Data Query Method, System, Device, Medium and Program Product

By introducing heterogeneous acceleration computing systems in the data center, using data encryption and decryption cores and query cores of programmable logic devices, the problem of high CPU resource consumption in traditional technology is solved, and safe and efficient data query is achieved.

CN119885247BActive Publication Date: 2025-07-22INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510380650.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-22
Estimated Expiration
2045-03-28

AI Technical Summary

Technical Problem

Traditional software encryption, decryption and accelerated query technology occupy a large amount of CPU resources in the data center, resulting in a decrease in the overall system efficiency and low query efficiency, which cannot meet the requirements of high security and high query efficiency at the same time.

Method used

The heterogeneous acceleration computing system is adopted, and the data encryption and decryption cores and query cores in programmable logic devices are used to realize hardware encryption and decryption and hardware query through the host's software stack scheduling, reducing the resource consumption of the host processor, and completing the data query task through the combination of software and hardware.

Benefits of technology

It realizes safe and efficient data query, reduces the resource consumption of the host processor, improves query efficiency, and is suitable for the high security and efficient query requirements of the data center.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119885247B_ABST
    Figure CN119885247B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data processing, and discloses a data query method, system, device, medium and program product. The method includes: in response to a data query request initiated by a user, determining target data to be queried; the target data is data obtained after encryption processing; obtaining the target data from a data storage device, sending the target data to a programmable logic device, and instructing the programmable logic device to perform decryption processing and query processing on the target data in sequence to obtain a corresponding query result; the programmable logic device includes a data encryption / decryption core for performing decryption processing and a data query core for performing query processing; obtaining the query result from the programmable logic device and returning the query result to the user side. In the present invention, the programmable logic device completes the hardware encryption / decryption task and the hardware query task, and the host only needs to perform scheduling, which greatly reduces the resource consumption of the host processor and can achieve secure and efficient data query.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly to a data query method, system, device, medium and program product. Background Art

[0002] To ensure the security of data in databases such as data centers, data is generally encrypted for storage; when a user queries data, the data is decrypted and queried, thereby completing the user's query task. Traditional data encryption and decryption technologies and accelerated query technologies are generally implemented based on software. Since software encryption and decryption and software accelerated query need to be executed by the CPU (Central Processing Unit), this will consume a large amount of CPU resources, especially when processing large-scale data. The excessive consumption of CPU resources will affect the performance of other applications, resulting in a decline in the overall efficiency of the system. The efficiency of software encryption and decryption and accelerated query is usually low, affecting the query efficiency. Summary of the Invention

[0003] In view of this, the present invention provides a data query method, system, device, medium and program product to solve the problem of low database query efficiency.

[0004] In a first aspect, the present invention provides a data query method applied to a host, including:

[0005] In response to a data query request initiated by a user, determining target data to be queried; the target data is data obtained after encryption processing;

[0006] Obtaining the target data from a data storage device, sending the target data to the programmable logic device, and instructing the programmable logic device to perform decryption processing and query processing on the target data in sequence to obtain a corresponding query result; the programmable logic device includes a data encryption and decryption core for performing decryption processing and a data query core for performing query processing;

[0007] Obtaining the query result from the programmable logic device and returning the query result to the user side.

[0008] In a second aspect, the present invention provides a data query system, including: a host, a data storage device and a programmable logic device; the programmable logic device includes a data encryption and decryption core and a data query core;

[0009] The host is connected to the data storage device and the programmable logic device, and the host is used to execute the data query method according to the first aspect or any corresponding embodiment thereof.

[0010] In a third aspect, the present invention provides a computer device, including: a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the data query method according to the first aspect or any corresponding embodiment thereof.

[0011] In a fourth aspect, the present invention provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the data query method according to the first aspect or any corresponding embodiment thereof.

[0012] In a fifth aspect, the present invention provides a computer program product, including computer instructions, and the computer instructions are used to cause a computer to execute the data query method according to the first aspect or any corresponding embodiment thereof.

[0013] The host in the present invention is configured with a programmable logic device that can implement hardware encryption / decryption and hardware query, forming a heterogeneous acceleration computing system. For a data query request initiated by a user, the host sends the corresponding target data to the programmable logic device, and then the data encryption / decryption core and data query core of the programmable logic device can be used to perform decryption processing and query processing on the target data in sequence, so as to realize the query of encrypted target data. The software stack of the host is used to implement the scheduling of the programmable logic device, and operations such as data writing, decryption, and query are completed successively. The data query task is quickly completed by combining software and hardware. Moreover, the programmable logic device completes the hardware encryption / decryption task and hardware query task, and the host only needs to perform scheduling, which greatly reduces the resource consumption of the host processor and can realize safe and efficient data query. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the related art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the related art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0015] Figure 1 is a schematic structural diagram of a data query system according to an embodiment of the present invention;

[0016] Figure 2 is a schematic process diagram of data transfer according to an embodiment of the present invention;

[0017] Figure 3 is a schematic flow diagram of a data query method according to an embodiment of the present invention;

[0018] Figure 4It is a schematic flowchart of another data query method according to an embodiment of the present invention;

[0019] Figure 5 It is a schematic diagram of the process of encrypting data according to an embodiment of the present invention;

[0020] Figure 6 It is a schematic diagram of the implementation of software and hardware combination between a host and a programmable logic device according to an embodiment of the present invention;

[0021] Figure 7 It is a schematic diagram of data query based on a five - level processing flow according to an embodiment of the present invention;

[0022] Figure 8 It is a schematic diagram of serial scheduling according to an embodiment of the present invention;

[0023] Figure 9 It is a schematic diagram of parallel scheduling based on a five - level processing flow according to an embodiment of the present invention;

[0024] Figure 10 It is a schematic overall flowchart of a data query method according to an embodiment of the present invention;

[0025] Figure 11 It is another schematic structural diagram of a data query system according to an embodiment of the present invention;

[0026] Figure 12 It is a structural block diagram of a data query device according to an embodiment of the present invention;

[0027] Figure 13 It is a schematic hardware structure diagram of a computer device according to an embodiment of the present invention. Detailed implementation manners

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0029] For ease of understanding, first, some terms involved in the embodiments of the present invention are explained.

[0030] Heterogeneous Computing: Heterogeneous computing refers to the utilization of computing resources with various different architectures, processors, or accelerators, combined together to achieve higher performance and efficiency. This approach can enhance the overall system performance by allocating tasks to the devices most suitable for executing them. Heterogeneous computing typically involves integrating different types of processors such as CPUs, GPUs (Graphics Processing Units), and FPGAs (Field Programmable Gate Arrays) to accelerate and optimize various applications.

[0031] Database: A database is a repository that organizes, stores, and manages data according to a certain structure. It is not just a simple collection of files but a complex system that allows users to efficiently insert, query, update, and delete data. The design of a database aims to ensure the security, integrity, and consistency of data.

[0032] Encryption and Decryption: Encryption and decryption refer to the process of protecting or hiding data using cryptographic techniques. Encryption converts the original data into data processed by a specific algorithm, making it difficult to understand or interpret without authorized access. Decryption restores the encrypted data to its original form. Encryption and decryption are commonly used to ensure data confidentiality, integrity, and authentication, preventing unauthorized access and modification. This technology is widely applied in the field of information security, such as data transmission, storage, and communication.

[0033] With the advent of the big data era, the security requirements for data have increased significantly, and the amount of data has also grown exponentially. To protect data security, data encryption technology has become indispensable. To improve the efficiency and speed of querying massive data, the heterogeneous acceleration query technology for databases located in data centers has attracted increasing attention in the industry.

[0034] Regarding data security and data acceleration query technology, traditional techniques can use software methods to encrypt and decrypt data and accelerate database queries. However, this traditional software encryption / decryption and software-accelerated database query method has many disadvantages in the computer systems of data centers. Whether it is software encryption / decryption or software-accelerated database query, they all belong to the category of software acceleration technology and ultimately require the CPU to execute. This will consume a large amount of CPU computing resources in the server and affect other software programs in the system. Additionally, the efficiency of software acceleration technology is generally low, and the acceleration effect is poor.

[0035] Traditional database acceleration queries and encryption / decryption are usually implemented at the software level. The main problems with this method are as follows: 1) Slow processing speed: Database acceleration queries and encryption implemented by software rely on the processing power of the CPU. For large-scale data processing, the performance bottleneck of the CPU will lead to a slower processing speed. 2) High consumption of CPU computing resources: Software implementation requires a large amount of CPU computing resources and memory resources. Especially in a multi-tasking environment, resource competition can easily lead to performance degradation and affect query efficiency.

[0036] To solve the above problems, hardware acceleration technology can be introduced into the database system to implement data encryption / decryption or acceleration queries at the hardware level. Existing hardware solutions mainly include the following: First, hardware encryption / decryption, which has the advantages of fast processing speed and high security, but the disadvantage is that it only focuses on encryption / decryption and does not solve the data query problem for the database. Second, the hardware implementation of database acceleration query technology, which has the advantage of fast query processing speed, but the disadvantage is that it only focuses on the acceleration query of the database and does not solve the data security problem.

[0037] These hardware technologies have solved some problems of querying data to a certain extent, but they cannot meet the requirements of both high security and high query efficiency at the same time. Implementing query acceleration and encryption / decryption calculations simultaneously at the hardware level has become an urgent problem to be solved.

[0038] The data query method provided by the embodiments of the present invention configures a programmable logic device that can implement hardware encryption / decryption and hardware query for the host of the server to build a heterogeneous acceleration computing system; moreover, the software stack of the host realizes the query scheduling of the programmable logic device, and uses a combination of software and hardware to quickly complete the data query task, and the programmable logic device completes the encryption / decryption task and the query task, greatly reducing the resource consumption of the host processor and enabling secure and efficient data query.

[0039] Figure 1 A schematic structural diagram of a data query system is shown, which can implement heterogeneous acceleration operations. As Figure 1 shown, the data query system includes: a host, a data storage device, and a programmable logic device. Among them, the host is connected to the data storage device and the programmable logic device. Moreover, the host can execute the data query method provided by this embodiment to achieve software and hardware collaborative query.

[0040] In this embodiment, as Figure 1As shown, the host is a server host, which can be, for example, an x86 architecture system. The host can be connected to the data storage device through the PCIe (Peripheral Component Interconnect express, a high-speed serial computer expansion bus standard) bus, enabling data transmission between the host and the data storage device. Among them, the data storage device can be a device with a storage function such as a disk, which specifically stores the data in the database.

[0041] Moreover, the host is connected to the programmable logic device through the PCIe bus to achieve data transmission between the two. Among them, the programmable logic device can be, for example, an FPGA, a CPLD (Complex Programmable Logic Device), etc.

[0042] In this embodiment, the programmable logic device includes a data encryption / decryption core and a data query core. Among them, the data encryption / decryption core is an IP (Intellectual Property) core that can implement data encryption and data decryption; the data query core is an IP core that can implement the data query function. It can be understood that the IP cores in programmable logic devices such as FPGAs are essentially a kind of logic circuit, that is, both the data encryption / decryption core and the data query core are hardware logic circuits that implement the corresponding functions, so that tasks such as data encryption / decryption and data query can be completed based on hardware acceleration technology.

[0043] Optionally, to improve data read / write efficiency, data read / write between the host and the data storage device and the programmable logic device is achieved through the DMA (Direct Memory Access) method. As Figure 1 shown, the data storage device and the programmable logic device are provided with corresponding direct memory access engines, that is, DMA engines. For ease of description, the two are respectively referred to as the first direct memory access engine and the second direct memory access engine, that is, the first DMA engine and the second DMA engine.

[0044] Among them, the first DMA engine is used to implement DMA read / write of the data storage device, and the second DMA engine is used to implement DMA read / write of the device memory in the programmable logic device.

[0045] In this embodiment, the data in the database is stored in the data storage device, and the data in the data storage device is sent to the host memory in the read mode of the first DMA engine ( Figure 1In the figure, the squares in the host memory represent the data blocks to be transferred), and then the host transfers the data to the device memory of the programmable logic device in the write mode of the second DMA engine. Similarly, the programmable logic device can also transfer the data after calculation to the host memory on the host side in the read mode of the second DMA engine, and transfer the data to the data storage device in the write mode of the second DMA engine. The process of data transfer can be seen in Figure 2 as shown.

[0046] In this embodiment, a data query method is provided, which can be applied to the above-mentioned host, for example, it can be applied to the processor (CPU) of the host. Figure 3 It is a flowchart of the data query method according to the embodiment of the present invention, as Figure 3 shown, and this process includes the following steps.

[0047] Step S301, in response to a data query request initiated by a user, determine the target data to be queried; the target data is the data obtained after encryption processing.

[0048] In this embodiment, to ensure the security of data, the data stored in the database is encrypted data, that is, the data in the data storage device (such as a disk) is the data after encryption processing.

[0049] When a user needs to query some information in the database, a request to query the database can be initiated, that is, a data query request. The data query request can include a query object, query conditions, etc. The query object is used to represent the data involved in the query operation, that is, the data to be queried. For the convenience of description, the data to be queried is called the target data, that is, the data required by the user needs to be queried from the target data.

[0050] For example, the data query request can include a specified table ID to query, and then the data table corresponding to the table ID can be used as the target data. Among them, since the target data itself is stored in the data storage device, the target data is also the data after encryption processing, that is, the target data needs to be decrypted first before the data query operation can be performed.

[0051] Step S302, obtain the target data from the data storage device, send the target data to the programmable logic device, and instruct the programmable logic device to perform decryption processing and query processing on the target data in sequence to obtain the corresponding query result; the programmable logic device includes a data encryption / decryption core for performing decryption processing and a data query core for performing query processing.

[0052] In this embodiment, for the target data that the user needs to query, the host can obtain the target data from the data storage device and then send the target data to the programmable logic device. As described above, since the target data is encrypted data, the programmable logic device needs to decrypt it first and then perform the query.

[0053] As described above, the programmable logic device includes a data encryption / decryption core and a data query core. To enable the two IP cores (i.e., the data encryption / decryption core and the data query core) to work efficiently in coordination, the host controls the working process of the programmable logic device. Among them, after sending the target data to the programmable logic device, the host instructs the programmable logic device to perform decryption processing and query processing on the target data in sequence.

[0054] Specifically, the host can send a request to the programmable logic device to decrypt the target data, so that the programmable logic device decrypts the target data based on the data encryption / decryption core to obtain the decrypted data corresponding to the target data, and the decrypted data is the plaintext corresponding to the target data. After that, the host sends a request to the programmable logic device to query the target data again, so that the programmable logic device queries the decrypted data corresponding to the target data based on the data query core, and finally obtains the query result corresponding to the target data.

[0055] Step S303: Obtain the query result from the programmable logic device and return the query result to the user side.

[0056] In this embodiment, after the hardware decryption and hardware query are completed using the programmable logic device, the query result of the target data can be obtained. The query result is located on the programmable logic device side, so the host can obtain the query result from the programmable logic device. For example, the host can actively obtain the query result, or after the programmable logic device obtains the query result, it can also be actively sent to the host. This embodiment does not make a limitation on this.

[0057] After the host obtains the query result of the target data, it can return the query result to the user side for the user to view. For example, if the user initiates a data query request based on the client, the host can return the corresponding query result to the client, so that the interface of the client can display the query result to the user.

[0058] The data query method provided in this embodiment is such that the host is configured with a programmable logic device that can implement hardware encryption / decryption and hardware query, forming a heterogeneous acceleration computing system. In response to a data query request initiated by a user, the host sends the corresponding target data to the programmable logic device, and then the data encryption / decryption core and data query core of the programmable logic device can be used to decrypt and query the target data in sequence, thereby realizing the query of encrypted target data. The scheduling of the programmable logic device is implemented using the software stack of the host, and operations such as data writing, decryption, and query are completed successively. The data query task is completed quickly in a combination of software and hardware. Moreover, since the programmable logic device completes the hardware encryption / decryption task and hardware query task, the host only needs to perform scheduling, greatly reducing the resource consumption of the host processor and enabling safe and efficient data query.

[0059] In this embodiment, a data query method is provided, which can be applied to the above-mentioned host, for example, to the processor of the host. Figure 4 It is a flowchart of the data query method according to an embodiment of the present invention, as Figure 4 shown, and this process includes the following steps.

[0060] Step S401, in response to a data query request initiated by a user, determine the target data to be queried; this target data is the data obtained after encryption processing.

[0061] For details, please refer to Figure 3 step S301 of the embodiment shown, which will not be elaborated here.

[0062] In some optional implementation manners, before the above step S401, corresponding data needs to be added to the database, and this data is encrypted. Specifically, this method further includes the following steps A1 to A3.

[0063] Step A1, obtain the original data to be stored.

[0064] Step A2, perform encryption processing on the original data to generate the corresponding encrypted data.

[0065] Specifically, the above step A2 may include the following steps A21 to A22.

[0066] Step A21, send the original data to the programmable logic device.

[0067] Step A22, initiate an encryption request to the programmable logic device to instruct the programmable logic device to encrypt the original data based on the data encryption / decryption core to obtain the corresponding encrypted data, and return the encrypted data to the host.

[0068] Step A3, store the encrypted data in the data storage device.

[0069] In this embodiment, at the initial stage of creating a database or when new data needs to be added to the database subsequently, the original data needs to be encrypted and then written to a data storage device such as a disk.

[0070] Specifically, for the original data to be stored in the data storage device, the host sends the original data to the programmable logic device, and then initiates an encryption request to the programmable logic device, enabling the programmable logic device to encrypt the original data based on the data encryption and decryption core to obtain the ciphertext corresponding to the original data, that is, the encrypted data. Moreover, the host obtains the encrypted data from the programmable logic device and finally stores the encrypted data in the data storage device.

[0071] Among them, data transmission between the host and the programmable logic device can be achieved based on DMA. Figure 5 The schematic diagram of the process of encrypting data is shown, as Figure 5 shown, this process includes steps S501 to S504.

[0072] Step S501, the host writes the original data to the device memory of the programmable logic device through the write mode of the second DMA engine.

[0073] Step S502, the programmable logic device uses the data encryption and decryption core to encrypt the original data to obtain the encrypted data and stores the encrypted data in the local device memory.

[0074] Step S503, through the read mode of the second DMA engine, the encrypted data is written to the host memory.

[0075] Step S504, the host transfers the encrypted data from the host memory to the data storage device through the write mode of the first DMA engine.

[0076] It can be understood that when storing data, the data (the above-mentioned original data) needs to be encrypted to ensure data security; during subsequent queries, the data does not need to be encrypted.

[0077] In this embodiment, by using the data encryption and decryption core of the programmable logic device, hardware encryption of data can be achieved. The host only needs to schedule the work of the programmable logic device and does not need the host to run an encryption algorithm at the software level, avoiding the occupation of the host processing resources.

[0078] Step S402, divide the target data into multiple data blocks.

[0079] Since the target data targeted by the data query request generally has a large data volume and the device memory of the programmable logic device is small, with limited memory space; to improve the query efficiency and reduce the requirements for the device memory of the programmable logic device, in this embodiment, the target data to be queried is divided into multiple data blocks, so that query operations can be performed on each data block respectively, and finally the query result of the entire target data can be obtained.

[0080] Among them, the target data can be divided into N data blocks, where N ≥ 2. The number N of data blocks can be determined based on the actual situation. For example, the size of the data block can be determined based on the processing capacity of the programmable logic device, the size of the device memory space, etc., and then the specific value of N can be determined based on the data volume of the target data.

[0081] Step S403, obtain the target data from the data storage device, send the target data to the programmable logic device, and instruct the programmable logic device to perform decryption processing and query processing on the target data in sequence to obtain the corresponding query result; the programmable logic device includes a data encryption / decryption core for performing decryption processing and a data query core for performing query processing.

[0082] Specifically, as Figure 4 shown, the above step S403 "obtain the target data from the data storage device, send the target data to the programmable logic device, and instruct the programmable logic device to perform decryption processing and query processing on the target data in sequence" includes steps S4031 to S4032.

[0083] Step S4031, obtain a data block from the data storage device in units of data blocks, and send the data block to the programmable logic device.

[0084] In this embodiment, when the host obtains the target data, it obtains the data in units of data blocks, that is, the host obtains a data block from the data storage device; after obtaining the data block, it then sends the data block to the programmable logic device. For other data blocks, they are also processed in the same way until all the data blocks (i.e., the entire target data) are sent to the programmable logic device.

[0085] In some alternative embodiments, the above step S4031 "obtain a data block from the data storage device and send the data block to the programmable logic device" includes steps B1 to B2.

[0086] Step B1, for the target data block among the multiple data blocks, after obtaining the previous data block from the data storage device, obtain the target data block from the data storage device.

[0087] Step B2, after obtaining the target data block, send the target data block to the programmable logic device until all the multiple data blocks are sent to the programmable logic device.

[0088] In this embodiment, when the host reads and writes the target data in the data storage device to the programmable logic device, since the target data is divided into multiple data blocks, and the read and write operations of each data block include at least two steps of read operation and write operation, it is not necessary to wait until one data block is written to the programmable logic device and then perform the read and write operations on the next data block.

[0089] Specifically, if the multiple data blocks are data blocks A, B, and C in sequence, after the host obtains data block A (the previous data block, that is, the data block before the target data block), it can immediately obtain data block B (the target data block) from the data storage device. At this time, the host simultaneously sends data block A to the programmable logic device; then, the host sends data block B to the programmable logic device, and at the same time, the host obtains the next data block C from the data storage device, and so on, so as to more efficiently complete the read and write operations of the target data, which is beneficial to improving the query efficiency.

[0090] In this embodiment, after the host obtains the previous data block, it directly obtains the next target data block from the data storage device, so that the read data block and the write data block can run in parallel, effectively reducing the read and write time of the entire target data, and improving the efficiency of the query operation.

[0091] Optionally, step B1 "obtain the target data block from the data storage device" can specifically include the following steps B11.

[0092] Step B11, initiate a data read request to the data storage device according to the first address information of the target data block in the data storage device; the data read request is used to instruct the first direct memory access engine of the data storage device to read the target data block according to the first address information and write the target data block to the host memory of the host.

[0093] And step B2 "send the target data block to the programmable logic device" can specifically include the following steps B21.

[0094] Step B21, initiate a data write request to the programmable logic device according to the second address information of the target data block in the host memory and the third address information specified in the device memory of the programmable logic device for storing the target data block; the data write request is used to instruct the second direct memory access engine of the programmable logic device to read the target data block according to the second address information and write the target data block to the memory space corresponding to the third address information in the device memory.

[0095] In this embodiment, the host uses the DMA method to realize the reading and writing of each data block. Specifically, after the host determines the target data and divides it into blocks, it can determine the relevant information of each data block. These information include the data block size, the location of the target data in the data storage device, the address offset of each data block, etc. Based on this information, the storage address of each data block in the data storage device can be determined.

[0096] Taking one of the target data blocks as an example, for this target data block, the relevant information of the storage address of this target data block in the data storage device can be determined, that is, the first address information (also called the source address). The host can initiate a data read request (DMA read) to the data storage device based on this first address information. After the first DMA engine of the data storage device obtains this data read request, it can obtain this target data block based on this first address information, and then directly write this target data block into the host's memory, that is, into the host memory. Among them, the data read request can also include the destination address, which indicates which memory space in the host memory the target data block needs to be written into.

[0097] After the data storage device writes the target data block into the host memory, it can initiate an interrupt to the host to indicate that the write operation is completed. After the host obtains the target data block, it can determine the second address information of the target data block in the host memory. This second address information is the host memory address where the first DMA engine writes the target data block; and, the host specifies which memory spaces in the device memory of the programmable logic device store this target data block, that is, the host specifies the address information of the memory space in the device memory that stores the target data block, that is, the third address information, and then initiates a corresponding data write request to the programmable logic device. In this data write request, the second address information represents the source address, and the third address information represents the destination address.

[0098] After the programmable logic device receives this data write request, its second DMA engine can move the data in the source address to the corresponding destination address in its own device memory based on the source address and destination address in this data write request, so as to write the target data block into the memory space corresponding to the third address information in the device memory and complete the write operation of the target data block.

[0099] Similar to the first DMA engine, after the second DMA engine completes the write operation of the target data block, it can also initiate another interrupt to the host, enabling the host to continue to execute subsequent scheduling processing, that is, the host can execute subsequent steps such as S4032.

[0100] In this embodiment, the host schedules the two DMA engines, which can realize the unified management of the data reading and writing process and is conducive to the seamless connection between the reading and writing operations of each data block, that is, immediately read the next data block after reading a data block, ensuring the query efficiency.

[0101] Step S4032: Instruct the programmable logic device to perform decryption processing and query processing on the data blocks in sequence until all data blocks are traversed.

[0102] In this embodiment, for each data block, after writing the data block into the device memory, the host can initiate corresponding decryption requests and query requests to the programmable logic device, enabling the programmable logic device to utilize its own IP core to complete the hardware decryption and hardware query tasks and obtain the query results of each data block; for the convenience of distinction and description, the result obtained after performing query processing on the decrypted data block is called the query sub-result.

[0103] In some alternative embodiments, the above step S4032, "Instruct the programmable logic device to perform decryption processing and query processing on the data blocks in sequence", may specifically include the following steps C1 to C2.

[0104] Step C1: For the target data block among multiple data blocks, after sending the target data block to the programmable logic device, initiate a decryption request corresponding to the target data block to the programmable logic device; the decryption request is used to instruct the programmable logic device to perform decryption processing on the target data block based on the data encryption and decryption to obtain the decrypted sub-data corresponding to the target data block.

[0105] Step C2: After the programmable logic device completes the decryption processing of the target data block, initiate a query request corresponding to the target data block to the programmable logic device; the query request is used to instruct the programmable logic device to perform query processing on the decrypted sub-data corresponding to the target data block based on the data query to obtain the query sub-result of the target data block; the query result includes this query sub-result.

[0106] In this embodiment, after the host sends the target data block to the programmable logic device, it can initiate a decryption request corresponding to the target data block to the programmable logic device; based on this decryption request, the programmable logic device can utilize its own data encryption and decryption to perform decryption processing on the target data block, thereby obtaining the decryption result corresponding to the target data block, that is, the decrypted sub-data.

[0107] Moreover, after the programmable logic device completes the decryption process of the target data block, it can initiate a corresponding interruption to the host, indicating that the decryption process has been completed. Then the host can initiate a query request corresponding to the target data block to the programmable logic device, enabling the programmable logic device to continue using its own data query core to perform query processing on the decrypted sub-data obtained in the previous step, and finally determining the query sub-result of the target data block.

[0108] It can be understood that this query sub-result is only a part of the query result of the entire target data, that is, the query result includes this query sub-result.

[0109] Among them, since the data required by the user may not exist in the target data block, the query sub-result at this time is empty. The programmable logic device can send the empty query sub-result to the host, or send a notification message indicating that the query sub-result is empty to the host, so that the host can determine that the query sub-result of the target data block is empty.

[0110] In this embodiment, the host can simply and conveniently implement the scheduling of the IP core in the programmable logic device by initiating corresponding decryption requests and query requests to the programmable logic device. Moreover, after writing the target data block, the decryption request and query request can be initiated in sequence, enabling the programmable logic device to perform operations such as data writing synchronously while executing hardware decryption and hardware query, which can further improve the query efficiency.

[0111] For example, if multiple data blocks are data blocks A, B, and C in sequence, after writing data block A to the device memory of the programmable logic device, the data encryption and decryption core can decrypt data block A, and at the same time, data block B can be synchronously written to the device memory; after completing the decryption process of data block A, the data query core can perform query processing on the decrypted sub-data of data block A. At the same time, the data encryption and decryption core can decrypt the next data block B, and data block C can also be synchronously written to the device memory, and so on, to realize parallel processing of operations such as data reading, data writing, decryption, and query, which can effectively ensure the overall efficiency of data query.

[0112] Optionally, to ensure that the data query core can perform queries according to user requirements, a corresponding query statement needs to be provided to the programmable logic device; specifically, the method further includes: converting the query statement corresponding to the data query request into a query code stream and sending the query code stream to the programmable logic device; the query request is used to instruct the data query core of the programmable logic device to perform query processing on the decrypted sub-data corresponding to the target data block according to the query code stream to obtain the query sub-result of the target data block.

[0113] In this embodiment, for the query statement corresponding to the data query request, such as an SQL query statement, the query statement is converted into a code stream recognizable by the programmable logic device, that is, a query code stream, and the query code stream is sent to the programmable logic device, so that the programmable logic device can subsequently perform corresponding query operations based on the query code stream. Specifically, the data query core of the programmable logic device can load the query code stream, so as to be able to query and process the decrypted sub-data according to user requirements and obtain the query sub-results required by the user.

[0114] Optionally, the programmable logic device is provided with registers required for query. The host can cooperate with the programmable logic device to complete operations such as hardware decryption and hardware query by adaptively configuring each register.

[0115] In this embodiment, the programmable logic device is provided with a data source address register, which is used to record the data source address, and the data source address is the memory address corresponding to the data that needs to be decrypted and stored in the device memory.

[0116] Among them, the data write request initiated by the host includes a first configuration instruction; the first configuration instruction is used to configure the data source address register of the programmable logic device as a first memory address; the first memory address is the memory address corresponding to the memory space where the target data block is written in the device memory.

[0117] Similarly, the programmable logic device may also be provided with a result address register, which is used to record the memory address of the query sub-result in the device memory after the query process. Among them, the query request initiated by the host includes a second configuration instruction; the second configuration instruction is used to configure the result address register of the programmable logic device as a second memory address; the second memory address is the memory address corresponding to the memory space where the query sub-result is written in the device memory.

[0118] Figure 6 Shows a schematic diagram of the host and the programmable logic device realizing the combination of software and hardware. As Figure 6 shown, after the target data is divided into blocks, for the target data block, the host sends a data read request ( Figure 6 abbreviated as read request in Figure 6 to the data storage device), so as to write the target data block into the host memory; then the host sends a data write request ( abbreviated as write request in

[0119] Among them, the host designates the memory space in the device memory for writing the target data block, that is, the host designates the first memory; and this first memory has a corresponding address in the device memory, that is, the first memory address. The data write request initiated by the host also configures the data source address register of the programmable logic device, and configures this data source address register as the first memory address, that is, the information recorded in the data source address register is the first memory address. When the host subsequently initiates a decryption request to the programmable logic device, the data encryption / decryption core can determine the memory address storing the target data block, that is, the first memory address, by reading this data source address register, and then read the target data block from the first memory address of the device memory and perform decryption processing on this target data block.

[0120] It can be understood that if the data write request includes the above-mentioned third address information, the memory space corresponding to this third address information is the first memory of the device memory, and the memory address corresponding to this third address information is the data source address.

[0121] As Figure 6 shown, after the data encryption / decryption core completes the decryption processing, it can determine the decryption sub-data of the target data block and temporarily store this decryption sub-data in the intermediate memory of the device memory. The host then initiates a query request, enabling the data query core to obtain the decryption sub-data from the intermediate memory and perform query processing on this decryption sub-data to obtain the corresponding query sub-results.

[0122] Moreover, the host designates the storage location of the query sub-results in the device memory, and the host designates to store the query sub-results in the second memory of the device memory. Then the query request initiated by the host also includes the second memory address, and configures the result address register of this programmable logic device as this second memory address; after the data query core obtains the query sub-results, it can read this result address register to determine the second memory address, so as to store the query sub-results in the memory space corresponding to the second memory address, that is, store them in the second memory. When the host subsequently obtains the query sub-results, it can return the data in the second memory to the host.

[0123] In addition, the programmable logic device can also be provided with a code stream address register, which is used to record the address storing the query code stream, generally also the memory address of the device memory. When the data query core performs query processing, it first reads the code stream address register to obtain the address storing the query code stream, and then can read the corresponding query code stream to complete the data query operation.

[0124] In this embodiment, not only data transmission is achieved between the host and the programmable logic device, but the programmable logic device is also provided with a variety of registers such as a code stream address register and a result address register. When the host initiates a request, the corresponding register is configured so that the IP core of the programmable logic device completes the corresponding data decryption and query operations by reading the corresponding register. The host and the programmable logic device work together to ensure efficient transmission of data between the host and the programmable logic device, and safely and efficiently complete the decryption, query and other operations required by the user.

[0125] Step S404, obtaining the query result from the programmable logic device, and returning the query result to the user side.

[0126] For details, please see Figure 3 Step S303 of the illustrated embodiment will not be described in detail here.

[0127] In some optional implementations, the above-mentioned step S404 "obtaining query results from the programmable logic device" may specifically include: for a target data block among multiple data blocks, after the programmable logic device obtains the query sub-result of the target data block, initiating an acquisition request for obtaining the query sub-result to the programmable logic device; the acquisition request is used to instruct the second direct memory access engine of the programmable logic device to write the query sub-result to the host memory of the host.

[0128] In this embodiment, the host actively obtains the query sub-results of each data block, which simplifies the processing function of the programmable logic device. The host schedules the programmable logic device throughout the process, which can achieve efficient collaboration between software and hardware.

[0129] Among them, the process of the second DMA engine of the programmable logic device moving the query sub-result from its own device memory (such as the second memory) to the host memory is similar to the process of the host obtaining the target data block from the data storage device, which is not repeated here.

[0130] Optionally, the kernel layer of the host is provided with: a read scheduling function, a write scheduling function, a decryption scheduling function, a query scheduling function and a result processing function.

[0131] The read scheduling function is used to initiate a data read request to a data storage device to obtain a target data block; the target data block is one of the multiple data blocks.

[0132] The write scheduling function is used to initiate a data write request to the programmable logic device to write a target data block.

[0133] The decryption scheduling function is used to initiate a decryption request to the programmable logic device to perform decryption processing on the target data block, so as to obtain the decrypted sub-data corresponding to the target data block.

[0134] The query scheduling function is used to send a query request to the programmable logic device to query the decrypted sub-data corresponding to the target data block, so as to obtain the query sub-result of the target data block.

[0135] The result processing function is used to send a fetch request to the programmable logic device to obtain the query sub-result.

[0136] In this embodiment, the operating system (e.g., Linux operating system) running on the host is divided into a user layer and a kernel layer. In the application layer, the user can initiate query operations on data files, including data encryption, data decryption, and data query, etc. In the kernel layer, the memory management mechanism is used to manage and allocate the host's memory resources, and then requests such as DMA data transfer are issued. Among them, the scheduling functions for implementing each request are all implemented in the kernel mode, which can reduce system calls and process switches between the kernel mode and the user mode.

[0137] Specifically, when the user initiates a data query request for the database, the data query request enters the kernel layer through a system call; after the kernel layer receives the data query request, it can block the target data to be queried, and then perform subsequent processing on each data block in the kernel layer (kernel mode).

[0138] For the target data block, the host generates a corresponding data read request based on the read scheduling function in the kernel layer and sends it to the data storage device, so as to obtain the target data block in the data storage device. Then the write scheduling function is called to generate a corresponding data write request and send it to the programmable logic device, so as to write the target data into the device memory of the programmable logic device. Then the decryption scheduling function is called to generate a decryption request and send it to the programmable logic device, so as to use the data encryption and decryption core of the programmable logic device to implement hardware decryption and obtain the decrypted sub-data. Then the query scheduling function is called to generate a query request and send it to the programmable logic device, so as to use the data query core of the programmable logic device to implement hardware query and obtain the query sub-result. Finally, the result processing function is called to generate a fetch request to obtain the query sub-result from the programmable logic device.

[0139] Optionally, the method further includes: storing the query result in the cache of the host; in the case of obtaining another data query request for querying the target data later, obtaining and returning the query result from the cache.

[0140] In this embodiment, after the host obtains the query result, it temporarily stores the query result in the cache of the host. Thus, when the user or other users query the same target data again later, the host can directly obtain the query result from the cache without using the programmable logic device for heterogeneous computing, which is convenient for the next query.

[0141] For example, the host transfers each query sub-result from the device memory on the programmable logic device side to the cache of the host-side operating system for caching, thereby achieving caching of the entire query result. When the user queries the same data next time, the query result can be directly obtained from the cache without performing operations such as heterogeneous computing, improving the efficiency of the next query. When the host shuts down, the cache space is insufficient, or the caching duration of the query result has reached the preset duration, the query result in the cache can be cleared.

[0142] In some alternative embodiments, to enable parallel processing, the host sets up multiple levels of processing streams that can run in parallel. Specifically, the process shown in steps S4031 to S4032 above, that is, taking data blocks as units, obtaining data blocks from the data storage device, sending the data blocks to the programmable logic device, and instructing the programmable logic device to perform decryption processing and query processing on the data blocks in sequence until all data blocks are traversed, may specifically include the following steps D1.

[0143] Step D1: Process M data blocks respectively according to the pre-configured M-level processing stream.

[0144] Among them, the k-th level of processing stream is specifically used to execute the following steps D11 to D14.

[0145] Step D11: After the (k - 1)-th level of processing stream obtains the (M×i + k - 1)-th data block from the data storage device, obtain the (M×i + k)-th data block from the data storage device; k = 1, 2, …, M, and i is the loop count of the processing stream. Among them, i is an integer between 0 and (N - M) / M, and N is the number of data blocks.

[0146] Step D12: Send the (M×i + k)-th data block to the programmable logic device; among them, when the (M×i + k)-th data block is not the last data block, instruct the (k + 1)-th level of processing stream to obtain the (M×i + k + 1)-th data block from the data storage device.

[0147] Step D13: Instruct the programmable logic device to perform decryption processing on the (M×i + k)-th data block to obtain the decrypted sub-data corresponding to the (M×i + k)-th data block.

[0148] Step D14: Instruct the programmable logic device to perform query processing on the decrypted sub-data corresponding to the (M×i + k)-th data block to obtain the query sub-result corresponding to the (M×i + k)-th data block.

[0149] In this embodiment, the host pre-configures the M-level processing stream, and partial tasks between each level of processing stream are interleaved for parallel processing of different tasks, thereby being able to reduce the data processing duration and improve the overall query efficiency.

[0150] Among them, the M-level processing flow of this embodiment completes the processing of all data blocks through one or more rounds of processing. Specifically, from the first-level processing flow to the M-level processing flow, the first data block to the Mth data block are processed in sequence first; then, from the first-level processing flow to the M-level processing flow, the (M + 1)th data block to the 2Mth data block are processed in sequence, and so on in a loop until the processing of all data blocks is completed.

[0151] It can be understood that for the i-th loop count, from the first-level processing flow to the M-level processing flow, the (M×i + 1)th data block to the (M×i + M)th data block are processed respectively; correspondingly, for the k-th processing flow (k is the index of the processing flow, and k = 1, 2,..., M), it specifically processes the (M×i + k)th data block.

[0152] In this embodiment, if there is a processing task in the (k - 1)-th processing flow, then for the k-th processing flow, after the (k - 1)-th processing flow obtains the corresponding data block (the (M×i + k - 1)th data block) from the data storage device, the k-th processing flow can initiate a data read request to obtain the (M×i + k)th data block from the data storage device. For the data storage device, it can continuously send each data block to the host to ensure that the host quickly reads the complete target data.

[0153] Moreover, after the k-th processing flow obtains the (M×i + k)th data block, it will send the (M×i + k)th data block to the programmable logic device based on the data write request. At the same time, if the (M×i + k)th data block is not the last data block at this time, that is, there are still unread data blocks, then the (k + 1)-th processing flow also starts to obtain the corresponding data block from the data storage device, that is, the (M×i + k + 1)th data block; it can be understood that if k = M, then the (k + 1)-th processing flow is the first-level processing flow. Similarly, if k = 1, then the (k - 1)-th processing flow is the M-level processing flow.

[0154] After that, the k-th processing flow sequentially initiates a decryption request for decrypting the (M×i + k)th data block and a query request for query processing to the programmable logic device, and finally the query sub-result corresponding to the (M×i + k)th data block can be obtained.

[0155] Among them, the processing speeds of the data encryption / decryption core and the data query core of the programmable logic device are relatively fast, and the data encryption / decryption core and the data query core can also perform parallel processing based on their own hardware logic circuits. For example, for parallel decryption processing of a certain data block, hardware decryption and hardware query can be quickly realized, and the time consumption is generally shorter than that of data reading and data writing. Therefore, for the k-th level processing stream, when it sends the (M×i + k)-th data block to the programmable logic device, it can be understood as initiating a corresponding decryption request; or, after the (k + 1)-th level processing stream (if it exists) obtains the (M×i + k + 1)-th data block, the k-th level processing stream can initiate a decryption request for the (M×i + k)-th data block. This embodiment does not make any limitation on this.

[0156] In this embodiment, the query process of the data block mainly includes five tasks: data reading, data writing, decryption, query, and result processing. Therefore, five-level processing streams can be set for cyclic processing to achieve parallel query, that is, M = 5. Currently, M can also be greater than 5, and this embodiment does not limit the specific value of M. In this embodiment, M threads can be set, each thread corresponding to one level of the processing stream to execute the above five tasks; or, 5 threads can also be set, each thread executing a unique task. Taking the thread for data reading as an example, after this thread completes the read request for a certain data block, it can continue to make a read request for the next data block, and so on until all data blocks are read.

[0157] Taking M = 5 as an example, the k-th level processing stream is used to process the (5i + k)-th data block. Figure 7 Fig. shows a schematic diagram of data query based on five-level processing streams.

[0158] As Figure 7 shown, the entire data query system is divided into three layers: the user layer, the kernel layer, and the device layer, where the user layer and the kernel layer are two different layers in the host-side operating system. The device layer corresponds to two devices, namely a data storage device (such as a disk) and a programmable logic device (such as an FPGA accelerator board), and both of these devices are mounted to the host. The programmable logic device in the device layer internally includes a data encryption / decryption core, a data query core, device memory, etc. Among them, the data encryption / decryption core and the data query core are logic circuits for data acceleration calculation, and their function is to offload the encryption / decryption algorithm and the data query algorithm to hardware, that is, to implement the encryption / decryption algorithm and the data query algorithm using hardware.

[0159] The host software stack adopts a five - level processing flow form, which can improve the parallel scheduling ability at the system software level, so as to adapt to the data processing throughput rate of the programmable logic device for parallel computing. For each level of the processing flow, five scheduling tasks, namely data reading from the data storage device, data writing to the programmable logic device, data decryption, data query, and result processing, are respectively carried out, and each scheduling task can be implemented based on the corresponding scheduling function in the kernel layer.

[0160] Specifically, when the user initiates a data query request, the data query request enters the kernel layer through a system call. After the kernel receives the data query request, it divides the target data to be queried into task blocks to determine each data block, for example, data block 1, data block 2,..., data block N, etc.; each data block corresponds to a corresponding task block, and the information of the task block can describe the relevant information of the data block. Generally, the target data is a file in the database, and the task block information can specifically include: the size of the data block to be processed, the file information of the database (file size, file location, file offset, etc.), the code stream of the data SQL query statement, data block id, task block id, and other information.

[0161] When the first - level processing line of the five - level processing line receives task block 1, it can start to sequentially execute data reading, data writing, data decryption, data query, and result processing for the corresponding data block 1. And, according to the characteristics of the processing line, the data reading of the second - level processing line and the data writing of the first - level processing line can be at the same time, that is, when the first - level processing line is writing data, the second - level processing line starts to read the data of data block 2 at the same time... and so on.

[0162] Among them, as Figure 7 shown, the data block ids corresponding to each level of the five - level processing line are 5i + 1, 5i + 2, 5i + 3, 5i + 4, 5i + 5 respectively, where i represents the loop count of task distribution, and its value range is from 0 to (n - 5) / 5. After each time the tasks are distributed to the fifth - level processing line, the value of i will increase by 1. When each level of the processing line is completed, the result will be transferred from the device memory of the programmable logic device to the cache of the host - side operating system for caching to facilitate the next query.

[0163] If the serial system call method is adopted, it will consume more time, which will cause a large delay and reduce the overall system performance. Taking the example of processing 5 data blocks (i.e., N = 5) Figure 8 shows a schematic diagram of serial scheduling, Figure 9 shows a schematic diagram of parallel scheduling based on the five - level processing flow, and its horizontal axis represents the time axis.

[0164] As Figure 8As shown, if a serial scheduling method is adopted, it takes 25 cycle units to complete the processing of five data blocks through five rounds of scheduling, while only 9 cycle units are consumed if the five-stage processing line of this embodiment is adopted. This greatly reduces the latency and can improve the overall system performance.

[0165] Figure 10 Fig. shows a schematic flow diagram for implementing data hardware decryption and query based on heterogeneous computing. As Figure 10 shown, this process includes the following steps.

[0166] Step S1001, the user initiates a data query request.

[0167] Step S1002, the operating system kernel layer receives the data query request.

[0168] Step S1003, the kernel layer chunking mechanism divides the database file to be queried into N equally sized task chunks. Each task chunk corresponds to a corresponding data chunk, and its relevant information includes the size of the data chunk to be processed, file information of the database (file size, file offset, etc.), code stream of the database query statement, data chunk id, task chunk id, etc.

[0169] Step S1004, allocate each task chunk to the five-stage processing line software stack.

[0170] Among them, a for loop mechanism can be used to allocate task chunk information to the five-stage processing line software stack. As Figure 10 shown, the processing process of each stage of the processing line includes:

[0171] (1) Start disk DMA to read and transfer data to the host DDR (Double Data Rate) memory. That is, read the corresponding data chunk to the host memory based on the first DMA engine.

[0172] (2) Start device DMA to write data from the host DDR memory to the FPGA. Device DMA represents the second DMA engine, and writes the corresponding data chunk into the device memory of the FPGA.

[0173] (3) The FPGA receives the data chunk and performs decryption operations.

[0174] (4) Send the query code stream corresponding to the data query request to the FPGA. The FPGA performs data query operations on the decrypted data chunk based on the query code stream.

[0175] Among them, the FPGA can send the query code stream only once, and the FPGA can directly call it later.

[0176] (5) Process the query result and send the query result to the cache of the host-side kernel layer.

[0177] The purpose of caching the query results is that when the same data is queried next time, there is no need to go through the FPGA-accelerated query again, and the results can be directly obtained from the cache.

[0178] Step S1005: Determine whether there are still unprocessed data blocks. If so, re-execute step S1004; otherwise, execute step S1006.

[0179] It should be noted that whenever a primary processing line completes the corresponding task block, step S1005 can be executed. If there are unprocessed data blocks, the next data block can be scheduled. After all the scheduling of the five-level processing line is completed, for example, when i is greater than (N - 5) / 5, it can be determined that the query of all data blocks has been completed.

[0180] Step S1006: The user obtains the query results in the cache. The process ends.

[0181] The data query method provided in this embodiment enables the host to schedule the hardware functions of the programmable logic device, simultaneously realizing hardware encryption / decryption and hardware query in a heterogeneous computing environment. Without occupying the host processing resources, it realizes secure and efficient query tasks. By designing a task block mechanism and a five-level processing line software stack at the kernel layer, tasks such as reading data, writing data, data decryption, data query, and result processing are successively called, realizing efficient collaborative parallel invocation of software and hardware, and greatly improving the computing throughput rate of the heterogeneous acceleration system. This method improves the performance and security of data processing, and is especially suitable for fields with extremely high requirements for data security, such as government departments, financial institutions, and other industries involving sensitive information processing, thus helping these institutions improve the work efficiency of relevant operations and ensuring the security and compliance during data transmission, and has broad application prospects.

[0182] This embodiment also provides a data query system, which includes: a host, a data storage device, and a programmable logic device. Among them, the host is connected to the data storage device and the programmable logic device. And the host can execute the data query method provided in this embodiment to realize software and hardware collaborative query. The structural schematic diagram of this data query system can be seen Figure 1 as shown.

[0183] Figure 11 shows the heterogeneous structural schematic diagram of the data query system. Among them, the data storage device (such as a disk) and the programmable logic device (such as an FPGA accelerator board) are both connected to the server host through the PCIe bus. The programmable logic device internally contains multiple key modules, such as DMA-IP, data encryption / decryption IP, data query IP, memory controller, and device memory, etc. Among them:

[0184] The DMA-IP is responsible for performing DMA read and write data transfers on the PCIe bus. The data encryption and decryption IP is responsible for the encryption and decryption operations of the data. The data query IP is responsible for implementing the accelerated query of data files. The memory controller is used to manage and control the device memory, such as implementing the staging of encrypted and decrypted data, query results after database filtering, etc.

[0185] Among them, the operating system running on the server host can be divided into a kernel layer and an application layer. In the application layer, the user can initiate a query operation on the data file; in the kernel layer, the memory management mechanism is used to manage and allocate memory resources, and then issue DMA data transfers and call the software stack workflow. In addition, the driver in the kernel layer is responsible for managing various devices, which can include a disk DMA driver for driving the first DMA engine and a device DMA driver for driving the second DMA engine.

[0186] In this embodiment, the device DMA driver not only realizes the DMA data transfer between the host side and the FPGA memory, but also realizes the database acceleration driver. The realization of the database acceleration driver is mainly based on adding a bitstream address register configuration, a result address register configuration, a data source address register, etc. on the basis of the device DMA driver. These components cooperate together to ensure the efficient transfer of data between the disk and the FPGA, and complete the decryption, query, result processing and other operations required by the user.

[0187] In this embodiment, a data query device is also provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0188] This embodiment provides a data query device, which is applied to a host, as Figure 12 shown, including:

[0189] A request module 1201, configured to determine target data to be queried in response to a data query request initiated by a user; the target data is data obtained after encryption processing;

[0190] A scheduling and processing module 1202, configured to obtain the target data from a data storage device, send the target data to the programmable logic device, and instruct the programmable logic device to perform decryption processing and query processing on the target data in sequence to obtain a corresponding query result; the programmable logic device includes a data encryption and decryption core for performing decryption processing and a data query core for performing query processing;

[0191] An output module 1203, configured to obtain the query result from the programmable logic device and return the query result to the user side.

[0192] In some alternative embodiments, after determining the target data to be queried, the scheduling and processing module 1202 is further configured to: divide the target data into multiple data blocks;

[0193] The scheduling and processing module 1202 obtains the target data from a data storage device, sends the target data to the programmable logic device, and instructs the programmable logic device to perform decryption processing and query processing on the target data in sequence, including: taking the data blocks as units, obtaining the data blocks from the data storage device, sending the data blocks to the programmable logic device, and instructing the programmable logic device to perform decryption processing and query processing on the data blocks in sequence until all the data blocks are traversed.

[0194] In some alternative embodiments, the scheduling and processing module 1202 obtains the data block from the data storage device and sends the data block to the programmable logic device, including: for a target data block among the multiple data blocks, after obtaining the previous data block from the data storage device, obtaining the target data block from the data storage device; after obtaining the target data block, sending the target data block to the programmable logic device until all the multiple data blocks are sent to the programmable logic device.

[0195] In some alternative embodiments, the scheduling and processing module 1202 takes the data blocks as units, obtains the data blocks from the data storage device, sends the data blocks to the programmable logic device, and instructs the programmable logic device to perform decryption processing and query processing on the data blocks in sequence until all the data blocks are traversed, including:

[0196] Processing M data blocks respectively according to a pre-configured M-level processing flow;

[0197] Wherein, the k-th level processing flow is used for:

[0198] After the (k - 1)-th level processing flow obtains the (M×i + k - 1)-th data block from the data storage device, obtaining the (M×i + k)-th data block from the data storage device; k = 1, 2, …, M, and i is the loop count of the processing flow;

[0199] Sending the (M×i + k)-th data block to the programmable logic device; wherein, when the (M×i + k)-th data block is not the last data block, instructing the (k + 1)-th level processing flow to obtain the (M×i + k + 1)-th data block from the data storage device;

[0200] instruct the programmable logic device to perform decryption processing on the (M×i + k)-th data block to obtain decrypted sub-data corresponding to the (M×i + k)-th data block;

[0201] instruct the programmable logic device to perform query processing on the decrypted sub-data corresponding to the (M×i + k)-th data block to obtain a query sub-result corresponding to the (M×i + k)-th data block.

[0202] The further function descriptions of the above various modules and units are the same as those in the corresponding foregoing embodiments, and will not be elaborated herein.

[0203] An embodiment of the present invention further provides a computer device. Please refer to Figure 13 , Figure 13 which is a schematic structural diagram of a computer device provided by an optional embodiment of the present invention. As shown in Figure 13 , the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including a high-speed interface and a low-speed interface. Each component communicates with each other using different buses and can be installed on a common main board or installed in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (such as an array of servers, a set of blade servers, or a multi-processor system). Figure 13 In

[0204] , one processor 10 is taken as an example.

[0205] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the foregoing embodiments.

[0206] The memory 20 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the computer device, etc. In addition, the memory 20 may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some alternative embodiments, the memory 20 may optionally include a memory remotely provided relative to the processor 10, and these remote memories can be connected to the computer device through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0207] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, a hard disk, or a solid-state drive; the memory 20 may further include a combination of the above types of memory.

[0208] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0209] Embodiments of the present invention also provide a computer-readable storage medium. The methods according to the embodiments of the present invention can be implemented in hardware, firmware, or be implemented as computer code that can be recorded on a storage medium, or be implemented as computer code originally stored in a remote storage medium or a non-transitory machine-readable storage medium and downloaded through a network and to be stored in a local storage medium, so that the methods described herein can be stored in such software processes on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc.; further, the storage medium can also include a combination of the above types of memory. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code, and when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the methods shown in the above embodiments are implemented.

[0210] A part of the present invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the present invention through the operations of the computer. Those skilled in the art should understand that the forms of existence of computer program instructions in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways for a computer to execute computer program instructions include, but are not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Herein, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.

[0211] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations should all be covered within the protection scope of the present invention.

Claims

1. A data query method, characterized in that, Applied to a host, the method includes: In response to a data query request initiated by a user, determining target data to be queried; the target data is data obtained after encryption processing; Dividing the target data into multiple data blocks; Taking the data blocks as units, obtaining the data blocks from a data storage device, sending the data blocks to a programmable logic device, and instructing the programmable logic device to perform decryption processing and query processing on the data blocks in sequence until all the data blocks are traversed to obtain corresponding query results; the programmable logic device includes a data encryption / decryption core for performing decryption processing and a data query core for performing query processing; Obtaining the query results from the programmable logic device and returning the query results to the user side; Among them, the process of processing each of the data blocks in units of data blocks includes: Processing M data blocks respectively according to a pre-configured M-level processing stream; Among them, the k-th level processing stream is used for: After the (k - 1)-th level processing stream obtains the (M×i + k - 1)-th data block from the data storage device, obtaining the (M×i + k)-th data block from the data storage device; k = 1, 2, …, M, and i is the loop count of the processing stream; Sending the (M×i + k)-th data block to the programmable logic device; among them, when the (M×i + k)-th data block is not the last data block, instructing the (k + 1)-th level processing stream to obtain the (M×i + k + 1)-th data block from the data storage device; Instructing the programmable logic device to perform decryption processing on the (M×i + k)-th data block to obtain decrypted sub-data corresponding to the (M×i + k)-th data block; Instructing the programmable logic device to perform query processing on the decrypted sub-data corresponding to the (M×i + k)-th data block to obtain query sub-results corresponding to the (M×i + k)-th data block.

2. The method according to claim 1, characterized in that, The obtaining the data blocks from the data storage device and sending the data blocks to the programmable logic device includes: For a target data block among the multiple data blocks, after obtaining the previous data block from the data storage device, obtaining the target data block from the data storage device; After obtaining the target data block, sending the target data block to the programmable logic device until all the multiple data blocks are sent to the programmable logic device.

3. The method according to claim 2, wherein The obtaining the target data block from the data storage device includes: According to the first address information of the target data block in the data storage device, initiating a data read request to the data storage device; the data read request is used to instruct a first direct memory access engine of the data storage device to read the target data block according to the first address information and write the target data block into the host memory of the host; The sending the target data block to the programmable logic device includes: Initiate a data write request to the programmable logic device according to the second address information of the target data block in the host memory and the third address information specified in the device memory of the programmable logic device for storing the target data block; the data write request is used to instruct the second direct memory access engine of the programmable logic device to read the target data block according to the second address information and write the target data block into the memory space corresponding to the third address information in the device memory.

4. The method according to claim 1, wherein The instructing the programmable logic device to perform decryption processing and query processing on the data block in sequence includes: For the target data block among the multiple data blocks, after sending the target data block to the programmable logic device, initiate a decryption request corresponding to the target data block to the programmable logic device; the decryption request is used to instruct the programmable logic device to perform decryption processing on the target data block based on the data encryption and decryption to obtain the decryption sub-data corresponding to the target data block. After the programmable logic device completes the decryption processing of the target data block, initiate a query request corresponding to the target data block to the programmable logic device; the query request is used to instruct the programmable logic device to perform query processing on the decryption sub-data corresponding to the target data block based on the data query to obtain the query sub-result of the target data block; the query result includes the query sub-result.

5. The method according to claim 4, characterized in that, It further includes: Convert the query statement corresponding to the data query request into a query code stream and send the query code stream to the programmable logic device. The query request is used to instruct the data query core of the programmable logic device to perform query processing on the decryption sub-data corresponding to the target data block according to the query code stream to obtain the query sub-result of the target data block.

6. The method according to claim 1, characterized in that, The obtaining the query result from the programmable logic device includes: For the target data block among the multiple data blocks, after the programmable logic device obtains the query sub-result of the target data block, initiate an acquisition request for acquiring the query sub-result to the programmable logic device; the acquisition request is used to instruct the second direct memory access engine of the programmable logic device to write the query sub-result into the host memory of the host.

7. The method according to claim 1, characterized in that, The kernel layer of the host is provided with: a read scheduling function, a write scheduling function, a decryption scheduling function, a query scheduling function, and a result processing function. The read scheduling function is used to initiate a data read request for acquiring a target data block to the data storage device; the target data block is one of the multiple data blocks. The write scheduling function is used to initiate a data write request for writing the target data block to the programmable logic device. The decryption scheduling function is used to initiate a decryption request for performing decryption processing on the target data block to the programmable logic device to obtain the decryption sub-data corresponding to the target data block. The query scheduling function is used to send a query request to the programmable logic device to query the decrypted sub-data corresponding to the target data block, so as to obtain a query sub-result of the target data block; The result processing function is used to send an acquisition request to the programmable logic device to acquire the query sub-result.

8. The method according to claim 1, characterized in that, The method further includes: Storing the query result in the cache of the host; When another data query request for querying the target data is obtained later, acquiring and returning the query result from the cache.

9. The method according to claim 1, wherein The method further includes: Acquiring the original data to be stored; Sending the original data to the programmable logic device; Sending an encryption request to the programmable logic device to instruct the programmable logic device to encrypt the original data based on the data encryption and decryption check to obtain corresponding encrypted data, and returning the encrypted data to the host; Storing the encrypted data in the data storage device.

10. A data query system, characterized in that, Including: A host, a data storage device, and a programmable logic device; the programmable logic device includes a data encryption and decryption core and a data query core; The host is connected to the data storage device and the programmable logic device, and the host is used to execute the data query method according to any one of claims 1 to 9.

11. A computer device, characterized in that, Including: A memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the data query method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, Computer instructions are stored on the computer-readable storage medium, and the computer instructions are used to cause a computer to execute the data query method according to any one of claims 1 to 9.

13. A computer program product, characterized in that, Including computer instructions, the computer instructions are used to cause a computer to execute the data query method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Data processing method and system for aggregation function in grouping query

    CN107122490A

  • Cloud database management architecture and accelerated query method

    CN116226180A