A hardware encryption-based FSU system
By adopting domestically produced CPUs and encryption chips, a flexible FSU system was designed, which solved the problems of limited chip supply and data leakage risks for FSU equipment, and achieved flexible adaptation and cost savings for the equipment in different scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-05
- Publication Date
- 2026-04-07
AI Technical Summary
Existing FSU equipment suffers from issues such as limited chip supply, risks of backdoors in foreign chips, data leakage risks, and inability to flexibly adapt to various application scenarios.
The system adopts domestic CPUs and encryption chips, and designs an FSU system based on hardware encryption. The main control board and interface board can adjust the interface type and quantity according to the application scenario. RS485, DI, DO, AI and other interfaces are integrated onto separate boards. Domestic power modules and backup power modules are used to ensure stable power supply.
It solves the problems of chip supply constraints and data leakage risks, enables flexible device adaptation to different application scenarios, and reduces costs and maintenance difficulties.
Smart Images

Figure CN115766276B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of machine room monitoring and the technical field of communication base station monitoring, in particular to an FSU device for machine room monitoring and a hardware encryption-based FSU system for communication base station monitoring. BACKGROUND
[0002] The FSU (Field Supervision Unit) device is the most basic element in the dynamic environment monitoring system of a machine room or a communication base station, which generally refers to an integrated monitoring host capable of accessing water immersion, access control, smoke, power and other sensing devices. The host can analyze and store monitoring data of various sensors, and is responsible for data-based and centralized monitoring of internal equipment and environment of the machine room or the communication base station and external security.
[0003] Most of the FSU devices on the market are currently developed based on foreign CPUs (such as NXP's iMX6 series and TI's AM335X series). Under the background of chip shortage in recent years, domestic manufacturers have difficulty in obtaining foreign supplies, which increases the development cycle and the risk of supply interruption of related products. At the same time, using foreign chips may be backdoored and may face the risk of data leakage.
[0004] Nowadays, most of the classified computers or other classified terminals in units adopt physical isolation (such as closed network ports and USB ports) and other means to prevent classified data from being stolen for the security management of the equipment. In the terminal data security management, the files in the computer need to be protected and the behavior of the employees needs to be effectively managed to ensure data security. The Domain Shield tool can be used to encrypt the files in the computer, such as encrypting important files through transparent encryption. The encrypted files will not affect the normal use of the employees. If the employees need to export, they need to be approved by the management end, otherwise any form of export and copying of the opened files in the terminal computer will be in the form of random code. To ensure data security, file operation auditing can also be used for management, such as recording which files are opened, modified or deleted by the employees during work. Moreover, the files modified or deleted by the employees can be automatically backed up to prevent malicious deletion of files by the employees and ensure data security. However, when a leaker in the internal steals sensitive data, the manager is difficult to discover in time. Moreover, document encryption controls the application software, and the generated document is written into a key when saved. However, when the encrypted file is opened on a computer with an encrypted product client, the encryption software will automatically decrypt the ciphertext first, and then the file can be normally opened. That is, the encrypted file still exists in the form of plaintext in the memory, which can be directly extracted by "reading memory" to bypass the encryption, and the security level is low.
[0005] In addition, most of the FSU devices are customized for a certain application scenario, once the application scenario is changed, the resources on the FSU device are not enough or redundant, which is easy to cause the increase of cost or insufficient resources. In order to meet different application scenarios, different scene customization schemes are needed, which not only increases the design and production cost, but also increases the difficulty of operation and maintenance management of the FSU device.
[0006] In addition, the existing FSU device is generally integrated with other boards in the system for external function interface (such as RS485, DI, DO, AI, etc.). In one scene, the resource utilization rate can be maximized, but when changed to another scene, the resource may not be enough or wasted. Re-development not only consumes time and cost, but also increases the risk items in the development process. Therefore, in view of the leakage risk in use of the FSU device and the problem of not being able to flexibly adapt to multiple application scenarios, a new FSU system needs to be developed to solve the above problems, but so far there is no public report. SUMMARY
[0007] In view of the above situation, in order to overcome the defects of the prior art, the purpose of the present application is to provide a FSU system based on hardware encryption, which can effectively solve the leakage risk in use of the existing FSU device and the problem of not being able to flexibly adapt to multiple application scenarios.
[0008] To achieve the above purpose, the technical scheme solved by the present application is a FSU system based on hardware encryption, comprising a case, the case is provided with a power module, a power board, a main control board, an interface board and a connector board, the power module comprises a main power module and a backup power module, the power module and the backup power module are connected with the power board, the power board combines the voltages output by the two power modules into one path and outputs to the main control board and the interface board connected with the power board, the main control board and the interface board are bidirectionally connected, the interface board is connected with the connector board, the connector board is mounted in the detachable front panel of the case, and the external RJ45 interface of the connector board is led out.
[0009] The main control board comprises a processor module and an external interface module, and the interface board comprises a DI interface, a DO interface, an AI interface, an RS485 interface and a CAN bus interface.
[0010] The present application has scientific and reasonable design, solves the risk of limited supply of foreign CPU, long cycle and pre-reserved backdoor of foreign chips, and solves the risk of leakage in data transmission process; according to the actual application scene, the interface form and quantity of the connector are adjusted to solve the problem of device application to different application scenes, and the social and economic benefits are remarkable. BRIEF DESCRIPTION OF DRAWINGS
[0011] Figure 1 It is the overall block diagram of the system of the present application.
[0012] Figure 2 is the functional block diagram of the master control board of the present application.
[0013] Figure 3 is the system block diagram of the interface board and the connector board of the present application.
[0014] Figure 4 is the schematic diagram of the UART interface part of the master control board and the connector board of the present application. DETAILED DESCRIPTION
[0015] The specific embodiments of the present application are described in detail below in combination with the drawings and examples.
[0016] As shown in the drawings, Figure 1 A FSU system based on hardware encryption comprises a case, the case 1 is internally provided with a power module, a power board 3, a master control board 5, an interface board 6 and a connector board 7, the power module comprises a main power module 2 and a backup power module 4, the main power module 2 and the backup power module 4 are connected with the power board 3, the power board 3 combines the voltages output by the two power modules into one path and outputs to the master control board 5 and the interface board 6 connected with the power board 3, the master control board 5 and the interface board 6 are bidirectionally connected, the interface board 6 is connected with the connector board 7, the connector board 7 is mounted in the detachable front panel of the case 1, and an external RJ45 interface of the connector board 7 is led out.
[0017] In the embodiment, the case 1 is a standard 1U case, which has a length of 440 mm, a width of 264.8 mm and a height of 42.8 mm. The case 1 is divided into front, rear, left, right, upper and lower panels, and the panels are connected and fixed by screws, wherein the front panel is used to lead out the external RJ45 interface of the connector board 7. Different front panels can be customized according to different application scenarios, and the other panels do not need to be replaced at the same time, which not only saves the cost of modifying the case, but also saves the modification time.
[0018] The power module in the embodiment adopts a 220V-to-48V power module, and two power modules are adopted, one of which is used as the main power 2 and the other is used as the backup power 4. When the main power 2 fails, the backup power 4 is automatically switched to ensure the normal operation of the system.
[0019] The power board 3 in the embodiment combines the 48V voltages output by the two power modules into one path and outputs to each board card, and at the same time, the power board 3 is responsible for automatically switching the main and backup powers (its own function) to ensure the normal power supply of the equipment.
[0020] As shown in the drawings, Figure 2As shown, the main control board 5 in this embodiment includes a processor module 501 and an external interface module 502. The processor module 501 mainly includes a CPU, an eMMC memory, an SDRAM, and an encryption chip. The eMMC memory, SDRAM, and encryption chip are bidirectionally connected to the CPU. The external interface module 502 includes multiple interfaces, which transmit data bidirectionally with the CPU for data transfer between devices or between devices and a host computer. In this embodiment, the domestic CPU used is the Allwinner Technology T507 chip, used for data transmission, instruction issuance and reception, and for collecting port data and distinguishing data types. The eMMC memory is used for data storage and firmware update package storage. The encryption chip on the main control board 5 is a domestic encryption chip; in this embodiment, it is the HSC32EU from Hongsi Electronics. The encryption chip communicates with the CPU via the SPI bus to read data from the CPU. The encryption chip has an embedded hardware-implemented encryption algorithm that independently generates keys and performs encryption and decryption. It has an independent processor and storage unit that can store keys and feature data. The encryption is performed by a security chip, and the key is stored in the hardware. Stolen data cannot be decrypted, thus protecting data security. The encrypted data is transmitted to the host computer or other devices through the CPU's network port.
[0021] It should be noted that the models used for each component in the above embodiments are not limited to these models. Equivalent embodiments that make changes or modifications to the above-disclosed technical content to achieve the same transformation all fall within the protection scope of this invention.
[0022] The external interface module 502 on the main control board 5 mainly includes four 100Mbps Ethernet ports (two of which integrate PoE functionality), one gigabit optical port, one USB interface, and one SD card interface. The Ethernet ports are mainly used for data transmission between devices or between devices and a host computer. The SD card interface and USB interface are mainly used to connect external storage devices for data storage.
[0023] In this embodiment, interface board 6 is a data signal processing board that integrates various data interfaces, such as DI, DO, AI, RS485 interface, and CAN bus interface. A series of interfaces are presented externally in the form of RJ45 interfaces, allowing access to various parameters of the power and environmental systems within the computer room, including power system parameters such as smart meters, battery banks, UPS, and power distribution cabinets, as well as environmental system parameters such as air conditioning, access control, water immersion, smoke, temperature, and humidity.
[0024] In this embodiment, the interface board 6 supports a maximum of 16 RS485 interfaces, 4 DI interfaces, 4 DO interfaces, 2 AI interfaces, and 2 CAN ports. Users can select different numbers and types of interfaces according to the actual situation in the computer room to monitor the equipment. When selecting different numbers of interfaces, the electronic components of other unselected interfaces do not need to be mounted; only the form and number of outgoing interfaces on the front panel need to be modified.
[0025] In this embodiment, the interface board 6 integrates a microcontroller and a CPLD. The microcontroller primarily outputs 2 CAN ports, 5 UART interfaces, 4 DI interfaces, and 4 DO interfaces. Of the 5 UART interfaces, 4 are used for external RS485 conversion, and 1 is used for communication with the CPU on the main control board 5. The CPLD primarily outputs 13 UART interfaces, mainly used for RS485 conversion. Additionally, the main control board also exposes 3 UART interfaces, which can also perform RS485 conversion. The RS485 interface is converted. When the microcontroller's UART interface is selected, one UART interface communicates with the CPU on the main control board 5. UART1_C, UART2_C, UART3_C, and UART4_C are converted to RS485 interfaces via resistors R5, R6, R7, and R8, respectively. When the CPLD's UART interface is selected, all nine UART interfaces are directly converted to RS485 interfaces. UART1_G, UART2_G, UART3_G, and UART4_G are converted to RS485 interfaces via resistors R1, R2, R3, and R4, respectively.
[0026] like Figure 4As shown, the UART interfaces of the microcontroller and CPLD are converted to RS485 interfaces using a two-to-one selection mechanism. Including the three UART interfaces from the main control board 5, a total of 16 RS485 interfaces are provided. The two-to-one UART interfaces for the microcontroller and CPLD are named UART1_C-UART4_C and UART1_G-UART4_G, respectively. Resistors R1-R8 are optional; when selecting the microcontroller as the UART interface, only resistors R5-R8 need to be soldered. In this case, the maximum number of externally accessible resources are 7 RS485 interfaces, 2 AI interfaces, 4 DI interfaces, 4 DO interfaces, and 2 CAN ports. This system is suitable for scenarios with a limited number of interfaces. The CPLD and any extra RS485 conversion circuitry do not need to be mounted, saving some cost. When selecting the CPLD to bring out the UART interface, only resistors R1-R4 are soldered. In this case, the maximum number of available resources is 16 RS485 interfaces, 2 AI interfaces, 4 DI interfaces, and 4 DO interfaces. This system is suitable for scenarios with a large number of interfaces, eliminating the need for a microcontroller and saving some costs. Therefore, this invention allows for arbitrary combinations of the number of external interfaces depending on the mounting method of the microcontroller and CPLD, enabling the system to adapt to different external environments.
[0027] In this embodiment, there is also a connector board 7, which is used in conjunction with the interface board 6. The interface board 6 transmits the signals of a series of data center environmental parameters collected to the CPU through the connector. The CPU transmits the data to the encryption chip to encrypt the data, and then transmits it back to the CPU, and then forwards it.
[0028] In this embodiment, the connecting board 7 can be modified according to the actual situation (resources) on site, and the front panel interface of the chassis 1 will change accordingly, thus saving maximum cost. For example Figure 3 The diagram shows the system block diagram of interface board 6 and connector board 7. Interface board 6 is connected to connector board 7, which is presented externally in the form of RJ45 interface. It can access various parameters of the power system and environmental system in the computer room, including power system parameters such as smart meters, battery packs, UPS, and cabinets, as well as environmental system parameters such as air conditioning, access control, water immersion, smoke, temperature and humidity.
[0029] The present invention is scientifically and rationally designed, and compared with the prior art, it has the following beneficial technical effects:
[0030] 1. Using domestically produced CPUs solves the problems of limited supply, long lead times, and backdoors in foreign chips.
[0031] 2. Domestically produced encryption chips are used to mitigate the risk of data leakage during transmission;
[0032] 3. The connectors for external interfaces (RS485, DI, DO, AI, etc.) are integrated onto a single board. The interface type and quantity of the connectors can be adjusted according to the actual application scenario to solve the problem of the device being suitable for different application scenarios. This enables quick and convenient interface replacement, greatly saving costs and resulting in significant social and economic benefits.
[0033] The above description is merely a preferred embodiment of the invention and does not limit the patent scope of the present invention. Any equivalent structural transformations made using the contents of the present invention's specification and drawings under the inventive concept of the present invention, or direct / indirect applications in other related technical fields, are included within the patent protection scope of the present invention.
Claims
1. A hardware-encrypted FSU system, comprising a chassis (1) housing a power module, a power board (3), a main control board (5), an interface board (6), and a connector board (7), wherein the power module includes a main power module (2) and a backup power module (4), both the power module (2) and the backup power module (4) being connected to the power board (3), characterized in that, The power board (3) combines the voltage output from the two power modules into one and outputs it to the main control board (5) and the interface board (6) connected to the power board (3). The main control board (5) and the interface board (6) are bidirectionally connected. The interface board (6) is connected to the connector board (7). The connector board (7) is installed in the removable front panel of the chassis (1) and the external RJ45 interface of the connector board (7) is brought out. The main control board (5) includes a processor module (501) and an external interface module (502). The main control board (5) has 3 UART interfaces. The interface board (6) integrates a microcontroller and a CPLD. The microcontroller outputs 2 CAN interfaces, 5 UART interfaces, 4 DI interfaces and 4 DO interfaces. 4 UART interfaces are converted to RS485 interfaces. 1 UART interface is connected to the CPU on the main control board (5) for communication. The CPLD outputs 13 UART interfaces to convert RS485 interfaces. When converting RS485 interfaces, the UART interface of the microcontroller or the CPLD is selected. The processor module (501) includes a CPU, an EMMC memory, an SDRAM, and an encryption chip. The EMMC memory, SDRAM, and encryption chip are bidirectionally connected to the CPU. The CPU is used for data transmission and instruction issuance and reception, and is used to collect port data and distinguish data types. The EMMC memory is used for data storage and firmware update package storage. The encryption chip communicates with the CPU via the SPI bus and reads the CPU's data. The encrypted data is transmitted through the CPU's network port. The external interface module (502) includes multiple interfaces. The interfaces are bidirectionally transmitted with the CPU and are used for data transmission between devices or between devices and a host computer. The interface board (6) includes a DI interface, a DO interface, an AI interface, an RS485 interface, and a CAN bus interface.
2. The hardware-encrypted FSU system according to claim 1, characterized in that, The chassis (1) is a 1U chassis with a length × width × height of 440mm × 264.8mm × 42.8mm. The outer shell of the chassis (1) is divided into front, rear, left, right, top and bottom panels, which are connected and fixed by screws.
3. The hardware-encrypted FSU system according to claim 1, characterized in that, The power module is a 220V to 48V power module.
4. The hardware-encrypted FSU system according to claim 1, characterized in that, The CPU is a T507 chip, and the encryption chip is an HSC32EU; the external interface module (502) includes 4 100M Ethernet ports, 1 Gigabit optical port, 1 USB interface and 1 SD card interface, wherein the SD card interface and USB interface are used for connecting external storage devices.
5. The hardware-encrypted FSU system according to claim 1, characterized in that, When the UART interface of the microcontroller is selected, one UART interface communicates with the CPU on the main control board (5). UART1_C, UART2_C, UART3_C and UART4_C are converted to RS485 interfaces via resistors R5, R6, R7 and R8 respectively. When the UART interface of the CPLD is selected, nine UART interfaces are directly converted to RS485 interfaces. UART1_G, UART2_G, UART3_G and UART4_G are converted to RS485 interfaces via resistors R1, R2, R3 and R4 respectively.
Citation Information
Patent Citations
Method and system employing national cryptographic algorithm and being applied to domesticated FSU
CN111181970A
AI dynamic environment monitoring system
CN213934598U