Method for executing operation on input / output equipment by confidential virtual machine and computing equipment
By synchronizing the I/O device status information of REE and TEE in the computing device, the conflict problem caused by CVM's inability to directly access the I/O device is solved, and stable sharing and security between REE and TEE are achieved.
Patent Information
- Application Number
- CN202410117681.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-26
- Publication Date
- 2025-07-29
AI Technical Summary
In computing devices, confidential virtual machines (CVMs) cannot directly access input/output devices, resulting in conflicts in the use of I/O devices in REE and TEE, limiting the migration of big data and AI applications to TEE.
By synchronizing the I/O device status information of REE and TEE in the communication interface in TEE, ensure that the status information in REE and TEE is consistent and avoiding conflicts.
The synchronization of I/O device status information between REE and TEE is achieved, avoiding usage conflicts, and improving the sharing stability and security between REE and TEE.
Smart Images

Figure CN120389999A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a method for a confidential virtual machine to operate on an input / output device and a computing device. Background Art
[0002] To protect data in use, computing devices usually adopt a confidential computing architecture, that is, the computing resources on the computing device are divided into a rich execution environment (REE) and a trusted execution environment (TEE).
[0003] REE provides a general operating system and application environment, allowing users to freely install and run various applications. Moreover, the data in REE can not only be used within REE, but also be transmitted and shared through the external interface of the computing device. Therefore, the data calculated in REE may be threatened by malware, network attacks, data leakage, etc.
[0004] TEE provides a hardware-level secure isolation environment, and does not allow users to freely install and run various applications. Only applications that have been verified and authorized can be installed and run in TEE. Moreover, the data in TEE can only be used within TEE. Therefore, the data calculated in TEE will not be exposed to REE and will not be obtained by malware or attackers.
[0005] To ensure the high security of TEE, it is not allowed for the confidential virtual machine (CVM) running in TEE to directly access I / O devices. This makes it impossible for all applications in CVM that need to access I / O devices (such as big data applications, AI applications) to directly run in TEE, which has caused a huge ecological limitation to the development of TEE and is one of the core pain points for the migration of applications such as big data applications and AI applications into TEE.
[0006] Moreover, to ensure the high security of TEE, it is also not allowed for CVM to directly access the shared buffer in REE. This shared buffer is used to store the usage of I / O devices by the virtual machine (VM) in REE. Therefore, CVM cannot know the usage of I / O devices by the VM in REE.
[0007] If CVM is allowed to directly access I / O devices, it will cause the VM and CVM to communicate with the I / O device independently, resulting in a conflict in the use of the I / O device. Summary of the Invention
[0008] To solve the above technical problems, the present application provides a method for a confidential virtual machine to operate on an input / output device and a computing device, which can make the status information of the I / O device consistent in the REE and TEE and avoid the use conflict of the I / O device.
[0009] In a first aspect, a method for a confidential virtual machine to operate on an input / output device is provided, which is applied to a computing device. The computing device includes a regular open environment (REE) and a trusted execution environment (TEE). Among them, the hardware occupied by the computing resources of the REE is isolated from the hardware occupied by the computing resources of the TEE. The REE includes a first REE buffer. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM runs based on the computing resources of the TEE. The method includes:
[0010] The above communication interface receives a first I / O request and synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer. Among them, the first I / O request is used to instruct the first CVM to perform a first I / O operation on the first I / O device. The status information of the first I / O device is used to indicate that the status of the first I / O device is an idle state or an occupied state.
[0011] The above first CVM operates on the first I / O device according to the status information of the first I / O device in the synchronized first TEE buffer. Among them, the status information of the first I / O device in the synchronized first TEE buffer is used to indicate the current status of the first I / O device.
[0012] In the above solution, when the first CVM in the TEE needs to establish a communication connection with the first I / O device to complete the first I / O request, the communication interface in the TEE is used to synchronize the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first REE buffer and the first TEE is the same, achieving the effect that the status information of the first I / O device is consistent in the REE and TEE. Therefore, the first CVM operates on the first I / O device according to the current status of the first I / O device. For example, when the current status of the first I / O device is an idle state, the first CVM immediately uses the first I / O device; when the current status of the first I / O device is an occupied state, the first CVM waits for the first I / O device. This can avoid conflicts with the use of the first I / O device by the VM in the REE.
[0013] In some possible implementations, the above REE further includes a shadow buffer, which is used to store the status information of the first I / O device, and the status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device. The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, including: the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0014] In the above solution, since the status information of the first I / O device stored in the shadow buffer is used to indicate the current status of the first I / O device, therefore, the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, which can make the status information of the first I / O device in the synchronized first TEE buffer also used to indicate the current status of the first I / O device, and make the status information of the first I / O device in the synchronized first REE buffer also used to indicate the current status of the first I / O device.
[0015] In some possible implementations, the above REE further includes a first VM, which runs based on the computing resources of the REE.
[0016] Before the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, the above method further includes: when the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer, so that the shadow buffer stores the status information of the first I / O device.
[0017] The communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, including: the communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer to obtain the status information of the first I / O device in the synchronized first TEE buffer. Among them, the operation permission of the communication interface for the shadow buffer is higher than the operation permission of the first VM for the shadow buffer.
[0018] In some possible implementations, the above REE further includes a control module.
[0019] The above communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, including: when the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, the communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer.
[0020] The above method further includes: the control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer to obtain the status information of the first I / O device in the synchronized first REE buffer. Among them, the status information of the first I / O device in the synchronized first REE buffer is used to indicate the current status of the first I / O device.
[0021] In the above solution, in the process of sharing the usage of the first I / O device by the first CVM in the TEE (that is, the status information of the first I / O device) with the first VM in the REE, first, the communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer in the REE. When the first REE buffer is not operated, the control module then writes the status information of the first I / O device in the shadow buffer into the first REE buffer. This can avoid operation conflicts on the first REE buffer due to the operation permission of the communication interface in the TEE being higher than the operation permission of the first VM in the REE, and further prevent the occurrence of data chaos problems in the first REE buffer, which is beneficial to improving the stability of sharing the status information of the first I / O device between the REE and the TEE.
[0022] In addition, the communication interface only needs to write the status information of the I / O device from the TEE into the shadow buffer in the REE all the time, or the communication interface only needs to read the status information of the I / O device from the REE from the shadow buffer in the REE all the time, without dynamically adjusting the operation object according to the access relationship of the VM in the REE to the I / O device. This operation is simple and reliable, and also reduces the risk of inconsistent or lost status information of the I / O device.
[0023] In some possible implementation manners, the operation permission of the above communication interface for the shadow buffer is higher than that of the first VM for the shadow buffer, including at least the following two implementation manners: In the first implementation manner, when the communication interface operates on the shadow buffer, the access of the first VM is refused. In the second implementation manner, when the first VM operates on the shadow buffer, the access of the communication interface is allowed.
[0024] In some possible implementation manners, the above TEE further includes a second CVM and a second TEE buffer, and the above REE further includes a second REE buffer, and the second CVM runs based on the computing resources of the TEE. The above method further includes:
[0025] The above communication interface receives a second I / O request, and synchronizes the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer. Among them, the second I / O request is used to instruct the second CVM to perform a second I / O operation on the second I / O device. The status information of the second I / O device is used to indicate that the status of the second I / O device is an idle state or an occupied state.
[0026] The above second CVM performs an operation on the second I / O device according to the status information of the second I / O device in the synchronized second TEE buffer. Among them, the status information of the second I / O device in the synchronized second TEE buffer is used to indicate the current status of the second I / O device.
[0027] In the above solution, during the process of sharing the status information of the I / O device between the CVM in the TEE and the VM in the REE, the status information of the I / O device from the TEE is always transmitted to the REE through the same communication interface, or the status information of the I / O device from the REE is always transmitted to the TEE through the same communication interface. Only using one communication interface in the TEE to transmit the status information of the I / O device can reduce the complexity of the technical solution of the present invention, simplify the development process, and can also save the computing resources and hardware of the TEE. More importantly, compared with using multiple communication interfaces, each communication interface may become the attack target of an insecure device. The technical solution of the present invention only uses one communication interface, which can reduce the attack surface and potential security vulnerabilities, and reduce the threat to the TEE. In addition, since the communication interface transmits the status information of the I / O device, the security and privacy of data calculation in the TEE can still be guaranteed.
[0028] In a second aspect, a computing device is provided, including a regular open environment REE and a trusted execution environment TEE. Among them, the hardware occupied by the computing resources of the REE is isolated from the hardware occupied by the computing resources of the TEE. The REE includes a first REE buffer. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM runs based on the computing resources of the TEE.
[0029] The above-mentioned communication interface is used to receive a first I / O request. Among them, the first I / O request is used to instruct the first CVM to perform a first I / O operation on a first I / O device.
[0030] The above-mentioned communication interface is further used to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer. Among them, the status information of the first I / O device is used to indicate that the status of the first I / O device is an idle state or an occupied state.
[0031] The above-mentioned first CVM is used to perform an operation on the first I / O device according to the synchronized status information of the first I / O device in the first TEE buffer. Among them, the synchronized status information of the first I / O device in the first TEE buffer is used to indicate the current status of the first I / O device.
[0032] In some possible implementation manners, the above-mentioned REE further includes a shadow buffer. The shadow buffer is used to store the status information of the first I / O device. The status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device.
[0033] The above-mentioned communication interface is specifically used to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer by using the status information of the first I / O device in the shadow buffer.
[0034] In some possible implementation manners, the above-mentioned REE further includes a first VM. The first VM runs based on the computing resources of the REE.
[0035] The above-mentioned first VM is used to write the status information of the first I / O device in the first REE buffer into the shadow buffer when the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer before the communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer by using the status information of the first I / O device in the shadow buffer, so that the shadow buffer stores the status information of the first I / O device.
[0036] The above communication interface is specifically used to write the status information of the first I / O device in the shadow buffer into the first TEE buffer, so as to obtain the status information of the first I / O device in the synchronized first TEE buffer.
[0037] Among them, the operation permission of the communication interface for the shadow buffer is higher than that of the first VM for the shadow buffer.
[0038] In some possible implementation manners, the above REE further includes a control module.
[0039] The above communication interface is specifically used to write the status information of the first I / O device in the first TEE buffer into the above shadow buffer when the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, so that the shadow buffer stores the status information of the first I / O device.
[0040] The above control module is used to write the status information of the first I / O device in the shadow buffer into the first REE buffer, so as to obtain the status information of the first I / O device in the synchronized first REE buffer. Among them, the status information of the first I / O device in the synchronized first REE buffer is used to indicate the current status of the first I / O device.
[0041] In some possible implementation manners, when the above shadow buffer is operated by the above communication interface, it rejects the access of the above first VM; or, when the above shadow buffer is operated by the above first VM, it allows the access of the above communication interface.
[0042] In some possible implementation manners, the above TEE further includes a second CVM and a second TEE buffer. The second CVM runs based on the computing resources of the TEE. The above REE further includes a second REE buffer.
[0043] The above communication interface is further used to receive a second I / O request. Among them, the second I / O request is used to instruct the second CVM to perform a second I / O operation on the second I / O device.
[0044] The above communication interface is further used to synchronize the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer. Among them, the status information of the second I / O device is used to indicate that the status of the second I / O device is an idle state or an occupied state.
[0045] The second CVM described above is used to perform operations on the second I / O device according to the status information of the second I / O device in the synchronized second TEE buffer. The status information of the second I / O device in the synchronized second TEE buffer is used to indicate the current status of the second I / O device.
[0046] In a third aspect, a computing device is provided, including a processor and a memory. The memory is used to store instructions, and the processor is used to execute the instructions. When the processor executes the instructions, the method according to any one of the first aspect is implemented.
[0047] In a fourth aspect, a computer program product including instructions is provided. When the instructions are run on a computing device, the computing device is caused to execute the method according to any one of the first aspect.
[0048] In a fifth aspect, a computer-readable storage medium is provided, characterized in that it includes computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method according to any one of the first aspect. Description of the Drawings
[0049] Figure 1 is an architecture diagram of a computing device provided by an embodiment of the present application;
[0050] Figure 2 is a schematic flowchart of a method for a CVM to perform operations on an I / O device provided by an embodiment of the present application;
[0051] Figure 3 is a schematic flowchart of another method for a CVM to perform operations on an I / O device provided by an embodiment of the present application;
[0052] Figure 4 is an architecture diagram of another computing device provided by an embodiment of the present application;
[0053] Figure 5 is a schematic flowchart of another method for a CVM to perform operations on an I / O device provided by an embodiment of the present application;
[0054] Figure 6 is a schematic flowchart of another method for a CVM to perform operations on an I / O device provided by an embodiment of the present application;
[0055] Figure 7 is a schematic structural diagram of a computing device provided by an embodiment of the present application. Detailed Embodiments
[0056] Next, the technical solutions in the embodiments of the present application will be described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0057] To solve the problem that the use of I / O devices by VMs in the REE on current computing devices conflicts with the use of I / O devices by CVMs in the TEE, the present application provides two types of computing devices. Both the first computing device and the second computing device can share the information of the use of I / O devices by VMs in the REE with the CVMs in the TEE through the communication interface in the TEE, and share the information of the use of I / O devices by CVMs in the TEE with the VMs in the REE, so that the status information of the I / O devices is consistent in the REE and the TEE, thereby avoiding conflicts in the use of I / O devices. Among them,
[0058] The first computing device can be referred to Figure 1 and the introduction of related content. And, based on Figure 1 The method for the CVM implemented on the computing device to perform operations on the I / O device can be referred to Figure 2 、 Figure 3 and the introduction of related content. This method for the CVM to perform operations on the I / O device can improve the speed of sharing the status information of the I / O device between the REE and the TEE.
[0059] The second computing device can be referred to Figure 4 and the introduction of related content. And, based on Figure 4 The method for the CVM implemented on the computing device to perform operations on the I / O device can be referred to Figure 5 、 Figure 6 and the introduction of related content. This method for the CVM to perform operations on the I / O device can improve the stability of sharing the status information of the I / O device between the REE and the TEE.
[0060] Next, the above two types of computing devices and the methods for their corresponding CVMs to perform operations on the I / O device will be introduced separately.
[0061] I. The first computing device and the method for its corresponding CVM to perform operations on the I / O device
[0062] Refer to Figure 1 , Figure 1 which is an architecture diagram of a computing device provided by an embodiment of the present application. As Figure 1 shown, this architecture includes a computing device 10 and an I / O device 11. Among them, communication can be carried out between the computing device 10 and the I / O device 11.
[0063] The computing device 10 refers to an electronic device capable of performing calculations, processing, and storing data, such as a server, supercomputer, personal computer, workstation, mobile device, etc. The computing device 10 includes multiple physical components (i.e., hardware), specifically including: motherboard, processor (such as CPU, GPU), memory module, hard disk drive, etc. The computing device 10 can execute various computing tasks based on the computing resources and storage resources provided by the hardware, such as mathematical operations, logical operations, data processing and storage, etc. Among them, the computing resources refer to the hardware and software in the computing device 10 used to execute computing tasks, including: central processing unit (CPU), graphic processing unit (GPU), software frameworks and libraries (such as operating system, programming language, algorithm library), etc. The storage resources refer to the hardware and software in the computing device 10 used to store data and programs, including internal memory (such as memory), external memory (such as hard disk, solid state drive, optical disc, USB flash drive), etc.
[0064] The I / O device 11 refers to a device used to interact with the outside of the computing device 10, such as a keyboard, mouse, monitor, printer, scanner, camera, audio device (such as speaker, earphone, microphone), disk drive (such as hard disk drive, solid state drive), optical disc drive (such as CD-ROM, DVD-ROM), USB device (such as USB flash drive, external hard disk drive), network adapter, touch screen, expansion card (such as graphic processor, sound card, network card), sensor (such as temperature sensor, pressure sensor, acceleration sensor), etc. The I / O device 11 is responsible for receiving input information from the user or other devices and transmitting the output information processed by the computing device 10 to the user or other devices.
[0065] The above Figure 1 The architecture of the computing device shown above is illustrated by taking the computing device 10 having two I / O devices as an example. In actual applications, the number of I / O devices 11 communicating with the computing device 10 can be less or more, and can be various types of I / O devices, which are not specifically limited here.
[0066] The communication process between the computing device 10 and the I / O device 11 can be divided into the following two stages:
[0067] (1) Input stage
[0068] I / O device 11 receives input information (such as images, text, and sound) from a user or other devices. It then converts the received input information into an input signal and sends the input signal to computing device 10. After receiving the input signal, computing device 10 transmits the input signal to an application or processor within computing device 10, which then performs the corresponding I / O operation (such as displaying the input text, moving the cursor, or executing a command) based on the received input signal.
[0069] (2) Output stage
[0070] An application or processor in computing device 10 generates output information (e.g., images, text, sounds) and transmits the output information to computing device 10. Computing device 10 then converts the received output information into an output signal and sends the output signal to I / O device 11. I / O device 11 performs corresponding I / O operations (e.g., displaying text, playing video, printing data) based on the received output signal.
[0071] The communication connection between the computing device 10 and the I / O device 11 may be a wired connection or a wireless connection, which is not specifically limited in this application.
[0072] In some possible implementations, the computing device 10 includes a common open environment (REE) 110 and a trusted execution environment (TEE) 120. The hardware occupied by the computing resources of the common open environment (REE) 110 (i.e., Figure 1 The hardware 130 in the Trusted Execution Environment (TEE) and the computing resources occupied by the Trusted Execution Environment (TEE) 120 (i.e. Figure 1 The following describes the common open environment REE 110 and the trusted execution environment TEE 120.
[0073] (1) Ordinary open environment REE 110
[0074] The common open environment REE 110 includes a first VM 111, a first REE buffer 112, a second VM 113, and a second REE buffer 114. The functions of these components are described below.
[0075] (1) First VM 111
[0076] The first VM 111 refers to a complete computer system that is implemented using network functions virtualization (NFV) technology, has the functions of a complete hardware system through software simulation, and runs in a completely isolated environment. Since the first VM 111 is implemented using NFV technology, its security protection mechanism and hardware support are relatively weak. Therefore, the security level of the first VM 111 is relatively low, and the protection of sensitive data and critical programs is relatively weak. However, the first VM 111 has great flexibility and can run various applications and operating systems.
[0077] The first VM 111 can transmit the data in the first VM 111 to the outside of the computing device 10 through the I / O device 11, and receive the data from the outside of the computing device 10. The first VM 111 allows access to all the I / O devices 11 in the computing device 10, or only allows access to some of the I / O devices 11 in the computing device 10, or does not allow access to the I / O devices 11 in the computing device 10, which is not specifically limited here.
[0078] (2) The first REE buffer 112
[0079] The first REE buffer 112 can be set in the internal memory and / or external memory allocated by the computing device 10 for the general open environment REE 110, and is used to store the status information of the I / O devices 11 that the first VM 111 is allowed to access. Among them, the status information of the I / O device 11 is used to indicate that the status of the I / O device 11 is an idle state or an occupied state. For example, if the first VM111 only allows access to Figure 1 one of the I / O devices 11, then the status information of this I / O device 11 is stored in the first REE buffer 112, and the status information of other I / O devices 11 is not stored.
[0080] The first REE buffer 112 can be implemented by software or by hardware. As an example of software implementation, the first REE buffer 112 can be implemented by code running on a computing instance in the general open environment REE 110. Among them, the computing instance can be a confidential virtual machine and / or a container. As an example of hardware implementation, the first REE buffer 112 can be implemented by hardware such as a memory chip and a cache chip allocated by the computing device 10 for the general open environment REE 110.
[0081] (3) The second VM 113
[0082] The second VM 113 refers to a complete computer system that is implemented using NFV technology, has the functions of a complete hardware system through software simulation, and runs in a completely isolated environment. Since the second VM 113 is implemented using NFV technology, its security protection mechanism and hardware support are relatively weak. Therefore, the security level of the second VM 113 is relatively low, and the protection for sensitive data and critical programs is relatively small. However, the second VM 113 has greater flexibility and can run various applications and operating systems.
[0083] The second VM 113 can transmit the data in the second VM 113 to the outside of the computing device 10 through the I / O device 11, and receive data from the outside of the computing device 10. The second VM 113 is allowed to access all the I / O devices 11 in the computing device 10, or only allowed to access some of the I / O devices 11 in the computing device 10, or not allowed to access the I / O devices 11 in the computing device 10. No specific limitation is made here.
[0084] The second VM 113 shares the hardware allocated by the computing device 10 for the general open environment REE 110 with the first VM 111. And the second VM 113 and the first VM 111 can communicate with each other through the network. However, the second VM 113 and the first VM 111 can independently configure and manage their own computing resources, storage resources, and network resources, can independently run their own applications and operating systems, and can also ensure that their own operations and data will not affect the operation of the other VM.
[0085] (4) The second REE buffer 114
[0086] The second REE buffer 114 can be set in the internal memory and / or external memory allocated by the computing device 10 for the general open environment REE 110, and is used to store the status information of the I / O devices 11 allowed to be accessed by the second VM 113. Among them, the status information of the I / O device 11 is used to indicate that the status of the I / O device 11 is an idle state or an occupied state. For example, if the second VM 113 is only allowed to access Figure 1 one of the I / O devices 11, then the status information of this I / O device 11 is stored in the second REE buffer 114, and the status information of other I / O devices 11 is not stored.
[0087] The second REE buffer 114 can be implemented by software or by hardware. The implementation method of the second REE buffer 114 is similar to the implementation method of the first REE buffer 112 in the above (2) the first REE buffer 112. For the sake of simplicity of the specification, it will not be elaborated here.
[0088] In some possible implementations, the first VM 111 may also perform operations on other REE buffers, or the second VM 113 may also perform operations on other REE buffers. Specifically, if the I / O device 11 that the first VM 111 is allowed to access is the same as the I / O device 11 that the second VM 113 is allowed to access, the first REE buffer 112 and the second REE buffer 114 store the same state information of the I / O device 11. Therefore, if the first VM 111 changes the state of the same I / O device 11, the first VM 111 writes the new state information of the same I / O device 11 to the first REE buffer 112 and the second REE buffer 114; if the second VM 113 changes the state of the same I / O device 11, the second VM 113 writes the new state information of the same I / O device 11 to the first REE buffer 112 and the second REE buffer 114.
[0089] It should be understood that (1) the first VM 111 to (4) the second REE buffer 114 in the above-mentioned (1) ordinary open environment REE 110 are explained by taking the ordinary open environment REE 110 as an example including two VMs and two REE buffers. In actual applications, the number of VMs and REE buffers can be one or more, and this application does not make specific limitations.
[0090] (2) Trusted Execution Environment TEE 120
[0091] The trusted execution environment TEE 120 further includes a first CVM 121, a first TEE buffer 122, a second CVM 123, a second TEE buffer 124, and a communication interface 125. The functions of these components are described below.
[0092] (1) First CVM 121
[0093] The first CVM 121 is a complete computer system implemented using secure encrypted virtualization (SEV) technology, simulated through software, and running in a completely isolated environment with complete hardware system functions. Because the first CVM 121 is implemented using SEV technology, its security protection mechanism and hardware support are relatively strong. Therefore, the security level of the first CVM 121 is relatively high, and the protection of sensitive data and critical programs is relatively strong. However, the first CVM 121 has greater restrictions and can only run verified and authorized applications and operating systems, and is strictly monitored by the Trusted Execution Environment TEE 120.
[0094] The first CVM 121 can transmit the data in the first CVM 121 to the outside of the computing device 10 through the I / O device 11 and receive the data from the outside of the computing device 10. The first CVM 121 allows access to all the I / O devices 11 in the computing device 10, or only allows access to some of the I / O devices 11 in the computing device 10, or does not allow access to the I / O devices 11 in the computing device 10, which is not specifically limited here.
[0095] (2) The first TEE buffer 122
[0096] The first TEE buffer 122 can be set in the internal memory and / or external memory allocated by the computing device 10 for the trusted execution environment TEE 120, and is used to store the status information of the I / O devices 11 allowed to be accessed by the first CVM 121. Among them, the status information of the I / O device 11 is used to indicate that the status of the I / O device 11 is an idle state or an occupied state. For example, if the first CVM 121 only allows access to Figure 1 one of the I / O devices 11, then the first TEE buffer 122 stores the status information of this I / O device 11 and does not store the status information of other I / O devices 11.
[0097] The first TEE buffer 122 can be implemented by software or by hardware. As an example of software implementation, the first TEE buffer 122 can be implemented by the code running on the computing instance of the trusted execution environment TEE 120. Among them, the computing instance can be a confidential virtual machine and / or a container. As an example of hardware implementation, the first TEE buffer 122 can be implemented by hardware such as a memory chip and a cache chip allocated by the computing device 10 for the trusted execution environment TEE 120.
[0098] (3) The second CVM 123
[0099] The second CVM 123 refers to a complete computer system with complete hardware system functions simulated by software and running in a completely isolated environment implemented by the SEV technology. Since the second CVM 123 is implemented by the SEV technology, its security protection mechanism and hardware support are relatively strong. Therefore, the security level of the second CVM 123 is relatively high, and the protection of sensitive data and key programs is relatively strong. However, the second CVM 123 has greater restrictions and can only run the applications and operating systems that have been verified and authorized and is strictly monitored by the trusted execution environment TEE 120.
[0100] The second CVM 123 can transmit the data in the second CVM 123 to the outside of the computing device 10 through the I / O device 11, and receive the data from the outside of the computing device 10. The second CVM 123 allows access to all I / O devices 11 in the computing device 10, or only allows access to some of the I / O devices 11 in the computing device 10, or does not allow access to the I / O devices 11 in the computing device 10, which is not specifically limited here.
[0101] The second CVM 123 shares the hardware allocated by the computing device 10 for the trusted execution environment TEE 120 with the first CVM 121. And the second CVM 123 and the first CVM 121 can communicate with each other through a network. However, the second CVM 123 and the first CVM 121 can independently configure and manage their own computing resources, storage resources and network resources, can independently run their own applications and operating systems, and can also ensure that their own operations and data will not affect the operation of another CVM.
[0102] (4) The second TEE buffer 124
[0103] The second TEE buffer 124 can be set in the internal memory and / or external memory allocated by the computing device 10 for the trusted execution environment TEE 120, and is used to store the status information of the I / O devices 11 allowed to be accessed by the second CVM 123. Among them, the status information of the I / O device 11 is used to indicate that the status of the I / O device 11 is an idle state or an occupied state. For example, if the second CVM 123 only allows access to Figure 1 one of the I / O devices 11, then the status information of this I / O device 11 is stored in the second TEE buffer 124, and the status information of other I / O devices 11 is not stored.
[0104] The second TEE buffer 124 can be implemented by software or by hardware. The implementation method of the second TEE buffer 124 is similar to the implementation method of the first TEE buffer 122 in the above (2) first TEE buffer 122. For the sake of simplicity of the specification, it will not be elaborated here.
[0105] (5) Communication interface 125
[0106] The communication interface 125 is used to transmit the status information of the I / O device 11 between the general open environment REE 110 and the trusted execution environment TEE 120. Specifically, the communication interface 125 can be used to transmit the status information of the I / O device 11 stored in the REE buffer in the general open environment REE 110 to the TEE buffer in the trusted execution environment TEE 120, or to transmit the status information of the I / O device 11 stored in the TEE buffer in the trusted execution environment TEE 120 to the REE buffer in the general open environment REE 110.
[0107] For example, in Figure 1 , the communication interface 125 can be used to transmit the status information of the I / O device 11 in the first REE buffer 112 and / or the second REE buffer 114 to the first TEE buffer 122 and / or the second TEE buffer 124; it can also be used to transmit the status information of the I / O device 11 in the first TEE buffer 122 and / or the second TEE buffer 124 to the first REE buffer 112 and / or the second REE buffer 114.
[0108] In some possible implementation manners, the communication interface 125 is specifically used to transmit the status information of the I / O device 11 between the general open environment REE 110 and the trusted execution environment TEE 120 only when there is an operation requirement for the I / O device 11 in the CVM in the trusted execution environment TEE 120.
[0109] Since the general open environment REE 110 provides a general operating system and application environment and allows users to freely install and run various applications, when the VMs in the general open environment REE 110 run various applications and operating systems, the operation requirements for the I / O device 11 are large, which causes the status information of the I / O device 11 in the REE buffer to change frequently, and thus the modification time of the status information of the I / O device 11 in the REE buffer is also updated frequently.
[0110] The trusted execution environment TEE 120 provides a hardware-level secure isolation environment and does not allow users to freely install and run various applications. Therefore, when the CVM in the trusted execution environment TEE 120 runs a small number of verified and authorized applications and operating systems, the operation requirements for the I / O device 11 are small, which causes the status information of the I / O device 11 in the TEE buffer to change occasionally, and thus the modification time of the status information of the I / O device 11 in the TEE buffer is also updated occasionally.
[0111] For the case where the VMs in the ordinary open environment REE 110 have a large demand for the operation of the I / O device 11, while the CVMs in the trusted execution environment TEE 120 have a small demand for the operation of the I / O device 11, the communication interface 125 transmits the status information of the I / O device 11 between the ordinary open environment REE 110 and the trusted execution environment TEE 120 according to the requirements of the CVMs, which can improve the utilization rate of the communication interface 125, reduce the number of transmissions of the status information, and reduce the load of the computing device 10.
[0112] The communication interface 125 can be implemented by software, hardware, or a combination of software and hardware. As an example of software implementation, the communication interface 125 can be implemented by code running on a computing instance in the trusted execution environment TEE 120. Among them, the computing instance can be a confidential virtual machine and / or a container. As an example of hardware implementation, the communication interface 125 can be implemented by hardware such as a serial port interface, an Ethernet interface, etc. allocated by the computing device 10 for the trusted execution environment TEE 120. As an example of a combination of software and hardware implementation, the communication interface 125 can be implemented by code running on a computing instance in the trusted execution environment TEE 120 to control the hardware allocated by the computing device 10 for the trusted execution environment TEE 120.
[0113] It should be understood that the above (ii) the first CVM 121 to (5) the communication interface 125 in the trusted execution environment TEE 120 are described by taking the trusted execution environment TEE 120 including two CVMs and two TEE buffers as an example. In practical applications, the number of CVMs and TEE buffers can both be one or more, and the present application does not make specific limitations.
[0114] It should be understood that the above (i) the ordinary open environment REE 110 to (ii) the trusted execution environment TEE 120 are described by taking Figure 1 the computing device 10 including one REE and one TEE as an example. In practical applications, the number of REEs and TEEs can both be one or more, and the present application does not make specific limitations.
[0115] Based on the foregoing Figure 1For the architecture of the computing device in , the method for the CVM provided by the embodiments of the present application to operate on the I / O device will be specifically introduced below. The method for the CVM to operate on the I / O device can make the status information of the I / O device consistent in the REE and the TEE, and avoid the use conflict of the I / O device. To achieve the consistency of the status information of the I / O device in the REE and the TEE, it includes: sharing the information of the VM in the REE using the I / O device with the CVM in the TEE, and sharing the information of the CVM in the TEE using the I / O device with the VM in the REE.
[0116] See Figure 2 , Figure 2 is a schematic flowchart of a method for the CVM provided by the embodiments of the present application to operate on the I / O device. The method for the CVM to operate on the I / O device can improve the speed of sharing the status information of the I / O device between the REE and the TEE. As Figure 2 shown, the method for the CVM of the embodiments of the present application to operate on the I / O device includes:
[0117] S201: The first CVM or the first I / O device sends a first I / O request to the communication interface. Correspondingly, the communication interface receives the first I / O request from the first CVM or the first I / O device.
[0118] Among them, the first I / O request is used to indicate that the first CVM performs a first I / O operation on the first I / O device. The first I / O operation includes reading data from the first I / O device and transmitting the data to an application or a virtual processor in the first CVM, and sending the data in the application or the virtual processor in the first CVM to the first I / O device, etc. The virtual processor in the first CVM is the processor occupied by the first CVM in the TEE.
[0119] Among them, the first CVM can be Figure 1 the first CVM 121 in the computing device 10 in . The first I / O device can be Figure 1 one of the I / O devices 11 in . The communication interface can be Figure 1 the communication interface 125 in the computing device 10 in .
[0120] S202: The communication interface determines whether the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer.
[0121] The modification time of the status information of the first I / O device can be a part of the metadata of the status information of the first I / O device. Among them, the metadata is data that describes the status information, including the creation time, access permission, storage location, etc. of the status information. The metadata is stored in the operating system or the file system. Specifically, the modification time of the status information of the first I / O device in the first REE buffer is stored in the operating system or the file system in the REE. The modification time of the status information of the first I / O device in the first TEE buffer is stored in the operating system or the file system in the TEE.
[0122] Therefore, the communication interface can obtain the modification time of the status information of the first I / O device in the first REE buffer from the metadata of the operating system in the REE or the metadata of the file system, and obtain the modification time of the status information of the first I / O device in the first TEE buffer from the metadata of the operating system in the TEE or the metadata of the file system.
[0123] Subsequently, the communication interface compares the modification time of the status information of the first I / O device in the first REE buffer with the modification time of the status information of the first I / O device in the first TEE buffer to determine the storage location of the status information indicating the current state of the first I / O device. There are mainly the following two cases:
[0124] Case 1: The modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the first REE buffer is new and the status information of the first I / O device in the first TEE buffer is old. Therefore, the status information stored in the first REE buffer of the first I / O device indicates the current state of the first I / O device.
[0125] Case 2: The modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the first REE buffer is old and the status information of the first I / O device in the first TEE buffer is new. Therefore, the status information stored in the first TEE buffer of the first I / O device indicates the current state of the first I / O device.
[0126] Among them, the above-mentioned first REE buffer can be Figure 1 the first REE buffer 112 in the computing device 10. The first TEE buffer can be Figure 1 the first TEE buffer 122 in the computing device 10.
[0127] In case 1 of step S202 above, go to S203; in case 2 of step S202 above, go to S207.
[0128] S203: The communication interface reads the status information of the first I / O device from the first REE buffer.
[0129] Since the first REE buffer is set in the REE, and the data in the REE can not only be used within the REE but also be shared with the TEE, the communication interface in the TEE can read the status information of the first I / O device from the first REE buffer.
[0130] S204: The communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0131] In some possible implementation manners, the communication interface may write the status information of the first I / O device in the first REE buffer into the first TEE buffer by means of overwrite write, append write, insert write, etc.
[0132] In a specific implementation manner, the communication interface adopts overwrite write. Specifically, the communication interface writes the status information of the first I / O device in the first REE buffer to the position in the first TEE buffer that stores the status information of the first I / O device, overwriting the original status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer.
[0133] In another specific implementation manner, the communication interface adopts append write. Specifically, the communication interface writes the status information of the first I / O device in the first REE buffer to the tail address of the first TEE buffer, so that the tail address of the first TEE buffer stores the status information of the first I / O device from the first REE buffer. By only reading the status information of the first I / O device at the tail address, the replacement of the status information of the first I / O device in the first REE buffer for the status information of the first I / O device in the first TEE buffer is completed.
[0134] In another specific implementation, the communication interface performs insert - type writing. Specifically, the communication interface writes the status information of the first I / O device in the first REE buffer to a specified position in the first TEE buffer. By only reading the status information of the first I / O device at the specified position, the replacement of the status information of the first I / O device in the first REE buffer with the status information of the first I / O device in the first TEE buffer is completed.
[0135] It should be understood that the above - mentioned overwriting writing, appending writing, and insert - type writing are only examples and are not specifically limited here. In practical applications, any method that can enable the communication interface to write the status information of the first I / O device in the first REE buffer to the first TEE buffer is within the protection scope of this application.
[0136] S205: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0137] In some possible implementation manners, when the first CVM reads the status information of the first I / O device from the first TEE buffer to obtain the current status of the first I / O device, it mainly includes the following two cases:
[0138] Case 1: The current status of the first I / O device is the idle state;
[0139] Case 2: The current status of the first I / O device is the occupied state.
[0140] In some possible implementation manners, different values can be used to represent different states of the first I / O device, that is, different values correspond to different cases in the above - mentioned step S205. Among them, case 1 of the above - mentioned step S205 can be represented by a first value, and case 2 of the above - mentioned step S205 can be represented by a second value. For example, the first value is 0, indicating that the current status of the first I / O device is the idle state; the second value is 1, indicating that the current status of the first I / O device is the occupied state. Or, the first value is A, indicating that the current status of the first I / O device is the idle state; the second value is B, indicating that the current status of the first I / O device is the occupied state.
[0141] In some possible implementation manners, before the above - mentioned first CVM reads the status information of the first I / O device from the first TEE buffer, triggering the reading operation of the first CVM for the first TEE buffer includes at least the following two implementation manners:
[0142] In a specific implementation manner, the first CVM receives a first notification from the communication interface. The first notification is used to instruct the first CVM to read the status information of the first I / O device from a specified position in the first TEE buffer.
[0143] In another specific implementation, the first CVM monitors the first TEE buffer so that after the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer, the first CVM can timely read the status information of the first I / O device from the first TEE buffer.
[0144] It should be understood that the above implementation for triggering the first CVM to read the first TEE buffer is only an example and is not specifically limited here. In practical applications, any implementation that can trigger the first CVM to read the first TEE buffer is within the protection scope of this application.
[0145] S206: The first CVM performs an operation on the first I / O device according to the status information of the first I / O device.
[0146] In some possible implementation manners, the operations performed by the first CVM according to the status information of the first I / O device at least include the following two types:
[0147] In the first operation, corresponding to case 1 of the above step S205, the first CVM immediately uses the first I / O device.
[0148] Specifically, the first CVM immediately establishes a communication connection with the first I / O device and performs a first I / O operation on the first I / O device. After completing the first I / O operation, the first CVM immediately releases the first I / O device and writes the status information indicating that the current status of the first I / O device is the idle state into the first TEE buffer. Subsequently, the communication interface executes step S207.
[0149] In the second operation, corresponding to case 2 of the above step S205, the first CVM waits for the first I / O device or preempts the first I / O device.
[0150] If the first CVM waits for the first I / O device, the first CVM establishes a communication connection with the first I / O device and performs a first I / O operation on the first I / O device after the current status of the first I / O device changes from the occupied state to the idle state.
[0151] If the first CVM preempts the first I / O device, the first CVM generates a first interrupt signal indicating the occupation of the first I / O device and sends the first interrupt signal to the first I / O device. After receiving the first interrupt signal, the first I / O device establishes a communication connection with the first CVM, enabling the first CVM to perform a first I / O operation on the first I / O device. Among them, the first interrupt signal includes information such as the device type, device address, and device characteristics (such as supported data formats, transmission rates, and cache capacities) of the first I / O device.
[0152] It should be understood that the above first operation and second operation are merely examples. In actual applications, the first CVM can also perform other operations according to the status information of the first I / O device. For example, before releasing the first I / O device, the first CVM generates a first release request indicating the release of the first I / O device and sends the first release request to the virtual machine monitor (VMM) in the TEE. Alternatively, the first CVM writes the status information indicating that the current status of the first I / O device is the idle state into the second TEE buffer.
[0153] S207: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0154] Since the first TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the first I / O device from the first TEE buffer.
[0155] S208: The communication interface writes the status information of the first I / O device in the first TEE buffer into the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0156] In some possible implementation manners, the communication interface can write the status information of the first I / O device in the first TEE buffer into the first REE buffer in manners such as overwriting write, append write, insert write, etc. It should be understood that the implementation manner of the communication interface writing the status information of the first I / O device in the first TEE buffer into the first REE buffer is similar to the implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in the above step S204. For the sake of simplicity of the specification, it will not be elaborated here.
[0157] S209: The first VM reads the status information of the first I / O device from the first REE buffer.
[0158] In some possible implementation manners, when the first VM reads the status information of the first I / O device from the first REE buffer to obtain the current status of the first I / O device, it mainly includes the following two situations:
[0159] Situation 1: The current status of the first I / O device is the idle state;
[0160] Situation 2: The current status of the first I / O device is the occupied state.
[0161] In some possible implementations, before the first VM reads the status information of the first I / O device from the first REE buffer, triggering the first VM to read the first REE buffer includes at least the following two implementation manners:
[0162] In a specific implementation manner, the first VM receives a second notification from the communication interface. The second notification is used to instruct the first VM to read the status information of the first I / O device from the first REE buffer.
[0163] In another specific implementation manner, the first VM monitors the first REE buffer so that after the communication interface writes the status information of the first I / O device in the first TEE buffer into the first REE buffer, the first VM can timely read the status information of the first I / O device from the first REE buffer.
[0164] It should be understood that the above implementation manners for triggering the first VM to read the first REE buffer are only taken as examples and are not specifically limited herein. In practical applications, any implementation manner that can trigger the first VM to read the first REE buffer is within the protection scope of this application.
[0165] S210: The first VM performs an operation on the first I / O device according to the status information of the first I / O device.
[0166] It should be understood that the operation performed by the first VM in case 1 of the above step S209 is similar to the first operation in the above step S206; the operation performed by the first VM in case 2 of the above step S209 is similar to the second operation in the above step S206. For the sake of simplicity of the specification, it will not be elaborated herein.
[0167] In summary, when the first CVM in the TEE needs to establish a communication connection with the first I / O device to complete the first I / O request, the communication interface in the TEE synchronizes the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first REE buffer and the first TEE is the same, achieving the effect that the status information of the first I / O device is consistent in the REE and the TEE. Therefore, the first CVM can perform an operation on the first I / O device according to the current status of the first I / O device. For example, when the current status of the first I / O device is the idle state, the first CVM immediately uses the first I / O device; when the current status of the first I / O device is the occupied state, the first CVM waits or preempts the first I / O device. This can avoid conflicts with the use of the first I / O device by the VM in the REE.
[0168] Further, the communication interface directly reads the status information of the first I / O device from the first REE buffer and writes it into the first TEE buffer; or, the communication interface directly reads the status information of the first I / O device from the first TEE buffer and writes it into the first REE buffer. This can effectively improve the sharing speed of the status information of the first I / O device between the REE and the TEE, and further improve the usage performance of the first VM and the first CVM for the first I / O device, including the data transfer speed, latency, throughput, response time, etc. between the computing device and the first I / O device.
[0169] Furthermore, since the status information of the first I / O device is transmitted in this technical solution, the security and privacy of data calculation in the TEE can still be ensured.
[0170] The foregoing Figure 2 The method for the CVM to operate on the I / O device in Figure 1 is applicable to the scenario of synchronizing the status information of an I / O device. Based on the architecture of the computing device in the foregoing Figure 2 and the method for the CVM to operate on the I / O device in the foregoing
[0171] Refer to Figure 3 Figure 3 which is a schematic flowchart of another method for the CVM to operate on the I / O device provided by an embodiment of the present application. As Figure 3 shown, the method for the CVM to operate on the I / O device in the embodiment of the present application includes:
[0172] S301: The first CVM or the first I / O device sends a first I / O request to the communication interface.
[0173] S302: The communication interface determines whether the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer.
[0174] If the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, go to S303; if the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, go to S307.
[0175] S303: The communication interface reads the status information of the first I / O device from the first REE buffer.
[0176] S304: The communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0177] S305: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0178] S306: Perform an operation on the first I / O device according to the status information of the first I / O device.
[0179] S307: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0180] S308: The communication interface writes the status information of the first I / O device in the first TEE buffer into the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0181] S309: The first VM reads the status information of the first I / O device from the first REE buffer.
[0182] S310: Perform an operation on the first I / O device according to the status information of the first I / O device.
[0183] The execution process of the above steps S301 to S310 can refer to the execution process of steps S201 to S210 in the foregoing Figure 2 For the sake of simplicity of the specification, it will not be elaborated here.
[0184] S311: The second CVM or the second I / O device sends a second I / O request to the communication interface. Correspondingly, the communication interface receives the second I / O request from the second CVM or the second I / O device.
[0185] Among them, the second I / O request is used to instruct the second CVM to perform a second I / O operation on the second I / O device. The second I / O operation includes reading data from the second I / O device and transferring the data to an application or a virtual processor in the second CVM, and sending the data in the application or the virtual processor in the second CVM to the second I / O device, etc. Among them, the virtual processor in the second CVM is the processor occupied by the second CVM in the TEE.
[0186] Among them, the second CVM can be Figure 1 the second CVM 123 in the computing device 10 in. The second I / O device can be Figure 1 one of the I / O devices 11 in.
[0187] S312: The communication interface determines whether the modification time of the status information of the second I / O device in the second REE buffer is later than the modification time of the status information of the second I / O device in the second TEE buffer.
[0188] The modification time of the status information of the second I / O device can be a part of the metadata of the status information of the second I / O device. Among them, the metadata is data describing the status information, including the creation time, access permission, storage location, etc. of the status information. The metadata is stored in the operating system or the file system. Specifically, the modification time of the status information of the second I / O device in the second REE buffer is stored in the operating system or the file system in the REE. The modification time of the status information of the second I / O device in the second TEE buffer is stored in the operating system or the file system in the TEE.
[0189] Therefore, the communication interface can obtain the modification time of the status information of the second I / O device in the second REE buffer from the metadata of the operating system in the REE or the metadata of the file system, and obtain the modification time of the status information of the second I / O device in the second TEE buffer from the metadata of the operating system in the TEE or the metadata of the file system.
[0190] Subsequently, the communication interface compares the modification time of the status information of the second I / O device in the second REE buffer with the modification time of the status information of the second I / O device in the second TEE buffer to determine the storage location of the status information indicating the current state of the second I / O device. There are mainly the following two cases:
[0191] Case 1: The modification time of the status information of the second I / O device in the second REE buffer is later than that in the second TEE buffer, indicating that the status information of the second I / O device in the second REE buffer is new and the status information of the second I / O device in the second TEE buffer is old. Therefore, the status information of the second I / O device stored in the second REE buffer indicates the current status of the second I / O device.
[0192] Case 2: The modification time of the status information of the second I / O device in the second REE buffer is earlier than that in the second TEE buffer, indicating that the status information of the second I / O device in the second REE buffer is old and the status information of the second I / O device in the second TEE buffer is new. Therefore, the status information of the second I / O device stored in the second TEE buffer indicates the current status of the second I / O device.
[0193] Among them, the above-mentioned second REE buffer can be Figure 1 the second REE buffer 114 in the computing device 10 in Figure 1 the second TEE buffer 124 in the computing device 10 in.
[0194] In case 1 of the above step S312, go to S313; in case 2 of the above step S312, go to S317.
[0195] S313: The communication interface reads the status information of the second I / O device from the second REE buffer.
[0196] Since the second REE buffer is set in the REE, and the data in the REE can not only be used inside the REE but also be shared with the TEE, the communication interface in the TEE can read the status information of the second I / O device from the second REE buffer.
[0197] S314: The communication interface writes the status information of the second I / O device in the second REE buffer into the second TEE buffer, so that the status information of the second I / O device in the second TEE buffer is replaced by the status information of the second I / O device in the second REE buffer, thereby realizing the synchronization of the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer.
[0198] In some possible implementations, the communication interface may write the status information of the second I / O device in the second REE buffer to the second TEE buffer in a way such as overwrite writing, append writing, insert writing, etc. It should be understood that the implementation of the communication interface writing the status information of the second I / O device in the second REE buffer to the second TEE buffer is similar to the implementation of the communication interface writing the status information of the first I / O device in the first REE buffer to the first TEE buffer in step S204 described above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 in step S204, and for the sake of simplicity of the specification, it will not be elaborated here.
[0199] S315: The second CVM reads the status information of the second I / O device from the second TEE buffer.
[0200] In some possible implementations, when the second CVM reads the status information of the second I / O device from the second TEE buffer to obtain the current status of the second I / O device, there are mainly the following two cases:
[0201] Case 1: The current status of the second I / O device is the idle state;
[0202] Case 2: The current status of the second I / O device is the occupied state.
[0203] In some possible implementations, different values may be used to represent different statuses of the second I / O device, that is, different values correspond to different cases in the above step S315. It should be understood that this is similar to using different values to represent different statuses of the first I / O device in step S205 described above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 in step S205, and for the sake of simplicity of the specification, it will not be elaborated here.
[0204] In some possible implementations, before the second CVM reads the status information of the second I / O device from the second TEE buffer, the read operation of the second CVM on the second TEE buffer is triggered. It should be understood that the implementation of triggering the read operation of the second CVM on the second TEE buffer is similar to the implementation of triggering the read operation of the first CVM on the first TEE buffer in step S205 described above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 in step S205, and for the sake of simplicity of the specification, it will not be elaborated here.
[0205] S316: The second CVM performs an operation on the second I / O device according to the status information of the second I / O device.
[0206] It should be understood that the operation performed by the second CVM in Case 1 of the above step S315 is similar to the first operation in step S206 described above; the operation performed by the second CVM in Case 2 of the above step S315 is similar to the operation in step S206 described above. Figure 2 in step S206; the operation performed by the second CVM in Case 2 of the above step S315 is similar to the operation in step S206 described above. Figure 2Similar to the second operation in step S206, for the sake of simplicity of the specification, it will not be elaborated here.
[0207] S317: The communication interface reads the status information of the second I / O device from the second TEE buffer.
[0208] Since the second TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the second I / O device from the second TEE buffer.
[0209] S318: The communication interface writes the status information of the second I / O device in the second TEE buffer into the second REE buffer, so that the status information of the second I / O device in the second REE buffer is replaced by the status information of the second I / O device in the second TEE buffer, thereby realizing the synchronization of the status information of the second I / O device in the second REE buffer and the status information of the second I / O device in the second TEE buffer.
[0210] In some possible implementation manners, the communication interface can write the status information of the second I / O device in the second TEE buffer into the second REE buffer by means of overwriting write, append write, insert write, etc. It should be understood that the implementation manner of the communication interface writing the status information of the second I / O device in the second TEE buffer into the second REE buffer is similar to the Figure 2 implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 above. For the sake of simplicity of the specification, it will not be elaborated here.
[0211] S319: The second VM reads the status information of the second I / O device from the second REE buffer.
[0212] In some possible implementation manners, when the second VM reads the status information of the second I / O device from the second REE buffer to obtain the current status of the second I / O device, it mainly includes the following two cases:
[0213] Case 1: The current status of the second I / O device is the idle state;
[0214] Case 2: The current status of the second I / O device is the occupied state.
[0215] In some possible implementation manners, before the second VM reads the status information of the second I / O device from the second REE buffer, the read operation of the second VM on the second REE buffer is triggered. It should be understood that the implementation manner of triggering the read operation of the second VM on the second REE buffer is the same as the above Figure 2The implementation method of triggering the first VM to read the first REE buffer in step S209 is similar. For the sake of simplicity of the specification, it will not be elaborated here.
[0216] S320: The second VM performs an operation on the second I / O device according to the status information of the second I / O device.
[0217] It should be understood that the operation performed by the second VM in case 1 of the above step S319 is similar to the first operation in step S206 above; the operation performed by the second VM in case 2 of the above step S319 is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 It should be understood that the operation performed by the second VM in case 1 of the above step S319 is similar to the first operation in step S206 above; the operation performed by the second VM in case 2 of the above step S319 is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 It should be understood that the operation performed by the second VM in case 2 of the above step S319 is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here.
[0218] It should be understood that this technical solution can either first execute the above steps S301 to S310 and then execute the above steps S311 to S320; or first execute the above steps S311 to S320 and then execute the above steps S301 to S310; or cross-execute the steps in the above steps S301 to S310 and the steps in the above steps S311 to S320. For example, first execute the above step S301, then execute the above step S311, then execute the above step S302, then execute the above step S312... Or first execute the above steps S311, S312, and then execute the above steps S301, S302...
[0219] In summary, when the CVM in the TEE needs to establish a communication connection with the I / O device to complete the I / O request, the communication interface in the TEE is used to synchronize the status information of the I / O device in the REE buffer and the status information of the I / O device in the TEE buffer, so that the status information of the I / O device in the REE buffer is the same as the status information of the I / O device in the TEE buffer, achieving the effect that the status information of the I / O device is consistent in the REE and the TEE. Therefore, the CVM can perform an operation on the I / O device according to the current status of the I / O device, which can avoid conflicts with the use of the I / O device by the VM in the REE.
[0220] Further, during the process of sharing the status information of the I / O device between the CVM in the TEE and the VM in the REE, the status information of the I / O device from the TEE is always transmitted to the REE through the same communication interface, or the status information of the I / O device from the REE is always transmitted to the TEE through the same communication interface. Using only one communication interface to transmit the status information of the I / O device in the TEE can reduce the complexity of the technical solution, simplify the development process, and also save the computing resources and hardware of the TEE. More importantly, compared with using multiple communication interfaces, each of which may become the target of attack by insecure devices, using only one communication interface in this technical solution can reduce the attack surface and potential security vulnerabilities, and reduce the threats to the TEE.
[0221] Furthermore, since the status information of the first I / O device is transmitted in this technical solution, the security and privacy of data calculation in the TEE can still be ensured.
[0222] II. Method for the Second Computing Device and Its Corresponding CVM to Perform Operations on the I / O Device
[0223] The second computing device is based on the structure of the first computing device above, and a shadow buffer for storing the status information of the I / O device is added in the REE. For details, please refer to Figure 4 and the introduction of relevant content.
[0224] Refer to Figure 4 , Figure 4 which is the architecture diagram of another computing device provided by the embodiments of the present application. As Figure 4 shown, the architecture includes a computing device 20 and an I / O device 21. Among them, communication can be carried out between the computing device 20 and the I / O device 21.
[0225] The computing device 20 refers to an electronic device capable of performing calculations, processing, and storing data, such as a server, a supercomputer, a personal computer, a workstation, a mobile device, etc. The computing device 20 includes multiple physical components (i.e., hardware). The computing device 20 can perform various computing tasks based on the computing resources and storage resources provided by the hardware. Among them, the computing resources refer to the hardware and software in the computing device 20 used to perform computing tasks. The storage resources refer to the hardware and software in the computing device 20 used to store data and programs.
[0226] The I / O device 21 refers to a device used for external interaction with the computing device 20.
[0227] The I / O device 21 can be Figure 1The I / O device 11 in it. The I / O device 21 is responsible for receiving input information from users or other devices and transmitting the output information processed by the computing device 20 to users or other devices.
[0228] The above-mentioned Figure 4 The architecture of the computing device shown above is described by taking the computing device 20 having two I / O devices as an example. In actual applications, the number of I / O devices 21 communicating with the computing device 20 can be less or more, and they can be various types of I / O devices, which are not specifically limited here.
[0229] In some possible implementation manners, the communication process between the computing device 20 and the I / O device 21 is similar to the communication process between the computing device 10 and the I / O device 11 in the foregoing Figure 1 For the sake of simplicity of the specification, it will not be elaborated here.
[0230] In some possible implementation manners, the computing device 20 includes a regular open environment REE 210 and a trusted execution environment TEE 220. The hardware occupied by the computing resources of the regular open environment REE 210 (i.e., Figure 4 the hardware 230 in it) and the hardware occupied by the computing resources of the trusted execution environment TEE 220 (i.e., Figure 4 the hardware 240 in it) are isolated from each other. The regular open environment REE 210 and the trusted execution environment TEE 220 will be introduced separately below.
[0231] (I) Regular open environment REE 210
[0232] The regular open environment REE 210 includes a first VM 211, a first REE buffer 212, a second VM 213, a second REE buffer 214, a shadow buffer 215, and a control module 216. Among them, the functions of the first VM 211, the first REE buffer 212, the second VM 213, and the second REE buffer 214 are respectively similar to the functions of the first VM 111, the first REE buffer 112, the second VM 113, and the second REE buffer 114 in the regular open environment REE 110 of the computing device 10 in the foregoing Figure 1 For the sake of simplicity of the specification, it will not be elaborated here. The functions of the shadow buffer 215 and the control module 216 will be described below.
[0233] (1) Shadow buffer 215
[0234] The shadow buffer 215 can be set in the internal memory and / or external memory allocated by the computing device 20 for the regular open environment REE 210, and is used to store the status information of the I / O devices accessible to the first CVM 221, and the status information of the I / O devices accessible to the second CVM 223.
[0235] The shadow buffer 215 can be implemented by software or by hardware. As an example of software implementation, the shadow buffer 215 can be implemented by code running on a computing instance in the regular open environment REE 210. As an example, the computing instance can be a confidential virtual machine and / or a container. As an example of hardware implementation, the shadow buffer 215 can be implemented by hardware such as a memory chip, a cache chip, etc. allocated by the computing device 20 for the regular open environment REE 210.
[0236] (2) Control module 216
[0237] The control module 216 can be implemented by software or by hardware. As an example of software implementation, the control module 216 can be implemented by code running on a computing instance in the regular open environment REE 210. Among them, the computing instance can be a virtual machine and / or a container. Further, the computing instance can be one or more. For example, the control module 216 can include code running on multiple virtual machines / containers. It should be noted that the multiple virtual machines / containers for running this code can be distributed in the same region or in different regions. As an example of hardware implementation, the control module 216 can be implemented by hardware such as a circuit, a memory chip, a cache chip, etc. allocated by the computing device 20 for the regular open environment REE 210.
[0238] (2) Trusted Execution Environment TEE 220
[0239] The Trusted Execution Environment TEE 220 includes a first CVM 221, a first TEE buffer 222, a second CVM 223, a second TEE buffer 224, and a communication interface 225. Among them, the functions of the first CVM 221, the first TEE buffer 222, the second CVM 223, the second TEE buffer 224, and the communication interface 225 are respectively similar to those of the first CVM 121, the first TEE buffer 122, the second CVM 123, the second TEE buffer 124, and the communication interface 125 in the Trusted Execution Environment TEE120 in the computing device 10 described above. For the sake of simplicity of the specification, no further elaboration will be given here. Figure 1 in the Trusted Execution Environment TEE120 in the computing device 10 described above. For the sake of simplicity of the specification, no further elaboration will be given here.
[0240] It should be understood that the above (i) general open environment REE 210 to (ii) trusted execution environment TEE 220 are described by taking Figure 4 a computing device 20 including one REE and one TEE as an example. In practical applications, the number of REEs and TEEs can both be one or more, and the present application does not make specific limitations.
[0241] Based on the architecture of the computing device described above Figure 4 below, another method for a CVM to operate on an I / O device provided by an embodiment of the present application will be specifically introduced.
[0242] Refer to Figure 5 , Figure 5 which is a schematic flowchart of another method for a CVM to operate on an I / O device provided by an embodiment of the present application. This method for a CVM to operate on an I / O device can improve the stability of sharing status information of the I / O device between the REE and the TEE. As Figure 5 shown, the method for a CVM to operate on an I / O device according to an embodiment of the present application includes:
[0243] S501: A first CVM or a first I / O device sends a first I / O request to a communication interface. Correspondingly, the communication interface receives the first I / O request from the first CVM or the first I / O device.
[0244] Among them, the first I / O request is used to instruct the first CVM to perform a first I / O operation on the first I / O device. The first I / O operation includes reading data from the first I / O device and transmitting the data to an application or a virtual processor in the first CVM, and sending the data in the application or the virtual processor in the first CVM to the first I / O device, etc.
[0245] Among them, the first CVM can be Figure 4 the first CVM 221 in the computing device 20. The first I / O device can be Figure 4 one of the I / O devices 21. The communication interface can be Figure 4 the communication interface 225 in the computing device 20.
[0246] S502: The communication interface determines whether the modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer.
[0247] The modification time of the status information of the first I / O device can be part of the metadata of the status information of the first I / O device. Among them, the metadata is data that describes the status information, including the creation time, access permission, storage location, etc. of the status information. The metadata is stored in the operating system or the file system. Specifically, the modification time of the status information of the first I / O device in the shadow buffer is stored in the operating system or the file system in the REE. The modification time of the status information of the first I / O device in the first TEE buffer is stored in the operating system or the file system in the TEE.
[0248] Therefore, the communication interface can obtain the modification time of the status information of the first I / O device in the shadow buffer from the metadata of the operating system in the REE or the metadata of the file system, and obtain the modification time of the status information of the first I / O device in the first TEE buffer from the metadata of the operating system in the TEE or the metadata of the file system.
[0249] Subsequently, the communication interface compares the modification time of the status information of the first I / O device in the shadow buffer with the modification time of the status information of the first I / O device in the first TEE buffer to determine the storage location of the status information indicating the current status of the first I / O device. There are mainly the following two situations:
[0250] Situation 1: The modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the shadow buffer is new and the status information of the first I / O device in the first TEE buffer is old. Therefore, the status information stored in the shadow buffer of the first I / O device indicates the current status of the first I / O device.
[0251] Situation 2: The modification time of the status information of the first I / O device in the shadow buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the shadow buffer is old and the status information of the first I / O device in the first TEE buffer is new. Therefore, the status information stored in the first TEE buffer of the first I / O device indicates the current status of the first I / O device.
[0252] Among them, the shadow buffer can be Figure 4 the shadow buffer 215 in the computing device 20. The first TEE buffer can be Figure 4 the first TEE buffer 222 in the computing device 20.
[0253] In the case 1 of the above step S502, go to S503; in the case 2 of the above step S502, go to S507.
[0254] S503: The communication interface reads the status information of the first I / O device from the first REE buffer from the shadow buffer.
[0255] In some possible implementation manners, before the communication interface reads the status information of the first I / O device from the first REE buffer from the shadow buffer, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer, so that the shadow buffer stores the status information of the first I / O device from the first REE buffer. Wherein, the status information of the first I / O device in the first REE buffer indicates the current status of the first I / O device.
[0256] Specifically, when the first VM obtains the operation permission of the first I / O device, the first VM writes the status information indicating that the current status of the first I / O device is the occupied status into the first REE buffer. Subsequently, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer. When the first VM releases the first I / O device, the first VM writes the status information indicating that the current status of the first I / O device is the idle status into the first REE buffer. Subsequently, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer. Therefore, the modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first REE buffer.
[0257] In some possible implementation manners, the above-mentioned first VM may write the status information of the first I / O device in the first REE buffer into the shadow buffer in a way of overwriting write, append write, insert write, etc. It should be understood that the implementation manner of the first VM writing the status information of the first I / O device in the first REE buffer into the shadow buffer is similar to the implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 described above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 The implementation manner of writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 described above is similar, and for the sake of simplicity of the specification, it will not be elaborated here.
[0258] After the shadow buffer stores the status information of the first I / O device from the first REE buffer, since the shadow buffer is set in the REE, and the data in the REE can not only be used inside the REE, but also be shared with the TEE, therefore, the communication interface in the TEE can read the status information of the first I / O device from the shadow buffer.
[0259] Wherein, the above-mentioned first REE buffer may be Figure 4 the first REE buffer 212 in the computing device 20 described above. The first VM may be Figure 4The first VM 211 in the computing device 20.
[0260] S504: The communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0261] In some possible implementation manners, the communication interface may write the status information of the first I / O device in the shadow buffer into the first TEE buffer by means of overwriting write, append write, insert write, etc. It should be understood that the implementation manner of the communication interface writing the status information of the first I / O device in the shadow buffer into the first TEE buffer is similar to the Figure 2 implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 above. For the sake of simplicity of the specification, it will not be elaborated here.
[0262] Since the status information of the first I / O device in the shadow buffer is replaced by the status information of the first I / O device in the first REE buffer, therefore, after the communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer, the status information of the first I / O device in the first TEE buffer is also replaced by the status information of the first I / O device in the first REE buffer.
[0263] S505: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0264] In some possible implementation manners, when the first CVM reads the status information of the first I / O device from the first TEE buffer to obtain the current status of the first I / O device, it mainly includes the following two situations:
[0265] Situation 1: The current status of the first I / O device is the idle status;
[0266] Situation 2: The current status of the first I / O device is the occupied status.
[0267] In some possible implementation manners, different values may be used to represent different statuses of the first I / O device, that is, different values correspond to different situations in step S505 above. It should be understood that this is similar to Figure 2 using different values to represent different statuses of the first I / O device in step S205 above. For the sake of simplicity of the specification, it will not be elaborated here.
[0268] In some possible implementation manners, before the foregoing first CVM reads the status information of the first I / O device from the first TEE buffer, a read operation of the first TEE buffer by the first CVM is triggered. It should be understood that the implementation manner of triggering the first CVM to perform the read operation on the first TEE buffer is similar to the implementation manner of triggering the first CVM to perform the read operation on the first TEE buffer in step S205 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 The implementation manner in which the read operation of the first TEE buffer by the first CVM is triggered in step S205 above is similar, and for the sake of simplicity of the specification, it will not be elaborated here.
[0269] S506: The first CVM performs an operation on the first I / O device according to the status information of the first I / O device.
[0270] It should be understood that the operation performed by the first CVM in case 1 of step S505 above is similar to the first operation in step S206 above; the operation performed by the first CVM in case 2 of step S505 above is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 The implementation manner in which the read operation of the first TEE buffer by the first CVM is triggered in step S205 above is similar, and for the sake of simplicity of the specification, it will not be elaborated here. Figure 2 The operation performed by the first CVM in case 2 of step S505 above is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here.
[0271] S507: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0272] Since the first TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the first I / O device from the first TEE buffer.
[0273] S508: The communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer, so that the shadow buffer stores the status information of the first I / O device.
[0274] In some possible implementation manners, the communication interface can write the status information of the first I / O device in the first TEE buffer into the shadow buffer in a way such as overwrite write, append write, insert write, etc. It should be understood that the implementation manner of the communication interface writing the status information of the first I / O device in the first TEE buffer into the shadow buffer is similar to the implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 The implementation manner in which the communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer is similar to the implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 above. For the sake of simplicity of the specification, it will not be elaborated here.
[0275] In some possible implementation manners, the communication interface has a higher operation permission for the shadow buffer than the first VM. In the case of a conflict in the operations of the communication interface and the first VM on the shadow buffer, the communication interface performs the operation on the shadow buffer. There are at least the following two implementation manners:
[0276] In a specific implementation manner, when the communication interface operates on the shadow buffer, the access of the first VM is refused.
[0277] As an example, a termination instruction is used to refuse the access of the first VM. In the case where the communication interface and the first VM simultaneously perform write operations on the shadow buffer, the communication interface performs the write operation on the shadow buffer. The communication interface can send a termination instruction to the first VM. The termination instruction is used to immediately abort the write operation of the first VM on the shadow buffer.
[0278] As another example, a mutex is used to refuse the access of the first VM. During the process of the communication interface performing a write operation on the shadow buffer, the shadow buffer is locked using the mutex to prevent the first VM from performing a write operation on the shadow buffer. Since the first VM does not obtain the mutex, the first VM cannot perform a write operation on the shadow buffer.
[0279] As another example, only the access of the first VM to a part of the shadow buffer is refused. In the case where the communication interface and the first VM simultaneously perform write operations on the same position in the shadow buffer, the communication interface performs the write operation on that position in the shadow buffer. The communication interface can use methods such as a termination instruction and a mutex to refuse the access of the first VM to that position in the shadow buffer.
[0280] In another specific implementation manner, when the first VM operates on the shadow buffer, the access of the communication interface is allowed.
[0281] As an example, an interrupt signal is used to implement the access of the communication interface. During the process of the first VM performing a write operation on the shadow buffer, the communication interface sends a second interrupt signal to the first VM. The second interrupt signal is used to abort the write operation of the first VM on the shadow buffer. Subsequently, the communication interface performs the write operation on the shadow buffer. After the communication interface completes the write operation, the first VM continues to perform the write operation on the shadow buffer.
[0282] As another example, a cancellation instruction is used to implement the access of the communication interface. During the process of the first VM performing a write operation on the shadow buffer, the communication interface sends a cancellation instruction to the first VM. The cancellation instruction is used to stop the write operation of the first VM on the shadow buffer. Subsequently, the communication interface performs the write operation on the shadow buffer.
[0283] It should be understood that the above two implementation manners are merely examples and are not specifically limited herein. In practical applications, any implementation manner that enables the communication interface to have a higher operation permission for the shadow buffer than the first VM for the shadow buffer falls within the protection scope of this application.
[0284] S509: The control module reads the status information of the first I / O device from the first TEE buffer from the shadow buffer.
[0285] Since the shadow buffer is set in the REE and the data in the REE can be used within the REE, the control interface in the REE can read the status information of the first I / O device from the shadow buffer. Among them, the above control module can be Figure 4 the control module 216 in the computing device 20 in
[0286] S510: The control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0287] In some possible implementation manners, the communication interface can write the status information of the first I / O device in the shadow buffer into the first REE buffer by means of overwrite writing, append writing, insert writing, etc. It should be understood that the implementation manner in which the control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer is similar to the Figure 2 implementation manner in which the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 above. For the sake of simplicity of the specification, it will not be elaborated herein.
[0288] Since the status information of the first I / O device in the shadow buffer is replaced by the status information of the first I / O device in the first TEE buffer, after the control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer, the status information of the first I / O device in the first REE buffer is also replaced by the status information of the first I / O device in the first TEE buffer.
[0289] In some possible implementation manners, the control module and the first VM have the same operation permission for the first REE buffer. At least the following two implementation manners are included:
[0290] In a specific implementation manner, when the control module operates on the first REE buffer, the access of the first VM is refused.
[0291] As an example, a mutex is used to deny access to the first VM. During the process of the control module performing a write operation on the first REE buffer, the first REE buffer is locked using the mutex to prevent the first VM from performing a write operation on the first REE buffer. Since the first VM does not obtain the mutex, the first VM cannot perform a write operation on the first REE buffer.
[0292] As another example, a flag bit is used to deny access to the first VM. During the process of the control module performing a write operation on the first REE buffer, the control module sets the flag bit of the first REE buffer to a first value, indicating that the first REE buffer is being occupied. Before accessing the first REE buffer, the first VM confirms the flag bit. When the flag bit is the first value, the first VM is not allowed to access the first REE buffer.
[0293] In another specific implementation manner, when the first VM operates on the first REE buffer, access to the control module is denied.
[0294] As an example, a flag bit is used to deny access to the control module. During the process of the first VM performing a write operation on the first REE buffer, the first VM sets the flag bit of the first REE buffer to a first value, indicating that the first REE buffer is being operated on. Before accessing the first REE buffer, the control module confirms the flag bit. When the flag bit is the first value, the control module is not allowed to access the first REE buffer.
[0295] As another example, a semaphore is used to deny access to the control module. During the process of the first VM performing a write operation on the first REE buffer, the first VM sets the semaphore of the first REE buffer to a second value, indicating that the first REE buffer is unavailable. Before accessing the first REE buffer, the control module confirms the semaphore. When the semaphore is the second value, the control module is not allowed to access the first REE buffer.
[0296] It should be understood that the above two implementation manners are only examples and are not specifically limited here. In practical applications, any implementation manner that can make the operation permissions of the control module and the first VM for the first REE buffer the same is within the protection scope of this application.
[0297] S511: The first VM reads the status information of the first I / O device from the first REE buffer.
[0298] In some possible implementation manners, when the first VM reads the status information of the first I / O device from the first REE buffer to obtain the current status of the first I / O device, there are mainly the following two situations:
[0299] Case 1: The current state of the first I / O device is the idle state;
[0300] Case 2: The current state of the first I / O device is the occupied state.
[0301] In some possible implementation manners, before the first VM reads the status information of the first I / O device from the first REE buffer, a read operation of the first VM on the first REE buffer is triggered. It should be understood that the implementation manner of triggering the first VM to read the first REE buffer is similar to the implementation manner of triggering the first VM to read the first REE buffer in step S209 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 In step S209 above, for the sake of simplicity of the specification, it will not be elaborated here.
[0302] S512: The first VM performs an operation on the first I / O device according to the status information of the first I / O device.
[0303] It should be understood that the operation performed by the first VM in Case 1 of the above step S511 is similar to the first operation in step S206 above; the operation performed by the first VM in Case 2 of the above step S511 is similar to the first operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 In step S206 above, for the sake of simplicity of the specification, it will not be elaborated here. Figure 2 In step S206 above, for the sake of simplicity of the specification, it will not be elaborated here.
[0304] In summary, when the first CVM in the TEE needs to establish a communication connection with the first I / O device to complete the first I / O request, the communication interface in the TEE is used to synchronize the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first REE buffer and the first TEE is the same, achieving the effect that the status information of the first I / O device is consistent in the REE and the TEE. Therefore, the first CVM can perform an operation on the first I / O device according to the current state of the first I / O device, which can avoid conflicts with the use of the first I / O device by the VM in the REE.
[0305] Further, in the process of sharing the usage of the first I / O device by the first CVM in the TEE (i.e., the status information of the first I / O device) with the first VM in the REE, first, the communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer in the REE, and then the control module with the same operation permission as the first VM writes the status information of the first I / O device in the shadow buffer into the first REE buffer. When the first REE buffer is not being operated, the control module can directly write the status information of the first I / O device in the shadow buffer into the first REE buffer; when the first REE buffer is being operated by the first VM, the control module waits for the first VM to complete the operation and then writes the status information of the first I / O device in the shadow buffer into the first REE buffer. This can avoid operation conflicts on the first REE buffer due to the operation permission of the communication interface in the TEE being higher than that of the first VM in the REE, and further prevent the occurrence of data chaos problems in the first REE buffer, which is beneficial to improving the stability of sharing the status information of the first I / O device between the REE and the TEE.
[0306] Furthermore, since the status information of the first I / O device is transmitted in this technical solution, the security and privacy of data calculation in the TEE can still be ensured.
[0307] The foregoing Figure 5 method for the CVM to operate on the I / O device is applicable to the scenario of synchronizing the status information of an I / O device. Based on the architecture of the computing device in the foregoing Figure 4 and the method for the CVM to operate on the I / O device in the foregoing Figure 5 below, another method for the CVM to operate on the I / O device is specifically introduced. This method for the CVM to operate on the I / O device is applicable to the scenario of synchronizing the status information of multiple I / O devices.
[0308] See Figure 6 and Figure 6 is a schematic flowchart of another method for the CVM to operate on the I / O device provided by an embodiment of the present application. As Figure 6 shown, the method for the CVM to operate on the I / O device in the embodiment of the present application includes:
[0309] S601: The first CVM or the first I / O device sends a first I / O request to the communication interface.
[0310] S602: The communication interface determines whether the modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer.
[0311] If the modification time of the status information of the first I / O device in the shadow buffer is later than that in the first TEE buffer, go to S603; if the modification time of the status information of the first I / O device in the shadow buffer is earlier than that in the first TEE buffer, go to S607.
[0312] S603: The communication interface reads the status information of the first I / O device from the first REE buffer in the shadow buffer.
[0313] S604: The communication interface writes the status information of the first I / O device in the shadow buffer to the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0314] S605: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0315] S606: The first CVM performs an operation on the first I / O device according to the status information of the first I / O device.
[0316] S607: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0317] S608: The communication interface writes the status information of the first I / O device in the first TEE buffer to the shadow buffer, so that the shadow buffer stores the status information of the first I / O device.
[0318] S609: The control module reads the status information of the first I / O device from the first TEE buffer in the shadow buffer.
[0319] S610: The control module writes the status information of the first I / O device in the shadow buffer to the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby realizing the synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0320] S611: The first VM reads the status information of the first I / O device from the first REE buffer.
[0321] S612: The first VM performs an operation on the first I / O device according to the status information of the first I / O device.
[0322] The execution processes of the above steps S601 to S612 can refer to the execution processes of steps S501 to S512 in the foregoing Figure 5 . For the sake of simplicity of the specification, it will not be elaborated here.
[0323] S613: The second CVM or the second I / O device sends a second I / O request to the communication interface. Correspondingly, the communication interface receives the second I / O request from the second CVM or the second I / O device.
[0324] Among them, the second I / O request is used to instruct the second CVM to perform a second I / O operation on the second I / O device. The second I / O operation includes reading data from the second I / O device and transmitting the data to an application or a virtual processor in the second CVM, and sending the data in the application or the virtual processor in the second CVM to the second I / O device, etc.
[0325] Among them, the second CVM can be Figure 4 the second CVM 223 in the computing device 20 in Figure 4 . The second I / O device can be
[0326] one of the I / O devices 21 in
[0327] S614: The communication interface determines whether the modification time of the status information of the second I / O device in the shadow buffer is later than the modification time of the status information of the second I / O device in the second TEE buffer.
[0328] The modification time of the status information of the second I / O device can be a part of the metadata of the status information of the second I / O device. Among them, the metadata is data describing the status information, including the creation time, access permission, storage location, etc. of the status information. The metadata is stored in the operating system or the file system. Specifically, the modification time of the status information of the second I / O device in the shadow buffer is stored in the operating system or the file system in the REE. The modification time of the status information of the second I / O device in the second TEE buffer is stored in the operating system or the file system in the TEE.
[0329] Subsequently, the communication interface compares the modification time of the status information of the second I / O device in the shadow buffer with the modification time of the status information of the second I / O device in the second TEE buffer to determine the storage location of the status information indicating the current status of the second I / O device. There are mainly the following two cases:
[0330] Case 1: The modification time of the status information of the second I / O device in the shadow buffer is later than the modification time of the status information of the second I / O device in the second TEE buffer, indicating that the status information of the second I / O device in the shadow buffer is new and the status information of the second I / O device in the second TEE buffer is old. Therefore, the status information of the second I / O device stored in the shadow buffer indicates the current status of the second I / O device.
[0331] Case 2: The modification time of the status information of the second I / O device in the shadow buffer is earlier than the modification time of the status information of the second I / O device in the second TEE buffer, indicating that the status information of the second I / O device in the shadow buffer is old and the status information of the second I / O device in the second TEE buffer is new. Therefore, the status information of the second I / O device stored in the second TEE buffer indicates the current status of the second I / O device.
[0332] Among them, the second TEE buffer can be Figure 4 the second TEE buffer 224 in the computing device 20 in
[0333] In case 1 of step S614 above, go to S615; in case 2 of step S614 above, go to S619.
[0334] S615: The communication interface reads the status information of the second I / O device from the second REE buffer from the shadow buffer.
[0335] In some possible implementation manners, before the communication interface reads the status information of the second I / O device from the second REE buffer from the shadow buffer, the second VM writes the status information of the second I / O device in the second REE buffer into the shadow buffer, so that the shadow buffer stores the status information of the second I / O device from the second REE buffer. Among them, the status information of the second I / O device in the second REE buffer indicates the current status of the second I / O device.
[0336] Specifically, when the second VM obtains the operation permission of the second I / O device, the second VM writes the status information indicating that the current status of the second I / O device is the occupied status into the second REE buffer. Subsequently, the second VM writes the status information of the second I / O device in the second REE buffer into the shadow buffer. When the second VM releases the second I / O device, the second VM writes the status information indicating that the current status of the second I / O device is the idle status into the second REE buffer. Subsequently, the second VM writes the status information of the second I / O device in the second REE buffer into the shadow buffer. Therefore, the modification time of the status information of the second I / O device in the shadow buffer is later than the modification time of the status information of the second I / O device in the second REE buffer.
[0337] In some possible implementation manners, the above-mentioned second VM may write the status information of the second I / O device in the second REE buffer into the shadow buffer by means of overwriting write, append write, insert write, etc. It should be understood that the implementation manner of the second VM writing the status information of the second I / O device in the second REE buffer into the shadow buffer is similar to the implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 described above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 in step S204, and will not be elaborated here for the sake of simplicity of the specification.
[0338] After the status information of the second I / O device from the second REE buffer is stored in the shadow buffer, since the shadow buffer is set in the REE, and the data in the REE can not only be used inside the REE, but also be shared with the TEE, therefore, the communication interface in the TEE can read the status information of the second I / O device from the shadow buffer.
[0339] Among them, the above-mentioned second REE buffer may be Figure 4 the second REE buffer 214 in the computing device 20 described above. The second VM may be Figure 4 the second VM 213 in the computing device 20 described above.
[0340] S616: The communication interface writes the status information of the second I / O device in the shadow buffer into the second TEE buffer, so that the status information of the second I / O device in the second TEE buffer is replaced with the status information of the second I / O device in the second REE buffer, thereby realizing the synchronization of the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer.
[0341] In some possible implementation manners, the communication interface may write the status information of the second I / O device in the shadow buffer into the second TEE buffer by means of overwrite writing, append writing, insert writing, etc. It should be understood that the implementation manner in which the communication interface writes the status information of the second I / O device in the shadow buffer into the second TEE buffer is similar to the implementation manner in the foregoing Figure 2 in step S204 where the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer. For the sake of simplicity of the specification, it will not be elaborated herein.
[0342] Since the status information of the second I / O device in the shadow buffer is replaced by the status information of the second I / O device in the second REE buffer, after the communication interface writes the status information of the second I / O device in the shadow buffer into the second TEE buffer, the status information of the second I / O device in the second TEE buffer is also replaced by the status information of the second I / O device in the second REE buffer.
[0343] S617: The second CVM reads the status information of the second I / O device from the second TEE buffer.
[0344] In some possible implementation manners, when the second CVM reads the status information of the second I / O device from the second TEE buffer to obtain the current status of the second I / O device, it mainly includes the following two cases:
[0345] Case 1: The current status of the second I / O device is the idle state;
[0346] Case 2: The current status of the second I / O device is the occupied state.
[0347] In some possible implementation manners, different values may be used to represent different statuses of the second I / O device, that is, different values correspond to different cases in the foregoing step S617. It should be understood that this is similar to using different values to represent different statuses of the first I / O device in step S205 in the foregoing Figure 2 For the sake of simplicity of the specification, it will not be elaborated herein.
[0348] In some possible implementation manners, before the second CVM reads the status information of the second I / O device from the second TEE buffer, a read operation of the second CVM on the second TEE buffer is triggered. It should be understood that the implementation manner of triggering the read operation of the second CVM on the second TEE buffer is similar to the implementation manner of triggering the read operation of the first CVM on the first TEE buffer in step S205 in the foregoing Figure 2 For the sake of simplicity of the specification, it will not be elaborated herein.
[0349] S618: The second CVM performs an operation on the second I / O device according to the status information of the second I / O device.
[0350] It should be understood that the operation performed by the second CVM in case 1 of the above step S617 is similar to the first operation in step S206 above; the operation performed by the second CVM in case 2 of the above step S617 is similar to the second operation in step S206 above. For the sake of brevity of the specification, it will not be elaborated here. Figure 2 in step S206 above; the operation performed by the second CVM in case 2 of the above step S617 is similar to the second operation in step S206 above. For the sake of brevity of the specification, it will not be elaborated here. Figure 2 in step S206 above. For the sake of brevity of the specification, it will not be elaborated here.
[0351] S619: The communication interface reads the status information of the second I / O device from the second TEE buffer.
[0352] Since the second TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the second I / O device from the second TEE buffer.
[0353] S620: The communication interface writes the status information of the second I / O device in the second TEE buffer into the shadow buffer, so that the shadow buffer stores the status information of the second I / O device.
[0354] In some possible implementation manners, the communication interface may write the status information of the second I / O device in the second TEE buffer into the shadow buffer in a covering write, append write, insert write, etc. manner. It should be understood that the implementation manner of the communication interface writing the status information of the second I / O device in the second TEE buffer into the shadow buffer is similar to the implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 above. For the sake of brevity of the specification, it will not be elaborated here. Figure 2 in step S204 above. For the sake of brevity of the specification, it will not be elaborated here.
[0355] In some possible implementation manners, the operation permission of the communication interface for the shadow buffer is higher than that of the second VM for the shadow buffer. In the case of a conflict between the operations of the communication interface and the second VM on the shadow buffer, the communication interface performs the operation on the shadow buffer. In a specific implementation manner, when the communication interface operates on the shadow buffer, the access of the second VM is denied. In another specific implementation manner, when the second VM operates on the shadow buffer, the access of the communication interface is allowed.
[0356] S621: The control module reads the status information of the second I / O device from the second TEE buffer from the shadow buffer.
[0357] Since the shadow buffer is set in the REE and the data in the REE can be used within the REE, the control interface in the REE can read the status information of the second I / O device from the shadow buffer.
[0358] S622: The control module writes the status information of the second I / O device in the shadow buffer into the second REE buffer, so that the status information of the second I / O device in the second REE buffer is replaced by the status information of the second I / O device in the second TEE buffer, thereby realizing the synchronization of the status information of the second I / O device in the second REE buffer and the status information of the second I / O device in the second TEE buffer.
[0359] In some possible implementation manners, the communication interface can write the status information of the second I / O device in the shadow buffer into the second REE buffer in manners such as overwrite writing, append writing, insert writing, etc. It should be understood that the implementation manner of the control module writing the status information of the second I / O device in the shadow buffer into the second REE buffer is similar to the implementation manner of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 described above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 In the description, for the sake of simplicity, it will not be elaborated here.
[0360] Since the status information of the second I / O device in the shadow buffer is replaced by the status information of the second I / O device in the second TEE buffer, after the control module writes the status information of the second I / O device in the shadow buffer into the second REE buffer, the status information of the second I / O device in the second REE buffer is also replaced by the status information of the second I / O device in the second TEE buffer.
[0361] In some possible implementation manners, the control module and the second VM have the same operation permissions for the second REE buffer. In a specific implementation manner, when the control module operates the second REE buffer, the access of the second VM is refused. In another specific implementation manner, when the second VM operates the second REE buffer, the access of the control module is refused.
[0362] S623: The second VM reads the status information of the second I / O device from the second REE buffer.
[0363] In some possible implementation manners, when the second VM reads the status information of the second I / O device from the second REE buffer to obtain the current status of the second I / O device, there are mainly the following two cases:
[0364] Case 1: The current status of the second I / O device is the idle state;
[0365] Case 2: The current state of the second I / O device is the occupied state.
[0366] In some possible implementation manners, before the second VM reads the status information of the second I / O device from the second REE buffer, a read operation of the second REE buffer by the second VM is triggered. It should be understood that the implementation manner of triggering the second VM to read the second REE buffer is similar to the implementation manner of triggering the first VM to read the first REE buffer in step S209 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 In the above, the implementation manner of triggering the first VM to read the first REE buffer in step S209 is similar. For the sake of simplicity of the specification, it will not be elaborated here.
[0367] S624: The second VM performs an operation on the second I / O device according to the status information of the second I / O device.
[0368] It should be understood that the operation performed by the second VM in Case 1 of step S623 above is similar to the first operation in step S206 above; the operation performed by the second VM in Case 2 of step S623 above is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 In the above, the operation performed by the second VM in Case 1 of step S623 is similar to the first operation in step S206 above; the operation performed by the second VM in Case 2 of step S623 is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here. Figure 2 In the above, the operation performed by the second VM in Case 2 of step S623 is similar to the second operation in step S206 above. For the sake of simplicity of the specification, it will not be elaborated here.
[0369] It should be understood that this technical solution can first execute the above steps S601 to S612, and then execute the above steps S613 to S624; or first execute the above steps S613 to S624, and then execute the above steps S601 to S612; or cross-execute the steps in the above steps S601 to S612 and the steps in the above steps S613 to S624. For example, first execute the above step S601, then execute the above step S613, then execute the above step S602, then execute the above step S614... Or first execute the above steps S613 and S614, and then execute the above steps S601 and S602...
[0370] In summary, when the CVM in the TEE needs to establish a communication connection with the I / O device to complete the I / O request, the communication interface in the TEE is used to synchronize the status information of the I / O device in the REE buffer and the status information of the I / O device in the TEE buffer, so that the status information of the I / O device in the REE buffer is the same as the status information of the I / O device in the TEE buffer, achieving the effect that the status information of the I / O device is consistent in the REE and the TEE. Therefore, the CVM can perform an operation on the I / O device according to the current state of the I / O device, which can avoid conflicts with the use of the I / O device by the VM in the REE.
[0371] Furthermore, in the process of the CVM in the TEE and the VM in the REE sharing the status information of the I / O device, the communication interface only needs to write the status information of the I / O device from the TEE into the shadow buffer in the REE all the time, or the communication interface only needs to read the status information of the I / O device from the REE from the shadow buffer in the REE all the time, without dynamically adjusting the operation object according to the access relationship of the VM in the REE to the I / O device. Such an operation is simple and reliable, and also reduces the risk of inconsistent or lost status information of the I / O device.
[0372] Furthermore, since the status information of the first I / O device is transmitted in this technical solution, the security and privacy of data calculation in the TEE can still be guaranteed.
[0373] In the above Figure 2 、 Figure 3 、 Figure 5 、 Figure 6 In the embodiments, the virtual input / output (virtIO) protocol can be used to implement the operations of the first VM in the REE on the first REE buffer and the I / O device, the operations of the second VM on the second REE buffer and the I / O device, and the operations of the first CVM in the TEE on the first TEE buffer and the I / O device, the operations of the second CVM on the second TEE buffer and the I / O device, and so on.
[0374] In the virtIO protocol, it includes front-end drivers, back-end drivers, and a virtual ring. Among them, the front-end drivers are set in virtual machines (such as VM, CVM), and the back-end drivers are set in the virtual machine monitor. The virtual ring is the communication channel between the front-end drivers and the back-end drivers.
[0375] The following takes the implementation of the operations of the first VM on the first REE buffer and the I / O device using the virtIO protocol as an example for specific introduction. Among them, the front-end driver runs in the first VM, the back-end driver runs in the virtual machine monitor, and the first REE buffer serves as the virtual ring. And the front-end driver is used to send the data generated by the first VM to the back-end driver. The back-end driver is used to receive the data sent from the front-end driver. The first REE buffer is used to implement the data transmission and communication between the front-end driver and the back-end driver.
[0376] (1) Implementing the operations of the first VM on the first REE buffer using the virtIO protocol
[0377] The front-end driver encapsulates the data packets generated by the first VM into descriptors and writes the descriptors into the first REE buffer. The back-end driver reads the descriptors from the first REE buffer and obtains the data packets according to the descriptors.
[0378] The following takes a data packet carrying the status information of the I / O device as an example of the data packet for specific introduction.
[0379] When the first VM generates a data packet carrying the status information of the I / O device, the front-end driver encapsulates the data packet carrying the status information of the I / O device into a descriptor and writes the descriptor into the first REE buffer. The back-end driver reads the descriptor from the first REE buffer, obtains the data packet carrying the status information of the I / O device according to the descriptor, and further obtains the current status of the I / O device.
[0380] It should be understood that the above data packet carrying the status information of the I / O device is only taken as an example and is not specifically limited here. In actual applications, the data packet can also carry other information, and the descriptor stored in the first REE buffer can be used to indicate the data packet carrying other information.
[0381] (2) Implement the operation of the first VM on the I / O device using the virtIO protocol
[0382] The front-end driver is used to send I / O requests to the back-end driver. The back-end driver is used to receive the I / O requests from the front-end driver, send the I / O requests to the corresponding I / O device, so that the I / O device performs I / O operations. The first REE buffer is used to implement the transmission and communication of I / O requests between the front-end driver and the back-end driver.
[0383] Specifically, when the first VM generates a data packet carrying an I / O request, the front-end driver encapsulates the data packet carrying the I / O request into a descriptor and writes the descriptor into the first REE buffer. The back-end driver reads the descriptor from the first REE buffer, obtains the data packet carrying the I / O request according to the descriptor, and further sends the data packet carrying the I / O request to the corresponding I / O device.
[0384] After receiving the data packet, the I / O device completes the corresponding I / O operation according to the I / O request and sends the data packet carrying the I / O request result to the back-end driver.
[0385] The backend driver sends an interrupt signal or notification to the frontend driver, encapsulates the data packet carrying the I / O request result into a descriptor, and writes the descriptor into the first REE buffer. After receiving the interrupt signal or notification, the frontend driver reads the descriptor from the first REE buffer, obtains the data packet carrying the I / O request result according to the descriptor, and then sends the data packet carrying the I / O request result to the application or virtual processor in the first VM, so that the application or virtual processor in the first VM can timely know the completion status of the I / O operation. Among them, the virtual processor in the first VM is the processor occupied by the first VM in the REE.
[0386] Due to the wide use of the virtIO protocol, adopting the virtIO protocol in this technical solution can reduce the compatibility problems caused by cross-platform, and greatly improve the development efficiency.
[0387] See Figure 7 , Figure 7 is a schematic structural diagram of a computing device provided by an embodiment of the present application. As Figure 7 shown, the computing device 700 provided by the present application includes: a bus 701, a processor 702, a memory 703, and a communication interface 704. The processor 702, the memory 703, and the communication interface 704 communicate with each other through the bus 701. The computing device 700 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the computing device 700.
[0388] The bus 701 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 7 only one line is shown in, but it does not mean that there is only one bus or one type of bus. The bus 701 can include a path for transmitting information between various components (for example, the memory 703, the processor 702, the communication interface 704) of the computing device 700.
[0389] The processor 702 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.
[0390] The memory 703 may include volatile memory, such as random access memory (RAM). The memory 703 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0391] The executable program code is stored in the memory 703, and the processor 702 executes the executable program code to implement the method for the CVM in the foregoing Figure 2 to perform operations on the I / O device, or to implement the method for the CVM in the foregoing Figure 3 to perform operations on the I / O device, or to implement the method for the CVM in the foregoing Figure 5 to perform operations on the I / O device, or to implement the method for the CVM in the foregoing Figure 6 to perform operations on the I / O device. That is, the memory 703 stores instructions for executing the method for the CVM to perform operations on the I / O device.
[0392] The communication interface 704 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 700 and other computing devices or communication networks.
[0393] The embodiment of the present application also provides a computer program product containing instructions. The computer program product may be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on a computing device, it causes the computing device to execute the method for the CVM in the foregoing Figure 2 to perform operations on the I / O device, or to execute the method for the CVM in the foregoing Figure 3 to perform operations on the I / O device, or to execute the method for the CVM in the foregoing Figure 5 to perform operations on the I / O device, or to execute the method for the CVM in the foregoing Figure 6 to perform operations on the I / O device.
[0394] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium may be any available medium that can be stored by a computing device or a data storage device such as a data center containing one or more available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state drive), etc. The computer-readable storage medium includes instructions that direct the computing device to execute the foregoingFigure 2 The method in which the CVM in Figure 3 performs an operation on the I / O device, or, performs the foregoing Figure 5 The method in which the CVM in Figure 6 performs an operation on the I / O device, or, performs the foregoing
[0395] It should be understood that in the embodiments of the present invention, both "when..." and "if" refer to the device making corresponding processing under a certain objective situation, which does not limit the time, and does not require the device to have a judgment action when implemented, nor does it mean that there are other limitations.
[0396] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for a confidential virtual machine CVM to perform operations on an input / output I / O device, characterized in that, Applied to a computing device, the computing device includes a regular open environment REE and a trusted execution environment TEE. The hardware occupied by the computing resources of the REE is isolated from the hardware occupied by the computing resources of the TEE. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM runs based on the computing resources of the TEE. The REE includes a first REE buffer. The method includes: The communication interface receives a first I / O request, where the first I / O request is used to instruct the first CVM to perform a first I / O operation on a first I / O device; The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, where the status information of the first I / O device is used to indicate that the status of the first I / O device is an idle state or an occupied state; The first CVM performs an operation on the first I / O device according to the synchronized status information of the first I / O device in the first TEE buffer, where the synchronized status information of the first I / O device in the first TEE buffer is used to indicate the current status of the first I / O device.
2. The method according to claim 1, wherein The REE further includes a shadow buffer, which is used to store the status information of the first I / O device. The status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device. The communication interface synchronizing the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer includes: The communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
3. The method according to claim 2, wherein The REE further includes a first virtual machine VM, and the first VM runs based on the computing resources of the REE. Before the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, the method further includes: When the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer; The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer by using the status information of the first I / O device in the shadow buffer, including: The communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer, obtaining the status information of the first I / O device in the synchronized first TEE buffer; Among them, the operation permission of the communication interface for the shadow buffer is higher than the operation permission of the first VM for the shadow buffer.
4. The method according to claim 2, wherein The REE further includes a control module, The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer by using the status information of the first I / O device in the shadow buffer, including: When the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, the communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer; The method further includes: The control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer, obtaining the status information of the first I / O device in the synchronized first REE buffer, where the status information of the first I / O device in the synchronized first REE buffer is used to indicate the current status of the first I / O device.
5. The method according to any one of claims 1-4, characterized in that, The TEE further includes a second CVM and a second TEE buffer, the second CVM runs based on the computing resources of the TEE, the REE further includes a second REE buffer, and the method further includes: The communication interface receives a second I / O request, where the second I / O request is used to instruct the second CVM to perform a second I / O operation on a second I / O device; The communication interface synchronizes the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer, where the status information of the second I / O device is used to indicate that the status of the second I / O device is an idle state or an occupied state; The second CVM performs an operation on the second I / O device according to the status information of the second I / O device in the synchronized second TEE buffer, where the status information of the second I / O device in the synchronized second TEE buffer is used to indicate the current status of the second I / O device.
6. The method according to claim 3, wherein When the shadow buffer is operated by the communication interface, access by the first VM is refused; or, When the shadow buffer is operated by the first VM, access to the communication interface is allowed.
7. A computing device, characterized in that, It includes a regular open environment REE and a trusted execution environment TEE. The hardware occupied by the computing resources of the REE is isolated from the hardware occupied by the computing resources of the TEE. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM runs based on the computing resources of the TEE. The REE includes a first REE buffer. The communication interface is used to receive a first I / O request, where the first I / O request is used to instruct the first CVM to perform a first I / O operation on a first I / O device. The communication interface is also used to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, where the status information of the first I / O device is used to indicate that the status of the first I / O device is an idle state or an occupied state. The first CVM is used to perform an operation on the first I / O device according to the synchronized status information of the first I / O device in the first TEE buffer, where the synchronized status information of the first I / O device in the first TEE buffer is used to indicate the current status of the first I / O device.
8. The device according to claim 7, characterized in that, The REE further includes a shadow buffer, which is used to store the status information of the first I / O device. The status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device. Specifically, the communication interface is used to use the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
9. The device according to claim 8, characterized in that, The REE further includes a first virtual machine VM, and the first VM runs based on the computing resources of the REE. Before the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, when the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, the first VM is used to write the status information of the first I / O device in the first REE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer. Specifically, the communication interface is used to write the status information of the first I / O device in the shadow buffer into the first TEE buffer to obtain the synchronized status information of the first I / O device in the first TEE buffer. Among them, the operation permission of the communication interface for the shadow buffer is higher than that of the first VM for the shadow buffer.
10. The device according to claim 8, characterized in that, The REE further includes a control module. Specifically, the communication interface is configured to write the status information of the first I / O device in the first TEE buffer into the shadow buffer when the modification time of the status information of the first I / O device in the first REE buffer is earlier than that in the first TEE buffer, so that the status information of the first I / O device is stored in the shadow buffer. The control module is configured to write the status information of the first I / O device in the shadow buffer into the first REE buffer to obtain the status information of the first I / O device in the synchronized first REE buffer, where the status information of the first I / O device in the synchronized first REE buffer is used to indicate the current status of the first I / O device.
11. The device according to any one of claims 7 to 10, characterized in that, The TEE further includes a second CVM and a second TEE buffer. The second CVM runs based on the computing resources of the TEE. The REE further includes a second REE buffer. The communication interface is further configured to receive a second I / O request, where the second I / O request is used to instruct the second CVM to perform a second I / O operation on a second I / O device. The communication interface is further configured to synchronize the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer, where the status information of the second I / O device is used to indicate that the status of the second I / O device is an idle state or an occupied state. The second CVM is configured to perform an operation on the second I / O device according to the synchronized status information of the second I / O device in the second TEE buffer, where the synchronized status information of the second I / O device in the second TEE buffer is used to indicate the current status of the second I / O device.
12. The device according to claim 9, wherein when the shadow buffer is operated by the communication interface, access by the first VM is refused; or when the shadow buffer is operated by the first VM, access by the communication interface is allowed.
13. A computing device, characterized in that, It includes a processor and a memory. The memory is used to store instructions, and the processor is used to execute the instructions. When the processor executes the instructions, the method described in any one of claims 1 to 6 is implemented.
14. A computer program product comprising instructions, characterized in that, When the instructions are run by a computing device, the computing device executes the method described in any one of claims 1 to 6.
15. A computer-readable storage medium, characterized in that, It includes computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method described in any one of claims 1 to 6.
Citation Information
Cited By
Method for executing operation on input / output device by confidential virtual machine, and computing device
WO2025157110A1