Remote terminal unit, national secret encryption and decryption method and interface resource allocation method

By integrating national cryptographic components and extension modules into the remote terminal unit, using national cryptographic algorithms to encrypt and decrypt data, and optimizing interface resource allocation, the problem of insufficient data security is solved, and data transmission with high security and flexibility is achieved.

CN116132044BActive Publication Date: 2025-12-05SHENZHEN GAS CORP +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211506207.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-12-05
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

Existing remote terminal units lack sufficient security during data acquisition and reception, and cannot effectively protect the data.

Method used

The remote terminal unit integrates a CPU module, national cryptographic components, and power supply components, supports SM1-SM4 encryption and decryption functions, and expands interface resources through communication expansion modules and IO expansion modules. It uses national cryptographic algorithms to encrypt and decrypt data and optimizes interface resource allocation.

Benefits of technology

It achieves high security during the data acquisition and reception process, with encryption and decryption rates up to 10Mbps, avoiding interface resource conflicts and improving the security and flexibility of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132044B_ABST
    Figure CN116132044B_ABST
Patent Text Reader

Abstract

The application discloses a remote terminal unit, a national secret encryption and decryption method and an interface resource allocation method. The remote terminal unit comprises a CPU module; the CPU module comprises a CPU core board, a national secret component and a power supply component; wherein the CPU core board is electrically connected with the national secret component and the power supply component; the national secret component is connected with the CPU core board through an interface and is electrically connected with the power supply component, the national secret component supports SM1-SM4 encryption and decryption and is used for providing a national secret encryption and decryption function national secret component; and the power supply component is used for providing power supply for the remote terminal unit. The national secret component is arranged on the CPU module, the national secret component is used for providing national secret encryption and decryption functions, and the security of the remote terminal unit in the process of collecting and receiving data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of industrial control security, and in particular to a remote terminal unit, a national secret encryption and decryption method, and an interface resource allocation method. BACKGROUND

[0002] With the gradual advancement of IT / OT integration in the industrial internet, industrial control systems are increasingly connected to enterprise networks and the internet, forming an open network environment, especially with the development of the 5G and industrial internet integration trend. The networking development of industrial control systems has led to increasing system security risks and intrusions, and the security of data transmission is becoming increasingly challenging and threatening. Therefore, the remote terminal unit collects industrial field device state information and data, securely transmits it to the server for storage, and remotely controls the device to ensure the security of the data, which is particularly important for various industries. However, the existing remote terminal unit lacks sufficient security for data protection.

[0003] Therefore, the prior art still needs to be improved and developed. SUMMARY

[0004] The technical problem to be solved by the present application is to provide a remote terminal unit, a national secret encryption and decryption method, and an interface resource allocation method to solve the problem of insufficient security in the process of collecting and receiving data of the existing remote terminal unit.

[0005] The present application is implemented by the following technical scheme: a remote terminal unit, comprising: a CPU module;

[0006] The CPU module comprises a CPU core board, a national secret component, and a power supply component; wherein,

[0007] The CPU core board is electrically connected to the national secret component and the power supply component;

[0008] The national secret component is connected to the CPU core board through an interface and is electrically connected to the power supply component, and the national secret component supports SM1-SM4 encryption and decryption, providing national secret encryption and decryption functions;

[0009] The power supply component is electrically connected to the CPU core board and the national secret component, and the power supply component provides power for the CPU core board and the national secret component.

[0010] The further setting of the present application further comprises a communication expansion module and an IO expansion module;

[0011] The communication expansion module is electrically connected to the CPU module, and the communication expansion module is used to provide communication interface expansion;

[0012] The IO expansion module is electrically connected with the CPU module, and is used for providing digital and analog input and output expansion.

[0013] The CPU core board comprises a CPU chip, a DDR chip and an EMMC chip, and the CPU core board is connected to the communication expansion module and the IO expansion module through a peripheral interface.

[0014] The CPU module, the communication expansion module and the IO expansion module are electrically connected through a printed circuit board and an interface.

[0015] The power supply module comprises a DC / DC conversion circuit, a power input interface and a power output interface.

[0016] The DC / DC conversion circuit is electrically connected with the power input interface, the power output interface and the CPU core board.

[0017] The DC / DC conversion circuit is used for providing two groups of isolated power supplies of DC 24 and DC 5V.

[0018] The DC 5V is a main power supply.

[0019] The CPU module further comprises a communication unit, which is electrically connected with the CPU core board and is used for providing a communication function.

[0020] The communication expansion module comprises a communication expansion unit.

[0021] The communication expansion unit comprises a MiniPCIe interface, a DEBUG interface and an RS485 interface.

[0022] The MiniPCIe interface is electrically connected with the DEBUG interface and the RS485 interface.

[0023] Based on the same inventive concept, the application further provides a national secret encryption and decryption method applied to the remote terminal unit, which comprises the following steps:

[0024] decrypting the national secret data; wherein

[0025] The national secret decryption data comprises:

[0026] The CPU core board receives encrypted external data.

[0027] The CPU core board analyzes the external data and sends the external data to the national secret component.

[0028] The national secret component decrypts external data and sends the decrypted data to the CPU core board;

[0029] The CPU core board judges whether the decrypted data is legal;

[0030] The CPU core board receives the legal decrypted data;

[0031] The CPU core board discards the illegal decrypted data.

[0032] The further setting of the application further comprises:

[0033] National secret encryption data; wherein,

[0034] The national secret encryption data comprises:

[0035] The CPU core board collects internal data and sends the internal data to the national secret component;

[0036] The national secret component encrypts the internal data into encrypted data and sends the encrypted data to the CPU core board;

[0037] The CPU core board receives and packs the encrypted data;

[0038] The CPU core board sends the encrypted data to the outside.

[0039] Based on the same inventive concept, the application further provides an interface resource allocation method, which is used in the remote terminal unit and comprises:

[0040] The multiple groups of the same resources on the interface are prioritized;

[0041] The IO expansion module preferentially uses the interface resources with high priority, and the used interface resources are not output from the cascade port;

[0042] The remaining interface resources are sequentially output according to the priority.

[0043] The application has the following beneficial effects:

[0044] The application integrates the national secret component in the CPU module. The CPU core board is electrically connected with the national secret component and the power supply component. The national secret component supports SM1-SM4 encryption and decryption, and is used for providing national secret encryption and decryption functions. The national secret component achieves the effect of improving the security of the remote terminal unit in the process of collecting and receiving data by performing national secret decryption on the collected external data and performing national secret encryption on the transmitted internal data. BRIEF DESCRIPTION OF DRAWINGS

[0045] Figure 1 It is an external structure schematic diagram of the remote terminal unit of the application.

[0046] Figure 2 It is an internal structure block diagram of a CPU module of a remote terminal unit of the present application.

[0047] Figure 3 It is an internal structure block diagram of a communication expansion module of a remote terminal unit of the present application.

[0048] Figure 4 It is an internal structure block diagram of an IO expansion module of a remote terminal unit of the present application.

[0049] Figure 5 It is a flow chart of an interface resource allocation method provided by the present application.

[0050] Figure 6 It is an application schematic diagram of the interface resource allocation method provided by the present application.

[0051] Figure 7 It is a flow chart of national secret encryption data of a national secret encryption and decryption method provided by the present application.

[0052] Figure 8 It is a flow chart of national secret decryption data of a national secret encryption and decryption method provided by the present application.

[0053] Main element symbol explanation

[0054] 100, remote terminal unit; 10, CPU module; 11, CPU core board; 111, CPU chip; 112, DDR chip; 113, EMMC chip; 114, EEPROM chip; 12, national secret component; 13, power supply component; 131, DC / DC conversion circuit; 132, power input interface; 133, power output interface; 15, communication unit; 151, RS232 interface; 152, Ethernet interface; 153, USB interface; 16, input board-to-board communication interface; 17, output board-to-board communication interface; 20, communication expansion module; 21, communication expansion unit; 211, MiniPCIe interface; 212, DEBUG interface; 213, RS485 interface; 214, SIM card slot; 30, IO expansion module; 31, digital processing unit; 32, digital quantity interface; 33, analog processing unit; 34, analog quantity interface. DETAILED DESCRIPTION

[0055] The present application provides a remote terminal unit, a national secret encryption and decryption method and an interface resource allocation method, which are suitable for the field of industrial control safety. In order to make the purpose, technical scheme and effect of the present application more clear and explicit, the present application is further described in detail below with reference to the drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0056] In the embodiments and the claims, unless otherwise specified, "a" and "the" can refer to one or more than one.

[0057] In addition, if the description of "first", "second" and the like is involved in the embodiments of the present application, the description of "first", "second" and the like is only for the purpose of description, and cannot be understood as indicating or implying the relative importance of the indicated technical features or implicitly indicating the number of the indicated technical features. Therefore, the features limited by "first", "second" can explicitly or implicitly include at least one of the features.

[0058] In the present application, unless otherwise specified and limited, the "on" or "under" of the first feature to the second feature can be that the first and second features are in direct contact, or the first and second features are in indirect contact through an intermediate medium. Moreover, the "over", "above" and "on" of the first feature to the second feature can be that the first feature is directly above or obliquely above the second feature, or only indicates that the horizontal height of the first feature is higher than that of the second feature. The "under", "below" and "under" of the first feature to the second feature can be that the first feature is directly below or obliquely below the second feature, or only indicates that the horizontal height of the first feature is less than that of the second feature.

[0059] It should be noted that when an element is referred to as "fixed to" or "disposed on" another element, it can be directly on the other element or there can be a middle element. When an element is referred to as "connected to" another element, it can be directly connected to the other element or there can be a middle element. The terms "vertical", "horizontal", "up", "down", "left", "right" and similar expressions used herein are for the purpose of illustration only and are not the only embodiments.

[0060] In addition, the technical solutions of various embodiments can be combined with each other, but it must be based on the realization of ordinary skilled in the art, when the combination of technical solutions appears contradictory or unachievable, it should be considered that the combination of technical solutions does not exist, nor within the scope of protection required by the present application.

[0061] Embodiments

[0062] Please refer to Figures 1-4 The present application is described with an embodiment of a remote terminal unit.

[0063] Please refer to Figure 1 The present application provides a remote terminal unit 100, which comprises a CPU (Central Processing Unit, CPU) module 10. Please refer to Figure 2The CPU module 10 comprises a CPU core board 11, a national secret component 12 and a power supply component 13. The CPU core board 11 is electrically connected with the national secret component 12 and the power supply component 13. The national secret component 12 is connected with the CPU core board 11 through an interface and is electrically connected with the power supply component 13. The national secret component 12 comprises an SM1 algorithm engine 121, an SM2 algorithm engine 122, an SM3 algorithm engine 123 and an SM4 algorithm engine 124. The SM1 algorithm engine 121, the SM2 algorithm engine 122, the SM3 algorithm engine 123 and the SM4 algorithm engine 124 are electrically connected with the power supply component 13 respectively. The national secret component 12 supports SM1-SM4 encryption and decryption and is used for providing national secret encryption and decryption functions. The national secret component 12 performs national secret encryption and decryption on communication data and IO data. The power supply component 13 is electrically connected with the CPU core board 11 and the national secret component 12. The power supply component 13 provides power supply for the CPU core board 11 and the national secret component 12. The national secret component 12 is integrated on the CPU module 10. The national secret component 12 performs national secret decryption on collected external data and performs national secret encryption on transmitted internal data, so as to achieve the effect of data security protection and ensure data security.

[0064] The national secret component 12 adopts a national secret algorithm to encrypt and decrypt the external data received by the remote terminal unit 100 and the internal data collected. The national secret algorithm is a series of algorithms formulated by the State Cryptography Administration. It includes symmetric encryption algorithm, elliptic curve asymmetric encryption algorithm and hash algorithm. Specifically, it includes SM1, SM2, SM3 and SMS4, etc. Among them, SM2 is a public key algorithm published by the State Cryptography Administration, with an encryption strength of 256 bits. Other important commercial cryptographic algorithms include: SM1, a symmetric encryption algorithm with an encryption strength of 128 bits, implemented by hardware; SM3, a cryptographic hash algorithm with a hash value length of 32 bytes, published at the same time as SM2 algorithm; SMS4, a symmetric encryption algorithm published with WAPI standard, implemented by software, with an encryption strength of 128 bits. The national secret component 12 in the embodiment has an SM1 algorithm engine 121, an SM2 algorithm engine 122, an SM3 algorithm engine 123 and an SM4 algorithm engine 124, supporting SM1-SM4 encryption and decryption, achieving the effect of protecting data security and ensuring data security. In the embodiment, the national secret component 12 can realize national secret encryption and decryption of communication data and IO data, and the encryption and decryption rate can reach 10 Mbps. The CPU module 10 is provided with the national secret component 12, which can quickly encrypt and decrypt the data of the remote terminal unit 100, to ensure the effect of data security. The national secret component 12 is connected to the CPU core board 11 through a USB interface.

[0065] Please continue to refer to Figure 1 In a further embodiment of the embodiment, the remote terminal unit further comprises a communication expansion module 20 and an IO (In&Out, input and output) expansion module 30. Within the interface resource limit, the IO expansion module 30 can support cascading multiple, i.e. the IO expansion module 30 can be a single IO expansion module 30 or multiple IO expansion modules 30. In the embodiment, two IO expansion modules 30 are provided, but this is not limited.

[0066] Please continue to refer to Figure 1 In a further embodiment of the embodiment, the CPU module 10, the communication expansion module 20 and the IO expansion module 30 are respectively arranged on printed circuit boards, and the CPU module 10, the communication expansion module 20 and the IO expansion module 30 are electrically connected through the printed circuit boards and interfaces.

[0067] Please continue to refer to Figure 2The CPU core board 11 is the minimum running unit of the system. In a further embodiment of the embodiment, the CPU core board 11 is integrated with a CPU chip 111, a DDR (Double Data Rate) chip 112, an EMMC (Embedded Multi Media Card) chip 113, an EEPROM (Electrically Erasable Programmable read only memory) chip 114 and the like. The CPU core board 11 supports running a Linux system and leads various peripheral interfaces to be connected to other modules.

[0068] Referring to Figure 2 In a further embodiment of the embodiment, the power supply assembly 13 includes a DC / DC (Direct Current) conversion circuit 131, a power input interface 132 and a power output interface 133. The DC / DC conversion circuit 131 is electrically connected with the power input interface 132, the power output interface 133 and the CPU core board 11. The DC / DC conversion circuit 131 provides two groups of isolated power supplies of DC 24 and DC 5V for the remote terminal unit 100. The DC 5V is the main power supply and the DC 24V is the power supply for the IO part. In the embodiment, all the IO interfaces are isolated.

[0069] Referring to Figure 2 In a further embodiment of the embodiment, the CPU module 10 further includes a communication unit 15. The communication unit 15 is electrically connected with the CPU core board 11. The communication unit 15 is used to provide communication functions. Specifically, in the embodiment, two RS232 interfaces 151, two Ethernet interfaces 152 and one USB (Universal Serial Bus) interface 153 are arranged on the CPU module 10. Further, the two RS232 interfaces are connected with the CPU core board 11 through UART (Universal Asynchronous Receiver / Transmitter) interfaces. The two Ethernet interfaces 152 are connected with the CPU core board 11 through MII (Media Independent Interface) interfaces and GMII (Gigabit Media Independent Interface) interfaces respectively, but the embodiment is not limited thereto.

[0070] The current remote terminal unit product mostly adopts the design of CPU and IO integration, but the design will cause the problems of insufficient IO module support quantity and poor flexibility of the remote terminal unit product. The remote terminal unit provided by the application adopts the form of extended IO unit and communication unit to solve the problems of insufficient IO module support quantity and poor flexibility of the current remote terminal unit product.

[0071] Please refer to Figure 1 In a further embodiment of the embodiment, the communication expansion module 20 and the IO expansion module 30 are arranged on the remote terminal unit 100 to expand the communication function and provide digital and analog input and output expansion. The communication expansion module 20 is electrically connected with the CPU module 10, and the communication expansion module 20 is an auxiliary module of the CPU module 10. The communication expansion module 20 is used to provide communication interface expansion. The communication expansion module 20 can expand the communication functions of RS485, NB-IOT (Narrow Band Internet of Things) and the like. The IO expansion module 30 is electrically connected with the CPU module 10, and the IO expansion module 30 is used to provide digital and analog input and output expansion.

[0072] Please refer to Figures 1-4 In a further embodiment of the embodiment, the CPU module 10 is provided with USB, UART, GPIO (General-purpose input / output), SDIO (Secure Digital Input and Output), SPI (Serial Peripheral Interface) and the like, but not limited thereto. The remote terminal unit 100 is provided with communication expansion and IO expansion through the inter-board communication interface 17. The communication expansion module 20 and the IO expansion module 30 are both provided with the input inter-board communication interface 16 and the output inter-board communication interface 17. The communication expansion module 20 and the IO expansion module 30 are both provided with GPIO, SPI and the like, but not limited thereto. In addition, the communication expansion module 20 and the IO expansion module 30 are both provided with the power input interface and the power output interface 133 to receive the isolated power supply provided by the power supply component 13. Each IO expansion module 30 is provided with the corresponding input inter-board communication interface 16, the power input interface 132, the output inter-board communication interface 17 and the power output interface 133. The positions and pin definitions of all input and output interfaces are one-to-one corresponding, so as to realize the cascading function of the IO expansion module 30.

[0073] Please refer to Figure 1 and Figure 3 In a further embodiment of the embodiment, the communication expansion module 20 is provided with a communication expansion unit 21 for providing communication functions, which includes a MiniPCIe (Mini Peripheral Component Interconnect) interface 211, a DEBUG interface 212 and two RS485 interfaces 213, but is not limited thereto. The MiniPCIe interface 211 is electrically connected to the DEBUG interface 212 and the RS485 interfaces 213. The DEBUG interface 212 and the RS485 interfaces 213 are connected to the input inter-board communication interface 16 and the output inter-board communication interface 17 through UART interfaces, respectively. The MiniPCIe interface 211 is connected to the input inter-board communication interface 16 and the output inter-board communication interface 17 through a USB interface 153, and a SIM card slot 214 is provided on the MiniPCIe interface 211 to meet the needs of communication expansion.

[0074] Please refer to Figure 1 and Figure 4 In a further embodiment of the embodiment, the IO expansion module 30 is provided with an optoelectronic isolation digital processing unit 31, a digital interface 32, an analog processing unit 33 and an analog interface 34. The digital processing unit 31 is electrically connected to the digital interface 32, and the analog processing unit 33 is electrically connected to the analog interface 34. The IO expansion module 30 mainly uses GPIO interfaces and SPI interfaces, the GPIO interfaces provide digital input and output expansion, and the SPI interfaces provide analog input and output expansion to meet the needs of IO expansion.

[0075] Further, the IO interface of the IO expansion module 30 adopts a unified 25-pin SCSI interface, so that each IO expansion module 30 is consistent in appearance. When the number of the IO expansion modules 30 remains unchanged, the shell of the remote terminal unit 100 can remain unchanged, achieving the effect of facilitating cost reduction and rapid product development.

[0076] Based on the same inventive concept, the application also provides an interface resource allocation method applied to the remote terminal unit, please refer to Figure 5 and Figure 6 The application is described in a application embodiment of the interface resource allocation method.

[0077] The commonly used IO cascade interface currently available has the following problems: for commonly used exclusive interface resources such as SPI interface, USB interface, GPIO interface, etc., the interface functions are set by grouping, and the IO module uses fixed interface resources. For example, if two IO expansion modules use the same group of SPI interface resources, even if there are other groups of SPI resources on the communication interface, the two IO expansion modules cannot be used simultaneously due to interface resource conflicts. Therefore, when using the IO module, in addition to considering the interface functions of the IO module, it is also necessary to consider whether the interface resources used between the IO modules conflict, which greatly limits the flexibility of the IO expansion module cooperation.

[0078] Figure 5 The flowchart of the interface resource allocation method. The order of the steps in the flowchart can be changed according to different needs, and some steps can be omitted. Figure 6 The schematic diagram of one embodiment of the interface resource allocation method applied to the IO expansion module 30. The interface resource allocation method provided by the present application optimizes the allocation of interface resources, and the steps thereof include:

[0079] S110, priority sorting of multiple groups of the same resources on the interface;

[0080] For details, please refer to Figure 5 and Figure 6 When the input board-to-board communication interface 16 of the IO expansion module 30 contains n (n≥2) identical exclusive interface resources, the interface resources are grouped into n priority channels according to P1-Pn. In this embodiment, n=3, the input board-to-board communication interface 16 and the output board-to-board communication interface 17 each contain 3 identical SPI interfaces, and the SPI interfaces are grouped according to P1-P3. That is, P1: SPI0, P2: SPI1, P3: SPI2.

[0081] S120, the IO expansion module preferentially uses the interface resources with high priority, and the used interface resources are no longer output from the cascade port;

[0082] For details, please refer to Figure 5 and Figure 6 When the IO expansion module 30 uses the SPI interface resources, it preferentially occupies the interface from P1, that is, P1 of the input board-to-board communication interface 16 is connected to the analog processing unit 33, P1 of the input board-to-board communication interface 16 is occupied by the IO expansion module 30 itself, and P1 is no longer output from the cascade port.

[0083] S130, for the remaining interface resources, output them in order according to the priority;

[0084] For details, please refer to Figure 5 andFigure 6 The interface resources remaining in the input interboard communication interface 16 are P2 and P3, and P2 and P3 of the input interboard communication interface 16 are output in the order of priority. That is, P2 of the input interboard communication interface 16 is connected and output before P1 of the output interboard communication interface 17, and P3 of the input interboard communication interface 16 is connected and output after P2 of the output interboard communication interface 17.

[0085] Compared with the direct cascade mode, the interface resource allocation method provided by the application can avoid the IO expansion module conflict problem caused by resource grouping, and improve the flexibility of the interface.

[0086] Based on the same inventive concept, the application further provides a national secret encryption and decryption method applied to the remote terminal unit. Figure 7 Figure 8 The application is described by an application embodiment of the national secret encryption and decryption method.

[0087] Figure 7 Figure 8 The national secret encryption and decryption method is shown in a flowchart, Figure 7 Figure Eight According to different requirements, the order of the steps in the above flowcharts can be changed, and some steps can be omitted. The steps of the national secret encryption and decryption method include:

[0088] S220, national secret decryption data; and S230, national secret encryption data.

[0089] Specifically, S220 further includes:

[0090] S221, the CPU core board receives encrypted external data;

[0091] S222, the CPU core board parses the received external data and sends the parsed data to the national secret component;

[0092] S223, the national secret component decrypts the received external data and sends the decrypted data to the CPU core board;

[0093] S224, the CPU core board judges whether the received decrypted data is legal;

[0094] Specifically, the CPU core board judges the decrypted data. When the CPU core board judges that the received decrypted data is legal, step S224 is entered. When the CPU core board judges that the received decrypted data is not legal, step S225 is entered.

[0095] S225, the CPU core board receives the legal decrypted data; ​​​

[0096] S226, the CPU core board discards the illegal decrypted data.

[0097] Specifically, S230 further comprises:

[0098] S231, the CPU core board collects internal data and sends the internal data to the national secret component;

[0099] Specifically, the internal data is data generated in the working process of the remote terminal unit;

[0100] S232, the national secret component encrypts the internal data into encrypted data and sends the encrypted data to the CPU core board;

[0101] S233, the CPU core board receives and packages the encrypted data;

[0102] S234, the CPU core board sends the encrypted data to the outside.

[0103] The national secret encryption and decryption method provided by the application realizes the decryption of external data and the encryption of internal data to be sent, achieves national secret level data encryption and decryption, and improves the security effect.

[0104] In summary, the remote terminal unit, the national secret encryption and decryption method and the interface resource allocation method provided by the application have the following beneficial effects:

[0105] The national secret component is integrated in the CPU module. The CPU core board is electrically connected with the national secret component and the power supply component. The national secret component is used for providing national secret encryption and decryption functions, so that the security of the remote terminal unit in the process of collecting and receiving data is improved

[0106] The secret component of the application is connected with the CPU core board through a USB interface, supports national secret SM1-SM4 encryption and decryption, and the encryption and decryption rate can reach 10Mbps, so that the encryption and decryption of communication data and IO data are realized.

[0107] The IO function of the application is realized in the form of an expansion module. The CPU module is connected with USB, SPI, SDIO, UART, GPIO interfaces and IO expansion modules, and provides two groups of isolated power supplies DC24V and DC5V for the IO expansion modules. The position and pin definition of the input and output interfaces on each IO expansion module are one-to-one corresponding, so that the cascading function of the IO expansion module is realized, the number of supported IO modules is increased, and the flexibility is improved.

[0108] The IO interface of the IO expansion module adopts a unified 25-pin SCSI interface, so that each IO expansion module is consistent in appearance, and when the number of IO expansion modules is unchanged, the shell of the remote terminal unit can remain unchanged, thereby achieving the effect of facilitating cost reduction and rapid product development

[0109] The interface resource allocation method provided by the application can avoid the IO expansion module conflict problem caused by resource grouping, and achieve the effect of improving the flexibility of the interface.

[0110] It should be understood that the application of the application is not limited to the above examples, and those skilled in the art can improve or change it according to the above description, and all these improvements and changes shall belong to the protection scope of the appended claims of the application.

Claims

1. A remote terminal unit, characterized in that, Includes: CPU module; The CPU module includes: a CPU core board, national cryptographic components, and a power supply component; wherein... The CPU core board is electrically connected to the national cryptographic component and the power supply component; The national cryptographic component is connected to the CPU core board via an interface and is electrically connected to the power supply component. The national cryptographic component supports SM1-SM4 encryption and decryption and is used to provide national cryptographic encryption and decryption functions. The power supply component is electrically connected to the CPU core board and the national cryptographic component, and the power supply component provides power to the CPU core board and the national cryptographic component; It also includes: a communication expansion module and an I / O expansion module; The communication expansion module is electrically connected to the CPU module, and the communication expansion module is used to provide communication interface expansion; The IO expansion module is electrically connected to the CPU module, and the IO expansion module is used to provide digital and analog input / output expansion.

2. The remote terminal unit according to claim 1, characterized in that... The CPU core board includes a CPU chip, a DDR chip, and an EMMC chip. The CPU core board extends peripheral interfaces to connect to the communication expansion module and the IO expansion module.

3. The remote terminal unit according to claim 1, characterized in that, The CPU module, the communication expansion module, and the IO expansion module are electrically connected via printed circuit boards and interfaces.

4. The remote terminal unit according to claim 1, characterized in that, The power supply components include: a DC / DC converter circuit, a power input interface, and a power output interface; The DC / DC converter circuit is electrically connected to the power input interface, the power output interface, and the CPU core board. The DC / DC converter circuit is used to provide two isolated power supplies, DC24V and DC5V. DC5V is the main power supply.

5. The remote terminal unit according to claim 1, wherein the CPU module further comprises: A communication unit is electrically connected to the CPU core board and is used to provide communication functions.

6. The remote terminal unit according to claim 1, wherein the communication extension module comprises: Communication expansion unit; The communication expansion unit includes: a MiniPCIe interface, a DEBUG interface, and an RS485 interface; The MiniPCIe interface is electrically connected to the DEBUG interface and the RS485 interface.

7. A national cryptographic encryption / decryption method, applied to the remote terminal unit according to any one of claims 1-6, characterized in that, include: Declassified national cryptographic data; The national cryptographic decryption data includes: The CPU core board receives encrypted external data from the I / O expansion module and the communication expansion module; The CPU core board parses external data and sends it to the national cryptographic components; The national cryptographic component decrypts external data and sends the decrypted data to the CPU core module; The CPU core board determines whether the decrypted data is valid. The CPU core board receives legitimate decrypted data; The CPU core board discards invalid decrypted data.

8. The national cryptographic encryption / decryption method according to claim 7, characterized in that, Also includes: National cryptographic encryption of data; The national cryptographic encryption data includes: The CPU core board collects internal data and sends the internal data to the national cryptographic components; The national cryptographic component encrypts internal data into encrypted data and sends the encrypted data to the CPU core board; The CPU core board receives and packages encrypted data; The CPU core board sends encrypted data to the outside.

9. An interface resource allocation method, applied to the remote terminal unit according to any one of claims 1-6, characterized in that, include: Prioritize multiple groups of the same resource on the interface; The IO extension module prioritizes the use of high-priority interface resources, and already used interface resources will no longer be output from the cascade port; The remaining interface resources are output sequentially according to their priority.

Citation Information

Patent Citations

  • A safety acquisition remote terminal unit based on a national password high performance chip

    CN106773941A

  • Platform slicing of central processing unit (CPU) resources

    US20200225724A1