A USB encryption card supporting multi-user and multi-task and its implementation method

Through the combination of modular design and AI technology, the resource FPGA of the USB encryption card is divided into multiple vFPGAs, and parallel encryption and decryption processing of multiple users and multiple tasks is realized, solving the problem of inefficiency of single users and single tasks in the existing technology, and improving the speed and efficiency of encryption and decryption.

CN119249379BActive Publication Date: 2025-06-24SHANDONG HUAYI MICRO ELECTRONICS
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411783758.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-06-24
Estimated Expiration
2044-12-06

AI Technical Summary

Technical Problem

Existing USB encryption cards usually only support a single user, and cannot encrypt and decrypt the data of multiple users at the same time. The multi-tasking needs of a single user can only be calculated by issuing data in serial, which is inefficient.

Method used

A USB encryption card adopts a modular design, including a management core board, multiple resource core boards and bottom boards. The management core board includes a management CPU, data transfer FPGA, AI accelerated FPGA and memory. The resource core board includes a resource FPGA and peripheral circuit. By dividing the resource FPGA into multiple isolated reconfigurable areas, each area is configured as a vFPGA as required to configure the algorithm core, and parallel encryption and decryption processing of multiple users and multiple tasks is realized.

Benefits of technology

It realizes parallel processing of multiple encryption and decryption tasks for multiple users, improves the speed of encryption and decryption, supports multi-user multi-task parallel computing, and uses AI technology to monitor resource usage in real time, and dynamically adjust resource allocation and recycling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119249379B_ABST
    Figure CN119249379B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of information security, and more specifically, relates to a USB encryption card supporting multi-user and multi-task and an implementation method thereof. The method includes a USB encryption card supporting multi-user and multi-task, which adopts a modular design and includes a management core board, multiple resource core boards and a bottom board. The management core board includes a management CPU, a data transfer FPGA, an AI acceleration FPGA and a memory. The resource core board includes a resource FPGA and its peripheral circuits such as a clock and a power supply. The management CPU includes an AI-based resource scheduling module, a host computer communication module, an encryption card cooperation module, and an algorithm core configuration module. The present invention solves two problems of the USB encryption card. One is that it often only supports single-user and cannot perform encryption and decryption processing on the data of multiple users at the same time. The other is that for multiple encryption and decryption tasks of a single user, they are realized by the way of serially sending data, and multiple encryption and decryption tasks cannot be calculated simultaneously, resulting in low efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and more specifically, relates to a USB encryption card supporting multiple users and multiple tasks and an implementation method thereof. Background Art

[0002] A USB encryption card is a security device that adopts a standard USB interface and integrates encryption technology. It is widely used in fields such as government, military, finance, and e-commerce, providing basic cryptographic services such as data encryption and decryption, signature verification, and key exchange for these industries.

[0003] Chinese invention patent CN116707970A discloses a network data encryption card and a transmission method based on a hardware protocol. The sending end and the receiving end of data transmission are connected to a transmission channel through their respective network data encryption cards. The network data encryption card includes: a receiving module, a cryptographic algorithm module, and a sending module connected in sequence. The receiving module is used to receive data to be encrypted and decrypted and transmit it to the cryptographic algorithm module. The cryptographic algorithm module performs real-time encryption and decryption on the received data based on the embedded national cryptographic algorithm, and also embeds a homomorphic encryption algorithm to support arithmetic operations on ciphertexts of key data, and transmits it to the sending module. The sending module is used to output the encrypted and decrypted data.

[0004] Common USB encryption cards often process multiple tasks by forming a serial data stream of data from multiple tasks through a driver for encryption and decryption processing on the encryption card, which limits the speed of data encryption, especially affecting the efficiency when users process a large amount of data. USB encryption cards often only support single users and cannot encrypt and decrypt data of multiple users simultaneously. For the multi-task requirements of a single user, the common processing method is to solve it by serially sending data for calculation, and multiple tasks cannot be calculated simultaneously, resulting in low efficiency. Summary of the Invention

[0005] The present invention aims to overcome at least one defect of the above-mentioned prior art and provides a USB encryption card supporting multiple users and multiple tasks to solve the problem that USB encryption cards often only support single users and cannot encrypt and decrypt data of multiple users simultaneously. For the multi-task requirements of a single user, the common processing method is to solve it by serially sending data for encryption and decryption, and multiple tasks cannot be encrypted and decrypted simultaneously, resulting in low efficiency.

[0006] On the other hand, the present invention also provides an implementation method of a USB encryption card supporting multiple users and multiple tasks.

[0007] A USB encryption card supporting multiple users and multiple tasks adopts a modular design and includes a management core board, multiple resource core boards, and a bottom board;

[0008] The management core board includes a management CPU, a data transfer FPGA, an AI acceleration FPGA, and a memory;

[0009] The management CPU is responsible for encryption and decryption resource scheduling, communication with the host computer, interconnection with other encryption cards, and configuration of the resource FPGA;

[0010] The data transfer FPGA is responsible for packet identification and forwarding, including multiple USB user interfaces and one encryption card interconnection interface. The encryption card interconnection interface is used for interconnection of two encryption cards; a forwarding relationship table based on TCAM is included in the data transfer FPGA to record the forwarding direction of packets. Each time the AI-based resource scheduling module in the management CPU allocates or deletes resources, the forwarding relationship table needs to be added to or deleted from.

[0011] The AI acceleration FPGA is responsible for hardware acceleration of the AI algorithms in the management CPU;

[0012] The memory is responsible for storing the system files of the management CPU and the configuration files of the algorithm cores;

[0013] The resource core board includes a resource FPGA and peripheral circuits;

[0014] The resource FPGA is responsible for executing the encryption algorithms of the encryption card.

[0015] Further, the resource FPGA is divided into multiple mutually isolated reconfigurable regions. Each reconfigurable region is configured as a vFPGA with algorithm cores as needed to execute encryption algorithms, enabling a resource FPGA to provide the same or different encryption and decryption for multiple users and multiple tasks simultaneously; meanwhile, a resource transfer module is built in the resource FPGA to be responsible for the transfer between internal vFPGAs and the data transfer FPGA.

[0016] The resource FPGA has two configuration methods: if configuring the vFPGA, it is through the ICAP interface; if configuring the FPGA, it is through the selectmap interface.

[0017] Further, the management CPU includes an AI-based resource scheduling module, a host computer communication module, an encryption card cooperation module, and an algorithm core configuration module:

[0018] The AI-based resource scheduling module optimizes and manages resource scheduling problems under multiple users and multiple tasks through AI, including the allocation and recycling of encryption and decryption resources;

[0019] The host computer communication module realizes data intercommunication with the host computer. The message types of the data include the resource requests of users, the resource request responses of encryption cards, the data to be encrypted and decrypted by users, the encrypted and decrypted processing data of encryption cards, the resource recovery requests of encryption cards, and the resource recovery responses of users.

[0020] The encryption card cooperation module realizes the cooperation between two encryption cards, facilitating the expansion of the encryption and decryption resources of the encryption cards, enabling users to simultaneously call the encryption and decryption resources in two encryption cards.

[0021] The algorithm core configuration module configures the corresponding algorithm cores into the resource FPGA according to user requirements.

[0022] The present invention also includes a method for implementing a USB encryption card supporting multiple users and multiple tasks. The method includes:

[0023] S1. The user informs the encryption card of the resource requests used in this task through the host computer, and transmits them to the management CPU through the data transfer FPGA for parsing. The resource allocation result is obtained and uploaded to the host computer.

[0024] S2. If the resource allocation result shows that cooperative processing between encryption cards is required, then:

[0025] First, connect the two encryption cards through the encryption card interconnection interface and enter the cooperation mode. Among them, the encryption card connected to the host computer is automatically set as the main encryption card, and the other encryption card is the slave encryption card. The management CPU of the main encryption card performs unified resource scheduling.

[0026] Then, the user calls the main encryption card for encryption and decryption, and then calls the slave encryption card for encryption and decryption.

[0027] If the resource allocation result shows that cooperative processing between encryption cards is not required, the user directly calls the main encryption card for encryption and decryption.

[0028] S3. The host computer sends the encrypted and decrypted data to the corresponding task.

[0029] Further, the specific steps of S1 include:

[0030] S11. The user informs the encryption card of the resource requests used in this task through the host computer, and reaches the host computer communication module in the management CPU through the data transfer FPGA.

[0031] S12. The host computer communication module of the management CPU parses the resource requests of the user. Then, it sends the number of vFPGAs requested and the algorithm types configured for each vFPGA to the AI-based resource scheduling module.

[0032] S13. The resource scheduling module based on AI in the management CPU analyzes the current resource usage situation to obtain a resource allocation result. If there are available resources, it returns the information of the available encryption and decryption resources corresponding to the request to complete the resource allocation. If there are no available resources currently, it predicts a waiting time and notifies the user to apply for resources after a waiting time.

[0033] S14. The host computer communication module of the management CPU encapsulates the resource allocation result into a resource response request message and then sends it to the host computer via the data transfer FPGA. At the same time, the data transfer FPGA updates the corresponding relationship between the user and the algorithm resource location information to the forwarding relationship table.

[0034] S15. After the host computer receives the resource request response of the encryption card, if it shows that resources have been allocated, it starts encryption and decryption. If it shows that no resources have been allocated, it waits for a period of time and then applies again.

[0035] Further, connecting the two encryption cards through the encryption card interconnection interface and entering the cooperative mode specifically includes:

[0036] S21. Connect the two encryption cards through the encryption card interconnection interface, and the encryption card connected to the host computer is automatically set as the main encryption card.

[0037] S22. The encryption card cooperation module in the main encryption card management CPU sends a request message, which is forwarded through two layers of the data transfer FPGA of the main encryption card and the data transfer FPGA of the slave encryption card to reach the encryption card cooperation module in the slave encryption card management CPU.

[0038] S23. The encryption card cooperation module in the slave encryption card management CPU sends the information of available resources, which is forwarded through two layers of the data transfer FPGA of the slave encryption card and the data transfer FPGA of the main encryption card to reach the encryption card cooperation module in the main encryption card management CPU.

[0039] S24. The encryption card cooperation module in the main encryption card management CPU sends the resource information of the slave encryption card to the resource scheduling module based on AI for unified resource scheduling.

[0040] Further, the user's invocation of the main encryption card for encryption and decryption specifically includes:

[0041] S31. The user groups and sends the data to be encrypted and decrypted in the task and the allocated algorithm resource information to the main encryption card through the host computer.

[0042] S32. The data transfer FPGA in the main encryption card forwards the message to the corresponding resource FPGA according to the information recorded in the forwarding relationship table.

[0043] S33. The data transfer module of the resource FPGA forwards the message to the corresponding vFPGA according to the algorithm resource information;

[0044] S34. The algorithm in the vFPGA encrypts and decrypts the data, and packets and sends the encryption / decryption result and the algorithm resource information;

[0045] S35. The data transfer module in the resource FPGA forwards the message to the data transfer FPGA, and then sends it to the corresponding user interface via the data transfer FPGA;

[0046] S36. The host computer sends the received encryption / decryption result to the corresponding task.

[0047] Further, the user's call for encryption and decryption from the encryption card specifically includes:

[0048] S41. The user packets and sends the data to be encrypted / decrypted in the task and the allocated algorithm resource information to the main encryption card through the host computer;

[0049] S42. The data transfer FPGA in the main encryption card records the information according to the forwarding relationship table, and then forwards the message to the corresponding resource FPGA; if the corresponding resource FPGA is in the slave encryption card, it is sent to the data transfer FPGA of the slave encryption card through the encryption card interconnection interface;

[0050] S43. The data transfer FPGA of the slave encryption card sends the data to be encrypted / decrypted to the corresponding resource FPGA;

[0051] S44. The data transfer module of the resource FPGA forwards the message to the corresponding vFPGA according to the algorithm resource information;

[0052] S45. The algorithm in the vFPGA encrypts and decrypts the data, and packets and sends the encryption / decryption result and the algorithm resource information;

[0053] S46. The data transfer module in the resource FPGA forwards the message to the data transfer FPGA, and then sends it to the corresponding user interface via the data transfer FPGA;

[0054] S47. The host computer sends the received encryption / decryption result to the corresponding task.

[0055] Further, during the process of S1 - S3, the encryption / decryption resources are recycled in real time, specifically including:

[0056] S51. The data transfer FPGA statistically counts the calls of each task to the encryption card in real time, and sends the statistical result to the AI-based resource scheduling module in the management CPU at regular intervals;

[0057] S52. The resource scheduling module based on AI in the management CPU analyzes the resource call statistics, determines the encryption and decryption resources that can be recycled, and sends the information of the recycled resources to the host communication module;

[0058] S53. The host communication module in the management CPU sends the resource recycling request to the host through the data transfer FPGA;

[0059] S54. After receiving the resource recycling request, the host gives a response;

[0060] S55. The host communication module in the management CPU parses the resource recycling response forwarded by the data transfer FPGA and sends the parsing result to the resource scheduling module based on AI; if the host does not respond for a long time, it is regarded as resource recycling;

[0061] S56. The resource scheduling module based on AI in the management CPU retains or recycles the resources according to the reply of the host; if the host agrees to recycle the resources, it updates its own statistics on the resources and notifies the data transfer FPGA to delete the forwarding association information of the resources to be recycled.

[0062] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0063] (1) The present invention provides a USB encryption card supporting multi-user and multi-task and its implementation method. It is designed from two aspects of "internal subdivision" and "external expansion". Each resource FPGA in the encryption card is divided into multiple mutually isolated vFPGAs, and then each resource FPGA is connected through the data transfer FPGA; at the same time, two encryption cards can expand resources through the interconnection interface, realizing parallel processing of multiple encryption and decryption tasks of multiple users.

[0064] (2) The present invention provides a USB encryption card supporting multi-user and multi-task and its implementation method. For a single user, the present invention supports parallel processing of multiple encryption and decryption tasks, without the need for serial processing of multiple tasks like traditional encryption cards, improving the speed of encryption and decryption;

[0065] (3) The present invention provides a USB encryption card supporting multi-user and multi-task and its implementation method. It applies AI technology, uses AI to monitor the usage of encryption and decryption resources in real time, and dynamically adjusts resource allocation and recycling by analyzing historical data and real-time data. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 is the overall architecture diagram of the encryption card described in the present invention.

[0067] Figure 2 is the interconnection schematic diagram of the encryption card in Embodiment 1 of the present invention. Detailed implementation manners

[0068] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0069] It should be noted that the following detailed descriptions are all exemplary and are intended to provide further descriptions of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0070] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular forms are also intended to include the plural forms. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0071] In the case of no conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0072] Embodiment 1

[0073] Refer to Figure 1 , this embodiment provides a USB encryption card that supports multi-user and multi-task, and adopts a modular design, including a management core board, multiple resource core boards, and a bottom board;

[0074] The management core board includes a management CPU, a data transfer FPGA, an AI acceleration FPGA, and a memory;

[0075] The management CPU is responsible for encryption and decryption resource scheduling, communicating with the host computer, interconnecting with other encryption cards, and configuring the resource FPGA; the encryption and decryption resource scheduling includes allocation and recovery.

[0076] The data transfer FPGA is responsible for message recognition and forwarding, including multiple USB user interfaces and an encryption card interconnection interface. The encryption card interconnection interface is used for the interconnection of two encryption cards, as Figure 2 shown; a forwarding relationship table based on TCAM is included in the data transfer FPGA for recording the forwarding direction of messages; specifically, each time the AI-based resource scheduling module in the management CPU allocates or deletes resources, the forwarding relationship table needs to be added to and deleted from.

[0077] The AI acceleration FPGA is responsible for hardware acceleration of the AI algorithm in the management CPU.

[0078] A memory, responsible for storing and managing the system files of the CPU and the configuration files of the algorithm cores; preferably, the memory is an NVMe memory.

[0079] The resource core board includes a resource FPGA and its peripheral circuits such as clock and power supply;

[0080] The resource FPGA is responsible for executing the encryption algorithm of the encryption card. In the art, executing the encryption algorithm of the encryption card also implicitly allows the corresponding decryption to be performed.

[0081] Preferably, a resource FPGA is divided into multiple mutually isolated reconfigurable regions, and each reconfigurable region serves as a vFPGA (Virtualized FPGA) to configure algorithm cores as required and execute the encryption algorithm. This enables a resource FPGA to simultaneously provide the same or different encryption and decryption services for multiple users and multiple tasks; meanwhile, a resource transfer module is built in the resource FPGA to be responsible for the transfer between each internal vFPGA and the data transfer FPGA;

[0082] The resource FPGA includes two configuration methods:

[0083] If configuring the vFPGA, it is through the ICAP interface; if configuring the FPGA, it is through the selectmap interface.

[0084] Furthermore, the management CPU includes an AI-based resource scheduling module, a host computer communication module, an encryption card coordination module, and an algorithm core configuration module:

[0085] The AI-based resource scheduling module is used for AI optimization and management of resource scheduling under multiple users and multiple tasks. The resource scheduling under multiple tasks includes the allocation and recycling of encryption and decryption resources; for example, when a user wants to use the encryption card, they need to first request resources from the encryption card. At this time, this AI-based resource scheduling module needs to determine whether there are any available resources in the encryption card; if this user does not perform data encryption for a long time later, then this AI-based resource scheduling module needs to judge whether this user has finished using the resources based on historical data.

[0086] The host computer communication module realizes data intercommunication with the host computer; the message types of the data include the user's resource request, the resource request response of the encryption card, the user's data to be encrypted and decrypted, the encryption and decryption processing data of the encryption card, the resource recycling request of the encryption card, and the resource recycling response of the user;

[0087] The encryption card coordination module realizes the coordination between two encryption cards, facilitating the expansion of the encryption and decryption resources of the encryption card, enabling the user to simultaneously call the encryption and decryption resources in two encryption cards;

[0088] The algorithm core configuration module configures the corresponding algorithm cores into the resource FPGA according to user requirements.

[0089] In summary, the present invention realizes multi-user and multi-task parallel computing. In order to meet the requirements of multi-user and multi-task parallel computing simultaneously in this embodiment, it is designed from two aspects: "internal subdivision" and "external expansion".

[0090] (1) "Internal subdivision" means that a resource FPGA is divided into multiple isolated reconfigurable regions. Each reconfigurable region serves as a vFPGA (Virtualized FPGA) and configures algorithm cores as needed, so that a resource FPGA can provide the same or different encryption and decryption for multiple users and multiple tasks simultaneously.

[0091] (2) "External expansion" means that the present invention adopts a modular design. There can be multiple resource core boards in an encryption card (each resource core board has a resource FPGA). In addition, encryption cards can be cascaded and expanded through the encryption card interconnection interface.

[0092] This embodiment supports multiple users, and each user occupies a user interface; each user can have multiple tasks; each task occupies a vFPGA; each vFPGA can be configured as one of a variety of pre-set encryption algorithm cores.

[0093] Virtualize the encryption and decryption resources of the encryption card. The same user can use the vFPGAs in the same resource FPGA, or can use the vFPGAs distributed in different resource FPGAs in the same encryption card. Even when two encryption cards are used in an extended manner, the same user can use the v encryption and decryption resources in different encryption cards.

[0094] The configuration of the resource FPGA is initiated by the algorithm core configuration module in the management CPU. There are two configuration methods. If configuring the vFPGA, it is through the ICAP interface (Internal Configuration Access Port), that is, the internal configuration access interface, which is used for partial reconfiguration of the FPGA; if performing global configuration on a certain resource FPGA, it is through the selectmap interface. The selectmap interface is a parallel configuration interface used to directly program or configure the FPGA.

[0095] This embodiment also realizes AI-based resource scheduling. In order to be able to process resource scheduling problems in multi-user and multi-task scenarios in real time and dynamically, AI technology is introduced. AI is used to monitor the usage of encryption and decryption resources in real time. By analyzing historical data and real-time data, resource allocation and recycling are dynamically adjusted. AI-based resource scheduling involves resource allocation, resource recycling, and AI acceleration:

[0096] (4)Resource allocation: If the management CPU receives a resource request from the host computer, the AI-based resource scheduling module will analyze it from two aspects. One is how many available resources there are currently, and the other is the quantity (number of vFPGAs) and type (which algorithm to configure the vFPGA to execute) of the resources requested by the user this time. If the current available resources can meet the user's needs, the user's request will be approved; otherwise, it will be rejected. At the same time, the management CPU will also inform the data transfer FPGA of the newly added resource allocation situation as a new forwarding basis.

[0097] (5)Resource recovery: The data transfer FPGA will count the plaintext algorithm data sent by the user and send the statistical results to the management CPU at regular intervals; the AI-based resource scheduling module in the management CPU will analyze this statistical result, infer the load situation of the encryption and decryption resources during a certain period of time, and thus infer which encryption and decryption resources in the allocated state can be released, and notify the host computer communication module to confirm with the host computer whether the resource can be released.

[0098] (6)AI acceleration: The management CPU and the AI acceleration FPGA together form a heterogeneous computing system. The inference calculation process tasks in the AI model calculation process are divided into multiple stages, and a pipeline design is carried out on the divided stages on the AI acceleration FPGA. The parallel processing ability of the FPGA is used to perform hardware acceleration on the AI model, improving the inference speed of the AI model in the management CPU.

[0099] Embodiment 2

[0100] This embodiment provides a method for implementing a USB encryption card that supports multiple users and multiple tasks. The method includes:

[0101] S1. The user informs the encryption card of the resource request used for this task through the host computer, and it is transmitted to the management CPU through the data transfer FPGA for parsing, and the resource allocation result is obtained and uploaded to the host computer. The resource request includes, but is not limited to, task-related information such as the requested number of vFPGAs, the encryption algorithm configured for the vFPGA, and the address.

[0102] Specifically, the S1 specifically includes:

[0103] S11. The user informs the encryption card of the resource request used for this task through the host computer, and it reaches the host computer communication module in the management CPU through the data transfer FPGA;

[0104] S12. The host computer communication module that manages the CPU parses the user's resource request; then, it sends the requested number of vFPGAs and the algorithm type configured for each vFPGA to the AI-based resource scheduling module;

[0105] S13. The AI-based resource scheduling module in the management CPU analyzes the current resource usage situation to obtain a resource allocation result; if there are available resources, it returns the information of the available encryption and decryption resources corresponding to the request to complete the resource allocation; if there are no available resources currently, it predicts a waiting time and notifies the user to apply for resources again after a waiting time;

[0106] S14. The host computer communication module of the management CPU encapsulates the resource allocation result into a resource response request message and then sends it to the host computer via the data transfer FPGA; at the same time, the data transfer FPGA updates the corresponding relationship between the user and the algorithm resource location information to the forwarding relationship table;

[0107] S15. After the host computer receives the resource request response of the encryption card, if it shows that resources have been allocated, it starts encryption and decryption; if it shows that no resources have been allocated, it waits for a period of time and then applies again.

[0108] S2. If the resource allocation result shows that collaborative processing between encryption cards is required. As Figure 2 shown, then:

[0109] First, connect the two encryption cards through the encryption card interconnection interface to enter the collaborative mode; among them, the encryption card connected to the host computer is automatically set as the main encryption card, and the other encryption card is the slave encryption card. The management CPU of the main encryption card performs unified resource scheduling;

[0110] Specifically, the process of connecting the two encryption cards through the encryption card interconnection interface to enter the collaborative mode specifically includes:

[0111] S21. Connect the two encryption cards through the encryption card interconnection interface, and the encryption card connected to the host computer is automatically set as the main encryption card; in the encryption card interconnection mode, only 1 encryption card is supported for communicating with the user, that is, the main encryption card communicates with users 1 to n;

[0112] S22. The encryption card collaboration module in the management CPU of the main encryption card sends a request message, which is forwarded through two layers of the data transfer FPGA of the main encryption card and the data transfer FPGA of the slave encryption card and reaches the encryption card collaboration module in the management CPU of the slave encryption card;

[0113] S23. The encryption card cooperation module in the encryption card management CPU sends available resource information. After two-layer forwarding through the data transfer FPGA of the slave encryption card and the data transfer FPGA of the master encryption card, it reaches the encryption card cooperation module in the master encryption card management CPU.

[0114] S24. The encryption card cooperation module in the master encryption card management CPU sends the resource information of the slave encryption card to the AI-based resource scheduling module for unified resource scheduling.

[0115] Then, the user calls the master encryption card for encryption and decryption, and then calls the slave encryption card for encryption and decryption.

[0116] Specifically, the user's call to the master encryption card for encryption and decryption specifically includes:

[0117] S31. The user uses the host computer to packetize the data to be encrypted and decrypted in the task and the allocated algorithm resource information and send it to the master encryption card. The allocated algorithm resource information is the algorithm resource information that needs to be encrypted and decrypted.

[0118] S32. The data transfer FPGA in the master encryption card records the information according to the forwarding relationship table, and then forwards the packet to the corresponding resource FPGA.

[0119] S33. The data transfer module of the resource FPGA forwards the packet to the corresponding vFPGA according to the algorithm resource information.

[0120] S34. The vFPGA encrypts and decrypts the data in the algorithm check, and packetizes and sends the encryption and decryption results and the algorithm resource information.

[0121] S35. The data transfer module in the resource FPGA forwards the packet to the data transfer FPGA, and then sends it to the corresponding user interface through the data transfer FPGA.

[0122] S36. The host computer sends the received encryption and decryption results to the corresponding task.

[0123] The user's call to the slave encryption card for encryption and decryption specifically includes:

[0124] S41. The user uses the host computer to packetize the data to be encrypted and decrypted in the task and the allocated algorithm resource information and send it to the master encryption card.

[0125] S42. The data transfer FPGA in the master encryption card records the information according to the forwarding relationship table, and then forwards the packet to the corresponding resource FPGA; if the corresponding resource FPGA is in the slave encryption card, it is sent to the data transfer FPGA of the slave encryption card through the encryption card interconnection interface.

[0126] S43. The data transfer FPGA in the encryption card sends the data to be encrypted / decrypted to the corresponding resource FPGA.

[0127] S44. The data transfer module in the resource FPGA forwards the message to the corresponding vFPGA according to the algorithm resource information.

[0128] S45. The algorithm in the vFPGA encrypts / decrypts the data and packages and sends the encryption / decryption result and the algorithm resource information.

[0129] S46. The data transfer module in the resource FPGA forwards the message to the data transfer FPGA, and then sends it to the corresponding user interface via the data transfer FPGA.

[0130] S47. The host computer sends the received encryption / decryption result to the corresponding task.

[0131] If the resource allocation result shows that no collaborative processing between encryption cards is required, the user directly calls the main encryption card for encryption / decryption.

[0132] S3. The host computer sends the encrypted / decrypted data to the corresponding task.

[0133] Preferably, during the process of S1 - S3, the encryption / decryption resources are recycled in real time, specifically including:

[0134] S51. The data transfer FPGA statistically counts the calls of each task to the encryption card in real time and sends the statistical result to the AI - based resource scheduling module in the management CPU at regular intervals.

[0135] S52. The AI - based resource scheduling module in the management CPU analyzes the resource call statistics, determines the encryption / decryption resources that can be recycled, and sends the information of the recycled resources to the host computer communication module.

[0136] S53. The host computer communication module in the management CPU sends the resource recycling request to the host computer through the data transfer FPGA.

[0137] S54. After receiving the resource recycling request, the host computer gives a response.

[0138] S55. The host computer communication module in the management CPU parses the resource recycling response forwarded by the data transfer FPGA and sends the parsing result to the AI - based resource scheduling module; if the host computer does not respond for a long time, it is regarded as resource recycling.

[0139] S56. The AI - based resource scheduling module in the management CPU retains or recycles the resources according to the reply from the host computer; if the host computer agrees to recycle the resources, it updates its own statistics of the resources and notifies the data transfer FPGA to delete the forwarding association information of the resources to be recycled.

[0140] Obviously, the above-mentioned embodiments of the present invention are merely examples for clearly illustrating the technical solutions of the present invention, rather than limitations on the specific implementation manners of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the claims of the present invention shall be included within the protection scope of the claims of the present invention.

Claims

1. A USB encryption card supporting multi-user and multi-tasking, characterized in that: Including management core board, multiple resource core boards and base board; The management core board includes a management CPU, a data transfer FPGA, an AI acceleration FPGA, and a memory; Management CPU, responsible for encryption and decryption resource scheduling, intercommunication with the host computer, interconnection with other encryption cards and configuration of resource FPGA; The management CPU includes an AI-based resource scheduling module, a host computer communication module, an encryption card coordination module, and an algorithm core configuration module: AI-based resource scheduling module, which uses AI to optimize and manage resource scheduling issues under multi-user and multi-task conditions; The host computer communication module realizes data intercommunication with the host computer. The message types of the data include the user's resource request, the encryption card's resource request response, the user's data to be encrypted and decrypted, the encryption card's encryption and decryption processing data, the encryption card's resource recovery request and the user's resource recovery response; The encryption card collaboration module realizes the collaboration between two encryption cards and facilitates the expansion of encryption and decryption resources of encryption cards; The algorithm core configuration module configures the corresponding algorithm core into the resource FPGA according to user requirements; The data transfer FPGA is responsible for the identification and forwarding of messages, including multiple USB user interfaces and an encryption card interconnection interface. The encryption card interconnection interface is used to interconnect two encryption cards. The encryption card connected to the host computer is automatically set as the main encryption card. The encryption card coordination module in the main encryption card management CPU sends a request message, which is forwarded by the data transfer FPGA of the main encryption card and the data transfer FPGA of the slave encryption card, and then reaches the encryption card coordination module in the slave encryption card management CPU. The available resource information is sent from the encryption card coordination module in the encryption card management CPU, and is forwarded through two layers of forwarding, namely, the data transfer FPGA of the slave encryption card and the data transfer FPGA of the master encryption card, to the encryption card coordination module in the master encryption card management CPU; The data transfer FPGA includes a TCAM-based forwarding relationship table for recording the forwarding direction of the message; AI acceleration FPGA, responsible for hardware acceleration of AI algorithms in the management CPU; Memory, responsible for storing and managing CPU system files and configuration files of algorithm cores; The resource core board includes a resource FPGA and peripheral circuits; Resource FPGA, responsible for executing the encryption algorithm of the encryption card; The resource FPGA is divided into multiple isolated reconfigurable areas, each of which acts as a vFPGA to configure the algorithm core as required and execute the encryption algorithm; at the same time, a resource transfer module is constructed in the resource FPGA to be responsible for the transfer between each internal vFPGA and the data transfer FPGA; The resource FPGA includes two configuration modes: If the vFPGA is configured, it is done through the ICAP interface; if the FPGA is configured, it is done through the selectmap interface.

2. A method for implementing a USB encryption card that supports multi-user and multi-tasking, characterized in that: The method comprises: S1. The user informs the encryption card of the resource request for this task through the host computer, and transmits it to the management CPU for analysis through the data transfer FPGA, obtains the resource allocation result and uploads it to the host computer; S2. If the resource allocation result shows that collaborative processing is required between encryption cards, then: First, connect the two encryption cards through the encryption card interconnection interface and enter the collaborative mode. The encryption card connected to the host computer is automatically set as the master encryption card, and the other encryption card is the slave encryption card. The management CPU of the master encryption card performs unified resource scheduling. Then, the user calls the master encryption card for encryption and decryption, and then calls the slave encryption card for encryption and decryption; If the resource allocation result shows that there is no need for collaborative processing between encryption cards, the user directly calls the main encryption card for encryption and decryption; S3, the host computer sends the encrypted and decrypted data to the corresponding task; The S1 specifically includes: S11, the user informs the encryption card of the resource request used for this task through the host computer, and the resource request is transmitted to the host computer communication module in the management CPU through the data transfer FPGA; S12, the host computer communication module of the management CPU parses the user's resource request; then, the requested number of vFPGAs and the algorithm type configured for each vFPGA are sent to the AI-based resource scheduling module; S13, the AI-based resource scheduling module in the management CPU analyzes the current resource usage to obtain the resource allocation result; if there are available resources, the information of available encryption and decryption resources corresponding to the request is returned to complete the resource allocation; if there are no available resources at present, a waiting time is predicted, and the user is informed to apply for resources after a waiting time; S14, the host computer communication module of the management CPU encapsulates the result of resource allocation into a resource response request message, and then sends it to the host computer via the data transfer FPGA; at the same time, the data transfer FPGA updates the corresponding relationship between the user and algorithm resource location information into the forwarding relationship table; S15, after the host computer receives the resource request response from the encryption card, if it shows that the resources have been allocated, it starts encryption and decryption; if it shows that the resources have not been allocated, it waits for a period of time and reapplies; The step of connecting the two encryption cards via the encryption card interconnection interface to enter the collaborative mode specifically includes: S21, connecting the two encryption cards through the encryption card interconnection interface, and the encryption card connected to the host computer is automatically set as the main encryption card; S22, the encryption card coordination module in the main encryption card management CPU sends a request message, which is forwarded by the data transfer FPGA of the main encryption card and the data transfer FPGA of the slave encryption card, and reaches the encryption card coordination module in the slave encryption card management CPU; S23, the encryption card coordination module in the slave encryption card management CPU sends available resource information, which is forwarded by the slave encryption card data transfer FPGA and the master encryption card data transfer FPGA, and reaches the encryption card coordination module in the master encryption card management CPU; S24. The encryption card coordination module in the main encryption card management CPU sends the resource information from the encryption card to the AI-based resource scheduling module for unified resource scheduling.

3. The method for implementing a USB encryption card supporting multi-user and multi-tasking according to claim 2, characterized in that: The user calling the main encryption card to perform encryption and decryption specifically includes: S31, the user sends the data to be encrypted and decrypted in the task and the allocated algorithm resource information package to the main encryption card through the host computer; S32, the data transfer FPGA in the main encryption card forwards the message to the corresponding resource FPGA according to the information recorded in the forwarding relationship table; S33, resource FPGA data transfer module forwards the message to the corresponding vFPGA according to the algorithm resource information; S34, the algorithm in the vFPGA encrypts and decrypts the data, and sends the encryption and decryption results and algorithm resource information in a package; S35, the data transfer module in the resource FPGA forwards the message to the data transfer FPGA, and then sends it to the corresponding user interface via the data transfer FPGA; S36. The host computer sends the received encryption and decryption results to the corresponding tasks.

4. The method for implementing a USB encryption card supporting multi-user and multi-tasking according to claim 3, characterized in that: The user calling the encryption and decryption from the encryption card specifically includes: S41, the user sends the data to be encrypted and decrypted in the task and the allocated algorithm resource information package to the main encryption card through the host computer; S42, the data transfer FPGA in the master encryption card forwards the message to the corresponding resource FPGA according to the information recorded in the forwarding relationship table; if the corresponding resource FPGA is in the slave encryption card, it is sent to the data transfer FPGA of the slave encryption card through the encryption card interconnection interface; S43, the data transfer FPGA of the encryption card sends the data to be encrypted and decrypted to the corresponding resource FPGA; S44, resource FPGA data transfer module forwards the message to the corresponding vFPGA according to the algorithm resource information; S45, the algorithm in the vFPGA encrypts and decrypts the data, and sends the encryption and decryption results and algorithm resource information in a package; S46, the data transfer module in the resource FPGA forwards the message to the data transfer FPGA, and then sends it to the corresponding user interface via the data transfer FPGA; S47, the host computer sends the received encryption and decryption results to the corresponding tasks.

5. The method for implementing a USB encryption card supporting multi-user and multi-tasking according to claim 2, characterized in that: During the S1-S3 process, encryption and decryption resources are recycled in real time, including: S51, the data transfer FPGA counts the calls of each task to the encryption card in real time, and sends the statistical results to the AI-based resource scheduling module in the management CPU at regular intervals; S52, the AI-based resource scheduling module in the management CPU analyzes the resource call statistics, determines the encryption and decryption resources that can be recycled, and sends the information of the recycled resources to the upper computer communication module; S53, the host computer communication module in the management CPU sends the resource recovery request to the host computer through the data transfer FPGA; S54, after receiving the resource recovery request, the host computer gives a response; S55, the upper computer communication module in the management CPU parses the resource recovery response forwarded by the data transfer FPGA, and sends the parsing result to the AI-based resource scheduling module; if the upper computer does not respond for a long time, it is regarded as resource recovery; S56. The AI-based resource scheduling module in the management CPU reserves or recycles the resources according to the response of the host computer; if the host computer agrees to recycle the resources, it updates its own statistics on the resources and notifies the data transfer FPGA to delete the forwarding association information of the resources to be recycled.

Citation Information

Patent Citations

  • Network data encryption card based on hardware protocol and transmission method

    CN116707970A

  • Data transmission processing method and device based on CPU and FPGA

    CN116467249A

  • High-speed cryptographic algorithm password card based on FPGA (Field Programmable Gate Array)

    CN214122946U