Method and device for trusted virtual machine, medium, electronic equipment and product
By storing the root file system and kernel in a read-only partition in the virtual machine and using hash tree verification, combined with transparently encrypted read-write partitions to store dynamic data, the data measurement and storage security issues at the virtual machine level are solved, and efficient data integrity verification and secure storage are achieved.
Patent Information
- Application Number
- CN202510900950.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-06-30
AI Technical Summary
Existing TEE technology has difficulty achieving efficient and complete data measurement and verification at the virtual machine level, and lacks security guarantees for data when it is stored on disk.
The root file system and kernel in the virtual machine's operating system image are stored in a read-only partition, and integrity verification is performed using a hash tree. Dynamic data is stored in a read-write partition in a transparently encrypted form to achieve encrypted and persistent storage of dynamic data.
It realizes the rapid integrity verification of virtual machines and the secure storage of dynamic data, ensuring the security of data when it is written to the disk and the seamless decryption when it is read out, thus improving the security and efficiency of TEE.
Smart Images

Figure CN120744909A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a method, device, medium, electronic device, and product for a trusted virtual machine. Background Art
[0002] A Trusted Execution Environment (TEE) is a hardware technology that uses hardware to ensure data confidentiality, isolation, and trustworthiness during computing. Early TEE technology primarily provided process-level security. Hardware-protected processes can defend against attacks from privileged processes and the operating system. Some TEEs also provide clear measurement mechanisms for protected processes, helping to verify their trustworthiness. However, process-level TEEs are difficult to use and incur high costs for service migration.
[0003] Currently, mainstream TEE capabilities extend their protection scope from a single process to the entire virtual machine (Confidential VM), providing hardware-hardened runtime for the entire VM. This provides a convenient and cost-effective way for the application layer to deploy a TEE environment. VMs contain a large number of dependent libraries and applications, and their Trusted Computing Base (TCB) is relatively large. Therefore, how to efficiently and comprehensively measure and verify the contents of Confidential VMs is a key issue. Furthermore, Confidential VMs focus on ensuring the memory security of data during computation, but do not provide support for ensuring the security of data when it is stored on disk. Summary of the Invention
[0004] This summary is provided to briefly introduce concepts that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0005] In a first aspect, the present disclosure provides a method for a trusted virtual machine, the method being applied to a virtual machine deployed in a trusted execution environment, wherein an operating system image of the virtual machine includes a root file system and a kernel, the root file system and the kernel being stored in a first partition, the first partition being further used to store a hash tree corresponding to the root file system and a hash value of a root node of the hash tree, and the first partition being a read-only partition; The method comprises: When the virtual machine is started, starting the kernel based on the hash value; Performing an integrity check on the root file system according to the hash value and the hash tree; If the root file system passes the integrity check, mounting the root file system; The second partition is mounted on the root file system; wherein the second partition is a read-write partition, which is used to store data generated by the virtual machine during operation in a transparent encrypted form.
[0006] In a second aspect, the present disclosure provides a device for a trusted virtual machine, the device being applied to a virtual machine deployed in a trusted execution environment, wherein an operating system image of the virtual machine includes a root file system and a kernel, the root file system and the kernel being stored in a first partition, the first partition being further used to store a hash tree corresponding to the root file system and a hash value of a root node of the hash tree, the first partition being a read-only partition; The device comprises: A kernel startup module, configured to start the kernel based on the hash value when the virtual machine is started; A verification module, configured to perform an integrity check on the root file system based on the hash value and the hash tree; A first mounting module, configured to mount the root file system if the root file system passes the integrity check; The second mounting module is used to mount the second partition onto the root file system; wherein the second partition is a read-write partition, which is used to store data generated by the virtual machine during operation in a transparently encrypted form.
[0007] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the method for a trusted virtual machine provided in the first aspect of the present disclosure.
[0008] In a fourth aspect, the present disclosure provides an electronic device, comprising: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of the method for a trusted virtual machine provided in the first aspect of the present disclosure.
[0009] In a fifth aspect, the present disclosure provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the method for a trusted virtual machine provided in the first aspect of the present disclosure.
[0010] In the above technical solution, the root file system and kernel in the virtual machine's operating system image, as well as the hash tree corresponding to the root file system and the hash value of the root node of the hash tree, which are immutable static contents required for the operation of the virtual machine, are stored in a read-only manner in the first partition. This facilitates rapid integrity verification of the entire root file system based on the hash value and hash tree in the first partition. In addition, the data generated by the virtual machine during operation is stored in a readable and writable second partition in a transparently encrypted form. That is, dynamic data is transparently encrypted when it is written to the disk, thereby ensuring the security of the dynamic data when it is written to the disk and stored. The dynamic data is also decrypted imperceptibly when it is read out, thereby achieving encrypted and persistent storage of the dynamic data.
[0011] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale. In the drawings: Figure 1 The figure is a flowchart of a method for a trusted virtual machine according to an exemplary embodiment.
[0013] Figure 2 The figure is a schematic diagram of a virtual machine disk partition according to an exemplary embodiment.
[0014] Figure 3 The figure is an architectural diagram showing a confidential virtual machine image solution according to an exemplary embodiment.
[0015] Figure 4 The figure is a schematic diagram showing a process of dynamic data encryption according to an exemplary embodiment.
[0016] Figure 5 The present invention is a block diagram showing a device for a trusted virtual machine according to an exemplary embodiment.
[0017] Figure 6 The figure is a schematic structural diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0018] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0019] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0020] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.
[0021] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0022] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0023] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0024] It is understandable that before using the technical solutions disclosed in the various embodiments of the present disclosure, the type, scope of use, usage scenarios, etc. of the information involved in the present disclosure should be informed to relevant users and authorization should be obtained from relevant users in an appropriate manner in accordance with relevant laws and regulations. The relevant users may include any type of right holders, such as individuals, enterprises, and groups.
[0025] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can independently choose whether to provide information to the software or hardware such as the electronic device, application, server or storage medium that executes the operation of the technical solution of the present disclosure based on the prompt message.
[0026] As an optional but non-limiting implementation, in response to receiving an active request from a relevant user, a prompt message may be sent to the relevant user in the form of a pop-up window, in which the prompt message may be presented in text form. Furthermore, the pop-up window may also include a selection control for the user to select "agree" or "disagree" to provide information to the electronic device.
[0027] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0028] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.
[0029] Figure 1 FIG. 1 is a flow chart showing a method for a trusted virtual machine according to an exemplary embodiment. Figure 1 As shown, the method for a trusted virtual machine may include S101 to S104.
[0030] In S101 , when the virtual machine is started, the kernel is started based on the hash value of the root node of the hash tree corresponding to the root file system.
[0031] In the present disclosure, the method for a trusted virtual machine can be applied to a virtual machine deployed in a trusted execution environment, wherein the main content of the virtual machine can be divided into a read-only immutable static part and a read-write mutable dynamic part.
[0032] The static portion contains common content required for virtual machine operation, such as pre-installed system libraries ( / lib) and pre-installed software (such as the contents of the / usr / sbin directory). This type of content is relatively common and unrelated to sensitive user-level data. Therefore, it can be stored in read-only mode and its consistency can be measured using efficient data integrity verification schemes.
[0033] The dynamic portion includes all types of data installed and generated during the operation of the virtual machine, such as deployed applications and temporary data generated by these applications. This content is business-related and may contain sensitive user-level data, so it needs to be stored in a dynamic and encrypted manner.
[0034] The operating system image (OS Image) of the virtual machine includes the root file system and the kernel. The root file system and the kernel are stored in the first partition. The first partition is also used to store the hash tree corresponding to the root file system and the hash value of the root node of the hash tree. The first partition is a read-only partition used to store plaintext data. Figure 2 and Figure 3 As shown, the first partition includes three sub-partitions, namely, the first sub-partition part0, the second sub-partition part1, and the third sub-partition part2. The first sub-partition part0 is the virtual machine boot partition, which contains the necessary content for virtual machine startup and is usually read-only. The second sub-partition part1 is used to store the root file system, which contains the necessary content for the operating system, such as system libraries and pre-installed software. The third sub-partition part2 is used to store verification elements, which are a type of data that assists in verifying the integrity of the root file system, such as the hash tree corresponding to the root file system. For example, the binary tree (Merkle Tree) corresponding to the root file system can be generated using the binary hash tree (Merkle Hash Tree) algorithm as the hash tree corresponding to the root file system.
[0035] like Figure 3 As shown, the first subpartition, part0, is used to store a unified kernel image (UKI). The UKI includes the kernel, the initial root file system (initrd), and kernel parameters (kernelparam, i.e., kernel command line parameters). The initial root file system is the initialization image that the virtual machine relies on to start up. That is, the virtual machine's operating system image also includes the initial root file system, which is stored in the first partition.
[0036] like Figure 2 and Figure 3 As shown, the virtual machine disk also includes a second partition part3, which is used to store the data of the above-mentioned dynamic part, that is, various types of data installed and generated during the operation of the virtual machine, such as applications, user data, container instances / images, etc. The second partition part3 is a read-write partition for storing encrypted data.
[0037] like Figure 3As shown, the third subpartition part2 is an optional partition, that is, the verification element can be stored separately in the third subpartition part2, or the third subpartition part2 can be omitted and the verification element can be stored at the end of the root file system in the second subpartition part1.
[0038] When the virtual machine starts, the virtual machine firmware can read the virtual machine startup configuration (i.e., kernel parameters) and the kernel from the first sub-partition part0, and read the integrity hash value of the root file system (i.e., the hash value of the root node of the hash tree corresponding to the root file system), and then use the value as the kernel parameter. After that, the kernel is started according to the kernel parameters.
[0039] Before the kernel is started, the kernel parameters can be measured and written into the hardware registers for use in the subsequent remote attestation of the virtual machine.
[0040] In S102, the integrity of the root file system is checked according to the hash value of the root node of the hash tree corresponding to the root file system and the hash tree corresponding to the root file system.
[0041] In S103, if the root file system passes the integrity check, the root file system is mounted.
[0042] like Figure 3 As shown in the figure, after the kernel is loaded, the integrity verification setting tool veritysetup can be used to perform integrity verification on the root file system based on the hash value (root hash) of the root node of the hash tree corresponding to the root file system and the hash tree corresponding to the root file system (i.e. verification element). If the root file system passes the integrity verification, the root file system is mounted using the veritysetup tool. Figure 3 If the root file system fails the integrity check, it indicates that the root file system content is incorrect. In this case, you can exit with an error.
[0043] The veritysetup tool is a command-line tool for configuring device-mapper mappings managed by dm-verity.
[0044] In S104, the second partition is mounted to the root file system, wherein the second partition is a read-write partition used to store data generated by the virtual machine during operation in a transparently encrypted form.
[0045] In one possible implementation, Figure 3 As shown, the second partition can be mounted on the root file system through the overlay mechanism by using the mount command, so that the root file system constitutes an overlay file system (such as Figure 3In this way, the application layer can access the overlay file system according to business needs.
[0046] Among them, such as Figure 3 As shown, the application layer can include containers, processes, data, etc. The second partition is Figure 3 The mount command is used to mount file systems in Unix-like operating systems such as Linux and macOS.
[0047] The second partition is used to store dynamic data generated by the virtual machine during operation in a transparently encrypted form. That is, dynamic data encryption is used to transparently encrypt and decrypt these dynamic data. That is, the dynamic data is transparently encrypted when it is written to the disk (that is, stored in the second partition) and is decrypted unconsciously when it is read out.
[0048] In the above technical solution, the root file system and kernel in the virtual machine's operating system image, as well as the hash tree corresponding to the root file system and the hash value of the root node of the hash tree, which are immutable static contents required for the operation of the virtual machine, are stored in a read-only manner in the first partition. This facilitates rapid integrity verification of the entire root file system based on the hash value and hash tree in the first partition. In addition, the dynamic data generated by the virtual machine during operation is stored in a readable and writable second partition in a transparently encrypted form. That is, the dynamic data is transparently encrypted when it is written to the disk, thereby ensuring the security of the dynamic data when it is written to the disk and stored. The dynamic data is also decrypted imperceptibly when it is read out, thereby achieving encrypted and persistent storage of the dynamic data.
[0049] In one possible implementation, when a virtual machine is first started, the virtual machine disk needs to be initialized. Specifically, the above method for a trusted virtual machine also includes the following three steps: Get the hash tree corresponding to the root file system and the hash value of the root node of the hash tree corresponding to the root file system; Store the hash tree corresponding to the root file system, the hash value of the root node of the hash tree corresponding to the root file system, the root file system, and the kernel in the first partition; Initialize the second partition as an empty partition.
[0050] In the present disclosure, dm-verity can be used to generate a hash tree corresponding to the root file system, and the hash value of the root node of the hash tree corresponding to the root file system can be calculated, and the hash tree can be stored as a verification element in the Figure 2 and Figure 3 The third subpartition part2 in the Figure 2 and Figure 3The first sub-partition part0 in the virtual machine is used as one of the startup parameters of the virtual machine. At the same time, the root file system can be stored in Figure 2 and Figure 3 The kernel is stored in the first subpartition part0, and the second partition part3 is initialized as a blank partition.
[0051] The following describes in detail the specific implementation method for performing integrity verification on the root file system based on the hash value of the root node of the hash tree corresponding to the root file system and the hash tree corresponding to the root file system in S102. Specifically, this can be achieved through the following steps (a1) and (a2): Step (a1): Based on the hash tree corresponding to the root file system, measure the root file system to obtain the measurement value of the root node of the hash tree corresponding to the root file system.
[0052] Step (a2): If the measurement value is consistent with the hash value of the root node of the hash tree corresponding to the root file system, it is determined that the root file system passes the integrity check.
[0053] In the present disclosure, a hash value of each file can be calculated when the file is opened in the root file system. Then, based on the hash value of each file, hash calculation is performed layer by layer according to the hash tree corresponding to the root file system to obtain the hash calculation value of the root node of the hash tree, which is used as the measurement value of the root node of the hash tree corresponding to the root file system. Afterwards, the measurement value of the root node is compared with the hash value of the root node of the hash tree corresponding to the root file system for consistency. If the two are consistent, it is determined that the root file system has passed the integrity check. If the two are inconsistent, it is determined that the root file system has failed the integrity check.
[0054] The following describes in detail the specific implementation of mounting the second partition to the root file system in S104. Specifically, S104 may include the following steps (b1) to (b4).
[0055] Step (b1): Load the initial root file system from the first partition.
[0056] Step (b2): Utilize the initial root file system to obtain the key for transparent encryption.
[0057] Step (b3): Open the second partition based on the key.
[0058] Step (b4): Utilize the initial root file system to mount the second partition onto the root file system through an overlay mechanism.
[0059] like Figure 4As shown, after the virtual machine is started and the kernel is loaded, the kernel can load the initial root file system from the first partition, so that the initial root file system can load the necessary system modules required for communication, such as network / virtualization communication components, and then start mounting the encrypted data disk (such as the Linux Unified Key Setup (LUKS) method). Specifically, Figure 4 As shown, the initial root file system can be used to obtain the key for transparent encryption from the Trusted Key Service (TKS) through the host. Subsequently, it is determined whether the virtual machine is being loaded for the first time, that is, whether the virtual machine is being started for the first time. If this is not the first time the virtual machine is started, the second partition is opened based on the key, and transparent encryption and decryption of the data in the second partition is achieved. The initial root file system is then used to mount the second partition onto the root file system through an overlay mechanism (i.e., mounting the second partition), thereby encrypting and decrypting all sensitive data during the virtual machine's operation.
[0060] like Figure 4 As shown in the figure, when the virtual machine is started for the first time, before opening the second partition, you can use the encryption tool to initialize the second partition (blank partition), and then use the obtained key to encrypt and initialize the second partition (i.e., partition initialization full disk encryption). That is, use the initial root file system to configure the second partition to be transparently encrypted using the key. Specifically, Figure 4 As shown, before the above step (b3), the above step S104 may further include the following step (b5): Step (b5): When the virtual machine is started for the first time, the second partition is configured using the initial root file system to be transparently encrypted using the key.
[0061] In the above implementation, the partition encryption scheme is combined with the external key management service to achieve secure data persistence and ensure the stateful restart of the virtual machine. That is, private data will not be lost or leaked after the virtual machine is shut down, and private data can be restored after restart.
[0062] The following describes in detail the specific implementation of obtaining the key for transparent encryption using the initial root file system in the above step (b2).
[0063] Specifically, the initial root file system of the virtual machine can be used to send a key acquisition request to the trusted key service via the host machine of the virtual machine, wherein the key acquisition request includes the remote attestation evidence of the virtual machine. The trusted key service is used to remotely attest the virtual machine based on the remote attestation evidence, and when the virtual machine is determined to be trustworthy through remote attestation, the locally stored key is sent to the initial root file system via the host machine; thereafter, the initial root file system receives the key.
[0064] In this disclosure, Figure 4 As shown, the initial root file system of the virtual machine can first send a key acquisition request including the remote attestation evidence of the virtual machine to the transit service in the host machine of the virtual machine to obtain the encryption key of the second partition; after the transit service receives the key acquisition request, it can forward the key acquisition request including the remote attestation evidence of the virtual machine to the trusted key service to obtain the encryption key of the second partition from the trusted key service; after the trusted key service obtains the key acquisition request, it can parse the key acquisition request to obtain the remote attestation evidence of the virtual machine; thereafter, the trusted key service remotely attests the virtual machine based on the remote attestation evidence to determine whether the virtual machine is running in a trusted execution environment, that is, to determine whether the virtual machine is trustworthy; only when the trusted key service determines that the virtual machine is trustworthy through remote attestation, will the locally stored key be sent to the initial root file system via the host machine.
[0065] In the present disclosure, the remote attestation evidence of a virtual machine may include a remote attestation report, wherein the virtual machine may be measured during the startup and running stages to obtain corresponding measurement values, which are included in the remote attestation report; thereafter, a measurement baseline value may be determined based on the virtual machine image, and then the measurement value may be compared with the measurement baseline value. If the two are consistent, the virtual machine is determined to be trustworthy; otherwise, the virtual machine is determined to be untrustworthy.
[0066] In the above implementation, the external key management service based on the remote attestation solution implements trusted key distribution, which can prevent the leakage of encrypted virtual machine data due to key leakage.
[0067] In a possible implementation, the above method for a trusted virtual machine may further include the following two steps: After mounting the second partition to the root file system, start the init process; The init process is used to initialize the root file system, and the data generated during the operation of the virtual machine is stored in the mounted second partition in a transparently encrypted form.
[0068] In this disclosure, the init process is the first user-level process started by the kernel. Its process number is always 1, also known as process 1. After the second partition is mounted to the root file system, that is, after the encrypted data disk is mounted, the init process can be started, and then control of the virtual machine is transferred to the init process. The init process completes the initialization of the operating system and writes the dynamically generated data to the second partition part3, which is mounted via the overlay.
[0069] Figure 5This is a block diagram of a device for a trusted virtual machine according to an exemplary embodiment. The device 300 for a trusted virtual machine is applied to a virtual machine deployed in a trusted execution environment. The operating system image of the virtual machine includes a root file system and a kernel. The root file system and the kernel are stored in a first partition. The first partition is also used to store a hash tree corresponding to the root file system and a hash value of the root node of the hash tree. The first partition is a read-only partition. Figure 5 As shown, the apparatus 300 for a trusted virtual machine includes: A kernel startup module 301 is configured to start the kernel based on the hash value when the virtual machine is started; A verification module 302 is configured to perform an integrity check on the root file system based on the hash value and the hash tree; A first mounting module 303 is configured to mount the root file system if the root file system passes the integrity check; The second mounting module 304 is configured to mount the second partition onto the root file system; wherein the second partition is a read-write partition, configured to store data generated by the virtual machine during operation in a transparently encrypted form.
[0070] In the above technical solution, the root file system and kernel in the virtual machine's operating system image, as well as the hash tree corresponding to the root file system and the hash value of the root node of the hash tree, which are immutable static contents required for the operation of the virtual machine, are stored in a read-only manner in the first partition. This facilitates rapid integrity verification of the entire root file system based on the hash value and hash tree in the first partition. In addition, the data generated by the virtual machine during operation is stored in a readable and writable second partition in a transparently encrypted form. That is, dynamic data is transparently encrypted when it is written to the disk, thereby ensuring the security of the dynamic data when it is written to the disk and stored. The dynamic data is also decrypted imperceptibly when it is read out, thereby achieving encrypted and persistent storage of the dynamic data.
[0071] Optionally, the operating system image further includes an initial root file system, and the initial root file system is stored in the first partition; The second mounting module 304 includes: A loading submodule, configured to load the initial root file system from the first partition; an opening submodule, configured to obtain a key for transparent encryption using the initial root file system, and to open the second partition based on the key; The mounting submodule is used to use the initial root file system to mount the second partition onto the root file system through an overlay mechanism.
[0072] Optionally, the opening submodule includes: a sending submodule, configured to use the initial root file system to send a key acquisition request to a trusted key service via the host machine of the virtual machine; wherein the key acquisition request includes remote attestation evidence of the virtual machine, the trusted key service is configured to remotely attest the virtual machine based on the remote attestation evidence, and when the virtual machine is determined to be trustworthy through the remote attestation, send the locally stored key via the host machine to the initial root file system; The receiving submodule is configured to receive the key via the initial root file system.
[0073] Optionally, the second mounting module 304 further includes: The configuration submodule is used to configure the second partition to be transparently encrypted using the key using the initial root file system when the virtual machine is started for the first time before the opening submodule opens the second partition based on the key.
[0074] Optionally, the apparatus 300 for a trusted virtual machine further includes: A startup module, configured to start an init process after mounting the second partition to the root file system; The first storage module is used to initialize the root file system using the init process, and store the data generated by the virtual machine during operation in the mounted second partition in a transparently encrypted form.
[0075] Optionally, when the virtual machine is started for the first time, the apparatus 300 for a trusted virtual machine further includes: An acquisition module, configured to acquire the hash tree and the hash value; a second storage module, configured to store the hash tree, the hash value, the root file system, and the kernel in the first partition; An initialization module is used to initialize the second partition as an empty partition.
[0076] Optionally, the verification module 302 includes: A measurement submodule, configured to measure the root file system based on the hash tree to obtain a measurement value of the root node; The determination submodule is configured to determine whether the root file system passes the integrity check if the metric value is consistent with the hash value.
[0077] In addition, the present disclosure also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the above-mentioned method for a trusted virtual machine provided by the present disclosure.
[0078] The present disclosure also provides a computer program product, including a computer program, which implements the steps of the above-mentioned method for a trusted virtual machine provided by the present disclosure when the computer program is executed by a processor.
[0079] Reference below Figure 6 , which shows a schematic diagram of the structure of an electronic device (e.g., a terminal device or a server) 600 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0080] like Figure 6 As shown, electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 602 or programs loaded from a storage device 608 into a random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing device 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to bus 604.
[0081] Typically, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or by wire to exchange data. Figure 6 The electronic device 600 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.
[0082] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0083] It should be noted that the computer-readable medium described above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. Computer-readable storage media may include, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wire, optical cable, RF (radio frequency), or any suitable combination thereof.
[0084] In some embodiments, the client and server can communicate using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.
[0085] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0086] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device: when the virtual machine is started, starts the kernel based on the hash value, wherein the operating system image of the virtual machine includes a root file system and a kernel, and the root file system and the kernel are stored in a first partition, and the first partition is also used to store a hash tree corresponding to the root file system and a hash value of the root node of the hash tree, and the first partition is a read-only partition; according to the hash value and the hash tree, the root file system is checked for integrity; if the root file system passes the integrity check, the root file system is mounted; the second partition is mounted on the root file system; wherein the second partition is a read-write partition, which is used to store data generated by the virtual machine during operation in a transparently encrypted form.
[0087] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0088] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0089] The modules described in the embodiments of the present disclosure may be implemented in software or hardware. In some cases, the name of a module does not necessarily define the module itself. For example, a kernel startup module may also be described as "a module that starts the kernel based on the hash value when the virtual machine is started."
[0090] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0091] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0092] According to one or more embodiments of the present disclosure, Example 1 provides a method for a trusted virtual machine, the method being applied to a virtual machine deployed in a trusted execution environment, wherein the operating system image of the virtual machine includes a root file system and a kernel, the root file system and the kernel being stored in a first partition, the first partition being further used to store a hash tree corresponding to the root file system and a hash value of a root node of the hash tree, and the first partition being a read-only partition; The method comprises: When the virtual machine is started, starting the kernel based on the hash value; Performing an integrity check on the root file system according to the hash value and the hash tree; If the root file system passes the integrity check, mounting the root file system; The second partition is mounted on the root file system; wherein the second partition is a read-write partition, which is used to store data generated by the virtual machine during operation in a transparent encrypted form.
[0093] According to one or more embodiments of the present disclosure, Example 2 provides the method of Example 1, wherein the operating system image further includes an initial root file system, and the initial root file system is stored in the first partition; Mounting the second partition on the root file system includes: Loading the initial root file system from the first partition; Obtaining a key for transparent encryption using the initial root file system, and opening the second partition based on the key; The second partition is mounted on the root file system by using the initial root file system through an overlay mechanism.
[0094] According to one or more embodiments of the present disclosure, Example 3 provides the method of Example 2, wherein obtaining a key for transparent encryption using the initial root file system includes: Using the initial root file system, a key acquisition request is sent to a trusted key service via the host machine of the virtual machine; wherein the key acquisition request includes remote attestation evidence of the virtual machine, and the trusted key service is configured to remotely attest the virtual machine based on the remote attestation evidence, and when the virtual machine is determined to be trustworthy through the remote attestation, send the locally stored key to the initial root file system via the host machine; The initial root file system receives the key.
[0095] According to one or more embodiments of the present disclosure, Example 4 provides the method of Example 2, wherein before the step of opening the second partition based on the key, the step of mounting the second partition to the root file system further includes: When the virtual machine is started for the first time, the second partition is configured using the initial root file system to be transparently encrypted using the key.
[0096] According to one or more embodiments of the present disclosure, Example 5 provides the method of Example 1, further comprising: After mounting the second partition to the root file system, starting the init process; The root file system is initialized by utilizing the init process, and data generated by the virtual machine during operation is stored in the mounted second partition in a transparently encrypted form.
[0097] According to one or more embodiments of the present disclosure, Example 6 provides the method of Example 1, wherein when the virtual machine is started for the first time, the method further includes: Obtaining the hash tree and the hash value; Storing the hash tree, the hash value, the root file system, and the kernel in the first partition; Initialize the second partition as an empty partition.
[0098] According to one or more embodiments of the present disclosure, Example 7 provides the method of Example 1, wherein performing integrity verification on the root file system according to the hash value and the hash tree includes: Measuring the root file system based on the hash tree to obtain a measurement value of the root node; If the metric value is consistent with the hash value, it is determined that the root file system passes the integrity check.
[0099] According to one or more embodiments of the present disclosure, Example 8 provides a device for a trusted virtual machine, the device being applied to a virtual machine deployed in a trusted execution environment, wherein an operating system image of the virtual machine includes a root file system and a kernel, the root file system and the kernel being stored in a first partition, the first partition being further used to store a hash tree corresponding to the root file system and a hash value of a root node of the hash tree, and the first partition being a read-only partition; The device comprises: A kernel startup module, configured to start the kernel based on the hash value when the virtual machine is started; A verification module, configured to perform an integrity check on the root file system based on the hash value and the hash tree; A first mounting module, configured to mount the root file system if the root file system passes the integrity check; The second mounting module is used to mount the second partition onto the root file system; wherein the second partition is a read-write partition, which is used to store data generated by the virtual machine during operation in a transparently encrypted form.
[0100] According to one or more embodiments of the present disclosure, Example 9 provides a computer-readable medium having a computer program stored thereon, which implements the steps of the method described in any one of Examples 1-7 when executed by a processing device.
[0101] According to one or more embodiments of the present disclosure, Example 10 provides an electronic device, including: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of the method described in any one of Examples 1-7.
[0102] According to one or more embodiments of the present disclosure, Example 11 provides a computer program product, including a computer program, which implements the steps of any one of the methods of Examples 1-7 when executed by a processor.
[0103] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the present disclosure is not limited to technical solutions formed by specific combinations of the aforementioned technical features. It also encompasses other technical solutions formed by any combination of the aforementioned technical features or their equivalents, without departing from the scope of the above disclosure. For example, a technical solution formed by replacing the aforementioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0104] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0105] Although the subject matter has been described using language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims. Regarding the apparatus in the above-described embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method and will not be elaborated upon here.
Claims
1. A method for a trusted virtual machine, characterized in that: The method is applied to a virtual machine deployed in a trusted execution environment, wherein the operating system image of the virtual machine includes a root file system and a kernel, the root file system and the kernel are stored in a first partition, the first partition is further used to store a hash tree corresponding to the root file system and a hash value of a root node of the hash tree, and the first partition is a read-only partition; The method comprises: When the virtual machine is started, starting the kernel based on the hash value; Performing an integrity check on the root file system according to the hash value and the hash tree; If the root file system passes the integrity check, mounting the root file system; The second partition is mounted on the root file system; wherein the second partition is a read-write partition, which is used to store data generated by the virtual machine during operation in a transparent encrypted form.
2. The method according to claim 1, characterized in that The operating system image further includes an initial root file system, and the initial root file system is stored in the first partition; Mounting the second partition on the root file system includes: Loading the initial root file system from the first partition; Obtaining a key for transparent encryption using the initial root file system, and opening the second partition based on the key; The second partition is mounted on the root file system by using the initial root file system through an overlay mechanism.
3. The method according to claim 2, characterized in that The obtaining of a key for transparent encryption using the initial root file system includes: Using the initial root file system, a key acquisition request is sent to a trusted key service via the host machine of the virtual machine; wherein the key acquisition request includes remote attestation evidence of the virtual machine, and the trusted key service is configured to remotely attest the virtual machine based on the remote attestation evidence, and when the virtual machine is determined to be trustworthy through the remote attestation, send the locally stored key to the initial root file system via the host machine; The initial root file system receives the key.
4. The method according to claim 2, characterized in that Before the step of opening the second partition based on the key, the step of mounting the second partition onto the root file system further includes: When the virtual machine is started for the first time, the second partition is configured using the initial root file system to be transparently encrypted using the key.
5. The method according to claim 1, wherein The method further comprises: After mounting the second partition to the root file system, starting the init process; The root file system is initialized by utilizing the init process, and data generated by the virtual machine during operation is stored in the mounted second partition in a transparently encrypted form.
6. The method according to claim 1, wherein When the virtual machine is started for the first time, the method further includes: Obtaining the hash tree and the hash value; Storing the hash tree, the hash value, the root file system, and the kernel in the first partition; Initialize the second partition as an empty partition.
7. The method according to claim 1, characterized in that The performing integrity check on the root file system according to the hash value and the hash tree includes: Measuring the root file system based on the hash tree to obtain a measurement value of the root node; If the metric value is consistent with the hash value, it is determined that the root file system passes the integrity check.
8. A device for a trusted virtual machine, characterized in that: The device is applied to a virtual machine deployed in a trusted execution environment. The operating system image of the virtual machine includes a root file system and a kernel. The root file system and the kernel are stored in a first partition. The first partition is also used to store a hash tree corresponding to the root file system and a hash value of a root node of the hash tree. The first partition is a read-only partition. The device comprises: A kernel startup module, configured to start the kernel based on the hash value when the virtual machine is started; A verification module, configured to perform an integrity check on the root file system based on the hash value and the hash tree; A first mounting module, configured to mount the root file system if the root file system passes the integrity check; The second mounting module is used to mount the second partition onto the root file system; wherein the second partition is a read-write partition, which is used to store data generated by the virtual machine during operation in a transparently encrypted form.
9. A computer-readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 7 are implemented.
10. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 7.
11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Method and system for operating multiple virtual machines
CN102521016A
Systems and methods for providing file level recovery
CN110795278A
Program integrity verification system and method suitable for read-only file system
CN115795432A
Remote attestation method and device, electronic equipment and storage medium
CN117834627A
Container virtualization method and device based on edge computing, equipment and storage medium
CN119065792A