Module with cryptographic operation and isolation exchange functions, design method and system

By using a multi-core processor and Ethernet optical module in the module, combined with a ring-linked list design, synchronous execution of password operations and network isolation exchange is achieved, solving the problem of limited data transmission rate in the prior art, and achieving high-performance data processing.

CN119995889APending Publication Date: 2025-05-13CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411950886.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the prior art, network isolation switching cards and PCI password cards are usually two independent modules, which cannot efficiently realize the simultaneous network isolation switching and password computing, and the data transmission rate is limited by the PCIe x1 interface, which cannot meet high performance needs.

Method used

Using a chip with a multi-core processor and a communication interface, combined with an Ethernet optical module, a module is designed, which includes a password operation processor and an isolated exchange processor, and synchronously performs password operation and isolated exchange functions through a ring-linked list.

Benefits of technology

It realizes high-performance synchronous execution of password operations and network isolation exchange, improves data transmission rate, and meets the rate requirements of high-end isolation gateways for password operations and network isolation exchange functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995889A_ABST
    Figure CN119995889A_ABST
Patent Text Reader

Abstract

The invention discloses a module with cryptographic operation and isolation exchange functions, a design method and a system. The module at least comprises a chip with a multi-core processor and a communication interface, and an Ethernet optical module, the multi-core processor comprises a password operation processor used for calculating to-be-encrypted data by using a security engine to obtain a calculation result when a memory address of a first annular linked list in a chip receives the to-be-encrypted data sent by a host connected through a communication interface, and transmitting the calculation result to the memory address of the first annular linked list, the calculation result is transmitted to the host; and the isolation exchange processor is used for transmitting to-be-exchanged data to an external module connected through the Ethernet optical module when the memory address of the second annular linked list in the chip receives the to-be-exchanged data sent by the host, so that the external module continues to transmit the to-be-exchanged data. According to the invention, high-performance synchronous cryptographic operation execution and isolation exchange functions can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computers, and in particular to a module with cryptographic operation and isolation exchange functions, a design method and a system. Background Art

[0002] At present, in the field of information security in the power industry, the application of domestic products is becoming more and more widespread; among them, network isolation switching cards and high-performance cryptographic operation modules based on the high-speed serial computer expansion bus standard (Peripheral Component Interconnect express, PCIe), namely PCI cryptographic cards, are two important components. Common network isolation switching cards and PCI cryptographic cards are usually two independent modules, and modules with both network isolation switching functions and cryptographic operation functions are relatively rare.

[0003] In the related technologies, a large number of chips with different functions are used for connection and combination to realize network isolation switching functions and cryptographic operations at the same time. However, the flow of data between different chips is limited by interface performance and encoding, and the interface connected to the computer is a PCIe x1 interface, and its theoretical data effective transmission rate is 4Gbps, that is, the communication speed corresponding to the interface is slow; thus, it is impossible to isolate the gateway with high performance, and it is impossible to meet the rate requirements for cryptographic operations and network isolation switching functions. Summary of the invention

[0004] In order to solve the problems of the prior art, the present invention proposes a module with cryptographic operation and isolation exchange functions, a design method and a system, aiming to achieve high-performance synchronous execution of cryptographic operation and isolation exchange functions.

[0005] The purpose of the present invention is achieved by adopting the following technical solutions:

[0006] On the one hand, the present invention provides a module with cryptographic operation and isolation switching functions, the module at least comprising: a chip with a multi-core processor and a communication interface, and an Ethernet optical module; the multi-core processor comprises: a cryptographic operation processor and an isolation switching processor; wherein:

[0007] The cryptographic operation processor is used to, when the memory address of the first circular linked list in the chip receives the data to be encrypted sent by the host connected through the communication interface, use the security engine to calculate the data to be encrypted, obtain a calculation result, and transmit the calculation result to the memory address of the first circular linked list, so as to transmit the calculation result to the host;

[0008] The isolated exchange processor is used to transmit the data to be exchanged to the external module connected through the Ethernet optical module when the memory address of the second circular linked list in the chip receives the data to be exchanged sent by the host, so that the external module continues to transmit the data to be exchanged.

[0009] Optionally, the cryptographic operation processor is further used to transmit the calculation result written in the memory address of the first circular linked list to the memory address of the third circular linked list in the host, so that the main processor of the host reads and sends the calculation result in the memory address of the third circular linked list to the first application in the host;

[0010] Among them, the data to be encrypted is data transmitted from the memory address of the third circular linked list to the memory address in the first circular linked list; the memory address of the third circular linked list is the address where the first application encapsulates the data to be encrypted when calling the application programming interface related to the cryptographic service.

[0011] Optionally, the isolated exchange processor is further used to transmit the data to be exchanged to the external module, so that the external chip with a multi-core processor in the external module continues to transmit the data to be exchanged using the circular linked list in the external chip;

[0012] Among them, the data to be exchanged is data transmitted from the memory address in the fourth circular linked list in the host to the memory address of the second circular linked list; the memory address in the fourth circular linked list is the address where the second application in the host encapsulates the data to be exchanged when calling the application programming interface related to isolation exchange.

[0013] Optionally, the isolated exchange processor is further used to, when receiving the data to be received in the memory address of the second circular linked list, transmit the data to be received to the memory address of the fourth circular linked list, so that the host reads the data to be received from the memory address of the fourth circular linked list;

[0014] The data to be received is data transmitted to the memory address of the second circular linked list through the memory address of the circular linked list in the external chip.

[0015] Optionally, the communication interface is a high-speed serial computer expansion bus standard interface.

[0016] Optionally, the chip and the host perform data transmission via the high-speed serial computer expansion bus standard interface using a data transmission method with a direct memory access function;

[0017] The chip and the external module perform data transmission via the Ethernet optical module using the data transmission method.

[0018] Optionally, the module further includes:

[0019] A noise source chip, a memory and a multimedia card are respectively connected to the chip.

[0020] On the other hand, the present invention also provides a method for designing a module having cryptographic operation and isolation exchange functions, the method comprising:

[0021] The chip with a multi-core processor is connected to a noise source chip, a memory, a multimedia card, and an Ethernet optical module through a physical interface to obtain an initial hardware architecture; wherein the multi-core processor includes: a cryptographic operation processor for performing cryptographic operations and an isolation switching processor for performing isolation switching;

[0022] Configuring the communication interface and the network interface of the chip in the initial hardware architecture, and initializing the noise source chip, the memory, the multimedia card, the Ethernet optical module, and the storage resources of the chip;

[0023] Applying for a first circular linked list and a second circular linked list corresponding to the memory area in the firmware program of the chip to obtain a module with cryptographic operation and isolation exchange functions;

[0024] Among them, the first circular linked list is a linked list corresponding to the memory area used for cryptographic operations, and the second circular linked list is a linked list corresponding to the memory area used for isolated exchange.

[0025] Correspondingly, the present invention also provides a design system for a module having cryptographic operation and isolation exchange functions, the system comprising:

[0026] A hardware connection module is used to connect the chip with a multi-core processor with a noise source chip, a memory, a multimedia card, and an Ethernet optical module through a physical interface to obtain an initial hardware architecture; wherein the multi-core processor includes: a cryptographic operation processor for performing cryptographic operations and an isolation switching processor for performing isolation switching;

[0027] An initialization module, configured to configure the communication interface and the network interface of the chip in the initial hardware architecture, and to initialize the noise source chip, the memory, the multimedia card, the Ethernet optical module, and the storage resources of the chip;

[0028] An application module, used for applying for a first circular linked list and a second circular linked list corresponding to a memory area in a firmware program of the chip, to obtain a module having cryptographic operation and isolation exchange functions;

[0029] Among them, the first circular linked list is a linked list corresponding to the memory area used for cryptographic operations, and the second circular linked list is a linked list corresponding to the memory area used for isolated exchange.

[0030] On the other hand, the present invention also provides an operating system with cryptographic operation and isolation switching functions, the system comprising at least: two modules with cryptographic operation and isolation switching functions as described above; the two modules are communicatively connected via the Ethernet optical module; one of the two modules communicates with an external first host via the communication interface of the internal chip, and the other module communicates with an external second host via the communication interface of the internal chip.

[0031] In another aspect, the present invention further provides an electronic device, comprising: at least one processor and a memory; the memory and the processor are connected via a bus;

[0032] The memory is used to store one or more programs;

[0033] When the one or more programs are executed by the at least one processor, the method for designing a module with cryptographic operation and isolation exchange functions as described above is implemented.

[0034] On the other hand, the present invention also provides a readable storage medium having an execution program stored thereon, and when the execution program is executed, the design method of a module with cryptographic operation and isolation exchange functions as described above is implemented.

[0035] Compared with the prior art, the present invention has the following beneficial effects:

[0036] The present invention provides a module, design method and system with cryptographic operation and isolation exchange functions, which builds a hardware architecture capable of synchronously executing cryptographic operation and isolation exchange functions based on a chip with a dual-core processor, and synchronously implements cryptographic operation and isolation exchange functions based on a circular linked list inside the chip. In this way, a chip with a dual-core processor can be used to simplify the hardware design to reduce product costs, and high-performance synchronous execution of cryptographic operations and network isolation exchange can be achieved.

[0037] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and are not intended to limit the technical solutions provided by the embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work, among which:

[0039] Figure 1 A schematic diagram of the composition of a module with cryptographic operation and isolation exchange functions provided by an embodiment of the present invention;

[0040] Figure 2 A schematic flow chart of a design method for a module with cryptographic operation and isolation exchange functions provided by an embodiment of the present invention;

[0041] Figure 3 A schematic diagram of the composition of a design system for a module with cryptographic operation and isolation exchange functions provided by an embodiment of the present invention;

[0042] Figure 4 A schematic diagram of the composition of an operating system with cryptographic operation and isolated exchange functions provided by an embodiment of the present invention;

[0043] Figure 5 A schematic diagram of a data exchange memory model constructed by a circular linked list between a host and a module provided by an embodiment of the present invention;

[0044] Figure 6 A schematic diagram of a hardware framework design corresponding to an operating system with cryptographic operation and isolated exchange functions provided by an embodiment of the present invention;

[0045] Figure 7 A schematic diagram of the composition of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0046] The following will describe the embodiments of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention, not for limiting the scope of protection of the present invention.

[0047] In the following description, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0048] In the following description, the terms "first\second\third" involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein.

[0049] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the technical field of the embodiments of the present invention. The terms used herein are only for the purpose of describing the embodiments of the present invention and are not intended to limit the embodiments of the present invention.

[0050] At present, in the field of information security in the power industry, the application of domestic products is becoming more and more widespread; among them, common network isolation cards and PCI cryptographic cards are usually two independent modules, and modules with both network isolation exchange function and cryptographic operation function are relatively rare, such as: "A Network Isolation Cryptographic Board Card" invented by China Southern Power Grid Research Institute Co., Ltd. and "A PCI-E-based Isolation Encryption Card" invented by Zhengzhou Xinda Huaxin Information Technology Co., Ltd. Although these two inventions can realize network isolation exchange and cryptographic operation at the same time, they both use a large number of chips with different functions for connection and combination. In this way, there will be data flow between different chips, which is easily limited by interface performance and encoding, and the interface connected to the computer is a PCIe x1 interface, which has slow communication speed, cannot isolate the gateway with high performance, and cannot meet the rate requirements for cryptographic operation and network isolation exchange functions.

[0051] Based on the above problems, the present invention proposes a module, design method and system with cryptographic operation and isolation exchange functions, which builds a hardware architecture capable of synchronously executing cryptographic operation and isolation exchange functions based on a chip with a dual-core processor, and synchronously implements cryptographic operation and isolation exchange functions based on a circular linked list inside the chip. In this way, a chip with a dual-core processor can be used to simplify the hardware design to reduce product costs, and achieve high-performance synchronous execution of cryptographic operations and network isolation exchange.

[0052] Embodiment 1:

[0053] The present invention provides a module with cryptographic operation and isolation exchange functions, such as Figure 1 As shown, it is a schematic diagram of the composition of a module with cryptographic operation and isolation switching functions provided by an embodiment of the present invention, wherein the module 100 at least includes: a chip 101 with a multi-core processor and a communication interface 1013, and an Ethernet optical module 102; the multi-core processor includes: a cryptographic operation processor 1011 and an isolation switching processor 1012; wherein:

[0054] The cryptographic operation processor 1011 is used to calculate the encrypted data using the security engine when the memory address of the first circular linked list in the chip 101 receives the encrypted data sent by the host 200 connected through the communication interface 1013, and obtain the calculation result, and transmit the calculation result to the memory address of the first circular linked list, so as to transmit the calculation result to the host 200;

[0055] The isolated exchange processor 1012 is used to transmit the data to be exchanged to the external module 300 connected through the Ethernet optical module 102 when the memory address of the second circular linked list in the chip 101 receives the data to be exchanged sent by the host 200, so that the external module 300 continues to transmit the data to be exchanged.

[0056] In some embodiments of the present invention, the chip 101 may be a National Core CCP1080T high-performance secure edge computing chip (National Core CCP1080T), so that the module designed by the present invention is a module with cryptographic operations and isolated exchange functions designed based on the National Core CCP1080T high-performance secure edge computing chip; wherein, the chip 101 may be a system-on-chip (SoC), that is, a SoC design, and the chip 101 may have built-in dual-core C9800 general processing, hardware accelerated security engine (for providing cryptographic operations), PCIe3.0, 10 Gigabit network port controller, storage controller, etc. At the same time, the hardware accelerated security engines SM1, SM3, and SM4 in the chip 101 have an operation performance of 20 Gbps, and the SM2 operation signature performance reaches 8 times / second; wherein, SM1, SM2, SM3, and SM4 are national secret encryption algorithms, that is, a series of domestic commercial cryptographic standard algorithms issued by the State Cryptography Administration.

[0057] In some embodiments of the present invention, chip 101 is a chip with a multi-core processor; wherein the multi-core processor may be: a dual-core processor, a triple-core processor, etc.; in the following embodiments of the present invention, the multi-core processor is a dual-core processor, and includes: a cryptographic operation processor 1011 and an isolation switching processor 1012 as an example for the following description.

[0058] In some embodiments of the present invention, the communication interface 1013 is a high-speed serial computer expansion bus standard interface.

[0059] In some embodiments of the present invention, the communication interface 1013 in the chip 101 is a high-speed serial computer expansion bus standard interface, namely PCIe. Further, the communication interface 1013, namely the PCIe interface of the chip 101, can be configured as PCIe3.0x4 EP mode, which has a theoretical data transmission rate of 15.3 Gbps and can be used to connect a high-end isolation gateway.

[0060] In this way, within the module 100, through the high-speed serial computer expansion bus standard interface in the chip 101 and the Ethernet optical module 102 connected to the chip 101, hardware support can be provided for the high-speed data transmission when the module 100 performs cryptographic operations and isolated switching functions simultaneously in the subsequent process.

[0061] In some embodiments of the present invention, the Ethernet optical module 102 can be supplemented with a 10Gbps Ethernet optical module, that is, a 10G optical module, which can support hot plugging, is small in size, has a long transmission distance, and is cost-effective. Here, the module 100 can be connected to the external module 300 through the Ethernet optical module 102, and the external module 300 can be: another module with cryptographic operation and isolation switching functions that interacts with the module 100 for data.

[0062] In some embodiments of the present invention, the host 200 may be a host or a central processing unit (CPU) in a server where the module 100 is located. The host 200 exchanges data with the module 100 (chip 101) through the communication interface 1013 of the chip 101.

[0063] Correspondingly, the external module 300 can be another module with the same hardware framework and software configuration as the module 100. Here, the external module 300 can also exchange data with another host by means of the communication interface of its internal chip; thus, the data exchange between the host 200 and another host can be further realized by means of the two modules (module 100, external module 300), that is, the isolated exchange of data between the host 200 and another host can be realized.

[0064] It should be noted that in the following other embodiments of the present invention, another host is connected via an external module 300, and the server where the other host is located is different from the server where the host 200 is located, that is, the network between the two is isolated, so that with the help of the module 100 and the external module 300, network-isolated data exchange between the host 200 and another host can be achieved; illustratively, the host 200 connected to the module 100 through the communication interface 1013 of the chip 101 inside it is an external network host, and the other host connected to the external module 300, also with the help of the communication interface of the chip inside the external module 300, is an internal network host.

[0065] In some embodiments of the present invention, the module 100 may further include: a noise source chip, a memory, and a multimedia card respectively connected to the chip 101 .

[0066] In some embodiments of the present invention, the noise source chip may be a physical noise source chip, which is a circuit element that can generate random signals using naturally occurring physical noises such as thermal noise and metastable noise. Such random signals are widely used in the fields of communication, encryption, testing, measurement, control, etc., and are called true random number sources.

[0067] Correspondingly, the memory may be a fourth generation double data rate (DDR) memory, namely, DDR4 memory; and the multimedia card may be an embedded multimedia card of an embedded memory standard specification (embedded Multi Media Card, eMMC).

[0068] It should be noted that the chip 101 inside the module 100 can be connected in sequence to: Ethernet optical module 102, noise source chip, memory and multimedia card through different internal communication interfaces (physical interfaces); at the same time, it can be connected to the external host 200 through the communication interface 1013 inside the chip 101.

[0069] In this way, by constructing the hardware architecture of module 100 (connecting the noise source chip, memory and multimedia card through chip 101 internally), the basic hardware connection inside module 100 is realized, and further support is provided for the operation of subsequent modules 100 (synchronous execution of cryptographic operations and isolated exchange functions).

[0070] In some embodiments of the present invention, the cryptographic operation processor 1011 is used to utilize the security engine, that is, the internal hardware acceleration security engine to perform calculations (or cryptographic operations) on the encrypted data when the memory address of the first circular linked list in the chip 101 receives the data to be encrypted sent by the host 200 connected through the communication interface 1013, obtain the calculation results, and transmit the calculation results to the memory address of the first circular linked list, so that the chip 101 can subsequently transmit the calculation results to the host 200 through the communication interface 1013.

[0071] Correspondingly, the isolated switching processor 1012 is used to transmit the data to be exchanged to the external module 300 connected through the Ethernet optical module 102 when the memory address of the second circular linked list in the chip 101 receives the data to be exchanged sent by the host 200, so that the relevant chip in the external module 300 continues to transmit the data to be exchanged.

[0072] In some embodiments of the present invention, the cryptographic operation processor 1011 and the isolation exchange processor 1012 can work (run) simultaneously; that is, the module 100 can synchronously implement the cryptographic operation and isolation exchange functions with the help of the chip 101.

[0073] It should be noted that before the cryptographic operation processor 1011 and the isolated exchange processor 1012 perform corresponding operations, the present invention needs to construct a circular linked list corresponding to the storage area for performing cryptographic operations in the firmware program of the chip 101, that is, a first circular linked list, and construct a circular linked list corresponding to the storage area for performing isolated exchange (data isolated exchange), that is, a second circular linked list; correspondingly, the cryptographic operation processor 1011 can respond to the writing of data at the relevant memory address in the first circular linked list, and perform corresponding cryptographic operations and transmission of data related to the cryptographic operations; the isolated exchange processor 1012 can respond to the writing of data at the relevant memory address in the second circular linked list, and perform isolated exchange of related data.

[0074] It should be noted that each linked list unit in the first circular linked list and the second circular linked list respectively stores: the virtual address and physical address of the firmware (ie chip 101) write memory block, the virtual address and physical address of the memory block read, and other data and task-related attributes.

[0075] In some embodiments of the present invention, the chip 101 and the host 200 perform data transmission via the high-speed serial computer expansion bus standard interface using a data transmission method with a direct memory access function;

[0076] The chip 101 and the external module 300 perform data transmission via the Ethernet module 102 using the data transmission method.

[0077] In some embodiments of the present invention, the data transmission method with direct memory access function can be direct memory access (DMA); correspondingly, the chip 101 inside the module 100 and the host 200 perform data transmission via PCIe DMA, and the chip 101 and the external module 300 perform data transmission via DMA by calling the 10 Gigabit network card, i.e., the Ethernet optical module 102.

[0078] In this way, the module 100 uses the internal communication interface 1013 or the Ethernet optical module 102 and adopts a data transmission method with direct memory access function to transmit data with the host 200 and the external module 300 respectively, which can improve the data transmission rate.

[0079] Continue to refer Figure 1As shown, in some embodiments of the present invention, the cryptographic operation processor 1011 is also used to transmit the calculation result written in the memory address of the first circular linked list to the memory address of the third circular linked list in the host 200, so that the main processor of the host 200 reads and sends the calculation result in the memory address of the third circular linked list to the first application in the host 200.

[0080] Among them, the data to be encrypted is data transmitted from the read memory address of the third circular linked list to the memory address in the first circular linked list; the read memory address of the third circular linked list is the address where the first application encapsulates the data to be encrypted when calling the application programming interface related to the cryptographic service.

[0081] In some embodiments of the present invention, before performing the corresponding cryptographic operation with the help of the cryptographic operation processor 1011, not only a circular linked list corresponding to the storage area for performing cryptographic operations is constructed in the firmware program of the chip 101, that is, a first circular linked list, but also a circular linked list corresponding to the storage area for performing cryptographic operations, that is, a third circular linked list, can be constructed in the driver of the host 200; so that when the first application in the host 200 calls the application programming interface (Application Programming Interface, API) related to the cryptographic service, the first application selects a memory address from the memory block (such as: write memory block) of the third circular linked list in the host 200, encapsulates the encrypted data, and enables the host 200 to transfer the encrypted data encapsulated in the memory address of the third circular linked list to the memory address of the first circular linked list through PCIe DMA; correspondingly, the cryptographic operation processor 1011 is used to calculate the encrypted data using the security engine when receiving the encrypted data in the memory address of the first circular linked list, obtain the calculation result, and write the obtained calculation result into the memory address of the first circular linked list. Here, the data to be encrypted and the calculation results can be stored in the memory addresses corresponding to the write memory block and the read memory block of the first circular linked list respectively; finally, the cryptographic operation processor 1011 also transfers the calculation results written in the memory address of the first circular linked list to the memory address of the third circular linked list in the host 200 through PCIe DMA, so that the main processor of the host 200 can read the calculation results and send them to the first application.

[0082] It should be noted that each linked list unit in the third circular linked list stores: the virtual address and physical address of the host 200 writing the memory block, the virtual address and physical address of the memory block reading, and other data and task-related attributes.

[0083] In some embodiments of the present invention, the data to be encrypted may include: a task to be encrypted and its corresponding encryption parameters, and the first application is an application in the host 200 that needs to perform related encryption.

[0084] It should be noted that the data to be encrypted and / or the calculation results can be written into the memory address of the first circular linked list in a preset order, and the data to be encrypted and / or the calculation results can be written into the memory address of the third circular linked list. The preset order here can be determined according to actual needs or according to the properties of the circular linked list, and the present invention does not impose any limitation on this.

[0085] Referring to the above description, the steps of executing the cryptographic operation by the module 100 may be as follows:

[0086] (1) The first application in the host 200 calls an API related to the cryptographic service. The first application takes out an element, namely, a memory address 1, from the third circular linked list in the memory area used for encryption operation in the host 200 according to the preset order in the circular linked list in the memory of the host 200, and encapsulates the data to be encrypted involved by the first application, namely, the cryptographic task, in the memory address 1; and then adds the memory address 1 to the PCIe DMA transfer linked list.

[0087] (2) The PCIe DMA transfer linked list will move the data in memory address 1 (data to be encrypted) from memory address 1 of the host 200 to chip 101 of module 100, such as memory address 2 of National Core CCP1080T (i.e., memory address 2 of the first circular linked list), and notify chip 101 (processor 1 of National Core CCP1080T). Here, processor 1 of National Core CCP1080T is assumed to be cryptographic processor 1011 of chip 101.

[0088] (3) Processor 1 of National Core CCP1080T, i.e., cryptographic processor 1011 of chip 101, calls the hardware accelerated security engine DMA to transfer the data to be encrypted to the security engine for calculation, and transmits the calculation result to memory address 3 of the first circular linked list.

[0089] (4) The cryptographic operation processor 1011 of the chip 101 uses PCIeDMA to move the calculation result to the memory specified by the host 200 according to the memory address 3 in the first circular linked list, such as the memory address 4 in the third circular linked list, and notifies the main processor of the host 200.

[0090] (5) The main processor of the host 200 reads the calculation result and sends it to the first application, thereby completing the cryptographic operation processing on the encrypted data.

[0091] It should be noted that the cryptographic operation task performed by the cryptographic operation processor 1011 of the chip 101 inside the module 100 is a synchronous task; therefore, the data corresponding to the cryptographic operation (task, i.e., the encrypted data mentioned above) will be encapsulated in the write memory of the circular linked list corresponding to the memory address in the host 200, and then the source address of the PCIe DMA is configured as the physical address of the write memory of the host 200, and the destination address is the chip 101, such as: the physical address of the read memory of the circular linked list corresponding to the memory address in the Guoxin CCP1080T. Correspondingly, after the cryptographic operation processor 1011 of the Guoxin CCP1080T calls the hardware acceleration security engine to calculate the data to be encrypted, the calculated data, i.e., the calculation result, is placed in the write memory physical address of the circular linked list corresponding to the memory address in the Guoxin CCP1080T, and the source address of the PCIe DMA is configured as the physical address of the write memory of the CCP1080T, and the destination address is the physical address of the read memory of the host 200 corresponding to the linked list element.

[0092] In some embodiments of the present invention, module 100 uses the data exchange memory model constructed by the third circular linked list of the host 200 and the first circular linked list of the chip 101 in turn to perform transmission and cryptographic operations on the data to be encrypted, so as to complete the cryptographic operations of the first application in the host 200 on the data to be encrypted.

[0093] In this way, the module 100 uses the cryptographic operation processor 1011 of the chip 101 to perform cryptographic operations on the relevant data in the external host 200, which can not only save the computing resources of the host 200, but also transmit and perform cryptographic operations on the data to be encrypted in the host 200 and the module 100 based on the data exchange memory model constructed by the first circular linked list and the third circular linked list to complete the cryptographic operations on the relevant data. In this way, based on the simplified hardware design of the module 100 (integrated cryptographic operations and isolated exchange functions) to reduce product costs, the cryptographic operations and network isolated exchange functions are executed synchronously to improve the high-performance operation of data.

[0094] In some embodiments of the present invention, the isolated exchange processor 1012 is also used to transmit the data to be exchanged to the external module 300, so that the external chip with a multi-core processor in the external module 300 continues to transmit the data to be exchanged using the circular linked list in the external chip.

[0095] Among them, the data to be exchanged is data transmitted from the memory address in the fourth circular linked list in the host 200 to the memory address in the second circular linked list; the memory address in the fourth circular linked list is the address where the second application in the host 200 encapsulates the data to be exchanged when calling the application programming interface related to isolation exchange.

[0096] In some embodiments of the present invention, before executing the corresponding isolation exchange with the help of the isolation exchange processor 1012, not only a circular linked list corresponding to the storage area for isolation exchange is constructed in the firmware program of the chip 101, that is, the second circular linked list, but also a circular linked list corresponding to the storage area for isolation exchange can be constructed in the driver of the host 200, that is, the fourth circular linked list; so that when the second application in the host 200 calls the API related to isolation exchange, the second application selects a memory address from the memory block (such as: write memory block) of the fourth circular linked list in the host 200, encapsulates the data to be exchanged, and enables the host 200 to access the storage area through PCIe DMA transfers the data to be exchanged encapsulated in the memory address of the fourth ring-linked list to the memory address of the second ring-linked list; then, the isolation exchange processor 1012 is also used to transfer the data to be exchanged to the memory address of the ring-linked list of the external chip in the external module 300 through the 10 Gigabit network card DMA when the data to be exchanged is received in the memory address of the second ring-linked list, so that the external chip in the external module 300 can transmit the data to be exchanged to another host connected to the external module card 300.

[0097] It should be noted that each linked list unit in the fourth circular linked list stores: the virtual address and physical address of the host 200 writing the memory block, the virtual address and physical address of the memory block reading, and other data and task-related attributes.

[0098] In some embodiments of the present invention, the data to be exchanged may be any data, and the present invention does not impose any limitation on this. Meanwhile, the second application is an application in the host 200 that needs to perform the isolation exchange of related data. Here, the first application is different from the second application.

[0099] It should be noted that the data to be exchanged can be written into the memory address of the second circular linked list or the memory address of the fourth circular linked list in a preset order. The preset order here can be determined according to actual needs or according to the properties of the circular linked list, and the present invention does not impose any limitation on this.

[0100] In some embodiments of the present invention, module 100 constructs a data exchange memory model using the fourth circular linked list of host 200, the second circular linked list of chip 101, and the circular linked list in an external chip with a multi-core processor in external module 300 to transmit the data to be exchanged, so as to complete the isolated exchange of the data to be exchanged.

[0101] In this way, the module 100 uses the isolation exchange processor 1012 of the chip 101 to perform the isolation exchange of relevant data in the external host 200, which can not only save the computing resources in the host 200, but also can transmit the data to be exchanged in the host 200→module 100→external module 300 (→host connected to the external module 300) based on the data exchange memory model constructed by the second circular linked list, the fourth circular linked list, and the circular linked list in the external chip with a multi-core processor in the external module 300, so as to complete the network isolation exchange of the data to be exchanged in different hosts. In this way, on the basis of simplifying the hardware design (integrating cryptographic operations and isolation exchange functions) based on the module 100 to reduce product costs, the cryptographic operations and isolation exchange functions are implemented synchronously to improve the high-performance operation of data.

[0102] Correspondingly, the isolation exchange processor 1012 is further configured to, when receiving the data to be received in the memory address of the second circular linked list, transmit the data to be received to the memory address of the fourth circular linked list, so that the host 200 reads the data to be received from the memory address of the fourth circular linked list;

[0103] The data to be received is data transmitted to the memory address of the second circular linked list through the memory address of the circular linked list in the external chip.

[0104] In some embodiments of the present invention, first, when the isolation exchange processor 1012 receives the data to be received from the memory address of the circular linked list of the external chip in the external module 300 and is transmitted to the memory address of the second circular linked list of the chip 101, the data to be received stored in the memory address of the second circular linked list can be further transmitted to the memory address of the fourth circular linked list of the host 200, so that the host 200 reads the data to be received from the memory address of the fourth circular linked list, that is, the isolation exchange of the data to be received from the external module 300 to the host 200 through the module 100 is completed. Here, the data to be received can be data initiated by another host connected to the external module 300 for isolation exchange. The other host connected to the external module 300 can be in different servers from the host 200, so that the network isolation exchange of data between different hosts can be realized by using the module 100→external module 300, or the external module 300→module 100.

[0105] In some embodiments of the present invention, the module 100 also sequentially uses the fourth circular linked list of the host 200, the second circular linked list of the chip 101, and the circular linked list in the external chip with a multi-core processor in the external module 300 to construct a data exchange memory model to transmit the data to be exchanged, so as to complete the isolated exchange of the data to be received. Here, if the isolated exchange is a network isolated exchange, it can refer to the network isolated exchange of data between the server where the module 100 is located and the server where the external module 300 is located.

[0106] It should be noted that the data to be exchanged is data that needs to be transmitted from the host 200 through the module 100 and the external module 300 to the host connected to the external module 300; correspondingly, the data to be received is data that is transmitted from the external module 300 and then through the module 100 to the host 200. Here, the data transmission of the data to be exchanged between the external module 300 and the host connected to the external module 300 can refer to the interaction mode between the host 200 and the module 100.

[0107] In some embodiments of the present invention, isolated exchange (network isolated exchange) is a single task. Based on the corresponding circular linked list, the order of reading and writing is kept consistent. Its PCIe DMA transmission configuration method is consistent with the configuration method corresponding to the cryptographic operation.

[0108] In this way, the module 100 uses the isolation exchange processor 1012 of the chip 101 to execute the transmission of the data to be received to the external host 200, which can not only save the computing resources in the host 200, but also based on the second circular linked list, the fourth circular linked list, the circular linked list in the external chip with a multi-core processor in the external module 300 and the constructed data exchange memory model, the data to be received can be transmitted in (host connected to the external module 300 →) external module 300 → module 100 → host 200 to complete the isolation exchange of the data to be received in different hosts. In this way, based on the simplified hardware design (integrated cryptographic operations and network isolation exchange) of the module 100 to reduce product costs, the synchronous execution of cryptographic operations and isolation exchange functions is achieved to improve the high-performance operation of data.

[0109] Referring to the above description, the CPU of the host 200 can schedule PCIe DMA for data (data to be encrypted, data to be exchanged, calculation results) transmission based on the circular linked list (first circular linked list, second circular linked list, third circular linked list and fourth circular linked list) with the cryptographic operation processor 1011 and the isolation exchange processor 1012 of the chip 101, that is, with the CPU of the National Core CCP1080T; wherein, the CPU of the host 200 only performs the operation of writing data from the memory of the host 200 to the memory of the National Core CCP1080T, and the CPU of the National Core CCP1080T only performs the write operation from the memory of the National Core CCP1080T to the memory of the host 200. The dual-core CPU of the National Core CCP1080T (the cryptographic operation processor 1011 and the isolation exchange processor 1012 of the chip 101) is used separately, one for scheduling cryptographic operation services and the other for scheduling data isolation exchange services.

[0110] That is to say, compared with other cryptographic cards with network isolation exchange functions, the module with cryptographic operation and isolation exchange functions in the present invention can achieve higher performance while simplifying the hardware design (integrating cryptographic operation and isolation exchange functions with the chip 101 with a dual-core processor), thereby reducing product costs. In other words, the key points of the present invention are the selection and architecture design of hardware (architecture design corresponding to the module with cryptographic operation and isolation exchange functions) and the design of data exchange memory model corresponding to the module with cryptographic operation and isolation exchange functions (data interaction between multiple circular linked lists). Through the combination of these two key points, efficient data transmission can be further achieved.

[0111] The module with cryptographic operation and isolation exchange functions provided by the embodiment of the present invention builds a hardware architecture capable of synchronously executing cryptographic operation and isolation exchange functions based on a chip with a dual-core processor, and synchronously implements cryptographic operation and isolation exchange functions based on a circular linked list inside the chip. In this way, high-performance synchronous execution of cryptographic operation and network isolation exchange can be achieved by using a chip with a dual-core processor while simplifying the hardware design to reduce product costs.

[0112] Example 2

[0113] Based on the same inventive concept, an embodiment of the present invention provides a design method for a module with cryptographic operation and isolation exchange functions, see Figure 2 FIG. 1 is a flow chart of a design method of a module with cryptographic operation and isolation exchange functions provided by an embodiment of the present invention, combined with Figure 2 The design method is described as follows:

[0114] Step 201: Connect a chip with a multi-core processor, a noise source chip, a memory, a multimedia card, and an Ethernet optical module through a physical interface to obtain an initial hardware architecture.

[0115] The multi-core processor includes: a cryptographic operation processor for performing cryptographic operations and an isolation switching processor for performing isolation switching.

[0116] In some embodiments of the present invention, the chip with a multi-core processor may be the Guoxin CCP1080T mentioned above, that is, the hardware part of the module is based on the Guoxin CCP1080T high-performance edge security computing chip. The specific description can be referred to the above description and will not be repeated here.

[0117] Here, the CCP1080T chip can be connected to the noise source chip, the memory, the multimedia card, and the Ethernet optical module through physical interfaces, thereby completing the hardware connection between multiple components.

[0118] Step 202: configure the communication interface and the network interface of the chip in the initial hardware architecture, and initialize the noise source chip, the memory, the multimedia card, the Ethernet optical module, and the storage resources of the chip.

[0119] The present invention provides a method for designing a PCI cryptographic card with high-speed network switching capability, which includes not only a hardware design part but also a software design part. The corresponding software design part can be described as follows:

[0120] The Guoxin CCP1080T firmware can be used to initialize the Guoxin CCP1080T, such as configuring the communication interface PCIe in the Guoxin CCP1080T to PCIe3.0 x4 EP mode, configuring the network interface to 10 Gigabit Ethernet Media Access Control (MAC) mode, that is, XGMAC mode, and configuring the network high-performance data path acceleration structure (DPAA) to 10 Gigabit mode, and initializing related peripherals, storage and other resources.

[0121] Step 203: Apply for the first circular linked list and the second circular linked list corresponding to the memory area in the firmware program of the chip to obtain a module with cryptographic operation and isolation exchange functions.

[0122] Among them, the first circular linked list is a linked list corresponding to the memory area used for cryptographic operations, and the second circular linked list is a linked list corresponding to the memory area used for isolated exchange.

[0123] In some embodiments of the present invention, a first circular linked list corresponding to a memory area for cryptographic operations and a second circular linked list corresponding to a memory area for isolated exchange, i.e., isolated data transmission are applied for in the firmware program of the National Core CCP1080T.

[0124] Here, the specific description of the first circular linked list and the second circular linked list can refer to the embodiment of the module with cryptographic operation and isolation exchange functions described above, and will not be repeated here.

[0125] It should be noted that the module with cryptographic operation and isolation switching functions is also a PCI cryptographic card.

[0126] In the present invention, in order to ensure the efficiency of subsequent data transmission, the host subsequently connected to the module, that is, the host in the server where the module is located, can be enumerated to the module, the driver completes the device initialization, and applies for the third circular linked list corresponding to the memory area for cryptographic operations within the driver, as well as the fourth circular linked list corresponding to the memory area for isolated exchange, that is, data isolation transmission, and interacts with the firmware through the PCIe inbound method to improve the information in the isolation linked list.

[0127] The design method of the module with cryptographic operation and isolation switching functions provided by the present invention can obtain a module with cryptographic operation and isolation switching functions, and the cryptographic operation and isolation switching can both reach 6Gbps when performed simultaneously, meeting the requirements of high-end isolation gateways for cryptographic operation and isolation switching at the same time; in addition, compared with the cryptographic card with network isolation switching function in the prior art, on the basis of achieving higher performance and simultaneous execution of cryptographic operation and isolation switching, the hardware design is also simplified, thereby reducing product costs.

[0128] Example 3

[0129] Based on the same inventive concept, the embodiment of the present invention also provides a design system for a module with cryptographic operation and isolation exchange functions, see Figure 3 As shown, it is a schematic diagram of the composition of a design system of a module with cryptographic operation and isolation exchange functions provided by an embodiment of the present invention, and the design system 300 includes:

[0130] The hardware connection module 301 is used to connect the chip with the multi-core processor with the noise source chip, the memory, the multimedia card, and the Ethernet optical module through a physical interface to obtain an initial hardware architecture; wherein the multi-core processor includes: a cryptographic operation processor for performing cryptographic operations and an isolation switching processor for performing isolation switching;

[0131] An initialization module 302, configured to configure the communication interface and the network interface of the chip in the initial hardware architecture, and to initialize the noise source chip, the memory, the multimedia card, the Ethernet optical module, and the storage resources of the chip;

[0132] An application module 303 is used to apply for the first circular linked list and the second circular linked list corresponding to the memory area in the firmware program of the chip to obtain a module with cryptographic operation and isolation exchange functions;

[0133] Among them, the first circular linked list is a linked list corresponding to the memory area used for cryptographic operations, and the second circular linked list is a linked list corresponding to the memory area used for isolated exchange.

[0134] It should be noted that the description of the design system 300 is similar to the description of the above-mentioned design method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the system embodiment of the present invention, please refer to the description of the method embodiment of the present invention for understanding.

[0135] Example 4

[0136] Based on the same inventive concept, the embodiment of the present invention also provides an operating system with cryptographic operation and isolated exchange functions, see Figure 4 As shown, it is a schematic diagram of the composition of an operating system with cryptographic operation and isolation exchange functions provided by an embodiment of the present invention; the operating system 400 at least includes: two modules with cryptographic operation and isolation exchange functions as described in any of the above embodiments; the two modules (refer to Figure 4 As shown, taking the first module 401 and the second module 402 as an example), the Ethernet optical module (including: Figure 4 The Ethernet optical module in the first module 401 and the Ethernet optical module in the second module 402 are connected to each other for communication; one module in the two modules (such as Figure 4 The first module 401 shown in FIG. 4 communicates with an external first host 403 through the communication interface of the internal chip, and another module (such as Figure 4 The second module 402 shown in FIG. 4 communicates with an external second host 404 through the communication interface of the internal chip.

[0137] In some embodiments of the present invention, the first host 403 and the second host 404 may be CPUs in different servers, such as the first host 403 is a CPU in an intranet server, and the second host 404 is a CPU in an extranet server.

[0138] It should be noted that the hardware framework and specific related implementation (simultaneous implementation of cryptographic operations and isolated exchange functions) inside the first module 401 and the second module 402 can be referred to the above description and will not be repeated here.

[0139] In some embodiments of the present invention, circular linked lists for cryptographic operations and isolated exchanges can be constructed in the respective drivers of the first host 403 and the second host 404, and circular linked lists for cryptographic operations and isolated exchanges can be constructed in the firmware programs in the chips of the first module 401 and the second module 402, so as to construct a dedicated data exchange memory model based on multiple circular linked lists to realize data transmission and exchange between the first host 403, the second host 404, the first module 401 and the second module 402. Correspondingly, see Figure 5 As shown, it is a schematic diagram of a data exchange memory model constructed by a circular linked list between a host and a module provided by an embodiment of the present invention; wherein, taking 501 as the memory of the first host 403 and 502 as the memory of the chip of the first module 401 as an example, the password in 501 can be represented by: a circular linked list corresponding to a memory area in the memory of the first host 403 for cryptographic operations; the isolation in 501 can be represented by: a circular linked list corresponding to a memory area in the memory of the first host 403 for isolated exchange; correspondingly, the password in 502 can be represented by: a circular linked list corresponding to a memory area in the memory of the chip deployed in the first module 401 for cryptographic operations; the isolation in 502 can be represented by: a circular linked list corresponding to a memory area in the memory of the chip deployed in the first module 401 for isolated exchange. Here, the first host 403 and the first module 401 can each select a memory address from the corresponding circular linked list in a preset order to perform operations such as data writing, and the first host 403 and the first module 401 (the chip in the first module 401) perform data transmission by means of PCIe DMA.

[0140] In some embodiments of the present invention, a cryptographic operation initiated by a relevant application within the first host 403, that is, after calling an API related to the cryptographic service, a transmission of relevant data and a cryptographic operation are performed between the first host 403 and the first module 403; correspondingly, a cryptographic operation initiated by a relevant application within the second host 404, that is, after calling an API related to the cryptographic service, a transmission of relevant data and a cryptographic operation are performed between the second host 404 and the second module 402.

[0141] In some embodiments of the present invention, the data isolation exchange service initiated by the relevant application in the first host 403, that is, after calling the isolation exchange related API, the relevant data needs to be transmitted in sequence through the first host 403 → the first module 401 → the second module 402 → the second host 404, so as to realize the transmission of the relevant data 1 in the first host 403 to the second host 404; correspondingly, the data isolation exchange service initiated by the relevant application in the second host 404, that is, after calling the isolation exchange related API, the relevant data 2 needs to be transmitted in sequence through the second host 404 → the second module 402 → the first module 401 → the first host 403, so as to realize the transmission of the relevant data 2 in the second host 404 to the first host 403.

[0142] The following description is made by taking an application program in the first host 403 calling an API related to isolation exchange to execute isolation exchange of related data 2 as an example:

[0143] (1) Application A of the first host 403 calls an API related to isolation exchange. Application A sequentially takes out an element, namely, memory address a, from a circular linked list in the memory of the first host 403 for data isolation exchange, and encapsulates the data transmission task called by application A, namely, related data 1 in the memory address a of the first host 403. Then, the memory address a is added to the PCIe DMA transmission linked list between the first host 403 and the first module 401.

[0144] (2) The PCIe DMA transfer linked list moves the relevant data 1 from the memory address a of the first host 403 to the memory address b in the circular linked list for data isolation exchange of the first module 401, and notifies the National Core CCP1080T (the isolation exchange processor of the CCP1080T chip) in the first module 401;

[0145] (3) After receiving the relevant data 1 at the memory address b, the isolation exchange processor of the National Core CCP1080T calls the 10G network card DMA to transfer the data to the memory address c in the circular linked list for data isolation exchange of the second module 402;

[0146] (4) After receiving the relevant data 1 at the memory address c, the second module 402 notifies the isolation switch processor of the National Core CCP1080T in the second module 402.

[0147] (5) The isolation exchange processor of the National Core CCP1080T in the second module 402 will transfer the relevant data 1 in the memory address c to the memory address d in the circular linked list used for data isolation exchange of the second host 404 through the PCIe DMA transmission linked list between the second module 402 and the second host 404.

[0148] (6) The main processor of the second host 404 reads the relevant data 1 from the memory address d to complete the isolated exchange of the relevant data 1 between the first host 403 and the second host 404.

[0149] Referring to the above description, the application program in the second host 404 calls the isolation exchange related API to execute the isolation exchange of the related data 2 as executable accordingly.

[0150] Referring to the above description, the first module 401 and the second module 402 may further include: a noise source chip, a memory and a multimedia card respectively connected to the chip. Figure 6 As shown, it is a schematic diagram of a hardware framework design corresponding to the operating system with cryptographic operation and isolation exchange functions provided by the embodiment of the present invention; wherein: 601 is module 1 with cryptographic operation and isolation exchange functions, that is, PCI cryptographic card A with high-speed network exchange capability, 602 is module 2 with cryptographic operation and isolation exchange functions, that is, PCI cryptographic card B with high-speed network exchange capability, and 601 and 602 respectively include: Guoxin CCP1080T, and DDR4 memory, eMMC, noise source chip, and 10Gbps optical module connected to Guoxin CCP1080T respectively; at the same time, the communication between 601 and 602 is through the 10Gbps optical modules inside the two, 601 is connected to the external network host 603, and 602 is connected to the internal network host 604.

[0151] In this way, in the operating systems corresponding to the internal and external networks, based on the hardware framework corresponding to the modules with cryptographic operations and isolation switching functions, that is, the architecture of the PCI cryptographic card with high-speed network isolation switching functions, and the design of constructing a data exchange memory model with multiple circular linked lists, it is possible to achieve higher performance of data in the operating system on the basis of two edge computing chips with dual-core processors to simplify hardware design and reduce product costs, that is, to achieve high-performance synchronous execution of cryptographic operations and isolation switching functions.

[0152] In practical applications, the module with cryptographic operation and isolation exchange functions provided by the present invention, that is, the cryptographic card with network isolation exchange function, can be deployed in a server equipped with Haiguang 7380CPU (32 cores, 2.2GHz), and the actual test is carried out at the driver layer. If only the service corresponding to the cryptographic operation is performed, the SM1 encryption performance reaches 12.1Gbps, the SM3 hash performance reaches 14.3Gbps, the SM4 encryption performance reaches 12.5Gbps, and the SM2 signature performance reaches 63,000 times / second. If only the service corresponding to the data isolation exchange is performed, the data exchange performance reaches 8.9Gbps. When the service corresponding to the cryptographic operation and the service corresponding to the data isolation exchange are performed simultaneously, the isolation exchange performance is limited to 6.5Gbps, at which time the SM1 encryption performance reaches 6.9Gbps, the SM3 hash performance reaches 7.1Gbps, the SM4 encryption performance reaches 6.8Gbps, and the SM2 signature performance reaches 62,000 times / second. That is, it has been verified that the network isolation switching performance and cryptographic operation performance of the PCI cryptographic card designed based on the module with cryptographic operation and isolation switching functions mentioned in this solution have reached the expected level.

[0153] Embodiment 5:

[0154] Based on the same inventive concept, Figure 7 As shown, the present invention also provides an electronic device, which may be a computer device, a single-chip device, an intelligent mobile device, etc. The electronic device in this embodiment may include a processor 710, a memory 720, a transceiver component 730, etc. The processor 710, the memory 720 and the transceiver component 730 are connected via a bus 740; the memory 720 can be used to store an execution program, and an exemplary execution program may include instructions; the processor 710 is used to execute the instructions stored in the memory. The memory 720 can also be used to store data, which can be called and / or modified when executing instructions.

[0155] The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in a storage medium to implement corresponding method flows or corresponding functions, so as to realize a design method of a module with cryptographic operation and isolation exchange functions in the above-mentioned embodiment.

[0156] Embodiment 6:

[0157] Based on the same inventive concept, the present invention also provides a readable storage medium, specifically an electronic device readable storage medium (Memory), which is a memory device in an electronic device for storing programs and data. It can be understood that the storage medium here can include both built-in storage media in electronic devices and, of course, extended storage media supported by electronic devices. The storage medium provides a storage space, which stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by a processor are also stored in the storage space, and these instructions can be one or more execution programs (including program codes). It should be noted that the storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor loads and executes one or more instructions stored in the storage medium to implement a design method for a module with cryptographic operations and isolated exchange functions in the above embodiment.

[0158] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0159] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0160] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0161] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0162] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A module with cryptographic operation and isolated exchange functions, characterized in that: The module at least includes: a chip with a multi-core processor and a communication interface, and an Ethernet optical module; the multi-core processor includes: a cryptographic operation processor and an isolation switching processor; wherein: The cryptographic operation processor is used to, when the memory address of the first circular linked list in the chip receives the data to be encrypted sent by the host connected through the communication interface, use the security engine to calculate the data to be encrypted, obtain a calculation result, and transmit the calculation result to the memory address of the first circular linked list, so as to transmit the calculation result to the host; The isolated exchange processor is used to transmit the data to be exchanged to the external module connected through the Ethernet optical module when the memory address of the second circular linked list in the chip receives the data to be exchanged sent by the host, so that the external module continues to transmit the data to be exchanged.

2. The module according to claim 1, characterized in that The cryptographic operation processor is further used to transmit the calculation result written in the memory address of the first circular linked list to the memory address of the third circular linked list in the host, so that the main processor of the host reads and sends the calculation result in the memory address of the third circular linked list to the first application in the host; Among them, the data to be encrypted is data transmitted from the memory address of the third circular linked list to the memory address in the first circular linked list; the memory address of the third circular linked list is the address where the first application encapsulates the data to be encrypted when calling the application programming interface related to the cryptographic service.

3. The module according to claim 1, characterized in that The isolated exchange processor is further used to transmit the data to be exchanged to the external module, so that the external chip with a multi-core processor in the external module continues to transmit the data to be exchanged using the circular linked list in the external chip; Among them, the data to be exchanged is data transmitted from the memory address in the fourth circular linked list in the host to the memory address of the second circular linked list; the memory address in the fourth circular linked list is the address where the second application in the host encapsulates the data to be exchanged when calling the application programming interface related to isolation exchange.

4. The module according to claim 3, characterized in that The isolated exchange processor is further configured to, when receiving the to-be-received data in the memory address of the second circular linked list, transmit the to-be-received data to the memory address of the fourth circular linked list, so that the host reads the to-be-received data from the memory address of the fourth circular linked list; The data to be received is data transmitted to the memory address of the second circular linked list through the memory address of the circular linked list in the external chip.

5. The module according to claim 1, characterized in that The communication interface is a high-speed serial computer expansion bus standard interface.

6. The module according to claim 5, characterized in that The chip and the host perform data transmission via the high-speed serial computer expansion bus standard interface in a data transmission mode with direct memory access function; The chip and the external module perform data transmission via the Ethernet optical module using the data transmission method.

7. The module according to claim 1, characterized in that The module also includes: A noise source chip, a memory and a multimedia card are respectively connected to the chip.

8. A design method for a module with cryptographic operation and isolated exchange functions, characterized in that: The method comprises: The chip with a multi-core processor is connected to a noise source chip, a memory, a multimedia card, and an Ethernet optical module through a physical interface to obtain an initial hardware architecture; wherein the multi-core processor includes: a cryptographic operation processor for performing cryptographic operations and an isolation switching processor for performing isolation switching; Configuring the communication interface and the network interface of the chip in the initial hardware architecture, and initializing the noise source chip, the memory, the multimedia card, the Ethernet optical module, and the storage resources of the chip; Applying for a first circular linked list and a second circular linked list corresponding to the memory area in the firmware program of the chip to obtain a module with cryptographic operation and isolation exchange functions; Among them, the first circular linked list is a linked list corresponding to the memory area used for cryptographic operations, and the second circular linked list is a linked list corresponding to the memory area used for isolated exchange.

9. A design system for a module with cryptographic operation and isolated exchange functions, characterized in that: The system comprises: A hardware connection module is used to connect the chip with a multi-core processor with a noise source chip, a memory, a multimedia card, and an Ethernet optical module through a physical interface to obtain an initial hardware architecture; wherein the multi-core processor includes: a cryptographic operation processor for performing cryptographic operations and an isolation switching processor for performing isolation switching; An initialization module, configured to configure the communication interface and the network interface of the chip in the initial hardware architecture, and to initialize the noise source chip, the memory, the multimedia card, the Ethernet optical module, and the storage resources of the chip; An application module, used for applying for a first circular linked list and a second circular linked list corresponding to a memory area in a firmware program of the chip, to obtain a module having cryptographic operation and isolation exchange functions; Among them, the first circular linked list is a linked list corresponding to the memory area used for cryptographic operations, and the second circular linked list is a linked list corresponding to the memory area used for isolated exchange.

10. An operating system with cryptographic operation and isolated exchange functions, characterized in that: The system comprises at least: two modules with cryptographic operation and isolation switching functions as described in any one of claims 1 to 7; the two modules are communicatively connected via the Ethernet optical module; one of the two modules communicates with an external first host via the communication interface of the internal chip, and the other module communicates with an external second host via the communication interface of the internal chip.