An encryption and decryption device based on the RISC-V architecture
Through the encryption and decryption device based on RISC-V architecture, combined with the characteristics of FPGA and Risc-v processors, the problem of insufficient flexibility of the traditional FPGA encryption processing mechanism is solved, and high-performance and low-power wireless communication link encryption is achieved to meet diversified service needs.
Patent Information
- Application Number
- CN202211474753.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-23
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-11-23
AI Technical Summary
The traditional wireless link encryption processing mechanism based on FPGA lacks the flexibility of a general-purpose processor, and is complex in design, programming and debugging, making it difficult to meet the diverse wireless communication service needs.
Using encryption and decryption devices based on RISC-V architecture, combined with the high performance of FPGA and the flexible programming characteristics of Risc-v processors, flexible processing of data and control data is achieved through the separation structure of the intranet and external network preprocessing modules, Risc-V processor modules and algorithm processing modules.
It provides high-performance, low-power encryption and decryption solutions, which can adapt to the link transmission encryption guarantee requirements of various wireless communication services and have flexible service logic processing capabilities.
Smart Images

Figure CN115776404B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cryptographic security, and more specifically, relates to an encryption and decryption device based on the RISC-V architecture. Background Art
[0002] Wireless link transmission encryption is mainly used to implement link layer encryption protection for wireless communication to ensure the security of data transmitted over the wireless link. Wireless link transmission encryption features modularity, low power consumption, and miniaturization. It usually adopts FPGA and CPU architectures, where the CPU completes configuration and management functions, and the FPGA completes service processing and encryption functions. With the development of wireless communication technologies, the types of wireless communication services are showing diverse development trends, posing more requirements for the functions of link encryption devices, such as the ability to support multiple cryptographic functions like unicast, multicast, point-to-point / point-to-multipoint, and network access authentication. The traditional FPGA-based link encryption processing mechanism lacks the flexibility of a general-purpose processor, and the design, programming, and debugging are complex.
[0003] Risc-V is an open-source instruction set architecture based on the principle of reduced instruction set, featuring a simple architecture, modular design, easy portability, and complete open source. It is currently widely used in scenarios such as the Internet of Things, data centers, and edge computing. The device and method for wireless link encryption based on the Risc-V architecture combine the characteristics of Rsic-V and FPGA. Based on the flexibility of the Risc-V processor, it meets the cryptographic application requirements of diverse services; based on the high performance of the FPGA, it meets the encryption requirements of high-bandwidth services, thus better meeting the application requirements for link password service guarantee in wireless communication. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the purpose of the present invention is to provide an encryption and decryption device based on the RISC-V architecture, aiming to solve the problems that the traditional FPGA-based link encryption processing mechanism lacks the flexibility of a general-purpose processor and is complex in design, programming, and debugging.
[0005] To achieve the above object, in a first aspect, the present invention provides a link encryption device based on the RISC-V architecture, and the encryption device includes: an internal network side preprocessing module, a Risc-V processor module, an algorithm processing module, and an external network side preprocessing module;
[0006] The internal network side preprocessing module is externally connected to the internal network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface, and is used for making a preliminary determination on the plaintext data, accordingly performing packet assembly and CRC check on the data, and then sending the data packet to the Risc-V processor;
[0007] The Risc-V processor includes: a service processing module and a control and management module;
[0008] The service processing module provides AXI Stream interfaces to connect to the preprocessing module on the internal network side, the preprocessing module on the external network side, and the algorithm processing module respectively, and provides an AXI RAM interface to connect to the control and management module. It is used to parse the fields in the data packets received from the internal network and distinguish the message types, forward the control messages to the control and management module, forward the data messages to the algorithm processing module, and after parsing the encrypted service data, forward the encrypted service data to the preprocessing module on the external network side;
[0009] The control and management module provides an AXI RAM interface to connect to the service processing module. It is used to perform protocol parsing and processing on the control messages and then forward them to the algorithm processing module. After receiving the control data returned by the algorithm processing module, it performs protocol processing according to the control protocol and then sends the data to the preprocessing module on the external network side through the service processing module;
[0010] The algorithm processing module provides an AXI Stream interface to connect to the service processing module. It is used to encrypt and protect the integrity of the control data and send it back to the control and management module. After encrypting the service data, it sends the encrypted data to the service processing module;
[0011] The preprocessing module on the external network side is externally connected to the Rapid IO interface on the external network side and internally connected to the Risc-V processor through the AXI Stream interface. It is used to complete the determination of basic information, and then perform data fragmentation and CRC calculation based on this, and then send the ciphertext data to the user interface on the external network side.
[0012] Preferably, the entire encryption device is implemented based on an FPGA programmable logic device, and 1 32-bit Risc-V processor is instantiated in the form of an IP core of the FPGA.
[0013] Preferably, after the preprocessing module on the internal network side receives the plaintext data from the Rapid IO interface, it groups the multiple Rapid io interface frame data according to the message frame length, completes the CRC check. After the check passes, it forwards the message to the service logic processing module in the Risc-V through the AXI Stream interface to parse and process the message type. When the message type indicates a data message, it forwards the message to the algorithm processing module for encryption processing, and forwards the encrypted ciphertext data to the preprocessing module on the external network side through the AXI Stream.
[0014] Preferably, the preprocessing module on the external network side performs CRC calculation on the message and fills in the CRC calculation result, and performs fragmentation processing according to the Rapid IO frame format and then sends it to the external network interface through the Rapid IO interface, thus completing the service encryption processing.
[0015] Preferably, the encryption device supports RC4 and AES encryption algorithms.
[0016] To achieve the above object, in a second aspect, the present invention provides a link decryption device based on the RISC-V architecture, the decryption device comprising: an external network side preprocessing module, a Risc-V processor module, an algorithm processing module, and an internal network side preprocessing module;
[0017] The external network side preprocessing module is externally connected to the external network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface, and is used for performing a preliminary determination on the ciphertext data, and after packetizing and CRC checking the data accordingly, sending the data packet to the Risc-V processor;
[0018] The Risc-V processor includes: a service processing module and a control management module;
[0019] The service processing module provides AXI Stream interfaces respectively connected to the internal network side preprocessing module, the external network side preprocessing module, and the algorithm processing module, and provides an AXI RAM interface connected to the control management module, and is used for parsing the fields in the data packet received from the external network and distinguishing the message type, forwarding the control message to the control management module, forwarding the data message to the algorithm processing module, and after parsing the decrypted service data, forwarding the decrypted service data to the internal network side preprocessing module;
[0020] The control management module provides an AXI RAM interface connected to the service processing module, and is used for performing protocol parsing and processing on the control message and then forwarding it to the algorithm processing module, and after receiving the control data returned by the algorithm processing module, performing protocol processing according to the control protocol and then sending the data to the internal network side preprocessing module through the service processing module;
[0021] The algorithm processing module provides an AXI Stream interface connected to the service processing module, and is used for performing decryption protection on the control data, sending it back to the control management module, and after decrypting and processing the service data, sending the decrypted data to the service processing module;
[0022] The internal network side preprocessing module is externally connected to the internal network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface, and is used for completing the basic information determination and then performing data fragmentation and CRC calculation according to this, and then sending the plaintext data to the internal network side user interface.
[0023] Preferably, the entire device is implemented based on an FPGA programmable logic device, and 1 32-bit Risc-V processor is instantiated in the form of an FPGA IP core.
[0024] Preferably, after receiving the ciphertext data from the Rapid IO interface, the external network side preprocessing module groups multiple Rapid io interface frame data according to the packet frame length, completes the CRC check. After the check passes, the packet is forwarded to the service logic processing module in the Rsic-V through the AXI Stream interface to parse and process the packet type. When the packet type indicates a data packet, the packet is forwarded to the algorithm processing module for decryption processing, and the decrypted plaintext data is forwarded to the internal network side preprocessing module through the AXI Stream.
[0025] Preferably, the internal network side preprocessing module calculates the CRC of the packet and fills the CRC calculation result, and performs fragmentation processing according to the Rapid IO frame format and then sends it to the internal network interface through the Rapid IO interface, thus completing the service decryption processing.
[0026] Preferably, the decryption device supports RC4 and AES decryption algorithms.
[0027] Generally speaking, compared with the prior art, the above technical solution conceived by the present invention has the following beneficial effects:
[0028] The present invention proposes an encryption and decryption device based on the RISC-V architecture. Combining the high performance of the FPGA and the flexible programming of the Risc-v processor, the Risc-v processor completes the parsing of complex service logic and flexible programming processing, and the FPGA completes the data plane acceleration processing and algorithm processing, with the characteristics of high performance, low power consumption and flexibility; adopting a structure with separation of control and service forwarding, service data is forwarded through the internal network preprocessing module, service logic processing module, algorithm processing module and external network processing module, providing high-speed service forwarding processing ability; control data is mainly processed through the control management module, providing flexible service logic processing ability, and can better adapt to and meet the link transmission encryption guarantee requirements of various wireless communication services. Brief Description of the Drawings
[0029] Figure 1 It is a schematic diagram of the overall structure of the encryption and decryption device provided by the present invention.
[0030] Figure 2 It is a schematic diagram of the service data forwarding processing flow direction of the encryption device provided by the present invention.
[0031] Figure 3 It is a schematic diagram of the control data forwarding processing flow direction of the encryption device provided by the present invention. Detailed Embodiments
[0032] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0033] As Figure 1 shown, the present invention provides a link encryption device based on the RISC-V architecture. The encryption device includes: an internal network side preprocessing module, a Risc-V processor module, an algorithm processing module, and an external network side preprocessing module.
[0034] The internal network side preprocessing module is externally connected to the internal network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. It is used to perform a preliminary determination on the plaintext data, packetize and perform CRC check on the data according to this, and then send the data packet to the Risc-V processor.
[0035] Preferably, after receiving the plaintext data from the Rapid IO interface, the internal network side preprocessing module packetizes multiple Rapid io interface frame data according to the packet frame length, completes the CRC check. After the check passes, it forwards the packet to the service logic processing module in the Risc-V through the AXI Stream interface to parse and process the packet type. When the packet type indicates a data packet, it forwards the packet to the algorithm processing module for encryption processing, and forwards the encrypted ciphertext data to the external network side preprocessing module through the AXI Stream.
[0036] The Risc-V processor includes: a service processing module and a control management module.
[0037] The service processing module provides AXI Stream interfaces to be respectively connected to the internal network side preprocessing module, the external network side preprocessing module, and the algorithm processing module, and provides an AXI RAM interface to be connected to the control management module. It is used to parse the fields in the data packet received from the internal network and distinguish the packet type, forward the control packet to the control management module, forward the data packet to the algorithm processing module, and after parsing the encrypted service data, forward the encrypted service data to the external network side preprocessing module.
[0038] The control management module provides an AXI RAM interface to be connected to the service processing module. It is used to perform protocol parsing and processing on the control packet and then forward it to the algorithm processing module. After receiving the control data returned by the algorithm processing module, it performs protocol processing according to the control protocol and then sends the data to the external network side preprocessing module through the service processing module.
[0039] The algorithm processing module provides an AXI Stream interface to connect to the service processing module, which is used to encrypt and protect the integrity of control data and send it back to the control management module. After encrypting the service data, the encrypted data is sent to the service processing module.
[0040] Preferably, the encryption device supports RC4 and AES encryption algorithms.
[0041] The external network side preprocessing module is externally connected to the external network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. After completing the determination of basic information, it slices and calculates the CRC of the data accordingly, and then sends the ciphertext data to the external network side user interface.
[0042] Preferably, the external network side preprocessing module calculates the CRC of the packet and fills in the CRC calculation result, and slices the packet according to the Rapid IO frame format and sends it to the external network interface through the Rapid IO interface, thus completing the service encryption process.
[0043] Preferably, the entire encryption device is implemented based on an FPGA programmable logic device, and a 32-bit Risc-V processor is instantiated in the form of an FPGA IP core.
[0044] As Figure 2 shown, the solid arrows represent the data interface communication relationship, and the dashed arrows represent the characteristic data processing flow. The service data forwarding flow of the encryption device mainly involves processing modules such as the preprocessing module, service logic processing module, and algorithm processing module. Taking the encryption forwarding flow from the internal network user interface data to the external network user interface data as an example, the data forwarding process is as follows:
[0045] (1) The internal network user interface sends the user service data to the internal network side preprocessing module of the wireless communication link encryption device through Rapid IO.
[0046] (2) After receiving the data to be encrypted, the internal network side preprocessing module completes the determination of basic information (such as length, packet header, etc.), slices and CRC checks the data accordingly, and then sends the data to the service logic processing module.
[0047] (3) After completing the parsing of the service data, the service processing module forwards the data to be encrypted to the algorithm processing module for encryption processing.
[0048] (4) After completing the encryption processing, the algorithm processing module sends the encrypted data to the service processing module.
[0049] (5) After completing the parsing of the service data, the service processing module forwards the received encrypted data to the external network side preprocessing module.
[0050] (6) After receiving the encrypted data, the preprocessing module on the external network side completes tasks such as basic information determination (such as length, packet header, etc.), and then performs operations such as data packet assembly and CRC calculation on the data, and finally sends the data to the user interface on the external network side.
[0051] As Figure 3 shown, the solid arrows represent the communication relationships of the data interfaces, and the dashed arrows represent the processing flows of the characteristic data. The control data forwarding flow of the encryption device mainly involves processing by modules such as the preprocessing module, service logic processing module, control management module, and algorithm processing module. Taking the control data forwarding flow from the internal network user interface to the external network user interface as an example, the data forwarding process is as follows:
[0052] (1) The internal network user interface sends control data to the preprocessing module on the internal network side of the wireless communication link encryption device through Rapid IO.
[0053] (2) After receiving the control data to be processed, the preprocessing module on the internal network side completes tasks such as basic information determination (such as length, packet header, etc.), and then performs operations such as data fragmentation and CRC verification on the data, and finally sends the data to the service logic processing module.
[0054] (3) After the service processing module completes the parsing of the service data, it forwards the control data to the control management module for processing.
[0055] (4) After the control management module completes the parsing and processing of the control protocol, it sends the control data to the algorithm processing module for encryption and integrity protection processing.
[0056] (5) After receiving the control data, the algorithm processing module performs encryption and integrity protection processing, and then sends the control data back to the control management module.
[0057] (6) After receiving the control data that has been encrypted and integrity protected, the control management module performs protocol processing according to the control protocol, and then sends the data to the preprocessing module on the external network side through the service processing module.
[0058] (7) After receiving the control data that has been encrypted and integrity protected, the preprocessing module on the external network side completes tasks such as basic information determination (such as length, packet header, etc.), and then performs operations such as data packet assembly and CRC calculation on the data, and finally sends the control data to the user interface on the external network side.
[0059] As Figure 1 shown, the present invention provides a link decryption device based on the RISC-V architecture. The decryption device includes: a preprocessing module on the external network side, a Risc-V processor module, an algorithm processing module, and a preprocessing module on the internal network side.
[0060] The external network side preprocessing module is externally connected to the external network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. It is used to perform a preliminary determination on the ciphertext data, packetize the data and perform CRC verification accordingly, and then send the data packet to the Risc-V processor.
[0061] Preferably, after receiving the ciphertext data from the Rapid IO interface, the external network side preprocessing module packetizes multiple Rapid io interface frame data according to the message frame length, completes the CRC verification. After the verification passes, it forwards the message to the service logic processing module in Rsic-V through the AXI Stream interface to parse and process the message type. When the message type indicates a data message, it forwards the message to the algorithm processing module for decryption processing, and forwards the decrypted plaintext data to the internal network side preprocessing module through the AXI Stream.
[0062] The Risc-V processor includes: a service processing module and a control management module.
[0063] The service processing module provides AXI Stream interfaces to connect to the internal network side preprocessing module, the external network side preprocessing module and the algorithm processing module respectively, and provides an AXI RAM interface to connect to the control management module. It is used to parse the fields in the data packet received from the external network and distinguish the message type, forward the control message to the control management module, forward the data message to the algorithm processing module, and after parsing the decrypted service data, forward the decrypted service data to the internal network side preprocessing module.
[0064] The control management module provides an AXI RAM interface to connect to the service processing module. It is used to perform protocol parsing and processing on the control message and then forward it to the algorithm processing module. After receiving the control data returned by the algorithm processing module, it performs protocol processing according to the control protocol and then sends the data to the internal network side preprocessing module through the service processing module.
[0065] The algorithm processing module provides an AXI Stream interface to connect to the service processing module. It is used to perform decryption protection on the control data and send it back to the control management module. After decrypting the service data, it sends the decrypted data to the service processing module.
[0066] Preferably, the decryption device supports RC4 and AES decryption algorithms.
[0067] The internal network side preprocessing module is externally connected to the internal network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. It is used to complete the basic information determination, perform fragmentation and CRC calculation on the data accordingly, and then send the plaintext data to the internal network side user interface.
[0068] Preferably, the preprocessing module on the intranet side calculates the CRC of the packet and fills in the CRC calculation result, and after fragmenting the packet according to the Rapid IO frame format, it is sent to the intranet interface through the Rapid IO interface, thus completing the service decryption process.
[0069] Preferably, the entire device is implemented based on an FPGA programmable logic device, and 1 32-bit Risc-V processor is instantiated in the form of an IP core of the FPGA.
[0070] It is easy for those skilled in the art to understand that the above are only preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A link encryption device based on the RISC-V architecture, characterized in that, The encryption device includes: an internal network side preprocessing module, a Risc-V processor module, an algorithm processing module, and an external network side preprocessing module; The internal network side preprocessing module is externally connected to the internal network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. It is used to perform a preliminary determination on the plaintext data, packetize and perform CRC check on the data according to this, and then send the data packet to the Risc-V processor; The Risc-V processor includes: a service processing module and a control and management module; The service processing module provides AXI Stream interfaces to connect to the internal network side preprocessing module, the external network side preprocessing module, and the algorithm processing module respectively, and provides an AXI RAM interface to connect to the control and management module. It is used to distinguish the message type by parsing the fields in the data packet received from the internal network, forward the control message to the control and management module, forward the data message to the algorithm processing module, and after parsing the encrypted service data, forward the encrypted service data to the external network side preprocessing module; The control and management module provides an AXI RAM interface to connect to the service processing module. It is used to perform protocol parsing and processing on the control message and then forward it to the algorithm processing module. After receiving the control data returned by the algorithm processing module, it performs protocol processing according to the control protocol and then sends the data to the external network side preprocessing module through the service processing module; The algorithm processing module provides an AXI Stream interface to connect to the service processing module. It is used to encrypt and protect the integrity of the control data and send it back to the control and management module. After encrypting the service data, it sends the encrypted data to the service processing module; The external network side preprocessing module is externally connected to the external network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. It is used to complete the basic information determination, and then perform fragmentation and CRC calculation on the data according to this, and then send the ciphertext data to the external network side user interface.
2. The encryption device according to claim 1, wherein The entire encryption device is implemented based on an FPGA programmable logic device, and a 32-bit Risc-V processor is instantiated in the form of an FPGA IP core.
3. The link encryption device according to claim 1, characterized in that, After receiving the plaintext data from the Rapid IO interface, the internal network side preprocessing module packetizes the multiple Rapid io interface frame data according to the message frame length, completes the CRC check. After the check passes, it forwards the message to the service logic processing module in the Risc-V through the AXI Stream interface to parse and process the message type. When the message type indicates a data message, it forwards the message to the algorithm processing module for encryption processing, and forwards the encrypted ciphertext data to the external network side preprocessing module through the AXI Stream.
4. The encryption device according to claim 1, wherein The external network side preprocessing module performs CRC calculation on the message and fills in the CRC calculation result, and performs fragmentation processing according to the Rapid IO frame format and then sends it to the external network interface through the Rapid IO interface, thus completing the service encryption processing.
5. The encryption device according to claim 1, wherein, The encryption device supports RC4 and AES encryption algorithms.
6. A link decryption device based on the RISC-V architecture, characterized in that, The decryption device includes: an external network side preprocessing module, a Risc-V processor module, an algorithm processing module, and an internal network side preprocessing module; The external network side preprocessing module is externally connected to the external network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. It is used to perform a preliminary determination on the ciphertext data, packetize the data and perform CRC verification accordingly, and then send the data packet to the Risc-V processor; The Risc-V processor includes: a service processing module and a control and management module; The service processing module provides AXI Stream interfaces to connect to the internal network side preprocessing module, the external network side preprocessing module, and the algorithm processing module respectively, and provides an AXI RAM interface to connect to the control and management module. It is used to parse the fields in the data packet received from the external network and distinguish the message type, forward the control message to the control and management module, forward the data message to the algorithm processing module, and after parsing the decrypted service data, forward the decrypted service data to the internal network side preprocessing module; The control and management module provides an AXI RAM interface to connect to the service processing module. It is used to perform protocol parsing and processing on the control message and then forward it to the algorithm processing module. After receiving the control data returned by the algorithm processing module, it performs protocol processing according to the control protocol and then sends the data to the internal network side preprocessing module through the service processing module; The algorithm processing module provides an AXI Stream interface to connect to the service processing module. It is used to perform decryption protection on the control data and send it back to the control and management module. After decrypting the service data, it sends the decrypted data to the service processing module; The internal network side preprocessing module is externally connected to the internal network side Rapid IO interface and internally connected to the Risc-V processor through the AXI Stream interface. It is used to complete the basic information determination, and then perform fragmentation and CRC calculation on the data, and finally send the plaintext data to the internal network side user interface.
7. The decryption device according to claim 6, wherein The entire device is implemented based on an FPGA programmable logic device, and a 32-bit Risc-V processor is instantiated in the form of an FPGA IP core.
8. The decryption device according to claim 6, wherein After receiving the ciphertext data from the Rapid IO interface, the external network side preprocessing module packetizes the multiple Rapid io interface frame data according to the message frame length, completes the CRC verification. After the verification passes, it forwards the message to the service logic processing module in the Rsic-V through the AXI Stream interface to parse and process the message type. When the message type indicates a data message, it forwards the message to the algorithm processing module for decryption processing, and forwards the decrypted plaintext data to the internal network side preprocessing module through the AXI Stream.
9. The decryption device according to claim 6, characterized in that, The internal network side preprocessing module performs CRC calculation on the message and fills the CRC calculation result, and performs fragmentation processing according to the Rapid IO frame format and then sends it to the internal network interface through the Rapid IO interface, thus completing the service decryption processing.
10. The decryption device according to claim 6, wherein The decryption device supports RC4 and AES decryption algorithms.
Citation Information
Patent Citations
Data encryption control system based on USB interface and chip
CN112329038A
Data processing method, device and system
CN112910932A