ARM platform-oriented kernel page table protection method and system

By using PAN and HPDS mechanisms to construct an isolated execution environment under the ARM architecture, and combining stack switching and gate structure design, the performance overhead and interruption problems of isolated execution environment under the ARM architecture are solved, and a secure kernel page table protection is achieved.

CN120256338APending Publication Date: 2025-07-04北京中关村实验室 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510422003.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The prior art has high performance overhead when constructing an isolated execution environment under the ARM architecture and cannot be interrupted, resulting in the impact of kernel performance and lack of effective kernel page table protection methods.

Method used

The PAN and HPDS mechanisms under the ARM architecture are used to construct an isolated execution environment. Through stack switching and gate structure design, the code in the isolated execution environment can switch the execution environment during a secure interruption, and achieve safe interruption through interrupt inlet and exit modification.

Benefits of technology

Effectively prevent privileged and non-privileged code from direct access to the isolated execution environment, reduce performance overhead, and ensure that code in the isolated execution environment can be switched and executed safely when interrupted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120256338A_ABST
    Figure CN120256338A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of operating system security, and discloses an ARM platform-oriented kernel page table protection method and system, and the method comprises the steps: isolating a virtual page configuration access privilege where an execution environment is located; establishing a stack structure for the codes in the isolated execution environment by utilizing a stack switching method, and performing permission setting on access to the local variables through stack switching operation when the codes in the isolated execution environment run; according to the method, a door structure is constructed in an isolated execution environment, external codes need to prepare corresponding parameters and enter the isolated execution environment through the door structure for interaction, and when interruption is sent in the interaction process, the codes in the isolated execution environment are allowed to be safely interrupted in the operation process by modifying an interruption inlet and an interruption outlet. According to the invention, direct access of non-privileged codes to the isolated execution environment can be prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of operating system security, and particularly relates to a kernel page table protection method and system for an ARM platform. Background Art

[0002] As a component that provides an interface between user programs and hardware, the operating system has the function of managing hardware resources such as memory and hard disks, and allocates these resources to user programs so that user programs can run properly on the hardware. To ensure the security of this process, modern operating systems generally divide different privilege levels so that different codes run under different hardware privilege levels to restrict the operation of codes with different privilege levels. Therefore, the security of the operating system itself plays a decisive role in the secure operation of user programs. Currently, most operating system kernels adopt a monolithic kernel structure, that is, the codes that provide various services of the operating system are concentrated together and run in the same address space and the same privilege level. As an operating system with a monolithic kernel structure, a large amount of kernel code in Linux kernel increases the complexity of the operating system kernel itself and also introduces a large number of vulnerabilities. The exploitation of a kernel vulnerability may pose a threat to other parts of the kernel and even the security of the entire operating system.

[0003] In recent years, a large number of attack methods have revolved around how to assist in discovering these Linux kernel vulnerabilities, and they can be used to achieve privilege escalation. Taking the common memory leak as an example, the simplest way is to directly use the vulnerability to inject code and execute it. The emergence of kernel address randomization (KASLR) and means of restricting data execution such as DEP, W⊕X, SMEP&SMAP have solved this problem. However, attacks of code reuse type, such as the earliest ROP attack constructed by modifying the return address in memory, and later attacks of automatically finding code fragments to construct control flow hijacking, and even DOP attacks implemented through non-control data, cannot be avoided by simple methods. Common means of preventing control flow hijacking include address randomization (ASLR), control flow integrity (CFI), code pointer integrity (CPI), and shadow stack, etc., and many methods to break them have been derived for these defense means.

[0004] Among many kernel defense means, the isolation of sensitive data is a widely used one, which is specifically completed by constructing an isolated execution environment. However, most of the related technologies for constructing an isolated execution environment, such as realizing memory isolation based on virtualization, constructing a secure execution environment based on ARM hardware characteristics, and making finer-grained isolation based on Intel hardware mechanisms, all have their limitations.

[0005] SecPod constructs an isolated environment through page table switching. It creates two different page tables: one is used to map ordinary kernel code and data. At this time, the kernel code has execution permission, but the page table does not map the critical data to be isolated, thus preventing ordinary kernel code from accessing the critical data; the other maps the critical data and its legal access interfaces. At this time, the kernel code does not have execution permission, so only the legal access interfaces can access the critical data. In addition, SecPod also provides a gate for the kernel code to switch the environment. This gate realizes the page table switching through the switching of the CR3 register under the X86 architecture and jumps to the legal access interface for access operations.

[0006] xMP uses virtualization mechanisms to construct an isolated environment. It is implemented based on altp2m under the X86 architecture and has greater flexibility. xMP divides into several xMP domains and creates a second-level address translation page table SLAT for each xMP domain, and opens its access permission in the SLAT page table corresponding to the xMP domain. In addition, xMP also creates a default SLAT page table, in which all xMP domains have the lowest access permission. Kernel threads run on this default SLAT page table by default. If a thread needs to switch to a certain xMP domain, it needs to be achieved by calling a specific interface. After the xMP domain is switched, the SLAT page table is not immediately switched, but an exception is triggered when the xMP domain is first accessed, and then the page table is switched through VFUNC to achieve legal access to the xMP domain. It should be noted that different from altp2m under ARM, altp2m under X86 can achieve SLAT switching without entering the VMM (Virtual Machine Manager), which has higher efficiency.

[0007] The above two technologies are both implemented based on the X86 architecture. The main reason is that the hardware characteristics of the X86 architecture are more rich and efficient. However, in fact, the existing hardware characteristics of ARM can also achieve the construction of a relatively efficient isolated execution environment. Hilps realizes this operation by using the TxSZ mechanism of ARM. In the ARM architecture, the entire virtual address space is divided into a high-address area and a low-address area. Their virtual-to-physical address translations are respectively based on different page table base address registers, and the sizes of the two address areas can be configured by TxSZ of the TCR register. Hilps maps the outer domain that stores ordinary data to the high part of the high-address area and maps the inner domain that stores sensitive data to the low part of the high-address area through page table configuration. The gate only needs to adjust T1SZ to hide the low-address space of the high-address area, so that the sensitive data in the inner domain is invisible.

[0008] In the related technologies of constructing isolated execution environments, most are implemented for the X86 architecture. The main reason is that X86 provides more support for hardware isolation mechanisms, and some virtualization operations of X86 do not require a trap to the VMM, which is more efficient. In contrast, constructing an isolated execution environment for the ARM architecture requires using the hardware mechanisms of ARM itself. The work of Hilps realizes entering and exiting the isolated environment by modifying the TCR register under the ARM architecture, which improves the efficiency of the gate compared with virtualization means. However, when there is frequent data interaction between the outside world and the isolated execution environment, the overhead caused by modifying the TCR register becomes non-negligible. In addition, most isolation means require that the code in the isolated execution environment cannot be interrupted during execution. Therefore, if the code in the isolated execution environment is relatively complex, it may have a greater impact on the kernel performance.

[0009] In summary, in the construction of isolated execution environments in the current related technologies, the performance overhead problem is a key issue. SecPod and xMP have achieved a reduction in overhead under the X86 architecture, but the overhead of related isolation means under the ARM architecture is still relatively high, and the operation of the above isolated execution environments cannot be interrupted.

[0010] Therefore, how to provide a kernel page table protection method and system for the ARM platform is an urgent problem to be solved at present. Summary of the Invention

[0011] Embodiments of the present invention provide a kernel page table protection method and system for the ARM platform to solve the problems in the prior art.

[0012] To have a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary part is not a general review, nor is it intended to identify key / important constituent elements or delineate the protection scope of these embodiments. Its sole purpose is to present some concepts in a simple form as a preamble to the subsequent detailed description.

[0013] According to the first aspect of the embodiments of the present invention, a kernel page table protection method for the ARM platform is provided.

[0014] In one embodiment, the kernel page table protection method for the ARM platform includes:

[0015] Construct an isolated execution environment by using the privilege level mechanism under the ARM architecture, and configure access privileges for the virtual pages where the isolated execution environment is located;

[0016] Use the method of stack switching to establish a stack structure for the code in the isolated execution environment, and set permissions for accessing local variables through stack switching operations when the code in the isolated execution environment is running;

[0017] Construct a gate structure in an isolated execution environment. External code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction. When an interrupt is sent during the interaction, by modifying the interrupt entry and exit, the code in the isolated execution environment is allowed to have a safe interrupt during operation.

[0018] In one embodiment, constructing the isolated execution environment using the privilege level mechanism under the ARM architecture and configuring access privileges for the virtual page where the isolated execution environment is located includes:

[0019] Divide the virtual address space under the ARM architecture into several regions, and allocate virtual address space in the high-address region for use as the isolated execution environment;

[0020] Use the PAN and HPDS mechanisms under the ARM architecture to complete the restriction of access permissions, including:

[0021] Set the virtual page where the isolated execution environment is located to unprivileged on the last-level page table, and use the PAN mechanism to prevent direct access to the isolated execution environment by privileged code;

[0022] Set the virtual page where the isolated execution environment is located to privileged on the first-level page table, and use the HPDS mechanism to change the selection of the permission check by the virtual-to-physical address translation component to prevent direct access to the isolated execution environment by unprivileged code.

[0023] In one embodiment, using the PAN mechanism to prevent direct access to the isolated execution environment by privileged code includes:

[0024] When the PAN mechanism is enabled, privileged code can access unprivileged code;

[0025] When the PAN mechanism is disabled, privileged code cannot access unprivileged code.

[0026] In one embodiment, using the HPDS mechanism to change the selection of the permission check by the virtual-to-physical address translation component to prevent direct access to the isolated execution environment by unprivileged code includes:

[0027] When the HPDS mechanism is disabled, the virtual-to-physical address translation component MMU (Memory Management Unit) in the ARM architecture adopts a mechanism of querying level by level, starting from the first-level page table to query access permissions until the page table entry access permission is not empty or reaches the last-level page table, and performs permission matching checks;

[0028] When the HPDS mechanism is enabled, the virtual-to-physical address translation component MMU (Memory Management Unit) in the ARM architecture ignores the permission settings of all page tables before the last-level page table and directly uses the permissions set by the last-level page table for permission checking.

[0029] In one embodiment, the method of using stack switching includes establishing a stack structure for the code in the isolated execution environment and setting permissions for accessing local variables through stack switching operations when the code in the isolated execution environment runs, including:

[0030] Establishing a stack structure for the code in the isolated execution environment and configuring permissions for this stack structure so that code outside the isolated execution environment cannot access this stack structure, and completing stack switching operations when code outside the isolated execution environment enters and exits the isolated execution environment;

[0031] Obtaining the process of the operating system kernel, judging the exception level when the ARM architecture is currently running, and selecting the corresponding register as the stack pointer to access stack data according to the currently running exception level.

[0032] In one embodiment, the ARM architecture includes an SP_EL0 stack register and an SP_EL1 stack register;

[0033] The SP_EL0 stack register is used to store the user stack pointer;

[0034] The SP_EL1 stack register is used to store the kernel stack pointer.

[0035] In one embodiment, constructing a gate structure in the isolated execution environment, where external code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction includes:

[0036] After the external code prepares the corresponding parameters, jump to the entrance of the gate structure in the isolated execution environment to execute the call to the internal code in the isolated execution environment;

[0037] When the code inside the isolated execution environment returns, it returns to the external code through the exit of the isolated execution environment to continue execution.

[0038] In one embodiment, after the external code prepares the corresponding parameters, jumping to the entrance of the gate structure in the isolated execution environment to execute the call to the internal code in the isolated execution environment includes:

[0039] At the entrance of the gate structure in the isolated execution environment, execute an instruction to disable the PAN, open the access permission of privileged code to unprivileged data, and perform stack switching;

[0040] The stack switching process is as follows: Save the kernel stack address of the register content in the member of the structure, and assign values to the register by assignment.

[0041] In one embodiment, when sending an interrupt during the interaction process, allowing the code in the isolated execution environment to have a safe interrupt during operation by modifying the interrupt entry and exit includes:

[0042] Based on the ARM architecture, during the process that the code has an interrupt and jumps to the exception handling entry to start execution, write the instruction address where the interrupt occurs into the ARM architecture register ELR_EL1;

[0043] Judge the position where the code has an interrupt by judging the size of the instruction address stored in the register ELR_EL1. The positions where the code has an interrupt include inside the isolated execution environment and outside the isolated execution environment;

[0044] Among them, when the instruction address stored in the register ELR_EL1 is greater than the starting address in the isolated execution environment and less than the ending address in the isolated execution environment, it is judged that the position where the code has an interrupt is inside the isolated execution environment; otherwise, it is judged that the position where the code has an interrupt is outside the isolated execution environment.

[0045] According to the second aspect of the embodiments of the present invention, a kernel page table protection system for an ARM platform is provided.

[0046] In one embodiment, a kernel page table protection system for an ARM platform includes:

[0047] An isolated execution environment construction unit, configured to construct an isolated execution environment by using the privilege level mechanism under the ARM architecture, and configure access privileges for the virtual page where the isolated execution environment is located;

[0048] A permission setting unit, configured to establish a stack structure for the code in the isolated execution environment by using the stack switching method, and perform permission setting on the access to local variables through stack switching operations when the code in the isolated execution environment is running;

[0049] A code interaction unit, configured to construct a gate structure in the isolated execution environment. External code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction, and when sending an interrupt during the interaction process, allow the code in the isolated execution environment to have a safe interrupt during operation by modifying the interrupt entry and exit.

[0050] According to the third aspect of the embodiments of the present invention, a computer device is provided.

[0051] In some embodiments, the computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.

[0052] According to a fourth aspect of the embodiments of the present invention, a computer-readable storage medium is provided.

[0053] In one embodiment, a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0054] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:

[0055] The present invention utilizes the PAN mechanism and the HPDS mechanism under the ARM architecture, which are respectively used to prevent external privileged code and unprivileged code from accessing the isolated execution environment, and implements a gate for isolating the interaction between the execution environment and the outside, so as to prevent direct access of unprivileged code to the isolated execution environment. The present invention uses the method of stack switching to ensure the security of the stack used by the code in the isolated execution environment; the present invention maliciously enables the code in the isolated execution environment to be safely interrupted. When it is interrupted and starts to execute ordinary kernel code, the execution environment is switched, and the execution environment can be switched again when the interrupt returns.

[0056] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention.

[0058] Figure 1 is a flowchart of a method for protecting a kernel page table for an ARM platform according to an exemplary embodiment;

[0059] Figure 2 is a schematic block diagram of a system for protecting a kernel page table for an ARM platform according to an exemplary embodiment;

[0060] Figure 3 is a schematic structural diagram of a computer device according to an exemplary embodiment;

[0061] Figure 4 is a schematic structural diagram of constructing an isolated execution environment using a privilege level mechanism in a method for protecting a kernel page table for an ARM platform according to an exemplary embodiment;

[0062] Figure 5It is a schematic structural diagram of using the HPDS mechanism to prevent user process code from accessing the isolated execution environment in a kernel page table protection method for the ARM platform shown according to an exemplary embodiment;

[0063] Figure 6 It is a schematic structural diagram of using the stack switching method to ensure the security of the code in the isolated execution environment in a kernel page table protection method for the ARM platform shown according to an exemplary embodiment;

[0064] Figure 7 It is a schematic structural diagram of the code in the isolated execution environment being interrupted and the execution environment being switched in a kernel page table protection method for the ARM platform shown according to an exemplary embodiment. Detailed implementation manners

[0065] The following description and drawings fully illustrate the specific embodiments herein, enabling those skilled in the art to practice them. Parts and features of some embodiments may be included in or substituted for parts and features of other embodiments. The scope of the embodiments herein includes the entire scope of the claims and all available equivalents of the claims. Herein, the terms "first", "second", etc. are only used to distinguish one element from another, without requiring or implying any actual relationship or order between these elements. In fact, the first element can also be called the second element, and vice versa. Moreover, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a structure, device or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such structure, device or equipment. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the structure, device or equipment including the said element. The various embodiments herein are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0066] As used herein, the terms "longitudinal", "lateral", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. They are only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In the description of the present application, unless otherwise specified and defined, the terms "mounted", "connected", and "coupled" shall be understood in a broad sense. For example, they can be mechanical connections or electrical connections, or the communication between two elements inside, can be directly connected, or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific circumstances.

[0067] As used herein, unless otherwise specified, the term "plurality" means two or more.

[0068] As used herein, the character " / " indicates that the objects before and after are in an "or" relationship. For example, A / B means: A or B.

[0069] As used herein, the term "and / or" is an associative relationship describing an object, indicating that three relationships can exist. For example, A and / or B means: A or B, or, the three relationships of A and B.

[0070] It should be understood that although the steps in the flowchart are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in the present application, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the figure may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these sub-steps or stages is not necessarily sequential either, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0071] Each module in the device or system of the present application can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory in the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.

[0072] Without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0073] Figure 1An embodiment of the kernel page table protection method for the ARM platform according to the present invention is shown.

[0074] Specifically, the present invention constructs an isolated execution environment using the privilege levels of the ARM architecture, such that the code outside the isolated execution environment does not have access rights to the data inside the isolated execution environment. To reduce performance overhead, the present invention does not adopt the method of page table switching, so the isolated execution environment and the outside share the same page table.

[0075] At the same time, to prevent external code from accessing the isolated execution environment, the present invention utilizes the PAN mechanism and HPDS mechanism under the ARM architecture to prevent external privileged code and non-privileged code from accessing the isolated execution environment respectively. And a gate (gate structure) is implemented for the interaction between the isolated execution environment and the outside, including the Entry gate (entry gate) through which external code passes when calling the isolated execution environment and the Exit gate (exit gate) through which the isolated execution environment returns to the outside. Modifications are made to ensure that external code must access the isolated execution environment by calling the Entry gate, which will open the access rights of the isolated execution environment, then start executing the code in the isolated execution environment, and the Exit gate will close the access rights of the isolated execution environment when returning.

[0076] In this alternative embodiment, the kernel page table protection method for the ARM platform includes:

[0077] Step S101, constructing an isolated execution environment using the privilege level mechanism under the ARM architecture, and configuring access privileges for the virtual page where the isolated execution environment is located;

[0078] Step S102, using the method of stack switching to establish a stack structure for the code in the isolated execution environment, and setting access permissions for the access of local variables through stack switching operations when the code in the isolated execution environment is running;

[0079] Step S103, constructing a gate structure in the isolated execution environment. External code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction. When an interrupt is sent during the interaction process, by modifying the interrupt entry and exit, the code in the isolated execution environment is allowed to have a safe interrupt during operation.

[0080] In this alternative embodiment, the constructing an isolated execution environment using the privilege level mechanism under the ARM architecture and configuring access privileges for the virtual page where the isolated execution environment is located includes:

[0081] Dividing the virtual address space under the ARM architecture into several regions, and allocating virtual address space in the high address region as the isolated execution environment;

[0082] Use the PAN and HPDS mechanisms under the ARM architecture to complete the restriction of access rights, including:

[0083] On the last-level page table, set the virtual page where the isolated execution environment is located to unprivileged, and use the PAN mechanism to prevent direct access to the isolated execution environment by privileged code;

[0084] On the first-level page table, set the virtual page where the isolated execution environment is located to privileged, and use the HPDS mechanism to change the selection of the virtual-to-physical address translation component for permission checking to prevent direct access to the isolated execution environment by unprivileged code.

[0085] In this alternative embodiment, the use of the PAN mechanism to prevent direct access to the isolated execution environment by privileged code includes:

[0086] When the PAN mechanism is enabled, privileged code can access unprivileged code;

[0087] When the PAN mechanism is disabled, privileged code cannot access unprivileged code.

[0088] In this alternative embodiment, the use of the HPDS mechanism to change the selection of the virtual-to-physical address translation component for permission checking to prevent direct access to the isolated execution environment by unprivileged code includes:

[0089] When the HPDS mechanism is disabled, the virtual-to-physical address translation component (MMU) in the ARM architecture uses a mechanism of querying level by level, starting from the first-level page table to query the access rights until the page table entry access right is not empty or reaches the last-level page table, and performs permission matching check;

[0090] When the HPDS mechanism is enabled, the virtual-to-physical address translation component (MMU) in the ARM architecture ignores the permission settings of all page tables before the last-level page table and directly uses the permissions set in the last-level page table for permission checking.

[0091] It should be added that to complete the restriction of access rights using the PAN and HPDS mechanisms under the ARM architecture, set the virtual page where the isolated execution environment is located to Unprivileged (unprivileged) on the last-level page table, and use the PAN mechanism to prevent direct access to the isolated execution environment by privileged code; set the virtual page where the isolated execution environment is located to Privileged (privileged) on the first-level page table, and use the HPDS mechanism to change the selection of the virtual-to-physical address translation component for permission checking, thereby preventing direct access to the isolated execution environment by unprivileged code.

[0092] In this alternative embodiment, the method using stack switching includes establishing a stack structure for the code in the isolated execution environment and setting permissions for accessing local variables through stack switching operations when the code in the isolated execution environment runs, including:

[0093] Establish a stack structure for the code in the isolated execution environment, and configure permissions for this stack structure so that the code outside the isolated execution environment cannot access this stack structure, and complete stack switching operations when the code outside the isolated execution environment enters and exits the isolated execution environment;

[0094] Obtain the process of the operating system kernel, and judge the exception level when the ARM architecture is currently running. Select the corresponding register as the stack pointer according to the currently running exception level to access stack data.

[0095] In this alternative embodiment, the ARM architecture includes an SP_EL0 stack register and an SP_EL1 stack register;

[0096] The SP_EL0 stack register is used to store the user stack pointer;

[0097] The SP_EL1 stack register is used to store the kernel stack pointer.

[0098] It should be added that the stack data security of the code running in the isolated execution environment is ensured by using the method of stack switching. During the running process of the code in the isolated execution environment, there may be access to local variables, and local variables are default stored on the stack during compilation. For the operating system kernel, there are generally a user stack and a kernel stack for stack access operations of non-privileged code and privileged code respectively. However, the data of both the user stack and the kernel stack can be accessed by the code outside the isolated execution environment. Therefore, it is necessary to establish a separate stack for the code in the isolated execution environment, set permissions so that the code outside the isolated execution environment cannot access this stack, and complete stack switching operations when entering and exiting the isolated execution environment.

[0099] In this alternative embodiment, constructing a gate structure in the isolated execution environment, where external code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction includes:

[0100] After the external code prepares the corresponding parameters, jump to the entrance of the gate structure in the isolated execution environment to execute the call of the internal code in the isolated execution environment;

[0101] When the code inside the isolated execution environment returns, it returns through the exit of the isolated execution environment to the external code to continue execution.

[0102] In this alternative embodiment, after the corresponding parameters are prepared in the external code, the execution of jumping to the entry of the gate structure in the isolated execution environment to call the internal code of the isolated execution environment includes:

[0103] At the entry of the gate structure in the isolated execution environment, the PAN is set to disabled by executing an instruction, the access permission of privileged code to unprivileged data is opened, and the stack is switched;

[0104] The process of stack switching is as follows: the kernel stack address of the register content is saved in the member of the structure, and the content of the register is assigned by assignment.

[0105] In this alternative embodiment, when an interruption is sent during the interaction process, allowing the code in the isolated execution environment to have a safe interruption during operation by modifying the interruption entry and exit includes:

[0106] Based on the ARM architecture, during the process that the code has an interruption and jumps to the exception handling entry to start execution, the instruction address where the interruption occurs is written into the register ELR_EL1 of the ARM architecture;

[0107] By judging the size of the instruction address stored in the register ELR_EL1, the position where the code has an interruption is judged, and the position where the code has an interruption includes inside and outside the isolated execution environment;

[0108] Among them, when the instruction address stored in the register ELR_EL1 is greater than the starting address in the isolated execution environment and less than the ending address in the isolated execution environment, it is judged that the position where the code has an interruption is inside the isolated execution environment, otherwise, it is judged that the position where the code has an interruption is outside the isolated execution environment.

[0109] It should be added that allowing the code in the isolated execution environment to have a safe interruption during operation by modifying the interruption entry and exit; since relevant operations of exiting the isolated execution environment and entering the ordinary kernel code execution need to be performed when the isolated execution environment is interrupted, the address where the interruption occurs needs to be judged at the interruption entry. If the interruption occurs in the isolated execution environment, relevant operations of exiting the isolated execution environment need to be performed, and after closing the access permission of the isolated execution environment, the ordinary kernel code is started to be executed; correspondingly, the return address also needs to be judged when returning from the interruption. If it is necessary to return to the isolated execution environment, relevant operations of entering the isolated execution environment need to be performed, and after opening the access permission of the isolated execution environment, the code in the isolated execution environment can be executed normally and safely.

[0110] To facilitate the understanding of the above technical solution of the present invention, the above technical solution of the present invention will be further described from the perspectives of architecture and principle as follows:

[0111] (1) PAN mechanism and HPDS mechanism based on the ARM architecture;

[0112] There is a bit in the page table of ARM to record the privilege level of the page. In fact, under exception level 1 of the ARM architecture (the exception level of a general operating system, not involving virtualization and security mode), it is divided into two privilege levels: Privileged and Unprivileged. When creating a page table, the page table created for the Linux kernel will set the corresponding page table entry to Privileged and make the kernel run at the privileged level. When the Linux kernel creates a page table for a user process, it will set the corresponding page table entry to Unprivileged and make the user process run at the non-privileged level.

[0113] Under the privilege level division of ARM, Unprivileged code can access Unprivileged data, and Privileged code can also access Privileged data, but Unprivileged code cannot access Privileged data. This is ensured by the virtual-to-physical address translation component MMU (Memory Management Unit). Otherwise, the MMU will generate an exception and be handled by the Linux exception handling mechanism.

[0114] Regarding the access permission of Privileged code to Unprivileged data, such access was allowed before the emergence of the PAN mechanism. The emergence of the PAN mechanism is to prevent Privileged code from accessing any Unprivileged data, specifically including:

[0115] When PAN is set to 1, Privileged code cannot access Unprivileged data;

[0116] When PAN is set to 0, Privileged code can access Unprivileged data.

[0117] The present invention utilizes this mechanism to construct an isolated execution environment, such as Figure 4As shown (in the figure, "Access not Permitted" means access is prohibited, "user space" means user space, and "Kernel Space" means the running space of the kernel, which can execute any command and call all system resources, while user space can only perform simple operations). Under the ARM architecture, the virtual address space is divided into two regions, and the register TTBR0_EL1 and TTBR1_EL1 are respectively used to query the page table for the two regions. The Linux kernel uses the low-address region and the high-address region to run user processes and kernel programs respectively. Among them, kernel data is set to Privileged, and kernel code also runs at the Privileged level, while user data is set to Unprivileged, and user code runs at the Unprivileged level. This technology allocates a virtual address space in the high-address region as an isolated execution environment, and sets the permissions in the corresponding page table to Unprivileged when constructing the page table for this region.

[0118] When the corresponding PSTATE register of the PAN mechanism is set to 1, Privileged code has no permission to access Unprivileged data. In this way, when the PAN mechanism is enabled, the kernel code running at the Privileged permission level cannot access the isolated area.

[0119] The HPDS mechanism of ARM is mainly used to determine the page table entry used by the MMU for permission checking. Each level of the ARM page table records the execution permissions of the page corresponding to the page table entry at the non-privileged and privileged levels, the write permission of the corresponding page, and the access privilege level of the corresponding page. And a page table query involves different page table entries of multiple page table levels at the same time. Then, there are settings for the above permissions in these page table entries. Which level of page table entry's specified permission the MMU uses for permission checking becomes a problem.

[0120] While performing address translation, the ARM's MMU will perform access permission verification, including execution permission, privilege level, write permission, etc. There are three page table formats under the ARM64 architecture: the table descriptor for describing the next-level page table; the block descriptor for describing the continuous physical page mapping; and the page descriptor for describing the single physical page mapping. Among them, the first two descriptors are only used for the first three levels of page tables, while the page descriptor is only used for the fourth level of page tables. For the table descriptor and the block descriptor, their [54:53] bits are respectively used to describe the execution permissions under non-privileged and privileged levels; while for the page descriptor, the [60:59] bits are used to describe the execution permissions under non-privileged and privileged levels. For the table descriptor, its [62:61] bits are respectively used to describe the write permission and the privilege level; while for the block descriptor and the page descriptor, the [7:6] bits are used to describe the write permission and the privilege level.

[0121] Before the HPDS mechanism emerged, the MMU adopted a mechanism of querying level by level: starting from the first-level page table, if the permission setting in the first-level page table is not empty (i.e., not all 0s), then the permissions set in the first-level page table are used for permission checking (the page table permissions mentioned here and below refer to the execution permissions of the corresponding page under non-privileged and privileged levels, the write permission of the corresponding page, and the access privilege level of the corresponding page mentioned above); if it is empty, then the first-level page table is skipped and the corresponding permission setting of the second-level page table is queried, and so on until the last-level page table. The operating system kernel tends to manage page permissions with finer granularity. Therefore, in the setting of page table permissions, the operating system kernel generally sets the permission bits of the first few levels of page tables to be empty and sets specific permissions on the last-level page table entry. That is to say, although the mechanism of querying level by level is used by default, the operating system kernel still defaults to using the permissions set in the last-level page table in design.

[0122] ARM v8.1 introduced the HPDS mechanism, mainly used to disable the above-mentioned mechanism of querying level by level:

[0123] When HPDS is 0 (i.e., when HPDS is disabled), the original mechanism is still adopted, starting from the first-level page table to query the access permission until the page table entry access permission is not empty or reaches the last-level page table, and then the permission matching check is performed (this process is carried out by the MMU and does not require manual intervention);

[0124] When HPDS is 1 (i.e., when HPDS is enabled), the MMU will ignore the permission settings of the previous levels of page tables and directly use the permissions set in the last level of the page table for permission checking.

[0125] The present invention utilizes the HPDS mechanism to prevent access by user process code to the isolated execution environment, such as Figure 5 as shown. In this technology, the page table design for the page where the isolated execution environment is located is as follows:

[0126] In the corresponding first-level page table entry, set the privilege level of the page to Privileged;

[0127] In the corresponding last-level page table entry, set the privilege level of the page to Unprivileged.

[0128] In this way, when HPD1 is 0, the page permissions in the high-address area are determined according to the mechanism of hierarchical query. Since the corresponding permissions of the isolated execution environment have been set to Privileged in the first-level page table, the privilege level of the isolated execution environment will be determined to be Privileged in this case; when HPD1 is 1, the high-address area directly uses the permission settings of the last-level page table. Since the permissions are set to Unprivileged in the fourth-level page table entry, the privilege level of the isolated execution environment will be determined to be Unprivileged in this case.

[0129] In summary, the present invention combines the PAN mechanism and the HPDS mechanism to prevent access by code outside the isolated execution environment to the isolated execution environment: when the kernel code is running, the data in the isolated execution environment should be Unprivileged, that is, HPD1 == 1; for the user process, when it is running, the data in the isolated environment should be Privileged, that is, HPD1 == 0.

[0130] Such a design requires secure modification of HPD1 when switching between the kernel and the user. This technology is achieved by modifying the exception handling of the operating system kernel. Since the execution must pass through the exception handling entry when switching from user process code to kernel code execution, and then the exception handling entry determines the exception type and jumps to a specific exception handling function for execution, and the exceptions that occur during the operation of the user process can only be EL0 (Exception Level 0, exception level) exceptions. Therefore, this technology modifies the exception handling entry kernel_ventry (a macro defining the exception vector), adds instructions when an EL0 exception occurs, and sets HPD1 to 1, so as to ensure that the data in the isolated execution environment is considered Unprivileged by the MMU after switching from the user process to the kernel code, preventing the kernel code from accessing the isolated execution environment. For the process of switching from kernel code to user code execution, this technology modifies this section of code, adds instructions to set HPD1 to 0, so as to ensure that the data in the isolated environment is considered Privileged by the MMU when returning from the kernel code to the user process to continue execution, preventing the user process from accessing the isolated execution environment.

[0131] (2) Stack switching design;

[0132] When constructing an isolated execution environment, the issue of stack data security also needs to be considered. In the operating system kernel, each process generally has a user stack and a kernel stack. The kernel stack pointer is stored in the Process Control Block (PCB) used to describe the process. In the ARM architecture, there are two stack registers, SP_EL0 and SP_EL1, which are used to store the user stack pointer and the kernel stack pointer respectively. The hardware will select the corresponding register as the stack pointer according to the current running exception level (EL0 or EL1) to access stack data. More specifically, when the process is in the user state, the hardware will use the pointer stored in the SP_EL0 register as the stack pointer for related operations. When the user process enters the kernel state through the exception entry and starts executing kernel code, the hardware will automatically switch and use the pointer stored in the SP_EL1 register as the stack pointer for related operations. If a process switch occurs during the exception handling of the kernel, the relevant code for the process switch will store the current kernel stack pointer SP_EL1 into the PCB, and then query the kernel stack pointer of the new process and restore it to the SP_EL1 register.

[0133] This technology uses the method of stack switching to ensure the security of the stack used by the code in the isolated execution environment, such as Figure 6As shown (switch in the figure represents conversion). A pointer iee_stack pointing to the IEE stack used by the code in the isolated execution environment is added to the PCB that describes the process information. When a process is created, a continuous memory space is allocated for the IEE stack, and the virtual pages where this continuous memory space is located are set with the same permissions as the isolated execution environment: the permissions in the first-level page table are set to Privileged, and the permissions in the last-level page table are set to Unprivileged. In this way, the pages allocated for the IEE stack can only be accessed by the code inside the isolated execution environment.

[0134] When this technology creates a process, it stores the starting address of the allocated IEE stack in the iee_stack pointer in the PCB. Specifically, a member variable called iee_stack is added to task_struct (the data structure that describes the PCB). When a process is created, the IEE starting address is assigned to iee_stack. At the same time, another member variable kernel_stack is added to save the pointer to the kernel stack. When entering and exiting the isolated execution environment, the stack switching operation is achieved by saving the current stack pointer and restoring the other stack pointer.

[0135] (3) Construction of the gate;

[0136] For the isolated execution environment constructed through the PAN mechanism and the HPDS mechanism, the data in this isolated execution environment cannot be accessed by the kernel code or user processes, thus ensuring the security of the data in the isolated execution environment. However, the code inside the isolated execution environment still needs to interact legally with the outside world, which requires the design of "gates" for entering and exiting the isolated execution environment respectively. That is, when external code calls the code in the isolated execution environment, it must jump to the Entry gate for entering the isolated execution environment after preparing the corresponding parameters. When the code inside the isolated execution environment returns, it must return to the external code through the Exit gate for exiting the isolated execution environment to continue execution.

[0137] In the Entry gate, an instruction is executed to set PAN to 0, granting Privileged code access to Unprivileged data, and a switch from the normal kernel stack to the IEE stack is performed. The switching process is as follows: First, the kernel stack address in the SP register is saved in the kernel_stack member of the task_struct structure, and then the content of the iee_stack member is assigned to the SP register. In the Exit gate, an instruction is executed to set PAN to 1, closing the access permission of Privileged code to Unprivileged data, and a switch from the IEE stack to the normal kernel stack is performed. The switching process is: First, the kernel stack address in the SP register is saved in the iee_stack member of the task_struct structure, and then the content of the kernel_stack member is assigned to the SP register.

[0138] In this way, the isolated execution environment code that starts to execute after the Entry gate is executed has access to the data in the isolated execution environment; after the interface code is executed and jumps to the Exit gate for execution, after returning to the external code, the external code does not have access to the data in the isolated execution environment, thus ensuring the security of the data in the isolated execution environment. If the isolated execution environment code is directly called without going through the Entry gate, then since the instruction to modify PSTATE PAN in the Entry gate has not been executed, a kernel space address access exception (page fault) will occur when the isolated execution environment code accesses the Unprivileged isolated execution environment data, and the operating system kernel will crash, thus ensuring the security of the system.

[0139] In addition, in the specific implementation, to ensure that the value of PAN is consistent with the currently used stack, interrupts need to be disabled during the execution of the two gates. Since the gate code is not complex, the short-term disabling of interrupts will not have a significant impact on the performance of the Linux kernel. To ensure that the isolated execution environment can be used at the initial stage of system initialization, the gate design needs to save the current value of the interrupt control register (DAIF register in the ARM architecture) before disabling interrupts and restore this value when the gate execution is completed, so as to ensure that interrupts are in the disabled state during the execution of the gate, and after the gate execution is completed, the interrupt state is the same as before the gate execution.

[0140] (4) Interrupt handling;

[0141] Most existing isolation means do not allow the code in the isolated execution environment to be interrupted during runtime. Therefore, this code cannot be too complex, otherwise it will have a greater impact on the performance of the kernel and is also likely to cause the kernel to crash. In this technology, interrupts are handled so that the code in the isolated execution environment can be safely interrupted. When it is interrupted and starts to execute ordinary kernel code, the execution environment is switched, and the execution environment can be switched again when the interrupt returns, as Figure 7 shown.

[0142] An important issue in this design is how to distinguish whether an interrupt occurs inside or outside the isolated execution environment. In the ARM architecture, during the process of a code interrupting and jumping to the exception handling entry to start execution, the hardware will automatically write the instruction address where the interrupt occurs into the register ELR_EL1. This technology distinguishes the code inside and outside the isolated execution environment by the instruction address where the interrupt occurs. To ensure the simplicity of the judgment logic, the present invention concentrates the code inside the isolated execution environment in a segment, the IEE segment. When judging, it only needs to judge whether the instruction address stored in the ELR_EL1 register is greater than the start address of the IEE segment and less than the end address of the IEE segment to determine whether the interrupt occurs inside the isolated execution environment.

[0143] More specifically, this technology adds code at the exception handling entry to provide support for interrupts occurring in the isolated execution environment. First, the ELR_EL1 register is checked. The check process is to compare the address size in the ELR_EL1 to see if the address is within the IEE environment address, so as to determine whether the current exception occurs inside the IEE environment. If it is determined that the current exception occurs in the isolated execution environment, then the interrupt address stored in the ELR_EL1 register is stored on the current stack (the IEE stack), and then the isolated execution environment is exited. Mainly, the currently used stack is switched to the kernel stack, and PAN is enabled. After this action, the isolated execution environment becomes inaccessible.

[0144] Code also needs to be added before the exception handling returns to provide support for the interrupt to return to the isolated execution environment. First, the ELR_EL1 register is checked. If the register indicates that the current exception occurs in the isolated execution environment, then enter the isolated execution environment, disable PAN and switch the currently used stack to the IEE stack. Considering the problem that the ELR_EL1 register may be tampered with, it is also necessary to obtain the previously stored value of the ELR_EL1 from the IEE stack and compare this value with the current ELR_EL1 register for verification.

[0145] It should be noted that during the exception handling process, the preservation and restoration of the register context exist: the register context is saved at the exception handling entry, and the register context is restored before the exception handling returns. Since the register context of the code in the isolated execution environment also belongs to a part of the isolated execution environment, this register context also needs to be used as isolated data. The method adopted by the present invention is that when the isolated execution environment is interrupted, the register context is first protected, and then the above-mentioned stack switching operation is performed. In this way, the register context will be saved in the IEE stack, and ordinary kernel code cannot access it. When returning, the stack switching operation is first performed, and then the register context is restored from the IEE stack and returned.

[0146] Figure 2 Fig. 4 shows an embodiment of the kernel page table protection system of the present invention for the ARM platform.

[0147] In this alternative embodiment, the kernel page table protection system for the ARM platform includes:

[0148] An isolated execution environment construction unit 201, configured to construct an isolated execution environment by using the privilege level mechanism under the ARM architecture, and configure access privileges for the virtual page where the isolated execution environment is located;

[0149] A permission setting unit 202, configured to establish a stack structure for the code in the isolated execution environment by using the method of stack switching, and perform permission setting on the access to local variables through stack switching operations when the code in the isolated execution environment is running;

[0150] A code interaction unit 203, configured to construct a gate structure in the isolated execution environment. External code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction. When an interruption is sent during the interaction process, by modifying the interruption entry and exit, it is allowed that the code in the isolated execution environment can have a safe interruption during the running process.

[0151] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in Figure 3 Fig. 5. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store static information and dynamic information data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0152] Those skilled in the art can understand that Figure 3 The structure shown in Figure 3 is only a block diagram of some structures related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0153] In addition, the present invention also provides a computer device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0154] In addition, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0155] Those of ordinary skill in the art can understand that all or part of the processes in the above method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, storage, database or other medium used in the various embodiments provided by the present invention can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0156] The present invention is not limited to the structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.

Claims

1. A kernel page table protection method for the ARM platform, characterized in that, Including: Construct an isolated execution environment by using the privilege level mechanism under the ARM architecture, and configure access privileges for the virtual pages where the isolated execution environment is located; Use the method of stack switching to establish a stack structure for the code in the isolated execution environment, and set permissions for accessing local variables through stack switching operations when the code in the isolated execution environment is running; Construct a gate structure in the isolated execution environment. External code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction. When an interrupt is sent during the interaction process, by modifying the interrupt entry and exit, allow the code in the isolated execution environment to have a safe interrupt during operation.

2. The kernel page table protection method for the ARM platform according to claim 1, characterized in that The constructing an isolated execution environment by using the privilege level mechanism under the ARM architecture and configuring access privileges for the virtual pages where the isolated execution environment is located includes: Divide the virtual address space under the ARM architecture into several regions, and allocate virtual address space in the high-address region as the isolated execution environment; Use the PAN and HPDS mechanisms under the ARM architecture to complete access permission restrictions, including: Set the virtual pages where the isolated execution environment is located as unprivileged on the last-level page table, and use the PAN mechanism to prevent direct access to the isolated execution environment by privileged code; Set the virtual pages where the isolated execution environment is located as privileged on the first-level page table, and use the HPDS mechanism to change the selection of the virtual-to-physical address translation component for permission checking to prevent direct access to the isolated execution environment by unprivileged code.

3. The method for protecting the kernel page table for the ARM platform according to claim 2, wherein The using the PAN mechanism to prevent direct access to the isolated execution environment by privileged code includes: When the PAN mechanism is enabled, privileged code can access unprivileged code; When the PAN mechanism is disabled, privileged code cannot access unprivileged code.

4. The method for protecting the kernel page table for the ARM platform according to claim 2, wherein The using the HPDS mechanism to change the selection of the virtual-to-physical address translation component for permission checking to prevent direct access to the isolated execution environment by unprivileged code includes: When the HPDS mechanism is disabled, the virtual-to-physical address translation component MMU (Memory Management Unit) in the ARM architecture adopts a mechanism of querying level by level, starting from the first-level page table to query access permissions until the page table entry access permission is not empty or reaches the last-level page table, and performs permission matching checks; When the HPDS mechanism is enabled, the virtual-to-physical address translation component MMU in the ARM architecture ignores the permission settings of all page tables before the last-level page table and directly uses the permissions set by the last-level page table for permission checking.

5. The method for protecting kernel page tables for the ARM platform according to claim 1, wherein The using the method of stack switching to establish a stack structure for the code in the isolated execution environment and setting permissions for accessing local variables through stack switching operations when the code in the isolated execution environment is running includes: Establish a stack structure for the code in the isolated execution environment, and configure permissions for this stack structure so that the code outside the isolated execution environment cannot access this stack structure, and complete the stack switching operation when the code outside the isolated execution environment enters and exits the isolated execution environment; Obtain the process of the operating system kernel, and judge the exception level when the ARM architecture is currently running, and select the corresponding register as the stack pointer to access stack data according to the currently running exception level.

6. The method for protecting the kernel page table for the ARM platform according to claim 5, wherein The ARM architecture includes an SP_EL0 stack register and an SP_EL1 stack register; The SP_EL0 stack register is used to store the user stack pointer; The SP_EL1 stack register is used to store the kernel stack pointer.

7. The method for protecting kernel page tables for the ARM platform according to claim 1, wherein Constructing a gate structure in the isolated execution environment, the external code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction, including: After the external code prepares the corresponding parameters, jump to the entry of the gate structure in the isolated execution environment to execute the internal code call of the isolated execution environment; When the code inside the isolated execution environment returns, it returns to the external code through the exit of the isolated execution environment and continues to execute.

8. The method for protecting kernel page tables for the ARM platform according to claim 7, wherein After the external code prepares the corresponding parameters, jump to the entry of the gate structure in the isolated execution environment to execute the internal code call of the isolated execution environment, including: At the entry of the gate structure in the isolated execution environment, set the PAN to disabled by executing an instruction, open the access permission of privileged code to unprivileged data, and perform stack switching; The stack switching process is as follows: save the kernel stack address of the register content in the member of the structure, and assign values to the register by assignment.

9. The method for protecting kernel page tables for the ARM platform according to claim 1, characterized in that, When an interruption is sent during the interaction process, by modifying the interruption entry and exit, allow the code in the isolated execution environment to have a safe interruption during operation, including: Based on the ARM architecture, during the process of an interruption occurring in the code and jumping to the exception handling entry to start execution, write the instruction address where the interruption occurs into the register ELR_EL1 of the ARM architecture; Judge the position where the code interruption occurs by judging the size of the instruction address stored in the register ELR_EL1. The position where the code interruption occurs includes inside and outside the isolated execution environment; Among them, when the instruction address stored in the register ELR_EL1 is greater than the starting address in the isolated execution environment and less than the ending address in the isolated execution environment, it is judged that the position where the code interruption occurs is inside the isolated execution environment, otherwise, it is judged that the position where the code interruption occurs is outside the isolated execution environment.

10. A kernel page table protection system for the ARM platform, characterized in that, Including: An isolated execution environment construction unit, which is used to construct an isolated execution environment by using the privilege level mechanism under the ARM architecture, and configure access privileges for the virtual page where the isolated execution environment is located; A permission setting unit, which is used to establish a stack structure for the code in the isolated execution environment by using the method of stack switching, and set the access permission for local variables through stack switching operations when the code in the isolated execution environment is running; A code interaction unit, which is used to construct a gate structure in the isolated execution environment. The external code needs to prepare corresponding parameters and enter the isolated execution environment through the gate structure for interaction, and when an interruption is sent during the interaction process, by modifying the interruption entry and exit, allow the code in the isolated execution environment to have a safe interruption during operation.