Encryption and decryption method and system based on PDCP
By using XDP on the NXP1046 platform for data diversion and PDCP data encryption and decryption processing in the kernel state, the problem of limited performance optimization effect of hardware encryption and decryption solutions on this platform is solved, and efficient PDCP data processing is achieved.
Patent Information
- Application Number
- CN202510275173.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-24
AI Technical Summary
The existing hardware encryption and decryption solutions have problems with limited performance optimization effects and excessive CPU resource utilization on the NXP1046 platform, making it difficult to achieve efficient PDCP data processing on resource-constrained embedded platforms.
By using XDP in the network card driver for data diversion, GTPU data is forwarded directly to the kernel, avoiding multiple pass paths of data in the kernel, and encrypting and decrypting PDCP data in the kernel state, and using the hardware encryption and decryption driver module for integrity protection and encryption and decryption operations.
It reduces memory copy and system calls, reduces CPU usage, improves encryption and decryption performance, and realizes efficient PDCP data processing on resource-constrained platforms.
Smart Images

Figure CN120201416A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to an encryption and decryption method based on PDCP. Background Art
[0002] In the 3GPP protocol stack, the PDCP (Packet Data Convergence Protocol) layer is responsible for performing integrity protection (hereinafter referred to as integrity protection) and encryption and decryption operations on data to ensure the security and integrity of data during transmission. The PDCP layer mainly uses three algorithms to implement these functions: SNOW 3G, AES, and ZUC. Although these algorithms perform excellently in terms of security, their computational complexity is relatively high. Especially when implemented in software, they will consume a large amount of CPU resources, resulting in a decline in system performance.
[0003] To address this challenge, hardware encryption and decryption technologies are introduced to reduce the burden on the CPU. Hardware encryption and decryption perform encryption, decryption, and integrity protection operations through dedicated hardware modules, which can significantly improve the processing efficiency and reduce the CPU load. The currently used platform is NXP1046. Although this chip only has 4 cores, its built-in hardware encryption and decryption module provides hardware support for the encryption and decryption operations of the PDCP layer.
[0004] However, in practical applications, the implementation method of hardware encryption and decryption has an important impact on system performance. Currently, there are mainly two hardware encryption and decryption implementation schemes on the NXP1046 platform: 1. Kernel-mode encryption and decryption: As Figure 1 shown, the downlink data is received through the Socket from the backhaul, and then passed to the PDCP module of the L2 layer. The PDCP module calls the kernel driver interface to perform hardware encryption, decryption, and integrity protection operations in the kernel mode. After completion, the data is returned to the user mode and handed over to the RLC (Radio Link Control) layer for subsequent processing. The processing flow of the uplink data is the opposite. This scheme utilizes the hardware encryption and decryption module, but due to the need for multiple switches and copies of data between the kernel mode and the user mode, the optimization effect of system performance is greatly reduced. Frequent context switches and data copies prevent the full play of the advantages of hardware encryption and decryption.
[0005] 2. DPDK User - mode Encryption and Decryption: Utilize the DPDK (Data Plane Development Kit) framework provided by the NXP1046 platform to directly implement hardware encryption and decryption operations in the user - mode. This approach avoids data copying between the kernel - mode and the user - mode, reducing the overhead of context switching. However, it requires both the post - transfer and the encryption / decryption operations to use the DPDK framework, which means that two CPU cores are needed to separately handle the post - transfer and the encryption / decryption tasks. For a platform like NXP1046 with only 4 cores, this way of resource occupation is obviously infeasible, especially in the case of limited resources and unable to meet the overall system requirements.
[0006] In summary, the existing two hardware encryption and decryption solutions both have certain limitations on the NXP1046 platform. Although the kernel - mode encryption and decryption solution utilizes hardware acceleration, due to frequent kernel - mode and user - mode switches, the performance optimization effect is limited; while the DPDK user - mode encryption and decryption solution reduces data copying and context switching, but has too high a CPU resource occupation and is difficult to be widely adopted in practical applications. Therefore, there is an urgent need for a new hardware encryption and decryption implementation solution that can minimize the CPU resource occupation while ensuring performance, so as to achieve efficient PDCP data processing on resource - constrained embedded platforms. Summary of the Invention
[0007] The present invention aims to at least solve one of the technical problems existing in the prior art. For this reason, the present invention proposes an encryption and decryption method based on PDCP, which can reduce memory copying, reduce system calls for encryption and decryption, reduce CPU resource occupation, and achieve encryption and decryption performance.
[0008] An encryption and decryption method based on PDCP according to an embodiment of the present invention includes: S1. In the network card driver, use XDP to split the received network data, directly forward the GTPU data to the kernel, and at the same time, the non - GTPU data continues to go through the standard kernel protocol stack; S2. The GTPU kernel module receives the GTPU data split by XDP and converts it into a PDCP - processable format to form PDCP data; S3. The PDCP kernel proxy module receives the PDCP data and, according to the parameters in the shared memory, calls the hardware encryption and decryption driver module to perform integrity protection and encryption / decryption operations on the data.
[0009] According to the encryption and decryption method based on PDCP in the embodiments of the present invention, by sinking GTPU and PDCP to the kernel for processing and using XDP for traffic splitting, GTPU data directly skips the TCP / IP protocol stack from the driver layer, and XDP directly goes to the kernel GTPU, shortening the processing delay, reducing one memory copy, and reducing the system calls of the socket. At the same time, GTPU and PDCP perform encryption and decryption of data in the kernel, reducing memory copy and system calls for encryption and decryption, greatly reducing the CPU occupancy and achieving encryption and decryption performance.
[0010] In some embodiments of the present invention, step S1 specifically includes: S11. In the network card driver, add XDP for splitting the received network data; S12. Determine whether the data is UDP protocol and the destination port is 2152 to determine whether it is GTPU data; S13. Directly forward the GTPU data to the GTPU kernel module through XDP, and at the same time, the non-GTPU data continues to go through the standard kernel protocol stack to achieve traffic splitting.
[0011] In some embodiments of the present invention, the setting of XDP in step S11 specifically includes: Create an AF_XDP Socket through the user-mode Socket system call; Allocate an RX ring and a TX ring for each AF_XDP Socket, and register the RX ring and the TX ring through the Socket options XDP_RX_RING and XDP_TX_RING respectively; wherein, the RX ring and the TX ring store descriptor sets, each descriptor points to a buffer in UMEM, and a frame is referenced by referring to the offset of the buffer in UMEM; Create a Filling ring and a Completion ring in UMEM for managing the reception and transmission of data packets.
[0012] In some embodiments of the present invention, the Filling ring is used to issue descriptors for GTPU, enabling XDP to fill the received data packets into the RX ring; when a data packet is received, XDP fills the ready descriptors into the RX ring; the GTPU kernel module waits for the arrival of the ready descriptors in the RX ring through the poll system call.
[0013] In some embodiments of the present invention, the Completion ring is used to notify XDP that one or more data packets are ready and request the kernel to send data; the GTPU kernel module triggers XDP to send data packets by writing to the Completion ring; and through the collaboration of the Filling ring and the Completion ring, zero copy is achieved during the reception and transmission of data packets.
[0014] In some embodiments of the present invention, step S2 specifically includes: S21, sink GTPU to kernel state; S22, the GTPU core module receives the GTPU data diverted through the XDP, parses the GTPU data, strips off the GTPU header, and converts it into a format that can be processed by the PDCP layer; S23. Forward the converted data directly to the next processing port.
[0015] In some embodiments of the present invention, step S3 specifically includes: S31, deploying the PDCP proxy service in the kernel state, and performing data interaction with the PDCP process in the user state through the shared memory; S32, the user-mode PDCP process is responsible for managing the overall service flow, and transmits UE-related information and encryption and decryption parameters of PDCP data to the PDCP kernel proxy module through shared memory; S33, the PDCP kernel agent receives data from the GTPU kernel module in kernel state, and calls the hardware encryption and decryption driver module to perform integrity protection and encryption and decryption operations on the data according to the parameters in the shared memory; S34: Submit the encrypted and decrypted data to the user-mode PDCP process for subsequent processing.
[0016] The present invention also discloses a system for improving PDCP encryption and decryption performance of an integrated NR base station system, including: XDP shunt module, used to quickly shunt GTPU data at the network card driver layer; The GTPU core processing module is used to receive the GTPU data diverted by XDP, strip the GTPU header and convert it into a format that can be processed by PDCP; The PDCP kernel proxy module is used to exchange parameters between the kernel state and the user state PDCP process through shared memory, and call the hardware encryption and decryption driver module to process the data; The hardware encryption and decryption driver module is used to perform integrity protection and encryption and decryption operations through a dedicated hardware accelerator.
[0017] The present invention also discloses a computer-readable storage medium storing program code for implementing the above method.
[0018] The present invention also discloses a network device, including a processor and a memory, where the memory stores program code, and when the processor executes the program code, the above method is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 is a flowchart of the existing kernel-mode encryption and decryption method; Figure 2 is a signal transmission schematic diagram of the present invention; Figure 3 is a schematic diagram of the kernel mode of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] The embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present invention and should not be construed as limiting the present invention.
[0021] The following refers to Figures 1 - 3 to describe a PDCP-based encryption and decryption method according to an embodiment of the present invention, including.
[0022] S1. In the network card driver, use XDP to split the received network data, directly forward the GTPU data to the kernel, and at the same time, the non-GTPU data continues to go through the standard kernel protocol stack; S2. The GTPU kernel module receives the GTPU data split by XDP and converts it into a PDCP-processable format to form PDCP data; S3. The PDCP kernel proxy module receives the PDCP data and, according to the parameters in the shared memory, calls the hardware encryption and decryption driver module to perform integrity protection and encryption and decryption operations on the data.
[0023] It can be understood that first use XDP to split all data. The non-GTPU data continues to go through the standard kernel protocol stack, while the GTPU data is directly forwarded to the GTPU kernel module, reducing the data transfer path in the kernel and delivering the data to the GTPU at the fastest speed after the network card receives the data; the GTPU directly converts the split GTPU data into a PDCP-processable format, forms PDCP data, and copies and forwards it. Compared with the traditional method, it reduces the processing of the tcp / ip protocol stack, also reduces the switching between the kernel mode and the user mode of the Socket, and at the same time reduces one memory copy and realizes the encryption and decryption performance.
[0024] In view of this, the PDCP in the kernel is responsible for receiving and sending data from and to the kernel GTPU. At the same time, it obtains the corresponding parameters from the shared memory and delivers them to the hardware encryption and decryption driver module for data integrity protection, encryption and decryption, and then delivers them to the user-space PDCP process. Compared with the traditional method, it reduces inter-process communication, reduces system calls from the user space to the kernel space, and reduces one memory copy.
[0025] According to the PDCP-based encryption and decryption method of the embodiments of the present invention, by sinking GTPU and PDCP to the kernel for processing and using XDP for traffic splitting, GTPU data directly skips the TCP / IP protocol stack from the driver layer, and XDP directly goes to the kernel GTPU, shortening the processing delay, reducing one memory copy, and reducing the system calls of the socket. At the same time, GTPU and PDCP process encrypted and decrypted data in the kernel, reducing memory copy and system calls for encryption and decryption, greatly reducing CPU occupancy and achieving encryption and decryption performance.
[0026] In some embodiments of the present invention, step S1 specifically includes: S11. In the network card driver program, add XDP for splitting the received network data; S12. Determine whether the data is UDP protocol and the destination port is 2152 to determine whether it is GTPU data; S13. Directly forward the GTPU data to the GTPU kernel module through XDP, and at the same time, non-GTPU data continues to go through the standard kernel protocol stack to achieve traffic splitting of the data.
[0027] In order to implement XDP traffic splitting, in some embodiments of the present invention, it is necessary to create an AF_XDP Socket through the user-space Socket system call; after creation, allocate an RX ring and a TX ring for each AF_XDP Socket, and register the RX ring and the TX ring through the Socket options XDP_RX_RING and XDP_TX_RING respectively. Each Socket must have at least one of the rings. The RX ring and the TX ring store descriptor sets, each descriptor points to a buffer in the UMEM, and the frame is referenced by referring to the offset of the buffer in the UMEM. At the same time, the UMEM also contains two rings: the Filling ring and the Completion ring, which are used to manage the reception and transmission of data packets.
[0028] In some embodiments of the present invention, the Filling ring is used for the GTPU to send descriptors so that the XDP can fill the received data packets into the RX ring; when the data packets are received, the XDP fills the ready descriptors into the RX ring; the GTPU waits for the arrival of the ready descriptors in the RX ring through the poll system call.
[0029] In some embodiments of the present invention, the Completion ring is used to notify XDP that one or more data packets are ready and request the kernel to send data; GTPU triggers XDP to send data packets by writing to the Completion ring; and through the collaboration of the Filling ring and the Completion ring, zero copy is achieved during the reception and transmission of data packets.
[0030] It should be noted that compared with conventional AF_XDP, the four rings here are not ultimately used in user mode to use XDP socket, but are used between GTPU and XDP in kernel mode, which further optimizes the latency of data transmission.
[0031] like Figure 3 As shown in the figure, the PDCP kernel agent and GTPU need to perform memory copying, copying the UMEM data to the continuous physical layer memory used by the encryption and decryption module, and after the encryption and decryption processing, the data is copied once more to the user-mode PDCP process. Therefore, no matter whether it is uplink or downlink, the data only needs to be copied twice.
[0032] In some embodiments of the present invention, step S2 specifically includes: S21, sink GTPU to kernel state; S22, the GTPU core module receives the GTPU data diverted through the XDP, parses the GTPU data, strips off the GTPU header, and converts it into a format that can be processed by the PDCP layer; S23. Forward the converted data directly to the next processing port.
[0033] In some embodiments of the present invention, step S3 specifically includes: S31, deploying the PDCP proxy service in the kernel state, and performing data interaction with the PDCP process in the user state through the shared memory; S32, the user-mode PDCP process is responsible for managing the overall service flow, and transmits UE-related information and encryption and decryption parameters of PDCP data to the PDCP kernel proxy module through shared memory; S33. The PDCP kernel proxy receives data from the GTPU kernel module in the kernel state and, according to the parameters in the shared memory, calls the hardware encryption and decryption driver module to perform integrity protection and encryption / decryption operations on the data; S34. Deliver the encrypted / decrypted data to the user-space PDCP process for subsequent processing.
[0034] In view of this, in order to implement the present invention, the following operations need to be performed first during actual use: Step 1. After the system starts, first initialize the network interface, and then load the compiled XDP into this network interface.
[0035] Step 2. Create UMEM and AF_XDP socket, and initialize four rings.
[0036] Step 3. Load the GTPU kernel processing module and pass the fd of the AF_XDP socket to the GTPU kernel processing module.
[0037] Step 4. Load the PDCP kernel proxy module and initialize the hardware encryption and decryption module.
[0038] Step 5. The user-space PDCP process starts, configures the shared memory with the PDCP kernel proxy module. Then the service can start.
[0039] After the above operations are completed, it can be used for subsequent data processing. Through actual measurement, for the processing of the same amount of data, the CPU occupancy of the present invention is only 30% of the original.
[0040] In summary, the present invention sinks PDCP and GTPU to the kernel and uses XDP for data diversion, so that GTPU data directly skips the TCP / IP protocol stack from the driver layer, and XDP directly goes to the kernel GTPU, shortening the processing delay, reducing one memory copy, and reducing the system call of the socket; GTPU and PDCP process encrypted / decrypted data in the kernel, reducing memory copy and the system call of encryption / decryption, greatly reducing the CPU occupancy.
[0041] In addition, the method of the present invention is applicable to various base station scenarios, not limited to the hardware form and the specifications of the cell, and such an architecture can reduce the CPU occupancy in this way.
[0042] The present invention also discloses a system for improving the PDCP encryption / decryption performance of an integrated NR base station system, including: An XDP diversion module for quickly diverting GTPU data at the network card driver layer; A GTPU kernel processing module for receiving the GTPU data diverted by XDP, stripping the GTPU header and converting it into a format processable by PDCP; The PDCP kernel proxy module is used to interact parameters between the kernel state and the user state PDCP processes through shared memory, and call the hardware encryption and decryption driver module to process data. The hardware encryption and decryption driver module is used to perform integrity protection and encryption and decryption operations through a dedicated hardware accelerator.
[0043] For the system according to the embodiment of the present invention, by sinking GTPU and PDCP to the kernel state, the XDP shunting module quickly shunts GTPU data at the network card driver layer. The shunted GTPU data is processed by the GTPU kernel processing module, converted into a format processable by PDCP, and transmitted to the PDCP kernel proxy module. The PDCP kernel proxy module interacts parameters between the kernel state and the user state PDCP processes through shared memory, and calls the hardware encryption and decryption driver module to process data to implement the encryption and decryption function. Among them, GTPU data directly skips the TCP / IP protocol stack from the driver layer, and XDP directly goes to the kernel GTPU, shortening the processing delay, reducing one memory copy, and reducing the system call of the socket. At the same time, GTPU and PDCP process encrypted and decrypted data in the kernel, reducing memory copy and the system call of encryption and decryption, greatly reducing the CPU occupancy and achieving the encryption and decryption performance.
[0044] The present invention also discloses a computer-readable storage medium storing program codes for implementing the above method.
[0045] The present invention also discloses a network device including a processor and a memory. The memory stores program codes, and when the processor executes the program codes, the above method is implemented.
[0046] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the claims and their equivalents.
Claims
1. A PDCP-based encryption and decryption method, characterized in that: The method includes: S1. In the network card driver, XDP is used to divert the received network data and forward the GTPU data directly to the kernel, while non-GTPU data continues to use the standard kernel protocol stack; S2, the GTPU core module receives the GTPU data diverted by XDP and converts it into a format that can be processed by PDCP to form PDCP data; S3. The PDCP kernel proxy module receives the PDCP data and calls the hardware encryption and decryption driver module to perform integrity protection and encryption and decryption operations on the data according to the parameters in the shared memory.
2. The PDCP-based encryption and decryption method according to claim 1, characterized in that: The step S1 specifically includes: S11. In the network card driver, an XDP is added for diverting the received network data; S12, judging whether the data is UDP protocol and the destination port is 2152, to determine whether it is GTPU data; S13, forwarding the GTPU data directly to the GTPU kernel module through XDP, while non-GTPU data continues to go through the standard kernel protocol stack to achieve data diversion.
3. The PDCP-based encryption and decryption method according to claim 2, characterized in that: The setting of XDP in step S11 specifically includes: Create AF_XDP Socket through user-mode Socket system call; Allocate an RX ring and a TX ring to each AF_XDP Socket, and register the RX ring and TX ring through the Socket options XDP_RX_RING and XDP_TX_RING respectively; the RX ring and TX ring store descriptor sets, each descriptor points to a buffer in UMEM, and references the frame by referencing the offset of the buffer in UMEM; Filling ring and Completion ring are created in UMEM to manage the reception and sending of data packets.
4. The PDCP-based encryption and decryption method according to claim 3, characterized in that: The Filling ring is used by GTPU to send descriptors, so that XDP can fill the received data packets into the RX ring; when a data packet is received, XDP fills the ready descriptors into the RX ring; The GTPU kernel module waits for the arrival of the ready descriptor in the RX ring through the poll system call.
5. The PDCP-based encryption and decryption method according to claim 3, characterized in that: The Completion ring is used to notify XDP that one or more data packets are ready and request the kernel to send data; the GTPU kernel module triggers XDP to send data packets by writing to the Completion ring; through the collaboration of the Filling ring and the Completion ring, zero copy is achieved during the reception and transmission of data packets.
6. The PDCP-based encryption and decryption method according to claim 1, characterized in that: The step S2 specifically includes: S21, sink GTPU to kernel state; S22, the GTPU core module receives the GTPU data diverted through the XDP, parses the GTPU data, strips off the GTPU header, and converts it into a format that can be processed by the PDCP layer; S23. Forward the converted data directly to the next processing port.
7. The PDCP-based encryption and decryption method according to claim 1, characterized in that: The step S3 specifically includes: S31, deploying the PDCP proxy service in the kernel state, and performing data interaction with the PDCP process in the user state through the shared memory; S32, the user-mode PDCP process is responsible for managing the overall service flow, and transmits UE-related information and encryption and decryption parameters of PDCP data to the PDCP kernel proxy module through shared memory; S33, the PDCP kernel agent receives data from the GTPU kernel module in kernel state, and calls the hardware encryption and decryption driver module to perform integrity protection and encryption and decryption operations on the data according to the parameters in the shared memory; S34: Submit the encrypted and decrypted data to the user-mode PDCP process for subsequent processing.
8. A system for improving PDCP encryption and decryption performance of an integrated NR base station system, characterized in that: include: XDP shunt module, used to quickly shunt GTPU data at the network card driver layer; The GTPU core processing module is used to receive the GTPU data diverted by XDP, strip the GTPU header and convert it into a format that can be processed by PDCP; The PDCP kernel proxy module is used to exchange parameters between the kernel state and the user state PDCP process through shared memory, and call the hardware encryption and decryption driver module to process the data; The hardware encryption and decryption driver module is used to perform integrity protection and encryption and decryption operations through a dedicated hardware accelerator.
9. A computer-readable storage medium, characterized in that: The program code for implementing the method according to any one of claims 1 to 7 is stored.
10. A network device, characterized in that: The method comprises a processor and a memory, wherein the memory stores program codes, and when the processor executes the program codes, the method according to any one of claims 1 to 7 is implemented.