The invention relates to an
operating system environment construction technology, and discloses an ARM (Advanced RISC Machines) processor-oriented micro-kernel
operating system confidential computing environment construction method, which is characterized in that a hierarchical
system architecture is constructed, a
virtual machine monitor and a confidential domain management monitor are decoupled at an ARM exception level EL2, and the
virtual machine monitor and the confidential domain management monitor run in mutually isolated address spaces. The RMM is used as an independent module for
dynamic loading, a management mechanism of a confidential computing domain is specially used, and the
Hypervisor is only responsible for strategy scheduling, so that the defect that the
Hypervisor is bloated in function in a traditional scheme is overcome. According to the method, the RMM is loaded through the security startup process during startup, the confidential
virtual machine is dynamically created during running,
mirror image security
verification, memory
encryption and other mechanisms are integrated, and finally the
security domain is destroyed after the application is finished. The method has the advantages that a flexible and safe confidential computing environment conforming to the minimum privilege principle is provided for the
microkernel system, and the method is particularly suitable for embedded scenes with high safety requirements such as
the Internet of Things and industrial control.