IPSec message forwarding method and device based on multi-core processor
By grouping multiple CPU processors in Linux system and using packet cache queues and inter-core interrupt mechanisms, the problem of lock competition among multi-core processors in the IPSec protocol stack is solved, and the forwarding performance of IPSec packets is improved.
Patent Information
- Application Number
- CN202211713001.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-29
AI Technical Summary
Multi-core processors frequently compete for locks in the IPSec protocol stack, affecting the forwarding performance of IPSec packets.
By initializing multiple CPU packets in the Linux system, they are used for packet collection and encryption and decryption processing respectively, and balance CPU processing speed through packet cache queue and inter-core interrupt mechanism to reduce lock competition.
It effectively reduces the frequency of lock competition between multi-core processors and improves the forwarding performance of IPSec packets.
Smart Images

Figure CN115967751B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network protocol security technology, and in particular to an IPsec message forwarding method and device based on a multi-core processor. Background Art
[0002] As a network transmission protocol that encrypts and authenticates data at the IP layer, the Internet Protocol Security (IPSec) plays an increasingly important role in network security technology. With the emergence of diverse application scenarios and the increase in network data throughput, the efficiency of IPSec message encryption and decryption has become a major factor limiting IPSec message forwarding performance.
[0003] With the development of multi-core processors, especially the increasingly mature support for multi-core processors in the Linux kernel, multiple cores in the Linux system can process data packet encryption and decryption in parallel. Different CPU processors receive data packets from the physical network interface card (NIC) and then process them in the Linux system's IPSec protocol stack. For packets requiring decryption, the CPU processor sends the packet to the IPSec protocol stack for decryption based on the packet's protocol number. After decryption is complete, the CPU processor sends the packet to the physical NIC for transmission. For packets requiring encryption, the CPU processor sends the packet to the IPSec protocol stack for encryption. After encryption is complete, the CPU processor sends the packet to the physical NIC for transmission. Each CPU processor performs processing in parallel.
[0004] Related technologies improve the processing efficiency of IPSec messages through parallel processing by multi-core processors, but this processing method will have the problem of concurrency competition. The encryption and decryption of each data packet in the IPSec protocol stack require querying the Security Association (SA) and policy. SA and policy are public resources that need to be locked when accessed by multi-core processors to avoid concurrency problems. As a result, the problem of lock competition between multi-core processors in the IPSec protocol stack frequently occurs, affecting the forwarding performance of IPSec messages. Summary of the Invention
[0005] In view of this, the embodiments of the present disclosure provide an IPsec message forwarding method and device based on a multi-core processor, which can reasonably allocate multi-core processor resources, reduce the frequency of multi-core processor competition for locks in the IPSec protocol stack, and improve the forwarding performance of IPsec messages.
[0006] In a first aspect, an embodiment of the present disclosure provides an IPSec message forwarding method based on a multi-core processor, which adopts the following technical solutions:
[0007] During the loading process of the IPSec protocol stack of the Linux system, a plurality of first data packet cache queues corresponding to a plurality of first CPU processors in the first CPU group are initialized, and a plurality of second data packet cache queues corresponding to a plurality of second CPU processors in the second CPU group are initialized;
[0008] Loading a network card driver, and shielding the packet receiving network card interrupt of the second CPU group in the network card driver;
[0009] Receiving a first data packet through the plurality of first CPU processors, and sending the first data packet to the plurality of first data packet cache queues for performing encryption and decryption operations at the entrance of the IPSec protocol stack, and notifying the plurality of second CPU processors through an inter-core interrupt;
[0010] Traversing the plurality of second data packet cache queues corresponding to the plurality of second CPU processors respectively, and processing the second data packets in the second data packet cache queues respectively in the soft interrupt processing functions of the plurality of second CPU processors;
[0011] The second data packet is sent to the IPSec protocol stack for encryption and decryption operations to obtain an encrypted and decrypted data packet, and the encrypted and decrypted data packet is sent by calling the interface of the network card driver.
[0012] In some embodiments, the method further comprises:
[0013] Creating linked list headers for the plurality of first data packet cache queues and the plurality of second data packet cache queues respectively, wherein the linked list headers include an encryption linked list header and a decryption linked list header;
[0014] Dynamically configuring maximum lengths of the plurality of first data packet cache queues and the plurality of second data packet cache queues;
[0015] Queue heads are allocated to the plurality of first data packet cache queues and the plurality of second data packet cache queues according to the linked list heads, wherein the queue heads include type information of a sending end CPU processor, a receiving end CPU processor and a linked list head.
[0016] In some embodiments, receiving a first data packet by the plurality of first CPU processors, sending the first data packet to the plurality of first data packet cache queues for performing encryption and decryption operations at the entry of the IPSec protocol stack, and notifying the plurality of second CPU processors by means of an inter-core interruption includes:
[0017] When the first data packets received by the plurality of first CPU processors are data packets to be encrypted and the length of the first data packet cache queue has not reached a maximum length, sending the data packets to be encrypted to the corresponding first data packet cache queue for performing encryption operations according to the queue head;
[0018] The plurality of second CPU processors serving as receiving-end CPU processors are notified to receive the encrypted first data packet through an inter-core interrupt.
[0019] In some embodiments, the method further comprises:
[0020] When the first data packets received by the plurality of first CPU processors are data packets to be decrypted and the length of the first data packet cache queue has not reached a maximum length, sending the data packets to be decrypted to the corresponding first data packet cache queue for performing a decryption operation according to the queue head;
[0021] The plurality of second CPUs serving as receiving-end CPU processors are notified by way of an inter-core interrupt to process and receive the decrypted first data packet.
[0022] The step of respectively traversing the plurality of second data packet cache queues corresponding to the plurality of second CPU processors and respectively processing the second data packets in the second data packet cache queues in the soft interrupt processing functions of the plurality of second CPU processors includes:
[0023] Traversing the second data packet cache queue for performing encryption operations in the soft interrupt processing functions of the plurality of second CPU processors;
[0024] Sending the second data packets to be encrypted in the second data packet cache queue to the IPSec protocol stack in sequence for encryption processing;
[0025] Traversing the second data packet cache queue for performing decryption operations in the soft interrupt processing functions of the plurality of second CPU processors;
[0026] The second data packets to be decrypted in the second data packet cache queue are sequentially sent to the IPSec protocol stack for decryption processing.
[0027] In a second aspect, the embodiments of the present disclosure further provide an IPSec message forwarding device based on a multi-core processor, which adopts the following technical solutions:
[0028] an initialization unit configured to initialize, during a loading process of an IPSec protocol stack of a Linux system, a plurality of first data packet cache queues corresponding to a plurality of first CPU processors in a first CPU group, and to initialize a plurality of second data packet cache queues corresponding to a plurality of second CPU processors in a second CPU group;
[0029] a network card interrupt shielding unit, configured to load a network card driver and shield the packet receiving network card interrupt of the second CPU group in the network card driver;
[0030] a sending unit configured to receive the first data packet through the plurality of first CPU processors, and send the first data packet to the plurality of first data packet cache queues performing encryption and decryption operations at the ingress of the IPSec protocol stack, and notify the plurality of second CPU processors through an inter-core interrupt;
[0031] a traversal unit configured to traverse the plurality of second data packet cache queues corresponding to the plurality of second CPU processors respectively, and process the second data packets in the second data packet cache queues respectively in the soft interrupt processing functions of the plurality of second CPU processors;
[0032] The encryption and decryption unit is configured to send the second data packet to the IPSec protocol stack for encryption and decryption operations to obtain an encrypted and decrypted data packet, and send the encrypted and decrypted data packet by calling the interface of the network card driver.
[0033] In some embodiments, the apparatus further comprises:
[0034] a creating unit, configured to create linked list headers for the plurality of first data packet cache queues and the plurality of second data packet cache queues respectively, wherein the linked list headers include an encryption linked list header and a decryption linked list header;
[0035] a setting unit, configured to dynamically configure maximum lengths of the plurality of first data packet cache queues and the plurality of second data packet cache queues;
[0036] The allocating unit is configured to allocate queue heads to the plurality of first data packet cache queues and the plurality of second data packet cache queues according to the linked list heads, wherein the queue heads include type information of a sending end CPU processor, a receiving end CPU processor and a linked list head.
[0037] In some embodiments, the sending unit includes:
[0038] a sending module configured to, when the first data packets received by the plurality of first CPU processors are data packets to be encrypted and the length of the first data packet cache queue has not reached a maximum length, send the data packets to be encrypted to the corresponding first data packet cache queue for performing encryption operations according to the queue head;
[0039] The notification module is configured to notify the plurality of second CPU processors serving as receiving-end CPU processors to receive the encrypted first data packet through an inter-core interruption.
[0040] In a third aspect, the present disclosure also provides an electronic device that employs the following technical solution:
[0041] The electronic device comprises:
[0042] at least one processor; and,
[0043] a memory communicatively connected to the at least one processor; wherein,
[0044] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any of the above-mentioned IPSec message forwarding methods based on a multi-core processor.
[0045] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute any of the above-mentioned IPSec message forwarding methods based on a multi-core processor.
[0046] An embodiment of the present disclosure provides an IPsec message forwarding method and device based on a multi-core processor. In the initialization phase of a Linux system, the CPU processors are grouped according to the number of CPU processors in the Linux system, for example, into a first CPU group and a second CPU group. The second CPU group is used to run the IPSec protocol stack to process encrypted and decrypted data packets and send packets, and the first CPU group is used to receive packets. The first CPU group and the second CPU group balance the processing speed between the two groups of CPUs through the encryption and decryption cache queues of several data packets. By reasonably allocating the resources of the multi-core CPU processors, the frequency of contention locks caused by the multi-core processors running the IPSec protocol stack at the same time is reduced, thereby improving the forwarding performance of IPSec messages.
[0047] The above description is only an overview of the technical solution of the present disclosure. In order to more clearly understand the technical means of the present disclosure, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present disclosure more obvious and easy to understand, the following specifically cites preferred embodiments and describes them in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0049] Figure 1 A flowchart of a multi-core processor-based IPSec message forwarding method provided in an embodiment of the present disclosure;
[0050] Figure 2 A schematic diagram of the structure of an IPSec message forwarding device based on a multi-core processor provided in an embodiment of the present disclosure;
[0051] Figure 3 A schematic diagram of the structure of another multi-core processor-based IPSec message forwarding device provided in an embodiment of the present disclosure;
[0052] Figure 4 A block diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0053] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.
[0054] It should be clear that the following embodiments of the present disclosure are described through specific concrete examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other in the absence of conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present disclosure.
[0055] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this disclosure, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this device and / or practice this method.
[0056] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present disclosure. The illustrations only show components related to the present disclosure and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.
[0057] Additionally, in the following description, specific details are provided to provide a thorough understanding of the examples. However, one skilled in the art will appreciate that the aspects described can be practiced without these specific details.
[0058] like Figure 1 As shown, the embodiment of the present disclosure provides an IPSec message forwarding method based on a multi-core processor, which can be applied to VPN (Virtual Private Network) products using the IPSec protocol under a multi-core processor based on a Linux system. The multi-core processor can be dual-core, hexa-core, octa-core, etc. The method includes the following steps:
[0059] S101. During the loading process of the IPSec protocol stack of the Linux system, initialize several first data packet cache queues corresponding to several first CPU processors in a first CPU group, and initialize several second data packet cache queues corresponding to several second CPU processors in a second CPU group.
[0060] Optionally, four CPU processors, namely CPU0, CPU1, CPU2 and CPU3, run in parallel in the Linux system of an embodiment of the present disclosure, wherein the several first CPU processors included in the first CPU group are CPU0 and CPU2, and the several second CPU processors included in the second CPU group are CPU1 and CPU3.
[0061] S102: Load the network card driver, and shield the network card interruption of the second CPU packet receiving in the network card driver.
[0062] Optionally, in the disclosed embodiment, the network card driver blocks the network card interrupts of several second CPU processors (CPU1 and CPU3) in the second CPU group. CPU1 and CPU3 do not participate in packet reception and are only responsible for encrypting and decrypting data packets and sending data packets. CPU1 and CPU3 are allowed to independently run the IPSec protocol stack, reducing the frequency of lock contention caused by four CPU processors running the IPSec protocol stack simultaneously.
[0063] S103: Receive the first data packet through several first CPU processors, and send the first data packet to several first data packet cache queues that perform encryption and decryption operations at the entrance of the IPSec protocol stack, and notify several second CPU processors through inter-core interruption.
[0064] S104 , traverse a plurality of second data packet cache queues corresponding to a plurality of second CPU processors respectively, and process the second data packets in the second data packet cache queues respectively in the soft interrupt processing functions of the plurality of second CPU processors.
[0065] Optionally, several second CPU processors (CPU1 and CPU3) traverse their respective second data packet cache queues, and send the second data packets in their respective second data packet cache queues to the IPSec protocol stack for encryption and decryption processing.
[0066] S105: Send the second data packet to the IPSec protocol stack for encryption and decryption operations to obtain an encrypted and decrypted data packet, and send the encrypted and decrypted data packet by calling the interface of the network card driver.
[0067] The disclosed embodiment groups the CPU processors according to the number of CPU processors in the Linux system during the initialization phase of the Linux system, for example, into a first CPU group and a second CPU group. The second CPU group is used to run the IPSec protocol stack to process encrypted and decrypted data packets and send packets, while the first CPU group is used to receive packets. The first and second CPU groups balance the processing speeds between the two groups of CPUs by caching a number of data packets for encryption and decryption. This reduces the original situation where all CPU processors compete for the IPSec protocol stack lock to only half of the CPU processors competing for the IPSec protocol stack lock. By rationally allocating the resources of multi-core CPU processors, the frequency of lock contention caused by the simultaneous operation of the IPSec protocol stack by multiple core processors is greatly reduced, performance loss is reduced, and the forwarding performance of IPSec messages is improved.
[0068] Optionally, in the embodiment of the present disclosure, a plurality of first CPU processors (CPU0 and CPU2) receive the first data packet and send the first data packet to the first data packet cache queue of each of CPU0 and CPU2.
[0069] In some embodiments, the method further comprises:
[0070] Creating linked list headers for the plurality of first data packet cache queues and the plurality of second data packet cache queues respectively, wherein the linked list headers include an encryption linked list header and a decryption linked list header;
[0071] Dynamically configure the maximum lengths of a plurality of first data packet cache queues and a plurality of second data packet cache queues;
[0072] Queue heads are allocated to a plurality of first data packet cache queues and a plurality of second data packet cache queues according to the linked list heads, wherein the queue heads include type information of a sending end CPU processor, a receiving end CPU processor and the linked list heads.
[0073] Optionally, the embodiment of the present disclosure creates a linked list header for each of the first data packet cache queues of CPU0 and CPU2, and creates a linked list header for each of the second data packet cache queues of CPU1 and CPU3. For example, an encryption linked list header is created for CPU0 as the sending CPU processor and CPU1 as the receiving CPU processor; a decryption linked list header is created for CPU0 as the sending CPU processor and CPU1 as the receiving CPU processor; an encryption linked list header is created for CPU2 as the sending CPU processor and CPU3 as the receiving CPU processor; and a decryption linked list header is created for CPU2 as the sending CPU processor and CPU3 as the receiving CPU processor.
[0074] The maximum lengths of the first packet buffer queue of CPU 0, the second packet buffer queue of CPU 1, the first packet buffer queue of CPU 2, and the second packet buffer queue of CPU 3 can be dynamically configured by the Linux system based on actual user needs. Queue heads are assigned to the first packet buffer queue of CPU 0, the second packet buffer queue of CPU 1, the first packet buffer queue of CPU 2, and the second packet buffer queue of CPU 3, respectively.
[0075] Among them, the queue head is E_cup0->cpu1, indicating that CPU0 sends the IPSec message to be encrypted to the first data packet cache queue, and notifies CPU1 to receive the encrypted first data packet through the inter-core interrupt; the queue head is D_cpu0->cpu1, indicating that CPU0 sends the IPSec message to be decrypted to the first data packet cache queue, and notifies CPU1 to receive the decrypted first data packet through the inter-core interrupt; the queue head is E_cpu2->cpu3, indicating that CPU2 sends the IPSec message to be encrypted to the first data packet cache queue, and notifies CPU3 to receive the encrypted first data packet through the inter-core interrupt; the queue head is D_cup2->cpu3, indicating that CPU2 sends the IPSec message to be decrypted to the first data packet cache queue, and notifies CPU3 to receive the decrypted first data packet through the inter-core interrupt.
[0076] In some embodiments, receiving a first data packet by a plurality of first CPU processors, sending the first data packet to a plurality of first data packet cache queues for performing encryption and decryption operations at the entrance of the IPSec protocol stack, and notifying a plurality of second CPU processors by means of an inter-core interrupt, includes:
[0077] When the first data packets received by the plurality of first CPU processors are data packets to be encrypted and the length of the first data packet cache queue has not reached the maximum length, the data packets to be encrypted are sent to the corresponding first data packet cache queue for performing encryption operations according to the queue head;
[0078] The plurality of second CPU processors serving as receiving-end CPU processors are notified to receive the encrypted first data packet through an inter-core interruption.
[0079] Optionally, when the first data packet received by CPU0 is a data packet to be encrypted, it is determined whether the first data packet cache queue of CPUO has reached the maximum length. If the first data packet cache queue of CPUO has reached the maximum length, the data packet to be encrypted received by CPU0 is discarded. If the first data packet cache queue of CPU0 has not reached the maximum length, the data packet to be encrypted received by CPU0 is sent to the first data packet cache queue with a queue head of E_cup0->cpu1 for encryption processing, and CPU1 is notified to receive the encrypted first data packet through an inter-core interrupt.
[0080] Optionally, when the first data packet received by CPU0 is a data packet to be decrypted, it is determined whether the first data packet cache queue of CPUO has reached the maximum length. If the first data packet cache queue of CPUO has reached the maximum length, the data packet to be decrypted received by CPU0 is discarded. If the first data packet cache queue of CPU0 has not reached the maximum length, the data packet to be decrypted received by CPU0 is sent to the first data packet cache queue with a queue head of D_cpu0->cpu1 for decryption processing, and CPU1 is notified to receive the decrypted first data packet through an inter-core interrupt.
[0081] In some embodiments, the method further comprises:
[0082] When the first data packets received by the plurality of first CPU processors are data packets to be decrypted and the length of the first data packet cache queue has not reached the maximum length, the data packets to be decrypted are sent to the corresponding first data packet cache queue for performing decryption operations according to the queue head;
[0083] The second CPU processor serving as the receiving end CPU processor is notified by way of an inter-core interrupt to receive the decrypted first data packet.
[0084] Optionally, when the first data packet received by CPU2 is a data packet to be encrypted, it is determined whether the first data packet cache queue of CPU2 has reached the maximum length. If the first data packet cache queue of CPU2 has reached the maximum length, the data packet to be encrypted received by CPU2 is discarded. If the first data packet cache queue of CPU2 has not reached the maximum length, the data packet to be encrypted received by CPU2 is sent to the first data packet cache queue with a queue head of E_cpu2->cpu3 for encryption processing, and CPU3 is notified to collect the encrypted first data packet through an inter-core interrupt.
[0085] Optionally, when the first data packet received by CPU2 is a data packet to be decrypted, it is determined whether the first data packet cache queue of CPU2 has reached the maximum length. If the first data packet cache queue of CPU2 has reached the maximum length, the data packet to be decrypted received by CPU2 is discarded. If the first data packet cache queue of CPU2 has not reached the maximum length, the data packet to be decrypted received by CPU2 is sent to the first data packet cache queue with the queue head being D_cup2->cpu3 for decryption processing, and CPU3 is notified to receive the decrypted first data packet through an inter-core interrupt.
[0086] In some embodiments, traversing a plurality of second data packet cache queues corresponding to a plurality of second CPU processors respectively and processing the second data packets in the second data packet cache queues respectively in the soft interrupt processing functions of the plurality of second CPU processors includes:
[0087] Traversing a second data packet buffer queue for performing encryption operations in a soft interrupt processing function of a plurality of second CPU processors;
[0088] Sending the second data packets to be encrypted in the second data packet buffer queue to the IPSec protocol stack in sequence for encryption processing;
[0089] Traversing the second data packet cache queue for performing the decryption operation in the soft interrupt processing functions of the plurality of second CPU processors;
[0090] The second data packets to be decrypted in the second data packet buffer queue are sequentially sent to the IPSec protocol stack for decryption processing.
[0091] Optionally, for CPU1, in the soft interrupt processing function of CPU1, the second data packet cache queue with the queue head being E_cup0->cpu1 (i.e., the first data packet cache queue with the queue head being E_cup0->cpu1 for CPU0) is first traversed, and the second data packets to be encrypted in the second data packet cache queue are taken out one by one, and the second data packets to be encrypted are sequentially sent to the IPSec protocol stack for encryption processing. After the encryption processing is completed, the encrypted second data packets are sent out by calling the interface of the network card driver. Secondly, in the soft interrupt processing function of CPU1, the second data packet cache queue with the queue head being D_cpu0->cpu1 (i.e., the first data packet cache queue with the queue head being D_cpu0->cpu1 for CPU0) is traversed, and the second data packets to be decrypted in the second data packet cache queue are taken out one by one, and the second data packets to be decrypted are sequentially sent to the IPSec protocol stack for decryption processing. After the decryption processing is completed, the decrypted second data packets are sent out by calling the interface of the network card driver.
[0092] Optionally, for CPU3, in the soft interrupt processing function of CPU3, the second data packet cache queue with the queue head being E_cup2->cpu3 (i.e., the first data packet cache queue with the queue head being E_cup2->cpu3 for CPU2) is first traversed, the second data packets to be encrypted in the second data packet cache queue are taken out one by one, and the second data packets to be encrypted are sequentially sent to the IPSec protocol stack for encryption processing. After the encryption processing is completed, the encrypted second data packets are sent out by calling the interface of the network card driver. Secondly, in the soft interrupt processing function of CPU3, the second data packet cache queue with the queue head being D_cpu2->cpu3 (i.e., the first data packet cache queue with the queue head being D_cpu2->cpu3 for CPU2) is traversed, the second data packets to be decrypted in the second data packet cache queue are taken out one by one, and the second data packets to be decrypted are sequentially sent to the IPSec protocol stack for decryption processing. After the decryption processing is completed, the decrypted second data packets are sent out by calling the interface of the network card driver.
[0093] like Figure 2 As shown, the embodiment of the present disclosure further provides an IPSec message forwarding device based on a multi-core processor, comprising:
[0094] The initialization unit 21 is configured to initialize a plurality of first data packet cache queues corresponding to a plurality of first CPU processors in the first CPU group, and initialize a plurality of second data packet cache queues corresponding to a plurality of second CPU processors in the second CPU group during the loading process of the IPSec protocol stack of the Linux system;
[0095] The network card interrupt shielding unit 22 is configured to load the network card driver and shield the packet receiving network card interrupt of the second CPU group in the network card driver;
[0096] The sending unit 23 is configured to receive the first data packet through the plurality of first CPU processors, and send the first data packet to the plurality of first data packet cache queues for performing encryption and decryption operations at the ingress of the IPSec protocol stack, and notify the plurality of second CPU processors through an inter-core interrupt;
[0097] The traversal unit 24 is configured to traverse the plurality of second data packet cache queues corresponding to the plurality of second CPU processors, and process the second data packets in the second data packet cache queues in the soft interrupt processing functions of the plurality of second CPU processors respectively;
[0098] The encryption and decryption unit 25 is configured to send the second data packet to the IPSec protocol stack for encryption and decryption operations to obtain an encrypted and decrypted data packet, and send the encrypted and decrypted data packet by calling the interface of the network card driver.
[0099] In some embodiments, the apparatus further comprises:
[0100] A creating unit is configured to create linked list headers for the plurality of first data packet cache queues and the plurality of second data packet cache queues respectively, wherein the linked list headers include an encryption linked list header and a decryption linked list header;
[0101] A setting unit configured to dynamically configure maximum lengths of a plurality of first data packet cache queues and a plurality of second data packet cache queues;
[0102] The allocating unit is configured to allocate queue heads to the plurality of first data packet cache queues and the plurality of second data packet cache queues according to the linked list heads, wherein the queue heads include type information of a sending end CPU processor, a receiving end CPU processor and the linked list head.
[0103] like Figure 3 As shown, in some embodiments, the sending unit 23 includes:
[0104] The sending module 231 is configured to send the first data packet to be encrypted to the corresponding first data packet cache queue for performing encryption operations according to the queue head when the first data packet received by the plurality of first CPU processors is a data packet to be encrypted and the length of the first data packet cache queue has not reached the maximum length;
[0105] The notification module 232 is configured to notify several second CPU processors serving as receiving-end CPU processors to receive the encrypted first data packet through an inter-core interrupt.
[0106] The data sending module 233 is configured to send the data packets to be decrypted to the corresponding first data packet cache queue for performing decryption operations according to the queue head when the first data packets received by the plurality of first CPU processors are data packets to be decrypted and the length of the first data packet cache queue has not reached the maximum length;
[0107] The data notification module 234 is configured to notify several second CPU processors serving as receiving-end CPU processors to receive the decrypted first data packet through an inter-core interrupt.
[0108] An electronic device according to an embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may, for example, include a read-only memory (ROM), a hard disk, a flash memory, etc.
[0109] The processor can be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and can control other components in the electronic device to perform desired functions. In one embodiment of the present disclosure, the processor is used to execute the computer-readable instructions stored in the memory, so that the electronic device executes all or part of the steps of the multi-core processor-based IPsec message forwarding method of each embodiment of the present disclosure.
[0110] Those skilled in the art should understand that in order to solve the technical problem of how to obtain a good user experience, this embodiment may also include well-known structures such as a communication bus and an interface, and these well-known structures should also be included in the scope of protection of this disclosure.
[0111] like Figure 4 The present invention provides a schematic diagram of the structure of an electronic device according to an embodiment of the present invention, which is suitable for implementing the electronic device according to an embodiment of the present invention. Figure 4 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0112] like Figure 4 As shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.
[0113] Typically, the following devices can be connected to the I / O interface: input devices such as sensors or visual information acquisition devices; output devices such as display screens; storage devices such as tapes and hard disks; and communication devices. The communication device allows the electronic device to communicate with other devices (such as edge computing devices) wirelessly or by wire to exchange data. Figure 4 The electronic device is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.
[0114] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, all or part of the steps of the multi-core processor-based IPsec message forwarding method of the embodiment of the present disclosure are executed.
[0115] For detailed description of this embodiment, please refer to the corresponding description in the aforementioned embodiments, which will not be repeated here.
[0116] According to an embodiment of the present disclosure, a computer-readable storage medium stores non-transitory computer-readable instructions. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the multi-core processor-based IPsec message forwarding method described in each embodiment of the present disclosure are performed.
[0117] The above-mentioned computer-readable storage media include, but are not limited to, optical storage media (e.g., CD-ROMs and DVDs), magneto-optical storage media (e.g., MOs), magnetic storage media (e.g., magnetic tapes or mobile hard disks), media with built-in rewritable non-volatile memory (e.g., memory cards), and media with built-in ROM (e.g., ROM cartridges).
[0118] For detailed description of this embodiment, please refer to the corresponding description in the aforementioned embodiments, which will not be repeated here.
[0119] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this disclosure are merely illustrative and not restrictive, and should not be construed as necessarily possessed by each embodiment of the present disclosure. Furthermore, the specific details disclosed above are provided for illustrative purposes and to facilitate understanding, rather than as limitations. These details do not limit the present disclosure to necessarily being implemented using these specific details.
[0120] In the present disclosure, relational terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. The block diagrams of the devices, devices, equipment, and systems involved in the present disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "including," "comprising," "having," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.
[0121] Additionally, as used herein, "or" used in a list of items beginning with "at least one" indicates a separate list, so that, for example, a list of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not mean that the example described is preferred or better than other examples.
[0122] It should also be noted that in the system and method of the present disclosure, each component or each step can be decomposed and / or recombined. Such decomposition and / or recombination should be regarded as equivalent solutions of the present disclosure.
[0123] Various changes, substitutions, and modifications may be made to the technology herein without departing from the teachings as defined by the appended claims. Moreover, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of things, means, methods, and actions described above. Currently existing or later developed processes, machines, manufactures, compositions of things, means, methods, or actions that perform substantially the same function or achieve substantially the same results as the corresponding aspects described herein may be utilized. Accordingly, the appended claims include within their scope such processes, machines, manufactures, compositions of things, means, methods, or actions.
[0124] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0125] The above description has been provided for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A method for forwarding IPSec messages based on a multi-core processor, characterized in that: include: During the loading process of the IPSec protocol stack of the Linux system, a plurality of first data packet cache queues corresponding to a plurality of first CPU processors in the first CPU group are initialized, and a plurality of second data packet cache queues corresponding to a plurality of second CPU processors in the second CPU group are initialized; Loading a network card driver, and shielding the packet receiving network card interruption of the second CPU group in the network card driver. When the packet receiving network card is interrupted, several second CPU processors in the second CPU group do not participate in packet receiving, but are only responsible for encrypting and decrypting data packets and sending data packets. The second CPU processors independently run the IPSec protocol stack; Receiving the first data packet through the plurality of first CPU processors, and sending the first data packet to the plurality of first data packet cache queues for performing encryption and decryption operations at the entrance of the IPSec protocol stack, and notifying the plurality of second CPU processors through an inter-core interrupt; Traversing the plurality of second data packet cache queues corresponding to the plurality of second CPU processors respectively, and processing the second data packets in the second data packet cache queues respectively in the soft interrupt processing functions of the plurality of second CPU processors; The second data packet is sent to the IPSec protocol stack for encryption and decryption operations to obtain an encrypted and decrypted data packet, and the encrypted and decrypted data packet is sent by calling the interface of the network card driver.
2. The IPSec message forwarding method based on a multi-core processor according to claim 1, characterized in that: The method further comprises: Creating linked list headers for the plurality of first data packet cache queues and the plurality of second data packet cache queues respectively, wherein the linked list headers include an encryption linked list header and a decryption linked list header; Dynamically configure the maximum lengths of the plurality of first data packet cache queues and the plurality of second data packet cache queues; Queue heads are allocated to the plurality of first data packet cache queues and the plurality of second data packet cache queues according to the linked list heads, wherein the queue heads include type information of a sending end CPU processor, a receiving end CPU processor and a linked list head.
3. The IPSec message forwarding method based on a multi-core processor according to claim 2, characterized in that: Receiving the first data packet through the plurality of first CPU processors, and sending the first data packet to the plurality of first data packet cache queues for performing encryption and decryption operations at the entrance of the IPSec protocol stack, and notifying the plurality of second CPU processors through an inter-core interrupt, including: When the first data packets received by the plurality of first CPU processors are data packets to be encrypted, and the length of the first data packet cache queue has not reached a maximum length, sending the data packets to be encrypted to a corresponding first data packet cache queue for performing encryption operations according to the queue head; The plurality of second CPU processors serving as receiving-end CPU processors are notified to receive the encrypted first data packet by means of an inter-core interrupt.
4. The IPSec message forwarding method based on a multi-core processor according to claim 3 is characterized in that: The method further comprises: When the first data packets received by the plurality of first CPU processors are data packets to be decrypted and the length of the first data packet cache queue has not reached a maximum length, sending the data packets to be decrypted to a corresponding first data packet cache queue for performing a decryption operation according to the queue head; The plurality of second CPUs serving as receiving-end CPU processors are notified by way of an inter-core interrupt to process and receive the decrypted first data packet.
5. The IPSec message forwarding method based on a multi-core processor according to claim 1, characterized in that: The step of respectively traversing the plurality of second data packet cache queues corresponding to the plurality of second CPU processors and respectively processing the second data packets in the second data packet cache queues in the soft interrupt processing functions of the plurality of second CPU processors includes: Traversing the second data packet cache queue for performing encryption operations in the soft interrupt processing functions of the plurality of second CPU processors; Sending the second data packets to be encrypted in the second data packet cache queue to the IPSec protocol stack in sequence for encryption processing; Traversing the second data packet cache queue for performing a decryption operation in the soft interrupt processing functions of the plurality of second CPU processors; The second data packets to be decrypted in the second data packet cache queue are sequentially sent to the IPSec protocol stack for decryption processing.
6. An IPSec message forwarding device based on a multi-core processor, characterized in that: include: an initialization unit, configured to initialize a plurality of first data packet cache queues corresponding to a plurality of first CPU processors in a first CPU group, and initialize a plurality of second data packet cache queues corresponding to a plurality of second CPU processors in a second CPU group during loading of an IPSec protocol stack of a Linux system; a network card interrupt shielding unit, configured to load a network card driver and shield the packet receiving network card interruption of the second CPU group in the network card driver; when the packet receiving network card is interrupted, several second CPU processors in the second CPU group do not participate in packet receiving, but are only responsible for encrypting and decrypting data packets and sending data packets, and the second CPU processors independently run the IPSec protocol stack; a sending unit configured to receive the first data packet through the plurality of first CPU processors, and respectively send the first data packet to the plurality of first data packet cache queues performing encryption and decryption operations at the entrance of the IPSec protocol stack, and notify the plurality of second CPU processors through an inter-core interrupt; A traversal unit is configured to traverse the plurality of second data packet cache queues corresponding to the plurality of second CPU processors respectively, and process the second data packets in the second data packet cache queues respectively in the soft interrupt processing functions of the plurality of second CPU processors; The encryption and decryption unit is configured to send the second data packet to the IPSec protocol stack for encryption and decryption operations to obtain an encrypted and decrypted data packet, and send the encrypted and decrypted data packet by calling the interface of the network card driver.
7. The IPSec message forwarding device based on a multi-core processor according to claim 6, characterized in that: The device also includes: A creating unit, configured to respectively create linked list headers for the plurality of first data packet cache queues and the plurality of second data packet cache queues, wherein the linked list headers include an encryption linked list header and a decryption linked list header; A setting unit, configured to dynamically configure the maximum lengths of the plurality of first data packet cache queues and the plurality of second data packet cache queues; The allocation unit is configured to allocate queue heads to the plurality of first data packet cache queues and the plurality of second data packet cache queues according to the linked list heads, wherein the queue heads include type information of a sending end CPU processor, a receiving end CPU processor and a linked list head.
8. The IPSec message forwarding device based on a multi-core processor according to claim 7, characterized in that: The sending unit comprises: a sending module, configured to send the to-be-encrypted data packet to a corresponding first data packet cache queue for performing encryption operations according to the queue head when the first data packet received by the plurality of first CPU processors is a to-be-encrypted data packet and the length of the first data packet cache queue has not reached a maximum length; The notification module is configured to notify the plurality of second CPU processors serving as receiving-end CPU processors to receive the encrypted first data packet through an inter-core interruption.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the IPSec message forwarding method based on a multi-core processor as described in any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the IPSec message forwarding method based on a multi-core processor as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Communication scheduling system and method among cores of isomerization multi-core processor
CN101354693A
Communication method, device and system among multiple processors and storage medium
CN111930676A