A method for integrated design of software and hardware of a cryptographic service platform

CN122818328APending Publication Date: 2026-09-25BEIJING GUOGUAN LIANZHONG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611026242.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-10
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

首先,硬件依赖性强;每项密码功能需配置特定硬件,导致 IT 基础设施复杂臃肿,采购、部署及后期维护成本大幅增加,管理负担沉重

Benefits of technology

1.硬件成本大幅降低:通过统一的密码卡硬件替代多种独立密码设备,硬件采购成本降低60%以上,机房空间占用减少70%,能耗降低65%,显著提升数据中心资源利用率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122818328A_ABST
    Figure CN122818328A_ABST
Patent Text Reader

Abstract

The application discloses a kind of cryptographic service platform software and hardware integrated design method, adopt unified cryptographic card hardware to replace traditional multiple independent cryptographic equipment, bottom C language library is encapsulated by hardware abstraction layer, Java is called channel is constructed using JNI bridging technology;The core innovation is in introducing the service matching algorithm MatchScore (S, B) based on multidimensional feature similarity = Σ [wᵢ × Sim (Cᵢˢ, Rᵢᴮ)], Intelligent recognition of business intent is realized;While constructing the resource allocation optimization model max [ΣUᵢ (xᵢ) - λ · C (x) - μ · P (x)] with constraint condition, under the constraint of meeting total amount of resources, service quality, performance delay, priority and load balancing, dynamic optimization scheduling of cryptographic computing resources is realized.The application realizes the goal of hardware unification, interface standardization, business intelligence, scheduling optimization, can intelligently adapt to electronic contract, data encryption, identity authentication and other diversified business scenarios, while reducing system complexity and cost, provide high performance, high reliability cryptographic service capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of cryptography and distributed computing technology, specifically to a method for integrated hardware and software design of a cryptographic service platform. Background Technology

[0002] Against the backdrop of rapid development in information technology, cryptography has become a core pillar for ensuring data security. Traditional cryptographic service models heavily rely on independent dedicated hardware devices such as signature verification servers, timestamp servers, cryptographic machines, and electronic signature servers. This decentralized deployment architecture has significant drawbacks, restricting its efficient application in modern information environments. First, it is highly dependent on hardware; each cryptographic function requires specific hardware configuration, resulting in a complex and bloated IT infrastructure, significantly increasing procurement, deployment, and subsequent maintenance costs, and placing a heavy management burden on the system. Secondly, the system lacks flexibility; resources for each device are fixed and cannot be dynamically adjusted and shared according to real-time business pressure, which easily leads to an imbalance where some devices are overloaded and others are idle, resulting in poor overall service elasticity. Furthermore, heterogeneous integration is highly complex; devices from different manufacturers often use proprietary interfaces and communication protocols, lacking a unified standard. When application systems access multiple cryptographic services, they need to be custom-developed, resulting in a large workload, long cycle, and difficulty in subsequent upgrades and modifications. Finally, resource utilization is low; dedicated hardware has limited functionality, creating "resource silos" that prevent cross-business computing power sharing and flexible scheduling, resulting in a double waste of hardware investment and computing resources. In summary, traditional cryptographic service systems face severe challenges in terms of cost, flexibility, integration efficiency, and resource utilization, and urgently need to be optimized and upgraded through architectural innovation. Summary of the Invention

[0003] The purpose of this invention is to provide an integrated hardware and software design method for a cryptographic service platform to solve the problems mentioned in the background art.

[0004] To achieve the above objectives, the present invention provides the following technical solution: a hardware and software integrated design method for a cryptographic service platform, comprising the following steps: Step S1: Construct a unified cryptographic hardware layer; A unified cryptographic card hardware is used as the core cryptographic operation unit, replacing multiple traditional independent cryptographic devices; Step S2: Construct the hardware abstraction layer; Develop a low-level driver library based on the C language, encapsulating the atomic operation functions of the cryptographic card, including but not limited to: key generation, key storage, data encryption, data decryption, digital signature, signature verification, hash calculation, and random number generation, forming a unified hardware call interface; Step S3: Construct the interface adaptation layer; By using JNI bridging technology, a calling channel is established between the Java platform and the underlying C library. The C language interface provided by the hardware abstraction layer is encapsulated into a native Java interface to achieve cross-language compatibility, enabling upper-layer business applications to uniformly call the password function through the Java language. Step S4: Receive business requests and extract features; The upper-layer application sends a business request to the cryptographic service platform. The request contains business data and metadata. The business parsing layer extracts multi-dimensional features of the business data, including data format features, data size, security level requirements, and business priority. Step S5: Service type identification based on multi-dimensional feature similarity; Based on predefined business rules and a feature vector-based service matching algorithm, identify the types of cryptographic services required by the business; calculate the degree of matching between the business requirements and each candidate service using a service capability matching degree calculation formula. Step S6: Dynamic interface matching and parameter configuration; Based on the identified service type, automatically select the corresponding password service interface and configure the algorithm parameters; Step S7: Hardware resource allocation based on the optimization model; By adopting a resource allocation optimization model, computing resources on the cryptographic card are dynamically allocated to maximize the overall system utility while meeting the service quality constraints of concurrent requests from multiple services. Step S8: Cryptographic operations are performed; The underlying C library is called through the JNI interface to perform cryptographic operations using the cryptographic card hardware, and the results are returned to the upper-layer application.

[0005] Preferably, the multidimensional features include: Data format characteristics, including data type, data structure tags, MIME type, and file header identifier; Data size characteristics include data length, number of data blocks, and data entropy value; Security requirements include algorithm identifiers, key identifiers, security level requirements, and compliance requirements; Business context features include the caller application identifier, request time characteristics, historical business patterns, and business priority tags.

[0006] Preferably, the similarity calculation function Sim uses cosine similarity or a Gaussian kernel function.

[0007] Preferably, the resource allocation optimization model is solved using an iterative optimization algorithm based on the Lagrange multiplier method, and the iterative update formula is: xᵢ⁽ᵏ⁺¹⁾ = xᵢ⁽ᵏ⁾ + η·∂L / ∂xᵢ, where L is the Lagrange function and η is the learning rate.

[0008] Preferably, the utility function Uᵢ(xᵢ) takes the form of a logarithmic function Uᵢ(xᵢ) = wᵢ × log(1 + xᵢ), where wᵢ is the business priority weight.

[0009] Preferably, the atomic operation functions encapsulated in the hardware abstraction layer include: key generation, key storage, data encryption, data decryption, digital signature, signature verification, hash calculation, and random number generation.

[0010] Preferably, the unified cryptographic card hardware supports both Chinese national cryptographic algorithms and international algorithms, including SM2, SM3, SM4, RSA, AES, ECDSA, and SHA algorithms, and provides hardware-level acceleration capabilities.

[0011] Preferably, the system further includes a business template self-learning module, which records and statistically analyzes the manually corrected business recognition results and regularly updates the feature vectors and weight coefficients wᵢ of the business template library.

[0012] Compared with the prior art, the beneficial effects of the present invention are: 1. Significantly reduced hardware costs: By replacing multiple independent cryptographic devices with a unified cryptographic card, hardware procurement costs are reduced by more than 60%, data center space occupancy is reduced by 70%, energy consumption is reduced by 65%, and data center resource utilization is significantly improved.

[0013] 2. Intelligent Business Identification: Based on a service matching algorithm with multi-dimensional feature similarity, the new business access cycle is shortened from several weeks to several hours. The business system does not need to pay attention to the details of the underlying password service interface. The system automatically completes service identification and parameter configuration, with an identification accuracy rate of over 95%.

[0014] 3. Maximize resource utilization: Through a resource allocation optimization model with constraints, dynamic scheduling of cryptographic computing resources is achieved, increasing overall throughput by 3-5 times and resource utilization from 30%-40% in traditional architecture to over 85%.

[0015] 4. Service Quality Assurance: A complete constraint system ensures that high-priority services receive resource guarantees, and the response time of critical services meets 99.9% of the requirements. At the same time, load balancing constraints prevent uneven resource allocation.

[0016] 5. Rigorous Mathematical Modeling: This invention formalizes the problem of cryptographic service resource allocation into an optimization problem with multiple constraints, and provides an iterative solution algorithm based on the Lagrange multiplier method, providing a rigorous mathematical foundation for system implementation.

[0017] 6. Flexible and Scalable Architecture: The layered architecture design enables the system to have good scalability. The hardware layer can be smoothly upgraded and the software layer can evolve independently, supporting the rapid access of new cryptographic algorithms and new business scenarios in the future. Attached Figure Description

[0018] Figure 1 This is a schematic diagram of the process of the present invention; Figure 2 This is a schematic diagram of the workflow of the present invention. Detailed Implementation

[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] Please see Figure 1-2 This invention provides a technical solution: a hardware and software integrated design method for a cryptographic service platform, the implementation steps of which are as follows: Step 1: Hardware Deployment Deploy a server in the data center with 4 national cryptographic cards. The cryptographic cards use PCI-E interfaces and support SM2 / SM3 / SM4 hardware acceleration. Each cryptographic card provides 64 parallel computing channels, and the total system resource capacity C=256 concurrent channels. Step 2: Business Requests and Feature Extraction The electronic contract platform calls the system interface of this invention via the Java SDK to submit 100 PDF contract files in batches. The intelligent parsing layer extracts feature vectors for each request. Data format characteristics: PDF file header "%PDF" identifier, MIME type "application / pdf"; Data size characteristics: File sizes range from 1.5MB to 3.2MB; Security requirement feature: The request header specifies "algorithm=SM2"; Business context characteristics: 10 requests carry the "priority=high" tag, while the remaining 90 have normal priority; Step 3: Service Type Identification Calculated using the service capability matching degree calculation formula: MatchScore(S,B) = Σ[wᵢ × Sim(Cᵢˢ, Rᵢᴮ)] Feature weight presets: data format feature w1=0.3, security requirement feature w2=0.4, data size feature w3=0.2, context feature w4=0.1.

[0021] Matching degree calculation with the "electronic contract signature" template: Data format matching score Sim1 = 0.98 (complete match for PDF format) Security requirement matching degree Sim2=1.00 (SM2 algorithm requires matching) Data size matching accuracy Sim3=0.85 (file size is within the template range) Context matching score Sim4=0.95 (Caller ID matches electronic contract business) MatchScore = 0.3×0.98 + 0.4×1.00 + 0.2×0.85 + 0.1×0.95 = 0.969 It is higher than other templates (data encryption 0.32, identity authentication 0.18) and is identified as an electronic contract signing service.

[0022] Step 4: Interface Matching and Parameter Configuration Based on the recognition results, the system automatically selects the signature service interface and configures the parameters: Algorithm: SM2 Key ID: Select "contract_signing_key" from the signing key pool. Hash Algorithm: SM3 Output format: PKCS#7 Step 5: Solving for resource allocation optimization There are currently 100 concurrent signature requests, of which 10 are high priority (Pᵢ=3) and 90 are normal priority (Pᵢ=1). The total system resources are C=256 concurrent channels.

[0023] Construct the utility function Uᵢ(xᵢ) = wᵢ × log(1 + xᵢ), where wᵢ is the priority weight (high priority wᵢ=3, normal priority wᵢ=1).

[0024] The resource cost function is C(x) = 0.1×Σxᵢ, and the priority penalty function is P(x) = 0.05×Σ(P_max - Pᵢ)xᵢ.

[0025] Quality of Service Constraint: R_minᵢ=1 (at least 1 channel is allocated for each request) Performance constraint: Tᵢ(xᵢ) = Dᵢ / xᵢ ≤ T_maxᵢ = 2 seconds, where Dᵢ is the signature computation time (related to file size). Load balancing constraint: |xᵢ - xⱼ| ≤ Δ_max=4 (the difference in resource allocation among similar services shall not exceed 4). The Lagrange multiplier method was used for iterative solution, and converged after 15 iterations. The resource allocation results are as follows: High-priority requests: each allocated 3-4 channels, estimated processing time 1.2-1.5 seconds. Normal priority requests: 2-3 channels allocated, estimated processing time 1.8-2.0 seconds. All requests are completed within 2 seconds, with higher priority requests receiving better service quality.

[0026] Step 6: Execute cryptographic operations By calling the sm2_sign function of the underlying C library through JNI, the cryptographic card hardware is driven to perform 100 signature operations in parallel, and high throughput processing is achieved by utilizing the 256 concurrent channels of the cryptographic card.

[0027] Step 7: Result Return The signing process for all 100 contracts was completed within 2.1 seconds, and the signing results were returned to the electronic contract platform in batches.

[0028] Example 2: Mixed Service Concurrency Scenarios Scene Description A government cloud platform simultaneously received three types of business requests: Category A: 50 electronic document signature requests (National Cryptographic Standard SM2, high priority, response time requirement ≤ 1 second) Category B: 200 database field encryption requests (SM4-CBC, normal priority, response time requirement ≤ 3 seconds) Category C: 10-timestamp issuance request (SM3, low priority, response time requirement ≤ 5 seconds) The total system resource capacity is C = 512 concurrent channels.

[0029] Implementation process Step 1: Feature Extraction and Service Identification The system extracts features from the three types of requests and accurately identifies them using a service matching algorithm: Class A matches the "electronic signature" template, MatchScore=0.97 Category B matches the "Data Encryption" template, MatchScore=0.95 Class C matches the "timestamp" template, MatchScore=0.98 Step 2: Resource Allocation Optimization Construct a multi-service utility function: U_total = ΣU_A(x_A) + ΣU_B(x_B) + ΣU_C(x_C) Priority weights: P_A=5, P_B=2, P_C=1 Quality of service constraints: R_min_A=1, R_min_B=1, R_min_C=1 Performance constraints: T_A ≤ 1 second, T_B ≤ 3 seconds, T_C ≤ 5 seconds Load balancing constraint: Within the same type of service, |Δx|≤2 Solving the optimization model yields the resource allocation scheme: Type A signature requests: 4-5 channels allocated per request (approximately 220 channels required in total). Type B encryption requests: 1-2 channels allocated per request (approximately 240 channels required in total). Type C timestamp requests: 1 channel allocated for each (10 channels required in total) The total resource usage is 470 channels, which is less than the system capacity of 512 channels.

[0030] Step 3: Dynamic Adjustment During execution, it was detected that some Class A requests had processing times approaching the 1-second threshold due to excessively large files. The system triggered a dynamic adjustment mechanism, reclaiming 20 channels from Class B services and redistributing them to Class A services to ensure SLA guarantees for high-priority services.

[0031] This invention provides a hardware and software integrated design method for a cryptographic service platform, comprising the following steps: Construct a unified cryptographic hardware layer, replace multiple independent cryptographic devices with a unified cryptographic card hardware, and provide atomic cryptographic operation functions; A hardware abstraction layer is constructed, and a low-level driver library is developed based on the C language to encapsulate the atomic operation functions of the cryptographic card and form a unified hardware call interface. An interface adaptation layer is built, and JNI bridging technology is used to establish a call channel between the Java platform and the underlying C library, encapsulating the C language interface into a native Java interface; Receive business requests and extract multidimensional features of the input data, including data format features, data size features, security requirement features, and business context features; A service matching algorithm based on multi-dimensional feature similarity is used to identify business intent. The service matching algorithm is expressed as follows: MatchScore(S,B) = Σ [wᵢ × Sim(Cᵢˢ, Rᵢᴮ)] Where S represents the cryptographic service, B represents the business requirement, wᵢ represents the weight of the i-th feature, Cᵢˢ represents the capability value of service S on the i-th feature, Rᵢᴮ represents the requirement value of business B on the i-th feature, and Sim is the similarity calculation function. Dynamically map the cryptographic service interface based on the identified business intent and configure the algorithm parameters; The computing resources on the cryptographic card are dynamically allocated using a resource allocation optimization model, which is expressed as follows: max [Σ Uᵢ(xᵢ) - λ·C(x) - μ·P(x)] And satisfy the constraint system: Σ xᵢ ≤ C xᵢ ≥ R_minᵢ Tᵢ(xᵢ) ≤ T_maxᵢ xᵢ ≥ Pᵢ × Bᵢ |xᵢ - xⱼ| ≤ Δ_max Where xᵢ is the amount of resources allocated to business i, Uᵢ(·) is the utility function of business i, C(x) is the resource usage cost function, P(x) is the priority penalty function, λ and μ are weight coefficients, Tᵢ(·) is the performance function of business i; λ, μ, ν are resource cost weight coefficients; γ, η, κ are algorithm step size parameters; P_Xᵢ[·] is the projection operator to the feasible set Xᵢ; [·]⁺ is the non-negative projection operator; The interface adaptation layer calls the hardware abstraction layer to drive the cryptographic card to perform cryptographic operations and return the operation results.

[0032] The contents not described in detail in this specification are prior art known to those skilled in the art. Although embodiments of the present invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for integrating hardware and software design of a cryptographic service platform, characterized in that: Includes the following steps: Step S1: Construct a unified cryptographic hardware layer; A unified cryptographic card hardware is used as the core cryptographic operation unit, replacing multiple traditional independent cryptographic devices; Step S2: Construct the hardware abstraction layer; Develop a low-level driver library based on the C language, encapsulating the atomic operation functions of the cryptographic card, including but not limited to: key generation, key storage, data encryption, data decryption, digital signature, signature verification, hash calculation, and random number generation, forming a unified hardware call interface; Step S3: Construct the interface adaptation layer; By using JNI bridging technology, a calling channel is established between the Java platform and the underlying C library. The C language interface provided by the hardware abstraction layer is encapsulated into a native Java interface to achieve cross-language compatibility, enabling upper-layer business applications to uniformly call the password function through the Java language. Step S4: Receive business requests and extract features; The upper-layer application sends a business request to the cryptographic service platform. The request contains business data and metadata. The business parsing layer extracts multi-dimensional features of the business data, including data format features, data size, security level requirements, and business priority. Step S5: Service type identification based on multi-dimensional feature similarity; Based on predefined business rules and a feature vector-based service matching algorithm, identify the types of cryptographic services required by the business; calculate the degree of matching between the business requirements and each candidate service using a service capability matching degree calculation formula. Step S6: Dynamic interface matching and parameter configuration; Based on the identified service type, automatically select the corresponding password service interface and configure the algorithm parameters; Step S7: Hardware resource allocation based on the optimization model; By adopting a resource allocation optimization model, computing resources on the cryptographic card are dynamically allocated to maximize the overall system utility while meeting the service quality constraints of concurrent requests from multiple services. Step S8: Cryptographic operations are performed; The underlying C library is called through the JNI interface to perform cryptographic operations using the cryptographic card hardware, and the results are returned to the upper-layer application.

2. The integrated hardware and software design method for a cryptographic service platform according to claim 1, characterized in that: The multidimensional features include: Data format characteristics, including data type, data structure tags, MIME type, and file header identifier; Data size characteristics include data length, number of data blocks, and data entropy value; Security requirements include algorithm identifiers, key identifiers, security level requirements, and compliance requirements; Business context features include the caller application identifier, request time characteristics, historical business patterns, and business priority tags.

3. The integrated hardware and software design method for a cryptographic service platform according to claim 1, characterized in that: The similarity calculation function Sim uses cosine similarity or Gaussian kernel function.

4. The integrated hardware and software design method for a cryptographic service platform according to claim 1, characterized in that: The resource allocation optimization model is solved using an iterative optimization algorithm based on the Lagrange multiplier method. The iterative update formula is: xᵢ⁽ᵏ⁺¹⁾ = xᵢ⁽ᵏ⁾ + η·∂L / ∂xᵢ, where L is the Lagrange function and η is the learning rate.

5. The integrated hardware and software design method for a cryptographic service platform according to claim 1, characterized in that: The utility function Uᵢ(xᵢ) takes the form of a logarithmic function Uᵢ(xᵢ) = wᵢ × log(1 + xᵢ), where wᵢ is the business priority weight.

6. The integrated hardware and software design method for a cryptographic service platform according to claim 1, characterized in that: The atomic operation functions encapsulated in the hardware abstraction layer include: key generation, key storage, data encryption, data decryption, digital signature, signature verification, hash calculation, and random number generation.

7. The integrated hardware and software design method for a cryptographic service platform according to claim 1, characterized in that: The unified cryptographic card hardware supports both Chinese and international cryptographic algorithms, including SM2, SM3, SM4, RSA, AES, ECDSA, and SHA algorithms, and provides hardware-level acceleration capabilities.

8. The integrated hardware and software design method for a cryptographic service platform according to claim 1, characterized in that: The system also includes a business template self-learning module, which records and statistically analyzes the manually corrected business recognition results and regularly updates the feature vectors and weight coefficients wᵢ of the business template library.