Instruction processing method, electronic equipment, chip system and readable storage medium
By executing REE instructions in TEE and performing security monitoring, the low security problem of REE is solved, the stability and security of REE are improved, and malicious attacks are prevented.
Patent Information
- Application Number
- CN202411110601.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-13
- Publication Date
- 2025-10-03
AI Technical Summary
Rich execution environments (REEs) in electronic devices have low security and are vulnerable to malware attacks, making them difficult to support complex and computationally intensive tasks such as biometric authentication for AI or computer vision.
The first instruction in the rich execution environment is executed in the trusted execution environment (TEE), and security monitoring is performed through the SMC instruction to ensure that the instructions executed in the REE are more secure in the TEE, including access control of the process's page table entries and dynamic data, as well as security checks.
It improves the security of the rich execution environment, prevents malicious tampering and attacks, and ensures the stability and security of the process during execution.
Smart Images

Figure CN120744997A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer security technology, and in particular to an instruction processing method, electronic equipment, chip system and readable storage medium. Background Art
[0002] The execution environment in an electronic device may include a rich execution environment (REE) and a trusted execution environment (TEE). Among them, REE is a general-purpose, open execution environment that can support the operation of various general-purpose operating systems (such as Android and iOS). Due to the openness of REE, REE is vulnerable to malware attacks, such as the theft of sensitive data. TEE is a secure area in an electronic device that can provide an isolated, trusted execution environment that can protect the data and code therein from external attacks. For example, trusted execution environments are often used in scenarios that require high security, such as mobile payments, fingerprint recognition, data encryption, etc.
[0003] However, TEEs face limitations in processing power and memory resources, making them difficult to support complex and computationally intensive tasks, such as biometric authentication based on artificial intelligence (AI) or computer vision (CV). Therefore, some computationally intensive tasks can be performed in REEs. However, because REEs are less secure than TEEs, the data and programs running in them face certain security risks. Therefore, improving the security of rich execution environments is an urgent issue. Summary of the Invention
[0004] Embodiments of the present application provide an instruction processing method, an electronic device, a chip system, and a readable storage medium, which can improve the security of a rich execution environment.
[0005] In a first aspect, an embodiment of the present application provides an instruction processing method, which is applied to an electronic device, wherein the execution environment of the electronic device includes a rich execution environment and a trusted execution environment. The method includes: in response to detecting that a first instruction is called in the rich execution environment; in the trusted execution environment, executing a security monitoring call SMC instruction corresponding to the first instruction.
[0006] It can be seen that changing the execution of the first instruction in the rich execution environment to executing the SMC instruction corresponding to the first instruction in the trusted execution environment can avoid executing unsafe instructions in the rich execution environment, thereby helping to improve the security of the rich execution environment.
[0007] In one possible implementation, the rich execution environment includes a virtual trusted isolation environment, and / or a virtual machine monitor runs in the rich execution environment; the first instruction includes: an instruction called in the virtual trusted isolation environment, and / or an instruction called by the virtual machine monitor.
[0008] It can be seen that by implementing the embodiments of the present application, the security of the virtual trusted isolation environment and the virtual machine monitor can be improved.
[0009] In a possible implementation, the first instruction is a read instruction and / or a write instruction for the first register.
[0010] In a possible implementation, the first register includes one or more of the following: a status register, a page table base address register, and a system control register.
[0011] In one possible implementation, the first instruction is an instruction in a first process; the method further includes: in response to the first process being scheduled for the first time and the access permission of the page table of the first process being read-only, executing the first process.
[0012] It can be seen that executing the first process while ensuring that the access permission of the page table of the first process is read-only is beneficial to preventing the SMC instruction corresponding to the first instruction from being tampered with.
[0013] In a possible implementation, the method further includes: in response to the first process being scheduled for the first time, modifying the access permission of the page table of the first process to read-only.
[0014] It can be seen that if the access permission of the page table of the first process is not read-only, it can be modified to read-only, which is helpful to prevent the SMC instruction corresponding to the first instruction from being tampered with.
[0015] In one possible implementation, the first instruction is an instruction in a first process, the first process includes at least one page table entry, and the at least one page table entry includes a first page table entry; the method also includes: in response to the first process being scheduled for the first time and the access permission of the first page table entry is read-only, executing the first process.
[0016] In this way, the first page table entry can be ensured to be read-only, and the first page table entry can be prevented from being maliciously tampered with, which is beneficial for preventing the first process from being attacked during execution.
[0017] In a possible implementation, the method further includes: in response to the first process being scheduled for the first time, modifying the access permission of the first page table entry to read-only.
[0018] It can be seen that if the access permission of the first page table is not read-only, it can be modified to read-only. This is beneficial to prevent the first page table entry from being maliciously tampered with and to avoid the first process from being attacked during execution.
[0019] In a possible implementation, the first page table entry includes a page table entry mapped to the kernel code.
[0020] In this way, the kernel code can be guaranteed to be read-only, and the page table of the first process can be prevented from being maliciously tampered with, which is beneficial to preventing the first process from being attacked during execution.
[0021] In one possible implementation, the first instruction is an instruction in a first process, and the dynamic data of the first process includes at least first dynamic data; the method also includes: in response to the first process being scheduled for the first time and the access permission of the first dynamic data being non-writable, executing the first process.
[0022] This helps prevent the execution of malicious code, thereby helping to improve the security and stability of the execution of the first process.
[0023] In a possible implementation, the method further includes: in response to the first process being scheduled for the first time, modifying the access permission of the first dynamic data to be non-writable.
[0024] In this way, after the access permission of the first dynamic data is modified to be non-writable, it is helpful to prevent the execution of malicious code.
[0025] In one possible implementation, the method further includes: performing a security check on the SMC instruction corresponding to the first instruction in a trusted execution environment; in response to the SMC instruction corresponding to the first instruction failing the security check, stopping execution of the first instruction and the SMC instruction corresponding to the first instruction, and generating a first alarm message.
[0026] Thus, when the SMC instruction of the first instruction fails the security check, it indicates that the first instruction may be an illegal instruction. In this case, promptly stopping the execution of the first instruction can prevent the rich execution environment from being attacked, thereby improving the security of the rich execution environment. The generated first warning information is useful for issuing warnings to users and facilitating system maintenance.
[0027] In a second aspect, an embodiment of the present application provides an instruction processing device. When the instruction processing device runs on an electronic device, the electronic device can execute the method described in the first aspect or any one of the implementations of the first aspect.
[0028] In a third aspect, an embodiment of the present application provides an electronic device, comprising: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the electronic device to execute the method described in the first aspect or any one of the implementation methods of the first aspect.
[0029] In a fourth aspect, an embodiment of the present application provides a chip system, which includes at least one processor, a memory and an interface circuit, wherein the memory, the interface circuit and at least one processor are interconnected through lines, and program instructions are stored in at least one memory; when the program instructions are executed by the processor, the chip system executes the method described in the first aspect or any one of the implementation methods of the first aspect.
[0030] In a fifth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when executed on an electronic device, enables the electronic device to execute the method described in the first aspect or any one of the implementations of the first aspect.
[0031] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium comprising instructions, which, when executed on an electronic device, enables the electronic device to execute the method described in the first aspect or any one of the implementations of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application;
[0033] Figure 2 A schematic diagram of the software structure of an electronic device provided in an embodiment of the present application;
[0034] Figure 3 A schematic diagram of the architecture of a central processing unit provided in an embodiment of the present application;
[0035] Figure 4 A flowchart of an instruction processing method provided in an embodiment of the present application;
[0036] Figure 5 A schematic diagram of the architecture of a processor of an electronic device provided in an embodiment of the present application;
[0037] Figure 6 A flowchart of executing an SMC instruction provided in an embodiment of the present application. DETAILED DESCRIPTION
[0038] The embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0039] The terms "first," "second," "third," and "fourth," etc., in the specification, claims, and drawings of this application are used to distinguish between different objects, not to describe a particular order. In addition, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements, but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.
[0040] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0041] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0042] As used in this specification, the terms "component," "module," "system," and the like are used to represent computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and a computing device can be a component. One or more components can reside in a process and / or an execution thread, and a component can be located on a computer and / or distributed between two or more computers. In addition, these components can be executed from various computer-readable media having various data structures stored thereon. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component on a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).
[0043] In order to better understand the technical solutions provided by the embodiments of the present application, before describing the technical solutions of the embodiments of the present application, the hardware structure of the electronic devices (such as mobile phones, tablet computers, laptop computers, etc.) to which the embodiments of the present application are applicable is first described in conjunction with the accompanying drawings.
[0044] For example, see Figure 1 , Figure 1 Schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. It should be understood that the electronic device 100 may have more Figure 1 More or fewer components may be shown, two or more components may be combined, or the components may be arranged differently. Figure 1 The various components shown in the drawings may be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.
[0045] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0046] It is understood that the structure shown in the embodiment of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include Figure 1 More or fewer components may be shown, or some components may be combined or separated, or the components may be arranged differently. Figure 1 The components shown can be implemented in hardware, software, or a combination of software and hardware.
[0047] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.
[0048] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0049] The processor 110 may further include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory.
[0050] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.
[0051] It is understood that the interface connection relationship between the modules illustrated in the embodiments of the present application is merely an illustrative illustration and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods from the above embodiments, or a combination of multiple interface connection methods.
[0052] Electronic device 100 implements display functionality through a GPU, display screen 194, and an application processor. The GPU is a microprocessor for image processing that connects display screen 194 and the application processor. Processor 110 may include one or more GPUs that execute program instructions to generate or change display information.
[0053] Display screen 194 is used to display images, videos, and the like. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), or a quantum dot light-emitting diode (QLED). In some embodiments, electronic device 100 may include one or N display screens 194, where N is a positive integer greater than one.
[0054] The electronic device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.
[0055] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU can enable intelligent cognitive applications in electronic device 100, such as image recognition, face recognition, speech recognition, and text comprehension.
[0056] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage functions. For example, compressed driver files and other files can be stored in the external memory card.
[0057] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, applications required for at least one function (such as a fingerprint recognition function), etc. The data storage area can store data (such as touch data, etc.) created during the use of the electronic device 100. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0058] The electronic device 100 can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.
[0059] The pressure sensor 180A is used to sense the pressure signal and convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194 .
[0060] The gyro sensor 180B may be used to determine the motion posture of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (ie, x, y, and z axes) may be determined by the gyro sensor 180B.
[0061] The distance sensor 180F is used to measure distance. The electronic device 100 can measure distance by infrared or laser.
[0062] The ambient light sensor 180L is used to sense the brightness of the ambient light. The electronic device 100 can adaptively adjust the brightness of the display screen 194 based on the sensed ambient light brightness. The ambient light sensor 180L can also be used to automatically adjust the white balance when taking photos.
[0063] The touch sensor 180K is also called a "touch panel." The touch sensor 180K can be disposed on the display screen 194. The touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen." The touch sensor 180K is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operations to the application processor to determine the type of touch event. Visual output related to the touch operations can be provided via the display screen 194. In other embodiments, the touch sensor 180K can also be disposed on the surface of the electronic device 100, at a location different from that of the display screen 194.
[0064] The buttons 190 include a power button, a volume button, and the like. The buttons 190 may be mechanical buttons or touch buttons. The electronic device 100 may receive key inputs and generate key signal inputs related to user settings and function control of the electronic device 100.
[0065] In addition, operating systems run on the above components, such as the iOS operating system, the Android open source operating system, and the Windows operating system.
[0066] The operating system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservice architecture, or a cloud architecture. The embodiment of the present application takes the Android system with a layered architecture as an example to illustrate the software structure of the electronic device 100. It should be noted that although the embodiment of the present application is described using the Android system as an example, its basic principles are also applicable to electronic devices based on operating systems such as iOS or Windows.
[0067] The operating system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservice architecture, or a cloud architecture. The embodiment of the present application takes the Android system with a layered architecture as an example to illustrate the software structure of the electronic device 100. It should be noted that although the embodiment of the present application is described using the Android system as an example, its basic principles are also applicable to electronic devices based on operating systems such as iOS or Windows.
[0068] Figure 2 1 is a schematic diagram of the software structure of an electronic device 100 provided in an embodiment of the present application. The software structure adopts a layered architecture, which divides the software into several layers, each with a clear role and division of labor. The layers communicate with each other through software interfaces. Taking the Android system running on an AP as an example, in some embodiments, the Android system is divided into five layers, from top to bottom, namely the application layer, the application framework layer (framework), the system runtime layer, the hardware abstraction layer (HAL), and the kernel layer (kernel).
[0069] The application layer may include a series of application packages. Application packages may include applications such as camera, calendar, news, music, SMS, gallery, phone, Bluetooth, video, and map. The application layer may also include a system user interface (system UI), which is used to display the interface of the electronic device 100, such as the call interface, desktop, and application interface.
[0070] The application framework layer provides an application programming interface (API) and programming framework for applications in the application layer. The application framework layer includes some predefined functions. For example, the application framework layer may include a window manager, content provider, view system, telephony manager, resource manager, notification manager, etc. The telephony manager is used to provide call functions for electronic device 100, such as managing call status (including answering and hanging up).
[0071] The system runtime layer consists of two parts: the C / C++ library and the Android runtime. The Android runtime includes the runtime environment, primarily responsible for scheduling and management of the Android system. The C / C++ library primarily includes the media framework, surface manager, 3D graphics library (e.g., OpenGL ES), and 2D graphics engine (e.g., SGL).
[0072] The hardware abstraction layer (HAL) isolates the application framework layer from the kernel layer, preventing the Android system from being overly dependent on the kernel layer. This allows application framework layer development to proceed without driver considerations. The HAL can include multiple functional modules, such as the display HAL, camera HAL, audio HAL, and sensor HAL.
[0073] The kernel layer is the layer between hardware and software. The kernel layer contains at least display driver, camera driver, audio driver, sensor driver, and shared memory driver.
[0074] Below, some of the terms involved in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0075] 1. Process
[0076] A process is the entity that represents a running program in an electronic device, such as a computer. A process is an independent unit used by the electronic device's system to allocate and schedule resources. Alternatively, a process is the dynamic execution of a program, containing all the resources required for program execution, such as code, data, stack memory, and state information. In electronic devices, multiple processes can execute concurrently within the same timeframe to improve system resource utilization and throughput.
[0077] A process consists of one or more instructions, along with the data and resources required to execute those instructions, and information about the process's status (e.g., running, ready, blocked, etc.). A process is executed by executing its instructions. When a process is created by the operating system, the instructions and data for the program corresponding to that process are loaded into a designated memory area, and then executed by the central processing unit (CPU).
[0078] 2. Pages, page tables, and page table entries
[0079] (1) page
[0080] Pages divide the virtual address space and physical memory into fixed-size blocks, each of which is called a page. Pages are the basic unit of memory management.
[0081] (2) Page table
[0082] The page table is a data structure used by the operating system for memory management. The main function of the page table is to map the addresses in the virtual address space of a process (i.e., virtual addresses) to the actual addresses in physical memory (i.e., physical addresses), allowing the process to access the data and instructions in its memory space.
[0083] A series of page tables can be organized into multi-level page tables. Multi-level page tables divide the virtual address space into multiple levels, with each level corresponding to a page table. In a multi-level page table, the top-most page table is called a level-1 page table.
[0084] The address of the starting location of the page table in memory is called the page table base address (PTBA). Correspondingly, the first-level page table base address (PTBA) refers to the address of the starting location of the first-level page table in memory.
[0085] Each process running in the operating system has a corresponding page table. The process's page table records the mapping between all pages in the process's virtual address space and pages in physical memory. This mapping mechanism allows the operating system to provide each process with an independent, contiguous virtual address space, thereby protecting the process's memory from direct access by other processes and making memory management more flexible and efficient. For example, when a process attempts to access a virtual address, the operating system searches the process's page table to determine the physical address corresponding to the virtual address.
[0086] (3) Page table entry (PTE)
[0087] Each entry in a page table is called a page table entry. In other words, a page table consists of one or more page table entries. A page table entry stores the mapping between a virtual page and a physical page, as well as other attributes of the page (such as access permissions and whether it is cached).
[0088] The access rights of a page table entry refer to the access rights to the page (physical page or virtual page) mapped by the page table entry. The access rights of a page table entry may include read permission (including readable or unreadable), write permission (including writable or unwritable), and execute permission (including executable or unexecutable). Among them, readable means that read operations are allowed on the page; writable means that write operations are allowed on the page; executable means that code execution is allowed on the page. Conversely, unreadable means that read operations are not allowed on the page; unwritable means that write operations are not allowed on the page; and unexecutable means that code execution is not allowed on the page.
[0089] The access permissions for each page table entry can be set independently. The access permissions for different page table entries can be the same or different. For example, the access permissions for a page table entry can be set to: readable, writable, and executable; or readable, non-writable, and non-executable; or non-readable, non-writable, and non-executable.
[0090] 3. Central Processing Unit
[0091] The central processing unit (CPU), as the computing and control core of electronic devices, is the final execution unit for information processing and program running.
[0092] See also Figure 3 , is a schematic diagram of the architecture of a central processing unit. Figure 3 As shown, the central processing unit (hereinafter referred to as the processor) in the embodiment of the present application can be a processor of an advanced reduced instruction set computer machines (ARM) architecture.
[0093] ARM's TrustZone technology divides the processor into two isolated zones—the secure world and the normal world—to isolate and protect data. When the processor is operating in the normal state, it can access resources in the normal world but not those in the secure world. When the processor is operating in the secure state, it can access resources in both the normal and secure worlds.
[0094] (1) Trusted Execution Environment
[0095] The secure world within a processor is also known as a Trusted Execution Environment (TEE). A TEE typically provides an independent execution space, providing an isolated, trusted execution environment for sensitive data, protecting the data and code within it from external attacks. For example, TEEs are often used in scenarios requiring high security, such as mobile payments, fingerprint recognition, and data encryption.
[0096] like Figure 3 As shown on the right side of the figure, the trusted execution environment can include a lightweight kernel or microkernel, which can be called a TEE kernel. The TEE kernel can be used to manage the internal resources of the trusted execution environment and run specific applications (hereinafter referred to as applications) in this secure environment. Among them, the application running in the trusted execution environment is called a trusted application (TA).
[0097] (2) Rich Execution Environment
[0098] The normal world within a processor is also known as a rich execution environment (REE). This refers to traditional operating system execution environments, such as those found on Android and iOS. A REE is an open environment, and compared to a trusted execution environment (TEE), data or programs within it are more vulnerable to malware attacks, such as sensitive data theft and mobile payment fraud.
[0099] The rich execution environment and the trusted execution environment can interact through certain mechanisms. For example, applications in the rich execution environment can call services in the trusted execution environment through the trusted execution environment application programming interface (API) to complete operations that require high security, such as fingerprint entry and comparison, payment verification and authentication, etc.
[0100] like Figure 3 As shown on the left side of the figure, a rich execution environment can run one or more virtual machines (VMs) and a hypervisor. A guest operating system (Guest OS) and various applications, called client applications (CA), can run on the VMs. The Guest OS can include one or more operating systems, such as Android, Linux, and iOS. The primary responsibilities of the hypervisor include managing the VMs running in the rich execution environment, such as processing and forwarding messages between VMs.
[0101] (3) Abnormal level
[0102] ARM architecture processors may include four exception levels (EL), from EL0 to EL3, each with different permissions and features. For example, please refer to Table 1, which shows the various exception levels and their application scopes. For example, ELn represents exception level n, where n can be an integer between 0 and 3. In ELn, as n increases, the execution permissions corresponding to the exception level also increase accordingly. EL0 is known as unprivileged execution or user mode, and applications typically run at EL0. EL1 is known as kernel mode, with higher execution permissions. The operating system kernel and drivers, for example, run at EL1. For example, the Android operating system runs at EL1. EL2 is known as hypervisor mode; in other words, the virtual machine monitor runs at EL2. EL3 is known as monitor mode. Typically, in a processor, the exception levels that need to be implemented include EL0 and EL1. Depending on the actual application requirements, you can choose whether to implement EL2 and / or EL3.
[0103] Table 1 Abnormal levels and application scope
[0104] ELn Application EL0 app EL1 Operating system kernel and drivers EL2 Hypervisor EL3 secure monitor
[0105] The Secure Monitor can be considered the gateway between the Normal World and the Secure World. Running at EL3 and with elevated execution privileges, the Secure Monitor is able to switch between the two worlds and manage access to secure resources. The Secure Monitor is also responsible for processing calls from the Normal World to the Secure World and performing necessary security checks.
[0106] (4) Memory management unit (MMU)
[0107] The MMU is an integral part of the processor, primarily responsible for processing memory access requests and providing memory protection. The MMU translates virtual addresses (or logical addresses) requested by users into actual physical addresses, enabling the processor to access physical memory. Furthermore, the MMU uses mechanisms such as page tables to provide each process or task with an independent virtual memory space and controls access to these spaces. Specifically, the MMU controls access to physical memory using the access permissions (such as read, write, and execute permissions) in the page table. When the processor attempts to access a virtual address, the MMU checks the access permissions of the corresponding page table entry to ensure that the access is legal. If the attempted access violates the access permissions, the MMU generates an access exception, preventing the illegal access. This indirectly prevents unauthorized tampering with the page table, thereby improving system security and stability.
[0108] 4. Program Status Register (PSR)
[0109] The program status register (SR), also known as the status register (SR), stores various status and control information during the processor's instruction execution. Information stored in the SR may include the result of instruction execution (such as the zero flag, sign flag, and overflow flag), interrupt enable / disable status, and program counter modification information. This information is crucial for the processor's instruction execution flow, exception handling, interrupt response, and conditional branching. For example, by reading the value of the SR, the program can make decisions such as whether to execute a jump or continue waiting for an interrupt.
[0110] The program status registers include the current program status register (CPSR) and the saved program status registers (SPSR). The move from status register (MRS) and move to status register (MSR) instructions allow you to control the processor's state, such as enabling interrupts and switching processor modes. In addition, the MRS instruction allows you to read the CPSR or SPSR. The MSR instruction allows you to write to the CPSR or SPSR.
[0111] 5. Translation table base register (TTBR)
[0112] The page table base address register is used to store the page table base address. The page table base address refers to the first address of the page table, indicating the starting position of the page table in physical memory.
[0113] In the ARM architecture, there are typically two page table base registers, TTBR0 and TTBR1. TTBR0 stores the base address of the user space's first-level page table. In user mode, the processor uses TTBR0 to access the user space page table to translate virtual addresses to physical addresses. TTBR1 stores the base address of the kernel space's first-level page table. In kernel mode, the processor uses TTBR1 to access the kernel space's page table to support the kernel's access and management of system resources.
[0114] When switching processes in user mode, the value of TTBR0 is updated to the base address of the first-level page table of the current process to ensure that the processor can correctly access the memory space of the process. In kernel mode, the value of TTBR1 usually remains unchanged because all kernel processes share the same set of kernel page tables.
[0115] 6. System control register (SCTLR)
[0116] The system control register is used to control system-level operations and behaviors. The system control register contains multiple control bits that can affect various processor behaviors, including memory management, exception handling, security, etc. For example, a certain bit in the system control register (usually bit 0, which can be called the MMU bit or simply the M bit) can be used to control whether the MMU is enabled or disabled. For example, when the M bit is set to 1, it indicates that the MMU is enabled; when the M bit is set to 0, it indicates that the MMU is disabled.
[0117] In such Figure 3 In the processor shown, the processing power and memory resources of the trusted execution environment (TEE) are limited, making it difficult for the TEE to support complex and computationally intensive tasks, such as biometric authentication based on artificial intelligence (AI) or computer vision (CV). Therefore, these computationally intensive tasks can be performed in a rich execution environment (REE). However, because the security of a REE is lower than that of a TEE, the data in the REE and the programs running in it face certain security risks.
[0118] In view of this, embodiments of the present application provide an instruction processing method, an electronic device, a chip system, and a readable storage medium, which can ensure the security of data and running programs in a rich execution environment.
[0119] See also Figure 4 , Figure 4 This is a flow chart of an instruction processing method provided by an embodiment of the present application. The instruction processing method can be applied to an electronic device, can be executed by the electronic device, can be executed by a processor in the electronic device, and can also be executed by a chip or chip system with processor functions in the electronic device. Among them, the execution environment of the electronic device includes a rich execution environment and a trusted execution environment. Figure 4 As shown, the instruction processing method may include but is not limited to the following steps:
[0120] S401: In a rich execution environment, it is detected that a first instruction is called.
[0121] For example, see Figure 5 , Figure 5 This is a schematic diagram of the architecture of a processor of an electronic device provided in an embodiment of the present application. Figure 5 As shown, the execution environment of the electronic device may include a rich execution environment (REE) and a trusted execution environment (TEE). The rich execution environment includes a virtual trusted isolation environment, and / or a virtual machine monitor (hypervisor) runs in the rich execution environment. One or more virtual machines may run in the rich execution environment, such as Figure 5 The virtual machines VM1 and VM2 are shown in FIG. In the virtual trusted isolation environment, one or more trusted applications (TA) can be run. The execution environment of VM1 can represent the virtual trusted isolation environment. Optionally, the virtual trusted isolation environment can be called a hypervisor TEE (HTEE). The virtual trusted isolation environment is different from other execution environments in the rich execution environment (such as Figure 5 The execution environments of VM2 shown in FIG4 are isolated from each other, thereby, to a certain extent, protecting the programs running in the virtual trusted isolation environment from the influence of other execution environments.
[0122] The virtual machines running in the rich execution environment can be managed and maintained by a virtual machine monitor. The operating system of the virtual machine monitor can be called the host operating system (host OS). Correspondingly, the operating system of the virtual machine can be called the guest OS. In the embodiment of the present application, a micro kernel can be used as the kernel of the operating system in the virtual trusted execution environment. Optionally, the Linux kernel can be used as the kernel in the VM2 operating system.
[0123] like Figure 5 As shown, the exception levels that can be implemented by the rich execution environment and the trusted execution environment can include EL0, EL1, EL2, and EL3. Applications run at EL0, the TEE kernel in the trusted execution environment and the kernel of the virtual machine in the rich execution environment run at EL1, the virtual machine monitor runs at EL2, and the security monitor runs at EL3.
[0124] The first instruction may include an instruction called in a virtual trusted isolation environment, and / or the first instruction may include an instruction called by a virtual machine monitor.
[0125] The first instruction being called in the virtual trusted isolation environment may include being called by an operating system (such as the aforementioned microkernel) of the virtual trusted isolation environment. Optionally, the microkernel of the virtual trusted isolation environment that calls the first instruction, or the virtual machine monitor that calls the first instruction, may be referred to as the caller of the first instruction.
[0126] The first instruction may include all or part of the instructions called in the rich execution environment. In response to the first instruction including part of the instructions called in the rich execution environment, the first instruction may include a read instruction and / or a write instruction for a first register. The read instruction for the first register may be used to perform a read operation on the first register, such as accessing data in the first register. The write instruction for the first register may be used to perform a write operation on the first register, such as writing data to the first register or modifying data in the first register.
[0127] The first register may include, but is not limited to, one or more of a program status register, a page table base register, and a system control register. The first instruction may include, but is not limited to, one or more of a write instruction and a read instruction to the program status register, a write instruction to the page table base register, and a write instruction to the system control register. Thus, through the first instruction, key functions such as controlling the processor's operating mode and managing the processor's memory can be implemented.
[0128] Optionally, in response to the first register including a program status register, the program status register may include at least one of a current program status register (CPSR) and a program status save register (SPSR). The first instruction may include a read instruction or a write instruction to the program status register. For example, the first instruction may include a write instruction to the current program status register and / or the program status save register, such as an MRS instruction. For another example, the first instruction may include a read instruction to the current program status register and / or the program status save register, such as an MSR instruction.
[0129] Optionally, in response to the first register including a page table base register (TTBR), the first instruction may include a write instruction to the page table base register. The first instruction may be used to initialize the page table. For example, when a process is created, the operating system may use the first instruction to write the page table base address of the page table into the page table base register so that the MMU can find and traverse the page table for address translation. The first instruction may also be used for dynamic memory management. For example, during the operation of the operating system, the operating system may update the page table base register or the page table itself through the first instruction according to memory usage to add, delete or merge page table entries, thereby dynamically adjusting the page table.
[0130] Optionally, the first register may include TTBR0 (TTBR0_EL2) with an exception level of 2 in the page table base register. TTBR0_EL2 is an instance of TTBR0 at EL2. It functions similarly to TTBR0, storing the page table base address and serving as a register for the virtual machine monitor. In other words, TTBR0_EL2 can be used to manage the mapping of virtual addresses to physical addresses in the virtual machine monitor.
[0131] Optionally, in response to the first register including a system control register (SCTLR), the first instruction may include a write instruction to the system control register, such as a write instruction to the M bit of the system control register. By writing an instruction to the M bit of the system control register, the MMU can be enabled or disabled. When the MMU is enabled, the processor maps virtual addresses to physical addresses according to the page table to implement virtual memory management. Disabling the MMU may bring about problems such as restrictions on memory management and application deployment, risks to system security and stability, etc.
[0132] Optionally, the write instruction to the system control register may include an MSR instruction, that is, the write operation to the system control register may be performed through the MSR instruction.
[0133] In one possible implementation, an electronic device may be started using secure boot. Secure boot is a security standard that helps ensure that only software trusted by the original equipment manufacturer (OEM) is used to start the device, thereby protecting the virtual machine monitor, programs, or data in the virtual trusted isolation environment from malicious tampering during the electronic device startup process.
[0134] S402: In the trusted execution environment, execute a security monitoring call SMC instruction corresponding to the first instruction.
[0135] Among them, the trusted execution environment can be Figure 5 shown.
[0136] Executing the SMC instruction corresponding to the first instruction in the trusted execution environment may include: performing a security check on the SMC instruction corresponding to the first instruction in the trusted execution environment; after ensuring that the SMC instruction corresponding to the first instruction passes the security check, implementing the operation indicated by the first instruction in the trusted execution environment. This process helps to ensure that the execution process of the first instruction can be isolated and protected at the hardware level. Specifically, the execution process of the SMC instruction corresponding to the first instruction can be referred to in Figure 6 And the following Figure 6 Description.
[0137] The Secure Monitor Call (SMC) instruction is a low-level system control instruction used to communicate with the System Management Controller (SMC) to directly manage and control system hardware resources. Within a trusted execution environment (TEE), SMC instructions can be used to invoke security services such as encryption, decryption, and signature verification to protect sensitive data and operations.
[0138] The SMC instruction corresponding to the first instruction is the instruction obtained by modifying the instruction type of the first instruction to an SMC instruction. The instruction content of the SMC instruction corresponding to the first instruction (excluding the instruction type) is the same as the instruction content of the first instruction, but the process of executing the instruction is different. In other words, the operation to be performed indicated by the SMC instruction corresponding to the first instruction is the same as the operation to be performed indicated by the first instruction; the execution environment of the SMC instruction corresponding to the first instruction is different from the execution environment of the first instruction.
[0139] For example, assuming that the first instruction in the rich execution environment is a write instruction to the system control register, executing the first instruction in the rich execution environment may indicate that the write operation to the system control register is performed in the rich execution environment. Correspondingly, executing the SMC instruction corresponding to the first instruction in the trusted execution environment may indicate that: a security check is performed on the SMC instruction corresponding to the first instruction in the trusted execution environment; after ensuring that the SMC instruction corresponding to the first instruction passes the security check, the write operation to the system control register is performed in the trusted execution environment.
[0140] In one possible implementation, during the development phase, the code for the SMC instruction corresponding to the first instruction can be added to the code file to which the first instruction belongs, through source code replacement or binary replacement, to replace the first instruction with the SMC instruction corresponding to the first instruction. In this way, when it is detected that the first instruction has been called, the SMC instruction corresponding to the first instruction can be executed. The code file to which the first instruction belongs can be a source code file or a binary file.
[0141] Exemplarily, in a trusted execution environment, a security check is performed on the SMC instruction corresponding to the first instruction, which may include but is not limited to checking one or more of the following:
[0142] (1) Instruction format and integrity: Check whether the format of the SMC instruction corresponding to the first instruction is correct and verify whether the instruction is complete. When the instruction format is correct and the instruction is complete, it helps to ensure that the instruction has not been tampered with or truncated.
[0143] (2) Parameter validity: Check whether the parameters passed in the SMC instruction corresponding to the first instruction are within a reasonable range. The reasonable range can be determined by the grammatical rules corresponding to the first instruction and the SMC instruction.
[0144] (3) Caller Identity and Permissions: Verify that the caller of the first instruction is legitimate and has the required permissions to execute the SMC instruction. For example, if the caller of the first instruction includes a virtual machine monitor, verify that the virtual machine monitor has the required permissions to execute the SMC instruction corresponding to the first instruction.
[0145] (4) Context preservation and restoration: Check whether the relevant context of the SMC instruction corresponding to the first instruction (such as processor status, register values, etc.) has been properly preserved, and whether there is an exception handling mechanism.
[0146] In a possible implementation, a security check application (referred to as check TA) may be run in the trusted execution environment. Check TA may perform the security check steps shown above on the SMC instruction corresponding to the first instruction.
[0147] Optionally, the first instruction may be subjected to a security check as described above, thereby facilitating confirmation of the security of the SMC instruction corresponding to the first instruction.
[0148] Optionally, if the SMC instruction corresponding to the first instruction passes the security check, the SMC instruction corresponding to the first instruction is executed in the trusted execution environment. Optionally, if a corresponding execution result is obtained after executing the SMC instruction corresponding to the first instruction, check TA may return the execution result to the caller of the first instruction in the rich execution environment.
[0149] Optionally, if the SMC instruction corresponding to the first instruction fails the security check, the execution of the first instruction may be stopped in the trusted execution environment, and the first instruction will not be executed in the rich execution environment. Optionally, if the SMC instruction corresponding to the first instruction fails the security check, a first alarm message may be generated to inform the user that there is a problem with the call of the first instruction. The first alarm message may include data such as the cause of the alarm, the location where it was generated, and related context information.
[0150] If the first instruction is detected to be called in the rich execution environment, executing the first instruction directly in the rich execution environment may expose the electronic device to attacks, such as causing illegal access to the data in the first register or illegal data tampering. Executing the SMC instruction corresponding to the first instruction in the trusted execution environment can effectively avoid these risks.
[0151] The following describes the attacks that may occur when executing the first instruction in a rich execution environment.
[0152] For example, in response to the first instruction including an MSR instruction and / or an MRS instruction, an attacker may use the MSR instruction and / or the MRS instruction to read, write, and modify the first register. If the first instruction is executed in a rich execution environment, the first register may be illegally accessed, and the contents of the first register may be illegally tampered with, which may lead to serious consequences such as abnormal system status, interrupt handling errors, and illegal tampering of program execution flow.
[0153] For example, in response to the first instruction including a write instruction to the page table base register, an attacker can use the write instruction to the page table base register to launch an attack, such as tampering with the page table or illegally accessing sensitive memory. If the first instruction is executed in a rich execution environment, the value of the page table base register may be tampered with by the attacker, causing the page table base register to point to a malicious page table. In this case, when the MMU performs address translation, the malicious page table will be used, threatening system security.
[0154] Exemplarily, in response to the first instruction including a write instruction to the system control register, such as a write instruction to the M bit, the attacker can disable the MMU through the first instruction, thereby attacking the page table, the system, etc. If the first instruction is executed in a rich execution environment, the MMU may be disabled by the attacker. If the MMU is disabled, the processor will directly use the physical address to access the memory, which will limit the system's ability to use virtual memory. In addition, since the MMU is responsible for providing memory protection functions, it controls access rights to memory through mechanisms such as page tables. After disabling the MMU, this memory protection mechanism will fail, which will increase the risk of the system being attacked by malicious attacks. Electronic devices may be more vulnerable to attackers accessing or tampering with sensitive data of the system, resulting in data leakage or system crashes.
[0155] If the SMC instruction corresponding to the first instruction is executed in a trusted execution environment, a security check can be performed on the SMC instruction corresponding to the first instruction, thereby preventing attacks such as those described above. Therefore, compared to executing the first instruction in a rich execution environment, executing the SMC instruction corresponding to the first instruction in a trusted execution environment is more conducive to improving the security of the instruction execution process, thereby improving the security of the rich execution environment.
[0156] In one possible implementation, the first instruction may include an instruction in a first process. In addition to the first instruction, the first process may also include multiple instructions. The first process may include a process running in a rich execution environment, such as a process running in an operating system in a virtual trusted isolation environment; for example, a process running in a virtual machine monitor. Furthermore, the one or more instructions included in the first process include the first instruction.
[0157] The execution of the first process is achieved by executing the instructions contained therein. When the first process is created by the operating system, the instructions and data of the first process are loaded into a designated memory area, and the processor executes these instructions in sequence according to the order of the instructions.
[0158] The execution of the first instruction in the rich execution environment may refer to a process in which, when the first process reaches the code location where the first instruction is located during execution, the first instruction is decoded and executed. Correspondingly, the execution of the SMC instruction corresponding to the first instruction in the trusted execution environment may refer to a process in which, when the first process reaches the code location where the first instruction is located during execution, the execution environment is switched from the rich execution environment to the trusted execution environment, and the SMC instruction corresponding to the first instruction is decoded and executed.
[0159] For example, see Figure 6 .like Figure 6 As shown, the execution process of the SMC instruction corresponding to the first instruction can be executed by a processor in the electronic device, and the processor can be as follows Figure 5 As shown, the execution process may include but is not limited to the following steps:
[0160] S601 , calling an SMC instruction corresponding to a first instruction to switch the execution environment from a rich execution environment to a trusted execution environment.
[0161] In response to detecting that a first instruction is called in a rich execution environment, such as detecting that a microkernel of a virtual trusted execution environment calls the first instruction, or detecting that a virtual machine monitor calls the first instruction, the processor will call an SMC instruction corresponding to the first instruction in the rich execution environment; when the SMC instruction corresponding to the first instruction is called, the execution mode of the processor will switch from privileged mode to monitor mode; in monitor mode, the processor will pause the execution process in the rich execution environment and transfer its control from the rich execution environment to the trusted execution environment, thereby switching the execution environment from the rich execution environment to the trusted execution environment. The processor may Figure 5 shown.
[0162] Optionally, during this process, the security monitor may save and restore context information corresponding to the first instruction to ensure smooth switching of the execution environment.
[0163] S602: Perform a security check on the SMC instruction corresponding to the first instruction in the trusted execution environment.
[0164] Optionally, a check TA in the trusted execution environment can perform a security check on the SMC instruction corresponding to the first instruction. For example, when the execution environment switches from the rich execution environment to the trusted execution environment, the security monitor can parse the SMC instruction corresponding to the first instruction to determine its call number. Based on the call number, the security monitor can locate the corresponding check TA in the trusted execution environment and dispatch the processor-related instruction and data streams to the check TA. In this way, the check TA in the trusted execution environment can perform a security check on the SMC instruction corresponding to the first instruction.
[0165] Optionally, the specific process of performing the security check may refer to the description in S402 above.
[0166] S603 : In response to the SMC instruction corresponding to the first instruction passing the security check, executing the SMC instruction corresponding to the first instruction in the trusted execution environment.
[0167] In the trusted execution environment, the processor may execute the SMC instruction corresponding to the first instruction and obtain an execution result, and may return the execution result to the rich execution environment.
[0168] Optionally, when executing the SMC instruction corresponding to the first instruction, it is necessary to stop calling the first instruction in the rich execution environment, or in other words, stop executing the first instruction.
[0169] S604 : In response to the SMC instruction corresponding to the first instruction failing the security check, stopping execution of the SMC instruction corresponding to the first instruction.
[0170] When the SMC instruction corresponding to the first instruction fails the security check, the processor needs to stop executing the SMC instruction corresponding to the first instruction and generate a first warning message. In this case, the execution result may also include the first warning message.
[0171] Optionally, when the SMC instruction corresponding to the first instruction fails the security check, execution of the first instruction is stopped in the rich execution environment. In other words, the first instruction and the SMC instruction corresponding to the first instruction are not executed in either the rich execution environment or the trusted execution environment.
[0172] S605: Switch the execution environment from the trusted execution environment back to the rich execution environment.
[0173] After returning the execution result to the rich execution environment, the processor's execution environment switches from the trusted execution environment back to the rich execution environment, and returns the execution result to the caller of the first instruction, that is, returns the execution result to the application or driver that initiated the SMC call request.
[0174] In this way, by Figure 6 The process shown can improve the security of the instruction execution process, thereby improving the security of the rich execution environment.
[0175] It can be seen that through the instruction processing method provided in the embodiment of the present application, when a first instruction is detected to be called in the rich execution environment, the execution environment can be switched from the rich execution environment to the trusted execution environment, and the SMC instruction corresponding to the first instruction can be executed in the trusted execution environment, thereby performing a security check on the SMC instruction corresponding to the first instruction and ensuring that the SMC instruction corresponding to the first instruction can be executed after passing the security check. In this way, the execution of the first instruction can be protected from malicious attacks, the security of the rich execution environment can be improved, and the security of the program running in the rich execution environment can be guaranteed.
[0176] Optionally, in addition to performing a security check on the SMC instruction corresponding to the first instruction, a security check (which may be referred to as a program security check) may also be performed on the first process. The first process includes the first instruction. The first process is allowed to execute only when it passes the process security check. This effectively prevents the rich execution environment from being attacked during the execution of the first process, thereby further improving the security of the rich execution environment. The inspection items for the process security check on the first process may include, but are not limited to, one or more of the following: access rights to the page table of the first process, access rights to the page table entries of the first process, access rights to the dynamic data of the first process, and the like.
[0177] The specific implementation process of checking the first process is exemplified below.
[0178] If the process security check includes the access permissions of the page table of the first process, in one possible implementation, in response to the first process being scheduled for the first time and the access permissions of the page table of the first process being read-only, the first process may be executed. In other words, when the first process is scheduled for the first time, the first process must be executed if the access permissions of the page table of the first process are read-only.
[0179] Among them, the first scheduling of the first process refers to the process in which a new process (i.e., the first process) is selected by the operating system for the first time after being created and obtains processor resources for execution, thereby allowing the first process to begin executing its code and complete the predetermined task. Specifically, when a process is scheduled to be executed on the processor, each instruction will be executed according to the instruction sequence in the code (or the execution order changed by instructions such as jumps and branches). Therefore, the execution of each instruction in the first process can be called a step in the execution process of the first process. In addition, when the first process is scheduled for the first time, the page table base register will point to the page table of the first process for the first time. In other words, the processor writes the base address of the page table of the first process to the page table base register for the first time.
[0180] If the process security check includes the access rights of the page table of the first process, in another possible implementation, in response to the first process being scheduled for the first time, the access rights of the page table of the first process may be modified to read-only. Alternatively, the access rights of the page table of the first process may be set to read-only when the first process is scheduled for the first time. For example, if the access rights of the page table of the first process are not read-only, but are any one of the following permissions: readable and executable, readable and writable, or readable, writable, and executable, then the access rights of the page table of the first process may be modified to read-only.
[0181] In this way, the SMC instruction corresponding to the first instruction can be prevented from being tampered with, thereby preventing the security check on the first instruction from being bypassed, and ensuring that the first instruction is not directly executed in the rich execution environment.
[0182] If the process security check includes the access permissions of the first process's page table entries, in one possible implementation, in response to the first process being scheduled for the first time and the first page table entry's access permissions being read-only, the first process may be executed. In other words, when the first process is scheduled for the first time, the first process must be executed if the first page table entry's access permissions are read-only. This ensures that the kernel code is read-only, preventing malicious tampering with the first process's page table and protecting the first process from attacks during execution.
[0183] The first process includes at least one page table entry, and the at least one page table entry includes the first page table entry. That is to say, the page table of the first process includes at least one page table entry, and the at least one page table entry includes the first page table entry. The first page table entry refers to the page table entry mapped to the kernel code. The first page table entry stores the mapping relationship between the virtual address and the physical address of the kernel code page, as well as some attributes of the mapping relationship (such as access rights, whether it exists in memory, etc.). The kernel code page refers to the physical memory page that stores the kernel code. These pages are loaded into the memory when the operating system starts and remain unchanged during the entire system operation.
[0184] If the process security check includes the access rights of a page table entry of the first process, in another possible implementation, in response to the first process being scheduled for the first time, the access rights of the first page table entry may be modified to read-only. For example, when the first process is scheduled for the first time, if the access rights of the first page table entry are not read-only, but are any one of readable and executable, readable and writable, or readable, writable, and executable, the access rights of the first page table entry may be modified to read-only.
[0185] Optionally, the at least one page table entry of the first process may further include a second page table entry, which is a page table entry that is mapped to the kernel non-code page. In other words, the second page table entry stores the mapping between the virtual address and the physical address of the kernel non-code page, as well as attributes such as the access permissions of the mapping. Optionally, the access permissions of the second page table entry can be set to non-executable. This helps improve the security and stability of the execution of the first process and prevents the execution of malicious code and illegal access to data.
[0186] If the process security check includes the access rights to the dynamic data of the first process, in one possible implementation, in response to the first process being scheduled for the first time and the access rights to the first dynamic data being non-writable, the first process may be executed. In other words, when the first process is scheduled for the first time, the first process must be executed if the access rights to the first dynamic data are non-writable.
[0187] The dynamic data of the first process includes at least first dynamic data. Dynamic data refers to temporary, real-time information generated during the execution of a process. Dynamic data in a process plays an important role in data security, performance optimization, and user experience. Optionally, the first dynamic data of the first process may include, but is not limited to, one or more of the following: memory management data of the first process, access control list data of the first process, and kernel module linked list of the first process.
[0188] If the process security check includes access rights to dynamic data of the first process, in another possible implementation, in response to the first process being scheduled for the first time, if it is detected that the access rights to the first dynamic data are writable, the access rights to the first dynamic data may be modified to non-writable. Optionally, the first process may be executed after the access rights to the first dynamic data are modified to non-writable.
[0189] In this way, by modifying the access rights of the first dynamic data to non-writable, unauthorized users or programs can be prevented from accessing sensitive data, illegal modification or deletion of data can be prevented, and the accuracy of the data can be ensured, which is conducive to protecting the security of the first process.
[0190] In one possible implementation, the process security check may also include checking the privileged execute-never (PXN) mechanism for user address space, specifically checking whether the PXN mechanism is enabled. The PXN mechanism is a kernel security feature that prevents the kernel from directly executing userspace code. When PXN is enabled, it effectively defends against attacks that exploit the kernel's ability to execute userspace code, such as return-to-user-space (RET2USR) attacks, thereby enhancing system security and memory protection.
[0191] Optionally, in response to the first process being scheduled for the first time and the PXN mechanism for the user address space being enabled, the first process may be executed. Optionally, in response to the first process being scheduled for the first time, the PXN mechanism for the user address space may be enabled. Optionally, the PXN mechanism for the user address space may be enabled when the electronic device is booted.
[0192] In one possible implementation, the first process can be executed when the PXN mechanism for the user address space is enabled, the page table of the first process has read-only access permissions, the first page table entry has read-only access permissions, the second page table entry has non-executable access permissions, and the first dynamic data of the first process has non-writable access permissions. This can largely maintain the security of the first process, thereby improving the security of the rich execution environment.
[0193] In one possible implementation, when the page table base register is updated to point to a new page table, such as the page table of a second process, the process security check described above may be performed on the second process. The page table base register being updated to point to the page table for executing the second process indicates the start of execution of the second process. The second process may be any process scheduled in the rich execution environment.
[0194] In this way, by checking the first process, sensitive information such as the page table, first page table entry, first dynamic data of the first process can be prevented from being leaked or tampered with. It is also helpful to identify malicious processes, such as Trojans, to prevent damage to the system, thereby effectively improving the security of the rich execution environment.
[0195] Some embodiments of the embodiments of the present application provide an instruction processing device, which, when running on an electronic device, enables the electronic device to execute the instruction processing method in the embodiments of the present application.
[0196] Some embodiments of the present application provide an electronic device, the electronic device comprising: one or more processors and a memory; the memory is used to store computer program code, the computer program code comprising computer instructions, when the one or more processors execute the computer instructions, the electronic device executes the above instruction processing method. Optionally, the processor in the electronic device may be as follows Figure 5 shown.
[0197] Some embodiments of the present application provide a chip system, which is applied to electronic devices. The chip system includes at least one processor and an interface, the interface is used to receive instructions and transmit them to at least one processor; at least one processor runs the instructions so that the electronic device executes the above instruction processing method. The chip system can be a modem processor, or a system on chip (SOC) including a modem processor, and the above instruction processing method can be implemented by a modem processor. Optionally, the processor in the chip system can be as follows: Figure 5 shown.
[0198] Some embodiments of the present application further provide a computer-readable storage medium comprising instructions, which, when executed on an electronic device, causes the electronic device to execute the above-mentioned instruction processing method. The specific implementation thereof can be referred to the above description and will not be repeated here.
[0199] Some embodiments of the present application also provide a computer program product comprising instructions, which, when executed on an electronic device, causes the electronic device to execute the above-described instruction processing method. The computer program product comprises computer instructions, which are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the computer device to execute the instruction processing method as described in the embodiments of the present application. The specific implementation method can be referred to the above description and will not be repeated here.
[0200] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state disk).
[0201] Those skilled in the art will appreciate that all or part of the process steps in the above-described method embodiments can be implemented by a computer program instructing the relevant hardware. The program can be stored in a computer-readable storage medium, and when executed, the program can include the process steps in the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
[0202] In short, the above description is only an embodiment of the technical solution of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent replacements, improvements, etc. made based on the disclosure of this application should be included in the scope of protection of this application.
Claims
1. A method for processing an instruction, characterized in that: Applied to an electronic device, the execution environment of the electronic device includes a rich execution environment and a trusted execution environment; the method includes: In response to detecting that a first instruction is called in the rich execution environment, a security monitoring call (SMC) instruction corresponding to the first instruction is executed in the trusted execution environment.
2. The method according to claim 1, characterized in that The rich execution environment includes a virtual trusted isolation environment, and / or a virtual machine monitor runs in the rich execution environment; The first instruction includes: an instruction called in the virtual trusted isolation environment, and / or an instruction called by a virtual machine monitor.
3. The method according to claim 1 or 2, characterized in that The first instruction is a read instruction and / or a write instruction for a first register.
4. The method according to claim 3, characterized in that The first register includes one or more of the following: a program status register, a page table base address register, and a system control register.
5. The method according to any one of claims 1 to 4, characterized in that The first instruction is an instruction in a first process; The method further comprises: In response to the first process being scheduled for the first time and the access permission of the page table of the first process being read-only, the first process is executed.
6. The method according to claim 5, characterized in that The method further comprises: In response to the first process being scheduled for the first time, the access permission of the page table of the first process is modified to read-only.
7. The method according to any one of claims 1 to 6, characterized in that The first instruction is an instruction in a first process, the first process includes at least one page table entry, and the at least one page table entry includes a first page table entry; The method further comprises: In response to the first process being scheduled for the first time and the access permission of the first page table entry being read-only, the first process is executed.
8. The method according to claim 7, characterized in that The method further comprises: In response to the first process being scheduled for the first time, the access permission of the first page table entry is modified to read-only.
9. The method according to claim 7 or 8, characterized in that The first page table entry includes a page table entry mapped to a kernel code.
10. The method according to any one of claims 1 to 9, characterized in that The first instruction is an instruction in a first process, and the dynamic data of the first process includes at least first dynamic data; The method further comprises: In response to the first process being scheduled for the first time and the access permission of the first dynamic data being non-writable, the first process is executed.
11. The method according to claim 10, characterized in that The method further comprises: In response to the first process being scheduled for the first time, the access permission of the first dynamic data is modified to be non-writable.
12. The method according to any one of claims 1 to 11, characterized in that The method further comprises: Performing a security check on an SMC instruction corresponding to the first instruction in the trusted execution environment; In response to the SMC instruction corresponding to the first instruction failing the security check, execution of the first instruction and the SMC instruction corresponding to the first instruction is stopped, and first warning information is generated.
13. An electronic device comprising a memory, one or more processors, a plurality of applications, and one or more programs; wherein, The one or more programs are stored in the memory; and it is characterized in that when the one or more processors execute the one or more programs, the electronic device implements the method according to any one of claims 1 to 12.
14. A chip system, characterized in that: The chip system includes at least one processor, a memory and an interface circuit, the memory, the interface circuit and the at least one processor are interconnected by lines, and program instructions are stored in the at least one memory; when the program instructions are executed by the processor, the chip system executes the method described in any one of claims 1-12.
15. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 12 is implemented.
Citation Information
Patent Citations
Virtualized operating system kernel protection method
CN111400702A
Kernel stack protection method and system
CN116415254A
Fine-grained integrity measurement model and method based on system page table access control
CN117113435A
Virtualization implementation method and apparatus, electronic device, non-volatile readable storage medium, and arm platform
WO2023184920A1