Cipher coprocessor virtualization method and system based on VFIO-MDEV
Through the virtualization method of VFIO-MDEV, the cloud computing encryption computing has been solved, with low performance, high resource utilization and high cost, flexible resource configuration and efficient encryption computing have been realized, and the resource utilization and security of the cloud platform have been improved.
Patent Information
- Application Number
- CN202510222360.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing cloud computing encryption computing solutions have problems such as low performance, high resource usage, high cost, inflexible resource allocation, and inability to meet the needs of efficient and secure encryption computing.
The virtualization method of cryptographic coprocessor based on VFIO-MDEV is adopted to obtain virtual device configuration requests through the hyper-converged cloud platform, and the virtual devices are allocated to the virtual machine using the MDEV framework and the VIFO framework, and the encryption tasks are performed through the Haiguang password coprocessor to achieve flexible resource configuration and hardware acceleration.
It improves the accuracy and flexibility of resource allocation, improves the performance and efficiency of encryption computing, ensures the stability and security of the system, reduces hardware costs, and is suitable for high security and high performance application scenarios.
Smart Images

Figure CN120104254A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing technology, and in particular to a cryptographic coprocessor virtualization method, system, device and storage medium based on VFIO-MDEV. Background Art
[0002] With the booming development of cloud computing, virtualization technology, as one of the core supporting technologies of cloud computing, plays a vital role. It abstracts and divides physical resources so that resources can be flexibly allocated and managed between virtual machines, greatly improving resource utilization and system flexibility. In a cloud computing environment, virtual machines undertake a variety of computing tasks, among which encryption computing tasks are crucial for data security and privacy protection. With the continuous growth of data volume and the increasing requirements for data security, the demand for high-performance hardware resources to support encryption computing by virtual machines has become more urgent.
[0003] At present, the existing technology mainly adopts the following two representative solutions: Software simulation solution: It mainly relies on software algorithms to simulate the encryption calculation process. It implements the logic of the encryption algorithm at the software level and does not require specific hardware support. However, the performance of this solution is relatively low. When facing large-scale encryption calculation tasks, it is difficult to meet the requirements of real-time and high throughput due to the execution efficiency limitations of the software algorithm. And when performing encryption calculations, the software simulation solution will occupy a large amount of CPU resources. This will cause the execution of other computing tasks to be affected while the virtual machine is performing encryption calculation tasks, and the execution speed of tasks may slow down or even freeze, reducing the overall computing efficiency of the virtual machine. External independent encryption card solution: With the fisherman encryption card as a typical representative, this solution realizes hardware-accelerated encryption computing capabilities by inserting an independent encryption card on the server. This encryption card is usually equipped with a dedicated encryption chip and processing unit, which can efficiently execute encryption algorithms. Compared with the software simulation solution, it has obvious performance advantages and can greatly improve the speed and efficiency of encryption calculations. Moreover, this solution is relatively flexible and does not depend on whether the processor itself supports encryption functions. Even if the server's processor does not have strong encryption capabilities, high-performance encryption calculations can be achieved by inserting an encryption card. However, this solution will occupy additional PCI card slots of the server. In some servers, the number of PCI card slots is limited, which limits the expansion possibilities of other hardware devices (such as high-performance network cards, additional storage expansion cards, etc.), affecting the overall scalability of the server. Secondly, users need to pay extra for encryption cards. As a specialized hardware device, the procurement cost of encryption cards is relatively high, which undoubtedly increases the overall hardware cost. For some cost-sensitive cloud computing service providers, this is an issue that cannot be ignored.
[0004] In addition to the shortcomings of the above two solutions, the existing solutions also have obvious deficiencies in resource management and allocation. In cloud environments, resource requirements change dynamically, and different application scenarios and user needs may cause the demand for cryptographic computing resources to fluctuate greatly in a short period of time. However, it is difficult for existing solutions to adjust resource allocation in a timely and flexible manner according to these changes, resulting in low resource utilization. The existence of these problems has resulted in the urgent need to achieve efficient and secure cryptographic computing on cloud platforms not being met. As data security becomes increasingly important, the inability to provide efficient cryptographic computing capabilities will seriously limit the development potential of cloud computing services in data processing and security. Summary of the invention
[0005] The purpose of the present invention is to solve the shortcomings of the prior art and provide a cryptographic coprocessor virtualization method based on VFIO-MDEV, comprising the following steps: S1: The hyper-converged cloud platform obtains a virtual device configuration request, the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, wherein the virtual machine device request includes information such as the number of CPU cores, memory size, and virtual device type; S2: The virtual machine sends the task request to the physical device driver according to the VIFO framework, and the physical device driver receives the task request and sends it to the Haiguang cryptographic coprocessor; S3: The Haiguang cryptographic coprocessor executes the task request and returns the task result to the physical device driver, the physical device driver returns the task result to the virtual machine, and the virtual machine returns the task result to the hyper-converged cloud platform.
[0006] Preferably, it is characterized in that, in step S1, the hyper-converged cloud platform obtains a virtual device configuration request, comprising the following steps: S111: The hyper-converged platform receives the task request including data encryption, data decryption, and digital signature verification; S112: Calculating available resources including computing resources, storage resources and network resources for the parsed task request, wherein the computing resources include information including the number of CPU cores and memory size, the storage resources include information including virtual device size and virtual device type, and the network resources include information including network bandwidth and IP address; S113: Obtain the virtual device request according to the available resources.
[0007] Preferably, in step S1, the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, including: S121: The MDEV framework monitors and parses the virtual device configuration request; S122: The MDEV framework calls the VFIO interface provided by the physical device driver to send a virtual device creation instruction according to the virtual device configuration request; S123: The physical device driver divides the resource area according to the virtual device in the Haiguang cryptographic coprocessor instruction, and allocates the virtual device to the virtual machine according to the VIFO framework, and the MDEV framework initializes each of the virtual devices.
[0008] Preferably, in step S123, allocating the virtual device to the virtual machine according to the VIFO framework further includes: The VFIO framework obtains virtual device information from the MDEV framework, wherein the virtual device information includes information including a virtual device ID, a virtual device name, and a current device status, wherein the current device status is determined according to a scheduled task mechanism; The VFIO framework obtains the running state of the virtual machine, and allocates the virtual device to the virtual machine according to the running state of the virtual machine and the virtual device information.
[0009] Preferably, in step S123, the MDEV framework initializes each of the virtual devices, further comprising: The MDEV framework initializes the virtual device ID, virtual device name, virtual device serial number, initializes the current device state to be unstarted, performs specific type initialization according to the virtual device type, and the virtual device serial number is obtained according to the virtual device ID and virtual machine ID; Among them, specific type initialization is performed according to the virtual device type, including: If the virtual device type is a virtual network card, configure the network protocol stack and connect to the virtual network; If the virtual device type is a virtual disk, then create a virtual disk file and initialize the file system structure; If the virtual device type is a virtual GPU, the driver is loaded, the GPU is configured, and the graphics context is set.
[0010] Preferably, it is characterized in that judging the current device status according to the timed task mechanism further comprises: Acquire the virtual device information and virtual machine status, wherein the virtual machine status includes the virtual machine ID and the virtual machine running status; The virtual machine ID and the virtual device ID are matched according to the virtual device serial number, and the virtual device is processed according to the matching result and the running state of the virtual machine.
[0011] Preferably, it is characterized in that the processing of the virtual device according to the matching result and the running state of the virtual machine further comprises: If the virtual machine is in a shutdown state, and the virtual device is currently normally associated with the virtual machine, then the virtual device is in a releasable state; If the virtual machine is powered on and running normally, and the communication and use between the virtual device and the virtual machine are normal, then it is determined that the virtual device is in normal use; If the virtual machine is in an abnormal state including failure or crash, but the virtual device is still associated with the virtual machine, further determine whether the virtual device can still work normally. If the virtual device itself is running normally but the virtual machine cannot use it normally, the virtual device is in an idle but not released state, and processing is performed to release resources. If the virtual device has an abnormal state including error logs and hardware failure prompts, it is determined that the virtual device is in a fault state, and troubleshooting and repair are performed; If the matching result shows that the virtual device serial number does not match the virtual machine ID or the virtual device ID, further investigate the cause of the error and take corresponding measures based on the investigation results, including serial number record errors and abnormalities in the device allocation process.
[0012] Based on the same concept, the present invention also provides a cryptographic coprocessor virtualization system based on VFIO-MDEV, including: Hyper-converged cloud platform module, used to obtain virtual device configuration requests, send task requests to virtual machines, and receive task results returned by virtual machines A virtualization module, wherein the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, wherein the virtual machine device request includes information including the number of CPU cores, memory size, and virtual device type; An execution module is used for the virtual machine to send a task request to a physical device driver according to the VIFO framework. The physical device driver receives the task request and sends it to the Haiguang cryptographic coprocessor. The Haiguang cryptographic coprocessor executes the task request and returns the task result to the physical device driver. The physical device driver returns the task result to the virtual machine, and the virtual machine returns the task result to the hyper-converged cloud platform.
[0013] Based on the same concept, the present invention also provides a computer device, including a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes the steps of the cryptographic coprocessor virtualization method based on VFIO-MDEV as described in any one of the embodiments.
[0014] Based on the same concept, the present invention also provides a storage medium storing computer-readable instructions, which, when executed by one or more processors, enables the one or more processors to perform the steps of the cryptographic coprocessor virtualization method based on VFIO-MDEV as described in any one of the embodiments.
[0015] Compared with the prior art, the present invention has the following beneficial effects: The present invention obtains virtual device configuration requests through a hyper-converged cloud platform, and the MDEV framework establishes virtual devices according to the virtual device configuration requests, and allocates virtual devices to virtual machines according to the VIFO framework, so that the configuration of virtual machines can be flexibly customized according to specific needs, and can meet the diverse requirements of different users and application scenarios for computing resources (such as CPU, memory) and device types, thereby improving the accuracy and flexibility of resource configuration and improving the resource utilization rate of the cloud platform; The present invention sends the task request to the physical device driver according to the VIFO framework through the virtual machine, and then the physical device driver forwards it to the encryption coprocessor. This task issuing mechanism is clear and direct, reducing the confusion and possibility of errors in the task transfer process. The encryption coprocessor is specifically responsible for the execution of encryption tasks and can efficiently process encryption tasks by using its professional hardware acceleration capabilities. Compared with software simulation and other methods, it greatly improves the performance and efficiency of encryption calculations and meets the demand for high performance of encryption tasks.
[0016] The present invention executes task requests through an encryption coprocessor and returns the task results to a physical device driver, which returns the task results to a virtual machine, and the virtual machine returns the task results to a hyper-converged cloud platform, which facilitates subsequent processing and decision-making by the cloud platform, is also beneficial for troubleshooting and system monitoring, and ensures the stability and manageability of the system.
[0017] The present invention uses an encryption coprocessor to perform hardware acceleration, and at the same time, implements resource isolation between virtual machines through the allocation of virtual devices. On the one hand, hardware acceleration improves encryption computing performance; on the other hand, resource isolation ensures resource independence between virtual machines, avoids mutual interference, and enhances the security and stability of the system. It is suitable for application scenarios with high requirements for data security and system stability, and finds a balance between software encryption and separate hardware encryption. By using the cryptographic coprocessor that comes with the processor, the encryption performance meets the requirements of the production environment without the need for users to purchase additional external encryption cards. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the following detailed description of the preferred embodiment.The drawings are only for the purpose of illustrating the preferred embodiments and are not to be construed as limiting the invention.
[0019] Figure 1 A flowchart of a cryptographic coprocessor virtualization method based on VFIO-MDEV of the present invention; Figure 2 It is a flow chart of the MDEV device of the virtual machine of the present invention under the boot task; Figure 3 This is a flow chart of the MDEV device of the virtual machine of the present invention under the shutdown task. DETAILED DESCRIPTION
[0020] In order to make the purpose, technical scheme and advantages of the present invention clearer, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of this application.
[0021] Those skilled in the art will appreciate that, unless otherwise stated, the singular forms "a", "an", and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present invention refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0022] First embodiment See also Figure 1 As shown, the cryptographic coprocessor virtualization method based on VFIO-MDEV provided in this embodiment provides users with more secure and efficient data processing services, including the following steps: S1: The hyper-converged cloud platform obtains a virtual device configuration request. The MDEV framework establishes a virtual device according to the virtual device configuration request and allocates the virtual device to the virtual machine according to the VIFO framework. The virtual machine device request includes information including the number of CPU cores, memory size, and virtual device type. Specifically, in this embodiment, an encryption device with 4 CPU cores and 8G memory size is established. The physical device driver is the HCT device driver. The HCT device driver creates multiple virtual devices. The virtual device is directly passed to the virtual machine and shared with multiple virtual machines for simultaneous use. The virtual machine can be used as a separate physical device. The driver layer keeps each virtual device isolated.
[0023] This embodiment greatly improves the data processing capabilities of virtual machines on the cloud platform by introducing the high-performance encryption computing capabilities of the Haiguang cryptographic coprocessor into the virtualized environment, especially in scenarios that require a large number of encryption operations.
[0024] Preferably, it is characterized in that, in step S1, the hyper-converged cloud platform obtains a virtual device configuration request, comprising the following steps: S111: The hyper-converged platform receives a task request including data encryption, data decryption, and digital signature verification. Specifically, in this embodiment, the user may need to encrypt sensitive data stored in the cloud to protect privacy, or perform digital signature verification during data transmission to ensure the integrity and authenticity of the data. For a data decryption task, it may be an operation initiated by a user when he needs to access encrypted data. The user-side application, upper-level management system, or other related components initiate a task request and send the task request to the hyper-converged platform. The hyper-converged platform monitors and receives these task requests in real time. When the task request arrives at the hyper-converged platform, the platform will preliminarily receive and record it to ensure the integrity and accuracy of the task information. After receiving the task, the hyper-converged platform identifies the task type and determines whether the task belongs to a specific type such as data encryption, data decryption, or digital signature verification. S112: Calculate available resources including computing resources, storage resources and network resources for the parsed task request, wherein computing resources include information including the number of CPU cores and memory size, storage resources include information including virtual device size and virtual device type, and network resources include information including network bandwidth and IP address. Specifically, in this embodiment, the hyper-converged platform first parses the received dispatched tasks, extracts key information and specific requirements in the tasks, and for data encryption tasks, parses out information such as the amount of data to be encrypted and the type of encryption algorithm; for digital signature verification tasks, parses out information such as the type of signature and the source of data to be verified; S113: A virtual device request is obtained according to available resources. Specifically, in this embodiment, the virtual device request includes specific configuration information determined according to task requirements and available resources, such as the required number of CPU cores, memory size, virtual device type and size, network bandwidth requirements, and IP address, etc. This virtual device request will serve as the basis for subsequent creation and allocation of virtual devices. The platform will send the request to the MDEV framework to perform virtual device creation and allocation operations, thereby providing necessary resource support for the execution of tasks.
[0025] Computing resource calculation: The platform estimates the number of CPU cores required to perform the task based on the complexity of the task and the expected amount of computing. For example, if it is a large-scale data encryption task, more CPU cores are needed to process data in parallel to increase the encryption speed. At the same time, the platform will calculate the required memory size based on the memory space that may be occupied during the execution of the task. The platform will monitor the CPU and memory usage in the system in real time, and determine whether the currently available computing resources can meet the task requirements based on the task requirements. Storage resource calculation: Storage resources include information such as virtual device size and virtual device type. For data encryption and decryption tasks, it may be necessary to store information such as data before encryption, encrypted ciphertext, and related keys; for digital signature verification tasks, it may be necessary to store data to be verified and signature information. The platform will calculate the required virtual device size based on the amount of data required to be stored for the task. At the same time, according to the characteristics and usage of the data, it determines the appropriate virtual device type, such as ordinary storage devices, high-speed storage devices, etc. The platform will also check the usage of storage resources in the system to determine whether the currently available storage resources can meet the storage requirements of the task.
[0026] Network resource calculation: Finally, the hyper-converged platform calculates network resources. Network resources include information such as network bandwidth and IP addresses. For data encryption, decryption, and digital signature verification tasks, data may need to be transmitted between different components, which requires a certain amount of network bandwidth to ensure fast data transmission. The platform will calculate the required network bandwidth based on the expected data transmission volume and transmission speed requirements of the task. At the same time, in order to ensure that the data related to the task can be accurately transmitted to the target location, the platform will assign a suitable IP address to the task. The platform will monitor the usage of network bandwidth and the allocation of IP addresses in real time to determine whether the currently available network resources can meet the network requirements of the task.
[0027] Preferably, in step S1, the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, including: S121: The MDEV framework monitors and parses the virtual device configuration request; S122: The MDEV framework calls the VFIO interface provided by the physical device driver to send a create virtual device instruction according to the virtual device configuration request. Specifically, in this embodiment, the MDEV framework calls the VFIO interface provided by the physical device driver. The VFIO interface is a technical interface for enabling a virtual machine to directly access a physical device. It allows a virtual machine to bypass a traditional virtualization layer and directly interact with a physical device, thereby improving the efficiency and performance of device access. The MDEV framework sends a create virtual device instruction to the physical device driver through the VFIO interface. The virtual device instruction includes specific configuration information of the virtual device. S123: The physical device driver divides the resource area according to the virtual device in the Haiguang cryptographic coprocessor instruction, and allocates the virtual device to the virtual machine according to the VIFO framework. The MDEV framework initializes each virtual device. Specifically, in this embodiment, the VFIO framework is a user-mode driver framework that can safely support the user-mode process to access the device. In the virtualization scenario, the VFIO framework can also ensure that the virtual machine can safely access the physical device, including IO access to the physical device (MMIO / PIO), device DMA remapping, and PCI address space configuration. The interaction between these virtual machines and physical devices can be safely carried out under the VFIO framework, and MDEV further supports sharing a single physical device with multiple virtual machines. Based on the VFIO framework, a single physical device is exposed to each virtual machine, and each virtual machine's access to the physical device can be isolated from each other. The physical device needs to provide a physical device driver, which is integrated into the VFIO framework to specifically handle each virtual machine's access request to the device, including how to isolate and how to schedule the virtual machine's access request.
[0028] Preferably, in step S123, allocating the virtual device to the virtual machine according to the VIFO framework further includes: The VFIO framework obtains virtual device information from the MDEV framework. The virtual device information includes virtual device ID, virtual device name, and current device status. The current device status is determined based on the scheduled task mechanism. The VFIO framework obtains the running status of the virtual machine and allocates virtual devices to the virtual machine according to the running status of the virtual machine and the virtual device information.
[0029] Preferably, in step S123, the MDEV framework initializes each virtual device, further comprising: The MDEV framework initializes the virtual device ID, virtual device name, virtual device serial number, initializes the current device state to unstarted, performs specific type initialization according to the virtual device type, and the virtual device serial number is obtained according to the virtual device ID and virtual machine ID; Among them, specific type initialization is performed according to the virtual device type, including: If the virtual device type is a virtual network card, configure the network protocol stack and connect to the virtual network; If the virtual device type is a virtual disk, create a virtual disk file and initialize the file system structure; If the virtual device type is a virtual GPU, the driver is loaded, the GPU is configured, and the graphics context is set.
[0030] Preferably, it is characterized in that judging the current device status according to the timed task mechanism further comprises: Obtain virtual device information and virtual machine status, where the virtual machine status includes the virtual machine ID and the virtual machine running status; The virtual machine ID and the virtual device ID are matched according to the virtual device serial number, and the virtual device is processed according to the matching result and the running status of the virtual machine.
[0031] Preferably, it is characterized in that processing the virtual device according to the matching result and the running state of the virtual machine further comprises: If the virtual machine is in shutdown state, and the virtual device is currently associated with the virtual machine normally, the virtual device is in a releasable state; If the virtual machine is powered on and running normally, and the communication and use between the virtual device and the virtual machine are normal, then it is determined that the virtual device is in normal use; If the virtual machine is in an abnormal state including failure or crash, but the virtual device is still associated with the virtual machine, further determine whether the virtual device can still work normally. If the virtual device itself is running normally but the virtual machine cannot use it normally, the virtual device is in an idle but not released state, and processing is performed to release resources. If the virtual device has an abnormal state including error logs and hardware failure prompts, it is determined that the virtual device is in a faulty state, and troubleshooting and repair are performed; If the matching result shows that the virtual device serial number does not match the virtual machine ID or virtual device ID, further investigate the cause of the error and take corresponding measures based on the investigation results, including serial number record errors and abnormalities in the device allocation process.
[0032] Automated management of the creation and destruction of MDEV devices during the life cycle of virtual machines enables efficient allocation and recycling of resources, and improves resource utilization and management efficiency of the cloud platform.
[0033] S2: The virtual machine sends the task request to the physical device driver according to the VIFO framework. The physical device driver receives the task request and sends it to the Haiguang cryptographic coprocessor. Specifically, in this embodiment, the virtual machine sends the task request data packet to the address space where the physical device driver is located. After receiving the task request data packet, the physical device driver checks the integrity of the data packet (such as through checksum verification), whether the format complies with the provisions of the VFIO framework, and the legality of the request (for example, whether there is permission to execute the task). If the task request passes, it is received and processed; if the check fails, an error message is sent to the virtual machine to request the task request to be resent. The physical device driver parses the received task request to obtain key information including the task type and operation parameters, determines the specific requirements of the task and the Haiguang cryptographic coprocessor according to the parsing results, converts the task request format, and sends the converted task request to the Haiguang cryptographic coprocessor, thereby ensuring the security of data during the encryption calculation process. By strictly controlling the access of the virtual machine instance to the coprocessor resources, data leakage and unauthorized access are effectively prevented.
[0034] S3: The Haiguang cryptographic coprocessor executes the task request and returns the task result to the physical device driver, the physical device driver returns the task result to the virtual machine, and the virtual machine returns the task result to the hyper-converged cloud platform. Specifically, in this embodiment, the Haiguang cryptographic coprocessor parses the task request to obtain information including the task type (encryption, decryption, digital signature verification, etc.), the algorithm used, the storage location of the input data, etc. The Haiguang cryptographic coprocessor calls the corresponding internal cryptographic operation module and algorithm logic to execute the task. For example, if it is an encryption task, it will encrypt the input data according to the specified encryption algorithm; if it is a digital signature verification task, it will verify the consistency of the signature and the data.
[0035] During the task execution, the Haiguang cryptographic coprocessor uses its internal cache and computing resources to gradually process data according to the requirements of the task request until the entire task is completed. After the task is completed, the Haiguang cryptographic coprocessor will generate the task result.
[0036] The operation process of using encryption coprocessors in virtual machines has been simplified, allowing cloud platform users to easily use the Haiguang cryptographic coprocessors for encryption calculations in virtual machines, improving the user experience.
[0037] See also Figure 2 As shown, the MDEV device process of a single virtual machine under the startup task is that a single virtual machine mounts several virtual devices. When the single virtual machine receives the issued startup task, several virtual devices are allocated to the single virtual machine, and the virtual devices are configured to the virtual machine through VFIO, and the virtual machine instance is started.
[0038] See also Figure 3 As shown, the MDEV device process of a single virtual machine under a shutdown task is that when a single virtual machine receives the issued shutdown task, it shuts down the virtual machine instance and releases the virtual device allocated to the virtual machine.
[0039] This embodiment is the first case in the industry to commercialize the Haiguang cryptographic coprocessor and successfully integrate it into the cloud platform. It has set a new benchmark for the field of cloud computing security, led the industry development trend, promoted the development of cloud computing security technology, and provided valuable experience for subsequent technological evolution and product innovation.
[0040] Second embodiment Based on the same concept, the present invention also provides a cryptographic coprocessor virtualization system based on VFIO-MDEV, including: Hyper-converged cloud platform module, used to obtain virtual device configuration requests, send task requests to virtual machines, and receive task results returned by virtual machines A virtualization module, wherein the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, wherein the virtual machine device request includes information including the number of CPU cores, memory size, and virtual device type; An execution module is used for the virtual machine to send a task request to a physical device driver according to the VIFO framework. The physical device driver receives the task request and sends it to the Haiguang cryptographic coprocessor. The Haiguang cryptographic coprocessor executes the task request and returns the task result to the physical device driver. The physical device driver returns the task result to the virtual machine, and the virtual machine returns the task result to the hyper-converged cloud platform.
[0041] Third embodiment In some embodiments of the present application, a computer device is also provided, including a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor performs the steps of the VFIO-MDEV-based cryptographic coprocessor virtualization method as described in any one of Example 1.
[0042] The present invention also provides a storage medium storing computer-readable instructions, which, when executed by one or more processors, causes the one or more processors to perform the steps of the VFIO-MDEV-based cryptographic coprocessor virtualization method as described in any one of Example 1.
[0043] It can be understood that for the aforementioned cryptographic coprocessor virtualization method based on VFIO-MDEV, if it is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or part of the contribution to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer server, or a network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read Only memory, ROM), random access memory (RandomAccess memory, RAM), disk or optical disk and other media that can store program code.
[0044] Computer readable storage media may include data signals propagated in baseband or as part of a carrier wave, wherein readable program codes are carried. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program codes contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.
[0045] The above is only a preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technicians in this technical field, some improvements and modifications without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.
Claims
1. A cryptographic coprocessor virtualization method based on VFIO-MDEV, characterized in that: The following steps are involved: S1: The hyper-converged cloud platform obtains a virtual device configuration request, the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, wherein the virtual machine device request includes information such as the number of CPU cores, memory size, and virtual device type; S2: The virtual machine sends the task request to the physical device driver according to the VIFO framework, and the physical device driver receives the task request and sends it to the Haiguang cryptographic coprocessor; S3: The Haiguang cryptographic coprocessor executes the task request and returns the task result to the physical device driver, the physical device driver returns the task result to the virtual machine, and the virtual machine returns the task result to the hyper-converged cloud platform.
2. The cryptographic coprocessor virtualization method based on VFIO-MDEV according to claim 1, characterized in that: In step S1, the hyper-converged cloud platform receives a virtual device configuration request, including the following steps: S111: The hyper-converged platform receives the task request including data encryption, data decryption, and digital signature verification; S112: Calculating available resources including computing resources, storage resources and network resources for the parsed task request, wherein the computing resources include information including the number of CPU cores and memory size, the storage resources include information including virtual device size and virtual device type, and the network resources include information including network bandwidth and IP address; S113: Obtain the virtual device request according to the available resources.
3. The cryptographic coprocessor virtualization method based on VFIO-MDEV according to claim 2, characterized in that: In step S1, the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, including: S121: The MDEV framework monitors and parses the virtual device configuration request; S122: The MDEV framework calls the VFIO interface provided by the physical device driver to send a virtual device creation instruction according to the virtual device configuration request; S123: The physical device driver divides the resource area according to the virtual device in the Haiguang cryptographic coprocessor instruction, and allocates the virtual device to the virtual machine according to the VIFO framework, and the MDEV framework initializes each of the virtual devices.
4. The cryptographic coprocessor virtualization method based on VFIO-MDEV according to claim 3, characterized in that: In step S123, allocating the virtual device to the virtual machine according to the VIFO framework further includes: The VFIO framework obtains virtual device information from the MDEV framework, wherein the virtual device information includes information including a virtual device ID, a virtual device name, and a current device status, wherein the current device status is determined according to a scheduled task mechanism; The VFIO framework obtains the running state of the virtual machine, and allocates the virtual device to the virtual machine according to the running state of the virtual machine and the virtual device information.
5. The cryptographic coprocessor virtualization method based on VFIO-MDEV according to claim 4, characterized in that: In step S123, the MDEV framework initializes each of the virtual devices, further comprising: The MDEV framework initializes the virtual device ID, virtual device name, virtual device serial number, initializes the current device state to be unstarted, performs specific type initialization according to the virtual device type, and the virtual device serial number is obtained according to the virtual device ID and virtual machine ID; Among them, specific type initialization is performed according to the virtual device type, including: If the virtual device type is a virtual network card, configure the network protocol stack and connect to the virtual network; If the virtual device type is a virtual disk, then create a virtual disk file and initialize the file system structure; If the virtual device type is a virtual GPU, the driver is loaded, the GPU is configured, and the graphics context is set.
6. The cryptographic coprocessor virtualization method based on VFIO-MDEV according to claim 5, characterized in that: Judging the current device status according to the timed task mechanism further includes: Acquire the virtual device information and virtual machine status, wherein the virtual machine status includes the virtual machine ID and the virtual machine running status; The virtual machine ID and the virtual device ID are matched according to the virtual device serial number, and the virtual device is processed according to the matching result and the running state of the virtual machine.
7. The cryptographic coprocessor virtualization method based on VFIO-MDEV according to claim 6, characterized in that: The processing of the virtual device according to the matching result and the running state of the virtual machine further includes: If the virtual machine is in a shutdown state, and the virtual device is currently normally associated with the virtual machine, then the virtual device is in a releasable state; If the virtual machine is powered on and running normally, and the communication and use between the virtual device and the virtual machine are normal, then it is determined that the virtual device is in normal use; If the virtual machine is in an abnormal state including failure or crash, but the virtual device is still associated with the virtual machine, further determine whether the virtual device can still work normally. If the virtual device itself is running normally but the virtual machine cannot use it normally, the virtual device is in an idle but not released state, and processing is performed to release resources. If the virtual device has an abnormal state including error logs and hardware failure prompts, it is determined that the virtual device is in a fault state, and troubleshooting and repair are performed; If the matching result shows that the virtual device serial number does not match the virtual machine ID or the virtual device ID, further investigate the cause of the error and take corresponding measures based on the investigation results, including serial number record errors and abnormalities in the device allocation process.
8. A cryptographic coprocessor virtualization system based on VFIO-MDEV, characterized in that: include: Hyper-converged cloud platform module, used to obtain virtual device configuration requests, send task requests to virtual machines, and receive task results returned by virtual machines The virtualization module, the MDEV framework establishes a virtual device according to the virtual device configuration request, and allocates the virtual device to the virtual machine according to the VIFO framework, wherein the virtual machine device request includes information including the number of CPU cores, memory size, and virtual device type; An execution module is used for the virtual machine to send a task request to a physical device driver according to the VIFO framework, the physical device driver receives the task request and sends it to the Haiguang cryptographic coprocessor, the Haiguang cryptographic coprocessor executes the task request and returns the task result to the physical device driver, the physical device driver returns the task result to the virtual machine, and the virtual machine returns the task result to the hyper-converged cloud platform.
9. A computer device, characterized in that: The invention comprises a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes the steps of the cryptographic coprocessor virtualization method based on VFIO-MDEV as described in any one of claims 1 to 7.
10. A storage medium storing computer-readable instructions, characterized in that: When the computer-readable instructions are executed by one or more processors, the one or more processors are caused to perform the steps of a cryptographic coprocessor virtualization method based on VFIO-MDEV as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Calculation acceleration method and device, calculation system, electronic equipment and computer readable storage medium
CN113419845A
Network system, resource processing method and equipment
CN113676512A
Extensible NVMe storage virtualization method and system
CN114138422A
Configuration method of encryption hardware, data confidentiality calculation method and related equipment
CN116841691A
USB device sharing method and system based on virtualization
CN116955236A