Electronic device, method and processor for executing hypervisor
By verifying the authenticity of hypervisor address information using a security function at a higher privilege level, the processor ensures secure loading and execution, addressing security challenges in electronic devices.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2026-03-12
AI Technical Summary
Existing electronic devices face challenges in securely loading and executing a hypervisor due to potential unauthorized access and authenticity issues, which can compromise system integrity and security.
The processor is configured to utilize a security function to verify the authenticity of address information for a hypervisor at a higher privilege level, loading it into a secure area within the memory, ensuring secure execution.
This approach enhances the security and integrity of the system by preventing unauthorized access and ensuring the secure loading and execution of the hypervisor, thereby protecting sensitive data and critical tasks.
Smart Images

Figure KR2025011544_12032026_PF_FP_ABST
Abstract
Description
Electronic device, method, and processor for executing a hypervisor
[0001] The present disclosure relates to an electronic device, method, and processor for executing a hypervisor.
[0002] An electronic device may include a processor. An exception may be generated in the processor of the electronic device. Based on the generation of the exception, the processor of the electronic device may interrupt the currently executing task. Based on the identification of the exception, the processor of the electronic device may execute an exception handling routine.
[0003] The above information may be provided as background art to aid in understanding the present disclosure. No claim or determination is made as to whether any of the above is applicable as prior art related to the present disclosure.
[0004] An electronic device is provided. The electronic device may include a memory. The electronic device may include a processor including processing circuitry. The processor may be configured to utilize an image file for a kernel at a first privilege, a hypervisor at a second privilege higher than the first privilege, and a security function at a third privilege higher than the second privilege. The processor may be configured to execute a command requesting the security function to load address information in response to the execution of a bootloader including address information for the hypervisor. The processor may be configured to load the address information into a secure area within the memory using the security function based on verifying the authenticity of the address information using the security function. The processor may be configured to load execution information for the hypervisor within the image file into the secure area using the security function in response to the execution of the kernel at the first privilege. The processor may be configured to execute the hypervisor.
[0005] A method is provided. The method can be performed in an electronic device having a processor including a processing circuit and a memory. The method may include an operation of requesting the security function to load address information in response to the execution of a bootloader including address information for the hypervisor. The method may include an operation of loading the address information into a secure area within the memory using the security function based on verifying the authenticity of the address information using the security function. The method may include an operation of loading execution information for the hypervisor within the image file into the secure area using the security function in response to the execution of the kernel in the first authority. The method may include an operation of executing the hypervisor.
[0006] A processor is provided. The processor may include a processing circuit configured to utilize an image file for a kernel at a first privilege, a hypervisor at a second privilege higher than the first privilege, and a security function at a third privilege higher than the second privilege. The processing circuit may be configured to execute an instruction requesting loading of address information for the hypervisor using the security function in response to execution of a bootloader including address information for the hypervisor. The processing circuit may be configured to load the address information into a secure area within a memory using the security function based on verifying the authenticity of the address information using the security function. The processing circuit may be configured to load execution information for the hypervisor within the image file into the secure area using the security function in response to execution of the kernel at the first privilege. The processing circuit may be configured to execute the hypervisor.
[0007] FIG. 1 is a block diagram of an electronic device within a network environment according to various embodiments.
[0008] FIG. 2 is a block diagram illustrating a program according to various embodiments.
[0009] FIG. 3 illustrates an example of the architecture of a processor according to one embodiment.
[0010] Figure 4 illustrates an example of converting a virtual address into a physical address.
[0011] Figure 5 illustrates an example of hypervisor data being loaded into memory.
[0012] Figure 6 illustrates an example of memory with a security area set.
[0013] Figure 7 illustrates an example of a processor that verifies the authenticity of address information using a security function and loads the address information into a secure area.
[0014] Figure 8 illustrates an example of a processor performing booting.
[0015] Figure 9 illustrates an example of a processor running a hypervisor.
[0016] It will be understood that like reference numerals throughout the drawings refer to like parts, components, and structures.
[0017] The terms used in this disclosure are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include plural expressions unless the context clearly indicates otherwise. Terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art described in this disclosure. Terms defined in general dictionaries among the terms used in this disclosure may be interpreted as having the same or similar meaning in the context of the relevant technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this disclosure. In some cases, even if a term is defined in this disclosure, it cannot be interpreted to exclude embodiments of the present disclosure.
[0018] The various embodiments of the present disclosure described below illustrate a hardware-based approach as an example. However, since the various embodiments of the present disclosure include techniques utilizing both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach.
[0019] In the following description, terms referring to data (e.g., data, information, address information, address, execution information, virtual address, incremental physical address, physical address), terms for operational states (e.g., operation, process, task), terms referring to objects, terms referring to network entities, terms referring to components of devices, etc. are examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms having equivalent technical meanings may be used. In addition, terms such as '... part', '... device', '... thing', '... body', etc. used below may mean at least one shape structure or a unit that processes a function.
[0020] In addition, in the present disclosure, expressions such as "more than" or "less than" may be used to determine whether a specific condition is satisfied or fulfilled, but this is merely a description for expressing an example and does not exclude descriptions such as "more than" or "less than." A condition described as "more than" may be replaced with "more than," a condition described as "less than" may be replaced with "less than," and a condition described as "more than and less than" may be replaced with "more than and less than." In addition, hereinafter, "A" to "B" mean at least one of elements from A (including A) to B (including B). hereinafter, "C" and / or "D" mean at least one of "C" or "D," that is, including {"C", "D", "C" and "D"}.
[0021] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to various embodiments.
[0022] Referring to FIG. 1, in a network environment (100), an electronic device (101) may communicate with an electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of an electronic device (104) or a server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).
[0023] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or a secondary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor)) that can operate independently or together therewith. For example, if the electronic device (101) includes a main processor (121) and a secondary processor (123), the secondary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a specified function. The secondary processor (123) may be implemented separately from the main processor (121) or as a part thereof.
[0024] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.
[0025] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).
[0026] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).
[0027] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).
[0028] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.
[0029] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. In one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.
[0030] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).
[0031] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.
[0032] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
[0033] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).
[0034] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. In one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
[0035] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.
[0036] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least a part of a power management integrated circuit (PMIC).
[0037] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.
[0038] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).
[0039] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.
[0040] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas by, for example, the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).
[0041] According to various embodiments, the antenna module (197) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high frequency band.
[0042] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).
[0043] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.
[0044] FIG. 2 is a block diagram (200) illustrating a program (140) according to various embodiments.
[0045] According to one embodiment, the program (140) may include an operating system (142), middleware (144), or an application (146) executable on the operating system (142) for controlling one or more resources of the electronic device (101). The operating system (142) may include, for example, Android™, iOS™, Windows™, Symbian™, Tizen™, or Bada™. At least some of the programs (140) may be preloaded on the electronic device (101), for example, at the time of manufacture, or may be downloaded or updated from an external electronic device (e.g., the electronic device (102 or 104), or a server (108)) when used by a user.
[0046] The operating system (142) may control the management (e.g., allocation or retrieval) of one or more system resources (e.g., processes, memory, or power) of the electronic device (101). The operating system (142) may additionally or alternatively include one or more driver programs for driving other hardware devices of the electronic device (101), for example, an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197).
[0047] Middleware (144) can provide various functions to the application (146) so that functions or information provided from one or more resources of the electronic device (101) can be used by the application (146). Middleware (144) can include, for example, an application manager (201), a window manager (203), a multimedia manager (205), a resource manager (207), a power manager (209), a database manager (211), a package manager (213), a connectivity manager (215), a notification manager (217), a location manager (219), a graphics manager (221), a security manager (223), a call manager (225), or a voice recognition manager (227).
[0048] The application manager (201) can manage, for example, the life cycle of the application (146). The window manager (203) can manage, for example, one or more GUI resources used on the screen. The multimedia manager (205) can, for example, identify one or more formats required for playing media files, and perform encoding or decoding of a corresponding media file among the media files using a codec suitable for the corresponding format selected among the formats. The resource manager (207) can manage, for example, the source code of the application (146) or the memory space of the memory (130). The power manager (209) can manage, for example, the capacity, temperature, or power of the battery (189), and determine or provide related information necessary for the operation of the electronic device (101) using the corresponding information. According to one embodiment, the power manager (209) can be linked with the basic input / output system (BIOS) (not shown) of the electronic device (101).
[0049] The database manager (211) can, for example, create, search, or modify a database to be used by the application (146). The package manager (213) can, for example, manage the installation or update of an application distributed in the form of a package file. The connectivity manager (215) can, for example, manage a wireless connection or direct connection between the electronic device (101) and an external electronic device. The notification manager (217) can, for example, provide a function for notifying a user of the occurrence of a specified event (e.g., an incoming call, a message, or an alarm). The location manager (219) can, for example, manage location information of the electronic device (101). The graphics manager (221) can, for example, manage one or more graphic effects to be provided to the user or a user interface related thereto.
[0050] The security manager (223) may provide, for example, system security or user authentication. The telephony manager (225) may manage, for example, a voice call function or a video call function provided by the electronic device (101). The voice recognition manager (227) may, for example, transmit the user's voice data to the server (108) and receive, from the server (108), a command corresponding to a function to be performed in the electronic device (101) based at least in part on the voice data, or text data converted based at least in part on the voice data. In one embodiment, the middleware (244) may dynamically delete some of the existing components or add new components. In one embodiment, at least a portion of the middleware (144) may be included as a part of the operating system (142) or implemented as separate software different from the operating system (142).
[0051] The application (146) may include, for example, a home (251), a dialer (253), an SMS / MMS (255), an instant message (IM) (257), a browser (259), a camera (261), an alarm (263), a contact (265), a voice recognition (267), an email (269), a calendar (271), a media player (273), an album (275), a watch (277), a health (279) (e.g., measuring biometric information such as the amount of exercise or blood sugar), or an environmental information (281) (e.g., measuring barometric pressure, humidity, or temperature information) application. According to one embodiment, the application (146) may further include an information exchange application (not shown) that can support information exchange between the electronic device (101) and an external electronic device. The information exchange application may include, for example, a notification relay application configured to transmit designated information (e.g., a call, a message, or an alarm) to an external electronic device, or a device management application configured to manage an external electronic device. The notification relay application may, for example, transmit notification information corresponding to a designated event (e.g., receipt of an email) that occurs in another application (e.g., an email application (269)) of the electronic device (101) to the external electronic device. Additionally or alternatively, the notification relay application may receive notification information from the external electronic device and provide the information to the user of the electronic device (101).
[0052] A device management application may, for example, control the power (e.g., turning on or off) or the function (e.g., brightness, resolution, or focus) of an external electronic device or a component thereof (e.g., a display module or a camera module of the external electronic device) that communicates with the electronic device (101). The device management application may additionally or alternatively support the installation, deletion, or update of an application running on the external electronic device.
[0053] According to one embodiment, the program (140) may include a hypervisor (291). For example, the hypervisor (291) may be an area that is inaccessible to the operating system (142) and at least one application (146). For example, the hypervisor (291) or a hyper module (293) operating in the hypervisor (291) area may manage or execute one or more virtual machines. The hypervisor (291) may manage to execute one or more operating systems (142) by executing one or more virtual machines. The hypervisor (291) will be described in detail with reference to FIGS. 3, 4, 5, 6, 7, 8, and 9.
[0054] FIG. 3 illustrates an example of the architecture of a processor (120) according to one embodiment.
[0055] In the present disclosure, the processor (120) may include processing circuitry. Embodiments of the present disclosure may be executed or operated by the processor (120) and / or the processing circuitry of the processor (120).
[0056] Referring to FIG. 3, the processor (120) can operate under multiple privileges. The privileges may be related to the access scope of processes processed by the processor (120). The processor (120) may be differentiated so that the higher the privilege, the more processes it can execute. The processor (120) can perform important tasks from a system perspective as the privilege increases. The privileges may include a basic privilege (310), a first privilege (311), a second privilege (312), and a third privilege (313). The third privilege (313) may be higher than the second privilege (312). The second privilege (312) may be higher than the first privilege (311). The first privilege (311) may be higher than the basic privilege (310).
[0057] According to one embodiment, the basic privilege (310) may be EL (exception level) 0 in a processor (120) supporting an advanced RISC (reduced instruction set computer) machine (ARM) architecture. The first privilege (311) may be EL1 in a processor (120) supporting an ARM architecture. The second privilege (312) may be EL2 in a processor (120) supporting an ARM architecture. The third privilege (313) may be EL3 in a processor (120) supporting an ARM architecture.
[0058] Although the ARM architecture is exemplified in this disclosure, the embodiments of the present disclosure are not limited thereto. The processor (120) according to the embodiments of the present disclosure may support other types of architectures. In one embodiment, the processor (120) may support the architecture of Intel x86. For example, the basic permission (310) may be level 0 in a processor (120) that supports the architecture of x86. For example, the first permission (311) may be level 1 in a processor (120) that supports the architecture of x86. For example, the second permission (312) may be level 2 in a processor (120) that supports the architecture of x86. For example, the third permission (313) may be level 3 in a processor (120) that supports the architecture of x86. In a processor (120) supporting the x86 architecture, the secure world (340) can be represented by SGX (secure guard extensions). SGX can provide a trusted execution environment (TEE) to the processor (120) supporting the x86 architecture. SGX can be configured to safely process sensitive data and high-priority tasks by providing a secure environment.
[0059] According to one embodiment, the processor (120) may support the architecture of RISC-V. For example, the basic privilege (310) may be a user mode in a processor (120) that supports the architecture of RISC-V. For example, the first privilege (311) may be a supervisor mode in a processor (120) that supports the architecture of RISC-V. For example, the second privilege (312) and / or the third privilege (313) may be a machine mode in a processor (120) that supports the architecture of RISC-V. In a processor (120) that supports the architecture of RISC-V, the secure world (340) may be represented by PMP (physical memory protection). PMP may be described as a technology for protecting memory in a processor (120) that supports the architecture of RISC-V. The processor (120) can divide memory into regions using the PMP and set access rights for each region. The processor (120) can strengthen the security of the system through the PMP.
[0060] According to an example, in order to provide a secure execution environment in an electronic device (101) supporting the ARM architecture, a processor (120) (e.g., CPU) may be hardware-separated into a non-secure world (320) and a secure world (340). The non-secure world (320) may be represented as an execution environment in which a general operating system and / or a general kernel operates. The secure world (340) may be represented as an execution environment in which a secure operating system and / or a secure kernel operates. The secure world (340) may be an execution environment in which a trusted trustzone operates. The processor (120) cannot directly access a memory area in which the secure world (340) is executed in the non-secure world (320). The processor (120) can provide a secure world (340) separated from the non-secure world (320) so that processes running in the non-secure world (320) cannot access it.
[0061] According to one embodiment, a first application (321), a second application (323), a first kernel (325), a second kernel (327), and a hypervisor (329) can be executed in a non-secure world (320). The processor (120) can execute the first application (321) and the second application (322) in the default privilege (310). The processor (120) can execute the first kernel (325) and the second kernel (327) in the first privilege (311). The processor (120) can execute the kernel using an image file for the kernel (e.g., the first kernel (325), the second kernel (327)) in the first privilege (311). The processor (120) can execute or utilize the hypervisor (329) (e.g., the hypervisor (291)) in the second privilege (312). The processor (120) can execute or use a security function (330) in the third authority (313).
[0062] In one embodiment, the hypervisor (329) can manage or execute one or more virtual machines. The hypervisor (329) can be executed in the second authority (312). In one embodiment, the processor (120) can execute a first virtual machine (326) and a second virtual machine (328) by executing the hypervisor (329). The processor (120) can execute a first kernel (325) within the first virtual machine (326). The processor (120) can execute a second kernel (327) within the second virtual machine (328). The first virtual machine (326) and the second virtual machine (328) can be provided with execution environments that are separated from each other by the hypervisor (329).
[0063] According to one embodiment, the hypervisor (329) can create and manage multiple virtual machines (e.g., a first virtual machine (326), a second virtual machine (328)) that run different kernels (or operating systems). For example, the first kernel (325) may be an operating system that the first virtual machine (326) runs, and the second kernel (327) may be an operating system that the second virtual machine (328) runs. The hypervisor (329) may be otherwise referred to as a virtual machine monitor or a virtual machine manager.
[0064] According to one embodiment, a security application (341) and a security kernel (343) may be executed in the secure world (340). The processor (120) may execute the security application (341) with the basic privilege (310). The security application (341) may be referred to as a trusted app. The processor (120) may execute the security kernel (343) with the first privilege (311). The security kernel (343) may be included in the operating system of the secure world (340) to perform functions related to the security application (341) in the secure world (340). According to one embodiment, the secure world (340) may not have an area executed with the second privilege (312).
[0065] In one embodiment, the secure kernel (343) may provide a secure operating system. For example, the secure operating system may be provided to perform functions related to a secure application (341).
[0066] As a non-limiting example, the processor (120) may provide a non-secure world (320) and a secure world (340), but this is merely an example and embodiments of the present invention are not limited thereto. For example, the processor (120) may provide one of the non-secure world (320) and the secure world (340).
[0067] According to one embodiment, the processor (120) may include a security function (330). The processor (120) may execute the security function (330) in the third authority (313). The security function (330) may be a secure monitor in a processor (120) that supports the ARM architecture. The security function (330) may support switching between the non-secure world (320) and the secure world (340). The security function (330) may provide the processor (120) with a trusted execution environment. The trusted execution environment may be described as a secure area designed to safely process sensitive data and tasks with high importance.
[0068] Figure 4 illustrates an example of converting a virtual address (411) into a physical address (415).
[0069] In the present disclosure, the processor (120) may include processing circuitry. Embodiments of the present disclosure may be executed or operated by the processor (120) and / or the processing circuitry of the processor (120).
[0070] A processor (e.g., processor (120)) may include a memory management unit (e.g., a first memory management unit (401) and a second memory management unit (402). The memory management unit may be described as a hardware component used for data transmission between the processor (120) and the memory (420) (e.g., memory (130)). In addition, the memory management unit may perform a memory management function. The memory management unit may perform a function of converting a virtual address into a physical address. Each of the processes performed in the processor (120) may have a virtual address. The processor (120) may read or write data by converting a virtual address into a physical address (or physical memory address) using the memory management unit.
[0071] According to one embodiment, the memory (420) may include the memory (130) of FIG. 1. The memory (420) may include hardware components for storing data input to and / or output from the processor (120). The memory (420) may include, for example, volatile memory such as random-access memory (RAM) and / or non-volatile memory such as read-only memory (ROM). The volatile memory may include, for example, at least one of dynamic RAM (DRAM), static RAM (SRAM), cache RAM, and pseudo SRAM (PSRAM). The non-volatile memory may include, for example, at least one of programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), flash memory, hard disk, compact disc, and embedded multimedia card (EMMC).
[0072] According to one embodiment, the processor (120) can utilize an address space larger than physical memory by utilizing a virtual memory system based on virtual addresses.
[0073] According to one embodiment, the processor (120) may use a memory management unit to prevent each process from accessing the memory area of another processor. By using the memory management unit, the processor (120) may enhance the stability and security of the system.
[0074] Referring to FIG. 4, the processor (120) may include a first memory management unit (401) and a second memory management unit (402). The first memory management unit (401) and the second memory management unit (402) may be represented as independently separated.
[0075] According to one embodiment, the first memory management unit (401) may be controlled by the first authority (311). The first memory management unit (401) may be used to manage a first virtual address (411-1) provided to a process of a first application (or user space). The first memory management unit (401) may be used to manage a second virtual address (411-2) provided to a process of the first kernel (325). The first memory management unit (401) may convert the virtual address (411) into an intermediate physical address (413). For example, the first memory management unit (401) may convert the first virtual address (411-1) into a first intermediate physical address (413-1). For example, the first memory management unit (401) may convert the second virtual address (411-2) into a second intermediate physical address (413-2).
[0076] According to one embodiment, the first memory management unit (401) may use address translation information to translate a virtual address (411) into an intermediate physical address (413). The address translation information may be described as a table indicating the relationship between the virtual address (411) and the intermediate physical address (413). The address translation information may be referenced as a page table.
[0077] According to one embodiment, the second memory management unit (402) may be controlled by the second authority (312). It may be used to convert an output address of the first memory management unit (401) into a physical address (415). For example, the second memory management unit (402) may be used to convert an intermediate physical address (413) into a physical address (415). For example, the second memory management unit (402) may convert a first intermediate physical address (413-1) into a first physical address (415-1). For example, the second memory management unit (402) may convert a second intermediate physical address (413-2) into a second physical address (415-2).
[0078] According to one embodiment, the second memory management unit (402) may use address conversion information to convert an intermediate physical address (413) into a physical address (415). The address conversion information may be described as a table indicating the relationship between the intermediate physical address (413) and the physical address (415). The address conversion information may be referenced as a page table.
[0079] According to one embodiment, the first physical address (415-1) may be represented as an address of first data (417-1) in the memory (420) (e.g., memory (130)). The processor (120) may identify the first data (417-1) in the memory (420) according to the first physical address (415-1). The processor (120) may read or write the first data (417-1) in the memory (420) according to the first physical address (415-1). The second physical address (415-2) may be represented as an address of second data (417-2) in the memory (420). The processor (120) may identify the second data (417-2) in the memory (420) according to the second physical address (415-2). The processor (120) can read or write second data (417-2) from the memory (420) according to the second physical address (415-2).
[0080] According to one embodiment, since the first kernel (325) in the first permission (311) only has access to the mapped first memory management unit (401), the first kernel (325) cannot directly access the memory area of another kernel (e.g., the second kernel (327)). In other words, even if the first kernel (325) is attacked by an attacker (e.g., a hacker), other components of the processor (120) may not be affected by the attack.
[0081] According to one embodiment, since the size of the source code of the hypervisor (329) is smaller than the size of the source code of the kernel (e.g., the first kernel (325), the second kernel (327)), when the hypervisor (329) is attacked by an attacker, the attack surface can be identified more quickly than when the kernel is attacked by the attacker.
[0082] According to one embodiment, the hypervisor (329) may be executed based on a kernel (e.g., a first kernel (325), a second kernel (327). For example, the source code of the kernel may include the source code of the hypervisor (329). For example, the data of the kernel may include the data of the hypervisor (329). For example, since the source code of the hypervisor (329) is included in the source code of the kernel, maintenance of the hypervisor (329) may be relatively easy.
[0083] The processor (120) can set the environment of the hypervisor (329) based on the booting of the kernel. The processor (120) can load the data of the hypervisor (329) into a normal region within the memory (420). If the hypervisor (329) is executed based on the kernel, an attack on the kernel may affect the hypervisor (329). If the hypervisor (329) is executed based on the kernel, a security issue of the kernel may be propagated to the hypervisor (329). In other words, the hypervisor (329) executed in the second privilege (312) and the kernel executed in the first privilege (311) may not be separated.
[0084] In the present disclosure, a technique may be described in which maintenance of a hypervisor (329) is relatively easy while security issues of a kernel are not propagated to the hypervisor (329). According to embodiments of the present disclosure, address information for the hypervisor (329) (e.g., address information (511) of FIG. 5, hypervisor vector) may be included in a bootloader (e.g., bootloader (510) of FIG. 5). Execution information for the hypervisor (e.g., execution information (521) of FIG. 5, hypervisor text, hypervisor read-only data) may be included in an image file for the kernel (e.g., image file (520), vmlinux). In response to executing the bootloader, the processor (120) may load the address information for the hypervisor (329) into a secure region (e.g., secure region (530) of FIG. 5) within the memory (420). This technique will be described and exemplified in more detail with reference to FIGS. 5 to 9.
[0085] FIG. 5 illustrates an example in which data of a hypervisor (e.g., hypervisor (329)) is loaded into memory (420).
[0086] In the present disclosure, the processor (120) may include processing circuitry. Embodiments of the present disclosure may be executed or operated by the processor (120) and / or the processing circuitry of the processor (120).
[0087] The data of the hypervisor (329) may include address information (511) and execution information (521). The address information (511) may be address information for the hypervisor. The address information (511) may indicate addresses (or vectors) of execution codes that the hypervisor (329) uses to handle exceptions in the second authority (312). The address information (511) may be configured for operation in the second authority (312) while the electronic device (101) (or processor (120)) is booting. If the address information (511) is damaged, the hypervisor (329) may not operate. The address information (511) may be referred to as a hypervisor vector.
[0088] The execution information (521) may include execution codes used in the hypervisor (329). The execution codes may include codes for configuring the second memory management unit (402) and codes for memory permissions. The execution codes used in the hypervisor (329) may be referred to as hypervisor text and / or hypervisor code. In addition, the execution information (521) may include read-only data used in the hypervisor (329). The read-only data used in the hypervisor (329) may be referred to as hypervisor read-only data.
[0089] Referring to FIG. 5, the address information (511) of the hypervisor (329) and the execution information (521) of the hypervisor (329) may be included in different components. The address information (511) of the hypervisor (329) may be included in the bootloader (510). The bootloader (510) may be described as the software (or program) that is executed first when the system boots. Since the bootloader (510) is executed in the secure world (340), it may be relatively safe from attackers (e.g., hackers). Since the bootloader (510) does not allow booting of a custom bootloader, it may be difficult for an attacker (e.g., hacker) to identify vulnerabilities. By including the address information (511) of the hypervisor (329) in the bootloader (510), the safety (or security) of the hypervisor (329) may be enhanced.
[0090] According to one embodiment, the processor (120) may identify a secure area (530) within the memory (420) in response to the execution of the bootloader (510). The processor (120) may load address information (511) of the hypervisor (329) within the identified secure area (530). The secure area (530) may be described as a portion of the memory (420) that provides a security function. Data (or information) within the secure area (530) may be configured to be accessible from the secure world (340). Access to data within the secure area (530) may be restricted from the non-secure world (320). Since data within the secure area (530) may only be accessible from the secure world (340), the safety (or security) of the address information (511) loaded within the secure area (530) may be enhanced. The secure region (530) may be referred to as a secure memory region, a safe region, a secure memory region, a restricted region, a boundary region, a hardened memory region, and / or equivalent technical terms in terms of providing security functions within the memory (420).
[0091] According to one embodiment, the image file (520) may include execution information (521) and kernel information (523) for the hypervisor (329). The image file (520) may be described as an image file including the entire code and debugging information of a kernel (e.g., a first kernel (325), a second kernel (327)). The image file (520) may be associated with a first authority (311). For example, the image file (520) may be vmlinux. The kernel information (523) may be represented as information used to execute a kernel (e.g., a first kernel (325), a second kernel (327)) in the first authority (311). The kernel information (523) may include kernel address information (524) and kernel execution information (525). For example, the kernel address information (524) may include a kernel vector. For example, kernel execution information (525) may include kernel text and kernel read-only data.
[0092] According to one embodiment, the image file (520) may include execution information (521) for the hypervisor (329). Since the execution information (521) for the hypervisor (329) is included within the image file (520), maintenance of the execution information (521) may be relatively easy.
[0093] According to one embodiment, the processor (120) can load execution information (521) into a secure area (530) within the memory (420). The execution information (521) for the hypervisor (329) can be securely mapped to the secure area (530) within the memory (420). Since data within the secure area (530) can only be accessed from the secure world (340), the safety (or security) of the execution information (521) loaded within the secure area (530) can be enhanced.
[0094] According to one embodiment, the processor (120) may generate address translation information as illustrated in FIG. 4 while executing a hypervisor. The processor (120) may generate the address translation information in a secure area (530) within memory (420). The address translation information may be managed by the secure area. By managing the address translation information in the secure area (530), the safety (or security) of the hypervisor may be enhanced.
[0095] Figure 6 illustrates an example of a memory (420) in which a security area is set.
[0096] Referring to FIG. 6, the memory (420) may include a first security area (610) and a second security area (620). The first security area (610) and / or the second security area (620) may be an example of the security area (530) of FIG. 5.
[0097] According to one embodiment, the first security area (610) and the second security area (620) may have different access rights. The processor (120) may use the security function (330) in the third authority (313) to identify or separate the first security area (610) and the second security area (620) within the memory (420).
[0098] According to one embodiment, the processor (120) can execute an address space controller (ASC) of the ARM Trustzone using a secure monitor in EL3. By executing the ASC, the processor (120) can identify a first security zone (610) and a second security zone (620).
[0099] According to one embodiment, the first security area (610) may be a security area for the first authority (311). The first security area (610) may be configured to be accessible from the first authority (311) and the third authority (313). The processor (120) may read or write data of the first security area (610) from the first authority (311) and the third authority (313).
[0100] The second security area (620) may be a security area for the second authority (312). The second security area (620) may be configured to be accessible from the second authority (312) and the third authority (313). The processor (120) may read or write data in the second security area (620) from the second authority (312) and the third authority (313). Since the second security area (620) is not accessible from the first authority (311), the security of data within the second security area (620) may be enhanced.
[0101] FIG. 7 illustrates an example of a processor (120) that verifies the authenticity of address information using a security function and loads the address information into a secure area.
[0102] In the present disclosure, the processor (120) may include processing circuitry. Embodiments of the present disclosure may be executed or operated by the processor (120) and / or the processing circuitry of the processor (120).
[0103] Referring to FIG. 7, at operation 701, the processing circuit of the processor (120) may execute a bootloader (510). The bootloader (510) may include address information (511) for the hypervisor (329). The bootloader (510) may be built to include the address information (511). In response to the execution of the bootloader (510), the processing circuit may execute an instruction for utilizing the security function (330). For example, the processing circuit may execute an instruction for utilizing the security function (330) to load the address information (511) and verify the authenticity of the address information (511). As the processing circuit executes the instruction for utilizing the security function (330), the processor (120) may transition from the non-secure world (320) to the secure world (340). The processing circuit can transfer control of the processor (120) to the third authority (313) by executing an instruction to utilize the security function (330). The processing circuit can utilize the security function (330) from the third authority (313). For example, the instruction can be referenced as a smc call (secure monitor call).
[0104] According to one embodiment, the processing circuit may execute the above command in the boot module (711) within the boot loader (510). The boot module (711) may be described as a module that performs the role of system booting and system initialization in the boot loader (510). The boot module (711) may be executed in the third authority (313). The boot module (711) may be used for booting a kernel (e.g., a first kernel (325), a second kernel (327)) and / or booting a hypervisor (329). The boot module (711) may be referred to as BL3 (boot loader stage 3).
[0105] In operation 703, the processing circuit of the processor (120) may use the security function (330) to verify the authenticity of the address information (511) for the hypervisor (329). For example, the processing circuit may use the security function (330) to verify the signature of the address information (511). In one embodiment, the processing circuit may add a module for the address information (511) to the security mechanism to verify the authenticity of the address information (511). The security mechanism may be referred to as a secure boot chain.
[0106] At operation 705, the processing circuit of the processor (120) may identify a secure region (e.g., secure region (530)) within memory (e.g., memory (420)). The processing circuit may isolate the secure region (530) from the memory (420). The secure region (530) may be represented as a region for a hypervisor. In one embodiment, the processing circuit may isolate the secure region (530) from the memory (420) using a trustzone address space controller in a third authority (313).
[0107] In operation 707, the processing circuit of the processor (120) may load address information (511) for the hypervisor (329) into a secure area (530) within the memory (420) using the security function (330) in the third authority (313). For example, the processing circuit may load the address information (511) into the secure area (530) based on verifying the reliability of the address information (511).
[0108] At operation 709, the processing circuit of the processor (120) may transfer control of the processor (120) to the bootloader (510) based on loading the address information (511) into the secure area (530). For example, the processing circuit may execute an instruction that returns control of the processor (120). For example, the instruction that returns control of the processor (120) may be referred to as eret (exception return). In one embodiment, the processing circuit may execute the eret instruction upon completion of the task according to the instruction executed at operation 701. By executing the eret instruction, the processing circuit may return control of the processor (120) to the state before the instruction was executed at operation 701.
[0109] In operation 711, the processing circuit of the processor (120) may execute a command for utilizing a security function (330). The command may be a command for setting address information (511) as data used for exception processing in the second authority (312). The data used for exception processing in the second authority (312) may be referenced as an EL2 exception table. For example, the command may be referenced as a smc call (secure monitor call).
[0110] In operation 713, the processing circuit of the processor (120) may use the security function (330) in the third authority (313) to set the starting address of the address information (511) in the register. For example, the register may be referenced as VBAR_EL2 (vector base address register for exception level 2). When an exception occurs, the processing circuit may perform exception processing by referencing the starting address in the register.
[0111] At operation 715, the processing circuit of the processor (120) may transfer control of the processor (120) to the bootloader (510) based on setting the starting address of the address information (511) in the register. For example, the processing circuit may execute an instruction that returns control of the processor (120). For example, operation 715 may correspond to operation 711.
[0112] Figure 8 illustrates an example of a processor (120) performing booting.
[0113] Referring to FIG. 8, in operation 801, the processing circuit of the processor (120) may execute a command for utilizing a security function (330) in the first authority (311). The command may be referred to as an smc call. The command may be expressed as a command for loading execution information (e.g., execution information (521)) of the hypervisor (329) into a secure area (530) within the memory (420).
[0114] In one embodiment, the processing circuit can transition the processor (120) from a non-secure world (320) to a secure world (340) by executing an instruction to utilize the security function (330). The processing circuit can transition control of the processor (120) from a first authority (311) to a third authority (313) by executing an instruction to utilize the security function (330).
[0115] In operation 803, the processing circuit of the processor (120) can load execution information (521) for the hypervisor (329) into the secure area (530) within the memory (420). By loading the execution information (521) for the hypervisor (329) into the secure area (530), the processing circuit can execute the hypervisor (329) in the secure area (530), thereby enhancing the security (or safety) of the hypervisor (329).
[0116] According to one embodiment, the processing circuit can perform a process for setting up the hypervisor (329) using the execution information (521).
[0117] At operation 805, the processing circuit of the processor (120) may transfer control of the processor (120) to the first kernel (325) of the first authority (311) based on loading the execution information (521) into the secure area (530). For example, the processing circuit may execute an instruction (e.g., eret) that returns control of the processor (120). For example, operation 805 may correspond to operation 709 of FIG. 7 .
[0118] In operation 807, the processing circuit of the processor (120) may execute a command (e.g., smc call) for utilizing a security function (330) in the first authority (311). The command may be expressed as a command for performing bootstrapping of the hypervisor (329). The bootstrapping of the hypervisor (329) may include a process for setting up a memory management unit (e.g., a second memory management unit (402)) and a process for setting up the hypervisor.
[0119] At operation 809, the processing circuit of the processor (120) may use the security function (330) to transfer control of the processor (120) from the third authority (313) to the second authority (312). The processing circuit may lower the authority from the third authority (313) to the second authority (312). The processing circuit may perform a bootstrap of the hypervisor (329) in the second authority (312).
[0120] In operation 811, the processing circuit of the processor (120) can execute the hypervisor (329) according to the execution information (521). The processing circuit can execute the hypervisor (329) according to the execution information (521) loaded into the security area (530).
[0121] At operation 813, the processing circuit of the processor (120) may transfer control of the processor (120) to the first kernel (325) of the first authority (311) based on the execution of the hypervisor (329) according to the execution information (521). For example, the processing circuit may execute an instruction (e.g., eret) that returns control of the processor (120). For example, operation 813 may correspond to operation 709 of FIG. 7 .
[0122] Figure 9 illustrates an example of a processor (120) executing a hypervisor (329).
[0123] Referring to FIG. 9, in operation 901, the processing circuit of the processor (120) may call the first kernel upon detecting an event for executing the hypervisor (329) while executing the first application (321) with basic privileges (310). For example, the event may include a process requiring higher privileges than the basic privileges (310). For example, the event may include a process requiring a new virtual machine.
[0124] At operation 903, the processing circuit of the processor (120) may execute a command for executing a hypervisor (329) in the first authority (313). The command may be referred to as a hyp call. The processing circuit may call the hypervisor (329).
[0125] According to one embodiment, the execution of the hypervisor (329) may utilize the register illustrated in operation 713 of FIG. 7. The register may include a starting address of address information (511) for the hypervisor (329). Since the address information (511) is loaded into a secure area (530) within the memory (420), the processing circuit may generate an alarm (e.g., a fault). The processing circuit may forward the alarm to the third authority (313). The processing circuit may forward the alarm to the third authority (313).
[0126] In operation 905, the processing circuit of the processor (120) may transmit the alarm to the third authority (313). For example, the processing circuit may provide the security function (330) with a signal for the third authority (313) to use the security function (330).
[0127] According to one embodiment, the processing circuit can set an exception handling routine according to the alarm (or signal) in the security function (330). The processing circuit can execute a function corresponding to the alarm (or signal) in the security function (330).
[0128] At operation 907, the processing circuit of the processor (120) may identify a secure area (530) using the security function (330). For example, the processing circuit may search for a secure area (530) within the memory (420) using the security function (330).
[0129] At operation 909, the processing circuit of the processor (120) may lower control of the processor (120) from the third authority (313) to the second authority (312).
[0130] In operation 911, the processing circuit of the processor (120) can identify an address corresponding to the event of operation 901 using a start address in a register. The start address can indicate an address of address information (511) for the hypervisor (329). The processing circuit can identify an address corresponding to the event in the address information (511) using the start address. For example, the processing circuit can identify an address of executable code for processing the event in the address information (511).
[0131] In operation 913, the processing circuit of the processor (120) may execute the hypervisor (329) according to the execution code of the hypervisor (329) corresponding to the address. The address may be associated with the event. The execution code may be used to execute a process for processing the event. The execution code may be included in the execution information (521) for the hypervisor (329).
[0132] At operation 915, the processing circuit of the processor (120) may transfer control of the processor (120) to the first kernel (325) of the first authority (311) based on executing the hypervisor (329) according to the executable code. For example, the processing circuit may execute an instruction (e.g., eret) that returns control of the processor (120). For example, operation 915 may correspond to operation 711 of FIG. 7.
[0133] At operation 917, the processing circuit of the processor (120) may transfer control of the processor (120) to the first application (321) of the basic authority (310). For example, the processing circuit may execute an instruction (e.g., eret) that returns control of the processor (120). For example, operation 917 may correspond to operation 711 of FIG. 7 .
[0134] In an embodiment according to the present disclosure, a processor (e.g., processor (120)) may be configured to build address information (e.g., address information (511)) of a hypervisor (e.g., hypervisor (329)) into a bootloader (e.g., bootloader (510)) having relatively high security. By having the processor (120) include the address information (511) in the bootloader (510), the security (or safety) of the hypervisor (329) may be enhanced. By loading execution information (e.g., execution information (521)) of the hypervisor (329) into a secure area (e.g., secure area (530)) within a memory (e.g., memory (420)), the security (or safety) of the hypervisor (329) may be enhanced. Additionally, by including the execution information (521) of the hypervisor (329) in an image file for the kernel (e.g., image file (520)), maintenance of the hypervisor (329) can be relatively easy.
[0135] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.
[0136] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by a person having ordinary knowledge in the technical field to which the present disclosure pertains.
[0137] As described above, an electronic device may include a memory. The electronic device may include a processor including processing circuitry. The processor may be configured to utilize an image file for a kernel at a first privilege, a hypervisor at a second privilege higher than the first privilege, and a security function at a third privilege higher than the second privilege. The processor may be configured to execute a command requesting the security function to load address information in response to execution of a bootloader including address information for the hypervisor. The processor may be configured to load the address information into a secure area within the memory using the security function based on verifying the authenticity of the address information using the security function. The processor may be configured to load execution information for the hypervisor within the image file into the secure area using the security function in response to execution of the kernel at the first privilege. The processor may be configured to execute the hypervisor.
[0138] According to one embodiment, the secure area may be configured to provide data loaded into the secure area to the processor in response to a read command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority. The secure area may be configured to change data loaded into the secure area in response to a write command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority.
[0139] In one embodiment, the first permission may be EL (exception level) 1 of the processor. The second permission may be EL2 of the processor. The third permission may be EL3 of the processor.
[0140] In one embodiment, the processor may be configured to generate address translation information in the secure area based on executing the hypervisor in the second authority. The address translation information may be used to translate a virtual address into a physical address.
[0141] In one embodiment, the processor may be configured to set a starting address of the address information in a register of the processor based on loading the address information into the secure area. The processor may be configured to identify the address information using the starting address in the register in the second authority.
[0142] In one embodiment, the processor may be configured to detect an event for executing the hypervisor while executing an application at a lower privilege than the first privilege. The processor may be configured to provide, based on detecting the event, a signal for utilizing the security function to the security function. The processor may be configured to identify, within the address information, an address corresponding to the event using the start address within the register at the second privilege, based on identifying the security area using the security function at the third privilege. The processor may be configured to execute the hypervisor at the second privilege according to the executable code of the hypervisor corresponding to the address. The executable code of the hypervisor corresponding to the address may be included in the execution information for the hypervisor.
[0143] In one embodiment, the image file for the kernel may be vmlinux. The security function may be a secure monitor.
[0144] In one embodiment, the address information for the hypervisor may be a hypervisor vector. The execution information for the hypervisor may include hypervisor text and hypervisor read-only data.
[0145] In one embodiment, the memory may be random-access memory (RAM).
[0146] In one embodiment, the processor may be configured to execute a first virtual machine and a second virtual machine in a second privilege based on the execution of the hypervisor. The processor may be configured to execute a first operating system in the first privilege using the first virtual machine. The processor may be configured to execute a second operating system in the first privilege using the second virtual machine.
[0147] A method performed in an electronic device having a processor and a memory, including a processing circuit as described above, may include an operation of executing a command requesting the security function to load address information for the hypervisor in response to execution of a bootloader including address information for the hypervisor. The method may include an operation of loading the address information into a secure area within the memory using the security function based on verifying the authenticity of the address information using the security function. The method may include an operation of loading execution information for the hypervisor within the image file into the secure area using the security function in response to execution of the kernel in the first authority. The method may include an operation of executing the hypervisor.
[0148] According to one embodiment, the secure area may be configured to provide data loaded into the secure area to the processor in response to a read command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority. The secure area may be configured to change data loaded into the secure area in response to a write command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority.
[0149] In one embodiment, the first permission may be EL (exception level) 1 of the processor. The second permission may be EL2 of the processor. The third permission may be EL3 of the processor.
[0150] In one embodiment, the method may include generating address translation information in the secure area based on executing the hypervisor in the second authority. The address translation information may be used to translate a virtual address into a physical address.
[0151] In one embodiment, the method may include an operation of setting a starting address of the address information in a register of the processor based on loading the address information into the secure area. The method may include an operation of identifying the address information using the starting address in the register in the second authority.
[0152] In one embodiment, the method may include detecting an event for executing the hypervisor while executing an application with a lower privilege than the first privilege. The method may include providing, to the security function, a signal for utilizing the security function based on detecting the event. The method may include identifying, in the address information, an address corresponding to the event using the start address in the register in the second privilege, based on identifying the security area using the security function in the third privilege. The method may include executing the hypervisor in the second privilege according to an execution code of the hypervisor corresponding to the address. The execution code of the hypervisor corresponding to the address may be included in the execution information for the hypervisor.
[0153] In one embodiment, the image file for the kernel may be vmlinux. The security function may be a secure monitor.
[0154] In one embodiment, the address information for the hypervisor may be a hypervisor vector. The execution information for the hypervisor may include hypervisor text and hypervisor read-only data.
[0155] In one embodiment, the memory may be random-access memory (RAM).
[0156] In one embodiment, the method may include executing a first virtual machine and a second virtual machine in a second authority based on the execution of the hypervisor. The method may include executing a first operating system in the first authority using the first virtual machine. The method may include executing a second operating system in the first authority using the second virtual machine.
[0157] As described above, the processor may include a processing circuit configured to utilize an image file for a kernel in a first privilege, a hypervisor in a second privilege higher than the first privilege, and a security function in a third privilege higher than the second privilege. The processing circuit may be configured to execute an instruction requesting loading of address information for the hypervisor using the security function in response to execution of a bootloader including address information for the hypervisor. The processing circuit may be configured to load the address information into a secure area in a memory using the security function based on verifying the authenticity of the address information using the security function. The processing circuit may be configured to load execution information for the hypervisor within the image file into the secure area using the security function in response to execution of the kernel in the first privilege. The processing circuit may be configured to execute the hypervisor.
[0158] According to one embodiment, the secure area may be configured to provide data loaded into the secure area to the processor in response to a read command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority. The secure area may be configured to change data loaded into the secure area in response to a write command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority.
[0159] In one embodiment, the first permission may be EL (exception level) 1 of the processor. The second permission may be EL2 of the processor. The third permission may be EL3 of the processor.
[0160] In one embodiment, the processing circuit may be configured to generate address translation information in the secure area based on the execution of the hypervisor in the second authority. The address translation information may be used to translate a virtual address into a physical address.
[0161] In one embodiment, the processing circuit may be configured to set a starting address of the address information in a register of the processor based on loading the address information into the secure area. The processing circuit may be configured to identify the address information using the starting address in the register in the second authority.
[0162] In one embodiment, the processing circuit may be configured to detect an event for executing the hypervisor while executing an application at a lower privilege than the first privilege. The processing circuit may be configured to provide, based on detecting the event, a signal for utilizing the security function to the security function. The processing circuit may be configured to identify, within the address information, an address corresponding to the event using the start address within the register at the second privilege, based on identifying the security area using the security function at the third privilege. The processing circuit may be configured to execute the hypervisor at the second privilege according to executable code of the hypervisor corresponding to the address. The executable code of the hypervisor corresponding to the address may be included in the execution information for the hypervisor.
[0163] In one embodiment, the image file for the kernel may be vmlinux. The security function may be a secure monitor.
[0164] In one embodiment, the address information for the hypervisor may be a hypervisor vector. The execution information for the hypervisor may include hypervisor text and hypervisor read-only data.
[0165] In one embodiment, the memory may be random-access memory (RAM).
[0166] In one embodiment, the processing circuit may be configured to execute a first virtual machine and a second virtual machine in a second privilege based on the execution of the hypervisor. The processing circuit may be configured to execute a first operating system in the first privilege using the first virtual machine. The processing circuit may be configured to execute a second operating system in the first privilege using the second virtual machine.
[0167] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, electronic devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.
[0168] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.
[0169] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0170] Various embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101) of FIG. 1). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.
[0171] According to one embodiment, the method according to various embodiments disclosed in the present document may be provided as included in a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or may be distributed online (e.g., downloaded or uploaded) via an application store (e.g., Play Store™) or directly between two user devices (e.g., smart phones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0172] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
Claims
1. In electronic devices, memory; and A processor comprising a processing circuit, The processor is configured to use an image file for the kernel in a first privilege, a hypervisor in a second privilege higher than the first privilege, and a security function in a third privilege higher than the second privilege, The above processor: In response to the execution of a bootloader containing address information for the hypervisor, execute a command requesting the security function to load the address information; Based on verifying the reliability of the address information using the above security function, the address information is loaded into a secure area within the memory using the above security function, In response to the execution of the kernel in the first authority, the execution information for the hypervisor in the image file is loaded into the secure area using the security function, and configured to run the above hypervisor, Electronic devices.
2. In claim 1, The security area is set to provide data loaded into the security area to the processor according to a read command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority, and The above security area is set to change data loaded into the security area according to a write command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority. Electronic devices.
3. In claim 1, The above first permission is EL (exception level) 1 of the processor, The second authority is EL2 of the processor, and The third authority is EL3 of the processor, Electronic devices.
4. In claim 1, The processor is configured to generate address translation information in the secure area based on executing the hypervisor in the second authority, and The above address translation information is used to convert a virtual address into a physical address. Electronic devices.
5. In claim 1, The above processor, Based on loading the above address information into the above security area, setting the starting address of the address information in the register of the above processor, and In the second authority, the address information is configured to be identified by using the start address in the register. Electronic devices.
6. In claim 5, The above processor, While executing an application with a lower privilege than the first privilege, detect an event to execute the hypervisor, Based on detecting the above event, providing a signal to the security function to use the above security function, Based on identifying the security area using the security function in the third authority, identifying an address corresponding to the event in the address information using the start address in the register in the second authority, and configured to execute the hypervisor in the second authority according to the execution code of the hypervisor corresponding to the address, and The executable code of the hypervisor corresponding to the address is included in the execution information for the hypervisor. Electronic devices.
7. In claim 1, The image file for the above kernel is vmlinux, and The above security feature is a secure monitor, Electronic devices.
8. In claim 1, The address information for the hypervisor is a hypervisor vector, and The execution information for the hypervisor includes hypervisor text and hypervisor read-only data. Electronic devices.
9. In claim 1, The above memory is RAM (random-access memory), Electronic devices.
10. In claim 1, The above processor, Based on running the above hypervisor, run the first virtual machine and the second virtual machine in the second authority, Using the first virtual machine, the first operating system is executed in the first authority, and Using the second virtual machine, configured to execute a second operating system in the first authority, Electronic devices.
11. In the processor, A processing circuit configured to utilize an image file for a kernel in a first privilege, a hypervisor in a second privilege higher than the first privilege, and a security function in a third privilege higher than the second privilege, The above processing circuit: In response to the execution of a bootloader containing address information for the hypervisor, a command is executed requesting loading of the address information using the security function, Based on verifying the reliability of the address information using the above security function, the address information is loaded into a secure area in memory using the above security function, In response to the execution of the kernel in the first authority, the execution information for the hypervisor in the image file is loaded into the secure area using the security function, and configured to run the above hypervisor, Processor.
12. In claim 11, The security area is set to provide data loaded into the security area to the processor according to a read command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority, and The above security area is set to change data loaded into the security area according to a write command of the processor executed in the second authority and the third authority among the first authority, the second authority, and the third authority. Processor.
13. In claim 11, The above first permission is EL (exception level) 1 of the processor, The second authority is EL2 of the processor, and The third authority is EL3 of the processor, Processor.
14. In claim 11, The processing circuit is configured to generate address translation information in the secure area based on executing the hypervisor in the second authority, and The above address translation information is used to convert a virtual address into a physical address. Processor.
15. In claim 11, The above processing circuit, Based on loading the above address information into the above security area, setting the starting address of the address information in the register of the above processor, and In the second authority, the address information is configured to be identified by using the start address in the register. Processor.
Citation Information
Patent Citations
Method and apparatus for isolating kernel from task
EP4155949A1
A method and apparatus for interrupt handling
KR1020160014647A
Insulation system using single truss structure
KR102556885B1
Hypervisor context switching using a redirection exception vector in processors having more than two hierarchical privilege levels
US20150370591A1
Secure interface control high-level instruction interception for interruption enablement
WO2020182498A1