Data processing method, system, electronic device and computer readable storage medium
By using the asynchronous HSM engine to write data to the buffer and cut out the target coroutine during the encryption and decryption task processing, the resource idle problem caused by the interaction between the business system and the HSM is solved, and the system performance is improved.
Patent Information
- Application Number
- CN202210987911.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-08-17
AI Technical Summary
During the process of encrypting and decrypting tasks, multiple information interactions may be required between the business system and the HSM, resulting in the idleness of relevant resources and low system performance.
The target coroutine calls the asynchronous HSM engine, writes the pending data into the buffer, causes the HSM service to take out the data from the buffer and sends it to the HSM for processing, and then cuts out the target coroutine and frees up the system resources.
It realizes normal processing of encryption and decryption tasks, and improves the utilization rate of system resources and the performance of the entire system.
Smart Images

Figure CN115378685B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a data processing method, system, electronic device and computer-readable storage medium. Background Art
[0002] At present, in order to ensure information security, the information exchange in the encryption and decryption process is generally realized through the OpenSSL Engine mechanism during encryption and decryption. Specifically, private information such as private keys will be stored in the hardware security module HSM (encryption machine) to protect the security of encryption keys and prevent private keys from being stolen.
[0003] When performing encryption and decryption operations, the business system calls Openssl, which then calls the synchronous HSM engine, so that the data is sent to the HSM for processing through the synchronous HSM engine, and the processed data is transmitted back to the business system in the opposite direction. During the entire processing process, the business system and the HSM may need to exchange information multiple times. The current Openssl Engine mechanism is designed based on the synchronous mode, that is, the relevant resources used for encryption and decryption in the business system must be released after the encryption and decryption tasks between the current HSM are completed to process other tasks. However, as mentioned above, during the processing of encryption and decryption tasks, the business system and the HSM may need to exchange information multiple times. During this period, if the processing node is not in the business system, the business system is in a waiting state, and the relevant resources are idle, resulting in low performance of the entire system. Summary of the invention
[0004] The purpose of the embodiments of the present application is to provide a data processing method, system, electronic device and computer-readable storage medium to solve the problem that related resources are idle during the processing of encryption and decryption tasks, resulting in low performance of the entire system.
[0005] An embodiment of the present application provides a data processing method, comprising: calling an asynchronous HSM engine through a target coroutine to write the data to be processed into a buffer through the asynchronous HSM engine, so that a preset HSM service takes out the data to be processed from the buffer and sends it to the HSM; and cutting out the target coroutine.
[0006] The solution of the present application, through the target coroutine calling the asynchronous HSM engine to write the data to be processed into the buffer, so that the HSM service sends the data to be processed to the HSM for encryption or decryption processing, can ensure that the encryption and decryption tasks performed with the HSM can be processed normally. After the data to be processed is written into the buffer through the asynchronous HSM engine, the solution of the present application will cut out the target coroutine, at which time the system resources occupied by the target coroutine are released, and the relevant resources can be used by other coroutines to process other data or perform other tasks, thereby improving the utilization of system resources and improving the performance of the entire system.
[0007] Furthermore, the method also includes: waking up the target coroutine when a preset target coroutine wake-up condition is met; detecting whether there is target data in the buffer through the target coroutine; the target data is the data obtained after the HSM completes processing the data to be processed; if it exists, taking out the target data and processing the target data through the target coroutine; if it does not exist, cutting out the target coroutine.
[0008] In the above implementation process, after the HSM completes processing of the pending data transmitted by the HSM service, the processed target data will be written into the buffer, thereby waking up the target coroutine and detecting whether the target data exists in the buffer. After the HSM completes processing of the pending data transmitted by the HSM service, the encryption and decryption tasks between the HSM and the HSM can be continued, thereby ensuring the normal execution of the entire encryption and decryption task.
[0009] Furthermore, the target coroutine wake-up condition includes at least one of the following:
[0010] There is currently no coroutine to be executed, and the wake-up round in the preset coroutine list is the turn of the target coroutine; the coroutine list records all the coroutines that have been created and switched out;
[0011] A first notification from the HSM service is received, the first notification indicating that the HSM service has written the target data into the buffer.
[0012] In the first target coroutine wake-up condition mentioned above, through the polling mechanism, when there is no coroutine to be executed at present and it is the target coroutine's turn to wake up in the coroutine list, the target coroutine is awakened to detect whether there is target data in the buffer, thereby ensuring the normal execution of the encryption and decryption tasks, and the whole method does not rely on other components or services, and has higher reliability. In the second target coroutine wake-up condition mentioned above, the target coroutine is awakened by notifying through the HSM service, which can avoid the invalid awakening of the target coroutine (that is, the target coroutine is awakened, but there is no target data to be processed), and to a certain extent reduce the resource loss caused by the invalid awakening of the target coroutine.
[0013] Furthermore, the buffer is a ring buffer.
[0014] In the embodiment of the present application, by using a circular buffer to store the data to be processed, the HSM service can retrieve the data to be processed on demand without being restricted to retrieving the data in the order in which the data was written.
[0015] Furthermore, before the data to be processed is written into the buffer through the asynchronous HSM engine, the method further includes: calling a preset Openssl library to configure an implementation method of an encryption algorithm or a decryption algorithm in the data to be processed.
[0016] In an embodiment of the present application, the implementation method of the required encryption algorithm or decryption algorithm can be defined through the Openssl library, so that by calling the Openssl library, the implementation method of the encryption algorithm or decryption algorithm in the data to be processed can be implemented according to the defined implementation method, thereby meeting the user's own encryption and decryption task requirements.
[0017] Furthermore, writing the data to be processed into the buffer through the asynchronous HSM engine includes: serializing the data to be processed through the asynchronous HSM engine; and writing the serialized data to be processed into the buffer.
[0018] An embodiment of the present application also provides a data processing system, including: a business system, an asynchronous HSM engine, a buffer and an HSM service; wherein: the business system is used to use the asynchronous HSM engine through a target coroutine to write the data to be processed into the buffer through the asynchronous HSM engine; the business system is also used to cut out the target coroutine after writing the data to be processed into the buffer through the asynchronous HSM engine; the HSM service is used to take out the data to be processed from the buffer and send it to the HSM.
[0019] Through the data processing system provided by the embodiment of the present application, when the business system needs to interact with the HSM, after the target coroutine calls the asynchronous HSM engine to write the data to be processed into the buffer, the target coroutine can be cut out to release system resources. Since the system resources are released, the business system can now create or wake up other coroutines to use the system resources to go to the relevant data or tasks of the coroutine, thereby improving the utilization of system resources and improving the performance of the entire system. At the same time, since the HSM service will send the data to be processed to the HSM for encryption or decryption processing, after the target coroutine is cut out, even if the business system is processing other tasks through other coroutines, it can also ensure that the encryption and decryption tasks performed between the HSM can be processed normally.
[0020] Furthermore, the business system is also used to wake up the target coroutine when a preset target coroutine wake-up condition is met, and detect whether there is target data in the buffer through the target coroutine; if so, take out the target data and process the target data through the target coroutine; if not, cut out the target coroutine; wherein the target data is the data obtained after the HSM completes processing the data to be processed.
[0021] An embodiment of the present application also provides an electronic device, which includes a processor, a memory and a buffer; the memory stores a program or firmware for implementing a business system, an encryption machine asynchronous HSM engine and an HSM service, and the program or the firmware runs on the processor to implement the above-mentioned data processing system.
[0022] A computer-readable storage medium is also provided in an embodiment of the present application. The computer-readable storage medium stores one or more programs. The one or more programs can be executed by one or more processors to implement any of the above-mentioned data processing methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0024] Figure 1 A schematic diagram of the structure of a data processing system and HSM provided in an embodiment of the present application;
[0025] Figure 2 A schematic diagram of a system structure for connecting to an HSM through a synchronous HSM engine or a network connection interface provided by an HSM manufacturer, provided in an embodiment of the present application;
[0026] Figure 3 A schematic diagram of a system structure with an OpenSSL library provided in an embodiment of the present application;
[0027] Figure 4 A schematic diagram of a serialized data structure provided in an embodiment of the present application;
[0028] Figure 5 A flowchart of a data processing method provided in an embodiment of the present application;
[0029] Figure 6 A schematic diagram of a specific overall structure of a system provided in an embodiment of the present application;
[0030] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0031] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0032] Embodiment 1:
[0033] In order to solve the problem that during the current encryption and decryption task processing, the business system and the HSM may need to exchange information multiple times. During this period, if the processing node is not in the business system, the business system is in a waiting state, and the relevant resources are idle, resulting in low performance of the entire system, the present application embodiment provides a data processing system. Figure 1 As shown, Figure 1 This is a basic structural diagram of the data processing system provided in an embodiment of the present application, including: a business system, an asynchronous HSM engine, a buffer and an HSM service.
[0034] It should be understood that the business system, asynchronous HSM engine, buffer and HSM service can be deployed on the same electronic device, but can also be deployed on different electronic devices, which is not limited in the embodiments of the present application.
[0035] It should also be understood that in the embodiments of the present application, the business system, asynchronous HSM engine, and HSM service can be deployed through programs or firmware and implemented through a processor of an electronic device (such as a CPU (Central Processing Unit / Processor)).
[0036] In an embodiment of the present application, the business system is used to call the asynchronous HSM engine through the target coroutine, so as to write the data to be processed into the buffer through the asynchronous HSM engine.
[0037] In an embodiment of the present application, the business system is also used to cut out the target coroutine after writing the to-be-processed data into the buffer through the asynchronous HSM engine.
[0038] In the embodiment of the present application, the HSM service is used to retrieve the data to be processed from the buffer and send it to the HSM.
[0039] In this way, when the business system needs to interact with the HSM, after the target coroutine calls the asynchronous HSM engine to write the data to be processed into the buffer, the target coroutine can be cut out to release system resources. Since the system resources are released, the business system can now create or wake up other coroutines to use the system resources to go to the relevant data or tasks of the coroutine, thereby improving the utilization of system resources and the performance of the entire system. At the same time, since the HSM service will send the data to be processed to the HSM for encryption or decryption, after the target coroutine is cut out, even if the business system is processing other tasks through other coroutines, it can ensure that the encryption and decryption tasks between the HSM and the HSM can be processed normally.
[0040] It should be noted that in the embodiments of the present application, the target coroutine refers to the coroutine used to perform encryption and decryption tasks. A coroutine is an execution unit that is lighter than a thread, and can collaboratively perform context switching to actively give up system resources without the participation of a scheduler. It should be understood that in some systems or files, coroutines are also referred to as fibers (for example, in the widows system, coroutines are called fibers, and the two are only different in name, but the essence is the same), so whether it is called a coroutine or a fiber, as long as it is implemented in accordance with the solution provided in the embodiments of the present application, it should be included in the scope of protection of the present application.
[0041] In the embodiment of the present application, considering that HSM is generally produced and provided by a dedicated HSM manufacturer, in order to ensure the normal interaction between the HSM service and the HSM, refer to Figure 2 As shown, the HSM service can interact with the HSM by calling the synchronous HSM engine provided by the HSM manufacturer (which is two independent and different engines from the asynchronous HSM engine provided in this application) or a network connection interface (such as HTTP (HyperText Transfer Protocol) API (Application Program Interface)), but this is not a limitation.
[0042] It should be understood that the so-called synchronous HSM engine is an HSM engine implemented in synchronous mode. The asynchronous HSM engine described in the embodiment of the present application is an HSM engine implemented in asynchronous mode. The so-called asynchronous mode means that after the HSM engine writes the data to be processed into the buffer, the relevant resources can be released, allowing the business system to use the released resources to process other data or tasks.
[0043] In the embodiment of the present application, the HSM service can be implemented through a web application or a microservice, but this is not a limitation.
[0044] In order to ensure that the HSM service can accurately take out the data to be processed from the buffer and send it to the HSM, in a feasible implementation of the embodiment of the present application, after the asynchronous HSM engine writes the data to be processed into the buffer, it can send a second notification to the HSM service indicating that the data to be processed has been written. After receiving the second notification, the HSM service can read the data to be processed from the buffer and send it to the HSM for processing.
[0045] In another feasible implementation of the embodiment of the present application, the HSM service can continuously access the buffer at a preset time interval to try to obtain the data to be processed. When the data to be processed is obtained, it can be sent to the HSM for processing.
[0046] In the embodiment of the present application, after the HSM completes processing the data to be processed, the target data obtained after processing the data to be processed is sent to the HSM service, and the HSM service writes the target data into the buffer. Thereafter, the business system can obtain the target data by waking up the target coroutine, and perform the next step of processing through the target coroutine.
[0047] In the embodiment of the present application, the business system can also be used to wake up the target coroutine when the preset target coroutine wake-up condition is met, and detect whether there is target data in the buffer through the target coroutine. If it exists, the target data is taken out and processed by the target coroutine; if it does not exist, the target coroutine is cut out. Among them, the target data is the data obtained after the HSM completes the processing of the data to be processed.
[0048] Exemplarily, in an optional implementation of the embodiment of the present application, a coroutine list can be configured in the business system, and all coroutines that have been created and cut out are recorded in the coroutine list. Then, the business system adopts a round-robin mechanism. As long as there is no coroutine to be executed at present, that is, the coroutines recorded in the round-robin coroutine list, each coroutine is awakened in turn and it is determined whether there is corresponding data or tasks to be processed. If so, the coroutine is used as the current coroutine to be executed, and the coroutine is executed to process the data or tasks corresponding to the coroutine. If not, the awakened coroutine is cut out, and the next coroutine is judged whether there is corresponding data or tasks to be processed.
[0049] In this optional implementation, the target coroutine wake-up condition may include: there is currently no coroutine to be executed, and the wake-up round in the preset coroutine list is the target coroutine's turn. In this way, after the target coroutine is cut out, the target coroutine is recorded in the coroutine record table. When there is currently no coroutine to be executed and the wake-up round in the preset coroutine list is the target coroutine's turn, the target coroutine will be awakened, so that the target coroutine can detect whether there is target data in the buffer. If it exists, the target data is taken out and processed by the target coroutine. If it does not exist, the target coroutine is cut out, and the next coroutine in the coroutine record table continues to be awakened and judged.
[0050] For example, suppose that there are two coroutines A and B recorded in the coroutine record table, where coroutine A is the target coroutine. After the currently executed coroutine C is terminated or cut out (it should be noted that in the embodiment of the present application, the coroutine is in a dormant state after being cut out, and the relevant resources are released. When the coroutine itself still exists and has not been terminated), the polling mechanism is started. First wake up coroutine A (i.e., the target coroutine), coroutine A detects whether there is target data in the buffer. If so, coroutine A processes the target data, and the processing method is determined by the encryption or decryption algorithm used and the encryption or decryption node. If not, coroutine A is cut out, coroutine B is awakened, and coroutine B detects whether there is data or tasks to be processed. If so, it is processed. If not, coroutine B is cut out and the current round of polling is terminated. It should be understood that if coroutine C is cut out, coroutine C will be added to the coroutine record table, so that in the polling process, after coroutine B is cut out, coroutine C will be awakened, and coroutine C will determine whether there is data or tasks to be processed.
[0051] It should be understood that in the embodiment of the present application, after each round of polling is completed, if there is no newly created coroutine to be executed, polling can be performed again after a preset time interval (for example, 0.1 second or 1 second).
[0052] In another optional implementation of the embodiment of the present application, after writing the target data into the buffer, the HSM service can actively send a first notification to the business system indicating that the target data has been written into the buffer. After receiving the first notification, the business system can wake up the target coroutine to obtain the target data from the buffer for processing.
[0053] In the above optional implementation manner, the target coroutine wake-up condition includes the business system receiving the first notification of the HSM service.
[0054] It should be understood that the above two optional implementation modes can be implemented separately or simultaneously, and there is no limitation on this in the embodiments of the present application.
[0055] It should be understood that when the target coroutine is processing the target data, if it is no longer necessary to interact with the HSM, the target coroutine can be terminated after the processing is completed, completing the encryption and decryption task. If the target coroutine is processing the target data, if it is still necessary to interact with the HSM, the processed visual data can be used as new data to be processed, and the new data to be processed can be written into the buffer by calling the asynchronous HSM engine, and the target coroutine is cut out, and the HSM service obtains the new data to be processed and sends it to the HSM for processing.
[0056] It should be understood that the asynchronous HSM engine includes a variety of algorithms for encryption or decryption, such as RSA algorithm, ECC (Ellipse Curve Ctyptography) algorithm, ECDH (Elliptic Curves DiffieHellman, elliptic curve key exchange) algorithm, DH (Diffie Hellman, key exchange protocol) algorithm, SM2 algorithm, etc. Each algorithm needs to be implemented through a large number of functions.
[0057] As mentioned above, coroutines can collaboratively perform context switching to actively give up system resources without the involvement of the scheduler. Therefore, when a coroutine is switched out, the stack corresponding to the coroutine can be completely retained in the structure corresponding to the coroutine. In an embodiment of the present application, when the target coroutine is awakened and the asynchronous HSM engine is called again, the relevant function can directly obtain the latest parameters from the stack corresponding to the target coroutine, thereby ensuring the reliability of calling the asynchronous HSM engine.
[0058] In an optional implementation of the embodiment of the present application, see Figure 3 As shown, the data processing system may also include an Openssl library, in which implementation methods of various encryption algorithms or decryption algorithms may be defined.
[0059] When calling the asynchronous HSM engine, the target coroutine can also call the Openssl library first to configure the implementation method of the encryption algorithm or decryption algorithm in the data to be processed. Generally speaking, the data to be processed will be configured with a default implementation method of the encryption algorithm or decryption algorithm. The target coroutine can call the Openssl library to replace the implementation method of the encryption algorithm or decryption algorithm in the data to be processed with the implementation method of the encryption algorithm or the decryption algorithm in the Openssl library, thereby realizing the configuration of the implementation method of the encryption algorithm or decryption algorithm in the data to be processed. If the implementation method of the encryption algorithm or decryption algorithm is not configured in the data to be processed, the target coroutine can call the Openssl library to configure the implementation method of the encryption algorithm or decryption algorithm for the data to be processed. In this way, the implementation method of the encryption algorithm or decryption algorithm can be defined according to the requirements, thereby meeting the encryption and decryption task requirements of the user itself.
[0060] In an optional implementation of the embodiment of the present application, the asynchronous HSM engine may first serialize the data to be processed to obtain serialized data to be processed, and then write the serialized data to be processed into a buffer.
[0061] For example, Figure 4 As shown, in an embodiment of the present application, the serialized data to be processed may include an algorithm unique identifier (i.e., the ID in the figure, different ID values correspond to different algorithms), a key (i.e., the key in the figure, generally a public key, and the private key is stored in the HSM and cannot be obtained), data content (i.e., data in the figure), parameters (i.e., params in the figure), and a processing status identifier (i.e., DD in the figure, when DD is a first identification value (for example, 0), it indicates that it is data to be processed that needs to be sent to the HSM for processing, and when DD is a second identification value (for example, 1), it indicates that it is target data that has been processed by the HSM, and the HSM service and the target coroutine can determine whether the data is data that can be obtained by themselves through DD).
[0062] In an embodiment of the present application, the buffer can be implemented using a circular buffer. By storing the data to be processed in the circular buffer, the HSM service can retrieve the data to be processed on demand without being restricted to retrieving the data in the order in which the data was written, thereby having higher flexibility.
[0063] Optionally, in an embodiment of the present application, the buffer may be a dedicated buffer configured for the HSM service, that is, it is only connected to the asynchronous HSM engine and the HSM service, so that it is only used to store data related to the encryption and decryption tasks, avoiding the situation where the data of other coroutines are mistakenly obtained. In addition, the buffer may also be a general buffer, so that the target coroutine and the HSM service can determine whether the data is involved in the encryption and decryption task through the algorithm unique identification of the data stored in the buffer.
[0064] Based on the same inventive concept, the present application also provides a data processing method in a business system that can be applied to the above data processing system, which can be seen in Figure 5 As shown, including:
[0065] S501: calling the encryption machine asynchronous HSM engine through the target coroutine to write the data to be processed into the buffer through the asynchronous HSM engine, so that the preset HSM service takes out the data to be processed from the buffer and sends it to the HSM.
[0066] S502: Cut out the target coroutine.
[0067] Corresponding to the foregoing, in the embodiment of the present application, the data processing method may further include:
[0068] When the preset target coroutine wake-up condition is met, the target coroutine is woken up. The target coroutine detects whether there is target data in the buffer; if so, the target data is taken out and processed by the target coroutine; if not, the target coroutine is cut out.
[0069] The target coroutine wake-up condition includes at least one of the following:
[0070] There is no coroutine to be executed at present, and the wake-up round in the preset coroutine list is the target coroutine's turn; the coroutine list records all the coroutines that have been created and switched out;
[0071] A first notification from the HSM service is received, the first notification indicating that the HSM service has written the target data into the buffer.
[0072] Optionally, in an embodiment of the present application, before writing the data to be processed into the buffer through the asynchronous HSM engine, the data processing method may also include: calling a preset Openssl library to configure an implementation method of the encryption algorithm or decryption algorithm in the data to be processed.
[0073] Optionally, in an embodiment of the present application, in the data processing method, the step of writing the data to be processed into the buffer through the asynchronous HSM engine may include: serializing the data to be processed through the asynchronous HSM engine, and writing the serialized data to be processed into the buffer.
[0074] It should be understood that the scheme described in the data processing system is also applicable to the data processing method. Therefore, for the sake of brevity, some of the contents described in the data processing system will not be repeated in the data processing method part.
[0075] It should also be noted that in the embodiment of the present application, the business system may have a coroutine management module, so that the relevant management and control operations of the coroutine in the embodiment of the present application can be implemented through the coroutine management module, such as the creation, switching out, waking up, ending, calling and other related control operations of the coroutine.
[0076] The data processing system and data processing method provided in the embodiments of the present application, when the business system needs to interact with the HSM, after the target coroutine calls the asynchronous HSM engine to write the data to be processed into the buffer, the target coroutine can be cut out to release system resources. Since the system resources are released, the business system can now create or wake up other coroutines to use the system resources to go to the relevant data or tasks of the coroutine, thereby improving the utilization of system resources and improving the performance of the entire system. At the same time, since the HSM service will send the data to be processed to the HSM for encryption or decryption processing, after the target coroutine is cut out, even if the business system is processing other tasks through other coroutines, it can also ensure that the encryption and decryption tasks performed between the HSM can be processed normally.
[0077] Embodiment 2:
[0078] This embodiment is based on the first embodiment. Figure 6 The implementation structure of the data processing system shown is taken as an example to further illustrate this application.
[0079] When there is an encryption and decryption task, the coroutine management module in the business system switches the coroutine currently to be executed to the target coroutine for executing the encryption and decryption task.
[0080] The target coroutine calls the asynchronous HSM engine, which replaces the implementation method of the encryption or decryption algorithm in the pending data to be sent to the HSM in the encryption and decryption task with the method in the Openssl library. Then, the asynchronous HSM engine serializes the replaced data to be processed, writes it into the ring buffer (the DD value of the data to be processed is 0 at this time, indicating that the data needs to be processed by the HSM), and notifies the HSM service. At this time, the coroutine management module in the business system cuts out the target coroutine and releases the system resources occupied by the target coroutine. At this time, the coroutine management module can create or wake up other coroutines as the current coroutines to be executed to process other tasks.
[0081] At the same time, the HSM service receives notification from the asynchronous HSM engine, takes out the data to be processed from the ring buffer, and transmits the data to be processed to the HSM for processing (encryption or decryption) through the synchronous HSM engine provided by the HSM manufacturer or the HTTP API interface provided by the HSM manufacturer.
[0082] After the HSM processing is completed, the processed target data is returned to the HSM service through the asynchronous HSM engine provided by the HSM manufacturer or the HTTP API interface provided by the HSM manufacturer.
[0083] The HSM service serializes the target data and writes it into the ring buffer (at this time, the DD value of the target data is 1, indicating that the data has been processed by the HSM).
[0084] At this time, the HSM service may optionally notify the business system. After the business system receives the notification, the coroutine management module wakes up the target coroutine and takes out the target data with DD 1 from the ring buffer for processing.
[0085] Optionally, the notification mechanism may not be adopted, but the coroutine management module may poll the coroutine list managed by the coroutine management module when the coroutine to be executed is cut out or ends. When the target coroutine is polled, if there is target data with DD of 1 in the buffer, the target coroutine obtains the target data and processes it. For the specific polling method, please refer to the description of the first embodiment, which will not be repeated here.
[0086] If multiple interactions are required between the business system and the HSM, the target coroutine will obtain new data to be processed after processing the target data, so the above method can be repeated until the entire encryption and decryption task is completed.
[0087] Through the above solution, when the HSM performs encryption and decryption operations, the business system can process other events in parallel, the probability of system resources being idle is reduced, and the overall performance of the system is improved.
[0088] Embodiment three:
[0089] Based on the same inventive concept, the present application also provides an electronic device, see Figure 7 As shown, it includes a processor 701, a memory 702 and a buffer 703. Among them: the memory stores a program or firmware for implementing a business system, an asynchronous HSM engine and an HSM service, and the program or the firmware runs on the processor to implement the data processing system provided in the first embodiment and / or the second embodiment.
[0090] Understandably, Figure 7 The structure shown is for illustration only. The electronic device may also include Figure 7 More or fewer components as shown, or with Figure 7 For example, the electronic device may also have a communication bus to realize the connection and communication between the processor 701, the memory 702 and the buffer 703. For another example, the electronic device may also have a wireless communication module to realize wireless communication with an external device.
[0091] It can also be understood that the processor described in the embodiments of the present application can be a device with data processing capabilities such as a CPU, an MCU (Microcontroller Unit), an MPU (Microprocessor Unit), etc., but it is not limited thereto. The memory described in the embodiments of the present application can be a device such as a memory, a flash memory, a hard disk, etc. that can be used to store programs or firmware, but it is not limited thereto.
[0092] This embodiment also provides a computer-readable storage medium, such as a floppy disk, an optical disk, a hard disk, a flash memory, a USB flash disk, an SD (Secure Digital Memory Card) card, an MMC (Multimedia Card) card, etc., in which one or more programs implementing the above method are stored, and the one or more programs can be executed by one or more processors to implement the data processing method executed by the business system in the above embodiment 1 and / or embodiment 2. No further details will be given here.
[0093] In the embodiments provided in this application, each embodiment can be implemented independently or in coordination with each other.
[0094] In the embodiments provided in the present application, relational terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any actual relationship or order between these entities or operations.
[0095] In the embodiments provided in this application, a plurality refers to two or more than two.
[0096] The above description is only an embodiment of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A data processing method, It is characterized in that include: The asynchronous HSM engine is called through the target coroutine to write the data to be processed into the buffer through the asynchronous HSM engine, so that the preset HSM service takes out the data to be processed from the buffer and sends it to the HSM; the data to be processed is the data that needs to be encrypted or decrypted by the HSM; wherein the data to be processed is the data serialized by the asynchronous HSM engine; the data to be processed includes the algorithm unique identifier, key, data content, parameters and processing status identifier; when the processing status identifier is the first identifier value, it indicates that the data to be processed needs to be sent to the HSM for processing, and when the processing status identifier is the second identifier value, it indicates that the data to be processed is the target data that has been processed by the HSM, and the HSM service and the target coroutine determine whether the data to be processed is data that can be obtained by themselves through the processing status identifier; Cut out the target coroutine; The method further comprises: When the preset target coroutine wake-up condition is met, wake up the target coroutine; Detecting whether there is target data in the buffer by the target coroutine; the target data is the data obtained after the HSM completes processing the data to be processed; If it exists, taking out the target data and processing the target data through the target coroutine; If it does not exist, the target coroutine is cut out.
2. The data processing method according to claim 1, It is characterized in that The target coroutine wake-up condition includes at least one of the following: There is currently no coroutine to be executed, and the wake-up round in the preset coroutine list is the turn of the target coroutine; the coroutine list records all the coroutines that have been created and switched out; A first notification from the HSM service is received, the first notification indicating that the HSM service has written the target data into the buffer.
3. The data processing method according to claim 1, It is characterized in that The buffer is a ring buffer.
4. The data processing method according to any one of claims 1 to 3, It is characterized in that Before writing the to-be-processed data into the buffer by the asynchronous HSM engine, the method further includes: The preset OpenSSL library is called to configure the implementation method of the encryption algorithm or decryption algorithm in the data to be processed.
5. The data processing method according to any one of claims 1 to 3, It is characterized in that Writing the data to be processed into the buffer through the asynchronous HSM engine includes: Serializing the data to be processed by the asynchronous HSM engine; The serialized data to be processed is written into the buffer.
6. A data processing system, It is characterized in that include: Business system, asynchronous HSM engine, buffer and HSM service; wherein: The business system is used to call the asynchronous HSM engine through the target coroutine to write the data to be processed into the buffer through the asynchronous HSM engine; the data to be processed is data that needs to be encrypted or decrypted by the HSM; wherein the data to be processed is data serialized by the asynchronous HSM engine; the data to be processed includes an algorithm unique identifier, a key, data content, parameters and a processing status identifier; when the processing status identifier is a first identifier value, it indicates that the data to be processed needs to be sent to the HSM for processing, and when the processing status identifier is a second identifier value, it indicates that the data to be processed is the target data that has been processed by the HSM, and the HSM service and the target coroutine determine whether the data to be processed is data that can be obtained by themselves through the processing status identifier; The business system is also used to cut out the target coroutine after the to-be-processed data is written into the buffer through the asynchronous HSM engine; The HSM service is used to take out the data to be processed from the buffer and send it to the HSM; The business system is also used to wake up the target coroutine when a preset target coroutine wake-up condition is met, and detect whether there is target data in the buffer through the target coroutine; if so, take out the target data and process the target data through the target coroutine; if not, cut out the target coroutine; wherein the target data is the data obtained after the HSM completes processing the data to be processed.
7. An electronic device, It is characterized in that The electronic device includes a processor, a memory and a buffer; the memory stores a program or firmware for implementing a business system, an encryption machine asynchronous HSM engine and an HSM service, and the program or the firmware runs on the processor to implement the data processing system as described in claim 6.
8. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the data processing method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Virtual machine backup method and device, electronic equipment and readable storage medium
CN112395050A
Data processing method and device, equipment and medium
CN114338629A