A Real-time Embedded IROS Secure Encryption Communication Method Based on FPGA

By using FPGA modules in the robot operating system for real-time encryption and decryption processing, the problem of encrypted communication affecting real-time in traditional technology is solved, and efficient and stable secure communication is achieved.

CN118174903BActive Publication Date: 2025-06-10浪潮智能终端有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410218106.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-28
Publication Date
2025-06-10
Estimated Expiration
2044-02-28

AI Technical Summary

Technical Problem

When traditional robot operating systems use encrypted communication on ARM embedded architecture, they affect the normal communication speed, and are not very real-time and cannot meet the requirements of strong real-time scenarios.

Method used

The real-time embedded IROS secure encryption communication method based on FPGA is adopted, and the encryption processing unit and the decryption processing unit on the FPGA module are used to combine heterogeneous communication between the ARM module and the FPGA module to realize real-time encryption and decryption of the data stream.

Benefits of technology

It improves the speed and efficiency of encrypted communication, meets the requirements of the real-time operating system, and realizes stable, efficient and secure encrypted communication of IROS.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118174903B_ABST
    Figure CN118174903B_ABST
Patent Text Reader

Abstract

The present invention discloses a real-time embedded IROS secure encryption communication method based on FPGA, which relates to the field of communication security technology. This method involves an ARM module and an FPGA module. Specifically: An embedded RLinux operating system runs on the ARM module, and the IROS intelligent robot operating system runs in the RLinux operating system, which is divided into a data publisher and a data subscriber. The ARM module is provided with an ARM parallel port write unit and an ARM parallel port read unit based on the data publisher and the data subscriber. The implementation process of this communication method is as follows: When the data publisher of the IROS intelligent robot operating system has data to be encrypted and published, the data is written into the FPGA module through the ARM parallel port write unit. The FPGA module first reads and encrypts the written data, then judges the communication method, discards the data, or decrypts the encrypted data, and then writes it into the ARM parallel port read unit. The ARM parallel port read unit sends the decrypted data to the data subscriber of the IROS intelligent robot operating system. The present invention can improve the encryption communication speed and efficiency and meet the requirements of real-time systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security technologies, and more specifically, to a real-time embedded IROS secure encryption communication method based on FPGA. Background Art

[0002] Robotics is a multi-disciplinary field that typically involves sensors, drivers, multi-robot communication, mechanical structures, algorithms, etc. To conduct robot research and development more efficiently, it is necessary to select a general development framework. ROS (Robot Operating System) is one of the popular frameworks. Simply put, ROS is a distributed communication framework that helps program processes communicate more conveniently.

[0003] Intelligent Robot Operating System, abbreviated as IROS, is an intelligent robot operating system independently developed by Inspur. It has functions similar to ROS, replaces the kernel of the open-source ROS, provides interfaces compatible with ROS, solves problems related to the reliability, performance, and security of ROS, and adds new functions, such as supporting cloud-based robot development, cloud-edge communication, and multi-robot collaboration. IROS also provides a Linux distribution RLinux specifically designed for real-time operation of robots, while ROS mainly relies on Ubuntu Linux for operation.

[0004] RLinux is the abbreviation of Inspur's real-time operating system Real-time Linux. It is a real-time Linux operating system designed based on the open-source Linux system. It supports real-time preemptive scheduling of processes, can achieve fully automated and rapid installation, has a customized graphical operation interface, has a real-time command interpreter, and can implement the function of customizing the priority configuration of processes for operation.

[0005] A real-time operating system, also known as a real-time system, refers to an operating system that can accept and process external events or data at a sufficient speed when they occur, and the processing results can control the production process or respond quickly to the processing system within a specified time. It schedules all available resources to complete real-time tasks and controls all real-time tasks to run in coordination. Providing timely response and high reliability are its main features.

[0006] Traditional robot operating systems generally use pure software programming methods for secure communication based on the x86 architecture or ARM architecture. The speed and efficiency of encrypted communication depend on the performance of the underlying hardware. When applied to embedded architectures such as ARM, using encrypted communication will affect the normal communication speed and the real-time performance is not strong, and it cannot meet the requirements of real-time systems in scenarios with strong real-time requirements. Summary of the Invention

[0007] In view of the requirements and deficiencies in the current technological development, the present invention provides a real-time embedded IROS secure encryption communication method based on FPGA to improve the encryption communication speed and efficiency and meet the requirements of real-time operating systems.

[0008] The technical solution adopted by the real-time embedded IROS secure encryption communication method based on FPGA of the present invention to solve the above technical problems is as follows:

[0009] A real-time embedded IROS secure encryption communication method based on FPGA, which involves two parts: an ARM module and an FPGA module, where:

[0010] The embedded RLinux operating system runs on the ARM module, and the IROS intelligent robot operating system runs in the embedded RLinux operating system, which is divided into a data publisher and a data subscriber. The ARM module is provided with an ARM parallel port write unit and an ARM parallel port read unit based on the data publisher and the data subscriber;

[0011] A control unit, an FPGA write memory, an encryption processing unit, an FPGA read memory, a decryption processing unit, and a communication unit are provided on the FPGA module;

[0012] The implementation process of this communication method is as follows:

[0013] When the data publisher of the IROS intelligent robot operating system has data to be encrypted and published, the data is written into the FPGA write memory through the ARM parallel port write unit. The encryption processing unit reads and encrypts the data in the FPGA write memory under the action of the control unit, and then writes it into the communication unit. The communication unit judges the communication method under the action of the control unit, and then discards the data, or the decryption processing unit decrypts the encrypted data under the action of the control unit and writes it into the FPGA read memory. The ARM parallel port read unit reads the decrypted data from the FPGA read memory and sends it to the data subscriber of the IROS intelligent robot operating system.

[0014] Optionally, the involved ARM module adopts a high-performance ARM embedded system with a kernel above ARM Cortex-A53 and runs the embedded RLinux operating system, and the functions are implemented in a software programming manner based on the embedded RLinux operating system and the IROS intelligent robot operating system inside the ARM module.

[0015] Optionally, the involved FPGA module adopts a high-performance FPGA processing system, and the functions are implemented by digital logic design using Verilog hardware description language inside the FPGA module.

[0016] Optionally, the FPGA write memory and the FPGA read memory set on the involved FPGA module are two RAM memories with different addresses.

[0017] Optionally, when the data publisher of the IROS intelligent robot operating system has data to be encrypted and published, first, the serialized data is sent to the ARM parallel port write unit to add the necessary information of the parallel port communication packet header and length, and then written into the FPGA write memory through the ARM parallel port write unit. During the writing process, different packet data is written into the FPGA write memory in sequence. After the address of the FPGA write memory is full, it starts to overwrite and write from the start address of the write address to ensure the parallel real-time processing of the FPGA.

[0018] Further optionally, when the FPGA module reads that the FPGA write memory is not empty, it starts to read the data until it finishes reading; after reading the FPGA write memory, the data in the FPGA write memory is automatically cleared;

[0019] The FPGA module writes the read binary data into different FIFOs according to different packets for pipelining operation. The encryption processing unit uses the SMS4 national cryptography algorithm and the data stream encryption method to encrypt the data stream, and the encrypted data stream is written into the communication unit.

[0020] Further optionally, when the communication unit determines that the current communication mode is configured for local communication, the communication unit first determines whether there are any discovered additional nodes in the current communication domain.

[0021] If not, the encrypted data is cached for a set time, and then it is determined again whether there are any discovered additional nodes in the current communication domain. If there are still none, the data is discarded;

[0022] If there are, the encrypted data stream is written into the FIFO of the decryption processing unit, and decryption operation is performed in a pipelining operation mode, and then written into the FPGA read memory.

[0023] Further optionally, when the communication unit determines that the current communication mode is configured for network communication, the communication unit first determines whether there are any discovered additional nodes at the remote end in the same communication domain.

[0024] If not, the encrypted data is cached for a set time, and then it is determined again whether there are any discovered additional nodes at the remote end in the same communication domain. If there are still none, the data is discarded;

[0025] If there are, the communication unit controls the network card to send the byte stream through a wired network or a wireless network, and the remote node decrypts it using the key negotiated when discovering the node. The communication unit writes the decrypted data into the FPGA read memory.

[0026] Further optionally, when the involved decryption processing unit writes the decrypted data into the FPGA read memory, it first detects whether the FPGA read memory is non-empty. When it is empty, it writes the data. After writing a packet, the write completion position is set to 1 to notify the ARM parallel port read unit to read the data;

[0027] After the ARM parallel port read unit reads the data from the FPGA read memory, the data in the FPGA read memory and the write completion bit are automatically cleared, waiting for the next read. At the same time, the ARM parallel port read unit deserializes the read data and determines whether there is a subscribed node subscribing to this data. If so, it sends this data to the data subscriber of the IROS intelligent robot operating system.

[0028] Preferably, when the involved encryption processing unit and decryption processing unit encrypt and decrypt the data,

[0029] the real-time stream data is divided into data blocks of a fixed size for SMS4 national cryptographic algorithm encryption and decryption.

[0030] When the length of the last packet for encryption and decryption is less than the block size, the ciphertext stealing technique is used to "steal" the tail data of the previous packet and encrypt and decrypt it together with the last packet, so as to complete the stream encryption and stream decryption of all data streams.

[0031] A real-time embedded IROS secure encryption communication method based on FPGA of the present invention has the beneficial effects compared with the prior art as follows:

[0032] The present invention uses the encryption and decryption algorithms implemented by low-level hardware logic programming on the FPGA platform, which has the characteristics of no software delay, parallel processing, extremely fast running speed, high processing efficiency, and strong security without an operating system. It realizes the real-time and efficient secure encryption and decryption communication of IROS on the ARM embedded platform based on FPGA. The FPGA module is programmed using the Verilog hardware description language, and the ARM module uses its own built-in parallel interface to realize the heterogeneous communication between the FPGA module and the ARM module. At the same time, an embedded data stream real-time encryption and decryption method applicable to FPGA and based on the national cryptographic algorithm is proposed, realizing the stable, efficient and secure encryption communication of IROS while ensuring real-time performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Attached Figure 1 is the functional block diagram involved in Embodiment 1 of the present invention;

[0034] Among them, the solid arrow is the data stream, and the hollow arrow is the control stream. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] To make the technical solution, the technical problems to be solved and the technical effects of the present invention more clearly understood, the following describes the technical solution of the present invention clearly and completely in conjunction with specific embodiments.

[0036] Embodiment 1:

[0037] Combined with the attached Figure 1 , this embodiment proposes a real-time embedded IROS secure encryption communication method based on FPGA. This communication method involves two parts: an ARM module and an FPGA module, where:

[0038] The ARM module uses a high-performance ARM embedded system with a kernel above ARM Cortex-A53 and runs the embedded RLinux operating system. Inside the ARM module, functions are implemented in a software programming manner based on the embedded RLinux operating system and the IROS intelligent robot operating system. The IROS intelligent robot operating system runs in the embedded RLinux operating system and is divided into a data publisher and a data subscriber. The ARM module is provided with an ARM parallel port write unit and an ARM parallel port read unit based on the data publisher and the data subscriber.

[0039] The involved FPGA module uses a high-performance FPGA processing system, and digital logic design is implemented in the FPGA module using Verilog hardware description language to achieve functions. A control unit, an FPGA write memory, an encryption processing unit, an FPGA read memory, a decryption processing unit, and a communication unit are provided on the FPGA module. The FPGA write memory and the FPGA read memory are two RAM memories with different addresses. The control unit sends control signals to the encryption processing unit, the decryption processing unit, and the communication unit.

[0040] The implementation process of the communication method in this embodiment is as follows:

[0041] (1) The data publisher of the IROS intelligent robot operating system encrypts and publishes data. First, the serialized data is sent to the ARM parallel port write unit to add the necessary information of the parallel port communication header and length, and then written into the FPGA write memory through the ARM parallel port write unit. During the writing process, different packet data is written into the FPGA write memory in sequence. After the address of the FPGA write memory is full, it starts to overwrite and write from the first address of the write address to ensure the parallel real-time processing of the FPGA;

[0042] (2) When the FPGA module reads that the FPGA write memory is not empty, it starts to read the data until it finishes reading. After finishing reading the FPGA write memory, the data in the FPGA write memory is automatically cleared. The FPGA module writes the read binary data into different FIFOs according to different packets for pipelining operation. The encryption processing unit reads the data in the FIFO under the action of the control unit and encrypts the data stream using the SMS4 national cryptography algorithm and the data stream encryption method. The encrypted data stream is written into the communication unit.

[0043] (i) When the communication unit determines that the current communication mode is configured for local communication, the communication unit first determines whether there are any discovered additional nodes within the communication domain.

[0044] If not, the encrypted data is cached for a set time, and then it is determined again whether there are any discovered additional nodes within the communication domain. If there are still none, the data is discarded.

[0045] If there are, the encrypted data stream is written into the FIFO of the decryption processing unit, and decryption operation is performed using the pipelining operation method, and then written into the FPGA read memory.

[0046] (ii) When the communication unit determines that the current communication mode is configured for network communication, the communication unit first determines whether there are any discovered additional nodes at the remote end within the same communication domain.

[0047] If not, the encrypted data is cached for a set time, and then it is determined again whether there are any discovered additional nodes at the remote end within the same communication domain. If there are still none, the data is discarded.

[0048] If there are, the communication unit controls the network card to send the byte stream through a wired network or a wireless network. The remote node decrypts it using the key negotiated when discovering the node, and the communication unit writes the decrypted data into the FPGA read memory.

[0049] (3) When the decryption processing unit writes the decrypted data into the FPGA read memory, it first detects whether the FPGA read memory is non-empty. When it is empty, it writes. After writing a packet, the write completion position is set to 1 to notify the ARM parallel port read unit to read the data.

[0050] After the ARM parallel port read unit finishes reading the data from the FPGA read memory, the data and the write completion bit in the FPGA read memory are automatically cleared and wait for the next read. At the same time, the ARM parallel port read unit deserializes the read data and determines whether there is a subscribed node subscribing to this data. If there is, this data is sent to the data subscriber of the IROS intelligent robot operating system.

[0051] In the above steps, when the encryption processing unit and the decryption processing unit encrypt and decrypt the data,

[0052] Divide the real-time stream data into data blocks of a fixed size for SMS4 national cryptography algorithm encryption and decryption.

[0053] When the length of the last packet for encryption and decryption is less than the block size, use the ciphertext stealing technique to "steal" the tail data of the previous packet and encrypt and decrypt it together with the last packet, so as to complete the stream encryption and stream decryption of all data streams.

[0054] It should be added that the additional nodes described in this embodiment refer to nodes other than the data publishing nodes.

[0055] In summary, by using a real-time embedded IROS security encryption communication method based on FPGA of the present invention, the encryption communication speed and efficiency can be improved, and the requirements of the real-time operating system can be met.

[0056] The above applications use specific examples to elaborate in detail on the principle and implementation manner of the present invention. These embodiments are only used to help understand the core technical content of the present invention. Based on the above specific embodiments of the present invention, those skilled in the art of this technology, without departing from the principle of the present invention, any improvements and modifications made to the present invention shall fall within the patent protection scope of the present invention.

Claims

1. A real-time embedded IROS secure encryption communication method based on FPGA, characterized in that: The communication method involves two parts: ARM module and FPGA module, among which: The embedded RLinux operating system runs on the ARM module, and the IROS intelligent robot operating system runs in the embedded RLinux operating system, which is divided into data publishers and data subscribers. The ARM module is equipped with an ARM parallel port write unit and an ARM parallel port read unit based on the data publisher and the data subscriber; The FPGA module is provided with a control unit, an FPGA write memory, an encryption processing unit, an FPGA read memory, a decryption processing unit, and a communication unit; The implementation process of this communication method is as follows: When the IROS intelligent robot operating system data publisher has data to be encrypted and published, the data is written into the FPGA write memory through the ARM parallel port write unit. The encryption processing unit reads and encrypts the data in the FPGA write memory under the action of the control unit, and then writes it into the communication unit. The communication unit determines the communication mode under the action of the control unit and discards the data or the decryption processing unit decrypts the encrypted data under the action of the control unit and writes it into the FPGA read memory. The ARM parallel port read unit reads the decrypted data from the FPGA read memory and sends it to the IROS intelligent robot operating system data subscriber.

2. According to claim 1, a real-time embedded IROS secure encryption communication method based on FPGA is characterized in that: The ARM module adopts a high-performance ARM embedded system with an ARM Cortex-A53 core and runs an embedded RLinux operating system. Software programming is used inside the ARM module to implement functions based on the embedded RLinux operating system and the IROS intelligent robot operating system.

3. A real-time embedded IROS secure encryption communication method based on FPGA according to claim 1 or 2, characterized in that: The FPGA module uses a high-performance FPGA processing system, and Verilog hardware description language is used inside the FPGA module to perform digital logic design and implement functions.

4. The real-time embedded IROS secure encryption communication method based on FPGA according to claim 1, characterized in that: The FPGA write memory and FPGA read memory set on the FPGA module are two RAM memories with different addresses.

5. The real-time embedded IROS secure encryption communication method based on FPGA according to claim 1, characterized in that: When the data publisher of the IROS intelligent robot operating system has data to be encrypted and published, the serialized data is first sent to the ARM parallel port write unit to add the necessary information of the parallel port communication packet header and length, and then written to the FPGA write memory through the ARM parallel port write unit. During the writing process, different package data are written to the FPGA write memory in sequence. When the address of the FPGA write memory is full, it is overwritten from the first address of the write address to ensure parallel real-time processing of the FPGA.

6. A real-time embedded IROS secure encryption communication method based on FPGA according to claim 5, characterized in that: When the FPGA module finds that the FPGA write memory is not empty, it starts to read data until the reading is completed; after reading the FPGA write memory, the data in the FPGA write memory is automatically cleared; The FPGA module writes the read binary data into different FIFOs according to different packages and performs pipeline operations. The encryption processing unit uses the SMS4 national encryption algorithm and data stream encryption method to encrypt the data stream, and the encrypted data stream is written into the communication unit.

7. A real-time embedded IROS secure encryption communication method based on FPGA according to claim 6, characterized in that: When the communication unit determines that the current communication mode is configured as local communication, the communication unit first determines whether there are any additional nodes discovered in the communication domain. If not, the encrypted data is cached for a set time, and then it is determined again whether there are any additional nodes discovered in the communication domain. If there are still no additional nodes, the data is discarded; If yes, the encrypted data stream is written into the FIFO of the decryption processing unit, the decryption operation is performed in a pipeline operation mode, and then written into the FPGA read memory.

8. The real-time embedded IROS secure encryption communication method based on FPGA according to claim 6, characterized in that: When the communication unit determines that the current communication mode is configured as network communication, the communication unit first determines whether there are any additional nodes discovered at the remote end in the same communication domain. If not, the encrypted data is cached for a set time, and then it is determined again whether there are any additional nodes discovered at the remote end in the same communication domain. If there are still no additional nodes, the data is discarded; If yes, the communication unit controls the network card to send the byte stream through the wired network or wireless network, and the remote node decrypts it using the key negotiated when discovering the node. The communication unit writes the decrypted data into the FPGA read memory.

9. A real-time embedded IROS secure encryption communication method based on FPGA according to claim 7 or 8, characterized in that: When the decryption processing unit writes the decrypted data into the FPGA read memory, it first checks whether the FPGA read memory is not empty. If it is empty, it writes the data. After writing a packet, the write completion position is set to 1, notifying the ARM parallel port read unit to read the data. After the ARM parallel port read unit finishes reading data from the FPGA read memory, the data and write completion bit of the FPGA read memory are automatically cleared and wait for the next read. At the same time, the ARM parallel port read unit deserializes the read data and determines whether there is a subscription node that subscribes to the data. If so, the data is sent to the IROS intelligent robot operating system data subscriber.

10. A real-time embedded IROS secure encryption communication method based on FPGA according to claim 9, characterized in that: When the encryption processing unit and the decryption processing unit encrypt and decrypt data, Divide the real-time streaming data into fixed-size data blocks for encryption and decryption using the SMS4 national encryption algorithm. When the length of the last encrypted and decrypted packet is less than the block size, the ciphertext stealing technology is used to obtain the tail data of the previous packet, and encrypt and decrypt it together with the last packet, thereby completing the stream encryption and decryption of the entire data stream.

Citation Information

Patent Citations

  • Data processing method, control system and equipment

    CN113568333A

  • Embedded communication system, method and device based on FPGA and ROS, medium and vehicle

    CN115733886A