Dual-core encryption bridge of multi-host interface to SATA bridge and encryption and decryption transmission method

By using a dual-core embedded processor module and a SATA high-speed interface to bridge the encryption and decryption transmission path, the problem of low performance of encryption bridges in existing technologies is solved, achieving efficient and flexible data encryption, decryption and transmission, and ensuring data security and transmission performance.

CN115357951BActive Publication Date: 2026-05-12TIH MICROELECTRONIC TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TIH MICROELECTRONIC TECH CO LTD
Filing Date
2022-08-19
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing encrypted bridge technologies suffer from low performance, low transmission efficiency, and limited application scenarios, making them unable to effectively protect sensitive data in terminal devices.

Method used

Employing dual-core queuing technology and a SATA high-speed interface bridging path, it achieves efficient encryption and decryption transmission of critical data through a dual-core embedded processor module, utilizes Crypto Engine for data encryption and decryption, and combines SDRAM and DTCM dual storage modes to improve transmission rate and efficiency.

Benefits of technology

It achieves efficient encryption and decryption transmission, improves data transmission rate and efficiency, supports multiple data interface types, provides flexible encryption and decryption operation options, and ensures data security and transmission performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115357951B_ABST
    Figure CN115357951B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of data security transmission, and more particularly to a dual-core encryption bridge of a multi-host interface to SATA bridge and an encryption and decryption transmission method. The dual-core encryption bridge of the multi-host interface to SATA bridge comprises a host, a dual-core embedded processor module, a first data interface, a second data interface and a total control program connected by a bus. The dual-core embedded processor module comprises a first core for receiving data transmitted by an external data interface and performing encryption and decryption, and transmitting the encrypted and decrypted data to an external interface; a second core for receiving or transmitting data from an SDRAM and monitoring each other with a DTCM; an SDRAM for storing data; a DTCM for storing a data transmission completion flag; the first core comprises a CryptoEngine for performing encryption and decryption processing on data; and the second core comprises a SATAHost for sending encrypted and decrypted data and a SATADevice for receiving encrypted and decrypted data. The application solves the problems of low performance and efficiency and limited application scenarios in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security transmission technology, and more specifically, relates to a dual-core encrypted bridge with a multi-host interface to SATA bridge and an encryption / decryption transmission method. Background Technology

[0002] With the widespread adoption of internet applications and the promotion of intelligent manufacturing in industry and commerce, the security of information storage has received increasing attention. Much of the file data stored on various terminals and servers involves sensitive and private information belonging to businesses or individuals. If hard drives are stolen or illegally accessed by internal personnel, there is a risk of information leakage, causing significant losses to businesses or individuals. In today's computer environment, many security threats exist on end-user devices. Some threats are unintentional, such as due to human error, while others are intentional. A common threat is the loss or theft of user hard drives. How to protect the data security on hard drives in the event of loss has become an urgent problem to be researched and solved.

[0003] Existing patent literature also discloses relevant solutions, such as:

[0004] Chinese patent document CN109657502A discloses a SATA bridged real-time transmission encryption system and method based on a domestically developed cryptographic algorithm. It includes a desktop system security storage control chip, a SATA DEVICE IP core, a SATAHOST IP core, and a hard drive connected sequentially. It also includes a USB HOST IP core for authenticating the storage device U_KEY plugged into the external USB port of the desktop system's security storage control chip. A Simple Data Management Protocol (SM1) module and an SM4 module for data encryption and decryption are connected to the SATA DEVICE IP core and SATA HOST IP core, respectively. Data transmission is accomplished by using registers to control two tables according to the command protocol in the FIS area.

[0005] Existing methods that add encryption chips to computer terminal hardware to encrypt and decrypt data written to the hard drive mostly use encryption bridges. SATA, short for Serial Advanced Technology Attachment, is an industry-standard serial hardware drive interface specification jointly proposed by Intel, IBM, Dell, APT, Maxtor, and Seagate. This solution only uses a USB interface for external data transmission, and the patent document is based on single-core encrypted data transmission, which is a serial process. The algorithm only includes domestically developed cryptographic algorithms, limiting its applicability. This solution incurs performance degradation during application, limiting the high-bandwidth performance of the high-speed interface. Summary of the Invention

[0006] The present invention aims to overcome at least one of the defects of the prior art and provide a dual-core encrypted bridge with a multi-host interface to SATA bridge.

[0007] This invention also discloses an encryption and decryption transmission method for a multi-host interface to SATA bridge, which solves the problems of low performance, low transmission efficiency and limited application scenarios of encryption bridges in the prior art.

[0008] This invention relies on dual-core queue technology and the underlying SATA high-speed interface bridging path to achieve efficient encrypted transmission of critical data.

[0009] Technical Terminology Explanation:

[0010] 1. SDRAM: It is an abbreviation for synchronous dynamic random-access memory.

[0011] 2. DTCM: This is an abbreviation for Data Tightly Coupled Memory.

[0012] 3. Crypto Engine: refers to the encryption engine;

[0013] 4. DMA: refers to Direct Memory Access;

[0014] 5. SATA Host: refers to a SATA host;

[0015] 6. SATA Device: Refers to SATA devices.

[0016] The detailed technical solution of this invention is as follows:

[0017] A dual-core encrypted bridge with a multi-host interface to SATA interface includes a host, a dual-core embedded processor module, a first data interface, a second data interface, and a main control program connected via a bus. The dual-core embedded processor module includes: a first core for receiving data transmitted through the external data interface and performing encryption / decryption processing, and transmitting the encrypted / decrypted data to the external data interface; a second core for receiving or transmitting encrypted / decrypted data from SDRAM and monitoring each other with a DTCM; SDRAM for storing data; a DTCM for storing a data transmission completion flag; the first and second cores share the DTCM and SDRAM; the first core includes a Crypto Engine for encrypting / decrypting data; the second core includes a SATA Host for sending encrypted / decrypted data and a SATA Device for receiving encrypted / decrypted data.

[0018] The host transmits data to the dual-core embedded processor module via the first data interface. The data is then encrypted by the dual-core embedded processor and transmitted out via the second data interface. The dual-core embedded processor module includes a first core, a second core, SDRAM, and a DTCM. The first core includes a Crypto Engine, and the second core includes a SATA Host and a SATA Device. After being encrypted by the Crypto Engine, the data is first stored in the SDRAM. Because the DTCM tracks the SDRAM synchronously, it sets a completion flag when the data storage in the SDRAM is complete. Furthermore, the second core of the dual-core embedded processor and the DTCM monitor each other, greatly improving the transmission rate. This dual-storage mode of SDRAM and DTCM—where SDRAM stores the data and the DTCM stores the flag—makes data less prone to loss and errors while also improving transmission efficiency.

[0019] The abbreviations or Chinese definitions of SDRAM (synchronous dynamic random-access memory), DTCM (data tightly coupled memory), Crypto Engine, SATA Host, and SATA Device are industry terms.

[0020] Furthermore, the dual-core embedded processor module includes: a first dual-core embedded processor and a second dual-core embedded processor; the SATA Host in the second core of the first dual-core embedded processor and the SATA Device in the second core of the second dual-core embedded processor are connected via a data transmission line; the SATA Device in the second core of the first dual-core embedded processor and the SATA Host in the second core of the second dual-core embedded processor are connected via a data transmission line.

[0021] Two dual-core embedded processors are connected via a data transmission line. The first data interface is for the first dual-core embedded processor, and the second data interface is for the second dual-core embedded processor. Each dual-core embedded processor has two cores. Both processors can perform data encryption, decryption, and transmission. This dual-core architecture allows data to enter through either the first or second data interface, or simultaneously, without interference. Furthermore, when processing multiple data packets, the two processors operate more smoothly, improving transmission efficiency and speed.

[0022] Preferably, the data interface includes a USB / PCIE / GMAC / SATA / SAS interface or other data interfaces. Multiple types of data interfaces are supported, and the choice of high-speed interface type is irrelevant to this invention.

[0023] Furthermore, the data between the SATA Host of the first dual-core embedded processor and the SATA Device of the second dual-core embedded processor is transmitted via SATA DMA;

[0024] Data is transferred between the SATA Device of the first dual-core embedded processor and the SATA Host of the second dual-core embedded processor via SATA DMA.

[0025] The SATA DMA transmission mode, also known as direct storage access mode, makes data transmission between the SATA Device of the first dual-core embedded processor and the SATA Host of the second dual-core embedded processor more efficient, improving the efficiency of encryption, decryption, and transmission of multiple data packets.

[0026] This invention also provides an encryption / decryption transmission method for a multi-host interface to SATA bridge, comprising:

[0027] Data configuration steps: The host issues data-related configuration commands according to the defined protocol: pass-through, encryption, or decryption;

[0028] Data encryption / decryption steps: After the dual-core embedded processor module receives the configuration command, the data to be encrypted / decrypted enters the dual-core embedded processor module through the data interface. The first core of the dual-core embedded processor module receives the data to be encrypted / decrypted and sends it to Crypto Engine, and starts encryption / decryption.

[0029] Data transmission steps: The encrypted and decrypted data is stored in the SDRAM of the dual-core embedded processor module, and a data storage completion flag is set in the DTCM of the dual-core embedded processor module. The second core of the dual-core embedded processor module monitors the DTCM of the dual-core embedded processor module in real time. When the SATAHost of the second core of the dual-core embedded processor module receives the data reception completion flag, the data is transmitted out through the SATA interface.

[0030] Furthermore, when the dual-core embedded processor module has only one dual-core processor, the second data interface is a SATA interface. The encryption, decryption, and data transmission steps are as follows:

[0031] a1. The host issues configuration commands according to the predefined protocol to set the parameters for this transmission: first, it selects the transmission method as transparent transmission, encryption, or decryption; then, it sets the parameters for the encryption / decryption algorithm and mode based on the transmission method. (The specific selection of encryption algorithm and mode parameters, as well as the key management method, are unrelated to the technical framework proposed in this invention. The encryption device of this invention needs to have a built-in encryption engine, which can use any symmetric encryption algorithm such as AES, SM1, or SM4 to encrypt and decrypt the data flowing through it. Regarding key management, encryption keys can be generated internally randomly, negotiated through asymmetric algorithms such as RSA or SM2, or any other acceptable key management method can be used.)

[0032] b1. After receiving the configuration command, the first dual-core embedded processor will reply to the host that the configuration is successful if it supports the configuration, and then continue data transmission; if it does not support the configuration, it will reply to the host that the configuration failed, and the host will need to return to step 1 to reconfigure.

[0033] c1, after successful configuration, the data to be encrypted / decrypted enters the first dual-core embedded processor through the data interface; the data to be encrypted / decrypted is the data before it enters the dual-core embedded processor.

[0034] d1, the first core of the first dual-core embedded processor receives the data to be encrypted / decrypted to the Crypto Engine and initiates encryption / decryption;

[0035] e1, the encrypted and decrypted data is stored in the SDRAM of the first dual-core embedded processor, and a data storage completion flag is set in the DTCM of the first dual-core embedded processor, and the second core of the first dual-core embedded processor is notified: the data has been received.

[0036] f1, the second core of the first dual-core embedded processor monitors the DTCM of the first dual-core embedded processor in real time. When it receives a flag indicating that the data reception is complete, it starts the SATA DMA of the first dual-core embedded processor and transmits the data to the SATA interface through the SATA Host of the first dual-core embedded processor.

[0037] Furthermore, when the dual-core embedded processor module includes a first dual-core embedded processor and a second dual-core embedded processor, the data transmission step includes:

[0038] a2, the host sends configuration commands according to the defined protocol to set the parameters of this transmission: first, select the transmission method as transparent transmission, encryption or decryption, and then set the parameters of encryption and decryption algorithm and encryption and decryption mode according to the transmission method;

[0039] b2. After receiving the configuration command, the first dual-core embedded processor will reply to the host that the configuration is successful if it supports the configuration, and then continue data transmission; if it does not support the configuration, it will reply to the host that the configuration failed, and the host will need to return to step 1 to reconfigure.

[0040] c2, the data to be encrypted / decrypted enters the first dual-core embedded processor through the data interface;

[0041] d2, the first core of the first dual-core embedded processor receives the data to be encrypted / decrypted to the Crypto Engine and initiates encryption / decryption;

[0042] e2, the encrypted and decrypted data is stored in the SDRAM of the first dual-core embedded processor, and a data storage completion flag is set in the DTCM of the first dual-core embedded processor, and the second core of the first dual-core embedded processor is notified: the data has been received.

[0043] f2, the second core of the first dual-core embedded processor monitors the DTCM of the first dual-core embedded processor in real time. When it receives a flag indicating that the data reception is complete, it starts the SATA DMA of the first dual-core embedded processor and sends the SDRAM data to the SATADevice of the second dual-core embedded processor through the SATA Host of the first dual-core embedded processor.

[0044] g2, the SATA Device of the second dual-core embedded processor receives data and transmits it to the SDRAM of the second dual-core embedded processor;

[0045] h2, after the data reception is completed, the data reception completion flag is set through the DTCM of the second dual-core embedded processor and the first core of the second dual-core embedded processor is notified;

[0046] i2, the first core of the second dual-core embedded processor monitors the DTCM of the second dual-core embedded processor in real time. When it receives a flag indicating that data reception is complete, it starts the data interface to transmit the data.

[0047] Furthermore, when the host sends multiple data packets sequentially, the dual-core embedded processor module operates on them including:

[0048] Once the first data packet, Data Pack 0, is encrypted and decrypted, the first core of the first dual-core embedded processor notifies the second core of the first dual-core embedded processor through the DTCM of the first dual-core embedded processor that there is data to be sent in SDRAM; at this time, the SATA DMA of the first dual-core embedded processor is started, and the data is sent to the second dual-core embedded processor through the SATA Host of the second core of the first dual-core embedded processor.

[0049] After the second core SATA of the first dual-core embedded processor finishes sending Data Pack 0, it notifies the first core of the first dual-core embedded processor through the DTCM of the first dual-core embedded processor that it can continue to receive new data packets.

[0050] Once the Crypto Engine of the first core of the first dual-core embedded processor has completed encrypting and decrypting the first data packet DataPack 0, the first core of the first dual-core embedded processor can continue to receive the second data packet Data Pack 1.

[0051] The encryption / decryption and transmission processes for the second data packet are the same as those for the first data packet, Data Pack 0.

[0052] Furthermore, the data to be encrypted or decrypted can enter through either the first data interface or the second data interface.

[0053] Both the first and second data interfaces can be used as data input or data output ends without affecting the data encryption / decryption and transmission processes, greatly facilitating users' encryption / decryption operations and eliminating the need to select a data interface.

[0054] Furthermore, the parameters configured on the host of the first data interface and the host of the second data interface can be the same or different, and the parameters at both ends are independent of each other and do not affect each other.

[0055] Users can perform encryption and decryption using both the first and second data interfaces simultaneously. Furthermore, the encryption, decryption, and transmission parameters configured on both hosts can be the same or different, providing users with a wide range of choices and greatly improving user efficiency.

[0056] Furthermore, both the first dual-core embedded processor and the second dual-core embedded processor each have one SATAHost and one SATA Device;

[0057] Data is transferred between the SATA Host of the first dual-core embedded processor and the SATA Device of the second dual-core embedded processor via SATA DMA, a process that does not require the involvement of the second core.

[0058] Data between the SATA Host of the second dual-core embedded processor and the SATA Device of the first dual-core embedded processor is transferred via SATA DMA, a process that does not require the involvement of the second core.

[0059] The data transmission in both directions mentioned above can be carried out almost simultaneously, which greatly improves the efficiency of bidirectional transmission. Theoretical and experimental results show that the performance of bidirectional simultaneous transmission is not much different from that of unidirectional transmission.

[0060] Furthermore, the first kernel can be a CK core, and the second kernel can be an ARM core. The type of kernel can be selected based on factors such as the host, hardware, and intended use.

[0061] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0062] (1) The present invention provides a dual-core encrypted bridge with a multi-host interface to SATA bridge. The structure is modular and highly versatile, and can be easily ported. The product form can be a USB / GMAC / PCIE / SATA / SAS encrypted transmission bridge, etc.

[0063] (2) The present invention provides an encryption and decryption transmission method for a multi-host interface to SATA bridge. The key in the encryption and decryption process can be generated by negotiation through asymmetric algorithms such as RSA and SM2 to ensure security.

[0064] (3) The encryption and decryption transmission method of the multi-host interface to SATA bridge provided by the present invention adopts dual-core communication, multi-queue management and SATA 3.0 high-speed bridge, making full use of the high bandwidth of the high-speed interface, and the encryption, decryption and transmission are very efficient.

[0065] (4) The present invention provides an encryption and decryption transmission method for a multi-host interface to SATA bridge. The method supports bidirectional, synchronous, asynchronous encryption and decryption and transmission modes, and realizes high-efficiency and high-performance encryption, decryption and transmission data. Attached Figure Description

[0066] Figure 1 This is an overall framework diagram of the present invention.

[0067] Figure 2 This is a schematic diagram of the one-way data encryption / decryption and transmission process in Embodiment 1 of the present invention.

[0068] Figure 3 This is a schematic diagram of the encryption, decryption, and transmission process of one-way multiple data packets in Embodiment 2 of the present invention.

[0069] Figure 4 This is a schematic diagram of the encryption, decryption, and transmission process of a bidirectional single data packet in Embodiment 3 of the present invention.

[0070] Figure 5 This is a schematic diagram (left) of the encryption, decryption, and transmission process of bidirectional multiple data packets in Embodiment 3 of the present invention.

[0071] Figure 6This is a schematic diagram (right) of the encryption, decryption, and transmission process of bidirectional multiple data packets in Embodiment 3 of the present invention.

[0072] Figure 7 This is a partially enlarged schematic diagram of the encryption, decryption, and transmission process of bidirectional multiple data packets in Embodiment 3 of the present invention.

[0073] Figure 8 This is a schematic diagram of a bidirectional data transmission and reception queue for bidirectional asynchronous queue management in Embodiment 4 of the present invention.

[0074] Figure 9 This is a schematic diagram of the data sender queue in Embodiment 4 of the present invention.

[0075] Figure 10 This is a schematic diagram of the data receiver queue in Embodiment 4 of the present invention.

[0076] Figure 11 This is a schematic diagram of the logical connection relationship of the data queues of the two embedded processors in Embodiment 4 of the present invention.

[0077] The first kernel in the diagram is an example of the CK kernel, and the second kernel is an example of the ARM kernel, but the scope of protection of this invention is not limited to the CK kernel and the ARM kernel.

[0078] The abbreviations and English definitions in the diagram are as follows: CPU 1 (first dual-core embedded processor), CPU 2 (second dual-core embedded processor), DataPack1 0 (first data packet from the first dual-core processor), DataPack1 1 (second data packet from the first dual-core processor), DataPack11 0 (first data packet from the second dual-core processor), and DataPack11 1 (second data packet from the second dual-core processor). Detailed Implementation

[0079] The present disclosure will be further described below with reference to the accompanying drawings and embodiments.

[0080] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of this disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0081] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments according to this disclosure. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms “comprising” and / or “including” are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0082] Where there is no conflict, the embodiments and features described herein can be combined with each other.

[0083] Example 1

[0084] This embodiment provides a dual-core encrypted bridge and method for a multi-host interface to SATA bridge. In this embodiment, the first core is a CK core and the second core is an ARM core, but the scope of protection of this invention is not limited to the CK core and the ARM core, as shown in Figure 1. Figure 2 As shown.

[0085] The technical solution adopted in this invention is a dual-core encrypted bridge with a multi-host interface to SATA bridge, including a host, a dual-core embedded processor module, a first data interface, a second data interface, and a main control program connected via a bus. The dual-core embedded processor module includes: a first core for receiving data transmitted from the external data interface and performing encryption / decryption processing, and transmitting the encrypted / decrypted data to the external data interface; a second core for receiving or transmitting encrypted / decrypted data from SDRAM and monitoring each other with the DTCM; SDRAM for storing data; and a DTCM for storing a flag indicating data transmission completion. The first and second cores share the DTCM and SDRAM. The first core includes a Crypto Engine for encrypting / decrypting data. The second core includes a SATA Host for sending encrypted / decrypted data and a SATA Device for receiving encrypted / decrypted data.

[0086] The host transmits data to the dual-core embedded processor module via the first data interface. The data is then encrypted by the dual-core embedded processor and transmitted out via the second data interface. The dual-core embedded processor module includes a first core, a second core, SDRAM, and a DTCM. The first core includes a Crypto Engine, and the second core includes a SATA Host and a SATA Device. After being encrypted by the Crypto Engine, the data is first stored in the SDRAM. Because the DTCM tracks the SDRAM synchronously, it sets a completion flag when the data storage in the SDRAM is complete. Furthermore, the second core of the dual-core embedded processor and the DTCM monitor each other, greatly improving the transmission rate. This dual-storage mode of SDRAM and DTCM—where SDRAM stores the data and the DTCM stores the flag—makes data less prone to loss and errors while also improving transmission efficiency.

[0087] This embodiment provides an encryption and decryption transmission method for a multi-host interface to SATA bridge. When the dual-core embedded processor module has only one dual-core embedded processor, its unidirectional data encryption, decryption, and transmission process includes steps a~f:

[0088] a1. The host sends configuration commands according to the defined protocol to set the parameters of this transmission: first, select the transmission method as transparent transmission, encryption or decryption, and then set the parameters of encryption and decryption algorithm and encryption and decryption mode according to the transmission method.

[0089] b1. After receiving the configuration command, the first dual-core embedded processor will reply to the host that the configuration is successful if it supports the configuration, and then continue data transmission; if it does not support the configuration, it will reply to the host that the configuration failed, and the host will need to return to step 1 to reconfigure.

[0090] c1, after successful configuration, the data to be encrypted / decrypted enters the first dual-core embedded processor through the data interface; the data to be encrypted / decrypted is the data before it enters the dual-core embedded processor.

[0091] d1, the first core of the first dual-core embedded processor receives the data to be encrypted / decrypted to the Crypto Engine and initiates encryption / decryption;

[0092] e1, the encrypted and decrypted data is stored in the SDRAM of the first dual-core embedded processor, and a data storage completion flag is set in the DTCM of the first dual-core embedded processor, and the second core of the first dual-core embedded processor is notified: the data has been received.

[0093] f1: The second core of the first dual-core embedded processor monitors the DTCM of the first dual-core embedded processor in real time. When it receives a flag indicating that data reception is complete, it initiates the SATA DMA of the first dual-core embedded processor and transmits the data to the SATA interface through the SATA Host of the first dual-core embedded processor.

[0094] Furthermore, the dual-core embedded processor module includes: a first dual-core embedded processor and a second dual-core embedded processor; the SATA Host in the second core of the first dual-core embedded processor and the SATA Device in the second core of the second dual-core embedded processor are connected via a data transmission line; the SATA Device in the second core of the first dual-core embedded processor and the SATA Host in the second core of the second dual-core embedded processor are connected via a data transmission line.

[0095] Two dual-core embedded processors are connected via a data transmission line. The first data interface is for the first dual-core embedded processor, and the second data interface is for the second dual-core embedded processor. Each dual-core embedded processor has two cores. Both processors can perform data encryption, decryption, and transmission. This dual-core architecture allows data to enter through either the first or second data interface, or simultaneously, without interference. Furthermore, when processing multiple data packets, the two processors operate more smoothly, improving transmission efficiency and speed.

[0096] Furthermore, the data between the SATA Host of the first dual-core embedded processor and the SATA Device of the second dual-core embedded processor is transmitted via SATA DMA;

[0097] Data is transferred between the SATA Device of the first dual-core embedded processor and the SATA Host of the second dual-core embedded processor via SATA DMA.

[0098] The SATA DMA transfer mode described above is a direct memory access mode, which makes data transfer between the SATA Device of the first dual-core embedded processor and the SATA Host of the second dual-core embedded processor more efficient, improving the efficiency of encryption, decryption, and transmission of multiple data packets.

[0099] When a dual-core embedded processor module has two dual-core embedded processors, its unidirectional data encryption / decryption and transmission process includes steps a~i:

[0100] a2, the host sends configuration commands according to the defined protocol to set the parameters of this transmission: first, select the transmission method as transparent transmission, encryption or decryption, and then set the parameters of encryption and decryption algorithm and encryption and decryption mode according to the transmission method;

[0101] b2. After receiving the configuration command, the first dual-core embedded processor will reply to the host that the configuration is successful if it supports the configuration, and then continue data transmission; if it does not support the configuration, it will reply to the host that the configuration failed, and the host will need to return to step 1 to reconfigure.

[0102] c2, the data to be encrypted / decrypted enters the first dual-core embedded processor through the data interface;

[0103] d2, the first core of the first dual-core embedded processor receives the data to be encrypted / decrypted to the Crypto Engine and initiates encryption / decryption;

[0104] e2, the encrypted and decrypted data is stored in the SDRAM of the first dual-core embedded processor, and a data storage completion flag is set in the DTCM of the first dual-core embedded processor, and the second core of the first dual-core embedded processor is notified: the data has been received.

[0105] f2, the second core of the first dual-core embedded processor monitors the DTCM of the first dual-core embedded processor in real time. When it receives a flag indicating that the data reception is complete, it starts the SATA DMA of the first dual-core embedded processor and sends the SDRAM data to the SATADevice of the second dual-core embedded processor through the SATA Host of the first dual-core embedded processor.

[0106] g2, the SATA Device of the second dual-core embedded processor receives data and transmits it to the SDRAM of the second dual-core embedded processor;

[0107] h2, after the data reception is completed, the data reception completion flag is set through the DTCM of the second dual-core embedded processor and the first core of the second dual-core embedded processor is notified;

[0108] i2, the first core of the second dual-core embedded processor monitors the DTCM of the second dual-core embedded processor in real time. When it receives a flag indicating that data reception is complete, it starts the data interface to transmit the data.

[0109] Example 2:

[0110] The purpose of this embodiment is to provide an encryption and decryption transmission method for a multi-host interface to SATA bridge under two dual-core embedded processors. In this embodiment, the first core is an CK core, and the second core is an ARM core. However, the scope of protection of this invention is not limited to CK cores and ARM cores. Figure 3 As shown. When the dual-core embedded processor module has two dual-core embedded processors, its unidirectional multi-data packet encryption / decryption and transmission process includes the following steps:

[0111] Once the first data packet, Data Pack 0, is encrypted and decrypted, the first core of the first dual-core embedded processor notifies the second core of the first dual-core embedded processor via the DTCM of the first dual-core embedded processor that there is data to be sent in SDRAM.

[0112] At this time, the SATA DMA of the first dual-core embedded processor is started, and data is sent to the second dual-core embedded processor through the SATA Host of the second core of the first dual-core embedded processor;

[0113] After the second core SATA of the first dual-core embedded processor finishes sending Data Pack 0, it notifies the first core of the first dual-core embedded processor through the DTCM of the first dual-core embedded processor that it can continue to receive new data packets.

[0114] Once the Crypto Engine of the first core of the first dual-core embedded processor has completed encrypting and decrypting the first data packet DataPack 0, the first core of the first dual-core embedded processor can continue to receive the second data packet Data Pack 1.

[0115] The encryption / decryption and transmission processes for the second data packet are the same as those for the first data packet, Data Pack 0.

[0116] Example 3:

[0117] The purpose of this embodiment is to provide an encryption and decryption transmission method for a multi-host interface to SATA bridge under two dual-core embedded processors. In this embodiment, the first core is an CK core, and the second core is an ARM core. However, the scope of protection of this invention is not limited to CK cores and ARM cores. Figure 4 , Figure 5 As shown, when the dual-core embedded processor module has two dual-core embedded processors, the encryption, decryption, and transmission processes of bidirectional single data packets and bidirectional multiple data packets are illustrated.

[0118] The data to be encrypted or decrypted can be entered through either the first data interface or the second data interface.

[0119] Both the first and second data interfaces can be used as data input or data output ends without affecting the data encryption / decryption and transmission processes, greatly facilitating users' encryption / decryption operations and eliminating the need to select a data interface.

[0120] Furthermore, the parameters configured on the host of the first data interface and the host of the second data interface can be the same or different, and the parameters at both ends are independent of each other and do not affect each other.

[0121] Furthermore, both the first dual-core embedded processor and the second dual-core embedded processor each have one SATAHost and one SATA Device;

[0122] Data is transferred between the SATA Host of the first dual-core embedded processor and the SATA Device of the second dual-core embedded processor via SATA DMA, a process that does not require the involvement of the second core.

[0123] Data between the SATA Host of the second dual-core embedded processor and the SATA Device of the first dual-core embedded processor is transferred via SATA DMA, a process that does not require the involvement of the second core.

[0124] The data transmission in both directions mentioned above can be carried out almost simultaneously, which greatly improves the efficiency of bidirectional transmission. Theoretical and experimental results show that the performance of bidirectional simultaneous transmission is not much different from that of unidirectional transmission.

[0125] The encryption, decryption, and transmission process of the bidirectional single data packet is as follows: Figure 4 As shown, since it includes the steps of the one-way data encryption / decryption and transmission process in Embodiment 1 and the one-way multi-data packet encryption / decryption and transmission process in Embodiment 2, and the two-way multi-data packet encryption / decryption and transmission process includes the two-way single-data packet encryption / decryption and transmission process, it can be easily understood by those skilled in the art, so the specific steps are not shown.

[0126] The encryption, decryption, and transmission process of the bidirectional multiple data packets is as follows: Figure 5 , 6 As shown in Figure 7, the following section will further illustrate the high bandwidth utilization of dual-core transmission by combining the bidirectional multi-line data transmission process.

[0127] Figure 5 , 6 Section 7 demonstrates the process of the device receiving, encrypting, and forwarding two data packets simultaneously from both hosts, or receiving and forwarding the data. It is important to note that:

[0128] The parameters configured on both ends of the host can be the same or different, and the parameters on both ends are independent of each other and do not affect each other.

[0129] Each of the two dual-core embedded processors has one SATA Host and one SATA Device. Data is transferred between the SATA Host and the SATA Device via SATA DMA, a process that does not require the ARM core's involvement. Figure 5 , 6 In section 7, data transmission in both directions, namely Data Pack 10 (the first data packet on the first dual-core processor side) and Data Pack 110 (the first data packet on the second dual-core processor side) (or Data Pack 11 (the second data packet on the first dual-core processor side) and Data Pack 111 (the second data packet on the second dual-core processor side)), can be carried out almost simultaneously. This greatly improves the efficiency of bidirectional transmission. Theoretical and experimental results show that the performance of bidirectional simultaneous transmission is not much different from that of unidirectional transmission.

[0130] The bidirectional multi-data packet encryption / decryption and transmission process involves both ends performing unidirectional multi-data packet encryption / decryption and transmission. Therefore, only the steps for one end performing unidirectional multi-data packet encryption / decryption and transmission are described in detail. The data encryption / decryption and transmission process at the other end is similar.

[0131] a3, the host at one end issues configuration commands according to the defined protocol to set the parameters of this transmission: first, select the transmission method as transparent transmission, encryption or decryption, and then set the parameters of encryption and decryption algorithm and encryption and decryption mode according to the transmission method; the host at the other end can also perform configuration operations, and both ends continue to perform the following operations.

[0132] b3. After receiving the configuration command, the first dual-core embedded processor will reply to the host that the configuration is successful if it supports the configuration, and then continue data transmission; if it does not support the configuration, it will reply to the host that the configuration failed, and the host will need to return to step 1 to reconfigure.

[0133] c3, the first data packet to be encrypted / decrypted, Data Pack 0, enters the first dual-core embedded processor through the data interface;

[0134] d3, the first core of the first dual-core embedded processor receives the first data packet DataPack 0 to be encrypted or decrypted to the Crypto Engine and initiates encryption and decryption;

[0135] e3, the encrypted and decrypted first data packet Data Pack 0 is stored in the SDRAM of the first dual-core embedded processor, and a data storage completion flag is set in the DTCM of the first dual-core embedded processor, and the second core of the first dual-core embedded processor is notified: the data has been received.

[0136] f3, the second core of the first dual-core embedded processor monitors the DTCM of the first dual-core embedded processor in real time. When it receives the flag that the first data packet Data Pack 0 has been received, it starts the SATA DMA of the first dual-core embedded processor and sends the first data packet Data Pack 0 of SDRAM to the SATA Device of the second dual-core embedded processor through the SATA Host of the first dual-core embedded processor.

[0137] After the second core of the first dual-core embedded processor (SATA) sends Data Pack 0, it notifies the first core of the first dual-core embedded processor (DTCM) that it can continue to receive new data packets. The first core of the first dual-core embedded processor can then continue to receive the second data packet, Data Pack 1. The encryption, decryption, and transmission processes of the second data packet are the same as those of the first data packet, Data Pack 0.

[0138] h3, the SATA Device of the second dual-core embedded processor receives the first data packet Data Pack 0 and transmits it to the SDRAM of the second dual-core embedded processor;

[0139] After the first data packet Data Pack 0 is received, the i3 processor sets the first data packet Data Pack 0 reception completion flag through the DTCM of the second dual-core embedded processor and notifies the first core of the second dual-core embedded processor.

[0140] j3, the first core of the second dual-core embedded processor monitors the DTCM of the second dual-core embedded processor in real time. When it receives the flag indicating that the first data packet Data Pack 0 has been received, it starts the data interface to transmit the first data packet Data Pack 0.

[0141] Example 4

[0142] Based on the same concept as Embodiment 3, this embodiment provides a multi-host interface to SATA bridge encryption and decryption transmission method based on two dual-core embedded processors for bidirectional data encryption, decryption, and transmission. The main difference from Embodiment 3 is that bidirectional data transmission can operate simultaneously and independently, either synchronously or asynchronously, and relies on independent bidirectional queue management to make the encryption, decryption, and transmission method more complete and standardized. In this embodiment, the first core is an CK core, and the second core is an ARM core. However, the scope of protection of this invention is not limited to CK cores and ARM cores. Figure 8 , 9 As shown in Figures 10 and 11.

[0143] 1. The DTCM area contains two independent arrays of queue pointers, namely TX_Queue and RX_Queue.

[0144] 2. Each Queue contains multiple Buffers, the number and length of which can be changed by the user as needed.

[0145] 3. Each embedded processor acts as both a data sender and a data receiver. The data sender uses TX_Queue, and the data receiver uses RX_Queue.

[0146] 4. The data sender uses a linked list of buffers (each buffer is linked end-to-end to form a chain) to receive and forward data, see [link to relevant documentation]. Figure 7 :

[0147] The peripherals connected to the two ends of the queue are a Productor that generates data and a Consumer that receives data. Figure 7The high-speed interface of the CK core is the Productor, while the SATA interface of the ARM core is the Consumer.

[0148] During program execution, the Productor continuously adds generated data into each Buffer in the queue and marks the Buffer as filled with data in the DTCM. If each Buffer is full when data is added, it waits.

[0149] The Consumer will retrieve data from each buffer in the queue in sequence, and similarly, it will wait if each buffer is empty.

[0150] Once the data arrives at the Buffer from the Productor, it is retrieved by the Consumer.

[0151] 5. The data receiver also uses a linked list of buffers (each buffer is linked end-to-end to form a chain) to receive and forward data, see [link to relevant documentation]. Figure 10 :

[0152] Conversely to the data sender, Figure 10 The SATA interface for the ARM core is the Productor, while the high-speed interface for the CK core is the Consumer.

[0153] During program execution, the Productor continuously adds received data into each Buffer in the queue and marks the Buffer as filled with data in the DTCM. If each Buffer is full when data is added, it waits.

[0154] The Consumer will retrieve data from each Buffer in the queue in sequence, and similarly, it will wait if each Buffer is empty.

[0155] Once the data arrives at the Buffer from the Productor, it is retrieved by the Consumer.

[0156] The logical connection relationship of the data queues of the two dual-core embedded processors is as follows: Figure 11 As shown.

[0157] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solution of the present invention, and are not intended to limit the specific implementation of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the claims of the present invention should be included within the protection scope of the claims of the present invention.

Claims

1. A dual-core encrypted bridge with a multi-host interface to SATA bridge, characterized in that, The host, the dual-core embedded processor module, the first data interface, the second data interface, and the total control program are connected through a bus; The dual-core embedded processor module comprises: a first core for receiving and decrypting / encrypting data transmitted by the external data interface, and transmitting the decrypted / encrypted data to the external data interface; a second core for receiving or transmitting the decrypted / encrypted data from the SDRAM, and monitoring each other with the DTCM; an SDRAM for storing data; a DTCM for storing a flag indicating completion of data transmission; the first core and the second core share the DTCM and the SDRAM; the first core comprises a Crypto Engine for decrypting / encrypting data; the second core comprises a SATA Host for sending the decrypted / encrypted data and a SATA Device for receiving the decrypted / encrypted data; the dual-core embedded processor module comprises a first dual-core embedded processor and a second dual-core embedded processor; the SATA Host in the second core of the first dual-core embedded processor is connected to the SATA Device in the second core of the second dual-core embedded processor through a data transmission line; the SATA Device in the second core of the first dual-core embedded processor is connected to the SATA Host in the second core of the second dual-core embedded processor through a data transmission line.

2. The dual-core encryption bridge of the multi-host interface to SATA bridge according to claim 1, wherein the first dual-core embedded processor and the second dual-core embedded processor each have one SATA Host and one SATA Device; the SATA Host of the first dual-core embedded processor and the SATA Device of the second dual-core embedded processor transmit data through SATA DMA; the SATA Host of the second dual-core embedded processor and the SATA Device of the first dual-core embedded processor transmit data through SATA DMA.

3. The dual-core encryption bridge of a multi-host interface-to-SATA bridge of claim 1, wherein, The data interface comprises a USB / PCIE / GMAC / SATA / SAS interface or other data interface.

4. The encryption and decryption transmission method of the dual-core encryption bridge of the multi-host interface to SATA bridge according to any one of claims 1-3, wherein, The method comprises: a data configuration step, in which the host issues a configuration command related to data according to a defined protocol: transparent transmission, encryption, or decryption; a data encryption / decryption step, in which when the dual-core embedded processor module receives the configuration command, the data to be encrypted / decrypted enters the dual-core embedded processor module through the data interface, the first core of the dual-core embedded processor module receives the data to be encrypted / decrypted to the Crypto Engine, and the encryption / decryption is started. The data transmission process involves storing the encrypted and decrypted data in the SDRAM of the dual-core embedded processor module and setting a data storage completion flag in the DTCM of the dual-core embedded processor module. The second core of the dual-core embedded processor module monitors the DTCM of the dual-core embedded processor module in real time. When the SATAHost of the second core of the dual-core embedded processor module receives the flag indicating that the data has been received, the data is transmitted out through the SATA interface.

5. The encryption and decryption transmission method of the dual-core encryption bridge of the multi-host interface to SATA bridge according to claim 4, characterized in that, The dual-core embedded processor module includes a first dual-core embedded processor and a second dual-core embedded processor; The data transmission step further includes: The SATA Host in the second core of the first dual-core embedded processor transmits data to the SATA Device in the second core of the second dual-core embedded processor. The SATA Device of the second dual-core embedded processor receives data and transmits it to the SDRAM of the second dual-core embedded processor; The DTCM of the second dual-core embedded processor sets the data reception completion flag and notifies the first core of the second dual-core embedded processor; The first core of the second dual-core embedded processor monitors the DTCM of the second dual-core embedded processor in real time. When the first core of the second dual-core embedded processor receives a flag indicating that the data reception is complete, it transmits the data out of the data interface of the second dual-core embedded processor.

6. The method of claim 4, wherein the method further comprises: When the host sends multiple data packets sequentially, the dual-core embedded processor module performs the following operations: Once the first data packet, Data Pack 0, is encrypted and decrypted, in the first dual-core embedded processor, the first core notifies the second core via DTCM that there is data to be sent in SDRAM. At this time, the SATA DMA of the first dual-core embedded processor is started, and data is sent to the second dual-core embedded processor through the SATA Host of the second core of the first dual-core embedded processor; In the first dual-core embedded processor, after the second core's SATAHost has finished sending Data Pack 0, it notifies the first core via DTCM to continue receiving new data packets; In the first dual-core embedded processor, after the Crypto Engine of the first core completes the encryption and decryption of the first data packet DataPack 0, the first core continues to receive the second data packet Data Pack 1; The encryption / decryption and transmission processes for the second data packet are the same as those for the first data packet, Data Pack 0.

7. The encryption and decryption transmission method of a dual-core encrypted bridge with a multi-host interface to SATA bridge according to claim 5, characterized in that, The data to be encrypted or decrypted enters through either the first data interface or the second data interface.

8. The encryption and decryption transmission method of the dual-core encryption bridge of the multi-host interface to SATA bridge according to claim 6, wherein, The host at the first data interface and the host at the second data interface are configured independently of each other.

9. The method of claim 4, wherein the method further comprises: receiving a request from a host to encrypt or decrypt a data packet; and encrypting or decrypting the data packet in response to the request. The first core is a CK core or other cores, and the second core is an ARM core or other cores.