memory access address indicated by the current instruction can be directly converted into the target memory access address based on operations such as displacement, addition, or multiplication.

[0068] In the embodiments of the present invention, based on the register mapping rule of the target platform, the address offset and the base address indicated by the current instruction are converted into the target address offset and the target base address, thereby accurately determining the target memory access address and improving the accuracy and efficiency of binary translation.

[0069] Optionally, step 102 may include the following steps:

[0070] Step 601, generate a target check instruction based on the address check register, the target register, and the second register in the target platform corresponding to the first register indicated by the current instruction; the starting address and the ending address corresponding to the preset address constraint range are stored in the address check register, and the target memory access address is stored in the target register.

[0071] In the embodiments of the present invention, the target check instruction may include the address check register, the target register, and the second register corresponding to the target platform. Among them, the starting address and the ending address corresponding to the preset address constraint range are stored in the address check register. When the preset address constraint range is a continuous memory area, the starting address is the lower limit of the address of the continuous memory area, and the ending address is the upper limit of the address of the continuous memory area. Correspondingly, in the case where the preset address constraint range includes multiple continuous memory areas, multiple sets of starting addresses and ending addresses are stored in the address check register. Exemplarily, the preset address constraint range may include the starting address and the ending address corresponding to the first process address space. The target register stores the target memory access address, that is, the address corresponding to the memory access operation that needs to be performed by the target check instruction. The first register indicated by the current instruction is the register that stores the data to be written during the memory access of the current instruction or the register that stores the data after reading the data. The second register in the target platform corresponding to the first register may be the second register corresponding to the first register in the target platform obtained by conversion based on the register mapping rule of the target platform. The second register is the register that stores the data to be written during the memory access after the address check of the target check instruction is passed or the register that stores the data after reading the data.

[0072] Based on an address check register including a start address and an end address corresponding to a preset address constraint range, a target register including a target memory access address, and a second register, fill the address check register, the target register, and the second register into the corresponding fields of the instruction according to the instruction format of a target check instruction predefined by the target platform to generate a target check instruction.

[0073] In an embodiment of the present invention, by generating a target check instruction, the binary translation method of the current instruction is changed. Through the address check function of the target check instruction, the memory access of the client of the binary translation system can be dynamically detected, improving the security of the binary translation process.

[0074] Optionally, when the preset address constraint range is the address space of the first process, that is, the target check instruction prohibits accessing the memory area of the executable file corresponding to the binary translator, the memory area of the executable file corresponding to the binary translator is a protected memory area. Step 103 may include the following steps:

[0075] Step 701: Based on the target check instruction, match the start address and the end address corresponding to the address space of the first process stored in the address check register with the target memory access address stored in the target register.

[0076] In an embodiment of the present invention, based on the target check instruction, obtain the start address and the end address corresponding to the address space of the first process stored in the address check register, and the target memory access address stored in the target register. Match the start address and the end address with the target memory access address to determine whether the target memory access address belongs to the address space of the first process.

[0077] Step 702: When the target memory access address is within the memory area range corresponding to the start address and the end address, determine that the target memory access address belongs to the preset address constraint range.

[0078] In an embodiment of the present invention, based on the start address and the end address, a memory area range can be defined. When the target memory access address is within this memory area range, it indicates that the target memory access address is included in the address space of the first process, and then it can be determined that the target memory access address belongs to the preset address constraint range.

[0079] Step 703: When the target memory access address is outside the memory area range corresponding to the start address and the end address, determine that the target memory access address does not belong to the preset address constraint range.

[0080] In an embodiment of the present invention, when the target memory access address is outside the range of this memory area, it indicates that the target memory access address is not included in the address space of the first process, and thus it can be determined that the target memory access address does not belong to the preset address constraint range.

[0081] In a possible implementation manner, the address check register may store an accessible memory area other than the prohibited access area. Correspondingly, when executing the target check instruction, if the target memory access address exceeds the accessible memory area stored in the address check register, the target memory access operation is not executed; if the target memory access address does not exceed the accessible memory area stored in the address check register, the target memory access operation is executed. The embodiment of the present invention does not limit the access permission type of the memory area stored in the address check register. When performing address check, the check logic can be adjusted according to the access permission type of the memory area stored in the address check register to ensure that the target memory access address is in the permitted access area.

[0082] Exemplarily, Figure 6 shows an execution schematic diagram of a target check instruction. As Figure 6 shown, after binary translation of the current instruction, the target address offset and the target base address are added to generate a target check instruction including an address check register, a target register, and a second register. Based on the target check instruction, address check is performed to determine whether the target memory access address exceeds the address space of the first process. If it exceeds the address space of the first process, the target memory access operation (load succeeds) can be performed; if it does not exceed the address space of the first process, the target memory access operation cannot be performed (the memory access operation is illegal and load fails).

[0083] In an embodiment of the present invention, the address space of the first process is used as the preset address constraint range, and address check logic is added to the translated instruction to ensure that before executing the memory access instruction on the target platform, it is verified whether the target memory access address is within the address space of the first process, that is, the prohibited memory interval, which can ensure that the address space of the first process corresponding to the executable file of the binary translator is strictly isolated, prevent illegal memory access, and thus ensure the security and stability of the system.

[0084] Exemplarily, Figure 7 shows a specific step flowchart of a binary translation method. As Figure 7As shown, during binary translation, basic blocks are used as the basic units for translation. First, the binary translator checks whether the current basic block has been translated in the code cache space, that is, whether the code cache space caches the instructions corresponding to the binary translation of the current basic block. The code cache space of the binary translator is a memory area located in the host machine's memory and is used to store the target code generated by the binary translator. When the binary translator translates the code of the source platform (client architecture) into the code of the target platform (host architecture), the translated target code can be stored in the code cache space for further execution. Since the code cache space stores the already translated code, when these translated codes need to be executed again, the translated codes can be directly loaded from the code cache space, avoiding repeated translation and thus significantly improving the execution speed. Therefore, if so, the target check instruction corresponding to the currently translated instruction is directly loaded from the code cache space and executed; if not, the current basic block is input to the disassembler for disassembly. The binary translator translates each instruction in the basic block according to the information obtained after disassembly. When the current instruction is a memory access instruction, the current instruction is translated into a target check instruction, the target check instruction is stored in the code cache space, and the target check instruction is executed to check the address of the target memory access address. When the target memory access address does not belong to the preset address constraint range, the target memory access operation corresponding to the current instruction is executed.

[0085] Figure 8 is a schematic structural diagram of a binary translation device provided by an embodiment of the present invention and is applied to a binary translator, as Figure 8 shown, the device may specifically include:

[0086] A first determination module 801, configured to, during the process of binary translating a binary file of a source platform, if the current instruction is a memory access instruction, determine a target memory access address corresponding to the target platform based on the address information corresponding to the binary translation of the current instruction;

[0087] A first generation module 802, configured to generate a target check instruction after binary translation corresponding to the current instruction based on the target memory access address;

[0088] A first check module 803, configured to execute the target check instruction to check the address of the target memory access address, and execute the target memory access operation corresponding to the current instruction when the target memory access address does not belong to a preset address constraint range; the preset address constraint range includes a memory area in the target platform where the target check instruction is not allowed to access memory.

[0089] An embodiment of the present invention provides a binary translation device. During the process of binary translation of a binary file of a source platform, if the current instruction is a memory access instruction, based on the target address information corresponding to the binary translation of the current instruction, determine the target memory access address corresponding to the target platform; based on the target memory access address, generate a target check instruction after binary translation corresponding to the current instruction; execute the target check instruction to perform an address check on the target memory access address, and when the target memory access address does not belong to the preset address constraint range, perform the target memory access operation corresponding to the current instruction; the preset address constraint range includes a memory area in the target platform where the target check instruction is not allowed to access memory. In this way, by generating a target check instruction after binary translation corresponding to the current instruction and changing the translation method during binary translation of the memory access instruction, it is possible to perform an address check on the memory access address before performing the target memory access operation. Only when the target memory access address does not belong to the preset address constraint range, perform the target memory access operation corresponding to the current instruction, thereby avoiding malicious access by the binary file of the source platform to data within the preset address constraint range, improving the security of the binary translation process, as well as the security and isolation of resource data in the target platform while ensuring the performance of binary translation.

[0090] Optionally, the device further includes:

[0091] A first processing module, when the target memory access address belongs to the preset address constraint range, does not perform the target memory access operation and triggers an exception event.

[0092] Optionally, the device further includes:

[0093] A second determination module, configured to determine the process address space corresponding to the target file based on the file format of the target file; the target file includes the executable file corresponding to the binary translator and the binary file corresponding to the source platform, and the process address space corresponding to the target file includes the first process address space corresponding to the executable file and the second process address space corresponding to the binary file;

[0094] A first loading module, configured to load the executable file corresponding to the binary translator into the first process address space;

[0095] A second loading module, configured to load the binary file corresponding to the source platform into the second process address space; the second process address space and the first process address space belong to different address regions of the memory address space in the target platform.

[0096] Optionally, the second determination module includes:

[0097] A first determination sub-module, configured to, when the file format of the target file is the first format, determine a process address space corresponding to the target file based on a free address space in the target platform;

[0098] A second determination sub-module, configured to, when the file format of the target file is the second format, obtain a target address space indicated by the target file, and determine the target address space as the process address space corresponding to the target file.

[0099] Optionally, the first determination module 801 includes:

[0100] A third determination sub-module, configured to determine a target address offset corresponding to an address offset indicated by the current instruction and a target base address corresponding to a base address indicated by the current instruction based on a register mapping rule of the target platform; the target address information includes the target address offset and the target base address;

[0101] A first calculation module, configured to perform an addition calculation on the target address offset and the target base address based on a target addition instruction to obtain the target memory access address.

[0102] Optionally, the first generation module 802 includes:

[0103] A first generation sub-module, configured to generate a target check instruction based on an address check register, a target register, and a second register in the target platform corresponding to a first register indicated by the current instruction; a start address and an end address corresponding to a preset address constraint range are stored in the address check register, and the target memory access address is stored in the target register.

[0104] Optionally, when the preset address constraint range is a first process address space, the first check module 803 includes:

[0105] A first matching module, configured to match a start address and an end address corresponding to the first process address space stored in the address check register with the target memory access address stored in the target register based on the target check instruction;

[0106] A fourth determination sub-module, configured to, when the target memory access address is within a memory area range corresponding to the start address and the end address, determine that the target memory access address belongs to the preset address constraint range;

[0107] A fifth determination sub-module, configured to, when the target memory access address is outside a memory area range corresponding to the start address and the end address, determine that the target memory access address does not belong to the preset address constraint range.

[0108] The present invention also provides an electronic device. Refer to Figure 9 , Figure 9 which is a schematic structural diagram of the electronic device provided by an embodiment of the present invention. The electronic device includes: a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface complete communication with each other through the communication bus. The memory is used to store at least one executable instruction, and the executable instruction causes the processor to execute the steps of the binary translation method in the foregoing embodiment.

[0109] The present invention also provides a readable storage medium. When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device can execute the binary translation method in the foregoing embodiment.

[0110] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.

[0111] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The structure required to construct such systems will be apparent from the above description. In addition, the present invention is not directed to any particular programming language. It should be understood that the content of the present invention described herein can be implemented using various programming languages, and the description of the specific language above is for disclosing the best mode of the present invention.

[0112] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures, and technologies have not been shown in detail so as not to obscure the understanding of this specification.

[0113] Similarly, it should be understood that, in order to streamline the present invention and assist in understanding one or more of the various inventive aspects, in the foregoing description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting the intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all the features of the preceding single embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into the detailed description, with each claim standing on its own as a separate embodiment of the present invention.

[0114] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and arranged in one or more devices different from those of the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted to combine all the features disclosed in this specification (including the accompanying claims, abstract and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise clearly stated, each feature disclosed in this specification (including the accompanying claims, abstract and drawings) can be replaced by an alternative feature that provides the same, equivalent or similar purpose.

[0115] Each component embodiment of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the sorting device according to the present invention. The present invention can also be implemented as a device or device program for executing some or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or in any other form.

[0116] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In the unit claims listing several devices, several of these devices can be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.

[0117] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0118] It should be noted that all actions of obtaining signals, information or data in this application are carried out on the premise of complying with the corresponding data protection regulations and policies of the country where the location is located and with the authorization given by the owner of the corresponding device.

[0119] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

[0120] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or replacements, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A binary translation method, characterized in that, Applied to a binary translator, the method includes: During the process of binary translating a binary file of a source platform, if the current instruction is a memory access instruction, based on the target address information corresponding to the binary translation of the current instruction, determine the target memory access address corresponding to the target platform; Based on the target memory access address, generate a target check instruction after binary translation corresponding to the current instruction; Execute the target check instruction to perform an address check on the target memory access address, and in the case where the target memory access address does not belong to a preset address constraint range, perform the target memory access operation corresponding to the current instruction; the preset address constraint range includes the memory areas in the target platform where the target check instruction is not allowed to access memory.

2. The method according to claim 1, wherein The method further includes: In the case where the target memory access address belongs to the preset address constraint range, do not perform the target memory access operation and trigger an exception event.

3. The method according to claim 1, characterized in that, The method further includes: Based on the file format of the target file, determine the process address space corresponding to the target file; the target file includes the executable file corresponding to the binary translator and the binary file corresponding to the source platform, and the process address space corresponding to the target file includes the first process address space corresponding to the executable file and the second process address space corresponding to the binary file; Load the executable file corresponding to the binary translator into the first process address space; Load the binary file corresponding to the source platform into the second process address space; the second process address space and the first process address space belong to different address regions of the memory address space in the target platform.

4. The method according to claim 3, characterized in that, The determining the process address space corresponding to the target file based on the file format of the target file includes: In the case where the file format of the target file is the first format, based on the free address space in the target platform, determine the process address space corresponding to the target file; In the case where the file format of the target file is the second format, obtain the target address space indicated by the target file, and determine the target address space as the process address space corresponding to the target file.

5. The method according to claim 1, wherein The determining the target memory access address corresponding to the target platform based on the target address information corresponding to the binary translation of the current instruction includes: Based on the register mapping rule of the target platform, determine the target address offset corresponding to the address offset indicated by the current instruction and the target base address corresponding to the base address indicated by the current instruction; the target address information includes the target address offset and the target base address; Based on a target addition instruction, perform an addition calculation on the target address offset and the target base address to obtain the target memory access address.

6. The method according to any one of claims 1 to 5, characterized in that The generating a target check instruction after binary translation corresponding to the current instruction based on the target memory access address includes: Generate a target check instruction based on an address check register, a target register, and a second register in a target platform corresponding to a first register indicated by the current instruction; the starting address and the ending address corresponding to the preset address constraint range are stored in the address check register, and the target memory access address is stored in the target register.

7. The method according to claim 6, characterized in that When the preset address constraint range is the address space of a first process, the address check of the target memory access address based on the target check instruction includes: Based on the target check instruction, match the starting address and the ending address corresponding to the address space of the first process stored in the address check register with the target memory access address stored in the target register; When the target memory access address is within the memory area corresponding to the starting address and the ending address, determine that the target memory access address belongs to the preset address constraint range; When the target memory access address is outside the memory area corresponding to the starting address and the ending address, determine that the target memory access address does not belong to the preset address constraint range.

8. A binary translation device, characterized in that, Applied to a binary translator, the device includes: A first determination module, configured to, during the binary translation of a binary file of a source platform, if the current instruction is a memory access instruction, determine a target memory access address corresponding to the target platform based on the target address information corresponding to the binary translation of the current instruction; A first generation module, configured to generate a target check instruction after binary translation corresponding to the current instruction based on the target memory access address; A first check module, configured to execute the target check instruction to perform an address check on the target memory access address, and perform a target memory access operation corresponding to the current instruction when the target memory access address does not belong to the preset address constraint range; the preset address constraint range includes a memory area in the target platform where the target check instruction is not allowed to perform memory access.

9. The device according to claim 8, characterized in that, The device further includes: A first processing module, configured not to perform the target memory access operation and trigger an exception event when the target memory access address belongs to the preset address constraint range.

10. The device according to claim 8, wherein, The device further includes: A second determination module, configured to determine the process address space corresponding to the target file based on the file format of the target file; the target file includes an executable file corresponding to the binary translator and a binary file corresponding to the source platform, and the process address space corresponding to the target file includes a first process address space corresponding to the executable file and a second process address space corresponding to the binary file; A first loading module, configured to load the executable file corresponding to the binary translator into the first process address space; A second loading module, configured to load the binary file corresponding to the source platform into the second process address space; the second process address space and the first process address space belong to different address regions of the memory address space in the target platform.

11. The method according to claim 10, characterized in that, The second determination module includes: The first determination sub-module is configured to, when the file format of the target file is the first format, determine the process address space corresponding to the target file based on the free address space in the target platform; The second determination sub-module is configured to, when the file format of the target file is the second format, obtain the target address space indicated by the target file and determine the target address space as the process address space corresponding to the target file.

12. The method according to claim 8, wherein The first determination module includes: The third determination sub-module is configured to determine a target address offset corresponding to the address offset indicated by the current instruction and a target base address corresponding to the base address indicated by the current instruction based on the register mapping rule of the target platform; the target address information includes the target address offset and the target base address; The first calculation module is configured to perform an addition calculation on the target address offset and the target base address based on a target addition instruction to obtain the target memory access address.

13. The method according to any one of claims 9 to 12, characterized in that, The first generation module includes: The first generation sub-module is configured to generate a target check instruction based on an address check register, a target register, and a second register in the target platform corresponding to the first register indicated by the current instruction; the start address and the end address corresponding to the preset address constraint range are stored in the address check register, and the target memory access address is stored in the target register.

14. The method according to claim 13, characterized in that, When the preset address constraint range is the first process address space, the first check module includes: The first matching module is configured to match the start address and the end address corresponding to the first process address space stored in the address check register with the target memory access address stored in the target register based on the target check instruction; The fourth determination sub-module is configured to determine that the target memory access address belongs to the preset address constraint range when the target memory access address is within the memory area range corresponding to the start address and the end address; The fifth determination sub-module is configured to determine that the target memory access address does not belong to the preset address constraint range when the target memory access address is outside the memory area range corresponding to the start address and the end address.

15. An electronic device, characterized in that, It includes: A processor, a memory, and a computer program stored on the memory and executable on the processor, and the processor implements the binary translation method according to any one of claims 1-7 when executing the program.

16. A readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is enabled to execute the binary translation method according to any one of claims 1-7.

Citation Information

Cited By

  • Address mapping method and device, electronic equipment and readable storage medium

    CN120448039A