Communication data processing method based on hardware interaction optimization, medium and equipment
By generating and sending comprehensive authentication information, including device-specific authentication information and resource status reports, during the authentication process, the latency and resource consumption issues between devices in collaborative computing of heterogeneous hardware devices are resolved. This enables the synchronous acquisition of device trustworthiness and resource status, as well as the optimization of secure channels, thereby improving the continuity and efficiency of task execution.
Patent Information
- Application Number
- CN202511739601.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-02-13
AI Technical Summary
In heterogeneous hardware device collaborative computing and IoT edge computing scenarios, the secure mutual trust and efficient interaction between devices are subject to latency, which leads to system task scheduling delays and increased resource consumption, making it impossible to adjust secure channel parameters and data transmission modes in the early stages of connection establishment.
By generating and sending comprehensive authentication information, including device-specific authentication information and resource status reports, during the authentication process, the device's trustworthiness and resource status are established using cryptographic binding. This enables the device to complete trustworthiness verification and resource status acquisition during the authentication process, and adjust secure channel parameters and data transmission modes based on the resource status.
It reduces communication latency between devices, improves the continuity and efficiency of task execution, avoids service interruptions caused by local failures, and achieves efficient collaboration and resource optimization between devices.
Smart Images

Figure CN121530682A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication data processing, more particularly, to a communication data processing method based on hardware interaction optimization, medium and device. BACKGROUND
[0002] Currently, in the scene of heterogeneous hardware device collaborative computing and Internet of Things edge computing, the secure mutual trust and efficient interaction between devices are the key to realize system performance optimization. Currently, device security authentication and device resource state acquisition are generally considered as two independent and serial processes. The typical interaction process is as follows: the control device first verifies the trustworthiness of the target device through a complete authentication process; after the authentication is successfully passed, the control device will separately initiate a query request for the real-time resource state of the target device.
[0003] Because the authentication process and the resource state acquisition process are strictly separated in time sequence, there is an unavoidable delay before the control device obtains the device trustworthiness and device resource state information of the target device. This delay directly translates into the delay of system task scheduling, reducing the overall response efficiency, which is particularly prominent in application scenarios that require fast response. In addition, after the control device is authenticated successfully, the parameters of the secure channel are determined to establish a secure channel for interaction. The control device cannot adjust the security channel parameters or the data transmission mode based on the resource state of the target device in the early stage of connection establishment, and will initiate high-load tasks to the overloaded target device, aggravating its resource consumption, leading to service performance degradation or even interruption and other problems. SUMMARY
[0004] The purpose of the embodiments of the present application is to overcome the defects of the prior art, and to provide a communication data processing method based on hardware interaction optimization, medium and device, so that the requesting authentication device obtains the resource state information of the authenticated device in the authentication process, completes the device trustworthiness verification and device resource state acquisition in one interaction, adjusts the security channel parameters and data transmission mode according to the device resource state in the early stage of device connection establishment, reduces the communication delay between devices, and improves the continuity of task execution.
[0005] The first aspect of the embodiments of the present application provides a communication data processing method based on hardware interaction optimization, medium and device, comprising the following steps: A first data processing device requests to initiate an authentication request to a second data processing device; The second data processing device responds to the authentication request and generates device authentication information and a resource status report; the device authentication information is generated based on a specific key of the second data processing device, the hardware configuration of the second data processing device, and the software configuration running on it; the resource status report is generated by the second data processing device monitoring the real-time status information of its internal hardware resources. The second data processing device cryptographically binds the device authentication information and the resource status report to generate comprehensive authentication information, and sends the comprehensive authentication information to the first data processing device; The first data processing device receives and verifies the comprehensive authentication information, obtains an authentication result based on the device authentication information in the comprehensive authentication information, and obtains a resource assessment result based on the resource status report in the comprehensive authentication information; If the authentication result is successful, the first data processing device establishes a secure channel with the second data processing device and transmits data based on the resource assessment result.
[0006] Compared to existing technologies, in this application, the second data processing device generates comprehensive authentication information that cryptographically binds device-specific authentication information and a resource status report monitoring the real-time status of the device's internal hardware resources, and sends this information to the first data processing device. The first data processing device receives and verifies this comprehensive authentication information to obtain device trustworthiness and resource assessment results. This allows the first data processing device to obtain the resource status information of the second data processing device during the authentication process, completing device trustworthiness verification and device resource status acquisition in a single interaction. Furthermore, by adjusting the secure channel parameters and data transmission mode based on the device resource status at the initial stage of establishing a connection between devices, communication latency between devices is reduced, and the continuity of task execution is improved.
[0007] In one embodiment, the step of the first data processing device establishing a secure channel with the second data processing device and transmitting data based on the resource assessment result includes: The first data processing device selects a security policy and a data transmission mode that match the resource assessment result from a predefined set of interaction policies, based on the resource assessment result; wherein, the set of interaction policies defines the mapping relationship between the resource assessment result, the security policy, and the data transmission mode. According to the security policy, determine the security parameters for establishing the secure channel with the second data processing device, and establish the secure channel with the second data processing device according to the security parameters; Based on the data transmission method, a data transmission mode for transmitting data with the second data processing device is determined, and data is transmitted with the second data processing device according to the data transmission mode.
[0008] Based on this embodiment, the first data processing device can select appropriate security channel parameters and data transmission mode according to the resource assessment results. While ensuring the security of interaction, it can select data encryption algorithms and data transmission methods that match the current processing capabilities of the second data processing device, thereby improving communication efficiency and the continuity of task execution.
[0009] In one embodiment, the step of the second data processing device generating the device authentication information includes: The second data processing device acquires the integrity metric values of its hardware and software configurations; The second data processing device uses its device-specific key to digitally sign the integrity metric value and generate device authentication information.
[0010] The device authentication information obtained based on this embodiment is generated by using the device's unique key and static configuration information to create an immutable identity credential. This not only establishes the device's trusted identity but also incorporates the device's inherent capabilities as part of a trusted statement. This allows the verifier to perceive the device's basic capability baseline while confirming its identity, thus enhancing the dimensionality of the authentication information.
[0011] In one embodiment, the second data processing device is connected to multiple hardware resources that perform the same function; the second data processing device identifies faulty hardware resources in the resource status report based on the real-time status information of the hardware resources in the resource status report; the resource evaluation result obtained by the first data processing device based on the resource status report in the comprehensive authentication information includes the identification of the faulty hardware resources; The step of the first data processing device transmitting data to the second data processing device based on the resource assessment result includes: When the first data processing device initiates data transmission to the second data processing device based on the resource assessment results, it may shield or bypass the faulty hardware resources.
[0012] The technical solution based on this embodiment can avoid the interruption of the entire device service or the failure of data transmission due to local failure, thereby improving the robustness and service continuity of the communication process.
[0013] In one embodiment, the resource status report includes at least one of the following: CPU utilization, memory usage, network bandwidth usage, and hardware accelerator availability.
[0014] In one embodiment, the resource status report further includes time-series-based historical status information of the internal hardware resources monitored by the second data processing device; The step of obtaining the resource assessment result based on the resource status report in the comprehensive verification information includes: The first data processing device obtains a first resource assessment result based on the real-time status information in the resource status report; the first data processing device obtains a second resource assessment result based on the historical status information in the resource status report; The first data processing device obtains a resource assessment result based on the first resource assessment result and the second resource assessment result.
[0015] The technical solution based on this embodiment improves upon the limitation of relying solely on the instantaneous state of the current hardware resources by introducing historical state information of hardware resources for evaluation. This upgrades the judgment of device processing capabilities from static snapshots to dynamic deduction, thereby enabling more accurate prediction of device performance and potential bottlenecks in future interactions.
[0016] In one embodiment, before the first data processing device establishes a secure channel with the second data processing device based on the resource assessment result, the first data processing device generates a resource allocation instruction based on the resource assessment result. After the first data processing device establishes a secure channel with the second data processing device based on the resource assessment result, it sends the resource allocation instruction to the second data processing device through the secure channel. The second data processing device responds to the resource allocation command and adjusts its internal resource allocation strategy.
[0017] The technical solution based on this embodiment decouples resource monitoring and resource control and distributes them across different devices, achieving efficient collaboration between centralized decision-making and distributed execution. This enables the second data processing device to quickly adjust its internal resource allocation strategy according to explicit external instructions, achieving precise on-demand allocation of computing resources and effectively improving the overall resource utilization efficiency and task execution timeliness in complex task scenarios.
[0018] In one embodiment, the adjustment of the internal resource allocation strategy includes at least one of: adjusting task scheduling priority, adjusting memory allocation, and adjusting I / O resources.
[0019] A second aspect of this application provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the communication data processing method based on hardware interaction optimization described above.
[0020] A third aspect of this application provides a computer device, including a memory and a processor, wherein a computer program capable of running on the processor is stored in the memory, characterized in that the processor, when executing the computer program, implements the steps of the above-described hardware interaction-optimized communication data processing method.
[0021] Compared to existing technologies, in this application, the second data processing device generates comprehensive authentication information that cryptographically binds device-specific authentication information and a resource status report monitoring the real-time status of the device's internal hardware resources, and sends this information to the first data processing device. The first data processing device receives and verifies this comprehensive authentication information to obtain device trustworthiness and resource assessment results. This allows the first data processing device to obtain the resource status information of the second data processing device during the authentication process, completing device trustworthiness verification and device resource status acquisition in a single interaction. Furthermore, by adjusting the secure channel parameters and data transmission mode based on the device resource status at the initial stage of establishing a connection between devices, communication latency between devices is reduced, and the continuity of task execution is improved.
[0022] To better understand and implement this application, the following detailed description is provided in conjunction with the accompanying drawings. Attached Figure Description
[0023] The accompanying drawings, which are included to provide a further understanding of the embodiments of this application and constitute a part of the embodiments of this application, are illustrative embodiments of this application and their descriptions are used to explain the embodiments of this application, and do not constitute an improper limitation on the embodiments of this application.
[0024] Figure 1 This is a flowchart illustrating the communication data processing method based on hardware interaction optimization provided in an embodiment of this application. Figure 2 This is a schematic diagram illustrating the process by which the first data processing device, according to the resource assessment results, establishes a secure channel with the second data processing device and transmits data. Figure 3 This is a schematic diagram of the process by which the second data processing device generates device authentication information, as provided in an embodiment of this application. Figure 4 This is a schematic diagram of the process by which the first data processing device obtains the resource evaluation result when the resource status report also includes time-series-based historical status information of the internal hardware resources monitored by the second data processing device. Figure 5 This is a schematic diagram illustrating the process by which the first data processing device generates a resource allocation instruction and establishes a secure channel with the second data processing device to transmit data, as provided in an embodiment of this application. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of the embodiments of this application.
[0026] In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. In the description of this application, it should be understood that the terms "first," "second," "third," etc., are used only to distinguish similar objects and are not necessarily used to describe a specific order or sequence, nor should they be construed as indicating or implying relative importance. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances. The singular forms "a," "the," and "the" used in this application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. The word "if" as used herein can be interpreted as "when," "when," or "in response to determination."
[0027] Furthermore, in the description of this application, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0028] Please see Figure 1 , Figure 1 This is a flowchart illustrating a communication data processing method based on hardware interaction optimization provided in an embodiment of this application. The communication data processing method based on hardware interaction optimization in this embodiment includes the following steps: S100: The first data processing device sends an authentication request to the second data processing device.
[0029] The first data processing device can be a cloud server, a master node, or any device that needs to establish a secure connection with the second data processing device and exchange data. The first data processing device, acting as the authenticator, initiates an authentication request to the second data processing device to verify its identity and credibility.
[0030] The authentication request includes a comprehensive verification of the second data processing device's identity, integrity of its hardware and software configurations, and real-time status information of its internal hardware resources. This authentication request can be sent via a network protocol.
[0031] S200: The second data processing device responds to the authentication request and generates device authentication information and a resource status report; the device authentication information is generated based on the specific key of the second data processing device, the hardware configuration of the second data processing device, and the software configuration running on it; the resource status report is generated by the second data processing device monitoring the real-time status information of its internal hardware resources.
[0032] After receiving the authentication request, the second data processing device generates device authentication information and resource status reports in parallel or sequentially.
[0033] The device authentication information is generated based on a device-specific key, the hardware configuration of the second data processing device, and the software configuration running on it. The device-specific key is an asymmetric cryptographic private key generated during the device manufacturing or initialization phase and permanently stored in the device's hardware security module, representing the device's unique cryptographic identity. The device-specific key provides cryptographic evidence for the authentication information to demonstrate the trustworthiness of the second data processing device.
[0034] The resource status report reflects the real-time operating status and data processing capabilities of the second data processing device. The second data processing device monitors the real-time status of its internal hardware resources through its operating system kernel or a dedicated monitoring unit, generating the resource status report. In one embodiment, the resource status report includes at least one or more of the following information: CPU utilization, memory usage, network bandwidth usage, and the availability status of hardware accelerators (such as GPUs and FPGAs). This information is dynamically changing, providing a snapshot of the current processing capabilities of the second data processing device.
[0035] S300: The second data processing device cryptographically binds the device authentication information and the resource status report to generate comprehensive authentication information, and sends the comprehensive authentication information to the first data processing device.
[0036] The second data processing device cryptographically binds the device authentication information and resource status report to prevent them from being maliciously tampered with or replaced during transmission.
[0037] Specifically, first, the device authentication information and the resource status report are sequentially concatenated to obtain a data block. For example, simple byte concatenation can be performed, or the data can be serialized before concatenation. Second, a cryptographically secure hash function is used to calculate the concatenated data block to generate a joint hash value. Third, a digital signature operation is performed on the joint hash value using a specific key of the second data processing device to obtain a signature value. Finally, the comprehensive authentication information consists of the concatenated data block of the device authentication information and the resource status report, and the signature value. Optionally, the comprehensive authentication information may also include identifiers indicating the hash function and digital signature operation algorithm used by the second data processing device.
[0038] S400: The first data processing device receives and verifies the comprehensive authentication information, obtains the authentication result based on the device authentication information in the comprehensive authentication information, and obtains the resource assessment result based on the resource status report in the comprehensive authentication information.
[0039] The first data processing device, acting as both the verifier and the decision-maker, first performs cryptographic verification on the received comprehensive authentication information, then authenticates the device authentication information and evaluates the resource status report.
[0040] The verification process requires a verification public key. This public key, along with a device-specific key, forms an asymmetric cryptographic key pair. The public key, calculated using a mathematical algorithm based on the device-specific key (private key), is a publicly distributed key used to verify digital signatures created with the corresponding private key. Data signed with the device-specific key can only be successfully verified using its corresponding verification public key; conversely, data encrypted with the verification public key can only be decrypted using the device-specific key.
[0041] The steps for cryptographically binding the received comprehensive authentication information include: the first data processing device deconstructs the comprehensive authentication information to obtain a concatenated data block and a signature value; the first data processing device uses the same hash function as the second data processing device to calculate the received concatenated data block to obtain a local hash value; the signature value is verified using the verification public key of the second data processing device, and the joint hash value can be restored; the local hash value and the joint hash value are compared byte by byte. If they are completely consistent, the cryptographic binding verification is successful, and the device authentication information is authenticated; otherwise, the first data processing device will terminate all subsequent processes and consider this interaction insecure.
[0042] The first data processing device parses the concatenated data block to obtain device authentication information and a resource status report. The first data processing device uses a verification public key to authenticate the device authentication information. During the authentication process, strict verification based on cryptography and trusted comparison is performed to obtain the authentication result. If the authentication result is successful, the resource status report is parsed and analyzed; otherwise, the first data processing device terminates the interaction.
[0043] When the authentication result is successful, the resource status report is in a trusted state. The first data processing device parses and analyzes the report, parsing real-time data and analyzing it according to preset business standards to obtain resource assessment results. The business standards define the mapping relationship between device resource status and resource assessment results. Optionally, the business standards can be set based on CPU utilization, memory availability, etc. For example, a CPU utilization of less than 60% and memory availability of more than 40% indicates a sufficient performance state, while a CPU utilization of more than 80% or memory availability of less than 20% indicates a resource-scarce state.
[0044] S500: If the authentication result is successful, the first data processing device establishes a secure channel with the second data processing device and transmits data based on the resource assessment result.
[0045] Only when the device is trustworthy (i.e., authentication is successful) will the first data processing device determine the interaction between the devices based on the resource assessment results of the second data processing device. A secure channel refers to a logical communication path established between two communicating entities, protected by cryptographic techniques, thereby ensuring the confidentiality and integrity of the data transmitted over it. Secure channel parameters refer to the configuration options and key materials that the communicating parties need to negotiate or unilaterally determine during the establishment of a secure channel. These parameters determine the channel's security level, performance, and functional characteristics, including the cryptographic suite and algorithm parameters that determine the security strength and computational overhead of the secure channel.
[0046] Compared to existing technologies, in this application, the second data processing device generates comprehensive authentication information that cryptographically binds device-specific authentication information and a resource status report monitoring the real-time status of the device's internal hardware resources, and sends this information to the first data processing device. The first data processing device receives and verifies this comprehensive authentication information to obtain device trustworthiness and resource assessment results. This allows the first data processing device to obtain the resource status information of the second data processing device during the authentication process, completing device trustworthiness verification and device resource status acquisition in a single interaction. Furthermore, by adjusting the secure channel parameters and data transmission mode based on the device resource status at the initial stage of establishing a connection between devices, communication latency between devices is reduced, and the continuity of task execution is improved.
[0047] Please see Figure 2 In one feasible embodiment, the step of the first data processing device establishing a secure channel with the second data processing device and transmitting data based on the resource assessment results includes: S510: The first data processing device selects a security policy and data transmission method that match the resource assessment results from a predefined set of interaction policies, based on the resource assessment results; wherein, the set of interaction policies defines the mapping relationship between the resource assessment results, security policies and data transmission methods.
[0048] The first data processing device parses the resource status report to obtain the resource assessment result, and matches the security policy and data transmission method corresponding to the resource assessment result in the interaction policy set.
[0049] S520: Based on the security policy, determine the security parameters for establishing a secure channel with the second data processing device, and establish a secure channel with the second data processing device based on the determined security parameters.
[0050] The first data processing device establishes a secure channel with the second data processing device based on the specific secure channel parameters in the security policy matched by the interaction policy set, such as key exchange algorithm and batch encryption algorithm.
[0051] S530: Determine the data transmission mode for data transmission with the second data processing device according to the data transmission method, and transmit data with the second data processing device according to the determined data transmission mode.
[0052] The first data processing device transmits data with the second data processing device through a secure channel according to the data transmission mode in the data transmission method matched by the interaction strategy set.
[0053] Before step S510, the following steps are also included: The first data processing device creates and maintains an interaction policy set, which defines the security policies and data transmission methods corresponding to different resource evaluation results. The security policy refers to the mode for selecting secure channel parameters, including a high-security, high-computational-overhead mode and a lightweight security mode. The data transmission method refers to the rules and modes by which the first data processing device controls how data is encapsulated, sent, received, and processed, focusing on the efficiency, priority, reliability, and resource consumption of data transmission, including a high-throughput mode and a low-latency-priority mode.
[0054] Specifically, part of the interaction strategy set is as follows: When the resource assessment result indicates a performance-sufficient state, the corresponding security strategy is a high-strength, high-computation-overhead mode. Specific security channel parameters include using ECDHE-RSA or ECDHE-ECDSA as the key exchange algorithm to provide forward secrecy, and using AES-256-GCM as the batch encryption algorithm to provide strong confidentiality and integrity protection; the data transmission method is a high-throughput mode. When the resource assessment result indicates a resource-scarce state, the corresponding security strategy is a lightweight security mode. Specific parameters include using AES-128-GCM or ChaCha20-Poly1305 as the encryption algorithm, and the data transmission method is a low-latency-priority mode.
[0055] Based on this embodiment, the first data processing device can select appropriate security channel parameters and data transmission mode according to the resource assessment results. While ensuring the security of interaction, it can select data encryption algorithms and data transmission methods that match the current processing capabilities of the second data processing device, thereby improving communication efficiency and the continuity of task execution.
[0056] Please see Figure 3 In one feasible embodiment, the step of the second data processing device generating device authentication information includes: S210: The second data processing device acquires the integrity metric of its hardware and software configurations.
[0057] The integrity metric of hardware and software configuration refers to the cryptographic hash value calculated by a cryptographic hash algorithm, which represents the initial state and integrity of a series of startup and runtime components of the second data processing device, from the underlying hardware to the upper-level software. It can characterize the static trusted state of the device at a certain moment.
[0058] S220: The second data processing device uses its device-specific key to digitally sign the integrity metric value and generate device authentication information.
[0059] The second data processing device can cryptographically bind trusted device identity proofs to the integrity of hardware and software configurations by digitally signing integrity metrics using a device-specific key.
[0060] The device authentication information obtained based on this embodiment is generated by using the device's unique key and static configuration information to create an immutable identity credential. This not only establishes the device's trusted identity but also incorporates the device's inherent capabilities as part of a trusted statement. This allows the verifier to perceive the device's basic capability baseline while confirming its identity, thus enhancing the dimensionality of the authentication information.
[0061] In one feasible embodiment, the second data processing device is connected to multiple hardware resources that perform the same function; the second data processing device identifies faulty hardware resources in the resource status report based on the real-time status information of the hardware resources in the resource status report; the resource evaluation result obtained by the first data processing device based on the resource status report in the comprehensive authentication information includes the identification of faulty hardware resources.
[0062] The steps of the first data processing device transmitting data to the second data processing device based on the resource assessment results include: When the first data processing device initiates data transmission to the second data processing device based on the resource assessment results, it may shield or bypass faulty hardware resources.
[0063] When generating resource status reports, the second data processing device not only reports the utilization rate of internal hardware resources, but also identifies specific faulty hardware resources. For example, it reports "GPU-1 status: faulty, GPU-2 status: available, CPU utilization 45%".
[0064] When the first data processing device parses the resource status report, it identifies faulty hardware resources. When establishing a connection and transmitting data with the second data processing device, it masks or bypasses these faulty hardware resources. For example, when the first data processing device needs to assign a computing task to the GPU of the second data processing device, it explicitly specifies to use the available "GPU-2", thereby avoiding assigning the task to the faulty "GPU-1", ensuring the smooth execution of the task and the robustness of the system.
[0065] The technical solution based on this embodiment can avoid the interruption of the entire device service or the failure of data transmission due to local failure, thereby improving the robustness and service continuity of the communication process.
[0066] Please see Figure 4 In one feasible embodiment, the resource status report also includes time-series-based historical status information of internal hardware resources monitored by the second data processing device; The steps for obtaining resource assessment results based on the resource status report in the comprehensive verification information include: S410: The first data processing device obtains the first resource assessment result based on the real-time status information in the resource status report; S420: The first data processing device obtains the second resource assessment result based on the historical status information in the resource status report; Specifically, historical state information based on time series can include CPU utilization curves, memory usage curves, etc., over the past 5 minutes. The first data processing device has a lightweight trend analysis module embedded in it, which can perform trend prediction analysis based on historical state information to obtain the second resource assessment results. Specific trend prediction methods include, but are not limited to, simple linear regression, peak and volatility analysis.
[0067] S430: The first data processing device obtains the resource assessment result based on the first resource assessment result and the second resource assessment result.
[0068] The resource assessment result can primarily reference the second resource assessment result. If the first resource assessment result indicates that the second data processing device is in a state of sufficient performance, while the second resource assessment result indicates that the second data processing device is in a state of resource scarcity, then the resource assessment result is a state of resource scarcity. Conversely, if the first resource assessment result indicates that the second data processing device is in a state of resource scarcity, while the second resource assessment result indicates that the second data processing device is in a state of sufficient performance, then the resource assessment result is a state of sufficient performance. In other embodiments, when the real-time status of the second data processing device has a significant impact on the task about to transmit data, the resource assessment result can also primarily reference the first resource assessment result.
[0069] The technical solution based on this embodiment improves upon the limitation of relying solely on the instantaneous state of the current hardware resources by introducing historical state information of hardware resources for evaluation. This upgrades the judgment of device processing capabilities from static snapshots to dynamic deduction, thereby enabling more accurate prediction of device performance and potential bottlenecks in future interactions.
[0070] Please see Figure 5 In one feasible embodiment, before the first data processing device establishes a secure channel with the second data processing device based on the resource assessment results, the method further includes the step: S51: The first data processing device generates a resource allocation instruction based on the resource assessment results.
[0071] When the first data processing device needs the second data processing device to handle important or urgent tasks, if the resource assessment results indicate that the second data processing device is in a state of resource shortage, the first data processing device will generate a resource allocation instruction to adjust the internal resource allocation of the second data processing device to improve its performance, so that the second data processing device can handle important or urgent tasks in a timely and smooth manner.
[0072] After the first data processing device establishes a secure channel with the second data processing device based on the resource assessment results, the process further includes the following step: S52: Sending a resource allocation instruction to the second data processing device through the secure channel.
[0073] Resource allocation instructions are sent to the second data processing device through a secure channel.
[0074] S53: The second data processing device responds to the resource allocation command and adjusts its internal resource allocation strategy.
[0075] Specifically, adjusting internal resource allocation strategies includes at least one of the following: adjusting task scheduling priorities, adjusting memory allocation, and adjusting I / O resources.
[0076] The technical solution based on this embodiment decouples resource monitoring and resource control and distributes them across different devices, achieving efficient collaboration between centralized decision-making and distributed execution. This enables the second data processing device to quickly adjust its internal resource allocation strategy according to explicit external instructions, achieving precise on-demand allocation of computing resources and effectively improving the overall resource utilization efficiency and task execution timeliness in complex task scenarios.
[0077] In summary, compared to existing technologies, in this application, the second data processing device generates comprehensive authentication information that cryptographically binds device-specific authentication information and a resource status report monitoring the real-time status of the device's internal hardware resources, and sends this information to the first data processing device. The first data processing device receives and verifies this comprehensive authentication information to obtain device trustworthiness and resource evaluation results. This allows the first data processing device to obtain the resource status information of the second data processing device during the authentication process, completing device trustworthiness verification and resource status acquisition in a single interaction. Furthermore, by adjusting the secure channel parameters and data transmission mode based on the device resource status at the initial stage of establishing a connection between devices, communication latency between devices is reduced, and the continuity of task execution is improved.
[0078] A second aspect of this application provides a computer-readable storage medium including a stored computer program, wherein the data processing method of any of the above embodiments is executed when the computer program is run.
[0079] A third aspect of this application provides a computer device, including a storage device, a processor, and a computer program stored in the storage device and executable by the processor. When the processor executes the computer program, it implements the above-described hardware interaction-optimized communication data processing method.
[0080] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0081] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function selected in one or more boxes.
[0082] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function selected in one or more boxes.
[0083] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0084] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0085] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0086] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0087] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A communication data processing method based on hardware interaction optimization, characterized in that, The method comprises: a first data processing device initiates an authentication request to a second data processing device; the second data processing device generates device authentication information and a resource status report in response to the authentication request; the device authentication information is generated based on a specific key of the second data processing device, a hardware configuration of the second data processing device and a software configuration running thereon; the resource status report is generated by the second data processing device monitoring real-time status information of internal hardware resources thereof; the second data processing device cryptographically binds the device authentication information and the resource status report to generate comprehensive authentication information and sends the comprehensive authentication information to the first data processing device; the first data processing device receives and verifies the comprehensive authentication information, obtains an authentication result from the device authentication information in the comprehensive authentication information and obtains a resource evaluation result from the resource status report in the comprehensive authentication information; if the authentication result is successful, the first data processing device establishes a secure channel with the second data processing device according to the resource evaluation result and performs data transmission.
2. The communication data processing method based on hardware interaction optimization according to claim 1, characterized in that, The step of the first data processing device establishing a secure channel with the second data processing device according to the resource evaluation result and performing data transmission comprises: the first data processing device selects a secure strategy and a data transmission mode matching the resource evaluation result from a pre-defined interaction strategy set according to the resource evaluation result; wherein the interaction strategy set defines a mapping relationship between the resource evaluation result, the secure strategy and the data transmission mode; determining a secure parameter for establishing the secure channel with the second data processing device according to the secure strategy, and establishing the secure channel with the second data processing device according to the secure parameter; determining a data transmission mode for data transmission with the second data processing device according to the data transmission mode, and performing data transmission with the second data processing device according to the data transmission mode.
3. The communication data processing method based on hardware interaction optimization according to claim 1, characterized in that, The step of the second data processing device generating the device authentication information comprises: the second data processing device obtains integrity measurement values of the hardware configuration and the software configuration thereof; the second data processing device uses a device-specific key thereof to digitally sign the integrity measurement values to generate the device authentication information.
4. The communication data processing method based on hardware interaction optimization according to claim 1, characterized in that, The second data processing device is connected with a plurality of hardware resources performing the same function; the second data processing device identifies a faulty hardware resource in the resource status report according to real-time status information of the hardware resources in the resource status report; the resource evaluation result obtained by the first data processing device from the resource status report in the comprehensive authentication information comprises identification of the faulty hardware resource; The step of the first data processing device performing data transmission with the second data processing device according to the resource evaluation result comprises: the first data processing device shields or bypasses the faulty hardware resource when initiating data transmission to the second data processing device according to the resource evaluation result.
5. The communication data processing method based on hardware interaction optimization according to claim 1, characterized in that, The resource status report comprises at least one of CPU utilization, memory occupancy, network bandwidth usage, and hardware accelerator availability.
6. The communication data processing method based on hardware interaction optimization according to claim 1, characterized in that, The resource status report further comprises time-series based historical status information of internal hardware resources monitored by the second data processing device; The step of obtaining resource evaluation results according to the resource status report in the comprehensive attestation information comprises: The first data processing device obtains a first resource evaluation result according to the real-time status information in the resource status report; and the first data processing device obtains a second resource evaluation result according to the historical status information in the resource status report; The first data processing device obtains a resource evaluation result according to the first resource evaluation result and the second resource evaluation result.
7. The communication data processing method based on hardware interaction optimization according to claim 1, characterized in that, Before the first data processing device establishes a secure channel with the second data processing device according to the resource evaluation result, the first data processing device generates a resource allocation instruction according to the resource evaluation result; After the first data processing device establishes a secure channel with the second data processing device according to the resource evaluation result, the first data processing device sends the resource allocation instruction to the second data processing device through the secure channel; The second data processing device adjusts its internal resource allocation strategy in response to the resource allocation instruction.
8. The communication data processing method based on hardware interaction optimization according to claim 7, characterized in that, The adjustment of the internal resource allocation strategy comprises at least one of adjustment of task scheduling priority, adjustment of memory allocation, and adjustment of I / O resources.
9. A computer-readable storage medium, characterized in that, A computer program is stored thereon, wherein the computer program is executed by a processor to implement the steps of the method according to any one of claims 1 to 8.
10. A computer device, comprising: A computer program is stored thereon, wherein the computer program is executed by a processor to implement the steps of the method according to any one of claims 1 to 8.