PCI-E interface password card based on XC7K325T chip

By employing a PCI-E interface and an FPGA chip management core in the cryptographic card, combined with DMA and multi-buffered pipeline scheduling technology, a high-speed encryption and decryption operation and a high-security encryption card were achieved, solving the problem of low communication speed in existing technologies.

CN115879169BActive Publication Date: 2026-02-13SHENZHEN LOONGSON JIANGSU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111124840.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-25
Publication Date
2026-02-13
Estimated Expiration
2041-09-25

AI Technical Summary

Technical Problem

Existing cryptographic cards have low communication rates, which cannot meet the needs of high-speed encryption devices.

Method used

The PCI-E interface is used as the interaction interface between the encryption card and the host, and an FPGA chip is used as the management core. In addition, a cryptographic algorithm chip approved by the State Cryptography Administration is used as the computing unit. DMA and multi-buffered pipeline scheduling technology are combined for data transmission and cryptographic operations.

Benefits of technology

It achieves high-speed data transmission and encryption/decryption operations, improves security, and solves the problems of traditional encryption card chips having many types and low data processing performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115879169B_ABST
    Figure CN115879169B_ABST
Patent Text Reader

Abstract

The application discloses a PCI-E interface password card based on an XC7K325T chip, which comprises a core processor and a power conversion chip, the core processor is connected with an SM1 operation chip through an FMC bus, the core processor is connected with a master control chip through the FMC bus, and the master control chip is connected with a second Flash memory chip through an SPI interface. By adopting the XC7K325T chip of the XILINX company and the DMA and multi-buffer pipeline scheduling technology on the bus interface unit, the bus data transmission and the password operation are concurrently executed, the encryption and decryption operation and the management of the key can be completed, the algorithm types include SM1, SM2, SM3 and SM4 national secret algorithms, compared with a traditional scheme, the password card not only has the characteristics of fast data transmission and processing speed, but also has high safety, the encryption card can perform high-speed encryption and decryption operation, and the problems of multiple chip types, low data processing performance and high manufacturing cost of the traditional encryption card are solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the field of servers, in particular to a PCI-E interface password card based on an XC7K325T chip. BACKGROUND

[0002] At present, most known password cards adopt serial ports or USB interfaces as the interactive interfaces of the password cards and hosts, and the communication rate of the serial ports or the USB interfaces is relatively low, so the serial ports or the USB interfaces cannot meet the requirement of high-speed encryption of encryption machines and the like.

[0003] In view of the above problems, the PCI-E interface password card based on the XC7K325T chip adopts a PCI-E interface with a relatively high communication rate as the interactive interface of the encryption card and the host, realizes communication with the host in the form of a bridge, and additionally, the encryption card adopts an FPGA chip as a management core and a password algorithm chip approved by the State Cryptography Administration as an operation unit. SUMMARY

[0004] In order to overcome the defects of the prior art, the PCI-E interface password card based on the XC7K325T chip adopts a PCI-E interface with a relatively high communication rate as the interactive interface of the encryption card and the host, realizes communication with the host in the form of a bridge, and additionally, the encryption card adopts an FPGA chip as a management core and a password algorithm chip approved by the State Cryptography Administration as an operation unit.

[0005] In order to solve the above technical problems, the application provides the following technical scheme: a PCI-E interface password card based on an XC7K325T chip, which comprises a core processor and a power conversion chip, the core processor is connected with an SM1 operation chip through an FMC bus, the core processor is connected with a master control chip through the FMC bus, the master control chip is connected with a second Flash memory chip through an SPI interface, the core processor is connected with a first Flash memory chip through the SPI interface, the master control chip is connected with two random number generator chips through an SPI, the master control chip is connected with a secret key management chip through the SPI interface, the core processor is connected with a PCI-E gold finger interactive interface through a PCI-E bus, the core processor is connected with a JTAG debugging interface through a JTAG bus, the master control chip is connected with a TTL level UART bus and a serial port management debugging port and the JTAG debugging interface through a JTAG bus, and the power conversion chip is electrically connected with the core processor, the first Flash memory chip, the second Flash memory chip, the master control chip, the operation chip, an SM2 operation chip, the secret key management chip and the random number generator chip.

[0006] As a preferred technical scheme of the present application, the power conversion chip converts voltage to 3.3V, 1.8V, 1.2V and 1.0V, respectively, and all of them are converted from 12V input power.

[0007] As a preferred technical scheme of the present application, the first and second Flash memory chips are all loss-preventing storage chips with power-off protection, the first Flash memory chip is used for information storage of the core processor and storage of start-up files of each chip, and the second Flash memory chip is used for storage of ARM-related programs.

[0008] As a preferred technical scheme of the present application, the master control chip is specifically SM32H753VI chip, which is used for control chip of ARM.

[0009] As a preferred technical scheme of the present application, the core processor is XILINX XC7K325T chip, which is mainly used for core data processing of the encryption card.

[0010] As a preferred technical scheme of the present application, the secret key management chip is specifically ACL16 chip, which is mainly used for management of user secret key information.

[0011] As a preferred technical scheme of the present application, the random number generator chip is used for generation of physical true random numbers.

[0012] As a preferred technical scheme of the present application, the JTAG debugging interface is used for downloading programs and online simulation function during program debugging.

[0013] As a preferred technical scheme of the present application, the serial port management debugging port is used for printing output debugging information and maintaining input and output interaction with program debuggers.

[0014] As a preferred technical scheme of the present application, the PCI-E gold finger interaction interface is used for information interaction between the encryption card and the upper computer served by the encryption card.

[0015] Compared with the prior art, the present application has the following beneficial effects:

[0016] By adopting the XILINX XC7K325T chip, a standard FMC interface is adopted, the VITA57.1 specification is met, x8 GTX@10Gbps / lane high-speed serial bus is supported, 80 pairs of LVDS signals and IIC bus interfaces are supported, 4-way 10G SFP+ optical fiber channels are supported, single-mode and multi-mode optical fibers and RapidIO, Aurora, Gigabit Ethernet and other high-speed serial transmission protocols are supported, the SATA3.0 standard is met and 6Gbps / lane line speed is supported, the storage bandwidth can reach 1.6GByte / s, the cache capacity is up to 4GByte DDR3 SDRAM, and at the same time, the DMA and multi-buffer pipeline scheduling technology are adopted on the bus interface unit, so that the bus data transmission and the password operation are concurrently executed, the encryption and decryption operation and the management of the key can be completed, the algorithm types include SM1, SM2, SM3 and SM4 national secret algorithms, compared with the traditional scheme, the password card not only has the characteristics of fast data transmission and processing speed, but also has high security, the encryption card can perform high-speed encryption and decryption operation, and the problems of the traditional encryption card, such as multiple chip types, low data processing performance and high manufacturing cost, are solved. BRIEF DESCRIPTION OF DRAWINGS

[0017] Fig. 1 It is a main structure schematic diagram of the encryption card of the application;

[0018] Fig. 2 It is a bus connection schematic diagram of the encryption card of the application;

[0019] Fig. 3 It is an outline size structure schematic diagram of the encryption card of the application.

[0020] Wherein: 1, core processor; 2, first Flash memory chip; 3, second Flash memory chip; 4, main control chip; 5, SM1 operation chip; 6, SM2 operation chip; 7, key management chip; 8, random number generator chip; 9, first JTAG debugging interface; 10 serial port management debugging port; 11, PCI-E golden finger interaction interface; 12, power conversion chip; 13, second JTAG debugging interface. DETAILED DESCRIPTION

[0021] In order to make the technical means, creative features, purposes and effects of the application easy to understand, the application is further described below in combination with specific embodiments, but the following embodiments are only preferred embodiments of the application, not all. Based on the embodiments in the embodiments, other embodiments obtained by those skilled in the art without creative labor belong to the protection scope of the application. In the following examples, the experimental methods are conventional methods, and the materials, reagents and the like used in the following examples are commercially available unless otherwise specified.

[0022] Embodiment

[0023] As Figs. 1-3 shown, the application provides a PCI-E interface password card based on XC7K325T chip, including core processor 1 and power conversion chip 12, the core processor 1 is connected with SM1 operation chip 5 through FMC bus, the core processor 1 is connected with main control chip 4 using FMC bus, the main control chip 4 is connected with second Flash memory chip 3 using SPI interface, the core processor 1 is connected with first Flash memory chip 2 through SPI interface, the main control chip 4 is connected with a plurality of random number generator chips 8 using SPI, the main control chip 4 is connected with secret key management chip 7 using SPI interface, the core processor 1 is connected with PCI-E golden finger interaction interface 11 through PCI-E bus, the core processor 1 is connected with first JTAG debugging interface 9 through JTAG bus, the main control chip 4 is connected with second JTAG debugging interface 13 through JTAG bus, the main control chip 4 is connected with serial port management debugging port 10 using TTL level UART bus, the power conversion chip 12 is electrically connected with core processor 1, first Flash memory chip 2, second Flash memory chip 3, main control chip 4, operation chip, SM2 operation chip 6, secret key management chip 7 and random number generator chip 8 respectively.

[0024] By using XC7K325T chip of XILINX company, standard FMC interface is adopted, VITA57.1 specification is met, x8 GTX@10Gbps / lane high-speed serial bus is supported, 80 pairs of LVDS signals and IIC bus interface are supported, 4-way 10G SFP+ optical fiber channel is supported, single-mode and multi-mode optical fiber and RapidIO, Aurora, Gigabit Ethernet and other high-speed serial transmission protocols are supported, SATA3.0 standard is met and 6Gbps / lane line speed is supported, storage bandwidth can reach 1.6GByte / s, cache capacity can support 4GByte DDR3 SDRAM, and at the same time, DMA and multi-buffer pipeline scheduling technology are used on the bus interface unit, so that bus data transmission and password operation are executed concurrently, encryption and decryption operation and key management can be completed, algorithm types include SM1, SM2, SM3 and SM4 national secret algorithm, compared with traditional scheme, the password card not only has the characteristics of fast data transmission and processing speed, but also has high security, the encryption card can perform high-speed encryption and decryption operation, solves the problems of multiple chip types, low data processing performance and high manufacturing cost of traditional encryption card.

[0025] The power conversion chip 12 converts voltage to 3.3V, 1.8V, 1.2V, 1.0V, and all are converted from 12V input power supply, the first flash memory chip 2 and the second flash memory chip 3 all adopt the anti-loss storage chip with power-off protection, the first flash memory chip 2 is used for information storage of the core processor 1 and storage of start-up files of each chip, the second flash memory chip 3 is used for storage of ARM related programs, the master control chip 4 specifically adopts an SM32H753VI chip, which is used for the control chip of ARM, the core processor 1 adopts an XILINX XC7K325T chip, which is mainly used for core data processing of the encryption card, the key management chip 7 specifically adopts an ACL16 chip, the key management chip 7 is mainly used for managing information of user keys, the random number generator chip 8 is used for generating physical true random numbers, the first JTAG debugging interface 9 is used for downloading programs and online simulation functions during program debugging, the serial port management debugging port 10 is used for printing debugging information and maintaining input and output interaction with a program debugger, and the PCI-E gold finger interaction interface 11 is used for information interaction between the encryption card and a host computer served by the encryption card.

[0026] In the present application, unless otherwise explicitly specified and limited, the first feature "on" or "under" the second feature can include that the first and second features are in direct contact, or that the first and second features are not in direct contact but are in contact through another feature between them. Moreover, the first feature "on", "above" and "over" the second feature includes that the first feature is directly above and obliquely above the second feature, or only indicates that the first feature is higher in horizontal height than the second feature. The first feature "under", "below" and "under" the second feature includes that the first feature is directly below and obliquely below the second feature, or only indicates that the first feature is lower in horizontal height than the second feature.

[0027] The basic principles, main features and advantages of the present application are shown and described above. It should be understood by those skilled in the art that the present application is not limited by the above embodiments, and the above embodiments and descriptions in the specification are only preferred examples of the present application and are not intended to limit the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.

Claims

1. A PCI-E interface cryptographic card based on the XC7K325T chip, comprising a core processor (1) and a power conversion chip (12), characterized in that: The password card also includes an SM1 computing chip (5) and an SM2 computing chip (6). The core processor (1) is connected to the SM1 computing chip (5) via an FMC bus. The core processor (1) is connected to the main control chip (4) via an FMC bus. The main control chip (4) is connected to the second Flash memory chip (3) via an SPI interface. The core processor (1) is connected to the first Flash memory chip (2) via an SPI interface. The main control chip (4) is connected to two random number generator chips (8) via SPI. The main control chip (4) is connected to the key management chip (7) via an SPI interface. The core processor (1) is connected to the key management chip (7) via a PCI-E bus. The line is connected to the PCI-E gold finger interaction interface (11). The core processor (1) is connected to the first JTAG debugging interface (9) via the JTAG bus. The main control chip (4) is connected to the second JTAG debugging interface (13) via the JTAG bus. The main control chip (4) is connected to the TTL level UART bus and the serial port management debugging port (10). The power conversion chip (12) is electrically connected to the core processor (1), the first Flash memory chip (2), the second Flash memory chip (3), the main control chip (4), the SM1 operation chip (5), the SM2 operation chip (6), the key management chip (7), and the random number generator chip (8), respectively.

2. The PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The power conversion chip (12) converts voltages of 3.3V, 1.8V, 1.2V, and 1.0V respectively, all of which are converted from a 12V input power supply.

3. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: Both the first Flash memory chip (2) and the second Flash memory chip (3) are anti-loss storage chips with power-off protection. The first Flash memory chip (2) is used as the information storage and startup file of the core processor (1), and the second Flash memory chip (3) is used to store ARM-related programs.

4. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The main control chip (4) specifically adopts the SM32H753VI chip, which is used as the control chip for ARM.

5. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The core processor (1) uses the XILINX XC7K325T chip for bus scheduling, cryptographic operations and data processing of the cryptographic card.

6. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The key management chip (7) adopts the ACL16 chip and is used to manage the generation, storage and verification of user keys.

7. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The random number generator chip (8) is used to generate physical true random numbers.

8. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The second JTAG debugging interface (13) is used for downloading programs and online simulation during program debugging.

9. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The first JTAG debugging interface (9) is used for downloading programs and online simulation during program debugging.

10. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The serial port management debugging port (10) is used to print out debugging information and maintain input / output interaction with the program debugger.

11. A PCI-E interface cryptographic card based on the XC7K325T chip according to claim 1, characterized in that: The PCI-E gold finger interaction interface (11) is used for the cryptographic card to interact with the host computer it serves.

Citation Information

Patent Citations

  • Encryption and decryption card based on PCI-E (peripheral component interconnect-express) bus technology

    CN204390237U

  • PCI-E (Peripheral Component Interconnect-Express) interface cipher card based on CCP903T chip

    CN209625213U