Low-power cryptographic card construction method based on dynamic cooperative optimization and cryptographic card
Patent Information
- Application Number
- CN202611009171.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-07
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2046-07-07
AI Technical Summary
[0003]在密码卡的运行过程中,密码卡会产生较大的待机功耗和运行功耗,造成大量能源浪费,显著增加数据中心的运营成本(如电费与冷却成本)
[0006]由以上技术方案可见,本申请实施例中,在对已休眠的密码卡进行唤醒之后,可以基于待处理请求对应的目标算法类型及预测数据量对主控处理器的主控频率进行配置,从而配置合适的主控频率,不是直接使用最大主控频率,从而节省密码卡的运行功耗,节省资源,降低数据中心的运营成本(如电费与冷却成本)。可以基于目标算法类型及预测数据量对密码卡的通道启用数量进行配置,从而配置合适的通道启用数量,不是直接使用最大通道启用数量,从而节省密码卡的运行功耗,节省资源,降低数据中心的运营成本。通过对密码卡进行休眠,可以节省密码卡的待机功耗,节省资源,降低数据中心的运营成本。
Smart Images

Figure CN122513096B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a method for constructing a low-power cryptographic card based on dynamic collaborative optimization and the cryptographic card itself. Background Technology
[0002] With the rapid development of cloud computing, big data, and edge computing, the deployment scale of information security infrastructure is growing exponentially. Cryptographic cards are a type of information security infrastructure, used to provide cryptographic operation services. They are widely used in servers, gateway devices, and various terminal devices, undertaking critical tasks such as data encryption, decryption, signing, and verification. For example, a cryptographic card is a dedicated hardware security module (HSM) used to perform cryptographic operations such as encryption / decryption, signature verification, and key management.
[0003] During operation, the password card generates significant standby and operating power consumption, resulting in substantial energy waste and significantly increasing the operating costs of the data center (such as electricity and cooling costs). Summary of the Invention
[0004] This application provides a method for constructing a low-power cryptographic card based on dynamic cooperative optimization. This method can be applied to cryptographic cards deployed on host devices. The method includes: After waking up the dormant cryptographic card, the power consumption parameters are configured based on the target algorithm type corresponding to the pending request and the amount of predicted data corresponding to the pending request. Under the power consumption parameters, the request to be processed is encrypted or decrypted by the first algorithm unit corresponding to the target algorithm type; wherein, the cryptographic card includes multiple algorithm units corresponding to one algorithm type; The first algorithm unit calls the main control processor to encrypt or decrypt the request to be processed; the interface of the password card includes multiple channels; the power consumption parameters include the main control frequency of the main control processor and / or the number of channels enabled in the multiple channels of the interface. The master control frequency is negatively correlated with the adjustment coefficient, and the master control frequency is positively correlated with the amount of predicted data. The adjustment coefficient is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the adjustment coefficient is a first coefficient value; if the target algorithm type corresponds to an I / O intensive algorithm, the adjustment coefficient is a second coefficient value; if the target algorithm type corresponds to a hardware-accelerated algorithm, the adjustment coefficient is a third coefficient value. The second coefficient value is greater than the first coefficient value, and the third coefficient value is greater than the second coefficient value. The number of channels activated is positively correlated with the security factor, and the number of channels activated is positively correlated with the amount of predicted data. The security factor is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the security factor is the fourth coefficient value. If the target algorithm type corresponds to an I / O intensive algorithm or a hardware-accelerated algorithm, the security factor is the fifth coefficient value. The fifth coefficient value is greater than the fourth coefficient value.
[0005] This application provides a cryptographic card, which is deployed on a host device, and the cryptographic card includes: The task processing unit is used to configure power consumption parameters based on the target algorithm type corresponding to the request to be processed and the amount of predicted data corresponding to the request to be processed after waking up the dormant password card. The first algorithm unit is used to encrypt or decrypt the request to be processed under the power consumption parameters; wherein, the cryptographic card includes multiple algorithm units corresponding to multiple algorithm types, the first algorithm unit is any algorithm unit, and the first algorithm unit corresponds to the target algorithm type; The first algorithm unit calls the main control processor to encrypt or decrypt the request to be processed; the interface of the password card includes multiple channels; the power consumption parameters include the main control frequency of the main control processor and / or the number of channels enabled in the multiple channels of the interface. The master control frequency is negatively correlated with the adjustment coefficient, and the master control frequency is positively correlated with the amount of predicted data. The adjustment coefficient is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the adjustment coefficient is a first coefficient value; if the target algorithm type corresponds to an I / O intensive algorithm, the adjustment coefficient is a second coefficient value; if the target algorithm type corresponds to a hardware-accelerated algorithm, the adjustment coefficient is a third coefficient value. The second coefficient value is greater than the first coefficient value, and the third coefficient value is greater than the second coefficient value. The number of channels activated is positively correlated with the security factor, and the number of channels activated is positively correlated with the amount of predicted data. The security factor is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the security factor is the fourth coefficient value. If the target algorithm type corresponds to an I / O intensive algorithm or a hardware-accelerated algorithm, the security factor is the fifth coefficient value. The fifth coefficient value is greater than the fourth coefficient value.
[0006] As can be seen from the above technical solutions, in this embodiment, after waking up the dormant cryptographic card, the main control frequency of the main control processor can be configured based on the target algorithm type and predicted data volume corresponding to the request to be processed, thereby configuring a suitable main control frequency instead of directly using the maximum main control frequency. This saves the operating power consumption of the cryptographic card, conserves resources, and reduces the operating costs of the data center (such as electricity and cooling costs). The number of channels enabled on the cryptographic card can also be configured based on the target algorithm type and predicted data volume, thereby configuring a suitable number of channels enabled instead of directly using the maximum number of channels enabled. This saves the operating power consumption of the cryptographic card, conserves resources, and reduces the operating costs of the data center. By putting the cryptographic card into dormancy, standby power consumption of the cryptographic card can be saved, resources can be conserved, and the operating costs of the data center can be reduced.
[0007] Power consumption parameters (such as main control frequency and number of channels) can be configured based on the target algorithm type corresponding to the request to be processed and the predicted data volume. This allows for the configuration of appropriate power consumption parameters, enabling intelligent perception of the service load (i.e., the predicted data volume) and proactive, fine-grained power consumption management. This achieves an adaptive balance between high-performance encryption and low-power operation, saving power consumption and resources while ensuring data processing efficiency. Furthermore, power management policies can be dynamically issued based on the target algorithm type, thereby configuring power consumption parameters and achieving fine-grained matching of hardware resources, significantly reducing the power consumption of the cryptographic card. Attached Figure Description
[0008] Figure 1 This is a flowchart illustrating a low-power cryptographic card construction method based on dynamic collaborative optimization. Figure 2 This is a schematic diagram of the structure of a password card in one embodiment of this application; Figure 3 This is a schematic diagram of a low-power cryptographic card construction method based on dynamic collaborative optimization; Figure 4 This is a flowchart illustrating the prediction process in one embodiment of this application; Figure 5 This is a flowchart illustrating the wake-up process in one embodiment of this application; Figure 6 This is a hardware structure diagram of a password card according to one embodiment of this application. Detailed Implementation
[0009] This application proposes a low-power cryptographic card construction method based on dynamic cooperative optimization. This method can be applied to cryptographic cards, and the cryptographic cards can be deployed on host devices (such as servers, gateway devices, and various terminal devices). See also Figure 1 The diagram shown is a flowchart of the method, which includes: Step 101: After waking up the dormant password card, configure the power consumption parameters based on the target algorithm type corresponding to the request to be processed and the amount of predicted data corresponding to the request to be processed.
[0010] Step 102: Under the power consumption parameter, the request to be processed is encrypted or decrypted by the first algorithm unit corresponding to the target algorithm type; wherein, the cryptographic card may include multiple algorithm units corresponding to multiple algorithm types, and the first algorithm unit is the algorithm unit corresponding to the target algorithm type.
[0011] For example, the first algorithm unit can invoke the main control processor to encrypt or decrypt the request to be processed, and the interface of the cryptographic card can include multiple channels. Based on this, power consumption parameters may include, but are not limited to, the main control frequency of the main control processor, and / or, the number of channels enabled on the multiple channels of the interface.
[0012] Regarding the main control frequency of the main control processor, when configuring the main control frequency based on the target algorithm type and the amount of predicted data, the main control frequency can be negatively correlated with the adjustment coefficient, or positively correlated with the amount of predicted data. Furthermore, the adjustment coefficient can be determined based on the target algorithm type. For example, if the target algorithm type corresponds to a computationally intensive algorithm, the adjustment coefficient is the first coefficient value; if the target algorithm type corresponds to an I / O intensive algorithm, the adjustment coefficient is the second coefficient value; and if the target algorithm type corresponds to a hardware-accelerated algorithm, the adjustment coefficient is the third coefficient value. The second coefficient value is greater than the first coefficient value, and the third coefficient value is greater than the second coefficient value.
[0013] Regarding the number of channels enabled for multiple channels of an interface (such as the PCIe interface of a cryptographic card), when configuring the number of channels enabled based on the target algorithm type and the predicted data volume, the number of channels enabled can be positively correlated with the security factor, and this security factor can be determined based on the target algorithm type. For example, if the target algorithm type corresponds to computationally intensive, the security factor can be the fourth factor value; if the target algorithm type corresponds to I / O intensive or hardware-accelerated, the security factor can be the fifth factor value; for example, the fifth factor value can be greater than the fourth factor value.
[0014] For example, if the power consumption parameter includes the main control frequency, then configuring the power consumption parameter based on the target algorithm type corresponding to the request to be processed and the predicted data volume corresponding to the request to be processed may include, but is not limited to: determining the adjustment coefficient based on the target algorithm type. Then, based on the configured minimum operating frequency, the configured maximum data volume, the acquired maximum operating frequency, the predicted data volume, and the adjustment coefficient, the main control frequency can be determined; wherein, the maximum operating frequency can be the main control frequency of the main control processor under the maximum data volume. The main control frequency is then configured for the main control processor.
[0015] For example, if the target algorithm type is RSA or SM2, then the target algorithm type corresponds to computationally intensive, which means that the amount of encryption or decryption operations is large; if the target algorithm type is SM3, SM4, or AES, then the target algorithm type corresponds to I / O intensive, which means that the I / O operations for encryption or decryption are large; if the target algorithm type is SM1, then the target algorithm type corresponds to hardware-accelerated, which means that the auxiliary processor is called to encrypt or decrypt the request to be processed.
[0016] For example, the master control frequency can be determined based on the configured minimum operating demand frequency, the configured maximum data volume, the acquired maximum operating demand frequency, the predicted data volume, and the adjustment coefficient. This can include, but is not limited to, determining the master control frequency using the following formula: F = Fmin + (Fmax - Fmin) × (T / Tmax). a Where F represents the main control frequency, Fmin represents the minimum operating frequency, Fmax represents the maximum operating frequency, T represents the amount of predicted data, Tmax represents the maximum amount of data, and a represents the adjustment coefficient.
[0017] For example, if the power consumption parameter includes the number of channels enabled, the power consumption parameter is configured based on the target algorithm type corresponding to the request to be processed and the predicted data volume corresponding to the request to be processed, including but not limited to: determining the security factor based on the target algorithm type; determining the interface link bandwidth based on the predicted data volume and the security factor, wherein the interface link bandwidth is positively correlated with the predicted data volume and the security factor; querying the bandwidth mapping table corresponding to the PCIe version of the cryptographic card based on the interface link bandwidth to obtain the number of channels enabled; wherein the bandwidth mapping table includes the correspondence between the number of channels and the bandwidth, and the bandwidth corresponding to the number of channels enabled is greater than or equal to the interface link bandwidth; and enabling the number of channels for the interface of the cryptographic card.
[0018] For example, the cryptographic card includes a memory controller, which includes a basic cache and a high-speed cache; the cryptographic card also includes a power management unit and a clock management unit corresponding to each algorithm unit. Before configuring power consumption parameters based on the target algorithm type corresponding to the request to be processed and the amount of predicted data corresponding to the request to be processed, if a pre-sleep instruction is received from the host device, the second algorithm unit and the power management unit and clock management unit corresponding to the second algorithm unit are turned off, and the high-speed cache is turned off; wherein, the second algorithm unit is the algorithm unit currently running on the cryptographic card. If it is detected that the basic cache has been written with the request to be processed, the cryptographic card that has been in sleep mode is woken up; wherein, the target algorithm type corresponding to the request to be processed is determined, the first algorithm unit corresponding to the target algorithm type and the power management unit and clock management unit corresponding to the first algorithm unit are turned on; the high-speed cache is turned on, and the request to be processed in the basic cache is migrated to the high-speed cache.
[0019] For example, the host device determines a first statistical characteristic based on the pending requests in the current period and a second statistical characteristic based on the pending requests in previous historical periods. Based on the first and second statistical characteristics, it predicts the probability of the cryptographic card being idle in the next period. If the probability of idle service is less than a threshold, the host device sends a pre-sleep command to the cryptographic card. If the probability of idle service is not less than the threshold, the host device predicts the predicted data volume of the cryptographic card in the next period based on the first and second statistical characteristics. Then, the host device sends the predicted data volume to the cryptographic card.
[0020] For example, the first statistical feature may include, but is not limited to, at least one of the following: the data packet size of the request to be processed, the arrival time of the request to be processed, the algorithm type corresponding to the request to be processed, the operation type carried by the request to be processed, and the burst density corresponding to the request to be processed; wherein, the operation type represents opening the password card, closing the password card, opening a session, or closing a session. The second statistical feature may include, but is not limited to, at least one of the following: the data packet size of the request to be processed, the arrival time of the request to be processed, the algorithm type corresponding to the request to be processed, the operation type carried by the request to be processed, and the burst density corresponding to the request to be processed. The host device inputs the first and second statistical features into a trained prediction model to obtain the business idle probability and the predicted data volume; wherein, the prediction model includes a quantized LSTM model, the LSTM model includes a first hidden layer and a second hidden layer, the first hidden layer includes K1 neurons, the second hidden layer includes K2 neurons, K1 can be greater than 1, and K2 can be greater than 1.
[0021] As can be seen from the above technical solutions, in this embodiment, after waking up the dormant cryptographic card, the main control frequency of the main control processor can be configured based on the target algorithm type and predicted data volume corresponding to the request to be processed, thereby configuring a suitable main control frequency instead of directly using the maximum main control frequency. This saves the operating power consumption of the cryptographic card, conserves resources, and reduces the operating costs of the data center (such as electricity and cooling costs). The number of channels enabled on the cryptographic card can also be configured based on the target algorithm type and predicted data volume, thereby configuring a suitable number of channels enabled instead of directly using the maximum number of channels enabled. This saves the operating power consumption of the cryptographic card, conserves resources, and reduces the operating costs of the data center. By putting the cryptographic card into dormancy, standby power consumption of the cryptographic card can be saved, resources can be conserved, and the operating costs of the data center can be reduced.
[0022] Power consumption parameters (such as main control frequency and number of channels) can be configured based on the target algorithm type corresponding to the request to be processed and the predicted data volume. This allows for the configuration of appropriate power consumption parameters, enabling intelligent perception of the service load (i.e., the predicted data volume) and proactive, fine-grained power consumption management. This achieves an adaptive balance between high-performance encryption and low-power operation, saving power consumption and resources while ensuring data processing efficiency. Furthermore, power management policies can be dynamically issued based on the target algorithm type, thereby configuring power consumption parameters and achieving fine-grained matching of hardware resources, significantly reducing the power consumption of the cryptographic card.
[0023] The technical solutions described above in the embodiments of this application will be explained below in conjunction with specific application scenarios.
[0024] A cryptographic card is a dedicated hardware security module (HSM) used to perform cryptographic operations such as encryption and decryption, signature verification, and key management. It is widely used in servers, gateway devices, and various terminal devices, undertaking critical tasks such as data encryption, data decryption, data signing, and data verification.
[0025] See Figure 2 The diagram shows the structure of a cryptographic card, which can be deployed on host devices (such as servers, gateway devices, and various terminal devices). For example, the cryptographic card can connect to the host device via a PCIe (Peripheral Component Interconnect express) interface (i.e., the PCIe bus).
[0026] A cryptographic card may include multiple algorithm units, each corresponding to a specific algorithm type. These algorithm types refer to the types of algorithms supported by the cryptographic card. For example, these algorithm types may include, but are not limited to, SM1, SM2, SM3, SM4, RSA, and AES types. The specific algorithm types are not limited. The cryptographic card may include algorithm units corresponding to SM1 type (denoted as algorithm unit a1), SM2 type (denoted as algorithm unit a2), SM3 type (denoted as algorithm unit a3), SM4 type (denoted as algorithm unit a4), RSA type (denoted as algorithm unit a5), and AES type (denoted as algorithm unit a6). The number of algorithm units can be more or less, without limitation.
[0027] When performing encryption or decryption tasks related to SM1 type on a request to be processed, algorithm unit a1 can encrypt or decrypt the request. When performing encryption or decryption tasks related to SM2 type on a request to be processed, algorithm unit a2 can encrypt or decrypt the request. When performing encryption or decryption tasks related to SM3 type on a request to be processed, algorithm unit a3 can encrypt or decrypt the request. When performing encryption or decryption tasks related to SM4 type on a request to be processed, algorithm unit a4 can encrypt or decrypt the request. When performing encryption or decryption tasks related to RSA type on a request to be processed, algorithm unit a5 can encrypt or decrypt the request. When performing encryption or decryption tasks related to AES type on a request to be processed, algorithm unit a6 can encrypt or decrypt the request.
[0028] The cryptographic card may also include a power management unit and a clock management unit corresponding to each algorithm unit. The power management unit manages the power supply to the algorithm units, such as regulating the voltage and current stability of the algorithm units. The clock management unit manages the clock of the algorithm units, such as controlling the clock frequency of the algorithm units.
[0029] For example, the password card may include a power management unit b1 and a clock management unit c1 corresponding to algorithm unit a1, a power management unit b2 and a clock management unit c2 corresponding to algorithm unit a2, a power management unit b3 and a clock management unit c3 corresponding to algorithm unit a3, a power management unit b4 and a clock management unit c4 corresponding to algorithm unit a4, a power management unit b5 and a clock management unit c5 corresponding to algorithm unit a5, and a power management unit b6 and a clock management unit c6 corresponding to algorithm unit a6.
[0030] The cryptographic card may also include a memory controller (such as a high-bandwidth memory controller), which may include a basic cache (such as a basic buffer memory) and a high-speed cache (such as a high-speed cache memory). For example, the high-speed cache is used to implement high-speed read and write operations for pending requests, while the basic cache is used to implement basic read and write operations for pending requests, i.e., slower read and write speeds.
[0031] When the host device sends a pending request to the cryptographic card, it needs to write the pending request to the cache, and the algorithm unit reads the pending request from the cache. When the pending requests in the cache reach a certain proportion (such as 90%) of the total space, the pending requests can be written to the basic cache.
[0032] The cryptographic card may also include a signal detection unit. After the cryptographic card goes into sleep mode, the signal detection unit remains active (i.e., the signal detection unit is not turned off). The signal detection unit can detect whether a pending request (a pending request written to the basic cache by the host device) has been written to the basic cache. If the signal detection unit detects that a pending request has been written to the basic cache, it wakes up the task processing unit of the cryptographic card.
[0033] The cryptographic card may also include a task processing unit. When the cryptographic card is in sleep mode, the task processing unit shuts down the algorithm unit, its corresponding power management unit, and clock management unit, disables the memory controller's cache, and shuts down the task processing unit itself, thus completing the cryptographic card's sleep mode. Clearly, after the cryptographic card enters sleep mode, the task processing unit is also in a powered-off state and does not operate.
[0034] If the signal detection unit detects that a pending request has been written to the basic cache, it wakes up the task processing unit of the cryptographic card. After the task processing unit is woken up, it activates the algorithm unit and its corresponding power management unit and clock management unit, enables the cache, and migrates the pending requests in the basic cache to the cache. Additionally, the task processing unit configures the power consumption parameters.
[0035] In the above application scenarios, this application proposes a low-power cryptographic card construction method based on dynamic collaborative optimization, which can intelligently sense the service load (i.e., predict the data volume) and proactively perform refined power consumption management to achieve an adaptive balance between high-performance encryption and low-power operation.
[0036] See Figure 3 The diagram illustrates a low-power cryptographic card construction method based on dynamic collaborative optimization, which may involve a prediction process, a sleep process, and a wake-up process. During the prediction process, the probability of the cryptographic card being idle in the next cycle and the predicted data volume for the next cycle can be predicted. During the sleep process, the cryptographic card can be put into sleep mode. During the wake-up process, the cryptographic card can be woken up, and its power consumption parameters can be configured. These processes are explained below.
[0037] First, regarding the prediction process.
[0038] See Figure 4 The diagram shown illustrates the prediction process, which may include: Step 401: The host device obtains the pending requests for the current period. The pending requests can be requests to be encrypted (to be encrypted later) or requests to be decrypted (to be decrypted later).
[0039] For example, the host device can start a timer with a period of x (e.g., 50ms). After the timer expires, the host device can obtain the pending requests within 50ms before the current time, that is, the pending requests in the current period. Obviously, the pending requests in the current period are the pending requests within 50ms.
[0040] Since the timer retrieves pending requests from the previous 50ms each time it expires, when obtaining pending requests for the current period, it has already retrieved pending requests from previous historical periods (such as one or more historical periods, each also 50ms). For example, assuming the current period is period T0, the host device has already retrieved pending requests from the first historical period T1 preceding period T0, the second historical period T2 preceding period T0, and so on, up to W historical periods' pending requests, where W is a positive integer, such as 7, 8, 9, 10, etc.
[0041] Step 402: The host device determines the first statistical feature based on the pending requests in the current period, and determines the second statistical feature based on the pending requests in the previous historical periods. The number of second statistical features can be W. For example, the second statistical feature 1 is determined based on the pending requests in the historical period T1, the second statistical feature 2 is determined based on the pending requests in the historical period T2, and so on.
[0042] For example, the host device can analyze the pending requests in the current period to obtain the first statistical characteristics of the current period. For instance, the first statistical characteristics may include, but are not limited to, at least one of the following: the data packet size of the pending request, the arrival time of the pending request, the algorithm type corresponding to the pending request, the operation type carried by the pending request, and the burst density corresponding to the pending request.
[0043] Regarding the size of the data packets for pending requests, since multiple pending requests will be received in the current period, and each pending request is a data packet (the data to be encrypted in the data packet needs to be encrypted, or the data to be decrypted in the data packet needs to be decrypted), there are multiple data packets in the current period. The first statistical characteristic can include the size of each data packet (also known as the data volume).
[0044] Regarding the arrival time of pending requests, since there are multiple data packets in the current period, the first statistical feature can include the arrival time of each data packet (i.e., the timestamp of the data packet). The first statistical feature can also include the arrival time interval of pending requests, i.e., the interval between the timestamps of two adjacent data packets.
[0045] For each algorithm type corresponding to a pending request, the algorithm type can be parsed from the pending request, such as SM1, SM2, SM3, SM4, RSA, or AES.
[0046] Regarding the operation type carried by the pending request, the pending request can include the operation type, which can be obtained from the pending request. For example, the operation type can indicate "Open Password Card" (used to open the password card when it is in the closed state, so that the password card can work normally), "Close Password Card" (used to close the password card when it is in the open state, so that the password card can no longer work), "Open Session" (used to open the session when it is in the closed state, so that the session can work normally), or "Close Session" (used to close the session when it is in the open state, so that the session can no longer run).
[0047] For the burst density corresponding to the pending requests, burst density is the instantaneous burst data volume, that is, the burst data volume within a short period of time. For example, the number of data packets within each 1 ms can be counted to obtain the number of 50 data packets in the current period, and the maximum value of these data packet counts can be used as the burst density.
[0048] For example, the host device can analyze pending requests from historical periods to obtain a second statistical characteristic of the historical period. For instance, the second statistical characteristic may include, but is not limited to, at least one of the following: the data packet size of the pending request, the arrival time of the pending request, the algorithm type corresponding to the pending request, the operation type carried by the pending request, and the burst density corresponding to the pending request.
[0049] Step 403: The host device predicts the probability of the cryptographic card being idle in the next cycle (i.e., the future cycle) based on the first and second statistical features. For example, idle service means that the cryptographic card will not process data in the next cycle (i.e., no encryption or decryption operation is required). The higher the probability of idle service, the greater the likelihood that the cryptographic card will not process data in the next cycle.
[0050] For example, the host device can input the first statistical feature and the second statistical feature into the trained prediction model to obtain the probability of the password card being idle in the next cycle of the current cycle.
[0051] For the prediction model, the input data consists of statistical features from multiple periods (such as the first statistical feature of the current period and the second statistical feature of multiple historical periods), and the output data is the business idle probability of the next period. There are no restrictions on the network structure and training process of the prediction model, as long as it can predict the business idle probability of the next period.
[0052] In one possible implementation, the prediction model may include, but is not limited to, an LSTM (Long Short Term Memory) model, and the LSTM model may include a first hidden layer and a second hidden layer. That is, by pruning the LSTM model, only the first hidden layer and the second hidden layer in the LSTM model are retained to obtain the prediction model in this embodiment. Thus, the lightweight LSTM model is used as the prediction model in this embodiment to adapt to the requirements of low latency and low resource consumption.
[0053] The first hidden layer can include K1 neurons, where K1 can be a positive integer greater than 1, such as 32 neurons. The second hidden layer can include K2 neurons, where K2 can be a positive integer greater than 1, such as 16 neurons. Therefore, the first hidden layer of the LSTM model has 32 neurons, and the second hidden layer has 16 neurons. To address the issue of the large number of parameters in the LSTM model, a lightweight LSTM model is constructed through network pruning, retaining only two hidden layers to meet the requirements of low latency and low resource consumption.
[0054] For the training process of the LSTM model, real business log data from the cryptographic card can be used as the training dataset. Real business log data covers requests to be processed under different business scenarios and different load intensities, thereby ensuring the diversity and representativeness of the training samples. There are no restrictions on this training process.
[0055] After the LSTM model is trained, it can be quantized, for example, using INT8 quantization compression, to obtain a quantized LSTM model. This quantized LSTM model serves as the prediction model and is deployed to the host device. Clearly, the prediction model can include the quantized LSTM model, and the LSTM model includes a first hidden layer and a second hidden layer. The first hidden layer contains K1 neurons, and the second hidden layer contains K2 neurons.
[0056] After the prediction model is deployed to the host device, the model size is less than 10KB, the inference time is less than 0.5ms, and the CPU resource utilization of the host device is less than 1%.
[0057] Based on the deployed prediction model, the host device can input the first and second statistical features into the prediction model to obtain the probability of the password card being idle in the next cycle of the current cycle.
[0058] Step 404: The host device determines whether the service idle probability is less than a threshold (this threshold can be configured according to actual needs, such as 0.7). If yes, that is, the service idle probability is less than the threshold, then proceed to step 405; if no, that is, the service idle probability is not less than the threshold, then proceed to step 406.
[0059] Step 405: The host device sends a pre-sleep command to the password card, triggering the password card to perform a pre-sleep operation. The implementation process of the pre-sleep operation can be found in the subsequent sleep process, and will not be repeated here.
[0060] Step 406: The host device predicts the amount of data the cryptographic card will process in the next cycle (i.e., the future cycle) based on the first and second statistical features. For example, if the cryptographic card has data processing (i.e., encryption or decryption operations are required) in the next cycle, the predicted data amount represents the number of pending requests that the cryptographic card needs to process in the next cycle, such as the number of pending requests within 50ms.
[0061] For example, the host device can input the first and second statistical features into a trained prediction model to obtain the predicted data volume of the cipher card in the next cycle. For instance, when inputting the first and second statistical features into the prediction model, the model can simultaneously output the business idle probability and the predicted data volume. Alternatively, the prediction model can output the business idle probability, and if the business idle probability is less than a threshold, it will not output the predicted data volume; only if the business idle probability is not less than the threshold will it output the predicted data volume.
[0062] Step 407: The host device sends the predicted data volume (i.e., the predicted data throughput) to the cryptographic card.
[0063] For example, after receiving a predicted data volume (the cryptographic card may receive multiple predicted data volumes over multiple cycles), if the cryptographic card is in a wake-up state and its power consumption parameters have not yet been configured, the power consumption parameters can be configured based on the predicted data volume. If the cryptographic card is in an active state and its power consumption parameters have already been configured, then the predicted data volume can be discarded directly, and the power consumption parameters will not be configured based on the predicted data volume. Alternatively, the power consumption parameters can be configured based on the predicted data volume, i.e., the already configured power consumption parameters of the cryptographic card can be adjusted and optimized.
[0064] Second, regarding the dormancy process.
[0065] For example, if the cryptographic card receives a pre-sleep command from the host device, it will trigger the cryptographic card to sleep. Based on this, the host device predicts the probability of the cryptographic card being idle in the next cycle. If the probability of idle service is less than a threshold, the cryptographic card can be triggered to sleep, instead of waiting for the cryptographic card to detect that there is no service processing before it goes into sleep mode. This allows the cryptographic card to enter sleep mode in advance, reducing the overall power consumption of the cryptographic card and avoiding the sleep delay caused by passive response.
[0066] For example, see Figure 2 As shown, the cryptographic card may include multiple algorithm units, a power management unit and a clock management unit corresponding to each algorithm unit, a memory controller, a signal detection unit, and a task processing unit. Based on this, when the cryptographic card is triggered to hibernate (i.e., a pre-hibernation instruction is received from the host device), the second algorithm unit and the power management unit and clock management unit corresponding to the second algorithm unit can be shut down, and the high-speed cache of the memory controller can be shut down (the basic cache of the memory controller is retained, i.e., the basic cache continues to be enabled, so that the host device can write pending requests to the basic cache).
[0067] The second algorithm unit is the algorithm unit currently running on the cryptographic card, that is, the algorithm unit that is currently activated on the cryptographic card. There can be one or more second algorithm units. In addition, the cryptographic card currently has the corresponding power management unit and clock management unit activated for the second algorithm unit.
[0068] For example, after receiving a pre-sleep instruction from the host device, the task processing unit shuts down the second algorithm unit, as well as the corresponding power management unit and clock management unit, and disables the memory controller's cache. Assuming the second algorithm unit is algorithm unit a1, the task processing unit shuts down algorithm unit a1, power management unit b1, and clock management unit c1.
[0069] After disabling the second algorithm unit, power management unit, clock management unit, and memory controller cache, the task processing unit can also disable itself, thus completing the cryptographic card's hibernation. After the cryptographic card hibernates, the memory controller's basic cache is enabled, allowing the host device to write pending requests to the basic cache. The signal detection unit is also enabled after the cryptographic card hibernates, and is used to wake the cryptographic card when a pending request exists.
[0070] For example, for multiple clock management units, a Boolean logic mapping value can be set for each clock management unit. The Boolean logic mapping value can be 0 or 1. When the Boolean logic mapping value is 0, it means that the clock management unit needs to be turned off. When the Boolean logic mapping value is 1, it means that the clock management unit needs to be turned on.
[0071] When disabling the clock management unit corresponding to the second algorithm unit, the Boolean logic mapping value of all clock management units can be set to 0, indicating that all clock management units need to be disabled, thereby disabling the clock management unit corresponding to the second algorithm unit. When enabling the clock management unit corresponding to the first algorithm unit (see the subsequent wake-up process), only the Boolean logic mapping value of the clock management unit corresponding to the first algorithm unit is set to 1, so that only the clock management unit corresponding to the first algorithm unit can be enabled.
[0072] For example, after receiving a pre-sleep command from the host device, the cryptographic card can immediately execute a sleep process, shutting down the second algorithm unit and its corresponding power management unit and clock management unit, disabling the memory controller's cache, and shutting down the task processing unit itself. This minimizes static power consumption during idle periods, putting the cryptographic card in a low-power mode (when inactive or under light load, the cryptographic card enters a sleep state by disabling redundant units, thereby reducing overall power consumption).
[0073] While disabling redundant units, the system also ensures that the PCIe link operates in a minimum power consumption detection mode, enabling only the signal detection unit to maintain real-time monitoring of pending requests from host devices. Once a pending request is detected in the memory controller's basic cache, the signal detection unit immediately triggers a wake-up process, quickly restoring the disabled units to their working state, ensuring that service response latency meets real-time requirements. If no pending request is detected, the system remains in a pre-sleep state until a pending request is detected in the basic cache.
[0074] The pre-sleep mechanism is triggered based on the probability of service idleness using a predictive model. By pre-emptively putting redundant units to sleep, it preserves the real-time detection capability of the signal detection unit, achieving a balance between power reduction and service response. It constructs a closed-loop control logic of "prediction-sleep-wake-up," reducing the number of invalid wake-ups and improving power management efficiency. Through this closed-loop mechanism, the number of invalid wake-ups of the cryptographic card during idle periods is effectively reduced (avoiding frequent sleep and wake-ups due to misjudgment of idle status), resulting in an average power consumption reduction of over 30% for the cryptographic card. Furthermore, the wake-up response delay can be controlled within the service tolerance range, without affecting the normal processing of pending requests. Through the closed-loop control of predictive sleep and fast wake-up, invalid power consumption is significantly reduced, achieving an average power consumption reduction of over 30%.
[0075] Third, regarding the wake-up process.
[0076] See Figure 5 The diagram shown is a flowchart of the wake-up process, which may include: Step 501: If a pending request is detected written to the basic cache, the dormant cryptographic card is woken up. When waking up the cryptographic card, the target algorithm type corresponding to the pending request can be determined, and the first algorithm unit corresponding to the target algorithm type, as well as the power management unit and clock management unit corresponding to the first algorithm unit, can be enabled; the cache can be enabled, and the pending requests in the basic cache can be migrated to the cache.
[0077] For example, when the cryptographic card is in sleep mode, the basic cache of the memory controller remains active, and the host device can write pending requests to the basic cache. The signal detection unit can detect in real time whether there are pending requests in the basic cache of the memory controller. Once a pending request is detected in the basic cache of the memory controller, the signal detection unit wakes up the task processing unit, triggering the wake-up process for the cryptographic card.
[0078] After the task processing unit is awakened, it determines the target algorithm type corresponding to the request to be processed, such as SM1, SM2, SM3, SM4, RSA, or AES. The task processing unit can activate the first algorithm unit corresponding to the target algorithm type, as well as the power management unit and clock management unit corresponding to the first algorithm unit. The first algorithm unit is the algorithm unit corresponding to the target algorithm type; there can be one or more first algorithm units. The first algorithm unit and the second algorithm unit can be the same, or they can be different. Assuming the first algorithm unit is algorithm unit a2, the task processing unit activates algorithm unit a2, power management unit b2, and clock management unit c2.
[0079] The task processing unit can also enable the memory controller's cache and migrate pending requests from the basic cache to the cache. Once the memory controller's cache is enabled, the host device can write pending requests to the cache, thereby achieving high-speed read and write of pending requests.
[0080] At this point, the password card wake-up process is complete. The task processing unit is awakened, the first algorithm unit and its corresponding power management unit and clock management unit are awakened, and the cache is enabled.
[0081] Step 502: After waking up the dormant password card, configure the main control frequency of the main control processor based on the target algorithm type and the amount of predicted data corresponding to the request to be processed. For example, the task processing unit configures the main control frequency based on the target algorithm type and the amount of predicted data corresponding to the request to be processed.
[0082] Once the task processing unit is activated, it can determine the target algorithm type corresponding to the request, such as SM1, SM2, SM3, SM4, RSA, or AES. Regarding the amount of prediction data corresponding to the request, the host device can send the prediction data to the cryptographic card, and the task processing unit can then determine the amount of prediction data.
[0083] The cryptographic card may include a main control processor, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), without limitation. Based on this, when the first algorithm unit encrypts or decrypts the request to be processed, the first algorithm unit can invoke the main control processor to encrypt or decrypt the request; that is, the first algorithm unit can utilize the main control processor's computing resources to encrypt or decrypt the request. In this way, the main control frequency of the main control processor can be configured based on the target algorithm type and the amount of predicted data corresponding to the request to be processed.
[0084] The main control frequency of the main control processor refers to the main frequency (also known as the clock frequency or core frequency), which is the number of pulses emitted by the main control processor per unit time. It is one of the important indicators for measuring the operating speed of the main control processor. In this embodiment, the main control frequency represents the amount of data processed by the main control processor per unit time.
[0085] For example, the following steps can be taken to configure the main control frequency of the main control processor: Step S11: Determine the adjustment coefficient based on the target algorithm type.
[0086] For example, if the target algorithm type corresponds to a computationally intensive algorithm, then the adjustment coefficient can be the first coefficient value. For instance, if the target algorithm type is RSA or SM2, then the target algorithm type corresponds to a computationally intensive algorithm, and computationally intensive means that the amount of computation involved in encryption or decryption is large.
[0087] For asymmetric algorithms such as RSA and SM2, which correspond to computationally intensive algorithms, the single-run time is long, they are sensitive to the base frequency, and have small throughput fluctuations. Based on this, the adjustment coefficient can be the first coefficient value, which can be between 1.0 and 1.1. The first coefficient value is used for conservative frequency reduction because if the frequency of large number operations is too low, it will lead to a single-run timeout, and a higher base frequency needs to be maintained to ensure real-time performance.
[0088] For example, if the target algorithm type corresponds to I / O intensive, i.e., for I / O intensive algorithms, the adjustment coefficient can be the second coefficient value, and the second coefficient value is greater than the first coefficient value. For instance, if the target algorithm type is SM3, SM4, or AES, then the target algorithm type corresponds to I / O intensive, and I / O intensive means that encryption or decryption involves a large amount of I / O, such as frequent input / output operations.
[0089] For cryptographic algorithms such as SM3, SM4, and AES, which correspond to I / O intensive algorithms, the I / O is intensive, the data packets are small and the frequency is high, and the load fluctuates drastically. Based on this, the adjustment factor can be a second factor value, which can be between 1.3 and 1.5. The second factor value is used for aggressive frequency reduction, which significantly reduces the frequency to save energy under low load and rapidly increases the frequency to process small data packets at line speed under high load.
[0090] For example, if the target algorithm type corresponds to a hardware-accelerated algorithm, then the adjustment coefficient can be the third coefficient value, and the third coefficient value is greater than the second coefficient value. For instance, if the target algorithm type is SM1, then the target algorithm type corresponds to a hardware-accelerated algorithm, and hardware acceleration means calling the auxiliary processor to encrypt or decrypt the request to be processed. For instance, when the target algorithm type corresponding to the first algorithm unit corresponds to a hardware-accelerated algorithm, when the first algorithm unit encrypts or decrypts the request to be processed, it can call both the main control processor and the auxiliary processor to encrypt or decrypt the request to be processed; that is, it calls the computing resources of the main control processor and the auxiliary processor to encrypt or decrypt the request to be processed. For instance, the auxiliary processor can be an external processor for the first algorithm unit, that is, an external FPGA or ASIC can be used as an auxiliary processor for the first algorithm unit. The first algorithm unit calls the computing resources of the main control processor and the auxiliary processor to encrypt or decrypt the request to be processed; there are no restrictions on this.
[0091] For pure hardware-accelerated algorithms like SM1, a hardware-accelerated version can be defined, where hardware acceleration is achieved through an auxiliary processor, while the main processor only performs scheduling. The main processor's computational load is extremely low, and the encryption or decryption process can be handled by the auxiliary processor. Based on this, the adjustment coefficient can be a third coefficient value, ranging from 1.5 to 1.8, thereby achieving extreme energy savings by drastically reducing the frequency through this adjustment.
[0092] Step S12: Determine the main control frequency of the main control processor based on the minimum operating frequency requirement, maximum data volume, maximum operating frequency requirement, predicted data volume, and adjustment coefficient. The main control frequency of the main control processor can be negatively correlated with the adjustment coefficient and positively correlated with the predicted data volume.
[0093] In one possible implementation, the main control frequency of the main control processor can be determined using the following formula: F = Fmin + (Fmax - Fmin) × (T / Tmax) a Of course, the above formula is just an example of the master control frequency. The master control frequency is negatively correlated with the adjustment coefficient and positively correlated with the amount of predicted data.
[0094] In the above formula, F represents the main control frequency of the main processor. Fmin represents the minimum operating frequency, that is, the minimum frequency required to run the algorithm, such as 200MHz. The minimum operating frequency can be pre-configured and can be an empirical value or an actual measured value.
[0095] For example, when encrypting or decrypting a request using the SM1 algorithm, each master control frequency is tried in turn to find the minimum master control frequency that satisfies the operation of the SM1 algorithm. Similarly, when encrypting or decrypting a request using the SM2 algorithm, each master control frequency is tried in turn to find the minimum master control frequency that satisfies the operation of the SM2 algorithm. This process continues until the minimum master control frequency corresponding to each algorithm type is obtained.
[0096] The minimum operating frequency requirement can be the minimum of the minimum master control frequency corresponding to all algorithm types, or the minimum operating frequency requirement can be the minimum master control frequency corresponding to the target algorithm type. For example, if the target algorithm type is SM1, the minimum master control frequency corresponding to the SM1 algorithm can be used as the minimum operating frequency requirement.
[0097] In the formula above, Tmax represents the maximum data size, that is, the maximum amount of data supported by the algorithm. The maximum data size can be pre-configured; it can be an empirical value or an actual measured value. For example, when encrypting or decrypting a request using the SM1 algorithm, each data size is tried sequentially to find the maximum data size that allows the SM1 algorithm to function correctly. Similarly, when encrypting or decrypting a request using the SM2 algorithm, each data size is tried sequentially to find the maximum data size that allows the SM2 algorithm to function correctly. This process continues to obtain the maximum data size corresponding to each algorithm type.
[0098] The maximum data size Tmax can be the minimum among the maximum data sizes corresponding to all algorithm types, or the maximum data size Tmax can be the maximum data size corresponding to the target algorithm type.
[0099] In the above formula, Fmax represents the maximum required operating frequency, that is, the maximum required frequency to satisfy the algorithm's operation. This maximum required operating frequency is the maximum frequency at which the main control processor can satisfy the algorithm's operation under the maximum data volume, such as 1.2GHz. For example, when using the SM1 algorithm to encrypt or decrypt a maximum of Tmax data requests (which could be the minimum of the maximum data volumes for all algorithm types, or the maximum data volume corresponding to the SM1 algorithm), each main control frequency is tried sequentially to find the maximum main control frequency that satisfies the SM1 algorithm's operation. When using the SM2 algorithm to encrypt or decrypt a maximum of Tmax data requests, each main control frequency is tried sequentially to find the maximum main control frequency that satisfies the SM2 algorithm's operation. This process continues until the maximum main control frequency corresponding to each algorithm type is obtained.
[0100] The maximum operating frequency requirement can be the minimum of the maximum master control frequency corresponding to all algorithm types, or the maximum operating frequency requirement can be the maximum master control frequency corresponding to the target algorithm type.
[0101] In the above formula, T represents the amount of predicted data, that is, the amount of predicted data sent by the host device to the cryptographic card. 'a' represents the adjustment coefficient, such as the first coefficient value, the second coefficient value, or the third coefficient value. The adjustment coefficient is used to significantly reduce the frequency in the low-load area and rapidly increase the frequency in the high-load area to ensure algorithm operation.
[0102] As can be seen from the above formula, the master control frequency is positively correlated with the amount of predicted data; that is, the larger the amount of predicted data, the higher the master control frequency. Furthermore, considering that the amount of predicted data T is less than or equal to the maximum amount of data Tmax, meaning T / Tmax is less than or equal to 1, for T / Tmax raised to the power of a, the larger the adjustment coefficient a, the smaller T / Tmax raised to the power of a is; that is, the master control frequency is negatively correlated with the adjustment coefficient.
[0103] Since the second coefficient value (1.3~1.5) is greater than the first coefficient value (1.0~1.1), the main control frequency for I / O-intensive algorithms is lower than that for computationally intensive algorithms. Furthermore, since the third coefficient value (1.5~1.8) is greater than the second coefficient value (1.3~1.5), the main control frequency for hardware-accelerated algorithms is lower than that for I / O-intensive algorithms.
[0104] Step S13: Configure the main control frequency for the main control processor, and the main control processor operates using the main control frequency.
[0105] In summary, the main control processor's clock speed (operating frequency) can be dynamically adjusted based on the target algorithm type (used to characterize task complexity) and the amount of predicted data. For example, for hardware-accelerated algorithms, the lowest clock speed can be used to reduce dynamic power consumption while meeting performance requirements. For I / O-intensive algorithms, a mid-range clock speed can be used to reduce dynamic power consumption while meeting performance requirements. For computationally intensive algorithms, the highest clock speed can be used to meet performance requirements, ensuring computational efficiency by increasing the clock speed. Frequency adjustment can be achieved through the main control processor's built-in controller, employing a smooth transition strategy to avoid computational anomalies caused by sudden frequency changes.
[0106] Step 503: After waking up the dormant password card, configure the number of channels to be enabled based on the target algorithm type and the amount of predicted data corresponding to the pending request. For example, the task processing unit configures the number of channels to be enabled based on the target algorithm type and the amount of predicted data corresponding to the pending request.
[0107] For example, the cryptographic card may include an interface (such as a PCIe interface) through which it communicates with the host device; that is, the host device sends pending requests to the cryptographic card via the PCIe interface. This PCIe interface of the cryptographic card may include multiple channels, such as 16 channels. Based on this, some or all of the 16 channels can be enabled, such as enabling 1 channel, 2 channels, 4 channels, 8 channels, or 16 channels. In this way, the number of channels enabled can be configured based on the target algorithm type and the amount of predicted data corresponding to the pending request. This number of enabled channels can represent how many channels are active. For example, the number of enabled channels could be 1, 2, 4, 8, 16, etc.
[0108] For example, to configure the number of channels enabled for a PCIe interface, the following steps can be taken: Step S21: Determine the safety factor (also known as the safety redundancy factor) based on the target algorithm type.
[0109] For example, if the target algorithm type corresponds to a computationally intensive algorithm, then the safety factor can be the fourth factor value. For instance, if the target algorithm type is RSA or SM2, then the target algorithm type corresponds to a computationally intensive algorithm. The fourth factor value can be between 0.10 and 0.15. This fourth factor value is used to achieve low redundancy because traffic prediction is relatively stable and does not require reserving an excessively large buffer.
[0110] For example, if the target algorithm type corresponds to I / O intensive, i.e., for I / O intensive algorithms, the security factor can be the fifth factor value, which is greater than the fourth factor value. For instance, if the target algorithm type is SM3, SM4, or AES, then the target algorithm type corresponds to I / O intensive, which can represent streaming processing or large-packet batch processing (such as file encryption, video stream encryption, database field encryption, etc.). The fifth factor value can be 0.25~0.30. The fifth factor value is used to achieve high redundancy, reserving sufficient bandwidth for sudden data surges and preventing packet loss or latency spikes due to prediction lag.
[0111] For example, if the target algorithm type corresponds to hardware acceleration, that is, for hardware-accelerated algorithms, then the full coefficient can be the fifth coefficient value, which is greater than the fourth coefficient value. For instance, if the target algorithm type is SM1, then the target algorithm type corresponds to hardware acceleration, and the fifth coefficient value can be 0.25~0.30.
[0112] Step S22: Determine the interface link bandwidth based on the predicted data volume and the security factor. The interface link bandwidth is positively correlated with the predicted data volume and the security factor.
[0113] For example, the interface link bandwidth can be determined using the following formula: B = T × (1 + c). Of course, the above formula is just one example for determining the interface link bandwidth. The interface link bandwidth is positively correlated with the predicted data volume and the security factor. In the above formula, B represents the interface link bandwidth, T represents the predicted data volume, i.e., the predicted data volume sent by the host device to the cryptographic card, and c represents the security factor, such as the fourth or fifth coefficient value. The security factor is used to implement security redundancy.
[0114] As can be seen from the above formula, interface link bandwidth is positively correlated with the amount of predicted data; that is, the larger the amount of predicted data, the larger the interface link bandwidth. Furthermore, interface link bandwidth is positively correlated with the security factor; that is, the larger the security factor, the larger the interface link bandwidth.
[0115] Step S23: Query the bandwidth mapping table corresponding to the PCIe version of the cryptographic card based on the interface link bandwidth to obtain the number of channels enabled; wherein, the bandwidth mapping table may include the correspondence between the number of channels and the bandwidth, and the bandwidth corresponding to the number of channels enabled may be greater than or equal to the interface link bandwidth.
[0116] For example, a bandwidth mapping table can be maintained in advance. See Table 1 for an example of a bandwidth mapping table. The bandwidth mapping table can include the correspondence between PCIe version, number of channels and bandwidth.
[0117] Table 1
[0118] For example, the PCIe version of the cryptographic card can be determined, that is, the PCIe version of the PCIe interface of the cryptographic card, indicating which version the PCIe interface is currently using. Taking PCIe version 4.0 as an example, the bandwidth mapping table corresponding to PCIe version 4.0 (i.e., part of Table 1) can be queried, as shown in Table 2.
[0119] Table 2
[0120] In Table 2, 1969 indicates that the bandwidth corresponding to channel number 1 is 1969 [MB / s], 3938 indicates that the bandwidth corresponding to channel number 2 is 3938 [MB / s], and so on. Clearly, this bandwidth mapping table can include the correspondence between the number of channels and the bandwidth; the number of channels can be 1, 2, 4, 8, 16, etc.
[0121] The number of channels activated is determined by querying the bandwidth mapping table based on the interface link bandwidth. The bandwidth corresponding to each activated channel can be greater than or equal to the interface link bandwidth. For example, if the interface link bandwidth is less than or equal to 1969 MB / s, the number of activated channels is 1, and the bandwidth corresponding to channel 1 is greater than or equal to the interface link bandwidth. If the interface link bandwidth is greater than 1969 MB / s and less than or equal to 3938 MB / s, the number of activated channels is 2, and the bandwidth corresponding to channel 2 is greater than or equal to the interface link bandwidth. The bandwidth corresponding to the previous channel number for channel 2 is less than the interface link bandwidth. If the interface link bandwidth is greater than 3938 MB / s and less than or equal to 7887 MB / s, the number of activated channels is 3, and the bandwidth corresponding to channel 3 is greater than or equal to the interface link bandwidth. The bandwidth corresponding to the previous channel number for channel 3 is less than the interface link bandwidth, and so on.
[0122] In summary, the number of channels enabled is positively correlated with the interface link bandwidth; that is, the higher the interface link bandwidth, the more channels can be enabled. Considering that interface link bandwidth is positively correlated with the security factor and the amount of predicted data, when configuring the number of channels enabled, both the number of channels enabled and the number of predicted data can be positively correlated.
[0123] Step S24: Enable the specified number of channels for the cryptographic card's interface (i.e., PCIe interface). For example, if the number of channels enabled is 4, then 4 channels are enabled for the cryptographic card's PCIe interface, and the remaining 12 channels are in a disabled state. By disabling 12 channels, the power consumption of the cryptographic card can be reduced.
[0124] In summary, it can be seen that the interface link bandwidth (number of channels enabled) of the PCIe interface can be dynamically adjusted based on the target algorithm type (used to characterize task complexity) and the predicted data volume. For example, the interface link bandwidth (also known as interface link width) can be dynamically adjusted according to the predicted data volume (i.e., the amount of business data transmitted). For instance, when the PCIe interface transmits a large amount of encrypted data, a full-width mode can be used to improve efficiency, such as enabling all channels. When the PCIe interface transmits control commands or is idle, it can switch to a narrow-width mode to reduce power consumption, such as enabling some channels. In this way, dynamic adaptation of the interface link bandwidth (number of channels enabled) can be achieved.
[0125] In the above process, taking the main control frequency of the main control processor and the interface link bandwidth of the PCIe interface as an example, in addition to the main control frequency and interface link bandwidth, other power consumption parameters may also be involved, such as the clock frequency of the clock management unit and / or the memory bandwidth of the main control processor, etc., without any restrictions.
[0126] The clock frequency of the clock management unit can also be configured based on the amount of predicted data. For example, the clock frequency may be positively correlated with the amount of predicted data; that is, the larger the amount of predicted data, the higher the clock frequency. For instance, each algorithm unit can be configured with an independent clock controller (i.e., a clock management unit). Based on the algorithm type, only the clock controller of the required algorithm unit is activated (i.e., the clock management unit corresponding to the first algorithm unit is enabled), and the clock frequency of the clock controller is adjusted to the appropriate frequency. The clock controllers of inactive algorithm units remain off. For example, when enabling the algorithm unit corresponding to SM3 operation, only the clock controller corresponding to the algorithm unit corresponding to SM3 operation is enabled, while the clock controllers corresponding to the algorithm units corresponding to other algorithms (such as SM2 and SM4) are disabled, thereby eliminating the power consumption of redundant clocks.
[0127] Regarding the memory bandwidth of the main control processor, the main control processor may include DDR memory. When processing data, the main control processor first writes external data to DDR memory and then reads data from DDR memory. The memory bandwidth is the bandwidth of the DDR memory, also known as the DDR memory frequency. The memory bandwidth (memory frequency) of the main control processor can be configured based on the predicted data volume. For example, the memory frequency may be positively correlated with the predicted data volume; that is, the larger the predicted data volume, the higher the memory frequency. Obviously, the memory frequency can be dynamically adjusted according to the data throughput of the encryption request. In high-throughput scenarios, the memory frequency is increased to ensure read and write performance, while in low-throughput scenarios, the memory frequency is decreased to save power. The adjustment process is implemented through the memory controller to ensure that the bandwidth matches the actual needs and avoids resource waste.
[0128] For example, to avoid resource conflicts that may arise from independent adjustments, a priority order can be pre-configured, such as the main controller frequency, memory bandwidth, clock frequency, and interface link width (number of channels enabled). Based on this priority order, power consumption parameters are adjusted sequentially. For instance, the main controller frequency of the main processor is adjusted first, then the memory bandwidth of the main controller's DDR memory is adjusted, then the clock frequency of the clock management unit (clock controller) is adjusted, and finally the interface link bandwidth (number of channels enabled) of the PCIe interface is adjusted. This ensures that hardware resources at each level match the task requirements, avoiding performance bottlenecks or wasted power.
[0129] When in operation, the cryptographic card identifies the task category (such as SM2 signature, SM4 encryption, SM3 hash, etc.) by parsing the requests to be processed. The task category can also be called the task type or algorithm type. Based on the algorithm type, the card dynamically adjusts the hardware parameters to achieve a precise match between power consumption and performance. The cryptographic card has a built-in power consumption policy template that can be updated online. For different algorithms with different computational characteristics (such as the high computational complexity of SM2 signature and the high throughput of SM4 encryption), multiple sets of DVFS adjustment policies are preset. The DVFS adjustment policies cover the adjustment logic and threshold range of parameters such as main control frequency, memory bandwidth, clock frequency, and interface link width.
[0130] DVFS (Dynamic Voltage and Frequency Scaling) achieves a balance between power consumption and performance by adjusting the operating voltage and frequency. A multi-level DVFS collaborative control mechanism dynamically distributes power management strategies based on the algorithm type (such as SM1, SM2, SM3, SM4, AES, RSA, etc.), dynamically adjusting hardware resources. The cryptographic card jointly adjusts the main control frequency, memory bandwidth, clock frequency, and interface link width, achieving fine-grained matching of hardware resources. This significantly reduces the cryptographic card's power consumption, achieving an adaptive balance between high-performance encryption and low-power operation while ensuring security and real-time performance.
[0131] Step 504: Under the configured power consumption parameters, the first algorithm unit encrypts or decrypts the request to be processed. For example, if the request to be processed is a request to be encrypted, the first algorithm unit performs an encryption operation on the request, such as the first algorithm unit calling the main control processor to encrypt the request; or, if the request to be processed is a request to be decrypted, the first algorithm unit performs a decryption operation on the request, such as the first algorithm unit calling the main control processor to decrypt the request.
[0132] For example, based on configuring the main control frequency for the main control processor and enabling the number of channels for the PCIe interface of the cryptographic card, the first algorithm unit can call the main control processor to encrypt or decrypt the request to be processed. In this embodiment, there are no restrictions on this encryption or decryption process.
[0133] For example, the units can work collaboratively to form a complete low-power control system. For instance, a predictive model can predict the probability of idle service and the amount of data to be processed in the next 50ms using a sliding window every 50ms. When the probability of idle service exceeds a threshold, a pre-sleep mechanism is triggered, shutting down redundant units and retaining only the real-time detection capability of the signal detection unit. In the pre-sleep state, if an external request is detected, the cryptographic card is immediately woken up. The algorithm type is identified based on the request, and power consumption parameters such as the main control frequency, memory bandwidth, clock frequency, and interface link width are dynamically adjusted based on the algorithm type and the amount of predicted data. If no external request is detected in the pre-sleep state, the pre-sleep state is maintained. Through close collaboration between the units, precise control of the cryptographic card's power consumption is achieved, while ensuring the real-time performance and security of service processing.
[0134] As can be seen from the above technical solutions, this application proposes a method for constructing a low-power cryptographic card based on dynamic collaborative optimization. Collaborative optimization refers to configuring multiple power consumption parameters after waking up a dormant cryptographic card, i.e., collaboratively optimizing multiple power consumption parameters to achieve a low-power cryptographic card. Furthermore, this application proposes a method for implementing a low-power cryptographic card based on dynamic hierarchical collaborative optimization. Dynamic hierarchical optimization refers to implementing a low-power cryptographic card through multiple layers. For example, a low-power cryptographic card can be implemented through a driver layer, firmware layer, and DVFS adjustment layer. For the driver layer, the driver layer can predict the probability of service idle time and the amount of data through a prediction model. For the firmware layer, after receiving a pre-sleep instruction from the driver layer, the firmware layer can shut down the cryptographic card (e.g., shut down the algorithm unit, power management unit, clock management unit, and cache); after detecting that a pending request has been written to the basic cache, the firmware layer can wake up the dormant cryptographic card (e.g., enable the algorithm unit, power management unit, clock management unit, and cache). For the DVFS tuning layer, the DVFS tuning layer dynamically adjusts power consumption parameters such as master control frequency, memory bandwidth, clock frequency, and interface link width based on algorithm type and predicted data volume.
[0135] As can be seen from the above technical solutions, in this embodiment, a lightweight prediction model is implemented on the host device to predict the probability of service idleness within a future time window in real time, realizing a paradigm shift from passive response to proactive prediction. By predicting service idleness trends in advance, the sleep entry time of the cryptographic card can be advanced by 50-100ms, reducing power consumption waste caused by passive detection delays. In intermittent workload scenarios, power consumption reduction can reach more than 30%. A pre-sleep instruction protocol is designed to enable the cryptographic card to shut down in advance while retaining PCIe link detection capabilities, achieving gradual sleep, which ensures both rapid response to burst requests and power savings from deep sleep. A four-level collaborative DVFS adjustment is implemented for the main control frequency, memory bandwidth, clock frequency, and interface link width, dynamically matching hardware resource configuration according to the algorithm type, realizing fine-grained scheduling of hardware resources, and obtaining appropriate power consumption configurations for different algorithm types, resulting in an overall energy efficiency improvement of more than 40%. It can intelligently sense the business load (i.e., predict the data volume) and proactively perform refined power consumption management to achieve an adaptive balance between high-performance encryption and low-power operation. While ensuring data processing efficiency, it can save the operating power consumption of the cryptographic card and save cryptographic card resources.
[0136] Based on the same concept as the above method, this application proposes a cryptographic card, which is deployed on a host device. See [link to relevant documentation]. Figure 6 The diagram shown is a structural schematic of a password card, which includes: The task processing unit 61 is configured to configure power consumption parameters based on the target algorithm type corresponding to the request to be processed and the predicted data volume corresponding to the request to be processed after waking up the dormant cryptographic card; the first algorithm unit 62 is configured to encrypt or decrypt the request to be processed under the power consumption parameters; wherein, the cryptographic card includes multiple algorithm units corresponding to multiple algorithm types, the first algorithm unit 62 is any algorithm unit, and the first algorithm unit 62 corresponds to the target algorithm type; The first algorithm unit 62 calls the main control processor to encrypt or decrypt the request to be processed; the interface of the password card includes multiple channels; the power consumption parameters include the main control frequency of the main control processor and / or the number of channels enabled in the multiple channels of the interface. The master control frequency is negatively correlated with the adjustment coefficient, and the master control frequency is positively correlated with the amount of predicted data. The adjustment coefficient is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the adjustment coefficient is a first coefficient value; if the target algorithm type corresponds to an I / O intensive algorithm, the adjustment coefficient is a second coefficient value; if the target algorithm type corresponds to a hardware-accelerated algorithm, the adjustment coefficient is a third coefficient value. The second coefficient value is greater than the first coefficient value, and the third coefficient value is greater than the second coefficient value. The number of channels activated is positively correlated with the security factor, and the number of channels activated is positively correlated with the amount of predicted data. The security factor is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the security factor is the fourth coefficient value. If the target algorithm type corresponds to an I / O intensive algorithm or a hardware-accelerated algorithm, the security factor is the fifth coefficient value. The fifth coefficient value is greater than the fourth coefficient value.
[0137] For example, if the power consumption parameter includes the main control frequency, the task processing unit 61 configures the power consumption parameter based on the target algorithm type corresponding to the request to be processed and the predicted data volume corresponding to the request to be processed, specifically by: determining the adjustment coefficient based on the target algorithm type; if the target algorithm type is RSA or SM2, the target algorithm type corresponds to computationally intensive, which means that the amount of encryption or decryption computation is large; if the target algorithm type is SM3, SM4, or AES, the target algorithm type corresponds to IO intensive, which means that the IO of encryption or decryption is large; if the target algorithm type is SM1, the target algorithm type corresponds to hardware acceleration, which means that the auxiliary processor is called to encrypt or decrypt the request to be processed; determining the main control frequency based on the configured minimum operating requirement frequency, the configured maximum data volume, the acquired maximum operating requirement frequency, the predicted data volume, and the adjustment coefficient; the maximum operating requirement frequency is the main control frequency of the main control processor under the maximum data volume; configuring the main control frequency of the main control processor.
[0138] For example, when the task processing unit 61 determines the master control frequency based on the minimum operating demand frequency, the maximum data volume, the acquired maximum operating demand frequency, the predicted data volume, and the adjustment coefficient, it specifically uses the following formula to determine the master control frequency: F = Fmin + (Fmax - Fmin) × (T / Tmax) a Where F represents the main control frequency, Fmin represents the minimum operating frequency, Fmax represents the maximum operating frequency, T represents the predicted data volume, Tmax represents the maximum data volume, and a represents the adjustment coefficient.
[0139] For example, if the power consumption parameter includes the number of channels enabled, the task processing unit 61 configures the power consumption parameter based on the target algorithm type corresponding to the request to be processed and the predicted data volume corresponding to the request to be processed, specifically by: determining a security factor based on the target algorithm type; determining the interface link bandwidth based on the predicted data volume and the security factor, wherein the interface link bandwidth is positively correlated with the predicted data volume and the security factor; querying the bandwidth mapping table corresponding to the PCIe version of the cryptographic card based on the interface link bandwidth to obtain the number of channels enabled; the bandwidth mapping table includes the correspondence between the number of channels and the bandwidth, wherein the bandwidth corresponding to the number of channels enabled is greater than or equal to the interface link bandwidth; and enabling the number of channels enabled for the interface of the cryptographic card.
[0140] For example, the cryptographic card includes a memory controller, which includes a basic cache and a high-speed cache; the cryptographic card also includes a power management unit and a clock management unit corresponding to each algorithm unit; the task processing unit 61 is further configured to, if it receives a pre-sleep instruction sent by the host device, shut down the second algorithm unit and the power management unit and clock management unit corresponding to the second algorithm unit, and shut down the high-speed cache; wherein, the second algorithm unit is the algorithm unit currently running on the cryptographic card; and shut down the task processing unit to put the cryptographic card into sleep mode.
[0141] The cryptographic card further includes a signal detection unit, which is used to wake up the task processing unit 61 if it is detected that the basic cache has been written with a pending request; the task processing unit 61 is used to determine the target algorithm type corresponding to the pending request, activate the first algorithm unit corresponding to the target algorithm type and the power management unit and clock management unit corresponding to the first algorithm unit; activate the cache, and migrate the pending request in the basic cache to the cache.
[0142] For example, the host device determines a first statistical feature based on the pending requests in the current period, and determines a second statistical feature based on the pending requests in previous historical periods. Based on the first and second statistical features, it predicts the service idle probability of the cryptographic card in the next period. If the service idle probability is less than a threshold, it sends the pre-sleep instruction to the cryptographic card. If the service idle probability is not less than the threshold, it predicts the predicted data volume of the cryptographic card in the next period based on the first and second statistical features, and sends the predicted data volume to the cryptographic card.
[0143] For example, the first statistical feature or the second statistical feature includes at least one of the following: the data packet size of the request to be processed, the arrival time of the request to be processed, the algorithm type corresponding to the request to be processed, the operation type carried by the request to be processed, and the burst density corresponding to the request to be processed; wherein, the operation type represents opening the password card, closing the password card, opening a session, or closing a session; The first statistical feature and the second statistical feature are input into the trained prediction model to obtain the business idle probability and the predicted data volume; the prediction model includes a quantized LSTM model, the LSTM model includes a first hidden layer and a second hidden layer, the first hidden layer includes K1 neurons, the second hidden layer includes K2 neurons, K1 is greater than 1, and K2 is greater than 1.
[0144] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for constructing a low-power cryptographic card based on dynamic cooperative optimization, characterized in that, Applied to a cryptographic card, wherein the cryptographic card is deployed on a host device, the method includes: After waking up the dormant cryptographic card, the power consumption parameters are configured based on the target algorithm type corresponding to the pending request and the amount of predicted data corresponding to the pending request. Under the power consumption parameters, the request to be processed is encrypted or decrypted by the first algorithm unit corresponding to the target algorithm type; wherein, the cryptographic card includes multiple algorithm units corresponding to one algorithm type; The first algorithm unit calls the main control processor to encrypt or decrypt the request to be processed; the interface of the password card includes multiple channels; the power consumption parameters include the main control frequency of the main control processor and / or the number of channels enabled in the multiple channels of the interface. The master control frequency is negatively correlated with the adjustment coefficient, and the master control frequency is positively correlated with the amount of predicted data. The adjustment coefficient is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the adjustment coefficient is a first coefficient value; if the target algorithm type corresponds to an I / O intensive algorithm, the adjustment coefficient is a second coefficient value; if the target algorithm type corresponds to a hardware-accelerated algorithm, the adjustment coefficient is a third coefficient value. The second coefficient value is greater than the first coefficient value, and the third coefficient value is greater than the second coefficient value. The number of channels activated is positively correlated with the security factor, and the number of channels activated is positively correlated with the amount of predicted data. The security factor is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the security factor is the fourth coefficient value. If the target algorithm type corresponds to an I / O intensive algorithm or a hardware-accelerated algorithm, the security factor is the fifth coefficient value. The fifth coefficient value is greater than the fourth coefficient value. Wherein, if the target algorithm type is RSA type or SM2 type, the target algorithm type corresponds to computationally intensive; if the target algorithm type is SM3 type, SM4 type or AES type, the target algorithm type corresponds to I / O intensive; if the target algorithm type is SM1 type, the target algorithm type corresponds to hardware accelerated.
2. The method according to claim 1, characterized in that, If the power consumption parameter includes the main control frequency, configuring the power consumption parameter based on the target algorithm type corresponding to the request to be processed and the amount of prediction data corresponding to the request to be processed includes: The adjustment coefficient is determined based on the target algorithm type; wherein, computationally intensive indicates a large amount of encryption or decryption computation; I / O intensive indicates a large amount of encryption or decryption I / O; hardware-accelerated indicates that an auxiliary processor is called to encrypt or decrypt the request to be processed; The master control frequency is determined based on the configured minimum operating frequency, the configured maximum data volume, the acquired maximum operating frequency, the predicted data volume, and the adjustment coefficient; wherein, the maximum operating frequency is the master control frequency of the master control processor under the maximum data volume. Configure the main control frequency for the main control processor.
3. The method according to claim 2, characterized in that, The process of determining the master control frequency based on the configured minimum operating demand frequency, the configured maximum data volume, the acquired maximum operating demand frequency, the predicted data volume, and the adjustment coefficient includes: The main control frequency is determined using the following formula: F = Fmin + (Fmax - Fmin) × (T / Tmax) a ; Where F represents the main control frequency, Fmin represents the minimum operating frequency, Fmax represents the maximum operating frequency, T represents the predicted data volume, Tmax represents the maximum data volume, and a represents the adjustment coefficient.
4. The method according to claim 1, characterized in that, If the power consumption parameter includes the number of channels enabled, configuring the power consumption parameter based on the target algorithm type corresponding to the request to be processed and the amount of prediction data corresponding to the request to be processed includes: The security factor is determined based on the target algorithm type; The interface link bandwidth is determined based on the predicted data volume and the security factor, wherein the interface link bandwidth is positively correlated with the predicted data volume and the security factor. Based on the interface link bandwidth, the bandwidth mapping table corresponding to the PCIe version of the cryptographic card is queried to obtain the number of channels enabled; wherein, the bandwidth mapping table includes the correspondence between the number of channels and the bandwidth, and the bandwidth corresponding to the number of channels enabled is greater than or equal to the interface link bandwidth; Enable the number of channels for the interface of the password card.
5. The method according to any one of claims 1-4, characterized in that, The cryptographic card includes a memory controller, which includes a basic cache and a high-speed cache; the cryptographic card also includes a power management unit and a clock management unit corresponding to each algorithm unit; Before configuring the power consumption parameters based on the target algorithm type corresponding to the request to be processed and the amount of prediction data corresponding to the request to be processed, the method further includes: If a pre-sleep command is received from the host device, the second algorithm unit, the power management unit and the clock management unit corresponding to the second algorithm unit are shut down, and the cache is shut down; wherein, the second algorithm unit is the algorithm unit currently running on the password card; If it is detected that the basic cache has been written with a pending request, the dormant cryptographic card is woken up; wherein, the target algorithm type corresponding to the pending request is determined, the first algorithm unit corresponding to the target algorithm type and the power management unit and clock management unit corresponding to the first algorithm unit are activated; the cache is activated, and the pending request in the basic cache is migrated to the cache.
6. The method according to claim 5, characterized in that, The method further includes: The host device determines a first statistical feature based on the pending requests in the current period, and determines a second statistical feature based on the pending requests in previous historical periods; based on the first and second statistical features, it predicts the probability of the password card being idle in the next period. If the service idle probability is less than the threshold, then the pre-sleep instruction is sent to the password card; If the business idle probability is not less than the threshold, then the predicted data volume of the password card in the next cycle is predicted based on the first statistical feature and the second statistical feature; The host device sends the predicted data to the cryptographic card.
7. The method according to claim 6, characterized in that, The first statistical feature includes at least one of the following: the data packet size of the pending request, the arrival time of the pending request, the algorithm type corresponding to the pending request, the operation type carried by the pending request, and the burst density corresponding to the pending request; wherein, the operation type represents opening the password card, closing the password card, opening a session, or closing a session; The host device inputs the first statistical feature and the second statistical feature into the trained prediction model to obtain the service idle probability and the prediction data volume. The prediction model includes a quantized LSTM model, which includes a first hidden layer and a second hidden layer. The first hidden layer includes K1 neurons, and the second hidden layer includes K2 neurons, where K1 is greater than 1 and K2 is greater than 1.
8. A password card, characterized in that, The password card is deployed on the host device, and the password card includes: The task processing unit is used to configure power consumption parameters based on the target algorithm type corresponding to the request to be processed and the amount of predicted data corresponding to the request to be processed after waking up the dormant password card. The first algorithm unit is used to encrypt or decrypt the request to be processed under the power consumption parameters; wherein, the cryptographic card includes multiple algorithm units corresponding to multiple algorithm types, the first algorithm unit is any algorithm unit, and the first algorithm unit corresponds to the target algorithm type; The first algorithm unit calls the main control processor to encrypt or decrypt the request to be processed; the interface of the password card includes multiple channels; the power consumption parameters include the main control frequency of the main control processor and / or the number of channels enabled in the multiple channels of the interface. The master control frequency is negatively correlated with the adjustment coefficient, and the master control frequency is positively correlated with the amount of predicted data. The adjustment coefficient is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the adjustment coefficient is a first coefficient value; if the target algorithm type corresponds to an I / O intensive algorithm, the adjustment coefficient is a second coefficient value; if the target algorithm type corresponds to a hardware-accelerated algorithm, the adjustment coefficient is a third coefficient value. The second coefficient value is greater than the first coefficient value, and the third coefficient value is greater than the second coefficient value. The number of channels activated is positively correlated with the security factor, and the number of channels activated is positively correlated with the amount of predicted data. The security factor is determined based on the target algorithm type. If the target algorithm type corresponds to a computationally intensive algorithm, the security factor is the fourth coefficient value. If the target algorithm type corresponds to an I / O intensive algorithm or a hardware-accelerated algorithm, the security factor is the fifth coefficient value. The fifth coefficient value is greater than the fourth coefficient value. Wherein, if the target algorithm type is RSA type or SM2 type, the target algorithm type corresponds to computationally intensive; if the target algorithm type is SM3 type, SM4 type or AES type, the target algorithm type corresponds to I / O intensive; if the target algorithm type is SM1 type, the target algorithm type corresponds to hardware accelerated.
9. The password card according to claim 8, characterized in that, If the power consumption parameter includes the main control frequency, when the task processing unit configures the power consumption parameter based on the target algorithm type corresponding to the request to be processed and the predicted data volume corresponding to the request to be processed, it specifically performs the following: determining the adjustment coefficient based on the target algorithm type; wherein, computationally intensive indicates a large amount of encryption or decryption computation; I / O intensive indicates a large amount of encryption or decryption I / O; hardware accelerated indicates calling an auxiliary processor to encrypt or decrypt the request to be processed; determining the main control frequency based on the configured minimum operating requirement frequency, the configured maximum data volume, the acquired maximum operating requirement frequency, the predicted data volume, and the adjustment coefficient; wherein, the maximum operating requirement frequency is the main control frequency of the main control processor under the maximum data volume; configuring the main control frequency for the main control processor; The task processing unit determines the master control frequency based on the configured minimum operating demand frequency, the configured maximum data volume, the acquired maximum operating demand frequency, the predicted data volume, and the adjustment coefficient. Specifically, it uses the following formula to determine the master control frequency: F = Fmin + (Fmax - Fmin) × (T / Tmax). a Where F represents the main control frequency, Fmin represents the minimum operating frequency, Fmax represents the maximum operating frequency, T represents the predicted data volume, Tmax represents the maximum data volume, and a represents the adjustment coefficient. If the power consumption parameter includes the number of channels enabled, when the task processing unit configures the power consumption parameter based on the target algorithm type corresponding to the request to be processed and the predicted data volume corresponding to the request to be processed, it specifically performs the following: determining a security factor based on the target algorithm type; determining the interface link bandwidth based on the predicted data volume and the security factor, wherein the interface link bandwidth is positively correlated with the predicted data volume and the security factor; querying the bandwidth mapping table corresponding to the PCIe version of the cryptographic card based on the interface link bandwidth to obtain the number of channels enabled; the bandwidth mapping table includes the correspondence between the number of channels and the bandwidth, wherein the bandwidth corresponding to the number of channels enabled is greater than or equal to the interface link bandwidth; and enabling the number of channels enabled for the interface of the cryptographic card.
10. The password card according to claim 8 or 9, characterized in that, The cryptographic card includes a memory controller, which includes a basic cache and a high-speed cache; the cryptographic card also includes a power management unit and a clock management unit corresponding to each algorithm unit; The task processing unit is further configured to, upon receiving a pre-sleep instruction sent by the host device, shut down the second algorithm unit and the power management unit and clock management unit corresponding to the second algorithm unit, and shut down the cache; wherein the second algorithm unit is the algorithm unit currently running on the cryptographic card; and shut down the task processing unit to put the cryptographic card into sleep mode. The cryptographic card further includes a signal detection unit, which is used to wake up the task processing unit if it is detected that the basic cache has been written with a pending request; the task processing unit is used to determine the target algorithm type corresponding to the pending request, activate the first algorithm unit corresponding to the target algorithm type and the power management unit and clock management unit corresponding to the first algorithm unit; activate the cache, and migrate the pending request in the basic cache to the cache; The host device determines a first statistical feature based on the pending requests in the current period and a second statistical feature based on the pending requests in previous historical periods. It then predicts the service idle probability of the cryptographic card in the next period based on the first and second statistical features. If the service idle probability is less than a threshold, it sends a pre-sleep instruction to the cryptographic card. If the service idle probability is not less than the threshold, it predicts the predicted data volume of the cryptographic card in the next period based on the first and second statistical features and sends the predicted data volume to the cryptographic card. Wherein, the first statistical feature or the second statistical feature includes at least one of the following: the data packet size of the request to be processed, the arrival time of the request to be processed, the algorithm type corresponding to the request to be processed, the operation type carried by the request to be processed, and the burst density corresponding to the request to be processed; wherein, the operation type represents opening the password card, closing the password card, opening a session, or closing a session; The first statistical feature and the second statistical feature are input into the trained prediction model to obtain the business idle probability and the predicted data volume; the prediction model includes a quantized LSTM model, the LSTM model includes a first hidden layer and a second hidden layer, the first hidden layer includes K1 neurons, the second hidden layer includes K2 neurons, K1 is greater than 1, and K2 is greater than 1.
Citation Information
Patent Citations
PCI password card master control asynchronous scheduling system and method
CN112765077A
Method and device for adjusting power consumption of camera
CN116366956A