Method and device for adaptively allocating cryptographic algorithm performance based on a hardware cryptographic module

By allocating data buffers to virtual device nodes and selecting buffers with higher weights for password processing, the problem of unreasonable performance allocation of hardware password modules in hardware virtualization scenarios is solved, and the utilization rate of hardware resources is improved.

CN120185812BActive Publication Date: 2025-07-22HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510646212.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-07-22
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

In the comprehensive hardware virtualization scenario, how to reasonably allocate the cryptographic algorithm performance of hardware password modules has become a technical problem that needs to be solved urgently.

Method used

By allocating data buffers to each virtual device node according to the number of virtual device nodes connected to the hardware password module and the weight of each virtual device node, and selecting them according to the weight of each data buffer. Then, according to the target password algorithm corresponding to the currently selected data buffer, the to be processed data is written into the input buffer and password processing is performed.

Benefits of technology

It realizes adaptive allocation of hardware cryptographic algorithm resources in a multi-device environment, and improves the utilization rate of hardware resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185812B_ABST
    Figure CN120185812B_ABST
Patent Text Reader

Abstract

The present application provides a method and device for adaptively allocating the performance of a cryptographic algorithm based on a hardware cryptographic module. In an example of the present application, the method includes: allocating data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node; selecting a data buffer according to the weights of each data buffer; writing the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer; and outputting the data after cryptographic processing. This method can achieve the adaptive allocation of hardware cryptographic algorithm resources and improve the utilization rate of hardware resources in a multi-device environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cryptographic technologies, and particularly to a method and apparatus for adaptively allocating the performance of cryptographic algorithms based on a hardware cryptographic module. Background Art

[0002] Full hardware virtualization technology is a technology that enables a hardware device (such as a processor, memory, storage device, etc.) to be shared and utilized by multiple virtual machines (VMs) through software technology. These virtual machines are isolated from each other through virtualization technology and execute tasks independently of each other, and the virtualization technology relies on a virtual machine monitor (Hypervisor) or a management program to manage and allocate hardware resources.

[0003] A hardware cryptographic module is a hardware device specifically designed to protect and manage encryption keys, perform encryption operations, and provide secure storage.

[0004] In the scenario of full hardware virtualization, how to reasonably allocate the performance of cryptographic algorithms of the hardware cryptographic module has become a technical problem to be solved urgently. Summary of the Invention

[0005] In view of this, this application provides a disk encryption method, apparatus, device, and system based on threshold cryptography.

[0006] Specifically, this application is implemented through the following technical solutions:

[0007] According to the first aspect of the embodiments of this application, a method for adaptively allocating the performance of cryptographic algorithms based on a hardware cryptographic module is provided, including:

[0008] Allocating data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node; wherein, the size of the data buffer allocated to each virtual device node is positively correlated with the weight of each virtual device node;

[0009] Selecting data buffers according to the weights of each data buffer; wherein, the weight of the data buffer allocated to each virtual device node is determined according to the weight of the virtual device node;

[0010] Writing the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer;

[0011] Outputting the data after cryptographic processing; wherein, the data after cryptographic processing is obtained by performing cryptographic processing on the data to be processed in the input buffer using the first target cryptographic algorithm.

[0012] According to a second aspect of the embodiments of the present application, there is provided a cryptographic algorithm performance adaptive allocation device based on a hardware cryptographic module, including:

[0013] An allocation unit, configured to allocate data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node; wherein, the size of the data buffer allocated to each virtual device node is positively correlated with the weight of each virtual device node;

[0014] A selection unit, configured to select a data buffer according to the weights of each data buffer; wherein, the weight of the data buffer allocated to each virtual device node is determined according to the weight of the virtual device node;

[0015] A writing unit, configured to write the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer;

[0016] An output unit, configured to output the data after cryptographic processing; wherein, the data after cryptographic processing is obtained by performing cryptographic processing on the data to be processed in the input buffer by using the first target cryptographic algorithm.

[0017] According to a third aspect of the embodiments of the present application, there is provided an electronic device, including a processor and a memory, wherein:

[0018] The memory is used to store a computer program;

[0019] The processor, when executing the program stored in the memory, implements the method provided in the first aspect.

[0020] The cryptographic algorithm performance adaptive allocation method based on a hardware cryptographic module in the embodiments of the present application allocates data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node, selects a data buffer according to the weights of each data buffer, and then writes the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer, and outputs the data after cryptographic processing, thereby realizing the adaptive allocation of hardware cryptographic algorithm resources and improving the utilization rate of hardware resources in a multi-device environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a schematic flowchart of a cryptographic algorithm performance adaptive allocation method based on a hardware cryptographic module shown in an exemplary embodiment of the present application;

[0022] Figure 2A schematic diagram of data buffer allocation shown in an exemplary embodiment of the present application;

[0023] Figure 3 A schematic diagram of cryptographic algorithm input control shown in an exemplary embodiment of the present application;

[0024] Figure 4 A schematic diagram of the input / output structure of a single algorithm core shown in an exemplary embodiment of the present application;

[0025] Figure 5 A schematic diagram of output data selection shown in an exemplary embodiment of the present application;

[0026] Figure 6 A schematic diagram of the overall structure of performance adaptive allocation of cryptographic algorithms based on a hardware cryptographic module shown in an exemplary embodiment of the present application;

[0027] Figure 7 A schematic diagram of the structure of a device for performance adaptive allocation of cryptographic algorithms based on a hardware cryptographic module shown in an exemplary embodiment of the present application;

[0028] Figure 8 A schematic diagram of the hardware structure of an electronic device shown in an exemplary embodiment of the present application. Detailed implementation manners

[0029] In order to enable those skilled in the art to better understand the technical solutions provided in the embodiments of the present application, and to make the above-mentioned objects, features, and advantages of the embodiments of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.

[0030] Please refer to Figure 1 , which is a flowchart of a method for performance adaptive allocation of cryptographic algorithms based on a hardware cryptographic module provided in an embodiment of the present application. As Figure 1 shown, the method for performance adaptive allocation of cryptographic algorithms based on a hardware cryptographic module may include the following steps:

[0031] Step S100: Allocate data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node; wherein, the size of the data buffer allocated to each virtual device node is positively correlated with the weight of each virtual device node.

[0032] In the embodiments of the present application, in order to improve the rationality of data buffer allocation, data buffers can be allocated to each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node. During the allocation process of the data buffers, it is ensured that the size of the data buffers allocated to each virtual device node is positively correlated with the weight of each virtual device node, that is, the data buffer allocated to the virtual device node with a larger weight is larger than the data buffer allocated to the virtual device node with a smaller weight.

[0033] Exemplarily, the weight used to allocate data buffers to each virtual device node can be the initial weight of each virtual device node.

[0034] The initial weight of each virtual device node can be determined according to the received weight configuration information.

[0035] Exemplarily, the data to be processed of each virtual device node (such as data to be encrypted or decrypted, etc.) can be saved in the allocated data buffer; the hardware cryptographic module can obtain the data to be processed from the data buffer and perform cryptographic processing (such as data encryption or data decryption, etc.) on the obtained data to be processed.

[0036] It should be noted that in the embodiments of the present application, when the virtual device nodes connected to the hardware cryptographic module increase or decrease (such as adding new nodes or there are nodes going offline, etc.) or the weights of the virtual device nodes connected to the hardware cryptographic module change, data buffers can be re-allocated to each virtual device node.

[0037] Exemplarily, re-allocating data buffers to each virtual device node can be performed when all the data to be processed in the current data buffer has been read.

[0038] Step S110: Select data buffers according to the weights of each data buffer; wherein, the weights of the data buffers allocated to each virtual device node are determined according to the weights of the virtual device nodes.

[0039] In the embodiments of the present application, in order to more reasonably perform cryptographic processing on the data to be processed provided by the virtual device nodes, data buffers for reading the data to be processed can be selected according to the weights of each data buffer.

[0040] Exemplarily, the probability of a data buffer being selected is positively correlated with the weight of the data buffer, that is, the greater the weight of the data buffer, the higher the probability of the data buffer being selected.

[0041] Exemplarily, for any data buffer, the probability of the data buffer being selected can be characterized by the proportion of the number of times the data buffer is selected in multiple consecutive data buffer selections.

[0042] Exemplarily, the weight of the data buffer allocated to the virtual device node is determined according to the weight of the virtual device node.

[0043] Exemplarily, the weight of the data buffer allocated to the virtual device node is positively correlated with the weight of the virtual device node.

[0044] For example, the weight of the data buffer allocated to the virtual device node may be the same as the weight of the virtual device node.

[0045] Step S120: Write the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer.

[0046] Step S130: Output the data after cryptographic processing; wherein, the data after cryptographic processing is obtained by performing cryptographic processing on the data to be processed in the input buffer by using the first target cryptographic algorithm.

[0047] In the embodiments of the present application, for any selection of the data buffer, the corresponding cryptographic algorithm (which can be referred to as the first target cryptographic algorithm) can be determined according to the currently selected data buffer.

[0048] Exemplarily, the cryptographic algorithm corresponding to the data buffer can be the cryptographic algorithm that the virtual device node allocated to the data buffer needs to use.

[0049] When the first target cryptographic algorithm is determined, the data to be processed can be read from the currently selected data buffer and written into the input buffer of the first target cryptographic algorithm.

[0050] Exemplarily, the algorithm core of the first target cryptographic algorithm can read the data to be processed from the input buffer and perform cryptographic processing on the read data to be processed to obtain the data after cryptographic processing.

[0051] Exemplarily, the data after cryptographic processing obtained by cryptographic processing can be stored in the output buffer of the algorithm core.

[0052] Exemplarily, the hardware cryptographic module can output the data after cryptographic processing stored in the output buffer.

[0053] In one example, when there are multiple cryptographic algorithms for cryptographic processing, the data after cryptographic processing of different cryptographic algorithms can be output according to the operation completion time of different cryptographic algorithms.

[0054] Exemplarily, cryptographic processing may include encryption processing or decryption processing.

[0055] Exemplarily, for encryption processing, the data to be processed may include plaintext data; for decryption processing, the data to be processed may include ciphertext data.

[0056] It can be seen that in Figure 1 the method flow shown, by allocating data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node, and selecting data buffers according to the weights of each data buffer, and then, according to the first target cryptographic algorithm corresponding to the currently selected data buffer, writing the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm, and outputting the data after cryptographic processing, the adaptive allocation of hardware cryptographic algorithm resources is realized, and the utilization rate of hardware resources is improved in a multi-device environment.

[0057] In some embodiments, the above-mentioned allocating data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node may include:

[0058] Determine the total weight of the virtual device nodes according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node;

[0059] For any virtual device node, determine the weight ratio of the virtual device node according to the weight of the virtual device node and the total weight of the virtual device nodes;

[0060] Allocate a data buffer with a ratio consistent with the weight ratio for the virtual device node from the entire buffer according to the weight ratio of the virtual device node.

[0061] Exemplarily, in the process of allocating data buffers, for any virtual device node, a proportional data buffer can be allocated for the virtual device node according to the proportion of the weight of the virtual device node in the total weight.

[0062] Exemplarily, the total weight of the virtual device nodes can be determined according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node, and the weight ratios of each virtual device node can be determined respectively, and then, according to the weight ratios of each virtual device node, data buffers with ratios consistent with the weight ratios are allocated for each virtual device node from the entire buffer.

[0063] For example, assume that the number of virtual device nodes connected to the hardware password module is 3 (assumed to be nodes 1 to 3 respectively), and the weights of each node are 3, 2, and 1 in sequence. Then the weight ratios of each node are 1 / 2, 1 / 3, and 1 / 6 in sequence. When allocating data buffers, 1 / 2, 1 / 3, and 1 / 6 of the entire buffer can be allocated for nodes 1 to 3 respectively.

[0064] It should be noted that the above method of allocating an equal - proportion data buffer for each virtual device node based on the weight ratio of the virtual device nodes is only a specific example of allocating a data buffer for virtual device nodes according to the weights of the virtual device nodes, rather than a limitation on the protection scope of this application. That is, in the embodiments of this application, other methods can also be used to allocate data buffers for each virtual device node, as long as it is ensured that the size of the data buffer allocated to each virtual device node is positively correlated with the weight of each virtual device node.

[0065] For example, still taking the previous example, for nodes 1 - 3, the data buffers allocated to them can account for 4 / 9, 1 / 3, and 2 / 9 of the entire buffer in sequence.

[0066] In some embodiments, the above selection of a data buffer according to the weights of each data buffer may include:

[0067] For any selection of a data buffer, based on the current weights of each data buffer, the data buffer with the highest current weight is determined as the currently selected data buffer;

[0068] Among them, after each selection of a data buffer, the weight of the selected data buffer in this selection is reduced.

[0069] Exemplarily, during the process of selecting a data buffer, in order to ensure that the data buffer with a high weight is preferentially selected, the data buffer can be selected according to the weights of the data buffers, and the data buffer with the highest weight is preferentially selected.

[0070] However, in order to avoid that the data buffer with the highest weight is selected each time, and the data in the data buffer with a non - highest weight cannot be processed all the time, during the process of selecting a data buffer, the weights of each data buffer can also be dynamically updated to ensure that the data buffer with an initially non - highest weight can also be selected.

[0071] Exemplarily, during the process of selecting a data buffer, the dynamic update of the weights of the data buffers can include reducing the weights of the selected data buffers according to a preset strategy.

[0072] Exemplarily, for any data buffer, each time it is selected, the dynamic update of the weight needs to be performed, that is, the weight will be reduced.

[0073] In one example, for the first selection of a data buffer, the current weights of each data buffer are the initial weights;

[0074] For non - first selections of a data buffer, the current weight of any data buffer is the sum of the weight of this data buffer after the previous selection of the data buffer and the initial weight of this data buffer;

[0075] After a data buffer is selected, the weight of the selected data buffer is updated to the difference between the current weight of the data buffer and the total initial weight of each data buffer; the weights of the unselected data buffers remain unchanged.

[0076] Exemplarily, after a data buffer is selected, for the selected data buffer, the weight of the selected data buffer can be updated by subtracting the initial total weight from the weight of the data buffer and then adding the initial weight of the data buffer; for the unselected data buffer, the weight of the unselected data buffer can be updated by adding the initial weight to the weight of the data buffer. Its specific implementation can be described in combination with specific examples below, and the embodiments of the present application will not be elaborated here.

[0077] It can be seen that through the above data buffer selection method, it not only ensures that the data buffer with a high weight can be preferentially selected, but also avoids always selecting the data buffer with the highest weight. While ensuring that the data buffer with a high weight is preferentially selected, it also ensures the selection of the data buffer with a low weight. Thus, the data in the data buffer with a low weight can also be processed in a timely manner, and the overall selection probability of each data buffer matches the weight ratio of each data buffer, improving the rationality of data buffer selection.

[0078] Exemplarily, when the currently selected data buffer is determined, data can be read from the currently selected buffer.

[0079] Among them, the data in the data buffer is transmitted from the host side in the form of data packets. The data packet has a maximum length limit, and each data packet header (the first frame of data) carries length information. The amount of data read at one time from the buffer is determined according to the length information.

[0080] In some embodiments, writing the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer includes:

[0081] When there are multiple algorithm cores for the first target cryptographic algorithm, determine the algorithm core with the largest remaining buffer space according to the remaining buffer spaces of the input buffers of each algorithm core of the first target cryptographic algorithm;

[0082] When the remaining buffer space of the algorithm core with the largest remaining buffer space is greater than or equal to the maximum data length, determine the algorithm core as the target algorithm core.

[0083] Exemplarily, in order to improve the password processing efficiency, multiple algorithm cores can be set for the same password algorithm, and a multi-algorithm core parallel operation structure can be adopted.

[0084] In order to achieve load balancing of multiple algorithm cores for the same password algorithm, the algorithm core can be selected according to the remaining buffer space size of the input buffer of different algorithm cores of the same password algorithm, and the data to be processed read currently can be written into the corresponding input buffer.

[0085] Correspondingly, in the case where there are multiple algorithm cores for the first target password algorithm, the algorithm core with the largest remaining buffer space can be determined according to the remaining buffer space of the input buffers of each algorithm core of the first target password algorithm.

[0086] Exemplarily, in order to improve the data writing processing efficiency, in the case where the remaining buffer space (which can be called the input remaining buffer space) of the algorithm core with the largest remaining buffer space in the input buffer is greater than or equal to the maximum data length (the maximum data length corresponding to this password algorithm), this algorithm core can be determined as the target algorithm core, and the data to be processed read from the currently selected data buffer can be written into the input buffer of this target algorithm core.

[0087] Among them, since in the above process of determining the target algorithm core, for the algorithm core with the largest input remaining buffer space, by comparing the input remaining buffer space of this algorithm core with the maximum data length, rather than comparing the input remaining buffer space of this algorithm core with the data length of the actual data to be processed, therefore, it can be pre-determined whether the input remaining buffer space of the algorithm core is greater than or equal to the maximum data length, without comparing the input remaining buffer space of the algorithm core with the data length of the data to be processed during the process of determining the target algorithm core.

[0088] In one example, for the input buffer of any algorithm core, in the case where the remaining buffer space size of this input buffer is updated, it can be determined whether the remaining buffer space of this input buffer is greater than or equal to the maximum data length, and a specified flag can be used to identify whether the remaining buffer space of this input buffer is greater than or equal to the maximum data length.

[0089] For example, the first flag indicates that the remaining buffer space of the input buffer is greater than or equal to the maximum data length; the second flag indicates that the remaining buffer space of the input buffer is less than the maximum data length.

[0090] For another example, in the case where there is a specified flag, it indicates that the remaining buffer space of the input buffer is greater than or equal to the maximum data length; in the case where there is no specified flag, it indicates that the remaining buffer space of the input buffer is less than the maximum data length.

[0091] For another example, in the absence of a specified flag, it indicates that the remaining buffer space of the input buffer is greater than or equal to the maximum data length; in the presence of a specified flag, it indicates that the remaining buffer space of the input buffer is less than the maximum data length.

[0092] In one example, the total buffer space size of the input buffer of the algorithm core can be twice the maximum data length, and the remaining buffer space of the input buffer being greater than or equal to the maximum data length can be that the remaining buffer space of the input buffer is greater than half of the total buffer space.

[0093] It should be noted that in the embodiments of the present application, in the case where the input remaining buffer space of the algorithm core with the largest remaining buffer space is less than the maximum data length, it can be determined that the remaining buffer spaces of the input buffers of each algorithm are all insufficient and data writing cannot be performed. Alternatively, the remaining buffer space of the algorithm core with the largest input remaining buffer space can be further compared with the actual data length of the data to be processed to be written, and its specific implementation will not be elaborated here.

[0094] In some embodiments, the above output of the data after password processing may include:

[0095] In the case where there are multiple different password algorithms in the hardware password module, obtain the first buffer length information currently to be processed for each password algorithm;

[0096] Based on the obtained buffer length information, the minimum data length, and the minimum time unit of each password algorithm, determine the operation completion time of each password algorithm; wherein, for any password algorithm, the minimum time unit of the password algorithm is the time for password processing of data with the minimum data length of the password algorithm;

[0097] Based on the operation completion times of each password algorithm, determine the second target password algorithm for current data output as the password algorithm with the minimum and non-zero operation completion time, and output the data after password processing saved in the output buffer of the second target password algorithm.

[0098] Exemplarily, considering that in the case where there are multiple different password algorithms in the hardware password module, there will be differences in the time for different password algorithms to complete password processing. During the process of data output, preferentially outputting the data of the password algorithm that has completed password processing (i.e., the password algorithm with data to be output) can improve the data output efficiency.

[0099] Correspondingly, in the case where there are multiple different password algorithms in the hardware password module, obtain the first buffer length information currently to be processed for each password algorithm.

[0100] Exemplarily, when the hardware password module writes the data to be processed read from the data buffer into the input buffer of the corresponding algorithm core, it can also record the length of the data to be processed written.

[0101] For example, for different cryptographic algorithms, a length information cache unit can be correspondingly set to record the data length of the data to be processed written into the input buffer at one time (which can be called the cache length).

[0102] Exemplarily, the first cache length information refers to the length information of the data to be processed written into the input buffer first.

[0103] Considering that the operation process of the hardware cryptographic algorithm is not affected by factors such as the performance of the CPU (Central Processing Unit), the time to complete the algorithm operation process is almost fixed when the clock frequency remains unchanged. Therefore, the time for password processing of the data with the minimum data length for each cryptographic algorithm can be obtained through simulation (which can be called the minimum time unit).

[0104] Correspondingly, based on the obtained cache length information, the minimum data length, and the minimum time unit of each cryptographic algorithm, the operation completion time of each cryptographic algorithm can be determined.

[0105] Exemplarily, based on the operation completion time of each cryptographic algorithm, the cryptographic algorithm with the minimum and non-zero operation completion time can be determined as the cryptographic algorithm for current data output (which can be called the second target cryptographic algorithm), and the password-processed data saved in the output buffer of the second target cryptographic algorithm can be output.

[0106] Through the above method, when the data is written into the input buffer, the data output order of different algorithms can be determined in advance according to the operation completion time of different algorithms, improving the rationality of data output and optimizing the data processing performance.

[0107] It should be noted that in the case where an algorithm has multiple algorithm cores, the multiple algorithm cores of the same algorithm share a length information cache unit, and the length information cache unit adopts the FIFO (First In First Out) mechanism. The length information stored in the length information cache unit first is read first. Thus, while the length information cache unit is used to assist in selecting the algorithm to be output first, it can also ensure that the output order of the cached data packets entering different algorithm cores of the same algorithm remains unchanged.

[0108] In addition, in the case where there are multiple algorithm cores for the same algorithm, the length information cache unit caches not only the length information, but also an algorithm core flag (such as an algorithm core serial number) for identifying the algorithm core corresponding to the data to be processed, so as to determine the algorithm core for data output according to the algorithm core flag.

[0109] For example, assume that the above-mentioned second target cryptographic algorithm is Algorithm 2, and the algorithm core flag (taking the serial number as an example) corresponding to the first cached length information in the length information cache unit of Algorithm 2 is 1, that is, it can be determined that the output data of algorithm core 1 of Algorithm 2 needs to be output first.

[0110] In one example, in the case where the second target cryptographic algorithm for current data output is determined, the method for adaptively allocating the performance of the cryptographic algorithm based on the hardware cryptographic module provided by the embodiments of the present application may further include:

[0111] For other cryptographic algorithms other than the second target cryptographic algorithm, the difference between the operation completion time of each other cryptographic algorithm and the current operation completion time of the second target cryptographic algorithm is determined as the latest operation completion time of each other cryptographic algorithm;

[0112] For the second target cryptographic algorithm, in the case where there is a next cached length information to be processed, the latest operation completion time of the second target cryptographic algorithm is determined according to the next cached length information to be processed, the minimum data length of the second target cryptographic algorithm, and the minimum time unit of the second target cryptographic algorithm;

[0113] According to the latest operation completion time of each cryptographic algorithm, a new second target cryptographic algorithm for data output is determined.

[0114] Exemplarily, in the case where the second target cryptographic algorithm for current data output is determined in the above manner, for other cryptographic algorithms other than the second target cryptographic algorithm, the difference between the operation completion time of each other cryptographic algorithm and the current operation completion time of the second target cryptographic algorithm can be determined as the latest operation completion time of each other cryptographic algorithm.

[0115] For the second target cryptographic algorithm, it can be determined whether there is still unprocessed data to be processed. In the case where there is unprocessed data to be processed, the latest operation completion time of the second target cryptographic algorithm can be determined according to the next cached length information to be processed, the minimum data length of the second target cryptographic algorithm, and the minimum time unit of the second target cryptographic algorithm. Furthermore, a new second target cryptographic algorithm for data output can be determined according to the latest operation completion time of each cryptographic algorithm. Its specific implementation can be described in the following in combination with specific examples, and the embodiments of the present application will not elaborate here.

[0116] To enable those skilled in the art to better understand the technical solutions provided by the embodiments of the present application, the technical solutions provided by the embodiments of the present application will be described below in conjunction with specific examples.

[0117] In this embodiment, based on the multi-core alignment parallel operation structure of the cryptographic algorithm, through the designed algorithm input and output control method, a suitable algorithm core is selected for operation and a pipelined transmission is formed, so as to improve the algorithm performance on the basis of ensuring the correctness of the algorithm.

[0118] In this embodiment, the specific implementation process of the adaptive allocation scheme of the cryptographic algorithm performance based on the hardware cryptographic module is as follows:

[0119] 1. The hardware cryptographic module connects to multiple front-end virtual device nodes (hereinafter referred to as nodes for short) through hardware virtualization technology and receives weight configuration information (including the initial weight information of each node), and completes the initialization of related functions.

[0120] 2. The device node weight dynamic configurator (which can be abbreviated as the weight dynamic configurator for short) allocates data buffers for each node according to the number of nodes and the weights of the nodes.

[0121] Exemplarily, as Figure 2 shown, assume that the maximum number of nodes supported by the current hardware cryptographic module is M, the size of the entire buffer is N, and the weight dynamic configurator allocates buffer N for each node according to the number of nodes x (x ≤ M) and the weight of each node.

[0122] Exemplarily, the weight ratio of the nodes is the same as the ratio of the cryptographic algorithm performance of the hardware cryptographic module allocated to the nodes. Since the higher the performance allocated to the nodes, the greater their data traffic, the larger the data buffer allocated should be. This design can avoid data overflow in the buffer.

[0123] Exemplarily, the weight ratio of the nodes is the same as the ratio of the size of the data buffer space allocated to the nodes.

[0124] 3. The adaptive algorithm resource allocation balancer provides the currently selected data buffer to the data shunt controller according to the weight value given by the device node weight dynamic configurator through an adaptive adjustment method. The data shunt controller obtains the data to be processed from the currently selected data buffer and inputs it to the cryptographic algorithm input controller corresponding to the type of cryptographic algorithm.

[0125] Exemplarily, the adaptive adjustment method is implemented as follows:

[0126] 3.1. Assume that there are currently 3 data buffers, namely buffer 1, buffer 2, and buffer 3, and their respective corresponding initial weights and total weights are:

[0127] weight1 = 4, weight2 = 3, weight3 = 2, weight_all = 9

[0128] 3.2. According to Formula 1:

[0129] The buffer choose = Max{weight1, weight2, weight3}

[0130] That is, each time the data buffer with the largest current weight is selected.

[0131] According to Formula 1, buffer 1 is selected for the first time. Notify the data shunt controller to check and process the data to be processed in the current buffer 1. After the access to buffer 1 is completed, weight1 is updated to weight1(new) = weight1(now) - weight_all = 4 - 9 = -5.

[0132] 3.3. During the second buffer selection process, add the current weights of each buffer ( -5, 3, 2 in sequence) to the initial weights of each buffer respectively to obtain the weights of each buffer participating in the buffer selection ( -1, 6, 4 in sequence).

[0133] According to Formula 1, during the second buffer selection process, Max{weight1, weight2, weight3} = 6, that is, weight2. Therefore, buffer 2 is selected.

[0134] Notify the data shunt controller to check and process the data to be processed in the current buffer 2. After the access to buffer 2 is completed, weight2 is updated to weight2(new) = weight2(now) - weight_all = 6 - 9 = -3.

[0135] 3.4. During the third buffer selection process, add the current weights of each buffer ( -1, -3, 4 in sequence) to the initial weights of each buffer respectively to obtain the weights of each buffer participating in the buffer selection ( 3, 0, 6 in sequence).

[0136] According to Formula 1, during the third buffer selection process, Max{weight1, weight2, weight3} = 6, that is, weight3. Therefore, buffer 3 is selected.

[0137] Notify the data shunt controller to check and process the data to be processed in the current buffer 3. After the access to buffer 3 is completed, weight3 is updated to weight3(new) = weight3(now) - weight_all = 6 - 9 = -3.

[0138] The buffer selection is performed in the above manner, and the data buffers for the first 9 accesses are successively buffer 1, buffer 2, buffer 3, buffer 1, buffer 2, buffer 1, buffer 3, buffer 2, and buffer 1.

[0139] It can be seen that during the first 9 buffer selection processes, the number of times buffer 1, buffer 2, and buffer 3 are selected are 4, 3, and 2 respectively, which is consistent with the weight ratio of each buffer.

[0140] 4. The cryptographic algorithm input controller writes the received data to be processed into the input buffer of the corresponding algorithm core to achieve pipelined operation.

[0141] Exemplarily, the cryptographic algorithm may include the national cryptographic algorithms publicly disclosed in China currently, such as SM2, SM3, SM4, and the commonly used foreign cryptographic algorithms AES, DES, SHA256, etc.

[0142] Exemplarily, as Figure 3 shown, the implementation of the cryptographic algorithm input control is as follows:

[0143] 4.1. Each algorithm core within the current cryptographic algorithm gives the data volume D0 - Dn to be operated on in its respective input buffer.

[0144] Exemplarily, the initial value of the data volume to be operated on in the input buffer of each algorithm core is 0, and each data volume to be operated on increases as the data to be processed is written and decreases as the data is taken away by the algorithm core.

[0145] 4.2. Set the maximum data volume of the input buffer to N, where N = twice the maximum data length of the group, and the remaining buffer space Rn of each algorithm core input is Rn = N - Dn.

[0146] 4.3. The cryptographic algorithm input controller monitors R0 - Rn in real time and updates the current maximum Rmax = Max{R0, R1...Rn}.

[0147] Exemplarily, if there are multiple algorithm cores with the largest remaining input buffer space, the algorithm core with the smaller serial number is preferentially selected as the data input point.

[0148] 4.4. In the case of the presence of data to be processed input, if Rmax ≥ N / 2 at this time, the data can be input to the algorithm core corresponding to the current Rmax.

[0149] Through the above design, the cryptographic algorithm input controller only needs to determine whether the remaining input buffer space Rmax of the currently selected algorithm core satisfies being greater than or equal to N / 2 at the moment when there is data to be processed input, and then the data to be processed can be input, without comparing the length of the data to be processed, and the logical complexity is low.

[0150] It should be noted that in this embodiment, when there is input data to be processed and Rmax < N / 2, it can be determined that the data to be processed cannot be written into the input buffer.

[0151] Exemplarily, as Figure 4 shown, it is the input-output structure of a single algorithm core, which consists of an input buffer, an output buffer, and an algorithm core. The input buffer and the output buffer play a role in data buffering, and the algorithm core plays a role in operation. This method is applicable to block cipher operations. Through the pipelining design of the data buffer and the internal pipelining of the algorithm core, the pipelined operation of the entire operation path is formed, and the performance of the cryptographic algorithm is improved on the basis of the multi-core whole-column parallel operation structure.

[0152] 5. The algorithm output selector, based on multi-algorithm operations, controls the data merger controller to select the output buffer areas of different algorithms for data output through relevant calculation methods.

[0153] As Figure 5 shown, the algorithm output implementation process is as follows:

[0154] 5.1. Since the operation process of the hardware cryptographic algorithm is not affected by factors such as CPU performance, the time to complete the algorithm operation process is almost fixed when the clock frequency remains unchanged. Therefore, the time (i.e., the above-mentioned minimum unit time) for each cryptographic algorithm to complete the operation of the minimum data length can be obtained through simulation.

[0155] 5.2. Assume that the current hardware cryptographic module supports the encryption and decryption operations of three cryptographic algorithms, namely Algorithm 1, Algorithm 2, and Algorithm 3. Through simulation software, the operation times of the minimum data lengths l1, l2, and l3 of each algorithm are obtained as t1, t2, and t3 respectively, as the minimum time units for their respective operation processes.

[0156] 5.3. When there is data diversion in the data splitter controller, it writes the data length information into the corresponding algorithm's length information cache unit. The algorithm output selector determines whether there is data in the length information cache units of each algorithm. Assume that there is data operation for each cryptographic algorithm. The algorithm output selector reads out a cache length information of each cryptographic algorithm, assumed to be L1, L2, and L3 respectively. According to Formula 2:

[0157] Tn = Ln / ln*tn

[0158] The operation completion times T1, T2, and T3 of each algorithm, as well as Min{T1, T2, T3}, are obtained.

[0159] 5.4. Assume that the current Min{T1, T2, T3} = T2 and T2 is not 0. Then, notify the data merging controller to select Algorithm 2 for data output currently, and update T1(new) = T1 - T2 and T3(new) = T3 - T2.

[0160] If there is still data in the length information buffer unit of Algorithm 2 at this time, the next length information needs to be read out, and T2(new) is updated to the newly calculated T2 time; otherwise, T2(new) = 0.

[0161] Loop and execute the operations in 5.3 and 5.4 to control the data merging controller to select the data (data after password processing) in the output buffers of different algorithms for output.

[0162] Exemplarily, the overall structure diagram of the password algorithm performance adaptive allocation scheme provided by this application can be as Figure 6 shown.

[0163] As Figure 6 shown, the weight dynamic configurator can allocate data buffers for each node according to the number of nodes and the weights of the nodes.

[0164] The adaptive algorithm resource allocation balancer selects a data buffer through an adaptive adjustment method according to the weight value given by the device node weight dynamic configurator, and provides the currently selected data buffer to the data shunt controller.

[0165] The data shunt controller obtains the data to be processed from the currently selected data buffer and inputs it to the password algorithm input controller corresponding to the password algorithm type.

[0166] For any password algorithm, the password algorithm input controller can write the received data to be processed into the selected input buffer according to the remaining buffer space of the input buffer of each algorithm core. The algorithm core reads the data to be processed from the input buffer, performs password processing, and writes the data after password processing into the output buffer to achieve pipelined operation.

[0167] In the case of data shunting in the data shunt controller, it can write the data length information into the length information buffer unit corresponding to the algorithm. The algorithm output selector determines the operation completion time of each algorithm according to the buffer length information recorded in the length information buffer unit of each algorithm, and selects the algorithm for data output based on the operation completion time of different algorithms, and notifies the data merging controller of the algorithm for data output currently. The data merging controller outputs the data in the output buffer corresponding to the algorithm.

[0168] The method provided by this application has been described above. Next, the device provided by this application will be described:

[0169] Please refer to Figure 7 , which is a schematic structural diagram of a password algorithm performance adaptive allocation device based on a hardware password module provided by an embodiment of the present application. As Figure 7 shown, the password algorithm performance adaptive allocation device based on the hardware password module may include:

[0170] An allocation unit 710, configured to allocate data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node; wherein, the size of the data buffer allocated to each virtual device node is positively correlated with the weight of each virtual device node;

[0171] A selection unit 720, configured to select a data buffer according to the weights of each data buffer; wherein, the weight of the data buffer allocated to each virtual device node is determined according to the weight of the virtual device node;

[0172] A writing unit 730, configured to write the data to be processed read from the currently selected data buffer into the input buffer of the first target password algorithm according to the first target password algorithm corresponding to the currently selected data buffer;

[0173] An output unit 740, configured to output the data after password processing; wherein, the data after password processing is obtained by performing password processing on the data to be processed in the input buffer by using the first target password algorithm.

[0174] In some embodiments, the allocation unit 710 allocates data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node, including:

[0175] Determining the total weight of the virtual device nodes according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node;

[0176] For any virtual device node, determining the weight ratio of the virtual device node according to the weight of the virtual device node and the total weight of the virtual device nodes;

[0177] Allocating a data buffer with a ratio consistent with the weight ratio for the virtual device node from the entire buffer according to the weight ratio of the virtual device node.

[0178] In some embodiments, the selection unit 720 selects a data buffer according to the weights of each data buffer, including:

[0179] For any selection of a data buffer, determining the currently selected data buffer as the data buffer with the highest current weight according to the current weights of each data buffer;

[0180] Among them, after each data buffer selection, the weight of the selected data buffer in that selection is reduced.

[0181] In some embodiments, for the first data buffer selection, the current weight of each data buffer is the initial weight;

[0182] For non-first data buffer selections, the current weight of any data buffer is the sum of the weight of the data buffer after the previous data buffer selection and the initial weight of the data buffer;

[0183] After a data buffer selection, the weight of the selected data buffer is updated to the difference between the current weight of the data buffer and the total initial weight of all data buffers; the weights of the unselected data buffers remain unchanged.

[0184] In some embodiments, the writing unit 730 writes the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer, including:

[0185] When there are multiple algorithm cores for the first target cryptographic algorithm, determine the algorithm core with the largest remaining buffer space according to the remaining buffer spaces of the input buffers of the algorithm cores of the first target cryptographic algorithm;

[0186] When the remaining buffer space of the algorithm core with the largest remaining buffer space is greater than or equal to the maximum data length, determine this algorithm core as the target algorithm core.

[0187] In some embodiments, the output unit 740 outputs the data after cryptographic processing, including:

[0188] When there are multiple different cryptographic algorithms in the hardware cryptographic module, obtain the first buffer length information to be processed for each cryptographic algorithm;

[0189] According to the obtained buffer length information of each cryptographic algorithm, the minimum data length of each cryptographic algorithm, and the minimum time unit of each cryptographic algorithm, determine the operation completion time of each cryptographic algorithm; among them, for any cryptographic algorithm, the minimum time unit of the cryptographic algorithm is the time for cryptographic processing of data with the minimum data length of the cryptographic algorithm;

[0190] According to the operation completion times of each cryptographic algorithm, determine the second target cryptographic algorithm that is currently performing data output as the cryptographic algorithm with the minimum and non-zero operation completion time, and output the data after cryptographic processing saved in the output buffer of the second target cryptographic algorithm.

[0191] In some embodiments, the output unit 740 is further configured to, when determining the second target cryptographic algorithm for current data output, determine, for other cryptographic algorithms other than the second target cryptographic algorithm, the difference between the operation completion time of each other cryptographic algorithm and the current operation completion time of the second target cryptographic algorithm as the latest operation completion time of each other cryptographic algorithm;

[0192] For the second target cryptographic algorithm, when there is the next cache length information to be processed, determine the latest operation completion time of the second target cryptographic algorithm according to the next cache length information to be processed, the minimum data length of the second target cryptographic algorithm, and the minimum time unit of the second target cryptographic algorithm;

[0193] Determine a new second target cryptographic algorithm for data output according to the latest operation completion time of each cryptographic algorithm.

[0194] An embodiment of the present application further provides an electronic device, including a processor and a memory. The memory is used to store a computer program. The processor is configured to implement the disk encryption method based on threshold cryptography described above when executing the program stored in the memory.

[0195] Please refer to Figure 8 , which is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present application. The electronic device may include a processor 801 and a memory 802 storing machine-executable instructions. The processor 801 and the memory 802 may communicate via a system bus 803. And by reading and executing the machine-executable instructions corresponding to the cryptographic algorithm performance adaptive allocation logic based on the hardware cryptographic module stored in the memory 802, the processor 801 may execute the cryptographic algorithm performance adaptive allocation method based on the hardware cryptographic module described above.

[0196] The memory 802 mentioned in this article may be any electronic, magnetic, optical or other physical storage device, which may contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium may be: RAM (Radom Access Memory, random access memory), volatile memory, non-volatile memory, flash memory, storage drive (such as a hard disk drive), solid state drive, any type of storage disk (such as an optical disk, DVD, etc.), or a similar storage medium, or a combination thereof.

[0197] In some embodiments, a machine-readable storage medium is also provided, such as Figure 8The memory 802 therein stores machine-executable instructions, and when the machine-executable instructions are executed by a processor, the method for adaptively allocating the cryptographic algorithm performance based on a hardware cryptographic module described above is implemented. For example, the machine-readable storage medium may be a ROM, a RAM, a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0198] An embodiment of the present application further provides a computer program product, storing a computer program, and when the processor executes the computer program, the processor is caused to execute the method for adaptively allocating the cryptographic algorithm performance based on a hardware cryptographic module described above.

Claims

1. A method for adaptively allocating the performance of a cryptographic algorithm based on a hardware cryptographic module, characterized in that Including: Allocating data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node; wherein, the size of the data buffer allocated to each virtual device node is positively correlated with the weight of each virtual device node; Selecting data buffers according to the weights of each data buffer; wherein, the weights of the data buffers allocated to each virtual device node are determined according to the weights of the virtual device nodes; Writing the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer; Outputting the data after cryptographic processing; wherein, the data after cryptographic processing is obtained by performing cryptographic processing on the data to be processed in the input buffer using the first target cryptographic algorithm.

2. The method according to claim 1, wherein The step of allocating data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node includes: Determining the total weight of the virtual device nodes according to the number of virtual device nodes connected to the hardware password module and the weights of each virtual device node; For any virtual device node, determining the weight ratio of the virtual device node according to the weight of the virtual device node and the total weight of the virtual device nodes; Allocating a data buffer for the virtual device node from the entire buffer according to the weight ratio of the virtual device node, and the ratio of the allocated data buffer is the same as the weight ratio.

3. The method according to claim 1, characterized in that, The step of selecting data buffers according to the weights of each data buffer includes: For any selection of data buffers, determining the data buffer with the highest current weight as the currently selected data buffer according to the current weights of each data buffer; Wherein, after each selection of data buffers, the weight of the data buffer selected in this selection is reduced.

4. The method according to claim 3, characterized in that For the first selection of data buffers, the current weights of each data buffer are the initial weights; For non-first selections of data buffers, the current weight of any data buffer is the sum of the weight of the data buffer after the previous selection of data buffers and the initial weight of the data buffer; After a selection of data buffers, the weight of the selected data buffer is updated to the difference between the current weight of the data buffer and the total initial weight of each data buffer; the weights of the unselected data buffers remain unchanged.

5. The method according to claim 1, characterized in that The step of writing the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm core according to the first target cryptographic algorithm corresponding to the currently selected data buffer includes: In the case where there are multiple algorithm cores for the first target cryptographic algorithm, determining the algorithm core with the largest remaining buffer space according to the remaining buffer spaces of the input buffers of each algorithm core of the first target cryptographic algorithm; In the case where the remaining buffer space of the algorithm core with the largest remaining buffer space is greater than or equal to the maximum data length, determining the algorithm core as the target algorithm core.

6. The method according to claim 1, wherein The step of outputting the data after cryptographic processing includes: In the case where there are multiple different cryptographic algorithms in the hardware password module, obtaining the first buffer length information to be processed by each cryptographic algorithm currently; Determine the operation completion time of each cryptographic algorithm based on the cache length information of each cryptographic algorithm, the minimum data length of each cryptographic algorithm, and the minimum time unit of each cryptographic algorithm; wherein, for any cryptographic algorithm, the minimum time unit of the cryptographic algorithm is the time for performing cryptographic processing on the data with the minimum data length of the cryptographic algorithm. Based on the operation completion time of each cryptographic algorithm, determine the second target cryptographic algorithm that has the minimum and non-zero operation completion time for current data output, and output the data after cryptographic processing stored in the output buffer of the second target cryptographic algorithm.

7. The method according to claim 6, wherein When the second target cryptographic algorithm for current data output is determined, the method further includes: For other cryptographic algorithms other than the second target cryptographic algorithm, determine the difference between the operation completion time of each other cryptographic algorithm and the current operation completion time of the second target cryptographic algorithm as the latest operation completion time of each other cryptographic algorithm. For the second target cryptographic algorithm, when there is a next cache length information to be processed, determine the latest operation completion time of the second target cryptographic algorithm based on the next cache length information to be processed, the minimum data length of the second target cryptographic algorithm, and the minimum time unit of the second target cryptographic algorithm. Based on the latest operation completion time of each cryptographic algorithm, determine a new second target cryptographic algorithm for data output.

8. A password algorithm performance adaptive allocation device based on a hardware password module, characterized in that, It includes: An allocation unit for allocating data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node; wherein, the size of the data buffer allocated to each virtual device node is positively correlated with the weight of each virtual device node. A selection unit for selecting a data buffer according to the weights of each data buffer; wherein, the weights of the data buffers allocated to each virtual device node are determined according to the weights of the virtual device nodes. A writing unit for writing the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer. An output unit for outputting the data after cryptographic processing; wherein, the data after cryptographic processing is obtained by performing cryptographic processing on the data to be processed in the input buffer using the first target cryptographic algorithm.

9. The device according to claim 8, characterized in that, The allocation unit allocates data buffers for each virtual device node according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node, including: Determine the total weight of the virtual device nodes according to the number of virtual device nodes connected to the hardware cryptographic module and the weights of each virtual device node. For any virtual device node, determine the weight ratio of the virtual device node according to the weight of the virtual device node and the total weight of the virtual device nodes. Allocate a data buffer with a ratio consistent with the weight ratio for the virtual device node from the entire buffer according to the weight ratio of the virtual device node. And / or The selection unit selects a data buffer according to the weights of each data buffer, including: For any selection of a data buffer, based on the current weights of each data buffer, the data buffer with the highest current weight is determined as the currently selected data buffer; Among them, after each selection of a data buffer, the weight of the data buffer selected in that selection is reduced; Among them, for the first selection of a data buffer, the current weights of each data buffer are the initial weights; For non-first selection of a data buffer, the current weight of any data buffer is the sum of the weight of the data buffer after the previous selection of the data buffer and the initial weight of the data buffer; After a selection of a data buffer, the weight of the selected data buffer is updated to the difference between the current weight of the data buffer and the total initial weight of each data buffer; the weights of the unselected data buffers remain unchanged; and / or The writing unit writes the data to be processed read from the currently selected data buffer into the input buffer of the first target cryptographic algorithm according to the first target cryptographic algorithm corresponding to the currently selected data buffer, including: In the case where there are multiple algorithm cores for the first target cryptographic algorithm, based on the remaining buffer space of the input buffers of each algorithm core of the first target cryptographic algorithm, determine the algorithm core with the largest remaining buffer space; In the case where the remaining buffer space of the algorithm core with the largest remaining buffer space is greater than or equal to the maximum data length, determine the algorithm core as the target algorithm core; and / or The output unit outputs the data after cryptographic processing, including: In the case where there are multiple different cryptographic algorithms in the hardware cryptographic module, obtain the first cache length information to be processed for each cryptographic algorithm; Based on the obtained cache length information of each cryptographic algorithm, the minimum data length of each cryptographic algorithm, and the minimum time unit of each cryptographic algorithm, determine the operation completion time of each cryptographic algorithm; among them, for any cryptographic algorithm, the minimum time unit of the cryptographic algorithm is the time for cryptographic processing of data with the minimum data length of the cryptographic algorithm; Based on the operation completion times of each cryptographic algorithm, determine the second target cryptographic algorithm that is currently performing data output and has the minimum non-zero operation completion time, and output the data after cryptographic processing saved in the output buffer of the second target cryptographic algorithm; Among them, the output unit is further configured to, in the case where the second target cryptographic algorithm for currently performing data output is determined, for other cryptographic algorithms other than the second target cryptographic algorithm, determine the difference between the operation completion time of each other cryptographic algorithm and the current operation completion time of the second target cryptographic algorithm as the latest operation completion time of each other cryptographic algorithm; For the second target cryptographic algorithm, in the case where there is a next cache length information to be processed, based on the next cache length information to be processed, the minimum data length of the second target cryptographic algorithm, and the minimum time unit of the second target cryptographic algorithm, determine the latest operation completion time of the second target cryptographic algorithm; Based on the latest operation completion times of each cryptographic algorithm, determine the new second target cryptographic algorithm for performing data output.

10. An electronic device, characterized in that, Includes a processor and a memory, where A memory for storing a computer program; A processor for implementing the method according to any one of claims 1-7 when executing the program stored on the memory.

Citation Information

Patent Citations

  • Method for dispatching I / O of asymmetry virtual machine based on multi-core dynamic partitioning

    CN101706742A

  • Hardware password module multi-core scheduling algorithm driving method and device and electronic equipment

    CN116684074A