Dynamic load IPsec optimization module and application method in embedded system
Through the dynamic load IPsec optimization module, the DMA interface is used to obtain data and adjust the encryption mode through the timeout timer and status register, which solves the problem of inefficient encryption processing in embedded systems, and realizes the rational allocation of resources and flexibility of encryption processing.
Patent Information
- Application Number
- CN202510349757.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-07-11
AI Technical Summary
The IPsec protocol lacks flexibility in embedded systems, resulting in inefficient encryption processing and unreasonable resource utilization.
The dynamic load IPsec optimization module is adopted to obtain data through the DMA interface to the core processor, the timeout timer times to time the data, the status register adjusts the encryption mode according to the timing results, and the AES encryption engine performs IPsec protocol processing in the target mode.
It realizes the flexibility of encryption processing, improves encryption processing efficiency and rationally allocates system resources.
Smart Images

Figure CN120296762A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network information security, and particularly to a dynamic load IPsec optimization module and an application method in an embedded system. Background Art
[0002] In the field of information security, the IPsec (Internet Protocol Security) protocol, as a key technology for ensuring network communication security, its performance optimization is crucial for improving data transmission efficiency and security. Especially in embedded systems, due to limited resources and the need to process a large amount of data traffic, the efficient implementation of the IPsec protocol has become an urgent problem to be solved. Currently, the main method to solve the performance optimization problem of the IPsec protocol in embedded systems is to adopt a fixed encryption mode and encryption engine. This method processes all data streams through preset encryption configurations. However, the fixed encryption mode lacks flexibility and cannot dynamically adjust the encryption policy according to the actual load situation, resulting in problems such as low encryption processing efficiency and unreasonable resource occupancy.
[0003] In the related technologies at the present stage, there are technical problems in the performance optimization of the IPsec protocol in embedded systems, such as lack of flexibility, resulting in low encryption processing efficiency and unreasonable resource occupancy. Summary of the Invention
[0004] This application provides a dynamic load IPsec optimization module and an application method in an embedded system. By using technical means such as obtaining data to the core processor through the DMA interface, the timeout timer timing the DMA data, the status register adjusting to the target encryption mode according to the timing result, and the AES encryption engine executing the IPsec protocol processing according to the target mode, the technical effects of realizing the flexibility of encryption processing, improving the encryption processing efficiency, and realizing the reasonable allocation of system resources are achieved.
[0005] This application provides a dynamic load IPsec optimization module, including: an AES encryption engine, which executes encryption processing and supports a first encryption mode and a second encryption mode; a timeout timer, which is triggered along with the AES encryption engine and executes data counting and overflow interruption; a status register, which acts on the AES encryption engine and is used for dynamic control adjustment of the mode status; an interrupt controller, which responds to the timeout timer and executes edge-triggered interruption.
[0006] In a possible implementation manner, the first encryption mode is the full mode, the second encryption mode is the lightweight mode, and the encryption mode is configured according to the DMA data volume, wherein the DMA data is obtained through DMA interface interaction.
[0007] The present application also provides an application method of a dynamic load IPsec optimization module in an embedded system, including: obtaining DMA data to a core processor through a DMA interface and performing data reading and writing; the timeout timer timing the data volume of the read and written DMA data to determine a timing result; the status register determining a target encryption mode according to the timing result, where the target encryption mode is the first encryption mode or the second encryption mode; the AES encryption engine performing data IPsec protocol processing based on the target encryption mode in response to the target encryption mode.
[0008] In a possible implementation manner, the application method of the timeout timer includes: initializing the timeout timer, where initializing is to clear the count value and set a timeout threshold; receiving a task start signal sent by the AES encryption engine, starting a counter in the timeout timer to measure the data volume of the DMA data to determine a count value; performing task management according to the count value.
[0009] In a possible implementation manner, the following processing is performed: determining whether the count value times out, and performing dynamic load encryption management according to the determination result; where if the count value is greater than or equal to the timeout threshold, an interrupt signal is generated; the interrupt controller performs dynamic load encryption management in response to the interrupt signal; the counter is reset to enter a standby state.
[0010] In a possible implementation manner, the following processing is performed: when the count value of the counter is in a non-increasing state and the count value is less than the timeout threshold, a task completion signal is generated; according to the task completion signal, the counter stops and is cleared, and is reset to enter a standby state.
[0011] In a possible implementation manner, the following processing is performed: introducing a load-aware scheduler, and the application method of the load-aware scheduler includes: triggering the load-aware scheduler according to the interrupt signal, clearing an interrupt flag and obtaining a load and a queue according to the count value of the DMA data; setting a load threshold and a queue threshold, judging the load and the queue to determine the target encryption mode.
[0012] In a possible implementation manner, the following processing is performed: establishing connections between the load-aware scheduler, the status register, the interrupt controller, and the core processor; where the load-aware scheduler performs response interrupt control and target encryption mode switching control by performing load monitoring.
[0013] In a possible implementation manner, the following processing is performed: if the load is less than or equal to the load threshold and the queue is less than or equal to the queue threshold, triggering the first encryption mode; writing the first encryption mode into the status register.
[0014] In a possible implementation, the following processing is performed: If the load is greater than the load threshold, or the queue is greater than the queue threshold, trigger QoS condition judgment; wherein, the QoS condition judgment includes: If QoS == 1 is satisfied, trigger the second encryption mode and write the second encryption mode into the status register; if QoS == 1 is not satisfied, perform latency processing on the DMA data.
[0015] It is intended to propose a dynamic load IPsec optimization module and an application method in an embedded system through this application. First, according to the DMA interface, DMA data is obtained to the core processor for data reading and writing. Then, the timeout timer times the amount of the read and written DMA data to determine the timing result. Furthermore, the status register responds to the timing result, and the status is adjusted to determine the target encryption mode, where the target encryption mode is the first encryption mode or the second encryption mode. Finally, the AES encryption engine responds to the target encryption mode and performs IPsec protocol processing on the data based on the target encryption mode. The technical effects of realizing the flexibility of encryption processing, improving the encryption processing efficiency, and realizing the reasonable allocation of system resources are achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings of the embodiments of the present invention will be briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the operations in the front or below do not necessarily need to be executed precisely in sequence. On the contrary, according to the need, various steps can be executed in reverse order or simultaneously. At the same time, other operations can also be added to these processes, or one or several operations can be removed from these processes.
[0017] Figure 1 It is a schematic flowchart of an application method of a dynamic load IPsec optimization module in an embedded system provided by an embodiment of the present application.
[0018] Figure 2 It is a schematic flowchart of the working process of the timeout timer in an application method of a dynamic load IPsec optimization module in an embedded system provided by an embodiment of the present application.
[0019] Figure 3 It is a schematic structural diagram of introducing a load-aware scheduler in an application method of a dynamic load IPsec optimization module in an embedded system provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] The above description is only an overview of the technical solution of this application. In order to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this application more obvious and understandable, the following specific embodiments of this application are specifically exemplified.
[0021] In order to make the purpose, technical solution and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of this application.
[0022] In the following description, "some embodiments" are involved, which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict. The terms "first / second" involved are only used to distinguish similar objects and do not represent a specific order for the objects. The terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application.
[0023] The embodiment of this application provides a dynamic load IPsec optimization module, and the module includes:
[0024] An AES encryption engine, which performs encryption processing and supports a first encryption mode and a second encryption mode.
[0025] Specifically, the AES encryption engine is the core component of the encryption processing. The encryption engine supports at least two encryption modes (the first encryption mode and the second encryption mode), which allows for flexible selection of the encryption strength and processing speed according to network load or other conditions.
[0026] A timeout timer, which is triggered along with the AES encryption engine to perform data counting and overflow interruption.
[0027] Specifically, the timeout timer works in cooperation with the AES encryption engine to monitor the progress of data processing. If the data processing time exceeds a preset threshold, the timeout timer will trigger an overflow interruption to timely detect and handle potential performance bottlenecks.
[0028] A status register that acts on the AES encryption engine and is used for dynamic control and adjustment of the mode status.
[0029] Specifically, the status register is used to store the current status information of the AES encryption engine, including the currently used encryption mode. By dynamically adjusting the values in the status register, flexible switching of the encryption mode can be achieved to adapt to different network communication requirements.
[0030] An interrupt controller that responds to the timeout timer and performs edge-triggered interrupts.
[0031] Specifically, the interrupt controller is responsible for responding to the interrupt signal from the timeout timer. When the timeout timer triggers an interrupt, the interrupt controller executes the corresponding interrupt handler, including restarting the encryption process or performing other error recovery operations.
[0032] In a possible implementation, the first encryption mode is the full mode, and the second encryption mode is the lightweight mode. The encryption mode is configured according to the DMA data volume, where the DMA data is obtained through the DMA interface interaction.
[0033] Specifically, the first encryption mode is the full mode, that is, the first encryption mode is comprehensive and detailed, including all encryption steps and features, providing the highest security but with a slower speed. For example, using the AES-256 encryption algorithm and HMAC-SHA256 integrity check. The second encryption mode is the lightweight mode, that is, the second encryption mode is a simplified version, omitting some encryption steps or features to improve the processing speed or reduce resource consumption, but with slightly lower security. For example, using the AES-128 encryption algorithm and reusing the key, skipping some integrity check steps.
[0034] The DMA interface is part of the dynamic load IPsec optimization module. The dynamic load IPsec optimization module directly reads data from the memory through DMA technology and transfers it to the AES encryption engine. The DMA data volume refers to the size of the data transmitted to the dynamic load IPsec optimization module through the DMA interface. If the data volume is small (such as only 16 bytes), the full mode can be selected because the data volume is small, the encryption time is short, and it will not affect real-time performance, while ensuring high security. If the data volume is large (such as 128 bytes), the encryption time of the full mode may time out, and at this time, it is necessary to switch to the lightweight mode to improve the encryption speed and ensure real-time performance.
[0035] In the above, a dynamic load IPsec optimization module according to an embodiment of the present invention has been described in detail. Next, with reference to Figures 1 - 3 Describe an application method of a dynamic load IPsec optimization module according to an embodiment of the present invention in an embedded system. AsFigure 1 As shown, a method for applying a dynamic load IPsec optimization module in an embedded system includes:
[0036] Step S100, obtaining DMA data to a core processor through a DMA interface and performing data reading and writing; Step S200, the timeout timer timing the amount of the DMA data read and written to determine a timing result; Step S300, the status register adjusting the status to determine a target encryption mode in response to the timing result, where the target encryption mode is the first encryption mode or the second encryption mode; Step S400, the AES encryption engine performing IPsec protocol processing on the data based on the target encryption mode in response to the target encryption mode.
[0037] Specifically, after data is transmitted to the dynamic load IPsec optimization module through the DMA interface, the dynamic load IPsec optimization module processes the data according to the current encryption mode. The timeout timer records the time from the start of data processing to the completion of processing. If the execution time of the encryption task exceeds a preset threshold (such as 5 milliseconds), it is considered a timeout. There are two cases for the timing result: if the encryption task is completed within the preset threshold, the timing result is "not timed out"; if the encryption task still has not been completed after exceeding the preset threshold, the timing result is "timed out". The status register is used to record the current encryption mode (full mode or lightweight mode) and the timeout flag. When the timing result of the timeout timer is "timed out", the status register records the timeout flag and decides whether to adjust the encryption mode according to the current encryption mode. If the current is the full mode and timed out, the mode is switched to the lightweight mode. The AES encryption engine selects a corresponding encryption algorithm according to the encryption mode (the first encryption mode or the second encryption mode) recorded in the status register. The embodiments of the present application adopt technical means such as obtaining data to the core processor through the DMA interface, the timeout timer timing the DMA data, the status register adjusting to the target encryption mode according to the timing result, and the AES encryption engine performing IPsec protocol processing according to the target mode, achieving the technical effects of realizing the flexibility of encryption processing, improving the encryption processing efficiency, and realizing the reasonable allocation of system resources.
[0038] As Figure 2 shown, in a possible implementation manner, the application method of the timeout timer includes: performing initialization processing on the timeout timer, where the initialization is to clear the count value and set a timeout threshold; receiving a task start signal sent by the AES encryption engine, starting a counter in the timeout timer to measure the amount of the DMA data and determining a count amount; performing task management according to the count amount.
[0039] Specifically, before the timeout timer starts working, its count value is cleared to ensure that each timing starts from zero, avoiding the counter retaining the count value of the previous time. According to the requirements of the system, a timeout threshold is set. For example, in the V2X (Vehicle-to-Everything) scenario, the timeout threshold can be set to 5 milliseconds (5 ms). That is, if the execution time of the encryption task exceeds 5 milliseconds, the task is considered timed out.
[0040] When the AES encryption engine starts processing a data packet, it sends a "task start" signal. The role of this signal is to notify the timeout timer to start timing. The task start signal is a synchronous signal to ensure the synchronization of the operations of the timeout timer and the AES encryption engine. There is a counter inside the timeout timer for recording time. When the task start signal is received, the counter starts timing. The clock frequency of the counter is fixed, for example, 1 MHz, that is, the counter counts 1,000,000 times per second, and the time interval for each count is 1 microsecond (1 μs).
[0041] The timeout threshold is set in units of time, such as 5 milliseconds (5 ms). Since the clock frequency of the counter is fixed, time can be converted into counts. Specifically: 1 second = 1,000,000 counts, 1 millisecond = 1,000 counts. Therefore, 5 milliseconds = 5,000 counts. The function of the counter is to measure time by counting. When the count value of the counter reaches the set threshold (such as 5,000 counts), it means that the time has reached the timeout threshold.
[0042] Based on the count value, it is decided whether to manage the current task. If the count value (time) is within the set timeout threshold (such as within 5 milliseconds), it indicates that the current encryption task is executed normally and can continue to be processed according to the current encryption mode.
[0043] As Figure 2 shown, in a possible implementation, according to the count value, performing task management may further include: determining whether the count value times out, and performing dynamic load encryption management according to the determination result; wherein, if the count value is greater than or equal to the timeout threshold, an interrupt signal is generated; the interrupt controller responds to the interrupt signal and performs dynamic load encryption management; the counter is reset and enters the standby state.
[0044] Specifically, if the count value is greater than or equal to the timeout threshold (e.g., 5,000 times), it indicates that the processing time of the current task has exceeded the set timeout threshold, and dynamic load encryption management needs to be performed. When the count value reaches or exceeds the timeout threshold (5,000 times), the timeout timer generates an interrupt signal. This interrupt signal is a hardware signal used to notify the system that the current task has timed out and needs to be processed. The interrupt signal is sent to the interrupt controller, and the interrupt controller responds to the interrupt signal to determine whether the encryption mode needs to be adjusted. For example: if the current is the full mode (AES-256+HMAC-SHA256) and the task times out, the encryption mode is switched to the lightweight mode (AES-128+reused key) to improve the encryption speed. After completing the dynamic load encryption management, the counter is reset, that is, the count value is cleared. After reset, the counter enters the standby state, waiting for the next task start signal. When a new task start signal is received, the counter will start timing again.
[0045] As Figure 2 shown, in a possible implementation, when the count value of the counter is in a non-increasing state and the count value is less than the timeout threshold, a task completion signal is generated; according to the task completion signal, the counter stops and is cleared, and is reset to enter the standby state.
[0046] Specifically, the system continuously monitors the count value of the counter. If the count value no longer increases, it indicates that the AES encryption engine has completed the encryption process of the current data packet and no further timing is required. At the same time, the count value is less than the timeout threshold, indicating that the task has been completed within the set time and has not timed out. When the count value is in a non-increasing state and less than the timeout threshold, the system generates a task completion signal. This signal is a hardware signal used to notify that the current task has been successfully completed. After receiving the task completion signal, the counter stops timing, and the count value of the counter is cleared to prepare for the next task. After the counter is reset, it enters the standby state, waiting for the next task start signal. When a new task start signal is received, the counter will start timing again.
[0047] As Figure 3 shown, in a possible implementation, a load-aware scheduler is introduced. The application method of the load-aware scheduler includes: triggering the load-aware scheduler according to the interrupt signal, clearing the interrupt flag, and obtaining the load and queue according to the count value of the DMA data; setting a load threshold and a queue threshold, judging the load and queue, and determining the target encryption mode.
[0048] Specifically, when the counter of the timeout timer reaches or exceeds the timeout threshold, an interrupt signal is generated. This interrupt signal is sent to the interrupt controller, which passes the interrupt signal to the load-aware scheduler. The load-aware scheduler responds to the interrupt signal and executes the task management logic.
[0049] After the load-aware scheduler is triggered, it clears the interrupt flag to avoid repeatedly responding to the same interrupt signal. The count value of the DMA data refers to the amount of data transmitted to the dynamic load IPsec optimization module through the DMA interface during the timeout timer's timing. The count value of the DMA data is used to estimate the data processing pressure (load) of the current system. For example, if the count value is high, it indicates that the current system has a large load. The queue refers to the number of data packets waiting to be processed. The load-aware scheduler checks the length of the data packet queue to determine the processing pressure of the current system.
[0050] A load threshold is set, such as 80% of the maximum load. If the current load exceeds this threshold, it indicates that the system is in a high-load state. A queue threshold is set, such as the queue length exceeding 50 data packets. If the current queue length exceeds this threshold, it indicates that the system has a large processing pressure.
[0051] Based on the actual situation of the load and the queue, the target encryption mode is determined. For example, if the current load exceeds the load threshold (e.g., 80%) or the queue length exceeds the queue threshold (e.g., 50 data packets), the load-aware scheduler switches the encryption mode to the lightweight mode to improve the encryption speed and meet the real-time requirements.
[0052] As Figure 3 As shown, in a possible implementation, connections are established between the load-aware scheduler, the status register, the interrupt controller, and the core processor; wherein, the load-aware scheduler performs load monitoring, response interrupt control, and target encryption mode switching control.
[0053] Specifically, the load-aware scheduler is a software module running on the core processor, responsible for dynamically adjusting the encryption mode to optimize system performance. The core processor is the core of the system, running the load-aware scheduler software module, responsible for processing interrupt signals and adjusting the encryption mode.
[0054] The connection relationships are as follows: The load-aware scheduler can read the content of the status register to obtain the current encryption mode and timeout flag, and can modify the content of the status register to switch the encryption mode. The load-aware scheduler can respond to the interrupt signals passed by the interrupt controller, and can clear the interrupt flag to avoid repeatedly responding to the same interrupt signal. The load-aware scheduler is a software module running on the core processor. The core processor provides a running environment for the load-aware scheduler, is responsible for executing the logic of the load-aware scheduler, handling interrupt signals, and interacting with the dynamic load IPsec optimization module.
[0055] When the counter of the timeout timer reaches or exceeds the timeout threshold, an interrupt signal is generated. The interrupt controller captures the interrupt signal and passes it to the core processor. The load-aware scheduler running on the core processor responds to the interrupt signal, clears the interrupt flag, dynamically evaluates the system load by monitoring the count value and queue length of the DMA data, and determines whether to adjust the encryption mode based on the current load condition and queue length. The load-aware scheduler switches the encryption mode by modifying the mode bit (such as Bit0) in the status register. For example: changing the mode bit from 0 (full mode) to 1 (lightweight mode); changing the mode bit from 1 (lightweight mode) to 0 (full mode).
[0056] In a possible implementation, if the load is less than or equal to the load threshold and the queue is less than or equal to the queue threshold, the first encryption mode is triggered; and the first encryption mode is written into the status register.
[0057] Specifically, when and only when the load is less than or equal to the load threshold and the queue is less than or equal to the queue threshold, the load-aware scheduler will trigger the first encryption mode. That is, in the case of low load and low queue pressure, the system will select a high-security encryption mode. The load-aware scheduler writes the first encryption mode into the status register by modifying the mode bit in the status register. In this way, the AES encryption engine of the dynamic load IPsec optimization module will switch to the full mode according to the mode bit in the status register. For example, it will perform AES-256 encryption and HMAC-SHA256 integrity check.
[0058] In a possible implementation, if the load is greater than the load threshold, or the queue is greater than the queue threshold, QoS condition judgment is triggered; where the QoS condition judgment includes: if QoS == 1 is satisfied, the second encryption mode is triggered and the second encryption mode is written into the status register; if QoS == 1 is not satisfied, delay processing is performed on the DMA data.
[0059] Specifically, if the load of the current system exceeds a pre-set load threshold, it indicates that the system is in a high-load state. If the length of the current data packet queue exceeds a pre-set queue threshold, it indicates that the system has a relatively high processing pressure. When the load or the queue exceeds the threshold, the load-aware scheduler will further determine whether the current task meets the QoS (Quality of Service) conditions. The QoS conditions are used to distinguish the importance and real-time requirements of the data. Among them, QoS == 1 means that the current task has a high priority and needs to meet strict real-time requirements; otherwise, it means that the priority of the current task is relatively low and a certain delay can be tolerated.
[0060] If the current task meets QoS == 1, it indicates that the task has a high priority and needs to ensure a certain degree of real-time performance even under high load. The load-aware scheduler will trigger the second encryption mode (lightweight mode) to improve the encryption speed and meet the real-time requirements. The load-aware scheduler switches the encryption mode to the lightweight mode by modifying the mode bit in the status register. If the current task does not meet QoS == 1, it indicates that the priority of the task is relatively low and a certain delay can be tolerated. The load-aware scheduler performs delay processing on the DMA data. For example, the current task is placed in the waiting queue and processed after the system load decreases.
[0061] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, however, any number of different modules can be used and run on the user terminal and / or the server. The various units and modules included are only divided according to the functional logic, but are not limited to the above division as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.
[0062] The above specific implementation manners do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present application shall be included within the protection scope of the present application. In some cases, the actions or steps recorded in the present application can be executed in a different order from that in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multi-tasking and parallel processing are also possible or may be advantageous.
Claims
1. A dynamic load IPsec optimization module, characterized in that, The module includes: An AES encryption engine that performs encryption processing and supports a first encryption mode and a second encryption mode; A timeout timer that is triggered along with the AES encryption engine and performs data counting and overflow interrupt; A status register that acts on the AES encryption engine and is used for dynamic control adjustment of the mode status; An interrupt controller that responds to the timeout timer and performs edge-triggered interrupt.
2. The dynamic load IPsec optimization module according to claim 1, characterized in that The first encryption mode is the full mode, and the second encryption mode is the lightweight mode. The encryption mode is configured according to the DMA data volume. Among them, the DMA data is obtained through DMA interface interaction.
3. A method for applying a dynamic load IPsec optimization module in an embedded system, characterized in that, The method is implemented according to a dynamic load IPsec optimization module according to any one of claims 1-2. The method includes: Obtain DMA data to the core processor through the DMA interface and perform data reading and writing; The timeout timer times the data volume of the read and written DMA data to determine the timing result; The status register responds to the timing result, and the status is adjusted to determine the target encryption mode, where the target encryption mode is the first encryption mode or the second encryption mode; The AES encryption engine responds to the target encryption mode and performs data IPsec protocol processing based on the target encryption mode.
4. The application method of a dynamic load IPsec optimization module in an embedded system according to claim 3, characterized in that, The application method of the timeout timer includes: Perform initialization processing on the timeout timer, where the initialization is to clear the count value and set the timeout threshold; Receive the task start signal sent by the AES encryption engine, start the counter in the timeout timer, measure the data volume of the DMA data, and determine the count value; Perform task management according to the count value.
5. The application method of a dynamic load IPsec optimization module in an embedded system according to claim 4, wherein Judge whether the count value times out, and perform dynamic load encryption management according to the judgment result; Among them, if the count value is greater than or equal to the timeout threshold, an interrupt signal is generated; The interrupt controller responds to the interrupt signal and performs dynamic load encryption management; The counter is reset and enters the standby state.
6. The application method of a dynamic load IPsec optimization module in an embedded system as described in claim 5, characterized in that When the count value of the counter is in a non-increasing state and the count value is less than the timeout threshold, a task completion signal is generated; According to the task completion signal, the counter stops and is cleared, and is reset to enter the standby state.
7. The application method of a dynamic load IPsec optimization module in an embedded system according to claim 6, characterized in that A load-aware scheduler is introduced. The application method of the load-aware scheduler includes: Trigger the load-aware scheduler according to the interrupt signal, clear the interrupt flag, and obtain the load and queue according to the count value of the DMA data; Set the load threshold and queue threshold, judge the load and queue, and determine the target encryption mode.
8. The application method of a dynamic load IPsec optimization module in an embedded system according to claim 7, characterized in that, Establish the connection between the load-aware scheduler and the status register, interrupt controller, and core processor; Among them, the load-aware scheduler performs load monitoring to perform response interrupt control and target encryption mode switching control.
9. The application method of a dynamic load IPsec optimization module in an embedded system according to claim 7, characterized in that, If the load is less than or equal to the load threshold and the queue is less than or equal to the queue threshold, trigger the first encryption mode; Write the first encryption mode into the status register.
10. The application method of a dynamic load IPsec optimization module in an embedded system as described in claim 9, characterized in that, If the load is greater than the load threshold, or the queue is greater than the queue threshold, trigger QoS condition judgment; Among them, the QoS condition judgment includes: If QoS == 1 is satisfied, trigger the second encryption mode and write the second encryption mode into the status register; If QoS == 1 is not satisfied, perform latency processing on the DMA data.
Citation Information
Patent Citations
Dual mode AES implementation to support single and multiple AES operations
CN101507116A
Device for supporting high-performance safety protocol
CN101997834A
Encryption and decryption architecture and method, processor and server
CN115549911A
Communication content security encryption method
CN119071074A
Serial communication loading monitor of the serialcommunication system and method thereof
KR1020000066247A