Call Control Method for Encryption Card and Communication Device

By creating an encryption and decryption thread pool for each processor core in the communication device, and starting the encryption and decryption thread to call the encryption card processing unit according to specific conditions, the problem of unstable network forwarding performance when the communication device maximizes the utilization of encryption card performance is solved, and stable high-performance encryption processing is achieved.

CN113722103BActive Publication Date: 2025-06-27QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111062763.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-10
Publication Date
2025-06-27
Estimated Expiration
2041-09-10

AI Technical Summary

Technical Problem

When existing communication devices maximize the performance of cryptocards, network forwarding performance is unstable, resulting in performance fluctuations.

Method used

A corresponding encryption and decryption thread pool is created for each processor core in the communication device, and upon receiving data that needs to be encrypted and decrypted, the corresponding encryption and decryption thread is started according to specific conditions to call the processing unit of the encryption card for processing.

Benefits of technology

Through this method, it is possible to maximize the utilization of multiple processing units of the encryption card without interfering with packet forwarding, improve the performance utilization rate of the encryption card, and stably improve the network forwarding performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113722103B_ABST
    Figure CN113722103B_ABST
Patent Text Reader

Abstract

The present application discloses a method for calling and controlling an encryption card and a communication device. The method is applied to the communication device, and the communication device includes multiple processor cores. Each of the processor cores corresponds to a thread pool respectively, and each of the thread pools contains multiple encryption and decryption threads. Each of the encryption and decryption threads corresponds to a processing unit in the encryption card. The method includes: after the communication device receives the first data, determining whether the first data meets the conditions for encryption and decryption processing; in the case where the first data meets the conditions for encryption and decryption processing, starting the encryption and decryption threads in the thread pool to call the processing unit corresponding to the encryption and decryption threads to perform a first processing on the first data to obtain second data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method for controlling the calling of an encryption card and a communication device. Background Art

[0002] In order to ensure the security of transmitted data, a specific encryption and decryption algorithm is usually used when transmitting data over a network. Currently, communication devices usually have built-in encryption cards, which are equipped with encryption and decryption algorithms. The encryption cards are then called by the communication devices to implement data encryption and decryption processing.

[0003] At present, when data needs to be encrypted and decrypted in a communication device, the encryption card is called to implement data encryption and decryption by switching threads. However, at this time, the communication device will interrupt the thread previously called by the communication device, so that the network forwarding and other services executed by the thread are interrupted, resulting in unstable performance on the service. Summary of the invention

[0004] In view of this, the present application provides a call control method and communication device for an encryption card, so as to solve the technical problem of unstable network forwarding performance when maximizing the performance of the encryption card in the prior art.

[0005] The present application provides a method for controlling the calling of an encryption card, which is applied to a communication device, wherein the communication device includes a plurality of processor cores, each of the processor cores corresponds to a thread pool, each of the thread pools includes a plurality of encryption and decryption threads, each of the encryption and decryption threads corresponds to a processing unit in the encryption card, and the method includes:

[0006] After the communication device receives the first data, determining whether the first data satisfies a condition for encryption and decryption processing;

[0007] When the first data meets the condition for the encryption and decryption processing, the encryption and decryption thread in the thread pool is started to call the processing unit corresponding to the encryption and decryption thread to perform a first processing on the first data to obtain second data.

[0008] Preferably, the above method further comprises, before starting the encryption and decryption threads in the thread pool:

[0009] Determine whether any of the following calling conditions are met:

[0010] The target thread is in an idle state; the target thread is a main thread for data transmission in the communication device;

[0011] or,

[0012] The target duration reaches the duration threshold, where the target duration is the duration from the last time the encryption / decryption thread was started to the current moment;

[0013] or

[0014] the cumulative quantity of the first data reaches a preset quantity threshold;

[0015] When any of the above call conditions is satisfied, execute the following: start the encryption and decryption threads in the thread pool.

[0016] In the above method, preferably, each thread pool is respectively provided with a corresponding forwarding queue, and the forwarding queue is used to store the data identifiers corresponding to the first data;

[0017] Moreover, each encryption and decryption thread is respectively provided with a corresponding thread queue. When the cumulative quantity of the data identifiers in the forwarding queue reaches a preset cumulative threshold, the data identifiers in the forwarding queue are distributed to each thread queue, so that the encryption and decryption threads call the corresponding processing unit to perform a first processing on the first data corresponding to the data identifiers in the thread queue.

[0018] In the above method, preferably, the data identifiers corresponding to the first data are stored in the forwarding queue according to the order identifiers corresponding to the first data, and the order identifiers represent the data streams to which the first data belongs, so that the data identifiers corresponding to the first data belonging to the same data stream are stored in the same forwarding queue.

[0019] In the above method, preferably, the order identifier also represents whether the first data meets the conditions for encryption and decryption processing;

[0020] Among them, the judgment of whether the first data meets the conditions for encryption and decryption processing includes:

[0021] judging whether the order identifier corresponding to the first data matches a preset data stream identifier; the data stream identifier is the identifier of the data stream that needs to be encrypted and decrypted;

[0022] Among them, if the order identifier corresponding to the first data matches the data stream identifier, it indicates that the first data meets the conditions for encryption and decryption processing; if the order identifier corresponding to the first data does not match the data stream identifier, it indicates that the first data does not meet the conditions for encryption and decryption processing.

[0023] In the above method, preferably, the storage space in the forwarding queue is equal to the sum of the storage spaces of the thread queues corresponding to the forwarding queue.

[0024] In the above method, preferably, the encryption and decryption threads in the thread pool have thread numbers, and the thread numbers represent the thread order among the encryption and decryption threads;

[0025] Before starting the encryption and decryption threads in the thread pool, the method further includes:

[0026] According to the thread numbers, in a polling manner, distribute the data identifiers in the forwarding queue to the corresponding thread queues of each encryption and decryption thread in turn, so that the encryption and decryption threads call the corresponding processing units to perform a first process on the first data corresponding to the data identifiers in the thread queues.

[0027] In the above method, preferably, the encryption and decryption threads call the corresponding processing units to perform a first process on the first data corresponding to the data identifiers in the thread queues, including:

[0028] The encryption and decryption threads read the first data corresponding to the data identifiers in the storage area according to the data identifiers in the thread queues;

[0029] The encryption and decryption threads send the first data to the processing units corresponding to the encryption and decryption threads, so that the processing units perform encryption processing or decryption processing on the received first data to obtain second data;

[0030] The encryption and decryption threads write the second data sent by the processing units into the storage area according to the data identifiers corresponding to them in the thread queues.

[0031] In the above method, preferably, the method further includes:

[0032] After obtaining the processing completion message, output the second data;

[0033] Wherein, the processing completion message is generated after all the encryption and decryption threads in the thread pool call the corresponding processing units to process all the first data corresponding to the data identifiers in the thread queues.

[0034] In the above method, preferably, before outputting the second data, the method further includes:

[0035] Perform data format conversion processing on the second data according to a preset target format to obtain the second data in the target format.

[0036] In the above method, preferably, the encryption and decryption threads are in a dormant state before being started; and, the encryption and decryption threads enter a dormant state after calling the processing units.

[0037] In the above method, preferably, the thread pool is created based on the number of detected processor cores when the communication device is started.

[0038] This application also provides a communication device, including:

[0039] One or more processors;

[0040] A memory on which a computer program is stored;

[0041] When the computer program is executed by the one or more processors, the one or more processors are caused to implement the call control method of the encryption card as described in any one of the above.

[0042] As can be seen from the above solution, in a call control method of an encryption card and a communication device provided in this application, corresponding encryption and decryption threads are created for a processor core in the communication device corresponding to each processing unit in the encryption card. Based on this, when the communication device receives the first data and the first data meets the conditions for encryption and decryption processing, the corresponding encryption and decryption threads are started to call the corresponding processing unit to process the first data, thereby obtaining the second data. It can be seen that in this application, corresponding threads are created for the processor core, so that the encryption and decryption processing can be implemented without switching the threads corresponding to normal network forwarding in the communication device to call the processing unit. Thus, the performance of multiple processing units of the encryption card can be maximized without interfering with the packet forwarding. Description of the Drawings

[0043] In order to more clearly illustrate the technical solutions of the embodiments of this application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0044] Figure 1 It is a flowchart of a call control method of an encryption card provided by an embodiment of this application;

[0045] Figures 2 - 4 They are respectively example diagrams of embodiments of this application;

[0046] Figure 5 It is another flowchart of a call control method of an encryption card provided by an embodiment of this application;

[0047] Figures 6 - 9 They are respectively another example diagrams of embodiments of this application;

[0048] Figure 10 It is a partial flowchart of a call control method of an encryption card provided by an embodiment of this application;

[0049] Figure 11 It is another example diagram of an embodiment of this application;

[0050] Figure 12Another flowchart of a method for controlling the invocation of an encryption card provided by an embodiment of the present application;

[0051] Figure 13 A schematic structural diagram of a communication device provided by an embodiment of the present application;

[0052] Figure 14 and Figure 15 Other example diagrams of an embodiment of the present application. Detailed implementation manners

[0053] When the inventors of the present application studied communication devices using encryption cards, they found that: Assume that an encryption card is installed on a communication device, and the encryption card generally consists of multiple hardware channels. Here, the hardware channel refers to the cryptographic chip in the encryption card for encryption and decryption processing. Since the performance of each hardware channel is not particularly high, it is necessary to use all the hardware channels of the encryption card as much as possible to maximize the performance.

[0054] Currently, in order to maximize the performance of the encryption card, a multi-threaded method is needed to invoke the encryption card to maximize the performance of the encryption card. In addition to invoking the encryption card, the operating system in the communication device also forwards network traffic. If many threads are enabled to invoke the encryption card, it will cause many thread switches in the system, resulting in many system switches. The switches themselves are uncontrollable, leading to unstable network forwarding performance and fluctuating performance.

[0055] To address the above deficiencies, the inventors of the present application propose an implementation technology that uses a software thread pool to simulate coroutines to improve the throughput of the encryption card. The advantage of using coroutines is that they are not preemptively scheduled by the operating system kernel of the communication device, but are self-managed cooperative "threads" managed by the created process in the user state. They do not participate in the operating system's time scheduling of the central processing unit (CPU) and are not evenly allocated time. In a specific implementation solution, by using a pre-allocated thread pool, these pre-allocated threads are in a non-preemptive mode and do not cause system thread switches, so as to ensure that there are no encryption and decryption tasks or normal network forwarding will not be disturbed when processing encryption and decryption tasks. When processing encryption and decryption, the CPU is fully occupied, multiple data packets are processed in batches, and as many hardware encryption channels as possible are utilized simultaneously to maximize the performance of the encryption card and achieve optimal performance.

[0056] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0057] Reference Figure 1 , which is a flowchart for implementing a method for controlling the invocation of an encryption card provided in an embodiment of the present application. This method is applied to a communication device. An encryption card is configured in the communication device, and the encryption card has multiple processing units. As Figure 2 shown, the processing unit here refers to the cryptographic chip in the encryption card, which can implement processing such as encryption and decryption of data. The data processing channel implemented can be called an encryption hardware channel. Moreover, the communication device contains multiple processor cores, and for each processor core, there is a corresponding thread pool. Each thread pool contains multiple encryption and decryption threads, and each encryption and decryption thread corresponds to a processing unit in the encryption card. The technical solution in this embodiment is mainly used to maximize the performance of multiple processing units of the encryption card under the condition of not interfering with the packet forwarding.

[0058] Specifically, the method in this embodiment may include the following steps:

[0059] Step 101: Monitor whether the communication device receives the first data. If the first data is received, execute Step 102. If the first data is not received, continue to execute Step 101.

[0060] Among them, the first data is the packet to be processed received by the communication device. The first data corresponds to a data identifier and a sequence identifier. The data identifier here may be the address pointer of the first data to be processed, and the address pointer is used to read the data to be processed, that is, the first data. The sequence identifier represents the data stream to which the first data belongs. In a specific implementation, the sequence identifier may be represented by a five-tuple hash value. The five-tuple here may include: the source IP address corresponding to the first data, the destination IP address, the source port, the destination port, and the protocol information. In addition, the sequence identifier may also be represented by the hash value of other tuples.

[0061] It should be noted that multiple processor cores may be included in the communication device. For example, as Figure 3 shown, the communication device contains 4 processor cores, namely: CPU0, CPU1, CPU2, and CPU3. Each processor core corresponds to a thread pool, and each thread pool contains multiple encryption and decryption threads. An encryption and decryption thread corresponds to a processing unit in the encryption card. For example, as Figure 3As shown, the processor cores CPU10, CPU1, CPU2, and CPU3 respectively correspond to thread pools 0, 1, 2, and 3. In each thread pool, each encryption / decryption thread corresponds to a cryptographic chip in the encryption card, that is, a hardware channel. For example, as Figure 4 shown, threads 0, 1, 2, and 3 in thread pool 0 sequentially correspond to 4 hardware channels 0-3 in the encryption card, threads 0, 1, 2, and 3 in thread pool 1 sequentially correspond to 4 hardware channels 4-7 in the encryption card, threads 0, 1, 2, and 3 in thread pool 2 sequentially correspond to 4 hardware channels 8-11 in the encryption card, and threads 0, 1, 2, and 3 in thread pool 3 sequentially correspond to 4 hardware channels 12-15 in the encryption card.

[0062] Step 102: Determine whether the first data meets the conditions for encryption / decryption processing. If the first data meets the conditions for encryption / decryption processing, execute step 103. If the first data does not meet the conditions for encryption / decryption processing, return and continue to execute step 101.

[0063] Among them, the conditions for encryption / decryption processing can be: the sequence identifier corresponding to the first data matches the preset data stream identifier, and here the data stream identifier is the identifier of the data stream that needs to be encrypted / decrypted. The data stream identifier is preset and set in the communication device according to requirements. Based on this, in this embodiment, after receiving the first data, it can be determined whether the sequence identifier corresponding to the first data matches the preset data stream identifier. If the sequence identifier corresponding to the first data matches the data stream identifier, then it can be determined that the first data is the data that needs to be encrypted / decrypted, that is, the first data meets the conditions for encryption / decryption processing. If the sequence identifier corresponding to the first data does not match the data stream identifier, then it can be determined that the first data is not the data that needs to be encrypted / decrypted, that is, the first data does not meet the conditions for encryption / decryption processing. Based on this, in this embodiment, it can be determined whether the first data needs to be encrypted / decrypted according to the source information and destination information of the first data and other contents.

[0064] Step 103: Start the encryption / decryption threads in the thread pool to call the processing unit corresponding to the encryption / decryption thread to perform a first processing on the first data to obtain a second data.

[0065] In specific implementation, in this embodiment, the data identifier corresponding to the first data can be sent to the started encryption / decryption thread through the interface between the encryption / decryption thread. Thus, the started encryption / decryption thread can call its corresponding processing unit to perform a first processing on the first data corresponding to the received data identifier to obtain a second data.

[0066] Among them, the first process may be an encryption process. In this case, the second data is the encrypted data obtained by encrypting the first data. The first processed data may be a decryption process. In this case, the second data is the decrypted data obtained by decrypting the first data.

[0067] It should be noted that the encryption and decryption threads in the thread pool are in a dormant state by default. Only when it is necessary to call the processing unit to perform the first process, the encryption and decryption threads in the thread pool are restarted, that is, awakened. Thus, the data identifier of the first data to be processed is sent to the awakened encryption and decryption threads. Furthermore, the awakened encryption and decryption threads call the corresponding processing unit to perform the corresponding first process. Further, after the encryption and decryption threads complete the call, the encryption and decryption threads enter the dormant state again until they are started next time.

[0068] As can be seen from the above solution, in a method for controlling the invocation of an encryption card provided in an embodiment of the present application, corresponding encryption and decryption threads are created for the processor core in the communication device corresponding to each processing unit in the encryption card. Based on this, when the communication device receives the first data and the first data meets the conditions for encryption and decryption processing, the corresponding encryption and decryption threads are started to call the corresponding processing unit to process the first data, thereby obtaining the second data. It can be seen that in this embodiment, corresponding threads are created for the processor core, so that the encryption and decryption processing can be realized without switching the threads corresponding to the normal network forwarding in the communication device to call the processing unit. Thus, the performance of multiple processing units of the encryption card can be maximized without interfering with the packet forwarding.

[0069] In one implementation, before starting the encryption and decryption threads in the thread pool in step 103, the method in this embodiment may further include the following steps, as Figure 5 shown in:

[0070] Step 104: Determine whether the call condition is satisfied. If the call condition is satisfied, then execute step 103. If the call condition is not satisfied, then continue to monitor whether the call condition is satisfied.

[0071] Among them, the satisfaction of the call condition includes the satisfaction of any of the following call conditions, as follows:

[0072] The first call condition may be: the target thread is in an idle state. Here, the target thread may be the main thread for data transmission in the communication device. Among them, when the target thread is in an idle state, there are more idle resources in the communication device. Therefore, when the first call condition is satisfied, the encryption and decryption threads in the thread pool can be started to call the corresponding processing unit to process the first data with the support of more idle resources, so as to improve the processing efficiency.

[0073] The second calling condition may be: the target duration reaches the duration threshold, where the target duration is the continuous duration from the most recent start of the encryption / decryption thread to the current moment. The time threshold can be preset according to requirements, such as 100 milliseconds. This time threshold can be understood as a preset time window. That is to say, after the encryption / decryption thread is started and the processing unit is called to complete a first processing for the first time, in this embodiment, the timing starts, and the first data received afterwards is accumulated. When the time window, that is, the target duration of the timing reaches the duration threshold, the encryption / decryption thread in the thread pool is started again to call the corresponding processing unit to batch process the accumulated first data, so as to avoid the low efficiency caused by frequently starting the encryption / decryption thread.

[0074] The third calling condition may be: the cumulative quantity of the first data reaches a preset quantity threshold, and the cumulative quantity is the total quantity of the first data received from the most recent start of the encryption / decryption thread to the current moment. That is to say, after the encryption / decryption thread is started and the processing unit is called to complete a first processing for the first time, in this embodiment, the received first data is accumulated. When the cumulative quantity reaches the quantity threshold, the encryption / decryption thread in the thread pool is started again to call the corresponding processing unit to batch process the accumulated first data, so as to avoid the low efficiency caused by frequently starting the encryption / decryption thread.

[0075] In specific implementation, in this embodiment, a corresponding forwarding queue is set for each thread pool, and the forwarding queue is used to store the data identifiers corresponding to the first data. As Figure 6 shown, thread pool 0 has forwarding queue 0, thread pool 1 has forwarding queue 1, thread pool 2 has forwarding queue 2, and thread pool 3 has forwarding queue 3.

[0076] Furthermore, a corresponding thread queue is set for each encryption / decryption thread. When the cumulative quantity of the data identifiers in the forwarding queue reaches a preset cumulative threshold, the data identifiers in the forwarding queue are distributed to each thread queue, so that the encryption / decryption thread calls the corresponding processing unit to perform a first processing on the first data corresponding to the data identifiers in the thread queue.

[0077] Among them, the cumulative threshold can be the upper limit value of the capacity of the forwarding queue, or other values less than the upper limit value of the capacity of the forwarding queue.

[0078] Taking thread pool 0 as an example, as Figure 7As shown, the encryption / decryption thread 0 in thread pool 0 has thread queue 0, the encryption / decryption thread 1 has thread queue 1, the encryption / decryption thread 2 has thread queue 2, and the encryption / decryption thread 3 has thread queue 3. Based on this, when the cumulative number of data identifiers stored in forwarding queue 0 reaches the capacity limit of forwarding queue 0, all the data identifiers in forwarding queue 0 are distributed to thread queue 0, thread queue 1, thread queue 2, and thread queue 3. Thus, the encryption / decryption thread 0 is started and calls hardware channel 0 to process the first data corresponding to the data identifier in thread queue 0, the encryption / decryption thread 1 calls hardware channel 1 to process the first data corresponding to the data identifier in thread queue 1, the encryption / decryption thread 2 calls hardware channel 2 to process the first data corresponding to the data identifier in thread queue 2, and the encryption / decryption thread 3 calls hardware channel 3 to process the first data corresponding to the data identifier in thread queue 3.

[0079] It should be noted that the data identifiers corresponding to the first data are stored in the forwarding queue corresponding to each thread pool according to the order identifier corresponding to the first data, and the order identifier represents the data stream to which the first data belongs, so that the data identifiers corresponding to the first data belonging to the same data stream are stored in the same forwarding queue. As Figure 8 shown, the data identifiers in forwarding queue 0, forwarding queue 1, forwarding queue 2, and forwarding queue 3 are stored according to the data streams corresponding to the first data to which they belong. The data streams corresponding to the first data to which the data identifiers stored in forwarding queue 0, forwarding queue 1, forwarding queue 2, and forwarding queue 3 belong can be different, which are data stream X, data stream Y, data stream Z, and data stream R respectively, but the data streams corresponding to the first data to which the data identifiers stored in the same forwarding queue belong are the same.

[0080] In specific implementation, the storage space in the forwarding queue is equal to the sum of the storage spaces of the thread queues corresponding to the forwarding queue. Thus, when the cumulative number of data identifiers in the forwarding queue reaches the capacity limit of the forwarding queue, the data identifiers stored in the forwarding queue can be all distributed to the corresponding thread queues. For example, the storage space of forwarding queue 0 is consistent with the sum of the storage spaces of thread queue 0, thread queue 1, thread queue 2, and thread queue 3. Based on this, when the data identifiers in forwarding queue 0 accumulate to reach the capacity limit of 16 of forwarding queue 0, the 16 data identifiers in forwarding queue 0 are distributed to thread queue 0, thread queue 1, thread queue 2, and thread queue 3, and 4 data identifiers are distributed to each thread queue respectively.

[0081] In one implementation, the encryption and decryption threads in the thread pool have thread numbers, such as encryption and decryption thread 0, encryption and decryption thread 1, encryption and decryption thread 2, and encryption and decryption thread 3. These thread numbers represent the thread order among the encryption and decryption threads, and also correspondingly represent the queue order among the thread queues corresponding to the encryption and decryption threads. For example, the thread order from encryption and decryption thread 0 to encryption and decryption thread 3, and for another example, the queue order from thread queue 0 to thread queue 3.

[0082] Based on this, before starting the encryption and decryption threads in the thread pool in step 103 of this embodiment, when distributing the data identifiers in the forwarding queue to the thread queues corresponding to each encryption and decryption thread in the thread pool, it can be specifically implemented in the following manner:

[0083] According to the thread numbers, in a polling manner, the data identifiers in the forwarding queue are sequentially distributed to the thread queues corresponding to each encryption and decryption thread, so that the encryption and decryption threads call the corresponding processing units to perform a first processing on the first data corresponding to the data identifiers in the thread queues.

[0084] Among them, the polling manner means: according to the thread order represented by the thread numbers, the first data identifier in the forwarding queue is sent to the thread queue of the first encryption and decryption thread in the thread pool; then, the next data identifier in the forwarding queue is sent to the thread queue of the second encryption and decryption thread in the thread pool; then, the next data identifier in the forwarding queue is sent to the thread queue of the third encryption and decryption thread in the thread pool; until the next data identifier in the forwarding queue is sent to the thread queue of the last encryption and decryption thread in the thread pool; then, the next data identifier in the forwarding queue is sent to the thread queue of the first encryption and decryption thread in the thread pool; then, the next data identifier in the forwarding queue is sent to the thread queue of the second encryption and decryption thread in the thread pool, and so on, until the last data identifier in the forwarding queue is sent to the thread queue of the last encryption and decryption thread in the thread pool.

[0085] For example, such as Figure 9As shown in the figure, the data identifier 0 in the forwarding queue 0 is sent to the thread queue 0, the data identifier 1 in the forwarding queue 0 is sent to the thread queue 1, the data identifier 2 in the forwarding queue 0 is sent to the thread queue 2, and the data identifier 3 in the forwarding queue 0 is sent to the thread queue 3; the data identifier 4 in the forwarding queue 0 is sent to the thread queue 0, the data identifier 5 in the forwarding queue 0 is sent to the thread queue 1, the data identifier 6 in the forwarding queue 0 is sent to the thread queue 2, and the data identifier 7 in the forwarding queue 0 is sent to the thread queue 3; and so on. Continue to send the data identifier 8 in the forwarding queue 0 to the thread queue 0, the data identifier 9 in the forwarding queue 0 to the thread queue 1, the data identifier 10 in the forwarding queue 0 to the thread queue 2, and the data identifier 11 in the forwarding queue 0 to the thread queue 3; the data identifier 12 in the forwarding queue 0 is sent to the thread queue 0, the data identifier 13 in the forwarding queue 0 is sent to the thread queue 1, the data identifier 14 in the forwarding queue 0 is sent to the thread queue 2, and the data identifier 15 in the forwarding queue 0 is sent to the thread queue 3 until the forwarding queue 0 is empty. After that, each encryption / decryption thread calls the corresponding processing unit to perform a first processing on the first data corresponding to the data identifier in its respective thread queue, thereby obtaining the second data.

[0086] Based on the above implementation, when each encryption / decryption thread calls the corresponding processing unit to perform a first processing on the first data corresponding to the data identifier in the thread queue, it can be specifically implemented in the following manner, as Figure 10 shown in the figure:

[0087] Step 1001: The encryption / decryption thread reads the first data corresponding to the data identifier in the storage area according to the data identifier in the thread queue.

[0088] Among them, the storage area can be the storage area in the communication device, or can be the storage area in other devices connected to the communication device. The data identifier can be an identifier that can point to the first data, such as an address pointer, etc. Based on this, the encryption / decryption thread reads the first data corresponding to each data identifier in the thread queue in the storage area.

[0089] Specifically, each encryption / decryption thread can read the corresponding first data in the order in which each data identifier in the thread queue is written; or, each encryption / decryption thread can read the first data corresponding to each data identifier in the thread queue in a random order; or, each encryption / decryption thread can read the first data corresponding to each data identifier in the thread queue simultaneously.

[0090] For example, after the address pointers in forwarding queue 0 are respectively sent to thread queues 0 to 3 in the order from encryption / decryption thread 0 to encryption / decryption thread 3, encryption / decryption thread 0 reads corresponding first data according to each address pointer in thread queue 0, encryption / decryption thread 1 reads corresponding first data according to each address pointer in thread queue 1, encryption / decryption thread 2 reads corresponding first data according to each address pointer in thread queue 2, and encryption / decryption thread 3 reads corresponding first data according to each address pointer in thread queue 3.

[0091] Step 1002: The encryption / decryption thread sends the first data to the processing unit corresponding to the encryption / decryption thread, so that the processing unit performs encryption processing or decryption processing on the received first data to obtain second data.

[0092] Among them, the encryption / decryption thread can send the first data to the processing unit through the data interface or path between the encryption / decryption thread and the corresponding processing unit. In addition, the encryption / decryption thread can also send other data together with the first data to the corresponding processing unit. Here, the other data is the data required for processing such as encrypting and decrypting the first data, such as keys.

[0093] Based on this, after the processing unit receives the first data, it performs processing such as encryption and decryption on the first data to obtain second data. After the processing unit obtains the second data corresponding to the first data, it sends the second data to the encryption / decryption thread. For example, as Figure 11 shown, encryption / decryption thread 0 sends the read first data to hardware channel 0, and hardware channel 0 performs encryption / decryption processing and sends the obtained second data to encryption / decryption thread 0. Encryption / decryption thread 1 sends the read first data to hardware channel 1, and hardware channel 1 performs encryption / decryption processing and sends the obtained second data to encryption / decryption thread 1. Encryption / decryption thread 2 sends the read first data to hardware channel 2, and hardware channel 2 performs encryption / decryption processing and sends the obtained second data to encryption / decryption thread 2. Encryption / decryption thread 3 sends the read first data to hardware channel 3, and hardware channel 3 performs encryption / decryption processing and sends the obtained second data to encryption / decryption thread 3.

[0094] Step 1003: The encryption / decryption thread writes the second data sent by the processing unit into the storage area according to the data identifier corresponding to it in the thread queue.

[0095] For example, the encryption / decryption thread 0 writes the second data sent by the hardware channel 0 to the storage location pointed to by the corresponding address pointer in the thread queue 0 in the storage area. The encryption / decryption thread 1 writes the second data sent by the hardware channel 1 to the storage location pointed to by the corresponding address pointer in the thread queue 1 in the storage area. The encryption / decryption thread 2 writes the second data sent by the hardware channel 2 to the storage location pointed to by the corresponding address pointer in the thread queue 2 in the storage area. The encryption / decryption thread 3 writes the second data sent by the hardware channel 3 to the storage location pointed to by the corresponding address pointer in the thread queue 3 in the storage area.

[0096] Based on the above implementation, after obtaining the second data in this embodiment, the method in this embodiment may further include the following steps, as Figure 12 shown below:

[0097] Step 105: After obtaining the processing completion message, output the second data.

[0098] Among them, the processing completion message is generated after all the encryption / decryption threads in the thread pool call the corresponding processing units to process all the first data corresponding to the data identifiers in the thread queue. That is to say, after each encryption / decryption thread in the thread pool receives the corresponding second data sent by the processing unit and writes the second data to the storage area, a processing completion message is generated to indicate that each encryption / decryption thread in the thread pool has completed the first processing by calling the processing unit. At this time, the second data in the storage area can be output.

[0099] Furthermore, before outputting the second data in this embodiment, the second data may be first read from the corresponding storage area according to the data identifier in the forwarding queue, and then the data format of the second data is converted according to a preset target format to obtain the second data in the target format. After that, the second data in the target format is output, such as outputting to the corresponding processor core, and the processor core performs other processing on the second data, such as outputting externally or performing internal calculations.

[0100] For example, after reading the second data, the second data is first converted according to the IPSec VPN (Internet Protocol Security Virtual Private Network) format to obtain the second data in the IPSec VPN format. After that, the second data is output. For example, in this embodiment, according to each address pointer in the forwarding queue 0, the corresponding second data is read from the storage area of the communication device. After that, the second data is converted according to the IPSec VPN format, and then the second data in the IPSec VPN format is output to the CPU0, and the CPU0 uses the second data for data calculation.

[0101] For another example, after the encryption / decryption threads 0 - 3 in thread pool 0 write the second data to the storage area according to the address pointers in the corresponding thread queues respectively, a processing completion message is generated to indicate that the first data corresponding to the address pointer in forwarding queue 0 has completed the encryption process or decryption process. Furthermore, after reading the second data according to the address pointer in forwarding queue 0, the second data is converted into the format of IPsec VPN, and then the second data in the format of IPsec VPN is output to CPU0; after the encryption / decryption threads 0 - 3 in thread pool 1 write the second data to the storage area according to the address pointers in the corresponding thread queues respectively, a processing completion message is generated to indicate that the first data corresponding to the address pointer in forwarding queue 1 has completed the encryption process or decryption process. Furthermore, after reading the second data according to the address pointer in forwarding queue 1, the second data is converted into the format of IPsec VPN, and then the second data in the format of IPsec VPN is output to CPU1; after the encryption / decryption threads 0 - 3 in thread pool 2 write the second data to the storage area according to the address pointers in the corresponding thread queues respectively, a processing completion message is generated to indicate that the first data corresponding to the address pointer in forwarding queue 2 has completed the encryption process or decryption process. Furthermore, after reading the second data according to the address pointer in forwarding queue 2, the second data is converted into the format of IPsec VPN, and then the second data in the format of IPsec VPN is output to CPU2; after the encryption / decryption threads 0 - 3 in thread pool 3 write the second data to the storage area according to the address pointers in the corresponding thread queues respectively, a processing completion message is generated to indicate that the first data corresponding to the address pointer in forwarding queue 3 has completed the encryption process or decryption process. Furthermore, after reading the second data according to the address pointer in forwarding queue 3, the second data is converted into the format of IPsec VPN, and then the second data in the format of IPsec VPN is output to CPU3.

[0102] In specific implementation, the thread pool is created based on the number of detected processor cores when the communication device starts. That is to say, when the communication device starts, the corresponding number of thread pools is created by detecting the number of processor cores it contains. For example, one processor core corresponds to one thread pool, and the total number of encryption / decryption threads in all thread pools is consistent with the total number of processing units in the encryption card. For example, first, 4 thread pools are created according to the number of processor cores 4, and then 4 corresponding encryption / decryption threads are created in each thread pool according to the total number of hardware channels 16 in the encryption card. Thus, each hardware channel corresponds to one encryption / decryption thread.

[0103] Reference Figure 13, which is a schematic structural diagram of a communication device provided by an embodiment of the present application. An encryption card is configured in the communication device. The encryption card has multiple processing units. As shown in Figure 2 As shown in, the processing unit here refers to the cryptographic chip in the encryption card, which can implement data encryption and decryption processing, etc. The data processing channel implemented can be called an encryption hardware channel. Moreover, the communication device contains multiple processor cores, each processor core corresponds to a thread pool respectively, each thread pool contains multiple encryption and decryption threads, and each encryption and decryption thread corresponds to a processing unit in the encryption card respectively. The technical solution in this embodiment is mainly used to maximize the performance of multiple processing units of the encryption card without interfering with the packet forwarding.

[0104] Specifically, the communication device in this embodiment may include the following structure:

[0105] One or more processors 1301;

[0106] A memory 1302, on which a computer program is stored;

[0107] When the computer program is executed by the one or more processors 1301, the one or more processors implement the following method:

[0108] After the communication device receives the first data, determine whether the first data meets the conditions for encryption and decryption processing;

[0109] When the first data meets the conditions for encryption and decryption processing, start the encryption and decryption threads in the thread pool to call the processing unit corresponding to the encryption and decryption thread to perform a first processing on the first data to obtain second data.

[0110] As can be seen from the above solution, a communication device provided by an embodiment of the present application creates corresponding encryption and decryption threads for the processor cores in the communication device to correspond to each processing unit in the encryption card. Based on this, when the communication device receives the first data and the first data meets the conditions for encryption and decryption processing, start the corresponding encryption and decryption threads to call the corresponding processing unit to process the first data, thereby obtaining second data. It can be seen that in this embodiment, corresponding threads are created for the processor cores, so that the encryption and decryption processing can be implemented without switching the threads corresponding to the normal network forwarding in the communication device to call the processing unit. Thus, the performance of multiple processing units of the encryption card can be maximized without interfering with the packet forwarding.

[0111] Taking a computer with a national secret encryption card as an example of the communication device, in order to improve the throughput of the national secret algorithm of the national secret encryption card, as shown in Figure 3As shown in the figure, each CPU (core) in the computer is bound to a forwarding process. Assuming that the hardware channels of the national cryptography encryption card are 16, each CPU is bound to 1 hardware channel. If the hardware channel of the national cryptography encryption card is 10 Mbps, the total national cryptography encryption and decryption algorithms of the computer can reach 160 Mbps.

[0112] As Figure 4 shown in the figure, the forwarding process in the kernel pre-allocates the corresponding number of threads (i.e., the encryption and decryption threads in the previous text) according to the number of hardware channels corresponding to each CPU. Each thread corresponds one-to-one with the hardware channel of the encryption card. The threads are default set to the sleep state. The forwarding process wakes up the threads in the thread pool only after there is an encryption and decryption event (i.e., after the forwarding process receives the data packet to be processed) to perform the task.

[0113] As Figure 14 and Figure 15 shown in [relevant figure or reference]: When the data needs to be encrypted and decrypted, the forwarding process uses a data queue (the ordered queue, i.e., the forwarding queue in the previous text) to store the addresses of all data (mainly used to ensure the order, because when calling different hardware channels for encryption, it cannot guarantee that the data is first-in, first-out, so the forwarding process uses a separate queue to ensure the order of the data). When the number of data addresses in the queue reaches a certain amount, it is allocated to the thread queues (working queues) on each thread. After the allocation is completed, all the threads in the thread pool are woken up to start working, and the forwarding process waits for the task completion results of all threads; all threads call the hardware channels in turn to perform encryption and decryption until all threads complete the tasks and notify the forwarding process; after the forwarding process gets the message, it takes out all the data in turn according to the ordered queue for processing.

[0114] In summary, in the embodiment of the present application, by pre-establishing the corresponding relationship between each core of the CPU and the hardware channels of the encryption card, establishing the corresponding relationship between the software coroutine stack (i.e., the thread pool) on the forwarding process running on each CPU and the encryption hardware channels, establishing the data list on the forwarding process (for ensuring order), allocating the corresponding relationship between the data of the forwarding process and each thread, and finally allocating the CPU slices to call the threads to achieve the operation of calling the encryption card to implement encryption and decryption, and finally completing the processing of the forwarded packets after encryption and decryption. Thus, the present application proposes an implementation technology that uses software to simulate coroutines to improve the throughput of the national cryptography algorithm, and then maximizes the utilization of multiple encryption channels of the national cryptography encryption card as much as possible without interfering with the normal data packet forwarding to achieve performance maximization, uses a software thread pool to simulate coroutine operations, and reduces the complexity of the upper-layer code.

[0115] In the present specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.

[0116] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0117] The steps of the methods or algorithms described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0118] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for controlling the invocation of an encryption card, characterized in that, Applied to a communication device, the communication device includes a plurality of processor cores, each of the processor cores corresponds to a thread pool, each of the thread pools includes a plurality of encryption and decryption threads, each of the encryption and decryption threads corresponds to a processing unit in an encryption card, and the encryption and decryption threads are all in a non-preemptive mode and do not cause thread switching on the system, so as to ensure that the normal network forwarding is not disturbed when processing the encryption and decryption tasks. The thread pool is created based on the detected number of processor cores when the communication device is started. The method includes: After the communication device receives the first data, determine whether the first data meets the conditions for encryption and decryption processing; When the first data meets the conditions for encryption and decryption processing, start the encryption and decryption threads in the thread pool to call the processing unit corresponding to the encryption and decryption thread to perform a first processing on the first data to obtain second data.

2. The method according to claim 1, wherein Before starting the encryption and decryption threads in the thread pool, the method further includes: Determine whether any of the following call conditions is met: The target thread is in an idle state; the target thread is the main thread for data transmission in the communication device; Or, The target duration reaches the duration threshold, and the target duration is the duration from the most recent start of the encryption and decryption thread to the current moment; Or, The cumulative quantity of the first data reaches a preset quantity threshold; When any of the call conditions is met, execute the following: start the encryption and decryption threads in the thread pool.

3. The method according to claim 1 or 2, characterized in that, Each of the thread pools is respectively provided with a corresponding forwarding queue, and the forwarding queue is used to store the data identifier corresponding to the first data; Moreover, each of the encryption and decryption threads is respectively provided with a corresponding thread queue. When the cumulative quantity of the data identifiers in the forwarding queue reaches a preset cumulative threshold, the data identifiers in the forwarding queue are distributed to each of the thread queues, so that the encryption and decryption threads call the corresponding processing units to perform a first processing on the first data corresponding to the data identifiers in the thread queue.

4. The method according to claim 3, characterized in that The data identifiers corresponding to the first data are stored in the forwarding queue according to the order identifier corresponding to the first data, and the order identifier represents the data stream to which the first data belongs, so that the data identifiers corresponding to the first data belonging to the same data stream are stored in the same forwarding queue.

5. The method according to claim 4, characterized in that, The order identifier also represents whether the first data meets the conditions for encryption and decryption processing; Among them, determining whether the first data meets the conditions for encryption and decryption processing includes: Determine whether the order identifier corresponding to the first data matches a preset data stream identifier; the data stream identifier is the identifier of the data stream that needs to be encrypted and decrypted; Among them, if the order identifier corresponding to the first data matches the data stream identifier, it indicates that the first data meets the conditions for encryption and decryption processing; if the order identifier corresponding to the first data does not match the data stream identifier, it indicates that the first data does not meet the conditions for encryption and decryption processing.

6. The method according to claim 3, characterized in that The storage space in the forwarding queue is equal to the sum of the storage spaces of the thread queues corresponding to the forwarding queue.

7. The method according to claim 3, wherein The encryption and decryption threads in the thread pool have thread numbers, and the thread numbers represent the thread order among the encryption and decryption threads; Wherein, before starting the encryption and decryption threads in the thread pool, the method further includes: According to the thread numbers, in a polling manner, distribute the data identifiers in the forwarding queue to the thread queues corresponding to each of the encryption and decryption threads in sequence, so that the encryption and decryption threads call the corresponding processing units to perform a first processing on the first data corresponding to the data identifiers in the thread queues.

8. The method according to claim 7, wherein The encryption and decryption threads call the corresponding processing units to perform a first processing on the first data corresponding to the data identifiers in the thread queues, including: The encryption and decryption threads read the first data corresponding to the data identifiers in the storage area according to the data identifiers in the thread queues; The encryption and decryption threads send the first data to the processing units corresponding to the encryption and decryption threads, so that the processing units perform encryption processing or decryption processing on the received first data to obtain second data; The encryption and decryption threads write the second data sent by the processing units into the storage area according to the data identifiers corresponding to them in the thread queues.

9. The method according to claim 7, characterized in that, The method further includes: After obtaining the processing completion message, output the second data; Wherein, the processing completion message is generated after all the encryption and decryption threads in the thread pool call the corresponding processing units to process all the first data corresponding to the data identifiers in the thread queues.

10. The method according to claim 9, wherein Before outputting the second data, the method further includes: Perform data format conversion processing on the second data according to a preset target format to obtain the second data in the target format.

11. The method according to claim 1 or 2, characterized in that, The encryption and decryption threads are in a dormant state before being started; and, the encryption and decryption threads enter a dormant state after calling the processing units.

12. A communication device, characterized in that, Including: One or more processors; A memory, on which a computer program is stored; When the computer program is executed by the one or more processors, the one or more processors are caused to implement the call control method of the encryption card according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Encryption and decryption method for encrypt card

    CN102724035A

  • Message encrypting / decrypting method

    CN102843235A