Domestic routing switch system and method

By adopting the collaborative design of multi-stage buck circuits and multiple core components in the domestic routing switch system, the problems of simple power supply design and inconvenient network management in traditional systems are solved, and high-efficiency and intelligent network management are achieved.

CN120050246APending Publication Date: 2025-05-27SHAANXI EMBEDDED ELECTRONIC TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411833836.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Traditional routing switch systems are simple in power supply design, resulting in serious energy waste and low energy efficiency; at the same time, the convenience and efficiency of network management still need to be improved, especially in the isolation of internal and external networks.

Method used

A domestic routing switch system is designed, using a multi-stage buck circuit to accurately adjust the voltage requirements of each part, and combined with the coordinated work of the controller, MCU, switching chip, network transformer and PHY transceiver to achieve isolation and stable communication between the internal and external networks.

Benefits of technology

It improves the energy efficiency of the system, reduces energy waste, simplifies wiring and maintenance costs, and enhances the automation and intelligence level of the network, improving the convenience and efficiency of network management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050246A_ABST
    Figure CN120050246A_ABST
Patent Text Reader

Abstract

The invention provides a domestic route switch system and method, the system comprises a controller, an MCU, a switch chip, a network transformer and a PHY transceiver, the data transmission end of the controller is connected with the first data transmission end of the MCU, and the control end of the controller is connected with the controlled end of the MCU; the second data transmission end of the MCU is connected with the data transmission end of the exchange chip; the other data transmission end of the switching chip is connected with the data transmission end of the first network transformer, and the other data transmission end of the first network transformer is connected with the terminal equipment; the third data transmission end of the MCU is connected with the data transmission end of the PHY transceiver, the other data transmission end of the PHY transceiver is connected with the data transmission end of the second network transformer, and the other data transmission end of the second network transformer is connected with the terminal equipment; the domestic routing switch system designed by the invention has excellent communication capability, can realize smooth communication between the internal network and the external network through multiple combination modes, and can realize an internal network and external network isolation function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of switches, and in particular, to a domesticated routing switch system and method. Background Art

[0002] With the rapid development of information technology, as the core device of network communication, the performance and stability of the routing switch system are directly related to the communication quality and data security of the entire network. In recent years, the domesticated routing switch system has gradually become the mainstream choice in the market due to its advantages such as independent controllability, security, and reliability.

[0003] Although the domesticated routing switch system has made remarkable progress in communication capabilities and stability, there are still some technical problems to be solved urgently. First of all, the power supply design of traditional routing switch systems is often relatively simple, lacking precise regulation for the voltage requirements of each part of the system, resulting in serious energy waste and low overall energy efficiency. In addition, although the existing systems already have a certain level of automation and intelligence, there is still room for improvement in the convenience and efficiency of network management. In particular, how to achieve isolation between the internal and external networks to ensure network security and stability. Summary of the Invention

[0004] The present invention aims to at least solve the technical problems existing in the prior art, and particularly innovatively proposes a domesticated routing switch system and method.

[0005] To achieve the above object of the present invention, the present invention provides a domesticated routing switch system and method. The domesticated routing switch system includes: a controller, an MCU, a switching chip, a network transformer, and a PHY transceiver.

[0006] The data transmission end of the controller is connected to the first data transmission end of the MCU, and the control end of the controller is connected to the controlled end of the MCU; the second data transmission end of the MCU is connected to the data transmission end of the switching chip; the other data transmission end of the switching chip is connected to the data transmission end of the first network transformer, and the other data transmission end of the first network transformer is connected to the terminal device.

[0007] The third data transmission end of the MCU is connected to the data transmission end of the PHY transceiver, the other data transmission end of the PHY transceiver is connected to the data transmission end of the second network transformer, and the other data transmission end of the second network transformer is connected to the terminal device.

[0008] The switching chip and the first network transformer are several with the same quantity.

[0009] Preferably, the other data transmission end of the first network transformer is connected to the terminal device; the other data transmission end of the second network transformer is connected to the terminal device.

[0010] Preferably, the data terminal of the controller is connected to the data transmission terminal of the flash memory, and another data terminal of the controller is connected to the data transmission terminal of the eMMC memory; the power management terminal of the MCU is connected to the monitoring terminal of the power monitoring chip.

[0011] Preferably, the power supply part of the system includes: a first step-down chip, a second step-down chip, a third step-down chip, a fourth step-down chip, a fifth step-down chip, and a secondary step-down chip.

[0012] Among them, the power output terminals of the first step-down chip, the second step-down chip, the third step-down chip, the fourth step-down chip, and the secondary step-down chip are connected to the power input terminal of the controller; the power input terminal of the secondary step-down chip is connected to the power output terminals of the third step-down chip and the fourth step-down chip.

[0013] The power output terminals of the fourth step-down chip and the fifth step-down chip are connected to the power input terminal of the switching chip.

[0014] Preferably, the controller is also connected to the memory and the eMMC memory.

[0015] The power input terminal of the memory is connected to the power output terminal of the third step-down chip.

[0016] The power input terminal of the eMMC memory is connected to the power output terminal of the fourth step-down chip.

[0017] Preferably, the controller is also connected to the memory and the eMMC memory.

[0018] The data transmission terminals of the eMMC memories are respectively connected to one end of a pull-up resistor through their respective connection line branches, and the other ends of the pull-up resistors are commonly connected to the power supply VCCIO501, and the power supply VCCIO501 is obtained by passing the power supply 3.3V through the ferrite bead L18 or the resistor R196.

[0019] Preferably, the controller is also connected to the memory and the eMMC memory.

[0020] The power output terminal of the fourth step-down chip is also connected to the power input terminal of the power monitoring chip and the power input terminal of the MCU, and the reset signal terminal of the power monitoring chip is connected to the reset terminal of the eMMC memory.

[0021] When the power monitoring chip detects that the output voltage of the fourth step-down chip is abnormal, it sends an interrupt signal to the MCU, and the MCU controls the fourth step-down chip to stop working to ensure the safety of the system. The MCU includes the processor of the road switch.

[0022] The power supply monitoring chip monitors the power supply status. When detecting power anomalies (such as power failure, undervoltage or overvoltage), it sends a reset signal to the MCU through the NRST terminal, and may also send a reset signal to the PHY transceiver through the PHYRSTB terminal to ensure the stable operation of the entire system.

[0023] Preferably, the output power supply of the first step-down chip is 1.05V, the output power supply of the second step-down chip is 1.8V, the output power supply of the third step-down chip is 1.5V, the output power supply of the fourth step-down chip is 3.3V, and the output power supply of the fifth step-down chip is 1.18V.

[0024] Preferably, the input power supplies of the first step-down chip, the second step-down chip, the third step-down chip, the fourth step-down chip, and the fifth step-down chip are VCC12V with a voltage value of 12V. The VCC12V is connected to the negative pole of the voltage stabilizing diode VD4. The positive pole of the voltage stabilizing diode VD4 is connected to the negative pole of the TVS diode VD3 and the first end of the fuse FU4. The second end of the fuse FU4 is connected to the external 12V power supply; the positive pole of the TVS diode VD3 is connected to the power ground.

[0025] The present invention also proposes a working method for a domesticated routing switch system, including the following steps:

[0026] S1, when the system is powered on, the MCU of the switching system starts, initializes the switching chip, and operates the I / O level, and resets the controller;

[0027] S2, the switching system runs;

[0028] S3, after the controller system starts, it runs the DHCP server and configures the Iptables policy to achieve isolation between the internal and external networks;

[0029] S4, the terminal device accesses the switching system port, and the switching chip learns the MAC address of the terminal device and saves it in the L2 table;

[0030] S5, the switching system sends a DHCP request to the DHCP server for the terminal device, and after receiving it, the DHCP server assigns an IP address to the terminal device;

[0031] S6, the system executes to obtain the MAC and IP addresses of the terminals on the switching ports: the controller system repeatedly executes the arp command to obtain the ARP cache entries, obtains the mapping relationship between the IP address and the MAC address in the local system ARP cache entries, and sends a query switching port L2 command through the communication serial port and obtains the L2 table information, parses to obtain the MAC address of the terminal on this port, and by traversing the ARP entries, checks whether there is such a MAC address. If it exists, parses the ARP entry to obtain the IP address of this terminal device;

[0032] S7, The controller system sends ping packets to the terminal device of the switching port every 1 second in a loop according to the terminal IP address information. If the ping is successful, it indicates that the terminal device is normal; if the ping fails, it indicates that the terminal device is abnormal.

[0033] S8, The controller system sends UDP packets to the intranet monitoring platform in a loop to report the running status and data of the terminal device of the switching port. The intranet detection platform displays the running status of each terminal device.

[0034] S9, The terminal device sends packets to the controller system's intranet interface eth0 in a loop, forwards the data to the extranet interface eth1 through iptables, and sends the packets to the extranet detection platform.

[0035] S10, The controller saves the operation log data to the eMMC.

[0036] S11, The LED lights of the switching system flash periodically to indicate that the system is running normally.

[0037] Preferably, the implementation of the internal and external network isolation by configuring the Iptables policy includes the following steps:

[0038] (1) Configure the IP forwarding function: Configure a Linux kernel parameter net.ipv4.ip_forward. When its value is 0, it means that IP forwarding is prohibited; when its value is 1, it means that the IP forwarding function is enabled. After enabling, the data packets are forwarded according to the routing table.

[0039] (2) Configure the iptables port forwarding rules:

[0040] iptables -t nat -I POSTROUTING -o eth0 -s 192.168.123.0 / 24 -j SNAT --to-source 192.168.1.120;

[0041] Among them: -t nat means that the table to operate on is NAT;

[0042] -I POSTROUTING means to insert (Insert) a rule into the POSTROUTING chain;

[0043] -o eth0 means which network interface (output interface) the data packets coming out of should be processed;

[0044] -s 192.168.123.0 / 24 means the source IP address range of the data packets;

[0045] -j SNAT means that we want to perform Source NAT (Source Address Translation);

[0046] --to-Source 192.168.1.120 indicates what kind of source address to be converted to.

[0047] It is used to set up Network Address Translation (NAT) rules so that when traffic from a specific internal IP address range (192.168.123.0 / 24) is forwarded through the internal network interface eth0, all packets on the outgoing interface are source address translated using the specified external network IP address (192.168.1.120).

[0048] Preferably, the system's execution of obtaining the MAC and IP addresses of the switching port terminal includes the following steps:

[0049] (1) After the controller system starts, obtain ARP cache entries through the arp command to get the mapping relationship from IP address to MAC address in the local system's ARP cache entries;

[0050] (2) The controller sends a query switching port L2 command through the communication serial port and obtains L2 table information, parses to get the MAC address of this port terminal, and by traversing the ARP entries, checks if there is such a MAC address. If it exists, parses the ARP entry to get the IP address of this terminal device.

[0051] Preferably, the S8 reporting the operating status and data of the switching port terminal device further includes the following steps:

[0052] Use the TLS protocol to protect data security. The TLS protocol establishes a secure session through a handshake process, which exchanges encryption keys, verifies identities, and negotiates encryption algorithms; submit a certificate signing request to a trusted certificate authority; after the CA verifies the identity of the requester, issue a server certificate containing information such as the public key, issuer information, and validity period; install the server certificate and private key on the controller of the switching system;

[0053] The server certificate and private key automatically edit the controller's configuration file according to a preset URL path, add the URL paths of the server certificate and private key to the corresponding configuration items. To prevent the URL paths from being tampered with, perform a verification operation on the URL paths and confirm the integrity of the server certificate and private key. After the integrity confirmation is completed, store the server certificate and private key in the HSM, set an access control list for the directory of the stored server certificate and private key, and formulate multiple virtual certificates to be stored in the corresponding access control lists. Identify the corresponding server certificate and private key through secure matching authentication. After successful identification, restart the server to make the server certificate and private key take effect.

[0054] Effective server certificate and private key, configure the server certificate and private key for TLS communication, and obtain the ClientHello message containing the supported TLS versions, list of cipher suites, and random number; the server responds with a ServerHello message, including the selected TLS version, cipher suite, random number, as well as the server certificate and private key. At the same time, the server sends a CertificateRequest message; the client and the server exchange private keys and use these private keys to generate a symmetric encryption key for subsequent data encryption; by configuring TLS parameters, test whether the TLS communication of the controller is normal, so as to ensure that a TLS connection can be successfully established, and regularly check the validity period of the certificate.

[0055] In summary, due to the adoption of the above technical solutions, the domestic routing switch system designed by the present invention has excellent communication capabilities, and it can achieve smooth communication between the internal and external networks through various combination methods. Specifically, using the controller as the core, cooperating with the MCU (micro-control unit) for fine regulation, and then combining with the efficient data forwarding function of the switching chip or PHY transceiver, as well as the signal transmission and isolation function of the network transformer, to jointly build a stable and reliable communication bridge between the internal and external networks. In addition, a multi-stage step-down power supply circuit is specifically designed for the system, which can accurately adjust according to the voltage requirements of each part of the system, avoiding unnecessary energy waste, thereby improving the overall energy efficiency. At the same time, the wiring and maintenance costs are also simplified. At the same time, the present invention designs a working method for the domestic routing switch system based on the system, which improves the automation and intelligence level of the network, and also greatly enhances the convenience and efficiency of network management. And, the present invention also designs the configuration of Iptables policies to achieve internal and external network isolation.

[0056] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the following description of the embodiments in conjunction with the accompanying drawings, wherein:

[0058] Figure 1 is a schematic diagram of the routing switch system of the present invention.

[0059] Figure 2 is a flowchart of the system of the present invention for the internal network to access the external network.

[0060] Figure 3 is a flowchart of the system of the present invention for obtaining the MAC and IP of the switch port terminal.

[0061] Figure 4It is the flowchart for the system of the present invention to send messages to the intranet monitoring platform.

[0062] Figure 5 It is the flowchart for the system of the present invention to work.

[0063] Figure 6 It is the schematic diagram of the circuit connection of the power supply module of the system of the present invention.

[0064] Figure 7 It is the schematic diagram of the secondary circuit connection of the power supply module of the system of the present invention.

[0065] Figure 8 It is the schematic diagram of the circuit connection of the memory of the system of the present invention.

[0066] Figure 9 It is the schematic diagram of the circuit connection of the eMMC memory of the present invention.

[0067] Figure 10 It is the schematic diagram of the circuit connection of the controller of the present invention.

[0068] Figure 11 It is the schematic diagram of the circuit connection of the controller, power supply monitoring chip and flash memory of the present invention.

[0069] Figure 12 It is the schematic diagram of the circuit connection of the MCU (processor) and the power supply monitoring chip of the present invention.

[0070] Figure 13 It is the schematic diagram of the circuit connection of the switching chip and the memory of the present invention.

[0071] Figure 14 It is the schematic diagram of the circuit connection of the PHY transceiver of the present invention.

[0072] Figure 15 It is the schematic diagram of the circuit connection of the network transformer of the present invention.

[0073] Figure 16 It is the schematic diagram of the circuit connection of the network serial port transparent transmission chip of the present invention.

[0074] Figure 17 It is the schematic diagram of the circuit connection of the level conversion chip and the USB to serial port chip of the present invention. Detailed implementation manners

[0075] The embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary only for explaining the present invention and should not be construed as limiting the present invention.

[0076] The present invention provides a domesticated routing switch system, and the system composition is asFigure 1 As shown in the figure, it includes a controller and a switching system. The switching system includes a processor module and a switching module. The processor module includes a processor, and the switching module includes a switching chip. The processor module is respectively connected to several switching modules, and the switching module is connected to terminal devices. In a specific embodiment, the processor is connected to two switching chips SW1 and SW2. SW1 and SW2 are cascaded through GMAC ports and provide a total of 8 10 / 100 / 1000M Ethernet switching ports externally.

[0077] The controller uses a domestic FMQL45T900 quad-core chip, which includes a processing system (PS) unit and a programmable logic (PL) unit. The PS unit is responsible for system initialization.

[0078] The controller is connected to a 64GB eMMC storage for storing massive data and operation logs, a 32MB QSPI Flash for storing the boot program and operating system, and 2GB of memory.

[0079] The controller has: a debug serial port for software debugging, a 1000M Ethernet interface for supporting data upload and debugging, a network interface, and a communication serial port.

[0080] The network interface has Network Interface 1 and Network Interface 2.

[0081] Network Interface 1: Connects to the external network to facilitate access to other local area network or public network resources.

[0082] Network Interface 2: Connects to the switching system and is configured as a DHCP server to provide dynamic IP address allocation services for the internal local area network.

[0083] The communication serial port is used to configure the switching system parameters; obtain the switching system information, which includes port link status, L2 table, port mirroring configuration, VLAN settings, port rate, etc.

[0084] The processor module uses a domestic GD32F427ZG processor, equipped with two I2C interfaces, which are respectively connected to two switching chips for configuring and managing the switching chips.

[0085] In addition, the processor has: a debug serial port for software debugging, a communication serial port for data communication with the controller, for configuring the switching system and obtaining relevant information, a 100M network interface for accessing the switching chip and jointly forming an internal local area network, and an I / O interface for the reset operation of the controller and the control of the indicator light.

[0086] The switching module adopts a domestic high-performance Ethernet switching chip SF2507V, which is configured and managed through the I2C interface. The switching module has 5 GigaPHY ports with low-power consumption characteristics and 2 GMAC ports.

[0087] It provides 8 10 / 100 / 1000M switching ports to form an internal local area network, which are respectively connected to 8 terminals, and provides a 10 / 100 / 1000M network port as an external interface. By configuring corresponding application rules, the internal local area network can access the external network, and the external network cannot access the internal local area network. The system provides the DHCP server function to dynamically allocate network configuration parameters such as IP addresses, subnet masks, default gateways, and DNS server addresses for client devices in the internal local area network.

[0088] The main functions of the domestic routing switch system proposed by the present invention are: accessing the external network from the internal network, obtaining the MAC and IP of the terminals on the switching ports, and sending packets to the internal network monitoring platform.

[0089] The working steps for the system to access the external network from the internal network are as Figure 2 shown: Use iptables to configure the network firewall and implement isolation between the internal and external networks. Iptables is an IP packet filtering system integrated into the Linux kernel, which allows users to define firewall rules based on packet filtering. The following are the steps on how to use iptables to achieve isolation between the internal and external networks, and view the network status and route tracking.

[0090] (1) Configure the IP forwarding function: Configure a Linux kernel parameter net.ipv4.ip_forward. When its value is 0, it means that IP forwarding is prohibited; when its value is 1, it means that the IP forwarding function is enabled. After enabling, packets can be forwarded according to the routing table.

[0091] (2) The method for configuring the iptables port forwarding rule is as follows:

[0092] iptables -t nat -I POSTROUTING -o eth0 -s 192.168.123.0 / 24 -j SNAT --to-source 192.168.1.120; The meaning of this command is:

[0093] -t nat: Specify that the table for the operation is NAT.

[0094] -I POSTROUTING: It means that we want to insert (Insert) a rule into the POSTROUTING chain.

[0095] -o eth0: This indicates the network interface (output interface) from which we want to process the packets.

[0096] -s 192.168.123.0 / 24: This indicates the source IP address range of the packets.

[0097] -j SNAT: This indicates that we want to perform Source Network Address Translation (SNAT).

[0098] --to-Source 192.168.1.120: This indicates what source address to convert to.

[0099] It is used to set up Network Address Translation (NAT) rules so that when traffic from a specific internal IP address range (192.168.123.0 / 24) is forwarded out through the internal network interface eth0, all packets on the outgoing interface are source address translated using the specified external network IP address (192.168.1.120).

[0100] The above rules are used for accessing from the internal network to the external network, to protect the internal network from unauthorized access from the external network and at the same time hide the real IP address of the internal network.

[0101] The system executes the work steps of obtaining the MAC and IP of the switch port terminal as Figure 3 shown below:

[0102] (1) After the controller system starts, it obtains the ARP cache entries through the arp command, and gets the mapping relationship from IP address to MAC address in the local system's ARP cache entries;

[0103] (2) The controller sends a query L2 command for the switch port through the communication serial port and obtains the L2 table information, parses to get the MAC address of the terminal of this port, and by traversing the ARP entries, checks if this MAC address exists. If it exists, parses the ARP entry to get the IP address of this terminal device;

[0104] The system executes the work steps of sending packets to the internal network monitoring platform as Figure 4 shown below:

[0105] (1) The master controller obtains the MAC and IP correspondence table of the switch port, and according to the IP address information, sends ping packets to the switch terminal device in a loop every 1 second;

[0106] (2) If the ping is successful, it indicates that the terminal device is normal; if the ping fails, it indicates that the terminal device is abnormal;

[0107] (3) The controller sends the switching terminal status to the intranet monitoring platform via UDP packets, and the monitoring platform parses the UDP packets to display the status information of each terminal.

[0108] The complete working process of the system is as Figure 5 shown:

[0109] (1) When the system is powered on, the switching system processor starts, initializes the switching chip, operates the I / O level, resets the controller, flowchart step A;

[0110] (2) The switching system runs, flowchart step B;

[0111] (3) After the controller system starts, it runs the DHCP server, configures the Iptables policy, flowchart step 2;

[0112] (4) The terminal device accesses the switching system port, and the switching chip learns the MAC address of the terminal device and saves it in the L2 table, flowchart step C;

[0113] (5) The switching system terminal device sends a DHCP request to the DHCP server, flowchart step b; the DHCP server assigns an IP address to the terminal device after receiving it, flowchart step 3;

[0114] (6) The controller system repeatedly executes the arp command to obtain the ARP cache entries, gets the mapping relationship between the IP address and the MAC address in the local system ARP cache entries, and sends a query switching port L2 command through the communication serial port and obtains the L2 table information, parses to get the MAC address of the terminal on this port, and checks whether this MAC address exists by traversing the ARP entries. If it exists, parses the ARP entry to get the IP address of this terminal device, flowchart steps 4 and D;

[0115] (7) The controller system sends ping packets to the switching port terminal device every 1 second according to the terminal IP address information. If the ping is successful, it means the terminal device is normal; if the ping fails, it means the terminal device is abnormal, flowchart steps 5 and E;

[0116] (8) The controller system repeatedly sends UDP packets to the intranet monitoring platform to report the running status and data of the switching port terminal device, and the intranet detection platform displays the running status of each terminal device, flowchart steps 6 and c;

[0117] Use encryption technology (TLS / SSL) to protect the security of the reported data and the forwarded data; reduce the occupancy of network bandwidth through data aggregation and compression.

[0118] Use the TLS protocol to protect data security. The TLS protocol establishes a secure session through a handshake process that exchanges encryption keys, verifies identities, and negotiates encryption algorithms; submit a Certificate Signing Request (CSR) to a trusted Certificate Authority (CA); after the CA verifies the identity of the requester, issue a server certificate containing information such as the public key, issuer information, and validity period; install the server certificate (.crt or.pem file) and the private key (.key file) on the controller of the switching system.

[0119] The server certificate and private key automatically edit the configuration file of the controller according to the preset URL path, add the URL paths of the server certificate and private key to the corresponding configuration items. To prevent the URL paths from being tampered with, perform verification operations on the URL paths and confirm the integrity of the server certificate and private key. After the integrity is confirmed, store the server certificate and private key in the HSM, set an access control list for the directory where the server certificate and private key are stored, and create multiple virtual certificates to be stored in the corresponding access control lists. Identify the corresponding server certificate and private key through secure matching authentication. After successful identification, restart the server to make the server certificate and private key take effect.

[0120] With the effective server certificate and private key, configure the server certificate and private key for TLS communication, and obtain a ClientHello message containing the supported TLS versions, list of cipher suites, and random number; the server responds with a ServerHello message containing the selected TLS version, cipher suite, random number, as well as the server certificate and private key. At the same time, the server sends a CertificateRequest message; the client and the server exchange private keys and use these private keys to generate a symmetric encryption key for subsequent data encryption; by configuring TLS parameters, test whether the TLS communication of the controller is normal to ensure that a TLS connection can be successfully established, and regularly check the validity period of the certificate.

[0121] (9) The terminal device repeatedly sends packets to the internal network interface eth0 of the controller system, forwards the data to the external network interface eth1 through iptables, and sends the packets to the external network detection platform, flowchart steps 7 and step d;

[0122] (10) The controller saves the operation log data to the eMMC, flowchart step 8;

[0123] (11) The LED lights of the switching system blink periodically to indicate that the system is running normally, flowchart step F.

[0124] The power supply module of the routing switch system proposed by the present invention is as Figures 6 - 7As shown, it includes: a first step-down chip, a second step-down chip, a third step-down chip, a fourth step-down chip, a fifth step-down chip, and a secondary step-down chip;

[0125] Among them, the power output terminals of the first step-down chip, the second step-down chip, the third step-down chip, the fourth step-down chip, and the secondary step-down chip are connected to the power input terminal of the controller; the power input terminal of the secondary step-down chip is connected to the power output terminals of the third step-down chip and the fourth step-down chip;

[0126] The power output terminals of the fourth step-down chip and the fifth step-down chip are connected to the power input terminal of the switching chip.

[0127] As Figures 8 - 9 shown, the controller is also connected to a memory and an eMMC memory;

[0128] The power input terminal of the memory is connected to the power output terminal of the third step-down chip;

[0129] The power input terminal of the eMMC memory is connected to the power output terminal of the fourth step-down chip.

[0130] The data transmission terminals of the eMMC memory are respectively connected to one end of a pull-up resistor through respective connection line branches, and the other ends of the pull-up resistors are commonly connected to the power supply VCCIO501, and the power supply VCCIO501 is obtained by passing the power supply 3.3V through the ferrite bead L18 or the resistor R196.

[0131] The data transmission terminals of the eMMC memory are connected to the power supply through pull-up resistors. Such a connection method ensures that when the data transmission line is not actively driven, it can maintain a determined level state provided by the power supply, thereby enhancing the stability and integrity of the signal.

[0132] The power output terminal of the fourth step-down chip is also connected to the power input terminal of the power supply monitoring chip and the power input terminal of the MCU. The reset signal terminal of the power supply monitoring chip is connected to the reset terminal of the eMMC memory.

[0133] When the power supply monitoring chip detects that the output voltage of the fourth step-down chip is abnormal, it sends an interrupt signal to the MCU, and the MCU controls the fourth step-down chip to stop working to ensure the safety of the system. The MCU includes the processor of the road switch.

[0134] Preferably, the output power supply of the first step-down chip is 1.05V, the output power supply of the second step-down chip is 1.8V, the output power supply of the third step-down chip is 1.5V, the output power supply of the fourth step-down chip is 3.3V, and the output power supply of the fifth step-down chip is 1.18V.

[0135] Preferably, the input power supplies of the first step-down chip, the second step-down chip, the third step-down chip, the fourth step-down chip, and the fifth step-down chip are VCC12V with a voltage value of 12V. The VCC12V is connected to the negative electrode of the voltage stabilizing diode VD4. The positive electrode of the voltage stabilizing diode VD4 is connected to the negative electrode of the TVS diode VD3 and the first end of the fuse FU4. The second end of the fuse FU4 is connected to an external 12V power supply. The positive electrode of the TVS diode VD3 is connected to the power ground.

[0136] The TVS diode is used for overvoltage protection, the fuse is used for short-circuit and overload protection, and the voltage stabilizing diode is used to maintain the stability of the output voltage.

[0137] Preferably, the circuit connections of the first step-down chip, the second step-down chip, the third step-down chip, the fourth step-down chip, and the fifth step-down chip all include:

[0138] The first end of the capacitor C449, the first end of the capacitor C458, the first end of the capacitor C463, the first end of the resistor R339, and the power input terminal VIN of the synchronous step-down converter are connected to the power supply VCC12V. The enable terminal EN of the synchronous step-down converter is connected to the second end of the resistor R339 and the first end of the resistor R340. The internal power supply terminal VCC of the synchronous step-down converter is connected to the first end of the capacitor C468. The mode selection terminal MODE of the synchronous step-down converter is connected to the first end of the resistor R349. The chip select terminal CS of the synchronous step-down converter is connected to the first end of the resistor R350. The bootstrap power supply terminal BST of the synchronous step-down converter is connected to the first end of the resistor R358. The second end of the resistor R358 is connected to the first end of the capacitor C473. The second end of the capacitor C473 is connected to the power switch terminals SW1, SW2 of the synchronous step-down converter and the first end of the inductor L21. The second end of the inductor L21 outputs power. Among them, the inductor L21 serves as the energy storage inductor of the DCDC power supply and cooperates with the MOS transistor inside the DCDC chip to complete voltage conversion; and it is connected to the first end of the capacitor C483, the first end of the resistor R380, the first end of the capacitor C488, the first end of the capacitor C493, and the first end of the capacitor C498.

[0139] The second terminal of capacitor C483 is connected to the first terminal of resistor R137. The second terminal of resistor R137 is connected to the feedback terminal FB of the synchronous buck converter, the second terminal of resistor R380, and the first terminal of resistor R381. The status indication terminal PGOOD of the synchronous buck converter is connected to the first terminal of resistor R366. The second terminal of resistor R366 outputs power supply VCC_VCC1V. The reference terminal REF of the synchronous buck converter is connected to the first terminal of capacitor C478. The ground terminals AGND, PGND1, PGND2 of the synchronous buck converter, the second terminal of capacitor C478, the second terminal of resistor R381, the second terminal of capacitor C488, the second terminal of capacitor C493, the second terminal of capacitor C498, the second terminal of capacitor C449, the second terminal of capacitor C458, the second terminal of capacitor C463, the second terminal of capacitor C468, the second terminal of resistor R340, the second terminal of resistor R349, and the second terminal of resistor R350 are connected to the power supply ground.

[0140] Preferably, the circuit connection of the fourth buck chip further includes:

[0141] The second terminal of inductor L21 is connected to the first terminal of resistor R376. The second terminal of resistor R376 is connected to the positive electrode of light-emitting diode HL6. The negative electrode of light-emitting diode HL6 is connected to the power supply ground.

[0142] The output power supply of the fourth buck chip supplies power to multiple components of the routing switch. Therefore, it is a good idea to design a light-emitting diode (LED) to monitor the status of this power supply. This can ensure that when there is a problem with the power supply, it can be quickly detected through the indication of the LED, thus avoiding potential equipment failures.

[0143] Preferably, the model of the synchronous buck converter is IS6605A.

[0144] Preferably, the circuit connection of the secondary buck chip includes:

[0145] The power supply terminal VCC of linear voltage regulator D12, the first terminal of capacitor C420, the first terminal of capacitor C423, and the first terminal of capacitor C426 are connected to power supply VCC3.3V.

[0146] The input voltage terminal VIN of linear voltage regulator D12, the first terminal of capacitor C428, the first terminal of capacitor C430, the first terminal of capacitor C431, and the first terminal of resistor R334 are connected to power supply VCC1.5V.

[0147] The reference voltage terminal REF of linear voltage regulator D12 is connected to the second terminal of resistor R334 and the first terminal of resistor R335.

[0148] The termination voltage terminal VTT of the linear voltage regulator D12 outputs the power supply PS_DDR3_VTT, and the current value of the power supply PS_DDR3_VTT is up to 2A; it is also connected to the first terminal of the capacitor C436, the first terminal of the capacitor C439, the first terminal of the capacitor C442, and the first terminal of the capacitor C444;

[0149] The ground terminal of the linear voltage regulator D12, the second terminal of the capacitor C420, the second terminal of the capacitor C423, the second terminal of the capacitor C426, the second terminal of the capacitor C428, the second terminal of the capacitor C430, the second terminal of the capacitor C431, the second terminal of the resistor R335, the second terminal of the capacitor C436, the second terminal of the capacitor C439, the second terminal of the capacitor C442, and the second terminal of the capacitor C444 are connected to the power supply ground.

[0150] The circuit design related to data transmission of the routing switch system proposed by the present invention is as Figures 10 - 17 shown, including a controller, an MCU, a switching chip, a network transformer, and a PHY transceiver.

[0151] The data transmission terminal of the controller is connected to the first data transmission terminal of the MCU, and the control terminal of the controller is connected to the controlled terminal of the MCU; the second data transmission terminal of the MCU is connected to the data transmission terminal of the switching chip; the other data transmission terminal of the switching chip is connected to the data transmission terminal of the first network transformer, and the other data transmission terminal of the first network transformer is connected to the terminal device;

[0152] The third data transmission terminal of the MCU is connected to the data transmission terminal of the PHY transceiver, the other data transmission terminal of the PHY transceiver is connected to the data transmission terminal of the second network transformer, and the other data transmission terminal of the second network transformer is connected to the terminal device.

[0153] The MCU (Microcontroller Unit) is connected to the switching chip and is used to process various control tasks and data forwarding instructions of the routing switch; and then it is connected to the terminal device through the network transformer, and the network transformer is used for signal isolation, transmission, and matching; ensuring that the data signal can be stably and reliably transmitted to the terminal device.

[0154] At the same time, the MCU is also connected to the PHY (Physical Layer) transceiver, and the PHY transceiver is used for data transmission and reception at the physical layer; the PHY transceiver is then connected to the external environment through another network transformer to achieve two-way data transmission.

[0155] Adopting a network transformer in the routing switch data transmission circuit can not only isolate electrical signals, protect the safety of equipment, but also improve the data transmission quality and network adaptability.

[0156] Preferably, the switching chip and the first network transformer are several with the same quantity.

[0157] Preferably, the other data transmission end of the first network transformer is connected to the terminal device; the other data transmission end of the second network transformer is connected to the terminal device. The configuration where the MCU is connected to the switching chip, network transformer, and external device in sequence is mainly used for internal network data exchange in the switch. However, if the switch has a gateway function and is configured with corresponding network protocols and routing tables, it can also support data exchange between the internal and external networks to a certain extent. The configuration where the MCU is connected to the PHY transceiver and network transformer in sequence can be used for both internal network data exchange and data exchange between the internal and external networks.

[0158] Preferably, the data end of the controller is connected to the data transmission end of the flash memory, and the other data end of the controller is connected to the data transmission end of the eMMC memory; the power management end of the MCU is connected to the monitoring end of the power monitoring chip.

[0159] Preferably, the circuit connection where the data end of the controller is connected to the data transmission end of the flash memory includes:

[0160] The storage signal end of controller U2 is connected to the data transmission end of flash memory D3.

[0161] The auxiliary power supply end VCCAUX_L10 of controller U2, the first ends of several parallel capacitors are connected to power supply VCC1.8V, and the second ends of the several parallel capacitors are connected to the power supply ground.

[0162] The auxiliary power supply end VCCPAUX_T9 of controller U2, the first ends of several parallel capacitors are connected to power supply VCC1.8V, and the second ends of the several parallel capacitors are connected to the power supply ground.

[0163] The phase-locked loop (PLL) power supply end VCCPLL_H10 of controller U2 is connected to the first end of bead L19 and the first ends of several parallel capacitors. The second end of bead L19 is connected to power supply VCC1.8V, and the second ends of the several parallel capacitors are connected to the power supply ground.

[0164] The core power supply end VCCPINT_R8 of controller U2, the first ends of several parallel capacitors, and the positive electrode of the polarized capacitor are connected to power supply VCC1.05V; the second ends of the several parallel capacitors and the negative electrode of the polarized capacitor are connected to the power supply ground.

[0165] The core power supply end VCCINT_R14 of controller U2, the first ends of several parallel capacitors, and the positive electrode of the polarized capacitor are connected to power supply VCC1.05V; the second ends of the several parallel capacitors and the negative electrode of the polarized capacitor are connected to the power supply ground.

[0166] The memory power supply terminal VCCBRAM_J10 of the controller U2, the first ends of a number of parallel capacitors are connected to the power supply VCC1.05V; the second ends of the number of parallel capacitors and the negative electrode of the polarized capacitor are connected to the power supply ground.

[0167] Preferably, the power management terminal of the controller is connected to the monitoring terminal of the power supply monitoring chip, and the circuit connection includes:

[0168] The status display terminal of the controller U2 is connected to the negative electrode of the light-emitting diode HL7, the positive electrode of the light-emitting diode HL7 is connected to the first end of the resistor R171, and the second end of the resistor R171 is connected to the power supply VCC3.3V;

[0169] The manual reset input MR of the power supply monitoring chip D4 is connected to the first end of the capacitor C7 and the first end of the resistor R170, the second end of the capacitor C7 is connected to the power supply ground, and the second end of the resistor R170, the first end of the capacitor C279, the first end of the capacitor C280, the first end of the resistor R176, and the power supply voltage input terminal VCC of the power supply monitoring chip D4 are connected to the power supply VCC3.3V;

[0170] The reset output terminal RESET of the power supply monitoring chip D4 is connected to the second end of the resistor R176, the first end of the capacitor C281, and the data transmission terminal of the flash memory D3, and the second end of the capacitor C281 is connected to the power supply ground;

[0171] The second end of the capacitor C279 and the ground terminal GND of the power supply monitoring chip D4 are connected to the power supply ground.

[0172] Preferably, it further includes a network serial port transparent transmission chip. The data transmission terminals of the network serial port transparent transmission chip are respectively connected to the data transmission terminals of the network transformer and the data transmission terminals of the level conversion chip. The other data transmission terminal of the level conversion chip is connected to the data transmission terminal of the USB serial port chip. The other data transmission terminal of the USB serial port chip is connected to the data transmission terminal of the common mode filter. The clock signal terminal of the USB serial port chip is connected to the clock signal terminal of the crystal oscillator. The data transmission terminal of the common mode filter is connected to the data transmission terminal of the USB connector.

[0173] The network serial port transparent transmission chip is responsible for converting the data on the network into UART signals for transmission. These UART signals are then sent to the SGM4553 dual-channel high-speed level conversion chip. The SGM4553 makes necessary level adjustments to the UART signals according to the voltage requirements of the receiving end (in this case, the USB serial port chip) to ensure that the signals can be received correctly without error. The level-converted UART signals are then passed to the USB serial port chip, which is responsible for further converting these signals into the USB format for communication with a computer or other USB devices. Before the USB signals are sent to the USB connector, they will first pass through a common-mode filter, which is used to filter out the common-mode noise that may interfere with signal transmission, thereby improving the quality and stability of the signals. Finally, the purified USB signals are connected and communicated with external devices through the USB connector. This process realizes a complete conversion and transmission link from the network to UART signals and then to USB signals.

[0174] Preferably, the circuit connection of the switching chip includes:

[0175] The power supply terminal of the switching chip U22, the first ends of several parallel capacitors are connected to the power supply VCC3.3V, and the second ends of several parallel capacitors are connected to the power supply ground;

[0176] The address terminal A0 of the memory D14 is connected to the first end of the resistor R304, the address terminal A1 of the memory D14 is connected to the first end of the resistor R303, the address terminal A2 of the memory D14 is connected to the first end of the resistor R302, and the second ends of the resistor R304, the resistor R303, and the resistor R302 are connected to the power supply VCC3.3V;

[0177] The power supply terminal VCC of the memory D14, the first end of the capacitor C252, and the first end of the capacitor C256 are connected to the power supply VCC3.3V, and the second ends of the capacitor C252 and the capacitor C256 are connected to the power supply ground; the write protection terminal WP of the memory D14 is connected to the first end of the resistor R305, and the second end of the resistor R305 is connected to the power supply ground;

[0178] The serial clock terminal SCL of the memory D14 and the clock terminal of the switching chip U22 are both connected to the clock control terminal of the MCU, and the serial data terminal SDA of the memory D14 and the data terminal of the switching chip U22 are both connected to the data terminal of the MCU for communication with the slave device on the I2C bus.

[0179] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and purposes of the present invention. The scope of the present invention is defined by the claims and their equivalents.

Claims

1. A domestic routing switch system, characterized in that: include: Controllers, MCUs, switch chips, network transformers and PHY transceivers, The data transmission end of the controller is connected to the first data transmission end of the MCU, and the control end of the controller is connected to the controlled end of the MCU; the second data transmission end of the MCU is connected to the data transmission end of the switching chip; the other data transmission end of the switching chip is connected to the data transmission end of the first network transformer, and the other data transmission end of the first network transformer is connected to the terminal device; The third data transmission end of the MCU is connected to the data transmission end of the PHY transceiver, another data transmission end of the PHY transceiver is connected to the data transmission end of the second network transformer, and another data transmission end of the second network transformer is connected to the terminal device; The number of the switching chips and the number of the first network transformers are the same.

2. A domestic routing switch system according to claim 1, characterized in that: The other data transmission end of the first network transformer is connected to the terminal device; the other data transmission end of the second network transformer is connected to the terminal device.

3. A domestic routing switch system according to claim 1, characterized in that: The data end of the controller is connected to the data transmission end of the flash memory, and the other data end of the controller is connected to the data transmission end of the eMMC memory; the power management end of the MCU is connected to the monitoring end of the power monitoring chip.

4. A domestic routing switch system according to claim 1, characterized in that: The power supply part of the system includes: a first buck chip, a second buck chip, a third buck chip, a fourth buck chip, a fifth buck chip and a secondary buck chip; The power output ends of the first buck chip, the second buck chip, the third buck chip, the fourth buck chip and the secondary buck chip are connected to the power input end of the controller; the power input end of the secondary buck chip is connected to the power output ends of the third buck chip and the fourth buck chip; The power output terminals of the fourth step-down chip and the fifth step-down chip are connected to the power input terminal of the switching chip.

5. A domestic routing switch system according to claim 4, characterized in that: The controller is also connected to the memory and the eMMC memory; The power input terminal of the memory is connected to the power output terminal of the third step-down chip; The power input terminal of the eMMC memory is connected to the power output terminal of the fourth step-down chip.

6. A domestic routing switch system according to claim 4, characterized in that: The controller is also connected to the memory and the eMMC memory; The data transmission ends of the eMMC memory are respectively connected to one end of a pull-up resistor through respective connection line branches, and the other end of the pull-up resistor is commonly connected to a power supply VCCIO501, and the power supply VCCIO501 is obtained by passing the power supply 3.3V through a ferrite bead L18 or a resistor R196.

7. A domestic routing switch system according to claim 4, characterized in that: The controller is also connected to the memory and the eMMC memory; The power output terminal of the fourth step-down chip is also connected to the power input terminal of the power monitoring chip and the power input terminal of the MCU, and the reset signal terminal of the power monitoring chip is connected to the reset terminal of the eMMC memory; When the power monitoring chip detects that the output voltage of the fourth buck chip is abnormal, an interrupt signal is sent to the MCU, and the MCU controls the fourth buck chip to stop working to ensure the safety of the system.

8. A working method of a domestic routing switch system, characterized in that: The following steps are involved: S1, the system is powered on and the MCU of the switching system starts, initializes the switching chip, operates the I / O level, and resets the controller; S2, switching system operation; S3, after the controller system is started, the DHCP server is run and the Iptables policy is configured to achieve internal and external network isolation; S4, the terminal device is connected to the switching system port, the switching chip learns the MAC address of the terminal device and saves it in the L2 table; S5, the switching system terminal device sends a DHCP request to the DHCP server, and the DHCP server assigns an IP address to the terminal device after receiving the request; S6, the system executes to obtain the MAC and IP addresses of the switch port terminal: the controller system executes the arp command cyclically to obtain the ARP cache entry, obtains the mapping relationship between the IP address and the MAC address in the local system ARP cache entry, and sends a query switch port L2 command through the communication serial port to obtain the L2 table information, parses to obtain the MAC address of the terminal on this port, and checks whether this MAC address exists by traversing the ARP entry. If so, parse the ARP entry to obtain the IP address of this terminal device; S7, the controller system sends a ping message to the switch port terminal device every 1 second according to the terminal IP address information. If the ping is successful, it means that the terminal device is normal. If the ping is unsuccessful, it means that the terminal device is abnormal. S8, the controller system cyclically sends UDP messages to the intranet monitoring platform to report the operating status and data of the switching port terminal equipment, and the intranet detection platform displays the operating status of each terminal equipment; S9, the terminal device cyclically sends messages to the controller system intranet interface eth0, forwards the data to the external network interface eth1 through iptables, and sends the message to the external network detection platform; S10, the controller saves the operation log data to the eMMC; S11, the LED lights of the switching system flash periodically, indicating that the system is operating normally.

9. The working method of a domestic routing switch system according to claim 8, characterized in that: The configuration of Iptables strategy to achieve internal and external network isolation includes the following steps: (1) Configure IP forwarding function: Configure a Linux kernel parameter net.ipv4.ip_forward. When its value is 0, it means that IP forwarding is prohibited; when its value is 1, it means that the IP forwarding function is enabled. After it is enabled, data packets are forwarded according to the routing table; (2) Configure iptables port forwarding rules: iptables -t nat -I POSTROUTING -o eth0 -s 192.168.123.0 / 24 -j SNAT --to-source 192.168.1.120; Among them: -t nat means the table to be operated is NAT; -I POSTROUTING means inserting a rule into the POSTROUTING chain; -o eth0 indicates which network interface (output interface) the data packets are to be processed from; -s 192.168.123.0 / 24 indicates the source IP address range of the data packet; -j SNAT means we want to perform source address translation (Source NAT); --to-Source 192.168.1.120 indicates what source address to convert to.

10. The working method of a domestic routing switch system according to claim 8, characterized in that: The system performs the steps of obtaining the MAC and IP addresses of the switch port terminal: (1) After the controller system is started, the ARP cache entry is obtained through the arp command to obtain the mapping relationship between the IP address and the MAC address in the ARP cache entry of the local system; (2) The controller sends a query switch port L2 command through the communication serial port and obtains the L2 table information, parses the MAC address of the terminal on this port, and checks whether this MAC address exists by traversing the ARP entry. If so, parse the ARP entry to obtain the IP address of this terminal device.

11. The working method of a domestic routing switch system according to claim 8, characterized in that: The S8 reports the operation status and data of the switching port terminal device, and further comprises the following steps: Use the TLS protocol to protect data security. The TLS protocol establishes a secure session through a handshake process, which exchanges encryption keys, verifies identities, and negotiates encryption algorithms; submits a certificate signing request to a trusted certificate authority; after the CA verifies the identity of the requester, it issues a server certificate containing the public key, issuer information, validity period, etc.; installs the server certificate and private key on the controller of the switching system; The server certificate and private key are automatically edited in the controller configuration file through the text processing tool according to the preset URL path, and the URL path of the server certificate and private key is added to the corresponding configuration item. In order to prevent the URL path from being tampered with, the URL path is verified and the integrity of the server certificate and private key is confirmed. After the integrity is confirmed, the server certificate and private key are stored in the HSM, and an access control list is set for the directory of the stored server certificate and private key. Multiple virtual certificates are formulated and stored in the corresponding access control list. The corresponding server certificate and private key are identified through security matching authentication. After successful identification, the server is restarted to make the server certificate and private key effective; The server certificate and private key are valid, configured for TLS communication, and a ClientHello message containing supported TLS versions, a list of encryption suites, and a random number is obtained; the server responds with a ServerHello message containing the selected TLS version, encryption suite, random number, and server certificate and private key; at the same time, the server sends a CertificateRequest message; the client and server exchange private keys and use these private keys to generate symmetric encryption keys for subsequent data encryption; by configuring TLS parameters, test whether the controller's TLS communication is normal to ensure that a TLS connection can be successfully established, and regularly check the validity period of the certificate.