Method for executing operation on input / output device by confidential virtual machine, and computing device
By synchronizing I/O device status information between REE and TEE, conflict problems caused by confidential virtual machines cannot directly access I/O devices are solved, and the performance and security of computing devices are improved.
Patent Information
- Application Number
- PCT/CN2025/073451
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-26
- Filing Date
- 2025-01-20
- Publication Date
- 2025-07-31
AI Technical Summary
In computing devices, confidential virtual machines cannot directly access input/output devices, resulting in conflicts in I/O devices and ecological restrictions, affecting the migration of big data and AI applications.
By synchronizing the status information of the I/O device in the communication interface between the trusted execution environment TEE and the ordinary open environment REE, ensuring that the status in the REE and TEE is consistent and avoiding conflicts.
The synchronization of I/O device status information between REE and TEE is achieved, avoiding usage conflicts, and improving the performance and security of computing devices.
Smart Images

Figure CN2025073451_31072025_PF_FP_ABST
Abstract
Description
Method and computing device for confidential virtual machine to perform operations on input / output device
[0001] This application claims priority to the Chinese patent application with application number 202410117681.3 filed with the State Intellectual Property Office of China on January 26, 2024, and priority to the Chinese patent application entitled “Method and computing device for performing operations on input / output devices by a confidential virtual machine”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of computer technology, and in particular to a method for a confidential virtual machine to perform operations on an input / output device and a computing device. Background Art
[0003] To protect data in use, computing devices typically adopt a confidential computing architecture, which divides the computing resources on the computing device into a common open environment (rich execution environment, REE) and a trusted execution environment (trusted execution environment, TEE).
[0004] REEs provide a common operating system and application environment, allowing users to freely install and run a variety of applications. Furthermore, data in REEs can be used not only within the REE but also transmitted and shared through external interfaces of computing devices. Therefore, data computed in REEs may be vulnerable to threats such as malware, cyberattacks, and data leaks.
[0005] The TEE provides a hardware-level secure isolation environment. Users are not allowed to freely install and run various applications. Only verified and authorized applications can be installed and run within the TEE. Furthermore, data in the TEE can only be used within the TEE. Therefore, data computed within the TEE is not exposed to the REE and cannot be accessed by malware or attackers.
[0006] To ensure the high security of TEE, the confidential virtual machine (CVM) running in the TEE is not allowed to directly access I / O devices. This prevents all applications in the CVM that require access to I / O devices (such as big data applications and AI applications) from running directly in the TEE. This has created significant ecological constraints on the development of the TEE and is one of the core pain points in migrating big data and AI applications to TEE.
[0007] Furthermore, to ensure high security for the TEE, the CVM is not allowed to directly access the shared buffer in the REE. This shared buffer is used to store the I / O device usage of the virtual machine (VM) in the REE. Therefore, the CVM cannot know the I / O device usage of the VM in the REE.
[0008] If the CVM is allowed to directly access the I / O device, the VM and CVM will communicate with the I / O device independently, which will cause a conflict in the use of the I / O device. Summary of the Invention
[0009] To solve the above technical problems, the present application provides a method and computing device for a confidential virtual machine to perform operations on input / output devices, which can keep the status information of the I / O devices consistent in REE and TEE, avoiding conflicts in the use of I / O devices.
[0010] In a first aspect, a method for a confidential virtual machine to perform operations on an input / output device is provided, which is applied to a computing device, the computing device including a common open environment (REE) and a trusted execution environment (TEE). The hardware occupied by the computing resources of the REE is isolated from the hardware occupied by the computing resources of the TEE. The REE includes a first REE buffer. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM operates based on the computing resources of the TEE. The method includes:
[0011] The communication interface receives a first I / O request and synchronizes status information of the first I / O device in the first TEE buffer and status information of the first I / O device in the first REE buffer. The first I / O request is used to instruct the first CVM to perform a first I / O operation on the first I / O device. The status information of the first I / O device is used to indicate whether the status of the first I / O device is idle or occupied.
[0012] The first CVM performs an operation on the first I / O device according to the state information of the first I / O device in the synchronized first TEE buffer, wherein the state information of the first I / O device in the synchronized first TEE buffer is used to indicate the current state of the first I / O device.
[0013] In the above scheme, when the first CVM in the TEE needs to establish a communication connection with the first I / O device to complete the first I / O request, the communication interface in the TEE is used to synchronize the status information of the first I / O device in the first REE buffer with the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first REE buffer and the first TEE are the same, achieving the effect of maintaining consistency of the status information of the first I / O device in the REE and TEE. Therefore, the first CVM performs operations on the first I / O device based on the current status of the first I / O device. For example, if the current status of the first I / O device is idle, the first CVM immediately uses the first I / O device; if the current status of the first I / O device is occupied, the first CVM waits for the first I / O device. This can avoid conflicts with the use of the first I / O device by the VM in the REE.
[0014] In some possible implementations, the REE further includes a shadow buffer for storing status information of the first I / O device, wherein the status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device. The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, including: the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0015] In the above scheme, since the status information of the first I / O device stored in the shadow buffer is used to indicate the current status of the first I / O device, the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, so that the status information of the first I / O device in the synchronized first TEE buffer can also be used to indicate the current status of the first I / O device, and the status information of the first I / O device in the synchronized first REE buffer can also be used to indicate the current status of the first I / O device.
[0016] In some possible implementations, the REE further includes a first VM, which runs based on computing resources of the REE.
[0017] Before the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, the method further includes: when the modification time of the status information of the first I / O device in the first REE buffer of the first VM is later than the modification time of the status information of the first I / O device in the first TEE buffer, writing the status information of the first I / O device in the first REE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer.
[0018] The communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, including: the communication interface writes the status information of the first I / O device in the shadow buffer to the first TEE buffer to obtain the synchronized status information of the first I / O device in the first TEE buffer. The communication interface has higher operating authority over the shadow buffer than the first VM has over the shadow buffer.
[0019] In some possible implementations, the REE further includes a control module.
[0020] The above-mentioned communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, including: when the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, the communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer.
[0021] The method further includes: the control module writing the status information of the first I / O device in the shadow buffer into the first REE buffer to obtain the status information of the first I / O device in the synchronized first REE buffer. The status information of the first I / O device in the synchronized first REE buffer indicates the current status of the first I / O device.
[0022] In the above scheme, when the usage of the first I / O device by the first CVM in the TEE (that is, the status information of the first I / O device) is shared with the first VM in the REE, the communication interface first writes the status information of the first I / O device in the first TEE buffer into the shadow buffer in the REE. When the first REE buffer is not operated, the control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer. This can avoid conflicts in operations on the first REE buffer caused by the operation authority of the communication interface in the TEE being higher than the operation authority of the first VM in the REE, thereby preventing the occurrence of data confusion in the first REE buffer, and is conducive to improving the stability of sharing the status information of the first I / O device between the REE and the TEE.
[0023] Furthermore, the communication interface only needs to write the status information of the I / O device in the TEE to the shadow buffer in the REE, or read the status information of the I / O device in the REE from the shadow buffer in the REE, without having to dynamically adjust the operation object based on the access relationship of the VM in the REE to the I / O device. This operation is simple and reliable, and also reduces the risk of inconsistent or lost I / O device status information.
[0024] In some possible implementations, the communication interface has higher permissions to operate the shadow buffer than the first VM, including at least the following two implementations: In a first implementation, if the communication interface operates the shadow buffer, access by the first VM is denied. In a second implementation, if the first VM operates the shadow buffer, access by the communication interface is permitted.
[0025] In some possible implementations, the TEE further includes a second CVM and a second TEE buffer, the REE further includes a second REE buffer, and the second CVM runs based on the computing resources of the TEE. The method further includes:
[0026] The communication interface receives a second I / O request and synchronizes the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer. The second I / O request is used to instruct the second CVM to perform a second I / O operation on the second I / O device. The status information of the second I / O device is used to indicate whether the status of the second I / O device is idle or occupied.
[0027] The second CVM performs an operation on the second I / O device based on the status information of the second I / O device in the synchronized second TEE buffer, wherein the status information of the second I / O device in the synchronized second TEE buffer is used to indicate the current status of the second I / O device.
[0028] In the above scheme, in the process of sharing the status information of the I / O device between the CVM in the TEE and the VM in the REE, the status information of the I / O device from the TEE is always transmitted to the REE through the same communication interface, or the status information of the I / O device from the REE is always transmitted to the TEE through the same communication interface. Using only one communication interface in the TEE to transmit the status information of the I / O device can reduce the complexity of the technical solution, simplify the development process, and save the computing resources and hardware of the TEE. More importantly, compared to using multiple communication interfaces, which makes each communication interface a target of attack by unsafe devices, the technical solution uses only one communication interface, which can reduce the attack surface and potential security vulnerabilities and reduce the threats to the TEE. In addition, since the communication interface transmits the status information of the I / O device, the security and privacy of the data calculated in the TEE can still be guaranteed.
[0029] In a second aspect, a computing device is provided, comprising a common open environment (REE) and a trusted execution environment (TEE). The hardware used by the REE's computing resources is isolated from the hardware used by the TEE's computing resources. The REE includes a first REE buffer. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM operates based on the TEE's computing resources.
[0030] The communication interface is configured to receive a first I / O request, wherein the first I / O request is configured to instruct the first CVM to perform a first I / O operation on the first I / O device.
[0031] The communication interface is further used to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, wherein the status information of the first I / O device is used to indicate whether the status of the first I / O device is idle or occupied.
[0032] The first CVM is configured to perform an operation on the first I / O device based on the status information of the first I / O device in the synchronized first TEE buffer, wherein the status information of the first I / O device in the synchronized first TEE buffer is used to indicate the current status of the first I / O device.
[0033] In some possible implementations, the REE further includes a shadow buffer. The shadow buffer is used to store status information of the first I / O device. The status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device.
[0034] The above-mentioned communication interface is specifically used to use the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0035] In some possible implementations, the REE further includes a first VM. The first VM runs based on computing resources of the REE.
[0036] The above-mentioned first VM is used to write the status information of the first I / O device in the first REE buffer into the shadow buffer before the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, if the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device is stored in the shadow buffer.
[0037] The above-mentioned communication interface is specifically used to write the status information of the first I / O device in the shadow buffer into the first TEE buffer, and obtain the status information of the first I / O device in the synchronized first TEE buffer.
[0038] The operation authority of the communication interface on the shadow buffer is higher than the operation authority of the first VM on the shadow buffer.
[0039] In some possible implementations, the REE further includes a control module.
[0040] The above-mentioned communication interface is specifically used to write the status information of the first I / O device in the first TEE buffer into the above-mentioned shadow buffer when the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device is stored in the shadow buffer.
[0041] The control module is configured to write the status information of the first I / O device in the shadow buffer into the first REE buffer, thereby obtaining the status information of the first I / O device in the synchronized first REE buffer. The status information of the first I / O device in the synchronized first REE buffer indicates the current status of the first I / O device.
[0042] In some possible implementations, the shadow buffer denies access by the first VM when operated by the communication interface; or, the shadow buffer allows access by the communication interface when operated by the first VM.
[0043] In some possible implementations, the TEE further includes a second CVM and a second TEE buffer. The second CVM runs based on the computing resources of the TEE. The REE further includes a second REE buffer.
[0044] The communication interface is further configured to receive a second I / O request, wherein the second I / O request is configured to instruct the second CVM to perform a second I / O operation on the second I / O device.
[0045] The communication interface is further used to synchronize the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer. The status information of the second I / O device is used to indicate whether the status of the second I / O device is idle or occupied.
[0046] The second CVM is configured to perform an operation on the second I / O device based on the status information of the second I / O device in the synchronized second TEE buffer, wherein the status information of the second I / O device in the synchronized second TEE buffer is used to indicate the current status of the second I / O device.
[0047] In a third aspect, a computing device is provided, comprising a processor and a memory, wherein the memory is used to store instructions, and the processor is used to execute the instructions. When the processor executes the instructions, the method of any one of the first aspects is implemented.
[0048] In a fourth aspect, a computer program product comprising instructions is provided, which, when executed by a computing device, causes the computing device to perform any method as described in the first aspect.
[0049] In a fifth aspect, a computer-readable storage medium is provided, characterized in that it includes computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method as described in any one of the first aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] FIG1 is an architecture diagram of a computing device provided in an embodiment of the present application;
[0051] FIG2 is a flow chart of a method for a CVM to perform an operation on an I / O device provided in an embodiment of the present application;
[0052] FIG3 is a flow chart of another method for a CVM to perform an operation on an I / O device provided in an embodiment of the present application;
[0053] FIG4 is an architecture diagram of another computing device provided in an embodiment of the present application;
[0054] FIG5 is a flow chart of another method for a CVM to perform an operation on an I / O device provided in an embodiment of the present application;
[0055] FIG6 is a flow chart of another method for a CVM to perform an operation on an I / O device provided in an embodiment of the present application;
[0056] FIG7 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0057] The following will describe the technical solutions in the embodiments of this application in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0058] In order to solve the problem that the use of I / O devices by the VM in the REE on the current computing device conflicts with the use of I / O devices by the CVM in the TEE, the present application provides two computing devices. The first computing device and the second computing device can both share the information of the use of I / O devices by the VM in the REE to the CVM in the TEE through the communication interface in the TEE, and share the information of the use of I / O devices by the CVM in the TEE to the VM in the REE, so that the status information of the I / O devices is consistent in the REE and TEE, thereby avoiding conflicts in the use of I / O devices. Among them,
[0059] The first computing device can be seen in Figure 1 and the related description. Furthermore, the method for performing operations on I / O devices using a CVM based on the computing device in Figure 1 can be seen in Figures 2 and 3 and the related description. This CVM method for performing operations on I / O devices can improve the speed of sharing I / O device status information between the REE and the TEE.
[0060] The second computing device can be seen in Figure 4 and the related description. Furthermore, the method for performing operations on I / O devices using the CVM implemented based on the computing device in Figure 4 can be seen in Figures 5 and 6 and the related description. This method can improve the stability of I / O device status information shared between the REE and TEE.
[0061] The following describes how the two computing devices and their corresponding CVMs perform operations on I / O devices.
[0062] 1. Method for a first computing device and its corresponding CVM to perform operations on an I / O device
[0063] Referring to Figure 1, Figure 1 is an architecture diagram of a computing device provided in an embodiment of the present application. As shown in Figure 1, the architecture includes a computing device 10 and an I / O device 11. The computing device 10 and the I / O device 11 can communicate with each other.
[0064] The computing device 10 refers to an electronic device capable of performing calculations, processing, and storing data, such as a server, supercomputer, personal computer, workstation, mobile device, etc. The computing device 10 includes multiple physical components (i.e., hardware), specifically including: a motherboard, a processor (such as a CPU, GPU), a memory module, a hard disk drive, etc. The computing device 10 can perform various computing tasks, such as mathematical operations, logical operations, data processing and storage, etc., based on the computing resources and storage resources provided by the hardware. Among them, computing resources refer to the hardware and software used in the computing device 10 to perform computing tasks, including: a central processing unit (CPU), a graphics processing unit (GPU), software frameworks and libraries (such as an operating system, programming language, algorithm library), etc. Storage resources refer to the hardware and software used in the computing device 10 to store data and programs, including internal memory (such as memory), external memory (such as hard disk, solid-state drive, optical disk, USB flash drive), etc.
[0065] I / O devices 11 refer to devices used to interact with the outside of computing device 10, such as keyboards, mice, monitors, printers, scanners, cameras, audio devices (such as speakers, headphones, and microphones), disk drives (such as hard disk drives and solid-state drives), optical disk drives (such as CD-ROMs and DVD-ROMs), USB devices (such as USB flash drives and external hard disk drives), network adapters, touch screens, expansion cards (such as graphics processors, sound cards, and network cards), sensors (such as temperature sensors, pressure sensors, and accelerometers), etc. I / O devices 11 are responsible for receiving input information from users or other devices and delivering output information processed by computing device 10 to users or other devices.
[0066] The architecture of the computing device shown in FIG1 is illustrated by taking the computing device 10 having two I / O devices as an example. In actual applications, the number of I / O devices 11 communicating with the computing device 10 may be less or more, and may be various types of I / O devices, which are not specifically limited here.
[0067] The communication process between the computing device 10 and the I / O device 11 can be divided into the following two stages:
[0068] (1) Input stage
[0069] I / O device 11 receives input information (such as images, text, and sound) from a user or other devices. It then converts the received input information into an input signal and sends the input signal to computing device 10. After receiving the input signal, computing device 10 transmits the input signal to an application or processor within computing device 10, which then performs the corresponding I / O operation (such as displaying the input text, moving the cursor, or executing a command) based on the received input signal.
[0070] (2) Output stage
[0071] An application or processor in computing device 10 generates output information (e.g., images, text, sounds) and transmits the output information to computing device 10. Computing device 10 then converts the received output information into an output signal and sends the output signal to I / O device 11. I / O device 11 performs corresponding I / O operations (e.g., displaying text, playing video, printing data) based on the received output signal.
[0072] The communication connection between the computing device 10 and the I / O device 11 may be a wired connection or a wireless connection, which is not specifically limited in this application.
[0073] In some possible implementations, computing device 10 includes a common open environment (REE) 110 and a trusted execution environment (TEE) 120. The hardware used for computing resources in common open environment REE 110 (i.e., hardware 130 in FIG. 1 ) is isolated from the hardware used for computing resources in trusted execution environment (TEE) 120 (i.e., hardware 140 in FIG. 1 ). The common open environment REE 110 and the trusted execution environment (TEE) 120 are described separately below.
[0074] (1) Ordinary open environment REE 110
[0075] The common open environment REE 110 includes a first VM 111, a first REE buffer 112, a second VM 113, and a second REE buffer 114. The functions of these components are described below.
[0076] (1) First VM 111
[0077] First VM 111 is a complete computer system implemented using network functions virtualization (NFV) technology, emulating complete hardware system functions through software and running in a completely isolated environment. Because first VM 111 is implemented using NFV technology, its security protection mechanisms and hardware support are relatively weak. Therefore, the security level of first VM 111 is relatively low, and the protection of sensitive data and critical programs is relatively weak. However, first VM 111 is highly flexible and can run a variety of applications and operating systems.
[0078] The first VM 111 can transmit data in the first VM 111 to the outside of the computing device 10 through the I / O device 11, and receive data from the outside of the computing device 10. The first VM 111 is allowed to access all I / O devices 11 in the computing device 10, or is allowed to access only some of the I / O devices 11 in the computing device 10, or is not allowed to access the I / O devices 11 in the computing device 10, which is not specifically limited here.
[0079] (2) First REE buffer zone 112
[0080] The first REE buffer 112 can be set in the internal memory and / or external memory allocated by the computing device 10 for the general open environment REE 110, and is used to store the status information of the I / O devices 11 that the first VM 111 is allowed to access. The status information of the I / O device 11 is used to indicate whether the status of the I / O device 11 is idle or occupied. For example, if the first VM 111 is only allowed to access one of the I / O devices 11 in Figure 1, the first REE buffer 112 will store the status information of this I / O device 11, and will not store the status information of other I / O devices 11.
[0081] The first REE buffer 112 can be implemented in software or hardware. As an example of a software implementation, the first REE buffer 112 can be implemented by code running on a computing instance of the common open environment REE 110. The computing instance can be a confidential virtual machine and / or container. As an example of a hardware implementation, the first REE buffer 112 can be implemented by hardware such as a memory chip or cache chip allocated by the computing device 10 to the common open environment REE 110.
[0082] (3) Second VM 113
[0083] Second VM 113 is a complete computer system implemented using NFV technology, emulated through software and possessing complete hardware system functionality, running in a completely isolated environment. Because Second VM 113 is implemented using NFV technology, its security protection mechanisms and hardware support are relatively weak. Therefore, Second VM 113 has a relatively low security level, providing less protection for sensitive data and critical programs. However, Second VM 113 offers significant flexibility and can run a variety of applications and operating systems.
[0084] The second VM 113 can transmit data in the second VM 113 to the outside of the computing device 10 through the I / O devices 11, and receive data from the outside of the computing device 10. The second VM 113 is allowed to access all I / O devices 11 in the computing device 10, or is allowed to access only some of the I / O devices 11 in the computing device 10, or is not allowed to access the I / O devices 11 in the computing device 10, which is not specifically limited here.
[0085] Second VM 113 and first VM 111 share the hardware allocated by computing device 10 for common open environment REE 110. Furthermore, second VM 113 and first VM 111 can communicate over a network. However, second VM 113 and first VM 111 can independently configure and manage their own computing resources, storage resources, and network resources, independently run their own applications and operating systems, and ensure that their own operations and data do not affect the operation of the other VM.
[0086] (4) Second REE buffer zone 114
[0087] The second REE buffer 114 can be set in the internal memory and / or external memory allocated by the computing device 10 for the common open environment REE 110, and is used to store the status information of the I / O devices 11 that the second VM 113 is allowed to access. The status information of the I / O device 11 is used to indicate whether the I / O device 11 is in an idle state or an occupied state. For example, if the second VM 113 is only allowed to access one of the I / O devices 11 in Figure 1, the second REE buffer 114 will store the status information of that I / O device 11, and will not store the status information of other I / O devices 11.
[0088] The second REE buffer 114 can be implemented by software or hardware. The implementation of the second REE buffer 114 is similar to the implementation of the first REE buffer 112 in (2) above. For the sake of brevity, it will not be further described here.
[0089] In some possible implementations, the first VM 111 may also perform operations on other REE buffers, or the second VM 113 may also perform operations on other REE buffers. Specifically, if the I / O device 11 that the first VM 111 is allowed to access is the same as the I / O device 11 that the second VM 113 is allowed to access, the first REE buffer 112 and the second REE buffer 114 store the same state information of the I / O device 11. Therefore, if the first VM 111 changes the state of the same I / O device 11, the first VM 111 writes the new state information of the same I / O device 11 to the first REE buffer 112 and the second REE buffer 114; if the second VM 113 changes the state of the same I / O device 11, the second VM 113 writes the new state information of the same I / O device 11 to the first REE buffer 112 and the second REE buffer 114.
[0090] It should be understood that (1) the first VM 111 to (4) the second REE buffer 114 in the above-mentioned (1) ordinary open environment REE 110 are explained by taking the ordinary open environment REE 110 as an example including two VMs and two REE buffers. In actual applications, the number of VMs and REE buffers can be one or more, and this application does not make specific limitations.
[0091] (2) Trusted Execution Environment TEE 120
[0092] The trusted execution environment TEE 120 further includes a first CVM 121, a first TEE buffer 122, a second CVM 123, a second TEE buffer 124, and a communication interface 125. The functions of these components are described below.
[0093] (1) First CVM 121
[0094] The first CVM 121 is a complete computer system implemented using secure encrypted virtualization (SEV) technology, simulated through software, and running in a completely isolated environment with complete hardware system functions. Because the first CVM 121 is implemented using SEV technology, its security protection mechanism and hardware support are relatively strong. Therefore, the security level of the first CVM 121 is relatively high, and the protection of sensitive data and critical programs is relatively strong. However, the first CVM 121 has greater restrictions and can only run verified and authorized applications and operating systems, and is strictly monitored by the Trusted Execution Environment TEE 120.
[0095] First CVM 121 can transmit data in first CVM 121 to the outside of computing device 10 through I / O devices 11, and receive data from the outside of computing device 10. First CVM 121 can allow access to all I / O devices 11 in computing device 10, or can only allow access to some I / O devices 11 in computing device 10, or can not allow access to I / O devices 11 in computing device 10, without specific limitation herein.
[0096] (2) First TEE buffer 122
[0097] The first TEE buffer 122 can be set in the internal memory and / or external memory allocated by the computing device 10 for the trusted execution environment TEE 120, and is used to store the status information of the I / O devices 11 that the first CVM 121 is allowed to access. The status information of the I / O device 11 is used to indicate whether the status of the I / O device 11 is idle or occupied. For example, if the first CVM 121 is only allowed to access one of the I / O devices 11 in Figure 1, the first TEE buffer 122 stores the status information of the I / O device 11, and does not store the status information of other I / O devices 11.
[0098] The first TEE buffer 122 can be implemented by software or hardware. As an example of software implementation, the first TEE buffer 122 can be implemented by code running on a computing instance of the trusted execution environment TEE 120. The computing instance can be a confidential virtual machine and / or container. As an example of hardware implementation, the first TEE buffer 122 can be implemented by hardware such as a memory chip, a cache chip, etc. allocated by the computing device 10 to the trusted execution environment TEE 120.
[0099] (3) Second CVM 123
[0100] The second CVM 123 is a complete computer system implemented using SEV technology, emulating the full hardware system functionality through software and running in a completely isolated environment. Because the second CVM 123 is implemented using SEV technology, its security protection mechanisms and hardware support are relatively strong. Therefore, the second CVM 123 has a relatively high security level, providing greater protection for sensitive data and critical programs. However, the second CVM 123 is more restrictive, running only authenticated and authorized applications and operating systems, and is strictly monitored by the Trusted Execution Environment (TEE) 120.
[0101] Second CVM 123 can transmit data in second CVM 123 to the outside of computing device 10 through I / O devices 11, and receive data from the outside of computing device 10. Second CVM 123 can allow access to all I / O devices 11 in computing device 10, or only allow access to some I / O devices 11 in computing device 10, or not allow access to any I / O devices 11 in computing device 10, without specific limitation herein.
[0102] Second CVM 123 and first CVM 121 share the hardware allocated by computing device 10 for Trusted Execution Environment (TEE) 120. Furthermore, second CVM 123 and first CVM 121 can communicate over a network. However, second CVM 123 and first CVM 121 can independently configure and manage their own computing, storage, and network resources, independently run their own applications and operating systems, and ensure that their own operations and data do not affect the operation of the other CVM.
[0103] (4) Second TEE buffer 124
[0104] The second TEE buffer 124 can be set in the internal memory and / or external memory allocated by the computing device 10 for the trusted execution environment TEE 120, and is used to store the status information of the I / O devices 11 that the second CVM 123 is allowed to access. The status information of the I / O device 11 is used to indicate whether the status of the I / O device 11 is idle or occupied. For example, if the second CVM 123 is only allowed to access one of the I / O devices 11 in Figure 1, the second TEE buffer 124 will store the status information of the I / O device 11, and will not store the status information of other I / O devices 11.
[0105] The second TEE buffer 124 can be implemented by software or hardware. The implementation of the second TEE buffer 124 is similar to the implementation of the first TEE buffer 122 in (2) above. For the sake of brevity, it will not be further described here.
[0106] (5) Communication interface 125
[0107] The communication interface 125 is used to transmit the status information of the I / O device 11 between the common open environment REE 110 and the trusted execution environment TEE 120. Specifically, the communication interface 125 can be used to transmit the status information of the I / O device 11 stored in the REE buffer in the common open environment REE 110 to the TEE buffer in the trusted execution environment TEE 120, and can also be used to transmit the status information of the I / O device 11 stored in the TEE buffer in the trusted execution environment TEE 120 to the REE buffer in the common open environment REE 110.
[0108] For example, in Figure 1, the communication interface 125 can be used to transmit the status information of the I / O device 11 in the first REE buffer 112 and / or the second REE buffer 114 to the first TEE buffer 122 and / or the second TEE buffer 124; it can also be used to transmit the status information of the I / O device 11 in the first TEE buffer 122 and / or the second TEE buffer 124 to the first REE buffer 112 and / or the second REE buffer 114.
[0109] In some possible implementations, the communication interface 125 is specifically used to transmit status information of the I / O device 11 between the common open environment REE 110 and the trusted execution environment TEE 120 only when the CVM in the trusted execution environment TEE 120 has an operation requirement for the I / O device 11.
[0110] Since the common open environment REE 110 provides a common operating system and application environment and allows users to freely install and run various applications, the VM in the common open environment REE 110 has a large demand for operating the I / O device 11 when running various applications and operating systems. This causes the status information of the I / O device 11 in the REE buffer to change frequently, and thus the modification time of the status information of the I / O device 11 in the REE buffer is also frequently updated.
[0111] The Trusted Execution Environment TEE 120 provides a hardware-level secure isolation environment and does not allow users to freely install and run various applications. Therefore, when the CVM in the Trusted Execution Environment TEE 120 runs a few verified and authorized applications and operating systems, the operation requirements of the I / O device 11 are small, so that the status information of the I / O device 11 in the TEE buffer is occasionally changed, and the modification time of the status information of the I / O device 11 in the TEE buffer is also occasionally updated.
[0112] In the case where the VM in the common open environment REE 110 has a large operation requirement for the I / O device 11, while the CVM in the trusted execution environment TEE 120 has a small operation requirement for the I / O device 11, the communication interface 125 transmits the status information of the I / O device 11 between the common open environment REE 110 and the trusted execution environment TEE 120 according to the requirements of the CVM, which can improve the utilization rate of the communication interface 125, reduce the number of transmissions of status information, and reduce the load on the computing device 10.
[0113] The communication interface 125 can be implemented by software, hardware, or a combination of software and hardware. As an example of software implementation, the communication interface 125 can be implemented by code running on a computing instance of the trusted execution environment TEE 120. The computing instance can be a confidential virtual machine and / or container. As an example of hardware implementation, the communication interface 125 can be implemented by hardware such as a serial port interface and an Ethernet interface allocated by the computing device 10 to the trusted execution environment TEE 120. As an example of implementation in a combination of software and hardware, the communication interface 125 can be implemented by controlling the hardware allocated by the computing device 10 to the trusted execution environment TEE 120 by code running on a computing instance of the trusted execution environment TEE 120.
[0114] It should be understood that (1) the first CVM 121 to (5) the communication interface 125 in the above-mentioned (2) trusted execution environment TEE 120 are explained by taking the example of two CVMs and two TEE buffers in the trusted execution environment TEE 120. In actual applications, the number of CVMs and TEE buffers can be one or more, and this application does not make specific limitations.
[0115] It should be understood that the above-mentioned (1) ordinary open environment REE 110 to (2) trusted execution environment TEE 120 are explained by taking the computing device 10 of Figure 1 as an example including one REE and one TEE. In actual applications, the number of REEs and TEEs can be one or more, and this application does not make specific limitations.
[0116] Based on the architecture of the computing device in Figure 1 above, the following describes in detail the method for the CVM to perform operations on I / O devices provided in an embodiment of the present application. The method for the CVM to perform operations on I / O devices can keep the status information of the I / O devices consistent in the REE and TEE, avoiding conflicts in the use of I / O devices. To achieve consistency in the status information of the I / O devices in the REE and TEE, it includes: sharing the information about the use of I / O devices by the VM in the REE with the CVM in the TEE, and sharing the information about the use of I / O devices by the CVM in the TEE with the VM in the REE.
[0117] See Figure 2, which is a flow chart of a method for a CVM to perform operations on an I / O device, provided in an embodiment of the present application. This method for a CVM to perform operations on an I / O device can improve the speed at which I / O device status information is shared between the REE and the TEE. As shown in Figure 2, the method for a CVM to perform operations on an I / O device in an embodiment of the present application includes:
[0118] S201: A first CVM or a first I / O device sends a first I / O request to a communication interface. Correspondingly, the communication interface receives the first I / O request from the first CVM or the first I / O device.
[0119] The first I / O request is used to instruct the first CVM to perform a first I / O operation on the first I / O device. The first I / O operation includes reading data from the first I / O device and transmitting the data to an application or virtual processor in the first CVM, as well as sending data from the application or virtual processor in the first CVM to the first I / O device. The virtual processor in the first CVM is the processor occupied by the first CVM in the TEE.
[0120] The first CVM may be the first CVM 121 in the computing device 10 in Figure 1 . The first I / O device may be one of the I / O devices 11 in Figure 1 . The communication interface may be the communication interface 125 in the computing device 10 in Figure 1 .
[0121] S202: The communication interface determines whether a modification time of the status information of the first I / O device in the first REE buffer is later than a modification time of the status information of the first I / O device in the first TEE buffer.
[0122] The modification time of the status information of the first I / O device may be part of the metadata of the status information of the first I / O device. Metadata is data that describes the status information, including the creation time, access rights, storage location, etc. of the status information. The metadata is stored in the operating system or file system. Specifically, the modification time of the status information of the first I / O device in the first REE buffer is stored in the operating system or file system in the REE. The modification time of the status information of the first I / O device in the first TEE buffer is stored in the operating system or file system in the TEE.
[0123] Therefore, the communication interface can obtain the modification time of the status information of the first I / O device in the first REE buffer from the metadata of the REE's operating system or the metadata of the file system, and obtain the modification time of the status information of the first I / O device in the first TEE buffer from the metadata of the TEE's operating system or the metadata of the file system.
[0124] Subsequently, the communication interface compares the modification time of the status information of the first I / O device in the first REE buffer with the modification time of the status information of the first I / O device in the first TEE buffer to determine the storage location of the status information indicating the current status of the first I / O device. This mainly includes the following two situations:
[0125] Case 1: The modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the first REE buffer is new, and the status information of the first I / O device in the first TEE buffer is old. Therefore, the status information of the first I / O device stored in the first REE buffer indicates the current status of the first I / O device.
[0126] Case 2: The modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the first REE buffer is old, and the status information of the first I / O device in the first TEE buffer is new. Therefore, the status information of the first I / O device stored in the first TEE buffer indicates the current status of the first I / O device.
[0127] The first REE buffer may be the first REE buffer 112 in the computing device 10 in FIG1 . The first TEE buffer may be the first TEE buffer 122 in the computing device 10 in FIG1 .
[0128] In case 1 of step S202 above, go to S203; in case 2 of step S202 above, go to S207.
[0129] S203: The communication interface reads the status information of the first I / O device from the first REE buffer.
[0130] Since the first REE buffer is set in the REE, and the data in the REE can not only be used within the REE but also be shared with the TEE, the communication interface in the TEE can read the status information of the first I / O device from the first REE buffer.
[0131] S204: The communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby achieving synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0132] In some possible implementations, the communication interface may write the status information of the first I / O device in the first REE buffer into the first TEE buffer by using overwrite write, append write, insert write, or the like.
[0133] In a specific implementation, the communication interface adopts overwrite writing. Specifically, the communication interface writes the status information of the first I / O device in the first REE buffer to the location where the status information of the first I / O device is stored in the first TEE buffer, overwriting the original status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer.
[0134] In another specific implementation, the communication interface uses append write. Specifically, the communication interface writes the status information of the first I / O device in the first REE buffer to the tail address of the first TEE buffer, so that the tail address of the first TEE buffer stores the status information of the first I / O device from the first REE buffer. By only reading the status information of the first I / O device at the tail address, the status information of the first I / O device in the first REE buffer is replaced with the status information of the first I / O device in the first TEE buffer.
[0135] In another specific implementation, the communication interface uses an insert write method. Specifically, the communication interface writes the status information of the first I / O device in the first REE buffer to a specified location in the first TEE buffer. By only reading the status information of the first I / O device at the specified location, the status information of the first I / O device in the first REE buffer replaces the status information of the first I / O device in the first TEE buffer.
[0136] It should be understood that the above-mentioned overwrite writing, append writing, and insert writing are only used as examples and are not specifically limited here. In actual applications, any method that can enable the communication interface to write the status information of the first I / O device in the first REE buffer to the first TEE buffer is within the scope of protection of this application.
[0137] S205: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0138] In some possible implementations, the first CVM reads the status information of the first I / O device from the first TEE buffer to obtain the current status of the first I / O device, which mainly includes the following two situations:
[0139] Case 1: The current state of the first I / O device is idle;
[0140] Case 2: The current state of the first I / O device is occupied.
[0141] In some possible implementations, different values may be used to represent different states of the first I / O device, that is, different values may be used to correspond to different situations in step S205. Situation 1 of step S205 may be represented by a first value, and situation 2 of step S205 may be represented by a second value. For example, if the first value is 0, it indicates that the current state of the first I / O device is idle; if the second value is 1, it indicates that the current state of the first I / O device is occupied. Alternatively, if the first value is A, it indicates that the current state of the first I / O device is idle; if the second value is B, it indicates that the current state of the first I / O device is occupied.
[0142] In some possible implementations, before the first CVM reads the status information of the first I / O device from the first TEE buffer, triggering the first CVM to read the first TEE buffer includes at least the following two implementations:
[0143] In a specific implementation, the first CVM receives a first notification from the communication interface. The first notification is used to instruct the first CVM to read status information of the first I / O device from a specified location in the first TEE buffer.
[0144] In another specific implementation, the first CVM monitors the first TEE buffer so that after the communication interface writes the status information of the first I / O device in the first REE buffer to the first TEE buffer, the first CVM can read the status information of the first I / O device from the first TEE buffer in a timely manner.
[0145] It should be understood that the above-mentioned implementation method of triggering the first CVM to read the first TEE buffer is only an example and is not specifically limited here. In actual applications, any implementation method that can trigger the first CVM to read the first TEE buffer is within the scope of protection of this application.
[0146] S206: The first CVM performs an operation on the first I / O device according to the status information of the first I / O device.
[0147] In some possible implementations, the operations performed by the first CVM based on the status information of the first I / O device include at least the following two:
[0148] In the first operation, corresponding to Case 1 of the above step S205 , the first CVM immediately uses the first I / O device.
[0149] Specifically, the first CVM immediately establishes a communication connection with the first I / O device and performs a first I / O operation on the first I / O device. After completing the first I / O operation, the first CVM immediately releases the first I / O device and writes status information indicating that the first I / O device is currently in an idle state into the first TEE buffer. Subsequently, the communication interface executes step S207.
[0150] In the second operation, corresponding to the case 2 of the above step S205 , the first CVM waits for the first I / O device, or preempts the first I / O device.
[0151] If the first CVM is waiting for the first I / O device, the first CVM establishes a communication connection with the first I / O device after the current state of the first I / O device changes from an occupied state to an idle state, and performs a first I / O operation on the first I / O device.
[0152] If the first CVM preempts the first I / O device, the first CVM generates a first interrupt signal indicating the occupation of the first I / O device and sends the first interrupt signal to the first I / O device. After receiving the first interrupt signal, the first I / O device establishes a communication connection with the first CVM, allowing the first CVM to perform the first I / O operation on the first I / O device. The first interrupt signal includes information such as the device type, device address, and device characteristics (e.g., supported data formats, transmission rate, and cache capacity) of the first I / O device.
[0153] It should be understood that the first and second operations described above are merely examples. In actual applications, the first CVM may also perform other operations based on the status information of the first I / O device. For example, before releasing the first I / O device, the first CVM may generate a first release request indicating the release of the first I / O device and send the first release request to the virtual machine monitor (VMM) in the TEE. Alternatively, the first CVM may write status information indicating that the current state of the first I / O device is idle into the second TEE buffer.
[0154] S207: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0155] Since the first TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the first I / O device from the first TEE buffer.
[0156] S208: The communication interface writes the status information of the first I / O device in the first TEE buffer into the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby achieving synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0157] In some possible implementations, the communication interface may write the status information of the first I / O device in the first TEE buffer into the first REE buffer by overwriting, appending, inserting, or the like. It should be understood that the implementation method of the communication interface writing the status information of the first I / O device in the first TEE buffer into the first REE buffer is similar to the implementation method of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 above. For the sake of brevity, this description will not be further elaborated here.
[0158] S209: The first VM reads the status information of the first I / O device from the first REE buffer.
[0159] In some possible implementations, the first VM reads the status information of the first I / O device from the first REE buffer to obtain the current status of the first I / O device, which mainly includes the following two situations:
[0160] Case 1: The current state of the first I / O device is idle;
[0161] Case 2: The current state of the first I / O device is occupied.
[0162] In some possible implementations, before the first VM reads the status information of the first I / O device from the first REE buffer, triggering the first VM to perform a read operation on the first REE buffer includes at least the following two implementations:
[0163] In a specific implementation, the first VM receives a second notification from the communication interface, wherein the second notification is used to instruct the first VM to read the status information of the first I / O device from the first REE buffer.
[0164] In another specific implementation, the first VM monitors the first REE buffer so that after the communication interface writes the status information of the first I / O device in the first TEE buffer to the first REE buffer, the first VM can read the status information of the first I / O device from the first REE buffer in a timely manner.
[0165] It should be understood that the above-mentioned implementation method of triggering the first VM to read the first REE buffer is merely an example and is not specifically limited here. In actual applications, any implementation method that can trigger the first VM to read the first REE buffer is within the scope of protection of this application.
[0166] S210: The first VM performs an operation on the first I / O device according to the status information of the first I / O device.
[0167] It should be understood that the operation performed by the first VM in case 1 of the above step S209 is similar to the first operation in the above step S206; the operation performed by the first VM in case 2 of the above step S209 is similar to the second operation in the above step S206. For the sake of brevity of the specification, it will not be elaborated here.
[0168] In summary, when the first CVM in the TEE needs to establish a communication connection with the first I / O device to complete the first I / O request, the communication interface in the TEE is used to synchronize the status information of the first I / O device in the first REE buffer with the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first REE buffer and the first TEE are the same, achieving the effect of maintaining consistency of the status information of the first I / O device in the REE and TEE. Therefore, the first CVM can perform operations on the first I / O device based on the current state of the first I / O device. For example, if the current state of the first I / O device is idle, the first CVM immediately uses the first I / O device; if the current state of the first I / O device is occupied, the first CVM waits for or preempts the first I / O device. This avoids conflicts with the use of the first I / O device by the VM in the REE.
[0169] Furthermore, the communication interface directly reads the status information of the first I / O device from the first REE buffer and writes it to the first TEE buffer; alternatively, the communication interface directly reads the status information of the first I / O device from the first TEE buffer and writes it to the first REE buffer. This can effectively improve the speed of sharing the status information of the first I / O device between the REE and TEE, thereby improving the performance of the first VM and the first CVM in using the first I / O device, including the speed, latency, throughput, and response time of data transmission between the computing device and the first I / O device.
[0170] Furthermore, since what is transmitted in this technical solution is the status information of the first I / O device, the security and privacy of data calculated in the TEE can still be guaranteed.
[0171] The method for performing operations on an I / O device using a CVM in Figure 2 is applicable to scenarios where the status information of a single I / O device is synchronized. Based on the computing device architecture in Figure 1 and the method for performing operations on an I / O device using a CVM in Figure 2, another method for performing operations on an I / O device using a CVM is described below. This method is applicable to scenarios where the status information of multiple I / O devices is synchronized.
[0172] Referring to Figure 3, Figure 3 is a flow chart of another method for a CVM to perform an operation on an I / O device provided in an embodiment of the present application. As shown in Figure 3, the method for a CVM to perform an operation on an I / O device in an embodiment of the present application includes:
[0173] S301: A first CVM or a first I / O device sends a first I / O request to a communication interface.
[0174] S302: The communication interface determines whether a modification time of the status information of the first I / O device in the first REE buffer is later than a modification time of the status information of the first I / O device in the first TEE buffer.
[0175] If the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, go to S303; if the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, go to S307.
[0176] S303: The communication interface reads the status information of the first I / O device from the first REE buffer.
[0177] S304: The communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby achieving synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0178] S305: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0179] S306: Perform an operation on the first I / O device according to the status information of the first I / O device.
[0180] S307: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0181] S308: The communication interface writes the status information of the first I / O device in the first TEE buffer into the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby achieving synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0182] S309: The first VM reads the status information of the first I / O device from the first REE buffer.
[0183] S310: Perform an operation on the first I / O device according to the status information of the first I / O device.
[0184] The execution process of the above-mentioned steps S301 to S310 can refer to the execution process of steps S201 to S210 in Figure 2, and for the sake of brevity of the description, they will not be elaborated here.
[0185] S311: The second CVM or the second I / O device sends a second I / O request to the communication interface. Correspondingly, the communication interface receives the second I / O request from the second CVM or the second I / O device.
[0186] The second I / O request is used to instruct the second CVM to perform a second I / O operation on the second I / O device. The second I / O operation includes reading data from the second I / O device and transmitting the data to an application or virtual processor in the second CVM, and sending data from the application or virtual processor in the second CVM to the second I / O device. The virtual processor in the second CVM is the processor occupied by the second CVM in the TEE.
[0187] The second CVM may be the second CVM 123 in the computing device 10 in FIG1 . The second I / O device may be one of the I / O devices 11 in FIG1 .
[0188] S312: The communication interface determines whether the modification time of the status information of the second I / O device in the second REE buffer is later than the modification time of the status information of the second I / O device in the second TEE buffer.
[0189] The modification time of the status information of the second I / O device may be part of the metadata of the status information of the second I / O device. Metadata is data that describes the status information, including the creation time, access rights, storage location, etc. of the status information. The metadata is stored in the operating system or file system. Specifically, the modification time of the status information of the second I / O device in the second REE buffer is stored in the operating system or file system in the REE. The modification time of the status information of the second I / O device in the second TEE buffer is stored in the operating system or file system in the TEE.
[0190] Therefore, the communication interface can obtain the modification time of the status information of the second I / O device in the second REE buffer from the metadata of the REE's operating system or the metadata of the file system, and obtain the modification time of the status information of the second I / O device in the second TEE buffer from the metadata of the TEE's operating system or the metadata of the file system.
[0191] Subsequently, the communication interface compares the modification time of the status information of the second I / O device in the second REE buffer with the modification time of the status information of the second I / O device in the second TEE buffer to determine the storage location of the status information indicating the current status of the second I / O device. This mainly includes the following two situations:
[0192] Case 1: The modification time of the status information of the second I / O device in the second REE buffer is later than the modification time of the status information of the second I / O device in the second TEE buffer, indicating that the status information of the second I / O device in the second REE buffer is new, and the status information of the second I / O device in the second TEE buffer is old. Therefore, the status information of the second I / O device stored in the second REE buffer indicates the current status of the second I / O device.
[0193] Case 2: The modification time of the status information of the second I / O device in the second REE buffer is earlier than the modification time of the status information of the second I / O device in the second TEE buffer, indicating that the status information of the second I / O device in the second REE buffer is old, and the status information of the second I / O device in the second TEE buffer is new. Therefore, the status information of the second I / O device stored in the second TEE buffer indicates the current status of the second I / O device.
[0194] The second REE buffer may be the second REE buffer 114 in the computing device 10 in FIG1 . The second TEE buffer may be the second TEE buffer 124 in the computing device 10 in FIG1 .
[0195] In case 1 of step S312 above, go to S313; in case 2 of step S312 above, go to S317.
[0196] S313: The communication interface reads the status information of the second I / O device from the second REE buffer.
[0197] Since the second REE buffer is set in the REE, and the data in the REE can not only be used within the REE but also be shared with the TEE, the communication interface in the TEE can read the status information of the second I / O device from the second REE buffer.
[0198] S314: The communication interface writes the status information of the second I / O device in the second REE buffer into the second TEE buffer, so that the status information of the second I / O device in the second TEE buffer is replaced by the status information of the second I / O device in the second REE buffer, thereby achieving synchronization of the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer.
[0199] In some possible implementations, the communication interface may write the status information of the second I / O device in the second REE buffer into the second TEE buffer by overwriting, appending, or inserting. It should be understood that the implementation method of the communication interface writing the status information of the second I / O device in the second REE buffer into the second TEE buffer is similar to the implementation method of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 of Figure 2. For the sake of brevity, this description will not be repeated here.
[0200] S315: The second CVM reads the status information of the second I / O device from the second TEE buffer.
[0201] In some possible implementations, the second CVM reads the status information of the second I / O device from the second TEE buffer to obtain the current status of the second I / O device, mainly including the following two situations:
[0202] Case 1: The current state of the second I / O device is idle;
[0203] Case 2: The current status of the second I / O device is occupied.
[0204] In some possible implementations, different values may be used to represent different states of the second I / O device, that is, different values may be used to correspond to different situations in step S315. It should be understood that this is similar to the use of different values to represent different states of the first I / O device in step S205 in Figure 2. For the sake of brevity, this description will not be repeated here.
[0205] In some possible implementations, before the second CVM reads the status information of the second I / O device from the second TEE buffer, the second CVM is triggered to read the second TEE buffer. It should be understood that the implementation method of triggering the second CVM to read the second TEE buffer is similar to the implementation method of triggering the first CVM to read the first TEE buffer in step S205 in Figure 2 above. For the sake of brevity, it will not be further described here.
[0206] S316: The second CVM performs an operation on the second I / O device according to the status information of the second I / O device.
[0207] It should be understood that the operation performed by the second CVM in case 1 of the above step S315 is similar to the first operation in step S206 in the above Figure 2; the operation performed by the second CVM in case 2 of the above step S315 is similar to the second operation in step S206 in the above Figure 2. For the sake of brevity of the specification, it will not be elaborated here.
[0208] S317: The communication interface reads the status information of the second I / O device from the second TEE buffer.
[0209] Since the second TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the second I / O device from the second TEE buffer.
[0210] S318: The communication interface writes the status information of the second I / O device in the second TEE buffer into the second REE buffer, so that the status information of the second I / O device in the second REE buffer is replaced by the status information of the second I / O device in the second TEE buffer, thereby achieving synchronization of the status information of the second I / O device in the second REE buffer and the status information of the second I / O device in the second TEE buffer.
[0211] In some possible implementations, the communication interface may write the status information of the second I / O device in the second TEE buffer into the second REE buffer by overwriting, appending, or inserting. It should be understood that the implementation method of the communication interface writing the status information of the second I / O device in the second TEE buffer into the second REE buffer is similar to the implementation method of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 in Figure 2. For the sake of brevity, this description will not be repeated here.
[0212] S319: The second VM reads the status information of the second I / O device from the second REE buffer.
[0213] In some possible implementations, the second VM reads the status information of the second I / O device from the second REE buffer to obtain the current status of the second I / O device, mainly including the following two situations:
[0214] Case 1: The current state of the second I / O device is idle;
[0215] Case 2: The current status of the second I / O device is occupied.
[0216] In some possible implementations, before the second VM reads the status information of the second I / O device from the second REE buffer, the second VM is triggered to perform a read operation on the second REE buffer. It should be understood that the implementation of triggering the second VM to perform a read operation on the second REE buffer is similar to the implementation of triggering the first VM to perform a read operation on the first REE buffer in step S209 in FIG. 2 , and for the sake of brevity, this description will not be repeated here.
[0217] S320: The second VM performs an operation on the second I / O device according to the status information of the second I / O device.
[0218] It should be understood that the operation performed by the second VM in case 1 of the above step S319 is similar to the first operation in step S206 in the above Figure 2; the operation performed by the second VM in case 2 of the above step S319 is similar to the second operation in step S206 in the above Figure 2. For the sake of brevity of the specification, it will not be elaborated here.
[0219] It should be understood that the present technical solution may first execute the above steps S301 to S310, and then execute the above steps S311 to S320; or first execute the above steps S311 to S320, and then execute the above steps S301 to S310; or alternately execute the steps in the above steps S301 to S310 and the steps in the above steps S311 to S320, for example, first execute the above step S301, then execute the above step S311, then execute the above step S302, and then execute the above step S312... or, first execute the above steps S311 and S312, and then execute the above steps S301 and S302...
[0220] In summary, when the CVM in the TEE needs to establish a communication connection with an I / O device to complete an I / O request, the TEE's communication interface is used to synchronize the I / O device status information in the REE buffer with the I / O device status information in the TEE buffer. This ensures that the I / O device status information in the REE buffer is the same as that in the TEE buffer, ensuring that the I / O device status information is consistent between the REE and TEE. Therefore, the CVM can perform operations on the I / O device based on its current state, avoiding conflicts with the VM's use of the I / O device in the REE.
[0221] Furthermore, in the process of sharing the status information of the I / O device between the CVM in the TEE and the VM in the REE, the status information of the I / O device from the TEE is always transmitted to the REE through the same communication interface, or the status information of the I / O device from the REE is always transmitted to the TEE through the same communication interface. Using only one communication interface in the TEE to transmit the status information of the I / O device can reduce the complexity of the technical solution, simplify the development process, and save the computing resources and hardware of the TEE. More importantly, compared to using multiple communication interfaces, which makes each communication interface a target of attack by unsafe devices, the technical solution uses only one communication interface, which can reduce the attack surface and potential security vulnerabilities and reduce the threats to the TEE.
[0222] Furthermore, since what is transmitted in this technical solution is the status information of the first I / O device, the security and privacy of data calculated in the TEE can still be guaranteed.
[0223] 2. Method for the Second Computing Device and Its Corresponding CVM to Perform Operations on I / O Devices
[0224] The second computing device is based on the structure of the first computing device described above, with a shadow buffer added to the REE for storing status information of I / O devices. For details, please refer to FIG. 4 and the introduction of related content.
[0225] Referring to Figure 4, which is an architecture diagram of another computing device provided in an embodiment of the present application, the architecture includes a computing device 20 and an I / O device 21. The computing device 20 and the I / O device 21 can communicate with each other.
[0226] Computing device 20 refers to an electronic device capable of performing calculations, processing, and storing data, such as a server, supercomputer, personal computer, workstation, mobile device, etc. Computing device 20 includes multiple physical components (i.e., hardware). Computing device 20 can perform various computing tasks based on the computing resources and storage resources provided by the hardware. Computing resources refer to the hardware and software in computing device 20 used to perform computing tasks. Storage resources refer to the hardware and software in computing device 20 used to store data and programs.
[0227] The I / O device 21 refers to a device for interacting with the outside of the computing device 20 .
[0228] The I / O device 21 may be the I / O device 11 in Figure 1. The I / O device 21 is responsible for receiving input information from a user or other devices, and transmitting output information processed by the computing device 20 to the user or other devices.
[0229] The architecture of the computing device shown in FIG4 is illustrated by taking the computing device 20 having two I / O devices as an example. In actual applications, the number of I / O devices 21 communicating with the computing device 20 may be less or more, and may be various types of I / O devices, which are not specifically limited here.
[0230] In some possible implementations, the communication process between the computing device 20 and the I / O device 21 is similar to the communication process between the computing device 10 and the I / O device 11 in Figure 1 above. For the sake of brevity, it will not be elaborated here.
[0231] In some possible implementations, computing device 20 includes a common open environment (REE) 210 and a trusted execution environment (TEE) 220. The hardware used for computing resources in common open environment (REE) 210 (i.e., hardware 230 in FIG. 4 ) is isolated from the hardware used for computing resources in trusted execution environment (TEE) 220 (i.e., hardware 240 in FIG. 4 ). The common open environment (REE) 210 and the trusted execution environment (TEE) 220 are described separately below.
[0232] (1) Ordinary open environment REE 210
[0233] Common open environment REE 210 includes a first VM 211, a first REE buffer 212, a second VM 213, a second REE buffer 214, a shadow buffer 215, and a control module 216. The functions of first VM 211, first REE buffer 212, second VM 213, and second REE buffer 214 are similar to those of first VM 111, first REE buffer 112, second VM 113, and second REE buffer 114 in common open environment REE 110 of computing device 10 in FIG. 1 , and for the sake of brevity, their detailed description is omitted here. The following description focuses on the functions of shadow buffer 215 and control module 216.
[0234] (1) Shadow Buffer 215
[0235] The shadow buffer 215 can be set in the internal memory and / or external memory allocated by the computing device 20 to the common open environment REE 210, and is used to store the status information of the I / O devices allowed to be accessed by the first CVM 221 and the status information of the I / O devices allowed to be accessed by the second CVM 223.
[0236] Shadow buffer 215 can be implemented in software or hardware. As an example of software implementation, shadow buffer 215 can be implemented by code running on a computing instance of common open environment REE 210. As an example, the computing instance can be a confidential virtual machine and / or container. As an example of hardware implementation, shadow buffer 215 can be implemented by hardware such as memory chips and cache chips allocated by computing device 20 to common open environment REE 210.
[0237] (2) Control module 216
[0238] The control module 216 can be implemented by software or by hardware. As an example of software implementation, the control module 216 can be implemented by code running on a computing instance of the common open environment REE 210. The computing instance can be a virtual machine and / or a container. Furthermore, the computing instance can be one or more. For example, the control module 216 can include code running on multiple virtual machines / containers. It should be noted that the multiple virtual machines / containers used to run the code can be distributed in the same region or in different regions. As an example of hardware implementation, the control module 216 can be implemented by hardware such as circuits, memory chips, cache chips, etc. allocated by the computing device 20 to the common open environment REE 210.
[0239] (2) Trusted Execution Environment TEE 220
[0240] The trusted execution environment TEE 220 includes a first CVM 221, a first TEE buffer 222, a second CVM 223, a second TEE buffer 224, and a communication interface 225. The functions of the first CVM 221, the first TEE buffer 222, the second CVM 223, the second TEE buffer 224, and the communication interface 225 are similar to those of the first CVM 121, the first TEE buffer 122, the second CVM 123, the second TEE buffer 124, and the communication interface 125 in the trusted execution environment TEE 120 in the computing device 10 in FIG. 1 , and are not further described here for the sake of brevity.
[0241] It should be understood that the above-mentioned (1) ordinary open environment REE 210 to (2) trusted execution environment TEE 220 are explained by taking the computing device 20 of Figure 4 as an example including one REE and one TEE. In actual applications, the number of REEs and TEEs can be one or more, and this application does not make specific limitations.
[0242] Based on the architecture of the computing device in FIG. 4 , another method for performing operations on an I / O device by a CVM provided in an embodiment of the present application is described in detail below.
[0243] See Figure 5, which is a flowchart of another method for performing operations on I / O devices by a CVM, provided in an embodiment of the present application. This method for performing operations on I / O devices by a CVM can improve the stability of sharing the status information of I / O devices between REE and TEE. As shown in Figure 5, the method for performing operations on I / O devices by a CVM in an embodiment of the present application includes:
[0244] S501: A first CVM or a first I / O device sends a first I / O request to a communication interface. Correspondingly, the communication interface receives the first I / O request from the first CVM or the first I / O device.
[0245] The first I / O request is used to instruct the first CVM to perform a first I / O operation on the first I / O device. The first I / O operation includes reading data from the first I / O device and transmitting the data to an application or virtual processor in the first CVM, and sending data from the application or virtual processor in the first CVM to the first I / O device.
[0246] The first CVM may be the first CVM 221 in the computing device 20 in Figure 4 . The first I / O device may be one of the I / O devices 21 in Figure 4 . The communication interface may be the communication interface 225 in the computing device 20 in Figure 4 .
[0247] S502: The communication interface determines whether the modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer.
[0248] The modification time of the status information of the first I / O device may be part of the metadata of the status information of the first I / O device. Metadata is data that describes the status information, including the creation time, access rights, storage location, etc. of the status information. The metadata is stored in the operating system or file system. Specifically, the modification time of the status information of the first I / O device in the shadow buffer is stored in the operating system or file system in the REE. The modification time of the status information of the first I / O device in the first TEE buffer is stored in the operating system or file system in the TEE.
[0249] Therefore, the communication interface can obtain the modification time of the status information of the first I / O device in the shadow buffer from the metadata of the REE's operating system or the metadata of the file system, and obtain the modification time of the status information of the first I / O device in the first TEE buffer from the metadata of the TEE's operating system or the metadata of the file system.
[0250] Subsequently, the communication interface compares the modification time of the status information of the first I / O device in the shadow buffer with the modification time of the status information of the first I / O device in the first TEE buffer to determine the storage location of the status information indicating the current status of the first I / O device. This mainly includes the following two situations:
[0251] Case 1: The modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the shadow buffer is new, and the status information of the first I / O device in the first TEE buffer is old. Therefore, the status information of the first I / O device stored in the shadow buffer indicates the current status of the first I / O device.
[0252] Case 2: The modification time of the status information of the first I / O device in the shadow buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, indicating that the status information of the first I / O device in the shadow buffer is old, and the status information of the first I / O device in the first TEE buffer is new. Therefore, the status information of the first I / O device stored in the first TEE buffer indicates the current status of the first I / O device.
[0253] The shadow buffer may be the shadow buffer 215 in the computing device 20 in FIG4 . The first TEE buffer may be the first TEE buffer 222 in the computing device 20 in FIG4 .
[0254] In case 1 of step S502 above, go to S503; in case 2 of step S502 above, go to S507.
[0255] S503: The communication interface reads the status information of the first I / O device from the first REE buffer from the shadow buffer.
[0256] In some possible implementations, before the communication interface reads the status information of the first I / O device from the first REE buffer from the shadow buffer, the first VM writes the status information of the first I / O device in the first REE buffer to the shadow buffer, so that the shadow buffer stores the status information of the first I / O device from the first REE buffer. The status information of the first I / O device in the first REE buffer indicates the current status of the first I / O device.
[0257] Specifically, when the first VM obtains operation permission for the first I / O device, the first VM writes status information indicating that the current state of the first I / O device is occupied into the first REE buffer. Subsequently, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer. When the first VM releases the first I / O device, the first VM writes status information indicating that the current state of the first I / O device is idle into the first REE buffer. Subsequently, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer. Therefore, the modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first REE buffer.
[0258] In some possible implementations, the first VM may write the status information of the first I / O device in the first REE buffer into the shadow buffer using overwrite, append, or insert write methods. It should be understood that the implementation method by which the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer is similar to the implementation method by which the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 of FIG. 2 , and for the sake of brevity, this description will not be repeated here.
[0259] After the status information of the first I / O device from the first REE buffer is stored in the shadow buffer, since the shadow buffer is set in the REE, the data in the REE can not only be used within the REE but also shared with the TEE. Therefore, the communication interface in the TEE can read the status information of the first I / O device from the shadow buffer.
[0260] The first REE buffer may be the first REE buffer 212 in the computing device 20 in FIG4 . The first VM may be the first VM 211 in the computing device 20 in FIG4 .
[0261] S504: The communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby achieving synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0262] In some possible implementations, the communication interface may write the status information of the first I / O device in the shadow buffer into the first TEE buffer by overwriting, appending, inserting, or the like. It should be understood that the implementation method in which the communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer is similar to the implementation method in which the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 of FIG. 2 . For the sake of brevity, this description will not be further elaborated here.
[0263] Since the status information of the first I / O device in the shadow buffer is replaced by the status information of the first I / O device in the first REE buffer, after the communication interface writes the status information of the first I / O device in the shadow buffer to the first TEE buffer, the status information of the first I / O device in the first TEE buffer is also replaced by the status information of the first I / O device in the first REE buffer.
[0264] S505: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0265] In some possible implementations, the first CVM reads the status information of the first I / O device from the first TEE buffer to obtain the current status of the first I / O device, which mainly includes the following two situations:
[0266] Case 1: The current state of the first I / O device is idle;
[0267] Case 2: The current state of the first I / O device is occupied.
[0268] In some possible implementations, different values may be used to represent different states of the first I / O device, that is, different values may be used to correspond to different situations in step S505. It should be understood that this is similar to the use of different values to represent different states of the first I / O device in step S205 in Figure 2. For the sake of brevity, this description will not be repeated here.
[0269] In some possible implementations, before the first CVM reads the status information of the first I / O device from the first TEE buffer, the first CVM is triggered to read the first TEE buffer. It should be understood that the implementation method of triggering the first CVM to read the first TEE buffer is similar to the implementation method of triggering the first CVM to read the first TEE buffer in step S205 in Figure 2 above. For the sake of brevity, it is not further described here.
[0270] S506: The first CVM performs an operation on the first I / O device according to the status information of the first I / O device.
[0271] It should be understood that the operation performed by the first CVM in case 1 of the above step S505 is similar to the first operation in step S206 in the aforementioned Figure 2; the operation performed by the first CVM in case 2 of the above step S505 is similar to the second operation in step S206 in the aforementioned Figure 2. For the sake of brevity of the specification, it will not be elaborated here.
[0272] S507: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0273] Since the first TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the first I / O device from the first TEE buffer.
[0274] S508: The communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer, so that the shadow buffer stores the status information of the first I / O device.
[0275] In some possible implementations, the communication interface may write the status information of the first I / O device in the first TEE buffer into the shadow buffer by overwriting, appending, inserting, or the like. It should be understood that the implementation method of the communication interface writing the status information of the first I / O device in the first TEE buffer into the shadow buffer is similar to the implementation method of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 in FIG. 2 . For the sake of brevity, this description will not be elaborated here.
[0276] In some possible implementations, the communication interface has higher permissions to operate the shadow buffer than the first VM. If there is a conflict between the operations of the communication interface and the first VM on the shadow buffer, the communication interface performs the operations on the shadow buffer. This includes at least the following two implementations:
[0277] In a specific implementation, when the communication interface operates the shadow buffer, access by the first VM is denied.
[0278] As an example, a terminate instruction is used to deny access to the first VM. If the communication interface and the first VM simultaneously perform write operations on the shadow buffer, the communication interface performs the write operation on the shadow buffer. The communication interface can send a terminate instruction to the first VM. The terminate instruction is used to immediately terminate the first VM's write operation to the shadow buffer.
[0279] As another example, a mutex lock is used to deny access to the first VM. While the communication interface is writing to the shadow buffer, the mutex lock is used to lock the shadow buffer, preventing the first VM from writing to the shadow buffer. Because the first VM does not obtain the mutex lock, it cannot write to the shadow buffer.
[0280] As another example, the first VM is denied access to only a portion of the shadow buffer. If the communication interface and the first VM simultaneously write to the same location in the shadow buffer, the communication interface performs the write operation on that location in the shadow buffer. The communication interface can deny the first VM access to that location in the shadow buffer using methods such as a termination instruction or a mutex.
[0281] In another specific implementation, when the first VM operates the shadow buffer, access to the communication interface is allowed.
[0282] As an example, an interrupt signal is used to enable access to the communication interface. While the first VM is performing a write operation on the shadow buffer, the communication interface sends a second interrupt signal to the first VM. The second interrupt signal is used to terminate the first VM's write operation on the shadow buffer. Subsequently, the communication interface performs the write operation on the shadow buffer. After the communication interface completes the write operation, the first VM resumes the write operation on the shadow buffer.
[0283] As another example, a cancel instruction is used to implement access to the communication interface. While the first VM is performing a write operation on the shadow buffer, the communication interface sends a cancel instruction to the first VM. The cancel instruction stops the first VM from performing the write operation on the shadow buffer. Subsequently, the communication interface performs the write operation on the shadow buffer.
[0284] It should be understood that the above two implementations are merely examples and are not specifically limited herein. In practical applications, any implementation of the communication interface that enables the communication interface to have higher operating authority over the shadow buffer than the first VM to have operating authority over the shadow buffer is within the scope of protection of this application.
[0285] S509: The control module reads the status information of the first I / O device from the first TEE buffer from the shadow buffer.
[0286] Since the shadow buffer is set in the REE and the data in the REE can be used within the REE, the control interface in the REE can read the status information of the first I / O device from the shadow buffer. The control module can be the control module 216 in the computing device 20 in FIG4 .
[0287] S510: The control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby achieving synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0288] In some possible implementations, the communication interface may write the status information of the first I / O device in the shadow buffer into the first REE buffer by overwriting, appending, or inserting. It should be understood that the implementation method in which the control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer is similar to the implementation method in which the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 of FIG. 2 . For the sake of brevity, this description will not be repeated here.
[0289] Since the status information of the first I / O device in the shadow buffer is replaced by the status information of the first I / O device in the first TEE buffer, after the control module writes the status information of the first I / O device in the shadow buffer to the first REE buffer, the status information of the first I / O device in the first REE buffer is also replaced by the status information of the first I / O device in the first TEE buffer.
[0290] In some possible implementations, the control module and the first VM have the same operation permissions on the first REE buffer, including at least the following two implementations:
[0291] In a specific implementation, when the control module operates the first REE buffer, access by the first VM is denied.
[0292] As an example, a mutex lock is used to deny access to the first VM. While the control module is performing a write operation on the first REE buffer, the mutex lock is used to lock the first REE buffer, preventing the first VM from performing write operations on the first REE buffer. Because the first VM does not obtain the mutex lock, the first VM cannot perform write operations on the first REE buffer.
[0293] As another example, a flag is used to deny access to the first VM. During a write operation on a first REE buffer by the control module, the control module sets a flag in the first REE buffer to a first value, indicating that the first REE buffer is occupied. Before accessing the first REE buffer, the first VM checks the flag. If the flag is the first value, the first VM is not allowed to access the first REE buffer.
[0294] In another specific implementation, when the first VM operates the first REE buffer, the access of the control module is denied.
[0295] As an example, a flag is used to deny access to the control module. During a write operation on a first REE buffer by a first VM, the first VM sets a flag in the first REE buffer to a first value, indicating that the first REE buffer is being operated on. Before accessing the first REE buffer, the control module checks the flag. If the flag is the first value, the control module denies access to the first REE buffer.
[0296] As another example, a semaphore is used to deny access to the control module. While a first VM is performing a write operation on a first REE buffer, the first VM sets the semaphore of the first REE buffer to a second value, indicating that the first REE buffer is unavailable. Before accessing the first REE buffer, the control module checks the semaphore. If the semaphore is the second value, the control module denies access to the first REE buffer.
[0297] It should be understood that the above two implementations are merely examples and are not specifically limited herein. In practical applications, any implementation that enables the control module and the first VM to have the same operating permissions on the first REE buffer is within the scope of protection of this application.
[0298] S511: The first VM reads status information of the first I / O device from the first REE buffer.
[0299] In some possible implementations, the first VM reads the status information of the first I / O device from the first REE buffer to obtain the current status of the first I / O device, which mainly includes the following two situations:
[0300] Case 1: The current state of the first I / O device is idle;
[0301] Case 2: The current state of the first I / O device is occupied.
[0302] In some possible implementations, before the first VM reads the status information of the first I / O device from the first REE buffer, the first VM is triggered to perform a read operation on the first REE buffer. It should be understood that the implementation of triggering the first VM to perform the read operation on the first REE buffer is similar to the implementation of triggering the first VM to perform the read operation on the first REE buffer in step S209 in FIG. 2 , and for the sake of brevity, this description is not further elaborated here.
[0303] S512: The first VM performs an operation on the first I / O device according to the status information of the first I / O device.
[0304] It should be understood that the operation performed by the first VM in case 1 of the above step S511 is similar to the first operation in step S206 in the aforementioned Figure 2; the operation performed by the first VM in case 2 of the above step S511 is similar to the first operation in step S206 in the aforementioned Figure 2. For the sake of brevity of the specification, it will not be elaborated here.
[0305] In summary, when the first CVM in the TEE needs to establish a communication connection with the first I / O device to complete the first I / O request, the communication interface in the TEE is used to synchronize the status information of the first I / O device in the first REE buffer with the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device in the first REE buffer and the first TEE are the same, achieving the effect of maintaining consistency of the status information of the first I / O device in the REE and TEE. Therefore, the first CVM can perform operations on the first I / O device based on the current status of the first I / O device, thus avoiding conflicts with the use of the first I / O device by the VM in the REE.
[0306] Furthermore, in the process of sharing the usage of the first I / O device by the first CVM in the TEE (that is, the status information of the first I / O device) to the first VM in the REE, the communication interface first writes the status information of the first I / O device in the first TEE buffer into the shadow buffer in the REE, and then the control module with the same operation authority as the first VM writes the status information of the first I / O device in the shadow buffer into the first REE buffer. When the first REE buffer is not operated, the control module can directly write the status information of the first I / O device in the shadow buffer into the first REE buffer; when the first REE buffer is operated by the first VM, the control module waits for the first VM to complete the operation before writing the status information of the first I / O device in the shadow buffer into the first REE buffer. In this way, the operation conflict of the first REE buffer caused by the operation authority of the communication interface in the TEE being higher than the operation authority of the first VM in the REE can be avoided, thereby preventing the occurrence of data confusion in the first REE buffer, which is conducive to improving the stability of sharing the status information of the first I / O device between the REE and the TEE.
[0307] Furthermore, since what is transmitted in this technical solution is the status information of the first I / O device, the security and privacy of data calculated in the TEE can still be guaranteed.
[0308] The method for performing operations on an I / O device using a CVM in Figure 5 is applicable to scenarios where the status information of a single I / O device is synchronized. Based on the computing device architecture in Figure 4 and the method for performing operations on an I / O device using a CVM in Figure 5, another method for performing operations on an I / O device using a CVM is described below. This method is applicable to scenarios where the status information of multiple I / O devices is synchronized.
[0309] Referring to Figure 6, Figure 6 is a flow chart of another method for a CVM to perform an operation on an I / O device provided in an embodiment of the present application. As shown in Figure 6, the method for a CVM to perform an operation on an I / O device in an embodiment of the present application includes:
[0310] S601: A first CVM or a first I / O device sends a first I / O request to a communication interface.
[0311] S602: The communication interface determines whether the modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer.
[0312] If the modification time of the status information of the first I / O device in the shadow buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, go to S603; if the modification time of the status information of the first I / O device in the shadow buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, go to S607.
[0313] S603: The communication interface reads the status information of the first I / O device from the first REE buffer from the shadow buffer.
[0314] S604: The communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer, so that the status information of the first I / O device in the first TEE buffer is replaced by the status information of the first I / O device in the first REE buffer, thereby achieving synchronization of the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
[0315] S605: The first CVM reads the status information of the first I / O device from the first TEE buffer.
[0316] S606: The first CVM performs an operation on the first I / O device according to the status information of the first I / O device.
[0317] S607: The communication interface reads the status information of the first I / O device from the first TEE buffer.
[0318] S608: The communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer, so that the shadow buffer stores the status information of the first I / O device.
[0319] S609: The control module reads the status information of the first I / O device from the first TEE buffer from the shadow buffer.
[0320] S610: The control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer, so that the status information of the first I / O device in the first REE buffer is replaced by the status information of the first I / O device in the first TEE buffer, thereby achieving synchronization of the status information of the first I / O device in the first REE buffer and the status information of the first I / O device in the first TEE buffer.
[0321] S611: The first VM reads status information of the first I / O device from the first REE buffer.
[0322] S612: The first VM performs an operation on the first I / O device according to the status information of the first I / O device.
[0323] The execution process of the above steps S601 to S612 can refer to the execution process of steps S501 to S512 in Figure 5 above, and for the sake of brevity of the description, they will not be elaborated here.
[0324] S613: The second CVM or the second I / O device sends a second I / O request to the communication interface. Correspondingly, the communication interface receives the second I / O request from the second CVM or the second I / O device.
[0325] The second I / O request is used to instruct the second CVM to perform a second I / O operation on the second I / O device. The second I / O operation includes reading data from the second I / O device and transmitting the data to an application or virtual processor in the second CVM, and sending data from the application or virtual processor in the second CVM to the second I / O device.
[0326] The second CVM may be the second CVM 223 in the computing device 20 in FIG4 . The second I / O device may be one of the I / O devices 21 in FIG4 .
[0327] S614: The communication interface determines whether the modification time of the status information of the second I / O device in the shadow buffer is later than the modification time of the status information of the second I / O device in the second TEE buffer.
[0328] The modification time of the status information of the second I / O device may be part of the metadata of the status information of the second I / O device. Metadata is data that describes the status information, including the creation time, access rights, storage location, etc. of the status information. The metadata is stored in the operating system or file system. Specifically, the modification time of the status information of the second I / O device in the shadow buffer is stored in the operating system or file system in the REE. The modification time of the status information of the second I / O device in the second TEE buffer is stored in the operating system or file system in the TEE.
[0329] Therefore, the communication interface can obtain the modification time of the status information of the second I / O device in the shadow buffer from the metadata of the REE's operating system or the metadata of the file system, and obtain the modification time of the status information of the second I / O device in the second TEE buffer from the metadata of the TEE's operating system or the metadata of the file system.
[0330] Subsequently, the communication interface compares the modification time of the status information of the second I / O device in the shadow buffer with the modification time of the status information of the second I / O device in the second TEE buffer to determine the storage location of the status information indicating the current status of the second I / O device. This mainly includes the following two situations:
[0331] Case 1: The modification time of the status information of the second I / O device in the shadow buffer is later than the modification time of the status information of the second I / O device in the second TEE buffer, indicating that the status information of the second I / O device in the shadow buffer is new, and the status information of the second I / O device in the second TEE buffer is old. Therefore, the status information of the second I / O device stored in the shadow buffer indicates the current status of the second I / O device.
[0332] Case 2: The modification time of the status information of the second I / O device in the shadow buffer is earlier than the modification time of the status information of the second I / O device in the second TEE buffer, indicating that the status information of the second I / O device in the shadow buffer is old, and the status information of the second I / O device in the second TEE buffer is new. Therefore, the status information of the second I / O device stored in the second TEE buffer indicates the current status of the second I / O device.
[0333] The second TEE buffer may be the second TEE buffer 224 in the computing device 20 in FIG. 4 .
[0334] In case 1 of step S614 above, go to S615; in case 2 of step S614 above, go to S619.
[0335] S615: The communication interface reads the status information of the second I / O device from the second REE buffer from the shadow buffer.
[0336] In some possible implementations, before the communication interface reads the status information of the second I / O device from the second REE buffer from the shadow buffer, the second VM writes the status information of the second I / O device in the second REE buffer to the shadow buffer, so that the shadow buffer stores the status information of the second I / O device from the second REE buffer. The status information of the second I / O device in the second REE buffer indicates the current status of the second I / O device.
[0337] Specifically, when the second VM obtains permission to operate the second I / O device, the second VM writes status information indicating that the second I / O device is currently in an occupied state into the second REE buffer. Subsequently, the second VM writes the status information of the second I / O device in the second REE buffer into the shadow buffer. When the second VM releases the second I / O device, the second VM writes status information indicating that the second I / O device is currently in an idle state into the second REE buffer. Subsequently, the second VM writes the status information of the second I / O device in the second REE buffer into the shadow buffer. Therefore, the modification time of the status information of the second I / O device in the shadow buffer is later than the modification time of the status information of the second I / O device in the second REE buffer.
[0338] In some possible implementations, the second VM may write the status information of the second I / O device in the second REE buffer into the shadow buffer using overwrite, append, or insert write methods. It should be understood that the implementation method by which the second VM writes the status information of the second I / O device in the second REE buffer into the shadow buffer is similar to the implementation method by which the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 of FIG. 2 , and for the sake of brevity, this description will not be repeated here.
[0339] After the status information of the second I / O device from the second REE buffer is stored in the shadow buffer, since the shadow buffer is set in the REE, the data in the REE can not only be used within the REE but also shared with the TEE. Therefore, the communication interface in the TEE can read the status information of the second I / O device from the shadow buffer.
[0340] The second REE buffer may be the second REE buffer 214 in the computing device 20 in FIG4 . The second VM may be the second VM 213 in the computing device 20 in FIG4 .
[0341] S616: The communication interface writes the status information of the second I / O device in the shadow buffer into the second TEE buffer, so that the status information of the second I / O device in the second TEE buffer is replaced by the status information of the second I / O device in the second REE buffer, thereby achieving synchronization of the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer.
[0342] In some possible implementations, the communication interface may write the status information of the second I / O device in the shadow buffer into the second TEE buffer by overwriting, appending, inserting, or the like. It should be understood that the implementation method of the communication interface writing the status information of the second I / O device in the shadow buffer into the second TEE buffer is similar to the implementation method of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 of FIG. 2 . For the sake of brevity, this description will not be further elaborated here.
[0343] Since the status information of the second I / O device in the shadow buffer is replaced by the status information of the second I / O device in the second REE buffer, after the communication interface writes the status information of the second I / O device in the shadow buffer into the second TEE buffer, the status information of the second I / O device in the second TEE buffer is also replaced by the status information of the second I / O device in the second REE buffer.
[0344] S617: The second CVM reads the status information of the second I / O device from the second TEE buffer.
[0345] In some possible implementations, the second CVM reads the status information of the second I / O device from the second TEE buffer to obtain the current status of the second I / O device, mainly including the following two situations:
[0346] Case 1: The current state of the second I / O device is idle;
[0347] Case 2: The current status of the second I / O device is occupied.
[0348] In some possible implementations, different values may be used to represent different states of the second I / O device, that is, different values may be used to correspond to different situations in step S617. It should be understood that this is similar to the use of different values to represent different states of the first I / O device in step S205 in FIG. 2 . For the sake of brevity, this description will not be repeated here.
[0349] In some possible implementations, before the second CVM reads the status information of the second I / O device from the second TEE buffer, the second CVM is triggered to read the second TEE buffer. It should be understood that the implementation method of triggering the second CVM to read the second TEE buffer is similar to the implementation method of triggering the first CVM to read the first TEE buffer in step S205 in Figure 2 above. For the sake of brevity, it will not be further described here.
[0350] S618: The second CVM performs an operation on the second I / O device according to the status information of the second I / O device.
[0351] It should be understood that the operation performed by the second CVM in case 1 of the above step S617 is similar to the first operation in step S206 in the aforementioned Figure 2; the operation performed by the second CVM in case 2 of the above step S617 is similar to the second operation in step S206 in the aforementioned Figure 2. For the sake of brevity of the specification, it will not be elaborated here.
[0352] S619: The communication interface reads the status information of the second I / O device from the second TEE buffer.
[0353] Since the second TEE buffer is set in the TEE and the data in the TEE can be used inside the TEE, the communication interface in the TEE can read the status information of the second I / O device from the second TEE buffer.
[0354] S620: The communication interface writes the status information of the second I / O device in the second TEE buffer into the shadow buffer, so that the status information of the second I / O device is stored in the shadow buffer.
[0355] In some possible implementations, the communication interface may write the status information of the second I / O device in the second TEE buffer into the shadow buffer by overwriting, appending, inserting, or the like. It should be understood that the implementation method of the communication interface writing the status information of the second I / O device in the second TEE buffer into the shadow buffer is similar to the implementation method of the communication interface writing the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 in FIG. 2 . For the sake of brevity, this description will not be elaborated here.
[0356] In some possible implementations, the communication interface has higher permissions to operate the shadow buffer than the second VM. If operations on the shadow buffer by the communication interface and the second VM conflict, the communication interface performs the operations on the shadow buffer. In one specific implementation, if the communication interface operates the shadow buffer, the second VM is denied access. In another specific implementation, if the second VM operates the shadow buffer, the communication interface is permitted access.
[0357] S621: The control module reads the status information of the second I / O device from the second TEE buffer from the shadow buffer.
[0358] Since the shadow buffer is set in the REE and the data in the REE can be used inside the REE, the control interface in the REE can read the status information of the second I / O device from the shadow buffer.
[0359] S622: The control module writes the status information of the second I / O device in the shadow buffer into the second REE buffer, so that the status information of the second I / O device in the second REE buffer is replaced by the status information of the second I / O device in the second TEE buffer, thereby achieving synchronization of the status information of the second I / O device in the second REE buffer and the status information of the second I / O device in the second TEE buffer.
[0360] In some possible implementations, the communication interface may write the status information of the second I / O device in the shadow buffer into the second REE buffer by overwriting, appending, or inserting. It should be understood that the implementation method in which the control module writes the status information of the second I / O device in the shadow buffer into the second REE buffer is similar to the implementation method in which the communication interface writes the status information of the first I / O device in the first REE buffer into the first TEE buffer in step S204 of FIG. 2 . For the sake of brevity, this description will not be repeated here.
[0361] Since the status information of the second I / O device in the shadow buffer is replaced by the status information of the second I / O device in the second TEE buffer, after the control module writes the status information of the second I / O device in the shadow buffer to the second REE buffer, the status information of the second I / O device in the second REE buffer is also replaced by the status information of the second I / O device in the second TEE buffer.
[0362] In some possible implementations, the control module and the second VM have the same access permissions to the second REE buffer. In one specific implementation, if the control module operates the second REE buffer, the second VM is denied access. In another specific implementation, if the second VM operates the second REE buffer, the control module is denied access.
[0363] S623: The second VM reads the status information of the second I / O device from the second REE buffer.
[0364] In some possible implementations, the second VM reads the status information of the second I / O device from the second REE buffer to obtain the current status of the second I / O device, mainly including the following two situations:
[0365] Case 1: The current state of the second I / O device is idle;
[0366] Case 2: The current status of the second I / O device is occupied.
[0367] In some possible implementations, before the second VM reads the status information of the second I / O device from the second REE buffer, the second VM is triggered to perform a read operation on the second REE buffer. It should be understood that the implementation of triggering the second VM to perform a read operation on the second REE buffer is similar to the implementation of triggering the first VM to perform a read operation on the first REE buffer in step S209 in FIG. 2 , and for the sake of brevity, this description will not be repeated here.
[0368] S624: The second VM performs an operation on the second I / O device according to the status information of the second I / O device.
[0369] It should be understood that the operation performed by the second VM in case 1 of the above step S623 is similar to the first operation in step S206 in the aforementioned Figure 2; the operation performed by the second VM in case 2 of the above step S623 is similar to the second operation in step S206 in the aforementioned Figure 2. For the sake of brevity of the specification, it will not be elaborated here.
[0370] It should be understood that the present technical solution may first execute steps S601 to S612 and then execute steps S613 to S624; may first execute steps S613 to S624 and then execute steps S601 to S612; may also alternately execute steps S601 to S612 and steps S613 to S624, for example, first execute step S601, then execute step S613, then execute step S602, then execute step S614... or, first execute steps S613 and S614, then execute steps S601 and S602...
[0371] In summary, when the CVM in the TEE needs to establish a communication connection with an I / O device to complete an I / O request, the TEE's communication interface is used to synchronize the I / O device status information in the REE buffer with the I / O device status information in the TEE buffer. This ensures that the I / O device status information in the REE buffer is the same as that in the TEE buffer, ensuring that the I / O device status information is consistent between the REE and TEE. Therefore, the CVM can perform operations on the I / O device based on its current state, avoiding conflicts with the VM's use of the I / O device in the REE.
[0372] Furthermore, when the CVM in the TEE and the VM in the REE share I / O device status information, the communication interface only needs to write the status information of the I / O device in the TEE to the shadow buffer in the REE, or read the status information of the I / O device in the REE from the shadow buffer in the REE, without dynamically adjusting the operation object based on the access relationship of the VM in the REE to the I / O device. This operation is simple and reliable, and also reduces the risk of inconsistent or lost I / O device status information.
[0373] Furthermore, since what is transmitted in this technical solution is the status information of the first I / O device, the security and privacy of data calculated in the TEE can still be guaranteed.
[0374] In the embodiments of Figures 2, 3, 5, and 6 above, the virtual input / output (virtIO) protocol can be used to implement the operations of the first VM on the first REE buffer and I / O device in the REE, the operations of the second VM on the second REE buffer and I / O device, and the operations of the first CVM on the first TEE buffer and I / O device in the TEE, the operations of the second CVM on the second TEE buffer and I / O device, and so on.
[0375] The virtIO protocol includes front-end drivers, back-end drivers, and a virtual ring. Front-end drivers are installed in virtual machines (such as VMs and CVMs), while back-end drivers are installed in the virtual machine monitor (HVM). The virtual ring serves as the communication channel between the front-end and back-end drivers.
[0376] The following uses the virtIO protocol to implement operations on a first VM's first REE buffer and I / O device as an example. The front-end driver runs in the first VM, the back-end driver runs in a virtual machine monitor, and the first REE buffer serves as a virtual ring. Furthermore, the front-end driver is configured to send data generated by the first VM to the back-end driver. The back-end driver is configured to receive data sent by the front-end driver. The first REE buffer facilitates data transmission and communication between the front-end and back-end drivers.
[0377] (1) Using the virtIO protocol to implement the first VM's operation on the first REE buffer
[0378] The front-end driver encapsulates the data packet generated by the first VM into a descriptor and writes the descriptor into the first REE buffer. The back-end driver reads the descriptor from the first REE buffer and obtains the data packet according to the descriptor.
[0379] The following describes in detail a data packet carrying status information of an I / O device as an example of a data packet.
[0380] When the first VM generates a data packet carrying I / O device status information, the front-end driver encapsulates the data packet carrying the I / O device status information into a descriptor and writes the descriptor to the first REE buffer. The back-end driver reads the descriptor from the first REE buffer, obtains the data packet carrying the I / O device status information based on the descriptor, and then obtains the current status of the I / O device.
[0381] It should be understood that the above-mentioned data packet carrying the status information of the I / O device is only an example and is not specifically limited here. In actual applications, the data packet may also carry other information, and the descriptor stored in the first REE buffer may be used to indicate the data packet carrying other information.
[0382] (2) Using the virtIO protocol to implement the first VM's operation on the I / O device
[0383] The front-end driver is used to send I / O requests to the back-end driver. The back-end driver is used to receive I / O requests from the front-end driver and send the I / O requests to the corresponding I / O device, so that the I / O device performs the I / O operation. The first REE buffer is used to facilitate the transmission and communication of I / O requests between the front-end driver and the back-end driver.
[0384] Specifically, when the first VM generates a data packet carrying an I / O request, the front-end driver encapsulates the data packet carrying the I / O request into a descriptor and writes the descriptor into the first REE buffer. The back-end driver reads the descriptor from the first REE buffer, obtains the data packet carrying the I / O request based on the descriptor, and then sends the data packet carrying the I / O request to the corresponding I / O device.
[0385] After receiving the data packet, the I / O device completes the corresponding I / O operation according to the I / O request and sends the data packet carrying the I / O request result to the back-end driver.
[0386] The backend driver sends an interrupt signal or notification to the frontend driver, encapsulates a data packet carrying the I / O request result into a descriptor, and writes the descriptor into a first REE buffer. After receiving the interrupt signal or notification, the frontend driver reads the descriptor from the first REE buffer, obtains the data packet carrying the I / O request result based on the descriptor, and then sends the data packet carrying the I / O request result to the application or virtual processor in the first VM so that the application or virtual processor in the first VM can promptly be informed of the completion status of the I / O operation. The virtual processor in the first VM is the processor occupied by the first VM in the REE.
[0387] Due to the widespread use of the virtIO protocol, this technical solution uses the virtIO protocol to reduce compatibility issues caused by cross-platform and greatly improve development efficiency.
[0388] Referring to Figure 7 , Figure 7 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. As shown in Figure 7 , the computing device 700 provided in the present application includes: a bus 701, a processor 702, a memory 703, and a communication interface 704. The processor 702, the memory 703, and the communication interface 704 communicate with each other via the bus 701. The computing device 700 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the computing device 700.
[0389] Bus 701 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG7 illustrates a single bus line, but this does not imply a single bus or type of bus. Bus 701 may include a path for transmitting information between various components of computing device 700 (e.g., memory 703, processor 702, and communication interface 704).
[0390] The processor 702 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0391] The memory 703 may include a volatile memory, such as a random access memory (RAM). The memory 703 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0392] Memory 703 stores executable program code. Processor 702 executes the executable program code to implement the method for the CVM to perform an operation on an I / O device in FIG2 , or the method for the CVM to perform an operation on an I / O device in FIG3 , or the method for the CVM to perform an operation on an I / O device in FIG5 , or the method for the CVM to perform an operation on an I / O device in FIG6 . That is, memory 703 stores instructions for executing the method for the CVM to perform an operation on an I / O device.
[0393] The communication interface 704 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 700 and other computing devices or a communication network.
[0394] The present application also provides a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on a computing device, the computing device executes the method for the CVM to perform operations on an I / O device in FIG2 , or the method for the CVM to perform operations on an I / O device in FIG3 , or the method for the CVM to perform operations on an I / O device in FIG5 , or the method for the CVM to perform operations on an I / O device in FIG6 .
[0395] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state hard disk), etc. The computer-readable storage medium includes instructions that instruct the computing device to execute the method for the CVM to perform operations on the I / O device in Figure 2, or to execute the method for the CVM to perform operations on the I / O device in Figure 3, or to execute the method for the CVM to perform operations on the I / O device in Figure 5, or to execute the method for the CVM to perform operations on the I / O device in Figure 6.
[0396] It should be understood that in the embodiments of the present invention, "when" and "if" both mean that the device will perform corresponding processing under certain objective circumstances, and do not limit the time. It does not require that the device must perform a judgment action when it is implemented, nor does it mean that there are other limitations.
[0397] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A method for a confidential virtual machine CVM to perform operations on input / output I / O devices, characterized in that, Applied to a computing device, the computing device includes a regular open environment REE and a trusted execution environment TEE. The hardware occupied by the computing resources of the REE is isolated from the hardware occupied by the computing resources of the TEE. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM runs based on the computing resources of the TEE. The REE includes a first REE buffer. The method includes: The communication interface receives a first I / O request, where the first I / O request is used to instruct the first CVM to perform a first I / O operation on a first I / O device; The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, where the status information of the first I / O device is used to indicate that the status of the first I / O device is an idle state or an occupied state; The first CVM performs an operation on the first I / O device according to the synchronized status information of the first I / O device in the first TEE buffer, where the synchronized status information of the first I / O device in the first TEE buffer is used to indicate the current status of the first I / O device.
2. The method according to claim 1, characterized in that, The REE further includes a shadow buffer, which is used to store the status information of the first I / O device. The status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device. The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, including: The communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
3. The method according to claim 2, wherein The REE further includes a first virtual machine VM, and the first VM runs based on the computing resources of the REE. Before the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, the method further includes: When the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, the first VM writes the status information of the first I / O device in the first REE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer; The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer by using the status information of the first I / O device in the shadow buffer, including: The communication interface writes the status information of the first I / O device in the shadow buffer into the first TEE buffer, so as to obtain the status information of the first I / O device in the synchronized first TEE buffer; Wherein, the operation permission of the communication interface for the shadow buffer is higher than the operation permission of the first VM for the shadow buffer.
4. The method according to claim 2, characterized in that, The REE further includes a control module, The communication interface synchronizes the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer by using the status information of the first I / O device in the shadow buffer, including: When the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, the communication interface writes the status information of the first I / O device in the first TEE buffer into the shadow buffer, so that the status information of the first I / O device is stored in the shadow buffer; The method further includes: The control module writes the status information of the first I / O device in the shadow buffer into the first REE buffer, so as to obtain the status information of the first I / O device in the synchronized first REE buffer, wherein the status information of the first I / O device in the synchronized first REE buffer is used to indicate the current status of the first I / O device.
5. The method according to any one of claims 1-4, characterized in that, The TEE further includes a second CVM and a second TEE buffer, the second CVM runs based on the computing resources of the TEE, the REE further includes a second REE buffer, and the method further includes: The communication interface receives a second I / O request, wherein the second I / O request is used to instruct the second CVM to perform a second I / O operation on a second I / O device; The communication interface synchronizes the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer, wherein the status information of the second I / O device is used to indicate that the status of the second I / O device is an idle state or an occupied state; The second CVM performs an operation on the second I / O device according to the status information of the second I / O device in the synchronized second TEE buffer, wherein the status information of the second I / O device in the synchronized second TEE buffer is used to indicate the current status of the second I / O device.
6. The method according to claim 3, wherein When the shadow buffer is operated by the communication interface, access by the first VM is refused; or, When the shadow buffer is operated by the first VM, access to the communication interface is allowed.
7. A computing device, characterized in that, It includes a regular open environment REE and a trusted execution environment TEE. The hardware occupied by the computing resources of the REE is isolated from the hardware occupied by the computing resources of the TEE. The TEE includes a communication interface, a first CVM, and a first TEE buffer. The first CVM runs based on the computing resources of the TEE. The REE includes a first REE buffer. The communication interface is used to receive a first I / O request. Among them, the first I / O request is used to instruct the first CVM to perform a first I / O operation on a first I / O device. The communication interface is also used to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer. Among them, the status information of the first I / O device is used to indicate that the status of the first I / O device is an idle state or an occupied state. The first CVM is used to perform an operation on the first I / O device according to the synchronized status information of the first I / O device in the first TEE buffer. Among them, the synchronized status information of the first I / O device in the first TEE buffer is used to indicate the current status of the first I / O device.
8. The device according to claim 7, characterized in that, The REE further includes a shadow buffer, which is used to store the status information of the first I / O device. The status information of the first I / O device in the shadow buffer is used to indicate the current status of the first I / O device. The communication interface is specifically used to use the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer.
9. The device according to claim 8, characterized in that, The REE further includes a first virtual machine VM, and the first VM runs based on the computing resources of the REE. The first VM is used to write the status information of the first I / O device in the first REE buffer into the shadow buffer before the communication interface uses the status information of the first I / O device in the shadow buffer to synchronize the status information of the first I / O device in the first TEE buffer and the status information of the first I / O device in the first REE buffer, when the modification time of the status information of the first I / O device in the first REE buffer is later than the modification time of the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device is stored in the shadow buffer. The communication interface is specifically used to write the status information of the first I / O device in the shadow buffer into the first TEE buffer to obtain the synchronized status information of the first I / O device in the first TEE buffer. Among them, the operation permission of the communication interface for the shadow buffer is higher than that of the first VM for the shadow buffer.
10. The device according to claim 8, characterized in that, The REE further includes a control module. The communication interface is specifically configured to write the status information of the first I / O device in the first TEE buffer into the shadow buffer when the modification time of the status information of the first I / O device in the first REE buffer is earlier than the modification time of the status information of the first I / O device in the first TEE buffer, so that the status information of the first I / O device is stored in the shadow buffer. The control module is configured to write the status information of the first I / O device in the shadow buffer into the first REE buffer to obtain the status information of the first I / O device in the synchronized first REE buffer, where the status information of the first I / O device in the synchronized first REE buffer is used to indicate the current status of the first I / O device.
11. The device according to any one of claims 7 to 10, characterized in that, The TEE further includes a second CVM and a second TEE buffer, the second CVM runs based on the computing resources of the TEE, and the REE further includes a second REE buffer. The communication interface is further configured to receive a second I / O request, where the second I / O request is used to instruct the second CVM to perform a second I / O operation on a second I / O device. The communication interface is further configured to synchronize the status information of the second I / O device in the second TEE buffer and the status information of the second I / O device in the second REE buffer, where the status information of the second I / O device is used to indicate that the status of the second I / O device is an idle state or an occupied state. The second CVM is configured to perform an operation on the second I / O device according to the synchronized status information of the second I / O device in the second TEE buffer, where the synchronized status information of the second I / O device in the second TEE buffer is used to indicate the current status of the second I / O device.
12. The device according to claim 9, wherein when the shadow buffer is operated by the communication interface, access by the first VM is refused; or when the shadow buffer is operated by the first VM, access by the communication interface is allowed.
13. A computing device, characterized in that, It includes a processor and a memory, the memory is used to store instructions, and the processor is used to execute the instructions. When the processor executes the instructions, the method described in any one of claims 1 to 6 is implemented.
14. A computer program product comprising instructions, characterized in that, When the instructions are run by a computing device, the computing device executes the method described in any one of claims 1 to 6.
15. A computer-readable storage medium, characterized in that, It includes computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method described in any one of claims 1 to 6.
Citation Information
Patent Citations
Method for executing operation on input / output equipment by confidential virtual machine and computing equipment
CN120389999A
Data access method, device and equipment and storage medium
CN111459869A
TEE extension-based computer security world real-time application dynamic loading method and system
CN111858004A
Communication method between virtual machine and security isolation interval and related device
CN115509677A
Method, apparatus and system for seamlessly sharing devices amongst virtual machines
US20050198633A1