Trusted DCS (Distributed Control System) controller and implementation method thereof

By integrating heterogeneous links and trusted configuration verification modules in FPGAs, the problem that the existing trusted DCS controller cannot operate when the interface fails, and a high reliability and security DCS controller is realized.

CN120010413APending Publication Date: 2025-05-16XIAN THERMAL POWER RES INST CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510146284.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When the existing trusted DCS controller fails, all network ports will not be able to operate, resulting in a reduced operating reliability of the DCS system.

Method used

Through the Ethernet link transceiver and PCIE link transceiver and processing module that integrates heterogeneous links in the FPGA, data interaction between the CPU and the FPGA is realized, data interaction is performed using the GMAC interface and the PCIE interface, and the trusted configuration verification module is integrated in the FPGA to perform trustworthy measurement and verification of configuration information.

Benefits of technology

It improves the reliability of the system and communication bandwidth, ensures the credibility of configuration information, and enhances the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010413A_ABST
    Figure CN120010413A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of distributed control systems, and discloses a trusted DCS (Distributed Control System) controller and an implementation method thereof, comprising a CPU (Central Processing Unit) and an FPGA (Field Programmable Gate Array), the CPU is used for receiving and sending configuration information of the port equipment to the FPGA and receiving a port equipment reply message fed back by the FPGA; the FPGA is used for distributing the received configuration information of the port devices to the corresponding port devices and receiving and sending reply messages of the port devices to the CPU; the FPGA comprises an Ethernet link transceiving processing module, a PCIE (Peripheral Component Interface Express) link transceiving processing module and a credible configuration verification module; the Ethernet link transceiving processing module and the PCIE link transceiving processing module are heterogeneous links and are used for sending and receiving messages between the FPGA and the CPU; the trusted configuration verification module is used for carrying out trusted measurement and verification on the received configuration information of the port equipment; the invention not only can improve the reliability of the system, but also can improve the communication bandwidth of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of distributed control systems, and in particular relates to a trusted DCS controller and an implementation method thereof. Background Art

[0002] The DCS (Distributed Control System) controller is the core component of the DCS system. It is responsible for executing control algorithms, managing the entire system and coordinating the work of various components. It plays an important role in the field of industrial automation and is widely used in petrochemical, electric power, metallurgy, pharmaceuticals and other fields. The trusted DCS controller adds a trusted system to the traditional DCS controller, so that the DCS controller can resist various network attacks to improve the reliability of the DCS system and the security of data.

[0003] At present, the existing trusted DCS controller adopts the multi-branch network technology of CPU+FPGA, and its implementation method is that the CPU sends all network messages to the FPGA through a single GMAC interface or PCIE interface, and then the FPGA distributes the message according to the network port flag in the message additional information, and distributes the message of each network port to the sending module of the corresponding network port for sending; however, when a single GMAC interface or PCIE interface is used for communication, if there is an interface failure, all network ports of the controller will not be able to operate, which greatly reduces the operation reliability of the DCS system. Summary of the invention

[0004] In view of the technical problems existing in the prior art, the present invention provides a trusted DCS controller and an implementation method thereof to solve the technical problem that when the existing trusted DCS controller uses a single GMAC interface or PCIE interface for communication, when there is an interface failure, all network ports of the controller will fail to operate, greatly reducing the operating reliability of the DCS system.

[0005] In order to achieve the above object, the technical solution adopted by the present invention is: The present invention provides a trusted DCS controller, including a CPU and an FPGA; The CPU is used to receive and send configuration information of the port device to the FPGA, and receive a port device reply message fed back by the FPGA; the FPGA is used to distribute the received configuration information of the port device to the corresponding port device, and receive and send a port device reply message to the CPU; The FPGA includes an Ethernet link transceiver processing module, a PCIE link transceiver processing module and a trusted configuration verification module; the Ethernet link transceiver processing module and the PCIE link transceiver processing module are heterogeneous links, both used for sending and receiving messages between the FPGA and the CPU; wherein the messages between the FPGA and the CPU include Ethernet messages and PCIE messages; the trusted configuration verification module is used to perform trusted measurement and verification on the configuration information of the received port device.

[0006] Further, the Ethernet link transceiver module includes an RGMII TX / RX module, an Ethernet message processing module, an Ethernet message distribution / merging module and an Ethernet message network port transceiver module; The RGMII TX / RX module is used to implement RGMII timing and receive or send Ethernet messages; wherein the Ethernet messages include Ethernet send messages and Ethernet receive messages; The Ethernet message processing module is used to verify the Ethernet sending message or the Ethernet receiving message; The Ethernet message distribution / merging module is used to distribute the Ethernet transmission message to the corresponding port device according to the network port identifier in the message additional segment, and is also used to receive and summarize the Ethernet reception messages of each port device and send them to the CPU; The Ethernet message network port transceiver module is used to perform Ethernet message verification and realize the conversion of the internal timing of the FPGA and the external PHY chip timing of the port device.

[0007] Further, the PCIE link transceiver processing module includes a PCIE DMA TX / RX module, a PCIE message processing module, a PCIE message conversion module, a PCIE message distribution / merging module and a PCIE message network port transceiver module; The PCIE DMA TX / RX module is used to implement PCIE timing and receive or send PCIE messages; wherein the PCIE messages include PCIE send messages and PCIE receive messages; The PCIE message processing module is used to verify the PCIE sending message or the PCIE receiving message; The PCIE message conversion module is used to realize the conversion between PCIE timing and internal user timing; The PCIE message distribution / merging module is used to distribute the PCIE transmission message to the corresponding port device according to the network port identifier in the message additional segment, and is also used to receive and summarize the PCIE reception messages of each port device and send them to the CPU; The PCIE message network port transceiver module is used to perform PCIE message verification and realize the conversion of the internal timing of the FPGA and the external PHY chip timing of the port device.

[0008] Further, the trusted configuration verification module includes an FPGA register and a trusted computing module; The FPGA register is used to store the received configuration information of the port device and record the internal operation status of the FPGA; The trusted computing module is used to perform trusted computing on the received configuration information of the port device.

[0009] Further, the FPGA register includes a configuration register and a status register; The configuration register is used to receive and store configuration information of the port device; The state configurator is used to record and store the internal operating state of the FPGA.

[0010] Furthermore, the communication between the CPU and the FPGA, and between the FPGA and the port device all adopts full-duplex mode.

[0011] Furthermore, the full-duplex mode includes four parallel branch links, and the four parallel branch links include: an Ethernet transmission link, an Ethernet reception link, a PCIE transmission link, and a PCIE reception link.

[0012] The present invention also provides a method for implementing a trusted DCS controller, comprising: Writing the configuration information of the port device sent by the CPU into the FPGA; wherein the configuration information of the port device includes the configuration parameters of the port device and the trusted calculation results of the configuration parameters; Perform trustworthy measurement on the configuration parameters of the port device to obtain the trusted calculated values ​​of the configuration parameters; The trusted calculation value of the configuration parameter is compared with the trusted calculation result of the configuration parameter; if the comparison result is the same, the FPGA determines that the configuration information of the port device is credible and enables the configuration.

[0013] Furthermore, if the trusted calculation value of the configuration parameter is different from the trusted calculation result of the configuration parameter, the FPGA discards the configuration information of the port device and generates a configuration error flag.

[0014] Furthermore, it also includes a configuration regeneration step; wherein, the configuration regeneration step is specifically: after the CPU reads the error flag, it resends the configuration information of the port device to the FPGA.

[0015] Compared with the prior art, the present invention has the following beneficial effects: The trusted DCS controller provided by the present invention integrates an Ethernet link transceiver processing module and a PCIE link transceiver processing module of heterogeneous links inside the FPGA, and respectively sends and receives messages through the Ethernet link and the PCIE link, and then uses the two interfaces of the GMAC interface and the PCIE interface to realize data interaction between the CPU and the FPGA. Starting from the network link layer, relying on the advantages of the rich interfaces, parallelism, programmability and scalability of the FPGA, not only the reliability of the system can be improved, but also the communication bandwidth of the system can be improved; secondly, by integrating a trusted configuration verification module, the configuration information of the CPU is measured and verified, so that the credibility of the configuration information is ensured, and the security and reliability of the system are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a structural block diagram of the trusted DCS controller of the present invention; Figure 2 The figure is a flow chart of the implementation principle of the trusted DCS controller described in the present invention. DETAILED DESCRIPTION

[0017] In order to make the technical problems, technical solutions and beneficial effects solved by the present invention more clearly understood, the present invention is further described in detail in the following specific embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0018] As attached Figure 1 As shown, the present invention provides a trusted DCS controller, including a CPU and an FPGA; the CPU is connected to a host computer, and each network port of the FPGA is respectively connected to a corresponding port device on site; the CPU is used to receive and send configuration information of the port device to the FPGA, and receive a port device reply message fed back by the FPGA; the FPGA is used to distribute the received port device configuration information to the corresponding port device, and receive and send the port device reply message to the CPU.

[0019] Specifically, the CPU is used to receive the user's on-site port device configuration information from the upper computer software, and send it to the FPGA after internal preset configuration calculation; secondly, the CPU is also used to receive the port device reply message sent back by the on-site port device from the FPGA, and send it to the upper computer software after internal preset configuration calculation for user viewing; wherein, the on-site port configuration information includes the configuration parameters of the port device and the trusted calculation results of the configuration parameters, and the configuration parameters of the port device include the configuration parameter setting value and configuration; the port device reply message includes the status information of the port device and the preset collection information.

[0020] The FPGA is used to receive the configuration information of the port device sent by the CPU, and distribute the configuration information of the port device to the corresponding port device according to the port information in the message header of the configuration information of the port device; the FPGA is also used to collect the reply messages of the port device replied by the port device from each network port, and send the reply messages of the port device to the CPU.

[0021] It should be noted that the configuration information of the port device and the port device reply message are in the form of Ethernet messages or PCIE messages, which are divided into Ethernet messages, Modbus messages and user-defined messages according to different interface forms.

[0022] In the present invention, the FPGA includes an Ethernet link transceiver processing module, a PCIE link transceiver processing module and a trusted configuration verification module; the Ethernet link transceiver processing module and the PCIE link transceiver processing module are heterogeneous links, both used for sending and receiving messages between the FPGA and the CPU; the messages between the FPGA and the CPU include Ethernet messages and PCIE messages; the trusted configuration verification module is used to perform trusted measurement and verification on the configuration information of the received port device.

[0023] The Ethernet link transceiver processing module includes an RGMII (Reduced Gigabit Media Independent Interface) TX / RX module, an Ethernet message processing module, an Ethernet message distribution / merging module, and an Ethernet message network port transceiver module.

[0024] The RGMII TX / RX module is used to implement RGMII timing and receive or send Ethernet messages; wherein the Ethernet messages include Ethernet send messages and Ethernet receive messages; wherein the process of implementing the RGMII timing is specifically to complete the conversion between the RGMII timing and the internal byte stream timing of the FPGA; the RGMII timing is the interface timing between the GMAC of the CPU and the FPGA, and 4 bits of data are transmitted on both the rising and falling edges of a clock, and the internal byte stream timing of the FPGA is to transmit 8 bits of data on the rising edge of the clock; specifically, the conversion between the RGMII timing and the internal byte stream timing of the FPGA is completed through the primitive IDDR / ODDR (input double date rate / outputdouble date rate).

[0025] The Ethernet message processing module is used to verify the Ethernet sent message or the Ethernet received message; wherein, the verification process of the Ethernet sent message or the Ethernet received message includes checking the message header, message length, CRC (Cyclic Redundancy Check) of the Ethernet sent message or the Ethernet received message, and realizing the flow control, storm and whitelist functions in the Ethernet message reception.

[0026] Specifically, the message header verification process of the Ethernet sent message or the Ethernet received message, for example: when a frame of Ethernet message is input, the synchronization code and the frame start code of the message will be checked first; wherein, the synchronization code and the frame start code of the message are 7 0x55+1 0xD5; if the header of the message meets the requirements, the subsequent message will be received, otherwise it will be discarded; the message length verification process of the Ethernet sent message or the Ethernet received message, for example: using a preset byte counter, when a frame of message arrives, each time 1 byte of data is received, the preset byte counter is counted. The counter is incremented by one. After the message is received, the preset byte counter is cleared. According to the count value of the preset byte counter, it is determined whether the message meets the requirement of 64-1518 bytes of Ethernet message length. If it meets the requirement, the frame message is received, otherwise it is discarded. The CRC check process for Ethernet sent messages or Ethernet received messages is as follows: the algorithm for checking whether the message data is correct, the message processing module will perform CRC calculation on the received message, and compare the calculated result with the last 4 bytes of the message. If the results are consistent, it is considered that the message is received correctly, otherwise, the message is discarded.

[0027] The process of realizing flow control, storm and whitelist functions in Ethernet message reception is as follows: (1) Whitelist function: Ethernet messages will have destination MAC address information. The preset whitelist processing module is used to extract the destination MAC information in the message and compare it with the pre-configured MAC address. If the comparison result is consistent, the message is received, otherwise the message is discarded; (2) Storm processing function, that is, to avoid repeated message reception; there are two detection methods: a. If the same message appears within the set time, it is considered that a storm has occurred, otherwise it is not; b. If the same message appears in 32 consecutive frames of messages, it is considered that a storm has occurred. If any of the above two conditions occur, it is considered a network storm and the latest frame of the received message will be discarded. Otherwise, the message will be received. (3) Flow control: Flow control is performed on broadcast, multicast, and unicast messages respectively. There are two methods for flow control checking: a. If the number of bits of the received message exceeds the maximum limit within a set statistical period, the message after the frame will no longer be received and will be restarted in the next period; b. If the number of received message frames exceeds the maximum limit within a set statistical period, the message after the frame will no longer be received and will be restarted in the next period. If any of the above two conditions occur, it is considered that the flow control conditions have been met.

[0028] The Ethernet message distribution / merging module is used to distribute the Ethernet sending message to the corresponding port device according to the network port identifier in the message additional segment, and is also used to receive and summarize the Ethernet receiving messages of each port device and send them to the CPU; wherein the message structure of the Ethernet sending message includes a leading word, an FSD frame start, additional segment information, a destination MAC, a source MAC, a Len / Type, an IP header, a UDP header, a hello world, a Pad filler word and a check bit; the additional segment information includes the port_mask information identified by the network port and the port_mask is a unique hot code, for example, 0x01 is network port 1, and 0x02 is network port 2; it should be noted that a FIFO is set inside the FPGA for each network port. After the FPGA receives the message, it writes the message for the network port into the corresponding FIFO according to the port_mask in the additional segment information to realize the distribution of the message.

[0029] The Ethernet message network port transceiver module is used to perform Ethernet message verification and realize the conversion between the internal timing of the FPGA and the external PHY (Physical, port physical layer) chip timing of the port device; wherein, the process of performing Ethernet message verification in the Ethernet message network port transceiver module is similar to the process of verifying the Ethernet sending message or the Ethernet receiving message in the above-mentioned Ethernet message processing module, and is not repeated here; the process of realizing the conversion between the internal timing of the FPGA and the external PHY (Physical, port physical layer) chip timing of the port device, since the internal FPGA uses a byte stream message processing mode, that is, one clock cycle processes one byte of data, but the timing of the external PHY chip varies according to different interfaces, so the FPGA needs to convert different external interface timings with the internal processing timing.

[0030] In the present invention, the PCIE link transceiver processing module includes a PCIE DMA TX / RX module, a PCIE message processing module, a PCIE message conversion module, a PCIE message distribution / merging module and a PCIE message network port transceiver module.

[0031] The PCIE DMA TX / RX module is used to implement PCIE timing and receive or send PCIE messages; wherein the PCIE messages include PCIE send messages and PCIE receive messages.

[0032] The PCIE message processing module is used to verify the PCIE sending message or the PCIE receiving message; specifically, the process of verifying the PCIE sending message or the PCIE receiving message includes checking the head, tail and checksum of the PCIE sending message or the PCIE receiving message; wherein, the head and tail check adopts adding specific data at the beginning and end of a frame message, such as 0x7E7EE7E7 and 0x5A5AA5A5, indicating the head and tail; the premise for the FPGA to correctly receive the message must be to correctly identify these head and tail marks, if the head and tail are not received correctly, it is considered that the message is wrong and it is discarded; checksum check: the FPGA sums the received message data, for example, each 32 bits of data is a group, and the received messages are summed by group, and there will be checksum inverse data at the end of the message, if the checksum obtained by the FPGA is 0xFFFFFFFF, it is considered that the data is received correctly, otherwise it is considered to be wrong.

[0033] The PCIE message conversion module is used to realize the conversion between the PCIE timing and the internal user timing, so as to encapsulate the content of the received configuration information of the port device into an Ethernet message to form a PCIE sending message; or encapsulate the content of the reply message of the port device to form a PCIE receiving message; The process of encapsulating the content of the received port device configuration information into an Ethernet message to form a PCIE sending message includes: extracting the message content of the received port device configuration information, and encapsulating the extracted message content into an Ethernet message; wherein the message content of the received port device configuration information extracted includes a TLP message header and a user-defined header, tail and checksum; for example: encapsulating a preamble, a frame start, a MAC address, an IP header, a UDP header and a CRC check.

[0034] The process of encapsulating the content of the reply message of the port device to form a PCIE receive message includes: extracting the message content of the reply message of the port device, and encapsulating the extracted content into a PCIE message to add a TLP message header and a user-defined header, tail, and checksum; wherein, extracting the message content of the reply message of the port device includes removing a preamble, a frame start, a MAC address, an IP header, a UDP header, and a CRC check.

[0035] The PCIE message distribution / merging module is used to distribute the PCIE send message to the corresponding port device according to the network port identifier in the message additional segment, and is also used to receive and summarize the PCIE receive messages of each port device and send them to the CPU; it should be noted that the PCIE send message and the PCIE receive message here are both Ethernet messages after content encapsulation; the principle of the PCIE message distribution / merging module is basically the same as the above-mentioned Ethernet message distribution / merging module, which will not be repeated here.

[0036] The PCIE message network port transceiver module is used to perform PCIE message verification and realize the conversion of the internal timing of the FPGA and the external PHY chip timing of the port device; it should be noted that the PCIE message here is also an Ethernet message after content encapsulation. The principle of the PCIE message network port transceiver module is basically the same as the above-mentioned Ethernet message network port transceiver module, which will not be repeated here.

[0037] In the present invention, the trusted configuration verification module includes an FPGA register and a trusted computing module; the FPGA register is used to store the configuration information of the received port device and record the internal operating state of the FPGA; the trusted computing module is used to perform trusted computing on the received configuration information of the port device; the FPGA register includes a configuration register and a status register; the configuration register is used to receive and store the configuration information of the port device; the status configurator is used to record and store the internal operating state of the FPGA for the CPU to read and monitor.

[0038] Implementation principles and methods: As attached Figure 2 As shown, the implementation method of the trusted DCS controller of the present invention includes: Step 1, write the configuration information of the port device sent by the CPU into the FPGA; wherein the configuration information of the port device includes the configuration parameters of the port device and the trusted calculation results of the configuration parameters; specifically, the configuration information of the port device includes the Ethernet module receiving and sending enable, the configured white list (MAC address), the number of frames and time of the network storm judgment condition, the period of the flow control judgment condition, the maximum number of bits, and the maximum number of frames.

[0039] Step 2: Perform a trustworthy measurement on the configuration parameters of the port device to obtain a trusted calculated value of the configuration parameters; wherein, the trustworthy measurement on the configuration parameters of the port device is implemented by using a preset trusted algorithm; preferably, the preset trusted algorithm includes the national secret algorithm SM2 or SM3; specifically, the configuration parameters of the port device are used as input of the preset trusted algorithm, and an output result will be obtained through calculation of the preset trusted algorithm, and this result is the trusted calculated value of the configuration parameters.

[0040] Step 3: Compare the trusted calculation value of the configuration parameter with the trusted calculation result of the configuration parameter; if the comparison result is the same, the FPGA determines that the configuration information of the port device is credible and enables the configuration; if the trusted calculation value of the configuration parameter is different from the trusted calculation result of the configuration parameter, the FPGA discards the configuration information of the port device and generates a configuration error flag.

[0041] It should be noted that when the CPU sends the configuration parameters of the port device, it will also send the trusted calculation results of the configuration parameters; the FPGA will reserve a register to store the trusted calculation results of the configuration parameters; when the FPGA receives the configuration parameters, the trusted configuration verification module inside the FPGA will perform trusted calculations on the configuration parameters of the port device, and compare the calculation results with the trusted calculation results of the configuration parameters. If the comparison results are consistent, the configuration parameters are considered correct, otherwise, the trusted calculation result status register inside the FPGA is set to an error, and after the CPU reads the calculation result status register error, it re-sends the configuration parameters and the trusted results; in addition, the trusted calculation module will periodically perform trusted calculations on the configuration parameters and ensure the correctness of the configuration parameters to avoid single-bit or multi-bit flipping inside the FPGA to modify the configuration parameters; wherein, the CPU and the FPGA both use the same trusted calculation algorithm to ensure that the two can obtain the same output by calculating the same input under the same algorithm, thereby ensuring the correctness of the configuration; when the FPGA determines that the configuration information of the port device is trusted successfully, the Ethernet link transceiver processing module and the PCIE link transceiver processing module are enabled, and at this time, the CPU and the port device communicate normally.

[0042] In the present invention, the communication between the CPU and the FPGA, and between the FPGA and the port device adopts full-duplex mode; specifically, the full-duplex mode includes four parallel branch links, and the four parallel branch links include: an Ethernet transmission link, an Ethernet reception link, a PCIE transmission link, and a PCIE reception link; wherein the Ethernet transmission link and the Ethernet reception link are implemented based on the Ethernet link transceiver processing module, and the PCIE transmission link and the PCIE reception link are implemented based on the above-mentioned PCIE link transceiver processing module; It should be explained in detail that the full-duplex communication process between the CPU and the FPGA, and between the FPGA and the port device is realized by using the Ethernet transmission link, the Ethernet reception link, the PCIE transmission link, and the PCIE reception link, as follows: Ethernet transmission link: The CPU sends the Ethernet message to the FPGA through the GMAC interface; the format of the Ethernet message is the format specified by the protocol; the FPGA performs header, length and CRC check on the received message; if the check passes, the next step is carried out, otherwise the frame message is discarded and the error count corresponding to the FPGA status register is increased by 1; the FPGA divides the message sent by the CPU according to the network port mask in the message, and sends the message of the corresponding network port to the corresponding network port transmission module for transmission; the network port number, message format and CRC of the received message are checked, and the messages that pass the check are sent to the device, and the messages with check errors are recorded for the CPU to read.

[0043] Ethernet receiving link: FPGA receives messages from each network port; the messages here come from the PHY chip outside the FPGA; each network port of the FPGA verifies the received messages, and if the verification passes, it proceeds to the next step, otherwise it makes an error record; the FPGA merges the messages that have passed the verification of each network port and prepares to send them to the CPU; considering that the RAM resources inside the FPGA are limited, the CPU uses a preset control mechanism to control the traffic sent to the FPGA; the control mechanism is that the FPGA sends control frames, pause frames and resume frames to the CPU; the judgment condition for sending control frames is whether the FPGA send FIFO is almost full or almost empty; if the send FIFO is almost full, it means that the FPGA storage capacity is about to overflow, and at this time the FPGA sends a pause frame to the CPU, requiring the CPU to suspend sending after sending the frame being sent; if the send FIFO is almost empty, it means that the FPGA is about to send the data that needs to be sent, and at this time the FPGA sends a resume frame to the CPU, requiring the CPU to continue sending data to the FPGA. FPGA sends control frames and data frames to CPU according to its internal storage capacity. Data frames and control frames are both Ethernet messages. The difference between them lies in the destination MAC, Ethernet message type and message format. Both message types are messages specified by Ethernet protocol. Considering that the communication rate between CPU and FPGA is much higher than that between FPGA and device, there is no need for control frame communication between FPGA and device.

[0044] PCIE transmission link: CPU sends PCIE message to FPGA through PCIE interface; PCIE message is TLP (Transaction Layer Packet) message, i.e. transaction layer packet; FPGA verifies the received message, and if the verification is passed, it proceeds to the next step, otherwise it discards the frame message and increases the error count corresponding to the FPGA status register by 1; then, the PCIE message is converted into Ethernet message; specifically, after FPGA receives TLP message, after the message verification is correct, FPGA will extract the content in TLP message, i.e. remove TLP message header and user-defined header, tail, checksum; then encapsulate the content into Ethernet message, such as encapsulation preamble, frame start, MAC address, IP header, UDP header and CRC check; then, FPGA shunts the message sent by CPU according to the network port mask in the message, and sends the message of the corresponding network port to the corresponding network port sending module for sending. FPGA network port sending module verifies the network port number, message format and CRC of the received message, sends the message that passes the verification to the device, and records the error of the verification error for CPU to read.

[0045] PCIE receiving link: FPGA receives messages from each network port; each network port receiving module of FPGA verifies the received message, and if the verification is passed, it proceeds to the next step, otherwise it makes an error record; FPGA merges the messages that have passed the verification of each network port and prepares to send them to the CPU; FPGA converts the merged Ethernet message into a PCIE message; specifically, after the received Ethernet message is correctly received, the message content is extracted; wherein, the extracted message content includes removing the leading code, frame start, MAC address, IP header, UDP header and CRC check; then, the extracted content is encapsulated into a PCIE message, and a TLP message header and a user-defined header, tail, and checksum are added; it should be noted that there is no mechanism for pausing frames and resuming frames in PCIE messages, but a similar mechanism can be implemented through interrupts; if the sending FIFO is almost full, FPGA sends a pause interrupt request to the CPU; if the sending FIFO is almost empty, FPGA sends a resume interrupt request to the CPU; FPGA sends the interrupt request and data frame to the CPU according to the internal storage capacity.

[0046] The trusted DCS controller of the present invention receives port device configuration information from an external or upper system through a CPU, and sends the configuration information to an FPGA; at the same time, receives a port device reply message fed back by the FPGA through the CPU, which includes a configuration result, a status update or an error message; receives the port device configuration information from the CPU through the FPGA, and distributes it to the corresponding port device; and receives the reply message of the port device through the FPGA, and sends it to the CPU for further processing; in the FPGA, an Ethernet link transceiver processing module is used to send and receive messages with the CPU through an Ethernet link, and a PCIE (PCI Express) link is used to send and receive messages with the CPU; wherein, the Ethernet link and the PCIE link constitute a heterogeneous link, which provides a flexible communication mode; secondly, the received port device configuration information is trusted and verified through a trusted configuration verification module, which helps to ensure the integrity of the configuration information and the reliability of the source, thereby enhancing the security of the system.

[0047] In the present invention, by combining the functions of CPU and FPGA, and utilizing heterogeneous links and trusted configuration verification modules, efficient and flexible port device configuration and management are achieved, while the security of the system is enhanced, so that the trusted DCS controller has broad application prospects in the fields of industrial automation, data center management, etc.

[0048] The above embodiment is only one of the implementation methods that can realize the technical solution of the present invention. The scope of protection claimed by the present invention is not limited only to this embodiment, but also includes changes, replacements and other implementation methods that can be easily thought of by any technician familiar with the technical field within the technical scope disclosed by the present invention.

Claims

1. A trusted DCS controller, characterized in that: Including CPU and FPGA; The CPU is used to receive and send configuration information of the port device to the FPGA, and receive a port device reply message fed back by the FPGA; the FPGA is used to distribute the received configuration information of the port device to the corresponding port device, and receive and send a port device reply message to the CPU; The FPGA includes an Ethernet link transceiver processing module, a PCIE link transceiver processing module and a trusted configuration verification module; The Ethernet link transceiver processing module and the PCIE link transceiver processing module are heterogeneous links, both used for sending and receiving messages between the FPGA and the CPU; wherein the messages between the FPGA and the CPU include Ethernet messages and PCIE messages; the trusted configuration verification module is used to perform trusted measurement and verification on the configuration information of the received port device.

2. A trusted DCS controller according to claim 1, characterized in that: The Ethernet link transceiver module includes an RGMII TX / RX module, an Ethernet message processing module, an Ethernet message distribution / merging module and an Ethernet message network port transceiver module; The RGMII TX / RX module is used to implement RGMII timing and receive or send Ethernet messages; wherein the Ethernet messages include Ethernet send messages and Ethernet receive messages; The Ethernet message processing module is used to verify the Ethernet sending message or the Ethernet receiving message; The Ethernet message distribution / merging module is used to distribute the Ethernet transmission message to the corresponding port device according to the network port identifier in the message additional segment, and is also used to receive and summarize the Ethernet reception messages of each port device and send them to the CPU; The Ethernet message network port transceiver module is used to perform Ethernet message verification and realize the conversion of the internal timing of the FPGA and the external PHY chip timing of the port device.

3. A trusted DCS controller according to claim 1, characterized in that: The PCIE link transceiver processing module includes a PCIE DMA TX / RX module, a PCIE message processing module, a PCIE message conversion module, a PCIE message distribution / merging module and a PCIE message network port transceiver module; The PCIE DMA TX / RX module is used to implement PCIE timing and receive or send PCIE messages; wherein the PCIE messages include PCIE send messages and PCIE receive messages; The PCIE message processing module is used to verify the PCIE sending message or the PCIE receiving message; The PCIE message conversion module is used to realize the conversion between PCIE timing and internal user timing; The PCIE message distribution / merging module is used to distribute the PCIE transmission message to the corresponding port device according to the network port identifier in the message additional segment, and is also used to receive and summarize the PCIE reception messages of each port device and send them to the CPU; The PCIE message network port transceiver module is used to perform PCIE message verification and realize the conversion of the internal timing of the FPGA and the external PHY chip timing of the port device.

4. A trusted DCS controller according to claim 1, characterized in that: The trusted configuration verification module includes an FPGA register and a trusted computing module; The FPGA register is used to store the received configuration information of the port device and record the internal operation status of the FPGA; The trusted computing module is used to perform trusted computing on the received configuration information of the port device.

5. A trusted DCS controller according to claim 4, characterized in that: The FPGA registers include a configuration register and a status register; The configuration register is used to receive and store configuration information of the port device; The state configurator is used to record and store the internal operating state of the FPGA.

6. A trusted DCS controller according to claim 1, characterized in that: The communication between the CPU and the FPGA, and between the FPGA and the port device all adopts the full-duplex mode.

7. A trusted DCS controller according to claim 6, characterized in that: The full-duplex mode includes four parallel branch links, and the four parallel branch links include: an Ethernet transmission link, an Ethernet reception link, a PCIE transmission link, and a PCIE reception link.

8. The method for implementing a trusted DCS controller according to any one of claims 1 to 7, characterized in that: include: Writing the configuration information of the port device sent by the CPU into the FPGA; wherein the configuration information of the port device includes the configuration parameters of the port device and the trusted calculation results of the configuration parameters; Perform trustworthy measurement on the configuration parameters of the port device to obtain the trusted calculated values ​​of the configuration parameters; The trusted calculation value of the configuration parameter is compared with the trusted calculation result of the configuration parameter; if the comparison result is the same, the FPGA determines that the configuration information of the port device is credible and enables the configuration.

9. The method for implementing a trusted DCS controller according to claim 8, characterized in that: If the trusted calculation value of the configuration parameter is different from the trusted calculation result of the configuration parameter, the FPGA discards the configuration information of the port device and generates a configuration error flag.

10. The method for implementing a trusted DCS controller according to claim 8, characterized in that: It also includes a configuration regeneration step; wherein, the configuration regeneration step is specifically: after the CPU reads the error flag, it resends the configuration information of the port device to the FPGA.