A Secure Network Card Based on PCIe Interface and Its Implementation Method

Through the design of a secure network card based on PCIe interface, multiple CPUs are used to realize the internal security logic of the network card, the problems of difficult debugging, long development cycle and high cost in the existing technology are solved, and flexible function upgrades and cost reduction are achieved.

CN115765971BActive Publication Date: 2025-07-04QINGDAO FANGCUN MICROELECTRONIC TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211338053.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2025-07-04
Estimated Expiration
2042-10-28

AI Technical Summary

Technical Problem

The existing security network card implementation methods have problems such as difficult debugging, long development cycle, difficult function upgrade and high cost.

Method used

The secure network card design based on the PCIe interface is adopted, and multiple CPUs are used to realize the internal security logic of the network card, including PCIe controller, master CPU, slave CPU, DMA controller, encryption and decryption algorithm module and network frame transceiver. The encryption and decryption functions are realized through software, supporting flexible function upgrades and cost reduction.

Benefits of technology

It greatly reduces the difficulty and cost of development, shortens the development cycle, and facilitates subsequent function upgrades, avoiding the problems of high technical thresholds and inability to upgrade to ASICs and FPGAs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115765971B_ABST
    Figure CN115765971B_ABST
Patent Text Reader

Abstract

A secure network card based on the PCIe interface and its implementation method, including: a PCIe controller, a main CPU, a slave CPU, a DMA controller, an encryption / decryption algorithm module crypto, and a network frame transceiver GMAC; the PCIe controller is used for the host to access the internal component registers of the secure network card to complete component configuration; the main CPU is used to complete the allocation and execution of tasks in each link of the network frame transceiver pipeline; the slave CPU is used to receive the network frames confirmed by the main CPU as needing encryption / decryption; at the same time, the slave CPU feeds back the network frames after encryption or decryption processing to the main CPU; the DMA controller, according to the instructions of the main CPU, configures to read the network frames to be sent by the host to the line into the secure network card; the network frame transceiver GMAC is used to implement the online transmission of network frames and receive network frames from the line. The present invention can greatly reduce the development difficulty, greatly shorten the development cycle, facilitate subsequent function upgrades, and reduce the development cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and more specifically, relates to a secure network card based on a PCIe interface and an implementation method thereof. Background Art

[0002] With the expansion and popularization of computer technology and network technology, computer networks play an important role in many aspects such as people's study, education, work and life, and have gradually become a necessity in people's lives. People's dependence on computer networks is increasing day by day. The development of computer technology has also made computer network security technology issues increasingly prominent. Malicious hacker attacks, the wanton spread of viruses, and frequent occurrences of online illegal events have brought more troubles and nuisances to people's lives. Nowadays, network security has become a hot topic of social discussion.

[0003] To ensure the secure transmission of data in the network, encrypting the data at the source is the most effective way. Therefore, a PCIe network card with an encryption function, as an encryption tool at the source of network data, plays a crucial role in the field of network security. Among them, a secure network card is a network security terminal device that can distinguish which network traffic needs to be encrypted / decrypted and which network traffic does not need to be encrypted / decrypted according to application settings. Encrypt the network traffic that needs to be encrypted before transmission; directly transmit the network traffic that does not need to be encrypted. Conversely, for the network traffic received from the line, decrypt it before receiving; for the network traffic that does not need to be decrypted, it can be directly received.

[0004] In the implementation of previous secure network cards, to ensure performance, ASIC special chips or FPGAs are usually used. These implementation methods have the characteristics of difficult debugging, long development cycle, difficult function upgrade, and high cost. With the development of semiconductor technology, the performance of CPUs is getting stronger and stronger, and the previous hard logic implementation of secure network cards can be realized by a general-purpose CPU running code logic in software. Summary of the Invention

[0005] In view of the above technical problems, the present invention proposes a secure network card based on a PCIe interface. The present invention uses multiple CPUs to implement the internal security soft logic of the network card, greatly reducing the development difficulty, greatly shortening the development cycle, enabling flexible function upgrade, and greatly reducing the product cost.

[0006] The present invention also discloses an implementation method of the above secure network card.

[0007] The detailed technical solution of the present invention is as follows:

[0008] A secure network card based on the PCIe interface, characterized by including: a PCIe controller, a main CPU, a slave CPU, a DMA controller, an encryption and decryption algorithm module crypto, and a network frame transceiver GMAC;

[0009] The PCIe controller is used for the host to access the internal component registers of the secure network card to complete component configuration, such as configuring the network frame transceiver GMAC and configuring the encryption and decryption algorithm module crypto; the PCIe interface is the communication interface between the host and the secure network card and is the bridge for communication between the host and each internal component of the network card;

[0010] The main CPU serves as the overall commander of each functional component inside the network card and is used to complete the allocation and execution of tasks in each link of the network frame transceiver pipeline, such as firmware initialization, starting the slave CPU, system memory space management, configuring the DMA to read / write back network frames, configuring the GMAC to receive / transmit network frames, and notifying the slave CPU to encrypt / decrypt network frames, etc.;

[0011] The slave CPU is used to receive the network frames confirmed by the main CPU as needing encryption / decryption, analyze and determine how to configure the encryption and decryption algorithm module crypto to encrypt or decrypt the network frames; at the same time, the slave CPU feeds back the network frames after encryption or decryption processing to the main CPU;

[0012] The DMA controller, according to the instructions of the main CPU, configures to read the network frames that the host wants to send to the line into the secure network card to encrypt or decrypt the network frames; according to the instructions of the main CPU, configures to write the network frames received from the line after analysis and processing back to the host;

[0013] The encryption and decryption algorithm module crypto is used to encrypt and decrypt any specified data according to the configuration parameters to complete the encryption and decryption of network frame data. Users can integrate different encryption / decryption algorithms according to application needs, such as AES, DES, RSA, etc.;

[0014] The network frame transceiver GMAC is used to implement the online transmission of network frames and receive network frames from the line.

[0015] Preferably according to the present invention, the PCIe controller, with the help of an address translation module AT (address translator), maps the SRAM memory on the secure network card to the host memory space to simulate a register space (virtual register). The advantage of this design is that the SRAM inside the network card can be operated on the host just like a register; when the host writes to the virtual register, the address translation module AT generates an interrupt to the main CPU, and the main CPU responds to this interrupt and knows which virtual register the host has written to by querying the address translation module AT. The main CPU parses the content of the virtual register and executes a custom action.

[0016] When the network card modifies a certain BUG or adds a new function (such as frame filtering), etc., the firmware in the network card needs to be upgraded. At this time, the host-side driver only needs to first write the host memory address where the new firmware package to be upgraded is located to the "upgrade package address" virtual register, and then write an upgrade command to the "upgrade request" virtual register. The modification of the "upgrade request" register will be notified to the main CPU by the AT module. The main CPU parses the upgrade command from the "upgrade request" register, finds the upgrade package address from the "upgrade package address" register, and then the DMA pulls the upgrade package from the host memory into the network card memory, and finally the main CPU completes the firmware upgrade.

[0017] The implementation method of the above-mentioned secure network card is characterized by including a non-encrypted frame sending process:

[0018] 1-1) The host prepares a network frame and then writes to a virtual register to notify the secure network card to send it;

[0019] 1-2) The main CPU receives the interrupt of the address translation module AT generated by the host writing to the virtual register;

[0020] 1-3) The main CPU queries the address translation module AT to know which virtual register the host has modified;

[0021] 1-4) The main CPU reads the value of the above virtual register and determines that the host has a frame to send;

[0022] 1-5) The main CPU configures the DMA controller according to the position information of the frame to be sent by the host;

[0023] 1-6) The DMA controller reads the frame to be sent by the host into the secure network card memory and generates an interrupt to notify the main CPU;

[0024] 1-7) The main CPU analyzes the above-read frame and determines that encryption is not required according to the frame information;

[0025] 1-8) The main CPU configures the network frame transceiver GMAC according to the frame information;

[0026] 1-9) The network frame transceiver GMAC sends the frame to the line according to the above configuration.

[0027] The implementation method of the above security network card is characterized in that it further includes an encrypted frame (such as IPSec traffic) sending process:

[0028] 2-1) The host prepares a network frame and then writes to a virtual register to notify the security network card to send it;

[0029] 2-2) The main CPU receives an address translation module AT interrupt generated by the host writing to the virtual register;

[0030] 2-3) The main CPU queries the address translation module AT to find out which virtual register the host has modified;

[0031] 2-4) The main CPU reads the value of the above virtual register and determines that the host has a frame to send;

[0032] 2-5) The main CPU configures the DMA controller according to the position information of the frame to be sent by the host;

[0033] 2-6) The DMA reads the frame to be sent by the host into the network card memory and generates an interrupt to notify the main CPU;

[0034] 2-7) The main CPU analyzes the frame read in above and determines that encryption is required according to the frame information;

[0035] 2-8) The main CPU notifies the slave CPU of the frame information to be encrypted;

[0036] 2-9) The slave CPU analyzes the frame information and configures the encryption and decryption algorithm module crypto for hardware encryption accordingly;

[0037] 2-10) After the above encryption is completed, the slave CPU notifies the main CPU that the encryption is completed;

[0038] 2-11) The main CPU configures the network frame transceiver GMAC according to the frame information after encryption is completed;

[0039] 2-12) The network frame transceiver GMAC sends the frame to the line according to the above configuration.

[0040] The implementation method of the above security network card is characterized in that it further includes a non-encrypted frame receiving process:

[0041] 3-1) The main CPU configures the network frame transceiver GMAC to be ready to receive network frames;

[0042] 3-2) The host driver prepares to receive network frames and writes to a virtual register to notify the security network card that it can receive;

[0043] 3-3) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register;

[0044] 3-4) The main CPU queries the address translation module AT to find out which virtual register the host has modified;

[0045] 3-5) The main CPU reads the value of the above virtual register and determines that the host can receive network frames;

[0046] 3-6) The main CPU configures the DMA controller according to the reception information configured by the host;

[0047] 3-7) The DMA controller reads the reception information configured by the host into the network card memory and generates an interrupt to notify the main CPU;

[0048] 3-8) The main CPU saves the above reception information;

[0049] 3-9) After the network frame transceiver GMAC receives a network frame from the line, it generates an interrupt to notify the main CPU;

[0050] 3-10) The main CPU analyzes the received network frame and determines that encryption is not required;

[0051] 3-11) The main CPU configures the DMA controller according to the information saved in step 3-8) and the information of the above received frame;

[0052] 3-12) The DMA controller writes the received frame to the host and notifies the main CPU;

[0053] 3-13) The main CPU generates an interrupt to the host by writing to the register of the PCIe controller;

[0054] 3-14) The host responds to the interrupt and obtains the received network frame.

[0055] The implementation method of the above security network card is characterized in that it further includes an encrypted frame (such as IPSec traffic) reception process:

[0056] 4-1) The main CPU configures the network frame transceiver GMAC to be ready to receive network frames;

[0057] 4-2) The host driver is ready to receive network frames and writes to the virtual register to notify the security network card that it can receive;

[0058] 4-3) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register;

[0059] 4-4) The main CPU queries the address translation module AT to find out which virtual register the host has modified;

[0060] 4 - 5) The main CPU reads the above virtual register value and determines that the host can receive network frames;

[0061] 4 - 6) The main CPU configures the DMA controller according to the received information configured by the host;

[0062] 4 - 7) The DMA controller reads the received information configured by the host into the network card memory and generates an interrupt to notify the main CPU;

[0063] 4 - 8) The main CPU saves the above - received information;

[0064] 4 - 9) After the network frame transceiver GMAC receives a network frame from the line, it generates an interrupt to notify the main CPU;

[0065] 4 - 10) The main CPU analyzes the received network frame and determines that decryption is required;

[0066] 4 - 11) The main CPU notifies the slave CPU of the frame information to be decrypted;

[0067] 4 - 12) The slave CPU analyzes the frame information and configures the encryption - decryption algorithm module crypto for hardware decryption accordingly;

[0068] 4 - 13) After the above decryption is completed, the slave CPU notifies the main CPU that the decryption is completed;

[0069] 4 - 14) The main CPU configures the DMA controller according to the information saved in step 4 - 8) and the information of the frame after the above decryption;

[0070] 4 - 15) The DMA controller writes the received frame to the host and notifies the main CPU;

[0071] 4 - 16) The main CPU generates an interrupt to the host by writing the register of the PCIe controller;

[0072] 4 - 17) The host responds to the interrupt and obtains the received network frame.

[0073] The technical advantages of the present invention are as follows:

[0074] 1. The present invention provides a secure network card based on the PCIe interface and an implementation method. In terms of cost, using the CPU + software method, compared with the ASIC hardening implementation method, it can save expensive chip - making costs. Moreover, once a bug appears in the ASIC method, it cannot be repaired and requires re - design and re - chip - making. Compared with the FPGA method, the CPU itself has a higher price advantage than the FPGA, greatly reducing the development difficulty and development cost.

[0075] 2. The present invention provides a secure network card based on the PCIe interface and an implementation method. From a development perspective, the CPU + software approach of this solution has a lower technical threshold compared to ASIC and FPGA. It does not require highly professional technical personnel for development and verification. Moreover, once a problem occurs during the development process, ASIC and FPGA cannot quickly locate the problem as conveniently and flexibly as software debugging. Therefore, this solution has extremely high advantages in terms of development labor cost and development cycle, greatly shortening the development cycle.

[0076] 3. The present invention provides a secure network card based on the PCIe interface and an implementation method. From a maintenance perspective, when there are defects in the product or functional upgrades are required, the CPU + software approach of this solution only needs to modify the software to quickly and conveniently perform upgrades, while ASIC cannot be upgraded. Therefore, the present invention facilitates subsequent functional upgrades. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] Figure 1 It is a schematic diagram of the functional structure of the secure network card of the present invention.

[0078] Figure 2 It is a schematic diagram of the non-IPSec data frame structure in Embodiment 1 of the present invention.

[0079] Figure 3 It is a schematic diagram of the IPSec data frame structure in Embodiment 1 of the present invention.

[0080] Figure 4 It is a schematic diagram of the IPSec frame matching linked list structure in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0081] The present invention will be described in detail below in conjunction with the embodiments and the accompanying drawings of the specification, but is not limited thereto.

[0082] As shown in the Figure 1 accompanying drawings.

[0083] A secure network card based on the PCIe interface includes: a PCIe controller, a main CPU, a slave CPU, a DMA controller, an encryption / decryption algorithm module crypto, and a network frame transceiver GMAC;

[0084] The PCIe controller is used for the host to access the internal component registers of the secure network card to complete component configuration, such as configuring the network frame transceiver GMAC and configuring the encryption / decryption algorithm module crypto; the PCIe interface is the communication interface between the host and the secure network card and is the bridge for communication between the host and each internal component of the network card;

[0085] The main CPU, as the overall commander of each functional component inside the network card, is used to complete the allocation and execution of tasks in each link of the network frame receiving and transmitting pipeline, such as firmware initialization, starting from the CPU, system memory space management, configuring DMA for network frame reading / writing back, configuring GMAC for network frame receiving / transmitting, notifying the slave CPU to perform encryption / decryption of network frames, etc.;

[0086] The slave CPU is used to receive the network frames that the main CPU confirms need to be encrypted / decrypted, analyze and determine how to configure the encryption and decryption algorithm module crypto to encrypt or decrypt the network frames; at the same time, the slave CPU feeds back the network frames after encryption or decryption processing to the main CPU;

[0087] The DMA controller, according to the instructions of the main CPU, configures to read the network frames that the host wants to send to the line into the security network card internally to encrypt or decrypt the network frames; according to the instructions of the main CPU, configures to write the network frames received from the line after analysis and processing back to the host;

[0088] The encryption and decryption algorithm module crypto is used to encrypt and decrypt any specified data according to the configuration parameters, so as to complete the encryption and decryption of network frame data. Users can integrate different encryption / decryption algorithms according to application needs, such as AES, DES, RSA, etc.;

[0089] The network frame transceiver GMAC is used to implement the online transmission of network frames and receive network frames from the line.

[0090] Further, for sending, the data frame starts from the host driver side. The host driver places the data frame to be sent into the host memory and indicates information such as the address and length of the data frame in the host memory through virtual registers, and then still notifies the main CPU that there is data to be sent through the virtual registers. The data frame is read into the network card internally from the host and sent to physical layer devices such as the network cable or WIFI by GMAC after being processed by the network card.

[0091] Preferably, for sending, the data frame starts from the host driver side. The PCIe controller completes the host's access to the internal component registers of the security network card and completes component configuration. The network card reads the network frame information into the DMA, and notifies the main CPU after the reading / writing back is completed; at the same time, the host writes to the virtual register and notifies the main CPU that there is data to be sent through the virtual register access. At this time, the main CPU submits the network frames to be sent that need to be encrypted to the slave CPU. The slave CPU configures the encryption and decryption algorithm module crypto to encrypt or decrypt the network frames, and returns to the main CPU after the encryption and decryption are completed; the network frames that do not need to be encrypted and the encrypted network frames are submitted by the main CPU to GMAC for sending.

[0092] Further, for reception, the data frame starts from the GMAC end of the network card. The GMAC can be connected to physical layer devices such as network cables or WIFI, and obtain the data frame from physical layer devices such as network cables or WIFI. After being processed by the network card, the data frame finally reaches the host memory and is finally handed over to the host driver for processing.

[0093] Preferably, for transmission, the data frame starts from the GMAC end of the network card. The network frame received from the network is analyzed by the main CPU, and the network frame that needs to be decrypted received from the network is submitted to the slave CPU. The slave CPU configures the encryption / decryption algorithm module crypto to encrypt or decrypt the network frame. After the encryption / decryption is completed, it returns to the main CPU. At this time, the main CPU configures the network frame information to be read or the network frame information to be written back and transmits it to the DMA. The security network card then writes back the network frame information through the PCIe controller network card, and at the same time, the main CPU notifies the host that there is data to be read through virtual register access.

[0094] Further, the IPSec data frame is a data frame that may need to be encrypted / decrypted, but not all IPSec frames need to be encrypted / decrypted.

[0095] The non-IPSec data frame structure is as Figure 2 shown. The IPSec data frame adds an IPSec header after the IP header of the non-IPSec data frame and indicates the IPSec protocol in the "next layer protocol" field in the IP header, as Figure 3 shown.

[0096] When the main CPU processes a data frame, it first needs to determine whether the data frame is an IPSec frame. If it is an IPSec frame, then it needs to determine whether it needs to be encrypted / decrypted in the next step.

[0097] The method for determining whether a data frame is an IPSec frame is as follows: The CPU first finds the IP header according to the protocol, and then parses whether the value of the "next layer protocol" field in the IP header is the IPSec protocol value. If it is not the IPSec protocol value, then it is not an IPSec frame, and no encryption / decryption processing is required.

[0098] If the main CPU determines that the frame is an IPSec frame, it also needs to match according to the destination IP address in the IP header of the frame and the SPI field in the IPSec header in a screening list maintained inside the network card. If a matching item is found, encryption / decryption is performed according to the key information and control information recorded in the matching item; if no matching item is found, no encryption / decryption is performed.

[0099] Further, the network card internally maintains two groups of IPSec frame matching linked lists, one for TX query, that is, encryption; one for RX query, that is, decryption. The content of the linked list item is as Figure 4 shown:

[0100] For the IPSec frames that need encryption / decryption processing, the destination address + SPI + decryption of the frames to be encrypted / decrypted should be sent to the corresponding linked list in the network card in advance through the virtual register method in the host driver.

[0101] When the network card fixes a certain bug or adds new functions (such as frame filtering), etc., the firmware in the network card needs to be upgraded. At this time, the host-side driver only needs to first write the host memory address where the new firmware package to be upgraded is located to the "upgrade package address" virtual register, and then write the upgrade command to the "upgrade request" virtual register. The modification of the "upgrade request" register will be notified to the main CPU by the AT module. The main CPU parses the upgrade command from the "upgrade request" register, finds the upgrade package address from the "upgrade package address" register, and then the DMA pulls the upgrade package from the host memory into the network card memory, and finally the main CPU completes the firmware upgrade.

[0102] Embodiment 2

[0103] A security network card based on the PCIe interface. The PCIe controller, with the help of the address translation module AT (address translator), maps the SRAM memory on the security network card to the host memory space to simulate a register space (virtual register). The virtual register is a register simulated by SRAM (memory), and the characteristics presented at the host driver side are the same as those of the hardware register. The role of the virtual register is to provide a configuration interface for the host driver so that the host driver can configure and control the functions and logics inside the network card, such as whether to enable the encryption / decryption function of the network card and whether to perform filtering checks on the transmitted and received data. The advantage of this design is that the SRAM inside the network card can be operated on the host just like operating a register; when the host writes to the virtual register, the address translation module AT generates an interrupt to the main CPU, the main CPU responds to this interrupt, and by querying the address translation module AT, it knows which virtual register the host has written to, and the main CPU parses the content of the virtual register and executes a custom action.

[0104] Embodiment 3

[0105] The implementation method of the security network card as described in Embodiments 1 and 2 includes the non-encrypted frame sending process:

[0106] 1-1) The host prepares the network frame and then writes to the virtual register to notify the security network card to send it.

[0107] 1-2) The main CPU receives the interrupt of the address translation module AT generated by the host writing to the virtual register.

[0108] 1-3) The main CPU queries the address translation module AT to know which virtual register the host has modified.

[0109] 1-4) The main CPU reads the above virtual register value and determines that the host has a frame to send.

[0110] 1-5) The main CPU configures the DMA controller according to the position information of the frame to be sent by the host.

[0111] 1-6) The DMA controller reads the frame to be sent by the host into the secure network card memory and generates an interrupt to notify the main CPU.

[0112] 1-7) The main CPU analyzes the above-read frame and determines that encryption is not required according to the frame information.

[0113] 1-8) The main CPU configures the network frame transceiver GMAC according to the frame information.

[0114] 1-9) The network frame transceiver GMAC sends the frame to the line according to the above configuration.

[0115] Embodiment 4

[0116] The implementation method of the secure network card as described in Embodiment 3 further includes an encrypted frame (such as IPSec traffic) sending process:

[0117] 2-1) The host prepares a network frame and then writes to the virtual register to notify the secure network card to send it.

[0118] 2-2) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register.

[0119] 2-3) The main CPU queries the address translation module AT to know which virtual register the host has modified.

[0120] 2-4) The main CPU reads the above virtual register value and determines that the host has a frame to send.

[0121] 2-5) The main CPU configures the DMA controller according to the position information of the frame to be sent by the host.

[0122] 2-6) The DMA reads the frame to be sent by the host into the network card memory and generates an interrupt to notify the main CPU.

[0123] 2-7) The main CPU analyzes the above-read frame and determines that encryption is required according to the frame information.

[0124] 2-8) The main CPU notifies the slave CPU of the frame information to be encrypted.

[0125] 2-9) The slave CPU analyzes the frame information and configures the encryption and decryption algorithm module crypto for hardware encryption accordingly.

[0126] After the above encryption is completed, the CPU notifies the main CPU that the encryption is completed;

[0127] 2-11) The main CPU configures the network frame transceiver GMAC according to the frame information indicating the completion of encryption;

[0128] 2-12) The network frame transceiver GMAC sends the frame to the line according to the above configuration.

[0129] Embodiment 5

[0130] The implementation method of the secure network card as described in Embodiment 3 further includes a non-encrypted frame receiving process:

[0131] 3-1) The main CPU configures the network frame transceiver GMAC to be ready to receive network frames;

[0132] 3-2) The host driver gets ready to receive network frames and writes to a virtual register to notify the secure network card that it can receive;

[0133] 3-3) The main CPU receives an address translation module AT interrupt generated by the host writing to the virtual register;

[0134] 3-4) The main CPU queries the address translation module AT to find out which virtual register the host has modified;

[0135] 3-5) The main CPU reads the value of the above virtual register and determines that the host can receive network frames;

[0136] 3-6) The main CPU configures the DMA controller according to the receiving information configured by the host;

[0137] 3-7) The DMA controller reads the receiving information configured by the host into the network card memory and generates an interrupt to notify the main CPU;

[0138] 3-8) The main CPU saves the above receiving information;

[0139] 3-9) After the network frame transceiver GMAC receives a network frame from the line, it generates an interrupt to notify the main CPU;

[0140] 3-10) The main CPU analyzes the received network frame and determines that encryption is not required;

[0141] 3-11) The main CPU configures the DMA controller according to the information saved in step 3-8) and the information of the received frame above;

[0142] 3-12) The DMA controller writes the received frame to the host and notifies the main CPU;

[0143] 3-13) The main CPU generates an interrupt to the host by writing to the register of the PCIe controller;

[0144] 3 - 14) The host responds to the interrupt and obtains the received network frame.

[0145] Embodiment 6

[0146] For the implementation method of the security network card as described in Embodiment 5, it further includes the receiving process of encrypted frames (such as IPSec traffic):

[0147] 4 - 1) The main CPU configures the network frame transceiver GMAC to be ready to receive network frames;

[0148] 4 - 2) The host driver is ready to receive network frames and writes to the virtual register to notify the security network card that it can receive;

[0149] 4 - 3) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register;

[0150] 4 - 4) The main CPU queries the address translation module AT to find out which virtual register the host has modified;

[0151] 4 - 5) The main CPU reads the value of the above virtual register and determines that the host can receive network frames;

[0152] 4 - 6) The main CPU configures the DMA controller according to the received information configured by the host;

[0153] 4 - 7) The DMA controller reads the received information configured by the host into the network card memory and generates an interrupt to notify the main CPU;

[0154] 4 - 8) The main CPU saves the above received information;

[0155] 4 - 9) After the network frame transceiver GMAC receives a network frame from the line, it generates an interrupt to notify the main CPU;

[0156] 4 - 10) The main CPU analyzes the received network frame and determines that decryption is required;

[0157] 4 - 11) The main CPU notifies the slave CPU of the frame information to be decrypted;

[0158] 4 - 12) The slave CPU analyzes the frame information and configures the encryption and decryption algorithm module crypto for hardware decryption accordingly;

[0159] 4 - 13) After the above decryption is completed, the slave CPU notifies the main CPU that the decryption is completed;

[0160] 4 - 14) The main CPU configures the DMA controller according to the information saved in step 4 - 8) and the information of the frame after the above decryption;

[0161] 4-15) The DMA controller writes the received frame to the host and notifies the main CPU;

[0162] 4-16) The main CPU generates an interrupt to the host by writing to the registers of the PCIe controller;

[0163] 4-17) The host responds to the interrupt and obtains the received network frame.

Claims

1. A secure network card based on the PCIe interface, characterized in that, It includes: a PCIe controller, a main CPU, a slave CPU, a DMA controller, an encryption / decryption algorithm module crypto, and a network frame transceiver GMAC; The PCIe controller is used for the host to access the internal component registers of the secure network card to complete component configuration; The main CPU is used to complete the allocation and execution of tasks in each link of the network frame transceiver pipeline; The slave CPU is used to receive the network frames confirmed by the main CPU as needing encryption / decryption, analyze and determine how to configure the encryption / decryption algorithm module crypto to encrypt or decrypt the network frames; at the same time, the slave CPU feeds back the network frames after encryption or decryption processing to the main CPU; The DMA controller, according to the instructions of the main CPU, configures to read the network frames to be sent by the host onto the line into the secure network card internally to encrypt or decrypt the network frames; according to the instructions of the main CPU, configures to write the network frames received from the line after analysis and processing back to the host; The encryption / decryption algorithm module crypto is used to encrypt and decrypt any specified data according to configuration parameters; The network frame transceiver GMAC is used to implement the online transmission of network frames and receive network frames from the line; The main CPU is used to complete the allocation and execution of tasks in each link of the network frame transceiver pipeline, and also includes: The main CPU distinguishes data frames as encrypted / decrypted data frames or non-encrypted data frames; The main CPU first finds the IP header according to the protocol, and then parses whether the value of the "next layer protocol" field in the IP header is the IPSec protocol value. If it is not the IPSec protocol value, it is not an IPSec frame, so no encryption / decryption processing is required; If the main CPU determines that the frame is an IPSec frame, it also needs to match according to the destination IP address in the IP header of the frame and the SPI field in the IPSec header in a screening list maintained internally in the network card. If a matching item is found, encryption / decryption is performed according to the key information and control information recorded in the matching item; if no matching item is found, no encryption / decryption is performed.

2. The security network card based on the PCIe interface according to claim 1, characterized in that, The PCIe controller, with the help of the address translation module AT, maps the SRAM memory on the secure network card to the host memory space to simulate a register space.

3. The secure network card based on the PCIe interface according to claim 2, characterized in that, Two groups of IPSec frame matching linked lists are maintained internally in the secure network card, one for TX query; one for RX query; For IPSec frames that need encryption / decryption processing, the destination address + SPI + decryption of the frames to be encrypted / decrypted need to be sent to the linked list in the network card in advance through the virtual register method in the host driver.

4. The implementation method of the secure network card according to any one of claims 1-3, characterized in that, It includes the non-encrypted frame sending process: 1-1) The host prepares the network frame and then writes to the virtual register to notify the secure network card to send; 1-2) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register; 1-3) The main CPU queries the address translation module AT to know which virtual register the host has modified; 1-4) The main CPU reads the value of the above virtual register and determines that the host has a frame to send; 1-5) The main CPU configures the DMA controller according to the position information of the frame to be sent by the host; 1-6) The DMA controller reads the frame to be sent by the host into the secure network card memory and generates an interrupt to notify the main CPU; 1-7) The main CPU analyzes the frame read above and determines that encryption is not required based on the frame information; 1-8) The main CPU configures the network frame transceiver GMAC according to the frame information; 1-9) The network frame transceiver GMAC sends the frame to the line according to the above configuration.

5. The implementation method of the secure network card according to any one of claims 1-3, characterized in that, It also includes the encrypted frame sending process: 2-1) The host prepares the network frame and then writes to the virtual register to notify the secure network card to send; 2-2) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register; 2-3) The main CPU queries the address translation module AT to find out which virtual register the host has modified; 2-4) The main CPU reads the value of the above virtual register and determines that the host has a frame to send; 2-5) The main CPU configures the DMA controller according to the position information of the frame to be sent by the host; 2-6) The DMA reads the frame to be sent by the host into the network card memory and generates an interrupt to notify the main CPU; 2-7) The main CPU analyzes the frame read above and determines that encryption is required based on the frame information; 2-8) The main CPU notifies the slave CPU of the frame information to be encrypted; 2-9) The slave CPU analyzes the frame information and configures the encryption / decryption algorithm module crypto for hardware encryption accordingly; 2-10) After the above encryption is completed, the slave CPU notifies the main CPU that the encryption is completed; 2-11) The main CPU configures the network frame transceiver GMAC according to the frame information after encryption is completed; 2-12) The network frame transceiver GMAC sends the frame to the line according to the above configuration.

6. The implementation method of the secure network card according to any one of claims 1-3, characterized in that, It also includes the non-encrypted frame receiving process: 3-1) The main CPU configures the network frame transceiver GMAC to be ready to receive network frames; 3-2) The host driver prepares to receive network frames and writes to the virtual register to notify the secure network card that it can receive; 3-3) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register; 3-4) The main CPU queries the address translation module AT to find out which virtual register the host has modified; 3-5) The main CPU reads the value of the above virtual register and determines that the host can receive network frames; 3-6) The main CPU configures the DMA controller according to the received information configured by the host; 3-7) The DMA controller reads the received information configured by the host into the network card memory and generates an interrupt to notify the main CPU; 3-8) The main CPU saves the above received information; 3-9) After the network frame transceiver GMAC receives a network frame from the line, it generates an interrupt to notify the main CPU; 3-10) The main CPU analyzes the received network frame above and determines that encryption is not required; 3-11) The main CPU configures the DMA controller according to the information saved in step 3-8) and the information of the received frame above; 3-12) The DMA controller writes the received frame to the host and notifies the main CPU; 3-13) The main CPU generates an interrupt to the host by writing to the register of the PCIe controller; 3-14) The host responds to the interrupt and obtains the received network frame.

7. The implementation method of the secure network card according to any one of claims 1-3, characterized in that, It also includes the encrypted frame receiving process: 4-1) The main CPU configures the network frame transceiver GMAC to be ready to receive network frames; 4-2) The host driver is ready to receive network frames and writes to the virtual register to notify the security network card that it can receive; 4-3) The main CPU receives the address translation module AT interrupt generated by the host writing to the virtual register; 4-4) The main CPU queries the address translation module AT to find out which virtual register the host has modified; 4-5) The main CPU reads the value of the above virtual register and determines that the host can receive network frames; 4-6) The main CPU configures the DMA controller according to the reception information configured by the host; 4-7) The DMA controller reads the reception information configured by the host into the network card memory and generates an interrupt to notify the main CPU; 4-8) The main CPU saves the above reception information; 4-9) After the network frame transceiver GMAC receives a network frame from the line, it generates an interrupt to notify the main CPU; 4-10) The main CPU analyzes the received network frame and determines that decryption is required; 4-11) The main CPU notifies the slave CPU of the frame information to be decrypted; 4-12) The slave CPU analyzes the frame information and configures the encryption / decryption algorithm module crypto for hardware decryption accordingly; 4-13) After the above decryption is completed, the slave CPU notifies the main CPU that the decryption is completed; 4-14) The main CPU configures the DMA controller according to the information saved in step 4-8) and the information of the frame after the above decryption; 4-15) The DMA controller writes the received frame to the host and notifies the main CPU; 4-16) The main CPU generates an interrupt to the host by writing to the register of the PCIe controller; 4-17) The host responds to the interrupt and obtains the received network frame.

Citation Information

Patent Citations

  • Network card and method for processing data by network card

    CN113778320A

  • Method for processing data message and network card

    CN114095427A