Hardware acceleration equipment management system and method applied to network security product
By using the PCIe to M.2 adapter board module and the corresponding monitoring, allocation, and scheduling modules, the compatibility and power management issues of hardware acceleration devices in cybersecurity products have been resolved, thereby improving the processing efficiency and stability of the devices.
Patent Information
- Application Number
- CN202511078960.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-02
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-08-02
AI Technical Summary
Existing cybersecurity products cannot directly use standard modules on the market for hardware acceleration devices, resulting in poor device compatibility, inflexible power management, and insufficient correlation between the heat dissipation system and task load, which affects device performance and stability.
It adopts a PCIe to M.2 adapter board module, a structural support module, a real-time load monitoring module, a dynamic resource allocation module, a cross-device task scheduling module, and a device compatibility adaptation module to achieve plug-and-play hardware, dynamic task allocation, and adaptive heat dissipation control.
It improved processing efficiency, reduced development and replacement costs, enhanced the compatibility and stability of equipment management, and achieved effective linkage between heat dissipation and task scheduling.
Smart Images

Figure CN120909969A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of hardware acceleration device management of network security products, in particular to a hardware acceleration device management system and method applied to network security products. BACKGROUND
[0002] For network security products, there is usually only a network interface externally. Previously, many software processing tasks were completely handled by the CPU. In recent years, with the emergence of hardware acceleration devices, hardware acceleration devices can be used to reduce the load of the CPU and improve the efficiency of the system. Network security products have increasingly high compatibility requirements for hardware acceleration devices.
[0003] Defects and deficiencies of the prior art:
[0004] The hardware acceleration devices on the market are usually in the form of PCIE cards or M.2. Since the external expansion of network security products needs to be expanded into non-standard PCIE cards through a PCIE connector, it is currently not possible to directly use standard modules on network security products.
[0005] In order to use acceleration devices, if the acceleration devices are directly designed according to the specifications of network security products, the circuit needs to be redesigned, which requires a long development cycle, and the demand for network security devices is relatively small, so the cost of newly designed acceleration devices is higher. At the same time, if a new hardware acceleration device needs to be replaced, it needs to be redesigned, and the replacement cost of the device is also high.
[0006] In traditional network security products, M.2 devices are used as hardware acceleration devices, and the existing power consumption management method has many defects. On the one hand, the power consumption configuration of the device is usually manually set statically in the initial stage, which cannot adapt to the dynamic changes of network security tasks. For example, during daily office hours, network traffic and encryption tasks are relatively small, but the device still runs according to the power consumption configuration of high load, resulting in energy waste, and the device being in a high power consumption state for a long time also accelerates hardware aging. On the other hand, the cooling system is not effectively associated with the task load and power consumption state of the device. Traditional cooling control is mostly based on a fixed temperature threshold, and when the device temperature exceeds the threshold, the cooling measures are started. This method does not take into account the power consumption difference generated by different task types and the cooling demand of the device in different performance states. For example, when performing high-intensity encryption tasks, the device power consumption increases significantly, generating a large amount of heat, but since the cooling system fails to adjust the cooling strategy in a timely manner according to the task load, the device temperature is too high, which affects the device performance and stability, and may even cause system failure, affecting the normal operation of network security products.
[0007] Based on the above problems, the present application proposes a hardware acceleration device management system and method applied to network security products to solve the above problems. SUMMARY
[0008] The application aims to provide a hardware acceleration device management system and method applied to network security products to solve the problems in the prior art.
[0009] To achieve the above-mentioned purpose, the application provides the following technical scheme:
[0010] A hardware acceleration device management system applied to network security products, comprising a PCIE-to-M.2 adapter plate module, a structure support module, a load real-time monitoring module, a resource dynamic allocation module, a cross-device task scheduling module, and a device compatibility adaptation module; the PCIE-to-M.2 adapter plate module is a hardware carrier, the input end is connected to a network security product PCIE X8 slot, and the output end is provided with two M.2 connectors; the structure support module connects the adapter plate and the M.2 device, and uses a physical bracket and screw holes to fix the device and the adapter plate; characterized in that: the load real-time monitoring module extracts traffic and encryption / decryption task quantity in real time through a network task acquisition unit, obtains the number of idle cores, the remaining bandwidth, and the temperature of the device through a device performance acquisition unit, and generates a JSON format real-time report by a data report generation unit; the resource dynamic allocation module calculates the score based on a formula, device resource score = (idle core number / total core number) x 0.6 + (remaining memory bandwidth / total memory bandwidth) x 0.4, and implements task allocation by a task allocation execution unit according to the strategy of preferentially allocating encryption tasks to hardware encryption devices, allocating traffic tasks to high-score devices, and uniformly allocating decryption tasks to double devices; the cross-device task scheduling module connects the allocation module and the M.2 device, calculates the device utilization rate through a load threshold monitoring unit, selects migratable tasks and migrates them to the target device by a task migration execution unit when the sampling is more than 80% for five consecutive times, dynamically configures the PCIE channel through a BIOS mode switching unit, and keeps the PCIE X8 mode in the single-device mode and configures the X4+X4 mode in the double-device mode; the device compatibility adaptation module connects the M.2 device and the system software layer, reads the device ID and firmware information through a firmware recognition unit, automatically loads compatible drivers by a driver management unit, updates the device list in real time and triggers resource reallocation through a hot plug detection unit, obtains the device power consumption parameters and establishes a task power consumption correlation model through a power consumption feature recognition unit, dynamically adjusts the device performance state and the speed of the cooling fan based on load prediction by a dynamic power consumption scheduling unit, and adjusts the speed of the fan and triggers the frequency reduction protection and task migration when the temperature is too high by an adaptive cooling control unit through a temperature and power consumption relationship model.
[0011] The PCIE-to-M.2 adapter plate module comprises an allocation unit and a clock processing unit;
[0012] The distribution unit splits the X8 signal input by the PCIE X8 slot of the network security product into two independent PCIE X4 signals through the internal wiring of the PCB, and the two X4 signals correspond to two M.2 connectors of the adapter board output end respectively; when a single slot is inserted with an M.2 device, only one X4 signal transmits data; when both slots are inserted with M.2 devices, two X4 signals transmit data in parallel, at this time, the PCIE slot needs to be configured as X4+X4 mode through BIOS to support parallel communication of double devices.
[0013] The clock processing unit integrates a clock buffer chip CLK BUFFER, which copies the clock signal CLK input by the PCIE slot into two synchronous clock signals, and the two clock signals are connected to the two M.2 connectors respectively, providing synchronous clock signals for the corresponding M.2 devices and ensuring the clock synchronization of the devices when working in single slot and double slot.
[0014] The structure support module includes a physical bracket unit and a screw fixing unit.
[0015] The physical bracket unit is a rectangular frame structure made of insulating material, and the frame size matches the edge of the PCB board of the PCIE to M.2 adapter board, and is fixed to the edge of the adapter board by welding; the inner side of the frame is provided with a limiting groove corresponding to the size of the M.2 device, and the groove length is compatible with the standard M.2 device, so that after the device is inserted into the M.2 connector and embedded in the limiting groove, the bottom surface is kept parallel to the PCB of the adapter board, and the side surface is embedded in the groove for positioning.
[0016] The screw fixing unit is responsible for fixing the M.2 device on the bracket, and the top of the physical bracket is provided with a threaded hole corresponding to the screw hole position of the M.2 device; after the M.2 device is inserted into the connector and embedded in the limiting groove, a countersunk screw is used to pass through the screw hole on the surface of the device and is screwed into the threaded hole of the bracket to fix the top surface of the device on the bracket; the number of screws corresponding to each M.2 device is configured according to the number of fixing holes of the standard M.2 device, so as to ensure that the device keeps stable electrical connection with the adapter board in a vibrating environment.
[0017] The load real-time monitoring module includes a network task acquisition unit, a device performance acquisition unit and a data report generation unit.
[0018] The network task acquisition unit establishes a data channel with the task processing queue through the network protocol stack interface of the network security product, and extracts the byte number of inbound / outbound traffic from the network card driver layer in real time, calculates the average traffic rate at a preset fixed interval, and the calculation formula is as follows:
[0019] ;
[0020] Where Δbyte number is the difference between the traffic byte values of adjacent two samples, and Δtime is the sampling interval, which is in seconds.
[0021] The average flow rate is calculated while monitoring the encryption / decryption task scheduling queue, the number of newly added task entries per second is counted, real-time data of the data encryption task quantity and the data decryption task quantity are formed, and the current network task load is directly reflected;
[0022] The device performance acquisition unit obtains device state data through a firmware management interface of the M.2 device; specifically, the number of idle cores is obtained by querying CPU / MCU core state registers and counting the number of cores in an idle state, and the number of idle cores is the number of registers with a utilization rate of less than or equal to 5%; then, the used memory bandwidth is obtained through a memory controller state register, and the remaining bandwidth is calculated according to the formula by combining the total nominal memory bandwidth, and the calculation formula is as follows:
[0023] Remaining memory bandwidth = total memory bandwidth - used memory bandwidth
[0024] Finally, the real-time temperature data of the M.2 device is obtained by reading the register value of the on-board temperature sensor, and all parameters are read in real time through a standardized interface;
[0025] The data report generation unit aligns the data output by the network task acquisition unit and the device performance acquisition unit in time stamp, generates a structured report in UTC time format; the report includes the fields of flow rate, encryption task quantity, decryption task quantity, idle core number, remaining memory bandwidth, and temperature, and is stored in the shared memory buffer of the network security product in JSON format for real-time calling by the resource dynamic allocation module.
[0026] The resource dynamic allocation module includes a data receiving unit, a fusion model calculation unit, and a task allocation execution unit.
[0027] The data receiving unit reads the JSON format real-time load performance data report generated by the load real-time monitoring module in real time through the shared memory interface of the network security product, and parses the fields of flow rate, encryption task quantity, decryption task quantity, idle computing core number, remaining memory bandwidth, and temperature from the report; the data reading frequency is consistent with the load monitoring frequency, the latest network task load and M.2 device performance state data are obtained in real time, and real-time basis is provided for subsequent task allocation;
[0028] The fusion model calculation unit processes the received real-time data based on a preset fusion model to generate a task allocation strategy; specifically, first, the device remaining resource ratio is calculated according to the task type and device performance parameters, and the task type is divided into encryption, decryption, and flow processing; the calculation formula is as follows:
[0029] ;
[0030] Wherein 0.6 and 0.4 are the weight coefficients of the core number and the memory bandwidth, which can be adjusted by BIOS configuration; then, according to the strategy of preferentially allocating the encryption task to the device supporting hardware encryption, allocating the traffic processing task to the device with high resource score, and uniformly allocating the decryption task to the dual-device, the matching relationship between the task and the device is determined.
[0031] The task allocation execution unit allocates the pending task in the task queue to the target M.2 device according to the fusion model calculation result, specifically: in the single-device mode PCIE X8, only the task instruction is sent to the slot of the inserted device; in the dual-device mode PCIE X4+X4, if the task can be split, the task quantity is split according to the device resource score ratio, and the device with higher resource score is allocated more tasks; if the task cannot be split, it is allocated to the device with the highest current resource score; the task allocation sends the task descriptor containing the task type, data address and priority information to the target device through the PCIe configuration space.
[0032] The cross-device task scheduling module includes a load threshold monitoring unit, a task migration execution unit and a BIOS mode switching unit.
[0033] The load threshold monitoring unit is used to read the M.2 device performance data output by the resource dynamic allocation module in real time, and calculate the device load through the formula as follows:
[0034] Device utilization rate = 1-(idle computing core number / total core number);
[0035] Wherein, the idle computing core number is the core number with utilization rate ≤5% counted by the device performance acquisition unit, and the total core number is the device firmware nominal value; when the utilization rate of a device is continuously sampled for 5 times and exceeds the threshold of 80%, the cross-device task migration process is triggered, wherein the interval time of continuous sampling is a preset fixed interval time;
[0036] The task migration execution unit, after receiving the trigger signal of the load threshold monitoring unit, first screens the migratable tasks and excludes the tasks that need to be processed by the fixed device; then, the source device task is suspended, the context information such as task progress and data pointer is stored to the shared memory, and the task descriptor containing the task ID, source device slot, target device slot and recovery address is sent to the target device through the PCIe configuration space, and the target device reads the information from the shared memory and continues to execute the task;
[0037] The migratable task refers to a task not dependent on unique hardware resources of the M.2 device, and specifically includes a general traffic cleaning task and a batch data encryption task; the general traffic cleaning task is a stateless processing such as filtering and rate limiting of network traffic, and can be executed on any M.2 device supporting the PCIe protocol; the batch data encryption task is batch data processing based on a standard encryption algorithm and is not dependent on a built-in key storage module of the device;
[0038] The fixed device processing task refers to a task that must depend on unique hardware resources of the M.2 device, and specifically includes a decryption task based on a unique key of the device and a customized protocol acceleration task; the decryption task based on the unique key of the device needs to call an exclusive key stored in a security chip on board of the M.2 device, and can only execute a decryption operation on the device; the customized protocol acceleration task is a task using a self-defined instruction set and a hardware acceleration unit of the device, and cannot be run on other models of devices;
[0039] The BIOS mode switching unit queries an insertion state of the M.2 device in real time through a system management interface; specifically, when only a single slot is inserted with the device, a PCIe_ConfigurateLinkWidth() function of the BIOS is called to configure the PCIE slot as an X8 mode; when both slots are inserted with the device, the function is called and an X4+X4 parameter is input to trigger the BIOS to split the PCIE channel into two independent X4s; after the configuration is completed, the mode is validated by restarting the PCIe link; if device hot plugging occurs, the above process is repeated in real time to dynamically switch the channel mode.
[0040] The device compatibility adaptation module includes a firmware identification unit, a driver management unit, an instruction set adaptation unit, and a hot plugging detection unit;
[0041] The firmware identification unit reads firmware information of the M.2 device through a PCIe configuration space; specifically, a vendor ID and a device ID are read from a device configuration register address; then a firmware version string is read from an extended configuration space to parse a PCIe protocol version, an interface mode, and an M.2 specification supported by the device; finally, the ID and the specification read are matched by a device information database built in a nonvolatile memory of the network security product to determine a device vendor, a model, and supported functions;
[0042] The driver management unit executes driver loading according to the device ID output by the firmware identification unit; specifically, first, a driver program file corresponding to the vendor ID and the device ID is retrieved from a driver library through a network security product operating system driver interface and loaded into a kernel and a system service layer; then initialization parameters are transmitted to the driver program according to device specification information; finally, before loading, the driver program version is checked for compatibility with the device firmware version, and an error prompt is triggered when the versions are incompatible;
[0043] The instruction set adaptation unit establishes a mapping between standardized task instructions and device-specific instruction sets based on device firmware identification results; specifically: first, define a unified task instruction format, which is converted into device native instructions through a lookup table; then, write an adaptation function for different device register layout differences, and the device automatically addresses through the adaptation function; finally, maintain a device instruction execution state table to ensure that the register state context is consistent when scheduling tasks across devices;
[0044] The hot plug detection unit manages hot plug through monitoring PCIe link state registers; specifically: periodically query the registers, and when the link state changes from Down to Up, it is determined that the device is inserted, and when it changes from Up to Down, it is determined that the device is removed; when insertion is detected, the firmware identification unit is triggered to start, and the device information is added to the system identifiable list, and when removal is detected, the device is deleted and its task is terminated; then, send the device state change notification to the resource dynamic allocation module through the system message bus, trigger the task allocation strategy, and mobilize the fusion model calculation unit to recalculate the device resource score;
[0045] The power consumption feature recognition unit obtains the basic power consumption parameters of the device, including the nominal maximum power, the power consumption value corresponding to each performance state, and the conversion delay, by reading the device management registers of the PCIe configuration space; based on the historical report data generated by the load real-time monitoring module, an association model of task type and power consumption feature is established, forming a power consumption feature library for different task types;
[0046] The dynamic power consumption scheduling unit processes historical load data using the Kalman filtering algorithm based on the task allocation results of the resource dynamic allocation module, establishes a state space model and generates a smooth future load change trend prediction sequence through a prediction-update two-stage iteration, and synchronizes the results to the resource dynamic allocation module to adjust the task allocation strategy; according to the predicted load, the ACPI interface of the device driver is called to dynamically adjust the performance state and idle state defined by ACPI; when the resource utilization is <30%, automatically switch to the lowest available performance state; when the resource utilization is between 30%-70%, maintain the default state; when the resource utilization is >70%, temporarily improve to the highest available performance state, which requires device support, and simultaneously adjust the fan speed;
[0047] The adaptive cooling control unit establishes a relationship model between device temperature and power consumption: Δtemperature=f(power consumption, cooling efficiency), where the cooling efficiency is related to fan speed and environmental temperature; based on the relationship model, the fan speed is dynamically adjusted through the pulse width modulation interface according to the real-time temperature and predicted load, and the calculation formula is as follows:
[0048] Target rotation speed = base rotation speed + coefficient k x (current temperature - reference temperature) + coefficient m x (predicted load - current load),
[0049] Wherein the coefficients k, m are configurable parameters, and the reference temperature is the optimal working temperature of the device; when the temperature exceeds the preset threshold, the load threshold triggers task migration in priority, and the performance state of the device is reduced, and the cross-device task scheduling module is notified to migrate part of the tasks.
[0050] A hardware acceleration device management method applied to a network security product, comprising the following steps:
[0051] S1, connect the PCIE X8 slot of the network security product with the M.2 device through the adapter board, split the X8 signal into two independent X4 signals by using internal wiring, and copy the clock signal into two paths for synchronous transmission to the device through the clock buffer, thereby providing a hardware basis for double-device parallel communication;
[0052] S2, on the basis of interface connection, use insulating brackets and screw holes for physical fixation, parallelly paste the bottom surface of the M.2 device with the PCB of the adapter board, and then embed the side surface into the limiting groove for positioning, and then fix the top surface of the device to the bracket through the countersunk screw, so as to ensure that the device maintains stable electrical connection with the adapter board in a compact space, and provides physical support for subsequent data collection;
[0053] S3, through the network protocol stack interface and the device firmware management interface, real-time extraction of network traffic rate, data encryption task quantity, data decryption task quantity, and device idle computing core number, remaining memory bandwidth and temperature data, generation of real-time load performance data report in JSON format according to preset frequency, and provision of real-time parameters for task allocation strategy;
[0054] S4, read real-time report from shared memory, calculate device resource score based on fusion model, and allocate tasks to target devices according to the strategy of preferentially supporting hardware acceleration of encryption task, allocating traffic processing task to device with high resource score, and uniformly allocating decryption task between double devices;
[0055] S5, when the single-device utilization rate exceeds 80% threshold for 5 times in succession, screen non-exclusive tasks, suspend source device tasks and migrate context information to idle device, and simultaneously call BIOS function to switch PCIE channel mode, thereby realizing dynamic balance of task processing efficiency;
[0056] S6, read the vendor ID, device ID and specification information of the device firmware through the PCIe configuration space, automatically load the corresponding driver and establish a mapping table of standardized instructions and device native instructions based on the device firmware identification result, and monitor the PCIe link state in real time, update the identifiable list when the device is inserted, terminate the task and trigger resource reallocation when the device is removed, finally, obtain the power consumption parameters by reading the device management register and establish a task power consumption model, dynamically adjust the device performance state and cooling fan speed based on load prediction, adjust the fan speed through the temperature and power consumption relationship model and trigger frequency reduction protection and task migration when the temperature is too high.
[0057] Compared with the prior art, the beneficial effects of the present application are:
[0058] 1, real-time load monitoring and dynamic scheduling, improve processing efficiency: the load real-time monitoring module collects network traffic, task quantity and device performance data at a frequency of 10 times per second to generate real-time reports. The resource dynamic allocation module allocates tasks based on the fusion model according to the remaining resource proportion of the device and the task type, for example, encryption tasks are preferentially allocated to devices supporting hardware acceleration, and traffic tasks are allocated to devices with high resource scores. When the utilization rate of a single device exceeds 80% for 5 consecutive times, the cross-device task scheduling module migrates the migratable task to an idle device and dynamically switches the PCIE channel mode to avoid single-point overload, and the overall task processing efficiency is improved by more than 40%.
[0059] 2, hardware plug and play, reduce development and replacement cost: through the PCIE to M.2 adapter board module, network security products can directly access standard M.2 hardware acceleration devices on the market without redesigning the circuit. The adapter board splits the PCIE X8 signal into two X4 signals through internal PCB wiring and realizes double-device clock synchronization through a clock buffer, so that network security products do not need to adapt to different device circuit interfaces, reducing the hardware development cycle by about 60%, and avoiding the cost of redesign caused by device replacement, reducing the adaptation cost by about 70%.
[0060] 3, standardization and compatibility, simplify device management: the device compatibility adaptation module reads the vendor ID, device ID and firmware version of the M.2 device, automatically loads the corresponding driver, and establishes a mapping table of standardized instructions and device native instructions; at the same time, it monitors the hot plug state in real time, automatically updates the identifiable list when the device is inserted, terminates the task and triggers resource reallocation when the device is removed, realizes plug and play, compatible with 2242 / 2260 / 2280 and other specifications M.2 devices, reduces 90% of manual adaptation operation, improves system compatibility and maintainability.
[0061] 4. Effective linkage of heat dissipation and task scheduling: In traditional network security products, heat dissipation control is often simply adjusted according to the current temperature, and is independent of task scheduling. When the device temperature is too high, it cannot be relieved in time through task migration and other methods, resulting in a decrease in device performance or even failure. The adaptive heat dissipation control unit of the present scheme can automatically trigger frequency reduction protection and notify the cross-device task scheduling module to migrate part of the tasks when the temperature exceeds the threshold, realizing effective linkage of heat dissipation and task scheduling and ensuring stable operation of the device within a safe temperature range. BRIEF DESCRIPTION OF DRAWINGS
[0062] Figure 1 A PCIE to M.2 hardware signal distribution and clock synchronization schematic diagram of a hardware acceleration device management system applied to a network security product of the present application;
[0063] Figure 2 A PCIE to M.2 device implementation form diagram of a hardware acceleration device management system applied to a network security product of the present application;
[0064] Figure 3 A PCIE to M.2 adapter board PCB block diagram of a hardware acceleration device management system applied to a network security product of the present application;
[0065] Figure 4 A system workflow diagram of a hardware acceleration device management system applied to a network security product of the present application. DETAILED DESCRIPTION
[0066] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.
[0067] Embodiment: As shown in the figure, the present application provides a technical solution, Figures 1-4
[0068] A hardware acceleration device management system applied to network security products, comprising a PCIE-to-M.2 adapter board module, a structural support module, a load real-time monitoring module, a resource dynamic allocation module, a cross-device task scheduling module, and a device compatibility adaptation module; the PCIE-to-M.2 adapter board module is a hardware carrier, the input end is connected to a network security product PCIE X8 slot, and the output end is provided with two M.2 connectors; the structural support module connects the adapter board and the M.2 device, and uses a physical bracket and screw holes to fix the device and the adapter board; characterized in that: the load real-time monitoring module extracts traffic and encryption / decryption task volume in real time through a network task acquisition unit, obtains the number of idle cores, the remaining bandwidth, and the temperature of the device through a device performance acquisition unit, and generates a JSON format real-time report by a data report generation unit; the resource dynamic allocation module calculates the score based on the formula device resource score = (idle core number / total core number) × 0.6 + (remaining memory bandwidth / total memory bandwidth) × 0.4, and implements task allocation by a task allocation execution unit according to the strategy of preferentially allocating encryption tasks to hardware encryption devices, allocating traffic tasks to high-score devices, and evenly allocating decryption tasks to double devices; the cross-device task scheduling module connects the allocation module and the M.2 device, calculates the device utilization rate through a load threshold monitoring unit, selects migratable tasks and migrates them to the target device through a task migration execution unit when the sampling is more than 80% for 5 consecutive times, dynamically configures the PCIE channel through a BIOS mode switching unit, and keeps the PCIE X8 mode in the single-device mode and configures the X4+X4 mode in the double-device mode; the device compatibility adaptation module connects the M.2 device and the system software layer, reads the device ID and firmware information through a firmware recognition unit, automatically loads compatible drivers through a driver management unit, updates the device list in real time and triggers resource reallocation through a hot plug detection unit, obtains device power consumption parameters and establishes a task power consumption correlation model through a power consumption feature recognition unit, dynamically adjusts the device performance state and the speed of the cooling fan based on load prediction through a dynamic power consumption scheduling unit, and adjusts the speed of the fan through a temperature and power consumption relationship model and triggers frequency reduction protection and task migration when the temperature is too high through an adaptive cooling control unit.
[0069] The PCIE-to-M.2 adapter board module comprises a distribution unit and a clock processing unit;
[0070] The distribution unit splits the X8 signal input by the network security product PCIE X8 slot into two independent PCIE X4 signals through internal wiring on the PCB, and the two X4 signals correspond to the two M.2 connectors at the output end of the adapter board; when a single slot is inserted with an M.2 device, only one X4 signal transmits data; when both slots are inserted with M.2 devices, two X4 signals transmit data in parallel, at which time the PCIE slot needs to be configured as X4+X4 mode through BIOS to support double-device parallel communication;
[0071] The clock processing unit integrates a clock buffer chip CLK BUFFER, which copies the clock signal CLK input from the PCIE slot into two synchronous clock signals, and the two clock signals are connected to two M.2 connectors respectively, to provide synchronous clock signals for the corresponding M.2 devices, ensuring the clock synchronization of the devices in single-slot and double-slot working modes.
[0072] The structural support module comprises a physical bracket unit and a screw fixing unit.
[0073] The physical bracket unit is a rectangular frame structure made of insulating material, and the frame size matches the edge of the PCB of the PCIE-to-M.2 adapter board, and is fixed to the edge of the adapter board by welding. The inner side of the frame is provided with a limiting groove corresponding to the size of the M.2 device, and the groove length is compatible with the standard M.2 device, to ensure that the bottom surface of the device is parallel to the PCB of the adapter board after the device is inserted into the M.2 connector, and the side surface is embedded in the groove for positioning.
[0074] The screw fixing unit is responsible for fixing the M.2 device on the bracket. The top of the physical bracket is provided with a threaded hole corresponding to the screw hole position of the M.2 device. After the M.2 device is inserted into the connector and embedded in the limiting groove, a countersunk screw is used to pass through the screw hole on the surface of the device and is screwed into the threaded hole of the bracket to fix the top surface of the device on the bracket. The number of screws corresponding to each M.2 device is equal to the number of fixing holes of the standard M.2 device, to ensure that the device remains electrically connected to the adapter board stably in a vibrating environment.
[0075] The load real-time monitoring module comprises a network task acquisition unit, a device performance acquisition unit and a data report generation unit.
[0076] The network task acquisition unit establishes a data channel with the task processing queue through the network protocol stack interface of the network security product, and extracts the number of bytes of inbound / outbound traffic from the network card driver layer in real time. The average traffic rate is calculated at a preset fixed interval time, and the calculation formula is as follows:
[0077] ;
[0078] Where Δbyte number is the difference between the traffic bytes of two adjacent samples, and Δtime is the sampling interval, in seconds.
[0079] While calculating the average traffic rate, the encryption / decryption task scheduling queue is monitored, the number of new task entries per second is counted, and the real-time data of the data encryption task quantity and the data decryption task quantity are formed, directly reflecting the current network task load.
[0080] The device performance acquisition unit obtains device state data through a firmware management interface of the M.2 device; specifically: the number of idle cores is counted by querying a CPU / MCU core state register to obtain the number of idle computing cores, and the number of idle cores is a register with a utilization rate ≤ 5%; then, used memory bandwidth is obtained through a memory controller state register, and the remaining bandwidth is calculated according to a formula in combination with a device nominal total memory bandwidth, and the calculation formula is as follows:
[0081] Remaining memory bandwidth = total memory bandwidth - used memory bandwidth
[0082] Finally, real-time temperature data of the M.2 device is obtained by reading a register value of a built-in temperature sensor, and all parameters are read in real time through a standardized interface;
[0083] The data report generation unit timestamps the data output by the network task acquisition unit and the device performance acquisition unit, generates a structured report in a UTC time format, and the report includes fields such as traffic rate, encryption task amount, decryption task amount, idle core number, remaining memory bandwidth, and temperature, which are stored in a shared memory buffer of the network security product in a JSON format for real-time calling by the resource dynamic allocation module.
[0084] The resource dynamic allocation module includes a data receiving unit, a fusion model calculation unit, and a task allocation execution unit.
[0085] The data receiving unit reads the JSON format real-time load performance data report generated by the load real-time monitoring module in real time through a shared memory interface of the network security product, parses the fields such as traffic rate, encryption task amount, decryption task amount, idle computing core number, remaining memory bandwidth, and temperature from the report, and the data reading frequency is consistent with the load monitoring frequency to obtain the latest network task load and M.2 device performance state data in real time to provide real-time basis for subsequent task allocation;
[0086] The fusion model calculation unit processes the received real-time data based on a preset fusion model to generate a task allocation strategy; specifically: first, the device remaining resource ratio is calculated according to the task type and device performance parameters, and the task type is divided into encryption, decryption, and traffic processing; the calculation formula is as follows:
[0087]
[0088] wherein 0.6 and 0.4 are weight coefficients of the core number and the memory bandwidth, which can be adjusted through BIOS configuration; then, the matching relationship between the task and the device is determined according to the strategy that the encryption task is preferentially allocated to the device supporting hardware encryption, the traffic processing task is allocated to the device with a high resource score, and the decryption task is uniformly allocated to the dual device.
[0089] The task allocation execution unit allocates the pending tasks in the task queue to the target M.2 device according to the fusion model calculation result, specifically: in the single-device mode PCIE X8, only the task instruction is sent to the slot of the inserted device; in the dual-device mode PCIE X4+X4, if the task can be split, the task quantity is split according to the device resource score ratio, and the device with higher resource score is allocated more tasks; if the task cannot be split, it is allocated to the device with the highest current resource score; the task allocation sends the task descriptor containing the task type, data address and priority information to the target device through the PCIe configuration space.
[0090] The cross-device task scheduling module includes a load threshold monitoring unit, a task migration execution unit and a BIOS mode switching unit.
[0091] The load threshold monitoring unit is used to read the M.2 device performance data output by the resource dynamic allocation module in real time, and calculate the device load through a formula, the calculation formula being as follows:
[0092] Device utilization rate = 1 - (number of idle computing cores / total number of cores);
[0093] Wherein, the number of idle computing cores is the number of cores with utilization rate ≤5% counted by the device performance acquisition unit, and the total number of cores is the nominal value of the device firmware; when the utilization rate of a device is continuously sampled for 5 times and exceeds the threshold of 80%, the cross-device task migration process is triggered, wherein the interval time of continuous sampling is a preset fixed interval time;
[0094] The task migration execution unit, after receiving the trigger signal of the load threshold monitoring unit, first screens the migratable tasks and excludes tasks that need to be processed by fixed devices; then suspends the source device task, stores the context information such as task progress and data pointer to the shared memory, sends the task descriptor containing the task ID, source device slot, target device slot and recovery address to the target device through the PCIe configuration space, and the target device continues to execute the task after reading the information from the shared memory;
[0095] Wherein, the migratable task refers to a task that does not depend on the unique hardware resources of the M.2 device, specifically including general traffic cleaning tasks and batch data encryption tasks; wherein, the general traffic cleaning task is a stateless processing such as filtering and rate limiting of network traffic, which can be executed on any M.2 device supporting PCIe protocol; the batch data encryption task is a batch data processing based on standard encryption algorithm, which does not depend on the built-in key storage module of the device;
[0096] The task handled by the fixed device refers to a task that must rely on the hardware resource unique to the M.2 device, and specifically includes a decryption task based on a unique key of the device and a customized protocol acceleration task; wherein the decryption task based on the unique key of the device needs to call a special key stored in a security chip on board of the M.2 device, and can only perform a decryption operation on the device; the customized protocol acceleration task is a task of using a device self-defined instruction set and a hardware acceleration unit, and cannot be run on other models of devices;
[0097] The BIOS mode switching unit queries the M.2 device insertion state in real time through a system management interface; specifically: when only a single slot is inserted with a device, a PCIe_ConfigurateLinkWidth() function of BIOS is called to configure the PCIE slot as an X8 mode; when both slots are inserted with devices, the function is called and an X4+X4 parameter is passed in to trigger the BIOS to split the PCIE channel into two independent X4s; after the configuration is completed, the mode is validated by restarting the PCIe link; if device hot plugging occurs, the above process is repeated in real time to dynamically switch the channel mode.
[0098] The device compatibility adaptation module includes a firmware identification unit, a driver management unit, an instruction set adaptation unit and a hot plug detection unit;
[0099] The firmware identification unit reads the firmware information of the M.2 device through the PCIe configuration space; specifically: the vendor ID and the device ID are read from the device configuration register address; then the firmware version string is read from the extended configuration space to parse the PCIe protocol version, the interface mode and the M.2 specification supported by the device; finally, through the device information database built in the non-volatile memory of the network security product, the read ID and specification are matched to determine the device manufacturer, model and supported functions;
[0100] The driver management unit executes driver loading according to the device ID output by the firmware identification unit; specifically: first, through the network security product operating system driver interface, the driver program file corresponding to the vendor ID and the device ID is retrieved from the driver library and loaded into the kernel and the system service layer; then, initialization parameters are passed to the driver program according to the device specification information; finally, before loading, the compatibility of the driver program version and the device firmware version is checked, and an error prompt is triggered when they are incompatible;
[0101] The instruction set adaptation unit establishes a mapping between the standardized task instruction and the device specific instruction set based on the device firmware identification result; specifically: first, define a unified task instruction format, which is converted into a device native instruction through a lookup table; then, for different device register layout differences, an adaptation function is written, and the device automatically addresses through the adaptation function; finally, a device instruction execution state table is maintained to ensure that the state context of the register is consistent when scheduling tasks across devices;
[0102] The hot plug detection unit realizes hot plug management by monitoring the PCIe link state register; specifically: periodically query the register, when the link state changes from Down to Up, it is determined that the device is inserted, and when it changes from Up to Down, it is determined that the device is removed; when insertion is detected, the firmware identification unit is triggered to start, and the device information is added to the system identifiable list, when removal is detected, the device is deleted and its task is terminated; then send the device state change notification to the resource dynamic allocation module through the system message bus, trigger the task allocation strategy, and mobilize the fusion model calculation unit to recalculate the device resource score;
[0103] The power consumption feature recognition unit obtains the basic power consumption parameters of the device by reading the device management register of the PCIe configuration space, including the nominal maximum power, the power consumption value corresponding to each performance state and the conversion delay; based on the historical report data generated by the load real-time monitoring module, an association model of task type and power consumption feature is established, and a power consumption feature library of different task types is formed;
[0104] The dynamic power consumption scheduling unit processes historical load data based on the task allocation result of the resource dynamic allocation module using the Kalman filtering algorithm, establishes a state space model and generates a smooth future load change trend prediction sequence through a prediction-update two-stage iteration, and synchronizes the result to the resource dynamic allocation module to adjust the task allocation strategy; according to the predicted load, the ACPI interface of the device driver is called to dynamically adjust the performance state and idle state defined by ACPI of the device: when the resource utilization rate is <30%, it is automatically switched to the lowest available performance state; when the resource utilization rate is between 30%-70%, the default state is maintained; when the resource utilization rate is >70%, it is temporarily boosted to the highest available performance state, which requires device support, and the speed of the cooling fan is adjusted synchronously;
[0105] The adaptive cooling control unit establishes a relationship model between device temperature and power consumption: Δtemperature=f(power consumption, cooling efficiency), where the cooling efficiency is related to the fan speed and the environment temperature; based on the relationship model, the speed of the cooling fan is dynamically adjusted through the pulse width modulation interface according to the real-time temperature and the predicted load, and the calculation formula is as follows:
[0106] Target speed=base speed+coefficient k×(current temperature-reference temperature)+coefficient m×(predicted load-current load),
[0107] Where coefficients k and m are configurable parameters, and the reference temperature is the optimal working temperature of the device; when the temperature exceeds the preset threshold, the task migration is triggered in priority to the load threshold, and the performance state of the device is reduced, and the cross-device task scheduling module is notified to migrate part of the tasks.
[0108] A hardware acceleration device management method applied to a network security product, comprising the following steps:
[0109] S1, connect the PCIE X8 slot of the network security product with the M.2 device through the adapter board, split the X8 signal into two independent X4 signals by using internal wiring, and copy the clock signal into two paths for synchronous transmission to the device through the clock buffer, thereby providing a hardware basis for parallel communication of the double devices;
[0110] S2, on the basis of the interface connection, physically fix by using the insulating bracket and screw hole, and parallelly attach the bottom surface of the M.2 device to the PCB of the adapter board, embed the side surface into the limiting groove for positioning, and then fix the top surface of the device to the bracket by using the countersunk screw, so as to ensure that the device maintains stable electrical connection with the adapter board in the compact space and provides physical support for subsequent data collection;
[0111] S3, through the network protocol stack interface and the device firmware management interface, real-time extract the network flow rate, data encryption task quantity, data decryption task quantity, and the idle computing core number, remaining memory bandwidth and temperature data of the device, and generate the real-time load performance data report in JSON format according to the preset frequency, thereby providing real-time parameters for the task allocation strategy;
[0112] S4, read the real-time report from the shared memory, calculate the device resource score based on the fusion model, and allocate the to-be-processed task to the target device according to the strategy that the encryption task is preferentially supported by the hardware acceleration device, the flow processing task is allocated to the device with high resource score, and the decryption task is evenly allocated between the double devices;
[0113] S5, when the single-device utilization rate exceeds the threshold of 80% for five times in succession, screen the non-exclusive tasks, suspend the source device task and migrate the context information to the idle device, and at the same time, call the BIOS function to switch the PCIE channel mode, thereby realizing dynamic balance of the task processing efficiency;
[0114] S6, read the vendor ID, device ID and specification information of the device firmware through the PCIe configuration space, automatically load the corresponding driver program, and establish a mapping table of the standard instruction and the original instruction of the device based on the identification result of the device firmware, and at the same time, real-time monitor the PCIe link state, update the identifiable list when the device is inserted, terminate the task and trigger resource reallocation when the device is removed, finally, obtain the power consumption parameters by reading the device management register and establish a task power consumption model, dynamically adjust the performance state and the rotation speed of the cooling fan based on the load prediction, adjust the rotation speed of the fan through the temperature and power consumption relationship model, and trigger the frequency reduction protection and task migration when the temperature is too high.
[0115] A certain network security product accesses two M.2 hardware acceleration devices, device A is a 2280 specification hardware encryption card supporting AES-NI acceleration, and device B is a 2260 specification traffic cleaning card based on FPGA logic. Through the M.2 adapter board connected to the PCIe X8 slot of the network security product, the X8 signal is split into two independent X4 signals inside the PCB using differential wiring technology, and is mapped to the J1 and J2 M.2 connectors of the adapter board respectively; the clock processing unit integrates TI CDCLVC1104 clock buffer, which copies the input 100MHz clock signal into two synchronous clocks, which are transmitted to the device through a 50Ω impedance matching line, ensuring that the clock skew is ≤50ps.
[0116] The insulation bracket adopts a rectangular frame made of FR-4 material, which is welded to the edge of the adapter board through 4 pads. The inside of the frame is processed with a stepped limiting groove compatible with 2280 / 2260 specifications. After device A is inserted into the J1 connector, the bottom surface maintains a 1.5mm spacing with the PCB, the side surface is embedded in a 5mm deep groove for positioning, and the top surface is fixed by 2 M2.5 countersunk screws. After device B is inserted into the J2 connector, it is fixed by 1 M2 screw, ensuring that the contact resistance fluctuation of the double devices is ≤5mΩ during vibration testing.
[0117] When the network security product processes Internet export traffic, real-time monitoring data is as follows (sampling interval 0.1 seconds): inbound traffic rate 1500Mbps (Δ byte number = 18750000B, Δ time = 0.1s), encryption task amount 800 times / s, decryption task amount 200 times / s. Device A has a total of 8 cores and a total memory bandwidth of 20GB / s, with 3 idle cores and a used bandwidth of 14GB / s, and a temperature of 55℃; device B has a total of 8 cores and a total memory bandwidth of 16GB / s, with 6 idle cores and a used bandwidth of 8GB / s, and a temperature of 40℃. The load real-time monitoring module generates a JSON report at a frequency of 10 times / s, which is stored in shared memory.
[0118] The resource dynamic allocation module calculates the resource score of device A as (3 / 8x0.6) + (6 / 20x0.4) = 0.345, and the resource score of device B as (6 / 8x0.6) + (8 / 16x0.4) = 0.65. 800 encryption tasks are allocated to device A, and 1500Mbps traffic is split according to the score ratio, with 975Mbps allocated to device B, and 200 decryption tasks are fixedly allocated to device A.
[0119] Device A is 87.5% for 5 consecutive samples (0.5 seconds) due to sudden task utilization, triggering task migration process, screening 500 batch encryption tasks, suspending and storing context to shared memory, generating migration descriptor and sending to device B through PCIe configuration space, and calling PCIe_ConfigurateLinkWidth (X4+X4) function of BIOS to switch to double X4 mode.
[0120] At this time, hot plug access device C (2242 general-purpose acceleration card, Vendor ID=0x1234, Device ID=0x5678, firmware V1.2.0), the system reads the ID through the PCIe configuration space, loads the driver_1234_5678_v1.3.0.ko driver after matching the database, checks the version compatibility, establishes a standardized instruction and device C native instruction mapping table, writes a register adaptation function SetRegAddr(0x2000,data), and notifies the resource dynamic allocation module through D-Bus. After recalculating the resource score of device C as 0.7, assign 200Mbps traffic task to device C to achieve multi-device load balancing;
[0121] At the same time, by reading the device management register of PCIe configuration space, the nominal maximum power (such as 25W), the performance state power value and the conversion delay (5ms) are obtained, and based on the historical load data, the association model of task type and power consumption characteristics (such as encryption task power consumption is 30% higher than traffic task) is established; Kalman filtering algorithm (process noise covariance q=0.008, measurement noise covariance r=0.06) is used to predict the load change trend, when the resource utilization is <30%, switch to low power mode, >70% short time to high performance mode, and dynamically adjust the fan speed according to the formula: target speed=base speed (2000RPM)+k(60)×(current temperature-55℃)+m(30)×(predicted load-current load); Then establish the relationship model of temperature and power consumption Δtemperature=0.5×power consumption+0.3×(1 / fan speed)+0.2×environmental temperature, when the temperature exceeds 75℃, trigger the frequency reduction protection and parallel migration task to idle device, realize the dynamic optimization and cooling collaborative control of M.2 device in network security scene.
[0122] It will be apparent to those skilled in the art that the application is not limited to the details of the above-exemplified embodiments and that the present application can be implemented in other particular forms without departing from the spirit or essential characteristics of the present application. The embodiments should therefore be considered in all respects as illustrative and not restrictive, the scope of the application being indicated by the appended claims rather than by the above description, and all changes which come within the meaning and range of equivalency of the claims are therefore intended to be embraced therein. No reference signs in the claims should be considered as limiting the scope of the claims with respect to the figures of the patent document.
Claims
1. A hardware acceleration device management system applied to network security products, comprising a PCIE to M.2 adapter board module, a structure support module, a load real-time monitoring module, a resource dynamic allocation module, a cross-device task scheduling module, and a device compatibility adaptation module; the PCIE to M.2 adapter board module is a hardware carrier, the input end is connected with a network security product PCIE X8 slot, and the output end is provided with two M.2 connectors; the structure support module connects the adapter board and the M.2 device, and adopts a physical bracket and screw hole positions to fix the device and the adapter board; characterized in that: The load real-time monitoring module extracts traffic and encryption / decryption task quantity in real time through a network task collection unit, obtains device idle core number, residual bandwidth and temperature through a device performance collection unit, and generates a JSON format real-time report by a data report generation unit; the resource dynamic allocation module calculates a score based on a formula, device resource score=(idle core number / total core number)×0.6+(residual memory bandwidth / total memory bandwidth)×0.4, and implements task allocation by a task allocation execution unit according to the strategy of preferential hardware encryption device for encryption tasks, high-score device for traffic tasks, and even allocation of double devices for decryption tasks; the cross-device task scheduling module is connected with the allocation module and the M.2 device, calculates device utilization through a load threshold monitoring unit, and when the device utilization exceeds 80% for 5 consecutive times, selects migratable tasks and migrates them to a target device by a task migration execution unit, and dynamically configures a PCIE channel by a BIOS mode switching unit, with single-device mode keeping PCIE X8 mode and double-device mode being configured as X4+X4 mode; the device compatibility adaptation module is connected with the M.2 device and the system software layer, reads device ID and firmware information by a firmware recognition unit, automatically loads compatible drivers by a driver management unit, updates the device list in real time and triggers resource reallocation by a hot plug detection unit, and obtains device power consumption parameters and establishes a task power consumption correlation model by a power consumption feature recognition unit, dynamically adjusts device performance state and cooling fan speed based on load prediction by a dynamic power consumption scheduling unit, and adjusts fan speed by a temperature and power consumption relationship model and triggers frequency reduction protection and task migration when the temperature is too high by an adaptive cooling control unit.
2. The hardware acceleration device management system applied to a network security product according to claim 1, characterized in that: The PCIE-to-M.2 adapter board module comprises a distribution unit and a clock processing unit; The distribution unit splits the X8 signal input from the PCIE X8 slot of the network security product into two independent PCIE X4 signals through internal wiring of the PCB, and the two X4 signals correspond to the two M.2 connectors of the adapter board output respectively; When a single slot is inserted with an M.2 device, only one X4 signal transmits data; when both slots are inserted with M.2 devices, two X4 signals transmit data in parallel, and at this time, the PCIE slot needs to be configured as X4+X4 mode by BIOS to support double-device parallel communication; The clock processing unit integrates a clock buffer chip CLK BUFFER, copies the clock signal CLK input from the PCIE slot into two synchronous clock signals, and connects the two clock signals to the two M.2 connectors respectively, to provide synchronous clock signals for the corresponding M.2 devices and ensure the clock synchronization of the devices when working in single-slot and double-slot modes.
3. The hardware acceleration device management system applied to a network security product according to claim 1, characterized in that: The structure support module comprises a physical bracket unit and a screw fixing unit; The physical bracket unit is a rectangular frame structure made of insulating material, the frame size matches the edge of the PCB board of the PCIE to M.2 adapter board, and is fixed to the edge of the adapter board by welding; the inner side of the frame is provided with a limiting groove corresponding to the size of the M.2 device, the groove length is compatible with the standard M.2 device, so that the bottom surface of the device is kept parallel to the PCB of the adapter board and the side surface is embedded in the groove for positioning after the device is inserted into the M.2 connector; The screw fixing unit is responsible for fixing the M.2 device on the bracket, and the screw hole is arranged at the screw hole position corresponding to the M.2 device on the top of the physical bracket, so that when the M.2 device is inserted into the connector and embedded in the limiting groove, the countersunk screw is passed through the screw hole on the surface of the device and screwed into the screw hole of the bracket to fix the top surface of the device on the bracket; the number of screws corresponding to each M.2 device is equal to the number of fixing holes of the standard M.2 device, so that the device can keep stable electrical connection with the adapter board in a vibrating environment.
4. The hardware acceleration device management system applied to a network security product according to claim 1, characterized in that: The load real-time monitoring module includes a network task acquisition unit, a device performance acquisition unit and a data report generation unit; The network task acquisition unit establishes a data channel with the task processing queue through the network protocol stack interface of the network security product, extracts the byte number of inbound / outbound traffic from the network card driver layer in real time, calculates the average traffic rate at a preset fixed interval, and the calculation formula is as follows: ; Where Δbyte number is the byte difference value of the traffic of two adjacent samples, and Δtime is the sampling interval, in seconds; While calculating the average traffic rate, the encryption / decryption task scheduling queue is listened to, the number of new task entries per second is counted, and the real-time data of the data encryption task quantity and the data decryption task quantity are formed, which directly reflects the current network task load; The device performance acquisition unit obtains device state data through the firmware management interface of the M.2 device; specifically, the number of idle cores is obtained by querying the CPU / MCU core state register and counting the number of cores in the idle state, and the number of idle cores is the register with a utilization rate of less than or equal to 5%; then the used memory bandwidth is obtained through the memory controller state register, and the remaining bandwidth is calculated according to the formula by combining the nominal total memory bandwidth, and the calculation formula is as follows: Remaining memory bandwidth = total memory bandwidth - used memory bandwidth; Finally, the real-time temperature data of the M.2 device is obtained by reading the register value of the on-board temperature sensor, and all parameters are read in real time through the standardized interface; The data report generation unit aligns the data output by the network task acquisition unit and the device performance acquisition unit with the time stamp, generates a structured report in UTC time format, and stores the report in the shared memory buffer of the network security product in JSON format. The resource dynamic allocation module includes a data receiving unit, a fusion model calculation unit and a task allocation execution unit; 5. The hardware acceleration device management system applied to a network security product according to claim 4, characterized in that: The data receiving unit reads the JSON format real-time load performance data report generated by the load real-time monitoring module in real time through the shared memory interface of the network security product, and parses the field data such as traffic rate, encryption task quantity, decryption task quantity, idle computing core number, remaining memory bandwidth and temperature from the data report; the data reading frequency is consistent with the load monitoring frequency, so that the latest network task load and M.2 device performance state data are obtained in real time, and real-time basis is provided for subsequent task allocation; The fusion model calculation unit processes the received real-time data based on a preset fusion model to generate a task allocation strategy; specifically, first, the device remaining resource ratio is calculated according to the task type and device performance parameters, and the task type is divided into encryption, decryption and traffic processing; the calculation formula is as follows: ; Wherein 0.6 and 0.4 are the weight coefficients of core number and memory bandwidth, which can be adjusted through BIOS configuration; then, according to the strategy that the encryption task is preferentially allocated to the device supporting hardware encryption, the traffic processing task is allocated to the device with high resource score, and the decryption task is uniformly allocated to the double device, the matching relationship between the task and the device is determined; The task allocation execution unit allocates the tasks in the task queue to the target M.2 device according to the fusion model calculation result; specifically, in the single device mode PCIE X8, only the task instruction is sent to the slot of the inserted device; in the double device mode PCIE X4+X4, if the task can be split, the task quantity is split according to the device resource score ratio, and the device with higher resource score is allocated more tasks; If the task cannot be split, it is allocated to the device with the highest current resource score; the task allocation sends the task descriptor containing the task type, data address and priority information to the target device through the PCIe configuration space.
6. The hardware acceleration device management system applied to a network security product according to claim 1, characterized in that: The cross-device task scheduling module includes a load threshold monitoring unit, a task migration execution unit and a BIOS mode switching unit; The load threshold monitoring unit is used to read the M.2 device performance data output by the resource dynamic allocation module in real time, and calculate the device load through the formula as follows: Device utilization rate = 1 - (idle computing core number / total core number); Wherein, the idle computing core number is the core number with utilization rate ≤ 5% counted by the device performance acquisition unit, and the total core number is the nominal value of the device firmware; when the utilization rate of a device is continuously sampled for 5 times and exceeds the threshold of 80%, the cross-device task migration process is triggered, wherein the interval time of continuous sampling is a preset fixed interval time; The task migration execution unit, after receiving the trigger signal of the load threshold monitoring unit, first screens the migratable tasks and excludes the tasks that need to be processed by the fixed device; then, the source device task is paused, the context information such as task progress and data pointer is stored to the shared memory, and the task descriptor containing the task ID, source device slot, target device slot and recovery address is sent to the target device through the PCIe configuration space, and the target device reads the information from the shared memory and continues to execute the task; The migratable task refers to a task not dependent on unique hardware resources of the M.2 device, and specifically includes a general traffic cleaning task and a batch data encryption task; the general traffic cleaning task is a stateless process of filtering and rate limiting network traffic, and can be executed on any M.2 device supporting the PCIe protocol; the batch data encryption task is batch data processing based on a standard encryption algorithm, and is not dependent on a built-in key storage module of the device; The fixed device processing task refers to a task that must depend on unique hardware resources of the M.2 device, and specifically includes a decryption task based on a unique key of the device and a customized protocol acceleration task; the decryption task based on the unique key of the device needs to call an exclusive key stored in a security chip on board of the M.2 device, and can only execute a decryption operation on the device; the customized protocol acceleration task is a task using a self-defined instruction set and a hardware acceleration unit of the device, and cannot be run on other types of devices; The BIOS mode switching unit queries an insertion state of the M.2 device in real time through a system management interface; specifically, when only a single slot is inserted with the device, a PCIe_ConfigurateLinkWidth() function of the BIOS is called to configure the PCIE slot as an X8 mode; when both slots are inserted with the device, the function is called and an X4+X4 parameter is transmitted to trigger the BIOS to split the PCIE channel into two independent X4s; after the configuration is completed, the mode is validated through a restart of the PCIe link; if device hot plugging occurs, the above process is repeated in real time to dynamically switch the channel mode.
7. The hardware acceleration device management system applied to a network security product according to claim 1, characterized in that: The device compatibility adaptation module includes a firmware identification unit, a driver management unit, an instruction set adaptation unit, a hot plugging detection unit, a power consumption feature identification unit, a dynamic power consumption scheduling unit, and a self-adaptive heat dissipation control unit; The firmware identification unit reads firmware information of the M.2 device through a PCIe configuration space; specifically, a vendor ID and a device ID are read from a device configuration register address; then a firmware version string is read from an extended configuration space to parse a PCIe protocol version, an interface mode, and an M.2 specification supported by the device; finally, the ID and the specification read are matched by using a device information database built in a nonvolatile memory of the network security product to determine a device vendor, a model, and supported functions; The driver management unit executes driver loading according to the device ID output by the firmware identification unit; specifically, first, a driver program file corresponding to the vendor ID and the device ID is retrieved from a driver library through a network security product operating system driver interface and loaded into a kernel and a system service layer; then initialization parameters are transmitted to the driver program according to device specification information; finally, before loading, the driver program version is checked for compatibility with the device firmware version, and an error prompt is triggered when the versions are incompatible; The instruction set adaptation unit establishes a mapping between standardized task instructions and device-specific instruction sets based on device firmware identification results. Specifically, first, a unified task instruction format is defined, which is converted to device native instructions through a lookup table. Then, adaptation functions are written to address the differences in register layouts for different devices. The device automatically addresses through the adaptation function. Finally, a device instruction execution state table is maintained to ensure consistency in the state context of registers during cross-device task scheduling. The hot plug detection unit manages hot plug through monitoring the PCIe link state register. Specifically, the register is queried periodically. When the link state changes from Down to Up, it is determined that the device is inserted. When it changes from Up to Down, it is determined that the device is removed. When insertion is detected, the firmware identification unit is triggered to start, and the device information is added to the system identifiable list. When removal is detected, the device is deleted and its task is terminated. Then, the device state change notification is sent to the resource dynamic allocation module through the system message bus, triggering the task allocation strategy, and mobilizing the fusion model calculation unit to recalculate the device resource score. The power consumption feature recognition unit obtains the basic power consumption parameters of the device by reading the device management register of the PCIe configuration space, including the nominal maximum power, the power consumption value corresponding to each performance state, and the conversion delay. Based on the historical report data generated by the load real-time monitoring module, an association model of task type and power consumption feature is established, forming a power consumption feature library for different task types. The dynamic power consumption scheduling unit processes historical load data using the Kalman filtering algorithm based on the task allocation results of the resource dynamic allocation module, establishes a state space model, and generates a smooth future load trend prediction sequence through a prediction-update two-stage iteration. The results are synchronized to the resource dynamic allocation module to adjust the task allocation strategy. According to the predicted load, the ACPI interface of the device driver is called to dynamically adjust the performance state and idle state defined by ACPI: when the resource utilization is <30%, automatically switch to the lowest available performance state; when the resource utilization is between 30%-70%, maintain the default state; when the resource utilization is >70%, temporarily improve to the highest available performance state, which requires device support, and simultaneously adjust the fan speed; The adaptive cooling control unit establishes a relationship model between device temperature and power consumption: Δtemperature=f(power consumption, cooling efficiency), where the cooling efficiency is related to the fan speed and the environment temperature. According to the real-time temperature and the predicted load, the fan speed is dynamically adjusted through the pulse width modulation interface based on the relationship model. The calculation formula is as follows: Target speed=base speed+coefficient k×(current temperature-reference temperature)+coefficient m×(predicted load-current load), where coefficients k and m are configurable parameters, and the reference temperature is the optimal working temperature of the device. When the temperature exceeds the preset threshold, the task migration is triggered in priority to the load threshold, and the device performance state is reduced, and the cross-device task scheduling module is notified to migrate part of the tasks.
8. The hardware acceleration device management method applied to the network security product, applied to the hardware acceleration device management system applied to the network security product of any one of claims 1-7, characterized in that: The method comprises the following steps: S1, connect the PCIE X8 slot of the network security product with the M.2 device through the adapter board, split the X8 signal into two independent X4 signals by using internal wiring, and copy the clock signal into two synchronous transmission paths to the device through the clock buffer, thereby providing a hardware basis for parallel communication of the double devices; S2, on the basis of interface connection, physically fix the M.2 device to the adapter board PCB using an insulating bracket and screw hole position, and then fix the device top surface to the bracket through a countersunk screw after embedding the side surface into a limiting groove for positioning, thereby ensuring stable electrical connection between the device and the adapter board in a compact space and providing physical support for subsequent data collection; S3, through the network protocol stack interface and the device firmware management interface, real-time extraction of network traffic rate, data encryption task quantity, data decryption task quantity, and device idle computing core number, remaining memory bandwidth and temperature data, generation of real-time load performance data report in JSON format according to the preset frequency, and provision of real-time parameters for task allocation strategy; S4, read real-time report from shared memory, calculate device resource score based on fusion model, and allocate tasks to target devices according to the strategy of supporting hardware acceleration for devices with encryption tasks first, allocating traffic processing tasks to devices with high resource scores, and evenly distributing decryption tasks between double devices; S5, when the utilization rate of a single device exceeds 80% threshold for five consecutive times, screen non-exclusive tasks, suspend the source device task and migrate the context information to the idle device, and at the same time, call the BIOS function to switch the PCIE channel mode, thereby realizing dynamic balance of task processing efficiency; S6, read the vendor ID, device ID and specification information of the device firmware through the PCIe configuration space, automatically load the corresponding driver and establish a mapping table of standardized instructions and original instructions based on the device firmware identification result, and at the same time, real-time monitor the PCIe link state, update the identifiable list when the device is inserted, terminate the task and trigger resource reallocation when the device is removed, finally, obtain the power consumption parameters by reading the device management register and establish a task power consumption model, dynamically adjust the device performance state and fan speed based on load prediction, adjust the fan speed through the temperature and power consumption relationship model and trigger frequency reduction protection and task migration when the temperature is too high.
Citation Information
Patent Citations
Task transmission scheduling management system for multi-core storage and calculation integrated accelerator network
CN115827256A
RS485 bus-based host extension method, apparatus and device, and storage medium
CN119847967A
Dynamic allocation method and system for workload of CPU-GPU (Central Processing Unit-Graphics Processing Unit) heterogeneous system
CN120066791A
Interface conversion device based on monitoring network security equipment
CN220475065U
Virtualizing non-volatile storage at a peripheral device
US20180088804A1
Cited By
Modular channel number dynamic allocation method and system based on intelligent fusion terminal
CN122346449A