Virtual machine monitor, secure operating system, operating method of virtual machine, apparatus, system, computer readable storage medium
By introducing middleware into the virtual machine monitor, using the storage location information of shared memory to communicate between the virtual machine and the secure operating system, the flexibility and scalability problems of multiple virtual machines in the prior art are solved, and more efficient and secure operations are achieved.
Patent Information
- Application Number
- CN202510599918.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-08-12
AI Technical Summary
The prior art lacks flexibility and scalability when supporting multiple virtual machines, resulting in poor resource waste and security, and low operational efficiency.
By introducing middleware into the virtual machine monitor, the storage location information of shared memory is used when obtaining and sending messages, communication between the virtual machine and the secure operating system is realized, data and processing results are avoided, and the secure operating system functions of multiple virtual machines are supported.
Improve the scalability, security and flexibility of virtual machine operations, reduce resource waste, and improve operational efficiency.
Smart Images

Figure CN120469767A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a method for operating a virtual machine monitor, a method for operating a secure operating system, and a method for operating a virtual machine. The present disclosure also relates to a virtual machine monitor, a secure operating system, a virtual machine, a virtual machine operating system, a computer-readable storage medium, and a computing device. Background Art
[0002] A Trusted Execution Environment (TEE) is a secure execution environment capable of running a secure operating system (Secure OS). Conventional operating systems (such as Linux, Android, or QNX) run in a so-called Rich Execution Environment (REE). The secure OS and the conventional OS in the TEE can run concurrently. Trusted services in the secure OS can provide critical security functions to the conventional OS. With the widespread adoption of virtualization technology, multiple virtual machines (VMs) are becoming increasingly common. Multiple operating systems, such as Linux and Android, can run concurrently on a hypervisor, each requiring the trusted services of the secure OS. In an Android VM, applications such as the gatekeeper, key master, and DRM (digital rights management) require trusted services from the secure OS. In a Linux VM, DRM and other applications requiring critical security functions similarly require trusted services from the secure OS.
[0003] Some related technologies can enable a secure operating system to support multiple virtual machines.
[0004] The first technique enables the secure OS to support multiple VMs by adding modules to the secure OS and hypervisor. This technique involves adding a module to the hypervisor layer to convert intermediate physical addresses (IPAs) to physical addresses (PAs) during communication between the VMs and the secure OS. A VM isolation module is then added to the secure OS to maintain VM state and address isolation. The VM isolation module needs to understand the number of VMs in the rich execution environment and allocate independent memory for each VM to manage its state and code segment.
[0005] Because the first technique only supports static configuration of the number of VMs, it lacks flexibility. Specifically, the VM isolation module in the first technique allocates memory to each VM based on the static configuration, even if some VMs are not running. This can lead to wasted resources. This technique is also specific to the secure operating system and virtual machine monitor, making it difficult to replace the secure operating system and thus lacking scalability.
[0006] The second technique enables the secure operating system to support multiple virtual machines by using front-end and back-end drivers within the virtual machines. This technique involves adding a back-end driver to a virtual machine called the system domain and adding a front-end driver to each of the other virtual machines. The other virtual machines communicate with the system domain through the front-end driver. The back-end driver in the system domain is responsible for forwarding all messages from the front-end driver to the secure operating system and completing all communications with the secure operating system.
[0007] The second technique suffers from poor scalability in both the backend and frontend drivers. Different virtual machine types (such as Linux, Android, and QNX) require different implementations for each, resulting in a lack of scalability. While the second technique does not require modifications to the secure operating system, it does involve additional data copies. Requests from the frontend driver are sent to the backend driver via a proprietary protocol, which processes these requests. This process involves repeated processing and copying of parameters and data, making the second technique less efficient. Furthermore, the second technique exposes frontend data to the backend, resulting in poor security.
[0008] The information disclosed in this background technology is technical information that the inventor already knew before the disclosure of this application, or that he or she obtained during the disclosure process. Therefore, the background technology may contain information that is not part of the prior art that is already known to the public. Summary of the Invention
[0009] An exemplary embodiment of the present disclosure is to provide an operating method and device, a system, a computer-readable storage medium, and a computing device to support the use of functions and services of a secure operating system on multiple virtual machines, thereby improving the scalability, security, and flexibility of virtual machine operations and improving the operating efficiency of virtual machines.
[0010] According to an exemplary embodiment of the present disclosure, a method for operating a virtual machine monitor is provided. The method comprises: obtaining a first message, wherein the first message is a message to be sent from a virtual machine to a secure operating system, the secure operating system being registered in a middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of the middleware, the middleware being related to the virtual machine and the secure operating system; sending the first message to the secure operating system; receiving a second message from the secure operating system, wherein the second message is based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, the second storage location information being related to a second location in the memory of the middleware; and sending the second message to the virtual machine.
[0011] Optionally, obtaining the first message may include: obtaining one or more transmission messages transmitted by the virtual machine through one or more calling instructions; determining the message with the destination being the secure operating system in the one or more transmission messages as the target transmission message; and determining the first message based on the target transmission message.
[0012] Optionally, the first message may further include a virtual machine flag, where the virtual machine flag may indicate a first virtual machine corresponding to the first message, wherein the second message may further include the virtual machine flag.
[0013] Optionally, determining the first message based on the target transmission message may include: updating a session field of the target transmission message based on the virtual machine flag; and determining the target transmission message as the first message.
[0014] Optionally, sending the first message to the secure operating system may include: converting address information in the first message into a physical address; and sending the first message to the secure operating system through a security monitor.
[0015] Optionally, sending the second message to the virtual machine may include: determining the first virtual machine indicated by the virtual machine flag in the second message; and sending the second message without the virtual machine flag to the first virtual machine.
[0016] Optionally, the first message may further include a function for the secure operating system to execute.
[0017] According to an exemplary embodiment of the present disclosure, a method for operating a secure operating system is provided. The method comprises: receiving a first message, wherein the first message is a message sent from middleware of a virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of the middleware, wherein the middleware is related to a virtual machine and the secure operating system; obtaining a second message based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, the second storage location information being related to a second location in the memory of the middleware; and sending the second message to the middleware.
[0018] Optionally, the first message may further include a virtual machine flag, where the virtual machine flag may indicate a first virtual machine corresponding to the first message, wherein the second message may further include the virtual machine flag.
[0019] Optionally, obtaining the second message may include: acquiring data related to the first message from the memory based on the first storage location information; and processing the data related to the first message.
[0020] Optionally, the first message may further include a function for the secure operating system to execute.
[0021] Optionally, obtaining the second message may include: processing data related to the first message based on the function.
[0022] According to an exemplary embodiment of the present disclosure, a method for operating a virtual machine is provided. The method comprises: transmitting a first message, wherein the first message is a message sent to a secure operating system based on a call instruction, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of a middleware, wherein the middleware is related to the virtual machine and the secure operating system; receiving a second message from the middleware, wherein the second message is obtained by the secure operating system based on the first message, wherein the second message includes second storage location information based on a result of processing the first message; and determining an operation result based on the second message.
[0023] Optionally, determining the operation result based on the second message may include: acquiring a result of processing the first message based on the second storage location information; and determining the result of the processing as the operation result.
[0024] According to an exemplary embodiment of the present disclosure, a virtual machine operating system is provided. The virtual machine operating system includes: at least one virtual machine; at least one secure operating system; a virtual machine monitor including middleware, the middleware connected to the at least one virtual machine, and wherein the at least one secure operating system is registered with the middleware; a security monitor connected to the middleware and the at least one secure operating system, wherein one or more processors in the middleware are configured to: obtain a first message, wherein the first message is a message to be sent from the at least one virtual machine to the at least one secure operating system, wherein the first message includes first storage location information of data related to the first message, the first storage location information is related to a first location in the memory of the middleware, and the middleware is related to the virtual machine and the secure operating system; send the first message to the at least one secure operating system; receive a second message from the at least one secure operating system, wherein the second message is a second message obtained by processing the first message, wherein the second message includes second storage location information based on the result of processing the first message, and the second storage location information is related to a second location in the memory of the middleware; and send the second message to the at least one virtual machine.
[0025] Optionally, the middleware may include a system page for the at least one secure operating system, wherein the system page is used to manage the status of the at least one virtual machine and the at least one secure operating system.
[0026] Optionally, the middleware may include a message ring for storing one or more transmission messages obtained from the at least one virtual machine.
[0027] Optionally, the middleware may include a memory manager, and the memory may be in the memory manager, wherein the memory is shared by the at least one virtual machine and the at least one secure operating system, and the memory manager manages the memory.
[0028] Optionally, each of the at least one secure operating system may be configured to: receive a first message sent from the middleware; obtain a second message based on the first message; and send the second message to the middleware.
[0029] Optionally, each of the at least one virtual machine can be configured to: transmit a first message using a call instruction; receive a second message from the middleware, wherein the second message is obtained by the at least one secure operating system based on the first message; and determine an operation result based on the second message.
[0030] According to an exemplary embodiment of the present disclosure, a virtual machine monitor is provided. The virtual machine monitor includes: a message acquisition unit configured to acquire a first message, wherein the first message is a message to be sent from a virtual machine to a secure operating system registered in a middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information is related to a first location in the memory of the middleware, and the middleware is related to the virtual machine and the secure operating system; a message sending unit configured to send the first message to the secure operating system; a message processing receiving unit configured to receive a second message from the secure operating system, wherein the second message is based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, and the second storage location information is related to a second location in the memory of the middleware; and a message processing sending unit configured to send the second message to the virtual machine.
[0031] Optionally, the message acquisition unit can be configured to: acquire one or more transmission messages transmitted by the virtual machine through one or more calling instructions; determine the message with the destination being the secure operating system among the one or more transmission messages as the target transmission message; and determine the first message based on the target transmission message.
[0032] Optionally, the first message may further include a virtual machine flag, where the virtual machine flag may indicate a first virtual machine corresponding to the first message, wherein the second message may further include the virtual machine flag.
[0033] Optionally, the message acquiring unit may be configured to: update a session field of the target transmission message based on the virtual machine flag; and determine the target transmission message as the first message.
[0034] Optionally, the message sending unit may be configured to: convert the address information in the first message into a physical address; and send the first message to the secure operating system through a security monitor.
[0035] Optionally, the message processing and sending unit may be configured to: determine the first virtual machine indicated by the virtual machine flag in the second message; and send the second message without the virtual machine flag to the first virtual machine.
[0036] Optionally, the first message may further include a function for the secure operating system to execute.
[0037] According to an exemplary embodiment of the present disclosure, a secure operating system is provided. The secure operating system includes: a message receiving unit configured to receive a first message, wherein the first message is a message sent from a middleware of a virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information is related to a first location in a memory of the middleware, and the middleware is related to the virtual machine and the secure operating system; a message processing unit configured to obtain a second message based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, and the second storage location information is related to a second location in the memory of the middleware; and a message sending unit configured to send the second message to the middleware.
[0038] Optionally, the first message may further include a virtual machine flag, where the virtual machine flag may indicate a first virtual machine corresponding to the first message, wherein the second message may further include the virtual machine flag.
[0039] Optionally, the message processing unit may be configured to: obtain data related to the first message from the memory based on the first storage location information; and process the data related to the first message.
[0040] Optionally, the first message may further include a function for the secure operating system to execute.
[0041] Optionally, the message processing unit may be configured to: process data related to the first message based on the function.
[0042] According to an exemplary embodiment of the present disclosure, a virtual machine is provided. The virtual machine includes: an instruction transmission unit configured to transmit a first message, wherein the first message is a message sent to a secure operating system based on a call instruction, wherein the first message includes first storage location information of data related to the first message, and the first storage location information is related to a first location in a memory of a middleware, wherein the middleware is related to the virtual machine and the secure operating system; a message receiving unit configured to receive a second message from the middleware, wherein the second message is obtained by the secure operating system based on the first message, wherein the second message includes second storage location information based on a result of processing the first message; and an operation result determination unit configured to determine an operation result based on the second message.
[0043] Optionally, the operation result determining unit may be configured to: acquire a result of processing the first message based on the second storage location information; and determine the result of the processing as the operation result.
[0044] According to an exemplary embodiment of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, an operating method according to an exemplary embodiment of the present disclosure is implemented.
[0045] According to an exemplary embodiment of the present disclosure, a computing device is provided, including: at least one processor; and at least one memory storing a computer program, wherein when the computer program is executed by the at least one processor, an operating method according to an exemplary embodiment of the present disclosure is implemented.
[0046] According to an exemplary embodiment of the present disclosure, a computer program product is provided. Instructions in the computer program product can be executed by a processor of a computer device to implement an operating method according to an exemplary embodiment of the present disclosure.
[0047] According to an exemplary embodiment of the present disclosure, an operating method and device for a virtual machine monitor are provided, by obtaining a first message, wherein the first message is a message to be sent from a virtual machine to a secure operating system, and the secure operating system is registered in the middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, and the first storage location information is related to a first location in the memory of the middleware, and the middleware is related to the virtual machine and the secure operating system, sending the first message to the secure operating system, and receiving a second message from the secure operating system, wherein the second message is based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, and the second storage location information is related to a second location in the memory of the middleware; sending the second message to the virtual machine, thereby supporting the use of functions and services of the secure operating system on multiple virtual machines through the middleware, improving the scalability, security and flexibility of virtual machine operations, and improving the operating efficiency of virtual machines.
[0048] According to an exemplary embodiment of the present disclosure, an operating method and apparatus for a secure operating system are provided, by receiving a first message, wherein the first message is a message sent from a middleware of a virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information is related to a first location in the memory of the middleware, and the middleware is related to the virtual machine and the secure operating system, obtaining a second message based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, the second storage location information is related to a second location in the memory of the middleware, and sending the second message to the middleware, thereby eliminating the need to send data and data processing results through the shared memory in the middleware of the virtual machine monitor, preventing the data and data processing results from being exposed, and improving security and efficiency.
[0049] According to the operating method of the virtual machine of the exemplary embodiment of the present disclosure, a first message is transmitted, wherein the first message is a message sent to the secure operating system based on a call instruction, wherein the first message includes first storage location information of data related to the first message, and the first storage location information is related to a first location in the memory of the middleware, and the middleware is related to the virtual machine and the secure operating system; a second message is received from the middleware, wherein the second message is obtained by the secure operating system based on the first message, wherein the second message includes second storage location information based on the result of processing the first message, and the operation result is determined based on the second message, so that the shared memory in the middleware of the virtual machine monitor does not need to send the data processing result, the data processing result will not be exposed, and the security and efficiency are improved.
[0050] Additional aspects and / or advantages of the present general inventive concept will be set forth in part in the following description and in part will be apparent from the description, or may be learned through practice of the present general inventive concept. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The above and other objects and features of exemplary embodiments of the present disclosure will become more apparent from the following description taken in conjunction with the accompanying drawings which exemplarily illustrate the embodiments, in which: Figure 1 A flowchart illustrating a process of a virtual machine monitor according to an exemplary embodiment of the present disclosure; Figure 2 A flowchart illustrating a process of a secure operating system according to an exemplary embodiment of the present disclosure; Figure 3 A flowchart illustrating processing of a virtual machine according to an exemplary embodiment of the present disclosure; Figure 4 A block diagram illustrating a virtual machine monitor according to an exemplary embodiment of the present disclosure; Figure 5 A block diagram illustrating a secure operating system according to an exemplary embodiment of the present disclosure; Figure 6 A block diagram illustrating a virtual machine according to an exemplary embodiment of the present disclosure; Figure 7 A schematic diagram illustrating a virtual machine operating system according to an exemplary embodiment of the present disclosure; and Figure 8 A schematic diagram illustrating a computing device according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0052] Reference will now be made in detail to the exemplary embodiments of the present disclosure, examples of which are illustrated in the accompanying drawings, wherein like reference numerals refer to like parts throughout. The embodiments will be described below with reference to the drawings to explain the present disclosure.
[0053] It should be understood that unless the context clearly indicates otherwise, singular forms include plural forms. The terms "include," "comprising," and "having" used herein indicate the presence of disclosed functions, operations, or elements, but do not exclude other functions, operations, or elements.
[0054] The expression "A or B" or "at least one of A and B" may indicate A and B, or A or B. For example, the expression "A or B" or "at least one of A and B" may indicate (1) A, (2) B, or (3) both A and B.
[0055] In various exemplary embodiments of the present disclosure, when a component (e.g., a first component) is referred to as being “coupled” or “connected” / “coupled” or “connected” to another component (e.g., a second component), the component may be directly connected to the other component or may be connected through another component (e.g., a third component). In contrast, when a component (e.g., a first component) is referred to as being “directly coupled” or “directly connected” / “directly connected” to another component (e.g., the second component), there is no other component (e.g., a third component) between the component and the other component.
[0056] The expression “configured to” used in describing various embodiments of the present disclosure may be used interchangeably with expressions such as “suitable for,” “capable of,” “designed to,” “suitable for,” “manufactured to,” and “capable of,” for example, depending on the circumstances. The term “configured to” may not necessarily indicate that it is “specially designed to” in terms of hardware. On the contrary, the expression “a device configured to” may in some cases indicate that the device and another device or component are “capable of”. For example, the expression “a processor configured to perform A, B, and C” may indicate a dedicated processor (e.g., an embedded processor) for performing the corresponding operations or a general-purpose processor (e.g., a central processing unit (CPU) or an application processor (AP)) for performing the corresponding operations by executing at least one software program stored in a storage device.
[0057] The present disclosure relates to implementing secure operating system functionality for multiple virtual machines by simply adding a module to a virtual machine monitor. The present disclosure enables applications in multiple virtual machines to use secure operating system functionality through middleware in the virtual machine monitor without requiring any modifications to the secure operating system.
[0058] The application scenarios of the present disclosure may include, for example, but not limited to, application scenarios in which users of an automotive system expect to utilize the secure operating system features across multiple virtual machines to conveniently add or remove virtual machines, and application scenarios in which users expect to be able to easily replace the secure operating system and significantly reduce workload.
[0059] In the present disclosure, middleware is used only in a virtual machine monitor as an example of supporting a secure operating system function for multiple virtual machines.
[0060] Figure 1 A flowchart illustrating an operating method of a virtual machine monitor according to an exemplary embodiment of the present disclosure is shown. Figure 1 The operating method of the virtual machine monitor in the embodiment can be executed by the middleware in the virtual machine monitor. In the present disclosure, the operating method of the virtual machine monitor executed by the middleware in the virtual machine monitor is used as an example for description, but the present disclosure is not limited thereto.
[0061] Reference Figure 1 In step S101, the middleware of the virtual machine monitor obtains a first message that the virtual machine is to send to the secure operating system registered with the middleware of the virtual machine monitor. In an embodiment, the first message may include first storage location information of data associated with the first message in a shared memory located in the middleware. For example, the secure operating system is located in a trusted execution environment. For example, the shared memory may be a World Shared Memory (WSM), and the first storage location information may be the shared memory or a WSM ID.
[0062] In an exemplary embodiment of the present disclosure, obtaining a first message that a virtual machine is to send to a secure operating system registered in a middleware of a virtual machine monitor may include: obtaining a transmission message transmitted by the virtual machine via a call instruction; determining a target transmission message in the transmission message whose destination is the secure operating system; and determining the first message based on the target transmission message, thereby filtering out messages that are not sent to the secure operating system to improve efficiency. For example, the middleware may obtain the transmission message transmitted by the virtual machine via a call instruction by interception. In an embodiment of the present disclosure, the middleware may obtain messages of multiple different virtual machines by interception. Here, the call instruction may be, for example, but not limited to, a Secure Monitor Call (SMC) instruction.
[0063] In an exemplary embodiment of the present disclosure, the first message may further include a virtual machine flag, which may be used to indicate a virtual machine corresponding to the first message, thereby marking the first message as being related to its corresponding virtual machine.
[0064] In an exemplary embodiment of the present disclosure, determining the first message based on the target transfer message may include: appending a virtual machine flag to the session field of the target transfer message; and determining the target transfer message appended with the virtual machine flag as the first message. This is an exemplary embodiment of marking the first message. For example, if a transfer message is destined for the secure operating system, the middleware determines that the transfer message is the target transfer message. The middleware then decodes the target transfer message and appends the virtual machine flag to the session field of the target transfer message, thereby obtaining the first message.
[0065] In an exemplary embodiment of the present disclosure, the first message may further include a function that the virtual machine requires the secure operating system to complete.
[0066] Specifically, the function that the virtual machine requires the secure operating system to perform in the first message may represent the function that the virtual machine wants the secure operating system to perform. The function that the virtual machine requires the secure operating system to perform may be a customized function, such as, but not limited to, data encryption and decryption.
[0067] The world shared memory identification number (WSM ID) is an integer greater than or equal to 0, representing the storage location information of the data in the world shared memory.
[0068] In an embodiment, the world shared memory is memory that can be accessed simultaneously by the virtual machine and the secure operating system. Each message corresponds to a block of world shared memory. In embodiments of the present disclosure, the message size can be very small (for example, but not limited to, only 64 bytes). The message does not contain specific relevant data and only stores the world shared memory identification number, which is an integer greater than or equal to 0. Other information about the message and large blocks of data can be stored in the world shared memory. When the secure operating system receives a message, it can use the world shared memory identification number to find the physical address of the world shared memory corresponding to the message. It can then retrieve the large block of data from the world shared memory for processing. Finally, the processed results can be stored in the world shared memory. The middleware can then look up the physical address of the world shared memory from a hash table associated with the world shared memory identification number, access the world shared memory, and obtain the required message processing results.
[0069] In step S102, the middleware sends a first message to the secure operating system.
[0070] In an exemplary embodiment of the present disclosure, sending a first message to the secure operating system may include: converting address information in the first message into a physical address; and sending the first message after the address conversion to the secure operating system via a security monitor. When converting the address information into a physical address, the destination of the first message is determined so that the first message is accurately sent. Here, the address information in the first message may be, for example, but not limited to, an intermediate physical address. For example, the middleware converts the intermediate physical address in the first message into a physical address and records it.
[0071] In step S103, the middleware receives a second message from the secure operating system, which is obtained by processing the first message. Here, the second message may include second storage location information related to the result of the processing in the shared memory.
[0072] In an exemplary embodiment of the present disclosure, the second message may further include the virtual machine flag to facilitate determination of the virtual machine corresponding to the second message.
[0073] In step S104, the middleware sends a second message to the virtual machine.
[0074] In an exemplary embodiment of the present disclosure, sending the second message to the virtual machine may include: determining the virtual machine indicated by the virtual machine flag included in the second message; and sending the second message to the virtual machine. That is, according to some embodiments, the second message may be sent to the virtual machine without the virtual machine flag. The returned second message is distributed based on the virtual machine flag, thereby improving the accuracy of second message delivery. That is, because the second message includes the virtual machine flag, the middleware can correctly distribute the second message to the corresponding virtual machine.
[0075] As an example, assume that the middleware intercepts the first message sent by the virtual machine, and the content of the first message is function (decryption) + WSM ID (1). The middleware then sends the first message to the secure operating system. This will cause the secure operating system to retrieve data from the world shared memory with WSM ID 1 after receiving the first message and perform a decryption operation on the data. The secure operating system can then put the result back into the world shared memory with WSM ID 1 and send a second message to the middleware. The middleware removes the virtual machine flag in the second message and sends the second message to the virtual machine indicated by the virtual machine flag.
[0076] According to exemplary embodiments of the present disclosure, the middleware is used solely within the virtual machine monitor to support secure operating systems for multiple virtual machines, without requiring any modifications to the secure operating systems or virtual machines. This facilitates support for multiple secure operating systems within the virtual machine monitor and improves scalability. Finally, shared memory within the middleware allows data and processing results to be transmitted without exposing them, improving security and efficiency.
[0077] Figure 2 A flowchart illustrating an operating method of a secure operating system according to an exemplary embodiment of the present disclosure.
[0078] Reference Figure 2 In step S201, a secure operating system receives a first message sent from a middleware of a virtual machine monitor. The first message may include information about a first storage location of data associated with the first message in a shared memory located in the middleware. In an exemplary embodiment of the present disclosure, for example, the secure operating system may be located in a trusted execution environment.
[0079] In an exemplary embodiment of the present disclosure, the first message may further include a virtual machine flag, and the virtual machine flag may be used to indicate a virtual machine corresponding to the first message, thereby marking the first message.
[0080] In an exemplary embodiment of the present disclosure, the first message may further include a function that the virtual machine requires the secure operating system to complete, thereby enabling the secure operating system to execute the function.
[0081] In step S202, the secure operating system processes the first message to obtain a second message. The second message may include second storage location information related to the result of the processing in the shared memory. In the present disclosure, since the secure operating system may be located in a trusted execution environment, the processing performed by the secure operating system based on the first message may also be referred to as trusted service processing.
[0082] In an exemplary embodiment of the present disclosure, processing based on the first message may include: retrieving data related to the first message from the shared memory based on the first storage location information; and processing the retrieved data related to the first message. By sharing the first storage location information related to the storage location of the data in the first message, sending the data is avoided.
[0083] In an exemplary embodiment of the present disclosure, processing the acquired data related to the first message may include: processing the acquired data related to the first message based on the function.
[0084] In step S203, the secure operating system sends a second message to the middleware.
[0085] In an exemplary embodiment of the present disclosure, the second message may further include the virtual machine flag, so as to facilitate identification of the virtual machine corresponding to the second message.
[0086] According to an exemplary embodiment of the present disclosure, the secure operating system processes the data in the shared memory based on the first message and stores the processing results in the shared memory. That is, by using the shared memory in the middleware, it is not necessary to send data and data processing results, thereby improving security and efficiency. In addition, in the present disclosure, there is no need to modify the secure operating system, so Figure 2 The processing shown in the can be applied to any secure operating system. Therefore, the secure operating system can be easily replaced in the present disclosure.
[0087] Figure 3 A flowchart illustrating an operating method of a virtual machine according to an exemplary embodiment of the present disclosure is shown. Figure 3 The operating method of the virtual machine in the embodiment can be executed by any virtual machine known to those skilled in the art.
[0088] Reference Figure 3 In step S301, the virtual machine transmits a first message to the secure operating system via a call instruction. Here, the first message may include information about a first storage location of data associated with the first message in a shared memory located in middleware included in the virtual machine monitor. In the present disclosure, for example, the secure operating system may be located in a trusted execution environment.
[0089] In step S302, the virtual machine receives a second message sent from the middleware, which is obtained by the secure operating system through processing based on the first message. Here, the second message may include second storage location information of the processing result in the shared memory.
[0090] In step S303, the virtual machine determines an operation result based on the second message.
[0091] In an exemplary embodiment of the present disclosure, determining the operation result based on the second message may include: retrieving the processing result from the shared memory based on the second storage location information; and determining the retrieved processing result as the operation result. Using the shared memory in the middleware eliminates the need to send data processing results. This prevents data processing results from being exposed, improving security and efficiency.
[0092] Furthermore, according to exemplary embodiments of the present disclosure, redundant data copying between virtual machines is reduced, thereby avoiding the risk of data exposure and improving security and efficiency.
[0093] The above has been combined Figures 1 to 3The operating method according to the exemplary embodiment of the present disclosure is described. Figures 4 to 6 A virtual machine monitor and its units, a secure operating system and its units, a virtual machine and its units according to an exemplary embodiment of the present disclosure are described, and reference is made to Figure 7 A virtual machine operating system according to an exemplary embodiment of the present disclosure is described.
[0094] Figure 4 A block diagram illustrating a virtual machine monitor according to an exemplary embodiment of the present disclosure is shown.
[0095] Reference Figure 4 The virtual machine monitor includes a message acquiring unit 41 , a message sending unit 42 , a processed message receiving unit 43 and a processed message sending unit 44 . The message acquisition unit 41 is configured to acquire a first message that the virtual machine is to send to a secure operating system registered with the middleware of the virtual machine monitor. The first message includes information about a first storage location of data associated with the first message in a shared memory located in the middleware. In the present disclosure, for example, the secure operating system may be located in a trusted execution environment.
[0096] In an exemplary embodiment of the present disclosure, the message acquisition unit 41 may be configured to: acquire a transmission message transmitted by the virtual machine via a call instruction; determine a target transmission message whose destination is the secure operating system in the transmission message; and determine the first message based on the target transmission message. In an embodiment, the call instruction may be, for example, but not limited to, a secure monitor call instruction.
[0097] In an exemplary embodiment of the present disclosure, the first message may further include a virtual machine flag, and the virtual machine flag may be used to indicate a virtual machine corresponding to the first message.
[0098] In an exemplary embodiment of the present disclosure, message acquisition unit 41 may be configured to: append a virtual machine flag to the session field of the target transmission message; and identify the target transmission message appended with the virtual machine flag as the first message. That is, in this embodiment, message acquisition unit 41 may mark the first message as corresponding to a virtual machine.
[0099] The message sending unit 42 is configured to send a first message to the secure operating system.
[0100] In an exemplary embodiment of the present disclosure, the message sending unit 42 may be configured to convert the address information in the first message into a physical address; and to send the first message after the address conversion to the secure operating system via the security monitor. The message sending unit 42 may convert the address information into a physical address, thereby determining the destination of the first message and accurately sending the first message. Here, the address information in the first message may be, for example, but not limited to, an intermediate physical address. For example, the middleware converts the intermediate physical address in the first message into a physical address and records it.
[0101] The processed message receiving unit 43 is configured to receive a second message obtained by processing the first message from the secure operating system, wherein the second message includes second storage location information of the processed result in the shared memory.
[0102] In an exemplary embodiment of the present disclosure, the second message may further include the virtual machine flag to identify the virtual machine to which the second message corresponds.
[0103] The message processing sending unit 44 is configured to send the second message to the virtual machine.
[0104] In an exemplary embodiment of the present disclosure, the message sending processing unit 44 may be configured to: determine the virtual machine indicated by the virtual machine flag included in the second message; and send the second message to the virtual machine. The message sending processing unit 44 may be configured to: determine the virtual machine indicated by the virtual machine flag included in the second message; and send the second message with the virtual machine flag removed to the virtual machine.
[0105] In an exemplary embodiment of the present disclosure, the first message may further include a function that the virtual machine requires the secure operating system to complete.
[0106] Figure 5 A block diagram illustrating a secure operating system according to an exemplary embodiment of the present disclosure is shown.
[0107] Reference Figure 5 The security operating system includes a message receiving unit 51, a message processing unit 52 and a message sending unit 53.
[0108] The message receiving unit 51 is configured to receive a first message sent from the middleware of the virtual machine monitor. In an embodiment, the first message includes first storage location information of data associated with the first message in a shared memory located in the middleware. In an exemplary embodiment of the present disclosure, for example, the secure operating system may be located in a trusted execution environment.
[0109] In an exemplary embodiment of the present disclosure, the first message may further include a virtual machine flag, and the virtual machine flag may be used to indicate a virtual machine corresponding to the first message.
[0110] The message processing unit 52 is configured to process the first message to obtain a second message. The second message includes second storage location information of the result of the processing in the shared memory. Here, the processing performed by the secure operating system based on the first message can also be referred to as trusted service processing.
[0111] In an exemplary embodiment of the present disclosure, the message processing unit 52 may be configured to: acquire data related to the first message from the shared memory based on the first storage location information; and process the acquired data related to the first message.
[0112] In an exemplary embodiment of the present disclosure, the first message may further include a function that the virtual machine requires the secure operating system to complete.
[0113] In an exemplary embodiment of the present disclosure, the message processing unit 52 may be configured to process the acquired data related to the first message based on the function.
[0114] The message sending unit 53 is configured to send the second message to the middleware.
[0115] In an exemplary embodiment of the present disclosure, the second message may further include the virtual machine flag to identify the virtual machine to which the second message corresponds (the virtual machine to which the second message will be sent).
[0116] Figure 6 A block diagram illustrating a virtual machine according to an exemplary embodiment of the present disclosure.
[0117] Reference Figure 6 The virtual machine includes an instruction transmission unit 61, a message receiving unit 62 and an operation result determination unit 63.
[0118] The instruction transmission unit 61 is configured to transmit a first message to the secure operating system via a call instruction. The first message includes information about a first storage location of data associated with the first message in a shared memory located in middleware included in a virtual machine monitor. For example, the secure operating system may be located in a trusted execution environment.
[0119] The message receiving unit 62 is configured to receive a second message sent from the middleware and obtained by the secure operating system through processing based on the first message. The second message includes second storage location information of the processing result in the shared memory.
[0120] The operation result determination unit 63 is configured to determine an operation result based on the second message.
[0121] In an exemplary embodiment of the present disclosure, the operation result determining unit 63 may be configured to: acquire the result of the processing from the shared memory based on the second storage location information; and determine the acquired result of the processing as the operation result.
[0122] Figure 7 A schematic diagram illustrating a virtual machine operating system according to an exemplary embodiment of the present disclosure is shown.
[0123] like Figure 7 As shown, the virtual machine operating system includes: at least one virtual machine (for example, Figure 7 two virtual machines in the system); at least one secure operating system (Secure OS); a virtual machine monitor comprising a middleware, the middleware being connected to the at least one virtual machine, the at least one secure operating system being registered in the middleware; and a security monitor being connected to the middleware and the at least one secure operating system. The middleware is not bound to any specific secure operating system and can support various secure operating systems. For example, the at least one secure operating system can be located in a trusted execution environment (TEE). Figure 7 Only two virtual machines are used as an example, and the present disclosure is not limited thereto.
[0124] like Figure 7 As shown, the middleware includes a message manager, a virtual machine manager, and a world shared memory (WSM) manager. The message manager includes a message stamper, a message filter, and a message dispatcher. The message stamper is used to add stamps to messages, including, for example, but not limited to, virtual machine flags and intermediate physical address (IPA) / physical address (PA) information. The message filter is used to filter out messages not destined for the secure operating system. The message dispatcher is used to distribute returned messages to the corresponding virtual machine.
[0125] A virtual machine manager (VM) is used to manage each of the multiple virtual machines. The VM manager includes system pages and message rings (e.g., Figure 7The message ring is used to temporarily store messages for filtering. The system page registers a system page for the secure operating system to manage the status of each of the multiple virtual machines. For example, the system page maintains some basic information about the virtual machines, including the number of virtual machines, the virtual machine ID, and whether the virtual machine is alive. During operation, the virtual machine can access the system page (to know the status of the secure operating system, such as whether the secure operating system is still alive) and know whether the secure operating system is still working properly. The system page can be used to dynamically configure the number of virtual machines, allowing the number of virtual machines to be increased or decreased without any modification to the virtual machines. Since the status of all virtual machines is managed in the system page, the secure operating system does not need to know how many virtual machines there are, so the secure operating system does not need to be modified.
[0126] The world shared memory manager manages shared memory between virtual machines and the secure operating system. The world shared memory manager may include a hash table. The world shared memory manager uses a hash algorithm to manage shared memory between multiple virtual machines and the secure operating system, or world shared memory.
[0127] A hash algorithm is a commonly used algorithm for quickly searching for data using an identification number (ID). In the present disclosure, a hash algorithm is used to search for the physical address of the world shared memory using the identification number of the world shared memory. However, the present disclosure is not limited thereto.
[0128] The specific process of using the hash algorithm to manage the world shared memory is as follows: During the middleware initialization phase, a hash table of length n is created. After receiving a message from the virtual machine, the middleware obtains the world shared memory identification number (WSM ID) in the message. The world shared memory identification number (WSM ID) is used to calculate the hash table index value index = (WSM ID) mod n. Using the index value, a hash table entry is found. The physical address of the world shared memory (WSM) is then stored in this entry hash_table[index]. After the secure operating system processes a message, the middleware uses the WSM ID to search the hash table for the physical address of the world shared memory (WSM), hash_table[(WSM ID) mod n]. This operation has a time complexity of O(1), so it can achieve the most efficient search speed.
[0129] In an exemplary embodiment of the present disclosure, the middleware is configured to: obtain a first message to be sent by the at least one virtual machine to the at least one secure operating system, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware; send the first message to the at least one secure operating system; receive a second message obtained by processing based on the first message from the at least one secure operating system, wherein the second message includes second storage location information of the result of the processing in the shared memory; and send the second message to the at least one virtual machine.
[0130] In an exemplary embodiment of the present disclosure, the middleware may also be configured to: obtain a transmission message transmitted by the at least one virtual machine via a call instruction; determine a target transmission message within the transmission message whose destination is the secure operating system; and determine a first message based on the target transmission message, thereby filtering out messages not destined for the secure operating system to improve efficiency. For example, the middleware may intercept the transmission message transmitted by the at least one virtual machine via a call instruction. Here, the call instruction may be a security monitor call instruction.
[0131] In an exemplary embodiment of the present disclosure, the first message may further include a virtual machine flag, which is used to indicate the virtual machine corresponding to the first message, and the second message also includes the virtual machine flag, thereby achieving marking of the first message and the second message.
[0132] In an exemplary embodiment of the present disclosure, the first message may further include a function that the at least one virtual machine requires the secure operating system to complete.
[0133] In an exemplary embodiment of the present disclosure, the middleware may be further configured to: append a virtual machine flag to the session field of the target transmission message; and identify the target transmission message appended with the virtual machine flag as the first message, thereby marking the first message. For example, if a transmission message is destined for the secure operating system, the middleware may determine that the transmission message is the target transmission message, decode the target transmission message, and append the virtual machine flag to the session field of the target transmission message, thereby obtaining the first message.
[0134] In an exemplary embodiment of the present disclosure, the middleware may be further configured to convert the address information in the first message into a physical address; and transmit the converted first message to the secure operating system via the security monitor. Here, the address information in the first message may be an intermediate physical address. Converting the address information into a physical address allows the destination of the first message to be determined, allowing the first message to be accurately transmitted. For example, the middleware converts the intermediate physical address in the first message into a physical address and records it.
[0135] In an exemplary embodiment of the present disclosure, the second message may further include the virtual machine flag, thereby facilitating determination of the virtual machine corresponding to the second message.
[0136] In an exemplary embodiment of the present disclosure, the middleware may be further configured to: determine the virtual machine indicated by the virtual machine flag included in the second message; and send the second message to the virtual machine indicated by the virtual machine flag. The middleware may also be configured to: determine the virtual machine indicated by the virtual machine flag included in the second message; and send the second message without the virtual machine flag to the virtual machine indicated by the virtual machine flag. Here, the returned second message is distributed based on the virtual machine flag, thereby improving the accuracy of the second message transmission. Because the second message includes the virtual machine flag, the middleware can correctly distribute the second message to the corresponding virtual machine.
[0137] In an exemplary embodiment of the present disclosure, the middleware may include a system page for the at least one secure operating system, wherein the system page is used to manage the status of the at least one virtual machine and the at least one secure operating system.
[0138] In an exemplary embodiment of the present disclosure, the middleware may include a message ring for storing a transmission message obtained from the at least one virtual machine.
[0139] In an exemplary embodiment of the present disclosure, the middleware may include a memory manager, and the shared memory may be located in the memory manager, wherein the shared memory is memory shared by the at least one virtual machine and the at least one secure operating system, and the memory manager may manage the shared memory.
[0140] In an exemplary embodiment of the present disclosure, each of the at least one secure operating system may be configured to: receive a first message sent from the middleware, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware; perform processing based on the first message to obtain a second message, wherein the second message includes second storage location information of a result of the processing in the shared memory; and send the second message to the middleware.
[0141] In an exemplary embodiment of the present disclosure, each of the at least one secure operating system may also be configured to: obtain data related to the first message from the shared memory based on the first storage location information; process the obtained data related to the first message, thereby avoiding the sending of data by determining the data based on the first storage location information in the first message.
[0142] In an exemplary embodiment of the present disclosure, each of the at least one secure operating system may be further configured to: process the acquired data related to the first message based on the function.
[0143] In an exemplary embodiment of the present disclosure, each of the at least one virtual machine may be configured to: transmit a first message to be sent to the at least one secure operating system through a calling instruction, wherein the first message includes first storage location information of data related to the first message in the shared memory, and the shared memory is located in the middleware included in the virtual machine monitor; receive a second message obtained by the at least one secure operating system sent from the middleware through processing based on the first message, wherein the second message includes second storage location information of the result of the processing in the shared memory; and determine the operation result based on the second message.
[0144] In an exemplary embodiment of the present disclosure, each of the at least one virtual machine can also be configured to: obtain the processing result from the shared memory based on the second storage location information; determine the obtained processing result as the operation result, thereby eliminating the need to send data processing results through the shared memory in the middleware, and the data processing results will not be exposed, thereby improving security and efficiency.
[0145] According to the virtual machine operating system of the exemplary embodiment of the present disclosure, only the middleware is used in the virtual machine monitor to realize the function of supporting the secure operating system for multiple virtual machines. No modification is required to the secure operating system and the virtual machine, and it is more convenient to support multiple secure operating systems, thereby improving scalability. The shared memory in the middleware eliminates the need to send data and data processing results, and the data and data processing results will not be exposed, thereby improving security and efficiency.
[0146] In addition, according to an exemplary embodiment of the present disclosure, there is also provided a computer-readable storage medium having a computer program stored thereon, which implements the operating method according to the exemplary embodiment of the present disclosure when the computer program is executed.
[0147] In an exemplary embodiment of the present disclosure, the computer-readable storage medium may carry one or more programs, and when the computer program is executed, the following steps may be implemented: obtaining a first message that the virtual machine is to send to a secure operating system registered in the middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware; sending the first message to the secure operating system; receiving a second message obtained by processing based on the first message from the secure operating system, wherein the second message includes second storage location information of the result of the processing in the shared memory; and sending the second message to the virtual machine.
[0148] In an exemplary embodiment of the present disclosure, the computer-readable storage medium may carry one or more programs, and when the computer program is executed, the following steps may be implemented: receiving a first message sent from the middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware; processing based on the first message to obtain a second message, wherein the second message includes second storage location information of a result of the processing in the shared memory; and sending the second message to the middleware.
[0149] In an exemplary embodiment of the present disclosure, the computer-readable storage medium may carry one or more programs, and when the computer program is executed, the following steps may be implemented: transmitting a first message to be sent to a secure operating system by calling an instruction, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in a middleware included in a virtual machine monitor; receiving a second message sent from the middleware and obtained by the secure operating system through processing based on the first message, wherein the second message includes second storage location information of a result of the processing in the shared memory; and determining an operation result based on the second message.
[0150] A computer readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. Examples of computer-readable storage media include read-only memory (ROM), random-access programmable read-only memory (PROM), electrically erasable programmable read-only memory (EEPROM), random-access memory (RAM), dynamic random-access memory (DRAM), static random-access memory (SRAM), flash memory, non-volatile memory, CD-ROM, CD-R, CD+R, CD-RW, CD+RW, DVD-ROM, DVD-R, DVD+R, DVD-RW, DVD+RW, DVD-RAM, BD-ROM, BD-R, BD-RLTH, BD-RE, Blu-ray or optical disk storage, hard disk drive (HDD), solid-state drive (SSD), card-type memory such as a multimedia card, a secure digital (SD) card or an extreme digital (XD) card, magnetic tape, floppy disk, magneto-optical data storage device, optical data storage device, hard disk, solid-state disk, and any computer configured to store a computer program and any associated data, data files, and data structures in a non-transitory manner and provide the computer program and any associated data, data files, and data structures to a processor or computer so that the processor or computer can execute the computer program.
[0151] In addition, according to the exemplary embodiments of the present disclosure, a computer program product is also provided. Instructions in the computer program product can be executed by a processor of a computer device to implement the operating method according to the exemplary embodiments of the present disclosure.
[0152] The above has been combined Figures 4 to 7 The virtual machine monitor, secure operating system, virtual machine, and virtual machine operating system according to the exemplary embodiment of the present disclosure are described. Figure 8 A computing device according to an exemplary embodiment of the present disclosure is described.
[0153] Figure 8 A schematic diagram illustrating a computing device according to an exemplary embodiment of the present disclosure.
[0154] Reference Figure 8 According to an exemplary embodiment of the present disclosure, a computing device 800 includes a memory 81 and a processor 82. The memory 81 stores one or more computer programs. The memory 81 may include one or more storage devices and / or structures. The processor 82 may include one or more processors capable of executing instructions individually or in combination. When the computer program is executed by the processor 82, the operating method according to the exemplary embodiment of the present disclosure is implemented.
[0155] In an exemplary embodiment of the present disclosure, when the computer program is executed by the processor 82, the following steps can be implemented: obtaining a first message that the virtual machine is to send to a secure operating system registered in the middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware; sending the first message to the secure operating system; receiving a second message obtained by processing based on the first message from the secure operating system, wherein the second message includes second storage location information of the result of the processing in the shared memory; and sending the second message to the virtual machine.
[0156] In an exemplary embodiment of the present disclosure, when the computer program is executed by the processor 82, the following steps can be implemented: receiving a first message sent from the middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware; processing based on the first message to obtain a second message, wherein the second message includes second storage location information of a result of the processing in the shared memory; and sending the second message to the middleware.
[0157] In an exemplary embodiment of the present disclosure, when the computer program is executed by the processor 82, the following steps can be implemented: transmitting a first message to be sent to the secure operating system by calling an instruction, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware included in the virtual machine monitor; receiving a second message sent from the middleware by the secure operating system through processing based on the first message, wherein the second message includes second storage location information of a result of the processing in the shared memory; and determining an operation result based on the second message.
[0158] The computing device in the embodiments of the present disclosure may include, but is not limited to, devices such as mobile phones, laptop computers, PDAs (personal digital assistants), PADs (tablet computers), desktop computers, and the like. Figure 8 The computing device shown is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.
[0159] The above has been referred to Figures 1 to 8 The operating methods and apparatus, systems, computer-readable storage media, and computing devices according to exemplary embodiments of the present disclosure are described. However, it should be understood that: Figures 4 to 6 The virtual machine monitor, secure operating system, virtual machine and its units shown in the figure may be configured as software, hardware, firmware or any combination of the above items to perform specific functions. Figure 8The computing device shown in is not limited to including the components shown above, but some components may be added or deleted as needed, and the above components may also be combined.
[0160] According to the operating method and device of the virtual machine monitor of the exemplary embodiment of the present disclosure, a first message to be sent by the virtual machine to the secure operating system registered in the middleware of the virtual machine monitor is obtained, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware. The first message is sent to the secure operating system, and a second message obtained by processing based on the first message is received from the secure operating system, wherein the second message includes second storage location information of the result of the processing in the shared memory. The second message is sent to the virtual machine, thereby supporting the use of functions and services of the secure operating system on multiple virtual machines through the middleware, improving the scalability, security and flexibility of virtual machine operations, and improving the operating efficiency of virtual machines.
[0161] According to the operating method of the secure operating system of the exemplary embodiment of the present disclosure, a first message is received from the middleware of the virtual machine monitor, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware; processing is performed based on the first message to obtain a second message, wherein the second message includes second storage location information of a result of the processing in the shared memory; and the second message is sent to the middleware, thereby eliminating the need to send data and data processing results through the shared memory in the middleware of the virtual machine monitor, and the data and data processing results will not be exposed, thereby improving security and efficiency.
[0162] According to the operating method of the virtual machine of the exemplary embodiment of the present disclosure, a first message to be sent to the secure operating system is transmitted via a call instruction, wherein the first message includes first storage location information of data related to the first message in a shared memory, and the shared memory is located in the middleware included in the virtual machine monitor; a second message obtained by the secure operating system through processing based on the first message sent from the middleware is received, wherein the second message includes second storage location information of the processing result in the shared memory; an operation result is determined based on the second message, thereby eliminating the need to send data processing results through the shared memory in the middleware of the virtual machine monitor, and the data processing results will not be exposed, thereby improving security and efficiency.
[0163] By such as Figures 4 to 8At least one of the components, elements, modules, and units (collectively referred to as "components" in this paragraph) represented by the blocks in the accompanying drawings may use a direct circuit structure (such as a memory, processor, logic circuit, lookup table, etc.) that can perform various functions under the control of one or more microprocessors or other control devices. In addition, at least one of these components may be specifically implemented by a module, program, or part of a code that includes one or more executable instructions for performing a specified logical function, and executed by one or more microprocessors or other control devices. In addition, at least one of these components may include a processor (such as a central processing unit (CPU), microprocessor, etc.) that performs the corresponding function, or may be implemented by a processor (such as a central processing unit (CPU), microprocessor, etc.) that performs the corresponding function.
[0164] While the present disclosure has been particularly shown and described with reference to exemplary embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the spirit and scope of the present disclosure as defined by the following claims.
Claims
1. A method for operating a virtual machine monitor, executed by one or more processors, the method comprising: Obtaining a first message, wherein the first message is a message to be sent from a virtual machine to a secure operating system, the secure operating system being registered in middleware of the virtual machine monitor, wherein the first message includes first storage location information of data associated with the first message, the first storage location information being associated with a first location in a memory of the middleware, the middleware being associated with the virtual machine and the secure operating system; sending a first message to the secure operating system; receiving a second message from the secure operating system, wherein the second message is based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, and wherein the second storage location information is associated with a second location in a memory of the middleware; A second message is sent to the virtual machine.
2. The operating method according to claim 1, wherein: The obtaining of the first message includes: Acquire one or more transmission messages transmitted by the virtual machine through one or more call instructions; determining a message having a destination of the secure operating system among the one or more transmission messages as a target transmission message; A first message is determined based on the target transmission message.
3. The operating method according to claim 1, wherein: The first message also includes a virtual machine flag, where the virtual machine flag indicates a first virtual machine corresponding to the first message. The second message also includes the virtual machine flag.
4. The operating method according to claim 3, wherein: The determining the first message based on the target transmission message includes: Based on the virtual machine flag, updating the session field of the target transmission message; The target transmission message is determined as the first message.
5. The operating method according to claim 1, wherein: The sending of the first message to the secure operating system comprises: Converting the address information in the first message into a physical address; A first message is sent to the secure operating system via a secure monitor.
6. The operating method according to claim 3, wherein: The sending the second message to the virtual machine includes: Determine a first virtual machine indicated by the virtual machine flag in the second message; The second message without the virtual machine flag is sent to the first virtual machine.
7. The operating method according to claim 3, wherein: The first message also includes a function for the secure operating system to execute.
8. A method for operating a secure operating system, executed by one or more processors, the method comprising: receiving a first message, wherein the first message is sent from middleware of a virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of the middleware, the middleware being related to the virtual machine and the secure operating system; Obtaining a second message based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, and the second storage location information is associated with a second location in the memory of the middleware; A second message is sent to the middleware.
9. The operating method according to claim 8, wherein: The first message also includes a virtual machine flag, where the virtual machine flag indicates a first virtual machine corresponding to the first message. The second message also includes the virtual machine flag.
10. The operating method according to claim 8, wherein: The obtaining of the second message includes: acquiring data related to the first message from the memory based on the first storage location information; Data associated with the first message is processed.
11. The operating method according to claim 10, wherein: The first message also includes a function for the secure operating system to execute.
12. The operating method according to claim 11, wherein: The obtaining of the second message includes: The data associated with the first message is processed based on the function.
13. A method for operating a virtual machine, executed by one or more processors, the method comprising: Transmitting a first message, wherein the first message is a message sent to the secure operating system based on the call instruction, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of the middleware, the middleware being related to the virtual machine and the secure operating system; receiving a second message from the middleware, wherein the second message is obtained by the secure operating system based on the first message, and wherein the second message includes second storage location information based on a result of processing the first message; An operation result is determined based on the second message.
14. The operating method according to claim 13, wherein: The determining the operation result based on the second message includes: Acquire a result of processing the first message based on the second storage location information; A result of the processing is determined as the operation result.
15. A virtual machine operating system, comprising: At least one virtual machine; at least one secure operating system; a virtual machine monitor comprising middleware, the middleware being coupled to the at least one virtual machine, and wherein the at least one secure operating system is registered with the middleware; a security monitor connected to the middleware and the at least one secure operating system, Wherein, one or more processors in the middleware are configured to: Obtaining a first message, wherein the first message is a message to be sent from the at least one virtual machine to the at least one secure operating system, wherein the first message includes first storage location information of data associated with the first message, the first storage location information being associated with a first location in a memory of the middleware, the middleware being associated with the virtual machine and the secure operating system; sending a first message to the at least one secure operating system; receiving a second message from the at least one secure operating system, wherein the second message is a second message obtained by processing the first message, wherein the second message includes second storage location information based on a result of processing the first message, and the second storage location information is associated with a second location in the memory of the middleware; A second message is sent to the at least one virtual machine.
16. A virtual machine monitor, comprising: a message acquiring unit configured to acquire a first message, wherein the first message is a message to be sent from the virtual machine to a secure operating system registered in middleware of a virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of the middleware, the middleware being related to the virtual machine and the secure operating system; a message sending unit, configured to send a first message to the secure operating system; a processed message receiving unit configured to receive a second message from the secure operating system, wherein the second message is based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, and the second storage location information is associated with a second location in the memory of the middleware; and The message processing unit is configured to send the second message to the virtual machine.
17. A secure operating system, comprising: a message receiving unit configured to receive a first message, wherein the first message is a message sent from middleware of a virtual machine monitor, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of the middleware, the middleware being related to the virtual machine and the secure operating system; a message processing unit configured to obtain a second message based on the first message, wherein the second message includes second storage location information based on a result of processing the first message, and the second storage location information is associated with a second location in the memory of the middleware; The message sending unit is configured to send the second message to the middleware.
18. A virtual machine, comprising: an instruction transmission unit configured to transmit a first message, wherein the first message is a message sent to the secure operating system based on a call instruction, wherein the first message includes first storage location information of data related to the first message, the first storage location information being related to a first location in a memory of the middleware, the middleware being related to the virtual machine and the secure operating system; a message receiving unit configured to receive a second message from the middleware, wherein the second message is obtained by the secure operating system based on the first message, and wherein the second message includes second storage location information based on a result of processing the first message; The operation result determining unit is configured to determine the operation result based on the second message.
19. A computer-readable storage medium storing a computer program, wherein: When the computer program is executed by a processor, the operating method according to any one of claims 1 to 14 is implemented.
20. A computing device comprising: at least one processor; At least one memory stores a computer program, and when the computer program is executed by the at least one processor, the operating method according to any one of claims 1 to 14 is implemented.