Method, device and equipment for encrypting and decrypting multiple data streams

By setting the counter cache and message authentication code intermediate cache in the GCM engine, and independently processing the counters and intermediate values of multiple data streams, the problems of resource waste and errors in data communication between PCIe devices are solved, and efficient data transmission and bandwidth utilization are achieved.

CN120372637APending Publication Date: 2025-07-25T-HEAD (SHANGHAI) SEMICON CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510375707.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

When data communication between PCIe devices is carried out, the GCM mode in the prior art is prone to resource waste and encryption and decryption errors when processing multiple data streams, resulting in incorrect data transmission or insufficient bandwidth utilization.

Method used

By setting the counter cache and message authentication code intermediate cache in the GCM engine, the counter value and intermediate value are obtained and updated according to the data flow encoding, and the encryption and decryption flow processing unit and multiplication operation unit are used for processing, ensuring that each data flow is processed independently and avoiding resource waste and errors.

Benefits of technology

It realizes the correct transmission of multiple data streams, while maintaining the full load bandwidth of the GCM engine, avoiding resource waste and data discarding, and improving data transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372637A_ABST
    Figure CN120372637A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a method, a device and equipment for encrypting and decrypting multiple data streams. In the embodiment of the invention, a first data transmission instruction is acquired, and a data stream code to which a data packet belongs in the first data transmission instruction is determined; obtaining a first counter value corresponding to the data stream code in a counter cache of the GCM engine; preprocessing the first counter value to generate a second counter value; inputting the numerical value of the second counter into an encryption and decryption pipeline processing unit to generate encryption and decryption data; acquiring a first intermediate numerical value corresponding to the data stream code in a message authentication code intermediate cache; and inputting the encrypted and decrypted data and the first intermediate value into a multiplication unit to generate a second intermediate value. Through the method, multiple data streams among multiple communication devices can be continuously encrypted and decrypted, so that the multiple data streams can be correctly transmitted, and the full-load bandwidth of the GCM engine can be saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and more particularly, to a method, apparatus, and device for encrypting and decrypting multiple data streams. Background Art

[0002] When data communication is performed between different high-speed Peripheral Component Interconnect Express (PCIe) devices, it is necessary to protect the confidentiality and integrity of data streams to prevent attackers from tampering with data and stealing sensitive information through physical attacks. During data transmission, the Advanced Encryption Standard (AES) / SM4-Galois / Counter Mode (GCM) mode is adopted.

[0003] In the prior art, the GCM mode operates in a pipelined manner. When multiple PCIe devices communicate with each other through the same Integrity & Data Encryption (IDE), the above IDE includes at least one GCM engine that issues multiple encryption and decryption request instructions with different sources and destinations to the GCM. When the previous and subsequent instructions come from different data streams, the first stream carries key information and the corresponding initial vector in the start-of-packet (sop), and updates the Message Authentication Code (MAC) authentication tag at the end-of-packet (eop). If, before the eop of the first stream arrives, instructions corresponding to other streams enter the pipeline for encryption and decryption, at this time, other stream instructions need to perform operations with their corresponding initial vectors and keys. However, since the encryption and decryption operations of the first stream are not yet completed, the initial vectors obtained by other streams are the values of the first stream, resulting in incorrect encryption and decryption results for other streams. Therefore, the data packets transmitted by other streams need to be discarded to ensure the correct operation of the current stream; if the first stream experiences a stall here, the above GCM engine will be in an idle state, causing waste of resources.

[0004] In summary, how to continuously encrypt and decrypt multiple data streams between multiple communication devices so that they can be correctly transmitted and the full bandwidth of the GCM engine can be maintained is a problem that needs to be solved currently. Summary of the Invention

[0005] In view of this, embodiments of the present invention provide a method, apparatus, and device for encrypting and decrypting multiple data streams. By continuously encrypting and decrypting multiple data streams, it can be correctly transmitted and the full bandwidth of the GCM engine can be maintained.

[0006] In a first aspect, an embodiment of the present invention provides a method for encrypting and decrypting multiple data streams, the method including: obtaining a first data transmission instruction, determining the data stream encoding to which the data packet in the first data transmission instruction belongs; obtaining a first counter value corresponding to the data stream encoding in the counter cache of the GCM engine;

[0007] preprocessing the first counter value to generate a second counter value; inputting the second counter value into an encryption / decryption pipelining processing unit to generate encryption / decryption data; obtaining a first intermediate value corresponding to the data stream encoding in a message authentication code intermediate cache; inputting the encryption / decryption data and the first intermediate value into a multiplication operation unit to generate a second intermediate value.

[0008] Optionally, the method further includes: writing the second intermediate value into the message authentication code intermediate cache; receiving a second data transmission instruction, and continuing to execute the same processing flow as after obtaining the first data transmission instruction.

[0009] Optionally, the method further includes: writing the second counter value into the counter cache.

[0010] Optionally, in response to the data in the first data transmission instruction including a start data packet of any data stream, the method further includes: parsing and preprocessing the start data packet to generate an initialization vector and an initial counter value.

[0011] Optionally, the method further includes: inputting the initial counter value into the encryption / decryption pipelining processing unit to generate initial encryption / decryption data; inputting the initial encryption / decryption data into the multiplication operation unit to generate an initial intermediate value; writing the initial intermediate value into the message authentication code intermediate cache.

[0012] Optionally, the method further includes: writing the initial counter value into the counter cache.

[0013] Optionally, in response to the data in the first data transmission instruction including an end data packet of any data stream, the method further includes: outputting a target message authentication code.

[0014] Optionally, in response to thermal migration of the device where the first data transmission instruction occurs, the method further includes: determining the data stream encoding to which the data packet in the first data transmission instruction belongs; respectively obtaining intermediate data corresponding to the data stream encoding in a counter cache and a message authentication code intermediate cache, where the intermediate data includes a counter value and an intermediate value; and migrating the intermediate data to another GCM engine.

[0015] Optionally, the multiplication operation unit uses the GHASH function.

[0016] In a second aspect, an embodiment of the present invention provides a device for encrypting and decrypting multiple data streams, the device including:

[0017] A first acquisition unit, configured to acquire a first data transmission instruction and determine the data stream encoding to which the data packet in the first data transmission instruction belongs;

[0018] A second acquisition unit, configured to acquire a first counter value corresponding to the data stream encoding in a counter cache of a GCM engine;

[0019] A first generation unit, configured to preprocess the first counter value to generate a second counter value;

[0020] A second generation unit, configured to input the second counter value into an encryption / decryption pipelining unit to generate encryption / decryption data;

[0021] A third acquisition unit, configured to acquire a first intermediate value corresponding to the data stream encoding in a message authentication code intermediate cache;

[0022] A third generation unit, configured to input the encryption / decryption data and the first intermediate value into a multiplication operation unit to generate a second intermediate value.

[0023] Optionally, the device further includes:

[0024] A writing unit, configured to write the second intermediate value into the message authentication code intermediate cache;

[0025] The first acquisition unit is further configured to receive a second data transmission instruction and continue to execute the same processing flow as after acquiring the first data transmission instruction.

[0026] Optionally, the writing unit is further configured to:

[0027] Write the second counter value into the counter cache.

[0028] Optionally, in response to the data in the first data transmission instruction including a start data packet for any data stream, the device further includes:

[0029] A fourth generation unit, configured to parse and preprocess the starting data packet to generate an initialization vector and an initial counter value.

[0030] Optionally, the fourth generation unit is further configured to:

[0031] Input the initial counter value into the encryption / decryption pipelining unit to generate initial encryption / decryption data;

[0032] Input the initial encryption / decryption data into the multiplication operation unit to generate an initial intermediate value;

[0033] The writing unit is further configured to: write the initial intermediate value into the message authentication code intermediate cache.

[0034] Optionally, the writing unit is further configured to:

[0035] Write the initial counter value into the counter cache.

[0036] Optionally, in response to the data in the first data transmission instruction including a termination data packet for any data stream, the apparatus further includes:

[0037] An output unit, configured to output a target message authentication code.

[0038] Optionally, in response to the device where the first data transmission instruction occurs undergoing thermal migration, the apparatus further includes:

[0039] A determination unit, configured to determine the data stream encoding to which the data packet in the first data transmission instruction belongs;

[0040] A fourth acquisition unit, configured to respectively acquire intermediate data corresponding to the data stream encoding in the counter cache and the message authentication code intermediate cache, where the intermediate data includes a counter value and an intermediate value;

[0041] A migration unit, configured to migrate the intermediate data to other GCM engines.

[0042] Optionally, the multiplication operation unit adopts the GHASH function.

[0043] In a third aspect, an embodiment of the present invention provides an electronic device, including a memory and a processor, where the memory is configured to store one or more computer program instructions, and where the one or more computer program instructions are executed by the processor to implement the method as described in any item of the first aspect or any possible item of the first aspect.

[0044] Fourthly, an embodiment of the present invention provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described in any one of the first aspect or any possible one of the first aspect is implemented.

[0045] In the embodiment of the present invention, by obtaining a first data transmission instruction, determining the data stream encoding to which the data packet in the first data transmission instruction belongs; obtaining a first counter value corresponding to the data stream encoding in the counter cache of the GCM engine; preprocessing the first counter value to generate a second counter value; inputting the second counter value into an encryption / decryption pipelining processing unit to generate encryption / decryption data; obtaining a first intermediate value corresponding to the data stream encoding in the message authentication code intermediate cache; inputting the encryption / decryption data and the first intermediate value into a multiplication operation unit to generate a second intermediate value. Through the above method, multiple data streams between multiple communication devices can be continuously encrypted and decrypted, so that multiple data streams can be correctly transmitted and the full load bandwidth of the GCM engine can be preserved. Description of the Drawings

[0046] Through the following description of the embodiments of the present invention with reference to the drawings, the above and other objects, features and advantages of the present invention will become clearer. In the drawings:

[0047] Figure 1 is a flowchart of a method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0048] Figure 2 is a schematic diagram of the processing flow of a method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0049] Figure 3 is another flowchart of a method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0050] Figure 4 is still another flowchart of a method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0051] Figure 5 is yet another flowchart of a method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0052] Figure 6 is a flowchart of a method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0053] Figure 7 is still another flowchart of a method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0054] Figure 8It is a schematic diagram of the processing flow of another method for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0055] Figure 9 It is a flowchart of hot migration processing in an embodiment of the present invention;

[0056] Figure 10 It is a schematic diagram of the hardware implementation of the GHASH function in an embodiment of the present invention;

[0057] Figure 11 It is a schematic diagram of the GCM engine structure in an embodiment of the present invention;

[0058] Figure 12 It is a schematic diagram of a device for encrypting and decrypting multiple data streams in an embodiment of the present invention;

[0059] Figure 13 It is a schematic diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners

[0060] The following describes the present application based on embodiments, but the present application is not limited to these embodiments. In the following detailed description of the present application, some specific details are described in detail. Those skilled in the art can fully understand the present application without the description of these details. In order to avoid obscuring the essence of the present application, well-known methods, processes, procedures, components, and circuits are not described in detail.

[0061] In addition, those of ordinary skill in the art should understand that the drawings provided herein are for illustrative purposes only, and the drawings are not necessarily drawn to scale.

[0062] Unless the context clearly requires otherwise, words such as "including", "comprising", and the like in the entire application document should be interpreted as having an inclusive meaning rather than an exclusive or exhaustive meaning; that is, it is the meaning of "including but not limited to".

[0063] In the description of the present application, it should be understood that terms such as "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. In addition, in the description of the present application, unless otherwise stated, the meaning of "plurality" is two or more.

[0064] In the prior art, when communicating between different Peripheral Component Interconnect Express (PCIe) devices, it is necessary to protect the confidentiality and integrity of the data stream to prevent attackers from tampering with the data stream and stealing sensitive information. The Advanced Encryption Standard (AES) / SM4-Galois / Counter Mode (GCM) mode is a common calculation method in PCIe device communication encryption and authentication; among them, the GCM is an operating mode of a symmetric key encryption algorithm, which is widely used in encrypting and authenticating communication data. The GCM combines the encryption function of the Counter Mode and the message authentication code (MAC) generation function of the Galois mode, providing the ability to encrypt and authenticate the data stream simultaneously; the AES is a symmetric encryption algorithm, which is widely used to protect the security of sensitive information; the SM4 is a symmetric block cipher algorithm.

[0065] In the GCM mode, when using the AES or SM4 symmetric block cipher algorithm, the protocol of the AES or SM4 stipulates that the length of a block is 16 bytes, that is, only 16 bytes of encryption or decryption can be calculated within 10 - 16 clock cycles. In the case of a relatively long packet length of a data packet, if waiting for one block of encryption or decryption to complete before performing encryption or decryption on the next block, it is not advisable in scenarios with high requirements for transmission rate and throughput. To achieve high bandwidth, a pipeline method is usually adopted; when the GCM mode operates in a pipeline manner and multiple PCIe devices communicate with each other through the same Integrity & Data Encryption (IDE), the above IDE includes at least one GCM engine that initiates multiple encryption and decryption request instructions with different sources and destinations for GCM. When the two consecutive instructions come from different data streams, the first Stream carries the key information and the corresponding initial vector in the start of packet (sop) of the starting data packet, and updates the Message Authentication Code (MAC) authentication tag at the end of packet (eop). Suppose before the eop of the first Stream arrives, the instructions corresponding to other Streams enter the pipeline for encryption and decryption. At this time, the instructions of other Streams need their corresponding initial vectors and keys for operation, but the encryption and decryption operation of the current first Stream has not been completed yet. Therefore, the initial vectors obtained by other Streams are the values of the first Stream, resulting in incorrect encryption and decryption results for other Streams. Furthermore, the data packets transmitted by other Streams need to be discarded to ensure the correct operation of the current Stream; if there is a stall in the first Stream here, the above GCM engine will be in an idle state, causing waste of resources. Therefore, how to continuously perform encryption and decryption on multiple data streams between multiple communication devices so that it can be correctly transmitted and the full bandwidth of the GCM engine can be maintained is a problem that needs to be solved currently.

[0066] In an embodiment of the present invention, to solve the above problems, a method for encrypting and decrypting multiple data streams is proposed, specifically as Figure 1 shown, the method includes:

[0067] Step S101, obtain a first data transmission instruction, and determine the data stream encoding to which the data packet in the first data transmission instruction belongs.

[0068] Specifically, the GCM engine obtains a first data transfer instruction sent by a PCIe device. The GCM engine is set in Integrity & Data Encryption (IDE). The Stream ID of the data stream to which the data packet in the first data transfer instruction belongs is set. The data packet is a Middle of Packet (Mop) in a long data packet. Assume that the Stream ID is Stream 0.

[0069] Step S102: Obtain a first counter value corresponding to the data stream encoding in the counter cache of the GCM engine.

[0070] Specifically, the counter cache can also be referred to as a Cipher Buffer. According to the Stream ID, find the corresponding counter value in the counter cache. The Stream ID and its corresponding counter value are stored in pairs in the counter cache. For example, there are multiple Stream IDs and their corresponding counter values in the counter cache. Assume that the data stream encoding is Stream 0, and find the counter value corresponding to Stream 0 in the counter cache according to Stream 0.

[0071] Step S103: Preprocess the first counter value to generate a second counter value.

[0072] Specifically, preprocessing the first counter value means updating the counter value in the Counter (Ctr) register. The above preprocessing process can also be referred to as a Ctr Process processing unit, and update the first counter value to the second counter value. For example, every time 16 bytes of data are received, the counter is incremented by 1.

[0073] Step S104: Input the second counter value into the encryption / decryption pipelining unit to generate encrypted / decrypted data.

[0074] Specifically, input the second counter value into the Pipe Round of the encryption / decryption pipelining unit to encrypt or decrypt the Middle of Packet in the long data packet to generate encrypted / decrypted data.

[0075] Step S105: Obtain a first intermediate value corresponding to the data stream encoding in the message authentication code intermediate cache.

[0076] Specifically, in the message authentication code intermediate cache (H Buffer) of the GCM engine, the corresponding intermediate value is searched for in the message authentication code intermediate cache according to the StreamID, and the StreamID and its corresponding intermediate value are stored in pairs in the message authentication code intermediate cache; for example, in the message authentication code intermediate cache, multiple Stream IDs and their corresponding intermediate values are included. Assume that the data stream is encoded as Stream 0, and the first intermediate value corresponding to Stream 0 is searched for in the message authentication code intermediate cache according to Stream0.

[0077] Step S106: Input the encrypted / decrypted data and the first intermediate value into the multiplication operation unit to generate a second intermediate value.

[0078] Specifically, input the encrypted / decrypted data and the first intermediate value into the multiplication operation unit, and the multiplication operation unit is a general multiplication in finite field (GMUL) to generate a second intermediate value.

[0079] In a possible implementation manner, the schematic diagram of the processing flow of the above steps S101 to S106 is specifically as Figure 2 shown. The GCM engine includes a counter process processing unit 201, an encryption / decryption pipeline processing unit 202, a multiplication operation unit 203, a counter cache 204, and a message authentication code intermediate cache 205. After the Stream0 is input into the GCM engine, it is processed in turn by the counter process processing unit 201, the encryption / decryption pipeline processing unit 202, and the multiplication operation unit 203. During the processing, intermediate data is obtained from the counter cache 204 and the message authentication code intermediate cache 205, and the intermediate data is saved to the counter cache 204 and the message authentication code intermediate cache 205.

[0080] In a possible implementation manner, after the step 106, there are also other steps, specifically as Figure 3 shown, including:

[0081] Step S107: Write the second intermediate value into the message authentication code intermediate cache.

[0082] Specifically, write the second intermediate value and its corresponding Stream ID into the message authentication code intermediate cache for storage.

[0083] Step S108: Receive a second data transmission instruction and continue to execute the same processing flow as after obtaining the first data transmission instruction.

[0084] Specifically, the GCM engine continues to receive the second data transmission instruction and then continues to execute step S101.

[0085] In a possible implementation, after the step S103, there are also other steps, specifically as Figure 4 shown, including:

[0086] Step S109: Write the second counter value into the counter cache.

[0087] Specifically, write the second counter value and its corresponding Stream ID into the counter cache for storage.

[0088] In the embodiment of the present invention, since when any data stream sends data to the GCM engine, each long data packet includes a start-of-packet (Sop), in response to the data in the first data transmission instruction including the start-of-packet of any data stream, specifically as Figure 5 shown, including the following steps:

[0089] Step S501: Parse and preprocess the start-of-packet to generate an initialization vector and an initial counter value.

[0090] Specifically, after the GCM engine receives a start-of-packet, parse the start-of-packet to generate an initialization vector (Initialization Vector, IV), and perform Ctr preprocessing on the start-of-packet to generate an initial counter value.

[0091] Step S502: Input the initial counter value into the encryption / decryption pipeline processing unit to generate initial encryption / decryption data.

[0092] Step S503: Input the initial encryption / decryption data into the multiplication operation unit to generate an initial intermediate value.

[0093] Step S504: Write the initial intermediate value into the message authentication code intermediate cache.

[0094] In a possible implementation, after the step S501, there are also other steps, specifically as Figure 6 shown, including:

[0095] Step S505: Write the initial counter value into the counter cache.

[0096] In a possible implementation, in response to the data in the first data transmission instruction including an end of packet (Eop) for any data stream, after step 105, there are also other steps, such as Figure 7 as shown, including:

[0097] Step S110: Input the encrypted / decrypted data and the first intermediate value into a multiplication operation unit to generate and output a target message authentication code MAC.

[0098] In a possible implementation, the processing flow of the above steps S101 to S110 is as Figure 8 shown. The GCM engine includes a counter process processing unit 801, an encryption / decryption pipeline processing unit 802, a multiplication operation unit 803, a MAC output unit 804, a counter buffer 805, and a message authentication code intermediate buffer 806. After Stream 0 is input into the GCM engine, it is sequentially processed by the counter process processing unit 801, the encryption / decryption pipeline processing unit 802, the multiplication operation unit 803, and the MAC output unit 804 to output the MAC. During the processing, intermediate data is obtained from the counter buffer 805 and the message authentication code intermediate buffer 806, and the intermediate data is saved to the counter buffer 805 and the message authentication code intermediate buffer 806.

[0099] The following uses three specific embodiments to respectively elaborate in detail on the situation where the GCM engine receives multiple Streams. Specific Embodiment 1:

[0101] When the GCM engine receives a data transmission instruction, and the data transmission instruction includes a start of packet of Stream0, the GCM engine performs the following processing: First, the GCM engine determines that the packet in the received data transmission instruction is a start of packet sop, and the start of packet carries a start identifier. The sop is subjected to IV parsing and Ctr preprocessing to generate an initialization vector and an initial counter value. The initial counter value is input into the encryption / decryption pipeline processing unit to generate initial encrypted / decrypted data, and at the same time, the initial counter value is written into the counter buffer; the initial encrypted / decrypted data is input into the multiplication operation unit to generate an initial intermediate value; the initial intermediate value is written into the message authentication code intermediate buffer.

[0102] In a possible implementation, the GCM engine continues to receive new data transfer instructions. If the new data transfer instruction includes the start packet Sop of Stream1, it continues to be processed according to the process in Specific Embodiment 1; if the new data transfer instruction includes the middle packet Mop of Stream0, it is processed according to Specific Embodiment 2 below. Specific Embodiment 2

[0104] When the GCM engine receives a new data transfer instruction, and the new data transfer instruction includes the middle packet Mop of Stream1, the GCM engine performs the following processing: First, the GCM engine determines that the Stream ID corresponding to the received new data transfer instruction is different from the Stream ID corresponding to the previous data transfer instruction. According to the Stream ID, it reads the counter value corresponding to the Stream ID in the counter cache, performs Ctr preprocessing on the obtained counter data to generate a new counter value; inputs the new counter value into the encryption / decryption pipelining unit to generate encryption / decryption data, and at the same time writes the new counter value into the counter cache; obtains the intermediate value corresponding to the Stream ID in the message authentication code intermediate cache according to the Stream ID; inputs the encryption / decryption data and the intermediate value corresponding to the Stream ID into the multiplication operation unit to generate a new intermediate value; writes the new intermediate value into the message authentication code intermediate cache.

[0105] In a possible implementation, the GCM engine continues to receive new data transfer instructions. If the new data transfer instruction includes the end packet Eop of Stream1, it is processed according to the process in Specific Embodiment 3 below. Specific Embodiment 3

[0107] When the GCM engine receives a new data transmission instruction, and the new data transmission instruction includes the end-of-packet (Eop) of the intermediate data packet of Stream1, the GCM engine performs the following processing: First, the GCM engine determines that the Stream ID corresponding to the received new data transmission instruction is different from the Stream ID corresponding to the previous data transmission instruction. According to the Stream ID, it reads the counter value corresponding to the Stream ID from the counter cache, performs Ctr preprocessing on the obtained counter data to generate a new counter value; inputs the new counter value into the encryption / decryption pipelining unit to generate encryption / decryption data, and at the same time writes the new counter value into the counter cache; obtains the intermediate value corresponding to the Stream ID from the message authentication code intermediate cache according to the Stream ID; inputs the encryption / decryption data and the intermediate value corresponding to the Stream ID into the multiplication operation unit to generate the MAC.

[0108] In the embodiments of the present invention, in the above three specific embodiments, only two Streams are taken as examples. The processing flow of multiple Streams is the same as that of the above two Streams. The capacities of the counter cache CipherBuffer and the message authentication code intermediate cache H Buffer can be expanded according to the number of Streams. The data stored in the counter cache Cipher Buffer and the message authentication code intermediate cache H Buffer is obtained by using the Stream ID as an index, so as to achieve complete independence between different Streams, and ensure that the GCM engine can correctly transmit data while maintaining the full bandwidth when multiple Streams are intertwined.

[0109] In a possible implementation manner, when multiple Streams alternately initiate encryption / decryption requests, they follow the Round-Robin policy for polling access. When the number of Streams is very large and one GCM engine cannot meet the throughput rate of the current scenario, and at this time, some Streams have already transmitted a part of the data in the current GCM engine, based on the above processing flow of multiple Streams intertwined, an additional set of bus interfaces can be added. The intermediate data of the current Stream during data transmission is obtained by accessing the Cipher Buffer and HBuffer of the current GCM engine through the bus interface, and according to the software allocation, it is written into the corresponding Cipher Buffer and H Buffer of other GCM engines through the bus interface to continue the encryption / decryption data transmission of the current Stream. In the current design, the bus interface and the encryption / decryption path are separated, and hot migration will not cause an interruption of the current pipeline, nor affect the normal transmission of other Streams and the overall throughput rate.

[0110] Specifically, in response to the occurrence of thermal migration of the device that issues the first data transmission instruction, the specific processing flow is as Figure 9 shown, including the following steps:

[0111] Step S901: Determine the data stream encoding to which the data packet in the first data transmission instruction belongs.

[0112] For example, determine that the data stream that needs to undergo thermal migration is Stream 0.

[0113] Step S902: Obtain the intermediate data corresponding to the data stream encoding from the counter cache and the message authentication code intermediate cache respectively.

[0114] Among them, the intermediate data includes the counter value and the intermediate value.

[0115] Specifically, obtain the intermediate data according to Stream 0 from the counter cache and the message authentication code intermediate cache.

[0116] Step S903: Migrate the intermediate data to other GCM engines.

[0117] Specifically, embed the intermediate data into the counter cache and the message authentication code intermediate cache in other GCM engines.

[0118] In a possible implementation manner, the multiplication operation unit GMUL adopts the GHASH function. The input of the GHASH function is the encryption / decryption data X and the multiplier H pre-computed through the key information. The length of X is an integer multiple of 16 bytes, that is, an integer multiple of 128 bits. The output intermediate value or MAC value of the GHASH function is represented by GHASH(X) or Y m indicated.

[0119] For example, since the bandwidth of common PCIe devices is 64 bytes input simultaneously, that is, 64 bytes are received in one clock cycle, it is necessary to divide them into four groups for simultaneous processing. At this time, four key multipliers pre-computed through the key information are required, which are H, H 2 , H 3 , H 4 ; the specific processing steps are as follows: First, split the encryption / decryption data X into groups of 16 bytes, and after splitting, it is represented as X = X1∥X2∥…∥X m-1 ∥X m , m represents the number of groups. Assuming it is divided into 4 groups, then m = 4; then, let the initial value of Y m be Y0 = 0 128 , and according to the formula that is, the GHASH function is executed serially to generate Y m .

[0120] In a possible implementation, to improve the operation parallelism of the GHASH function, calculations are performed according to the following formula, as shown below:

[0121]

[0122] In the above formula represents an exclusive-or calculation.

[0123] Assume that m = 4. The schematic diagram of the hardware implementation of the above formula is as Figure 10 shown. The hardware instantiates 4 GMUL multiplication units and simultaneously starts the multiplication operations on multiple data packets to achieve the matching of the encryption / decryption channel rate and the multiplication core operation rate, without backpressure to the previous pipeline stage. When the parallelism is 4, it is necessary to pre-store the corresponding key multiplier H of the multiplication core in advance, H 2 ,H 3 ,H 4 . Here is only an exemplary illustration. The specific PCIe device bandwidth, parallelism, and the number of key multipliers are determined according to the actual situation, and the embodiments of the present invention do not limit them.

[0124] In the embodiments of the present invention, one stream corresponds to a group of key multipliers, and different streams correspond to multiple groups of key multipliers. While calculating the key multipliers, the key expansion parameter Round key required for AES / SM4 encryption / decryption operations is synchronously calculated. The key expansion parameter Round key is stored in the Cipher Roundkey table to achieve the offload of Round key. When the GCM engine needs to support the scenario of using M keys, the scenario support of M keys can be achieved by pre-calculating and storing M H SUBKEYs (i.e., key multiplier H) and M Cipher Roundkey tables.

[0125] In a possible implementation, the schematic diagram of the GCM engine structure is as Figure 11As shown in the figure, it includes an input register (input Logic) 1101, an Advanced Peripheral Bus (APB) Slave Regbank 1102, a KEY Process unit 1103, a CipherKEY Memory 1104, an H SUBKEY Memory 1105, an AES / SM4 encryption and decryption pipelining unit (Pipe Round) 1106, a GMUL unit 1107, an output register (output Logic) 1108, a Ctr Process processing unit 1109, a data fifo 1110, a counter cache 1111, and a MAC intermediate cache 1112; among them, the input register 1101 is connected to the host through the APB0 BUS (bus) and the APB1 BUS, and receives the key configured by the host through software. The input register 1101 also receives multiple streams sent by the PCIe device through the CMDIN BUS and the DATAIN BUS. The specific number of buses is determined according to the actual situation, and only an exemplary description is provided here; the APB Slave Regbank 1102 is used to store the register information that can be accessed, specifically the status information and cache information of the GMC engine; the KEY Process unit 1103 is used to calculate the cipher key expansion parameters and the key multiplier; the CipherKEY Memory 1104 is used to store the cipher key expansion parameters; the H SUBKEY Memory 1105 is used to store the key multiplier; the AES / SM4 encryption and decryption pipelining unit 1106 is used to encrypt and decrypt data; the GMUL unit 1107 is used to calculate the intermediate data and the MAC; the output register 1108 is used to output the MAC and the encryption and decryption results; the Ctr Process processing unit 1109 is used to perform Ctr preprocessing on the data packet, that is, to parse the data packet; the data fifo 1110 is used to cache the source data in the stream; the counter cache 1111 is used to cache the counter value, and the MAC intermediate cache 1112 is used to cache the intermediate value calculated by the GMUL; during hot migration, intermediate data can be obtained from the counter cache 1111 and the MAC intermediate cache 1112 through the bus.

[0126] Through the above embodiments, the GCM engine supports communication between multiple different PCIes. By setting up a counter cache and a message authentication code intermediate cache in the GCM engine to save the intermediate data corresponding to each Stream during the transmission process, different Streams are distinguished by the Stream ID, realizing multiple data streams, freely switching between different keys, meeting the complete independence between different Streams, supporting normal communication with multiple keys interwoven for multiple Streams, keeping the GCM engine fully loaded with bandwidth without causing any performance loss; and realizing hot migration based on the GCM engine; and by performing formula transformation on GHASH, the parallelism and throughput rate of the GCM engine operation are improved.

[0127] In an embodiment of the present invention, there is provided a device for encrypting and decrypting multiple data streams, as Figure 12 shown, specifically including: a first acquisition unit 1201, a second acquisition unit 1202, a first generation unit 1203, a second generation unit 1204, a third acquisition unit 1205, and a third generation unit 1206; wherein, the first acquisition unit 1201 is used to acquire a first data transmission instruction and determine the data stream coding to which the data packet in the first data transmission instruction belongs; the second acquisition unit 1202 is used to acquire a first counter value corresponding to the data stream coding in the counter cache of the GCM engine; the first generation unit 1203 is used to preprocess the first counter value to generate a second counter value; the second generation unit 1204 is used to input the second counter value into the encryption and decryption pipeline processing unit to generate encryption and decryption data; the third acquisition unit 1205 is used to acquire a first intermediate value corresponding to the data stream coding in the message authentication code intermediate cache; the third generation unit 1206 is used to input the encryption and decryption data and the first intermediate value into the multiplication operation unit to generate a second intermediate value.

[0128] Further, the device further includes: a writing unit, configured to write the second intermediate value into the message authentication code intermediate cache; the first acquisition unit is further configured to receive a second data transmission instruction and continue to execute the same processing flow as after acquiring the first data transmission instruction.

[0129] Further, the writing unit is further configured to: write the second counter value into the counter cache.

[0130] Further, in response to the data in the first data transmission instruction including the start data packet of any data stream, the device further includes: a fourth generation unit, configured to parse and preprocess the start data packet to generate an initialization vector and an initial counter value.

[0131] Further, the fourth generation unit is further configured to: input the initial counter value into the encryption / decryption pipelining unit to generate initial encryption / decryption data; input the initial encryption / decryption data into the multiplication operation unit to generate an initial intermediate value; the writing unit is further configured to: write the initial intermediate value into the message authentication code intermediate cache.

[0132] Further, the writing unit is further configured to: write the initial counter value into the counter cache.

[0133] Further, in response to the data in the first data transmission instruction including a termination data packet for any data stream, the apparatus further includes: an output unit, configured to output a target message authentication code.

[0134] Further, in response to the device where the first data transmission instruction occurs undergoing thermal migration, the apparatus further includes: a determination unit, configured to determine the data stream encoding to which the data packet in the first data transmission instruction belongs;

[0135] A fourth acquisition unit, configured to respectively acquire intermediate data corresponding to the data stream encoding in the counter cache and the message authentication code intermediate cache, where the intermediate data includes a counter value and an intermediate value; a migration unit, configured to migrate the intermediate data to other GCM engines.

[0136] Further, the multiplication operation unit adopts the GHASH function.

[0137] Figure 13 is a schematic structural diagram of the electronic device in the embodiment of the present invention. As Figure 13 shown, it includes a general computer hardware structure, which at least includes a processor 1301 and a memory 1302. The processor 1301 and the memory 1302 are connected through a bus 1303. The memory 1302 is adapted to store instructions or programs executable by the processor 1301. The processor 1301 may be an independent microprocessor or a set of one or more microprocessors. Thus, the processor 1301 executes the instructions stored in the memory 1302, thereby executing the method flow of the embodiment of the present invention as described above to implement the processing of data and the control of other devices. The bus 1303 connects the above-mentioned multiple components together, and at the same time connects the above-mentioned components to a display controller 1304, a display device, and an input / output (I / O) device 1305. The input / output (I / O) device 1305 may be a mouse, a keyboard, a modem, a network interface, a touch input device, a somatosensory input device, a printer, and other devices well known in the art. Typically, the input / output device 1305 is connected to the system through an input / output (I / O) controller 1306.

[0138] Among them, the instructions stored in the memory 1302 are executed by at least one processor 1301 to implement: obtaining a first data transmission instruction, determining the data stream encoding to which the data packet in the first data transmission instruction belongs; obtaining a first counter value corresponding to the data stream encoding in the counter cache of the GCM engine; preprocessing the first counter value to generate a second counter value; inputting the second counter value into the encryption / decryption pipelining unit to generate encryption / decryption data; obtaining a first intermediate value corresponding to the data stream encoding in the message authentication code intermediate cache; inputting the encryption / decryption data and the first intermediate value into the multiplication operation unit to generate a second intermediate value.

[0139] Specifically, the electronic device includes: one or more processors 1301 and a memory 1302. Figure 13 Taking one processor 1301 as an example. The processor 1301 and the memory 1302 can be connected through a bus or other means. Figure 13 Taking the connection through the bus as an example. The memory 1302, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The processor 1301 executes various functional applications and data processing of the device by running the non-volatile software programs, instructions, and modules stored in the memory 1302, that is, to implement the method for determining encryption / decryption for multiple data streams as described above.

[0140] The memory 1302 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store an option list, etc. In addition, the memory 1302 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some embodiments, the memory 1302 may optionally include a memory remotely set relative to the processor 1301, and these remote memories can be connected to an external device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0141] One or more modules are stored in the memory 1302 and, when executed by one or more processors 1301, execute the method for encrypting / decrypting multiple data streams in any of the above method embodiments.

[0142] As those skilled in the art will realize, various aspects of the embodiments of the present invention can be implemented as a system, a method, or a computer program product. Accordingly, various aspects of the embodiments of the present invention may take the form of: a full hardware implementation, a full software implementation (including firmware, resident software, microcode, etc.), or an implementation combining software aspects with hardware aspects that can generally be referred to herein as "circuits", "modules", or "systems". In addition, various aspects of the embodiments of the present invention may take the form of a computer program product implemented in one or more computer-readable media having computer-readable program code embodied thereon.

[0143] Any combination of one or more computer-readable media may be utilized. A computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium would include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the embodiments of the present invention, a computer-readable storage medium may be any tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device.

[0144] A computer-readable signal medium may include a propagated digital signal having computer-readable program code embodied therein, such as in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including but not limited to: electromagnetic, optical, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium that is not a computer-readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0145] Any suitable medium may be used to transmit the program code embodied on the computer-readable medium, including but not limited to wireless, wired, fiber optic cable, RF, etc., or any suitable combination of the foregoing.

[0146] Computer program code for performing operations in accordance with various aspects of the embodiments of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, C++, etc.; and conventional procedural programming languages such as the "C" programming language or similar programming languages. The program code may execute entirely on the user's computer as a stand-alone software package, partially on the user's computer, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0147] The flowcharts and / or block diagrams of the methods, apparatus (systems), and computer program products according to the embodiments of the present invention described above depict various aspects of the embodiments of the present invention. It will be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing device to produce a machine, such that the instructions, executed by the processor of the computer or other programmable data processing device, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0148] These computer program instructions may also be stored in a computer-readable medium that can direct a computer, other programmable data processing device, or other apparatus to operate in a particular manner, such that the instructions stored in the computer-readable medium produce an article of manufacture including instructions for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0149] The computer program instructions may also be loaded onto a computer, other programmable data processing device, or other apparatus to cause a series of operational steps to be performed on the computer, other programmable device, or other apparatus to produce a computer-implemented process, such that the instructions executed on the computer or other programmable device provide a process for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0150] The above are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

[0151] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject. If a user refuses to process personal information other than the necessary information required for basic functions, it will not affect the user's use of basic functions.

Claims

1. A method for encrypting and decrypting multiple data streams, characterized in that, The method includes: Obtaining a first data transmission instruction and determining the data stream encoding to which the data packet in the first data transmission instruction belongs; Obtaining a first counter value corresponding to the data stream encoding in the counter cache of the GCM engine; Preprocessing the first counter value to generate a second counter value; Inputting the second counter value into an encryption / decryption pipelining unit to generate encryption / decryption data; Obtaining a first intermediate value corresponding to the data stream encoding in the message authentication code intermediate cache; Inputting the encryption / decryption data and the first intermediate value into a multiplication operation unit to generate a second intermediate value.

2. The method according to claim 1, characterized in that, The method further includes: Writing the second intermediate value into the message authentication code intermediate cache; Receiving a second data transmission instruction and continuing to execute the same processing flow as after obtaining the first data transmission instruction.

3. The method according to claim 1, wherein The method further includes: Writing the second counter value into the counter cache.

4. The method according to claim 1, wherein In response to the data in the first data transmission instruction including a start data packet for any data stream, the method further includes: Parsing and preprocessing the start data packet to generate an initialization vector and an initial counter value.

5. The method according to claim 4, wherein The method further includes: Inputting the initial counter value into the encryption / decryption pipelining unit to generate initial encryption / decryption data; Inputting the initial encryption / decryption data into the multiplication operation unit to generate an initial intermediate value; Writing the initial intermediate value into the message authentication code intermediate cache.

6. The method according to claim 5, characterized in that, The method further includes: Writing the initial counter value into the counter cache.

7. The method according to claim 1, characterized in that, In response to the data in the first data transmission instruction including an end data packet for any data stream, the method further includes: Outputting a target message authentication code.

8. The method according to claim 1, characterized in that In response to the device where the first data transmission instruction occurs undergoing thermal migration, the method further includes: Determining the data stream encoding to which the data packet in the first data transmission instruction belongs; Respectively obtaining intermediate data corresponding to the data stream encoding in the counter cache and the message authentication code intermediate cache, where the intermediate data includes a counter value and an intermediate value; Migrating the intermediate data to another GCM engine.

9. The method according to claim 1, characterized in that The multiplication operation unit uses the GHASH function.

10. An encryption and decryption device for multiple data streams, characterized in that, The device includes: A first obtaining unit, configured to obtain a first data transmission instruction and determine the data stream encoding to which the data packet in the first data transmission instruction belongs; A second obtaining unit, configured to obtain a first counter value corresponding to the data stream encoding in the counter cache of the GCM engine; A first generating unit, configured to preprocess the first counter value to generate a second counter value; A second generating unit, configured to input the second counter value into an encryption / decryption pipelining unit to generate encryption / decryption data; A third obtaining unit, configured to obtain a first intermediate value corresponding to the data stream encoding in the message authentication code intermediate cache; A third generating unit, configured to input the encryption / decryption data and the first intermediate value into a multiplication operation unit to generate a second intermediate value.

11. An electronic device, comprising a memory and a processor, characterized in that, The memory is used to store one or more computer program instructions, wherein the one or more computer program instructions are executed by the processor to implement the method according to any one of claims 1-9.

12. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method according to any one of claims 1-9 is implemented.