A method, apparatus, and device for allocating cryptographic resources, and a computer storage medium.
By dynamically adjusting the number of access cryptographic devices according to changes in data traffic, the problem of resource waste and overload caused by fixed cryptographic resources is solved, and efficient resource utilization is achieved.
Patent Information
- Application Number
- CN202411411769.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-10
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2044-10-10
AI Technical Summary
In existing technologies, cryptographic devices provide fixed cryptographic resources, which cannot adapt to the changing data traffic demands. This leads to resource shortages, resulting in inefficiency or system crashes during high traffic periods, and resource waste during low traffic periods.
By continuously acquiring the target data stream and dividing it into multiple sub-data streams, the number of cryptographic devices connected is dynamically adjusted based on traffic change information to ensure a balance between resources and demand.
It achieves dynamic balancing of cryptographic resources, avoids resource waste and equipment overload, improves resource utilization efficiency, and prevents downtime and inefficiency problems.
Smart Images

Figure CN119382945B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, specifically to a method, apparatus, and device for allocating cryptographic resources, as well as a computer storage medium. Background Technology
[0002] With the continuous development of science and society, integrating business with the internet has become a common trend across all industries. However, an unavoidable issue arises: how to ensure the security of information transmission and storage over the internet. Therefore, information security technology has become essential for all information technologies. Among these, cryptographic devices, as the core foundation of information security, have become both a crucial component of information systems and a potential source of risk in their application.
[0003] A cryptographic device (or cryptographic machine) is a hardware device specifically designed to provide cryptographic services such as data encryption, decryption, digital signature, and signature verification. Its main purpose is to ensure the security of stored and transmitted data and prevent unauthorized access and data leakage.
[0004] However, in related technologies, the cryptographic devices providing cryptographic services in a data center or service system are usually pre-configured. This results in a fixed amount of cryptographic resources that the cryptographic service can provide, but the data traffic required by the cryptographic server is not. This leads to insufficient cryptographic resources provided by the cryptographic service when the data traffic is too high, resulting in low encryption efficiency or even system crashes. Conversely, when the data traffic is low, the cryptographic service provides too many cryptographic resources, leading to a waste of cryptographic resources.
[0005] Therefore, how to manage and allocate cryptographic resources to improve their utilization efficiency is a technical problem that urgently needs to be solved. Summary of the Invention
[0006] This application provides a method, apparatus, device, and computer storage medium for allocating cryptographic resources, in order to improve the utilization efficiency of cryptographic resources.
[0007] In a first aspect, embodiments of this application provide a method for allocating cryptographic resources, including:
[0008] Continuously acquire target data streams, the target data streams being cryptographically serviced by a pre-defined group of cryptographic devices;
[0009] Based on a preset time interval, the target data stream is divided into at least two sub-data streams; wherein the acquisition time corresponding to the data contained in each sub-data stream is within the same time period, and the time periods corresponding to different sub-data streams are different;
[0010] Based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period, the corresponding traffic change information is obtained; the traffic change information represents: the change of the amount of data in the target data stream per unit time over time.
[0011] Based on the traffic change information, adjust the number of access cryptographic devices in the cryptographic device group;
[0012] Based on the adjusted cryptographic device group, cryptographic services are provided for the target data stream.
[0013] Optionally, obtaining the corresponding traffic change information based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data streams corresponding to the adjacent time periods adjacent to the target time period, includes:
[0014] Based on the length of the target time period and the amount of data in the target sub-data stream obtained within the target time period, the corresponding target time period traffic is obtained;
[0015] Based on the duration of the adjacent time period and the amount of data in the adjacent sub-data streams obtained within the adjacent time period, the corresponding adjacent time period traffic is obtained.
[0016] Based on the difference between the traffic flow during the target time period and the traffic flow during the adjacent time period, the corresponding traffic change information is obtained.
[0017] Optionally, adjusting the number of access cryptographic devices in the cryptographic device group based on the traffic change information includes:
[0018] When the traffic change information indicates an increase in traffic, the resource address of the newly added cryptographic device is obtained, and the resource address is added to the configuration file corresponding to the cryptographic device group to increase the number of cryptographic devices connected in the cryptographic device group.
[0019] When the traffic change information indicates a decrease in traffic, the resource addresses of a preset number of cryptographic devices are deleted from the configuration file corresponding to the cryptographic device group, in order to reduce the number of cryptographic devices connected in the cryptographic device group.
[0020] Optionally, the data processing specifications corresponding to the cryptographic devices in the group of cryptographic devices are different;
[0021] The provision of cryptographic services for the target data stream based on the adjusted cryptographic device group includes:
[0022] For each piece of data to be processed in the target data stream, perform the following operations:
[0023] Obtain the request identifier corresponding to the data to be processed; the request identifier represents the target data processing specification corresponding to the data to be processed.
[0024] Based on the target data processing specification, the data to be processed is encapsulated into first data having a target data format corresponding to the target data processing specification;
[0025] The first data is sent to the target cryptographic device corresponding to the target data processing specification, so that the target cryptographic device performs data processing operations on the first data and returns the processing result.
[0026] The system receives the processing result from the target cryptographic device, encapsulates the processing result into second data with a preset data format, and sets a corresponding specification identifier for the second data; wherein the specification identifier is used to characterize the data processing specification corresponding to the second data.
[0027] Optionally, the cryptographic devices in the cryptographic device group may correspond to different operating systems;
[0028] Before continuously acquiring the target data stream, the method further includes:
[0029] Select a cryptographic device as the source cryptographic device, and select a cryptographic device with an operating system different from the source operating system corresponding to the source cryptographic device as the target cryptographic device;
[0030] Obtain the source key data from the source operating system corresponding to the source cryptographic device;
[0031] Based on the source key data, the target key data in the target cryptographic device is replaced so that the operating systems of the cryptographic devices in the cryptographic device group have the same source key data.
[0032] Optionally, replacing the target key data in the target cryptographic device based on the source key data includes:
[0033] Based on the operating system of the target cryptographic device, generate the corresponding original image file;
[0034] Delete the target key data from the original image file and add the source key data to the original image file to obtain the corresponding target image file;
[0035] The target image file is pushed to the target cryptographic device.
[0036] Secondly, embodiments of this application provide an apparatus for allocating cryptographic resources, comprising:
[0037] The acquisition module is used to continuously acquire the target data stream, which is provided with cryptographic services by a preset group of cryptographic devices;
[0038] The segmentation module is used to divide the target data stream into at least two sub-data streams based on a preset time interval; wherein the acquisition time of the data contained in each sub-data stream is within the same time period, and the time periods corresponding to different sub-data streams are different.
[0039] The processing module is used to obtain corresponding traffic change information based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period; the traffic change information represents: the change of the amount of data in the target data stream per unit time over time;
[0040] The adjustment module is used to adjust the number of access cryptographic devices in the cryptographic device group based on the traffic change information; and to provide cryptographic services for the target data stream based on the adjusted cryptographic device group.
[0041] Optionally, when the processing module obtains the corresponding flow change information based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period, it is specifically used for:
[0042] Based on the length of the target time period and the amount of data in the target sub-data stream obtained within the target time period, the corresponding target time period traffic is obtained;
[0043] Based on the duration of the adjacent time period and the amount of data in the adjacent sub-data streams obtained within the adjacent time period, the corresponding adjacent time period traffic is obtained.
[0044] Based on the difference between the traffic flow during the target time period and the traffic flow during the adjacent time period, the corresponding traffic change information is obtained.
[0045] Optionally, when the adjustment module is used to adjust the number of access cryptographic devices in the cryptographic device group based on the traffic change information, it is specifically used for:
[0046] When the traffic change information indicates an increase in traffic, the resource address of the newly added cryptographic device is obtained, and the resource address is added to the configuration file corresponding to the cryptographic device group to increase the number of cryptographic devices connected in the cryptographic device group.
[0047] When the traffic change information indicates a decrease in traffic, the resource addresses of a preset number of cryptographic devices are deleted from the configuration file corresponding to the cryptographic device group, in order to reduce the number of cryptographic devices connected in the cryptographic device group.
[0048] Optionally, if the data processing specifications of the cryptographic devices in the cryptographic device group are different, then when the adjustment module provides cryptographic services for the target data stream based on the adjusted cryptographic device group, it is specifically used for:
[0049] For each piece of data to be processed in the target data stream, perform the following operations:
[0050] Obtain the request identifier corresponding to the data to be processed; the request identifier represents the target data processing specification corresponding to the data to be processed.
[0051] Based on the target data processing specification, the data to be processed is encapsulated into first data having a target data format corresponding to the target data processing specification;
[0052] The first data is sent to the target cryptographic device corresponding to the target data processing specification, so that the target cryptographic device performs data processing operations on the first data and returns the processing result.
[0053] The system receives the processing result from the target cryptographic device, encapsulates the processing result into second data with a preset data format, and sets a corresponding specification identifier for the second data; wherein the specification identifier is used to characterize the data processing specification corresponding to the second data.
[0054] Optionally, if the cryptographic devices in the cryptographic device group have different operating systems, then before continuously acquiring the target data stream, the acquisition module is further configured to:
[0055] Select a cryptographic device as the source cryptographic device, and select a cryptographic device with an operating system different from the source operating system corresponding to the source cryptographic device as the target cryptographic device;
[0056] Obtain the source key data from the source operating system corresponding to the source cryptographic device;
[0057] Based on the source key data, the target key data in the target cryptographic device is replaced so that the operating systems of the cryptographic devices in the cryptographic device group have the same source key data.
[0058] Optionally, when the acquisition module replaces the target key data in the target cryptographic device based on the source key data, it is specifically used for:
[0059] Based on the operating system of the target cryptographic device, generate the corresponding original image file;
[0060] Delete the target key data from the original image file and add the source key data to the original image file to obtain the corresponding target image file;
[0061] The target image file is pushed to the target cryptographic device.
[0062] Thirdly, embodiments of this application provide an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the at least one processor, by executing the instructions stored in the memory, causes the at least one processor to perform the method described in the first aspect or any optional embodiment of the first aspect.
[0063] Fourthly, embodiments of this application provide a computer-readable storage medium for storing instructions that, when executed, cause a method as described in the first aspect or any optional implementation thereof to be implemented.
[0064] Fifthly, embodiments of this application provide a computer program product containing instructions, wherein the computer program product stores instructions that, when run on a computer, cause the computer to perform the method described in the first aspect or any optional implementation thereof.
[0065] The beneficial effects of this application are as follows:
[0066] In this solution, by continuously acquiring the target data stream and analyzing the changes in traffic per unit time, the trend of data traffic requiring cryptographic services is determined. Based on this trend, the number of cryptographic devices connected to the cryptographic device group is adjusted. In this way, the cryptographic resources that the cryptographic device group can provide can be adjusted at any time according to the traffic trend, so that the supply and demand of cryptographic resources are in a dynamic balance. This avoids both the waste of control of some cryptographic resources due to the excessive supply of cryptographic resources but the insufficient demand, and the problem of reduced data processing efficiency or downtime due to excessive load on cryptographic devices caused by insufficient supply of cryptographic resources but excessive demand. Attached Figure Description
[0067] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0068] Figure 1 This is a schematic diagram illustrating possible application scenarios provided for embodiments of this application;
[0069] Figure 2 A flowchart illustrating a method for allocating cryptographic resources provided in an embodiment of this application;
[0070] Figure 3 A schematic diagram of data traffic corresponding to a time period provided in the embodiments of this application;
[0071] Figure 4 A logical diagram illustrating the distribution of target data traffic as provided in an embodiment of this application;
[0072] Figure 5 A flowchart illustrating a method for obtaining traffic change information provided in an embodiment of this application;
[0073] Figure 6 A schematic diagram illustrating the length of a time period as provided in an embodiment of this application;
[0074] Figure 7 A logical diagram illustrating a cryptographic resource management method provided in an embodiment of this application;
[0075] Figure 8 This is a flowchart illustrating an encapsulation method proposed in an embodiment of this application;
[0076] Figure 9 This is a logical schematic diagram of an encapsulation method proposed in an embodiment of this application;
[0077] Figure 10 This is a logical schematic diagram of a method for obtaining a target image file according to an embodiment of this application;
[0078] Figure 11 This is a logical schematic diagram of a method for pushing a target image file according to an embodiment of this application;
[0079] Figure 12 A schematic diagram of a cryptographic resource allocation device provided in an embodiment of this application;
[0080] Figure 13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0081] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.
[0082] The terms "first" and "second" in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. The term "multiple" in this application can mean at least two, for example, two, three, or more, and the embodiments of this application do not impose limitations.
[0083] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These embodiments should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description. It should be noted that in the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solutions of this application, and do not imply that the applicant has already used or necessarily used such solutions.
[0084] The acquisition, transmission, storage, and use of data in this application all comply with relevant national laws and regulations.
[0085] With the continuous development of science and society, more and more industries are choosing to migrate their business data online. Therefore, information security becomes a crucial concern when transmitting data over the internet. Among information security technologies, cryptographic devices, as the core foundation of information security, have become both an important component of information systems and a potential risk factor in their application.
[0086] However, in related technologies, the cryptographic devices providing cryptographic services in a data center or service system are usually pre-configured. This results in a fixed amount of cryptographic resources that the cryptographic service can provide, but the data traffic required by the cryptographic server is not fixed. This leads to insufficient cryptographic resources provided by the cryptographic service when the data traffic is too high, resulting in low encryption efficiency and even downtime. Conversely, when the data traffic is low, the cryptographic service provides too many cryptographic resources, resulting in a waste of cryptographic resources.
[0087] In view of this, this application proposes a method for allocating cryptographic resources to improve the utilization efficiency of cryptographic resources. First, it is necessary to continuously acquire a target data stream, which is provided with cryptographic services by a preset group of cryptographic devices. In other words, it is necessary to continuously acquire the target data stream that requires cryptographic services. Then, based on a preset time interval, the target data can be divided into at least two sub-data streams. The acquisition events corresponding to the data in each of these at least two sub-data streams are all within the same time period, and the time periods corresponding to different sub-data streams are different.
[0088] Next, based on the target sub-data stream corresponding to the target time period where the current time is located, and the adjacent sub-data stream corresponding to the adjacent event segment adjacent to the target time period, traffic change information is obtained, which represents the change of the data volume of the unit data stream per unit time period over time. In this way, the number of access cryptographic devices in the cryptographic device group can be adjusted according to the traffic change information, so as to provide cryptographic services for the target data stream based on the adjusted cryptographic device group.
[0089] In this way, the number of access devices in the cryptographic device group can be dynamically adjusted according to the changes in the target data flow, which can effectively improve the utilization efficiency of cryptographic resources and prevent the waste of cryptographic resources.
[0090] After introducing the main inventive concept of the embodiments of this application, the specific implementation of the cryptographic resource allocation method proposed in the embodiments of this application will be described below through some specific embodiments and accompanying drawings.
[0091] The following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application are applicable. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.
[0092] See Figure 1 This is a schematic diagram of a possible application scenario provided by an embodiment of this application. In this scenario, a terminal device 101 and a server 102 may be included.
[0093] Terminal device 101 can be a mobile phone, tablet computer (PAD), personal computer (PC), wearable device, vehicle terminal, etc. Server 102 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms.
[0094] Terminal device 101 and server 102 can communicate directly or indirectly through one or more communication networks 103. The communication network 103 can be a wired network or a wireless network. For example, the wireless network can be a mobile cellular network or a Wireless-Fidelity (WIFI) network. Of course, it can also be other possible networks, and this embodiment of the invention does not limit them.
[0095] It should be noted that the method for allocating cryptographic resources in this embodiment can be executed by a computer device, which can be a terminal device 101 or a server 102. For example, when the method for allocating cryptographic resources is performed by the server 102, the server can obtain target data streams from various terminal devices or other servers, and then, based on the data volume of the target data stream within a set time range per unit time, and the change over time, determine the adjustment method for the number of cryptographic devices connected in the cryptographic device group, and provide cryptographic services to the target data stream based on the adjusted cryptographic device group.
[0096] It should be noted that, Figure 1 The examples shown are merely illustrative; in reality, the number of terminal devices and servers, as well as the communication methods, are not limited and are not specifically restricted in the embodiments of this application.
[0097] The following describes the method for allocating cryptographic resources provided by exemplary embodiments of this application, in conjunction with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.
[0098] See Figure 2 This is a flowchart illustrating a method for allocating cryptographic resources according to an embodiment of this application. The execution entity of this method can be... Figure 1The terminal devices and / or servers shown are not limited in this application. However, for the sake of clarity in the following explanation, the data processing method proposed in this application will be described using a server as the execution subject as an example.
[0099] like Figure 2 As shown, the specific implementation steps of this method are as follows:
[0100] Step S201: Continuously acquire the target data stream, which is cryptographically serviced by a preset group of cryptographic devices.
[0101] When the server enables the cryptographic service for data, it first sets up the corresponding cryptographic device group according to the preset configuration parameters for the cryptographic device group. This cryptographic device group includes at least one cryptographic device, and the specific number of cryptographic devices is determined by the cryptographic resources that a cryptographic device can provide and the maximum cryptographic resources that the server needs to provide.
[0102] For example, suppose a server needs to provide cryptographic services for the transmission and storage of data in a cloud storage system. When initializing the configuration of the cryptographic device group, the server needs to estimate the maximum amount of business data in the cloud storage system, and then set up the original cryptographic device group according to the cryptographic resources required by the maximum amount of business data. At this time, the cryptographic resources provided by the cryptographic devices connected in the cryptographic device group can cover the cryptographic resource requirements of the maximum amount of business data in the cloud storage system.
[0103] In normal circumstances, cloud storage systems do not always maintain the maximum amount of business data. Therefore, if the cryptographic device group always maintains the maximum number of connected devices, it will result in the idle and wasted cryptographic resources. Therefore, this application proposes a cryptographic resource allocation method to improve the utilization rate of cryptographic resources.
[0104] The target data stream mentioned in step S201 above refers to the data that requires cryptographic services from the cryptographic device group. This data may come from different business servers or systems, and this application does not make any distinction. However, regardless of the source of this data, it needs to be provided with cryptographic services by the cryptographic device group, namely encryption, decryption, digital signature, signature authentication and other services.
[0105] Data from different servers or systems is continuously transmitted to the server providing the password service. Therefore, the server providing the password service can continuously obtain the target data stream for subsequent operations.
[0106] Step S202: Based on a preset time interval, divide the target data stream into at least two sub-data streams; wherein the acquisition time of the data contained in each sub-data stream is within the same time period, and the time periods corresponding to each sub-data stream are different.
[0107] The server continuously acquires the target data stream. Therefore, the server can divide these data streams according to a preset time interval. The preset time interval can be set according to the actual needs of the application, such as one minute or half a minute, and this application does not limit it.
[0108] During the continuous acquisition of the target data stream by the server, the server can divide the time into different time periods based on the time interval. The data stream acquired within the same time period can be used as the sub-data stream corresponding to that time period. In this way, the target data stream is divided into at least two sub-data streams.
[0109] For example, assuming the preset time interval is T, the data stream obtained in the time interval [0, T) can be used as sub-data stream 1, the data stream obtained in the time interval [T, 2T) can be used as sub-data stream 2, and so on, until the current time is reached, the server can obtain n sub-data streams.
[0110] It should be noted that, as Figure 3 As shown, since the server continuously acquires the target data stream, but the amount of data contained in the acquired data stream is not uniformly distributed, the amount of data contained in the at least two sub-data streams obtained from the division is not necessarily the same.
[0111] In one possible implementation, the server can also acquire the sub-data stream in the following way:
[0112] When the server acquires the target data stream, it can set corresponding time markers for the data streams received in different time periods according to a preset time interval, which are used to represent the correspondence between the data stream and the time period.
[0113] For example, suppose the server contains something like... Figure 4 The structure shown executes the above method, wherein the time aspecter sets the corresponding time marker for the data in the target data stream, and the generator forwards the marked data to the corresponding receiving queue.
[0114] So if Figure 4 As shown, after a data stream X{.....} passes through a time sectioner, a new time marker t will be added to it. i The data stream X{.....,t is obtained. i}, where i is the sequence number of the time identifier.
[0115] And this data stream X{.....,t iAfter passing through the generator, the data will be sent to the corresponding receiving queue based on the timestamp. For example... Figure 4 As shown, different data stream receiving queues correspond to different time periods. In other words, data streams received within the same time period will be sent to the same data stream receiving queue. The data in these receiving queues will then be transmitted to the cryptographic device group based on a first-in, first-out principle to perform the corresponding cryptographic services.
[0116] Step S203: Based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period, obtain the corresponding flow change information; wherein, the flow change information represents: the change of the amount of data in the target data stream per unit time over time.
[0117] For sub-data streams within different time periods, the server can take the current time period as the target time period and obtain the time periods adjacent to the target time period as adjacent time periods. In this way, the server can obtain the corresponding traffic change information for the target sub-data stream corresponding to the target time period and the adjacent sub-data streams corresponding to the adjacent time periods to represent the change of the amount of data in the target data stream per unit time over time.
[0118] In one possible implementation, when the server obtains traffic change information, it can do so through methods such as... Figure 5 Perform as shown.
[0119] See Figure 5 The flowchart below shows a method for obtaining traffic change information provided in an embodiment of this application. Figure 5 As shown, the specific implementation steps of this method are as follows:
[0120] Step S501: Based on the length of the target time period and the amount of data in the target sub-data stream obtained within the target time period, obtain the corresponding target time period traffic.
[0121] Step S502: Based on the duration of the adjacent time period and the amount of data in the adjacent sub-data streams obtained within the adjacent time period, obtain the corresponding adjacent time period traffic.
[0122] Among them, such as Figure 6 As shown, since the length of the target time period and the length of the adjacent time period are not necessarily the same, it is necessary to obtain the corresponding time period traffic for the sub-data streams corresponding to the target time period and the adjacent time period respectively.
[0123] Specifically, the same method can be used to obtain data traffic in different time periods: divide the amount of data in the sub-data stream received within the corresponding time period by the corresponding time length to obtain the data traffic.
[0124] After obtaining the traffic for the target time period and the traffic for adjacent time periods using this method, the server can continue to perform the following operations:
[0125] Step S503: Based on the difference between the traffic flow in the target time period and the traffic flow in the adjacent time period, obtain the corresponding traffic change information.
[0126] In this way, by measuring the difference in traffic between two adjacent time periods, the server can determine the traffic change information corresponding to the target data stream at the current time.
[0127] This traffic change information can represent different things. For example, the traffic change information can be used to determine the trend of traffic changes based on the relationship between the difference and zero.
[0128] When the difference is greater than zero, it is considered that the trend is upward, the pressure on the cryptographic device group to process data is increasing, and cryptographic resources can be appropriately increased.
[0129] When the difference is zero, the trend remains unchanged, the data processing capacity of the cryptographic device group is appropriate, and the current cryptographic resources remain unchanged;
[0130] When the difference is less than zero, it is considered that the trend is downward and the data processing capacity of the cryptographic device group is excessive, so some cryptographic resources can be removed.
[0131] Furthermore, in addition to the zero mentioned above, the difference can also be compared with other thresholds. That is, only when the difference is greater than a certain threshold, indicating a significant trend change, is it necessary to adjust the number of cryptographic devices connected in the cryptographic device group.
[0132] Once the server obtains the corresponding traffic change information, it can then proceed with the following operations:
[0133] Step S204: Adjust the number of cryptographic devices connected in the cryptographic device group based on traffic change information.
[0134] The server will adjust the number of cryptographic devices connected in the cryptographic device group based on the meaning represented by the traffic change information.
[0135] In one possible implementation, the server can adjust the number of access points in the following way:
[0136] When traffic change information indicates an increase in traffic, obtain the resource address of the newly added cryptographic device and add the resource address to the configuration file corresponding to the cryptographic device group to increase the number of cryptographic devices connected in the cryptographic device group;
[0137] When traffic change information indicates a decrease in traffic, delete the resource addresses of a preset number of cryptographic devices recorded in the configuration file corresponding to the cryptographic device group, in order to reduce the number of cryptographic devices connected in the cryptographic device group.
[0138] Step S205: Provide cryptographic services for the target data stream based on the adjusted cryptographic device group.
[0139] In this way, the server can provide cryptographic services for the target data stream based on the adjusted cryptographic device set.
[0140] In this solution, by continuously acquiring the target data stream and analyzing the changes in traffic per unit time, the trend of data traffic requiring cryptographic services is determined. Based on this trend, the number of cryptographic devices connected to the cryptographic device group is adjusted. In this way, the cryptographic resources that the cryptographic device group can provide can be adjusted at any time according to the traffic trend, so that the supply and demand of cryptographic resources are in a dynamic balance. This avoids both the waste of control of some cryptographic resources due to the excessive supply of cryptographic resources but the insufficient demand, and the problem of reduced data processing efficiency or downtime due to excessive load on cryptographic devices caused by insufficient supply of cryptographic resources but excessive demand.
[0141] The above describes some possible implementations of the cryptographic resource management method provided in the embodiments of this application. In order to clarify the above scheme, the following will use an example to give an overall introduction to the method.
[0142] See Figure 7 The above is a logical schematic diagram of a cryptographic resource management method provided in an embodiment of this application, as shown below. Figure 7 As shown, the specific implementation steps of this method are as follows:
[0143] The cryptographic device group needs to provide cryptographic services to the business server or business system. Therefore, the business server or business system will continuously transmit data to the cryptographic device group. At this time, the cryptographic server corresponding to the cryptographic device group can continuously obtain the target data stream and input the target data stream into the time aspect. The time aspect sets the corresponding time stamp for the data input to the time aspect based on the preset time interval, and then transmits it to the generator. The generator sends each data stream to the corresponding receiving queue. Finally, the data in the receiving queue with the smallest queue number is passed into the cryptographic device group according to the first-in-first-out principle.
[0144] Meanwhile, the generator can also obtain the corresponding traffic change information based on the data volume information of sub-data streams with different time identifiers, and then transmit the traffic change information to the decision analyzer. The decision analyzer determines the adjustment strategy of the cryptographic device group and transmits the adjustment strategy to the cryptographic device group.
[0145] On the other hand, the structure of the cryptographic device group is as follows: Figure 7 As shown, it includes structures such as device selector, decision executor, dynamic forwarding configuration library, and dynamic forwarder.
[0146] The device selector receives the target data stream from the receive queue and then transmits it to the dynamic forwarder. The decision executor receives the adjustment policy from the generator and transmits the adjustment policy to the dynamic forwarding configuration library. The dynamic forwarding configuration library adjusts the number of cryptographic devices connected based on the adjustment policy.
[0147] For example, after receiving the adjustment policy from the generator, the decision executor can convert the adjustment policy into the corresponding enumeration value (Add, Delete, Keep), and then forward the enumeration value to the dynamic configuration library for related operations on password resource configuration.
[0148] When the enumeration value is Add, the original cryptographic device resources remain unchanged. Then, the addresses of the newly added working cryptographic device resources are filled into the dynamic configuration library. When the configuration file is saved, the dynamic forwarder is triggered to load the latest configuration into memory and perform the forwarding operation of the target data stream.
[0149] When the enumeration value is Delete, the existing cryptographic device resources need to be reduced. The decision executor will use a random strategy to reduce the cryptographic device resources in the configuration file. Each decision result only affects one record. When the cryptographic device resource configuration file is saved, it will trigger the dynamic forwarder to load the latest configuration into memory and perform the forwarding operation of the target data stream.
[0150] When the enumeration value is Keep, the cryptographic device resources remain unchanged.
[0151] In this way, the cryptographic server completes the adjustment of the cryptographic device group, and can then provide cryptographic services for the target data stream based on the adjusted cryptographic device group.
[0152] The above describes methods for allocating cryptographic resources, including methods to increase the number of cryptographic devices that can be connected. In practical applications, cryptographic devices may come from multiple manufacturers, leading to inconsistencies in model and manufacturer. This, in turn, results in significant differences in interface implementations across different cryptographic devices. For example, even if cryptographic devices from different manufacturers provide the same data interface, their corresponding data processing specifications may differ. For instance, Manufacturer 1's cryptographic device public key fingerprint generation method is as follows:
[0153] Signature1=Base64(SM3(password));
[0154] Manufacturer 2's cryptographic device public key fingerprint generation method is as follows:
[0155] Signature2=SM3(Base64(password));
[0156] The two services offer different data processing specifications for the public key fingerprint generation function.
[0157] Therefore, this application proposes a compatibility method for different types and manufacturers of equipment.
[0158] In one possible implementation, the data processing specifications corresponding to the cryptographic devices in the cryptographic device group are different. Therefore, this application proposes the following implementation:
[0159] See Figure 8 The above is a flowchart of an encapsulation method proposed in an embodiment of this application. To clarify the specific implementation steps of this method, the following will describe the method by taking a single piece of data to be processed in the target data stream as an example. Figure 8 As shown, the specific implementation steps of this method are as follows:
[0160] Step S801: Obtain the request identifier corresponding to the data to be processed. The request identifier represents the target data processing specification corresponding to the data to be processed.
[0161] Because the cryptographic device group contains cryptographic devices with different data processing specifications, the data to be processed in the target data stream that requires cryptographic services from the cryptographic device group needs to carry a corresponding request identifier to indicate the target data processing specification it expects to use. Furthermore, to ensure the smooth operation of the cryptographic services, different business systems or users using the cryptographic services provided by the cryptographic device group need to consistently specify a data processing specification to ensure the correct execution of encryption, decryption, and verification processes.
[0162] Step S802: Based on the target data processing specification, encapsulate the data to be processed into first data with a target data format corresponding to the target data processing specification.
[0163] Thus, after the server encapsulates the data to be processed into first data, this first data can be distributed to the corresponding cryptographic device based on its corresponding request identifier, that is:
[0164] Step S803: Send the first data to the target cryptographic device corresponding to the target data processing specification, so that the target cryptographic device performs data processing operations on the first data and returns the processing result.
[0165] After the first data is sent to the target cryptographic device, the target cryptographic device can perform corresponding data processing operations on the first data, such as encryption or decryption, data signing or signature verification, etc. This application does not impose any restrictions on this.
[0166] Once the server receives the processing result from the target cryptographic device, it can perform the following operations:
[0167] Step S804: Receive the processing result from the target cryptographic device, encapsulate the processing result into second data with a preset data format, and set a corresponding specification identifier for the second data; wherein, the specification identifier is used to characterize the data processing specification corresponding to the second data.
[0168] After receiving the processing result, the processing result is a processing result with the target data format. However, for a cryptographic device group, it includes multiple data processing specifications, which will include multiple target data formats. However, for business servers or business systems that use cryptographic services provided by cryptographic device groups, they do not expect to obtain data with different data formats when facing cryptographic device groups.
[0169] Therefore, after receiving the processing result, the server will encapsulate the processing result into second data with a preset data format. In this way, the data returned to various business systems will have the same data format, namely the preset data format.
[0170] In this way, from the perspective of upper-layer applications, they are unaware of the multiple data transmission standards existing within the cryptographic device cluster, thus ensuring the consistency and standardization of the cryptographic services used. For example, it can be like... Figure 9 As shown, the above operations are integrated into the device middleware layer. In this way, the target data from the business system will enter the device middleware layer through the device selector, be encapsulated, and then sent to the cryptographic devices corresponding to different data processing specifications. The processing results are then fed back to the device middleware layer, and after unified encapsulation, the second data with a preset data format is obtained. Finally, the processing results are returned to the business system.
[0171] In one possible implementation, the cryptographic devices in the cryptographic device group correspond to different operating systems. Therefore, when creating a cryptographic device group using different cryptographic devices, the following operations need to be performed:
[0172] First, select a cryptographic device as the source cryptographic device, and select a cryptographic device whose operating system is different from the source operating system corresponding to the source cryptographic device as the target cryptographic device.
[0173] Next, obtain the source key data from the source operating system corresponding to the source cryptographic device.
[0174] For cryptographic devices within a group of cryptographic devices, the cryptographic services they provide need to be consistent. Therefore, all cryptographic devices in the group need to have the same key data. To this end, the server can select one cryptographic device as the source cryptographic device and use the key data contained within it as the source key data. Optionally, this source key data can be data pre-set and input into the source cryptographic device by the administrator; this application does not impose any restrictions on this.
[0175] Finally, based on the source key data, the target key data in the target cryptographic device is replaced so that the operating systems of the cryptographic devices in the cryptographic device group have the same source key data.
[0176] By using source key data to replace target key data in other cryptographic devices, all cryptographic devices in the cryptographic device group have the same source key data, thus ensuring consistency in the cryptographic services provided by the cryptographic device group.
[0177] Optionally, the server can perform the replacement of the target cryptographic device in the following ways:
[0178] like Figure 10 As shown, the server first generates the corresponding original image file based on the operating system of the target cryptographic device, then deletes the target key data in it, and adds the source key data to the corresponding address in the original image file, thus obtaining the corresponding target image file.
[0179] Next, the obtained target image file is pushed to the corresponding target cryptographic device to complete the replacement of the key data in the target cryptographic device.
[0180] It should be noted that, since the cryptographic device group may have multiple operating systems, therefore, as Figure 11 As shown, after selecting a cryptographic device corresponding to one operating system as the source cryptographic device, the server needs to perform the above operations separately for other types of cryptographic devices, and then use the source key data to replace the key data of different operating systems.
[0181] Based on the same inventive concept, embodiments of this application also provide an apparatus for allocating cryptographic resources.
[0182] See Figure 12 This is a schematic diagram of the structure of a cryptographic resource allocation device provided in an embodiment of this application. The device may be the aforementioned server or a chip or integrated circuit in the device. The device includes modules / units / technical means for executing the method executed by the server in the above method embodiment.
[0183] For example, the device 1200 includes:
[0184] The acquisition module 1201 is used to continuously acquire the target data stream, wherein the target data stream is provided with cryptographic services by a preset group of cryptographic devices;
[0185] The segmentation module 1202 is used to divide the target data stream into at least two sub-data streams based on a preset time interval; wherein the acquisition time corresponding to the data contained in each sub-data stream is within the same time period, and the time periods corresponding to different sub-data streams are different;
[0186] Processing module 1203 is used to obtain corresponding flow change information based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period; the flow change information represents: the change of the amount of data in the target data stream per unit time over time;
[0187] The adjustment module 1204 is used to adjust the number of access cryptographic devices in the cryptographic device group based on the traffic change information; and to provide cryptographic services for the target data stream based on the adjusted cryptographic device group.
[0188] Optionally, when the processing module 1203 obtains the corresponding flow change information based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period, it is specifically used for:
[0189] Based on the length of the target time period and the amount of data in the target sub-data stream obtained within the target time period, the corresponding target time period traffic is obtained;
[0190] Based on the duration of the adjacent time period and the amount of data in the adjacent sub-data streams obtained within the adjacent time period, the corresponding adjacent time period traffic is obtained.
[0191] Based on the difference between the traffic flow during the target time period and the traffic flow during the adjacent time period, the corresponding traffic change information is obtained.
[0192] Optionally, when the adjustment module 1204 adjusts the number of access cryptographic devices in the cryptographic device group based on the traffic change information, it is specifically used for:
[0193] When the traffic change information indicates an increase in traffic, the resource address of the newly added cryptographic device is obtained, and the resource address is added to the configuration file corresponding to the cryptographic device group to increase the number of cryptographic devices connected in the cryptographic device group.
[0194] When the traffic change information indicates a decrease in traffic, the resource addresses of a preset number of cryptographic devices are deleted from the configuration file corresponding to the cryptographic device group, in order to reduce the number of cryptographic devices connected in the cryptographic device group.
[0195] Optionally, if the data processing specifications of the cryptographic devices in the cryptographic device group are different, then when the adjustment module 1204 provides cryptographic services for the target data stream based on the adjusted cryptographic device group, it is specifically used for:
[0196] For each piece of data to be processed in the target data stream, perform the following operations:
[0197] Obtain the request identifier corresponding to the data to be processed; the request identifier represents the target data processing specification corresponding to the data to be processed.
[0198] Based on the target data processing specification, the data to be processed is encapsulated into first data having a target data format corresponding to the target data processing specification;
[0199] The first data is sent to the target cryptographic device corresponding to the target data processing specification, so that the target cryptographic device performs data processing operations on the first data and returns the processing result.
[0200] The system receives the processing result from the target cryptographic device, encapsulates the processing result into second data with a preset data format, and sets a corresponding specification identifier for the second data; wherein the specification identifier is used to characterize the data processing specification corresponding to the second data.
[0201] Optionally, if the cryptographic devices in the cryptographic device group have different operating systems, then before continuously acquiring the target data stream, the acquisition module 1201 is further configured to:
[0202] Select a cryptographic device as the source cryptographic device, and select a cryptographic device with an operating system different from the source operating system corresponding to the source cryptographic device as the target cryptographic device;
[0203] Obtain the source key data from the source operating system corresponding to the source cryptographic device;
[0204] Based on the source key data, the target key data in the target cryptographic device is replaced so that the operating systems of the cryptographic devices in the cryptographic device group have the same source key data.
[0205] Optionally, when the acquisition module 1201 replaces the target key data in the target cryptographic device based on the source key data, it is specifically used for:
[0206] Based on the operating system of the target cryptographic device, generate the corresponding original image file;
[0207] Delete the target key data from the original image file and add the source key data to the original image file to obtain the corresponding target image file;
[0208] The target image file is pushed to the target cryptographic device.
[0209] As one example, Figure 12 The device described can be used to perform Figure 2 The method described in the illustrated embodiment is therefore relevant to the functions that each functional module of the device can achieve. Figure 2 The description of the embodiments shown will not be repeated here.
[0210] It should be noted that although several modules or sub-modules of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more units described above can be embodied in a single module. Conversely, the features and functions of a module described above can be further divided and embodied by multiple modules.
[0211] As one possible product form of the aforementioned device, see [link to product description]. Figure 13 This application also provides an electronic device 1300, comprising:
[0212] At least one processor 1301; and a communication interface 1303 communicatively connected to the at least one processor 1301; the at least one processor 1301 causes the electronic device 1300 to execute the method steps performed by any device in the above method embodiments through the communication interface 1303 by executing instructions stored in the memory 1302.
[0213] Optionally, the memory 1302 is located outside the electronic device 1300.
[0214] Optionally, the electronic device 1300 includes the memory 1302, which is connected to the at least one processor 1301. The memory 1302 stores instructions that can be executed by the at least one processor 1301. (Appendix) Figure 13 The dashed line indicates that memory 1302 is optional for electronic device 1300.
[0215] The processor 1301 and the memory 1302 can be coupled through an interface circuit or integrated together; no restriction is imposed here.
[0216] This application embodiment does not limit the specific connection medium between the processor 1301, memory 1302, and communication interface 1303. This application embodiment... Figure 13 The processor 1301, memory 1302, and communication interface 1303 are connected via a bus 1304. Figure 13 The connections between other components are shown in bold and are for illustrative purposes only, not as limiting information. The bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 13 The text uses only a single thick line to represent a bus, but this does not imply that there is only one bus or one type of bus. It should be understood that the processor mentioned in the embodiments of this application can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.
[0217] For example, the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0218] It should be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate Synchronous DRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct RAM (DR RAM).
[0219] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0220] It should be noted that the memories described herein are intended to include, but are not limited to, these and any other suitable types of memories.
[0221] As another possible product form, this application embodiment also provides a computer-readable storage medium for storing instructions that, when executed, cause a computer to perform the method steps performed by any of the devices in the above method examples.
[0222] As another possible product form, this application embodiment also provides a computer program product containing instructions, wherein the computer program product stores instructions that, when run on a computer, cause the computer to execute the method steps performed by any device in the above method embodiments.
[0223] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0224] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0225] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0226] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0227] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for allocating cryptographic resources, characterized in that, include: The target data stream is continuously acquired, and the target data stream is provided with cryptographic services by a preset group of cryptographic devices; wherein, the data processing specifications of the cryptographic devices in the group of cryptographic devices are different. Based on a preset time interval, the target data stream is divided into at least two sub-data streams; wherein the acquisition time corresponding to the data contained in each sub-data stream is within the same time period, and the time periods corresponding to different sub-data streams are different; Based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period, the corresponding traffic change information is obtained; the traffic change information represents: the change of the amount of data in the target data stream per unit time over time. Based on the traffic change information, adjust the number of access cryptographic devices in the cryptographic device group; For each piece of data to be processed in the target data stream, perform the following operations: Obtain the request identifier corresponding to the data to be processed; the request identifier represents the target data processing specification corresponding to the data to be processed. Based on the target data processing specification, the data to be processed is encapsulated into first data having a target data format corresponding to the target data processing specification; The first data is sent to the target cryptographic device corresponding to the target data processing specification, so that the target cryptographic device performs data processing operations on the first data and returns the processing result. The system receives the processing result from the target cryptographic device, encapsulates the processing result into second data with a preset data format, and sets a corresponding specification identifier for the second data; wherein the specification identifier is used to characterize the data processing specification corresponding to the second data.
2. The method as described in claim 1, characterized in that, The process of obtaining corresponding traffic change information based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period, includes: Based on the length of the target time period and the amount of data in the target sub-data stream obtained within the target time period, the corresponding target time period traffic is obtained; Based on the duration of the adjacent time period and the amount of data in the adjacent sub-data streams obtained within the adjacent time period, the corresponding adjacent time period traffic is obtained. Based on the difference between the traffic flow during the target time period and the traffic flow during the adjacent time period, the corresponding traffic change information is obtained.
3. The method as described in claim 1 or 2, characterized in that, Adjusting the number of accessing cryptographic devices in the cryptographic device group based on the traffic change information includes: When the traffic change information indicates an increase in traffic, the resource address of the newly added cryptographic device is obtained, and the resource address is added to the configuration file corresponding to the cryptographic device group to increase the number of cryptographic devices connected in the cryptographic device group. When the traffic change information indicates a decrease in traffic, the resource addresses of a preset number of cryptographic devices are deleted from the configuration file corresponding to the cryptographic device group, in order to reduce the number of cryptographic devices connected in the cryptographic device group.
4. The method as described in claim 1 or 2, characterized in that, The cryptographic devices in the group of cryptographic devices correspond to different operating systems; Before continuously acquiring the target data stream, the method further includes: Select a cryptographic device as the source cryptographic device, and select a cryptographic device whose operating system is different from the source operating system corresponding to the source cryptographic device as the target cryptographic device; Obtain the source key data from the source operating system corresponding to the source cryptographic device; Based on the source key data, the target key data in the target cryptographic device is replaced so that the operating systems of the cryptographic devices in the cryptographic device group have the same source key data.
5. The method as described in claim 4, characterized in that, The step of replacing the target key data in the target cryptographic device based on the source key data includes: Based on the operating system of the target cryptographic device, generate the corresponding original image file; Delete the target key data from the original image file and add the source key data to the original image file to obtain the corresponding target image file; The target image file is pushed to the target cryptographic device.
6. An apparatus for allocating cryptographic resources, characterized in that, include: An acquisition module is used to continuously acquire a target data stream, the target data stream being provided with cryptographic services by a preset group of cryptographic devices; wherein, in the group of cryptographic devices, the data processing specifications corresponding to the cryptographic devices are different; The segmentation module is used to divide the target data stream into at least two sub-data streams based on a preset time interval; wherein the acquisition time of the data contained in each sub-data stream is within the same time period, and the time periods corresponding to different sub-data streams are different. The processing module is used to obtain corresponding traffic change information based on the target sub-data stream corresponding to the target time period in which the current time is located, and the adjacent sub-data stream corresponding to the adjacent time period adjacent to the target time period; the traffic change information represents: the change of the amount of data in the target data stream per unit time over time; An adjustment module is used to adjust the number of access cryptographic devices in the cryptographic device group based on the traffic change information; for each piece of data to be processed in the target data stream, the following operations are performed respectively: obtaining the request identifier corresponding to the data to be processed; the request identifier represents the target data processing specification corresponding to the data to be processed; based on the target data processing specification, encapsulating the data to be processed into first data with a target data format corresponding to the target data processing specification; sending the first data to the target cryptographic device corresponding to the target data processing specification, so that the target cryptographic device performs data processing operations on the first data and feeds back the processing result; receiving the processing result from the target cryptographic device, encapsulating the processing result into second data with a preset data format; and setting a corresponding specification identifier for the second data; wherein, the specification identifier is used to represent the data processing specification corresponding to the second data.
7. An electronic device, characterized in that, include: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores instructions executable by the at least one processor, which executes the instructions stored in the memory to perform the method as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store instructions that, when executed, cause the method as described in any one of claims 1-5 to be implemented.
9. A computer program product containing instructions, characterized in that, The computer program product stores instructions that, when run on a computer, cause the computer to perform the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Video Internet of Things high-performance password service method, device and system
CN113179285A
Device for processing electronic data in an access-protected manner
WO2001059548A2