Information processing device, control method for information processing device, and control program

JPWO2024189770A5Pending Publication Date: 2025-09-16
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025506313
Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2025-07-04
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing technologies fail to effectively protect virtual machines from attacks by hypervisors, despite efforts to improve confidentiality and security, as they do not adequately address the translation of addresses and encryption processes.

Method used

An information processing device with a cache and memory system that employs an authenticated cryptographic engine for encryption and authentication, along with address translation mechanisms managed by the guest and hypervisor, to convert external addresses into guest and machine physical addresses, preventing unauthorized access.

Benefits of technology

Enhances the confidentiality and security of virtual machines by ensuring that only authorized access occurs, protecting data from hypervisor attacks through secure address translation and encryption processes.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This information processing device (1) comprises: memory (102) having a data storage area to which a machine physical address is assigned; a cache (101) having a data storage area to which a guest physical address is assigned; an authenticated encryption engine (103) for performing encryption processing and authentication processing on data to be transferred between the cache (101) and the memory (102); a first address conversion means (104) that is managed by a guest and converts an external address indicating access to data to be subjected to the encryption processing and the authentication processing into the guest physical address; and a second address conversion means (105) that is managed by a hypervisor and converts the guest physical address into a machine physical address corresponding to the guest physical address.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing device, control method for information processing device, and non-transitory computer-readable medium storing a program

[0001] The present disclosure relates to an information processing device, a control method for an information processing device, and a non-transitory computer-readable medium on which a program is stored.

[0002] In recent years, there has been a demand for improving confidentiality and security against attacks on virtual machines from a hypervisor. Related technology is disclosed in, for example, Japanese Patent Laid-Open No. 2003-222296.

[0003] JP 2013-205972 A

[0004] Meysam Taassori, Ali Shafiee, and Rajeev Balasubramonian. VAULT: reducing paging overheads in SGX with efficient integrity verification structures. In Xipeng Shen, James Tuck, Ricardo Bianchini, and Vivek Sarkar, editors, Proceedings of the Twenty-Third International Conference on Architectural Support for Programming Languages ​​and Operating Systems, ASPLOS 2018, Williamsburg, VA, USA, March 24-28, 2018, pages 665-678. ACM, 2018.

[0005] However, Patent Document 1 only describes converting a virtual address recognized by a guest into a physical address recognized by a host, and still has the problem that it cannot protect virtual machines from attacks by the hypervisor.

[0006] The present disclosure has been made to solve such problems, and aims to provide an information processing device, a control method for an information processing device, and a non-transitory computer-readable medium on which a program is stored, which can improve confidentiality and security against attacks on virtual machines from a hypervisor.

[0007] The information processing device according to the present disclosure comprises: a memory having a data storage area to which a machine physical address is assigned; a cache having a data storage area to which a guest physical address is assigned; an authenticated encryption engine that performs encryption and authentication processing on data exchanged between the cache and the memory; a first address conversion means that is managed by a guest and converts an external address that instructs access to data that is the subject of encryption and authentication processing into a guest physical address; and a second address conversion means that is managed by a hypervisor and converts the guest physical address into a machine physical address corresponding to the guest physical address.

[0008] The control method of an information processing device disclosed herein is a control method of an information processing device comprising: a memory having a data storage area assigned to a machine physical address; a cache having a data storage area assigned to a guest physical address; an authenticated encryption engine that performs encryption and authentication processing on data exchanged between the cache and the memory; a first address translation means managed by a guest; and a second address translation means managed by a hypervisor; when accessing the cache, the first address translation means is used to translate an external address that instructs access to data that is the subject of encryption and authentication processing into a guest physical address; and when accessing the memory, the second address translation means is used to translate the guest physical address into a machine physical address corresponding to the guest physical address.

[0009] The non-transitory computer-readable medium disclosed herein is a non-transitory computer-readable medium having stored thereon a control program that causes a computer to execute control processing in an information processing device that includes a memory having a data storage area assigned to a machine physical address, a cache having a data storage area assigned to a guest physical address, an authenticated encryption engine that performs encryption processing and authentication processing on data exchanged between the cache and the memory, a first address translation means managed by a guest, and a second address translation means managed by a hypervisor. The control program stored thereon causes a computer to execute control processing including: when accessing the cache, using the first address translation means to convert an external address that instructs access to data that is the subject of encryption processing and authentication processing into a guest physical address; and when accessing the memory, using the second address translation means to convert the guest physical address into a machine physical address that corresponds to the guest physical address.

[0010] The present disclosure provides an information processing device, a control method for an information processing device, and a non-transitory computer-readable medium on which a program is stored, which can improve confidentiality and security against attacks on a virtual machine from a hypervisor.

[0011] 1 is a block diagram showing an example of the configuration of an information processing device according to a first embodiment. FIG. 2 is a diagram schematically showing an information processing device according to a second embodiment. FIG. 3 is a conceptual diagram showing an access control structure realized in the information processing device according to the second embodiment. FIG. 4 is a diagram showing an address flow of a machine. FIG. 5 is a diagram showing a data flow when saving a register value of a virtual machine. FIG. 6 is a diagram showing a data flow when restoring a register value of a virtual machine. FIG. 7 is a diagram showing a processing flow of address conversion by a virtual machine. FIG. 8 is a diagram showing a processing flow of address conversion by a hypervisor. FIG. 9 is a conceptual diagram of an authentication tree. FIG. 10 is a diagram showing the relationship between each node constituting the authentication tree and its corresponding cache line. FIG. 11 is a diagram showing the flow of data, keys, and an authentication tree when a guest reads data. FIG. 12 is a diagram showing the flow of data, keys, and an authentication tree when a guest writes back data. FIG. 13 is a diagram showing the flow of key installation.

[0012] Hereinafter, embodiments will be described with reference to the drawings. In the embodiments, the same or equivalent elements are denoted by the same reference numerals, and redundant description will be omitted.

[0013] 1 is a block diagram showing a configuration example of an information processing device 1 according to embodiment 1. As shown in Fig. 1, the information processing device 1 includes a cache 101, a memory 102, an authenticated encryption engine 103, a first address conversion unit 104, and a second address conversion unit.

[0014] The cache 101 has a data storage area to which a guest physical address is assigned. The guest physical address is an address that is assigned individually to each guest (virtual machine) and that specifies the data storage area of ​​the cache 101. In other words, the cache 101 is configured to be able to access data in a storage area specified by a guest physical address. Note that the cache 101 stores plaintext data.

[0015] The memory 102 has a data storage area to which a machine physical address is assigned. The machine physical address is an address actually assigned to the data storage area of ​​the memory 102. In other words, the memory 102 is configured to be able to access data in a storage area specified by a machine physical address. Note that the memory 102 stores encrypted data (ciphertext).

[0016] The authenticated encryption engine 103 performs encryption and authentication processes on data exchanged between the cache 101 and the memory 102. For example, plaintext data read from the cache is encrypted and authenticated before being written to the memory. Encrypted data read from the memory is decrypted and authenticated before being stored in the cache. Hereinafter, the encryption and authentication processes (including the decryption and authentication processes) performed by the authenticated encryption engine 103 are also referred to as authenticated encryption processes.

[0017] Preferably, the authenticated encryption engine 103 performs authentication processing using an authentication tree consisting of multiple nodes connected in a tree shape, each node being assigned a pair of a counter and an identifier. In authentication processing using an authentication tree, authentication is performed not only for data but also for the authenticator, further reducing the risk of data leakage.

[0018] The first address conversion unit (first address conversion means) 104 converts an address (external address) supplied from outside that instructs access to data that is managed by a guest (virtual machine) and is the target of authenticated encryption processing, into a guest physical address. Here, because a guest physical address managed by the guest is assigned to the data storage area of ​​the cache 101, the hypervisor cannot tamper with the access destination of the cache 101. In other words, the information processing device 1 can prevent attacks on the cache 101 from the hypervisor. Note that a hypervisor is software that creates and runs guests (virtual machines).

[0019] The first address conversion unit 104 may be configured to convert the address into a guest physical address according to the identification information vmid of the specified virtual machine in addition to the address supplied from the outside, thereby enabling access to the cache 101 belonging to the specified virtual machine among the multiple virtual machines.

[0020] The second address conversion unit (second address conversion means) 105 is managed by the hypervisor and converts a guest physical address into a machine physical address. That is, when data read from the cache 101 is written back to the memory 102 after being subjected to authenticated encryption or processing, the guest physical address is converted into a machine physical address corresponding to the guest physical address.

[0021] In this way, the information processing device 1 according to the present embodiment can prevent attacks from the hypervisor on the cache 101 by configuring the cache 101 to be accessible to a data storage area specified by a guest physical address managed by the guest. In other words, the information processing device 1 according to the present embodiment can improve confidentiality and security against attacks from the hypervisor on virtual machines.

[0022] Note that the cache 101 may further include a data storage area assigned to a machine physical address in addition to the data storage area assigned to a guest physical address. The data storage area of ​​the cache 101 assigned to a machine physical address stores, for example, data that is not subject to authenticated cryptographic processing, and is accessible not only from guests but also from a hypervisor. In this case, the first address conversion unit 104 converts an address supplied from the outside that instructs access to data that is subject to authenticated cryptographic processing into a guest physical address, while converting an address supplied from the outside that instructs access to data that is not subject to authenticated cryptographic processing into a machine physical address.

[0023] Furthermore, during a context switch, it is preferable that the register values ​​of each virtual machine be stored in a storage area designated by the guest physical address assigned to that virtual machine. This allows the register values ​​of a virtual machine to be saved using the virtual machine's key, making it possible to transfer data from one virtual machine to another during migration, for example, without requiring special protection processes such as re-encryption processes for exchanging encryption keys or access control with higher privileges.

[0024] Second Embodiment In a second embodiment, the information processing device 1 will be described in more detail.

[0025] <Machine Security Model> In this embodiment, no consideration is given to physical attacks on the respective elements of the CPU (Central Processing Unit), MMU (Memory Management Unit), IOMMU (Input-Output Memory Management Unit), cache, TLB (Translation Lookaside Buffer), and IOTLB (Input-Output Translation Lookaside Buffer) provided in the processor in the information processing device 1. In other words, in this embodiment, it is assumed that the respective elements of the CPU, MMU, IOMMU, cache, TLB, and IOTLB provided in the processor are implemented so robustly that there is no need to consider attacks. In this embodiment, it is also assumed that the security of communications between the above-mentioned multiple elements provided in the processor is ensured to such an extent that there is no need to consider attacks.

[0026] On the other hand, the memory bus and memory are subject to attacks such as eavesdropping and tampering. Referring to the schematic diagram in Figure 2, this shows that physical attacks on the inside of the processor are difficult, but physical attacks on the outside of the processor are not necessarily difficult.

[0027] In this embodiment, it is assumed that three authorities, namely, machine, hypervisor, and guest, are implemented in the CPU. The guest is assumed to be a virtual machine. The guest authority is assumed to be a supervisor authority (guest supervisor authority) of the virtual machine.

[0028] A guest user (a user of a virtual machine) is assigned a virtual address by a guest supervisor. This virtual address is converted into a guest physical address according to the conversion content specified by the guest supervisor, and this guest physical address is converted into a machine physical address according to the conversion content specified by the hypervisor. The attacker is assumed to be all or some of the following: the hypervisor, a non-target guest, and a physical attacker. The machine authority is assumed to be resistant to attacks from the hypervisor authority. However, a mechanism for the machine authority to resist attacks from the hypervisor authority must be implemented separately. For example, to make memory available in machine mode, a method for protecting memory from the hypervisor must be implemented separately.

[0029] When a guest is granted permission to use an accessible memory space by a guest with authority above the hypervisor, that guest can use the computing resources in the given memory space without interference from the hypervisor or machine authority until that permission is revoked by an exception or interrupt. However, as already explained, it cannot be ruled out that the given memory space may be subject to physical attacks. Furthermore, when a guest has permission, the hypervisor or other guests cannot access registers, caches, TLBs, etc., but if that guest surrenders their permission, other authorities will not be prevented from accessing these.

[0030] <Access Control Using Authenticated Encryption Processing> A guest virtual machine is identified by its identification information vmid. When the privilege is in guest mode, that is, when a virtual machine is assumed to be running, the identification information vmid of the running virtual machine is specified in the MMU. This limits the data accessible by the running virtual machine to only the data associated with the identification information vmid specified in the MMU.

[0031] 3 is a conceptual diagram showing an access control structure realized in the information processing device 1. As shown in Fig. 3, by applying a designated access control method to a hierarchical storage area configured by a register, a cache, and a memory provided in each virtual machine (VM) and to a register at the time of a context switch, the information processing device 1 can perform access control according to the designated method.

[0032] If no measures are taken, the registers of each virtual machine may be manipulated by the hypervisor during a context switch. However, these registers can be protected directly by hardware or by saving register values ​​in advance in machine mode.

[0033] Furthermore, if no measures are taken, the cache of each virtual machine may be manipulated by the registers of other virtual machines. However, first, cache lines in the cache of each virtual machine are tagged with the identification information vmid of the corresponding virtual machine. Furthermore, the registers of each virtual machine are configured to be accessible only to cache lines tagged with the same identification information vmid as the corresponding virtual machine. This protects the cache of each virtual machine.

[0034] Furthermore, if no countermeasures are taken, the memory of each virtual machine may be vulnerable to attacks when transferring data to and from the cache. However, each virtual machine applies authenticated encryption processing to data transferred between the cache and memory, thereby protecting the data in the memory. Note that authenticated encryption processing can also prevent physical attacks on the memory. The key used in authenticated encryption processing limits access by the hypervisor.

[0035] Below, the register access control, the cache access control, and the memory access control will each be described in detail.

[0036] <Register access control> In a context switch, a hypervisor with execution authority temporarily suspends the execution of a process and transfers execution authority to a guest (virtual machine), or a guest (virtual machine) with execution authority suspends the execution of a process and returns execution authority to the hypervisor.

[0037] For example, when a hypervisor transfers execution authority to a guest, the hypervisor first transmits the identification information vmid of the virtual machine to be executed to the machine, and then returns execution authority to the machine.The machine then passes the identification information vmid received from the hypervisor to the MMU.The machine also restores the register values ​​saved in the memory area of ​​the virtual machine to start execution of the virtual machine with the identification information vmid received from the hypervisor.The machine then transfers execution authority to the guest.Note that the machine cannot pass the identification information vmid to the MMU except when transferring execution authority to a guest.

[0038] Furthermore, when a guest (virtual machine) returns execution authority to a hypervisor, the guest with execution authority first saves the register values ​​of the virtual machine whose execution has been suspended to the memory area of ​​that virtual machine. Then, the guest with execution authority instructs the MMU to invalidate the identification information vmid that it had previously passed. Then, the guest returns execution authority to the hypervisor. However, if the guest can give execution authority to the supervisor of the same virtual machine without returning it to the hypervisor even when execution of the virtual machine has been suspended, the guest transfers execution authority to the relevant guest supervisor without saving the register values.

[0039] When a machine saves a register value of a virtual machine to the memory area of ​​the virtual machine, or when a register value saved in the memory area of ​​the virtual machine is restored, the machine code needs to access the memory area of ​​the virtual machine. This access is performed using a guest physical address. Specifically, the machine accesses memory through a cache using a machine address for instructions, and through a cache using a virtual machine address for data.

[0040] 4 is a diagram showing the address flow of the machine. Note that page tables, address translation by page table walk, and the TLB will be described later.

[0041] In Fig. 4, the Main Cache corresponds to the cache 101 in Fig. 1. The guest TLB corresponds to the first address translation unit 104 in Fig. 1. The Machine TLB corresponds to the second address translation unit 105 in Fig. 1. The Memory corresponds to the memory 102 in Fig. 1. The auth-encryption, auth-decryption, tag-verification, and tag-generation correspond to the authenticated encryption engine 103 in Fig. 1.

[0042] When authenticated encryption processing is performed on data, an authenticator is generated in addition to the ciphertext. The elements of this authenticator are represented as PAT in Figure 4. The data to be protected is converted into ciphertext and authenticator by authenticated encryption processing and stored in memory. However, the authenticator may also be stored in the PAT cache. When ciphertext stored in memory is read, the authenticator corresponding to the ciphertext is also read, and the ciphertext is decrypted and verified using the read ciphertext and authenticator. This verification makes it possible to confirm that the ciphertext has not been tampered with or replaced.

[0043] Generally, authenticators used to verify whether ciphertext has been tampered with or substituted have a mutual dependency with authenticators of other data. This dependency makes it possible to determine which data stored in memory has been tampered with, even if some data in memory is tampered with by restoring it to previous data. In authenticated encryption processing where multiple authenticators are dependent on each other, the processing order of the multiple authenticators must be adjusted. The PAT scheduler in Figure 4 adjusts the processing order of these multiple authenticators.

[0044] FIG. 4 shows the address flow in the process of saving register values ​​of a virtual machine when execution of the virtual machine is suspended, and in the process of restoring saved register values ​​to the virtual machine register when execution of the virtual machine is resumed. The program counter in FIG. 4 points to the address of the code that saves the register values. This address is the address of the machine privileged code and exists in the machine's address space. Therefore, this address is read into the main cache without passing through the guest TLB or being translated. Note that this address is stored in a secure area before being read into the main cache. The code at the address pointed to by the program counter is the code that saves the register values, but the program counter points to the address of the VM state as the address where the register values ​​are saved. Since this address is a guest address, it is converted to a machine address by the guest TLB and machine TLB. Note that, because address translation is performed within the virtual machine in the guest TLB, some data does not pass through the guest TLB. These address flows are represented by Y1.

[0045] When saving register values ​​to the VM state, the authenticated encryption engine reads the key specified by the virtual machine identifier vmid from the key cache and uses that key to perform authenticated encryption processing on the register values ​​to be saved. If the required key is not written to the key cache, the authenticated encryption engine reads the encrypted key stored in enc-VM keys in memory, decrypts it, and uses it. The flow of these addresses is represented by Y3.

[0046] In authenticated encryption processing, in addition to encrypting or decrypting data, an authenticator is generated and verified. The memory storage area where this authenticator is stored is specified by an address. The address flow is represented by Y2.

[0047] The guest TLB uses a page table walk to translate virtual addresses within a virtual machine into physical addresses for the virtual machine. This translation table is stored in the (real) machine's memory. Machine addresses are assigned to storage areas in the machine's memory where this translation table is stored. However, in a virtual machine, virtual machine addresses are apparently assigned to storage areas in the machine's memory, so addresses specified in the virtual machine must be translated into machine addresses by the Machine TLB. This address flow is represented by Y4.

[0048] The Machine TLB uses a page table walk to translate virtual machine addresses into (true) machine addresses. This translation table is stored in the machine's memory. Therefore, the storage area in the machine's memory where this translation table is stored is specified by the machine's address. This address flow is represented by Y5.

[0049] 5 is a diagram showing the data flow when saving register values ​​of a virtual machine. Y1 shows the flow of saving the values ​​of registers and the enc-boundaries register, which indicates the scope of application of authenticated encryption processing. When data read from the main cache is written to memory, authenticated encryption processing is performed on the data using auth-encryption.

[0050] In authenticated encryption processing, in addition to encrypting or decrypting data, an authenticator is generated. The flow of generating an authenticator, storing the authenticator in the PAT cache, and storing another authenticator related to the authenticator in memory is represented by Y6. Another authenticator is used to generate this authenticator, and the flow of retrieving the other authenticator from the PAT cache is represented by Y2.

[0051] The process flow for reading a key used in authenticated encryption processing from the key cache is represented by Y3. If the required key is not written in the key cache, the encrypted key stored in the enc-VM keys in memory is read, decrypted using the machine key, and then stored in the key cache. This process flow is represented by Y5.

[0052] 6 is a diagram showing the data flow when restoring the register values ​​of a virtual machine. Y1 shows the flow of restoring the values ​​of registers and the enc-boundaries register, which indicates the scope of application of authenticated encryption processing. When data read from memory is written to the main cache, authenticated encryption processing is performed on the data by auth-decryption. As a result, the data is decrypted, verified, and then restored.

[0053] In the verification of data decryption in authenticated encryption processing, the authenticator of the data and other related authenticators are read from memory, decrypted, verified, and then written to the main cache. This processing flow is represented by Y6. Furthermore, the processing of using the authenticator of the restored data to verify data decryption in authenticated encryption processing is represented by Y2.

[0054] The process flow for reading a key used in authenticated encryption processing from the key cache is represented by Y3. If the required key has not been written to the key cache, the encrypted key stored in the enc-VM keys in memory is read, decrypted using the machine key, and then stored in the key cache. This process flow is represented by Y5. Note that this key is generated and registered by a user of the virtual machine outside the cloud. Specifically, the key generated outside the cloud is encrypted using the machine's public key, decrypted using the machine's key via the cloud's hypervisor register, and then registered. This process flow is represented by Y4.

[0055] FIG. 7 is a diagram showing the flow of address translation processing by a virtual machine. When a virtual machine executes its own code, the program counter points to the virtual machine's address as the address of that code. This address is either the virtual machine's virtual address or the virtual machine's actual address. Here, the virtual machine's virtual address is translated to the virtual machine's actual address in the guest TLB. On the other hand, the virtual machine's actual address is used to access the main cache without being translated in the guest TLB. However, the address of data accessed by the virtual machine that is not protected by authenticated encryption processing is translated to the machine's address. When accessing memory from the main cache, the virtual machine's address is translated to the machine's address in the machine TLB. The flow of these addresses is represented by Y1.

[0056] For data accessed by a virtual machine that is protected by authenticated encryption processing, the address of the authenticator corresponding to that data is found from the address of that data. This authenticator address is an actual address of the virtual machine, and the required authenticator is retrieved from the storage area of ​​the PAT cache specified by this address. If the authenticator is not cached in the PAT cache, it must be retrieved from memory. In this case, the authenticator address is converted into a machine address in the Machine TLB and then used to access memory. This address flow is represented by Y2.

[0057] Among the address conversions using the page table walk, the guest page table is referenced when converting the virtual address of a virtual machine. The storage address of this table is represented by the virtual machine's address at the virtual machine level. Therefore, if this table is stored in the main cache, the storage address of this table is used directly to access the main cache. On the other hand, if this table is stored in memory, the storage address of this table is converted to a machine address in the machine TLB and then used to access the memory. This address flow is represented by Y4.

[0058] The Machine TLB translates virtual machine addresses into machine addresses, and this translation is recorded in the hypervisor PT (Page Table). Whether this page table is stored in the main cache or in memory, the storage address of the page table is represented by a common machine address. This address flow is represented by Y5.

[0059] The key used for the authenticated encryption process of the virtual machine is read from the storage area of ​​the key cache assigned by the virtual machine's identifier vmid. If the required key is not cached in the key cache, the encrypted key is read from the enc-VM keys in memory, decrypted using the machine key, and then stored in the key cache. This processing flow is represented by Y3.

[0060] FIG. 8 is a diagram showing the flow of address translation processing by the hypervisor. When a virtual address is used in the hypervisor, the virtual address is translated into a machine address in the Machine TLB. Addresses other than virtual addresses in the hypervisor are machine addresses and do not require translation. This address flow is represented by Y1. Note that a hypervisor PT (Page Table) is used to translate virtual addresses. The storage location of this table is represented by a machine address. This address flow is represented by Y5.

[0061] In a virtual machine, how register values ​​saved in a memory area specified by a guest physical address are protected from attacks by other guests or the hypervisor is determined based on the same access control as in the case of caches and memories, which will be described later. Note that guests do not have access rights to the hypervisor's registers, and the hypervisor does not have access rights to the machine's registers.

[0062] <Cache Access Control> When the identification information vmid of a virtual machine is specified in the MMU, the virtual machine running with guest privileges accesses data stored in the cache. At this time, the virtual machine specifies the address of a cache line in the cache to the MMU using an instruction or instruction pointer. This address is either a virtual address (an address provided by the guest supervisor to the guest process) or a guest physical address (a virtual address provided by the hypervisor to the guest supervisor). In the case of a virtual address, the MMU converts the virtual address into a guest physical address according to the conversion content specified by the guest supervisor.

[0063] The virtual machine classifies the guest physical addresses into those that prohibit access by others and those that allow access by the hypervisor. The guest physical addresses that allow access by the hypervisor are used for I / O requests to the hypervisor. The guest classifies the guest physical addresses by specifying a range using a unique register.

[0064] Specifically, the MMU tags protected guest physical addresses with virtual machine identification information vmid, and converts unprotected guest physical addresses into machine physical addresses according to conversion content defined by the hypervisor. As a result, cache lines written from a guest (virtual machine) register to a cache and cache lines read from a guest cache to a register are identified by guest physical addresses tagged with the guest identification information vmid, or by machine physical addresses not tagged with the identification information vmid.

[0065] Note that the translation specified by the guest supervisor is the translation specified by the guest page table. Here, the guest stores the guest page table in a memory area of ​​the guest physical address that is not shared with others. The upper part of Figure 7 shows the address translation flow from the guest's register to the cache.

[0066] Next, when the hypervisor accesses the cache, the hypervisor specifies the virtual address or machine physical address of a cache line in the cache to the MMU. For example, when a virtual address is input, the MMU converts the virtual address into a machine physical address according to the conversion content specified by the hypervisor.

[0067] At this time, the MMU does not tag the specified address with any guest identification information vmid. In other words, vmid=0 is set. Figure 8 shows the flow of address translation in the hypervisor. As a result, cache lines written from the hypervisor register to the cache and cache lines read from the cache to the hypervisor register are identified by machine physical addresses that are not tagged with identification information vmid.

[0068] A machine accesses a cache by specifying a machine physical address, but can only access the cache of the virtual machine whose identification information vmid is specified by the MMU at the time of context switching, as shown in FIG.

[0069] As a result of the above address conversion, access control to the cache is realized as follows: A guest (virtual machine) to which a certain identification information vmid is assigned can access a cache line tagged with the same identification information vmid by specifying its own guest physical address.

[0070] This virtual machine can access a cache line specified by a guest physical address that has been shared with the hypervisor. This cache line is identified in the cache by a machine physical address, and the machine physical address assigned to this cache line is determined by the hypervisor. That is, this virtual machine can access a cache line identified by a machine physical address assigned by the hypervisor.

[0071] Each virtual machine cannot access cache lines that other guests (virtual machines) with identification information vmid have not authorized to share with the hypervisor. The hypervisor can access cache lines that have been authorized to be shared with the hypervisor, but cannot access any cache lines with identification information vmid.

[0072] The machine can access the cache line of data that has the identification information vmid that is the target of the context switch and that is specified by the MMU. The cache line of guest data that the machine can access is only used to save register values, so the guest physical address used to specify the cache line may be limited to a small portion.

[0073] <Memory Access Control> Cache-level access control is extended to memory access control by applying authenticated cryptography to data passing between cache and memory. Authenticated cryptography is performed by the MMU. Authenticated cryptography significantly reduces the reliance on machine privileges for guest memory protection.

[0074] A cache line tagged with the identification information vmid of a certain guest cannot be accessed by the hypervisor or guests with other identification information vmid. However, if this cache line is written to a memory storage area specified by a certain address, and no countermeasures are taken, there is a risk that the hypervisor will attack by specifying the address as a machine physical address. Alternatively, there is a risk that the hypervisor will attack by allocating the address as a guest physical address of another guest, or allocating the address as another guest physical address of the same guest. These attacks can be prevented by authenticated encryption processing.

[0075] The reason why the address of a cache line that is prohibited from being accessed by the hypervisor or other guests is a guest physical address is that the integrity of this address is guaranteed only by authenticated cryptographic processing when the cache is accessed from memory. If the address of a cache line that is prohibited from being accessed by the hypervisor or other guests were a guest physical address, the correctness of the translation from the guest physical address to the machine physical address must also be guaranteed in order to guarantee the integrity of the guest physical address. Because the translation from the guest physical address to the machine physical address is performed by the hypervisor, a special mechanism is additionally required to guarantee the correctness of this translation.

[0076] In this embodiment, the MMU holds a plurality of sets of keys and root counters corresponding to a plurality of guests. Each guest performs authenticated cryptographic processing using the corresponding key and root counter held in the MMU. How to prepare the keys and root counters used in authenticated cryptographic processing will be described later.

[0077] For example, cache lines are read from memory and written to the cache as needed, and cache lines are read from the cache and written to memory and back.

[0078] When a cache line at an address tagged with a certain identification information vmid is read from memory and written to the cache, the MMU decrypts the data read from memory using the authenticated encryption key and root counter associated with the identification information vmid and then writes the decrypted data to the cache. The MMU also associates the data written to the cache with its guest physical address and performs authentication processing for them.

[0079] When a cache line at an address tagged with a certain identification information vmid is read from the cache and written to memory, the MMU encrypts the data read from the cache using the authenticated encryption key and root counter associated with the identification information vmid and then writes the encrypted data to memory. At this time, the MMU updates the value of the corresponding counter and generates an authenticator associated with the guest physical address and writes it to memory.

[0080] In this embodiment, data authentication is performed using an authentication tree consisting of a plurality of nodes connected in a tree shape, each of which is assigned a pair of a counter and an identifier. In data authentication using an authentication tree, not only data but also authenticators are authenticated, further reducing the risk of data leakage.

[0081] 9 is a conceptual diagram of an authentication tree. Each node constituting this authentication tree is assigned a counter and an identifier. The identifier of each leaf node (node ​​in the lowest layer) matches the memory address of the corresponding cache line. The identifier of an intermediate node is derived based on its position in the tree. Each leaf node is also assigned data corresponding to the memory address (identifier). That is, when this data is written to the cache 101, it matches the cache line written to the cache 101.

[0082] 10 is a diagram showing the relationship between each node constituting an authentication tree and its corresponding cache line. As shown in Fig. 10, in each leaf node 301, encrypted data (hereinafter also referred to simply as ciphertext) 303 is generated from plaintext data 302 stored in the corresponding cache line, and a tag (authenticator, MAC) 306 is generated using the ciphertext 303, a memory address 304, and the count value of a counter 305. The tag generated in each leaf node 301 is stored in another cache line 307 together with tags generated in other nodes (sibling nodes) that have the same intermediate node as their parent node.

[0083] In each intermediate node 311, a tag 315 is generated based on the assigned identifier 312, the count value of the counter 313, and a set 314 of count values ​​of the counters of the child nodes. Similarly, in the root node (the node in the top layer) 321, a tag 325 is generated based on the assigned identifier 322, the count value of the counter 323, and a set 324 of count values ​​of the counters of the child nodes.

[0084] Here, when the counter value indicates "0," it means that the addresses assigned to the node to which the counter is assigned and its descendant nodes are not used (data at those addresses is not read). As a result, unused nodes are excluded from the authentication tree, making it possible to achieve efficient operation even when the address space is large but the amount of data used is small. Note that a key 330 is also used to encrypt data and generate tags.

[0085] In this embodiment, each counter is described as a split type. Details of split type counters are disclosed in, for example, Non-Patent Document 1. The counter assigned to each node is a minor counter with a small area. Furthermore, multiple minor counters assigned to multiple child nodes (sibling nodes) of a common node share a single major counter. This enables a large number of updates while reducing memory occupation. For example, when the count value of a minor counter exceeds the maximum value, the count value of the major counter is counted up, and the count values ​​of all minor counters with count values ​​other than "0" among the minor counter and its sibling nodes are reset to "1." As already explained, addresses assigned to a node assigned a counter with a count value of "0" and its descendant nodes are not used.

[0086] Each counter in the split type is static, and the area allocated to each minor counter is always the same. The major counter is assumed to reside in the same cache line as the minor counter. The appropriate size and structure of the authentication tree are assumed to be determined based on the size of the address space to be authenticated and the number of branches in each layer of the authentication tree.

[0087] When data at a leaf node is updated, in principle, the count values ​​of all counters on the path from this leaf node to the root node are incremented. However, for some counters, the count increment may be delayed, or multiple count increments may be performed at once. The counter assigned to the root node is specially protected to prevent direct manipulation by an attacker. The tag of the corresponding node is then updated using the counter at the root node, the counter at each intermediate node, or the counter and data at each leaf node. This ensures that the tag at each node is updated to the latest status. Here, by using a secret key and a counter at the root node that cannot be tampered with, it is possible to detect tampering of the ciphertext or tag or replacement with old data.

[0088] When data at a leaf node is updated, not only is the data at this leaf node authenticated, but the tags (authenticators) of the nodes on the path from this leaf node to the root node are also authenticated, further reducing the risk of data leakage.

[0089] The machine physical address specified for a memory when the memory is accessed is determined by an address translation process performed by the hypervisor. Whether the address translation process performed by the hypervisor is correct or not depends on whether the hypervisor behaves correctly. For example, whether the address translation process performed by the hypervisor is correct or not depends on whether the hypervisor is an attacker. Note that the guest with the identification information vmid assigned to the cache line to be written to the memory does not necessarily have authority at the time the cache line is written to the memory.

[0090] The lower part of Fig. 7 shows the process flow for converting a guest's cache address to a memory address, the process flow for specifying an address in the authentication tree, and the process flow for reading a key. Fig. 11 shows the flow of data, keys, and authentication trees when a guest reads data. Fig. 12 shows the flow of data, keys, and authentication trees when a guest writes back data.

[0091] <Address Translation and TLB> A guest's virtual address is translated into a guest physical address using a guest page table managed by the guest. Then, the cache is accessed using a guest physical address tagged with, for example, identification information vmid. Furthermore, when data read from the cache is written back to memory, the guest physical address is translated into a machine physical address, and the memory is accessed using that machine physical address.

[0092] The guest physical address is translated into a machine physical address using a hypervisor page table managed by the hypervisor. Then, for example, the cache is accessed using the machine physical address (not tagged with the identification information vmid). Furthermore, when data read from the cache is written back to memory, the memory is directly accessed using the machine physical address.

[0093] The MMU converts the guest virtual address into either a guest physical address or a machine physical address, and then searches the cache for the cache line to be accessed. Here, both types of address conversion depend on the guest page table and the hypervisor page table. The conversion from the virtual address to the guest physical address depends on not only the guest page table but also the hypervisor page table because the storage area of ​​the guest page table, among the storage areas of the memory, depends on the storage area of ​​the hypervisor page table. However, the reliability of the guest page table is guaranteed by authenticated encryption processing.

[0094] The conversion contents (correspondence tables) of the two types of address conversions described above used when accessing the cache are cached in the guest's TLB. For example, when the identification information vmid and a virtual address are input, the guest's TLB uses the correspondence table corresponding to the identification information vmid to output a guest physical address tagged with the identification information vmid corresponding to the virtual address, or a machine physical address not tagged with the identification information vmid corresponding to the virtual address. If the guest physical address or machine physical address corresponding to the virtual address does not exist in the correspondence table, the guest's TLB uses the guest page table or the hypervisor page table to output a guest physical address tagged with the identification information vmid corresponding to the virtual address, or a machine physical address not tagged with the identification information vmid corresponding to the virtual address.

[0095] The MMU also converts guest physical addresses to machine physical addresses using the hypervisor page table when accessing memory from the cache. The address conversion details (correspondence table) used when accessing memory from the cache are cached in the machine's TLB. Figure 7 also shows the process using the two types of page tables described above.

[0096] <Basic Configuration of Authenticated Encryption Processing> The basic configuration of authenticated encryption processing will be described.

[0097] In this embodiment, it is assumed that the cache is a write-back type, and data stored in the cache of each virtual machine is identified by the guest physical address of the virtual machine.

[0098] In addition, in this embodiment, writing data to a cache will be described using examples where data is written from a register to a cache (or the highest-level cache if the cache is configured in multiple levels) at the instruction of the CPU, and where data is written from memory to a cache (or the lowest-level cache if the cache is configured in multiple levels) at the instruction of the MMU.

[0099] In addition, in this embodiment, the reading of data from the cache will be explained using examples of when data is read from the cache to a register at the instruction of the CPU, when an instruction is read from the cache to the CPU, and when data is read from the cache to memory at the instruction of the MMU.

[0100] In this embodiment, all data written to the cache is assumed to be plain text, and data is exchanged between multiple hierarchical layers that make up the cache by normal read and write operations.

[0101] <Processing of Secure Processor and MMU in Authenticated Encryption Processing> Next, processing of the secure processor and MMU in authenticated encryption processing will be described.

[0102] To achieve authenticated encryption processing, the information processing device 1 has a seed for generating pseudo-random numbers and a master counter that maintains the internal state. The information processing device 1 also has a pair of signature key S and verification key V used for authentication, and a pair of public key E and private key D used for encryption. The CPU manufacturer certifies and publishes the public key E and verification key V. A secure communication path is provided between the machine, the secure processor, and the MMU. The secure processor, as well as the MMU, can securely access the virtual machine's key cache, which stores key K. The information processing device 1 has data related to the conditions of the machine in which the secure processor is installed.

[0103] First, the secure processor receives from the machine an identification information ID and a ciphertext C of a key K encrypted with a public key E, decrypts the ciphertext C with a private key D to generate the key K, and then stores the identification information ID and the key K in a key cache.

[0104] Thereafter, when the MMU receives the identification information ID and the authentication code L of the counter R from the machine, it reads the key K corresponding to the identification information ID from the key cache, verifies the authentication code L of the counter R using the key K, and if there is no problem with the verification result, it stores the counter R in addition to the identification information ID and the key K in the key cache.

[0105] Thereafter, when the secure processor receives a sufficiently short message from the machine, it generates a signature for the message using the signature key S and returns the signature to the machine. Thereafter, when the secure processor is requested by the machine to generate a pseudo-random number, it generates the pseudo-random number using the master counter and seed and returns the pseudo-random number to the machine.

[0106] <BYOK Key Management in Authenticated Encryption Processing> Next, BYOK (Bring Your Own Key) key management in authenticated encryption processing will be described.

[0107] In this embodiment, an example will be described in which the key used for encryption is generated by the user himself / herself and used in a TEE (Trusted Execution Environment). Normally, if the key used for encryption is used without being leaked outside the CPU or a secure processor, the confidentiality of the key can be greatly improved. However, if the user of a virtual machine wants to hide the contents of the virtual machine from the hypervisor, the user knowing the key (i.e., the key being leaked outside the CPU, etc.) itself is not a threat.

[0108] Below, we will explain how to securely share a TEE and a key guaranteed by the cloud and a CPU, how to load and verify an image (data) of a virtual machine encrypted using the shared key, how to load the same image into another TEE, and how to migrate to a TEE guaranteed by the cloud and a CPU and approved by the user.

[0109] (Preliminary Preparation) First, preliminary preparation is performed. It is assumed that the TEE has a secure pair of public key ET and private key DT. The TEE manufacturer has a pair of signing key SC and verification key VC, and the verification key VC is certified. The TEE manufacturer will publish a signature σC_ET using the signing key SC for the public key ET for all TEEs it manufactures. Various attributes are also added to the signature target. The cloud provider has a pair of signing key SP and verification key VP, and the verification key VP is certified. The cloud provider P will publish a signature σP_ET using the signing key SP for the public key ET for all clouds it provides. Various attributes are also added to the signature target. A user U has a pair of signing key SU and verification key VU. It is assumed that the verification key VU is recognized by the cloud provider P as the verification key for user U.

[0110] (Key Installation) After that, the key is installed. FIG. 13 is a diagram showing the flow of key installation. As shown in FIG. 13, first, the user U generates a key KU, a root counter RU, and conditions FU to be used in authenticated encryption processing. Then, the user U registers a pair of a signature key SP and a verification key VP with the cloud provider P. Then, the user U receives a list of public keys ET with appropriate attributes from the cloud provider P, and verifies the signatures σC_ET and σP_ET using the verification keys VC and VP, respectively.

[0111] Then, user U encrypts key KU and conditions FU with public key ET to generate ciphertext CU. User U also generates a signature σU_CU for ciphertext CU using signature key SU. User U then sends information about user U, ciphertext CU, and signature σU_CU to cloud provider P. Cloud provider P verifies signature σU_CU using verification key VU, and if the verification result is satisfactory, accepts information about user U and ciphertext CU. Cloud provider P then passes ciphertext CU to the hypervisor. The machine is assumed to have an interface through which the hypervisor passes ciphertext CU to the machine. The hypervisor then generates a locally unique key identifier IDU and passes the key identifier IDU and ciphertext CU to the machine. The machine then passes the key identifier IDU and ciphertext CU to the secure processor. The secure processor then decrypts the ciphertext CU to generate a key KU and conditions FU, and then checks whether the conditions FU satisfy predetermined conditions. If the conditions FU satisfy the predetermined conditions, the secure processor stores the key KU indexed using the key identifier IDU in a key cache.

[0112] (Loading of secret image) Then, the secret image is loaded. Specifically, first, a cloud user U prepares an image of a guest machine. The guest machine image is composed of a storage image DU, a memory image, a register image, and predetermined setting contents OU. Furthermore, the guest machine prepared by user U is set with secret information, etc., that enables this machine to securely communicate with the user. Then, in the guest machine prepared by user U, the storage image is placed as is as storage, and the memory image is placed as is as memory. This allows the guest machine to operate according to instructions immediately after preparation. Here, the storage is assumed to be storage that supports authenticated encryption processing. Furthermore, the key for this storage is assumed to be included only in the memory image, or to be encrypted by authenticated encryption processing in the same way as the memory key.

[0113] Then, in authenticated encryption processing, user U encrypts the memory image and the register image using key KU and root counter RU to generate ciphertext MU. User U also generates an authenticator LU for root counter RU. Using signing key SU, signatures σU_MU, σU_DU, σU_OU, σU_RU, and σU_LU are generated for ciphertext MU, storage image DU, configuration contents OU, root counter RU, and its authenticator LU, respectively.

[0114] Thereafter, user U sends U, MU, DU, OU, RU, LU and signatures σU_MU, σU_DU, σU_OU, σU_RU, σU_LU to cloud provider P. Cloud provider P verifies signatures σU_MU, σU_DU, σU_OU, σU_RU, σU_LU using verification key VU, and if there are no problems with the verification results, accepts U, MU, DU, OU, RU, LU.

[0115] The cloud provider P then passes MU, DU, OU, RU, and LU to the hypervisor. The hypervisor writes the ciphertext MU to memory, places the storage image DU directly in the storage, and performs configuration according to the configuration content OU.

[0116] Thereafter, the hypervisor requests the machine to transfer authority to the guest by specifying the key identifier IDU, the root counter RU, its authenticator LU, and the address range of the ciphertext MU.

[0117] The machine then passes the key identifier IDU, the root counter RU, and its authenticator LU to the MMU, which verifies the authenticator LU of the root counter RU using the key KU, and if successful, stores the root counter RU in its key cache in addition to the key identifier IDU and the key KU.

[0118] The machine then assigns the key identifier IDU to the MMU, restores the guest's registers from the registers included in the ciphertext MU with the help of the MMU, and then transfers execution authority from the hypervisor to the guest. The MMU executes the guest using the key KU and the root counter RU.

[0119] Secure communication is performed between the user U and the virtual machine using secret information set in the virtual machine. Note that, although attestation is not required in this process, authentication in authenticated encryption processing can be considered to correspond to attestation.

[0120] (Migration) After that, migration is performed. In this embodiment, a case will be described in which, when a machine in which memory data is encrypted using a key K is operating in a certain TEE, the machine is moved from that TEE to another TTE.

[0121] First, migration settings are made. It is assumed that user U has generated key KU and conditions FU' to be used in authenticated encryption processing. It is also assumed that TEE before migration has a pair of public key ET' and private key DT', and that signatures σC_ET' and σP_ET' made by signing key SC for public key ET' are public.

[0122] User U receives a list of public keys ET' with appropriate attributes from cloud provider P, and verifies signatures σC_ET' and σP_ET' using verification keys VC and VP. User U then encrypts key KU and conditions FU' with public key ET to generate ciphertext CU'. User U also generates a signature σU_CU' for ciphertext CU' using signature key SU. User U then sends information about user U, ciphertext CU', and signature σU_CU' to cloud provider P. Cloud provider P verifies signature σU_CU' using verification key VU, and if there are no problems with the verification results, accepts information about user U and ciphertext CU'.

[0123] The cloud provider P then passes the ciphertext CU' to the hypervisor. The hypervisor then generates a locally unique key identifier IDU' and passes the key identifier IDU' and the ciphertext CU' to the machine. The machine then passes the key identifier IDU' and the ciphertext CU' to the secure processor. The secure processor then decrypts the ciphertext CU' to generate a key KU and conditions FU', and then checks whether the conditions FU' satisfy predetermined conditions. If the conditions FU' satisfy the predetermined conditions, the secure processor stores the key KU indexed using the key identifier IDU' in a key cache.

[0124] After the migration is set, the migration is executed. Specifically, first, the hypervisor confirms that the key of user U is installed in TEE T', and then decides to migrate virtual machine M from TEE T to TEE T'. Then, the hypervisor copies the storage and memory of virtual machine M created in the machine to which TEE T belongs to another machine to which TEE T' belongs. Note that every time the storage and memory of virtual machine M are changed, the hypervisor copies the changed storage and memory of virtual machine M to the other machine. Then, the hypervisor stops virtual machine M. The hypervisor also sends to TEE T' an authenticated ciphertext generated at this time using the register key KU of virtual machine M.

[0125] Then, in order to execute the migration, the hypervisor requests the MMU to generate an authenticator LU' using the key KU of the current root counter RU'. Then, the hypervisor sends the root counter RU and its authenticator LU to the hypervisor of the machine to which TEE T' belongs.

[0126] Then, the hypervisor of TEE T' specifies the key identifier IDU' corresponding to the key KU and passes the registers of the virtual machine M, the root counter RU, and its authenticator LU to the machine of TEE T'. The machine of TEE T' passes the key identifier IDU', the root counter RU', and its authenticator LU' to the MMU.

[0127] The MMU then verifies the authenticator LU' of the root counter RU' using the key KU, and if the verification is successful, stores the root counter RU' in the key cache in addition to the key identifier IDU' and the key KU.

[0128] The machine then assigns the key identifier IDU' to the MMU, and transfers execution authority from the hypervisor to the guest. The MMU executes the guest using the key KU and root counter RU'.

[0129] The hypervisor of TEE T' requests the hypervisor running on TEE T to send any of the latest memory and storage of virtual machine M on TEE T's machine that has not yet been acquired. Once all of the latest memory and storage of virtual machine M on TEE T's machine has been acquired, TEE T's machine is deleted. The sequential acquisition of memory in this migration is the same as normal migration. Since TEE T and T' can use the same key KU, memory is replicated while remaining encrypted.

[0130] As described above, the information processing device according to the present embodiment can prevent attacks on the cache from the hypervisor by configuring the cache to be accessible to a data storage area specified by a guest physical address managed by the guest. In other words, the information processing device according to the present embodiment can improve confidentiality and security against attacks on virtual machines from the hypervisor.

[0131] Note that the present disclosure can be realized by causing a CPU to execute a computer program to perform part or all of the processing of the information processing device according to the present embodiment.

[0132] The above-described program includes a set of instructions (or software code) that, when loaded into a computer, causes the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drives (SSDs) or other memory technologies, CD-ROMs, digital versatile discs (DVDs), Blu-ray discs or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage, or other magnetic storage devices. The program may also be transmitted on a transitory computer-readable medium or a communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.

[0133] The embodiments of the present disclosure have been described in detail above with reference to the drawings, but the specific configurations are not limited to those described above, and various design changes and the like are possible within the scope that does not deviate from the gist of the present disclosure.

[0134] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes.

[0135] (Supplementary Note 1) An information processing device comprising: a memory having a data storage area to which a machine physical address is assigned; a cache having a data storage area to which a guest physical address is assigned; an authentication-enabled encryption engine that performs encryption and authentication processes on data exchanged between the cache and the memory; a first address translation means that is managed by a guest and that translates an external address that instructs access to data that is the subject of encryption and authentication processes into a guest physical address; and a second address translation means that is managed by a hypervisor and that translates the guest physical address into a machine physical address that corresponds to the guest physical address.

[0136] (Supplementary Note 2) The information processing device according to Supplementary Note 1, wherein the cache further has a data storage area to which the machine physical address is assigned, in addition to a data storage area to which the guest physical address is assigned.

[0137] (Supplementary Note 3) The information processing device according to Supplementary Note 1, wherein the cache further has a data storage area to which the machine physical address is assigned in addition to the data storage area to which the guest physical address is assigned, and the first address conversion means further converts the external address that instructs access to data that is not subject to encryption processing and authentication processing into the machine physical address corresponding to the external address.

[0138] (Supplementary Note 4) The information processing device according to Supplementary Note 1, wherein the first address conversion means converts the external address into a guest physical address according to identification information of a virtual machine.

[0139] (Supplementary Note 5) The information processing device according to Supplementary Note 4, wherein, during a context switch, the register values ​​of each virtual machine are stored in a storage area of ​​the cache of the virtual machine that is designated by the guest physical address assigned to the virtual machine.

[0140] (Supplementary Note 6) The information processing device according to Supplementary Note 1, wherein the authenticated encryption engine performs encryption processing on data exchanged between the cache and the memory, and authentication processing using an authentication tree consisting of a plurality of nodes connected in a tree shape, each of which is assigned a set of a counter and an identifier.

[0141] (Supplementary Note 7) A control method for an information processing device comprising: a memory having a data storage area to which a machine physical address is assigned; a cache having a data storage area to which a guest physical address is assigned; an authenticated encryption engine that performs encryption processing and authentication processing on data exchanged between the cache and the memory; a first address translation means managed by a guest; and a second address translation means managed by a hypervisor, wherein when accessing the cache, the first address translation means is used to translate an external address instructing access to data to be encrypted and authenticated into a guest physical address; and when accessing the memory, the second address translation means is used to translate the guest physical address into a machine physical address corresponding to the guest physical address.

[0142] (Supplementary Note 8) The control method for an information processing device described in Supplementary Note 7, wherein the cache further has a data storage area to which the machine physical address is assigned in addition to the data storage area to which the guest physical address is assigned, and the first address conversion means is used to convert the external address that instructs access to data that is not subject to encryption processing and authentication processing into the machine physical address that corresponds to the external address.

[0143] (Supplementary Note 9) A non-transitory computer-readable medium having stored thereon a control program that causes a computer to execute control processing in an information processing device, the information processing device comprising: a memory having a data storage area to which machine physical addresses are assigned; a cache having a data storage area to which guest physical addresses are assigned; an authenticated encryption engine that performs encryption processing and authentication processing on data exchanged between the cache and the memory; a first address translation means managed by a guest; and a second address translation means managed by a hypervisor, the non-transitory computer-readable medium having stored thereon a control program that causes a computer to execute control processing including: when accessing the cache, using the first address translation means to convert an external address that instructs access to data that is the subject of encryption processing and authentication processing into a guest physical address; and when accessing the memory, using the second address translation means to convert the guest physical address into a machine physical address that corresponds to the guest physical address.

[0144] (Supplementary Note 10) A non-transitory computer-readable medium having stored thereon the control program described in Supplementary Note 9 that causes a computer to execute a control process further including, using the first address conversion means, converting the external address that instructs access to data that is not subject to encryption processing and authentication processing into the machine physical address that corresponds to the external address, wherein the cache further has, in addition to the data storage area to which the guest physical address is assigned, a data storage area to which the machine physical address is assigned.

[0145] REFERENCE SIGNS LIST 1 Information processing device 101 Cache 102 Memory 103 Authenticated encryption engine 104 First address translation unit 105 Second address translation unit

Claims

1. a memory having a data storage area to which machine physical addresses are assigned; a cache having a data storage area to which guest physical addresses are assigned; an authentication-enabled encryption engine that performs encryption and authentication processes on data exchanged between the cache and the memory; a first address conversion means for converting an external address, which is managed by the guest and instructs access to data that is the subject of encryption processing and authentication processing, into a guest physical address; a second address conversion means, managed by a hypervisor, for converting the guest physical address into a machine physical address corresponding to the guest physical address; An information processing device comprising:

2. the cache further includes a data storage area to which the machine physical address is assigned in addition to the data storage area to which the guest physical address is assigned; The information processing device according to claim 1 .

3. the cache further includes a data storage area to which the machine physical address is assigned in addition to the data storage area to which the guest physical address is assigned; the first address conversion means further converts the external address instructing access to data not subject to encryption processing and authentication processing into the machine physical address corresponding to the external address. The information processing device according to claim 1 .

4. the first address conversion means converts the external address into a guest physical address according to identification information of the virtual machine. The information processing device according to claim 1 .

5. At the time of a context switch, the register value of each virtual machine is stored in a storage area of ​​the cache of the virtual machine, the storage area being designated by the guest physical address assigned to the virtual machine. The information processing device according to claim 4 .

6. The authenticated encryption engine performs encryption processing on data exchanged between the cache and the memory, and authentication processing using an authentication tree consisting of a plurality of nodes connected in a tree shape, each node being assigned a pair of a counter and an identifier. The information processing device according to claim 1 .

7. a memory having a data storage area to which machine physical addresses are assigned; a cache having a data storage area to which guest physical addresses are assigned; an authentication-enabled encryption engine that performs encryption and authentication processes on data exchanged between the cache and the memory; a first address translation means managed by the guest; a second address translation means managed by the hypervisor; A control method for an information processing device, comprising: When accessing the cache, the first address conversion means converts an external address instructing access to data that is the subject of encryption processing and authentication processing into a guest physical address; When accessing the memory, the guest physical address is converted into a machine physical address corresponding to the guest physical address using the second address conversion means. A method for controlling an information processing device.

8. the cache further includes a data storage area to which the machine physical address is assigned in addition to the data storage area to which the guest physical address is assigned; using the first address conversion means to convert the external address instructing access to data not subject to encryption processing and authentication processing into the machine physical address corresponding to the external address; The method for controlling an information processing apparatus according to claim 7.

9. a memory having a data storage area to which machine physical addresses are assigned; a cache having a data storage area to which guest physical addresses are assigned; an authentication-enabled encryption engine that performs encryption and authentication processes on data exchanged between the cache and the memory; a first address translation means managed by the guest; a second address translation means managed by the hypervisor; A control program for causing a computer to execute control processing in an information processing device, comprising: When accessing the cache, a process of converting an external address instructing access to data that is the target of encryption processing and authentication processing into a guest physical address using the first address conversion means; When accessing the memory, a process of converting the guest physical address into a machine physical address corresponding to the guest physical address using the second address conversion means; A control program that causes a computer to execute control processing including the above.

10. the cache further includes a data storage area to which the machine physical address is assigned in addition to the data storage area to which the guest physical address is assigned; 10. The control program according to claim 9, which causes a computer to execute a control process further including a process of using the first address conversion means to convert the external address that instructs access to data that is not subject to encryption processing and authentication processing into the machine physical address corresponding to the external address.