Load balancing program, load balancing method, and information processing device.

A load balancing program addresses the challenge of varying cryptographic processing device integration by monitoring and managing load across these devices, ensuring optimal resource allocation and reducing load concentration.

JP2026121150APending Publication Date: 2026-07-23エフサステクノロジーズ株式会社
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
エフサステクノロジーズ株式会社
Filing Date
2025-01-10
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

The integration of cryptographic processing devices into processors results in varying numbers depending on the processor model, leading to challenges in load balancing across these devices.

Method used

A load balancing program that obtains information from the processor about cryptographic processing devices and virtual devices, generates correspondence information, monitors load, and assigns virtual devices to applications based on this information to balance the load across multiple cryptographic processing devices.

Benefits of technology

Enables effective load balancing across multiple cryptographic processing devices embedded in a processor, optimizing resource allocation and reducing load concentration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026121150000001_ABST
    Figure 2026121150000001_ABST
Patent Text Reader

Abstract

This enables load balancing across multiple cryptographic processing devices built into the processor. [Solution] The processing unit 12 obtains information from the processor 20 about multiple cryptographic processing devices, which are built into the processor 20 and are destinations for offloading cryptographic processing, and multiple virtual devices that can be used by the multiple cryptographic processing devices. Based on the obtained information, the processing unit 12 generates correspondence information 11a that shows the correspondence between cryptographic processing devices and virtual devices. The processing unit 12 monitors the load of the first virtual device to which the first application is assigned and records the load of the first virtual device in load information 11b that shows the load of each virtual device. In response to a request to assign a virtual device to the second application, the processing unit 12 selects a second virtual device to assign to the second application based on the correspondence information 11a and load information 11b, and assigns the second virtual device to the second application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a load distribution program, a load distribution method, and an information processing apparatus.

Background Art

[0002] Data may be encrypted to enhance data confidentiality. The load of encryption processing is relatively high. When encryption processing is executed by a CPU (Central Processing Unit), the load on the CPU increases. For this reason, encryption processing may be offloaded to a physical device for encryption processing (encryption processing device) outside the CPU. The encryption processing device is provided, for example, mounted on an acceleration card as an external PCI (Peripheral Component Interconnect) device. A plurality of encryption processing devices may be mounted on the acceleration card.

[0003] The resources of the encryption processing device may be divided into a plurality of virtual devices and assigned to a plurality of applications. In an existing acceleration card, the number of mounted encryption processing devices is predetermined. Also, the pattern of identifying virtual devices for each of the predetermined number of encryption processing devices is fixed in advance. For this reason, based on the fixed pattern in advance, by selecting an encryption processing device on the acceleration card from an application, control such as avoiding load concentration on a specific encryption processing device on the acceleration card is possible.

[0004] In addition, there is a proposal for a computer that reflects the operating state of an operating business system in the information of the standard base of the system. The business system includes a load balancer that distributes the processing load in a virtual machine and a virtual storage device.

[0005] Furthermore, there is a proposal for a computer that, when creating a virtual computer, calculates the computing resources to be used for the I / O control logical partition (I / O-dedicated LPAR) for the virtual I / O (Input / Output) adapter based on a QoS (Quality of Service) policy. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] International Publication No. 2014 / 006739 [Patent Document 2] Japanese Patent Publication No. 2012-73660 [Overview of the project] [Problems that the invention aims to solve]

[0007] In recent years, cryptographic processing devices are sometimes integrated into processors such as CPUs. The number of cryptographic processing devices integrated into a processor varies depending on the processor model. In this case, the method of load balancing across multiple cryptographic processing devices integrated into the processor becomes an issue. In one aspect, the present invention aims to enable load balancing across multiple cryptographic processing devices embedded in a processor. [Means for solving the problem]

[0008] In one embodiment, a load balancing program is provided. The load balancing program causes a computer to perform the following processes: The computer obtains information from the processor about multiple cryptographic processing devices, which are built into the processor and are destinations for offloading cryptographic processing, and multiple virtual devices available on the multiple cryptographic processing devices. Based on the information obtained from the processor, the computer generates correspondence information showing the correspondence between the multiple cryptographic processing devices and the multiple virtual devices. The computer monitors the load of the first virtual device to which the first application is assigned, and records the load of the first virtual device in the load information showing the load of each of the multiple virtual devices. In response to a request to assign a virtual device to a second application, the computer selects a second virtual device to assign to the second application based on the correspondence information and load information, and assigns the second virtual device to the second application.

[0009] In one embodiment, a load balancing method performed by a computer is provided. In one embodiment, an information processing device having a storage unit and a processing unit is provided. [Effects of the Invention]

[0010] In one respect, it can enable load balancing across multiple cryptographic processing devices built into the processor. [Brief explanation of the drawing]

[0011] [Figure 1] This is a diagram illustrating the information processing device of the first embodiment. [Figure 2] This figure shows an example of the hardware of the information processing device according to the second embodiment. [Figure 3] This figure shows an example of a cryptographic processing device built into a processor. [Figure 4] This figure shows an example of the functions of an information processing device. [Figure 5] This figure shows an example of offloading cryptographic processing in a virtual machine. [Figure 6] It is a diagram showing a first example of a management table. [Figure 7] It is a diagram showing a second example of a management table. [Figure 8] It is a diagram showing a third example of a management table. [Figure 9] It is a diagram showing an example of a load history table. [Figure 10] It is a flowchart showing an example of information acquisition of PF and VF. [Figure 11] It is a flowchart showing an example of VF allocation to a virtual machine. [Figure 12] It is a flowchart showing an example of load monitoring. [Figure 13] It is a flowchart showing an example of load adjustment. [Figure 14] It is a sequence diagram showing an example of information acquisition of PF and VF. [Figure 15] It is a sequence diagram showing an example of VF allocation to a virtual machine. [Figure 16] It is a sequence diagram showing an example of load monitoring. [Figure 17] It is a diagram explaining the addition of a virtual machine in a single host. [Figure 18] It is a diagram showing a first example of VF allocation when adding a virtual machine. [Figure 19] It is a diagram showing a second example of VF allocation when adding a virtual machine. [Figure 20] It is a diagram showing an example of the load range of a virtual device. [Figure 21] It is a diagram explaining the addition of a virtual machine in a redundant host. [Figure 22] It is a diagram showing a third example of VF allocation when adding a virtual machine. [Figure 23] It is a diagram showing a comparative example.

Mode for Carrying Out the Invention

[0012] Hereinafter, this embodiment will be described with reference to the drawings. [First Embodiment] A first embodiment will be described. Figure 1 is a diagram illustrating an information processing device according to a first embodiment. The information processing device 10 has a storage unit 11 and a processing unit 12. The storage unit 11 may be a volatile semiconductor memory such as RAM (Random Access Memory), or a non-volatile storage such as an HDD (Hard Disk Drive) or flash memory. The processing unit 12 is a processor such as a CPU, GPU (Graphics Processing Unit), or DSP (Digital Signal Processor). However, the processing unit 12 may also include application-specific electronic circuits such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array). The processor executes programs stored in memory such as RAM (which may also be the storage unit 11). A collection of multiple processors is sometimes called a "multiprocessor" or simply a "processor".

[0013] The information processing device 10 has a processor 20. The processor 20 is, for example, a CPU, GPU, DSP, etc. The processor 20 has multiple processor cores. Processor cores 21 and 22 are examples of multiple processor cores. The information processing device 10 may have multiple processors, including the processor 20. Here, the processing unit 12 may be, for example, some of the multiple processor cores included in the processor 20, or it may be a processor separate from the processor 20.

[0014] The processor 20 incorporates multiple cryptographic processing devices. These cryptographic processing devices are hardware accelerators dedicated to cryptographic processing, such as data encryption and decryption of encrypted data. An example of a cryptographic processing device is Intel®'s QAT (Quick Assist Technology) device. The cryptographic processing devices are used as an offload destination for cryptographic processing within the processor core. Cryptographic processing devices 23 and 24 are examples of multiple cryptographic processing devices.

[0015] The resources of the cryptographic processing devices 23 and 24 are divided into multiple virtual devices. That is, one virtual device is one of several parts into which the computational resources of the cryptographic processing device are divided. Virtual devices 31, 32, ... are examples of multiple virtual devices. Virtual devices 31, 32, ... can be assigned to applications executed by the information processing device 10. The application may be executed by, for example, the processor cores 21 and 22. The application may be a virtual machine implemented by virtual machine management software such as a hypervisor, or a container implemented by container virtualization software. The application may also be executed without using virtualization technology.

[0016] The processing unit 12 obtains information from the processor 20 about multiple cryptographic processing devices and multiple virtual devices available to those devices. For example, the processing unit 12 obtains information from the processor 20 about cryptographic processing devices 23, 24 and virtual devices 31, 32, ... Let's assume there are a total of 6 virtual devices 31, 32, ... The information obtained from the processor 20 indicates that the processor 20 has two cryptographic processing devices 23 and 24, and that each of the cryptographic processing devices 23 and 24 has 3 virtual devices.

[0017] The processing unit 12 generates correspondence information 11a based on information obtained from the processor 20 and stores it in the storage unit 11. Correspondence information 11a indicates the correspondence between the cryptographic processing devices 23, 24 and the virtual devices 31, 32, ... For example, the identification information for cryptographic processing device 23 is "PF1". The identification information for cryptographic processing device 24 is "PF2". Correspondence information 11a indicates that three virtual devices identified by identification information "VF11", "VF12", and "VF13" are available for use in cryptographic processing device 23. Correspondence information 11a also indicates that three virtual devices identified by identification information "VF21", "VF22", and "VF23" are available for use in cryptographic processing device 24. Note that PF stands for Physical Function and VF stands for Virtual Function.

[0018] Here, applications 41 and 42 are examples of applications executed by the information processing device 10. The identification information for application 41 is "ap1". The identification information for application 42 is "ap2". In Figure 1, "App" is an abbreviation for "Application".

[0019] For example, suppose virtual devices 31, 32, ... are assigned to applications 41, 42 as follows: The virtual device "VF11" is assigned to application 41 (ap1). The virtual device "VF12" is assigned to application 42 (ap2). The virtual device "VF21" is assigned to application 41 (ap1). The virtual devices "VF13", "VF22", and "VF23" are not assigned to any application.

[0020] The allocation of the above virtual devices to applications 41 and 42 may be performed by the processing unit 12. For example, the processing unit 12 can allocate a number of virtual devices (e.g., 2) to application 41 that meet the performance requirements of application 41. When allocating 2 virtual devices to application 41, the processing unit 12 may distribute the load by allocating one virtual device from each of the two cryptographic processing devices 23 and 24. The processing unit 12 can also allocate a number of virtual devices (e.g., 1) to application 42 that meet the performance requirements of application 42.

[0021] For example, the processing unit 12 may register the application assignment details for the virtual device in the correspondence information 11a. A hyphen (-) in the correspondence information 11a indicates that there is no application assignment for the virtual device.

[0022] The processing unit 12 monitors the load of the first virtual device to which the first application is assigned, among the multiple virtual devices. The processing unit 12 records the load of the first virtual device in load information 11b, which indicates the load of each of the multiple virtual devices. Applications 41 and 42 are examples of the first application. The virtual devices "VF11" and "VF21" are examples of the first virtual device to which the first application (application 41) is assigned. The virtual device "VF12" is an example of the first virtual device to which the first application (application 42) is assigned.

[0023] For example, the processing unit 12 monitors the load on the virtual devices "VF11" and "VF21" used by application 41 and records it in load information 11b. The processing unit 12 also monitors the load on the virtual device "VF12" used by application 42 and records it in load information 11b.

[0024] The load is evaluated by load indicator values, such as the transfer rate of the data to be encrypted. The sum of the load indicator values ​​of each virtual device in a single encryption processing device corresponds to the load indicator value of that encryption processing device. In the example of the first embodiment, the upper limit of the load indicator value in a single encryption processing device is assumed to be 100.

[0025] For example, load information 11b indicates that the load index value for the virtual device "VF11" is 30. Load information 11b indicates that the load index value for the virtual device "VF12" is 20. In this case, the load index value indicating the load of the cryptographic processing device 23 is 30 + 20 = 50. Load information 11b indicates that the load index value for the virtual device "VF21" is 30. In this case, the load index value indicating the load of the cryptographic processing device 24 is 30. In load information 11b, a hyphen (-) is entered in the column for the load of virtual devices that are not assigned to any application.

[0026] The processing unit 12, in response to a request to allocate a virtual device to the second application, selects a second virtual device to assign to the second application based on the correspondence information 11a and load information 11b. The processing unit 12 then assigns the second virtual device to the second application.

[0027] Application 43 is executed by the information processing device 10. Application 43 is an example of a second application. For example, the processing unit 12 receives a request to allocate a virtual device to application 43 when application 43 is started. The request to allocate a virtual device to application 43 may be issued by application 43, or by other software that starts application 43 or other software that interacts with application 43.

[0028] For example, in response to a request to allocate a virtual device to application 43, the processing unit 12 selects a second virtual device to assign to application 43 based on correspondence information 11a and load information 11b. The second virtual device is selected from virtual devices that are not assigned to any application. For example, the processing unit 12 may select the second virtual device based on correspondence information 11a and load information 11b in order to equalize the load on cryptographic processing devices 23 and 24.

[0029] More specifically, the processing unit 12 may preferentially select a virtual device belonging to an encryption processing device with a low load as the second virtual device. For example, according to correspondence information 11a and load information 11b, encryption processing device 24 (PF2) has a lower load than encryption processing device 23 (PF1). Therefore, the processing unit 12 may select a virtual device of encryption processing device 24 (for example, the virtual device of "VF22") as the second virtual device.

[0030] Furthermore, the virtual device allocation request for application 43 may include information indicating the performance required for application 43. The required performance may be expressed using the same metric values ​​as load metric values, such as the transfer rate of data to be encrypted. As an example, consider the case where the required performance of application 43 is 50. In this case, for example, the following first and second allocation methods can be considered.

[0031] (First allocation method) The processing unit 12 may select a virtual device of the cryptographic processing device 24 (for example, the virtual device "VF22") that has a lower load than the cryptographic processing device 23 as the second virtual device, based on the correspondence information 11a and the load information 11b. In the first allocation method, the load index value of the cryptographic processing device 24 after the allocation of the second virtual device to the application 43 is expected to be 30 + 50 = 80.

[0032] (Second allocation method) Based on the correspondence information 11a and load information 11b, the processing unit 12 may select one second virtual device from each of the cryptographic processing devices 23 and 24 so as not to exceed the upper limit of the load that can be allowed for each cryptographic processing device. For example, the processing unit 12 selects the virtual device of cryptographic processing device 23 (for example, the virtual device "VF13") as the first second virtual device. The processing unit 12 also selects the virtual device of cryptographic processing device 24 (for example, the virtual device "VF22") as the second second virtual device. In the second allocation method, the cryptographic processing of application 43 is shared between the two cryptographic processing devices. For this reason, the processing unit 12 may estimate the required performance per virtual device as, for example, 50 / 2=25 for a required performance of 50. In this case, the load index value of cryptographic processing device 23 after allocating the second virtual devices to application 43 is expected to be 30+20+25=75. Furthermore, the load index value of the cryptographic processing device 24 after the allocation of the second virtual device to application 43 is expected to be 30 + 25 = 55.

[0033] The processing unit 12 may, for example, evaluate an index value (e.g., distribution) that indicates the variation in the expected load of all virtual devices in each case, such as when the first allocation method is used and when the second allocation method is used, and adopt an allocation method that reduces the index value.

[0034] Another example is when the required performance of application 43 is 80. In this case, if the processing unit 12 uses the first allocation method, it is expected that both cryptographic processing devices 23 and 24 will exceed the upper limit of 100 for the load index value. Therefore, by using the second allocation method, the processing unit 12 can select one second virtual device from each of the cryptographic processing devices 23 and 24 so that the upper limit of 100 for the load index value does not exceed for either of them. In this case, the load index value of 80, which corresponds to the required performance, is distributed to the two cryptographic processing devices. In this case, the increase in the load index value of each cryptographic processing device 23 and 24 is expected to be 80 / 2 = 40.

[0035] Then, the processing unit 12 assigns the second virtual device to the second application. For example, the processing unit 12 assigns the second virtual device selected by the first or second assignment method to application 43. The processing unit 12 can reflect the assignment details in the correspondence information 11a. The processing unit 12 also releases the virtual device that has been assigned to the application in response to the application stopping (for example, shutting down the virtual machine or stopping the container). By releasing the virtual device, the load on that virtual device is eliminated, and therefore the load on the cryptographic processing device to which that virtual device belongs is reduced.

[0036] Thus, according to the information processing device 10, information on multiple cryptographic processing devices, which are built into the processor and are destinations for offloading cryptographic processing, and information on multiple virtual devices available to the multiple cryptographic processing devices are obtained from the processor. Based on the information obtained from the processor, correspondence information is generated that shows the correspondence between the multiple cryptographic processing devices and the multiple virtual devices. Among the multiple virtual devices, the load of the first virtual device to which the first application is assigned is monitored, and the load of the first virtual device is recorded in the load information that shows the load of each of the multiple virtual devices. In response to a request to assign a virtual device to the second application, a second virtual device to be assigned to the second application is selected based on the correspondence information and load information. The second virtual device is assigned to the second application.

[0037] This enables the information processing device 10 to distribute the load across multiple cryptographic processing devices built into the processor. For example, the processing unit 12 obtains information on cryptographic processing devices 23, 24 and virtual devices 31, 32, ... from the processor 20 and generates correspondence information 11a. This allows the processing unit 12 to appropriately manage the number of cryptographic processing devices included in the processor 20, the number of virtual devices available for each cryptographic processing device, and the correspondence between cryptographic processing devices 23, 24 and virtual devices 31, 32, .... Furthermore, the processing unit 12 can appropriately manage the load on virtual devices 31, 32, ... and cryptographic processing devices 23, 24 based on the correspondence information 11a and load information 11b. Therefore, based on the correspondence information 11a and load information 11b, the processing unit 12 can determine which virtual devices to assign to a new application in order to equalize the load on cryptographic processing devices 23, 24, for example, by the first and second assignment methods described above.

[0038] [Second Embodiment] Next, a second embodiment will be described. Figure 2 shows an example of the hardware of an information processing device according to the second embodiment. The information processing device 100 virtualizes the functions of network devices such as switches, routers, and firewalls. The information processing device 100 may also be called a computer. The technology for virtualizing the functions of network devices on a computer is called NFV (Network Function Virtualization).

[0039] The information processing device 100 includes a processor 101, RAM 102, HDD 103, GPU 104, input interface 105, media reader 106, and communication interface 107. These units of the information processing device 100 are connected to a bus inside the information processing device 100.

[0040] Processor 101 executes program instructions. Processor 101 is, for example, a CPU. Processor 101 loads at least a portion of the program and data stored in HDD 103 into RAM 102 and executes the program. Processor 101 includes multiple processor cores. Information processing device 100 may have multiple processors. The processor that executes one of the multiple processes performed by the information processing device 100 may be different from the processor that executes a different process from the multiple processes. A collection of multiple processors is sometimes called a "multiprocessor" or simply a "processor". A processor may also be called a "processor circuitry".

[0041] RAM 102 is a volatile semiconductor memory that temporarily stores programs executed by the processor 101 and data used by the processor 101 for calculations. The information processing device 100 may also be equipped with other types of memory, and may be equipped with multiple types of memory.

[0042] The HDD 103 is a non-volatile storage device that stores software programs such as the OS (Operating System), middleware, and application software, as well as data. The information processing device 100 may also include other types of storage devices such as flash memory or SSD (Solid State Drive), and may include multiple non-volatile storage devices. The RAM 102 or HDD 103 is an example of the storage unit 11 in the first embodiment.

[0043] The GPU 104 outputs an image to the display 51 connected to the information processing unit 100, according to instructions from the processor 101. Any type of display can be used as the display 51, such as a CRT (Cathode Ray Tube) display, a liquid crystal display (LCD), a plasma display, or an organic electro-luminescence (OEL) display.

[0044] The input interface 105 acquires input signals from the input device 52 connected to the information processing device 100 and outputs them to the processor 101. The input device 52 can be a pointing device such as a mouse, touch panel, touchpad, or trackball, a keyboard, a remote controller, or a button switch. Furthermore, multiple types of input devices may be connected to the information processing device 100.

[0045] The media reader 106 is a reading device that reads programs and data recorded on the recording medium 53. The recording medium 53 can be, for example, a magnetic disk, an optical disk, a magneto-optical disk (MO), or semiconductor memory. Magnetic disks include flexible disks (FD) and HDDs. Optical disks include CDs (Compact Discs) and DVDs (Digital Versatile Discs).

[0046] The media reader 106 copies programs and data read from the recording medium 53 to other recording media such as RAM 102 or HDD 103. The read programs are executed by the processor 101, for example. The recording medium 53 may be a portable recording medium and may be used for distributing programs and data. The recording medium 53 and HDD 103 are sometimes referred to as computer-readable recording media.

[0047] The communication interface 107 is connected to the network 54 and communicates with other information processing devices via the network 54. The communication interface 107 may be a wired communication interface connected to a wired communication device such as a switch or router, or a wireless communication interface connected to a wireless communication device such as a base station or access point.

[0048] Figure 3 shows an example of a cryptographic processing device built into a processor. Processor 101 has processor cores 110, 111, ... and cryptographic processing devices 120, 120a, ... Each of the processor cores 110, 111, ... is an arithmetic unit capable of independently executing programs. In the following, "processor core" may be simply referred to as "core".

[0049] The cryptographic processing devices 120, 120a, ... are physical devices dedicated to cryptographic processing. The cryptographic processing devices 120, 120a, ... are hardware accelerators that perform cryptographic processing. Cryptographic processing is the process of encrypting data and decrypting encrypted data. The cryptographic processing devices 120, 120a, ... serve as offload destinations for cryptographic processing in processor cores 110, 111, ... Each of the cryptographic processing devices 120, 120a, ... is sometimes abbreviated as "PF".

[0050] The resources of the cryptographic processing device 120 are divided and managed into virtual devices 121, 122, ... Virtual devices 121, 122, ... can be assigned to applications such as virtual machines. By assigning virtual devices 121, 122, ... to an application, the information processing device 100 can offload cryptographic processing of data handled by that application to the cryptographic processing device 120. The resources of other cryptographic processing devices, including cryptographic processing device 120a, are also divided into multiple virtual devices. Virtual devices 121, 122, ... are sometimes abbreviated as "VF".

[0051] An example of processor 101 is Intel's Xeon® D-2700. The Xeon D-2700 is a CPU that incorporates a QAT device (encryption processing device). The number of encryption processing devices built into a processor varies depending on the processor model. For example, the number of built-in encryption processing devices ranges from 0 to 4 depending on the processor model.

[0052] Here, the processor 101 or other processors other than the processor 101 in the information processing device 100 are examples of the processing unit 12 in the first embodiment. A part of the processor cores 110, 111, ... or a part of the multiple processor cores of the other processor may be an example of the processing unit 12. Furthermore, in the following description, a virtual machine is used as an example of an application to which a virtual device is assigned.

[0053] Figure 4 shows an example of the functions of an information processing device. The information processing device 100 includes a management information storage unit 130, NFV infrastructure software 140, and virtual machines 150, 160, and 170. The management information storage unit 130 uses the storage areas of RAM 102 and HDD 103. The functions of the NFV infrastructure software 140 are realized by the execution of programs stored in RAM 102 by the processor 101 or other processors of the information processing device 100. The virtual machines 150, 160, and 170 are virtual computers that operate on the information processing device 100 using the hardware resources of the information processing device 100.

[0054] The management information storage unit 130 stores data used for processing by the NFV infrastructure software 140. The management information storage unit 130 stores the management table 131 and the load history tables 132-1, 132-2, ... The management table 131 and the load history tables 132-1, 132-2, ... are created by the operation management unit 143.

[0055] Management table 131 contains information for managing the cryptographic processing devices 120, 120a, ... and the virtual devices embedded in each of the cryptographic processing devices 120, 120a, ... in the processor 101. Management table 131 includes information on the correspondence between cryptographic processing devices and the virtual devices available to those cryptographic processing devices. Management table 131 includes information on the correspondence between virtual devices and the virtual machines to which those virtual devices are assigned. Management table 131 includes information on the load statistics of each virtual device.

[0056] Load history tables 132-1, 132-2, ... are the history of the load monitored for virtual machines, cryptographic processing devices, and virtual devices. For example, one load history table is generated for one virtual machine, or one cryptographic processing device, or one virtual device. Load history tables 132-1, 132-2, ... are used to obtain load statistics for each virtual device.

[0057] The NFV infrastructure software 140 is software that implements NFV. The NFV infrastructure software 140 includes an OS 141, a hypervisor 142, and an operations management unit 143. OS141 is the basic software for the information processing device 100. OS141 is, for example, Linux (registered trademark).

[0058] Hypervisor 142 is virtual machine management software that implements virtual machines on the information processing device 100. Hypervisor 142 operates multiple virtual machines using the hardware resources of the information processing device 100. Hypervisor 142 is, for example, OPENSTACK®.

[0059] The operations management unit 143 is software for operations management that performs load balancing on each cryptographic processing device. The operations management unit 143 performs this load balancing based on the management table 131. The operations management unit 143 operates independently of the hypervisor 142. That is, the programs of the operations management unit 143 are executed by a processor such as the processor 101, independently of the hypervisor 142.

[0060] The Operations Management Unit 143 monitors the load on virtual machines, cryptographic processing devices, and virtual devices in order to distribute the load across each cryptographic processing device. The Operations Management Unit 143 records the monitored load in load history tables 132-1, 132-2, ... Based on the monitoring of the load, the Operations Management Unit 143 assigns virtual devices to virtual machines.

[0061] Virtual machines 150, 160, and 170 are examples of multiple virtual machines operating on the information processing device 100. Virtual machines 150, 160, and 170 relay packets on network 54. Next, an example of offloading encryption processing in the packet relay function of virtual machine 150 will be described. Virtual machines 160 and 170 will also be used to illustrate relay functions similar to those of virtual machine 150.

[0062] Figure 5 shows an example of offloading cryptographic processing in a virtual machine. Virtual machine 150 performs relay processing and cryptographic processing. Virtual machine 150 is assigned cores 110, 111, 112, 113, ... and LAN (Local Area Network) cards 107a, 107b, 107c, 107d, ... The LAN cards 107a, 107b, 107c, 107d, ... are examples of communication interfaces 107. Virtual machine 150 is also assigned virtual devices 121, 122, ...

[0063] Core 110 receives packets via LAN card 107a and relays them via LAN card 107b. At this time, Core 110 requests Core 111 to encrypt the received packets. Communication between Cores 110 and 111 is secured by a tunnel. Core 111 offloads the encryption processing to encryption processing device 120 via virtual device 121 and obtains the result of the encryption processing. Core 111 responds to Core 110 with the encrypted packets. Core 110 forwards the encrypted packets from LAN card 107b to the destination.

[0064] Core 112 receives packets via LAN card 107c and relays them to LAN card 107d. At this time, core 112 requests core 113 to encrypt the received packets. Communication between cores 112 and 113 is secured by a tunnel. Core 113 offloads the encryption processing to encryption processing device 120 via virtual device 122 and obtains the result of the encryption processing. Core 113 responds to core 112 with the encrypted packets. Core 112 forwards the encrypted packets from LAN card 107d to the destination.

[0065] In this way, virtual machine 150 is equipped with multiple sets of resources for relay processing and encryption processing. This allows virtual machine 150 to execute relay processing and encryption processing in parallel.

[0066] Figure 6 shows the first example of a management table. Management table 131 includes items for Processor, PF, VF, Enable, VM (Virtual Machine), and Throughput. The Processor item registers the processor's identification information. The PF item registers the cryptographic processing device's identification information. The VF item registers the virtual machine's identification information. The Enable item registers a flag indicating whether the virtual device can be assigned to the virtual machine. If it can be assigned, Enable is set to "1". If it cannot be assigned, Enable is set to "-" (hyphen). The VM item registers the identification information of the virtual machine assigned to the virtual device. For example, the Enable item for assigned and assignable virtual devices is set to "1". The Throughput item registers the virtual device's throughput. Throughput is the data transfer rate or data processing rate in the virtual device. Throughput is expressed in units of Gbps. The virtual device throughput is an example of a load indicator value that shows the load on the virtual device.

[0067] Figure 6 shows an example immediately after the correspondence between "Processor," "PF," and "VF" has been registered in the management table 131. The example in Figure 6 shows a case where there are 3 PFs on 1 CPU, and 1 PF can be divided into 3 VFs. In this case, the Enable, VM, and Throughput items in the management table 131 are not set.

[0068] For example, in management table 131, the processor "CPU-1" is associated with PFs "PF-1-1", "PF-1-2", and "PF-1-3". This indicates that the processor identified as "CPU-1" (e.g., processor 101) has three cryptographic processing devices identified as "PF-1-1", "PF-1-2", and "PF-1-3".

[0069] Furthermore, in management table 131, the PF "PF-1-1" is associated with the VFs "VF-1-1-1", "VF-1-1-2", and "VF-1-1-3". This indicates that the cryptographic processing device identified as "PF-1-1" has three virtual devices identified as "VF-1-1-1", "VF-1-1-2", and "VF-1-1-3" available for use.

[0070] According to the example in management table 131, the cryptographic processing device identified as "PF-1-2" has three virtual devices available, identified as "VF-1-2-1", "VF-1-2-2", and "VF-1-2-3". Similarly, the cryptographic processing device identified as "PF-1-3" has three virtual devices available, identified as "VF-1-3-1", "VF-1-3-2", and "VF-1-3-3".

[0071] Figure 7 shows a second example of the management table. In Figure 7, the management table 131 shows an example where, in addition to the settings in Figure 6, the virtual machine information is registered. In the example in Figure 7, the virtual machine's required performance (throughput) is 50 Gbps, and the maximum throughput per VF is 30 Gbps. In this case, 2 VFs will be allocated to the virtual machine. Since using multiple VFs from 1 PF (one cryptographic processing device) may result in performance degradation, one VF is used from each of the 2 PFs.

[0072] For example, in management table 131, Enable "1" and VM "VM1" are registered for VF "VF-1-1-2". This indicates that the virtual device identified as "VF-1-1-2" is assigned to the virtual machine identified as "VM1".

[0073] Furthermore, in management table 131, Enable "1" and VM "VM1" are registered for VF "VF-1-2-1". This indicates that the virtual device identified as "VF-1-2-1" is assigned to the virtual machine identified as "VM1".

[0074] Figure 8 shows a third example of the management table. In Figure 8, the management table 131 shows an example where, in addition to the settings in Figure 7, the throughput of a virtual device is registered. As mentioned above, throughput is an indicator of the load on a virtual device. For example, in the management table 131, Enable "1", VM "VM2", and throughput "15Gbps" are registered for VF "VF-1-1-1". Gbps is an abbreviation for Gigabits per second. This indicates that the virtual device identified as "VF-1-1-1" is assigned to the virtual machine identified as "VM2", and that the throughput of that virtual device is 15Gbps.

[0075] Furthermore, in management table 131, Enable "1", VM "VM1", and throughput "15Gbps" are registered for VF "VF-1-1-2". This indicates that the virtual device identified as "VF-1-1-2" is assigned to the virtual machine identified as "VM1", and that the throughput of that virtual device is 15Gbps.

[0076] Furthermore, in management table 131, Enable "1", VM "VM1", and throughput "30Gbps" are registered for VF "VF-1-2-1". This indicates that the virtual device identified as "VF-1-2-1" is assigned to the virtual machine identified as "VM1", and that the throughput of that virtual device is 30Gbps.

[0077] Furthermore, in management table 131, Enable "1", VM "VM2", and throughput "30Gbps" are registered for VF "VF-1-3-3". This indicates that the virtual device identified as "VF-1-3-3" is assigned to the virtual machine identified as "VM2", and that the throughput of that virtual device is 30Gbps.

[0078] For example, the operations management unit 143 can detect, based on the management table 131, that the load on the encryption processing device "PF-1-1" is high for the virtual machine "VM1", and that the virtual machine's required performance (50Gbps) is not being met. Specifically, the total throughput of the two virtual devices assigned to the virtual machine "VM1" is 15Gbps + 30Gbps, which is less than the required performance of 50Gbps. In this case, the operations management unit 143 can perform adjustments (load balancing) based on the management table 131, such as changing the underperforming virtual device (VF-1-1-2) to one derived from another encryption processing device, or increasing the number of virtual devices assigned to the virtual machine.

[0079] Figure 9 shows an example of a load history table. Load history table 132-1 shows the load history of a virtual machine identified as "VM1" as an example. The operations management unit 143 also monitors the load for other virtual machines, each cryptographic processing device (PF), and each virtual device (VF), and creates load history tables similar to load history table 132-1. Note that although load history table 132-1 in Figure 9 is an example of the load history for one day, it may also include the load history for each of multiple days.

[0080] Load history table 132-1 includes the following items: Time (hours), Load (%), Throughput (Gbps), Normalized (Load), Normalized (Throughput), Standardized (Load), and Standardized (Throughput). The Time item registers the time period. A time period is set by dividing a day into predetermined time lengths, such as 4 hours. For example, the time "0-3" indicates the time period from 0:00 to 3:59. The Load item registers the processor utilization rate of the virtual machine. The processor utilization rate of a virtual machine is the average value for the proportion of resources used out of the maximum amount of processor resources available to the virtual machine during the relevant time period. The Throughput item registers the throughput of the virtual machine. The throughput of a virtual machine is, for example, the average value for the amount of packets transferred per unit time during the relevant time period. The Normalized (Load) and Normalized (Throughput) items register the normalized values ​​of the Load item and the Throughput item, respectively. The "Standardized (Load)" and "Standardized (Throughput)" fields register the standardized values ​​of the load and throughput fields, respectively. Normalization and standardization of each value are performed for the load and throughput for the given day.

[0081] For example, load history table 132-1 contains a record with the following entries: Time "0-3", Load "0", Throughput "50", Normalized (Load) "-1.13", Normalized (Throughput) "0.65", Standardized (Load) "0.13", and Standardized (Throughput) "0.74". This record indicates that for the virtual machine "VM1", the load was 0% and the throughput was 50 Gbps during the period from 0:00 to 3:59. It also shows that the normalized load value for the period from 0:00 to 3:59 was -1.13, the normalized throughput value was 0.65, the standardized load value was 0.13, and the standardized throughput value was 0.74.

[0082] The load history table 132-1 similarly records the load history for other time periods such as "4-7" and "8-11". Furthermore, the operations management unit 143 can calculate the average value, standard deviation, and standard error of the load and throughput for the relevant day based on the load history table 132-1. For example, for load (processor utilization), the average value is 37.5%, the standard deviation is 33.13, and the standard error is 36.30. For throughput, the average value is 47.5 Gbps, the standard deviation is 3.82, and the standard error is 4.18.

[0083] For example, the operations management unit 143 calculates the throughput of each virtual device to be registered in the management table 131 based on the load history table of each virtual device. At this time, the operations management unit 143 identifies days when the load is relatively stable based on the load history tables of each virtual machine, each cryptographic processing device, and each virtual device, and calculates the throughput of that virtual device based on the load history table of that virtual device for that day. Possible methods for identifying days when the load is relatively stable include, for example, prioritizing the selection of days with small standard deviations in load or throughput. This prevents the throughput of a virtual device from being overestimated due to information from sudden high load conditions, and improves the accuracy of evaluating the throughput of that virtual device.

[0084] Furthermore, the operations management unit 143 may calculate the number of VFs (virtual devices) allocated from one PF (one cryptographic processing device) based on the evaluation values ​​of the maximum performance of one PF and one VM (one virtual machine) based on each load history table. For example, the operations management unit 143 may obtain the maximum performance (maximum throughput) such as a maximum of 50 Gbps per PF and a maximum of 30 Gbps per VF. The maximum performance per PF and the maximum performance per VF may be given to the operations management unit 143 in advance.

[0085] Furthermore, load history table 132-1 provides an example of data calculated by summarizing a particular day's data in 4-hour increments from hourly measurements of the load status and throughput of the virtual machine "VM1" over several days. The operations management unit 143 generates load history tables not only at the virtual machine level, but also at the cryptographic processing device (PF) level and virtual device (VF) level. For example, if the required performance of the virtual machine "VM1" is 50 Gbps, load history table 132-1 shows that the performance requirement is not met from 8:00 to 15:00. If this state of not meeting the performance requirement occurs for several days, it is not an outlier, and load adjustment is necessary. Based on the load history tables for each cryptographic processing device (PF) and virtual device (VF), the operations management unit 143 determines whether it is possible to change to other PFs and VFs.

[0086] The operations management unit 143 can acquire virtual devices that meet the performance requirements of the virtual machine from the cryptographic processing device and assign them to the virtual machine. The operations management unit 143 may also use the standard deviation to correct the number of virtual frames (VFs) allocated from 1 PF required by the virtual machine. The operations management unit 143 may also calculate the number of VFs allocated from 1 PF and the number of VFs used from the sampling evaluation value. Sampling may be performed at predetermined intervals, such as every hour. Furthermore, the data transfer rate may be used as the evaluation target for the load range.

[0087] Next, the processing procedure for the Operations Management Unit 143 will be explained. Figure 10 is a flowchart showing an example of acquiring PF and VF information. For example, the operations management unit 143 executes the process of acquiring PF and VF information when the information processing device 100 is started up.

[0088] (S10) The operations management unit 143 obtains the number of PFs, i.e., the number of cryptographic processing devices 120, 120a, ... from the processor 101.

[0089] (S11) The operations management unit 143 confirms the number of virtual devices (VFs) that can be enabled by 1PF, i.e., one cryptographic processing device. Specifically, the operations management unit 143 confirms with the processor 101 the number of virtual devices available for each of the cryptographic processing devices 120, 120a, ... The operations management unit 143 can obtain the information from steps S10 and S11 using a predetermined API (Application Programming Interface) of the cryptographic processing device (PF). For example, the operations management unit 143 can use the QAP-API as a predetermined API for the QAT device.

[0090] (S12) The operations management unit 143 registers the correspondence between PF (encryption processing device) and VF (virtual device) in the management table 131. The management table 131 in Figure 6 shows the state after registration in step S12. Then, the acquisition of PF and VF information is completed.

[0091] Figure 11 is a flowchart showing an example of VF assignment to a virtual machine. The operations management unit 143 can execute the VF assignment procedure shown below for each virtual machine.

[0092] (S20) The operations management unit 143 obtains a VF request. A VF request is a request to allocate a virtual device to a virtual machine. A VF request is made, for example, when the virtual machine is created. A VF request includes information indicating the performance (e.g., throughput) required by the virtual machine to the virtual device. The operations management unit 143 may obtain the VF request via the hypervisor 142. The operations management unit 143 stores the virtual machine's performance requirements in the management information storage unit 130.

[0093] (S21) The operations management unit 143 determines the VF (virtual device) in response to the VF request based on the management table 131.

[0094] (S22) The operations management unit 143 identifies the cryptographic processing device to which the determined virtual device belongs based on the management table 131, and sets up a VF (virtual device) on that cryptographic processing device via a predetermined API. As a result, for example, the operations management unit 143 activates the virtual device.

[0095] (S23) The operations management unit 143 assigns a VF (virtual device) to the virtual machine and starts the virtual machine. The operations management unit 143 may also start the virtual machine via the hypervisor 142.

[0096] (S24) The operations management unit 143 updates the management table 131 according to the assignment of VFs (virtual devices). For example, the operations management unit 143 registers the identification information of the virtual machine to which the virtual device is assigned for the relevant virtual device.

[0097] (S25) The operations management unit 143 obtains the load of the assigned virtual device. Based on the load of the virtual device, the operations management unit 143 changes the VF (virtual device) assigned to the virtual machine. Specifically, if the current virtual device does not meet the performance requirements of the virtual machine, the operations management unit 143 decides to change the virtual device to another virtual device on another cryptographic processing device. Then, the operations management unit 143 proceeds to step S21 and redoes the assignment of the virtual device to the virtual machine.

[0098] The Operations Management Unit 143 periodically monitors the load of the virtual devices assigned to the virtual machine until the virtual machine is shut down, and repeatedly reallocates the virtual devices according to the load. When the virtual machine is shut down, the Operations Management Unit 143 terminates the reallocation process for that virtual machine.

[0099] Figure 12 is a flowchart showing an example of load monitoring. The operations management unit 143 can perform the load monitoring process shown below periodically (for example, every hour).

[0100] (S30) The operations management unit 143 checks the load status of virtual machines, cryptographic processing devices, and virtual devices. At this time, virtual devices not assigned to a virtual machine are unused. Therefore, the operations management unit 143 only needs to obtain the load of virtual devices that have been assigned to a virtual machine.

[0101] (S31) The operations management unit 143 records the load status obtained for each virtual machine, cryptographic processing device, and virtual device in load history tables 132-1, 132-2, ...

[0102] (S32) The Operations Management Unit 143 calculates the load statistics of virtual devices using the standard deviation based on the load history tables 132-1, 132-2, ... For example, the Operations Management Unit 143 identifies the load history for a period in which a certain amount of load occurred periodically on the virtual device in question, based on the load history table of at least one of the virtual machine, cryptographic processing device, and virtual device. Then, the Operations Management Unit 143 calculates the load statistics of the virtual device in question from the load history for the identified period, based on the load history table of the virtual device in question. For example, the Operations Management Unit 143 may use the value obtained by adding a constant multiple of the standard deviation (e.g., 2 times) to the average throughput of the days belonging to the relevant period as the load (throughput) statistics of the virtual device in question. Details of the method for calculating the load statistics of virtual devices will be described later.

[0103] (S33) The operations management unit 143 updates the management table 131. Specifically, the operations management unit 143 registers the statistical values ​​of the virtual device load calculated in step S32 into the throughput column of the management table 131. Then the load monitoring process is completed.

[0104] Figure 13 is a flowchart showing an example of load balancing. The operations management unit 143 can periodically (for example, every hour) execute the load balancing process shown below for each virtual machine. For example, the load balancing process may be executed in step S25.

[0105] (S40) The Operations Management Department 143 refers to the management table 131 to check the statistics of the load (throughput) of the virtual devices assigned to the virtual machine in question.

[0106] (S41) The operations management unit 143 determines whether the throughput of the virtual device meets the required performance of the virtual machine. If the required performance is met, the process proceeds to step S44. If the required performance is not met, the process proceeds to step S42. The operations management unit 143 may use the required performance specified in the VF request for the virtual machine as the required performance (throughput) of the virtual machine. Alternatively, the operations management unit 143 may update the required performance of the virtual machine to a value that reflects actual performance (for example, the average throughput on a day when a standard load occurred for the virtual machine) based on the load history table of the virtual machine. If multiple virtual devices are assigned to a virtual machine, the required performance of the virtual machine will be met if the total throughput of the multiple virtual devices is equal to or greater than the required performance of the virtual machine.

[0107] (S42) The operations management unit 143 determines, based on the management table 131, whether improvement can be expected by changing a VF (virtual device) to another PF (encryption processing device) or by changing the number of VFs. If improvement can be expected, the process proceeds to step S43. If improvement cannot be expected, the process proceeds to step S44.

[0108] (S43) The operations management unit 143 modifies the VF (virtual device) and changes the management table 131. For example, the operations management unit 143 assigns a new virtual device for a different cryptographic processing device to the virtual machine in question to meet the performance requirements. At this time, the operations management unit 143 may either release the original virtual device that was assigned to the virtual machine from the original cryptographic processing device, or it may maintain the original virtual device assignment to the virtual machine while adding a new virtual device. Then the load balancing process is completed.

[0109] (S44) The operations management unit 143 does not change the VF (virtual device) and does not change the management table 131. Then the load balancing process is completed.

[0110] Next, a specific example of the processing sequence of the information processing device 100 will be explained. Figure 14 is a sequence diagram showing an example of acquiring PF and VF information. For example, the operation management unit 143 executes the process of acquiring PF and VF information when the information processing device 100 is started up. In the following, a QAT device is assumed as an example of an encryption processing device. The information processing device 100 has a QAT-API 180 for acquiring information from the QAT device. Note that the virtual machine 150 has not been created when the information processing device 100 is started up and is not involved in the process of acquiring PF and VF information.

[0111] (ST10) The operations management unit 143 queries the processor 101 for the number of available PFs - VFs via the QAT-API 180.

[0112] (ST11) The operations management unit 143 receives a response from the processor 101 via the QAT-API 180, which is the number of PFs and the number of VFs.

[0113] (ST12) The operations management unit 143 registers the correspondence between PF and VF in the management table 131. Then, the process of acquiring information on PF and VF is completed.

[0114] Figure 15 is a sequence diagram showing an example of VF assignment to a virtual machine. While virtual machine 150 is primarily used as an example below, the sequence is similar for other virtual machines.

[0115] (ST20) The Operations Management Unit 143 determines the PF (encryption processing device) and VF (virtual device) to be used when creating the virtual machine 150, according to the performance requirements of the virtual machine 150.

[0116] (ST21) The operations management unit 143 configures the PF and VF to be used on the processor 101 via the QAT-API 180.

[0117] (ST22) The operations management unit 143 assigns the configured VF to the virtual machine 150. The operations management unit 143 starts the virtual machine 150 via the hypervisor 142.

[0118] (ST23) The operations management unit 143 updates the management table 131 according to the VF assignment in step ST22.

[0119] (ST24) The Operations Management Unit 143 begins monitoring the load on virtual machine 150 and the VF assigned to virtual machine 150, and begins updating the load history table 132-1 corresponding to virtual machine 150 and the load history table corresponding to the VF. Then, the VF assignment process is completed.

[0120] Figure 16 is a sequence diagram showing an example of load monitoring. The operations management unit 143 periodically executes load monitoring processing (for example, every hour). The following examples mainly use virtual machine 150, but the sequence is similar for other virtual machines.

[0121] (ST30) The operations management unit 143 collects the performance of the PF (cryptographic processing device) and VF (virtual device) via QAT-APT180.

[0122] (ST31) Operations Management Unit 143 collects performance data for virtual machine 150.

[0123] (ST32) The operations management unit 143 stores the collected performance information (e.g., processor utilization and throughput) in the load history tables 132-1,.... The operations management unit 143 also calculates load statistics for each virtual device based on the load history tables 132-1,... and stores them in the management table 131. Then the load monitoring process is completed.

[0124] Next, we will explain a specific example of assigning virtual devices to virtual machines. Figure 17 illustrates the addition of virtual machines on a single host. A single host represents one information processing unit 100. The information processing unit 100 is assumed to have three cryptographic processing devices (PFs). The three cryptographic processing devices of the information processing unit 100 are identified as PF-x, PF-y, and PF-z. Three virtual devices are assumed to be available for each of the cryptographic processing devices "PF-x", "PF-y", and "PF-z". In cryptographic processing device "PF-x", the virtual device "VF-a" is in use. In cryptographic processing device "PF-y", the virtual devices "VF-c" and "VF-d" are in use. In cryptographic processing device "PF-z", the virtual device "VF-e" is in use. In cryptographic processing device "PF-z", the virtual device "VF-a'" is already allocated to the standby VM.

[0125] The assignment relationships of virtual devices to virtual machines are as follows: For example, in the information processing device 100, virtual device "VF-a" is assigned to virtual machine "VM1". Virtual device "VF-c" is assigned to virtual machine "VM2". Virtual device "VF-d" is assigned to virtual machine "VM3". Virtual device "VF-e" is assigned to virtual machine "VM4". Furthermore, virtual device "VF-a'" is assigned to virtual machine "VM1'", which is a standby virtual machine for virtual machine "VM1". For example, virtual machine "VM1'" is a standby VM for virtual machine "VM1" via cold standby.

[0126] The remaining capacity of cryptographic processing device "PF-x" is p. The remaining capacity of cryptographic processing device "PF-y" is q. The remaining capacity of cryptographic processing device "PF-z" is r. The remaining capacity is, for example, the maximum performance (maximum throughput) of the cryptographic processing device minus the throughput used by the virtual device. In this example, we assume p > r > q. In the single-host configuration described above, consider the case where we add a new virtual machine "VM5" and a virtual device "VF-b" to be assigned to virtual machine "VM5".

[0127] Figure 18 shows the first example of VF allocation when adding a virtual machine. The PF-x allowable load, PF-y allowable load, and PF-z allowable load correspond to the maximum performance of the cryptographic processing devices "PF-x", "PF-y", and "PF-z". The VF-a load range is the throughput used by the virtual device "VF-a" from the PF-x allowable load.

[0128] The VF-c load range represents the throughput used by the virtual device "VF-c" out of the PF-y allowable load. The VF-d load range represents the throughput used by the virtual device "VF-d" out of the PF-y allowable load.

[0129] The VF-e load range represents the throughput already used by the virtual device "VF-e" within the PF-z allowable load. The VF-a' load range represents the throughput reserved by the virtual device "VF-a'" within the PF-z allowable load. The VF-a' load range can be considered a provisional load range for redundancy for the virtual device "VF-a".

[0130] The load range of a virtual device assigned to a virtual machine corresponds to the load statistics calculated based on the load history table of that virtual device. The VF-b load range is the expected load range (throughput) for the newly added virtual device "VF-b". The expected load range for the newly added virtual device is specified to the operations management unit 143 by a VF request, according to the specifications of the virtual machine "VM5".

[0131] For example, the VF-b load range is smaller than the available capacity p. The VF-b load range is larger than the available capacity q. The VF-b load range is smaller than the available capacity r. Therefore, the operations management unit 143 excludes the cryptographic processing device "PF-y" from the list of candidates to add to the virtual device "VF-b".

[0132] Furthermore, as mentioned above, the available capacity p is greater than the available capacity r. Therefore, the operations management unit 143 prioritizes selecting the encryption processing device "PF-x" over the encryption processing device "PF-z". The operations management unit 143 then configures the virtual device "VF-b" on the selected encryption processing device "PF-x" and assigns it to the virtual machine "VM5". In this way, the operations management unit 143 can equalize the load on each cryptographic processing device.

[0133] Figure 19 shows a second example of VF allocation when adding a virtual machine. In this second example, the expected VF-b load range is larger than the available capacity p, q, and r, which is different from the first example in Figure 18. In this case, the operations management unit 143 may divide the virtual device "VF-b" among multiple cryptographic processing devices rather than assigning it to a single cryptographic processing device. For example, if it is divided among two cryptographic processing devices, the operations management unit 143 selects two cryptographic processing devices with larger available capacity and assigns one virtual device each from these two cryptographic processing devices "PF-x" and "PF-z" to the virtual machine "VM5". The operations management unit 143 can also assign one virtual device each from three or more cryptographic processing devices to the virtual machine.

[0134] Thus, if the operations management unit 143 cannot meet the performance requirements of a virtual machine by simply allocating a virtual device from a single cryptographic processing device, it can also allocate a virtual device to the virtual machine from multiple cryptographic processing devices. In this case, the operations management unit 143 can prioritize selecting cryptographic processing devices with more available capacity, i.e., those with lower loads, and allocate virtual devices from those cryptographic processing devices, thereby leveling the load on each cryptographic processing device.

[0135] While Figures 18 and 19 illustrate examples of assigning virtual devices to a new virtual machine, the operations management unit 143 can also perform virtual device reallocation to existing virtual machines using the same method shown in Figures 18 and 19.

[0136] Figure 20 shows an example of the load range of a virtual device. Based on the load history table of the virtual device "VF-a", the operation management unit 143 calculates, for example, the average throughput μ1 and the standard deviation of throughput σ1 on days when load fluctuations are relatively small. Then, the operation management unit 143 calculates, for example, μ1 + 2σ1 (Gbps) as a statistical value of the load (throughput) and registers it in the management table 131. 0 to μ1 + 2σ1 corresponds to the load range of VF-a.

[0137] Similarly, the operations management unit 143 calculates the average throughput μ2 and the standard deviation of throughput σ2 on days with relatively small load fluctuations, based on the load history table of the virtual device "VF-b". Then, the operations management unit 143 calculates, for example, μ2 + 2σ2 (Gbps) as a statistical value of the load (throughput) and registers it in the management table 131. 0 to μ2 + 2σ2 corresponds to the load range of VF-b. In this case, for example, {(μ1 + 2σ1) + (μ2 + 2σ2)} (Gbps) is the throughput used by the encryption processing device "PF-x". Also, if the allowable load of PF-x is 100 (Gbps), then 100 - {(μ1 + 2σ1) + (μ2 + 2σ2)} (Gbps) corresponds to the remaining capacity p.

[0138] In this way, the operations management unit 143 can appropriately estimate the load of each virtual device by calculating the statistical value of the load of each virtual device using the standard deviation, taking into account statistical load fluctuations. As a result, the operations management unit 143 can appropriately distribute the load of each cryptographic processing device.

[0139] Figure 21 illustrates the addition of virtual machines to a redundant host. For example, an information processing system can be realized with information processing device 100 as the primary and information processing device 100a as the secondary. In this case, information processing devices 100 and 100a are connected to each other via a network or a dedicated interface.

[0140] For example, let's assume that information processing devices 100 and 100a each have one cryptographic processing device (PF). The cryptographic processing device in information processing device 100 is identified by PF-x. The cryptographic processing device in information processing device 100a is identified by PF-x'.

[0141] Assume that three virtual devices are available for each of the cryptographic processing devices "PF-x" and "PF-x'". In cryptographic processing device "PF-x", virtual devices "VF-a" and "VF-c" are used. In cryptographic processing device "PF-x'", virtual devices "VF-d" and "VF-e" are used.

[0142] The assignment relationship of virtual devices to virtual machines is as follows: For example, virtual device "VF-a" is assigned to virtual machine "VM1" on the information processing device 100. Virtual device "VF-c" is assigned to virtual machine "VM2" on the information processing device 100.

[0143] Furthermore, the virtual device "VF-d" is assigned to the virtual machine "VM3" on the information processing device 100a. The virtual device "VF-e" is assigned to the virtual machine "VM4" on the information processing device 100a. Note that the remaining capacity of the cryptographic processing device "PF-x'" is p.

[0144] In this redundant host configuration, the operations management unit 143 shares the load of virtual machines, cryptographic processing devices, and virtual devices on the information processing device 100 with the information processing device 100a. The information processing device 100a also has an operations management unit equivalent to the operations management unit 143. The operations management unit of the information processing device 100a shares the load of virtual machines, cryptographic processing devices, and virtual devices on the information processing device 100a with the information processing device 100.

[0145] For example, if the primary information processing device 100 stops, at least some of the virtual machines on the information processing device 100 are moved to the information processing device 100a. For example, the virtual machine "VM1'" corresponding to the virtual machine "VM1" on the information processing device 100 is automatically deployed to the information processing device 100a. In this case, the operation management unit of the information processing device 100a newly assigns the virtual device "VF-a'" to the virtual machine "VM1'".

[0146] Figure 22 shows a third example of VF allocation when adding a virtual machine. The available capacity p of the cryptographic processing device "PF-x'" is the value obtained by subtracting the VF-e load range and VF-d load range from the allowable load of PF-x'. The expected load (throughput) of the virtual device "VF-a'" is smaller than the available capacity p of the cryptographic processing device "PF-x'". Therefore, it is possible to allocate the virtual device "VF-a'" to the virtual machine "VM1'".

[0147] For example, the expected load (throughput) of the virtual device "VF-a'" may be greater than the available capacity p of the cryptographic processing device "PF-x'". In that case, the information processing device 100a may allocate the virtual device from other cryptographic processing devices provided by the information processing device 100a. Alternatively, the information processing device 100a may reduce the burden on each cryptographic processing device by allocating one virtual device each from the cryptographic processing device "PF-x'" and the other cryptographic processing devices to the virtual machine "VM1'".

[0148] Next, we will explain the comparative examples. Figure 23 shows a comparative example. The comparative example information processing device 200 has an acceleration card 210, a resource pool 220, and a virtual machine 230. Although not shown in the figure, the information processing device 200 has hardware similar to that of the information processing device 100, such as a processor and RAM.

[0149] The acceleration card 210 is an external PCI card to the processor. For example, an example of an acceleration card 210 is Intel's QuickAssist adapter 8970. The acceleration card 210 has three cryptographic processing devices 211, 212, and 213. Here, the number of cryptographic processing devices in existing acceleration cards 210, such as the QuickAssist adapter 8970, is fixed at, for example, three.

[0150] The resource pool 220 is data managed by the hypervisor of the information processing device 200. The resource pool 220 contains information about virtual devices in each of the cryptographic processing devices 211, 212, and 213.

[0151] For example, resource pool 220 includes information indicating that cryptographic processing device 211 (identifier "b0:00.0") has virtual devices with identifiers "b0:01.0", "b0:01.1", ..., "b0:01.3". Resource pool 220 includes information indicating that cryptographic processing device 212 (identifier "b1:00.0") has virtual devices with identifiers "b1:01.0", "b1:01.1", ..., "b1:01.3". Resource pool 220 includes information indicating that cryptographic processing device 213 (identifier "b2:00.0") has virtual devices with identifiers "b2:01.0", "b2:01.1", ..., "b2:01.3". The correspondence between the identifiers of cryptographic processing devices 211, 212, and 213 and the identifiers of each virtual device is fixed in advance and immutable.

[0152] The correspondence between the identifiers of virtual devices used by virtual machine 230 and the identifiers of virtual devices managed by resource pool 220 is fixed and immutable. Specifically, the identifiers of virtual devices in resource pool 220, "b0:01.0", "b0:01.1", ..., "b0:01.3", correspond to the identifiers on the virtual machine 230 side, "00:0b.0", "00:0a.0", ..., "00:08.0", respectively. The identifiers of virtual devices in resource pool 220, "b1:01.0", "b1:01.1", ..., "b1:01.3", correspond to the identifiers on the virtual machine 230 side, "00:0f.0", "00:0e.0", ..., "00:0c.0", respectively. The virtual device identifiers "b2:01.0", "b2:01.1", ..., and "b2:01.3" in resource pool 220 correspond to the identifiers "01:04.0", "01:03.0", ..., and "01:01.0" on the virtual machine 230 side, respectively. In this way, the information processing device 200 was able to manage the virtual devices (VFs) in resource pool 220 while maintaining their origin.

[0153] For example, suppose the performance requirements for virtual machine 230 dictate that it needs 6 VFs (i.e., 6 virtual devices). If there are 3 PFs (i.e., 3 cryptographic processing devices), allocating 2 VFs from each PF to virtual machine 230 avoids concentrating the load on any particular PF. In this case, since the origin of each virtual device is known in advance, it is easy to allocate one virtual device from the same cryptographic processing device to, for example, two cores that perform cryptographic processing in parallel. For example, suppose that among the 6 cores c1 to c6 of virtual machine 230, the pairs of cores c1 and c2, cores c3 and c4, and cores c5 and c6 each perform cryptographic processing in parallel.

[0154] In this case, for example, virtual machine 230 uses the virtual devices with identifiers "00:0b.0" and "00:0a.0" for cores c1 and c2, respectively. Furthermore, virtual machine 230 uses the virtual devices with identifiers "00:0f.0" and "00:0e.0" for cores c3 and c4, respectively. Additionally, virtual machine 230 uses the virtual devices with identifiers "00:04.0" and "00:03.0" for cores c5 and c6, respectively. In this way, the information processing device 200 can easily determine from the virtual machine which of the cryptographic processing devices 211, 212, and 213 to use, based on a fixed pattern between the cryptographic processing devices and virtual devices. Therefore, the development of applications such as virtual machines was minimized when selecting which virtual devices to use.

[0155] However, in recent years, cryptographic processing devices have been built into processors such as CPUs. The number of built-in cryptographic processing devices varies depending on the CPU type. For example, with QAT devices, the number of virtual devices (QAT virtual devices) that can be created from one QAT device remains constant. Also, for example, the number of QAT devices varies from 0 to 4 depending on the CPU model.

[0156] Therefore, it is necessary to know the number of cryptographic processing devices (e.g., QAT devices) built into each processor (e.g., CPU) installed in a computer such as the information processing device 100, and to perform communication control by applying a uniform load to the installed cryptographic processing devices.

[0157] Therefore, the information processing device 100 is equipped with NFV infrastructure software 140 having an operation management unit 143. The operation management unit 143 manages the load status of the cryptographic processing devices (PF) and virtual devices (VF) used by virtual machines. The operation management unit 143 creates a database of the usage status of the cryptographic processing devices (PF) and virtual devices (VF) of virtual machines. Based on this database, the operation management unit 143 determines which virtual devices (VF) to assign to virtual machines. Furthermore, in situations where the number of virtual devices (VF) requested by each virtual machine is different, the operation management unit 143 determines which virtual devices (VF) to assign when another virtual machine is started, in accordance with the load status of the cryptographic processing devices (PF) that changes when a virtual machine is stopped. This enables the information processing device 100 to distribute the load across multiple cryptographic processing devices built into the processor.

[0158] As explained above, the information processing device 100 performs, for example, the following processes. The processes of the operation management unit 143 described below can be interpreted as processes performed by the processor 101 or other processors provided by the information processing device 100.

[0159] The operations management unit 143 obtains information from the processor 101 about multiple cryptographic processing devices, which are built into the processor 101 and serve as offload destinations for cryptographic processing, as well as information about multiple virtual devices available on those cryptographic processing devices. Based on the information obtained from the processor 101, the operations management unit 143 generates correspondence information showing the correspondence between the multiple cryptographic processing devices and the multiple virtual devices. The operations management unit 143 monitors the load of the first virtual device to which the first application is assigned among the multiple virtual devices. The operations management unit 143 records the load of the first virtual device in the load information showing the load of each of the multiple virtual devices. In response to a request to assign a virtual device to the second application, the operations management unit 143 selects a second virtual device to assign to the second application based on the correspondence information and load information. The operations management unit 143 assigns the second virtual device to the second application. This enables the information processing device 100 to distribute the load across the multiple cryptographic processing devices built into the processor.

[0160] The information in management table 131 showing the correspondence between cryptographic processing devices (PF) and virtual devices (VF) is an example of the correspondence information described above. As illustrated in management table 131, the correspondence information may also include information showing the correspondence between a virtual device and the virtual machine to which that virtual device is assigned. In addition, the throughput of each virtual device in management table 131 is an example of the load information described above. Furthermore, if there are two or more unassigned virtual devices in the cryptographic processing device that is the source of the virtual device assignment, the operation management unit 143 may select any of these two or more virtual devices, for example randomly, and assign them to the application.

[0161] For example, when selecting a second virtual device, the operations management unit 143 prioritizes selecting a virtual device belonging to a cryptographic processing device with a low load among multiple cryptographic processing devices as the second virtual device. This allows the information processing device 100 to prevent excessive load on a specific cryptographic processing device and to equalize the load across multiple cryptographic processing devices.

[0162] Furthermore, a virtual device allocation request may include the required performance for the virtual device. When selecting a second virtual device, the operations management unit 143 may select a cryptographic processing device from among multiple cryptographic processing devices that can meet the required performance based on the required performance, load information, and the upper limit of the load allowed for each of the multiple cryptographic processing devices. The operations management unit 143 may then select a second virtual device belonging to the selected cryptographic processing device. This allows the information processing device 100 to prevent excessive load on a specific cryptographic processing device and to equalize the load on multiple cryptographic processing devices. In addition, the information processing device 100 can appropriately meet the required performance of the second application for the virtual device and prevent processing delays of the second application.

[0163] The required performance, the load on each virtual device, and the upper limit of the load that can be tolerated by the cryptographic processing device are expressed, for example, in throughput (Gbps). The sum of the loads of each virtual device belonging to a given cryptographic processing device corresponds to the load of that cryptographic processing device. If the value obtained by subtracting the load of that cryptographic processing device from the upper limit of the allowable load is equal to or greater than the required performance, then that cryptographic processing device can meet the required performance.

[0164] If there is no single cryptographic processing device capable of meeting the performance requirements of the second application, the operations management unit 143 may select one second virtual device from two or more cryptographic processing devices. The operations management unit 143 may then assign the two or more selected second virtual devices to the second application. This allows the information processing device 100 to prevent excessive load on a specific cryptographic processing device and to equalize the load on multiple cryptographic processing devices. Furthermore, the information processing device 100 can appropriately meet the performance requirements of the second application for the virtual devices and prevent processing delays in the second application. The number of two or more cryptographic processing devices from which the second virtual device will be assigned may be predetermined. The operations management unit 143 may select cryptographic processing devices from which the second virtual device will be assigned, prioritizing those with lower loads, until that number is reached. Alternatively, the operations management unit 143 may select from among multiple cryptographic processing devices those with loads lower than a standard value as the two or more cryptographic processing devices from which the second virtual device will be assigned.

[0165] The operations management unit 143 may determine, based on load information, whether the first virtual device meets the performance requirements of the first application. If the first virtual device does not meet the performance requirements, the operations management unit 143 may, based on correspondence information, select a third virtual device belonging to a second cryptographic processing device different from the first cryptographic processing device that assigned the first virtual device. The operations management unit 143 may then assign the third virtual device to the first application. This allows the information processing device 100 to appropriately meet the performance requirements of the first application, which has already been assigned a virtual device and is in operation, thereby preventing processing delays in the first application.

[0166] The operations management unit 143 may, when selecting the third virtual device, prioritize selecting the cryptographic processing device with the lowest load among multiple cryptographic processing devices as the second cryptographic processing device. This allows the information processing device 100 to prevent excessive load on a specific cryptographic processing device and to equalize the load across multiple cryptographic processing devices.

[0167] In selecting the third virtual device, the operations management unit 143 may select a cryptographic processing device from among multiple cryptographic processing devices that can meet the required performance based on the required performance and load information of the first application and the upper limit of the load that can be allowed for each of the multiple cryptographic processing devices. The operations management unit 143 may also select a third virtual device belonging to the selected cryptographic processing device (second cryptographic processing device). This allows the information processing device 100 to prevent excessive load on a particular cryptographic processing device and to equalize the load on multiple cryptographic processing devices. Furthermore, the information processing device 100 can appropriately meet the required performance of the first application for the virtual device and prevent processing delays of the first application.

[0168] If there is no single cryptographic processing device capable of meeting the performance requirements of the first application, the operations management unit 143 may select one third virtual device from two or more cryptographic processing devices. The operations management unit 143 may then assign the two or more selected third virtual devices to the first application. This allows the information processing device 100 to prevent excessive load on a specific cryptographic processing device and to equalize the load on multiple cryptographic processing devices. Furthermore, the information processing device 100 can appropriately meet the performance requirements of the first application for the virtual devices and prevent processing delays in the first application. The number of two or more cryptographic processing devices from which the third virtual devices will be assigned may be predetermined. The operations management unit 143 may select cryptographic processing devices from which the third virtual devices will be assigned, prioritizing those with lower loads, until that number is reached. Alternatively, the operations management unit 143 may select two or more cryptographic processing devices from which the third virtual devices will be assigned, based on the load of multiple cryptographic processing devices that are lower than a certain threshold.

[0169] The operations management unit 143 may, after allocating the third virtual device to the first application, release the allocation of the first virtual device to the first application. For example, if the operations management unit 143 can meet the performance requirements of the first application using only the third virtual device, it may release the allocation of the first virtual device to the first application. This allows the information processing device 100 to reduce the load on the first cryptographic processing device, which is the source of the allocation of the first virtual device. In addition, the information processing device 100 can prepare to allocate the resources equivalent to the first virtual device of the first cryptographic processing device to other applications.

[0170] As illustrated in the second embodiment, each of the first and second applications may be a virtual machine running on a computer. For example, the information processing device 100 is suitable for NFV-based systems where there are many opportunities to offload cryptographic processing to the processor. For example, the information processing device 100 can reduce the delay of packet forwarding processing in an NFV-based system. The first and second applications may also be containers implemented by container-type virtualization software.

[0171] Furthermore, the functions of the operations management unit 143 can be realized by a processor such as the processor 101 executing a load balancing program stored in the RAM 102. The load balancing program may be a program executed by a computer such as the information processing unit 100, separate from the hypervisor 142 that runs the virtual machines. This allows the information processing unit 100 to use existing virtual machine management software as the hypervisor 142, and the functions of the operations management unit 143 can be used without depending on the virtual machine management software. Therefore, the possibility of using the functions of the operations management unit 143 in various information processing systems that operate virtual machines is increased.

[0172] The information processing in the first embodiment can be achieved by having the processing unit 12 execute a program. The information processing in the second embodiment can be achieved by having the processor 101 or another processor in the information processing device 100 execute a program. The program can be recorded on a computer-readable recording medium 53.

[0173] For example, a program can be distributed by distributing a recording medium 53 on which the program is stored. Alternatively, the program may be stored on another computer and distributed via a network. A computer may, for example, store (install) a program stored on the recording medium 53 or a program received from another computer into a storage device such as RAM 102 or HDD 103, and then read and execute the program from that storage device. [Explanation of symbols]

[0174] 10 Information Processing Devices 11 Storage section 11a Compatibility Information 11b Load information 12 Processing Units 20 processors 21,22 processor cores 23,24 Cryptographic processing devices 31,32 Virtual Devices 41, 42, 43 Applications

Claims

1. On the computer, Information on multiple cryptographic processing devices, which are built into the processor and serve as offload destinations for cryptographic processing, and information on multiple virtual devices available to the multiple cryptographic processing devices, is obtained from the processor. Based on the information obtained from the processor, correspondence information is generated that shows the correspondence between the plurality of cryptographic processing devices and the plurality of virtual devices. The load of the first virtual device to which the first application is assigned is monitored among the plurality of virtual devices, and the load of the first virtual device is recorded in the load information indicating the load of each of the plurality of virtual devices. In response to a request to allocate a virtual device to a second application, a second virtual device is selected to be allocated to the second application based on the correspondence information and load information, and the second virtual device is allocated to the second application. A load balancing program that executes processing tasks.

2. In selecting the second virtual device, the virtual device belonging to the cryptographic processing device with the lowest load among the multiple cryptographic processing devices is preferentially selected as the second virtual device. The load balancing program according to claim 1.

3. In selecting the second virtual device, based on the required performance included in the allocation request, the load information, and the upper limit of the load allowed for each of the multiple cryptographic processing devices, an cryptographic processing device capable of satisfying the required performance is selected from among the multiple cryptographic processing devices, and the second virtual device belonging to the selected cryptographic processing device is selected. The load balancing program according to claim 1.

4. If there is no cryptographic processing device capable of meeting the required performance, select one second virtual device from each of the two or more cryptographic processing devices, and assign the two or more selected second virtual devices to the second application. The load balancing program according to claim 3.

5. Based on the load information, it is determined whether the first virtual device meets the performance requirements of the first application. If the first virtual device does not meet the required performance, a third virtual device belonging to a second cryptographic processing device different from the first cryptographic processing device that assigned the first virtual device is selected based on the correspondence information, and the third virtual device is assigned to the first application. The load balancing program according to claim 1.

6. When selecting the third virtual device, the cryptographic processing device with the lowest load among the multiple cryptographic processing devices is preferentially selected as the second cryptographic processing device. The load balancing program according to claim 5.

7. After assigning the third virtual device to the first application, the assignment of the first virtual device to the first application is released. The load balancing program according to claim 5.

8. Each of the first application and the second application is a virtual machine running on the computer. The load balancing program according to claim 1.

9. The load balancing program is a program that runs on the computer separately from the hypervisor that operates the virtual machines. The load balancing program according to claim 8.

10. Computers Information on multiple cryptographic processing devices, which are built into the processor and serve as offload destinations for cryptographic processing, and information on multiple virtual devices available to the multiple cryptographic processing devices, is obtained from the processor. Based on the information obtained from the processor, correspondence information is generated that shows the correspondence between the plurality of cryptographic processing devices and the plurality of virtual devices. The load of the first virtual device to which the first application is assigned is monitored among the plurality of virtual devices, and the load of the first virtual device is recorded in the load information indicating the load of each of the plurality of virtual devices. In response to a request to allocate a virtual device to a second application, a second virtual device is selected to be allocated to the second application based on the correspondence information and load information, and the second virtual device is allocated to the second application. Load balancing method.

11. Memory unit and, A processing unit that obtains information from the processor about multiple cryptographic processing devices that are built into the processor and are destinations for offloading cryptographic processing, and multiple virtual devices that can be used by the multiple cryptographic processing devices, generates correspondence information showing the correspondence between the multiple cryptographic processing devices and the multiple virtual devices based on the information obtained from the processor and stores it in the storage unit, monitors the load of the first virtual device to which the first application is assigned among the multiple virtual devices, shows the load of each of the multiple virtual devices, records the load of the first virtual device in the load information stored in the storage unit, and in response to a request to assign a virtual device to the second application, selects a second virtual device to assign to the second application based on the correspondence information and load information stored in the storage unit, and assigns the second virtual device to the second application, An information processing device having