A general-purpose cryptographic device test platform
By designing a universal cryptographic machine testing platform, the problem of traditional testing platforms being incompatible with different types of cryptographic machines and large-scale testing was solved. It enables compatibility testing of different types of cryptographic machines and large-scale testing, measures hardware parameters, and improves testing efficiency and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING INST OF COMP TECH & APPL
- Filing Date
- 2022-07-28
- Publication Date
- 2026-04-17
AI Technical Summary
Traditional cryptographic machine testing platforms are incompatible with different types of cryptographic machines, cannot perform large-scale testing, and lack hardware parameter testing capabilities.
Design a general-purpose cryptographic machine test platform, including a main controller, backplane, interface board, and adapter board, supporting multiple interface protocols and physical interfaces. It achieves anti-interference long-distance communication through differential-to-single-ended signal conversion, measures the startup time and power consumption of cryptographic machines, and adopts a plug-in card platform to support large-scale testing of multiple cryptographic machines.
It achieves compatibility with different types of cryptographic machines, supports large-scale testing, and can measure hardware parameters, thus improving testing efficiency and reliability.
Smart Images

Figure CN115237697B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of cryptographic machine testing, and specifically relates to a general-purpose cryptographic machine testing platform. Background Technology
[0002] Cryptographic machines are essential critical devices in information security systems, typically used for encryption (plaintext-ciphertext) or decryption (ciphertext-plaintext). Beyond military and diplomatic intelligence, cryptographic machines are now widely integrated into daily life, such as in encrypted financial cards, secure gateways, and encrypted voice communication. They are crucial to information security at both the national and individual levels, serving as core equipment in the entire information security field. Therefore, the robustness of the cryptographic machine itself is paramount, impacting the security of the entire information system. Generally, cryptographic machines undergo extensive functional, performance, and reliability testing before deployment—a tedious and lengthy process. However, the diverse physical forms, sizes, interface protocols, and application scenarios of cryptographic machines present a significant challenge for testing and maintenance.
[0003] Traditional automated testing platforms for cryptographic machines can now achieve independence between test cases and maintenance tools, and automatically convert test data formats and command lengths, thus improving the level of automation in testing. For example, the patent application No. 201310368525.6, "An Automated Cryptographic Machine Testing System and Its Working Method," discloses an automated testing system for cryptographic machines and its working method. Its purpose is to address the issue that "the management methods for cryptographic machine testing and maintenance are relatively simple, not easily expandable, and not conducive to automated and intelligent testing and maintenance."
[0004] For example, the application No. 202011203466.3, "Cryptographic Machine Testing Device and Method for Testing Cryptographic Machines Using the Same", discloses a cipher machine testing device and testing method. Its purpose is to solve the problem that "due to the large number of variable fields and the complexity of the rules, each instruction needs to be concatenated byte by byte according to the rules. In addition, some variable fields need to send hexadecimal data, while others need to be ASCII. The encoding needs to be converted by ourselves. Furthermore, the length of the command also needs to be calculated by ourselves. Therefore, this method is too complicated, time-consuming, and prone to errors."
[0005] In summary, traditional cryptographic machine testing platforms only describe relevant testing methods at the software application layer, without describing hardware compatibility between the cryptographic machine and the testing platform, thus failing to achieve universality. Secondly, they cannot test cryptographic machines in large batches simultaneously. Finally, they lack the function of testing cryptographic machine hardware parameters (such as power consumption and startup time).
[0006] The purpose of this invention is to provide a general-purpose cryptographic machine testing platform to solve one or more of the above-mentioned technical problems. Summary of the Invention
[0007] (a) Technical problems to be solved
[0008] The technical problem this invention aims to solve is how to provide a universal cryptographic machine testing platform to address the issues of traditional cryptographic machine testing platforms that only describe relevant testing methods at the software application layer without describing hardware compatibility between the cryptographic machine and the testing platform, thus failing to achieve universality and the ability to test cryptographic machines in large quantities simultaneously; and finally, lacking the capability to test the hardware parameters of the cryptographic machine.
[0009] (II) Technical Solution
[0010] To address the aforementioned technical issues, this invention proposes a universal cryptographic machine testing platform. This platform includes a main controller, a backplane, an interface board, and an adapter board. The main controller runs test software and underlying drivers. The interface board is compatible with various interface protocols. The backplane has mixed slots, providing power interfaces and interconnection channels for the main controller and interface board. The adapter board is used for non-standard cryptographic machine testing scenarios, connecting the interface board and the cryptographic machine to achieve differential-to-single-ended conversion and to measure the cryptographic machine's startup time and power consumption. For standard PXIe and VPX cryptographic machines, the machine under test is directly installed on the backplane of the testing platform. If the cryptographic machine uses a standard physical interface RJ45 / SFP for external interconnection, a standard physical interface is designed on the interface board. If the cryptographic machine uses a low-speed interface such as UART, SPI, or IIC for external interconnection, differential signal transmission is used. Connecting a differential-to-single-ended adapter board in series with the cryptographic machine and then connecting it to the interface board enables interference-resistant long-distance communication.
[0011] Furthermore, the interface board is 3U in size and supports board-level hot-swapping functionality, including ZYNQ, RS-485 bus, J30J quick-lock connector, and single-ended to differential chip; based on the ZYNQ core architecture, it can run ARM software and FPGA logic simultaneously, facilitating multi-protocol calling and logic control; the hot-swappable interchangeable electrical and optical ports support Ethernet protocol, with a maximum speed of 10Gbps; the RS-485 bus and single-ended to differential chip are used to connect the J30J quick-lock connector and ZYNQ, for receiving cryptographic machine hardware parameters collected by external adapter boards and transmitting them to the main controller; the interface board uses the J30J quick-lock connector that supports high-speed signal transmission, supporting up to 50 pairs of differential signals.
[0012] Furthermore, the interface board ZYNQ is the core architecture, and ZYNQ can be programmed with configuration files via SD card; the Ethernet interface is interconnected with ZYNQ via high-speed SERDES signals, with a maximum speed of 10Gbps; the single-ended control signals LVTTL interconnected with ZYNQ are sent to the single-ended to differential chip after being isolated by an optocoupler, realizing differential transmission function; the interface board and the main controller are interconnected via PCIe×4 on the backplane.
[0013] Furthermore, the J30J quick-lock connector has 100 pins, including 44 pairs of differential signals and 12 ground signals, which are divided into two channels. Each channel has 22 pairs of differential signals, one of which is RS-485, leaving 21 pairs available for use, along with 6 ground signals. The two channels are powered by different isolated power supplies to achieve electrical isolation between the channels. At the same time, all single-ended signals are optocoupled for isolation between the board and the external circuitry. The power management unit directly powers the devices in the GND domain on the board. Isolation power supply 1 powers the ISO_GND1 domain circuitry, corresponding to channel 1, while isolation power supply 2 powers the ISO_GND2 domain circuitry, corresponding to channel 2.
[0014] Furthermore, the adapter board is located between the interface board and the cipher machine under test. It converts the differential signal transmitted from the interface board into a single-ended signal, measures the power consumption and startup time of the cipher machine, and provides an independent power supply channel for the cipher machine. The adapter board uses an MCU as its control core. The MCU controls the cipher machine to power on and transmits the power consumption and startup time of the board to the interface board via RS-485. Precision resistors and acquisition chips are used to collect the power consumption of the cipher machine board. The startup time of the cipher machine is the difference between the power-on time of the cipher machine and the indication signal sent after it is working normally. The power module provides power to the adapter board and the subsequent cipher machine, and they are independent of each other.
[0015] Furthermore, the adapter board is powered by a separate 12V power connector, which is then converted to a 5V input multi-channel power supply by an isolated power module. The multi-channel power module enables the independent channel for powering the MCU. The enable pins and PGOOD signals of the other power output channels are interconnected with the MCU. Only when the MCU is working normally can the enable pins of other power supplies be output. The cipher machines under test are powered independently without affecting each other. A high-precision metal film resistor is connected in series at the power supply interface of each cipher machine. The two ends of the metal film resistor are connected to the differential input terminals of the acquisition chip LTC2991. The ADC integrated inside converts the acquired analog voltage signal into a digital signal and sends it to the MCU through the IIC bus. The MCU sends the power consumption information to the interface board through the RS-485 bus.
[0016] Furthermore, the metal film resistors are kept away from interference from clock and high-speed signals, the traces are kept as short and thick as possible, no components are placed on the bottom layer, and the copper is completely poured.
[0017] Furthermore, the cipher machine startup time is measured by the MCU acquiring the PGOOD signal generated by the multi-channel power module and the status indication signal issued by the cipher machine. The time difference between the two signals is the startup time of the cipher machine. The MCU sends the time information to the interface board via the RS-485 bus, and the interface board then sends the time information to the main controller, thus obtaining the startup time of the cipher machine and proceeding to the next step, ultimately displaying whether it passes or fails.
[0018] Furthermore, the power consumption detection unit is independently powered. After the power consumption detection unit is working normally, it controls the power supply channel to independently power the cipher machine. A precision resistor is connected in series on each independent power supply channel. The voltage across the precision resistor is collected, converted into a digital signal, and sent to the MCU via the bus. The MCU sends the power consumption of the cipher machine to the interface board via the bus. The interface board then transmits the power consumption information to the main controller to obtain the power consumption value of the cipher machine. Subsequent secondary processing can be performed to determine whether the power consumption meets the requirements.
[0019] Furthermore, the state indication signal issued by the cipher machine under test is used to control the enable of the differential-to-single-ended chip. Data interaction can only be carried out when the device under test is fully ready, so that the test system is in a safe and reliable state.
[0020] (III) Beneficial Effects
[0021] This invention proposes a universal cryptographic machine testing platform, which includes a main controller, a backplane, an interface board, and an adapter board. The main controller runs the testing software and underlying drivers; the interface board is compatible with commonly used interface protocols; the backplane has mixed slots and supports standard boards such as VPX, PXIe, and CPCIe (including but not limited to the standard boards mentioned in this paper), providing power interfaces and interconnection channels for the main controller and interface boards; the adapter board is mainly used for non-standard cryptographic machine testing scenarios, realizing differential-to-single-ended conversion and testing cryptographic machine startup time and power consumption, improving the anti-interference performance of business interfaces, enhancing environmental adaptability, and expanding application scenarios.
[0022] The main controller of this general-purpose cryptographic machine testing platform is used to simulate test data and run the test environment, and is interconnected with the interface board via a PCIe bus. Both the data bus bandwidth and the onboard resources are sufficient to support large-scale testing of multiple cryptographic machines. Secondly, the cryptographic testing platform adopts a plug-in card platform, theoretically allowing for the installation of multiple interface boards. One interface board can test multiple cryptographic machines simultaneously, greatly increasing the number of cryptographic machines that can be tested concurrently. Increasing the physical size of the interface board can further increase the number of cryptographic machines that can be tested concurrently. Attached Figure Description
[0023] Figure 1 This is a schematic diagram of the universal cryptographic machine test platform of the present invention;
[0024] Figure 2 A test scheme for standard board-type cryptographic machines;
[0025] Figure 3 This is a schematic diagram of a pluggable optical port (left) and electrical port (right);
[0026] Figure 4 This is a schematic diagram of a non-standard cryptographic machine (single-ended signal) test platform.
[0027] Figure 5 This is a schematic diagram of the interface board (3U board) of the password testing platform.
[0028] Figure 6 It is an adapter board with functions for measuring cipher machine power consumption and startup time, as well as differential to single-ended conversion.
[0029] Figure 7 The system block diagram for implementing Case 1. Detailed Implementation
[0030] To make the objectives, contents, and advantages of the present invention clearer, the specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples.
[0031] This invention provides a universal cryptographic machine testing platform, which includes a cryptographic testing platform and a cryptographic machine. The cryptographic testing platform includes input / output devices, a main controller, interface boards, a backplane, and adapter boards, etc.
[0032] Because cryptographic machines use different external interface protocols (such as TCP / IP, PCIe, SRIO, UART, SPI, IIC, etc.) and have varying physical shapes and sizes (such as rack servers, standard boards, and non-standard products), traditional cryptographic machine testing systems or platforms are incompatible with various types of cryptographic machines, making it difficult to achieve universality. In addition, traditional testing platforms always simulate the simultaneous testing of multiple cryptographic machines at the application layer, but there is no description of how to achieve simultaneous large-scale testing at the actual hardware level, nor does it include testing of cryptographic machine hardware performance.
[0033] Therefore, in order to adapt to various types of cipher machines and support large-scale testing and hardware performance testing of cipher machines, this invention proposes a universal cipher machine testing platform. This platform can support multi-type, large-scale testing of cipher machines and can also test cipher machine hardware parameters. The universal cipher machine testing platform consists of the following components: Figure 1 As shown.
[0034] The cryptographic testing platform includes a main controller, backplane, interface board, adapter board, mouse, keyboard, and monitor. The main controller runs the testing software and underlying drivers; the interface board is compatible with commonly used interface protocols; the backplane has mixed slots and supports standard boards such as VPX, PXIe, and CPCIe (including but not limited to the standard boards mentioned in this document), providing power interfaces and interconnection channels for the main controller and interface boards; the adapter board is mainly used for non-standard cryptographic machine testing scenarios, connecting the interface board and the cryptographic machine to achieve differential to single-ended conversion and to measure the startup time and power consumption of the cryptographic machine, improving the anti-interference performance of the business interface, enhancing environmental adaptability, and expanding application scenarios.
[0035] This invention provides a universal cryptographic machine testing platform. By adopting a hybrid backplane that supports multiple standard boards, a high-performance main controller, and interface boards and adapter boards that are compatible with multiple interface protocols and physical interfaces, it realizes functions such as universal and large-scale testing and cryptographic machine hardware parameter measurement.
[0036] (I) How to achieve universality?
[0037] The main difficulties in implementing a universal cryptographic machine testing platform are: (1) the external interface protocols of cryptographic machines are different; secondly, the physical links for transmitting signals include single-ended signals and differential signals, as well as low-speed signals and high-speed signals. Therefore, to implement a universal cryptographic machine testing platform, it is necessary to solve the problems of different external interface protocols and physical links of cryptographic machines, and different physical shapes and sizes of cryptographic machines. Through the classification and summary of the business interface protocols and physical forms of common cryptographic machines, the universal cryptographic machine testing platform can be divided into the following three application scenarios.
[0038] (1) Standard board form cryptographic machine
[0039] Common standard board-type cryptographic machines (VPX, PXIe, CPCIe) typically use high-speed point-to-point communication for their service interfaces, employing protocols such as PCIe, SRIO, and Gigabit or 10 Gigabit Ethernet. The external interface is located on the board's backplane connector. For this scenario, the cryptographic test platform can use a hybrid slot backplane, which must support multiple board standards, such as VPX, PXIe, and CPCIe. In this case, the cryptographic machine can be directly plugged into the backplane of the cryptographic test platform. The backplane provides information exchange and power supply channels for the master controller and the tested standard board-type cryptographic machine. The master controller runs test software to perform performance and functional tests on the cryptographic machine. Standard board-type cryptographic machine testing scenarios only require the master controller and backplane, such as... Figure 2 As shown.
[0040] (2) Standard equipment cryptographic machine
[0041] Standard form factor cryptographic devices are most commonly rack-mounted server cryptographic machines. These typically use standard Ethernet (electrical or optical) interfaces, supporting the TCP / IP protocol. This solution's interface board supports interchangeable electrical (RJ45, twisted pair) and optical (SFP, fiber optic) interfaces. The optical interface speed can reach up to 10Gbps. Replaceable optical and electrical ports include... Figure 3 As shown. Through replaceable physical interfaces, this test platform is compatible with commonly used server cryptographic machines.
[0042] Another advantage of this testing platform is that the main controller also has a standard Ethernet interface. If only one cryptographic machine with a standard Ethernet interface is being tested, the main controller becomes the cryptographic testing platform. The testing software or function library running on the main controller can then be used to test the performance and functionality of the cryptographic machine.
[0043] In this test scenario, if multiple devices with standard Ethernet interfaces need to be tested simultaneously, the test platform consists of a main controller, interface boards, and a backplane; if there is only one device under test, only the main controller and backplane are needed.
[0044] (3) Non-standard cipher machine
[0045] Non-standard cryptographic machines come in various forms and offer numerous choices for their business interface protocols. Therefore, an interface board is essential. It must be compatible with multiple interface protocols and adapt to the hybrid backplane of the test platform, making the test platform as universal as possible. The interface board can also be dedicated (achieving universality by replacing the interface board). If the non-standard cryptographic machine uses standard physical links such as twisted-pair cables or fiber optic cables as its business ports, then the interface board only needs to support the corresponding interface (optical or electrical), and can be directly connected via twisted-pair cables or fiber optic cables. If the non-standard cryptographic machine's business port involves parallel data and requires long-distance communication, the interface board can use differential transmission. Connecting a differential signal to single-ended signal adapter board to the cable at one end of the test cryptographic machine enables reliable long-distance communication. Figure 4 As shown.
[0046] (4) Interface board design
[0047] The "general functions" of the general-purpose cryptographic machine test platform are mainly achieved through the compatibility of the interface board and the backplane. The backplane can use multiple standard mixed slots, which makes it relatively easy to achieve universality.
[0048] The interface board is a standard board-type module mounted on the backplane. It interconnects directly with the cryptographic machine under test (TMD) or indirectly through an adapter board. It is compatible with multiple interface protocols and supports various standard physical interfaces. Common protocols used for TMD service ports include PCIe, SRIO, UART, SPI, TCP / IP, and IIC. Common standard physical interfaces for TCP / IP include RJ45 and SFP. PCIe and SRIO are typically used in standard board-type TMDs, interconnecting with the test platform via the TMD board's backplane connector to complete functional performance testing. Low-speed interfaces such as UART, SPI, and IIC have varying physical forms, and due to their short transmission distances and weak anti-interference capabilities, they require comprehensive consideration.
[0049] Based on the above analysis, for cipher machines in standard board form (PXIe, VPX, etc.), the cipher machine under test can be directly installed on the backplane of the test platform; if the cipher machine uses a standard physical interface RJ45 / SFP for external interconnection, then a standard physical interface can be designed on the interface board; if the cipher machine uses a low-speed interface for external interconnection, such as UART, SPI, IIC, etc., then differential signal transmission can be used, and an adapter board with differential signal to single-ended signal conversion function can be connected in series at the cipher machine device end to achieve interference-resistant long-distance communication.
[0050] This solution uses a 3U (5HP) interface board that supports board-level hot-swapping. It includes a ZYNQ connector, RS-485 bus, J30J quick-lock connector, and a single-ended to differential converter chip. Based on the ZYNQ core architecture, it can simultaneously run ARM software and FPGA logic, facilitating multi-protocol calls and logic control. The hot-swappable electrical and optical ports primarily support Ethernet protocols, with a maximum speed of 10Gbps. The RS-485 bus and single-ended to differential converter chip connect the J30J quick-lock connector and ZYNQ, receiving cryptographic hardware parameters from external adapter boards and transmitting them to the main controller. The interface board uses the J30J quick-lock connector, supporting high-speed signal transmission and up to 50 pairs of differential signals.
[0051] To ensure compatibility with general-purpose cryptographic machine testing platforms, the interface board must also meet the mechanical and electrical performance requirements of the hybrid slot backplane. The interface board's schematic diagram is as follows: Figure 5 As shown.
[0052] like Figure 5As shown, the interface board ZYNQ is the core architecture, and ZYNQ's configuration files are burned via SD card. There are two main physical forms of external interfaces: one is a replaceable optoelectronic Ethernet interface, and the other is a J30J quick-lock connector – a differential interface. The Ethernet interface is interconnected with ZYNQ via a high-speed SERDES signal, with a maximum speed of 10Gbps. The single-ended control signal LVTTL interconnected with ZYNQ is sent to a single-ended to differential chip (chip model: DS26LV31WQML) after being isolated by an optocoupler, realizing differential transmission. The interface board is interconnected with the main controller via a PCIe×4 backplane. The interface board is powered through the baseboard connector, and the hot-swap controller at the interface is used to realize board-level hot-swap functionality; the power management unit directly powers the devices in the GND domain on the board; isolation power supply 1 powers the ISO_GND1 domain circuit, corresponding to channel 1, and isolation power supply 2 powers the ISO_GND2 domain circuit, corresponding to channel 2, as shown below.
[0053] This solution uses the J30J quick-lock connector (specifically model J30JA-100ZKW-J), a 100-pin connector comprising 44 differential signal pairs and 12 ground signals (6 each for ISO_GND1 and ISO_GND2). These are divided into two channels (represented by two colors in the diagram), each channel containing 22 differential pairs (one pair for RS-485, leaving 21 freely usable pairs) and 6 ground signals. The two channels are powered by different isolated power supplies, achieving electrical isolation between the channels; simultaneously, all single-ended signals are optocoupled for internal and external board isolation.
[0054] (5) Adapter plate design
[0055] The adapter board, located between the interface board and the cipher machine under test (closer to the cipher machine due to its weak anti-interference capability during single-ended signal transmission), is an independent module (or device). Its main functions include converting the differential signal from the interface board into a single-ended signal, measuring the cipher machine's power consumption and startup time (and potentially adding environmental data acquisition), and providing an independent power supply channel for the cipher machine. The adapter board uses an MCU (STM32, etc.) as its control core. The MCU controls the cipher machine's power-on and transmits the board's power consumption and startup time to the interface board via RS-485. Precision resistors and acquisition chips are used to collect the cipher machine's power consumption. The cipher machine's startup time is the difference between its power-on time and the indicator signal it sends after normal operation. The power supply module provides power to the adapter board and the cipher machine behind it, operating independently. The adapter board can interconnect two cipher machines with up to 25-pin signals and provides an 80W load capacity, covering test scenarios where a single-board cipher machine's power consumption is below 40W. Its schematic block diagram is shown below. Figure 6 As shown.
[0056] like Figure 6As shown, the adapter board is powered by a separate 12V power connector, which is then converted to a 5V input multi-channel power supply by an isolated power module. This multi-channel power supply features a wide input range and adjustable output voltage. The multi-channel power module enables an independent channel for the MCU, while the enable pins and PGOOD signals of the other power output channels are interconnected with the MCU. Only when the MCU is functioning correctly can the enable pins of other power supplies output. The cipher machines under test are independently powered without interference. A high-precision metal film resistor (10mohm in this solution) is connected in series at each cipher machine power supply interface. The two ends of the metal film resistor are connected to the differential input terminals of the acquisition chip (LTC2991). The integrated ADC converts the acquired analog voltage signal into a digital signal, which is sent to the MCU via the IIC bus. The MCU then sends the power consumption information to the interface board via the RS-485 bus. It is important to note that the metal film resistor should be kept away from clock signals, high-speed signals, and other interference. The traces should be as short and thick as possible, and no components should be placed on the bottom layer. Complete copper plating is essential to ensure measurement accuracy.
[0057] The differential interface on the board uses a high-reliability connector (J30JZLN100ZKWA000), which can support harsh mechanical experiments such as vibration and shock (meeting GJB150.16A / 18A test requirements); the differential interface signal is still divided into two groups, which are converted into single-ended signals after passing through the differential chip DS26LV32AWQML, and then communicate with the cryptographic machine under test through the J63A connector.
[0058] Measurement of cipher machine startup time
[0059] The cipher machine startup time is measured by the MCU acquiring the PGOOD (2&3) signal generated by the multi-channel power module and the status indication signal (indicating that the cipher machine module is fully ready and working normally) signal emitted by the cipher machine. The time difference between the two signals is the startup time of the cipher machine. The MCU sends the time information to the interface board via the RS-485 bus, and the interface board then sends the time information to the main controller, thus obtaining the startup time of the cipher machine and performing the next step, such as target value comparison, and finally displaying whether it passes or fails, etc., for secondary processing.
[0060] Power consumption measurement
[0061] The power consumption detection unit is independently powered (CH1 channel). After the detection unit is working normally, it controls the power supply channel to independently power the cipher machine. A precision resistor is connected in series on each independent power supply channel. The voltage across the precision resistor is collected, converted into a digital signal, and sent to the MCU via the bus. The MCU sends the power consumption of the cipher machine to the interface board via the bus. The interface board then transmits the power consumption information to the main controller to obtain the power consumption value of the cipher machine. Subsequent secondary processing can be performed to determine whether the power consumption meets the requirements.
[0062] safe state
[0063] To prevent the ZYNQ interface board from outputting incorrect information due to uncontrollable IO status during power-up, which could lead to test failure, this solution uses the status indication signal issued by the cryptographic device under test to control the enable of the differential-to-single-ended chip (DS26LV32AWQML). Data interaction can only be performed when the device under test is fully ready, thus ensuring that the test system is in a safe and reliable state.
[0064] (ii) How to achieve simultaneous large-scale testing?
[0065] There are two main limiting factors for a testing platform to achieve large-scale testing. First, whether the platform's main software resources are sufficient; second, whether the hardware can interconnect a sufficient number of test objects.
[0066] The main controller of this general-purpose cryptographic machine testing platform is used to simulate test data and run the test environment, and is interconnected with the interface board via a PCIe bus. Both the data bus bandwidth and the onboard resources are sufficient to support large-scale testing of multiple cryptographic machines. Secondly, the cryptographic testing platform adopts a plug-in card platform, theoretically allowing for the installation of multiple interface boards. One interface board can test multiple cryptographic machines simultaneously, greatly increasing the number of cryptographic machines that can be tested concurrently. Increasing the physical size of the interface board can further increase the number of cryptographic machines that can be tested concurrently.
[0067] Implementation Case 1
[0068] The cryptographic machine involved in this case is a non-standard physical form with a single board. Its business interface uses the SPI protocol, and its management interface uses the UART protocol. The implementation block diagram for Case 1 is as follows: Figure 7 As shown in the image, this testing platform enables the functional and performance testing required for the case studies, reducing overall time consumption and improving testing efficiency.
[0069] This cryptographic machine testing platform mainly consists of a cryptographic testing platform, an adapter board, and the cryptographic machines under test (DUTs). The DUTs are interconnected with the testing platform via differential cables (SPI and UART protocols). The testing machine has 9 slots, with the main control board located in the first slot (expanding downwards). Eight peripheral slots can accommodate 8 interface boards, each interface board connecting to one adapter board. One adapter board can connect to two DUTs (the DUTs use SPI for business interfaces and full UART for management interfaces; each DUT requires 20 pins, while one adapter board supports 50 single-ended pins and 50 pairs of differential pins). Therefore, this testing platform can test 16 DUTs simultaneously. The acquisition circuitry on the adapter board can accurately and automatically measure the power consumption and startup time of the DUTs, eliminating human measurement errors and making the test results more reliable. The main control slot and all peripheral slots on the backplane of the testing machine are interconnected via PCIe 3.0 × 4 (4GB / s bandwidth), supporting high-bandwidth, high-capacity data transmission and adapting to a wider range of scenarios. Meanwhile, the test platform is simple to set up, requires fewer interconnecting cables, and simplifies the required supporting equipment, which can greatly save the platform setup time.
[0070] The key point of this invention is:
[0071] 1. Universal type;
[0072] 2. Simultaneous testing of large batches;
[0073] 3. Supports measurement of cryptographic machine hardware parameters;
[0074] 4. Since the test platform and the object under test are interconnected in a way that has anti-interference capabilities, it can support applications in harsh electromagnetic environments.
[0075] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A universal cryptographic machine testing platform, characterized in that, The test platform includes a main controller, backplane, interface board, and adapter board. The main controller runs the test software and underlying drivers; the interface board is compatible with interface protocols; the backplane has mixed slots, providing power interfaces and interconnection channels for the main controller and interface board; the adapter board is used for non-standard cipher machine testing scenarios, connecting the interface board and the cipher machine to realize differential to single-ended conversion and test the cipher machine's startup time and power consumption measurement; for cipher machines in standard board PXIe and VPX form, the cipher machine under test is directly installed on the backplane of the test platform; if the cipher machine uses the standard physical interface RJ45 / SFP for external interconnection, a standard physical interface is designed on the interface board; if the cipher machine uses low-speed interfaces UART, SPI, or IIC for external interconnection, differential signal transmission is used, and an adapter board with differential to single-ended signal conversion function is connected in series with the cipher machine and then connected to the interface board to achieve interference-resistant long-distance communication.
2. The universal cryptographic machine testing platform as described in claim 1, characterized in that, The interface board is 3U in size and supports board-level hot-swapping, including ZYNQ, RS-485 bus, J30J quick-lock connector and single-ended to differential chip; Based on the ZYNQ core architecture, it can run ARM software and FPGA logic simultaneously, facilitating multi-protocol calling and logic control; the hot-swappable and interchangeable electrical and optical ports support Ethernet protocol with a maximum speed of 10Gbps. The RS-485 bus and single-ended to differential chip are used to connect the J30J quick-lock connector and ZYNQ to receive the cryptographic machine hardware parameters collected by the external adapter board and transmit them to the main controller; the interface board uses the J30J quick-lock connector that supports high-speed signal transmission and supports up to 50 pairs of differential signals.
3. The universal cryptographic machine testing platform as described in claim 2, characterized in that, The interface board ZYNQ is the core architecture. ZYNQ can be programmed with configuration files via SD card. The Ethernet interface is interconnected with ZYNQ via high-speed SERDES signals, with a maximum speed of 10Gbps. The single-ended control signals LVTTL interconnected with ZYNQ are sent to the single-ended to differential chip after being isolated by an optocoupler to realize differential transmission. The interface board is interconnected with the main controller via PCIe×4 on the backplane.
4. The universal cryptographic machine testing platform as described in claim 3, characterized in that, The J30J quick-lock connector has 100 pins, including 44 pairs of differential signals and 12 ground signals, which are divided into two channels. Each channel has 22 pairs of differential pairs, one of which is RS-485, leaving 21 pairs available for use, and 6 ground signals. The two channels are powered by different isolated power supplies to achieve electrical isolation between the channels. At the same time, all single-ended signals are optocoupled for isolation between the board and the outside. The power management unit directly powers the devices in the GND domain on the board. Isolation power supply 1 powers the circuits in the ISO_GND1 domain, corresponding to channel 1. Isolation power supply 2 powers the circuits in the ISO_GND2 domain, corresponding to channel 2.
5. The universal cryptographic machine testing platform as described in any one of claims 1-4, characterized in that, The adapter board is located between the interface board and the cryptographic machine under test. It converts the differential signal transmitted from the interface board into a single-ended signal, measures the power consumption and startup time of the cryptographic machine, and provides an independent power supply channel for the cryptographic machine. The adapter board uses an MCU as its control core. The MCU controls the power-on of the cryptographic machine and transmits the power consumption and startup time of the board to the interface board via RS-485. Precision resistors and acquisition chips are used to collect the power consumption of the cryptographic machine board. The startup time of the cryptographic machine is the difference between the power-on time of the cryptographic machine and the indication signal sent after it is working normally. The power module provides power to the adapter board and the cipher machine behind it, and they are independent of each other.
6. The universal cryptographic machine testing platform as described in claim 5, characterized in that, The adapter board is powered by a separate 12V power connector, which is then converted to a 5V input multi-channel power supply by an isolated power module. The multi-channel power module enables the independent channel for MCU power supply. The enable pins and PGOOD signals of the other power output channels are interconnected with the MCU. Only when the MCU is working normally can the enable pins of other power supplies be output. The cipher machines under test are powered independently without affecting each other. A high-precision metal film resistor is connected in series at the power supply interface of each cipher machine. The two ends of the metal film resistor are connected to the differential input terminals of the acquisition chip LTC2991. The ADC integrated in the chip converts the acquired analog voltage signal into a digital signal and sends it to the MCU through the IIC bus. The MCU sends the power consumption information to the interface board through the RS-485 bus.
7. The universal cryptographic machine testing platform as described in claim 6, characterized in that, Metal film resistors should be kept away from interference from clock and high-speed signals, and traces should be as short and thick as possible. No components should be placed on the bottom layer, and copper should be completely poured in.
8. The universal cryptographic machine testing platform as described in claim 6, characterized in that, The cipher machine startup time is measured by the MCU acquiring the PGOOD signal generated by the multi-channel power module and the status indication signal issued by the cipher machine. The time difference between the two signals is the startup time of the cipher machine. The MCU sends the time information to the interface board via the RS-485 bus, and the interface board then sends the time information to the main controller, thus obtaining the startup time of the cipher machine and proceeding to the next step. Finally, it displays whether the pass or fail is achieved.
9. The universal cryptographic machine testing platform as described in claim 6, characterized in that, The power consumption detection unit is independently powered. After the power consumption detection unit is working normally, it controls the power supply channel to independently power the cipher machine. A precision resistor is connected in series on each independent power supply channel. The voltage across the precision resistor is collected, converted into a digital signal, and sent to the MCU via the bus. The MCU sends the power consumption of the cipher machine to the interface board via the bus. The interface board then transmits the power consumption information to the main controller to obtain the power consumption value of the cipher machine. Subsequent secondary processing can be performed to determine whether the power consumption meets the requirements.
10. The universal cryptographic machine testing platform as described in claim 6, characterized in that, The differential-to-single-ended chip is enabled by using the status indication signal issued by the cipher machine under test. Data interaction can only be carried out when the device under test is fully ready, so that the test system is in a safe and reliable state.
Citation Information
Patent Citations
Automatic cipher machine test system and working method thereof
CN103441895A
Cipher machine testing device and cipher machine testing method using same
CN112269698A
System capable of performing multi-interface testing
CN110362433A
Microsystem module AC parameter test method based on ATE test machine
CN113157501A