Data encryption transmission chip and method

By integrating a PCIe interface module, a data encryption/decryption module, and a media-related interface module into the data encryption transmission chip, the problems of insufficient software algorithm performance and high hardware algorithm cost are solved, achieving high-performance and low-cost data encryption transmission and improving the security and efficiency of data transmission.

CN120979689APending Publication Date: 2025-11-18BEIJING URBAN CONSTR INTELLIGENT CONTROL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510960189.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In existing technologies, software encryption algorithms cannot meet the requirements of high performance, while hardware encryption algorithms are costly, resulting in data encryption transmission failing to simultaneously meet the requirements of high performance and low cost.

Method used

Design a data encryption transmission chip that integrates a high-speed serial computer expansion bus standard PCIE interface module, a data encryption/decryption module, a data transmission module, and a media-dependent interface (MDI) module. Implement data encryption/decryption and transmission through hardware, including a Media Access Control (MAC) unit, a data conversion unit, a Physical Coding Sublayer (PCS) sublayer, a Physical Media Adaptation (PMA) sublayer, and a Physical Media Dependent (PMD) sublayer, thereby reducing hardware costs and ensuring high performance.

Benefits of technology

It achieves both high performance and low cost in hardware for encrypted data transmission, improving the security and efficiency of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979689A_ABST
    Figure CN120979689A_ABST
Patent Text Reader

Abstract

The invention provides a data encryption transmission chip and method, and relates to the technical field of data transmission, the data encryption transmission chip comprises a high-speed serial computer expansion bus standard PCIE interface module, a data encryption and decryption module, a data transmission module and a medium-dependent interface MDI interface module, the PCIE interface module is respectively connected with a processor and the data encryption and decryption module, and the data encryption and decryption module is connected with the processor. The data transmission module is respectively connected with the data encryption and decryption module and the MDI interface module, and the MDI interface module is connected with network equipment. Data transmission between the PCIE and the Ethernet is realized through the modules in the data encryption transmission chip, so that the hardware cost is reduced by integrating the modules on a hardware chip, and meanwhile, high performance and high security of data transmission are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission technology, and in particular to a data encryption transmission chip and method. Background Technology

[0002] In the transition from the high-speed serial computer expansion bus standard (Peripheral Component Interconnect Express, PCIE) to gigabit Ethernet encryption technology, it is necessary to ensure data security and high performance.

[0003] There are two main types of encryption and decryption algorithms in the existing technology: one is to implement the encryption and decryption algorithm in software, and the other is to implement encryption and decryption operations in hardware devices such as Field Programmable Gate Array (FPGA) or Application-Specific Integrated Circuit (ASIC). However, existing software algorithms cannot meet the requirements of high performance, and hardware algorithms have the problem of high cost, which means that data encryption transmission cannot simultaneously meet the requirements of high performance and low cost. Summary of the Invention

[0004] This invention provides a data encryption transmission chip and method to solve the problems in the prior art where software algorithms cannot meet the high performance requirements and hardware algorithms are costly, resulting in the inability of data encryption transmission to simultaneously meet the requirements of high performance and low cost, and to achieve data encryption transmission that simultaneously meets the requirements of high performance and low cost.

[0005] This invention provides a data encryption transmission chip, comprising: a high-speed serial computer expansion bus standard PCIe interface module, a data encryption / decryption module, a data transmission module, and a media-dependent interface (MDI) module, wherein: The PCIe interface module is connected to the processor and the data encryption / decryption module respectively; the data transmission module is connected to the data encryption / decryption module and the MDI interface module respectively; and the MDI interface module is connected to the network device. The PCIe interface module is used to provide a first transmission channel; The data encryption / decryption module is used to encrypt the first digital data from the processor to obtain encrypted data, or to decrypt the second digital data corresponding to the analog data from the network device to obtain decrypted data. The digital data is used to represent the data transmitted at the data link layer, and the analog data is used to represent the data transmitted at the physical layer. The data transmission module is used to process the encrypted data to obtain target data, or to process the simulated data to obtain the second digital data; the first transmission channel is used to transmit the digital data and / or the decrypted data. The MDI interface module is used to provide a second transmission channel for transmitting the analog data and / or the target data.

[0006] According to a data encryption transmission chip provided by the present invention, the data transmission module includes a Media Access Control (MAC) unit and a data conversion unit, wherein: the MAC unit is connected to the data encryption / decryption module and the data conversion unit respectively, and the data conversion unit is connected to the MDI interface module; the MAC unit is used to perform a first media access processing on the encrypted data to obtain access data; the data conversion unit is used to perform a first conversion processing on the access data to obtain the target data.

[0007] According to a data encryption transmission chip provided by the present invention, the data conversion unit includes: a Physical Coding Sublayer (PCS) subunit, a Physical Media Adaptation (PMA) subunit, and a Physical Media Dependent Layer (PMD) subunit, wherein: the PCS subunit is connected to the PMA subunit and the MAC unit respectively, and the PMD subunit is connected to the MDI interface module and the PMA subunit respectively; the PCS subunit is used to encode the format of the accessed data to obtain encoded data; the PMA subunit is used to convert the parallel format of the encoded data into a serial format for transmission at the physical layer to obtain serial data; and the PMD subunit is used to convert the electrical signal of the serial data into an optical signal to obtain the target data.

[0008] According to a data encryption transmission chip provided by the present invention, the PMD subunit is further configured to convert the optical signal of the analog data into an electrical signal to obtain electrical signal data; the PMA subunit is further configured to convert the serial format of the electrical signal data into a parallel format for transmission at the data link layer to obtain parallel data; the PCS subunit is further configured to decode the format of the parallel data to obtain decoded data; and the MAC unit is further configured to perform a second medium access processing on the decoded data to obtain the second digital data.

[0009] The data encryption transmission chip provided by the present invention further includes: a direct memory access (DMA) module, wherein the DMA module is connected to the encryption / decryption module and the PCIe interface module respectively; the DMA module is used to directly obtain the first digital data from the processor, or to directly transmit the decrypted data to the processor.

[0010] According to a data encryption transmission chip provided by the present invention, it further includes: a queue control module, which is connected to the DMA module and the encryption / decryption module respectively; the queue control module is used to manage the input and output operations of the first digital data or the decrypted data.

[0011] The present invention also provides a data encryption transmission method, applied to any of the above-mentioned data encryption transmission chips, characterized in that it includes: The first digital data in the processor is obtained through the PCIE interface module in the data encryption transmission chip; the digital data is used to characterize the data transmitted at the data link layer. The data encryption and decryption module in the data encryption transmission chip encrypts the first digital data to obtain encrypted data. The encrypted data is processed by the data transmission module in the data encryption transmission chip to obtain the target data. The target data is transmitted to the network device via the MDI interface module in the data encryption transmission chip. or, The simulated data in the network device is obtained through the MDI interface module; the simulated data is used to characterize the data transmitted at the physical layer. The analog data is processed by the data transmission module in the data encryption transmission chip to obtain the second digital data; The second digital data is decrypted by the data encryption / decryption module in the data encryption transmission chip to obtain decrypted data. The decrypted data is transmitted to the processor via the PCIe interface module.

[0012] According to a data encryption transmission method provided by the present invention, the data transmission module includes a media access unit and a data conversion unit. The step of transmitting and processing the encrypted data through the data transmission module in the data encryption transmission chip to obtain target data includes: performing media access processing on the encrypted data through the media access processing unit to obtain access data; and converting the access data into the target data through the data conversion unit.

[0013] According to a data encryption transmission method provided by the present invention, the data conversion unit includes a PCS subunit, a PMA subunit, and a PMD subunit; the step of converting the access data into the target data through the data conversion unit includes: encoding the format of the access data through the PCS subunit to obtain encoded data; converting the parallel format of the encoded data into a serial format for transmission at the physical layer through the PMA subunit to obtain serial data; and converting the electrical signal of the serial data into an optical signal through the PMD subunit to obtain the target data.

[0014] According to a data encryption transmission method provided by the present invention, the step of transmitting and processing the analog data through the data transmission module in the data encryption transmission chip to obtain second digital data includes: converting the optical signal of the analog data into an electrical signal through a PMD subunit to obtain electrical signal data; converting the format of the electrical signal data into parallel data transmitted at the data link layer through a PMA subunit to obtain parallel data; performing decoding processing on the parallel data through a PCS subunit to obtain decoded data; and performing media access processing on the decoded data through a MAC unit to obtain the second digital data.

[0015] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the data encryption transmission method as described above.

[0016] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the data encryption transmission method as described above.

[0017] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the data encryption transmission method as described above.

[0018] The data encryption transmission chip and method provided by this invention integrate a PCIe interface module, a data encryption / decryption module, a data transmission module, and a Medium Dependent Interface (MDI) module onto a single chip to obtain a data encryption transmission chip. Data transmission between PCIe and Ethernet is achieved through the various modules in the data encryption transmission chip. In this way, by integrating the modules onto a hardware chip, hardware costs are reduced while ensuring high performance and high security of data transmission. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0020] Figure 1 This is one of the structural schematic diagrams of the data encryption transmission chip provided by the present invention.

[0021] Figure 2 This is the second schematic diagram of the data encryption transmission chip provided by the present invention.

[0022] Figure 3 This is the third schematic diagram of the data encryption transmission chip provided by the present invention.

[0023] Figure 4 This is the fourth schematic diagram of the data encryption transmission chip provided by the present invention.

[0024] Figure 5 This is the fifth schematic diagram of the data encryption transmission chip provided by the present invention.

[0025] Figure 6 This is the sixth schematic diagram of the data encryption transmission chip provided by the present invention.

[0026] Figure 7 This is one of the flowcharts illustrating the data encryption transmission method provided by the present invention.

[0027] Figure 8 This is the second flowchart of the data encryption transmission method provided by the present invention.

[0028] Figure 9 This is a schematic diagram of the structure of the electronic device provided by the present invention.

[0029] Figure label: 100: Data encryption transmission chip; 110: PCIe interface module; 120: Data encryption / decryption module; 130: Data transmission module; 140: MDI interface module; 131: MAC unit; 132: Data conversion unit; 1321: PCS subunit; 1322: PMA subunit; 1323: PMD subunit; 150: DMA module; 160: Queue control module; 170: Basic module. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0031] The following is combined with Figures 1-6 This invention describes a data encryption transmission chip.

[0032] Figure 1 This is one of the structural schematic diagrams of the data encryption transmission chip provided by the present invention, such as... Figure 1 As shown, the data encryption transmission chip 100 includes: a high-speed serial computer expansion bus standard PCIe interface module, a data encryption / decryption module 120, a data transmission module 130, and a media-dependent interface (MDI) module 140, wherein: The PCIe interface module 110 is connected to the processor and the data encryption / decryption module 120 respectively. The data transmission module 130 is connected to the data encryption / decryption module 120 and the MDI interface module 140 respectively. The MDI interface module 140 is connected to the network device. The PCIe interface module 110 is used to provide a first transmission channel; The data encryption / decryption module 120 is used to encrypt the first digital data from the processor to obtain encrypted data, or to decrypt the second digital data corresponding to the analog data from the network device to obtain decrypted data. The digital data is used to represent the data transmitted at the data link layer, and the analog data is used to represent the data transmitted at the physical layer. The data transmission module 130 is used to process the encrypted data to obtain target data, or to process the analog data to obtain the second digital data; the first transmission channel is used to transmit the digital data and / or the decrypted data. The MDI interface module 140 is used to provide a second transmission channel for transmitting the analog data and / or the target data.

[0033] It should be noted that the data encryption transmission chip can achieve both PCIe to Gigabit Ethernet and Gigabit Ethernet to PCIe conversion.

[0034] Here, the PCIe interface module 110 may include a PCIe controller and a PCIe I / O port.

[0035] Here, the first transmission channel is actually obtained by connecting the PCIe interface module 110 in the chip with the PCIe interface module 110 in the processor, and is used for data link transmission. The second transmission channel is obtained by connecting the MDI interface module 140 in the chip with the network device, and is used for physical layer transmission.

[0036] Here, processor types include, but are not limited to, central processing units (CPUs), graphics processing units (GPUs), and microprocessors (MPUs); network devices include, but are not limited to, network cables, routers, and switches.

[0037] It should be noted that the transmitted data can be either sent data or received data. For example, through a data encryption transmission chip, the processor can send data to the network cable or receive data sent by the network cable.

[0038] It should be noted that network devices receive or send analog data, which is transmitted at the physical layer; processors receive or send digital data, which is transmitted at the data link layer. The physical layer is responsible for transmitting bit streams and providing the physical connection for data communication between devices, while the data link layer, located above the physical layer, is responsible for transmitting frames between adjacent network nodes.

[0039] Here, the algorithms in the encryption / decryption module include, but are not limited to, block cipher algorithms such as Shang Yong Mi Ma (SM) 4, SM2, and SM3. By selecting secure encryption algorithms and key management schemes in the encryption / decryption module, the security of data transmission is improved.

[0040] For example, the encryption operation may include the following three steps: (1) generating 32 round keys, (2) performing 32 round operation selection operations on the plaintext, and (3) dividing the data after the iteration into 4 32-bit words and reversing the 4 words to obtain the final ciphertext.

[0041] The specific implementation of PCIe to Gigabit Ethernet includes: the PCIe interface module 110 in the chip is connected to the PCIe in the processor to form a first transmission channel, obtains the first digital data in the processor, the encryption and decryption module encrypts the first digital data to obtain encrypted data; the data transmission module 130 transmits the encrypted data to obtain the target data; and the target data is transmitted to the network device through the second transmission channel between the MDI interface module 140 and the network device.

[0042] The specific implementation of Gigabit Ethernet to PCIe conversion includes: the MDI interface module 140 in the chip is connected to the network device to form a second transmission channel, acquires analog data from the network device, processes the analog data through the data transmission module 130 to obtain second digital data; decrypts the second digital data through the data encryption / decryption module 120 to obtain decrypted data; and transmits the decrypted data to the processor through the first transmission channel.

[0043] In this embodiment of the invention, a data encryption and transmission chip is obtained by integrating the PCIE interface module 110, the data encryption and decryption module 120, the data transmission module 130, and the Medium Dependent Interface (MDI) module on a chip. Data transmission between PCIE and Ethernet is realized through the various modules in the data encryption and transmission chip. In this way, by integrating the various modules on the hardware chip, the hardware cost is reduced, while ensuring high performance and high security of data transmission.

[0044] Figure 2 This is the second schematic diagram of the data encryption transmission chip provided by the present invention, as shown below. Figure 2 As shown, the data transmission module 130 includes a Media Access Control (MAC) unit 131 and a data conversion unit 132, wherein: the MAC unit 131 is connected to the data encryption / decryption module 120 and the data conversion unit 132 respectively, and the data conversion unit 132 is connected to the MDI interface module 140; the MAC unit 131 is used to perform a first media access processing on the encrypted data to obtain access data; the data conversion unit is used to perform a first conversion processing on the access data to obtain the target data.

[0045] It should be noted that in the case of PCIe to Gigabit Ethernet conversion, the first media access process may include encapsulating the first digital data, executing the media access control protocol, and collision detection and handling.

[0046] Here, the first conversion process essentially converts the digital data transmitted at the data link layer into analog data suitable for transmission at the physical layer.

[0047] Figure 3 This is the third schematic diagram of the data encryption transmission chip provided by the present invention, as shown below. Figure 3 As shown, the data conversion unit includes: a Physical Coding Sublayer (PCS) subunit 1321, a Physical Media Adaptation (PMA) subunit 1322, and a Physical Media Dependent Layer (PMD) subunit 1323, wherein: The PCS subunit 1321 is connected to the PMA subunit 1322 and the MAC unit 131 respectively, and the PMD subunit 1323 is connected to the MDI interface module 140 and the PMA subunit 1322 respectively. The PCS subunit 1321 is used to encode the format of the access data to obtain encoded data. The PMA subunit 1322 is used to convert the parallel format of the encoded data into a serial format transmitted at the physical layer to obtain serial data; The PMD subunit 1323 is used to convert the electrical signal of the serial data into an optical signal to obtain the target data.

[0048] Here, the Physical Coding Sublayer (PCS) unit encodes the information provided by the MAC, applicable to scenarios with speeds greater than or equal to 100 megabits per second (Mb / s), such as 8-byte (B) / 10-byte, 64-byte / 66-byte, and 256-byte / 257-byte encoding. The PCS mainly includes line coding and Cyclic Redundancy Check (CRC), and is a standard Complementary Metal-Oxide-Semiconductor (CMOS) digital logic unit.

[0049] The Physical Medium Attachment (PMA) sub-unit integrates serializers (SERDES) primarily for serialization and deserialization, receiving and transmitting high-speed serial data on the serial channel, clock generator and clock data recovery functions, as well as analog front-end functions such as continuous-time linear equalizer (CTLE), decision feedback equalizer (DFE), and transmission equalization. The PMA sub-layer contains mixed-signal current-mode logic (CML) / CMOS circuits.

[0050] The Physical Medium Dependent (PMD) subunit is typically replaced by an optical module to perform photoelectric / electro-optical conversion and is responsible for serial signal communication. Furthermore, the PMD subunit 1323, conforming to ISO / IEC IEEE standards, features MLT-3 encoding and decoding functions for data stream scrambling, descrambling, three-level, and multi-edge transitions, as well as DC recovery and equalization of the received signal.

[0051] In this invention, in the case of PCIe to Gigabit Ethernet conversion, the specific implementation of the data conversion unit 132 includes: PCS subunit 1321 encoding the format of the access data to obtain encoded data; PMA subunit 1322 converting the parallel format of the encoded data into the serial format transmitted at the physical layer to obtain serial data; and PMD subunit 1323 converting the electrical signal of the serial data into an optical signal to obtain the target data.

[0052] In this embodiment of the invention, by integrating the PCS subunit 1321, PMA subunit 1322 and PMD subunit 1323 into a chip, data encoding, format conversion and signal conversion are realized, reducing the hardware cost of format conversion, while using hardware to implement encoding, format conversion and signal conversion to meet high performance requirements.

[0053] Furthermore, the PMD subunit 1323 is also used to convert the optical signal of the analog data into an electrical signal to obtain electrical signal data; The PMA subunit 1322 is also used to convert the serial format of the electrical signal data into a parallel format transmitted at the data link layer to obtain parallel data; The PCS subunit 1321 further decodes the format of the parallel data to obtain decoded data; The MAC unit is further configured to perform a second medium access process on the decoded data to obtain the second digital data.

[0054] It should be noted that, in the case of Gigabit Ethernet to PICE conversion, the specific implementation of the data transmission module 130 includes: the PMD subunit 1323 converts the optical signal of the analog data into an electrical signal to obtain electrical signal data; the PMA subunit 1322 converts the serial format of the electrical signal data into a parallel format for transmission at the data link layer to obtain parallel data; and the MAC unit 131 performs media access processing on the decoded data to obtain the second digital data.

[0055] In this embodiment of the invention, by integrating the PCS subunit 1321, PMA subunit 1322 and PMD subunit 1323 into a chip, signal conversion, format conversion and decoding of data are realized, reducing hardware costs. At the same time, using hardware to implement signal conversion, format conversion and decoding of data meets high performance requirements.

[0056] Figure 4 This is the fourth schematic diagram of the data encryption transmission chip provided by the present invention, as shown below. Figure 4 As shown, the data encryption transmission chip also includes a direct memory access (DMA) module 150, which is connected to the encryption / decryption module and the PCIe interface module 110 respectively. The DMA module 150 is used to directly obtain the first digital data from the processor, or to directly transmit the decrypted data to the processor.

[0057] Here, Direct Memory Access (DMA) is a technology that allows computer hardware (such as peripheral devices) to exchange data directly with system memory without the intervention of the CPU, which is responsible for coordinating data transfer.

[0058] Specifically, the DMA module 150 directly accesses the processor through the first transmission channel formed by the PCIe interface module 110 to obtain the first digital data, or the DMA module 150 directly stores the encrypted data output by the encryption / decryption module into the processor.

[0059] In this embodiment of the invention, the DMA module 150 significantly improves the efficiency of data transmission and reduces the CPU load during data transmission, thereby improving the performance of the entire computer system.

[0060] Figure 5 This is the fifth schematic diagram of the data encryption transmission chip provided by the present invention, as shown below. Figure 5 As shown, the data encryption transmission chip also includes a queue control module 160, which is connected to the DMA module 150 and the encryption / decryption module respectively. The queue control module 160 is used to manage the input and output operations of the first digital data or the decrypted data.

[0061] The Queue Control module is a key part of managing data flow, providing queue management functions, including enqueue and dequeue operations, as well as queue status monitoring.

[0062] In this embodiment of the invention, the queue control module 160 manages and optimizes data input and output operations, thereby improving chip throughput and real-time response speed, optimizing resource allocation and load balancing, and integrating the queue control module 160 onto the chip, thereby reducing hardware costs.

[0063] The following are application scenarios of the data encryption transmission chip provided by this invention. In practical applications, in addition to the aforementioned PCIE interface module 110, data encryption / decryption module 120, data transmission module 130, MDI interface module 140, DMA module 150, and queue control module 160, it also includes basic modules, such as a power management (Power Generator LDO / SWR) module for providing stable power; a crystal oscillator (XTAL) module for providing stable clock signals; a power-on reset module for power reset and power-on; an LED controller module for controlling the switching of various positions in the LED circuit; a one-time programmable (OTP) module for storing fixed configuration information, unique device identifiers, encryption keys, authentication token seeds, etc.; and a wake-on-LAN (WOL) module for waking up the chip. All basic modules are built from the minimum components provided by TSMC's CMOS process library.

[0064] Figure 6 This is the sixth schematic diagram of the data encryption transmission chip provided by the present invention, as shown below. Figure 6 As shown, the data encryption transmission chip 100 includes: a PCIe interface module 110, a DMA module 150, a queue control module 160, a data encryption / decryption module 120, a data transmission module 130, an MDI interface module 140, and a basic module 170. The DMA module 150 includes receive DMA (RXDMA) and transmit DMA (TXDMA). The data transmission module 130 includes a MAC unit 131 and a data conversion unit 132. The data conversion unit 132 includes a PCS subunit 1321, a PMA subunit 1322, and a PMD subunit 1323. The MAC unit 131 includes receive MAC (RXMAC) and transmit MAC (TXMAC).

[0065] The data encryption transmission method provided by the present invention is described below. The data encryption transmission method described below can be referred to in correspondence with the data encryption transmission chip described above.

[0066] Figure 7 This is one of the flowcharts illustrating the data encryption transmission method provided by the present invention, such as... Figure 7 As shown, the data encryption transmission chip described above is characterized by comprising: Step 701: Obtain the first digital data from the processor through the PCIE interface module in the data encryption transmission chip; Step 702: Encrypt the first digital data using the data encryption / decryption module in the data encryption transmission chip to obtain encrypted data; Step 703: The encrypted data is transmitted and processed through the data transmission module in the data encryption transmission chip to obtain the target data; Step 704: Transmit the target data to the network device through the MDI interface module in the data encryption transmission chip.

[0067] The digital data is used to characterize the data transmitted at the data link layer.

[0068] Figure 8 This is the second flowchart illustrating the data encryption transmission method provided by the present invention, as shown below. Figure 8 As shown, the data encryption transmission chip described above is characterized by comprising: Step 801: Obtain analog data from the network device through the MDI interface module; Step 802: The analog data is processed by the data transmission module in the data encryption transmission chip to obtain the second digital data; Step 803: Decrypt the second digital data using the data encryption / decryption module in the data encryption transmission chip to obtain decrypted data; Step 804: Transmit the decrypted data to the processor through the PCIE interface module.

[0069] The simulated data is used to characterize the data transmitted at the physical layer.

[0070] Furthermore, the data transmission module 130 includes a media access unit and a data conversion unit 132. The process of transmitting the encrypted data through the data transmission module 130 in the data encryption transmission chip to obtain the target data includes: The encrypted data is processed by the media access processing unit to obtain access data. The access data is converted into the target data by the data conversion unit 132.

[0071] Furthermore, the data conversion unit 132 includes a PCS subunit 1321, a PMA subunit 1322, and a PMD subunit 1323; The process of converting the accessed data into the target data through the data conversion unit 132 includes: The format of the access data is encoded by the PCS subunit 1321 to obtain encoded data. The parallel format of the encoded data is converted into a serial format for transmission at the physical layer by the PMA subunit 1322 to obtain serial data; The PMD subunit 1323 converts the electrical signal of the serial data into an optical signal to obtain the target data.

[0072] Furthermore, the process of transmitting the analog data through the data transmission module 130 in the data encryption transmission chip to obtain the second digital data includes: The optical signal of the analog data is converted into an electrical signal by the PMD subunit 1323 to obtain electrical signal data. The PMA subunit 1322 converts the electrical signal data into parallel data that is transmitted at the data link layer to obtain parallel data. Decoded data is obtained by decoding the parallel data of PCS subunit 1321; The decoded data is processed by the MAC unit 131 to obtain the second digital data.

[0073] Figure 9 This is a schematic diagram of the structure of the electronic device provided by the present invention, such as... Figure 9 As shown, the electronic device may include: a processor 910, a communications interface 920, a memory 930, and a communications bus 940, wherein the processor 910, the communications interface 920, and the memory 930 communicate with each other through the communications bus 940. The processor 910 can invoke logic instructions in the memory 930 to execute a data encryption transmission method, which includes: acquiring first digital data from the processor through a PCIe interface module in the data encryption transmission chip; the digital data being used to represent data transmitted at the data link layer; encrypting the first digital data through a data encryption / decryption module in the data encryption transmission chip to obtain encrypted data; transmitting the encrypted data through a data transmission module in the data encryption transmission chip to obtain target data; transmitting the target data to a network device through an MDI interface module in the data encryption transmission chip; or, acquiring analog data from the network device through the MDI interface module; the analog data being used to represent data transmitted at the physical layer; transmitting the analog data through a data transmission module in the data encryption transmission chip to obtain second digital data; decrypting the second digital data through a data encryption / decryption module in the data encryption transmission chip to obtain decrypted data; and transmitting the decrypted data to the processor through the PCIe interface module.

[0074] Furthermore, the logical instructions in the aforementioned memory 930 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0075] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data encryption transmission method provided by the above methods. The method includes: obtaining first digital data from the processor through a PCIe interface module in the data encryption transmission chip; the digital data being used to represent data transmitted at the data link layer; encrypting the first digital data through a data encryption / decryption module in the data encryption transmission chip to obtain encrypted data; transmitting the encrypted data through a data transmission module in the data encryption transmission chip to obtain target data; transmitting the target data to a network device through an MDI interface module in the data encryption transmission chip; or, obtaining analog data from the network device through the MDI interface module; the analog data being used to represent data transmitted at the physical layer; transmitting the analog data through a data transmission module in the data encryption transmission chip to obtain second digital data; decrypting the second digital data through a data encryption / decryption module in the data encryption transmission chip to obtain decrypted data; and transmitting the decrypted data to the processor through the PCIe interface module.

[0076] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the data encryption transmission method provided by the above methods. The method includes: acquiring first digital data from a processor through a PCIe interface module in the data encryption transmission chip; the digital data representing data transmitted at the data link layer; encrypting the first digital data through a data encryption / decryption module in the data encryption transmission chip to obtain encrypted data; transmitting the encrypted data through a data transmission module in the data encryption transmission chip to obtain target data; transmitting the target data to a network device through an MDI interface module in the data encryption transmission chip; or, acquiring analog data from the network device through the MDI interface module; the analog data representing data transmitted at the physical layer; transmitting the analog data through the data transmission module in the data encryption transmission chip to obtain second digital data; decrypting the second digital data through the data encryption / decryption module in the data encryption transmission chip to obtain decrypted data; and transmitting the decrypted data to the processor through the PCIe interface module.

[0077] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0078] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0079] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data encryption transmission chip, characterized in that, include: The high-speed serial computer expansion bus standard PCIe interface module, data encryption / decryption module, data transmission module, and media-dependent interface (MDI) module include: The PCIe interface module is connected to the processor and the data encryption / decryption module respectively; the data transmission module is connected to the data encryption / decryption module and the MDI interface module respectively; and the MDI interface module is connected to the network device. The PCIe interface module is used to provide a first transmission channel; The data encryption / decryption module is used to encrypt the first digital data from the processor to obtain encrypted data, or to decrypt the second digital data corresponding to the analog data from the network device to obtain decrypted data. The digital data is used to represent the data transmitted at the data link layer, and the analog data is used to represent the data transmitted at the physical layer. The data transmission module is used to process the encrypted data to obtain target data, or to process the simulated data to obtain the second digital data; the first transmission channel is used to transmit the digital data and / or the decrypted data. The MDI interface module is used to provide a second transmission channel for transmitting the analog data and / or the target data.

2. The data encryption transmission chip according to claim 1, characterized in that, The data transmission module includes a Media Access Control (MAC) unit and a data conversion unit, wherein: The MAC unit is connected to the data encryption / decryption module and the data conversion unit, and the data conversion unit is connected to the MDI interface module. The MAC unit is used to perform a first medium access process on the encrypted data to obtain access data; The data conversion unit is used to perform a first conversion process on the accessed data to obtain the target data.

3. The data encryption transmission chip according to claim 2, characterized in that, The data conversion unit includes: a Physical Coding Sub-layer (PCS) sub-unit, a Physical Media Adaptation Sub-layer (PMA) sub-unit, and a Physical Media Dependent Layer (PMD) sub-unit, wherein: The PCS sub-unit is connected to the PMA sub-unit and the MAC unit respectively, and the PMD sub-unit is connected to the MDI interface module and the PMA sub-unit respectively; The PCS sub-segment is used to encode the format of the access data to obtain encoded data; The PMA sub-unit is used to convert the parallel format of the encoded data into a serial format transmitted at the physical layer to obtain serial data; The PMD sub-unit is used to convert the electrical signal of the serial data into an optical signal to obtain the target data.

4. The data encryption transmission chip according to claim 3, characterized in that, The PMD sub-unit is also used to convert the optical signal of the analog data into an electrical signal to obtain electrical signal data; The PMA sub-unit is also used to convert the serial format of the electrical signal data into a parallel format transmitted at the data link layer to obtain parallel data; The PCS sub-unit also decodes the format of the parallel data to obtain decoded data; The MAC unit is further configured to perform a second medium access process on the decoded data to obtain the second digital data.

5. The data encryption transmission chip according to any one of claims 1-4, characterized in that, Also includes: A direct memory access (DMA) module is provided, which is connected to the encryption / decryption module and the PCIe interface module respectively. The DMA module is used to directly obtain the first digital data from the processor, or to directly transmit the decrypted data to the processor.

6. The data encryption transmission chip according to claim 5, characterized in that, Also includes: A queue control module, which is connected to the DMA module and the encryption / decryption module respectively; The queue control module is used to manage the input and output operations of the first digital data or the decrypted data.

7. A data encryption transmission method, applied to the data encryption transmission chip according to any one of claims 1 to 6, characterized in that, include: The first digital data in the processor is obtained through the PCIE interface module in the data encryption transmission chip; The digital data is used to characterize the data transmitted at the data link layer; The data encryption and decryption module in the data encryption transmission chip encrypts the first digital data to obtain encrypted data. The encrypted data is transmitted and processed by the data transmission module in the data encryption transmission chip to obtain the target data; The target data is transmitted to the network device via the MDI interface module in the data encryption transmission chip. or, The simulated data in the network device is obtained through the MDI interface module; the simulated data is used to characterize the data transmitted at the physical layer. The analog data is processed by the data transmission module in the data encryption transmission chip to obtain the second digital data; The second digital data is decrypted by the data encryption / decryption module in the data encryption transmission chip to obtain decrypted data. The decrypted data is transmitted to the processor via the PCIe interface module.

8. The data encryption transmission method according to claim 7, characterized in that, The data transmission module includes a media access unit and a data conversion unit. The process of transmitting the encrypted data through the data transmission module in the data encryption transmission chip to obtain the target data includes: The encrypted data is processed by the media access processing unit to obtain access data. The accessed data is converted into the target data by the data conversion unit.

9. The data encryption transmission method according to claim 8, characterized in that, The data conversion unit includes a PCS sub-unit, a PMA sub-unit, and a PMD sub-unit; The process of converting the accessed data into the target data through the data conversion unit includes: The format of the access data is encoded using a PCS sub-segment to obtain encoded data. The parallel format of the encoded data is converted into a serial format for transmission at the physical layer through the PMA sub-unit to obtain serial data; The PMD sub-unit converts the electrical signal of the serial data into an optical signal to obtain the target data.

10. The data encryption transmission method according to claim 9, characterized in that, The process of transmitting and processing the analog data through the data transmission module in the data encryption transmission chip to obtain the second digital data includes: The optical signal of the analog data is converted into an electrical signal through the PMD sub-unit to obtain electrical signal data; The PMA sub-unit converts the electrical signal data into parallel data that is transmitted at the data link layer, thus obtaining parallel data. Decoded data is obtained by decoding the PCS sub-single parallel data. The decoded data is processed by the MAC unit to obtain the second digital data.