Data processing unit (DPU)
By integrating the post-quantum cryptographic algorithm in the data processing unit DPU, the full TCP network card unloading mode is realized, and the security and performance bottlenecks of TLS hardware unloading technology in the quantum computing environment are solved, providing quantum security and efficient TLS unloading capabilities.
Patent Information
- Application Number
- CN202510678998.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2045-05-26
AI Technical Summary
The existing TLS hardware offload technology relies on classic cryptographic algorithms, cannot withstand the threat of quantum computing, and has a large computing overhead, resulting in security and performance bottlenecks.
The post-quantum cryptographic algorithm is used to integrate the data processing unit DPU, including the TCP traffic control module, the TSL recording processing module and the post-quantum cryptographic acceleration module, to realize the full TCP network card offload mode, and support the key negotiation, identity authentication and data encryption and decryption of the post-quantum algorithm.
Provide guarantees in quantum security and performance, reduce CPU load, improve network throughput, and ensure that the system resists quantum computing threats.
Smart Images

Figure CN120567412A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a data processing unit (DPU). Background Art
[0002] With the rapid development of internet technology, the security of network communications has become a critical issue, especially in high-security sectors such as e-commerce, online payments, and cloud computing. Transport Layer Security (TLS), the cornerstone of network communication security, is widely used for data encryption, identity authentication, and data integrity protection. However, traditional TLS relies on classical cryptographic algorithms such as RSA and ECDH, which pose serious security risks in the face of future quantum computing threats. Quantum computers, using Shor's algorithm, can crack these algorithms in polynomial time, rendering existing TLS vulnerable to quantum attacks.
[0003] At the same time, with the explosive growth of network traffic, the computational overhead of the TLS protocol has placed an increasing burden on server CPUs. This is especially true in high-concurrency scenarios like data centers, where traditional software-implemented TLS has become a performance bottleneck. To improve performance, modern network cards and data processing units (DPUs) have introduced TLS hardware offload technology, which offloads TLS encryption, decryption, key exchange, and other operations from the CPU to hardware execution, significantly reducing CPU load and improving network throughput. However, existing TLS hardware offload technology still relies on classical cryptographic algorithms, lacks quantum security, and cannot withstand the future threat of quantum computing.
[0004] In this context, how to combine post-quantum cryptographic algorithms with TLS hardware offload technology to ensure quantum security while fully leveraging the performance advantages of hardware has become a technical problem that needs to be solved urgently. Summary of the Invention
[0005] The purpose of the embodiments of the present application is to provide a data processing unit (DPU) to solve the above-mentioned problems existing in the prior art, and to provide efficient TLS offloading capabilities while ensuring quantum security.
[0006] In a first aspect, a data processing unit (DPU) is provided, which includes: a TCP flow control module, a TSL record processing module, and a post-quantum cryptography acceleration module;
[0007] The post-quantum cryptography acceleration module is used to integrate the post-quantum algorithm and use the post-quantum algorithm for key negotiation and identity authentication during the TLS handshake phase;
[0008] The TLS record processing module is configured to, during the data exchange phase, split the encrypted data into TLS records and send the split TLS records to the TCP flow control module; and decrypt the TLS records extracted by the TCP flow control module so as to send the decrypted data to the operating system protocol stack; the operating system protocol stack supports post-quantum algorithms;
[0009] The TCP flow control module is used to encapsulate the split TLS records into TCP data packets during the data interaction stage; perform flow control and sequence processing of TCP data packets; and receive TCP data packets, extract TLS records, and send the extracted TLS records to the TSL record processing module.
[0010] In one possible implementation, the post-quantum cryptography acceleration module is specifically configured to implement key negotiation using a post-quantum algorithm through the following steps:
[0011] generating a first key pair based on the post-quantum algorithm, the first key pair comprising a first public key and a first private key;
[0012] Receive the second public key in the second key pair generated by the server, determine the shared key, and send the ciphertext encrypted by the shared key using the second public key to the server, so that the server uses the second private key in the second key pair to decrypt the ciphertext and obtain the shared key.
[0013] In one possible implementation, the DPU is applied to a client device;
[0014] The post-quantum cryptography acceleration module is specifically used to implement identity authentication using a post-quantum algorithm through the following steps:
[0015] Based on the received server certificate sent by the server, obtain the post-quantum public key generated by the post-quantum algorithm in the server certificate;
[0016] Authenticate the server based on the post-quantum public key and the server certificate.
[0017] In one possible implementation, the post-quantum cryptography acceleration module is further used to determine an encryption key based on the shared key and send the encryption key to the TSL record processing module.
[0018] In one possible implementation, the TLS record processing module is specifically configured to receive a data stream sent by the operating system protocol stack during the data interaction phase, and encrypt the data stream according to the encryption key and the symmetric encryption algorithm; split the encrypted data stream into TLS records that comply with the TLS protocol format;
[0019] and decrypting the TLS record extracted by the TCP flow control module according to the encryption key and the symmetric decryption algorithm, wherein the symmetric decryption algorithm corresponds to the symmetric encryption algorithm.
[0020] In one possible implementation, each TLS record includes a record header, encrypted data, and a message authentication code (MAC); wherein the record header includes a version, a data type, and a data length; and the MAC is obtained by signing the corresponding TLS record using a post-quantum algorithm.
[0021] In one possible implementation, the TCP flow control module is specifically configured to, during the data exchange phase, after encapsulating the TLS records into TCP data packets, sort the encapsulated TCP data packets according to the sequence numbers of the encapsulated TCP data packets;
[0022] And, in the data interaction stage, after receiving the TCP data packets, the received TCP data packets are sorted according to the sequence numbers of the received TCP data packets, so as to extract TLS records from the sorted TCP data packets in sequence.
[0023] In one possible implementation, the TCP flow control module is further specifically used to detect whether the TCP data packet is lost through the sequence number and ACK confirmation mechanism of the TCP data packet. If it is detected that the TCP data packet is lost, a retransmission request is triggered to indicate that the TCP data packet is resent.
[0024] In one possible implementation, the post-quantum algorithm includes:
[0025] Kyber, which provides an efficient key exchange mechanism;
[0026] LMS-SM3 / HSS-SM3, for providing quantum-safe identity authentication and signature verification;
[0027] SM3 is used as a message authentication code algorithm to ensure data integrity.
[0028] In one possible implementation, the DPU is applied to a client device.
[0029] An embodiment of the present application provides a data processing unit (DPU), which includes: a TCP flow control module, a TSL record processing module, and a post-quantum cryptography acceleration module; wherein the post-quantum cryptography acceleration module is used to integrate post-quantum algorithms and use post-quantum algorithms for key negotiation and identity authentication during the TLS handshake phase; the TSL record processing module is used to split encrypted data into TLS records during the data exchange phase and send the split TLS records to the TCP flow control module; and decrypt the TLS records extracted by the TCP flow control module so that the decrypted data can be sent to the operating system protocol stack; the operating system protocol stack supports post-quantum algorithms; the TCP flow control module is used to encapsulate the split TLS records into TCP data packets during the data exchange phase; perform flow control and sequence processing of TCP data packets; and receive TCP data packets, extract TLS records, and send the extracted TLS records to the TSL record processing module. The DPU works in conjunction with the operating system protocol stack, completely replacing the kernel network stack, supporting full TCP network card offload mode, while supporting efficient key management and encryption and decryption operations, and providing efficient TLS offload capabilities while ensuring quantum security. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0031] Figure 1 A schematic diagram of the data transmission process involved in a system architecture for implementing DPU-based post-quantum TLS hardware offload provided in an embodiment of the present application;
[0032] Figure 2 A schematic diagram of the structure of a DPU provided in an embodiment of the present application. DETAILED DESCRIPTION
[0033] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments of the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. Unless otherwise defined, the technical terms or scientific terms used in this application should be the common meanings understood by people with ordinary skills in the field to which the invention belongs. "Include" or "comprising" and similar words mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect", "couple" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect.
[0034] For ease of understanding, the terms involved in the embodiments of this application are explained below:
[0035] TLS: Transport Layer Security;
[0036] Data Processing Unit DPU: Data Processing Unit;
[0037] PQMagic: Post-Quantum Magic;
[0038] Post-quantum key encapsulation mechanism KEM: Key Encapsulation Mechanism;
[0039] The existing technology is a packet-based network card offload mode. This mode processes TLS encryption and decryption operations packet by packet through the network card, is deeply integrated with the kernel network stack, and supports efficient TLS offload. The packet-based network card offload mode is enabled through ethtool flags (such as tls-hw-tx-offload and tls-hw-rx-offload), which realizes hardware-accelerated processing of TLS packets. However, the packet-based network card offload mode is only a partial offload and fails to completely replace the kernel network stack. It relies on classical cryptographic algorithms such as RSA or ECDH for key exchange and identity authentication, which cannot withstand attacks from quantum computers. In addition, the packet-based network card offload mode cannot handle the complete process of TLS records and still needs to rely on some functions of the kernel network stack, which limits its performance and availability. The above-mentioned existing technologies have the following shortcomings:
[0040] Lack of quantum security: Existing TLS hardware offload technology relies on classical cryptographic algorithms such as RSA or ECDH, which can be quickly cracked in a quantum computing environment, resulting in the leakage of TLS session keys and unable to defend against future quantum attacks.
[0041] Insufficient security of signature algorithms: The existing packet-based network card offload mode uses RSA or ECDSA signature algorithms for identity authentication. These algorithms are also unable to resist attacks from quantum computers, threatening the identity authentication security of both communicating parties.
[0042] Incomplete offloading: The packet-based NIC offloading mode is only a partial offloading and fails to completely replace the kernel network stack. It still relies on the kernel to handle some TLS record functions, which limits performance and availability.
[0043] Lack of support for post-quantum cryptographic algorithms: The existing packet-based network card offload mode does not integrate post-quantum cryptographic algorithms, and cannot support quantum-secure key exchange, signature authentication, and data encryption at the hardware level, and cannot meet the security requirements of future quantum computing environments.
[0044] Based on this, the inventors proposed a system architecture for DPU-based post-quantum TLS hardware offload to address the aforementioned issues. This architecture leverages post-quantum cryptographic algorithms to enhance the security of traditional TLS protocols while leveraging the DPU's hardware acceleration advantages to reduce CPU computational pressure and improve network throughput and security. This solution implements a full TCP offload mode and ensures the system is resilient to future quantum computing threats.
[0045] The post-quantum TLS hardware offload system architecture provided in embodiments of the present application may include an application, an operating system, a device processing unit (DPU), and a network interface card (NIC). The DPU can be deployed on a client device and includes a post-quantum cryptography acceleration module, a TLS record processing module, and a TCP flow control module. The system can communicate with a server to enable data transmission.
[0046] Figure 1 A schematic diagram of the data transmission process involved in the system architecture provided in an embodiment of the present application. Figure 1 It includes the TLS handshake phase and the data interaction phase.
[0047] A. During the TLS handshake phase, the post-quantum cryptography acceleration module uses post-quantum algorithms for key negotiation and identity authentication;
[0048] (1) The post-quantum cryptography acceleration module implements key negotiation using the post-quantum algorithm through the following steps:
[0049] Step 1: Generate the first key pair based on the post-quantum algorithm.
[0050] The first key pair may include a first public key and a first private key.
[0051] Step 2: Receive the second public key in the second key pair generated by the server and determine the shared key;
[0052] Among them, the second key pair may also include a second private key; the post-quantum algorithm used to generate the first key pair and the post-quantum algorithm used to generate the second key pair may be the same or different, and this application does not limit this.
[0053] Step 3: Send the encrypted ciphertext of the shared key using the second public key to the server.
[0054] After receiving the ciphertext, the server uses the second private key to decrypt the ciphertext to obtain the shared key.
[0055] (2) The post-quantum cryptography acceleration module implements identity authentication using post-quantum algorithms through the following steps:
[0056] Step 4: Receive the server certificate sent by the server and obtain the post-quantum public key generated by the post-quantum algorithm in the server certificate;
[0057] Step 5: Authenticate the server based on the post-quantum public key and server certificate.
[0058] If the authentication of the server is successful, the data interaction phase begins.
[0059] B. In the data interaction stage, the workflow of the TSL record processing module and the TCP flow control module includes two processes: data sending and data receiving.
[0060] (1) Data sending process, including:
[0061] Step 6: The TSL record processing module receives the data stream sent by the application through the operating system protocol stack;
[0062] Step 7: The TSL record processing module encrypts the data stream;
[0063] Step 8: The TSL record processing module splits the encrypted data stream into TLS records;
[0064] Step 9: The TSL record processing module sends the split TLS record to the TCP flow control module;
[0065] Step 10: The TCP flow control module encapsulates the TLS record into a TCP data packet and sends it through the network card.
[0066] (2) Data receiving process, including:
[0067] Step 11: The TCP flow control module receives the TCP data packet;
[0068] Step 12: The TCP flow control module extracts the TLS record from the received TCP data packet;
[0069] Step 13: The TCP flow control module sends the extracted TLS record to the TSL record processing module;
[0070] Step 14: The TSL record processing module decrypts the extracted TLS record to obtain decrypted data;
[0071] Step 15: The TSL record processing module sends the decrypted data to the application through the operating system protocol stack.
[0072] As can be seen from the preceding process, the aforementioned data transmission method enables DPU-based post-quantum TLS hardware offload. The DPU works in conjunction with the operating system protocol stack to completely replace the kernel network stack and support full TCP network card offload mode. The operating system protocol stack must support post-quantum algorithms and integrate them into the TLS protocol stack to ensure collaboration with the DPU hardware to complete data encryption, decryption, authentication, and flow control.
[0073] Furthermore, the execution functions of the post-quantum cryptography acceleration module, TLS record processing module, and TCP flow control module in the DPU are described in detail below. Figure 2 Shown is a schematic diagram of the structure of DPU.
[0074] 1) Post-quantum cryptography acceleration module, which is used to integrate post-quantum algorithms and use them for key negotiation and identity authentication during the TLS handshake phase.
[0075] The post-quantum cryptography acceleration module integrates PQMagic's post-quantum algorithms, including Kyber, LMS-SM3, HSS-SM3, and SM3. Kyber's post-quantum algorithm provides an efficient key exchange mechanism that is resistant to quantum computing attacks. LMS-SM3 / HSS-SM3 post-quantum algorithms provide quantum-safe authentication and signature verification. SM3's post-quantum algorithm can be used as a message authentication code (MAC) algorithm to ensure data integrity. These post-quantum algorithms implement key negotiation and authentication during the TLS handshake phase, providing hardware acceleration support to optimize the computational performance of post-quantum algorithms and reduce CPU load.
[0076] Specifically, the post-quantum cryptography acceleration module implements key negotiation using a post-quantum algorithm, including: generating a first key pair based on the post-quantum algorithm, the first key pair including a first public key and a first private key; receiving the second public key in the second key pair generated by the server, determining the shared key, and sending the ciphertext encrypted with the second public key to the server, so that the server uses the second private key in the second key pair to decrypt the ciphertext and obtain the shared key.
[0077] The post-quantum cryptography acceleration module implements identity authentication using the post-quantum algorithm, including: obtaining the post-quantum public key generated by the post-quantum algorithm in the server certificate based on the server certificate received from the server; and authenticating the server based on the post-quantum public key and the server certificate.
[0078] Furthermore, the post-quantum cryptography acceleration module is also used to determine the encryption key based on the shared key, and send the encryption key to the TSL record processing module to enable the TSL record processing module to encrypt the data stream, or decrypt the extracted TSL record sent by the TCP flow control module.
[0079] 2) A TSL record processing module is used to split the encrypted data into TLS records during the data exchange phase and send the split TLS records to the TCP flow control module; and to decrypt the TLS records extracted by the TCP flow control module so that the decrypted data can be sent to the operating system protocol stack; the operating system protocol stack supports post-quantum algorithms, that is, it supports the post-quantum algorithms involved in the above-mentioned PQMagic library.
[0080] Specifically, during the data exchange phase, the system receives the data stream sent by the operating system protocol stack and encrypts it using an encryption key and a symmetric encryption algorithm. The encrypted data stream is then split into TLS records that conform to the TLS protocol format. Finally, the system decrypts the TLS records extracted by the TCP flow control module using the encryption key and a symmetric decryption algorithm corresponding to the symmetric encryption algorithm. Because each TCP packet has a sequence number, the data obtained after decrypting the TLS records can be spliced together based on the sequence number of the corresponding TCP packet to obtain the received data stream.
[0081] A TLS record is the smallest unit of data transmission in the TLS protocol. Data streams are split into multiple TLS records, and the processing is entirely done by the DPU hardware, reducing the burden on the CPU.
[0082] Furthermore, each TLS record may include: a record header, encrypted data, and a message authentication code MAC; wherein the record header may include information such as version, data type, and data length; the MAC is obtained by signing the corresponding TLS record using a post-quantum algorithm (such as the SM3 algorithm) to ensure data integrity and authentication.
[0083] 3) TCP flow control module, which is used to encapsulate the split TLS records into TCP data packets during the data interaction stage; perform flow control and sequence processing of TCP data packets; and receive TCP data packets, extract TLS records, and send the extracted TLS records to the TSL record processing module.
[0084] The flow control and sequence processing of TCP data packets may include flow control, data packet sending, data packet receiving, data packet sorting, and data packet retransmission, etc. This ensures that there is no packet loss or sequence error during data transmission.
[0085] Specifically, in the data interaction stage, after the TLS record is encapsulated into a TCP data packet, the encapsulated TCP data packet is sorted according to the sequence number of the encapsulated TCP data packet; and in the data interaction stage, after the TCP data packet is received, the received TCP data packet is sorted according to the sequence number of the received TCP data packet, so as to extract the TLS record from the sorted TCP data packets in sequence.
[0086] Furthermore, the TCP flow control module is also specifically used to detect whether the TCP data packet is lost through the sequence number and ACK confirmation mechanism of the TCP data packet. If it is detected that the TCP data packet is lost, a retransmission request is triggered to instruct the TCP data packet to be resent.
[0087] That is, the packet loss handling of the TCP flow control module includes:
[0088] a. Packet loss detection: Detect whether TCP data packets are lost through the sequence number and ACK confirmation mechanism of the TCP data packet.
[0089] b. Data packet retransmission: Triggers a retransmission request, asking the source host that sent the TCP data packet to resend the lost TCP data packet. The TLS record processing module can re-decrypt the retransmitted TCP data packet received by the TCP flow control module.
[0090] The TCP flow control module handles TCP packet loss, including:
[0091] a. Data packet reception: The received data packets may be out of order.
[0092] b. Packet sorting: Reorder TCP packets according to their sequence numbers.
[0093] In some embodiments, in order to further improve security, after the shared key is obtained through the handshake stage, a key update time can be set for the shared key. For example, during the communication process after obtaining the shared key, the current shared key will be changed to a new shared key every preset key update time period, and the encryption key will be changed accordingly. The change process is carried out in both the client's DPU and the server.
[0094] Specifically, in the key exchange during the TLS handshake phase, a configured character update sequence is exchanged simultaneously; the character update sequence includes random strings of different lengths arranged in sequence; according to the arrangement order of the random strings, corresponding random strings are extracted from the character update sequence in sequence, and the current shared key needs to be changed every preset key update time period. The extracted random string can be spliced at the end or beginning of the current shared key to obtain a new shared key, which is stored on the client and the server, and the acquisition time of the shared key is recorded (including the shared key randomly generated by the initial client and the corresponding acquisition time).
[0095] It should be noted that, in order to ensure that the random character strings extracted from the character update sequence are not repeated, the extracted random character strings can be deleted from the character update sequence. If all random character strings in the character update sequence have been extracted (or deleted), the stored shared keys can be used in a cyclic manner according to the time when the shared keys were obtained.
[0096] In some embodiments, each time a new connection is established or at regular intervals, the initial shared key and / or the currently changed shared key are combined with current context information (such as a random number, timestamp, etc.) to generate a new session key through a key derivation function.
[0097] In some embodiments, a fixed time period can be set to automatically replace the key at the end of each period, or when certain events are detected (such as suspected key leakage, network attack, etc.), that is, at the beginning of each period, the client and server renegotiate to generate a new shared key using a post-quantum KEM (such as Kyber). A key derivation function (such as HKDF) is used to derive specific encryption keys and MAC keys from the newly generated shared key. The updated key is notified to the other party through a secure channel (for example, the new key information encrypted with the current session key), so that both parties switch to the new encryption key for communication at the same time.
[0098] In another embodiment provided in the present application, a computer-readable storage medium is also provided, which stores instructions. When the computer-readable storage medium is run on a computer, it enables the computer to execute the execution method of any module in the DPU in the above embodiment.
[0099] In another embodiment provided in the present application, a computer program product including instructions is also provided, which, when executed on a computer, enables the computer to execute the execution method of any module in the DPU in the above embodiments.
[0100] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the embodiments of the present application can be implemented in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the embodiments of the present application can be implemented in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0101] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0102] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0103] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0104] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0105] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present application without departing from the spirit and scope of the embodiments of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims and their equivalents, the embodiments of the present application are also intended to include these modifications and variations.
Claims
1. A data processing unit DPU, characterized in that: The DPU includes: a TCP flow control module, a TSL record processing module and a post-quantum cryptography acceleration module; The post-quantum cryptography acceleration module is used to integrate the post-quantum algorithm and use the post-quantum algorithm for key negotiation and identity authentication during the TLS handshake phase; The TLS record processing module is configured to, during the data exchange phase, split the encrypted data into TLS records and send the split TLS records to the TCP flow control module; and decrypt the TLS records extracted by the TCP flow control module so as to send the decrypted data to the operating system protocol stack; the operating system protocol stack supports post-quantum algorithms; The TCP flow control module is used to encapsulate the split TLS records into TCP data packets during the data interaction stage; perform flow control and sequence processing of TCP data packets; and receive TCP data packets, extract TLS records, and send the extracted TLS records to the TSL record processing module.
2. The DPU according to claim 1, wherein The post-quantum cryptography acceleration module is specifically used to implement key negotiation using a post-quantum algorithm through the following steps: generating a first key pair based on the post-quantum algorithm, the first key pair comprising a first public key and a first private key; Receive the second public key in the second key pair generated by the server, determine the shared key, and send the ciphertext encrypted by the shared key using the second public key to the server, so that the server uses the second private key in the second key pair to decrypt the ciphertext and obtain the shared key.
3. The DPU according to claim 1, wherein: The DPU is applied to a client device; The post-quantum cryptography acceleration module is specifically used to implement identity authentication using a post-quantum algorithm through the following steps: Based on the received server certificate sent by the server, obtain the post-quantum public key generated by the post-quantum algorithm in the server certificate; Authenticate the server based on the post-quantum public key and the server certificate.
4. The DPU according to claim 2, wherein: The post-quantum cryptography acceleration module is further used to determine an encryption key based on the shared key and send the encryption key to the TSL record processing module.
5. The DPU according to claim 4, wherein: The TLS record processing module is specifically used to receive the data stream sent by the operating system protocol stack during the data interaction stage, and encrypt the data stream according to the encryption key and the symmetric encryption algorithm; split the encrypted data stream into TLS records that comply with the TLS protocol format; and decrypting the TLS record extracted by the TCP flow control module according to the encryption key and a symmetric decryption algorithm, wherein the symmetric decryption algorithm corresponds to the symmetric encryption algorithm.
6. The DPU according to claim 5, wherein: Each TLS record includes a record header, encrypted data, and a message authentication code (MAC). The record header includes the version, data type, and data length. The MAC is obtained by signing the corresponding TLS record using a post-quantum algorithm.
7. The DPU according to claim 1, wherein: The TCP flow control module is specifically used to encapsulate TLS records into TCP data packets during the data exchange phase, and then sort the encapsulated TCP data packets according to the sequence numbers of the encapsulated TCP data packets; And, in the data interaction stage, after receiving the TCP data packets, the received TCP data packets are sorted according to the sequence numbers of the received TCP data packets, so as to extract TLS records from the sorted TCP data packets in sequence.
8. The DPU according to claim 1, wherein: The TCP flow control module is further specifically used to detect whether the TCP data packet is lost through the sequence number and ACK confirmation mechanism of the TCP data packet. If it is detected that the TCP data packet is lost, a retransmission request is triggered to instruct the TCP data packet to be resent.
9. The DPU according to any one of claims 1 to 8, wherein: The post-quantum algorithm includes: Kyber, which provides an efficient key exchange mechanism; LMS-SM3 / HSS-SM3, for providing quantum-safe identity authentication and signature verification; SM3 is used as a message authentication code algorithm to ensure data integrity.
10. The DPU according to any one of claims 1 to 8, wherein: The DPU is applied to a client device.
Citation Information
Patent Citations
Secure transmission method and system based on quantum key encapsulation and negotiation after mixing
CN114629646A
TLS protocol negotiation method and device, and medium
CN115174267A
Method and device for transport layer security protocol message service, and medium
CN116232944A
Extensible TLS protocol post quantum encryption system
CN116996210A
Session processing method, system and device, equipment and storage medium
CN117749865A