Virtual machine access method, and device
By storing the first key table and the second key table in the processor and memory, and obtaining and using the virtual machine key to encrypt or decrypt the access requested data, the problem of limited number of virtual machines in the prior art is solved, and the security protection and performance guarantee of a larger number of virtual machines is achieved.
Patent Information
- Application Number
- PCT/CN2024/097817
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-06-06
- Publication Date
- 2025-07-03
AI Technical Summary
The existing cloud computing virtual machine encryption technology only supports a small number of keys, which cannot meet the cloud business's demand for the number of virtual machines, making it difficult to guarantee data security and privacy.
By storing the first and second key tables in the processor and memory, using the correspondence between the virtual machine number and the virtual machine key, encrypting or decrypting the access requested data using the virtual machine key, a larger amount of virtual machine data security protection is supported.
It realizes security protection for more data of virtual machines, ensures the independence and privacy of data, and does not affect the performance of virtual machines of cloud computing users.
Smart Images

Figure CN2024097817_03072025_PF_FP_ABST
Abstract
Description
Virtual machine access method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to Chinese patent application No. 202311828910.4 filed in China on December 28, 2023, the entire contents of which are incorporated herein by reference. Technical Field
[0003] The present disclosure relates to the field of computer technology, and in particular to a virtual machine access method, device, electronic device, readable storage medium, computer program product, and computer program. Background Art
[0004] With the development of cloud computing technology, cloud usage and demand across various industries are increasing, and virtualization technology is widely used in cloud computing environments. Cloud computing environments are characterized by the sharing of hardware resources between multiple users through virtualization technology, which can lead to potential data security issues.
[0005] Currently, virtual machine encryption is used to mitigate data security issues. Hardware encryption is typically used to isolate data between virtual machines. This provides enhanced security isolation for virtual machines, preventing them from accessing data they shouldn't, and effectively preventing attacks from the virtual machine monitor (VMM) and other virtual machines. Virtual machine encryption schemes maintain data independence and privacy by providing each virtual machine with independent, hardware-encrypted memory space, ensuring data is protected from leaks and attacks. However, current cloud computing virtual machine encryption technology only supports a small number of keys, limiting the number of virtual machines that can be encrypted and failing to meet the demand for a large number of virtual machines in cloud services.
[0006] Summary of the Invention
[0007] In response to the problems existing in the related technologies, the embodiments of the present disclosure provide a virtual machine access method, apparatus, electronic device, readable storage medium, computer program product and computer program, which can support the protection of a larger number of virtual machines.
[0008] In a first aspect, an embodiment of the present disclosure provides a virtual machine access method, which is applied to an electronic device. The electronic device includes a processor and a memory. The processor stores a first key table, and the memory stores a second key table. The first key table and the second key table are used to store a correspondence between a virtual machine number and a virtual machine key. The method includes:
[0009] Get access request to virtual machine;
[0010] Determining, according to the virtual machine number corresponding to the access request, whether the first key table includes a virtual machine key corresponding to the virtual machine;
[0011] If the first key table does not include the virtual machine key corresponding to the virtual machine, obtaining the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request;
[0012] Encrypt or decrypt the data corresponding to the access request using the virtual machine key,
[0013] The second key table is an encrypted key table, and obtaining the virtual machine key corresponding to the virtual machine from the second key table includes: obtaining a target key from a key register in the processor, decrypting the second key table using the target key; and obtaining the virtual machine key corresponding to the virtual machine from the decrypted second key table.
[0014] In some embodiments, the access request is a read request, the processor includes at least one cache area, and before determining, based on the virtual machine number corresponding to the access request, whether the first key table includes the virtual machine key corresponding to the virtual machine, the process further includes:
[0015] Determining whether the virtual machine number corresponding to the access request is stored in the at least one cache area;
[0016] If the virtual machine number corresponding to the access request is stored in the cache, determining whether the data corresponding to the access request is stored in the cache;
[0017] If the data corresponding to the access request is stored in the cache area, reading the data corresponding to the access request;
[0018] If the virtual machine number corresponding to the access request or the data corresponding to the access request is not stored in the cache area, a step of determining whether the first key table includes a virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request is executed.
[0019] In some embodiments, each of the cache areas stores a correspondence between the virtual machine number allowed to be accessed and the label corresponding to the address of the cache area; if the virtual machine number corresponding to the access request is stored in the cache area, then determining whether the data corresponding to the access request is stored in the cache area includes: if the virtual machine number corresponding to the access request is stored in the cache area, and the access address corresponding to the access request matches the label corresponding to the virtual machine number, then determining whether the data corresponding to the access request is stored in the cache area.
[0020] In some embodiments, encrypting or decrypting data corresponding to the access request using the virtual machine key includes:
[0021] If the access request is a read request, obtaining memory data from the memory according to the memory address corresponding to the read request;
[0022] Decrypting the memory data using the virtual machine key; or,
[0023] If the access request is a write-back request, the write-back data corresponding to the write-back request is encrypted using the virtual machine key, and the encrypted data is written into the memory according to the memory address corresponding to the write-back request.
[0024] In some embodiments, the method further comprises:
[0025] If the second key table does not include the virtual machine key corresponding to the virtual machine, generating a virtual machine key corresponding to the virtual machine, and storing the generated virtual machine key corresponding to the virtual machine in the first key table;
[0026] After obtaining the virtual machine key corresponding to the virtual machine from the second key table, the method further includes:
[0027] The obtained virtual machine key corresponding to the virtual machine is stored in the first key table.
[0028] In some embodiments, storing the generated virtual machine key corresponding to the virtual machine into the first key table includes:
[0029] If the storage space of the first key table is full, the generated virtual machine key corresponding to the virtual machine is used to replace the key in the first key table according to a preset replacement strategy;
[0030] Storing the acquired virtual machine key corresponding to the virtual machine into the first key table includes:
[0031] According to a preset replacement strategy, the key in the first key table is replaced with the obtained virtual machine key corresponding to the virtual machine.
[0032] In some embodiments, when the second key table and the first key table are in a non-inclusion relationship, the method further includes:
[0033] The replaced key in the first key table is written back to the second key table.
[0034] In some embodiments, when the second key table and the first key table are in an inclusion relationship, the method further includes:
[0035] The generated virtual machine key corresponding to the virtual machine is stored in the second key table.
[0036] In some embodiments, when the second key table and the first key table are in a non-inclusion relationship, the method further includes:
[0037] Writing the replaced virtual machine key in the first key table back to the second key table;
[0038] Delete the virtual machine key corresponding to the virtual machine in the second key table.
[0039] In some embodiments, the second key table is an encrypted key table, and writing the replaced virtual machine key in the first key table back to the second key table includes:
[0040] obtaining a target key from a key register in the processor;
[0041] The second key table is decrypted using the target key, and the replaced virtual machine key is written back to the decrypted second key table.
[0042] In some embodiments, the method further comprises:
[0043] During initialization, generating a target key for encrypting and decrypting the second key table using a random number generator in the processor, and storing the target key in a key register in the processor;
[0044] During initialization, the storage address of the second key table in the memory is stored in an address register in the processor.
[0045] In some embodiments, before determining, based on the virtual machine number corresponding to the access request, whether the first key table includes the virtual machine key corresponding to the virtual machine, the method further includes:
[0046] Determining whether the memory address corresponding to the access request belongs to the memory space where the second key table is located;
[0047] If so, a prompt message is output, where the prompt message is used to indicate that the accessed memory address is invalid or illegal.
[0048] In some embodiments, the preset replacement strategy includes at least one of the following: least recently used (LRU), least frequently used (LFU), first in first out (FIFO), and random replacement strategy.
[0049] In some embodiments, the processor includes: a key generation and deletion module and a key import and export module, and the method further includes:
[0050] When the life cycle of the virtual machine ends, the key generation and deletion module is used to delete the virtual machine keys in the first key table and the second key table through the key import and export module; the address space of the second key table is only accessible by the key import and export module.
[0051] In a second aspect of the present disclosure, an embodiment provides a virtual machine access device, which is applied to an electronic device. The electronic device includes a processor and a memory. The processor stores a first key table, and the memory stores a second key table. The first key table and the second key table are used to store a correspondence between a virtual machine number and a virtual machine key. The device includes:
[0052] An acquisition module, used to obtain an access request of a virtual machine;
[0053] a processing module, configured to determine, based on the virtual machine number corresponding to the access request, whether the first key table includes a virtual machine key corresponding to the virtual machine;
[0054] The processing module is further configured to obtain the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request if the first key table does not include the virtual machine key corresponding to the virtual machine;
[0055] The processing module is further configured to encrypt or decrypt data corresponding to the access request using the virtual machine key.
[0056] The second key table is an encrypted key table, and obtaining the virtual machine key corresponding to the virtual machine from the second key table includes: obtaining a target key from a key register in the processor, decrypting the second key table using the target key; and obtaining the virtual machine key corresponding to the virtual machine from the decrypted second key table.
[0057] An embodiment of the third aspect of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the virtual machine access method of any embodiment of the first aspect is implemented.
[0058] An embodiment of a fourth aspect of the present disclosure provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the virtual machine access method of any one of the embodiments of the first aspect is implemented.
[0059] A fifth aspect of the present disclosure provides a computer program product, including a computer program, which, when executed by a processor, implements the virtual machine access method of any one of the first aspects.
[0060] A sixth aspect of the present disclosure provides a computer program, comprising computer program code. When the computer program code runs on a computer, the computer executes the virtual machine access method of any one of the first aspects.
[0061] The virtual machine access method, apparatus, electronic device, readable storage medium, computer program product, and computer program provided by the embodiments of the present disclosure first obtain an access request for a virtual machine; determine whether the first key table includes the virtual machine key corresponding to the virtual machine based on the virtual machine number corresponding to the access request; if the first key table does not include the virtual machine key corresponding to the virtual machine, obtain the virtual machine key corresponding to the virtual machine from the second key table based on the virtual machine number corresponding to the access request; and use the obtained virtual machine key to encrypt or decrypt data corresponding to the access request. By storing the virtual machine key in the first key table and the second key table, it is possible to support security protection of a larger number of virtual machine data, while ensuring the security of the virtual machine data without affecting the performance of the cloud computing user virtual machine. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] In order to more clearly illustrate the technical solutions in the present disclosure or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0063] FIG1 is a flow chart of a virtual machine access method provided by the present disclosure;
[0064] FIG2 is a schematic diagram showing the principles of a virtual machine access method provided by the present disclosure;
[0065] FIG3 is a second schematic diagram of the principle of the virtual machine access method provided by the present disclosure;
[0066] FIG4 is a third schematic diagram of the principle of the virtual machine access method provided by the present disclosure;
[0067] FIG5 is a schematic diagram of the position of a VMID in a control register of a virtual machine access method provided by the present disclosure;
[0068] FIG6 is a schematic structural diagram of a virtual machine access device provided by the present disclosure;
[0069] FIG7 is a schematic structural diagram of an electronic device provided by the present disclosure. DETAILED DESCRIPTION
[0070] To make the objectives, technical solutions, and advantages of this disclosure more clear, the technical solutions of this disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this disclosure, not all of them. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments of this disclosure without creative effort shall fall within the scope of protection of this disclosure.
[0071] First, the terms and application scenarios involved in the embodiments of the present disclosure are introduced:
[0072] A virtual machine monitor (VMM), also known as a hypervisor, is used to manage the operation of virtual machines. Each virtual machine shares virtualized hardware resources.
[0073] The disclosed embodiments propose a virtual machine access method, device, electronic device, readable storage medium, computer program product, and computer program. By storing virtual machine numbers in caches at all levels, the virtual machine keys are stored on the processor chip and in memory. The virtual machine keys are generated and recovered according to the execution status of the virtual machine, and the virtual machine keys stored on the processor chip and in the off-chip memory are scheduled. The storage space of the memory virtual machine keys is further encrypted and protected, providing a larger and more secure virtual machine key storage space, thereby supporting the protection of a larger number of virtual machines. The disclosed embodiments ensure the performance of the cloud computing user virtual machines while ensuring the security of the virtual machines, and do not require modification of the application software. It can also maintain the independence and privacy of the data, ensuring that the data will not be leaked or attacked. It creates a more secure, efficient, and convenient computing environment for cloud users, and brings a new security protection method to cloud computing, ensuring the security of data while improving the performance of the cloud computing system.
[0074] The technical solutions of the embodiments of the present disclosure are described in detail below with reference to Figures 1 to 7. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0075] Figure 1 is a schematic flow chart of a method for accessing a virtual machine provided by an embodiment of the first aspect of the present disclosure. As shown in Figure 1, the method provided by this embodiment is applied to an electronic device, the electronic device including a processor and a memory, the processor storing a first key table, the memory storing a second key table, the first key table and the second key table being used to store a correspondence between a virtual machine number and a virtual machine key, the method comprising the following steps 101 to 104.
[0076] Step 101: Obtain an access request from a virtual machine.
[0077] Step 102: Determine whether the first key table includes a virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request.
[0078] Specifically, the first key table is a table stored on the processor chip for storing virtual machine keys. As shown in Table 1 below, each data item in the first key table (i.e., a row of data in Table 1) includes a virtual machine ID (VMID), a virtual machine key corresponding to the virtual machine with that VMID, and a valid bit (Valid) indicating whether the table item is valid. The number of data items in the first key table can be flexibly configured based on the size of the on-chip storage space, such as 512 items, 1024 items, or 2048 items. To expand the key storage space, the memory includes a second key table with a larger capacity. The number of data items in the second key table is generally greater than the number of virtual machine keys that can be stored in the first key table. The memory is used to store the virtual machine keys of all virtual machines. The second key table has a large storage capacity and can support a larger number of virtual machines. The virtual machine key corresponding to the virtual machine most recently used by the processor is stored in the first key table for quick access, while the virtual machine keys corresponding to other virtual machines are stored in the second key table, which can support a larger key table capacity.
[0079] Table 1
[0080] According to the virtual machine number, the first key table is queried to determine whether it includes a virtual machine key corresponding to the virtual machine number, that is, a virtual machine key of the virtual machine corresponding to the initiating access request.
[0081] Step 103: If the first key table does not include the virtual machine key corresponding to the virtual machine, obtain the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request.
[0082] Specifically, if the virtual machine key corresponding to the virtual machine is not found in the first key table, the virtual machine key corresponding to the virtual machine is further obtained from the second key table based on the virtual machine number.
[0083] The second key table is similar to the first key table, as shown in Table 1, and stores the correspondence between the virtual machine number and the virtual machine key.
[0084] Step 104: Use the virtual machine key to encrypt or decrypt the data corresponding to the access request.
[0085] Specifically, the obtained virtual machine key is used to encrypt or decrypt the data corresponding to the access request. For example, if the access request is a read request, the corresponding data is obtained from the memory according to the read request, and the data is decrypted using the virtual machine key; if the access request is a write-back request, the data corresponding to the write-back request is encrypted using the virtual machine key and written into the memory.
[0086] The method of this embodiment obtains an access request for a virtual machine; determines whether the first key table includes the virtual machine key corresponding to the virtual machine based on the virtual machine number corresponding to the access request; if the first key table does not include the virtual machine key corresponding to the virtual machine, obtains the virtual machine key corresponding to the virtual machine from the second key table based on the virtual machine number corresponding to the access request; and uses the obtained virtual machine key to encrypt or decrypt data corresponding to the access request. By storing the virtual machine key in the first key table and the second key table, it can support the security protection of a larger number of virtual machine data, while ensuring the security of the virtual machine data without affecting the performance of the cloud computing user virtual machine.
[0087] In some embodiments, the processor includes at least one cache area, and the following operations may be performed before step 102:
[0088] Determining whether the virtual machine number corresponding to the access request is stored in the at least one cache area;
[0089] If the virtual machine number corresponding to the access request is stored in the cache, determining whether the data corresponding to the access request is stored in the cache;
[0090] If the data corresponding to the access request is stored in the cache area, reading the data corresponding to the access request;
[0091] If the virtual machine number corresponding to the access request or the data corresponding to the access request is not stored in the cache area, a step of determining whether the first key table includes a virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request is executed.
[0092] In some embodiments, each of the cache areas stores a correspondence between a virtual machine number allowed to be accessed and a tag corresponding to an address of the cache area; if the cache area stores the virtual machine number corresponding to the access request, determining whether the cache area stores data corresponding to the access request includes:
[0093] If the virtual machine number corresponding to the access request is stored in the cache area, and the access address corresponding to the access request matches the tag corresponding to the virtual machine number, it is determined whether the data corresponding to the access request is stored in the cache area.
[0094] Specifically, the processor includes at least one cache area, and the at least one cache area is implemented, for example, by a cache area corresponding to at least one level of cache hierarchy, that is, the tag storage body of each level of cache (Cache) stores the virtual machine number corresponding to the address of the cache area. As shown in Table 2, the tag storage body of the cache includes not only the valid bit Valid, the tag TAG (corresponding to the address of the cache area), etc., but also the virtual machine number VMID. When the virtual machine sends an access request to the cache or memory at each level, it also carries the virtual machine number VMID. The virtual machine number comes from the value of the VMID of the control register hgatp when the memory access instruction is executed in the mainstream pipeline, and this VMID is stored in the tag storage body of the cache at each level.
[0095] Table 2
[0096] In some embodiments, as shown in FIG2 , the processor includes a memory controller and a multi-level cache hierarchy of cache space; a control register for storing a virtual machine number is provided in the multi-level cache hierarchy.
[0097] After receiving an access request (such as a read request), first determine whether a virtual machine number corresponding to the access request is stored in at least one cache area of the processor;
[0098] If the virtual machine number corresponding to the access request is stored in the cache area, it indicates a cache hit (Cache Hit), and the cache area is accessed. If the access request is a read request, it is determined whether the cache area stores the data corresponding to the access request; if the cache area stores the data corresponding to the access request, the data corresponding to the access request is read;
[0099] If the virtual machine number corresponding to the access request is not stored in the cache area, indicating a cache miss, or the data corresponding to the access request is not stored in the cache space, the memory is accessed, that is, step 102 is executed.
[0100] In some embodiments, as shown in Table 2, VMIDs are cached in tag banks at all levels of the cache hierarchy. A cache hit occurs only when the virtual machine number corresponding to an access request to the cache matches the virtual machine number in the cache tag bank, and the access address included in the access request matches the corresponding tag bit in the tag bank. This protects the virtual machine from accessing the cache, preventing it from accessing cache data that does not correspond to its own virtual machine number.
[0101] In some embodiments, cache access fails, and data is read from the memory, or the data obtained from the memory can be replaced and written back to the data in the cache (for example, replacing the infrequently used data in the cache with the currently accessed data). The cache transmits the VMID together with the requested physical address to the memory controller. The modules of the memory controller use the VMID to determine which virtual machine is accessing the data, and use the VMID to distinguish the virtual machine keys. The VMID is automatically added by the hardware and cannot be directly modified by the software. Therefore, the data read from the memory is directly encrypted and decrypted by the memory controller using the corresponding virtual machine key. Each virtual machine is associated only with its own virtual machine key through the VMID. Other virtual machines or virtual machine monitors can only access the encrypted data, thereby achieving secure isolation of the virtual machines.
[0102] In the above implementation, by adding a virtual machine number to the cache, only when the virtual machine number matches does it indicate a cache hit, and the data in the corresponding cache can be accessed. This also provides security protection for the virtual machine's access to the cache, and ensures that the virtual machine cannot access cache data corresponding to a virtual machine number other than its own.
[0103] In some embodiments, the second key table is an encrypted key table, and obtaining the virtual machine key corresponding to the virtual machine from the second key table in step 103 can be specifically implemented as follows:
[0104] Obtaining a target key from a key register in the processor, and decrypting the second key table using the target key;
[0105] The virtual machine key corresponding to the virtual machine is obtained from the decrypted second key table.
[0106] Specifically, in order to improve security, the second key table stored in the memory can be encrypted, and after obtaining the second key table from the memory, the second key table is decrypted, and the virtual machine key is obtained from the decrypted second key table, and then the obtained virtual machine key is used to encrypt or decrypt the data corresponding to the access request; after reading the virtual machine key, the second key table is encrypted.
[0107] For example, as shown in FIG2 , a key register may be provided in the processor for storing the target key, that is, the target key is stored in a dedicated hardware register, and the second key table is decrypted using the target key.
[0108] In some embodiments, the memory controller may use a variety of encryption and decryption algorithms, such as the Advanced Encryption Standard (AES), to encrypt and decrypt the second key table and read-write data, but the embodiments of the present disclosure do not limit this. The second key table or written data is encrypted when written to the memory and decrypted when read. The virtual machine key or target key used for encryption and decryption is randomly generated each time the system is restarted and is invisible to the software. The virtual machine key or target key is generated based on a random number generated by a random number generator. After the key is generated, the hardware is protected.
[0109] In the above implementation, since the security of virtual machine access depends on the security of the key, if the key is leaked, the encrypted data in the virtual machine will no longer be secure. To protect the key security, the key space in the memory is further encrypted, that is, the second key table stored in the memory is also encrypted, thereby improving security.
[0110] In some embodiments, step 104 may be implemented as follows:
[0111] If the access request is a read request, obtaining memory data according to the memory address corresponding to the read request;
[0112] Decrypting the memory data using the virtual machine key; or,
[0113] If the access request is a write-back request, the write-back data corresponding to the write-back request is encrypted using the virtual machine key corresponding to the virtual machine, and the encrypted data is written into the memory according to the memory address corresponding to the write-back request.
[0114] Specifically, as shown in Figure 3, the access request is a read request for the memory. The processor receives the virtual machine number of the virtual machine's read request for the memory and the memory address of the read request, performs memory access on the memory address, obtains the memory data, and after returning the memory data, uses the virtual machine key of the virtual machine number corresponding to the read request to decrypt the memory data and return the decrypted data.
[0115] In some embodiments, the processor may maintain a read request queue for receiving read requests from the virtual machine to the memory.
[0116] As shown in Figure 4, the access request is a write-back request to the memory. The processor receives the virtual machine number of the virtual machine's write-back request to the memory, as well as the memory address and write-back data of the write-back request. The processor uses the key of the virtual machine corresponding to the write-back request to encrypt the data written to the memory, and then sends the write-back address and encrypted write-back data to the memory for memory write-back.
[0117] In some embodiments, the processor may maintain a write-back request queue for receiving write-back requests from the virtual machine to the memory.
[0118] In some embodiments, the method further comprises:
[0119] Determining whether the memory address corresponding to the access request belongs to the memory space where the second key table is located;
[0120] If so, a prompt message is output, where the prompt message is used to indicate that the accessed memory address is invalid or illegal.
[0121] Specifically, before accessing the memory, for example, it is determined whether the memory address corresponding to the read request belongs to the address of the memory space where the second key table is located. If not, the data is directly read from the memory based on the memory address; if so, the read request is no longer sent to the memory, but the accessed memory address is reported to be invalid or illegal, and an invalid or constant value is directly returned, such as an all-zero value.
[0122] For example, determine whether the memory address corresponding to the write-back request belongs to the address of the memory space where the second key table is located. If not, use the virtual machine key to encrypt the write-back data, and write the encrypted write-back data into the memory based on the memory address; if so, no longer send this write-back request to the memory, but report that the accessed memory address is invalid or illegal.
[0123] In the above implementation, it can be determined whether the memory address corresponding to the access request belongs to the memory space where the second key table is located. If so, access to the memory is not allowed, thereby improving security.
[0124] In some embodiments, the method further comprises:
[0125] If the second key table does not include the virtual machine key corresponding to the virtual machine, generating a virtual machine key corresponding to the virtual machine, and storing the generated virtual machine key corresponding to the virtual machine in the first key table;
[0126] After obtaining the virtual machine key corresponding to the virtual machine from the second key table, the method further includes:
[0127] The obtained virtual machine key corresponding to the virtual machine is stored in the first key table.
[0128] Specifically, the first key table and the second key table are accessed to determine whether a new virtual machine key needs to be generated. If neither the first key table nor the second key table includes the virtual machine key corresponding to the virtual machine number, a new virtual machine key needs to be generated and the generated new virtual machine key is stored in the first key table.
[0129] In some embodiments, a random number generated by a random number generator may be used to generate a virtual machine key corresponding to the virtual machine.
[0130] As shown in FIG2 , the random number generator is included in the processor.
[0131] In some embodiments, if the second key table includes the virtual machine key but the first key table does not include the virtual machine key, the virtual machine key obtained from the second key table may be stored in the first key table for quick access.
[0132] In some embodiments, the memory controller in Figure 2 includes a key generation and deletion module. This module is responsible for generating and deleting virtual machine keys. When a virtual machine accesses memory for the first time, including reading and writing to memory, a key corresponding to the virtual machine is generated and the newly generated key is stored in the first key table. When a virtual machine's lifecycle ends, the processor notifies the key generation and deletion module via a secure channel to delete the virtual machine key corresponding to the virtual machine.
[0133] In some embodiments, the key calling-in and calling-out module in FIG2 is responsible for accessing the first key table and the second key table to determine whether a new virtual machine key needs to be generated when the virtual machine performs read and write access to the memory. If a new virtual machine key needs to be generated, the key generation and deletion module is notified to put the generated new virtual machine key into the first key table. When receiving the key deletion signal from the key generation and deletion module, the module is responsible for deleting the virtual machine keys in the first key table and the second key table, and is responsible for calling-in and calling-out the virtual machine keys between the first key table and the second key table.
[0134] In some embodiments, storing the first key table may be implemented in the following manner:
[0135] If the storage space of the first key table is full, the generated virtual machine key corresponding to the virtual machine is used to replace the key in the first key table according to a preset replacement strategy;
[0136] Specifically, if the storage space of the first key table is not full, the virtual machine key and the corresponding virtual machine number are directly stored in the first key table;
[0137] If the storage space of the first key table is full, that is, the first key table has no storage space, then according to the preset replacement strategy, an item in the first key table is replaced with the virtual machine key to be stored.
[0138] In some embodiments, the preset replacement strategy includes at least one of the following: Least Recently Used (LRU), Least Frequently Used (LFU), First In First Out (FIFO), and random replacement strategy.
[0139] In some embodiments, when the second key table and the first key table are in a non-inclusion relationship, the replaced key in the first key table is written back to the second key table.
[0140] Specifically, the non-inclusive relationship between the second key table and the first key table means that the inclusion relationship between the first and second key tables is not maintained. That is, the virtual machine key of the same virtual machine can exist in either the first or second key table, or in both. In this case, a new virtual machine key is generated and stored in the first key table. The entry in the first key table is replaced and then written back to the second key table. The virtual machine key in the second key table is transferred to the first key table, and the virtual machine key in the second key table can be deleted or not.
[0141] In some embodiments, when the second key table and the first key table are in an inclusion relationship, generating the virtual machine key corresponding to the virtual machine further includes:
[0142] The generated virtual machine key corresponding to the virtual machine is stored in the second key table.
[0143] In some embodiments, when the second key table and the first key table are in a non-inclusion relationship, replacing the key in the first key table further includes:
[0144] Writing the replaced virtual machine key in the first key table back to the second key table;
[0145] Delete the virtual machine key corresponding to the virtual machine in the second key table.
[0146] Specifically, the first key table and the second key table can be maintained as inclusive. That is, the second key table includes the first key table, meaning that the virtual machine keys in the first key table have a backup in the second key table. In this case, newly generated virtual machine keys are stored in both the first and second key tables. The entries in the first key table are replaced without needing to be written back to the second key table. The virtual machine keys in the second key table are loaded into the first key table, without requiring deletion of the virtual machine keys in the second key table.
[0147] Alternatively, the first key table and the second key table can maintain an exclusive relationship. This means that the virtual machine key for the same virtual machine exists in only one of the first and second key tables, meaning the first and second key tables do not intersect. In this case, a new virtual machine key is generated and stored in the first key table. The entry in the first key table is replaced and written back to the second key table. The virtual machine key in the second key table is loaded into the first key table, and the virtual machine key in the second key table is deleted accordingly.
[0148] In some embodiments, the second key table is an encrypted key table, and the virtual machine key replaced in the first key table is written back to the second key table. This can be implemented in the following manner:
[0149] obtaining a target key from a key register in the processor;
[0150] The second key table is decrypted using the target key, and the replaced virtual machine key is written back to the decrypted second key table.
[0151] Specifically, as shown in Figure 2, when the virtual machine key is called out from the first key table to the second key table, when the virtual machine key is written to the memory, it is written to the memory area corresponding to the address of the second key table address register (the address is the storage address of the second key table). Before writing to the memory, the second key table needs to be decrypted, and the replaced virtual machine key is written back to the decrypted second key table. The decrypted target key is read from the key register of the second key table, and the second key table is encrypted after the write back is completed.
[0152] Specifically, as shown in Figure 2, when the virtual machine key is called out from the second key table to the first key table, the virtual machine key to be obtained is read from the memory area corresponding to the address of the address register of the second key table. When reading, the second key table needs to be decrypted first, for example, using the decryption module of the second key table of the memory controller to decrypt it, and then the virtual machine key is obtained and written into the first key table. The decrypted key is read from the key register of the second key table.
[0153] In some embodiments, the present disclosure can transfer the virtual machine key in use from the second key table outside the chip to the first key table in the memory controller. When the storage space of the first key table is full, the key that has not been used for a long time is placed in the second key table in the memory. When the life cycle of the virtual machine is over, the processor notifies the key table to delete the key.
[0154] In some embodiments, the address register of the second key table records the storage address of the virtual machine key in the memory. To protect the memory address space storing the virtual machine key, the data in the address space storing the virtual machine key can also be encrypted and protected. The address space of the second key table is only accessible by the key call-in and call-out modules. If the address space of the second key table is not accessed by the memory key call-in and call-out, such as a processor read request or write-back request accessing the address space of the second key table, the read request queue and write-back request queue of the memory controller will no longer send this request to the memory, but will instead report that the access address is invalid or illegal, and directly return an invalid or constant value, such as an all-zero value, for the read request. For the write-back request, no memory write is performed to protect the address space of the second key table.
[0155] In the above implementation, the data security is further improved by encrypting and protecting the keys in the second key table.
[0156] In some embodiments, when a virtual machine's lifecycle ends, the processor notifies the key generation and deletion module through a secure channel to delete the virtual machine key corresponding to the virtual machine. The key generation and deletion module deletes the virtual machine key in the first key table and the second key table through the key import and export module.
[0157] If the second key table and the first key table maintain an inclusive relationship (Inclusive) or do not maintain an inclusive relationship (Non-Inclusive), it is necessary to delete the virtual machine keys of the first key table and the second key table at the same time.
[0158] If the second key table and the first key table maintain an exclusive relationship, if the virtual machine key for the virtual machine exists in the first key table, after deleting the virtual machine key from the first key table, it will definitely not exist in the second key table, so there is no need to operate the second key table to delete the virtual machine key. If the virtual machine key for the virtual machine does not exist in the first key table, the virtual machine key for the virtual machine is deleted from the second key table.
[0159] In some embodiments, when the system is initialized, a random number generator generates a random number for generating a target key, which is stored in a key register of a second key table; a storage address of the second key table is allocated and stored in a second key table address register; the key register of the second key table and the second key table address register are not readable or writable.
[0160] In some embodiments, the processor further includes: a control register storing information about the number of the virtual machine being executed.
[0161] Specifically, processors supporting various instruction sets for virtualization have control registers (e.g., Control Status Registers (CSRs)) that store virtual machine ID information. For example, as shown in Figure 5, bits 44-57 of the hypervisor guest address translation and protection register (hgatp) in the fifth-generation reduced instruction set processor (RISC-V) control register are the virtual machine ID bits, or VMID bits, which store the ID of the executing virtual machine.
[0162] The following describes a virtual machine access device provided by an embodiment of the second aspect of the present disclosure. The virtual machine access device described below and the virtual machine access method described above can refer to each other.
[0163] FIG6 is a schematic diagram of the structure of a virtual machine access device provided by the present disclosure. As shown in FIG6, the virtual machine access device provided by this embodiment is applied to an electronic device, wherein the electronic device includes a processor and a memory, the processor stores a first key table, and the memory stores a second key table. The first key table and the second key table are used to store the correspondence between the virtual machine number and the virtual machine key. The virtual machine access device includes:
[0164] An acquisition module 610 is configured to acquire an access request from a virtual machine;
[0165] The processing module 620 is configured to determine, based on the virtual machine number corresponding to the access request, whether the first key table includes a virtual machine key corresponding to the virtual machine;
[0166] The processing module 620 is further configured to obtain the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request if the first key table does not include the virtual machine key corresponding to the virtual machine;
[0167] The processing module 620 is further configured to use the virtual machine key to encrypt or decrypt data corresponding to the access request.
[0168] In some embodiments, the processor includes at least one cache area, the access request is a read request, and the processing module 620 is further configured to:
[0169] Determining whether the virtual machine number corresponding to the access request is stored in the at least one cache area;
[0170] If the virtual machine number corresponding to the access request is stored in the cache, determining whether the data corresponding to the access request is stored in the cache;
[0171] If the data corresponding to the access request is stored in the cache area, reading the data corresponding to the access request;
[0172] If the virtual machine number corresponding to the access request or the data corresponding to the access request is not stored in the cache area, a step of determining whether the first key table includes a virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request is executed.
[0173] In some embodiments, each of the cache areas stores a correspondence between a virtual machine number allowed to be accessed and a tag corresponding to the address of the cache area; the processing module 620 is specifically configured to:
[0174] If the virtual machine number corresponding to the access request is stored in the cache area, and the access address corresponding to the access request matches the tag corresponding to the virtual machine number, it is determined whether the data corresponding to the access request is stored in the cache area.
[0175] In some embodiments, the second key table is an encrypted key table, and the processing module 620 is specifically configured to:
[0176] Obtaining a target key from a key register in the processor, and decrypting the second key table using the target key;
[0177] The virtual machine key corresponding to the virtual machine is obtained from the decrypted second key table.
[0178] In some embodiments, the processing module 620 is specifically configured to:
[0179] If the access request is a read request, obtaining memory data from the memory according to the memory address corresponding to the read request;
[0180] Decrypting the memory data using the virtual machine key; or,
[0181] If the access request is a write-back request, the write-back data corresponding to the write-back request is encrypted using the virtual machine key, and the encrypted data is written into the memory according to the memory address corresponding to the write-back request.
[0182] In some embodiments, the processing module 620 is further configured to:
[0183] If the second key table does not include the virtual machine key corresponding to the virtual machine, a virtual machine key corresponding to the virtual machine is generated, and the generated virtual machine key corresponding to the virtual machine is stored in the first key table.
[0184] In some embodiments, the processing module 620 is further configured to:
[0185] After obtaining the virtual machine key corresponding to the virtual machine from the second key table, the obtained virtual machine key corresponding to the virtual machine is stored in the first key table.
[0186] In some embodiments, the processing module 620 is specifically configured to:
[0187] If the storage space of the first key table is full, the generated virtual machine key corresponding to the virtual machine is used to replace the key in the first key table according to a preset replacement strategy;
[0188] According to a preset replacement strategy, the key in the first key table is replaced with the obtained virtual machine key corresponding to the virtual machine.
[0189] In some embodiments, when the second key table and the first key table are in a non-inclusion relationship, the processing module 620 is further configured to:
[0190] The replaced key in the first key table is written back to the second key table.
[0191] In some embodiments, the processing module 620 is further configured to: when the second key table and the first key table are in an inclusion relationship, store the generated virtual machine key corresponding to the virtual machine into the second key table.
[0192] In some embodiments, when the second key table and the first key table are in a non-inclusion relationship, the virtual machine key replaced in the first key table is written back to the second key table;
[0193] Delete the virtual machine key corresponding to the virtual machine in the second key table.
[0194] In some embodiments, the second key table is an encrypted key table, and the processing module 620 is specifically configured to:
[0195] obtaining a target key from a key register in the processor;
[0196] The second key table is decrypted using the target key, and the replaced virtual machine key is written back to the decrypted second key table.
[0197] In some embodiments, the processing module 620 is further configured to:
[0198] During initialization, generating a target key for encrypting and decrypting the second key table using a random number generator in the processor, and storing the target key in a key register in the processor;
[0199] During initialization, the storage address of the second key table in the memory is stored in an address register in the processor.
[0200] In some embodiments, the processing module 620 is further configured to:
[0201] Before determining, based on the virtual machine number corresponding to the access request, whether the first key table includes the virtual machine key corresponding to the virtual machine, determining whether the memory address corresponding to the access request belongs to the memory space where the second key table is located;
[0202] If so, a prompt message is output, where the prompt message is used to indicate that the accessed memory address is invalid or illegal.
[0203] In some embodiments, the preset replacement strategy includes at least one of the following: least recently used (LRU), least frequently used (LFU), first in first out (FIFO), and random replacement strategy.
[0204] In some embodiments, the processor further includes: a key generation and deletion module and a key import and export module, and the processing module 620 is further configured to:
[0205] When the life cycle of the virtual machine ends, the key generation and deletion module is used to delete the virtual machine keys in the first key table and the second key table through the key import and export module; the address space of the second key table is only accessible by the key import and export module.
[0206] The second aspect of the present disclosure provides an apparatus for executing a method in any of the aforementioned first aspect method embodiments. The implementation principle and technical effects thereof are similar and will not be described in detail here.
[0207] FIG7 shows a schematic diagram of the physical structure of an electronic device provided by an embodiment of the third aspect of the present disclosure. As shown in FIG7 , the electronic device may include: a processor 710, a communication interface 720, a memory 730, and a communication bus 740, wherein the processor 710, the communication interface 720, and the memory 730 communicate with each other via the communication bus 740. The processor 710 may call the logic instructions in the memory 730 to execute the virtual machine access method. The electronic device also includes a memory. The processor stores a first key table, and the memory stores a second key table. The first key table and the second key table are used to store the correspondence between the virtual machine number and the virtual machine key. The method includes:
[0208] Get access request to virtual machine;
[0209] Determining, according to the virtual machine number corresponding to the access request, whether the first key table includes a virtual machine key corresponding to the virtual machine;
[0210] If the first key table does not include the virtual machine key corresponding to the virtual machine, obtaining the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request;
[0211] The data corresponding to the access request is encrypted or decrypted using the virtual machine key.
[0212] In addition, the logic instructions in the above-mentioned memory 730 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0213] A fourth aspect of the present disclosure provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method for accessing a virtual machine according to any one of the embodiments of the first aspect is implemented, the method comprising: obtaining an access request of the virtual machine;
[0214] Determining, according to the virtual machine number corresponding to the access request, whether the first key table includes a virtual machine key corresponding to the virtual machine;
[0215] If the first key table does not include the virtual machine key corresponding to the virtual machine, obtaining the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request;
[0216] The data corresponding to the access request is encrypted or decrypted using the virtual machine key.
[0217] A fifth aspect of the present disclosure provides a computer program product, the computer program product including a computer program, which may be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the virtual machine access method provided in any one of the first aspects above, the method including: obtaining an access request for the virtual machine;
[0218] Determining, according to the virtual machine number corresponding to the access request, whether the first key table includes a virtual machine key corresponding to the virtual machine;
[0219] If the first key table does not include the virtual machine key corresponding to the virtual machine, obtaining the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request;
[0220] The data corresponding to the access request is encrypted or decrypted using the virtual machine key.
[0221] A sixth aspect of the present disclosure provides a computer program, including computer program code. When the computer program code is executed on a computer, the computer is caused to execute the virtual machine access method provided in any one of the first aspects above. The method includes: obtaining an access request of the virtual machine;
[0222] Determining, according to the virtual machine number corresponding to the access request, whether the first key table includes a virtual machine key corresponding to the virtual machine;
[0223] If the first key table does not include the virtual machine key corresponding to the virtual machine, obtaining the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request;
[0224] The data corresponding to the access request is encrypted or decrypted using the virtual machine key.
[0225] It should be noted that the explanations of the virtual machine access method and apparatus in the aforementioned embodiments are also applicable to the electronic device, readable storage medium, computer program product, and computer program in the embodiments of the present disclosure, and will not be repeated here.
[0226] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0227] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.
[0228] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than to limit them. Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present disclosure.
[0229] All embodiments of the present disclosure may be implemented individually or in combination with other embodiments, and are all considered to be within the scope of protection claimed by the present disclosure.
Claims
1. A virtual machine access method, applied to an electronic device, the electronic device including a processor and a memory, wherein the processor stores a first key table, and the memory stores a second key table, the first key table and the second key table being used to store the correspondence between virtual machine numbers and virtual machine keys. The method includes: Obtaining an access request for a virtual machine; Determining whether the first key table includes the virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request; If the first key table does not include the virtual machine key corresponding to the virtual machine, obtaining the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request; Encrypting or decrypting the data corresponding to the access request by using the virtual machine key, wherein the second key table is an encrypted key table, and the obtaining the virtual machine key corresponding to the virtual machine from the second key table includes: obtaining a target key from a key register in the processor, and decrypting the second key table by using the target key; and obtaining the virtual machine key corresponding to the virtual machine from the decrypted second key table.
2. The virtual machine access method according to claim 1, wherein the processor includes at least one buffer, the access request is a read request, and before determining whether the first key table includes the virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request, it further includes: Determining whether the virtual machine number corresponding to the access request is stored in the at least one buffer; If the virtual machine number corresponding to the access request is stored in the buffer, determining whether the data corresponding to the access request is stored in the buffer; If the data corresponding to the access request is stored in the buffer, reading the data corresponding to the access request; If the virtual machine number corresponding to the access request or the data corresponding to the access request is not stored in the buffer, performing the step of determining whether the first key table includes the virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request.
3. The virtual machine access method according to claim 2, wherein the correspondence relationship between the virtual machine numbers allowed to be accessed stored in each of the buffer areas and the tags corresponding to the addresses of the buffer areas is stored; if the virtual machine number corresponding to the access request is stored in the buffer area, determining whether the data corresponding to the access request is stored in the buffer area includes: If the virtual machine number corresponding to the access request is stored in the buffer, and the access address corresponding to the access request matches the label corresponding to the virtual machine number, determining whether the data corresponding to the access request is stored in the buffer.
4. The virtual machine access method according to any one of claims 1 to 3, wherein the encrypting or decrypting the data corresponding to the access request by using the virtual machine key includes: If the access request is a read request, obtaining memory data from the memory according to the memory address corresponding to the read request; Decrypting the memory data by using the virtual machine key; Or, If the access request is a write-back request, encrypting the write-back data corresponding to the write-back request by using the virtual machine key, and writing the encrypted data into the memory according to the memory address corresponding to the write-back request.
5. The virtual machine access method according to any one of claims 1 to 4, wherein the method further includes: If the second key table does not include the virtual machine key corresponding to the virtual machine, generate the virtual machine key corresponding to the virtual machine, and store the generated virtual machine key corresponding to the virtual machine in the first key table; After obtaining the virtual machine key corresponding to the virtual machine from the second key table, it further includes: Store the obtained virtual machine key corresponding to the virtual machine in the first key table.
6. The virtual machine access method according to claim 5, wherein storing the generated virtual machine key corresponding to the virtual machine in the first key table includes: If the storage space of the first key table is full, replace the key in the first key table with the generated virtual machine key corresponding to the virtual machine according to a preset replacement policy; Storing the obtained virtual machine key corresponding to the virtual machine in the first key table includes: Replace the key in the first key table with the obtained virtual machine key corresponding to the virtual machine according to a preset replacement policy.
7. The virtual machine access method according to claim 6, wherein in the case where the second key table and the first key table are not in an inclusion relationship, the method further includes: Write the replaced key in the first key table back to the second key table.
8. The virtual machine access method according to claim 6, wherein in the case where the second key table and the first key table are in an inclusion relationship, the method further includes: Store the generated virtual machine key corresponding to the virtual machine in the second key table.
9. The virtual machine access method according to claim 6, wherein in the case where the second key table and the first key table are not in an inclusion relationship, the method further includes: Write the replaced virtual machine key in the first key table back to the second key table; Delete the virtual machine key corresponding to the virtual machine in the second key table.
10. The virtual machine access method according to claim 7 or 9, wherein the second key table is an encrypted key table, and writing the replaced virtual machine key in the first key table back to the second key table includes: Obtain a target key from the key register in the processor; Use the target key to decrypt the second key table, and write the replaced virtual machine key back to The decrypted second key table.
11. The virtual machine access method according to any one of claims 1 to 10, wherein the method further includes: During initialization, use the random number generator in the processor to generate a target key for encrypting and decrypting the second key table, and store the target key in the key register in the processor; During initialization, store the storage address of the second key table in the memory in the address register in the processor.
12. The virtual machine access method according to any one of claims 1 to 11, wherein before determining whether the first key table includes the virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request, it further includes: Determine whether the memory address corresponding to the access request belongs to the memory space where the second key table is located; If so, a prompt message is output, wherein the prompt message is used to prompt that the accessed memory address is invalid or illegal.
13. The virtual machine access method according to any one of claims 6 to 9, wherein the preset replacement strategy comprises at least one of the following: least recently used (LRU), least frequently used (LFU), first in first out (FIFO), and random replacement strategy.
14. The virtual machine access method according to any one of claims 1 to 13, wherein the processor further comprises: A key generation and deletion module and a key import and export module, the method also includes: When the life cycle of the virtual machine ends, the key generation and deletion module is used to delete the virtual machine keys in the first key table and the second key table through the key import and export module; the address space of the second key table is only accessible by the key import and export module.
15. A virtual machine access device, applied to an electronic device, the electronic device comprising a processor and a memory, wherein the processor stores a first key table, the memory stores a second key table, the first key table and the second key table are used to store a correspondence between a virtual machine number and a virtual machine key, the device comprising: An acquisition module, used to obtain an access request of a virtual machine; A processing module, configured to determine whether the first key table includes a virtual machine key corresponding to the virtual machine according to the virtual machine number corresponding to the access request; The processing module is further configured to obtain the virtual machine key corresponding to the virtual machine from the second key table according to the virtual machine number corresponding to the access request if the first key table does not include the virtual machine key corresponding to the virtual machine; The processing module is further configured to encrypt or decrypt data corresponding to the access request using the virtual machine key. The second key table is an encrypted key table, and obtaining the virtual machine key corresponding to the virtual machine from the second key table includes: obtaining a target key from a key register in the processor, and decrypting the second key table using the target key; and obtaining the virtual machine key corresponding to the virtual machine from the decrypted second key table key.
16. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the virtual machine access method according to any one of claims 1 to 14 when executing the program.
17. A non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the virtual machine access method according to any one of claims 1 to 14 when executed by a processor.
18. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the virtual machine access method according to any one of claims 1 to 14.
19. A computer program, comprising computer program codes, which, when executed on a computer, enable the computer to execute the virtual machine access method according to any one of claims 1 to 14.
Citation Information
Patent Citations
Virtual magnetic disk file protecting method, device and equipment and readable storage medium
CN108133144A
Access processing method, virtual machine identifier configuration method, chip and computer equipment
CN116450281A
Virtual machine access method and equipment
CN117492932A
Seamless one-way access to protected memory using accessor key identifier
US20210006395A1