A hardware grouping-based password task dynamic scheduling method and system
By grouping and dynamically scheduling cryptographic devices in hardware and using DNN models to predict changes in task load, the problem of uneven resource allocation in existing technologies is solved, achieving efficient matching and compatibility between tasks and devices, and improving task processing efficiency.
Patent Information
- Application Number
- CN202510539257.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-04-27
AI Technical Summary
Existing cryptographic task scheduling methods do not fully utilize the hardware information and processing capabilities of cryptographic devices, resulting in uneven resource allocation, overload of high-performance devices and idleness of low-performance devices, and scheduling delays or service quality degradation when the task size changes.
Cryptographic devices are classified and grouped using a hardware-based grouping method. A DNN model is used to predict the trend of task volume changes, and a dynamic scheduling algorithm is combined to optimize task allocation, thereby meeting the requirements of real-time performance, security, and computing power.
This achieves efficient matching of cryptographic tasks with devices, improves task processing efficiency, reduces resource waste, and ensures timely completion of tasks at different times and device compatibility.
Smart Images

Figure CN120415813B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data encryption, and in particular to a hardware grouping-based cryptographic task dynamic scheduling method and system. BACKGROUND
[0002] With the wide application of cryptographic technology, cryptographic task scheduling is facing increasingly complex challenges in the fields of government affairs, finance, Internet of Things, etc. The existing cryptographic task scheduling methods include:
[0003] A multi-level scheduling method based on task deadline, which usually takes task deadline as the core indicator, converts task urgency into priority, and realizes task allocation through a multi-level scheduling model, which has good scheduling effect for scenes with high time efficiency requirements; but it ignores resource load balancing, leading to overload of high-performance devices and idling of low-performance devices, and is sensitive to task size changes, so sudden high-load tasks can easily cause scheduling delays.
[0004] A scheduling method based on genetic algorithm and particle swarm optimization, which searches for the optimal scheduling scheme through global intelligence algorithm, and optimizes task allocation through selection, crossover and mutation operations of genetic algorithm; particle swarm algorithm iteratively updates the scheduling strategy through individual and group optimal solutions, which is usually used for complex multi-objective optimization problems; but the calculation cost is high, especially when the task size is large, the convergence speed is slow, which affects the real-time performance.
[0005] A dynamic priority scheduling method, which dynamically adjusts the priority according to the real-time system load, task security level and deadline, usually allocates high-security-level tasks to physical cryptographic machines and ordinary tasks to virtual cryptographic machines, and does not fully consider the needs of tasks at all levels, making it difficult to allocate resources fairly in a multi-tenant environment, and the quality of service decreases when facing high-frequency tasks.
[0006] As can be seen, the commonly used cryptographic task scheduling methods only consider the real-time load information of cryptographic tasks and devices, but do not fully utilize the hardware information and processing capacity of cryptographic devices to assist the efficient implementation of cryptographic task scheduling. SUMMARY
[0007] In order to solve the problems existing in the prior art, the present application provides a hardware grouping-based cryptographic task dynamic scheduling method and system, which solves the technical problem that the prior art only considers the real-time load information of cryptographic tasks and devices, but does not fully utilize the hardware information and processing capacity of cryptographic devices to assist the efficient implementation of cryptographic task scheduling.
[0008] A hardware grouping-based cryptographic task dynamic scheduling method, comprising:
[0009] Step 1: classify cryptographic devices according to their hardware characteristics;
[0010] Step 2: grouping the classified cryptographic devices according to the historical task processing data of the cryptographic devices;
[0011] Step 3: constructing a DNN model and training to obtain a cryptographic task classification model;
[0012] Step 4: determining the cryptographic device category corresponding to the to-be-processed cryptographic task by using the cryptographic task classification model;
[0013] Step 5: storing the cryptographic task classification of the cryptographic devices of different categories, and respectively adopting a dynamic scheduling algorithm for task scheduling.
[0014] Further, the step 1 comprises detecting the hardware characteristics of the cryptographic devices through a CPUID instruction set, combining PCIe device capability negotiation, dynamically constructing a hardware capability matrix of the cryptographic devices, classifying the cryptographic devices, and the classification types of the cryptographic devices include national secret type, general type, edge type and GPU heterogeneous type.
[0015] Further, the step 2 comprises:
[0016] Step 2.1: setting a first unit time and a second unit time, and successively analyzing and predicting the change trend of the task quantity in the second unit time according to the historical task processing data of the cryptographic devices in different unit times;
[0017] Step 2.2: according to the change trend of the task quantity in the second unit time, dividing the first unit time into multiple periods including peak period, trough period and ordinary period, and grouping according to the period in which the cryptographic device is located.
[0018] Further, the step 2.1 comprises: obtaining the historical task processing data of various types of cryptographic devices, setting a first unit time; dividing and performing data analysis and processing on the historical task processing data of various types of cryptographic devices by using the first unit time, and giving the change trend of the task quantity of each first unit time except for the burst situation; setting a second unit time, the first unit time includes multiple second unit times, dividing and performing data analysis and processing on the historical task processing data of the first unit time by using the second unit time, and giving the change of the task quantity in each second unit time in the first unit time, that is, the task quantity processed in each second unit time accounts for how much of the task quantity in each first unit time, so as to further predict the change trend of the task quantity in the second unit time in combination with the change trend of the task quantity in the first unit time.
[0019] Further, the step 2.2 comprises: according to the second unit time task quantity change trend, dividing the first unit time into multiple periods including peak period, trough period and ordinary period, determining the duration of the trough period and the ordinary period, if the duration of the trough period is long, grouping the cryptographic devices of each type based on the task quantity of each second unit time in the trough period, ensuring that the cryptographic devices in each group can complete the task quantity per hour in the trough period, and when the ordinary period and the peak period arrive, merging each group of cryptographic devices according to the ratio of the task quantity of the ordinary period and the peak period to the task quantity of the trough period in the second unit time, if the average value of the second unit time cryptographic task quantity of the ordinary period is twice the average value of the second unit time cryptographic task quantity of the trough period, then the original two groups of cryptographic devices are temporarily grouped as a group of cryptographic devices for task processing, if the average value of the second unit time cryptographic task quantity of the peak period is three times the average value of the second unit time cryptographic task quantity of the trough period, then the original three groups of cryptographic devices are temporarily grouped as a group of cryptographic devices for task processing.
[0020] The task quantity is measured by the required computing power of the task, so that the grouping of each different cryptographic device matches the corresponding task quantity. In order to improve the processing speed of concurrent tasks, and when a group of cryptographic devices fails to be unavailable, it can be replaced in time by other groups of cryptographic devices of the same type without worrying too much about the problem of computing power compatibility, ensuring that the cryptographic task is completed in time and efficiently.
[0021] Further, step 2 also comprises managing the cryptographic devices:
[0022] When a new cryptographic device is registered, its computing power indicators, including signature speed, memory bandwidth, etc., need to be recorded; at the same time, the classification of cryptographic devices of the same type or with similar computing power indicators is checked, and then the cryptographic devices are further divided into the corresponding groups based on the classification;
[0023] During the operation of the cryptographic devices, the load rate, queue depth and health status of each group are collected in real time; the load rate is set with an upper load limit and a lower load limit; if the load rate of the first group of cryptographic devices exceeds the upper load limit, it means that the task quantity of the first group at this moment exceeds the expected value, then a cryptographic device is selected from the idle cryptographic device group of the same type and temporarily labeled, and temporarily coded into the first group, so that the load rate of the first group is lower than the upper load limit, avoiding the impact of overloading of the cryptographic devices on the timely completion of the task. When the load rate of the first group is lower than the lower load limit, it means that the task quantity of the first group at this time can be completely completed by the original cryptographic devices in the first group, at this time, the temporarily coded cryptographic device is removed from the temporary label and coded back to its corresponding original group.
[0024] Further, the step 3 comprises: extracting information of each type of cryptographic task involved, including real-time information, importance information, security information and cooperativity information with other tasks, according to historical task processing data, and then establishing a task feature label library including real-time, computing power requirement and importance, collecting the feature labels of each cryptographic task and determining the corresponding cryptographic device type, so as to make a data set to train a DNN model to obtain a cryptographic task classification model, which can quickly determine the corresponding cryptographic device type when receiving a cryptographic task. The DNN model comprises an input layer, a feature embedding layer, an attention layer, a full connection layer and an output layer.
[0025] Further, the dynamic scheduling algorithm comprises: acquiring the load condition of each group of cryptographic devices in real time, the load condition comprising a cryptographic task being processed and a cryptographic task queue to be processed, predicting the response time of the cryptographic device group according to the load condition of the cryptographic device group, and integrating the feature labels of the cryptographic tasks to be scheduled into a vector matrix, and sorting and packing scheduling the cryptographic devices according to the following formula.
[0026]
[0027] In the formula, A ij represents the priority value of the jth cryptographic task allocated to the ith cryptographic device, i=0, 1, 2, 3 respectively representing that the cryptographic task belongs to the national secret type, the edge type, the general type and the GPU heterogeneous type, a is the real-time requirement value, b is the computing power requirement value, c is the security requirement value, α is the real-time weight, β is the computing power weight, and γ is the security weight.
[0028] Further, the dynamic scheduling algorithm further comprises: satisfying the computing power value requirement:
[0029] satisfying the real-time requirement:
[0030] In the formula, is the computing power value of A ij , C i is the average value of the cryptographic computing power of the second unit time of the ith cryptographic device in the current period, n is the number of cryptographic task items packed into the same group, is the completion time limit value of A ij , T m is the response time of the cryptographic device group m corresponding to A ij .
[0031] The hardware grouping-based password task dynamic scheduling system comprises a device classification module, a device grouping module, a model training module, a task classification module and a task scheduling module.
[0032] The beneficial effects of the present application include:
[0033] 1. According to the hardware characteristics, the password devices are classified, and then the password devices are further grouped according to the task quantity and processing efficiency, so that the matching degree of the password task and the corresponding password device is higher when the password task is scheduled subsequently.
[0034] 2. The password devices are grouped by fully considering the distribution of password tasks in different time periods, so that when the task quantity is small, too many password device resources are not called to cause resource waste, and when the task quantity is large, the temporary grouping can be used to respond in time, so as to ensure the task processing efficiency and the compatibility between different groups of password devices.
[0035] 3. When the password task is processed, the real-time performance, security and computing power requirements are fully considered, so that the task scheduling and the password devices are fully matched. BRIEF DESCRIPTION OF DRAWINGS
[0036] Figure 1 A flowchart of a hardware grouping-based password task dynamic scheduling method according to an embodiment of the present application. DETAILED DESCRIPTION
[0037] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme of the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments of the present application. Therefore, the detailed description of the embodiments of the present application provided in the following is not intended to limit the scope of the claimed present application, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0038] Embodiment 1
[0039] The following will be described in combination with the drawingsFigure 1 Detailed description of specific embodiments of the present application is made;
[0040] Cryptographic tasks involve multiple types including: encryption and decryption tasks, digital signature and verification tasks, identity authentication tasks, key management tasks, cryptographic hash tasks, access control tasks, etc.
[0041] A hardware grouping-based cryptographic task dynamic scheduling method, comprising:
[0042] The hardware characteristics of the cryptographic device are detected through the CPUID instruction set, combined with the PCIe device capability negotiation, the hardware capability matrix of the cryptographic device is dynamically constructed, and the cryptographic device is classified. The classification types of the cryptographic device include national secret type, general type, edge type and GPU heterogeneous type, wherein the national secret group includes cryptographic cards / HSMs supporting SM2 / SM3 / SM4 / SM9 instruction sets, and is used for national secret tasks requiring high security and real-time performance; the general group includes x86 / ARM server CPU clusters, and is used for non-national secret tasks or low-priority batch encryption; the edge group includes domestic TF cards and cryptographic modules such as GM / T0016, and is used for low-power encryption scenarios such as data encryption of Internet of Things terminals; and the GPU heterogeneous group includes Nvidia GPUs or domestic DCU acceleration cards, and is used for complex tasks such as cryptographic analysis and algorithm development.
[0043] The hardware characteristics of the cryptographic device are detected through the CPUID instruction set, including: in the x86 architecture, the CPUID instruction (EAX = 07H, ECX = 00H) can obtain the hardware support state of the processor for national secret algorithms such as SM2 / SM3 / SM4 / SM9, and the flag bit is detected through the BIT 5-8 of the EDX register. For ARMv8.4 and above architecture, the ID_AA64ISAR0_EL1 register needs to be read to determine the hardware acceleration support of SM3 / SM4. The RISC-V architecture realizes the national secret instruction set identification through custom CSR register extension.
[0044] The PCIe capability negotiation mechanism includes that in the Capability structure of the PCIe configuration space, the VSEC (Vendor-Specific Capability) of type 0x09 is used to store the cryptographic device characteristics: 0x10-0x1F: algorithm support bitmap (SM2: 0x01, RSA4096: 0x02, AES256: 0x04); 0x20-0x23: cryptographic power value (unit Gbps); 0x24-0x27: maximum key storage capacity; 0x28-0x2B: TRNG entropy source quality level (AIS-31 standard); dynamic capability matrix construction.
[0045] When the national secret group device fails, the following processes are automatically triggered for the failed device: isolate the fault node and update the topology graph; select a node with SM2 soft implementation from the general group; dynamically load the white box password library as a downgrade solution; generate FIPS 140-3 failover audit logs; integrate a remote attestation mechanism in the classification decision process:
[0046] The processing capacity of each type of device is evaluated to obtain the real-time processing capacity of each type of device, and a buffer queue is set to temporarily store tasks that exceed the real-time processing capacity in the buffer queue to avoid hardware overload and service degradation. And during the low load period of the system, non-real-time tasks in the buffer queue are automatically extracted and processed, thereby fully utilizing the resources of the cryptographic device.
[0047] After classifying the cryptographic devices, historical task processing data of each type of cryptographic device is obtained, and a first unit of time is set. The historical task processing data of each type of cryptographic device is divided and processed using the first unit of time, and the trend of the task quantity of each first unit of time is given, excluding sudden situations. A second unit of time is set, and the first unit of time includes multiple second units of time. The historical task processing data of the first unit of time is divided and processed using the second unit of time, and the task quantity change of each second unit of time within the first unit of time, i.e. the task quantity processed by each second unit of time accounts for how much of the task quantity of each first unit of time, is given. Thus, in combination with the aforementioned trend of the task quantity of the first unit of time, the trend of the task quantity of the second unit of time can be further predicted.
[0048] According to the trend of the task quantity of the second unit of time, the first unit of time is divided into multiple periods including peak period, trough period and ordinary period, and the duration of the trough period and the ordinary period is determined. If the duration of the trough period is long, the cryptographic devices of each type are grouped based on the task quantity of each second unit of time in the trough period, to ensure that the cryptographic devices in each group can complete the task quantity per hour in the trough period. When the ordinary period and the peak period arrive, each group of cryptographic devices is merged based on the ratio of the task quantity of the second unit of time in the ordinary period and the peak period to that in the trough period. If the average task quantity of the second unit of time in the ordinary period is twice the average task quantity of the second unit of time in the trough period, the original two groups of cryptographic devices are temporarily combined as a group of cryptographic devices for task processing. If the average task quantity of the second unit of time in the peak period is three times the average task quantity of the second unit of time in the trough period, the original three groups of cryptographic devices are temporarily combined as a group of cryptographic devices for task processing.
[0049] For example, according to the, for the national secret type and the edge type, the first unit time is 1 minute, and the second unit time is 1 second; for the general type, the first unit time is 1 day, and the second unit time is 1 hour; for the GPU heterogeneous type, the first unit time is 1 month, and the second unit time is 1 day.
[0050] The task amount is measured by the required computing power of the task, so that the grouping of each different cryptographic device matches the corresponding task amount. In order to improve the processing speed of concurrent tasks, and when a certain group of cryptographic devices is unavailable, it can be replaced with other groups of cryptographic devices of the same type without worrying too much about the problem of computing power compatibility, ensuring that the cryptographic task is completed in time and efficiently.
[0051] The management of the cryptographic device includes:
[0052] When a new cryptographic device is registered, its computing power indicators, including signature speed, memory bandwidth, etc., need to be recorded; at the same time, the classification of cryptographic devices of the same type or with similar computing power indicators is checked, and then the cryptographic devices are further divided into the corresponding groups based on the classification.
[0053] During the operation of the cryptographic device, the load rate, queue depth and health status of each group are collected in real time; the load upper limit and the load lower limit are set for the load rate, and the replacement threshold is set for the health status. If the load rate of the first group of cryptographic devices exceeds the load upper limit, it means that the task amount of the first group at this time exceeds the expected value, so a cryptographic device is selected from the idle cryptographic device group of the same type and temporarily labeled, and temporarily coded into the first group, so that the load rate of the first group is lower than the load upper limit, avoiding the impact of overloading of the cryptographic device on the timely completion of the task. When the load rate of the first group is lower than the load lower limit, it means that the task amount of the first group can be completed completely by the original cryptographic devices in the first group, so the temporarily coded cryptographic device is removed from the temporary label and coded back to its corresponding original group.
[0054] When the health status value of the cryptographic device in a certain group is lower than the replacement threshold, the group of cryptographic devices is automatically marked as unavailable and the corresponding cryptographic task is migrated to other idle groups of the same type; at the same time, the management personnel are notified to process the cryptographic devices in the group.
[0055] According to the historical password task processing data, information of various types of password tasks involved is extracted, including real-time information, importance information, security information and collaboration information with other tasks, and a task feature label library is established, including real-time, computing power requirement and importance, the real-time is divided into hard real-time, soft real-time and non-real-time according to time limit requirements; the computing power requirement is divided into high computing power, general computing power and low computing power by quantifying the consumption of CPU / GPU / password chip of the task; the security level is given a security label according to the data sensitivity (such as confidential level / secret level) in order to allocate different password resource pools for subsequent processing.
[0056] Among them, the hard real-time task requires the task to be completed in milliseconds, and the corresponding application scenarios are, for example, when a user accesses a government cloud platform through a national secret browser, the SSL / TLS handshake and data encryption need to be completed in milliseconds to avoid communication delay affecting user experience; the operation and maintenance personnel remotely manage the government cloud resources through a secure access platform (such as IPSec VPN or SSL VPN), which needs to verify the identity in real time and encrypt the operation instructions to prevent unauthorized access; the transmission of cross-departmental instructions in emergency events (such as public security, fire, and medical cooperation) requires that the encrypted instructions be signed and verified within hundreds of milliseconds and transmitted to ensure emergency response efficiency; the soft real-time is, for example, file encryption with a time limit of less than 1s, and the non-real-time is, for example, backup encryption with a time limit of 1 hour.
[0057] The feature labels of various password tasks are collected and the corresponding password device types are determined to train a DNN model to obtain a password task classification model. The password task classification model can quickly determine the corresponding password device type when receiving a password task, and the DNN model includes an input layer, a feature embedding layer, an attention layer, a fully connected layer and an output layer.
[0058] The password tasks of different types of password devices are classified and stored, and a dynamic scheduling algorithm is used for task scheduling.
[0059] The dynamic scheduling algorithm includes: real-time acquisition of the load status of each group of password devices, the load status including the password tasks being processed and the password task queue to be processed, prediction of the response time of the password device group according to the load status of the password device group, integration of the feature labels of the password tasks to be scheduled into a vector matrix, and sorting and packaging scheduling of the password devices according to the following formula.
[0060]
[0061] In the formula, A ijPriority value of the jth cryptographic task assigned to the ith cryptographic device, i = 0, 1, 2, 3 respectively represent that the cryptographic task belongs to the national secret class, the edge class, the general class and the GPU heterogeneous class, a is the real-time requirement value, b is the computing power requirement value, c is the security requirement value, a is the real-time weight, b is the computing power weight, and g is the security weight, and the specific is:
[0062]
[0063] Meanwhile, the computing power value requirement is met:
[0064] The real-time requirement is met:
[0065] In the formula, is the computing power value of A ij , C i is the average value of the cryptographic computing power of the ith cryptographic device in the second unit time of the current period, and n is the number of cryptographic task items packaged into the same group, is the completion time limit value of A ij , T m is the response time of the cryptographic device group m corresponding to A ij .
[0066] Embodiment 2
[0067] A cryptographic task dynamic scheduling system based on hardware grouping comprises a device classification module, a device grouping module, a model training module, a task classification module, and a task scheduling module. The device classification module is used to classify cryptographic devices according to the hardware characteristics of the cryptographic devices. The device grouping module is used to group the classified cryptographic devices according to the historical task processing data of the cryptographic devices. The model training module is used to construct a DNN model and train the cryptographic task classification model. The task classification module is used to determine the cryptographic device category corresponding to the to-be-processed cryptographic task by using the cryptographic task classification model. The task scheduling module is used to store the cryptographic tasks of different categories of cryptographic devices and perform task scheduling by using a dynamic scheduling algorithm.
[0068] The above-described embodiments only express the specific implementation of the present application, and the description is more specific and detailed, but it cannot be understood as a limitation on the protection scope of the present application. It should be noted that for ordinary skilled persons in the art, without departing from the technical concept of the present application, a number of modifications and improvements can be made, which are within the protection scope of the present application.
Claims
1. A dynamic scheduling method for cryptographic tasks based on hardware block structuring, characterized in that, Includes the following steps: Step 1: Classify cryptographic devices according to their hardware characteristics; Step 2: Group the classified cryptographic devices according to their historical task processing data; Step 3: Construct a DNN model and train it to obtain a cryptography task classification model; Step 4: Use the cryptographic task classification model to determine the category of cryptographic device corresponding to the cryptographic task to be processed; Step 5: Categorize and store cryptographic tasks for different types of cryptographic devices, and use dynamic scheduling algorithms to schedule tasks accordingly. The dynamic scheduling algorithm includes: real-time acquisition of the current load status of each group of cryptographic devices, the load status including the cryptographic tasks currently being processed and the queue of cryptographic tasks to be processed, estimating the response time of the cryptographic device group based on the load status of the cryptographic device group, integrating the feature labels of the cryptographic tasks to be scheduled into a vector matrix, and sorting and packaging the cryptographic devices according to the following formula; ; In the formula, A ij This represents the priority value of the j-th cryptographic task assigned to the i-th type of cryptographic device, where i = 0, 1, 2, 3 represent the cryptographic task belonging to the national cryptographic category, the edge category, the general category, and the GPU heterogeneous category, respectively. a is the real-time requirement value, b is the computing power requirement value, c is the security requirement value, α is the real-time weight, β is the computing power weight, and γ is the security weight. Specifically: ; Simultaneously meet the computing power requirements: ; Meets real-time requirements: ; In the formula, For A ij The computing power value, Let be the average cryptographic computing power of the i-th type of cryptographic device in the current period, and n be the number of cryptographic tasks packaged into the same group. For A ij The completion time limit, For A ij The response time of the corresponding cryptographic device group m.
2. The method for dynamic scheduling of cryptographic tasks based on hardware blocks according to claim 1, characterized in that, Step 1 includes: detecting the hardware characteristics of cryptographic devices through the CPUID instruction set, dynamically constructing a hardware capability matrix of cryptographic devices in conjunction with PCIe device capability negotiation, and classifying cryptographic devices. The classification types of cryptographic devices include national cryptographic devices, general-purpose devices, edge computing devices, and GPU heterogeneous devices.
3. The method for dynamic scheduling of cryptographic tasks based on hardware block ciphers according to claim 1, characterized in that, Step 2 includes: Step 2.1: Set the first unit time and the second unit time, and analyze and predict the changing trend of the task volume in the second unit time by analyzing the historical task processing data of the cryptographic device in different unit time periods. Step 2.2: Based on the trend of task volume changes in the second unit of time, divide the first unit of time into multiple periods, including peak period, trough period and normal period, and group them according to the period in which the cryptographic device is located.
4. The method for dynamic scheduling of cryptographic tasks based on hardware blocks according to claim 3, characterized in that, Step 2.1 includes: acquiring historical task processing data of various cryptographic devices and setting a first unit time; using the first unit time to divide the historical task processing data of various cryptographic devices and perform data analysis processing to give the trend of task volume change in each first unit time except for emergencies; then setting a second unit time, wherein the first unit time includes multiple second unit times, using the second unit time to divide the historical task processing data of the first unit time and perform data analysis processing to give the change of task volume in each second unit time within the first unit time, that is, how much of the task volume processed in each second unit time accounts for the task volume of each first unit time, and thus, combined with the aforementioned trend of task volume change in each first unit time, the trend of task volume change in the second unit time can be further predicted.
5. The method for dynamic scheduling of cryptographic tasks based on hardware blocks according to claim 3, characterized in that, Step 2.2 includes: dividing the first unit of time into multiple periods, including peak period, trough period and normal period, according to the trend of the task volume change in the second unit of time; determining the duration of the trough period and normal period; if the trough period lasts for a long time, grouping various cryptographic devices based on the task volume of each second unit of time in the trough period to ensure that each group of cryptographic devices can complete the task volume of each hour in the trough period; and when the normal period and peak period arrive, merging each group of cryptographic devices according to the ratio of the task volume of the normal period and peak period to that of the trough period in the second unit of time; if the average cryptographic task volume of the second unit of time in the normal period is twice the average cryptographic task volume of the second unit of time in the trough period, then the original two groups of cryptographic devices are treated as a provisional group of cryptographic devices for task processing; if the average cryptographic task volume of the second unit of time in the peak period is three times the average cryptographic task volume of the second unit of time in the trough period, then the original three groups of cryptographic devices are treated as a provisional group of cryptographic devices for task processing. The workload is measured by the computing power required for the task, so that the grouping of different cryptographic devices matches the corresponding workload, and when a group of cryptographic devices fails and becomes unavailable, it is replaced with other groups of cryptographic devices of the same type.
6. The method for dynamic scheduling of cryptographic tasks based on hardware blocks according to claim 1, characterized in that, Step 2 includes managing cryptographic devices: When a new cryptographic device is registered, its computing power indicators, including signature speed and memory bandwidth, need to be recorded. At the same time, the classification of cryptographic devices of the same type or with similar computing power indicators should be checked, and then further classified into the group corresponding to that type of cryptographic device based on the classification. During the operation of the cryptographic devices, the load rate, queue depth, and health status of each group are collected in real time. Upper and lower load limits are set for the load rate. If the load rate of the first group exceeds the upper load limit, it indicates that the workload of the first group exceeds expectations. In this case, a cryptographic device is selected from an idle group of the same type, temporarily tagged, and temporarily assigned to the first group. This keeps the load rate of the first group below the upper load limit, preventing the cryptographic devices from overloading and affecting the timely completion of tasks. When the load rate of the first group is below the lower load limit, it indicates that the workload of the first group can be completely completed by the existing cryptographic devices in the first group. The temporary tag of the temporarily assigned cryptographic device is removed, and it is reassigned to its original group.
7. The method for dynamic scheduling of cryptographic tasks based on hardware block ciphers according to claim 1, characterized in that, Step 3 includes: extracting information on various cryptographic tasks based on historical task processing data, including real-time information, importance information, security information, and collaborative information with other tasks; establishing a task feature label library, including real-time performance, computing power requirements, and importance; collecting feature labels for each cryptographic task and determining its corresponding cryptographic device type; and using this to create a dataset to train a DNN model to obtain a cryptographic task classification model. The cryptographic task classification model can quickly determine the corresponding cryptographic device type when it receives a cryptographic task. The DNN model includes an input layer, a feature embedding layer, an attention layer, a fully connected layer, and an output layer.
8. A dynamic scheduling system for cryptographic tasks based on hardware block ciphers, characterized in that, include: Equipment classification module, equipment grouping module, model training module, task classification module, and task scheduling module; The device classification module is used to classify cryptographic devices according to their hardware characteristics; the device grouping module is used to group the classified cryptographic devices according to their historical task processing data; the model training module is used to construct a DNN model and train it to obtain a cryptographic task classification model. The task classification module is used to determine the cryptographic device category corresponding to the cryptographic task to be processed using a cryptographic task classification model. The task scheduling module is used to classify and store cryptographic tasks for different types of cryptographic devices, and to schedule tasks using dynamic scheduling algorithms. The dynamic scheduling algorithm includes: real-time acquisition of the current load status of each group of cryptographic devices, the load status including the cryptographic tasks currently being processed and the queue of cryptographic tasks to be processed, estimating the response time of the cryptographic device group based on the load status of the cryptographic device group, integrating the feature labels of the cryptographic tasks to be scheduled into a vector matrix, and sorting and packaging the cryptographic devices according to the following formula; ; In the formula, A ij This represents the priority value of the j-th cryptographic task assigned to the i-th type of cryptographic device, where i = 0, 1, 2, 3 represent the cryptographic task belonging to the national cryptographic category, the edge category, the general category, and the GPU heterogeneous category, respectively. a is the real-time requirement value, b is the computing power requirement value, c is the security requirement value, α is the real-time weight, β is the computing power weight, and γ is the security weight. Specifically: ; Simultaneously meet the computing power requirements: ; Meets real-time requirements: ; In the formula, For A ij The computing power value, Let be the average cryptographic computing power of the i-th type of cryptographic device in the current period, and n be the number of cryptographic tasks packaged into the same group. For A ij The completion time limit, For A ij The response time of the corresponding cryptographic device group m.
Citation Information
Patent Citations
Scheduling system and method for heterogeneous cryptographic resource pool
CN115514766A
Resource scheduling method, data processing system, computing device, medium and product
CN119847773A