A fast assistant system for SSL hardware acceleration card and working method

CN115455494BActive Publication Date: 2026-10-09TIH MICROELECTRONIC TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211066858.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-01
Publication Date
2026-10-09
Estimated Expiration
2042-09-01

AI Technical Summary

Technical Problem

[0005]1)缺少SSL硬件加速卡管理的环节:加速卡一般会有多个加速单元,每个加速单元用于完成对称或非对称算法的加解密,该环节的缺失将无法做到对硬件加速单元的精细化管理

Benefits of technology

[0066] 1) This invention provides a resource management mechanism that controls and separates the hardware acceleration units occupied by a process (or a group of processes) through configuration files, thereby satisfying the computing power required by a single process and providing dynamic allocation of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115455494B_ABST
    Figure CN115455494B_ABST
Patent Text Reader

Abstract

A fast assistant system for SSL hardware acceleration card, comprising: a service access module, an acceleration driver module, an operating system adaptation module and an OpenSSL engine module; the service access module provides acceleration services for application programs, and each service is provided by a service entity in the module; the acceleration driver module contains services relied on by the service access module, and also provides hardware-level interaction of the Platform, especially Platform registration and reset; the operating system adaptation module is used to provide an access layer to shield differences between operating systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention discloses a fast assistance system and its working method for SSL hardware acceleration cards, belonging to the technical field of security chips. Background Technology

[0002] Currently, over 50% of internet traffic accesses data center servers via the SSL protocol. While SSL enhances authentication and data security for web applications, its encryption and decryption processes significantly consume server resources. To alleviate this performance pressure, encryption and decryption operations during web application access to the server are offloaded to SSL hardware accelerator cards, reducing server performance load while still meeting high concurrency requirements. Therefore, to make offloading data encryption and decryption to SSL hardware accelerator cards possible, it's necessary to efficiently transmit or receive data to and from these cards while maximizing compatibility with the hardware algorithms supported by the SSL hardware accelerator cards.

[0003] To this end, Chinese patent document CN201310701609.7 discloses a device and method for improving SSL data processing speed, which uses an SSL accelerator card with a PCI-e standard interface to process data in the network. The method includes a data processing module and an address translation module.

[0004] However, existing technologies still have the following problems or shortcomings:

[0005] 1) Lack of SSL hardware acceleration card management: Acceleration cards typically have multiple acceleration units, each used to perform encryption and decryption of symmetric or asymmetric algorithms. The absence of this step will prevent fine-grained management of the hardware acceleration units.

[0006] 2) The address translation module does not provide cache consistency guarantees: To improve data transfer efficiency, publicly available methods provide zero-copy technology based on address translation. This requires that the same physical address be accessible to user space, kernel space, and the SSL hardware acceleration card, and that the data read by all three must be consistent at all times. Publicly available methods only guarantee consistency between user space and kernel space, not between the three.

[0007] 3) The process of adapting SSL hardware acceleration card algorithms, especially Chinese cryptographic algorithms, is lacking. Summary of the Invention

[0008] In view of the technical problems existing in the prior art, the present invention discloses a fast assistance system for SSL hardware acceleration cards.

[0009] The present invention also discloses the working method of the above system.

[0010] The technical problem to be solved by this invention is to make up for the lack of SSL hardware acceleration card management and algorithm adaptation in the prior art, overcome the defects of inconsistent caching, and provide a fast auxiliary technology, thereby providing a software-based foundation for security and authentication, improving the performance of applications and platforms, and providing measurable improvements.

[0011] Explanation of technical terms:

[0012] SSL: Secure Sockets Protocol.

[0013] OpenSSL: An open-source software package for the SSL protocol.

[0014] The detailed technical solution of this invention is as follows:

[0015] A fast auxiliary system for SSL hardware acceleration cards, characterized in that it includes: a service access module (A), an acceleration driver module (B), an operating system adaptation module (C), and an OpenSSL engine module (D).

[0016] The service access module (A) provides acceleration services for the application. Each service is provided by a service entity in this module. Although contained in a single logical module, each service is independent and distinct. Therefore, these services do not depend on each other, making parallel access of the application possible.

[0017] The acceleration driver module (B) provides a support framework that includes the services on which the service access module (A) depends, and also provides hardware-level interaction of the Platform, especially Platform registration and reset.

[0018] The operating system adaptation module (C) is used to access the operating system interface. The quick assistance technology supports deployment on various Linux or UNIX-like operating systems, thus providing an access layer to shield the differences between operating systems.

[0019] The OpenSSL engine module (D) is the engine module for OpenSSL (version 1.1.0 and above).

[0020] According to a preferred embodiment of the present invention, the service access module (A) is further configured to:

[0021] Events from the acceleration driver module (B), such as registration notifications, queries, and heartbeats;

[0022] Initialize the service according to the settings in the configuration file;

[0023] Initialize and model the logic accelerator instance according to the configuration;

[0024] Process the Fast Assist Technology API functions and encapsulate them into descriptors to pass to the SSL hardware acceleration card.

[0025] According to a preferred embodiment of the present invention, the service access module (A) depends on the services in the acceleration driver module (B), including:

[0026] Event: Service access module (A) relies on acceleration driver module (B) to provide event notification service. Service access module (A) obtains runtime key event notifications by registering events. Service access module (A) triggers initialization and shutdown operations through these events, while monitoring the running status of the SSL hardware acceleration card.

[0027] Discovery: The acceleration driver module (B) is responsible for discovering all Platform hardware devices to support different models of SSL hardware acceleration cards;

[0028] Circular queue control and access: The acceleration driver module (B) provides mechanisms for configuring the circular queue, including enabling interrupts on the circular queue. The acceleration driver module (B) abstracts the communication mechanism with the SSL hardware acceleration card.

[0029] According to a preferred embodiment of the present invention, the operating system adaptation module (C) is further configured to:

[0030] Independent of the specific operating system, it provides system calls: atomic operations and memory address mapping;

[0031] Provides a general-purpose cache-coherent memory library:

[0032] For mature CPU architectures such as x86, the operating system adaptation module (C) uses the DMA operation interface to provide cache coherency guarantees;

[0033] For emerging CPU architectures such as RISC-V, the compatibility of lower kernel versions is not high. The operating system adaptation module (C) uses the method of flushing the CacheLine to ensure cache consistency.

[0034] According to a preferred embodiment of the present invention, the OpenSSL engine module (D) is further used for:

[0035] Supports both synchronous and asynchronous encryption and decryption operations;

[0036] Asymmetric acceleration is supported, with RSA supporting key lengths of 1024 / 2048 / 4096; SM2 supporting key lengths of 1024 / 2048 / 4096; DSA supporting key lengths of 160 / 1024, 224 / 2048, 256 / 2048, 256 / 3072; and ECDH supporting the following curves: P-192 / P-224 / P-256 / P-384 / P-521.

[0037] Symmetric acceleration with pipelining capabilities, including SM4, AES128 / 256, DES / 3DES; SM3, MD5, SHA1, SHA256, SHA512; HMAC, CMAC; AES128 / 256-CBC-HMAC-SHA1 / SHA256, SM4-CBC-HMAC-SM3;

[0038] Pipelined operations;

[0039] The engine's soft algorithm switching function switches to the engine's soft algorithm when the service access module (A) detects that the SSL hardware accelerator card is unresponsive or unable to encrypt or decrypt normally. This provides continuity of encryption and decryption operations for the application during hardware reset. Once the SSL hardware accelerator card is back online, new requests can switch back to the SSL hardware accelerator card.

[0040] A method for operating the aforementioned rapid assistance system, characterized in that it includes: enabling the device;

[0041] The steps to enable the device are as follows:

[0042] Step 1: Load the acceleration driver module (B) and detect the SSL hardware acceleration card on the Platform bus: After discovering the device, query the physical address of the CSR (control register) of the symmetric / asymmetric acceleration unit of the SSL hardware acceleration card through the DTS (device tree) and map the physical address of the CSR (control register) to the acceleration driver module (B).

[0043] Step 2: Load the operating system adaptation module (C);

[0044] Step 3: Write the configuration file, which needs to specify: the number of symmetric / asymmetric acceleration units used, and whether to use polling or interrupt to access acceleration units;

[0045] Step 4: The service access module (A) sends a start command to the acceleration driver module (B);

[0046] Step 5: The acceleration driver module (B) parses the configuration file and checks its validity. If valid, it enables the corresponding SSL hardware acceleration card acceleration unit.

[0047] Step 6: Enable the SSL hardware acceleration card acceleration unit;

[0048] Step 7: The acceleration driver module (B) records the resource usage of the SSL hardware acceleration card acceleration unit and notifies the service access module (A) that the device is enabled.

[0049] A method for operating the aforementioned rapid assistance system, characterized in that it further includes: software enabling;

[0050] The software enablement includes:

[0051] Step 1: The application calls the OpenSSL engine module (D) to enable the software;

[0052] Step 2: The OpenSSL engine module (D) calls the service access module (A) to instantiate the service;

[0053] Step 3: Service access module (A) instantiates the service, including:

[0054] (1) The control register of the SSL hardware acceleration card acceleration unit is mapped from the acceleration driver module (B) to the service access module (A). Preferably, the mapping service uses UIO technology.

[0055] (2) The service access module (A) allocates cache-consistent memory from the operating system adaptation module (C) for the SSL hardware acceleration card acceleration unit;

[0056] Step 4: Initialize the available instances one by one;

[0057] Step 5: Notify the application layer software that it has been enabled.

[0058] A method for operating the aforementioned rapid assistance system, characterized in that it further includes the following acceleration step:

[0059] Step 1-Step 2: The OpenSSL engine module (D) initiates an encryption request;

[0060] Steps 3-4: The service access module (A) fills the descriptor with the encryption algorithm, key length, initialization vector, and plaintext, and puts it into the circular buffer; at this time, the hardware will detect a new encryption request and perform hardware encryption operation; the service access module (A) notifies the OpenSSL engine module (D) of the status.

[0061] Step 5: The OpenSSL engine module (D) notifies the application of the status;

[0062] Steps 6-7: The application obtains the descriptor from the OpenSSL engine module (D);

[0063] Steps 8-9: The OpenSSL engine module (D) polls to receive encrypted data. If the SSL hardware acceleration card puts the encrypted data into the circular buffer, it notifies the application through the descriptor.

[0064] Steps 10-12: The application obtains the encrypted ciphertext from the OpenSSL engine module (D).

[0065] The technical advantages of this invention are:

[0066] 1) This invention provides a resource management mechanism that controls and separates the hardware acceleration units occupied by a process (or a group of processes) through configuration files, thereby satisfying the computing power required by a single process and providing dynamic allocation of resources.

[0067] 2) Based on zero-copy, an address translation module is used to ensure cache consistency, that is, the memory data accessed by user space, kernel space and hardware acceleration card at the same time are consistent.

[0068] 3) Supports hardware acceleration for international algorithms and SM2-SM3-SM4 national cryptographic algorithms.

[0069] 4) Adapts to various deployment methods including motherboard chipsets, PCIe, and SOC, and provides SR-IOV virtualization technology.

[0070] 5) Provides measurable performance improvements. This user-space fast assist technology has been proven to bypass kernel-space system call overhead, achieving computing power comparable to bare metal, and is suitable for various types of accelerators. Attached Figure Description

[0071] Figure 1 This is a schematic diagram of the module described in this invention;

[0072] Figure 2 This is a schematic diagram of the OpenSSL engine module described in this invention;

[0073] Figure 3 This is a schematic diagram of the device enabling function of the present invention;

[0074] Figure 4 This is a schematic diagram of the software enable function of the present invention;

[0075] Figure 5 This is a schematic diagram of the acceleration of the present invention. Detailed Implementation

[0076] The present invention will now be described in detail with reference to the embodiments and accompanying drawings, but is not limited thereto.

[0077] Example 1

[0078] like Figure 1 , 2 As shown.

[0079] A fast auxiliary system for SSL hardware acceleration cards includes: a service access module (A), an acceleration driver module (B), an operating system adaptation module (C), and an OpenSSL engine module (D).

[0080] The service access module (A) provides acceleration services for the application, and each service is provided by a service entity in this module;

[0081] The acceleration driver module (B) includes the services that the service access module (A) depends on, and also provides hardware-level interaction of the Platform, especially Platform registration and reset.

[0082] The operating system adaptation module (C) is used to provide an access layer to shield the differences between operating systems;

[0083] The OpenSSL engine module (D) is the engine module for OpenSSL (version 1.1.0 and above).

[0084] The service access module (A) is also used for:

[0085] Events from the acceleration driver module (B), such as registration notifications, queries, and heartbeats;

[0086] Initialize the service according to the settings in the configuration file;

[0087] Initialize and model the logic accelerator instance according to the configuration;

[0088] Process the Fast Assist Technology API functions and encapsulate them into descriptors to pass to the SSL hardware acceleration card.

[0089] The service access module (A) depends on the services in the acceleration driver module (B), including:

[0090] Event: Service access module (A) relies on acceleration driver module (B) to provide event notification service. Service access module (A) obtains runtime key event notifications by registering events. Service access module (A) triggers initialization and shutdown operations through these events, while monitoring the running status of the SSL hardware acceleration card.

[0091] Discovery: The acceleration driver module (B) is responsible for discovering all Platform hardware devices to support different models of SSL hardware acceleration cards;

[0092] Circular queue control and access: The acceleration driver module (B) provides mechanisms for configuring the circular queue, including enabling interrupts on the circular queue. The acceleration driver module (B) abstracts the communication mechanism with the SSL hardware acceleration card.

[0093] The operating system adaptation module (C) is also used for:

[0094] Independent of the specific operating system, it provides system calls: atomic operations and memory address mapping;

[0095] Provides a general-purpose cache-coherent memory library:

[0096] For mature CPU architectures such as x86, the operating system adaptation module (C) uses the DMA operation interface to provide cache coherency guarantees;

[0097] For emerging CPU architectures such as RISC-V, the compatibility of lower kernel versions is not high. The operating system adaptation module (C) uses the method of flushing the CacheLine to ensure cache consistency.

[0098] The OpenSSL engine module (D) is also used for:

[0099] Supports both synchronous and asynchronous encryption and decryption operations;

[0100] Asymmetric acceleration is supported, with RSA supporting key lengths of 1024 / 2048 / 4096; SM2 supporting key lengths of 1024 / 2048 / 4096; DSA supporting key lengths of 160 / 1024, 224 / 2048, 256 / 2048, 256 / 3072; and ECDH supporting the following curves: P-192 / P-224 / P-256 / P-384 / P-521.

[0101] Symmetric acceleration with pipelining capabilities, including SM4, AES128 / 256, DES / 3DES; SM3, MD5, SHA1, SHA256, SHA512; HMAC, CMAC; AES128 / 256-CBC-HMAC-SHA1 / SHA256, SM4-CBC-HMAC-SM3;

[0102] Pipelined operations;

[0103] The engine's soft algorithm switching function switches to the engine's soft algorithm when the service access module (A) detects that the SSL hardware accelerator card is unresponsive or unable to encrypt or decrypt normally. This provides continuity of encryption and decryption operations for the application during hardware reset. Once the SSL hardware accelerator card is back online, new requests can switch back to the SSL hardware accelerator card.

[0104] Example 2

[0105] like Figure 3 As shown, a method of operating the rapid assistance system as described in Embodiment 1 includes: device enabling;

[0106] The steps to enable the device are as follows:

[0107] Step 1: Load the acceleration driver module (B) and detect the SSL hardware acceleration card on the Platform bus: After discovering the device, query the physical address of the CSR (control register) of the symmetric / asymmetric acceleration unit of the SSL hardware acceleration card through the DTS (device tree) and map the physical address of the CSR (control register) to the acceleration driver module (B).

[0108] Step 2: Load the operating system adaptation module (C);

[0109] Step 3: Write the configuration file, which needs to specify: the number of symmetric / asymmetric acceleration units used, and whether to use polling or interrupt to access acceleration units;

[0110] Step 4: The service access module (A) sends a start command to the acceleration driver module (B);

[0111] Step 5: The acceleration driver module (B) parses the configuration file and checks its validity. If valid, it enables the corresponding SSL hardware acceleration card acceleration unit.

[0112] Step 6: Enable the SSL hardware acceleration card acceleration unit;

[0113] Step 7: The acceleration driver module (B) records the resource usage of the SSL hardware acceleration card acceleration unit and notifies the service access module (A) that the device is enabled.

[0114] Example 3

[0115] like Figure 4 As shown, a method for operating the rapid assistance system as described in Embodiment 2 further includes: software enabling;

[0116] The software enablement includes:

[0117] After the device is enabled, enabling software is required to abstract the SSL hardware acceleration card acceleration unit into a software service instance, taking OpenSSL as an example.

[0118] Step 1: The application calls the OpenSSL engine module (D) to enable the software;

[0119] Step 2: The OpenSSL engine module (D) calls the service access module (A) to instantiate the service;

[0120] Step 3: Service access module (A) instantiates the service, including:

[0121] (1) The control register of the SSL hardware acceleration card acceleration unit is mapped from the acceleration driver module (B) to the service access module (A). Preferably, the mapping service uses UIO technology.

[0122] (2) The service access module (A) allocates cache-consistent memory from the operating system adaptation module (C) for the SSL hardware acceleration card acceleration unit;

[0123] Steps 4-7: Initialize the available instances sequentially;

[0124] Step 8: Notify the application layer software that it has been enabled.

[0125] Example 4

[0126] like Figure 5 As shown, a method for operating the rapid assistance system as described in Embodiment 2 further includes the following acceleration steps:

[0127] Once enabled, it can provide accelerated encryption and decryption services for applications, taking encryption, asynchronous mode, and polling to receive responses as examples;

[0128] Step 1-Step 2: The OpenSSL engine module (D) initiates an encryption request;

[0129] Steps 3-4: The service access module (A) fills the descriptor with the encryption algorithm, key length, initialization vector, and plaintext, and puts it into the circular buffer; at this time, the hardware will detect a new encryption request and perform hardware encryption operation; the service access module (A) notifies the OpenSSL engine module (D) of the status.

[0130] Step 5: The OpenSSL engine module (D) notifies the application of the status;

[0131] Steps 6-7: The application obtains the descriptor from the OpenSSL engine module (D);

[0132] Steps 8-9: The OpenSSL engine module (D) polls to receive encrypted data. If the SSL hardware acceleration card puts the encrypted data into the circular buffer, it notifies the application through the descriptor.

[0133] Steps 10-12: The application obtains the encrypted ciphertext from the OpenSSL engine module (D).

Claims

1. A fast assistance system for SSL hardware acceleration cards, characterized in that, include: Service access module, acceleration driver module, operating system adaptation module, and OpenSSL engine module; The service access module provides acceleration services for the application, and each service is provided by a service entity in this module; The acceleration driver module includes the services that the service access module depends on, and also provides hardware-level interaction with the Platform, especially Platform registration and reset. The operating system adaptation module is used to provide an access layer to shield the differences between operating systems; The operating system adaptation module is also used for: Independent of the specific operating system, it provides system calls: atomic operations and memory address mapping; Provides a general-purpose cache-coherent memory library: For CPU architecture, the operating system adaptation module uses the DMA operation interface to provide cache consistency guarantees; For CPU architecture, the operating system adaptation module uses the method of flushing the CacheLine to ensure cache consistency; The OpenSSL engine module is also used for: Supports both synchronous and asynchronous encryption and decryption operations; Asymmetric acceleration is supported, with RSA supporting key lengths of 1024 / 2048 / 4096; SM2 supporting key lengths of 1024 / 2048 / 4096; DSA supporting key lengths of 160 / 1024, 224 / 2048, 256 / 2048, 256 / 3072; and ECDH supporting the following curves: P-192 / P-224 / P-256 / P-384 / P-521. Symmetric acceleration with pipelining capabilities, including SM4, AES128 / 256, DES / 3DES; SM3, MD5, SHA1, SHA256, SHA512; HMAC, CMAC; AES128 / 256-CBC-HMAC-SHA1 / SHA256, SM4-CBC-HMAC-SM3; Pipelined operations; The engine's soft algorithm switching function switches to the engine's soft algorithm when the service access module detects that the SSL hardware acceleration card is unresponsive or cannot encrypt or decrypt normally, so as to provide continuity of encryption and decryption operations for the application during hardware reset; once the SSL hardware acceleration card is back online, new requests will switch back to the SSL hardware acceleration card.

2. The fast assistance system for an SSL hardware acceleration card according to claim 1, characterized in that, The service access module is also used for: Registration notifications, queries, and heartbeats are events originating from the acceleration driver module; Initialize the service according to the settings in the configuration file; Initialize and model the logic accelerator instance according to the configuration; Process the Fast Assist Technology API functions and encapsulate them into descriptors to pass to the SSL hardware acceleration card.

3. The fast assistance system for an SSL hardware acceleration card according to claim 1, characterized in that, The service access module depends on services in the acceleration driver module, including: Event: The service access module relies on the acceleration driver module to provide event notification services. The service access module obtains runtime key event notifications by registering events. The service access module triggers initialization and shutdown operations through these events, and at the same time monitors the running status of the SSL hardware acceleration card. Discovery: The acceleration driver module is responsible for discovering all Platform hardware devices to support different models of SSL hardware acceleration cards; Control and access to the circular queue: The acceleration driver module provides a mechanism for configuring the circular queue, including enabling interrupts on the circular queue.

4. A method of operating the rapid assistance system as described in any one of claims 1-3, characterized in that, Includes: device enable; The steps to enable the device are as follows: Step 1-1: Load the acceleration driver module and detect the SSL hardware acceleration card on the Platform bus: After discovering the device, query the physical address of the CSR control register of the symmetric / asymmetric acceleration unit of the SSL hardware acceleration card through the DTS device tree, and map the physical address of the CSR control register to the acceleration driver module. Steps 1-2: Load the operating system adaptation module; Steps 1-3: Write the configuration file, which needs to specify: the number of symmetric / asymmetric acceleration units used, and whether to use polling or interrupt to access acceleration units; Steps 1-4: The service access module sends a start command to the acceleration driver module; Steps 1-5: The acceleration driver module parses the configuration file and checks its validity. If valid, the corresponding SSL hardware acceleration card acceleration unit is enabled. Steps 1-6: Enable the SSL hardware acceleration card acceleration unit; Steps 1-7: The acceleration driver module (B) records the resource usage of the SSL hardware acceleration card acceleration unit and notifies the service access module that the device has been enabled.

5. A method of operating the rapid assistance system as described in claim 4, characterized in that, Also includes: Software enablement; The software enablement includes: Step 2-1: The application calls the OpenSSL engine module to enable the software; Step 2-2: The OpenSSL engine module calls the service access module to instantiate the service; Steps 2-3: Instantiate the service in the service access module, including: (1) The control register of the SSL hardware acceleration card acceleration unit is mapped from the acceleration driver module to the service access module, and the mapping service uses UIO technology; (2) The service access module allocates cache-consistent memory from the operating system adaptation module for the SSL hardware acceleration card acceleration unit; Steps 2-4: Initialize the available instances sequentially; Steps 2-5: Notify the application layer software that it has been enabled.

6. A method of operating the rapid assistance system as described in claim 5, characterized in that, Also includes: The acceleration steps are as follows: Step 3-1 - Step 3-2: The OpenSSL engine module initiates an encryption request; Step 3-3-Step 3-4: The service access module fills the descriptor with the encryption algorithm, key length, initialization vector, and plaintext, and puts it into the circular buffer; at this time, the hardware will detect a new encryption request and perform hardware encryption operation; the service access module will notify the OpenSSL engine module of the status. Steps 3-5: The OpenSSL engine module notifies the application of the status; Steps 3-6 to 3-7: The application obtains the descriptor from the OpenSSL engine module; Steps 3-8 to 3-9: The OpenSSL engine module polls to receive encrypted data. If the SSL hardware acceleration card puts the encrypted data into the circular buffer, it notifies the application through the descriptor. Steps 3-10 to 3-12: The application retrieves the encrypted ciphertext from the OpenSSL engine module.

Citation Information

Patent Citations

  • Device and method both for accelerating SSL (Security Socket Layer) data processing speed

    CN104732164A

  • Method for uninstalling SSL / TLS protocol by using pipeline hardware design

    CN107634950A

  • Distributed SSL processing

    US20070074282A1