Kernel parameter protection method and system during operation of operating system
By creating a hash table on the kernel side and combining the encryption identifier in the /proc/sys directory, the kernel parameters are protected, which solves the problem of direct reading by users, ensuring that the parameter tuning results are not leaked, and user modifications take effect directly.
Patent Information
- Application Number
- CN202510501212.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-18
AI Technical Summary
The prior art allows users to directly read operating system kernel parameters, resulting in insufficient confidentiality and leakage of commercial value.
Create a hash table on the kernel side and combine it with the encryption identifier in the /proc/sys directory to start the manufacturer's tuning mode, read the parameters before tuning in the user's operating mode, and write the parameters configured by the user.
Effectively protect the confidentiality of kernel parameters, users cannot perceive parameter tuning, and the modification operation takes effect directly, compatible with user modifications, and protects commercial value.
Smart Images

Figure CN120337295A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of operating systems, and particularly to a method and system for protecting kernel parameters during the operation of an operating system. Background Art
[0002] Linux can modify kernel parameters during system operation without rebooting the system. This function is implemented through the / proc virtual file system. Most kernel parameters are stored in the / proc / sys directory and are designed to be changeable while the system is running. The purpose of modifying kernel parameters can be achieved by changing the files corresponding to the kernel parameters in / proc / sys. Sysctl is a tool and interface for configuring Linux kernel parameters at runtime. It allows users to dynamically adjust the running parameters of the kernel without restarting the system to optimize system performance, adjust resource allocation, or modify kernel behavior. When the operating system runs specific applications (such as applications in professional fields like high-performance computing), a set of sysctl parameters need to be allocated to enable these applications to achieve the best performance on the operating system. In the prior art, operating system manufacturers usually optimize sysctl parameters using professional tools and expert experience. These parameters have high commercial value. However, the prior art allows users to directly read sysctl parameters through the cat / proc / sys or sysctl command, resulting in a lack of confidentiality for these key parameters, which may disclose the technical advantages of the manufacturers. Therefore, how to effectively protect the confidential sysctl parameters and be compatible with users' modification of sysctl parameters has become a key technical problem to be solved urgently. Summary of the Invention
[0003] The technical problem to be solved by the present invention: In view of the above problems of the prior art, a method and system for protecting kernel parameters during the operation of an operating system are provided. The present invention aims to effectively protect the confidential kernel parameters and be compatible with users' modification of kernel parameters, thereby effectively protecting the optimization results and commercial value of the operating system kernel parameters.
[0004] To solve the above technical problems, the technical solution adopted by the present invention is as follows: A method for protecting kernel parameters during the operation of an operating system, comprising the following steps: S101, configure and create a hash table on the kernel side and start the vendor tuning mode by combining the encryption identifier in the / proc / sys directory. In the vendor tuning mode, write the kernel parameters before tuning into the hash table and configure the tuned kernel parameters into the system kernel; S102, close the vendor tuning mode and enter the user operation mode; S103. In the user operation mode, if the user reads kernel parameters, the optimized kernel parameters before tuning are preferentially read from the hash table and returned to the user; if the user writes kernel parameters, the kernel parameters configured by the user are configured into the system kernel.
[0005] Optionally, in step S101, configuring and creating a hash table on the kernel side includes: declaring a global hash table in the kernel module, where the hash table includes two parameter items, procname and data. Procname is used to store the parameter names of kernel parameters, and data is used to store the original parameter values of kernel parameters.
[0006] Optionally, in step S101, starting the vendor tuning mode by combining the encryption identifier under the / proc / sys directory includes: creating an encryption identifier interface for the proc file system under the / proc / sys directory. The status of the encryption identifier interface is controlled by the proc_dointvec function in the kernel to distinguish the enabled status of the encryption identifier. The enabled status of the encryption identifier indicates the vendor tuning mode, and the disabled status of the encryption identifier indicates the user operation mode; enabling the encryption identifier to enter the vendor tuning mode.
[0007] Optionally, in step S101, when writing the kernel parameters before tuning into the hash table and configuring the tuned kernel parameters into the system kernel in the vendor tuning mode, the response processing for the write request of any kernel parameter includes: S201. Search for the kernel parameter in the hash table to determine whether the kernel parameter already exists in the hash table. If it already exists in the hash table, jump to step S202; otherwise, jump to step S203; S202. Directly write the actual protected parameter value of the kernel parameter into the system kernel, and end; S203. Read the current parameter value of the kernel parameter in the system kernel; S204. Write the read current parameter value as the original parameter value of the kernel parameter into the hash table; S205. Write the actual protected parameter value of the kernel parameter into the system kernel.
[0008] Optionally, in step S101 in the vendor tuning mode, it further includes the response processing for the read request of any kernel parameter: reading the current parameter value of the kernel parameter and returning it to the user, where the current parameter value is the original parameter value before kernel parameter tuning or the actual protected parameter value after tuning.
[0009] Optionally, configuring the kernel parameters configured by the user into the system kernel in step S103 includes: S301. Search for the kernel parameter that the user needs to write in the hash table. If the kernel parameter that the user needs to write is found, jump to step S302; otherwise, jump to step S303; S302. Delete the parameter entry corresponding to the kernel parameter that the user needs to write in the hash table, and jump to step S303; S303. Write the parameter user configuration value of this kernel parameter into the system kernel.
[0010] Optionally, the step of preferentially reading the kernel parameter before tuning from the hash table and returning it to the user in step S103 includes: S401. Search for the kernel parameter that the user needs to read in the hash table. If the kernel parameter that the user needs to read is found, jump to step S402; otherwise, jump to step S403; S402. Directly read the original parameter value of the kernel parameter that the user needs to read from the hash table and return it to the user, and exit; S403. Read the current parameter value of this kernel parameter in the system kernel and return it to the user.
[0011] In addition, the present invention also provides a kernel parameter protection system during the operation of an operating system, including a microprocessor and a memory connected to each other. The microprocessor is programmed or configured to execute the kernel parameter protection method during the operation of the operating system.
[0012] In addition, the present invention also provides a computer-readable storage medium, in which a computer program or instruction is stored. The computer program or instruction is programmed or configured to execute the kernel parameter protection method during the operation of the operating system through a processor.
[0013] In addition, the present invention also provides a computer program product, including a computer program or instruction. The computer program or instruction is programmed or configured to execute the kernel parameter protection method during the operation of the operating system through a processor.
[0014] Compared with the prior art, the present invention can mainly achieve the following beneficial effects: The present invention enables the kernel parameters allocated by the operating system during operation to not be directly readable by users, and when users modify the parameters, users are not aware that the parameters have been specially protected inside the system, so as to effectively protect the confidential kernel parameters and be compatible with users' modification of kernel parameters, thereby effectively protecting the optimization results and commercial value of the operating system kernel parameters. It has the following advantages: High protection efficiency: Use a hash table on the kernel side to store the original parameter values and combine with the encryption identifier under / proc / sys to achieve real-time protection of system optimization parameters. Good concealment: When users perform ordinary reading operations, the system returns the original value in the protected data, making users unable to perceive that parameter optimization has been carried out inside the system. Automatic cleaning: When users perform parameter writing operations, the system automatically deletes the corresponding hash table entries to ensure that the parameter values modified by users take effect directly. High flexibility: The method of the present invention has low invasiveness to the existing sysctl mechanism, can be seamlessly integrated during kernel optimization, and has little impact on the overall system performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 It is a schematic diagram of the basic process of the method in an embodiment of the present invention.
[0016] Figure 2 It is a schematic diagram of the encrypted writing process in the manufacturer optimization mode in an embodiment of the present invention.
[0017] Figure 3 It is a schematic diagram of the encrypted reading process in the manufacturer optimization mode in an embodiment of the present invention.
[0018] Figure 4 It is a schematic diagram of the ordinary writing process in the user operation mode in an embodiment of the present invention.
[0019] Figure 5 It is a schematic diagram of the ordinary reading process in the user operation mode in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] The main object of the present invention is to provide a method that enables the sysctl parameters allocated by the operating system during operation to not be directly readable by users, and when users modify the parameters, users are not aware that the parameters have been specially protected inside the system, so as to effectively protect the parameter optimization results and commercial value of the operating system. To enable those skilled in the art to better understand the technical solutions of the present invention, the technical solutions of the present invention will be further described in detail below with reference to the accompanying drawings in the embodiments of the present invention.
[0021] As Figure 1 shown, the method for protecting kernel parameters during the operation of the operating system in this embodiment includes the following steps: S101. Configure and create a hash table on the kernel side, and start the vendor tuning mode by combining the encryption identifier in the / proc / sys directory. In the vendor tuning mode, write the kernel parameters before tuning into the hash table, and configure the tuned kernel parameters (sysctl parameters) into the system kernel. S102. Turn off the vendor tuning mode and enter the user operation mode. S103. In the user operation mode, if the user reads the kernel parameters, then preferentially read the kernel parameters before tuning from the hash table and return them to the user; if the user writes the kernel parameters, then configure the kernel parameters configured by the user into the system kernel.
[0022] Create a hash table on the kernel side to store the specified sysctl parameters and their original values (i.e., the values of the parameters before being applied to the operating system). Among them, each entry in the hash table consists of a "key-value pair", where the key is the full path of the parameter under / proc / sys (for example, " / vm / nr_hugepages"), and the value is the corresponding original parameter value. In step S101 of this embodiment, configuring and creating a hash table on the kernel side includes: declaring a global hash table in the kernel module, and its command is: DECLARE_HASHTABLE(proc_sys_table, 5) Among them, DECLARE_HASHTABLE is the operation of declaring a global hash table, proc_sys_table is the name of the hash table, and 5 is the bit width of the hash table.
[0023] In this embodiment, the hash table includes two parameter items, procname and data. Among them, procname is used to store the parameter name of the kernel parameter, and data is used to store the original parameter value of the kernel parameter. Its data structure is: struct proc_sys_entry { char procname; char data; struct hlist_node node; }; Among them, procname is a pointer to the parameter name procname, data is a pointer to the original parameter value data, and struct hlist_node node is the node information of the linked list structure.
[0024] In step S101 of this embodiment, starting the manufacturer tuning mode by combining the encryption identifier in the / proc / sys directory includes: creating an encryption identifier interface for the proc file system in the / proc / sys directory, and the status of the encryption identifier interface is controlled by the proc_dointvec function in the kernel to distinguish the enabled status of the encryption identifier. The enabled status of the encryption identifier indicates the manufacturer tuning mode, and the disabled status of the encryption identifier indicates the user operation mode; enabling the encryption identifier to enter the manufacturer tuning mode. In this embodiment, creating an encryption identifier interface for the proc file system in the / proc / sys directory specifically is: { .procname = "param_encrypt", .data =¶m_encrypt, .maxlen = sizeof(int), .mode = 0644, .proc_handler = proc_dointvec }, Among them,.procname is the name of the encryption identifier,.data is the data of the encryption identifier,.maxlen is the maximum length of the encryption identifier,.mode is the operation permission of the encryption identifier, and.proc_handler is the definition of the processing function of the encryption identifier.
[0025] As Figure 2 shown, in the encryption write process (encryption identifier enabled), when the encryption identifier is enabled, if the parameter does not exist in the hash table, the current parameter value is first queried, the result is written into the hash table, and then written; if it already exists, it is directly written. Specifically, in step S101 of this embodiment, when writing the kernel parameters before tuning into the hash table and configuring the tuned kernel parameters into the system kernel in the manufacturer tuning mode (encryption identifier enabled), the response processing for the write request of any kernel parameter includes: S201, search for the kernel parameter in the hash table to determine whether the kernel parameter already exists in the hash table. If it already exists in the hash table, jump to step S202; otherwise, jump to step S203; S202, directly write the actual protected parameter value of the kernel parameter into the system kernel, and end; As Figure 2 shown, in this embodiment, it is specifically to directly call table->proc_handler() to write the actual protected parameter value in write mode; S203, read the current parameter value of the kernel parameter in the system kernel; As Figure 2As shown, in this embodiment, specifically call table->proc_handler() to query the current parameter value in read mode; S204. Write the read current parameter value into the hash table as the original parameter value of the kernel parameter. Specifically, the add_proc_sys_entry() interface can be called to store the key-value pair composed of the kernel parameter and its original parameter value into the hash table; S205. Write the actual protected parameter value of the kernel parameter into the system kernel. As Figure 2 shown, in this embodiment, specifically call table->proc_handler() to write the actual protected parameter value in write mode.
[0026] In this embodiment, when the encryption flag is enabled and a write operation is performed, the system determines whether the target sysctl parameter already exists in the hash table before writing: if the parameter does not exist in the hash table, first call the kernel-side proc_handler to read the current value of the parameter, and store it in the hash table in the format of "key=value\n"; after the write operation, continue to write the data into the actual sysctl parameter according to the normal process. The format of the kernel-side proc_handler function is: table->proc_handler(table, 0, read_buf,&count,&iocb->ki_pos); Among them, table->proc_handler represents the read and write operations on the hash table, table is the pointer to the hash table, 0 is the parameter to be written (the value for the read operation is different), read_buf is the read buffer, &count is the number of bytes read, and &iocb->ki_pos is the pointer to the offset, which is used to indicate the position of the read.
[0027] As Figure 3 shown, in the encrypted read mode, directly call proc_handler to read the actually effective parameter value in the system. In step S101 of this embodiment, in the manufacturer tuning mode, the response processing for the read request of any kernel parameter further includes: reading the current parameter value of the kernel parameter and returning it to the user. The current parameter value is the original parameter value before the kernel parameter tuning or the actually protected parameter value after the tuning. As Figure 3 shown, in this embodiment, specifically call table->proc_handler() to query the current parameter value in read mode. When the encryption flag is enabled and a read operation is performed, directly call proc_handler (read mode) to read the actually effective parameter value and return it to the user. At this time, the user obtains the actually used parameter value after the internal tuning of the system, and the protection mechanism does not intervene.
[0028] When the encryption flag is turned off and the user operation mode is entered: When the encryption flag is turned off (user operation mode), for write operations, if the parameter to be written exists in the hash table, the system first deletes the corresponding entry in the hash table and then executes the actual write process to ensure that the parameter manually modified by the user is the real value that finally takes effect. As Figure 4 shown, configuring the kernel parameters configured by the user into the system kernel in step S103 of this embodiment includes: S301, Search for the kernel parameter that the user needs to write in the hash table. If the kernel parameter that the user needs to write is found, jump to step S302; otherwise, jump to step S303; S302, Delete the parameter entry corresponding to the kernel parameter that the user needs to write in the hash table, and jump to step S303; S303, Write the parameter user configuration value of this kernel parameter into the system kernel. As Figure 4 shown, in this embodiment, it is specifically to directly call table->proc handler() to execute the write process in write mode.
[0029] When the encryption flag is turned off and the user operation mode is entered: When the encryption flag is turned off (user operation mode), for read operations, if the sysctl parameter read exists in the hash table, the original value stored in the hash table is returned instead of the parameter value that has actually been optimized by the system, so that the user cannot perceive the change of the system internal parameters; As Figure 5 shown, preferentially reading the kernel parameters before tuning from the hash table and returning them to the user in step S103 of this embodiment includes: S401, Search for the kernel parameter that the user needs to read in the hash table. If the kernel parameter that the user needs to read is found, jump to step S402; otherwise, jump to step S403; S402, Directly read the original parameter value of the kernel parameter that the user needs to read from the hash table and return it to the user, and exit; S403, Read the current parameter value of this kernel parameter in the system kernel and return it to the user. As Figure 5 shown, in this embodiment, it is specifically to call table->proc handler() to perform normal reading in read mode.
[0030] Through the above steps, the method of this embodiment realizes the protection of key sysctl parameters, so that the optimized parameters inside the system cannot be directly read by users. At the same time, when users modify the parameters, the protection records are automatically lifted, thereby achieving the purpose of protecting the results of the operating system parameter tuning. The key to the method of this embodiment lies in including: Kernel-side hash table protection mechanism: Using the kernel hash table to store the original values of key sysctl parameters in real time to achieve the protection of the parameter tuning results. This solution has not been publicly disclosed in the prior art. Encryption identifier control: By setting encryption identifiers under / proc / sys, the automatic switching between vendor tuning and user operation modes is realized, so that users cannot perceive the tuning operations of internal parameters, ensuring the confidentiality of the parameters. Automatic protection removal mechanism: When users perform parameter writing operations, the system automatically clears the corresponding protection records to ensure that the user's modification operations take effect directly. This design improves the flexibility and transparency of the system. The combination of the above mechanisms makes the method of this embodiment have the following technical effects and advantages: Efficient protection: Using the kernel-side hash table to store the original parameter values and combining the encryption identifiers under / proc / sys to achieve real-time protection of the system tuning parameters. Concealment: When users perform ordinary reading operations, the system returns the original values in the protected data, making users unable to perceive that parameter tuning has been performed inside the system. Automatic cleaning: When users perform parameter writing operations in this embodiment, the system automatically deletes the corresponding hash table entries to ensure that the parameter values modified by users take effect directly. Flexibility: The method of this embodiment has low invasiveness to the existing sysctl mechanism, can be seamlessly integrated during the kernel tuning process, and has little impact on the overall performance of the system.
[0031] In addition, this embodiment also provides a kernel parameter protection system during the operation of the operating system, including a microprocessor and a memory connected to each other, and the microprocessor is programmed or configured to execute the kernel parameter protection method during the operation of the operating system.
[0032] In addition, this embodiment also provides a computer-readable storage medium, in which a computer program or instruction is stored, and the computer program or instruction is programmed or configured to execute the kernel parameter protection method during the operation of the operating system through a processor.
[0033] In addition, this embodiment also provides a computer program product, including a computer program or instruction, and the computer program or instruction is programmed or configured to execute the kernel parameter protection method during the operation of the operating system through a processor.
[0034] Those skilled in the art should understand that the technical solution provided by the present invention can be in the form of a method, a system, or a computer program product. Therefore, the present invention can be implemented in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can be in the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code. The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in the process Figure 1 one process or multiple processes and / or blocks Figure 1 These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in the process Figure 1 one process or multiple processes and / or blocks Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0035] The above description is only the preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.
Claims
1. A method for protecting kernel parameters during the operation of an operating system, characterized in that It includes the following steps: S101, configure and create a hash table on the kernel side and start the vendor tuning mode by combining the encryption identifier in the / proc / sys directory. In the vendor tuning mode, write the kernel parameters before tuning into the hash table and configure the tuned kernel parameters into the system kernel; S102, turn off the vendor tuning mode and enter the user operation mode; S103, in the user operation mode, if the user reads the kernel parameters, then preferentially read the kernel parameters before tuning from the hash table and return them to the user; If the user writes the kernel parameters, then configure the kernel parameters configured by the user into the system kernel.
2. The method for protecting kernel parameters during the operation of an operating system according to claim 1, wherein In step S101, configuring and creating a hash table on the kernel side includes: declaring a global hash table in the kernel module. The hash table includes two parameter items, procname and data, where procname is used to store the parameter name of the kernel parameter, and data is used to store the original parameter value of the kernel parameter.
3. The method for protecting kernel parameters during the operation of an operating system according to claim 1, wherein In step S101, starting the vendor tuning mode by combining the encryption identifier in the / proc / sys directory includes: creating an encryption identifier interface for the proc file system in the / proc / sys directory. The status of the encryption identifier interface is controlled by the proc_dointvec function in the kernel to distinguish the on state of the encryption identifier. The on state of the encryption identifier indicates the vendor tuning mode, and the off state of the encryption identifier indicates the user operation mode; turn on the encryption identifier to enter the vendor tuning mode.
4. The method for protecting kernel parameters during the operation of an operating system according to claim 1, characterized in that, In step S101, when writing the kernel parameters before tuning into the hash table and configuring the tuned kernel parameters into the system kernel in the vendor tuning mode, the response processing for the write request of any kernel parameter includes: S201, search for the kernel parameter in the hash table to determine whether the kernel parameter already exists in the hash table. If it already exists in the hash table, then jump to step S202; otherwise, jump to step S203; S202, directly write the actual protected parameter value of the kernel parameter into the system kernel, and end; S203, read the current parameter value of the kernel parameter in the system kernel; S204, write the read current parameter value into the hash table as the original parameter value of the kernel parameter; S205, write the actual protected parameter value of the kernel parameter into the system kernel.
5. The method for protecting kernel parameters during the operation of an operating system according to claim 4, wherein In step S101, in the vendor tuning mode, it also includes the response processing for the read request of any kernel parameter: read the current parameter value of the kernel parameter and return it to the user. The current parameter value is the original parameter value before tuning of the kernel parameter or the actual protected parameter value after tuning.
6. The method for protecting kernel parameters during the operation of an operating system according to claim 4, wherein Configuring the kernel parameters configured by the user into the system kernel in step S103 includes: S301, search for the kernel parameter that the user needs to write in the hash table. If the kernel parameter that the user needs to write is found, then jump to step S302; otherwise, jump to step S303; S302, delete the parameter entry corresponding to the kernel parameter that the user needs to write in the hash table, and jump to step S303; S303, write the parameter user configuration value of the kernel parameter into the system kernel.
7. The method for protecting kernel parameters during the operation of an operating system according to claim 4, characterized in that, The step of preferentially reading the kernel parameters before tuning from the hash table and returning them to the user in step S103 includes: S401, Search for the kernel parameter that the user needs to read in the hash table. If the kernel parameter that the user needs to read is found, jump to step S402; otherwise, jump to step S403; S402, Directly read the original parameter value of the kernel parameter that the user needs to read from the hash table and return it to the user, and exit; S403, Read the current parameter value of this kernel parameter in the system kernel and return it to the user.
8. A kernel parameter protection system during the operation of an operating system, comprising a microprocessor and a memory connected to each other, characterized in that, The microprocessor is programmed or configured to execute the kernel parameter protection method during the operation of the operating system according to any one of claims 1 to 7.
9. A computer-readable storage medium storing a computer program or instructions, characterized in that, The computer program or instruction is programmed or configured to execute the kernel parameter protection method during the operation of the operating system according to any one of claims 1 to 7 through a processor.
10. A computer program product, comprising a computer program or instructions, characterized in that, The computer program or instruction is programmed or configured to execute the kernel parameter protection method during the operation of the operating system according to any one of claims 1 to 7 through a processor.