IP Library Granted Patent US 12,223,068
Granted Patent B2
US 12,223,068 · App. 17/758,086 · Granted Feb 11, 2025

Secure computing control method, data packet processing method and device and system thereof

Inventors: Jie Liu (Shenzhen, CN); Haibo Wang (Shenzhen, CN); Guoqiang Wang (Shenzhen, CN); Yubin Xu (Shenzhen, CN)
Assignee: ZTE CORPORATION
G06F21/606G06F21/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,068
App. No.
17/758,086
Granted
Feb 11, 2025
Kind
B2
Abstract

A secure computing control method, a data packet processing method and device, and a system thereof are disclosed. The secure computing method may include: receiving a first data packet message for secure computing from a processor, the first data packet message including data packet information and secure computing configuration information corresponding to the data packet information; acquiring corresponding first data packet data from a memory according to the data packet information of the first data packet message; selecting a corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message; performing secure computing on the first data packet data by the selected security algorithm to generate secure computed second data packet data and a second data packet message corresponding to the second data packet data; transmitting the second data packet data to the memory; and transmitting the second data packet message to the processor.

Claims (85)

1. A secure computing control method, comprising:

receiving a first data packet message for secure computing from a processor, the first data packet message comprising data packet information and secure computing configuration information corresponding to the data packet information;

acquiring corresponding first data packet data from a memory according to the data packet information of the first data packet message;

selecting a corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message;

performing secure computing on the first data packet data by means of the selected security algorithm to generate secure computed second data packet data and a second data packet message corresponding to the second data packet data;

transmitting the second data packet data to the memory; and

transmitting the second data packet message to the processor;

wherein, the second data packet message comprises information about a data packet on which secure computing has been performed and secure computing processing information corresponding to the information about the data packet;

wherein, the performing of secure computing on the first data packet data by means of the selected security algorithm comprises:

performing secure computing on each piece of the first data packet data respectively, based on the message input queue according to the security algorithm corresponding to a respective one piece of first data packet data, which in turn comprises:

allocating at least one idle secure computing spatial resource for secure computing in an order of the first data packet message in the input queue; and

performing secure computing on each piece of the first data packet data respectively, according to the security algorithm corresponding to a respective one piece of first data packet data.

2. The secure computing control method of claim 1 , wherein the receiving of the first data packet message for secure computing from a processor comprises:

receiving at least one first data packet message for secure computing from the processer, and the at least one first data packet message forms a message input queue; and

the transmitting of the second data packet message to the processor comprises:

acquiring at least one second data packet message each corresponding to a respective one of the at least one first data packet message, forming the second data packet message into a message output queue, and transmitting the message output queue to the processor.

3. The secure computing control method of claim 1 , wherein the data packet information of the first data packet message comprises segment information of a data packet, the first data packet data comprises segment data corresponding to the segment information, and the acquiring of corresponding first data packet data from the memory according to the data packet information of the first data packet message comprises:

acquiring segment data of the corresponding data packet from the memory according to the segment information of the data packet, and

splicing the segment data to generate data packet cache data.

4. The secure computing control method of claim 3 , wherein the secure computing configuration information of the first data packet message comprises information of security algorithm to be selected, information of an order of processing by security algorithm, and security algorithm configuration information;

the selecting of the corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message comprises:

selecting and acquiring at least one corresponding security algorithm from the memory according to the secure computing configuration information corresponding to the first data packet message; and

the performing of secure computing on the first data packet data by means of the selected security algorithm comprises:

in response to one security algorithm being selected, performing single-stage secure computing, according to the secure computing configuration information, on the data packet cache data by means of the selected security algorithm, or

in response to a plurality of security algorithms being selected, performing multi-stage secure computing, according to the secure computing configuration information and in the processing order of security algorithms, on the data packet cache data by means of the plurality of security algorithms.

5. The secure computing control method of claim 1 , wherein the selecting the corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message comprises:

selecting at least one corresponding security algorithm from the memory according to the secure computing configuration information corresponding to the first data packet message, and

allocating each of the at least one security algorithm to a respective one of the at least one secure computing spatial resource.

6. A secure computing control apparatus, comprising:

a storage device, a processing unit and at least one computer program stored on the storage device and executable by the processing unit which, when executed by the processing unit, causes the processing unit to perform a secure computing control method comprising,

receiving a first data packet message for secure computing from a processor, the first data packet message comprising data packet information and secure computing configuration information corresponding to the data packet information;

acquiring corresponding first data packet data from a memory according to the data packet information of the first data packet message;

selecting a corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message;

performing secure computing on the first data packet data by means of the selected security algorithm to generate secure computed second data packet data and a second data packet message corresponding to the second data packet data;

transmitting the second data packet data to the memory; and

transmitting the second data packet message to the processor;

wherein, the second data packet message comprises information about a data packet on which secure computing has been performed and secure computing processing information corresponding to the information about the data packet; and

wherein, the performing of secure computing on the first data packet data by means of the selected security algorithm comprises:

performing secure computing on each piece of the first data packet data respectively, based on the message input queue according to the security algorithm corresponding to a respective one piece of first data packet data, which in turn comprises:

allocating at least one idle secure computing spatial resource for secure computing in an order of the first data packet message in the input queue; and

performing secure computing on each piece of the first data packet data respectively, according to the security algorithm corresponding to a respective one piece of first data packet data.

7. The secure computing control apparatus of claim 6 , wherein the receiving of the first data packet message for secure computing from a processor comprises:

receiving at least one first data packet message for secure computing from the processer, and the at least one first data packet message forms a message input queue;

the transmitting of the second data packet message to the processor comprises:

acquiring at least one second data packet message each corresponding to a respective one of the at least one first data packet message, forming the second data packet message into a message output queue, and transmitting the message output queue to the processor.

8. The secure computing control apparatus of claim 6 , wherein the data packet information of the first data packet message comprises segment information of a data packet, the first data packet data comprises segment data corresponding to the segment information, and the acquiring of corresponding first data packet data from the memory according to the data packet information of the first data packet message comprises:

acquiring segment data of the corresponding data packet from the memory according to the segment information of the data packet, and

splicing the segment data to generate data packet cache data.

9. The secure computing control apparatus of claim 8 , wherein the secure computing configuration information of the first data packet message comprises information of security algorithm to be selected, information of an order of processing by security algorithm, and security algorithm configuration information;

the selecting of the corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message comprises:

selecting and acquiring at least one corresponding security algorithm from the memory according to the secure computing configuration information corresponding to the first data packet message; and

the performing of secure computing on the first data packet data by means of the selected security algorithm comprises:

in response to one security algorithm being selected, performing single-stage secure computing, according to the secure computing configuration information, on the data packet cache data by means of the selected security algorithm, or

in response to a plurality of security algorithms being selected, performing multi-stage secure computing, according to the secure computing configuration information and in the processing order of security algorithms, on the data packet cache data by means of the plurality of security algorithms.

10. The secure computing control apparatus of claim 6 , wherein the selecting the corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message comprises:

selecting at least one corresponding security algorithm from the memory according to the secure computing configuration information corresponding to the first data packet message, and

allocating each of the at least one security algorithm to a respective one of the at least one secure computing spatial resource.

11. A non-transitory computer-readable storage medium, storing at least one computer program which, when executed by a processor, causes the processor to perform a secure computing control method comprising,

receiving a first data packet message for secure computing from a processor, the first data packet message comprising data packet information and secure computing configuration information corresponding to the data packet information;

acquiring corresponding first data packet data from a memory according to the data packet information of the first data packet message;

selecting a corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message;

performing secure computing on the first data packet data by means of the selected security algorithm to generate secure computed second data packet data and a second data packet message corresponding to the second data packet data;

transmitting the second data packet data to the memory; and

transmitting the second data packet message to the processor;

wherein, the second data packet message comprises information about a data packet on which secure computing has been performed and secure computing processing information corresponding to the information about the data packet; and

wherein, the performing of secure computing on the first data packet data by means of the selected security algorithm comprises:

performing secure computing on each piece of the first data packet data respectively, based on the message input queue according to the security algorithm corresponding to a respective one piece of first data packet data, which in turn comprises:

allocating at least one idle secure computing spatial resource for secure computing in an order of the first data packet message in the input queue; and

performing secure computing on each piece of the first data packet data respectively, according to the security algorithm corresponding to a respective one piece of first data packet data.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the receiving of the first data packet message for secure computing from a processor comprises:

receiving at least one first data packet message for secure computing from the processer, and the at least one first data packet message forms a message input queue;

the transmitting of the second data packet message to the processor comprises:

acquiring at least one second data packet message each corresponding to a respective one of the at least one first data packet message, forming the second data packet message into a message output queue, and transmitting the message output queue to the processor.

13. The non-transitory computer-readable storage medium of claim 11 , wherein the data packet information of the first data packet message comprises segment information of a data packet, the first data packet data comprises segment data corresponding to the segment information, and the acquiring of corresponding first data packet data from the memory according to the data packet information of the first data packet message comprises:

acquiring segment data of the corresponding data packet from the memory according to the segment information of the data packet, and

splicing the segment data to generate data packet cache data.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the secure computing configuration information of the first data packet message comprises information of security algorithm to be selected, information of an order of processing by security algorithm, and security algorithm configuration information;

the selecting of the corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message comprises:

selecting and acquiring at least one corresponding security algorithm from the memory according to the secure computing configuration information corresponding to the first data packet message; and

the performing of secure computing on the first data packet data by means of the selected security algorithm comprises:

in response to one security algorithm being selected, performing single-stage secure computing, according to the secure computing configuration information, on the data packet cache data by means of the selected security algorithm, or

in response to a plurality of security algorithms being selected, performing multi-stage secure computing, according to the secure computing configuration information and in the processing order of security algorithms, on the data packet cache data by means of the plurality of security algorithms.

15. The non-transitory computer-readable storage medium of claim 11 , wherein the selecting the corresponding security algorithm according to the secure computing configuration information corresponding to the first data packet message comprises:

selecting at least one corresponding security algorithm from the memory according to the secure computing configuration information corresponding to the first data packet message, and

allocating each of the at least one security algorithm to a respective one of the at least one secure computing spatial resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2022
From: LIU, JIE; WANG, HAIBO; WANG, GUOQIANG; XU, YUBIN
To: ZTE CORPORATION
Reel/Frame 060336/0970 →
Priority Claims (1)
CN 201911421497.3 · Dec 31, 2019 · national
Continuity (1)
Related Publication 20230033312A1 · Feb 2, 2023
References Cited (31)
US 7017042B1 · Ziai · 2006 [cited by examiner]
US 10164770B1 · Lee · 2018 [cited by examiner]
US 10498529B1 · Hashmi · 2019 [cited by examiner]
US 10826876B1 · Sinn · 2020 [cited by examiner]
US 20040128553A1 · Buer · 2004 [cited by examiner]
US 20050076228A1 · Davis · 2005 [cited by examiner]
US 20070289014A1 · Pyo · 2007 [cited by examiner]
US 20080028210A1 · Asano · 2008 [cited by examiner]
US 20080077793A1 · Tan · 2008 [cited by examiner]
US 20080270785A1 · Loprieno · 2008 [cited by examiner]
US 20090060197A1 · Taylor et al. · 2009 [cited by applicant]
US 20090113212A1 · Koehler · 2009 [cited by examiner]
US 20100217971A1 · Radhakrishnan et al. · 2010 [cited by applicant]
US 20110153985A1 · Saha · 2011 [cited by examiner]
US 20120011351A1 · Mundra et al. · 2012 [cited by applicant]
US 20120278615A1 · Liu · 2012 [cited by examiner]
US 20140331330A1 · Abhijeet · 2014 [cited by examiner]
US 20180103018A1 · Chauhan · 2018 [cited by examiner]
US 20190180041A1 · Bhunia et al. · 2019 [cited by applicant]
US 20210168138A1 · Paruchuri · 2021 [cited by examiner]
CN 103516684A · 2014 [cited by applicant]
CN 107491317A · 2017 [cited by applicant]
CN 107528690A · 2017 [cited by applicant]
CN 108616878A · 2018 [cited by applicant]
CN 110086752A · 2019 [cited by applicant]
KR 20070061329A · 2007 [cited by applicant]
The State Intellectual Property Office of People's Republic of China. First Office Action for CN Application No. 2019114214973 and English translation, mailed Jul. 20, 2023, pp. 1-14. [cited by applicant]
The State Intellectual Property Office of People's Republic of China. First Search Report for CN Application No. 2019114214973 and English translation, mailed Jul. 14, 2023, pp. 1-4. [cited by applicant]
International Searching Authority. International Search Report and Written Opinion for PCT Application No. PCT/CN2020/138355 and English translation, mailed Mar. 24, 2021, pp. 1-10. [cited by applicant]
European Patent Office. Extended European Search Report for EP Application No. 20910529.5, mailed May 10, 2023, pp. 1-9. [cited by applicant]
Wang, H., et al. “A Gbps IPSec SSL Security Processor Design and Implementation in an FPGA Prototyping Platform,” Journal of Signal Processing Systems for Signal, Image, and Video Technology, May 2009, vol. 58, No. 3, p… [cited by applicant]