Transparent encryption and decryption computing system based on heterogeneous computing, and method, device and medium
By introducing heterogeneous computing units into the transparent encryption and decryption system, and using heterogeneous computing programs to perform encryption and decryption processing between the kernel layer and the user layer, the performance overhead and security risks caused by frequent switching and data transmission in existing systems are solved, and efficient and secure transparent encryption and decryption are achieved.
Patent Information
- Application Number
- PCT/CN2024/122113
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-05
- Filing Date
- 2024-09-29
- Publication Date
- 2025-06-12
AI Technical Summary
The existing transparent encryption and decryption system frequently switches and data transmission between the kernel layer and the user layer, resulting in increased performance overhead, and there are data security risks due to running in the user state.
A transparent encryption and decryption computing system based on heterogeneous computing is adopted. By deploying transparent file systems and middleware at the kernel layer, heterogeneous computing programs are deployed at the user layer, and encrypting and decrypting processing is used to avoid frequent copying and switching of data.
It improves the efficiency of transparent encryption and decryption, reduces system performance overhead, and enhances data security, avoids security risks caused by data copying to the user layer.
Smart Images

Figure CN2024122113_12062025_PF_FP_ABST
Abstract
Description
Transparent encryption and decryption computing system, method, device and medium based on heterogeneous computing
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on December 5, 2023, with application number 2023116569011 and application name “Transparent encryption and decryption computing system, method, device and medium based on heterogeneous computing”, all contents of which are incorporated by reference into this application. Technical Field
[0003] The embodiments of the present application relate to the technical field of transparent encryption and decryption, and specifically, to a transparent encryption and decryption computing system, method, device, and non-volatile readable storage medium and electronic device based on heterogeneous computing. Background Art
[0004] With the increasing emphasis on data security and the increase in computing needs, transparent encryption and decryption have become key technologies for protecting corporate electronic documents.
[0005] In order to improve the efficiency of transparent encryption and decryption, a transparent encryption and decryption scheme based on hardware acceleration is proposed; optionally, as shown in Figure 1: Fuse (Filesystem in Userspace) transparent file system runs in user space, so it can be used on different operating systems and platforms with good portability and flexibility.
[0006] The Fuse transparent file system includes a kernel module and . / fuse / mnt (mount, directory) where the Fuse transparent file system is mounted. Furthermore, an interface device, / dev (device) / fuse, is registered. This interface block device serves as a bridge for communication between . / fuse / mnt and the kernel. . / fuse / mnt reads file requests through / dev / fuse, processes them, and writes the reply to / dev / fuse. The reply then returns to the kernel layer through / dev / fuse, from which it is returned to the user or stored on a storage device.
[0007] During this encryption and decryption process, the Fuse transparent file system requires frequent switching and data transmission between the kernel layer and the user layer, which introduces additional performance overhead. Moreover, since the Fuse transparent file system runs in user mode, its code is executed in an environment with a lower privilege level of the operating system. This may lead to data security risks due to attacks or exploitation by malicious users.
[0008] Summary of the Invention
[0009] In view of the above problems, a transparent encryption and decryption computing system, method, device, and medium based on heterogeneous computing are proposed to overcome or at least partially solve the above problems, including:
[0010] A transparent encryption and decryption computing system based on heterogeneous computing, comprising an operating system and a heterogeneous computing unit, wherein the operating system comprises a transparent file system and middleware deployed at the kernel layer, and a heterogeneous computing program deployed at the user layer;
[0011] The transparent file system is configured to respond to a data operation request from a user layer of the operating system, send first data corresponding to the data operation request to the middleware, receive encrypted and decrypted second data corresponding to the first data returned by the middleware, and forward the second data according to the data operation request;
[0012] The middleware is provided with a memory unit; the middleware is configured to store the first data in the memory unit and send a memory address of the first data in the memory unit to the heterogeneous computing program;
[0013] The heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data.
[0014] Optionally, the data operation request is a request to write data into a storage device of the transparent encryption and decryption computing system, and the data operation request includes first data, where the first data is data to be encrypted, and the second data is encrypted data;
[0015] The transparent encryption and decryption computing system also includes:
[0016] A virtual file system is provided in the kernel layer of the operating system; the virtual file system is configured to receive data operation requests from the user layer of the operating system and send the data operation requests to the transparent file system;
[0017] The underlying file system is set in the kernel layer of the operating system; the underlying file system is configured to receive the second data forwarded by the transparent file system and write the second data into the storage device.
[0018] Optionally, the data operation request is a request to read data from a storage device of the transparent encryption and decryption computing system, the first data is data to be decrypted, and the second data is decrypted data;
[0019] The transparent encryption and decryption computing system also includes:
[0020] a virtual file system provided in a kernel layer of an operating system; the virtual file system being configured to receive a data operation request from a user layer of the operating system and to send the data operation request to the transparent file system; and being configured to return the second data to the system initiating the data operation request;
[0021] The underlying file system is set in the kernel layer of the operating system; the underlying file system is configured to respond to a data operation request sent by the transparent file system, read the first data from the storage device, and send the first data to the transparent file system.
[0022] Optionally, the memory unit includes a plurality of memory blocks;
[0023] The middleware is configured to determine, in response to a memory allocation function of the middleware called by the transparent file system, a target memory block configured to store the first data and the second data from the plurality of memory blocks;
[0024] The transparent file system is configured to write first data into a target memory block.
[0025] Optionally, the transparent file system is further configured to call a memory release function of the middleware to release the target memory block after forwarding the second data according to the data operation request.
[0026] Optionally, the first data includes a plurality of sub-data;
[0027] The middleware is configured to respond to a memory allocation function of the middleware called by the transparent file system, and determine a target memory block corresponding to each sub-data from a plurality of memory blocks;
[0028] The transparent file system is configured to store each sub-data into its corresponding target memory block.
[0029] Optionally, the multiple memory blocks include a used memory block set and an unused memory block set;
[0030] The middleware is configured to determine a target memory block configured to store the first data from a set of unused memory blocks, and classify the target memory block into a set of used memory blocks;
[0031] The middleware is further configured to place the target memory block into an unused memory block set after releasing the target memory block.
[0032] Optionally, the transparent file system is configured to write data information associated with the first data and an encryption / decryption start flag into a data request queue set in the middleware in response to the data operation request;
[0033] The middleware is configured to send data information associated with the first data in the data request queue and an encryption and decryption start flag to the heterogeneous computing program in an order in the data request queue;
[0034] The heterogeneous computing program is configured to call the heterogeneous computing unit to perform decryption processing on the first data according to the data information and the encryption and decryption start flag.
[0035] Optionally, the middleware is configured to mark the memory block storing the second data according to the data information of the first data corresponding to the second data; the middleware is provided with an output result queue, and the output result queue stores the data information of the first data corresponding to the second data; the middleware is configured to send the second data to the transparent file system according to the order in the output result queue.
[0036] Optionally, the heterogeneous computing unit includes a programmable logic device and a board memory;
[0037] The programmable logic device is configured to perform encryption and decryption processing on the first data;
[0038] The board memory is configured to cache the first data and the second data.
[0039] Optionally, data is exchanged between the operating system and the heterogeneous computing units via direct memory access technology (DMA).
[0040] The transparent encryption and decryption computing system also includes:
[0041] The DMA controller is configured to write first data in the memory unit into the heterogeneous computing unit in response to a data write instruction of the heterogeneous computing program; and write second data into the memory unit in response to a data read instruction of the heterogeneous computing program.
[0042] The present application also provides a method for reading and writing data, which should be configured as a transparent encryption and decryption computing system based on heterogeneous computing. The transparent encryption and decryption computing system includes: an operating system and a heterogeneous computing unit. The operating system includes: a transparent file system and middleware deployed at the kernel layer, and a heterogeneous computing program deployed at the user layer. The method includes:
[0043] In response to the data operation request, writing first data corresponding to the data operation request into a memory unit of the middleware;
[0044] Sending a memory address of the first data in the memory unit to the heterogeneous computing program; the heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain second data;
[0045] The second data returned by the heterogeneous computing unit is received, and the second data is sent to the transparent file system; the transparent file system is configured to forward the second data according to the data operation request.
[0046] Optionally, the memory unit includes a plurality of memory blocks, and in response to the data operation request, writing the first data corresponding to the data operation request into the memory unit of the middleware includes:
[0047] In response to a memory allocation function called by the transparent file system when receiving a data operation request, determining a target memory block configured to store the first data from a plurality of memory blocks;
[0048] Write the first data into the target memory block.
[0049] Optionally, the method further comprises:
[0050] In response to the transparent file system calling the memory release function after forwarding the second data, the target memory block is released.
[0051] Optionally, the multiple memory blocks include a used memory block set and an unused memory block set, and determining a target memory block set to store the first data from the multiple memory blocks includes:
[0052] Determining, from an unused memory block set, a target memory block set to store the first data, and moving the target memory block from the unused memory block set to the used memory block set;
[0053] Release the target memory block including:
[0054] Move the target memory block from the used memory block set to the unused memory block set.
[0055] Optionally, receiving the second data returned by the heterogeneous computing unit and sending the second data to the transparent file system includes:
[0056] receiving second data returned by the heterogeneous computing unit, and writing the second data into the target memory block;
[0057] The second data in the target memory block is sent to the transparent file system.
[0058] Optionally, the middleware is provided with an output result queue, the output result queue stores data information of the first data corresponding to the second data, and sends the second data in the target memory block to the transparent file system, including:
[0059] Marking a target memory block storing the second data according to data information of the first data corresponding to the second data;
[0060] The second data is sent to the transparent file system according to the order in the output result queue.
[0061] Optionally, a data request queue is provided in the middleware, and the method further includes:
[0062] Writing data information associated with the first data and an encryption / decryption start identification flag into a data request queue according to the data operation request;
[0063] According to the order in the data request queue, the data information associated with the first data and the encryption and decryption startup identification flag are sent to the heterogeneous computing program; the heterogeneous computing program is configured to call the heterogeneous computing unit to encrypt the first data according to the data information associated with the first data and the encryption and decryption startup identification flag.
[0064] An embodiment of the present application also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the above-mentioned data reading and writing method when executed by the processor.
[0065] An embodiment of the present application further provides a non-volatile computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned method of reading and writing data is implemented.
[0066] The embodiments of the present application have the following advantages:
[0067] In an embodiment of the present application, a transparent encryption and decryption computing system includes: an operating system and a heterogeneous computing unit, the operating system includes: a transparent file system and middleware deployed at the kernel layer, and a heterogeneous computing program deployed at the user layer; the transparent file system is configured to respond to a data operation request at the user layer of the operating system, and send the first data corresponding to the data operation request to the middleware; and receive the encrypted and decrypted second data corresponding to the first data returned by the middleware, and forward the second data according to the data operation request; the middleware is provided with a memory unit; the middleware is configured to store the first data in the memory unit, and send the memory address of the first data in the memory unit to the heterogeneous computing program; the heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for the description of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0069] FIG1 is a schematic diagram of the structure of a transparent encryption and decryption system in the prior art;
[0070] FIG2 is a schematic diagram of the structure of a transparent encryption and decryption computing system based on heterogeneous computing according to an embodiment of the present application;
[0071] FIG3a is a schematic diagram of data transmission in a transparent encryption and decryption computing system according to an embodiment of the present application;
[0072] FIG3 b is a schematic diagram of the structure of a transparent encryption and decryption computing system according to an embodiment of the present application;
[0073] FIG4 is a schematic diagram of partial data transmission in a transparent encryption and decryption computing system according to an embodiment of the present application;
[0074] FIG5 is a flowchart of a method for reading and writing data according to an embodiment of the present application;
[0075] FIG6 a is a flowchart of another method for reading and writing data according to an embodiment of the present application;
[0076] FIG6 b is a flowchart of the steps of transparently encrypting data according to an embodiment of the present application;
[0077] FIG7 is a schematic structural diagram of an electronic device according to an embodiment of the present application;
[0078] FIG8 is a schematic structural diagram of a non-volatile computer-readable storage medium according to an embodiment of the present application. DETAILED DESCRIPTION
[0079] To make the above-mentioned purposes, features, and advantages of this application more clearly understood, the present application is described in detail below with reference to the accompanying drawings and specific embodiments. It is apparent that the embodiments described are only a portion of the embodiments of this application, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments in this application without inventive effort are also within the scope of protection of this application.
[0080] In order to solve the problems of system performance degradation and data insecurity caused by frequent data copying, the present application proposes a transparent encryption and decryption computing system based on heterogeneous computing. The system directly copies data from the kernel layer to the heterogeneous computing unit to avoid the problem of system performance degradation caused by frequent data interaction between the user layer and the kernel layer, as well as the problem of data insecurity caused by copying data to the user layer. Optionally, reference may be made to FIG2 , which shows a schematic structural diagram of a transparent encryption and decryption computing system based on heterogeneous computing according to an embodiment of the present application. As shown in FIG2 , the transparent encryption and decryption computing system may include:
[0081] Operating system and heterogeneous computing unit. The operating system includes: transparent file system and middleware deployed in the kernel layer, and heterogeneous computing programs deployed in the user layer;
[0082] In some embodiments, the transparent encryption and decryption computing system may be composed of an operating system and a heterogeneous computing unit; wherein, the operating system may refer to an operating system deployed on a CPU (Central Processing Unit), which may be a Linux operating system or other operating systems, and the embodiments of the present application do not impose any restrictions on this.
[0083] Heterogeneous computing units can refer to hardware devices configured to implement heterogeneous computing together with an operating system, such as FPGAs (Field Programmable Gate Arrays). Heterogeneous computing can also refer to a computing method that uses computing units with different instruction sets and architectures to form a system. Common computing units that implement heterogeneous computing include CPUs, GPUs (Graphics Processing Units), DSPs (Digital Signal Processors), ASICs (Application Specific Integrated Circuits), FPGAs, and other processors.
[0084] In some embodiments, the operating system may include a transparent file system and middleware deployed at the kernel layer; wherein the transparent file system and middleware can transmit data at the kernel layer, thereby avoiding the problem of system performance degradation caused by frequent data copying, and the problem of data insecurity caused by copying to the user layer.
[0085] Optionally, the transparent file system is configured to respond to a data operation request from a user layer of the operating system, send first data corresponding to the data operation request to the middleware; and receive encrypted and decrypted second data corresponding to the first data returned by the middleware, and forward the second data according to the data operation request;
[0086] The middleware is provided with a memory unit; the middleware is configured to store the first data in the memory unit and send a memory address of the first data in the memory unit to the heterogeneous computing program;
[0087] The heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data.
[0088] In some embodiments, when a user needs to obtain data from a storage device or wants to write data to a storage device, the user can perform corresponding operations in a user-layer application; in response to the operation, the application can generate a corresponding data operation request; illustratively, the data operation request can be a request to read data or a request to write data, which is not limited in this embodiment of the present application.
[0089] After generating a data operation request, the user-layer application can send the data operation request to the kernel layer of the operating system; after receiving the data operation request, the transparent file system of the kernel layer can respond to the data operation request and send the first data to be operated corresponding to the data operation request to the middleware of the kernel layer of the operating system.
[0090] After receiving the first data, the middleware can first store the first data in the memory unit of the middleware; at this time, the first data has a memory address in the memory unit, that is, the memory unit stores the memory address of the first data; after storing the first data in the memory unit, the middleware can send the memory address of the first data in the memory unit to the heterogeneous computing program located in the user layer of the operating system.
[0091] Exemplarily, the heterogeneous computing program may refer to a user-layer program, which may be configured to issue commands such as data transmission, calculation, and result recovery.
[0092] Optionally, after receiving the memory address of the first data in the memory unit, the heterogeneous computing program can write the first data in the memory unit into the heterogeneous computing unit according to the memory address; this writing process is completed by the heterogeneous computing program relying on the memory address, and there is no need to transmit the first data to the heterogeneous computing program; therefore, the system performance degradation caused by frequent data copying and the problem of data insecurity can be avoided.
[0093] After receiving the first data, the heterogeneous computing unit can perform corresponding operations on the first data in response to the instructions of the heterogeneous computing program; for example: when the data operation request is a request for data writing, the heterogeneous computing program can issue an encrypted instruction to the heterogeneous computing unit; the heterogeneous computing unit can encrypt the first data in response to the encrypted instruction to obtain the second data.
[0094] For another example: if the data operation request is a data read request, the heterogeneous computing program can issue a decryption instruction to the heterogeneous computing unit; the heterogeneous computing unit can decrypt the first data in response to the decryption instruction to obtain the second data.
[0095] After generating the second data, the heterogeneous computing unit may return the second data to the middleware; then, the middleware may return the second data to the transparent file system.
[0096] After receiving the second data, the transparent file system can forward the second data according to the data operation request received previously; for example, if the data operation request is a data write request, the second data can be written to the storage device; if the data operation request is a data read request, the second data can be returned to the user.
[0097] The following is an example explanation of different data operation requests:
[0098] In an embodiment of the present application, the data operation request is a request to write data to a storage device of a transparent encryption and decryption computing system, and the data operation request includes first data, the first data is data to be encrypted, and the second data is encrypted data;
[0099] The transparent encryption and decryption computing system also includes:
[0100] A virtual file system is provided in the kernel layer of the operating system; the virtual file system is configured to receive data operation requests from the user layer of the operating system and send the data operation requests to the transparent file system;
[0101] The underlying file system is set in the kernel layer of the operating system; the underlying file system is configured to receive the second data forwarded by the transparent file system and write the second data into the storage device.
[0102] In some embodiments, the transparent encryption and decryption computing system may also include a virtual file system and an underlying file system; wherein, the virtual file system may be a unified interface provided by the operating system for all kernel layer file systems, and any form of data operation in the user layer must pass through the virtual file system to enter the kernel layer before calling the corresponding file system in the kernel layer for subsequent operations.
[0103] The underlying file system can refer to the inherent file system of the operating system. For example, if the operating system is a Linux operating system, the underlying file system can be EXT3 (Third Extended Filesystem) / EXT4 (Fourth Extended Filesystem), etc. The underlying file system can be set to manage files on the storage device so as to perform file reading and writing and other add, delete, check, and modify operations with the user layer.
[0104] When a user-layer data operation request enters the kernel layer, it can first be sent to the virtual file system. After the virtual file system determines that the data operation request is a data operation request requiring transparent encryption and decryption, it can send the data operation request to the transparent file system. Exemplarily, when the data operation request is a request to write data to a storage device of the transparent encryption and decryption computing system, the data operation request can include first data to be encrypted. In an embodiment where the data operation request is a request to write data to a storage device of the transparent encryption and decryption computing system, the second data is the encrypted data.
[0105] After receiving a data operation request, the transparent file system may write the first data to a memory unit of the middleware located in the kernel layer. After the first data to be encrypted is written to the memory unit of the middleware, the middleware may send the memory address of the first data in the memory unit to the heterogeneous computing unit. After receiving the memory address, the heterogeneous computing unit may write the first data to be encrypted in the memory unit to the heterogeneous computing unit based on the memory address and instruct the heterogeneous computing unit to perform an encryption operation on the first data.
[0106] After receiving the second data obtained after the heterogeneous computing unit performs an encryption operation on the first data, the transparent file system can send the second data to the underlying file system, and then the underlying file system writes the second data to the storage device.
[0107] In the embodiment of the present application, the data operation request is a request to read data from a storage device of a transparent encryption and decryption computing system, the first data is data to be decrypted, and the second data is decrypted data;
[0108] The transparent encryption and decryption computing system also includes:
[0109] a virtual file system provided in a kernel layer of an operating system; the virtual file system being configured to receive a data operation request from a user layer of the operating system and to send the data operation request to the transparent file system; and being configured to return the second data to the system initiating the data operation request;
[0110] The underlying file system is set in the kernel layer of the operating system; the underlying file system is configured to respond to a data operation request sent by the transparent file system, read the first data from the storage device, and send the first data to the transparent file system.
[0111] In other embodiments, when the data operation request is a request to read data from a storage device of the transparent encryption and decryption computing system, the data operation request may include an identifier of the first data to be decrypted, or an address in the storage device. In embodiments where the data operation request is a request to read data from a storage device of the transparent encryption and decryption computing system, the second data is the decrypted data.
[0112] After receiving the data operation request, the transparent file system may send the data operation request to the underlying file system; in response to the data operation request, the underlying file system may read the first data from the storage device and send the first data to the transparent file system.
[0113] After receiving the first data, the transparent file system may write the first data into a memory unit of the middleware located in the kernel layer.
[0114] After the middleware's memory unit writes the first data to be encrypted, the middleware can send the memory address of the first data in the memory unit to the heterogeneous computing unit. After receiving the memory address, the heterogeneous computing unit can write the first data to be decrypted in the memory unit to the heterogeneous computing unit based on the memory address and instruct the heterogeneous computing unit to perform a decryption operation on the first data.
[0115] After receiving the second data obtained after the heterogeneous computing unit performs a decryption operation on the first data, the transparent file system can send the second data to the virtual file system, and the virtual file system returns the second data to the system that initiated the data operation request; illustratively, the second data can be returned to the application in the user layer that initiated the data operation request, which is not limited in this embodiment of the present application.
[0116] In the following embodiments, the transparent encryption and decryption computing system is described as follows:
[0117] In an embodiment of the present application, the memory unit includes multiple memory blocks; the middleware is configured to respond to the memory allocation function of the middleware called by the transparent file system, and determine the target memory block configured to store the first data and the second data from the multiple memory blocks; the transparent file system is configured to write the first data to the target memory block.
[0118] In some embodiments, when the kernel-mode file system has memory requirements, it dynamically requests memory. This dynamic memory request increases system call latency and degrades system performance. To address this issue, embodiments of the present application can pre-divide the middleware's memory unit into multiple memory blocks. These multiple memory blocks can be of the same or different sizes, and this embodiment of the present application does not impose any restrictions on this.
[0119] In actual applications, when the transparent file system writes the first data into the memory unit, it can first call the memory allocation function of the middleware. The memory allocation function can be a customized function that is set to apply for a target memory block for storing the first data from multiple memory blocks of the memory unit.
[0120] In response to the memory allocation function, the middleware may determine a target memory block configured to store the first data and the second data from a plurality of memory blocks; then, the middleware may store the first data written by the transparent file system in the target memory block.
[0121] In addition, after generating the second data, the heterogeneous computing unit may write the second data into the target memory block; then, the middleware may forward the second data in the target memory block to the transparent file system.
[0122] As an example, the transparent file system is further configured to call a memory release function of the middleware to release the target memory block after forwarding the second data according to the data operation request.
[0123] In some embodiments, to avoid occupying the target memory block, the transparent file system may call a memory release function of the middleware after forwarding the second data to release the target memory block, thereby allowing other requests to apply for use of the target memory block.
[0124] In the embodiment of the present application, the first data includes a plurality of sub-data;
[0125] The middleware is configured to respond to a memory allocation function of the middleware called by the transparent file system, and determine a target memory block corresponding to each sub-data from a plurality of memory blocks;
[0126] The transparent file system is configured to store each sub-data into its corresponding target memory block.
[0127] In some embodiments, the first data may include multiple sub-data. For example, if the first data is data to be encrypted, the first data may be data to be written that is split and the resultant multiple sub-data are obtained by splitting; if the first data is data to be decrypted, the first data may be data read from a storage device that is split and the resultant multiple sub-data are obtained by splitting.
[0128] After receiving the first data, the transparent file system may call the memory allocation function of the middleware, and apply for a corresponding target memory block for each sub-data in the memory unit of the middleware.
[0129] After applying for the target memory block, the transparent file system can write each sub-data in the first data into the corresponding target memory block.
[0130] Then, the middleware may send the memory address corresponding to the target memory block storing the sub-data of the first data to the heterogeneous computing program, so that the heterogeneous computing unit may transfer and process the data based on the memory address.
[0131] In an embodiment of the present application, the multiple memory blocks include a used memory block set and an unused memory block set; wherein, the used memory block set may include memory blocks that are currently storing data or will store data, and the unused memory block set may include memory blocks that currently do not store data and currently have no data that needs to be stored.
[0132] The middleware is configured to determine a target memory block configured to store the first data from a set of unused memory blocks, and classify the target memory block into a set of used memory blocks;
[0133] The middleware is further configured to place the target memory block into an unused memory block set after releasing the target memory block.
[0134] In some embodiments, when the transparent file system applies for a memory block, the middleware can determine the target memory block set to store the first data from the unused memory block set; after the application is successful, the transparent file system can write the first data to the target memory block. At the same time, the middleware can classify the target memory block into the used memory block set to avoid subsequent other requests from requesting the memory block.
[0135] In other embodiments, after forwarding the second data, the transparent file may call a memory release function to cause the middleware to release the target memory block occupied by the second data. In this case, after releasing the target memory block, the middleware may transfer the target memory block from the used memory block set to the unused memory block set so that other subsequent requests can use the target memory block.
[0136] In the embodiment of the present application, in order to uniformly schedule the encryption and decryption operation process, a data request queue can be set in the middleware; then, data operation requests are processed based on the data request queue. Optionally:
[0137] The transparent file system is configured to write data information associated with the first data and an encryption / decryption start flag into a data request queue configured in the middleware in response to a data operation request;
[0138] The middleware is configured to send data information associated with the first data in the data request queue and an encryption and decryption start flag to the heterogeneous computing program in an order in the data request queue;
[0139] The heterogeneous computing program is configured to call the heterogeneous computing unit to perform decryption processing on the first data according to the data information and the encryption and decryption start flag.
[0140] In some embodiments, after receiving a data operation request, the transparent file system can determine data information related to the first data based on the data operation request. The data information may include calculation items required for encryption and decryption, such as: the size of the first data, the ID (Identity document) of the first data, etc.
[0141] At the same time, based on the data operation request, the encryption and decryption start flag corresponding to the first data can be determined. The encryption and decryption start flag is a character information transmitted to the heterogeneous computing unit. After obtaining this encryption and decryption start flag, the heterogeneous computing unit can perform corresponding encryption or decryption operations on the first data; exemplarily, the data information and the encryption and decryption start flag can be included in the data operation request, and the embodiment of the present application does not limit this.
[0142] After obtaining the data information and encryption / decryption start flag of the first data, the transparent file system can write the data information and encryption / decryption start flag into the data request queue set in the middleware; illustratively, the data request queue can also include data information and encryption / decryption start flags of other data, and the data information and encryption / decryption start flags of each data are arranged in the data request queue according to preset rules. For example, they can be arranged in the order of the time when the transparent file system receives the requests, or they can be arranged according to the priority of the data. This embodiment of the present application does not limit this.
[0143] For the middleware, the data information and encryption / decryption start flag associated with the first data in the data request queue can be sent to the heterogeneous computing program in the order in the data request queue; the heterogeneous computing program can call the heterogeneous computing unit to decrypt the first data according to the data information and encryption / decryption start flag in the order received.
[0144] Exemplarily, after receiving the data information of the first data and the encryption and decryption start flag, the heterogeneous computing program can generate a corresponding execution instruction and add the execution instruction to the execution command queue; when it is the turn of the execution instruction corresponding to the first data, the heterogeneous computing program can call the heterogeneous computing unit through the execution instruction to decrypt the first data.
[0145] In the embodiment of the present application, for the output results, an output result queue can also be set, and then the output results are uniformly scheduled based on the output result queue. Optionally:
[0146] The middleware is configured to mark a memory block storing the second data according to data information of the first data corresponding to the second data; the middleware is provided with an output result queue, and the output result queue stores data information of the first data corresponding to the second data; the middleware is configured to send the second data to the transparent file system according to the order in the output result queue.
[0147] In some embodiments, an output result queue may also be set in the middleware, which may store data information of the first data corresponding to the second data. For example, the ID of the first data may be stored so that the middleware can determine which second data is based on which first data based on the ID.
[0148] Exemplarily, the output result queue may be arranged based on the time when the second data is generated.
[0149] When the middleware stores the second data in the memory block, it can mark the memory block storing the second data according to the data information of the first data corresponding to the second data; the memory block storing the second data can be the aforementioned target memory block or a re-determined memory block, and the embodiment of the present application does not limit this.
[0150] For the middleware, the second data corresponding to the first data may be sent to the transparent file system according to the order in the output result queue.
[0151] In an embodiment of the present application, a heterogeneous computing unit includes a programmable logic device and a board memory; wherein the programmable logic device is configured to perform encryption and decryption processing on the first data; and the board memory is configured to cache the first data and the second data.
[0152] In some embodiments, the heterogeneous computing unit may be composed of a programmable logic device and a board memory. For example, the programmable logic device may be composed of a DDR (Double Data Rate) controller and a computing unit.
[0153] The programmable logic device may be configured to implement encryption and decryption algorithm calculation tasks; optionally, the programmable logic device may be configured to perform encryption or decryption processing on the first data.
[0154] The board memory can be set to cache the first data transmitted to the programmable logic device, or to cache the second data to be transmitted by the programmable logic device to the middleware; illustratively, the operating system and the heterogeneous computing unit can be connected via a PCIE (Peripheral Component Interconnect Express) bus, which is not limited in this embodiment of the present application.
[0155] As an example, data exchange between the operating system and the heterogeneous computing units is performed through DMA (Direct Memory Access).
[0156] The transparent encryption and decryption computing system also includes:
[0157] The DMA controller is configured to write first data in the memory unit into the heterogeneous computing unit in response to a data write instruction of the heterogeneous computing program; and write second data into the memory unit in response to a data read instruction of the heterogeneous computing program.
[0158] In some embodiments, data exchange can be performed directly between the operating system and the heterogeneous computing unit via DMA; optionally, the data exchange can be implemented based on a DMA controller.
[0159] Exemplarily, the heterogeneous computing program can generate a data write instruction for the first data and send the data write instruction to the DMA controller; in response to the data write instruction, the DMA controller can write the first data in the memory unit of the middleware into the heterogeneous computing unit, and the heterogeneous computing unit can perform corresponding encryption and decryption processing.
[0160] In addition, the heterogeneous computing program can also generate a data read instruction for the second data and send the data read instruction to the DMA controller; in response to the data read instruction, the DMA controller can write the second data in the heterogeneous computing unit into the memory unit.
[0161] For example, as shown in Figure 3a, the transparent encryption and decryption computing system based on heterogeneous computing can be divided into three levels: user layer, kernel layer and device layer; among them, user read / write operations can be performed at the user layer; the kernel layer is provided with a virtual file system, a transparent file system, an underlying file system and middleware; the device layer is provided with storage devices and heterogeneous computing units (i.e., the field programmable gate array accelerator card in Figure 3a).
[0162] In addition, the user layer also includes a heterogeneous computing program, which can be hls_host in Figure 3a. The internal structure of hls_host includes the OpenCL (Open Computing Language) execution model, memory addresses and data sizes passed through the middleware, encryption and decryption startup flags, etc. The OpenCL execution model provides developers with a flexible and efficient way to utilize parallel computing devices. OpenCL includes an execution command queue and an API (Application Programming Interface) for FPGA hardware-accelerated computing, thereby achieving the goal of high-performance encryption and decryption computing. During the entire encryption and decryption process, neither encrypted nor decrypted data passes through hls_host.
[0163] When a user performs a write operation, it is an encryption operation. First, the user-mode write operation calls the virtual file system API to establish an association with the transparent file system. Then, it enters the middleware through the transparent file system and reaches the field programmable logic gate array accelerator card for encryption operation. After that, it returns to the middleware and enters the underlying file system through the transparent file system. Finally, the data is encrypted and written to the storage device. The data flow transmission path is ①→②→③→④→⑤→⑥→⑦→⑧.
[0164] The read operation at the user layer is the decryption operation. Decryption is the reverse process of encryption. First, a read operation is initiated at the user layer. The read operation needs to pass through the virtual file system, transparent file system, underlying file system, and finally reach the storage device. The data needs to be read from the storage device, then pass through the underlying file system, transparent file system, and middleware, and enter the field programmable logic gate array accelerator card for decryption. After decryption is completed, it passes through the middleware, transparent file system, virtual file system, and finally returns the decrypted data to the user at the user layer. The decryption operation process is as follows: Among them, ①, ②, ⑦, and ⑧ are read request processes initiated by users, ⑨, ⑩, ③, ④, ⑤, ⑥, It is the decrypted data flow path; the middleware acts as a bridge for data transmission between the transparent file system and the field programmable logic gate array accelerator card.
[0165] As an example, the operating system in the transparent encryption and decryption computing system based on heterogeneous computing shown in Figure 3b can be a Linux operating system, which can be deployed on the CPU of the server host; the storage device can be a disk, and the field programmable logic gate array accelerator card can include a field programmable logic gate array and a board memory; wherein the field programmable logic gate array can include a double data rate controller and a computing unit, and the board memory can be a double data rate board memory.
[0166] The user layer of the Linux operating system can include a heterogeneous computing program, such as hls_host, and user-generated file read and write operations. The kernel layer includes a transparent file system, middleware, and memory units. The kernel layer can interact with other components via drivers and application programming interfaces (APIs). The server host and heterogeneous computing units can be connected via a Peripheral Component Interconnect Express bus, with data exchanged using direct memory access technology.
[0167] As shown in Figure 4, taking the write operation as an example: when the transparent file system receives a write operation request, it can add the data flag, data size and encryption and decryption start flag of the data corresponding to the write operation in the data request queue of the middleware; the middleware can send the data flag, data size and encryption and decryption start flag in the data request queue to the heterogeneous computing program of the user layer in sequence based on the order of the data request queue, such as: hls_host.
[0168] On the other hand, the transparent file system can call the middleware's memory allocation function to apply for the corresponding memory block, and write the data to be written into the applied memory block; the memory block with written data can be included in the memory pool of used memory; at this time, the data in the memory block is plaintext data.
[0169] When plaintext data is written into a memory block, the plaintext data corresponds to a memory address; the memory address is sent to the hls_host in the user layer through memory mapping (mmap).
[0170] hls_host can generate corresponding commands based on the memory address and data flag (for example, data ID), data size, and encryption and decryption start flag; as shown in FIG4 , hls_host can generate different sets of commands for different requests.
[0171] Next, hls_host can send commands through the open computing language application programming interface to enable the plaintext in the middleware to be written to the field programmable logic gate array accelerator card through DMA; the field programmable logic gate array accelerator card responds to hls_host, encrypts the plaintext data, and obtains ciphertext data.
[0172] The middleware is also provided with an output result queue, which contains a data flag of plaintext data. The data flag is used to encrypt the ciphertext data, so that when the ciphertext data is written into the memory block, the plaintext data corresponding to the ciphertext data is transmitted in the memory block written first. After the ciphertext data is transmitted to the transparent file system, the transparent file system can copy the ciphertext data to the underlying file system so that the underlying file can be written to the storage device in coordination. On the other hand, the transparent file system can call the memory release function to release the occupied memory block; the released memory block can enter the memory pool of unused memory.
[0173] Based on the transparent encryption and decryption computing system provided in the above embodiment, an embodiment of the present application further provides a method for reading and writing data applied to the transparent encryption and decryption computing system. Exemplarily, the transparent encryption and decryption computing system includes an operating system and a heterogeneous computing unit. The operating system includes: a transparent file system and middleware deployed at the kernel layer, and a heterogeneous computing program deployed at the user layer. The method can refer to FIG5 , which shows a flowchart of the steps of the method for reading and writing data in an embodiment of the present application. The method may include the following steps:
[0174] Step 501: In response to a data operation request, write first data corresponding to the data operation request into a memory unit of the middleware.
[0175] In some implementations, when a user needs to obtain data from a storage device or wants to write data to a storage device, the user may perform a corresponding operation in a user-layer application; in response to the operation, the application may generate a corresponding data operation request.
[0176] After generating a data operation request, the user-layer application can send the data operation request to the kernel layer of the operating system; after receiving the data operation request, the transparent file system of the kernel layer can respond to the data operation request and send the first data to be operated corresponding to the data operation request to the middleware of the kernel layer of the operating system.
[0177] After receiving the first data, the middleware may store the first data in the memory unit of the middleware first; at the same time, the middleware may determine the memory address of the first data in the memory unit, that is, the location where the first data is stored in the memory unit.
[0178] Step 502: Send the memory address of the first data in the memory unit to the heterogeneous computing program; the heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data.
[0179] After storing the first data in the memory unit, the middleware may send the memory address of the first data in the memory unit to the heterogeneous computing program located in the user layer of the operating system.
[0180] After receiving the memory address of the first data in the memory unit, the heterogeneous computing program can write the first data in the memory unit into the heterogeneous computing unit according to the memory address; this writing process is completed by the heterogeneous computing program relying on the memory address, and there is no need to transmit the first data to the heterogeneous computing program; therefore, the system performance degradation caused by frequent data copying and the problem of data insecurity can be avoided.
[0181] After receiving the first data, the heterogeneous computing unit may perform corresponding encryption or decryption processing on the first data in response to instructions of the heterogeneous computing program, thereby obtaining corresponding second data.
[0182] Step 503: Receive the second data returned by the heterogeneous computing unit, and send the second data to the transparent file system; the transparent file system is configured to forward the second data according to the data operation request.
[0183] After generating the second data, the heterogeneous computing unit may return the second data to the middleware; then, the middleware may send the received second data to the transparent file system.
[0184] After receiving the second data, the transparent file system can forward the second data according to the data operation request received previously; for example: if the data operation request is a data write request, the second data can be written to the storage device; if the data operation request is a data read request, the second data can be returned to the user. This embodiment of the present application does not limit this.
[0185] In an embodiment of the present application, in response to a data operation request, the transparent encryption and decryption computing system can first write the first data corresponding to the data operation request into the memory unit of the middleware; then send the memory address of the first data in the memory unit to the heterogeneous computing program; the heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data; thereafter, the second data returned by the heterogeneous computing unit is received and sent to the transparent file system; the transparent file system is configured to forward the second data according to the data operation request. Through the embodiment of the present application, data can be copied directly from the kernel layer to the heterogeneous computing unit, thereby avoiding the problem of system performance degradation caused by frequent data interaction between the user layer and the kernel layer, and the problem of data insecurity caused by copying data to the user layer.
[0186] 6a, a flowchart of another method for reading and writing data according to an embodiment of the present application is shown, which may include the following steps:
[0187] Step 601: The memory unit includes multiple memory blocks. In response to a memory allocation function called by the transparent file system when receiving a data operation request, a target memory block set to store first data is determined from the multiple memory blocks.
[0188] In some embodiments, a plurality of memory blocks may be pre-divided in the memory unit of the middleware, and the sizes of the plurality of memory blocks may be the same or different.
[0189] When writing the first data into the memory unit, the transparent file system may first call the memory allocation function of the middleware. The memory allocation function may be a customized function configured to apply for a target memory block for storing the first data from multiple memory blocks of the memory unit.
[0190] In response to the memory allocation function, the middleware may determine, from a plurality of memory blocks, a target memory block configured to store the first data and the second data.
[0191] In an embodiment of the present application, the multiple memory blocks include a used memory block set and an unused memory block set; when determining a target memory block, the target memory block may be determined in the following manner:
[0192] A target memory block configured to store the first data is determined from an unused memory block set, and the target memory block is moved from the unused memory block set to the used memory block set.
[0193] In some embodiments, when the transparent file system applies for a memory block, the middleware can determine the target memory block set to store the first data from the unused memory block set; after the application is successful, the transparent file system can write the first data to the target memory block. At the same time, the middleware can classify the target memory block into the used memory block set to avoid subsequent other requests from requesting the memory block.
[0194] Step 602: Write the data to be encrypted into the target memory block.
[0195] After applying for the target memory block, the middleware may write the first data into the target memory block in response to a write operation of the transparent file system.
[0196] Step 603: Send the memory address of the first data in the memory unit to the heterogeneous computing program; the heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data.
[0197] After storing the first data in the memory unit, the middleware may send the memory address of the first data in the memory unit to the heterogeneous computing program located in the user layer of the operating system.
[0198] After receiving the memory address of the first data in the memory unit, the heterogeneous computing program can write the first data in the memory unit into the heterogeneous computing unit according to the memory address; this writing process is completed by the heterogeneous computing program relying on the memory address, and there is no need to transmit the first data to the heterogeneous computing program; therefore, the system performance degradation caused by frequent data copying and the problem of data insecurity can be avoided.
[0199] After receiving the first data, the heterogeneous computing unit may perform corresponding encryption or decryption processing on the first data in response to instructions of the heterogeneous computing program, thereby obtaining corresponding second data.
[0200] Step 604: Receive the second data returned by the heterogeneous computing unit, and write the second data into the target memory block.
[0201] After generating the second data, the heterogeneous computing unit can return the second data to the middleware; optionally, the heterogeneous computing unit can write the second data into the memory unit of the middleware; in response to the write operation of the heterogeneous computing unit, the middleware can write the second data into the target memory block of the memory unit.
[0202] Step 605: Send the second data in the target memory block to the transparent file system; the transparent file system is configured to forward the second data according to the data operation request.
[0203] After storing the second data in the target memory block, the middleware can send the second data in the target memory block to the transparent file system at a preset time; then, the transparent file system can send the second data to the underlying file system to write to the storage device, or send the second data to the virtual file system, and the virtual file system returns it to the user. The embodiments of the present application do not limit this.
[0204] In one embodiment of the present application, the middleware is provided with an output result queue, and the output result queue stores data information of the first data corresponding to the second data. Step 605 can be implemented by the following sub-steps, including:
[0205] Sub-step 11: Mark the target memory block storing the second data according to the data information of the first data corresponding to the second data.
[0206] In some embodiments, an output result queue may be set in the middleware, and data information of the first data corresponding to the second data may be stored in the output result queue.
[0207] Exemplarily, the output result queue may be arranged based on the time when the second data is generated.
[0208] When the middleware stores the second data in the memory block, it can mark the memory block storing the second data according to the data information of the first data corresponding to the second data; the memory block storing the second data can be the aforementioned target memory block or a re-determined memory block, and the embodiment of the present application does not limit this.
[0209] Sub-step 12: Send the second data to the transparent file system according to the order in the output result queue.
[0210] For the middleware, the second data corresponding to the first data may be sent to the transparent file system for forwarding according to the order in the output result queue.
[0211] In another embodiment of the present application, a data request queue is provided in the middleware, and the above method may further include the following steps:
[0212] According to the data operation request, the data information and the encryption and decryption startup identification flag associated with the first data are written into the data request queue; according to the order in the data request queue, the data information and the encryption and decryption startup identification flag associated with the first data are sent to the heterogeneous computing program; the heterogeneous computing program is configured to call the heterogeneous computing unit to encrypt the first data according to the data information and the encryption and decryption startup identification flag associated with the first data.
[0213] In some embodiments, after receiving a data operation request, the transparent file system may determine data information related to the first data according to the data operation request. The data information may include calculation items required for encryption and decryption.
[0214] At the same time, based on the data operation request, the encryption and decryption start flag corresponding to the first data can be determined. The encryption and decryption start flag is a character information transmitted to the heterogeneous computing unit. After obtaining this encryption and decryption start flag, the heterogeneous computing unit can perform corresponding encryption or decryption operations on the first data.
[0215] After obtaining the data information and encryption / decryption startup flag of the first data, the transparent file system can write the data information and encryption / decryption startup flag into the data request queue set in the middleware; illustratively, the data request queue can also include data information and encryption / decryption startup flags of other data, and the data information and encryption / decryption startup flags of each data are arranged in the data request queue according to preset rules.
[0216] For the middleware, the data information and encryption / decryption start flag associated with the first data in the data request queue can be sent to the heterogeneous computing program in the order in the data request queue; the heterogeneous computing program can call the heterogeneous computing unit to decrypt the first data according to the data information and encryption / decryption start flag in the order received.
[0217] After receiving the data information of the first data and the encryption and decryption start flag, the heterogeneous computing program can generate a corresponding execution instruction and add the execution instruction to the execution command queue; when it is the turn of the execution instruction corresponding to the first data, the heterogeneous computing program can call the heterogeneous computing unit through the execution instruction to decrypt the first data.
[0218] Step 606: In response to the transparent file system calling the memory release function after writing the encrypted data to the storage device, the target memory block is released.
[0219] In some embodiments, to avoid occupying the target memory block, the transparent file system can call a memory release function of the middleware after forwarding the second data to release the target memory block, thereby allowing other requests to apply for use of the target memory block. In response to the transparent file system calling the memory release function after writing the encrypted data to the storage device, the middleware can release the target memory block.
[0220] In one embodiment of the present application, when releasing the target memory block, it can be achieved in the following manner:
[0221] Move the target memory block from the used memory block set to the unused memory block set.
[0222] In some embodiments, after forwarding the second data, the transparent file may call a memory release function to cause the middleware to release the target memory block occupied by the second data. In this case, after releasing the target memory block, the middleware may transfer the target memory block from the used memory block set to the unused memory block set so that other subsequent requests can use the target memory block.
[0223] For example, as shown in FIG6b , a 1GB memory pool can be pre-allocated in the middleware and divided into 32 memory blocks, each of which is 32 KB in size. Furthermore, a memory block allocation function can be sent to the transparent file system so that the transparent file system can subsequently call the memory block allocation function to allocate memory blocks.
[0224] When a user initiates a write operation or an encryption operation, the plaintext data to be encrypted can be split into multiple data blocks, obtaining data block 1, data block 2, ..., data block n.
[0225] Afterwards, the transparent file system can call the memory allocation function of the middleware to apply for a memory block from multiple memory blocks to store plaintext data; if the application fails, it will reapply; if the application succeeds, the plaintext data can be written to the applied memory block.
[0226] After the plaintext data is written to the memory block, one or more memory blocks in the middleware will contain the plaintext data; at this time, an asynchronous notification message can be sent to the heterogeneous computing program running in the background, such as: hls_host; hls_host can determine whether the asynchronous notification message is received. If not, it will receive it again; if received, the memory address of the plaintext data can be obtained; optionally, the memory address of the plaintext data in the memory can be mapped to the user layer through mmap.
[0227] After writing the plaintext data to the memory block, the transparent file system can send a computing request to the middleware; the middleware can forward the computing request to the hls_host.
[0228] After receiving the computation request, hls_host can issue execution commands (①, DMA write command; ②, start FPGA computation; ③, DMA read command) to the DMA controller and FPGA accelerator card. In response to the DMA write command, the DMA controller can write the plaintext data block to the FPGA accelerator card based on the memory address. In response to the command to start FPGA computation, the FPGA accelerator card encrypts the plaintext data to obtain ciphertext data.
[0229] The DMA controller then responds to the DMA read command to write the encrypted data into the middleware, which then transmits the encrypted data to the transparent file system.
[0230] After receiving the encrypted data, the transparent file system can send it to the underlying file system, allowing it to write the encrypted data to the storage device. Furthermore, the transparent file system can call the middleware's memory release function to free up the occupied memory blocks. This completes the transparent encryption and decryption of the data.
[0231] In an embodiment of the present application, in response to the transparent file system receiving a data operation request, the memory allocation function called determines a target memory block set to store the first data from multiple memory blocks; the data to be encrypted is written into the target memory block; the memory address of the first data in the memory unit is sent to the heterogeneous computing program; the heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data; the second data returned by the heterogeneous computing unit is received, and the second data is written into the target memory block; the second data in the target memory block is sent to the transparent file system; the transparent file system is configured to forward the second data according to the data operation request; in response to the transparent file system writing the encrypted data to the storage device, the memory release function called releases the target memory block. Through the embodiment of the present application, the memory unit can be efficiently managed, avoiding the impact of dynamic memory allocation and release operations on system performance, thereby improving the overall system performance.
[0232] During the encryption and decryption operations, unified scheduling is performed based on queues to improve system performance, avoid resource conflicts, and simplify system design.
[0233] It should be noted that, for the sake of simplicity, the method embodiments are described as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present application are not limited by the order of the actions described, because according to the embodiments of the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions involved are not necessarily required by the embodiments of the present application.
[0234] An embodiment of the present application also provides an electronic device, as shown in Figure 7, the electronic device 7 includes a processor 701, a memory 702, and a computer program stored in the memory 702 and capable of running on the processor, and when the computer program is executed by the processor, the above data reading and writing method is implemented.
[0235] An embodiment of the present application further provides a non-volatile computer-readable storage medium, as shown in FIG8 . The non-volatile computer-readable storage medium 8 stores a computer program 801 , which implements the above-mentioned data reading and writing method when executed by a processor.
[0236] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0237] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0238] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, electronic devices, or non-volatile computer-readable storage media. Therefore, the embodiments of the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the embodiments of the present application may take the form of a computer program product implemented on one or more computer-usable non-volatile readable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0239] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, systems, electronic devices, and moisture according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0240] Although alternative embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concept. Therefore, the appended claims are intended to be interpreted as including alternative embodiments and all changes and modifications that fall within the scope of the present invention.
[0241] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.
[0242] The above is a detailed introduction to a transparent encryption and decryption computing system, method, device and medium based on heterogeneous computing. This article uses individual examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method of this application and its core idea; at the same time, for general technical personnel in this field, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on this application.
Claims
1. A transparent encryption and decryption computing system based on heterogeneous computing, the transparent encryption and decryption computing system comprising: An operating system and a heterogeneous computing unit, wherein the operating system includes: a transparent file system and middleware deployed at the kernel layer, and a heterogeneous computing program deployed at the user layer; The transparent file system is configured to respond to a data operation request of a user layer of the operating system, send first data corresponding to the data operation request to the middleware; and receive encrypted and decrypted second data corresponding to the first data returned by the middleware, and forward the second data according to the data operation request; The middleware is provided with a memory unit; the middleware is configured to store the first data in the memory unit, and send the memory address of the first data in the memory unit to the heterogeneous computing program; The heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain the second data.
2. The transparent encryption and decryption computing system according to claim 1, characterized in that: The data operation request is a request to write data into a storage device of the transparent encryption and decryption computing system, and the data operation request includes the first data, the first data is the data to be encrypted, and the second data is the encrypted data; The transparent encryption and decryption computing system also includes: A virtual file system is arranged in the kernel layer of the operating system; the virtual file system is arranged to receive a data operation request from the user layer of the operating system and send the data operation request to the transparent file system; The underlying file system is arranged in the kernel layer of the operating system; the underlying file system is arranged to receive the second data forwarded by the transparent file system and write the second data into the storage device.
3. The transparent encryption and decryption computing system according to claim 1, characterized in that: The data operation request is a request to read data from a storage device of the transparent encryption and decryption computing system, the first data is data to be decrypted, and the second data is decrypted data; The transparent encryption and decryption computing system also includes: a virtual file system, arranged in the kernel layer of the operating system; the virtual file system is arranged to receive a data operation request from the user layer of the operating system and send the data operation request to the transparent file system; and is arranged to return the second data to the system initiating the data operation request; An underlying file system is arranged in the kernel layer of the operating system; the underlying file system is arranged to respond to a data operation request sent by the transparent file system, read the first data from the storage device, and send the first data to the transparent file system.
4. The transparent encryption and decryption computing system according to any one of claims 1 to 3, characterized in that: The memory unit includes a plurality of memory blocks; The middleware is configured to respond to a memory allocation function of the middleware called by the transparent file system, and determine, from the plurality of memory blocks, a target memory block configured to store the first data and the second data; The transparent file system is configured to write the first data into the target memory block.
5. The transparent encryption and decryption computing system according to claim 4, characterized in that: The transparent file system is further configured to call a memory release function of the middleware to release the target memory block after forwarding the second data according to the data operation request.
6. The transparent encryption and decryption computing system according to claim 5, characterized in that: The first data includes a plurality of sub-data; The middleware is configured to respond to a memory allocation function of the middleware called by the transparent file system, and determine a target memory block corresponding to each sub-data from the plurality of memory blocks; The transparent file system is configured to store each sub-data in its corresponding target memory block.
7. The transparent encryption and decryption computing system according to claim 5, characterized in that: The multiple memory blocks include a used memory block set and an unused memory block set; The middleware is configured to determine a target memory block configured to store the first data from an unused memory block set, and classify the target memory block into a used memory block set; The middleware is further configured to classify the target memory block into a set of unused memory blocks after releasing the target memory block.
8. The transparent encryption and decryption computing system according to claim 1, characterized in that: The transparent file system is configured to write data information and an encryption / decryption start flag associated with the first data into a data request queue set in the middleware in response to the data operation request; The middleware is configured to send data information associated with the first data in the data request queue and an encryption and decryption start flag to the heterogeneous computing program in an order in the data request queue; The heterogeneous computing program is configured to call the heterogeneous computing unit to perform decryption processing on the first data according to the data information and the encryption and decryption start flag.
9. The transparent encryption and decryption computing system according to claim 8, characterized in that: The middleware is configured to mark a memory block storing the second data according to data information of the first data corresponding to the second data; the middleware is provided with an output result queue, and the output result queue stores data information of the first data corresponding to the second data; the middleware is configured to send the second data to the transparent file system according to the order in the output result queue. System.
10. The transparent encryption and decryption computing system according to claim 1, characterized in that: The heterogeneous computing unit includes a programmable logic device and a board memory; Wherein, the programmable logic device is configured to perform encryption and decryption processing on the first data; The board memory is configured to cache the first data and the second data.
11. The transparent encryption and decryption computing system according to claim 1, characterized in that: The operating system and the heterogeneous computing unit perform data interaction via direct memory access technology; The transparent encryption and decryption computing system also includes: a direct memory access technology controller, configured to write the first data in the memory unit into the heterogeneous computing unit in response to a data write instruction of the heterogeneous computing program; And, in response to a data read instruction of the heterogeneous computing program, writing the second data into the memory unit.
12. A method for reading and writing data, characterized in that: The method is applied to a transparent encryption and decryption computing system based on heterogeneous computing, the transparent encryption and decryption computing system comprising: an operating system and a heterogeneous computing unit, the operating system comprising: a transparent file system and middleware deployed at the kernel layer, and a heterogeneous computing program deployed at the user layer, and the method comprises: In response to a data operation request, writing first data corresponding to the data operation request into a memory unit of the middleware; Sending the memory address of the first data in the memory unit to the heterogeneous computing program; the heterogeneous computing program is configured to write the first data in the memory unit into the heterogeneous computing unit according to the memory address, and the heterogeneous computing unit performs encryption and decryption processing to obtain second data; The second data returned by the heterogeneous computing unit is received, and the second data is sent to the transparent file system; the transparent file system is configured to forward the second data according to the data operation request.
13. The method according to claim 12, characterized in that The memory unit includes a plurality of memory blocks, and in response to the data operation request, writing the first data corresponding to the data operation request into the memory unit of the middleware includes: In response to a memory allocation function called by the transparent file system when receiving the data operation request, determining a target memory block set to store the first data from a plurality of memory blocks; The first data is written into the target memory block.
14. The method according to claim 13, characterized in that The method further comprises: In response to the transparent file system calling a memory release function after forwarding the second data, the target memory block is released.
15. The method according to claim 14, characterized in that The multiple memory blocks include a used memory block set and an unused memory block set, and determining a target memory block set to store the first data from the multiple memory blocks includes: Determine, from an unused memory block set, a target memory block set to store the first data, and move the target memory block from the unused memory block set to the used memory block set; The releasing of the target memory block comprises: The target memory block is moved from a used memory block set to an unused memory block set.
16. The method according to claim 13, characterized in that The receiving the second data returned by the heterogeneous computing unit and sending the second data to the transparent file system includes: receiving second data returned by the heterogeneous computing unit, and writing the second data into the target memory block; The second data in the target memory block is sent to the transparent file system.
17. The method according to claim 16, characterized in that The middleware is provided with an output result queue, the output result queue stores data information of the first data corresponding to the second data, and the sending the second data in the target memory block to the transparent file system includes: marking a target memory block storing the second data according to data information of the first data corresponding to the second data; The second data is sent to the transparent file system according to the order in the output result queue.
18. The method according to claim 12, characterized in that The middleware is provided with a data request queue, and the method further comprises: According to the data operation request, writing data information associated with the first data and an encryption / decryption start identification flag into the data request queue; According to the order in the data request queue, the data information associated with the first data and the encryption and decryption start identification flag are sent to the heterogeneous computing program; the heterogeneous computing program is configured to call the heterogeneous computing unit to encrypt the first data according to the data information associated with the first data and the encryption and decryption start identification flag.
19. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the method for reading and writing data as claimed in any one of claims 12 to 18 is implemented.
20. A non-volatile computer-readable storage medium, characterized in that: The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for reading and writing data as claimed in any one of claims 12 to 18 is implemented.
Citation Information
Patent Citations
Encryption and decryption method and device, computer readable storage medium and server
CN116861470A
Screen projection management method and device
CN117156190A
Transparent encryption and decryption computing system and method based on heterogeneous computing, equipment and medium
CN117349870A
Computer system including a transparent and secure file transform mechanism
US5584023A