PCIE (Peripheral Component Interface Express) password card, communication method and device thereof and medium
By designing a PCIE cryptographic card without integrating PCIE switch, integrating security algorithms and quantum-resistant algorithm engines, and using quantum random number generators, the traditional PCIE cryptographic card cannot resist quantum attacks and high hardware costs, achieving high security, low cost and efficient data processing effects.
Patent Information
- Application Number
- CN202510522042.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-06-27
AI Technical Summary
Traditional PCIE trusted password cards cannot resist quantum attacks and have high hardware costs, which weakens market competitiveness.
A PCIE password card is designed, and the high-speed data transmission between the main PCIE chip device and the slave PCIE chip device is realized using a method without the need for integrated PCIE switch. The cryptographic card integrates a security algorithm engine and a quantum-resistant algorithm engine, and uses a quantum random number generator to provide high security and low cost solutions.
It improves the quantum resistance of PCIE password cards, enhances security and reliability, reduces hardware costs, avoids the use of PCIE switches, and thus improves data processing efficiency.
Smart Images

Figure CN120223309A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer hardware, and particularly to a PCIE cryptographic card and its communication method, device, and medium. Background Art
[0002] In the current era of rapid digital development, the importance of information security has become increasingly prominent, especially in key fields such as servers, cryptographic machines, and network devices. With the rapid progress of quantum computing technology, the traditional cryptographic system is facing unprecedented challenges.
[0003] Traditional PCIE (Peripheral Component Interconnect Express, a high-speed serial computer expansion bus standard) trusted cryptographic cards, as key devices to ensure system security, have been widely used in many scenarios. However, most of the random numbers used by traditional PCIE trusted cryptographic cards during operation are pseudo-random numbers, with poor anti-attack capabilities; at the same time, traditional PCIE trusted cryptographic cards usually integrate a PCIE switch bridging chip to connect an FPGA (Field-Programmable Gate Array) and a main control chip, but the significant increase in hardware costs weakens the market competitiveness.
[0004] In this context, the development of quantum computing technology has added new variables to the field of cryptographic security. Quantum computers, with their supercomputing power, pose a serious threat to traditional cryptographic algorithms based on mathematical problems. Once quantum computers reach the practical stage, the existing cryptographic system may collapse instantly. Therefore, it is urgent to develop a PCIE anti-quantum cryptographic card that can not only resist quantum threats but also use quantum random number technology with high security, reliability, and low-cost advantages. This is not only related to the market performance of individual products but also closely related to the future development of the entire information security industry, becoming a key problem that technicians in this field urgently need to overcome. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a PCIE cryptographic card and its communication method, device, and medium, which can provide the anti-quantum ability of the cryptographic card, solve the problem that traditional PCIE cryptographic cards cannot resist quantum attacks, and improve the security and reliability of PCIE cryptographic cards; at the same time, by using a method that does not require integrating a PCIE switch, the interconnection and interoperability of multiple chips are realized. The specific solutions are as follows:
[0006] In a first aspect, the present application discloses a PCIE cryptographic card, including:
[0007] The main PCIe chip device includes a first PCIe endpoint port, a security algorithm engine, and a PCIe root complex port; the first PCIe endpoint port is used to communicate with the host computer, and the security algorithm engine is used to accelerate the operation of the security algorithm based on the first random number generated by the quantum random number generator;
[0008] The slave PCIe chip device includes a second PCIe endpoint port and an anti-quantum algorithm engine; the second PCIe endpoint port is used to connect to the PCIe root complex port on the main PCIe chip device, and the anti-quantum algorithm engine is used to perform calculations in a quantum computing environment based on the second random number generated by the quantum random number generator;
[0009] The quantum random number generator is used to generate random numbers based on the principles of quantum mechanics and provide them to the security algorithm engine and the anti-quantum algorithm engine.
[0010] In a second aspect, the present application discloses a communication method for a PCIe cryptographic card, which is applied to the aforementioned PCIe cryptographic card and includes:
[0011] Obtain the read / write operation instruction of the host computer;
[0012] Determine the base address register configuration of the first PCIe endpoint port controller in the PCIe cryptographic card, and based on the base address register configuration, determine the first mapping address of the security algorithm engine in the host computer and the second mapping address of the anti-quantum algorithm engine in the main PCIe chip device;
[0013] Use the anti-quantum algorithm engine to generate a first algorithm execution result for the read / write operation instruction, and based on the second mapping address, write the first algorithm execution result into the main PCIe chip device through the PCIe root complex port;
[0014] Use the security algorithm engine to generate a second algorithm execution result for the read / write operation instruction, and based on the first mapping address, return the first algorithm execution result and the second algorithm execution result to the host computer through the first PCIe endpoint port.
[0015] Optionally, the using the anti-quantum algorithm engine to generate a first algorithm execution result for the read / write operation instruction includes:
[0016] Set the corresponding anti-quantum algorithm type and the corresponding security level for the read / write operation instruction;
[0017] Based on the anti-quantum algorithm type and the security level, use the anti-quantum algorithm engine to generate a first algorithm execution result for the read / write operation instruction.
[0018] Optionally, in the process of using the anti-quantum algorithm engine to generate the first algorithm execution result for the read / write operation instruction, the following steps are further included:
[0019] Determine the algorithm request type when using the cryptographic service according to the read / write operation instruction, and perform calculations using the anti-quantum algorithm based on the algorithm request type; wherein, the algorithm request types include key generation, signature processing, de-encapsulation processing, and encryption / decryption processing.
[0020] Optionally, performing calculations using the anti-quantum algorithm based on the algorithm request type includes:
[0021] When the algorithm request type is key generation, use the anti-quantum algorithm engine to obtain quantum random numbers generated by a quantum random number generator through a quantum random number generator interface;
[0022] Based on the quantum random numbers, use the anti-quantum algorithm to generate a public-private key pair;
[0023] Output the public key in the public-private key pair to the host computer, and encrypt the private key in the public-private key pair using the root key of the key file system in the storage medium, and store the encrypted private key ciphertext in the key file system.
[0024] Optionally, performing calculations using the anti-quantum algorithm based on the algorithm request type includes:
[0025] When the algorithm request type is signature processing, obtain the data to be signed sent by the host computer;
[0026] Extract the private key ciphertext from the key file system, and decrypt the private key ciphertext using the root key to obtain the corresponding private key plaintext;
[0027] Use the anti-quantum algorithm engine to perform signature processing on the data to be signed based on the private key plaintext, and return the generated signature result to the host computer.
[0028] Optionally, performing calculations using the anti-quantum algorithm based on the algorithm request type includes:
[0029] When the algorithm request type is de-encapsulation processing, obtain the data to be de-encapsulated sent by the host computer;
[0030] Extract the de-encapsulation key ciphertext from the key file system, and decrypt the de-encapsulation key ciphertext using the root key to obtain the corresponding de-encapsulation key plaintext;
[0031] Using the anti - quantum algorithm engine, perform an anti - quantum algorithm on the data to be unpacked based on the plaintext of the unpacking key, and return the generated unpacking result to the host computer.
[0032] Optionally, perform calculations using an anti - quantum algorithm based on the algorithm request type, including:
[0033] When the algorithm request type is encryption / decryption processing, obtain the data to be encrypted / decrypted sent by the host computer;
[0034] Extract the encrypted / decrypted key ciphertext from the key file system, and use the root key to decrypt the encrypted / decrypted key ciphertext to obtain the corresponding plaintext of the encrypted / decrypted key;
[0035] Using the anti - quantum algorithm engine, perform an anti - quantum algorithm on the data to be encrypted / decrypted based on the plaintext of the encrypted / decrypted key, and return the generated encryption / decryption result to the host computer.
[0036] In a third aspect, the present application discloses a communication device for a PCIE cryptographic card, which is applied to the aforementioned PCIE cryptographic card, and includes:
[0037] An instruction acquisition module, configured to acquire read - write operation instructions from the host computer;
[0038] A data path determination module, configured to determine the base address register configuration of the first PCIE endpoint port controller in the PCIE cryptographic card, and determine the first mapping address of the security algorithm engine in the host computer and the second mapping address of the anti - quantum algorithm engine in the main PCIE chip device according to the base address register configuration;
[0039] A first data transmission module, configured to use the anti - quantum algorithm engine to generate a first algorithm execution result for the read - write operation instruction, and write the first algorithm execution result into the main PCIE chip device through the PCIE root complex port based on the second mapping address;
[0040] A second data transmission module, configured to use the security algorithm engine to generate a second algorithm execution result for the read - write operation instruction, and return the first algorithm execution result and the second algorithm execution result to the host computer through the first PCIE endpoint port based on the first mapping address.
[0041] In a fourth aspect, the present application discloses a computer - readable storage medium for storing a computer program; wherein when the computer program is executed by a processor, it implements the communication method of the PCIE cryptographic card as described above.
[0042] The present application provides a PCIE cryptographic card, including: a main PCIE chip device, which includes a first PCIE endpoint port, a security algorithm engine, and a PCIE root complex port; the first PCIE endpoint port is used to communicate with a host computer, and the security algorithm engine is used to perform operation acceleration of security algorithms based on the first random number generated by a quantum random number generator; a slave PCIE chip device, which includes a second PCIE endpoint port and an anti-quantum algorithm engine; the second PCIE endpoint port is used to connect to the PCIE root complex port on the main PCIE chip device, and the anti-quantum algorithm engine is used to perform calculations in a quantum computing environment based on the second random number generated by the quantum random number generator; the quantum random number generator is used to generate random numbers provided to the security algorithm engine and the anti-quantum algorithm engine based on the principles of quantum mechanics.
[0043] Advantages of the present application: In the PCIE cryptographic card provided by the present application, the PCIE root complex port allows high-speed data transmission between the main PCIE chip device and the slave PCIE chip device, eliminating the need for a PCIE switch bridging chip, improving data processing efficiency, reducing costs, and enhancing reliability. In addition, in the PCIE cryptographic card, not only is the operation acceleration of traditional security algorithms for data operations achieved using the security algorithm engine, but also, on this basis, an anti-quantum algorithm engine is added, and by integrating the anti-quantum algorithm and the quantum random number generator, the security of the PCIE cryptographic card is improved.
[0044] In addition, a communication method, device, and storage medium for a PCIE cryptographic card provided by the present application correspond to the above-mentioned PCIE cryptographic card, and the effects are the same. Description of the Drawings
[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative efforts.
[0046] Figure 1 It is a schematic structural diagram of a PCIE cryptographic card disclosed in the present application;
[0047] Figure 2 It is a schematic structural diagram of a specific main PCIE chip device disclosed in the present application;
[0048] Figure 3 It is a schematic structural diagram of a specific slave PCIE chip device disclosed in the present application;
[0049] Figure 4 Schematic diagram of the structure of a key file system disclosed in this application;
[0050] Figure 5 Flowchart of the communication method of a PCIE cryptographic card disclosed in this application;
[0051] Figure 6 Schematic diagram of the data path of a quantum-resistant PCIE cryptographic card disclosed in this application;
[0052] Figure 7 Schematic diagram of the PCIE configuration space disclosed in this application;
[0053] Figure 8 Flowchart of the data processing of a quantum-resistant algorithm disclosed in this application;
[0054] Figure 9 Schematic diagram of the structure of the communication device of a PCIE cryptographic card disclosed in this application. Detailed implementation manners
[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0056] Currently, traditional PCIE trusted cryptographic cards usually integrate a PCIE switch bridging chip to connect the FPGA and the main control chip, significantly increasing the hardware cost and weakening the market competitiveness. At the same time, the development of quantum computing technology has added new variables to the field of password security, and the problem that traditional PCIE cryptographic cards cannot resist quantum attacks.
[0057] Therefore, this application provides a PCIE cryptographic card, which can provide the quantum-resistant ability of the cryptographic card, improve the security and reliability of the PCIE cryptographic card; at the same time, by using a method that does not require integrating a PCIE switch, the interconnection of multiple chips is realized.
[0058] The embodiments of the present invention disclose a PCIE cryptographic card, see Figure 1 as shown, including:
[0059] The main PCIE chip device includes a first PCIE endpoint port, a security algorithm engine, and a PCIE root complex port; the first PCIE endpoint port is used to communicate with the host computer, and the security algorithm engine is used to perform operation acceleration of the security algorithm based on the first random number generated by the quantum random number generator.
[0060] In this embodiment, the main PCIE chip device is the main control chip of the PCIE cryptographic card and is usually responsible for the control of the overall operation. The main PCIE chip device establishes a connection with the host computer through its first PCIE endpoint port to achieve data interaction and communication.
[0061] The main PCIE chip device also includes a security algorithm engine and a PCIE root complex port. The security algorithm engine can accelerate the operation when using traditional security algorithms to perform algorithm operations, improving the operation efficiency. The security algorithm engine also includes a DMA (Data Memory Access) module and a security algorithm module; the DMA module is used to quickly transfer data between the host computer CPU (Central Processing Unit) and the device for direct data encryption and decryption, and directly write the encrypted and decrypted data into the host memory through the PCIE bus; the security algorithm module is used to process and execute traditional block algorithms, public key algorithms, hash algorithms, etc.
[0062] In a feasible implementation, the block algorithm, i.e., the symmetric algorithm, may include algorithms such as SM1, SM4, AES (Advanced Encryption Standard), DES (Data Encryption Standard), etc.; the public key algorithm, i.e., the asymmetric algorithm, may include algorithms such as SM2, RSA, etc.; the hash algorithm may include algorithms such as SM3, SHA1, SHA256, SHA384, SHA512, etc.
[0063] Such as Figure 2The following is a schematic structural diagram of a specific main PCIE chip device provided exemplarily in this embodiment, and its type can be a CCP1080T main control chip. This chip supports national cryptography algorithms such as SM1, SM2, SM3, and SM4, and can provide high-speed cryptographic operation services for multi-threaded and multi-process processing of various trusted computing security platforms, meeting their requirements for functions such as digital signature / verification, asymmetric / symmetric encryption and decryption, data integrity verification, true random number generation, key generation and management, etc., to ensure the security, authenticity, integrity, and non-repudiation of sensitive data. In addition, there are two storage media involved in the chip, specifically including EMMC (Embedded Multi-Media Card) media and FLASH media; the EMMC media is used to store the firmware program of the anti-quantum cryptographic card; the FLASH media is used for the storage of the cryptographic card key file and system management. Specifically, the FLASH media is used to implement a secure and reliable key file system, and all user key pairs and key encryption keys (KEK) and other data are encrypted by the root key and stored in the key file system in ciphertext form.
[0064] Figure 2It also provides more specific types of data communication interfaces, namely PCIE interface, USB (Universal Serial Bus) interface, SPI (Serial Peripheral Interface), and UART (Universal Asynchronous Receiver / Transmitter) interface. Thus, the appropriate interface can be selected according to the specific type of data to be processed and forwarded to the inside of the main control chip for processing. At the same time, a QRNG (Quantum Random Number Generator) chip is adopted, which is dedicated to generating quantum random numbers for use by the security algorithm engine. The security algorithm engine calculates and obtains the random numbers generated by the quantum random number generator through the SPI (Serial Peripheral Interface) simulated by GPIO (General Purpose Input / Output). In addition, C9800 in the figure is the core of CCP1080T. CCP1080T adopts a 64-bit high-performance dual-core C9800 processor. The C9800 processor core adopts a 64-bit superscalar PowerPC architecture with dual-issue and 7-stage pipeline, supports an SMP (Symmetric Multi-Processing) system with hardware memory consistency, and is a domestic self-controlled processor core; JTAG (Joint Test Action Group) is an interface standard for debugging electronic devices and is widely used in the development and maintenance of embedded systems and microcontrollers; RAM (Random Access Memory), ROM (Read-Only Memory), and DDR (Double Data Rate dynamic random access memory) are common types of memories.
[0065] From the PCIE chip device, including the second PCIE endpoint port and the anti-quantum algorithm engine; the second PCIE endpoint port is used to connect to the PCIE root complex port on the main PCIE chip device, and the anti-quantum algorithm engine is used to perform calculations in a quantum computing environment based on the second random number generated in the quantum random number generator.
[0066] In this embodiment, the slave PCIE chip device focuses on the implementation of the encryption algorithm and data processing. The second PCIE endpoint port in the slave PCIE chip device is used to closely connect with the above-mentioned main PCIE chip device to achieve stable communication between the two. The second PCIE endpoint port is directly connected to the PCIE root complex port of the main PCIE chip device. This unique connection mode cleverly avoids the use of the PCIE Switch chip, while ensuring that the password card has excellent IO throughput and guarantees high-speed and smooth data transmission. The anti-quantum algorithm engine in the slave PCIE chip device is specially designed for the quantum computing environment to ensure data security in the quantum computing environment. The anti-quantum algorithm engine includes anti-quantum algorithms such as Kyber and Dilithium, which are implemented by loading algorithm code through FPGA, support algorithm update function, and the application program accesses a unified interface library to use the anti-quantum algorithm.
[0067] The following is a description of the PCIE chip device with a specific example. The PCIE chip device takes FPGA as an example. Figure 3 The FPGA chip used in this embodiment uses a PCIE interface to communicate with Figure 2 The main PCIE chip device in the PCIE interface is connected to the PCIE interface. The PCIE interface is the second PCIE endpoint port, and the PCIE root complex port on the main PCIE chip device is also a PCIE interface. The PCIE interface is used to connect the FPGA and the main control chip to achieve high-bandwidth, low-latency data throughput.
[0068] Furthermore, the FPGA includes a FLASH storage medium for storing the FPGA's running algorithm code, that is, the executable program file. The built-in RAM of the FPGA is used to cache and process the above data. Among them, the FPGA's FLASH storage medium is connected to the main control chip through the SPI interface, and the SPI interface of the main control chip is used to update the FPGA algorithm code. At the same time, in the FPGA, the anti-quantum algorithm engine calculates and obtains the random number generated by the quantum random number generator through the QRNG (Quantum Random Number Generator) interface. In addition, the SGDMA (Scatter-GatherDirect Memory Access) shown in the figure is a linked list-based DMA (direct memory access) technology used to process physically discontinuous storage space. The scatter-aggregation mechanism allows data to be stored in memory in a dispersed manner, and these dispersed data blocks are connected through the descriptor linked list to achieve efficient data transmission.
[0069] A quantum random number generator for generating random numbers provided to the secure algorithm engine and the quantum-resistant algorithm engine based on the principles of quantum mechanics.
[0070] In this embodiment, the quantum random number generator relies on the principles of quantum mechanics to extract ultra-high-quality random numbers from the intrinsic random quantum shot noise, and accurately deliver these random numbers to the quantum-resistant algorithm engine and the secure algorithm engine, providing a solid foundation of randomness for the operation of various algorithms and enhancing the security and reliability of the entire cryptographic card system. Therefore, this random number is the core for generating keys in information security and is an essential module for each information security encryption card. The data throughput rate and random performance of the random number directly determine the reliability of information security.
[0071] In a feasible implementation, the quantum random number chip CQWNG10 can be used. It is a quantum random number chip built by the 32-bit high-performance and low-power central processor CS0.
[0072] Advantages of this application: In the PCIE cryptographic card provided in this application, the PCIE root complex port allows high-speed data transmission between the main PCIE chip device and the slave PCIE chip device without using a PCIE switch bridging chip, improving data processing efficiency, reducing costs, and enhancing reliability. In addition, in the PCIE cryptographic card, not only does the secure algorithm engine achieve operation acceleration for data operations using traditional security algorithms, but on this basis, a quantum-resistant algorithm engine is added. By integrating quantum-resistant algorithms and quantum random number generators, the security of the PCIE cryptographic card is improved.
[0073] Based on the foregoing embodiments, a key file system is embedded in the storage medium of the PCIE cryptographic card, and the key file system can provide efficient and secure key storage and management functions for the PCIE cryptographic card. As Figure 4 shown is a schematic diagram of a key management structure provided in this embodiment.
[0074] Among them, the root key is located at the bottom of the key management hierarchical structure and is the highest-level key. The root key is used to encrypt the key encryption key (KEK) to ensure the security of the KEK. If the root key is leaked, the security of the entire key system will be seriously threatened. The key encryption key (KEK) is located between the root key and the user key pair and is used to encrypt and protect the user key pair. The user key pair consists of a pair of keys, namely the public key and the private key. These two keys are mathematically related. The public key can be made public to others for encrypting information or verifying digital signatures; the private key is strictly kept confidential by the user and is used to decrypt the information encrypted with the public key or generate digital signatures. The session key is a temporary key generated during a specific communication session and is used to encrypt and decrypt the data in the session. The session key is usually discarded after the session ends, and a new session key will be generated for the next session. Except for the session key, all data such as the user key pair and the key encryption key (KEK) are encrypted by the system protection root key and stored in the key file system in ciphertext form.
[0075] Furthermore, the embodiment of the present application discloses a communication method for a PCIe cryptographic card. Refer to Figure 5 as shown, which is applied to the aforementioned PCIe cryptographic card. The method includes:
[0076] Step S11: Obtain the read / write operation instruction of the host computer.
[0077] In the embodiment of the present application, when applied to the PCIe cryptographic card, the following is described in conjunction with Figure 6 for illustration. The main control chip 102 is the main PCIe chip device, and the FPGA 106 is the slave PCIe chip device.
[0078] The host computer 101 is used to run the relevant host computer software of the PCIe cryptographic card for relevant secure data processing, etc.; the PCIe root complex port included therein is used to connect to the first PCIe endpoint port on the PCIe cryptographic card and communicate with the main control chip to transmit the read / write operation instructions of the host computer, such as data encryption, decryption, and key management. In this embodiment, the PCIe root complex port of the host computer and the first PCIe endpoint port on the PCIe cryptographic card use the PCIe interface to connect the host computer and the main control chip.
[0079] It should be noted that the read / write operation instruction usually carries a data request sent by the host computer. This data request is transmitted to the main control chip through the PCIe interface. This data request is a data protocol packet defined by the present application for the host computer to send data, and includes a command header, a total length, a characteristic value, a command word, a data length, and a data segment, etc.; similarly, for the data format of this data request, the present application also defines a data protocol packet for the host computer to receive data, which includes a command header, a total length, a command word, a characteristic value, and a data segment, etc.
[0080] Step S12: Determine the base address register configuration of the first PCIe endpoint port controller in the PCIe cryptographic card, and determine the first mapping address of the secure algorithm engine in the host computer and the second mapping address of the quantum-resistant algorithm engine in the main PCIe chip device according to the base address register configuration.
[0081] As Figure 7 shown is a schematic diagram of the PCIe controller configuration space exemplarily provided in this embodiment. This configuration space is a section of memory space of the controller, and the system allocates 4KB of configuration space for each PCIe device. Among them, the first 256 bytes are configuration registers compatible with PCI, and the space from 256 bytes to 4KB is the PCIe extended configuration space. Figure 7 The registers shown in include base address register 0, base address register 1, base address register 2, base address register 3, base address register 4, and base address register 5. The above registers are used for PCIe resource allocation and define the position of the device's memory space or I / O space in the system address space; of course, in addition to the above registers, it also includes device identification information for device identification, such as device ID and manufacturer ID, and registers for status monitoring and device configuration, etc., which will not be elaborated here.
[0082] In the embodiment of the present application, the host computer 101 is connected to the PCIe endpoint port of the main control chip 102 through the PCIe root complex port. By configuring the base address register of the PCIe endpoint port controller of the main control chip, the registers of the secure algorithm engine 104 and the AXI DMA 105 in the main control chip are mapped to the host computer. Among them, the AXI DMA module is used to transfer data, command instructions, etc. between the host computer and the main control chip to achieve access to the quantum-resistant cryptographic card. The PCIe root complex port of the main control chip is connected to the PCIe endpoint port of the FPGA. By configuring the base address register of the above PCIe controller, the registers of the quantum-resistant algorithm engine 108 and the SGDMA 109 of the FPGA are mapped to the main control chip. In addition, the system bus 103 in the main control chip and the system bus 107 in the FPGA are a group of common communication trunks used to connect various functional components inside the computer and are responsible for transmitting information between components. These information include data information, address information, and control information.
[0083] Exemplarily, assume that the address where the secure algorithm engine register is mapped to the host computer is addr_A. Then, the read and write operations of the host computer on addr_A are to operate the registers of the secure algorithm engine; assume that the address where the AXI DMA register is mapped to the host computer is addr_B. Then, the read and write operations of the host computer on addr_B are to operate the AXI DMA register.
[0084] Similarly, assume that the anti-quantum algorithm engine register is mapped to addr_C of the main control chip, and the SGDMA register is mapped to addr_D of the main control chip. Then, accessing addr_C and addr_D is equivalent to accessing the anti-quantum algorithm register and the SGDMA register. Through the above-mentioned PCIE address mapping, a complete data path from the host computer to the main control chip and then to the FPGA is established. When public key operations, block operations, or hash operations need to be performed, the data stream is transmitted to the security algorithm engine of the main control chip for processing. When anti-quantum algorithm operations need to be performed, the data stream is transmitted to the anti-quantum algorithm engine of the FPGA for processing.
[0085] Step S13: Use the anti-quantum algorithm engine to generate a first algorithm execution result for the read / write operation instruction, and based on the second mapping address, write the first algorithm execution result into the main PCIE chip device through the PCIE root complex port.
[0086] It can be understood that after receiving the read / write operation instruction sent by the host computer, it will be parsed according to the pre-defined data protocol format to obtain the algorithm request when using the cryptographic service. Specifically, it includes two types of security algorithm requests. One is traditional block algorithms, hash algorithms, and public key algorithms, which are processed in the security algorithm engine of the main control chip. The other is anti-quantum algorithms, including the Kyber algorithm and the Dilithium algorithm, but not limited to the above-mentioned quantum algorithms. The Kyber algorithm includes Kyber 512, Kyber 768, and Kyber 1024. The shared key established through Kyber can be combined with symmetric cryptographic algorithms to perform encryption and decryption functions in secure communication. The Dilithium algorithm is based on difficult problems on modular lattices and is particularly suitable for digital signature scenarios. These algorithms are transmitted through PCIE to the anti-quantum algorithm engine of the FPGA chip for processing, that is, completed in the above-mentioned FPGA, implemented by loading algorithm code in the FPGA, supporting the algorithm update function, and the application program can use the anti-quantum algorithm by accessing the unified interface library. This application focuses on the processing of anti-quantum algorithms.
[0087] It should be noted that after parsing the read / write operation instruction, when using the anti-quantum algorithm engine for calculation, the corresponding anti-quantum algorithm type and the corresponding security level will be set for the read / write operation instruction. The anti-quantum algorithm type includes the Kyber algorithm and the Dilithium algorithm, but not limited to the above two anti-quantum algorithms. The security level is the strength of the algorithm's resistance to attacks, usually expressed in bits. The higher the security level, the more difficult it is for the algorithm to be cracked. Then, based on the anti-quantum algorithm type and the security level, the anti-quantum algorithm engine is used to generate the corresponding algorithm execution result for the read / write operation instruction.
[0088] In the embodiments of the present application, when using an anti-quantum engine for computing, the processing types and functions corresponding to the algorithm requests include four anti-quantum algorithm processing sub-processes. Specifically, when using an anti-quantum engine, the algorithm request types when using cryptographic services include key generation, signature processing, decapsulation processing, and encryption / decryption processing. Combining Figure 8 for illustration, the corresponding processing sub-processes are as follows:
[0089] In the first specific embodiment, it is the key generation process of the anti-quantum algorithm, including the following steps:
[0090] Step 1: When the algorithm request type is key generation, use the anti-quantum algorithm engine to obtain quantum random numbers generated by a quantum random number generator through a quantum random number generator interface;
[0091] Step 2: Based on the quantum random numbers, use the anti-quantum algorithm to generate a public-private key pair;
[0092] Step 3: Output the public key in the public-private key pair to the host computer, and encrypt the private key in the public-private key pair using the root key of the key file system in the storage medium, and store the encrypted private key ciphertext in the key file system.
[0093] It can be seen that quantum random numbers are obtained through the QRNG interface, and an anti-quantum algorithm is used to generate a pair of public and private keys for subsequent encryption or signature processes.
[0094] In the second specific embodiment, it is the signature process of the anti-quantum algorithm, including the following steps:
[0095] Step 1: When the algorithm request type is signature processing, obtain the data to be signed sent by the host computer;
[0096] Step 2: Extract the private key ciphertext from the key file system, and decrypt the private key ciphertext using the root key to obtain the corresponding private key plaintext;
[0097] Step 3: Use the anti-quantum algorithm engine to perform anti-quantum algorithm signature processing on the data to be signed based on the private key plaintext, and return the generated signature result to the host computer.
[0098] It can be seen that in the storage medium, all data such as keys are encrypted by the root key and stored in the key file system in ciphertext form. Therefore, when processing the signature process, the algorithm request sent by the host computer will carry the data to be signed and the corresponding private key identifier. Extract the signature private key ciphertext corresponding to the private key identifier in the storage medium, and use the root key to decrypt the signature private key to obtain the signature private key plaintext; then, based on the private key plaintext, use the private key to perform signature processing on the data to be signed, and return the signature result to the host computer after the processing is completed.
[0099] In the third specific implementation manner, it is the decapsulation process of the quantum-resistant algorithm, including the following steps:
[0100] Step 1: When the algorithm request type is decapsulation processing, obtain the data to be decapsulated sent by the host computer;
[0101] Step 2: Extract the decapsulation key ciphertext from the key file system, and use the root key to decrypt the decapsulation key ciphertext to obtain the corresponding decapsulation key plaintext;
[0102] Step 3: Use the quantum-resistant algorithm engine to perform a quantum-resistant algorithm on the data to be decapsulated based on the decapsulation key plaintext for decapsulation processing, and return the generated decapsulation result to the host computer.
[0103] It can be seen that when processing the decapsulation process, the host computer will send the data to be decapsulated and the target decapsulation key ID; the cryptographic card obtains the decapsulation key ciphertext stored in the storage medium according to the target decapsulation key ID, uses the root key to decrypt the decapsulation key to obtain the decapsulation key plaintext, and performs decapsulation processing on the data to be decapsulated using the decapsulation key by executing the quantum-resistant algorithm, such as extracting the session key, and returns the decapsulation result to the host computer after the processing is completed. Among them, the decapsulation key can be a private key or a symmetric key, specifically depending on how the host computer encapsulates the data to be decapsulated.
[0104] In the fourth specific implementation manner, it is the encryption / decryption process of the quantum-resistant algorithm, including the following steps:
[0105] Step 1: When the algorithm request type is encryption / decryption processing, obtain the data to be encrypted / decrypted sent by the host computer;
[0106] Step 2: Extract the encryption / decryption key ciphertext from the key file system, and use the root key to decrypt the encryption / decryption key ciphertext to obtain the corresponding encryption / decryption key plaintext;
[0107] Step 3: Using the anti-quantum algorithm engine, perform an anti-quantum algorithm on the data to be encrypted / decrypted based on the plaintext of the encryption / decryption key, and return the generated encryption / decryption result to the host computer.
[0108] It can be seen that when processing the encryption / decryption process, the host computer sends the data to be processed, including the specific operation type (encryption / decryption) and the corresponding key ID; the cryptographic card obtains the ciphertext of the encryption / decryption key stored in the storage medium according to the key ID, decrypts the encryption / decryption key using the root key to obtain the plaintext of the encryption / decryption key, executes the anti-quantum algorithm, and uses the encryption / decryption key to perform encryption / decryption processing on the data to be encrypted / decrypted. After the processing is completed, the encryption / decryption result is returned to the host computer.
[0109] It should be noted that the above process supports parallel scheduling. The cryptographic card can achieve concurrent processing of multiple processes through hardware resource isolation, and the plaintext of the key only exists in the secure area of the cryptographic card. Further, since all keys are encrypted by the root key, in a feasible implementation, the corresponding instruction priorities can be set to allocate the root key decryption resources during parallel execution, such as decryption > signature, and only one process is allowed to access the root key at the same time. At the same time, lifecycle management is performed on the root key, supporting regular updates (such as the key rotation algorithm based on timestamps), and the business process is not interrupted during the update process. In addition, to further improve security, a response timeout mechanism can be set. The cryptographic card sets a hard timeout for single-process processing, and automatically clears the plaintext of the key in the cache after the timeout. In this way, the secure concurrency of parallel processes is achieved, breaking through the performance bottleneck of the single-threaded cryptographic card.
[0110] Step S14: Using the security algorithm engine, generate a second algorithm execution result for the read / write operation instruction, and based on the first mapped address, return the first algorithm execution result and the second algorithm execution result to the host computer through the first PCIE endpoint port.
[0111] In this embodiment, before the quantum computer becomes mature, the cryptographic card can support both traditional encryption and anti-quantum encryption to ensure long-term data security. After the anti-quantum algorithm operation is completed, the first algorithm execution result is written into the memory area of the main control chip through the DMA unit. Then, the second algorithm execution result generated for the read / write operation instruction by using the security algorithm engine is written into the memory area specified by the host computer together.
[0112] Advantages of the present application: In the PCIe cryptographic card provided by the present application, the PCIe root complex port allows high-speed data transmission between the main PCIe chip device and the slave PCIe chip device, eliminating the need for a PCIe switch bridging chip, improving data processing efficiency, reducing costs, and enhancing reliability. Additionally, in the PCIe cryptographic card, not only is the operation acceleration of traditional security algorithms for data operations achieved using a security algorithm engine, but also an anti-quantum algorithm engine is added on this basis. By integrating the anti-quantum algorithm and the quantum random number generator, the security of the PCIe cryptographic card is improved.
[0113] It should be noted that both the PCIe root complex port and the PCIe endpoint port include an I / O address translation unit. The I / O address translation unit is used to convert the address space of the device itself to the host memory address space to ensure that data can be correctly stored in the corresponding location of the host memory and is used to convert and transfer data for the PCIe bus address. Therefore, after the PCIe cryptographic card receives the read / write operation instruction from the host computer through the first PCIe endpoint port, it also includes the step of address translation, specifically:
[0114] Using the address translation module to translate the read / write operation instruction into a bus-recognizable address, which is achieved by looking up the PCIe address and bus address conversion table;
[0115] Using the address translation module to translate the read / write operation instruction into an endpoint-recognizable address and encapsulating the endpoint-recognizable address and the read / write operation instruction into a PCIe protocol message.
[0116] Among them, the encapsulated PCIe protocol message is transmitted to the main control chip through the PCIe endpoint port of the main control chip; the encapsulated PCIe protocol message is transmitted to the PCIe endpoint port of the FPGA through the PCIe root complex port of the main control chip. After the PCIe protocol message is transmitted to the main control chip, calculations are performed using the security algorithm engine, and the result is written into the memory area specified by the external host through the DMA unit; after the PCIe protocol message is transmitted to the FPGA, calculations are performed using the anti-quantum algorithm engine, and the result is written into the memory area of the main control chip through the DMA unit. It can be seen that the read / write operation instructions sent by the host computer are transmitted layer by layer based on the translated address, and then after calculations by different algorithm engines, based on the mapped address, the I / O address translation unit is used for address conversion to achieve correct data writing.
[0117] Correspondingly, the embodiment of the present application also discloses a communication device for a PCIe cryptographic card. Refer to Figure 9 As shown, applied to the aforementioned PCIe cryptographic card, the device includes:
[0118] An instruction acquisition module 11, configured to acquire the read / write operation instruction of the host computer;
[0119] A data path determination module 12 is configured to determine the base address register configuration of the first PCIe endpoint port controller in the PCIe cryptographic card, and determine the first mapping address of the security algorithm engine in the host computer and the second mapping address of the quantum-resistant algorithm engine in the main PCIe chip device according to the base address register configuration;
[0120] A first data transmission module 13 is configured to generate a first algorithm execution result for the read / write operation instruction by using the quantum-resistant algorithm engine, and write the first algorithm execution result into the main PCIe chip device through the PCIe root complex port based on the second mapping address;
[0121] A second data transmission module 14 is configured to generate a second algorithm execution result for the read / write operation instruction by using the security algorithm engine, and return the first algorithm execution result and the second algorithm execution result to the host computer through the first PCIe endpoint port based on the first mapping address.
[0122] Among them, for the more specific working processes of the above-mentioned various modules, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0123] Advantages of the present application: In the PCIe cryptographic card provided by the present application, the PCIe root complex port allows high-speed data transmission between the main PCIe chip device and the slave PCIe chip device, without using a PCIe switch bridging chip, improving data processing efficiency, reducing costs, and enhancing reliability. In addition, in the PCIe cryptographic card, not only is the security algorithm engine used to accelerate the data operation of traditional security algorithms, but also a quantum-resistant algorithm engine is added on this basis. By integrating the quantum-resistant algorithm and the quantum random number generator, the security of the PCIe cryptographic card is improved.
[0124] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium. The computer-readable storage medium mentioned here includes random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, magnetic disks, or optical disks, or any other form of storage medium known in the technical field. Among them, when the computer program is executed by a processor, the communication method of the foregoing PCIe cryptographic card is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0125] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0126] The steps of the communication method or algorithm of the PCIE cryptographic card described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0127] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0128] The above has introduced in detail a PCIE cryptographic card and its communication method, device, and medium provided by the present invention. Specific examples are used herein to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A PCIE password card, characterized in that: include: A main PCIE chip device, including a first PCIE endpoint port, a security algorithm engine, and a PCIE root complex port; The first PCIE endpoint port is used to communicate with a host computer, and the security algorithm engine is used to accelerate the operation of the security algorithm based on the first random number generated by the quantum random number generator; From the PCIE chip device, including the second PCIE endpoint port and the quantum-resistant algorithm engine; The second PCIE endpoint port is used to connect to the PCIE root complex port on the main PCIE chip device, and the anti-quantum algorithm engine is used to perform calculations in a quantum computing environment based on the second random number generated by the quantum random number generator; The quantum random number generator is used to generate random numbers provided to the security algorithm engine and the anti-quantum algorithm engine based on the principles of quantum mechanics.
2. A communication method for a PCIE cryptographic card, characterized in that: The PCIE cryptographic card as claimed in claim 1 comprises: Get the read and write operation instructions of the host computer; Determine the base address register configuration of the first PCIE endpoint port controller in the PCIE cryptographic card, and determine the first mapping address of the security algorithm engine in the host computer and the second mapping address of the anti-quantum algorithm engine in the main PCIE chip device according to the base address register configuration; Generate a first algorithm execution result for the read and write operation instruction using the quantum-resistant algorithm engine, and write the first algorithm execution result into the main PCIE chip device through a PCIE root complex port based on the second mapping address; The security algorithm engine is used to generate a second algorithm execution result for the read and write operation instruction, and based on the first mapping address, the first algorithm execution result and the second algorithm execution result are returned to the host computer through the first PCIE endpoint port.
3. The communication method of the PCIE cryptographic card according to claim 2, characterized in that: The step of using the quantum-resistant algorithm engine to generate a first algorithm execution result for the read and write operation instruction includes: Setting a corresponding quantum-resistant algorithm type and a corresponding security level for the read and write operation instructions; Based on the quantum-resistant algorithm type and the security level, the quantum-resistant algorithm engine is used to generate a first algorithm execution result for the read and write operation instructions.
4. The communication method of the PCIE cryptographic card according to claim 2, characterized in that: The process of using the quantum-resistant algorithm engine to generate the first algorithm execution result for the read-write operation instruction also includes: Determine the algorithm request type when using the cryptographic service according to the read and write operation instructions, and use the quantum-resistant algorithm for calculation based on the algorithm request type; wherein the algorithm request type includes key generation, signature processing, decapsulation processing, and encryption / decryption processing.
5. The communication method of the PCIE cryptographic card according to claim 4, characterized in that: The using a quantum-resistant algorithm to perform calculation based on the algorithm request type includes: When the algorithm request type is key generation, using the anti-quantum algorithm engine, obtaining the quantum random number generated by the quantum random number generator through the quantum random number generator interface; Based on the quantum random number, a public-private key pair is generated using a quantum-resistant algorithm; The public key in the public-private key pair is output to the host computer, and the private key in the public-private key pair is encrypted using the root key of the key file system in the storage medium, and the encrypted private key ciphertext is stored in the key file system.
6. The communication method of the PCIE cryptographic card according to claim 5, characterized in that: Based on the algorithm request type, use quantum-resistant algorithms for calculations, including: When the algorithm request type is signature processing, obtaining the data to be signed sent by the host computer; Extracting the private key ciphertext from the key file system, and decrypting the private key ciphertext using the root key to obtain a corresponding private key plaintext; The quantum-resistant algorithm engine is used to execute a quantum-resistant algorithm based on the private key plaintext to sign the data to be signed, and the generated signature result is returned to the host computer.
7. The communication method of the PCIE cryptographic card according to claim 5, characterized in that: Based on the algorithm request type, use quantum-resistant algorithms for calculations, including: When the algorithm request type is decapsulation processing, obtaining the to-be-decapsulated data sent by the host computer; Extracting a decapsulation key ciphertext from the key file system, and decrypting the decapsulation key ciphertext using the root key to obtain a corresponding decapsulation key plaintext; The anti-quantum algorithm engine is used to execute an anti-quantum algorithm based on the decapsulation key plaintext to decapsulate the data to be decapsulated, and the generated decapsulation result is returned to the host computer.
8. The communication method of the PCIE cryptographic card according to claim 5, characterized in that: Based on the algorithm request type, use quantum-resistant algorithms for calculations, including: When the algorithm request type is encryption / decryption processing, obtaining the data to be encrypted / decrypted sent by the host computer; Extracting encryption / decryption key ciphertext from the key file system, and decrypting the encryption / decryption key ciphertext using the root key to obtain corresponding encryption / decryption key plaintext; The quantum-resistant algorithm engine is used to execute a quantum-resistant algorithm based on the encryption / decryption key plaintext to encrypt / decrypt the data to be encrypted / decrypted, and the generated encryption / decryption result is returned to the host computer.
9. A communication device for a PCIE cryptographic card, characterized in that: The PCIE cryptographic card as claimed in claim 1 comprises: Instruction acquisition module, used to obtain read and write operation instructions from the host computer; A data path determination module, used to determine the base address register configuration of the first PCIE endpoint port controller in the PCIE cryptographic card, and determine the first mapping address of the security algorithm engine in the host computer and the second mapping address of the anti-quantum algorithm engine in the main PCIE chip device according to the base address register configuration; A first data transmission module, configured to generate a first algorithm execution result for the read and write operation instruction by using the quantum-resistant algorithm engine, and write the first algorithm execution result to the main PCIE chip device through a PCIE root complex port based on the second mapping address; The second data transmission module is used to generate a second algorithm execution result for the read and write operation instruction using the security algorithm engine, and return the first algorithm execution result and the second algorithm execution result to the host computer through the first PCIE endpoint port based on the first mapping address.
10. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein the computer program, when executed by a processor, implements the communication method of the PCIE cryptographic card as described in any one of claims 2 to 8.
Citation Information
Cited By
Universal interface algorithm acceleration device and acceleration method
CN120950432A