Kernel permission separation method and device, intelligent terminal and storage medium
By dividing the central processor core space into the memory management core and the traditional external core, setting gate code and address translation page tables is solved, and the problems of insufficient memory system isolation and cross-platform deployment are realized, and the kernel permission separation and secure application of cross-platform is achieved.
Patent Information
- Application Number
- CN202510455254.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, memory systems lack sufficient isolation mechanisms, kernel mechanisms cannot be flexibly deployed across platforms, and relying on hardware security features leads to limited security and deployment flexibility.
The kernel space of the central processor is divided into memory management cores and traditional external cores, and the gate code and address translation page table are set. The page table and context are switched through specific signals, and the kernel permissions are separated, providing flexible gate code interfaces and security applications without relying on hardware security features.
It effectively improves the security of the operating system kernel, protects confidential data from being leaked by malicious code, realizes cross-platform deployment, provides a low-privilege level secure application interface, and improves the security and flexibility of the system.
Smart Images

Figure CN120372648A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and particularly to a kernel privilege separation method, apparatus, intelligent terminal, and storage medium. Background Art
[0002] The privacy and integrity of confidential data are very crucial. However, the protection of confidential data by the traditional operating system kernel is very limited. First, when the entire operating system has a consistent privilege level in the kernel address space, the memory system lacks sufficient isolation mechanisms. Any exploited kernel vulnerability may cause malicious code to threaten all memory data without restriction. Second, traditional operating systems are usually written in C / C++. Although this language has high operating efficiency, the language itself lacks a memory security check module, which is prone to potential memory security vulnerabilities.
[0003] Existing solutions usually mark the memory pages where data is located as non-executable, or establish security mechanisms such as mandatory privilege access control. For example, solutions such as SKEE and Hi l ps utilize the TTBCR feature of ARM to divide the address space, while xMP and KDPM utilize the MPK feature of Intel to restrict page table reading and writing. By leveraging hardware features, they ultimately achieve privilege separation for the operating system. However, due to relying on hardware security features, it will be difficult to deploy on processors that do not support this feature. Nested Kerne l adds an additional layer of address translation in the kernel in a virtualization-like manner, isolating a section of memory for use by a "nested kernel" with a high privilege level. However, its security depends on static inspection of the kernel code, and its security can no longer be guaranteed. VMM isolates by software virtualizing multiple hardware systems. However, the performance overhead is large, and it can only be used in virtualization scenarios. In summary, these kernel mechanisms strengthen the security of the operating system kernel to a certain extent, but these kernel security mechanisms rely on the security of the key data of their own operating system kernel, and need to be bound to the kernel of the trusted execution environment, and cannot be flexibly deployed across platforms.
[0004] Therefore, the prior art still needs to be improved and developed. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a kernel privilege separation method, apparatus, intelligent terminal, and storage medium for the above-mentioned defects of the prior art, aiming to solve the problems of insufficient isolation mechanism in the memory system and inflexible cross-platform deployment of the kernel mechanism in the prior art.
[0006] The technical solution adopted by the present invention to solve the technical problem is as follows:
[0007] In a first aspect, the present invention provides a method for separating kernel permissions, wherein the method includes:
[0008] Partition the kernel space of the central processing unit to obtain a memory management core and a traditional external kernel;
[0009] Set a gate code between the memory management core and the traditional external kernel;
[0010] Set an address translation page table on the memory management core to obtain a memory management core page table and a traditional external kernel page table;
[0011] Trigger the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switch the page table according to the page table switching instruction, switch the central processing unit execution state context according to the context switching instruction, and transmit the specific signal.
[0012] In one implementation, the partitioning of the kernel space to obtain a memory management core and a traditional external kernel includes:
[0013] Obtain the kernel space of the central processing unit;
[0014] Partition a first physical address space on the kernel space to obtain the memory management core, where the memory management core is used to control interrupt processing, manage memory, and store confidential data;
[0015] Partition a second physical address space on the kernel space to obtain the traditional external kernel, and the memory management core is completely inaccessible to the traditional external kernel.
[0016] In one implementation, the setting of the gate code between the memory management core and the traditional external kernel includes:
[0017] Partition a third physical address space on the kernel space to obtain a gate code area;
[0018] Deploy a gate code in the gate code area, where the gate code is used to provide an interface for the traditional external kernel to transmit a memory management signal request to the memory management core.
[0019] In one implementation, the setting of the address translation page table on the memory management core to obtain a memory management core page table and a traditional external kernel page table includes:
[0020] Set the memory management core page table on the memory management core, where the memory management core page table contains page frames mapped to the entire physical address space, and the entire physical address space on the kernel space can be accessed through the memory management core page table;
[0021] Set the traditional external kernel page table on the memory management core, where the memory management core page table only contains page frames mapped to the second and third physical address spaces, and the page frames corresponding to the third physical address space are read-only. The first physical address space cannot be accessed through the traditional external kernel page table, and the third physical address space cannot be modified;
[0022] Allocate different memory allocators for the page frames of each physical space.
[0023] In one implementation, the gate code is triggered by a specific signal to issue a page table switching instruction and a context switching instruction. The page table is switched according to the page table switching instruction, and the execution state context of the central processing unit is switched according to the context switching instruction. Passing the specific signal includes:
[0024] Send a request memory management signal through the traditional external kernel and trigger the gate code;
[0025] Issue the page table switching instruction through the gate code to switch the memory management core page table;
[0026] Pass the request memory management signal to the memory management core through the gate code;
[0027] Issue a context switching instruction through the gate code to switch the execution state context of the central processing unit, and make the central processing unit start to execute the memory management core;
[0028] According to the request memory management signal, make corresponding changes to the traditional external kernel page table through the memory management core;
[0029] When the changes are completed, the memory management core issues a return signal, and triggers the gate code to issue a page table switching instruction, a context switching instruction and pass the return signal. The page table switching instruction is used to switch the traditional external kernel page table, the context switching instruction is used to make the central processing unit execute the traditional external kernel, and the return signal is used to notify the traditional external kernel of the change result.
[0030] In one implementation, the making corresponding changes to the traditional external kernel page table through the memory management core according to the request memory management signal includes:
[0031] Obtain the request memory management signal through the memory management core;
[0032] If the request memory management signal includes setting the execution permission of the physical page frame to executable, set the write permission of the physical page frame to non-writable;
[0033] If the requested memory management signal includes setting the execution permission of a physical page frame to executable and the physical page frame contains the page table switching instruction, then remove the page table switching instruction from the physical page frame.
[0034] In one implementation, the corresponding modification of the traditional external kernel page table by the memory management according to the requested memory management signal further includes:
[0035] If the content of the requested memory management signal includes modifying the traditional external kernel page table mapping, then determine whether the requested memory management signal meets the request conditions, where the request conditions are not accessing the first physical address space and not modifying the third physical address space;
[0036] If the request conditions are met, modify the traditional external kernel page table mapping according to the request signal;
[0037] If the request conditions are not met, reject the execution of the requested memory management signal and return an error prompt message.
[0038] In a second aspect, an embodiment of the present invention further provides a kernel privilege separation method device, where the device includes:
[0039] A kernel partitioning module, configured to partition the kernel space of a central processing unit to obtain a memory management core and a traditional external kernel;
[0040] A gate code module, configured to set gate codes between the memory management core and the traditional external kernel;
[0041] A page table module, configured to set an address translation page table on the memory management core to obtain a memory management core page table and a traditional external kernel page table;
[0042] A switching and modification module, configured to trigger the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switch the page table according to the page table switching instruction, switch the central processing unit execution state context according to the context switching instruction, and transmit the specific signal.
[0043] In a third aspect, an embodiment of the present invention further provides an intelligent terminal, where the intelligent terminal includes a memory, a processor, and a kernel privilege separation method program stored in the memory and executable on the processor. When the processor executes the kernel privilege separation method program, the steps of the kernel privilege separation method as described in any one of the above are implemented.
[0044] Fourthly, an embodiment of the present invention further provides a computer-readable storage medium, where a kernel privilege separation method program is stored on the computer-readable storage medium. When the kernel privilege separation method program is executed by a processor, the steps of the kernel privilege separation method as described in any one of the above are implemented.
[0045] Beneficial effects: Compared with the prior art, the present invention provides a kernel privilege separation method. First, the kernel space of the central processing unit is divided to obtain a memory management core and a traditional external kernel. By setting the privilege levels of the memory management core and the traditional external kernel, kernel privilege separation is achieved. Secondly, a gate code is set between the memory management core and the traditional external kernel. By operating the page table through the gate code, a flexible gate code interface and secure application are provided for low privilege levels without affecting the reading and writing of high privilege levels. Thirdly, an address translation page table is set on the memory management core to obtain a memory management core page table and a traditional external kernel page table, realizing the preservation of private data for high privilege levels without relying on hardware security features. Finally, according to the gate code, a switching modification instruction is obtained, and based on the switching modification instruction, the base addresses of the memory management core page table and the traditional external kernel page table are switched and the traditional external kernel page table is modified, so that the access privilege of confidential data is improved while the privilege of potential malicious kernel modules is restricted, effectively establishing a boundary between high-risk code and sensitive data in the operating system kernel. Description of the Drawings
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0047] Figure 1 It is a schematic flowchart of the kernel privilege separation method provided by an embodiment of the present invention.
[0048] Figure 2 It is a structural diagram of a virtual address space provided by an embodiment of the present invention.
[0049] Figure 3 It is a schematic diagram of privilege level switching provided by an embodiment of the present invention.
[0050] Figure 4 It is a summary diagram of memory management interfaces provided by an embodiment of the present invention.
[0051] Figure 5 It is an example diagram of the overall control flow provided by an embodiment of the present invention.
[0052] Figure 6It is a schematic diagram of the interrupt control code provided by an embodiment of the present invention.
[0053] Figure 7 It is a principle block diagram of the kernel privilege separation device provided by an embodiment of the present invention.
[0054] Figure 8 It is a principle block diagram of the internal structure of the intelligent terminal provided by an embodiment of the present invention. Detailed implementation manners
[0055] To make the objectives, technical solutions and effects of the present invention clearer and more definite, the present invention will be further described in detail below with reference to the accompanying drawings and by way of examples. It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0056] Those skilled in the art of the present technology can understand that unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present invention means the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups. It should be understood that when we say that an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more related listed items.
[0057] Those skilled in the art of the present technology can understand that unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the field to which the present invention belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted in an idealized or overly formal sense unless specifically defined as here.
[0058] Privilege separation is an important isolation mechanism designed to minimize the attack surface of confidential data, thereby protecting confidential data. It can separate the original operating system kernel into various parts and assign different privilege levels to different parts. Through privilege separation, the access rights of confidential data are elevated, while the privileges of potentially malicious kernel modules are restricted. This effectively establishes a boundary between high-risk code and sensitive data in the operating system kernel.
[0059] In a traditional kernel, it is necessary to place confidential data in a secure area that is isolated and has a small attack surface. Through isolation, even if conventional vulnerabilities can damage most of the operating system code, they cannot leak the confidential data in the isolated area. Compared with the dependence of traditional work on a high hardware privilege level at the bottom layer, this application proposes a cross-platform privilege separation architecture that does not rely on hardware security features and a high hardware privilege level. Through a low-coupling solution and a privilege separation architecture that can easily support various operating systems and user programs, after privilege separation is completed, an architecture that can truly and conveniently provide secure applications for low privilege levels can be realized.
[0060] Exemplary method
[0061] This embodiment provides a kernel privilege separation method, and this embodiment can be applied to memory management.
[0062] As Figure 1 shown, the method includes the following steps:
[0063] Step S100, divide the kernel space of the central processing unit to obtain a memory management core and a traditional external kernel.
[0064] Specifically, in order to achieve general kernel privilege separation and solve the problems of not relying on hardware security features and dynamic code loading, this embodiment provides a cross-platform kernel privilege separation solution for secure applications. As shown in the appendix Figure 2 shown, the kernel space is divided into two parts belonging to different privilege levels, namely the memory management core (abbreviated as MMK) and the traditional external kernel (abbreviated as OS in the following text). The privilege level is the state of the central processing unit (CPU) operation given by the external (such as hardware features, software mechanisms, virtualization, etc.). Programs running in a higher privilege level state can access more memory addresses, registers, etc. By dividing the kernel space, the memory management core that guarantees storage security is isolated.
[0065] In this embodiment, the Rust language with memory safety is used to implement privilege separation. Rust is a system programming language that focuses on security, especially concurrent security, and is a multi-paradigm language that supports programming paradigms such as functional, imperative, and generic. The Rust language enables designers to provide better memory security while ensuring performance, manages memory through the ownership system, and avoids memory leaks and data races. It has the feature of concurrent security, making the ownership system and type system more secure for concurrent programming.
[0066] In one implementation, step S100 in this embodiment includes the following steps:
[0067] Step S101: Obtain the kernel space of the central processing unit;
[0068] Step S102: Divide a first physical address space on the kernel space to obtain the memory management core, where the memory management core is used to control interrupt processing, manage memory, and store confidential data;
[0069] Interrupt processing means that when the CPU executes a current instruction, if a peripheral device sends an interrupt request to the CPU, then when the CPU meets the response condition, it will send an interrupt response signal, and at the same time, it will close the interrupt, indicating that the CPU is not accepting the interrupt of another device. At this time, the CPU will find out which device the interrupt request source is and save the content of its own program counter (PC). Then, it will transfer to the interrupt service program that processes the interrupt source. After the CPU saves the scene information and performs device services (such as exchanging data), it will restore the scene information. After these operations are completed, the interrupt is opened, and it returns to the next instruction of the original interrupted main program.
[0070] In this embodiment, interrupt processing is controlled by the memory management core. The interrupt processing function of the memory management core, such as Figure 6 As shown, when it realizes that an interrupt occurs during the execution of the door, it will handle this exception. Entering the door code execution midway instead of starting from the first line, since the code in the second line that "locks" the door is not executed, the door will throw an exception and handle the exception at line 8 in Figure 6 The interrupt processing function can detect the exception. Since when an interrupt occurs, the interrupt address will be saved in a specific register (such as the sepc register in riscv), the interrupt processing function will read this register and analyze whether its address is in the door code area to determine whether an interrupt has occurred in the door code. Since the memory management core controls the interrupt processing, the secure application provided by the memory management core for user processes can interact bypassing the operating system kernel.
[0071] Specifically, as Figure 2 shown, the virtual address space is divided into three regions as Figure 2 shown. It can be seen that an address space called the "MMK space" is isolated, that is, on the memory management core, and all physical page table page frames are in the MMK space.
[0072] Specifically, a better privilege level is given to the memory management core. The memory management core is only responsible for controlling interrupt processing and memory management, and stores confidential data, and its confidential data cannot be modified by the traditional external kernel, thus realizing the separation of permissions.
[0073] Step S103: Divide a second physical address space on the kernel space to obtain the traditional external kernel, where the memory management core is completely inaccessible to the traditional external kernel.
[0074] Specifically, assign a lower privilege level to the traditional external kernel, which has most of the contents that a traditional operating system should have, such as process scheduling, drivers, file systems, kernel modules, etc. Since the traditional external kernel contains dynamically loaded code, potential vulnerabilities and malicious code, by assigning it a lower privilege level, it can be ensured that the traditional external kernel can only access the traditional external kernel space and cannot access the memory management core space, thus effectively protecting the confidential data in the memory management core from being leaked and maliciously tampered with.
[0075] Step S200: Set up gate code between the memory management core and the traditional external kernel.
[0076] In one implementation, step S200 of this embodiment includes the following steps:
[0077] Step S201: Divide a third physical address space on the kernel space to obtain a gate code area;
[0078] Step S202: Deploy gate code in the gate code area, where the gate code is used to provide an interface for the traditional external kernel to transfer a request for memory management signals to the memory management core.
[0079] In this embodiment, a section of gate code and a series of interfaces are set between the memory management core and the traditional external kernel. The traditional external kernel can call the gate code interface to initiate requests to the memory management core, such as managing memory, using security applications, managing confidential data, etc. The gate code will review whether the requests of the traditional external kernel have the intention of malicious tampering. After passing the review, the gate code will send a modification instruction to the memory management core on behalf of the traditional external kernel.
[0080] Specifically, in this embodiment, by deploying the gate code, it does not rely on high-privilege-level code and only requires the hardware to have the support of a memory management unit (MMU). And the memory management unit, as a basic hardware module, is very popular in IoT devices and does not require additional costs during deployment. In addition, by deploying the architecture of the gate code to provide interfaces for modifying the page tables of the memory management core and the traditional external kernel, it provides flexible interfaces for low-privilege levels and can provide security applications for low-privilege levels.
[0081] Step S300: Set up address translation page tables on the memory management core to obtain a memory management core page table and a traditional external kernel page table;
[0082] Specifically, a page table is a special data structure placed in the page table area of the system space, storing the correspondence between logical pages and physical page frames; the page table serves to map logical addresses to physical addresses; the page table is used to map virtual pages to physical pages and store the protection bits of the pages, i.e., access permissions; physical memory itself is readable and writable, and the access permissions are controlled by the page table to improve the security of the system.
[0083] In this embodiment, in order to isolate a higher privilege level, the memory management core needs to use the address mapping mechanism to completely hide a section of physical address space and dynamically check the instructions of the lower privilege level to prevent the code that may break the privilege separation from being executed by the central processing unit. After isolating the address space, it is natural to establish a higher privilege level for this section of address space, that is, to make the traditional kernel unable to access this section of address space. For this purpose, as Figure 3 shown, we prepare two sets of address translations (page tables). One set is prepared for the memory management core and can access all physical address spaces; the other set is prepared for the traditional external kernel and cannot access the memory management core space and cannot write to the door code area. Then, a door code that is only executable and not writable is provided in the door code area, and there are instructions for switching the page table base address inside it, which are used to switch between these two sets of page tables, so as to achieve privilege elevation / downgrade.
[0084] In one implementation, step S300 of this embodiment includes the following steps:
[0085] Step S301: Set the memory management core page table on the memory management core, where the memory management core page table contains page frames mapped to all physical address spaces, and all physical address spaces on the kernel space can be accessed through the memory management core page table;
[0086] Step S302: Set the traditional external kernel page table on the memory management core, where the memory management core page table contains second page frames, and the first physical address space cannot be accessed through the traditional external kernel page table, and the third physical address space cannot be modified;
[0087] Step S303: Set the traditional external kernel page table on the memory management core, where the memory management core page table only contains page frames mapped to the second and third physical address spaces, and the page frame corresponding to the third physical address space is read-only, and the first physical address space cannot be accessed through the traditional external kernel page table, and the third physical address space cannot be modified
[0088] Specifically, although the traditional external kernel is placed at a lower privilege level and cannot access the memory management core space at a higher privilege level, a malicious OS will still attempt to break the privilege barrier by corrupting the address translation mechanism. Therefore, the memory management core needs to protect the address translation mechanism. In order to be able to perform memory segmentation without relying on a higher privilege level, in this embodiment, the address translation mechanism of the page table is borrowed, that is, during the life cycle of the traditional kernel, the address translation mechanism will always be kept on and controlled by the memory management core. And the memory management core page table can access all the physical address spaces on the kernel space.
[0089] In this embodiment, by placing all page table page frames in the memory management core space, the traditional external kernel page table cannot directly access the memory management core, that is, the first physical address space. At the same time, privilege control makes it impossible for the traditional external kernel to modify the gate code section, that is, the third physical address space. At the same time, the memory management core can access all physical address spaces.
[0090] Step S304: Allocate different memory allocators for the page frames of each physical space.
[0091] The double-free vulnerability exploits the mechanism defect of the page frame allocator, which can map the same physical page to two different virtual pages at the same time. At this time, operating one virtual page can directly affect the other virtual page, resulting in a security vulnerability.
[0092] In this embodiment, in order to avoid any potential harm caused by the double-free vulnerability, resulting in the overlap of the virtual pages of the memory management core and the virtual pages of the traditional external kernel, the page frame allocation of the memory management core page table and the traditional external kernel page table uses completely different allocators (memory allocators).
[0093] Step S400: Trigger the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switch the page table according to the page table switching instruction, switch the central processor execution state context according to the context switching instruction, and transmit the specific signal.
[0094] Specifically, under the protection of the address translation mechanism, the traditional external kernel is placed at a lower privilege level and cannot access the memory management core space at a higher privilege level. However, a malicious traditional external kernel will attempt to break the privilege barrier by corrupting the address translation mechanism, which requires the traditional external kernel to protect the address translation mechanism. In this embodiment, the traditional external kernel should generate a request signal and trigger the gate code to request the memory management core to perform corresponding operations according to the signal. After checking the legality of the request signal, the gate code performs corresponding operations on behalf of the traditional external kernel. Generally speaking, it is to perform the operation of modifying the traditional external kernel page table.
[0095] In one implementation, step S400 of this embodiment includes the following steps:
[0096] Step S401: Send a request for memory management signal through the traditional external kernel and trigger the gate code;
[0097] Step S402: Send the page table switching instruction through the gate code to switch the memory management core page table;
[0098] Step S403: Pass the request for memory management signal to the memory management core through the gate code;
[0099] Step S404: Send a context switching instruction through the gate code to switch the execution state context of the central processing unit, causing the central processing unit to start executing the memory management core.
[0100] Step S405: Make corresponding changes to the traditional external kernel page table through the memory management core according to the request for memory management signal;
[0101] Step S406: When the changes are completed, the memory management core sends a return signal, and through triggering the gate code, sends a page table switching instruction, a context switching instruction, and passes the return signal. The page table switching instruction is used to switch the traditional external kernel page table, the context switching instruction is used to cause the central processing unit to execute the traditional external kernel, and the return signal is used to notify the traditional external kernel of the change result.
[0102] Specifically, the memory management core needs to protect the address translation mechanism and protect the memory management core page table and the traditional external kernel page table from being directly read and written by the traditional external kernel. In this embodiment, if the traditional external kernel page table needs to modify the page table, it should call the interface of the memory management core to send a page table modification signal. After checking the legality of the page table modification signal, the memory management core issues a modification instruction through the gate code and executes the corresponding operation on behalf of the traditional external kernel page table.
[0103] In one implementation, step S405 in this embodiment includes the following steps:
[0104] Step S4051: Obtain the request for memory management signal through the memory management core;
[0105] Step S4052: If the request for memory management signal includes setting the execution permission of the physical page frame to executable, then set the write permission of the physical page frame to non-writable;
[0106] Step S4053: If the request for memory management signal includes setting the execution permission of the physical page frame to executable and the physical page frame contains the page table switching instruction, then remove the page table switching instruction from the physical page frame.
[0107] Specifically, the memory management core needs to protect the page table base address from being tampered with. Regardless of the hardware instruction set architecture, the page table base address is usually stored in a fixed control and status register and configured through specific hardware instructions. For example, in RISC-V, it can be modified using the "csrw satp, x" assembly instruction. In this embodiment, the memory management is responsible for the memory management core, and the traditional external kernel has no need to modify the page table base address instruction. Therefore, any first instruction of the physical page frame that the traditional external kernel attempts to apply to be set as executable will be scanned once by the memory management core, all relevant first instructions will be removed, and then the physical page frame of the first instruction will be set to read-only. This can ensure that there are no instructions in the executable pages inside the traditional external kernel that can modify the page table base address. Based on the basic requirements of the traditional external kernel for memory management, a set of basic interfaces is designed in this embodiment, such as Figure 4 as shown. Through the basic interface, simple security applications can be deployed at a high privilege level and used by programs at a low privilege level; programs at a low privilege level can choose to hand over their confidential data to a high privilege level for storage and processing.
[0108] In one implementation manner, step S405 described in this embodiment further includes the following steps:
[0109] Step S4054: If the content of the requested memory management signal includes modifying the page table mapping of the traditional external kernel, determine whether the requested memory management signal meets the request conditions, where the request conditions are not accessing the first physical address space and not modifying the third physical address space;
[0110] Step S4055: If the request conditions are met, modify the page table mapping of the traditional external kernel according to the request signal;
[0111] Step S4056: If the request conditions are not met, reject the execution of the requested memory management signal and return an error prompt message
[0112] Specifically, during the life cycle of the traditional kernel, the address translation mechanism will always remain enabled and be controlled by the MMK. As Figure 3 shown, when the memory management core issues a page table switching signal to switch the page table base address, a gate code that is only executable (not writable) is provided in the gate code area, and there are switching instructions inside it for switching the page tables of the memory management core and the traditional external kernel, so as to achieve privilege elevation or downgrading.
[0113] In summary, as Figure 5As shown in the figure, there are complete control flow closed loops between the MMK part (i.e., the memory management core), the OS part (i.e., the traditional external kernel), and the user processes. An interrupt generated by the user reaches the memory management core, an interrupt generated by the user is proxied by the traditional external kernel, and the traditional external kernel calls the API to the memory management core. Moreover, each control flow has a privilege elevation / demotion gate to protect the privilege boundary. Among them, the privileges and privilege gates of the MMK are only implemented by using the mechanism of virtual / physical address translation. Therefore, it does not rely on additional hardware security features and only requires an MMU. In addition, whether it is a user process or the traditional external kernel, there is a control flow channel to directly interact with the memory management core. Therefore, security applications can be well designed for them to provide security services.
[0114] Specifically, compared with the dependence on the underlying hardware (high hardware privilege level) in related work, the RPOS work does not rely on any hardware security features and high-privilege-level programs. It only requires the hardware to have an MMU, and the RPOS starts prior to the low-privilege-level part. Therefore, its deployability is very wide. During the experiment, we have conducted deployment tests on the Cortex-a72 cpu (arm64 ISA) and riscv64 cpu natively simulated by Qemu, and also conducted deployment experiments on development boards such as K210 and Nezha-D1. The RPOS can run well on these platforms.
[0115] In this practical example, considering the application of privilege separation to actual requirements, a series of standard interfaces (MMK API and Extended Syscall) are provided for both the kernel and user-mode programs. Through these interfaces, some simple security applications can be deployed at a high privilege level and used by programs at a low privilege level; through these interfaces, programs at a low privilege level can choose to hand over their confidential data to a high privilege level for storage and processing. Compared with other work that can only be applied to a limited number of operating systems after completing privilege segmentation, the RPOS supports multiple external systems and user programs across platforms and languages in a highly loosely coupled manner. In the experiment, we selected several representative projects and applied the RPOS to them:
[0116] (1) rCore: An experimental Unix-like operating system under the risc-v instruction set mainly written in the Rust language.
[0117] (2) rCore in C: An experimental Unix-like operating system under the risc-v instruction set mainly written in the C language.
[0118] (3) FreeRTOS: A cross-platform real-time operating system mainly written in the C language. We ported its Aarch64 port.
[0119] As can be seen from the above embodiments, RPOS can support various operating systems written in different languages and running on different platforms. By effectively separating kernel permissions, the present invention improves the security of the operating system kernel. It does not rely on hardware security features to save private data for high privilege levels, and provides a flexible gate code interface and secure applications for low privilege levels. It is a secure and efficient kernel permission separation solution that can cross platforms.
[0120] Exemplary Device
[0121] As Figure 7 shown in [reference], this embodiment also provides a kernel permission separation device, which includes:
[0122] A kernel partitioning module 10, configured to partition the kernel space of the central processing unit to obtain a memory management core and a traditional external kernel;
[0123] A gate code module 20, configured to set a gate code between the memory management core and the traditional external kernel;
[0124] A page table module 30, configured to set an address translation page table on the memory management core to obtain a memory management core page table and a traditional external kernel page table;
[0125] A switching and modification module 40, configured to trigger the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switch the page table according to the page table switching instruction, switch the central processing unit execution state context according to the context switching instruction, and transmit the specific signal.
[0126] In one implementation, the kernel partitioning module 10 includes:
[0127] A kernel space acquisition unit, configured to acquire the kernel space of the central processing unit;
[0128] A first partitioning unit, configured to partition a first physical address space on the kernel space to obtain the memory management core, where the memory management core is used to control interrupt processing, manage memory, and save confidential data;
[0129] A second partitioning unit, configured to partition a second physical address space on the kernel space to obtain the traditional external kernel, where the memory management core is completely inaccessible to the traditional external kernel.
[0130] In one implementation, the gate code module 20 includes:
[0131] A third partitioning unit, configured to partition a third physical address space on the kernel space to obtain a gate code area;
[0132] A gate code unit for deploying a gate code in the gate code area, where the gate code is used to provide an interface for the traditional external kernel to transfer a request memory management signal to the memory management core.
[0133] In one implementation, the page table module 30 includes:
[0134] A memory management core page table setting unit for setting the memory management core page table on the memory management core, where the memory management core page table contains page frames mapped to the entire physical address space, and the entire physical address space on the kernel space can be accessed through the memory management core page table;
[0135] A traditional external kernel page table setting unit for setting the traditional external kernel page table on the memory management core, where the memory management core page table only contains page frames mapped to the second and third physical address spaces, and the page frames corresponding to the third physical address space are read-only. The first physical address space cannot be accessed through the traditional external kernel page table, and the third physical address space cannot be modified;
[0136] A memory allocator setting unit for allocating different memory allocators for the page frames of each physical space.
[0137] In one implementation, the switching and modification module 40 includes:
[0138] A signal acquisition unit for triggering the gate code to acquire a page table modification signal sent by the traditional external kernel or a page table switching signal sent by the memory management core;
[0139] A gate code trigger unit for sending a request memory management signal through the traditional external kernel and triggering the gate code;
[0140] A page table switching unit for sending the page table switching instruction through the gate code to switch the memory management core page table;
[0141] A memory management signal transmission unit for transmitting the request memory management signal to the memory management core through the gate code;
[0142] A context switching unit for sending a context switching instruction through the gate code to switch the execution state context of the central processing unit, and making the central processing unit start to execute the memory management core;
[0143] A modification unit for making corresponding changes to the traditional external kernel page table through the memory management core according to the request memory management signal;
[0144] A notification unit, which is used to, after the changes are completed, send a return signal by the memory management core, and issue a page table switching instruction, a context switching instruction, and a passing return signal by triggering the gate code, where the page table switching instruction is used to switch the traditional external kernel page table, the context switching instruction is used to make the central processing unit execute the traditional external kernel, and the return signal is used to notify the traditional external kernel of the change result.
[0145] In one implementation, the gate code modification unit includes:
[0146] A memory management signal request subunit, which is used to obtain the requested memory management signal through the memory management core;
[0147] A permission request subunit, which is used to, if the requested memory management signal includes setting the execution permission of the physical page frame to executable, set the write permission of the physical page frame to non-writable;
[0148] An instruction removal subunit, which is used to, if the requested memory management signal includes setting the execution permission of the physical page frame to executable and the physical page frame contains the page table switching instruction, remove the page table switching instruction in the physical page frame.
[0149] In one implementation, the gate code modification unit includes:
[0150] A request judgment subunit, which is used to, if the content of the requested memory management signal includes modifying the traditional external kernel page table mapping, judge whether the requested memory management signal meets the request conditions, where the request conditions are not accessing the first physical address space and not modifying the third physical address space;
[0151] A page table mapping modification subunit, which is used to, if the request conditions are met, modify the traditional external kernel page table mapping according to the request signal;
[0152] A message notification subunit, which is used to, if the request conditions are not met, reject the execution of the requested memory management signal and return an error prompt message.
[0153] Based on the above embodiments, the present invention also provides an intelligent terminal, and its principle block diagram can be as Figure 8As shown in the figure. The intelligent terminal includes a processor, a memory, a network interface, a display screen, and a temperature sensor connected via a system bus. Among them, the processor of the intelligent terminal is used to provide computing and control capabilities. The memory of the intelligent terminal includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the intelligent terminal is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements a method for separating kernel permissions. The display screen of the intelligent terminal can be a liquid crystal display screen or an electronic ink display screen. The temperature sensor of the intelligent terminal is pre-set inside the intelligent terminal and is used to detect the operating temperature of internal devices.
[0154] Those skilled in the art can understand that Figure 8 the block diagram of the principle shown in the figure is only the block diagram of some structures related to the solution of the present invention, and does not constitute a limitation on the intelligent terminal to which the solution of the present invention is applied. The specific intelligent terminal may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0155] In one embodiment, an intelligent terminal is provided. The intelligent terminal includes a memory, a processor, and a kernel permission separation method program stored in the memory and executable on the processor. When the processor executes the kernel permission separation method program, the following operation instructions are implemented:
[0156] Divide the kernel space of the central processing unit to obtain a memory management core and a traditional external kernel;
[0157] Set a gate code between the memory management core and the traditional external kernel;
[0158] Set an address translation page table on the memory management core to obtain a memory management core page table and a traditional external kernel page table;
[0159] Trigger the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switch the page table according to the page table switching instruction, switch the execution state context of the central processing unit according to the context switching instruction, and transmit the specific signal.
[0160] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, operational database, or other medium used in the various embodiments provided by the present invention can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0161] In summary, the present invention discloses a kernel privilege separation method, including: dividing the kernel space of the central processing unit to obtain a memory management core and a traditional external kernel; setting a gate code between the memory management core and the traditional external kernel; setting an address translation page table on the memory management core to obtain a memory management core page table and a traditional external kernel page table; obtaining a switching modification instruction according to the gate code, and switching the base addresses of the memory management core page table and the traditional external kernel page table and modifying the traditional external kernel page table according to the switching modification instruction. The present invention effectively improves the security of the operating system kernel by separating kernel privileges, does not rely on hardware security features to save private data for high privilege levels, and provides a flexible gate code interface and secure applications for low privilege levels. It is a secure, efficient, and cross-platform kernel privilege separation solution.
[0162] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A kernel privilege separation method, characterized in that The method includes: Dividing the kernel space of the central processing unit to obtain a memory management core and a traditional external core; Setting up a gate code between the memory management core and the traditional external core; Setting up an address translation page table on the memory management core to obtain a memory management core page table and a traditional external core page table; Triggering the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switching the page table according to the page table switching instruction, switching the execution state context of the central processing unit according to the context switching instruction, and transmitting the specific signal.
2. The kernel privilege separation method according to claim 1, wherein The dividing the kernel space of the central processing unit to obtain a memory management core and a traditional external core includes: Obtaining the kernel space of the central processing unit; Dividing a first physical address space on the kernel space to obtain the memory management core, where the memory management core is used to control interrupt processing, manage memory, and save confidential data; Dividing a second physical address space on the kernel space to obtain the traditional external core, where the memory management core is completely inaccessible to the traditional external core.
3. The kernel privilege separation method according to claim 2, wherein The setting up a gate code between the memory management core and the traditional external core includes: Dividing a third physical address space on the kernel space to obtain a gate code area; Deploying a gate code in the gate code area, where the gate code is used to provide an interface for the traditional external core to transmit a request memory management signal to the memory management core.
4. The kernel privilege separation method according to claim 3, characterized in that, The setting up an address translation page table on the memory management core to obtain a memory management core page table and a traditional external core page table includes: Setting up the memory management core page table on the memory management core, where the memory management core page table contains page frames mapped to the entire physical address space, and the entire physical address space on the kernel space can be accessed through the memory management core page table; Setting up the traditional external core page table on the memory management core, where the memory management core page table only contains page frames mapped to the second and third physical address spaces, and the page frames corresponding to the third physical address space are read-only. The first physical address space cannot be accessed through the traditional external core page table, and the third physical address space cannot be modified; Allocating different memory allocators for the page frames of each physical space.
5. The kernel privilege separation method according to claim 1, wherein The triggering the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switching the page table according to the page table switching instruction, switching the execution state context of the central processing unit according to the context switching instruction, and transmitting the specific signal includes: The traditional external core issues a request memory management signal and triggers the gate code; Issuing the page table switching instruction through the gate code to switch the memory management core page table; Transmitting the request memory management signal to the memory management core through the gate code; Issuing a context switching instruction through the gate code to switch the execution state context of the central processing unit, and causing the central processing unit to start executing the memory management core; Making corresponding changes to the traditional external core page table through the memory management core according to the request memory management signal; After the changes are completed, the memory management core sends a return signal, and issues a page table switching instruction, a context switching instruction, and transmits the return signal by triggering the gate code, where the page table switching instruction is used to switch the traditional external kernel page table, the context switching instruction is used to cause the central processing unit to execute the traditional external kernel, and the return signal is used to notify the traditional external kernel of the change result.
6. The kernel privilege separation method according to claim 5, wherein According to the requested memory management signal, making corresponding changes to the traditional external kernel page table through the memory management core includes: Obtaining the requested memory management signal through the memory management core; If the requested memory management signal includes setting the execution permission of a physical page frame to executable, then setting the write permission of the physical page frame to non-writable; If the requested memory management signal includes setting the execution permission of a physical page frame to executable and the physical page frame contains the page table switching instruction, then removing the page table switching instruction from the physical page frame.
7. The kernel privilege separation method according to claim 6, wherein According to the requested memory management signal, making corresponding changes to the traditional external kernel page table through the memory management core further includes: If the content of the requested memory management signal includes modifying the traditional external kernel page table mapping, then determining whether the requested memory management signal meets the request conditions, where the request conditions are not accessing the first physical address space and not modifying the third physical address space; If the request conditions are met, modifying the traditional external kernel page table mapping according to the request signal; If the request conditions are not met, rejecting the execution of the requested memory management signal and returning an error prompt message.
8. A kernel privilege separation device, characterized in that, The device includes: A kernel division module for dividing the kernel space of the central processing unit to obtain a memory management core and a traditional external kernel; A gate code module for setting a gate code between the memory management core and the traditional external kernel; A page table module for setting an address translation page table on the memory management core to obtain a memory management core page table and a traditional external kernel page table; A switching and modification module for triggering the gate code to issue a page table switching instruction and a context switching instruction through a specific signal, switching the page table according to the page table switching instruction, switching the central processing unit execution state context according to the context switching instruction, and transmitting the specific signal.
9. An intelligent terminal, characterized in that, The intelligent terminal includes a memory, a processor, and a kernel privilege separation method program stored in the memory and executable on the processor. When the processor executes the kernel privilege separation method program, the steps of the kernel privilege separation method according to any one of claims 1-7 are implemented.
10. A computer-readable storage medium, characterized in that, A kernel privilege separation method program is stored on the computer-readable storage medium. When the kernel privilege separation method program is executed by the processor, the steps of the kernel privilege separation method according to any one of claims 1-7 are implemented.