Secure communication method suitable for confidential virtual machine and PCIe device, computing device and medium

By introducing a control bridge into the computing device to realize the security fence of PCIe devices, the problem that heterogeneous acceleration devices and confidential virtual machines cannot be used together is solved, and secure and trustworthy data transmission and computing are achieved.

CN120301713AActive Publication Date: 2025-07-11SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

Patent Information

Application Number
CN202510780014.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-11
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

The existing heterogeneous acceleration computing power and special acceleration equipment cannot be used in conjunction with a confidential virtual machine-level trusted execution environment, resulting in the inability to effectively protect the security of the internal data of the computing power card and the inability to achieve the purpose of safe and trustworthy computing.

Method used

By introducing a control bridge into the computing device, the secure fence of the PCIe device is realized, and the control bridge communicates with the confidential virtual machine encrypted communication, ensuring that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext.

Benefits of technology

The combined use of PCIe devices and confidential virtual machines is realized to ensure the security and credibility of data transmission and meet users' security needs for heterogeneous acceleration computing power and internal data of special acceleration devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301713A_ABST
    Figure CN120301713A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of confidential computing, in particular to a secure communication method suitable for a confidential virtual machine and PCIe equipment, computing equipment and a medium. The method is applied to a computing device, the computing device comprises a confidential virtual machine, a PCIe device and a control bridge, the control bridge achieves a security fence for the PCIe device, the PCIe device communicates with the confidential virtual machine through the control bridge, and the method comprises the steps that the control bridge obtains target data between the PCIe device and the confidential virtual machine; and the control bridge encrypts / decrypts the target data, so that the target data is transmitted between the PCIe equipment and the confidential virtual machine in a ciphertext form. According to the method and the device, the control bridge used for realizing the security fence of the PCIe equipment is arranged, and the encrypted transmission is carried out through the control bridge and the confidential virtual machine, so that the PCIe equipment can be combined with the confidential virtual machine for use, and the secure and trusted computing capability is realized through the encrypted transmission between the control bridge and the confidential virtual machine.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of confidential computing technology, and particularly to a secure communication method, a computing device, and a medium applicable to confidential virtual machines and PCIe devices. Background Art

[0002] With the rapid development of artificial intelligence (AI) and large models, the demand for computing resources is increasing day by day. To meet these demands, heterogeneous acceleration computing power cards are currently widely used as devices for executing AI and large model computing tasks, and are equipped with a large number of special acceleration devices, such as FPGA acceleration cards, ASIC acceleration cards, etc. However, existing heterogeneous acceleration computing power and special acceleration devices cannot be used jointly with the confidential virtual machine-level trusted execution environment (TEE), which limits the effective protection of the internal data security of the computing power card and cannot achieve the purpose of secure and trusted computing.

[0003] Therefore, the existing technology still needs to be improved. Summary of the Invention

[0004] The technical problem to be solved by this application is to provide a secure communication method, a computing device, and a medium applicable to confidential virtual machines and PCIe devices in view of the deficiencies of the existing technology.

[0005] To solve the above technical problem, a first aspect of this application provides a secure communication method applicable to confidential virtual machines and PCIe devices, which is applied to a computing device. The computing device includes a confidential virtual machine, a PCIe device, and a control bridge. The control bridge implements a security fence for the PCIe device, and the PCIe device communicates with the confidential virtual machine through the control bridge. The method includes: The control bridge obtains target data between the PCIe device and the confidential virtual machine; The control bridge encrypts / decrypts the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form.

[0006] In the secure communication method applicable to confidential virtual machines and PCIe devices, the target data includes first data transmitted from the confidential virtual machine to the PCIe device and second data transmitted from the PCIe device to the confidential virtual machine. The control bridge encrypts / decrypts the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form, which specifically includes: When the target data is the first data transmitted from the confidential virtual machine to the PCIe device, the control bridge decrypts the first data so that the PCIe device can obtain the decrypted first data; When the target data is the second data transmitted from the PCIe device to the confidential virtual machine, the control bridge encrypts the second data and transmits the encrypted second data to the confidential virtual machine.

[0007] The described secure communication method applicable to a confidential virtual machine and a PCIe device, wherein the confidential virtual machine is used to encrypt the data to be transmitted to obtain the first data and decrypt the encrypted second data.

[0008] The described secure communication method applicable to a confidential virtual machine and a PCIe device, wherein the control bridge obtaining the target data between the PCIe device and the confidential virtual machine specifically includes: The control bridge obtains the trigger reason for triggering the transmission of the target data; When the trigger reason is that the confidential virtual machine actively accesses the PCIe device, the control bridge obtains the first data formed by the confidential virtual machine through a write operation and / or the second data determined by the PCIe device based on the read operation of the confidential virtual machine to obtain the target data between the PCIe device and the confidential virtual machine; When the trigger reason is that the PCIe device actively performs DMA, the control bridge obtains the first data moved by the PCIe device from a preset shared memory and / or obtains the second data formed by the PCIe device based on a DMA write operation to obtain the target data between the PCIe device and the confidential virtual machine, where the first data is written into the preset shared memory by the confidential virtual machine based on a DMA read operation.

[0009] The described secure communication method applicable to a confidential virtual machine and a PCIe device, wherein when the target data is the second data formed by the PCIe device based on a DMA write operation, the control bridge encrypts / decrypts the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form as: The control bridge encrypts the second data and transmits the encrypted second data to the preset shared memory so that the confidential virtual machine moves the encrypted second data from the preset shared memory.

[0010] The described secure communication method applicable to a confidential virtual machine and a PCIe device, wherein the preset shared memory is outside the TEE side so that both the confidential virtual machine and the PCIe device can move the memory data in the preset shared memory.

[0011] The described secure communication method applicable to a confidential virtual machine and a PCIe device, wherein the method further includes: When the triggering cause is a PCIe device interrupt, the control bridge controls the interrupt data of the PCIe device and transmits the interrupt data in plain text.

[0012] The secure communication method applicable to a confidential virtual machine and a PCIe device, wherein, before the control bridge obtains the target data between the PCIe device and the confidential virtual machine, the method further includes: The confidential virtual machine authenticates the identity of the control bridge; When the identity authentication is successful, the confidential virtual machine negotiates a communication key with the control bridge, so that the confidential virtual machine and the control bridge encrypt / decrypt the target data using the communication key.

[0013] The second aspect of the present application provides a computing device, wherein the computing device includes a processor and a memory; the processor of the computing device is configured to execute instructions stored in the memory of the computing device, so that the computing device executes the secure communication method applicable to a confidential virtual machine and a PCIe device as described above. The third aspect of the present application provides a computer-readable storage medium, which includes computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the secure communication method applicable to a confidential virtual machine and a PCIe device as described above.

[0014] Beneficial effects: Compared with the prior art, the present application provides a secure communication method, a computing device and a medium applicable to a confidential virtual machine and a PCIe device. The method is applied to a computing device, which includes a confidential virtual machine, a PCIe device and a control bridge. The control bridge realizes a security fence for the PCIe device. The PCIe device communicates with the confidential virtual machine through the control bridge. The method includes that the control bridge obtains the target data between the PCIe device and the confidential virtual machine; the control bridge encrypts / decrypts the target data, so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext. By setting a control bridge for realizing the security fence of the PCIe device and performing encrypted transmission between the control bridge and the confidential virtual machine, the PCIe device can be used in combination with the confidential virtual machine, and the ability of secure and trustworthy computing is realized through the encrypted transmission between the control bridge and the confidential virtual machine. Description of the Drawings

[0015] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0016] Figure 1 It is a schematic block diagram of the principle of an example of the computing device provided by the embodiment of the present application.

[0017] Figure 2 It is a schematic block diagram of the principle of another example of the computing device provided by the embodiment of the present application.

[0018] Figure 3 It is a schematic flowchart of the secure communication method applicable to confidential virtual machines and PCIe devices provided by the embodiment of the present application. Detailed implementation manners

[0019] The embodiments of the present application provide a secure communication method, a computing device, and a medium applicable to confidential virtual machines and PCIe devices. To make the objectives, technical solutions, and effects of the present application clearer and more definite, the following further elaborates on the present application with reference to the accompanying drawings and by way of examples. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0020] Those skilled in the art of this technology can understand that unless specifically stated otherwise, the singular forms "a", "an", "the", and "said" used herein may also include the plural forms. It should be further understood that the term "including" used in the specification of the present application means the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more related listed items.

[0021] Those skilled in the art of this technology can understand that unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the field to which the present application belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless specifically defined as here.

[0022] It should be understood that the sequence numbers and magnitudes of the steps in this embodiment do not indicate the order of execution. The order of execution of each process is determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0023] The following further illustrates the application content by describing the embodiments in conjunction with the accompanying drawings.

[0024] To make the technical solution provided by the present application clearer, the following first explains relevant terms.

[0025] (1) Virtual machine: It refers to a complete computer system with complete hardware system functions simulated by software and running in a completely isolated environment. What can be done on a server can be achieved in a virtual machine. Each virtual machine has an independent hard disk and operating system, and the user of the virtual machine can operate the virtual machine just like using a server.

[0026] (2) PCIe device: A device that conforms to the PCIe bus standard is called a PCIe device, and can also be called an endpoint device, external device or I / O device. It is at the end of the PCIe bus system topology and generally serves as the initiator or terminator of bus operations. The PCIe bus architecture can contain multiple PCIe devices, such as graphics cards, network cards, sound cards, acceleration devices (such as GPUs, NPUs), disks, etc.

[0027] (3) Direct memory access (DMA): It is an interface technology in which an external device directly exchanges data with the system memory without passing through the processor (which can also be called the central processing unit (CPU)). The external device can use DMA to transfer data in batches to the memory and then send an interrupt to notify the processor. Its transmission process does not pass through the processor, reducing the burden on the processor.

[0028] Next, the application scenarios related to the present application are introduced.

[0029] This application relates to a secure communication scenario applicable to confidential virtual machines and PCIe devices. In this secure communication scenario, a computing device (such as a server) includes a hardware layer and a software layer. The hardware layer is the conventional configuration of the computing device, where the PCIe device can be, for example, a network card, GPU, NPU, offloading card, or other devices that can be inserted into the PCIe slot of the server. However, existing heterogeneous acceleration computing power and special acceleration devices cannot be used in conjunction with the trusted execution environment (TEE) at the confidential virtual machine level. This makes it necessary to send the data inside the heterogeneous acceleration computing power and special acceleration devices to the REE side (which can also be referred to as the normal world), and the REE side cannot provide security protection for the data inside the heterogeneous acceleration computing power and special acceleration devices, posing a security threat to the data inside the heterogeneous acceleration computing power and special acceleration devices and failing to achieve the goal of secure and trusted computing.

[0030] Therefore, how to enable PCIe devices to be used in conjunction with confidential virtual machines to meet the security requirements of users for data devices inside heterogeneous acceleration computing power and special acceleration devices has become an urgent problem to be solved in this field.

[0031] To solve the above problems, this application provides a secure communication method, computing device, and medium applicable to confidential virtual machines and PCIe devices. The method is applied to a computing device, which includes a confidential virtual machine, a PCIe device, and a control bridge. The control bridge implements a security fence for the PCIe device, and the PCIe device communicates with the confidential virtual machine through the control bridge. The method includes the control bridge obtaining target data between the PCIe device and the confidential virtual machine; the control bridge encrypting / decrypting the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form. By setting up a control bridge for implementing a security fence for the PCIe device and performing encrypted transmission between the control bridge and the confidential virtual machine, this application enables PCIe devices to be used in conjunction with confidential virtual machines and realizes the ability of secure and trusted computing through the encrypted transmission between the control bridge and the confidential virtual machine.

[0032] Specifically, as Figure 1 shown, the computing device 100 includes a PCIe device, a confidential virtual machine, and a control bridge; the confidential virtual machine can be one or more confidential virtual machines. In Figure 1Taking a computing device including a confidential virtual machine as an example, the confidential virtual machine can be deployed on the TEE side. The control bridge is used to implement a security fence for PCIe devices. The PCIe device and the confidential virtual machine both communicate with the control bridge to achieve the joint use of the PCIe device and the confidential virtual machine through the control bridge, that is, the PCIe device and the confidential virtual machine communicate with each other through the control bridge. Among them, the confidential virtual machine may include an operating system kernel and one or more applications (APPs) ( Figure 1 not shown). The operating system kernels in the confidential virtual machine and the ordinary confidential virtual machine can be powerful general operating system kernels such as Linux, and the present application does not make specific limitations on this. In addition, Figure 1 only an example provided by the present application is given, and the computing device 100 may have more or fewer components than Figure 1 the components shown, or may have different configurations of components, etc., which are not specifically limited here.

[0033] Furthermore, the control bridge cooperates with the confidential virtual machine to implement secure and trusted computing to achieve the secure and trusted technology of PCIe devices. Among them, the control bridge does not change the logical layer behavior of the PCIe device and has control capabilities over the data of the PCIe device. Specifically, the control bridge can be a hardware board, which uses a PCIe transparent bridge to implement a security fence for the PCIe device. Among them, the PCIe transparent bridge does not change the logical layer behavior of the connected PCIe device, so that it is not necessary to modify the device's own driver within the confidential virtual machine. The control bridge is located between the PCIe device and the confidential virtual machine, and the data of the PCIe device is transmitted to the confidential virtual machine through the control bridge. The control bridge realizes the security enhancement of the data of the PCIe device and realizes the joint use of the PCIe device and the confidential virtual machine on the TEE side.

[0034] Next, in combination with Figure 3 the flowchart of the secure communication method provided by the present application applicable to the confidential virtual machine and the PCIe device, the process of the secure communication method applicable to the confidential virtual machine and the PCIe device will be described in detail.

[0035] As Figure 3 shown, the secure communication method applicable to the confidential virtual machine and the PCIe device specifically includes: S10. The control bridge obtains the target data between the PCIe device and the confidential virtual machine; S20. The control bridge encrypts / decrypts the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form.

[0036] Specifically, in step S10, the target data is the IO data between the PCIe device and the confidential virtual machine. The IO data may include the first data transmitted from the confidential virtual machine to the PCIe device, or the second data transmitted from the PCIe device to the confidential virtual machine. That is, when the confidential virtual machine transmits the first data to the PCIe device, the first data will be acquired by the control bridge; when the PCIe device transmits the second data to the confidential virtual machine, the PCIe device will transmit the second data to the control bridge.

[0037] In one embodiment, since all data of the PCIe device interacts with the confidential virtual machine through the control bridge, in order to ensure the security of communication between the control bridge and the confidential virtual machine, before implementing secure communication between the PCIe device and the confidential virtual machine through the control bridge, it is necessary to perform identity authentication on the control bridge. Based on this, before the control bridge acquires the target data between the PCIe device and the confidential virtual machine, the method further includes: The confidential virtual machine performs identity authentication on the control bridge; When the identity authentication is successful, the confidential virtual machine negotiates a communication key with the control bridge so that the confidential virtual machine and the control bridge use the communication key to encrypt / decrypt the target data.

[0038] Specifically, identity authentication is used to verify the control bridge to ensure its security. Among them, identity authentication may include remote authentication and identity verification. Remote authentication is for the confidential virtual machine to determine the identity legality of the control bridge through remote authentication, and identity verification is for the confidential virtual machine to perform identity verification on the control bridge with legal identity. Among them, the identity verification method can be completed using existing methods, such as the national standard GB / T 15843.3-2016, etc.

[0039] Further, after the identity authentication of the control bridge is passed, a communication key is negotiated between the control bridge and the confidential virtual machine, and this communication key is used to encrypt / decrypt the target data between the control bridge and the confidential virtual machine. That is to say, both the confidential virtual machine and the control bridge use the communication key to encrypt / decrypt the target data. Specifically, the control bridge will use this communication key to decrypt the first data from the confidential virtual machine and encrypt the second data to be transmitted to the confidential virtual machine; similarly, the confidential virtual machine will use this communication key to decrypt the second data from the control bridge and encrypt the data to be transmitted to the control bridge to obtain the first data. Among them, the communication key can be jointly negotiated by the control bridge and the confidential virtual machine, such as using the DH algorithm, the SM2 key exchange protocol, etc.; it can also be directly distributed by the confidential virtual machine. And when the communication key is distributed by the confidential virtual machine, the confidential virtual machine can use the authentication public key of the control bridge to encrypt the communication key and send the encrypted communication key to the control bridge. The control bridge uses its own authentication private key to decrypt the encrypted communication key to obtain the communication key. This can avoid the leakage of the communication key during the transmission from the confidential virtual machine to the control bridge, improve the security of the communication key, and further improve the security and trust level between the control bridge and the confidential virtual machine.

[0040] In one implementation, since the target data is the IO data between the PCIe device and the confidential virtual machine, where the IO data between the PCIe device and the confidential virtual machine can include the IO data generated by the confidential virtual machine actively accessing the PCIe device (such as the CPU actively accessing the computing device, etc.), the IO data generated by the PCIe device interrupt, the IO data generated by the PCIe device actively performing DMA, etc. Among them, the confidential virtual machine actively accessing the PCIe device includes the software accessing the configuration space of the PCIe device and the memory mapping space of the PCIe device. The configuration space between the PCIe device and the PCIe device is unified, and its data does not need to be encrypted / decrypted for protection; the memory mapping space is set for each PCIe device itself, and it is related to the task data and needs to be encrypted / decrypted for protection. Therefore, the data called by the confidential virtual machine actively accessing the PCIe device needs to be encrypted / decrypted for protection. The IO data generated by the PCIe device interrupt is irrelevant to the task data, so the IO data generated by the PCIe device interrupt does not need to be encrypted / decrypted for protection. The IO data generated by the PCIe device actively performing DMA is closely related to the task data and needs to be encrypted / decrypted for protection.

[0041] To this end, when the control bridge obtains the target data between the PCIe device and the confidential virtual machine, it determines whether to encrypt / decrypt the target data according to the trigger reason of the target data. Accordingly, the control bridge obtaining the target data between the PCIe device and the confidential virtual machine specifically includes: The control bridge obtains the trigger reason that triggers the transmission of the target data; When the trigger reason is that the confidential virtual machine actively accesses the PCIe device, the control bridge obtains the first data formed by the confidential virtual machine through a write operation and / or the second data determined by the PCIe device based on the read operation of the confidential virtual machine, so as to obtain the target data between the PCIe device and the confidential virtual machine; When the trigger reason is that the PCIe device actively performs DMA, the control bridge obtains the first data transferred by the PCIe device from the preset shared memory and / or obtains the second data formed by the PCIe device based on the DMA write operation, so as to obtain the target data between the PCIe device and the confidential virtual machine, where the first data is written into the preset shared memory by the confidential virtual machine based on the DMA read operation.

[0042] Specifically, the trigger reason is the reason for data transmission between the PCIe device and the confidential virtual machine. As can be seen from the above, the trigger reasons include that the confidential virtual machine actively accesses the PCIe device, the PCIe device interrupts, and the PCIe device actively performs DMA. Among them, when the trigger reason is that the confidential virtual machine actively accesses the PCIe device, the control bridge will obtain the first data that the confidential virtual machine needs to write to the PCIe device (that is, the first data is the write data formed based on the write operation of the confidential virtual machine), and will also obtain the second data returned by the PCIe device based on the read operation of the confidential virtual machine (that is, the second data is the return data formed based on the read operation of the confidential virtual machine). That is to say, when the confidential virtual machine actively accesses the PCIe device, the confidential virtual machine will perform read and write operations on the PCIe device. When performing a read operation, the PCIe device will transmit the second data that needs to be fed back to the confidential virtual machine based on the read operation to the control bridge; when performing a write operation, the confidential virtual machine will transmit the first data that needs to be written to the PCIe device to the control bridge.

[0043] Furthermore, when the trigger reason is a PCIe device interrupt, the control bridge directly obtains the interrupt data formed by the PCIe device interrupt.

[0044] Furthermore, when the trigger reason is that the PCIe device actively performs DMA, the DMA of the PCIe device is initiated by the device driver software in the confidential virtual machine (such as application software calls, etc.), such as Figure 2As shown, the driver can apply for a shared memory (denoted as the preset shared memory) for DMA, and the PCIe device and the confidential virtual machine use this preset shared memory to achieve data transmission. Specifically, the PCIe device encrypts the data formed by DMA into second data through the control bridge and then shares it to the preset shared memory, so that the confidential virtual machine can move the second data from this preset shared memory; at the same time, the PCIe device also moves the first data stored in the preset shared memory by the virtual set based on the DMA of the PCIe device from the preset shared memory, and the control bridge reads the first data moved by the PCIe device and decrypts it. Among them, the first data is written into the preset shared memory by the confidential virtual machine based on the DMA read operation, and the second data is formed by the PCIe device based on the DMA write operation.

[0045] The above completes the description of step S10. Next, the description of step S20 will be given.

[0046] In step S20, the control bridge encrypts / decrypts the obtained target data. Specifically, when the target data is the first data transmitted from the confidential virtual machine to the PCIe device, the first data is the ciphertext data encrypted by the confidential virtual machine, and the control bridge decrypts the first data; when the target data is the second data transmitted from the PCIe device to the confidential virtual machine, the second data is the plaintext data, and the control bridge encrypts the second data and transmits the decrypted second data to the confidential virtual machine.

[0047] Furthermore, as can be seen from the description of step S10, according to the triggering reason of the target data, when the first data and the second data are interrupt data, there is no need to encrypt / decrypt the first data and the second data, and the first data and the second data can be directly transmitted between the control bridge and the confidential virtual machine in plaintext form. Therefore, when the control bridge encrypts and decrypts the target data, it can first determine whether to encrypt / decrypt the target data according to the triggering reason of the target data. Specifically, when the triggering reason is a PCIe device interruption, the control bridge does not encrypt / decrypt the target data and transmits the interruption data of the PCIe device in plaintext form. Of course, the confidential virtual machine also does not encrypt / decrypt the target data generated due to the PCIe device interruption; when the triggering reason is that the confidential virtual machine actively accesses the PCIe device and the PCIe device actively performs DMA, the control bridge encrypts / decrypts the target data and transmits the target data to the confidential virtual machine in ciphertext form, and the confidential virtual machine also encrypts / decrypts the target data generated due to the confidential virtual machine actively accessing the PCIe device and the PCIe device actively performing DMA, so as to transmit the target data in ciphertext form. Of course, in practical applications, the control bridge and the confidential virtual machine can also encrypt / decrypt the target data generated due to the PCIe device interruption according to user needs.

[0048] The processes of encrypting / decrypting the target data formed by the confidential virtual machine actively accessing the PCIe device and the target data formed by the PCIe device actively performing DMA are described below respectively.

[0049] In the process of encrypting / decrypting the target data formed by the confidential virtual machine actively accessing the PCIe device, the software accesses the memory mapped space mainly using system functions such as iowrite32() / ioread32(). Therefore, only the system functions need to be modified so that when the confidential virtual machine accesses the PCIe device, the control bridge decrypts the first data to be written to the PCIe device and encrypts the second data read from the PCIe device.

[0050] In the process of encrypting / decrypting the target data formed by the PCIe device actively performing DMA, since the memory space within the TEE is protected by the TEE, the data in the memory space within the TEE is in ciphertext form, and the key corresponding to this ciphertext is only known to the TEE. This makes it impossible for the PCIe device to know the key and thus impossible to decrypt the data in the memory space within the TEE. Therefore, in order to enable the data corresponding to the control bridge DMA operation, a preset shared memory is applied for outside the TEE side. The control bridge and the confidential virtual machine write data in ciphertext form to this preset shared memory. The confidential virtual machine will move the data from this preset shared memory and decrypt the moved data. The PCIe device will move the data from the preset shared memory, and the control bridge will decrypt the data moved by the PCIe device. Specifically, the confidential virtual machine encrypts the data to obtain the first data and writes the first data to the preset shared memory, and at the same time moves the encrypted second data from the preset shared memory and decrypts the encrypted second data; the control bridge encrypts the second data and writes the encrypted second data to the preset shared memory, the PCIe device moves the first data from the preset shared memory, and the control bridge decrypts the first data moved by the PCIe device.

[0051] In a specific implementation, when the PCIe device actively performs a DMA read operation through DMA, the write operation of the confidential virtual machine writing data into the preset shared memory is intercepted, and the written data formed by the write operation is encrypted to obtain the first data, and the first data is written into the preset shared memory. The PCIe device initiates a MemRd request through the PCIe bus to transfer the first data in the preset memory into the memory of the PCIe device, and the control bridge decrypts the first data transferred into the memory of the PCIe device. This can avoid writing the data to be transmitted into the preset shared memory in plaintext, and during the process of the PCIe device initiating a MemRd request through the PCIe bus to transfer the data in the preset shared memory to the device memory, the problem that the data to be transmitted is easily snooped and stolen by high-privilege users or the confidential virtual machine monitor (hypervisor).

[0052] Similarly, when the PCIe device actively performs a DMA write operation through DMA, the control bridge encrypts the data of the device MemWr (i.e., the second data), and transmits the encrypted second data to the preset shared memory, and then notifies the confidential virtual machine (such as using the interrupt method, etc.). After the confidential virtual machine transfers the encrypted second data in the preset shared memory to the secure memory, it decrypts the encrypted second data (if technologies such as GCM are used, the integrity of the data can also be verified).

[0053] In the embodiment of the present application, by pre-applying for a shared memory, and then encrypting the data that needs to be written into the preset shared content through the control bridge and the confidential virtual machine so that the data is stored in the preset shared memory in ciphertext, the data in the preset shared memory is prevented from being snooped and stolen. At the same time, the preset shared memory and the confidential virtual machine, the PCIe device, and the control bridge all use ciphertext form for transmission, ensuring the data security of the transmission link and avoiding data leakage during the transmission process. In addition, the data is in a secure state in both the memory space of the PCIe device and the memory space of the confidential virtual machine. Therefore, the present application ensures the full-link security protection of the DMA data and further improves the security of the DMA data.

[0054] In addition, after decrypting the first data, the control bridge can verify the integrity of the decrypted first data. If the verification passes, it is legal data; if the verification fails, it is illegal data. The control bridge will intercept the illegal data (i.e., the decrypted first data that fails the verification) to ensure that all decrypted first data comes from a legitimate confidential virtual machine. At the same time, the confidential virtual machine side can also ensure that all second data comes from a legitimate PCIe device in the same way. Therefore, the security of the memory data on the PCIe device side can be protected.

[0055] Based on the above security communication method applicable to confidential virtual machines and PCIe devices, this embodiment provides a computer-readable storage medium. The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement some or all of the steps in the security communication method applicable to confidential virtual machines and PCIe devices as described in the above embodiment.

[0056] Based on the above security communication method applicable to confidential virtual machines and PCIe devices, this application further provides a computing device. The computing device includes a processor and a memory; the processor of the computing device is configured to execute instructions stored in the memory of the computing device to cause the computing device to execute the security communication method applicable to confidential virtual machines and PCIe devices as described above.

[0057] In addition, the specific processes of loading and executing multiple instructions in the above storage medium and computing device have been described in detail in the above method, and will not be repeated here one by one.

[0058] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.

Claims

1. A secure communication method applicable to confidential virtual machines and PCIe devices, characterized in that, An application computing device, the computing device includes a confidential virtual machine, a PCIe device, and a control bridge, the control bridge implements a security fence for the PCIe device, and the PCIe device communicates with the confidential virtual machine through the control bridge. The method includes: The control bridge obtains target data between the PCIe device and the confidential virtual machine; The control bridge encrypts / decrypts the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form.

2. The secure communication method applicable to confidential virtual machines and PCIe devices according to claim 1, characterized in that, The target data includes first data transmitted from the confidential virtual machine to the PCIe device and second data transmitted from the PCIe device to the confidential virtual machine. The control bridge encrypts / decrypts the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form specifically includes: When the target data is the first data transmitted from the confidential virtual machine to the PCIe device, the control bridge decrypts the first data so that the PCIe device can know the decrypted first data; When the target data is the second data transmitted from the PCIe device to the confidential virtual machine, the control bridge encrypts the second data and transmits the encrypted second data to the confidential virtual machine.

3. The secure communication method applicable to confidential virtual machines and PCIe devices according to claim 2, wherein The confidential virtual machine is used to encrypt the data to be transmitted to obtain the first data and decrypt the encrypted second data.

4. The secure communication method applicable to confidential virtual machines and PCIe devices according to claim 1, wherein The control bridge obtains the target data between the PCIe device and the confidential virtual machine specifically includes: The control bridge obtains the trigger reason for triggering the transmission of the target data; When the trigger reason is that the confidential virtual machine actively accesses the PCIe device, the control bridge obtains the first data formed by the confidential virtual machine through a write operation and / or the second data determined by the PCIe device based on the read operation of the confidential virtual machine to obtain the target data between the PCIe device and the confidential virtual machine; When the trigger reason is that the PCIe device actively performs DMA, the control bridge obtains the first data moved by the PCIe device from a preset shared memory and / or obtains the second data formed by the PCIe device based on the DMA write operation to obtain the target data between the PCIe device and the confidential virtual machine, where the first data is written into the preset shared memory by the confidential virtual machine based on the DMA read operation.

5. The secure communication method for a confidential virtual machine and a PCIe device according to claim 4, wherein When the target data is the second data formed by the PCIe device based on the DMA write operation, the control bridge encrypts / decrypts the target data so that the target data is transmitted between the PCIe device and the confidential virtual machine in ciphertext form is: The control bridge encrypts the second data and transmits the encrypted second data to the preset shared memory so that the confidential virtual machine moves the encrypted second data from the preset shared memory.

6. The secure communication method applicable to confidential virtual machines and PCIe devices according to claim 4 or 5, characterized in that, The preset shared memory is outside the TEE side so that both the confidential virtual machine and the PCIe device can move the memory data in the preset shared memory.

7. The secure communication method applicable to confidential virtual machines and PCIe devices according to claim 4, wherein The method further includes: When the trigger reason is a PCIe device interruption, the control bridge controls the interruption data of the PCIe device and transmits the interruption data in plain text.

8. The secure communication method applicable to confidential virtual machines and PCIe devices according to claim 1, characterized in that Before the control bridge obtains the target data between the PCIe device and the confidential virtual machine, the method further includes: The confidential virtual machine authenticates the identity of the control bridge; When the identity authentication is successful, the confidential virtual machine negotiates a communication key with the control bridge so that the confidential virtual machine and the control bridge encrypt / decrypt the target data using the communication key.

9. A computing device, characterized in that, The computing device includes a processor and a memory; the processor of the computing device is configured to execute instructions stored in the memory of the computing device so that the computing device executes the secure communication method applicable to the confidential virtual machine and the PCIe device according to any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that, It includes computer program instructions, when the computer program instructions are executed by a computing device, the computing device executes the secure communication method applicable to the confidential virtual machine and the PCIe device according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Cross-bus-domain equipment virtualization method and system, terminal and storage medium

    CN118445223A

  • Cross-bus-domain device-to-host space DMA (direct memory access) method and related device

    CN118445231A

  • Method and system for safely using cross-bus-domain virtual equipment, terminal and medium

    CN118673496A

  • Secured peripheral device communication via bridge device in virtualized computer system

    US20240072995A1

  • Secure virtual machine and peripheral device communication

    US20240095059A1

Cited By

  • TEE cluster implementation method and system, terminal and storage medium

    CN122268684A