Method and device for encrypting and decrypting integrated hardware of DPU (Data Processing Unit) centralized sunken service grid and electronic equipment

By integrating hardware encryption units into the DPU chip and using internal logical communication instead of pciE interface, the problems of poor expansion and adaptability and high data delay of traditional hardware encryption and decryption cards are solved, and more efficient and flexible encryption and decryption operations are achieved.

CN120561978AActive Publication Date: 2025-08-29YUSUR TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510680457.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-08-29
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

The traditional solution of plugging hardware encryption and decryption cards through the pcie interface on the DPU has technical problems such as poor scalability and adaptability and high data delay.

Method used

Integrated hardware encryption units are integrated into the DPU chip, and the internal logical communication of the pciE hardware interface communication is replaced by the chip, and the encryption and decryption operations are realized, and software updates are used to adapt to new encryption standards and security threats to form a tight and efficient unit.

Benefits of technology

It reduces data transmission delay, improves flexibility and scalability, reduces long-term operation costs, enhances adaptability, and solves the problems of poor scalability and adaptability and high data delay of traditional solutions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120561978A_ABST
    Figure CN120561978A_ABST
Patent Text Reader

Abstract

The invention provides a DPU (Data Processing Unit) centralized sunken service grid integrated hardware encryption and decryption method and device and electronic equipment, in the method, a first integrated hardware encryption unit is integrated in a first DPU chip, a tighter and more efficient unit is formed and is externally embodied as a chip, internal logic communication of the chip replaces pcie hardware interface communication, and the communication efficiency is greatly improved. The high integration reduces the delay in the data transmission process, the first DPU chip is a programmable platform, a specific acceleration algorithm or security policy can be loaded according to service requirements, higher flexibility is provided, along with the increase of the complexity and security requirements of the service grid, the first DPU chip can be updated through software, and the data transmission efficiency is improved. According to the invention, new encryption standards and security threats (namely encryption strategies) are quickly adapted, hardware (namely the first integrated hardware encryption unit) does not need to be replaced, the long-term operation cost is reduced, the expandability and flexibility are enhanced, and the adaptability is better.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption and decryption, and in particular to a method, device and electronic device for integrating hardware encryption and decryption in a DPU centralized sinking service grid. Background Art

[0002] The traditional sidecar service mesh is deployed in sidecar mode, which requires starting a sidecar container when starting each service. In a large cluster with thousands of services, thousands of sidecar containers need to be created. Starting each sidecar container consumes a certain amount of system resources such as CPU and memory. Starting a sidecar container takes up a considerable amount of system resources, resulting in fewer resources available for business services. Therefore, the centralized DPU service mesh has emerged, which offloads the service mesh's business to the DPU, thereby saving business system resources, increasing the amount of resources available to business services (CPU, memory, etc.), and thus improving the efficiency of business services.

[0003] With the prevalence of cloud computing and microservices architecture, the security of data interactions within service meshes, as key infrastructure for connecting, managing, and protecting inter-service communications, has become particularly important. Therefore, service meshes provide means for identity authentication and data encryption and decryption between microservices. These processes require significant CPU computing resources (statistically, CPU resource consumption accounts for over 60% of the encryption and decryption of large, dense data). This increases the proxy load on the service mesh and reduces performance, contradicting the original intention of the DPU-centric, decentralized service mesh to offload CPU-intensive resources. Therefore, increasing the speed of identity authentication and data encryption and decryption has become a pressing issue that needs to be addressed.

[0004] Currently, the industry has traditional hardware encryption and decryption card solutions that need to be plugged into the server motherboard via the PCI bus. PCI-Express (Peripheral Component Interconnect Express) is a high-speed serial computer expansion bus standard. Its original name was "3GIO" and it was proposed by Intel in 2001 to replace the old PCI, PCI-X and AGP bus standards.

[0005] Among them, the hardware encryption and decryption card is connected to the DPU through the PCIE interface. Figure 1 The independent hardware encryption and decryption card is plugged into the DPU via the PCIe interface. This allows the service network software encryption and decryption functions on the DPU to be offloaded to the hardware encryption and decryption card. Similarly, the CPU consumption is also offloaded to the hardware encryption and decryption card, thus saving CPU resources and accelerating data encryption and decryption performance.

[0006] The above-mentioned traditional hardware encryption and decryption cards have poor scalability and adaptability because the hardware is highly customized and non-programmable. As the password complexity and security requirements of the service grid become increasingly higher, traditional hardware encryption and decryption cards may need to be replaced frequently, which makes the cost relatively high. In addition, although traditional hardware encryption and decryption cards have powerful encryption and decryption capabilities, they need to use the PCIe system bus for data transmission and interaction, which will generate additional delays.

[0007] In summary, the traditional solution of plugging a hardware encryption and decryption card into the DPU through the PCIe interface has technical problems such as poor scalability and adaptability, and high data latency. Summary of the Invention

[0008] In view of this, the purpose of the present invention is to provide a method, device and electronic device for integrating hardware encryption and decryption in a DPU centralized sinking service grid, so as to alleviate the technical problems of poor scalability and adaptability and large data latency of the traditional solution of plugging hardware encryption and decryption cards into the DPU through the PCIe interface.

[0009] In a first aspect, an embodiment of the present invention provides a method for integrating hardware encryption and decryption in a DPU centralized and sunken service grid, which is applied to a first DPU chip. The first DPU chip includes: a first centralized and sunken service grid unit and a first integrated hardware encryption unit. The first centralized and sunken service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module, and a first data forwarding module. The method includes:

[0010] The first grid data processing module monitors the data code stream transmitted by the first container through the PCIE interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing and fuse processing;

[0011] After the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the first integrated hardware encryption unit encrypts the data processed by the grid data according to the target encryption policy of the target encryption logic interface to obtain encrypted data;

[0012] The first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module;

[0013] The first data forwarding module forwards the encrypted data.

[0014] Furthermore, before the first grid data processing module monitors the data stream transmitted by the first container through the PCIE interface, the method further includes:

[0015] Configuring a communication channel between the first centralized sinking service grid unit and the first integrated hardware encryption unit;

[0016] Installing service grid management software and an encryption acceleration driver on the first DPU chip, wherein the encryption acceleration driver provides the encryption logic interface;

[0017] Registering the first container to the first DPU chip, and configuring the target encryption policy of the first container;

[0018] A key management module is configured on the first DPU chip to generate, distribute and manage keys required for encryption through the key management module.

[0019] Furthermore, the first data forwarding module forwards the encrypted data, including:

[0020] The first data forwarding module forwards the encrypted data to a data receiving cluster determined by the routing service.

[0021] Furthermore, if the data receiving cluster is a second container, and the second container PCIE interface is connected to a second DPU chip, the second DPU chip includes: a second centralized sinking service grid unit and a second integrated hardware decryption unit, and the second centralized sinking service grid unit includes: a second grid data processing module, a second grid encryption and decryption interface module, and a second data forwarding module, the method further includes:

[0022] The second data forwarding module receives the encrypted data;

[0023] After the second grid data processing module calls the target decryption logic interface of the second grid encryption and decryption interface module, the second integrated hardware decryption unit decrypts the encrypted data according to the target decryption strategy of the target decryption logic interface to obtain decrypted data;

[0024] The second integrated hardware decryption unit transmits the decrypted data to the second grid data processing module through the second grid encryption and decryption interface module;

[0025] The second grid data processing module performs grid data processing on the decrypted data to obtain grid data processed data, and transmits the grid data processed data to the second container through the PCIE interface.

[0026] Furthermore, the encryption acceleration driver can be edited and updated.

[0027] In a second aspect, an embodiment of the present invention further provides a DPU centralized sinking service grid integrated hardware encryption and decryption device, which is applied to a first DPU chip. The first DPU chip includes: a first centralized sinking service grid unit and a first integrated hardware encryption unit. The first centralized sinking service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module, and a first data forwarding module. The device includes:

[0028] The first grid data processing module monitors the data code stream transmitted by the first container through the PCIE interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing and fuse processing;

[0029] After the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the first integrated hardware encryption unit encrypts the data processed by the grid data according to the target encryption policy of the target encryption logic interface to obtain encrypted data;

[0030] The first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module;

[0031] The first data forwarding module forwards the encrypted data.

[0032] Furthermore, the device is also used for:

[0033] Configuring a communication channel between the first centralized sinking service grid unit and the first integrated hardware encryption unit;

[0034] Installing service grid management software and an encryption acceleration driver on the first DPU chip, wherein the encryption acceleration driver provides the encryption logic interface;

[0035] Registering the first container to the first DPU chip, and configuring the target encryption policy of the first container;

[0036] A key management module is configured on the first DPU chip to generate, distribute and manage keys required for encryption through the key management module.

[0037] Furthermore, the first data forwarding module forwards the encrypted data to a data receiving cluster determined by the routing service.

[0038] In a third aspect, an embodiment of the present invention further provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any one of the methods described in the first aspect when executing the computer program.

[0039] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to execute any method described in the first aspect above.

[0040] In an embodiment of the present invention, a method for integrating hardware encryption and decryption of a DPU centralized service grid is provided, which is applied to a first DPU chip. The first DPU chip includes: a first centralized service grid unit and a first integrated hardware encryption unit. The first centralized service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module and a first data forwarding module. The method includes: the first grid data processing module monitors the data code stream transmitted by the first container through the pcie interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing and fuse processing; when the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the grid data processed data is encrypted in the first integrated hardware encryption unit according to the target encryption strategy of the target encryption logic interface to obtain encrypted data; the first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module; and the first data forwarding module forwards the encrypted data. From the above description, it can be seen that in the DPU centralized sinking service grid integrated hardware encryption and decryption method of the present invention, the first DPU chip is integrated with the first integrated hardware encryption unit, forming a more compact and efficient unit, which is externally manifested as a chip, and the internal logic communication of the chip replaces the PCIE hardware interface communication. This high degree of integration reduces the delay in the data transmission process because the first DPU chip and the first integrated hardware encryption unit no longer need to exchange data through PCIE. In addition, the first DPU chip is a programmable platform and can load specific acceleration algorithms or security policies according to business needs, providing higher flexibility. As the complexity and security requirements of the service grid increase, the first DPU chip can quickly adapt to new encryption standards and security threats (i.e., encryption policies) through software updates without replacing hardware (i.e., the first integrated hardware encryption unit), reducing long-term operating costs, enhancing scalability and flexibility, and having better adaptability, alleviating the technical problems of poor scalability and adaptability and large data delay in the traditional solution of plugging hardware encryption and decryption cards through the PCIE interface on the DPU. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0042] Figure 1 Schematic diagram of the hardware encryption and decryption card provided in an embodiment of the present invention connected to the DPU via the PCIE interface;

[0043] Figure 2 A flowchart of a method for integrating hardware encryption and decryption in a DPU centralized sinking service grid provided by an embodiment of the present invention;

[0044] Figure 3 A schematic diagram of a DPU integrated hardware encryption and decryption card provided in an embodiment of the present invention;

[0045] Figure 4 A schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0046] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0047] The traditional solution of plugging hardware encryption and decryption cards into the DPU through the PCIe interface has poor scalability and adaptability and high data latency.

[0048] Based on this, in the DPU centralized sinking service grid integrated hardware encryption and decryption method of the present invention, the first DPU chip is integrated with the first integrated hardware encryption unit to form a more compact and efficient unit, which is externally manifested as a chip, and the internal logic communication of the chip replaces the PCIE hardware interface communication. This high degree of integration reduces the delay in the data transmission process because the first DPU chip and the first integrated hardware encryption unit no longer need to interact with data through PCIE. In addition, the first DPU chip is a programmable platform and can load specific acceleration algorithms or security policies according to business needs, providing higher flexibility. As the complexity and security requirements of the service grid increase, the first DPU chip can quickly adapt to new encryption standards and security threats (i.e., encryption policies) through software updates without replacing hardware (i.e., the first integrated hardware encryption unit), reducing long-term operating costs, enhancing scalability and flexibility, and having better adaptability.

[0049] To facilitate understanding of this embodiment, a method for integrating hardware encryption and decryption in a DPU centralized sinking service grid disclosed in an embodiment of the present invention is first introduced in detail.

[0050] Example 1:

[0051] According to an embodiment of the present invention, an embodiment of a method for integrating hardware encryption and decryption in a DPU centralized sinking service grid is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0052] Figure 2 This is a flow chart of a method for integrating hardware encryption and decryption in a DPU centralized sinking service grid according to an embodiment of the present invention. Figure 2 As shown, the method includes the following steps:

[0053] In step S202, the first grid data processing module monitors the data stream transmitted by the first container through the PCIE interface, performs grid data processing on the data stream, and obtains grid data processed data. The grid data processing includes decoding, routing, encoding, and fuse processing.

[0054] In an embodiment of the present invention, the above-mentioned DPU centralized sinking service grid integrated hardware encryption and decryption method can be applied to the first DPU chip, such as Figure 3As shown, the first DPU chip includes: a first centralized sinking service grid unit and a first integrated hardware encryption unit, and the first centralized sinking service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module and a first data forwarding module. That is, the present invention provides a service grid encryption and decryption solution based on DPU (i.e. DPU chip) integrated encryption card (i.e. integrated hardware encryption unit), such as Figure 3 As shown in the figure, by integrating the self-developed encryption card with the DPU, the hardware offload of encryption and decryption operations is realized, the encryption and decryption performance and security of the service grid are improved, and the latency is reduced. Among them, the data flow process: the data processing process of hardware encryption is used, such as Figure 3 For the specific process, please refer to Figure 2 Description.

[0055] The above-mentioned grid data processing is the native data processing flow of the service grid, in which, after monitoring the data code stream transmitted by the first container through the pcie interface, the above-mentioned data code stream is decoded to obtain the decoded data, and the decoded data is further processed by routing service to determine the target address contained therein, and then the data receiving cluster corresponding to the data code stream is determined. Before sending the decrypted data to the data receiving cluster, the decrypted data may also be modified to obtain the modified data, and then the modified data is encoded and fused to finally obtain the data after grid data processing.

[0056] First, some concepts involved in this invention are briefly introduced:

[0057] DPU (Data Processing Unit or dedicated data processor): A new generation of computing chips that are data-centric, I / O-intensive, and use software-defined technology to support infrastructure resource layer virtualization. They have the ability to improve computing system efficiency, reduce the total cost of ownership of the overall system, improve data processing performance, and reduce the performance loss of other computing chips.

[0058] A service mesh is a platform used to manage communication between services in a microservices architecture. It typically consists of two components: a control plane and a data plane. The control plane is responsible for tasks such as service discovery, load balancing, and traffic management, while the data plane is responsible for actual request forwarding and processing. The industry typically uses Istio as the control plane component of a service mesh, and Envoy as the data plane component.

[0059] Envoy is an open-source, high-performance proxy that typically serves as the data plane for a service mesh, responsible for forwarding and processing requests. Envoy's architecture consists of three planes: the data plane, the management plane, and the control plane. The control plane manages policies and configurations related to traffic routing and forwarding. The management plane accesses the latest traffic configuration information through a standard API. The data plane forwards traffic based on the configuration rules issued by the control plane.

[0060] Service grid encryption and decryption operations: The communication between microservices uses a lot of identity authentication and data encryption and decryption operations. For data security considerations

[0061] Hardware encryption and decryption card: Replace traditional software encryption and decryption with hardware encryption and decryption, integrate the encryption and decryption module and PCI interface module into a single FPGA chip, and reduce the burden on the CPU.

[0062] Step S204: After the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the grid data processed data is encrypted in the first integrated hardware encryption unit according to the target encryption policy of the target encryption logic interface to obtain encrypted data.

[0063] Step S206: The first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module;

[0064] Step S208: The first data forwarding module forwards the encrypted data.

[0065] The following is a comparison between the solution of the traditional technology and the solution of this application:

[0066] like Figure 1 As shown, in the traditional structure, the DPU and the independent encryption card are two hardware chips, and two PCIe slots are required on the server motherboard (i.e., the host) to insert the DPU and the independent encryption card. In the present invention, there is only one DPU chip (refer to Figure 3), only one pcie slot is needed on the server motherboard (i.e., the host), which saves the pcie slot resources of the host. All processing flows in the present invention are completed inside the DPU chip; in the traditional solution, the grid processing part is first completed on the DPU chip (specifically, the grid data processing unit therein), and after completion, it is transmitted to the independent encryption card through the external pcie interface between the chip (DPU) and the chip (independent encryption card). After encryption by the independent encryption card, it is transmitted to the data forwarding module of the DPU through the pcie interface. The above process involves external communication and has a long delay; in the present invention, the DPU chip also includes a first centralized sinking service grid unit and a first integrated hardware encryption unit. The communication between the two belongs to the internal communication of the DPU chip, which is faster than traditional external communication. Because the communication between the board levels is avoided, the delay is shorter.

[0067] The service mesh is a logical service, and the DPU can offload this logic. In the traditional two-card solution, the DPU processes the logic and then transmits the processed data to another encryption and decryption card for encryption and decryption. The data is then returned to the DPU for forwarding. This process is better accomplished within a single DPU. The DPU chip processes the data internally before sending it out. This reduces latency and is programmable, allowing software control of any unit or module within it, improving scalability and adaptability.

[0068] In an embodiment of the present invention, a method for integrating hardware encryption and decryption of a DPU centralized service grid is provided, which is applied to a first DPU chip. The first DPU chip includes: a first centralized service grid unit and a first integrated hardware encryption unit. The first centralized service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module and a first data forwarding module. The method includes: the first grid data processing module monitors the data code stream transmitted by the first container through the pcie interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing and fuse processing; when the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the grid data processed data is encrypted in the first integrated hardware encryption unit according to the target encryption strategy of the target encryption logic interface to obtain encrypted data; the first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module; and the first data forwarding module forwards the encrypted data. From the above description, it can be seen that in the DPU centralized sinking service grid integrated hardware encryption and decryption method of the present invention, the first DPU chip is integrated with the first integrated hardware encryption unit, forming a more compact and efficient unit, which is externally manifested as a chip, and the internal logic communication of the chip replaces the PCIE hardware interface communication. This high degree of integration reduces the delay in the data transmission process because the first DPU chip and the first integrated hardware encryption unit no longer need to exchange data through PCIE. In addition, the first DPU chip is a programmable platform and can load specific acceleration algorithms or security policies according to business needs, providing higher flexibility. As the complexity and security requirements of the service grid increase, the first DPU chip can quickly adapt to new encryption standards and security threats (i.e., encryption policies) through software updates without replacing hardware (i.e., the first integrated hardware encryption unit), reducing long-term operating costs, enhancing scalability and flexibility, and having better adaptability, alleviating the technical problems of poor scalability and adaptability and large data delay in the traditional solution of plugging hardware encryption and decryption cards through the PCIE interface on the DPU.

[0069] The above content briefly introduces the DPU centralized sinking service grid integrated hardware encryption and decryption method of the present invention. The specific contents involved are described in detail below.

[0070] In an optional embodiment of the present invention, before the first grid data processing module monitors the data stream transmitted by the first container through the PCIE interface, the method further includes the following steps:

[0071] (1) configuring a communication channel between the first centralized sinking service grid unit and the first integrated hardware encryption unit;

[0072] Specifically, a first integrated hardware encryption unit is integrated on the first DPU chip, and a communication channel is configured between the first centralized sinking service grid unit (ie, the first DPU chip) and the first integrated hardware encryption unit.

[0073] (2) installing service grid management software and an encryption acceleration driver on the first DPU chip, wherein the encryption acceleration driver provides an encryption logic interface;

[0074] Specifically, the encryption acceleration driver ensures that the first grid data processing module accesses the hardware encryption and decryption logic in the first integrated hardware encryption unit. The encryption acceleration driver provides encryption strategies for each interface in the grid encryption and decryption interface module for the first grid data processing module to call and process data encryption.

[0075] (3) Register the first container to the first DPU chip and configure the target encryption policy of the first container;

[0076] Specifically, each container in the service grid is registered with the first DPU chip, and the first container's target encryption policy is configured. The target encryption policy corresponds to the target encryption logical interface. Subsequently, when the first container starts, the first DPU chip is notified that the data stream sent from the first container needs to be encrypted according to the target encryption policy. This way, the first DPU chip knows the specific target encryption logical interface to call.

[0077] The target encryption strategy may specifically be a mathematical operation strategy between encryption units in the first integrated hardware encryption unit, such as adding first, then multiplying, and then multiplying again.

[0078] (4) A key management module is configured on the first DPU chip to generate, distribute and manage the keys required for encryption through the key management module.

[0079] In an optional embodiment of the present invention, the first data forwarding module forwards the encrypted data, including:

[0080] The first data forwarding module forwards the encrypted data to the data receiving cluster determined by the routing service.

[0081] In an optional embodiment of the present invention, if the data receiving cluster is a second container, and the second DPU chip is connected to the PCIE interface of the second container, the second DPU chip includes: a second centralized sinking service grid unit and a second integrated hardware decryption unit, and the second centralized sinking service grid unit includes: a second grid data processing module, a second grid encryption and decryption interface module, and a second data forwarding module. The method also includes the following steps:

[0082] (1) The second data forwarding module receives the encrypted data;

[0083] (2) After the second grid data processing module calls the target decryption logic interface of the second grid encryption and decryption interface module, the encrypted data is decrypted in the second integrated hardware decryption unit according to the target decryption strategy of the target decryption logic interface to obtain decrypted data;

[0084] (3) The second integrated hardware decryption unit transmits the decrypted data to the second grid data processing module through the second grid encryption and decryption interface module;

[0085] (4) The second grid data processing module performs grid data processing on the decrypted data to obtain grid data processed data, and transmits the grid data processed data to the second container through the PCIE interface.

[0086] Specifically, refer to Figure 3 The decryption process is similar to the encryption process described above and will not be described in detail here. Furthermore, before decryption, system initialization and service registration are required. This involves configuring the communication channel, installing the service grid management software and decryption acceleration driver, and registering the second container with the second DPU chip. These steps will not be described here. For reference, the encryption process is described above, and the encryption phase is simply replaced with decryption. Note that the same DPU chip can perform both encryption and decryption. The encryption and decryption processes are described separately for different DPU chips.

[0087] In an optional embodiment of the present invention, the encryption acceleration driver can be edited and updated. Correspondingly, there is also a decryption acceleration driver, which can also be edited and updated.

[0088] This invention provides a technology based on a DPU integrated hardware encryption card to accelerate identity authentication between microservices, improve encryption and decryption performance, and reduce CPU resource consumption. The method of the invention has the following advantages:

[0089] (1) The present invention utilizes the operation of the DPU integrated hardware encryption card, so that the DPU and the encryption card are in the same chip package, which reduces the complexity of connecting the DPU to a separate encryption card through PCIE and reduces the complexity of maintenance;

[0090] (2) The present invention utilizes the operation of the DPU integrated hardware encryption card to reduce the consumption of CPU resources for encryption and decryption data, thereby improving the performance of the service grid. Although traditional hardware encryption cards have powerful encryption and decryption capabilities, they generate additional delays and overhead due to the need to transmit data through the system bus;

[0091] (3) The present invention utilizes the operation of the DPU highly integrated encryption card to reduce the delay caused by the interaction between the separate encryption card and the separate DPU card, thereby improving the performance of the DPU service grid centralized sinking service grid and reducing the delay;

[0092] (4) The present invention utilizes the programmable logic of the DPU, so that after the DPU is integrated into the encryption card, it can realize functional expansion through software logic. It can cope with complex encryption and decryption scenarios in the future without changing the hardware logic, thereby improving scalability. The scalability of traditional hardware encryption cards is limited by hardware design, and it is necessary to replace or add hardware equipment to achieve functional expansion, which has poor flexibility.

[0093] Example 2:

[0094] An embodiment of the present invention also provides a device for integrating hardware encryption and decryption of a DPU centralized and downward service grid. The device for integrating hardware encryption and decryption of a DPU centralized and downward service grid is mainly used to execute the method for integrating hardware encryption and decryption of a DPU centralized and downward service grid provided in the first embodiment of the present invention. The following is a detailed introduction to the device for integrating hardware encryption and decryption of a DPU centralized and downward service grid provided in the embodiment of the present invention.

[0095] The DPU centralized sinking service grid integrated hardware encryption and decryption device is applied to a first DPU chip. The first DPU chip includes: a first centralized sinking service grid unit and a first integrated hardware encryption unit. The first centralized sinking service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module, and a first data forwarding module. The device includes:

[0096] The first grid data processing module monitors the data code stream transmitted by the first container through the PCIE interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing, and fuse processing;

[0097] After the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the data processed by the grid data is encrypted in the first integrated hardware encryption unit according to the target encryption strategy of the target encryption logic interface to obtain encrypted data;

[0098] The first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module;

[0099] The first data forwarding module forwards the encrypted data.

[0100] In an embodiment of the present invention, a device for integrated hardware encryption and decryption of a DPU centralized service grid is provided, which is applied to a first DPU chip. The first DPU chip includes: a first centralized service grid unit and a first integrated hardware encryption unit. The first centralized service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module and a first data forwarding module. The device includes: the first grid data processing module monitors the data code stream transmitted by the first container through the pcie interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing and fuse processing; when the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the grid data processed data is encrypted in the first integrated hardware encryption unit according to the target encryption strategy of the target encryption logic interface to obtain encrypted data; the first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module; and the first data forwarding module forwards the encrypted data. From the above description, it can be seen that in the DPU centralized sinking service grid integrated hardware encryption and decryption device of the present invention, the first DPU chip is integrated with the first integrated hardware encryption unit, forming a more compact and efficient unit, which is externally manifested as a chip, and the internal logic communication of the chip replaces the PCIE hardware interface communication. This high degree of integration reduces the delay in the data transmission process because the first DPU chip and the first integrated hardware encryption unit no longer need to interact with data through PCIE. In addition, the first DPU chip is a programmable platform and can load specific acceleration algorithms or security policies according to business needs, providing higher flexibility. As the complexity and security requirements of the service grid increase, the first DPU chip can quickly adapt to new encryption standards and security threats (i.e., encryption policies) through software updates without replacing hardware (i.e., the first integrated hardware encryption unit), reducing long-term operating costs, enhancing scalability and flexibility, and having better adaptability, alleviating the technical problems of poor scalability and adaptability and large data delay in the traditional solution of plugging hardware encryption and decryption cards through the PCIE interface on the DPU.

[0101] Optionally, the device is also used to: configure a communication channel between the first centralized sinking service grid unit and the first integrated hardware encryption unit; install service grid management software and an encryption acceleration driver on the first DPU chip, wherein the encryption acceleration driver provides an encryption logic interface; register the first container to the first DPU chip, and configure the target encryption policy of the first container; configure a key management module on the first DPU chip to generate, distribute and manage the keys required for encryption through the key management module.

[0102] Optionally, the first data forwarding module forwards the encrypted data to a data receiving cluster determined by the routing service.

[0103] Optionally, if the data receiving cluster is a second container, and the second DPU chip is connected to the pcie interface of the second container, the second DPU chip includes: a second centralized sinking service grid unit and a second integrated hardware decryption unit, and the second centralized sinking service grid unit includes: a second grid data processing module, a second grid encryption and decryption interface module and a second data forwarding module. The device is also used for: the second data forwarding module receives encrypted data; when the second grid data processing module calls the target decryption logical interface of the second grid encryption and decryption interface module, the encrypted data is decrypted in the second integrated hardware decryption unit according to the target decryption strategy of the target decryption logical interface to obtain decrypted data; the second integrated hardware decryption unit transmits the decrypted data to the second grid data processing module through the second grid encryption and decryption interface module; the second grid data processing module performs grid data processing on the decrypted data to obtain grid data processed data, and transmits the grid data processed data to the second container through the pcie interface.

[0104] Optionally, the encryption acceleration driver can be edited and updated.

[0105] The device provided in the embodiment of the present invention has the same implementation principle and technical effects as those in the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference can be made to the corresponding content in the aforementioned method embodiment.

[0106] like Figure 4 As shown, an electronic device 600 provided in an embodiment of the present application includes: a processor 601, a memory 602 and a bus, wherein the memory 602 stores machine-readable instructions executable by the processor 601. When the electronic device is running, the processor 601 communicates with the memory 602 through the bus, and the processor 601 executes the machine-readable instructions to perform the steps of the method for integrated hardware encryption and decryption of the DPU centralized sinking service grid as described above.

[0107] Specifically, the above-mentioned memory 602 and processor 601 can be general-purpose memory and processor, which are not specifically limited here. When the processor 601 runs the computer program stored in the memory 602, it can execute the above-mentioned DPU centralized sinking service grid integrated hardware encryption and decryption method.

[0108] The processor 601 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by an integrated logic circuit of hardware in the processor 601 or by instructions in the form of software. The above-mentioned processor 601 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in memory 602, and processor 601 reads the information in memory 602 and performs the steps of the above method in conjunction with its hardware.

[0109] Corresponding to the above-mentioned DPU centralized sinking service grid integrated hardware encryption and decryption method, an embodiment of the present application also provides a computer-readable storage medium, which stores machine-executable instructions. When the computer-executable instructions are called and executed by the processor, the computer-executable instructions prompt the processor to execute the steps of the above-mentioned DPU centralized sinking service grid integrated hardware encryption and decryption method.

[0110] The device for integrated hardware encryption and decryption of the DPU centralized sinking service grid provided in the embodiment of the present application can be specific hardware on the device or software or firmware installed on the device. The implementation principle and technical effects of the device provided in the embodiment of the present application are the same as those of the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference can be made to the corresponding content in the aforementioned method embodiment. Technical personnel in the relevant field can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices and units described above can all refer to the corresponding processes in the aforementioned method embodiment, and will not be repeated here.

[0111] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0112] For another example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0113] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0114] In addition, each functional unit in the embodiments provided in the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0115] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling an electronic device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the DPU centralized sinking service grid integrated hardware encryption and decryption method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program codes.

[0116] It should be noted that similar numbers and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. In addition, the terms "first", "second", "third", etc. are only used to distinguish the description and are not to be understood as indicating or implying relative importance.

[0117] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The scope of protection of the present application is not limited thereto. Although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-mentioned embodiments within the technical scope disclosed in the present application, or perform equivalent replacements for some of the technical features thereof. However, these modifications, changes, or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application. They should all be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for integrating hardware encryption and decryption in a DPU centralized sinking service grid, characterized in that: Applied to a first DPU chip, the first DPU chip includes: a first centralized sinking service grid unit and a first integrated hardware encryption unit, the first centralized sinking service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module, and a first data forwarding module, the method includes: The first grid data processing module monitors the data code stream transmitted by the first container through the PCIE interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing and fuse processing; After the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the first integrated hardware encryption unit encrypts the data processed by the grid data according to the target encryption policy of the target encryption logic interface to obtain encrypted data; The first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module; The first data forwarding module forwards the encrypted data.

2. The method according to claim 1, characterized in that Before the first grid data processing module monitors the data stream transmitted by the first container through the PCIE interface, the method further includes: Configuring a communication channel between the first centralized sinking service grid unit and the first integrated hardware encryption unit; Installing service grid management software and an encryption acceleration driver on the first DPU chip, wherein the encryption acceleration driver provides the encryption logic interface; Registering the first container to the first DPU chip, and configuring the target encryption policy of the first container; A key management module is configured on the first DPU chip to generate, distribute and manage keys required for encryption through the key management module.

3. The method according to claim 1, characterized in that The first data forwarding module forwards the encrypted data, including: The first data forwarding module forwards the encrypted data to a data receiving cluster determined by the routing service.

4. The method according to claim 3, characterized in that If the data receiving cluster is a second container, and the second container PCIe interface is connected to a second DPU chip, the second DPU chip includes: a second centralized sinking service grid unit and a second integrated hardware decryption unit, and the second centralized sinking service grid unit includes: a second grid data processing module, a second grid encryption and decryption interface module, and a second data forwarding module. The method further includes: The second data forwarding module receives the encrypted data; After the second grid data processing module calls the target decryption logic interface of the second grid encryption and decryption interface module, the second integrated hardware decryption unit decrypts the encrypted data according to the target decryption strategy of the target decryption logic interface to obtain decrypted data; The second integrated hardware decryption unit transmits the decrypted data to the second grid data processing module through the second grid encryption and decryption interface module; The second grid data processing module performs grid data processing on the decrypted data to obtain grid data processed data, and transmits the grid data processed data to the second container through the PCIE interface.

5. The method according to claim 2, characterized in that The encryption acceleration driver can be edited and updated.

6. A device for DPU centralized sinking service grid integrated hardware encryption and decryption, characterized in that: Applied to a first DPU chip, the first DPU chip includes: a first centralized sinking service grid unit and a first integrated hardware encryption unit, the first centralized sinking service grid unit includes: a first grid data processing module, a first grid encryption and decryption interface module and a first data forwarding module, the device includes: The first grid data processing module monitors the data code stream transmitted by the first container through the PCIE interface, performs grid data processing on the data code stream, and obtains grid data processed data, wherein the grid data processing includes: decoding processing, routing service, encoding processing and fuse processing; After the first grid data processing module calls the target encryption logic interface of the first grid encryption and decryption interface module, the first integrated hardware encryption unit encrypts the data processed by the grid data according to the target encryption policy of the target encryption logic interface to obtain encrypted data; The first integrated hardware encryption unit transmits the encrypted data to the first data forwarding module; The first data forwarding module forwards the encrypted data.

7. The device according to claim 6, characterized in that The device is also used for: Configuring a communication channel between the first centralized sinking service grid unit and the first integrated hardware encryption unit; Installing service grid management software and an encryption acceleration driver on the first DPU chip, wherein the encryption acceleration driver provides the encryption logic interface; Registering the first container to the first DPU chip, and configuring the target encryption policy of the first container; A key management module is configured on the first DPU chip to generate, distribute and manage keys required for encryption through the key management module.

8. The device according to claim 6, characterized in that The first data forwarding module forwards the encrypted data to a data receiving cluster determined by the routing service.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Hardware encryption card and encryption method

    CN108345806A

  • DPU-based service grid acceleration method and system, and storage medium

    CN117675579A

  • Credible cross-network cross-domain legal information data security fusion method

    CN118590281A

  • Secure communication method and device, electronic equipment and nonvolatile storage medium

    CN119996006A

  • High-speed cryptographic algorithm password card based on FPGA (Field Programmable Gate Array)

    CN214122946U