Low-coupling data encryption method and device
By adopting a low-coupled data encryption method in the on-chip system, and encrypting data using multiple sets of encryption modules and preset routing rules, the problem of easy cracking of data encryption in the prior art is solved, and higher security and adaptability are achieved.
Patent Information
- Application Number
- CN202510165185.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-30
AI Technical Summary
The single interface type and encryption module of data encryption algorithms in existing systems on chips are easily cracked by attackers through traversal, resulting in data leakage.
The low-coupled data encryption method is adopted to obtain the data stream to be encrypted from the on-chip system through the preset module interface and package it into a data packet. The packets are routed to multiple sets of encryption modules for encryption according to preset routing rules. Each set of encryption modules uses the same encryption engine but has a unique label. After encryption, the packets are saved to the cache module in the identification order.
It reduces the coupling degree of data encryption in the system on chip, improves the security and adaptability of encryption, enhances the encryption ability of different types of system on chip data, and avoids data leakage.
Smart Images

Figure CN120068168A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computers, and particularly relates to a low-coupling data encryption method and device. Background Art
[0002] In these electronic fields such as computers, in order to pursue higher performance, lower power consumption and smaller occupied area, all necessary components are usually integrated into a unified package named system-on-chip. The system-on-chip has the characteristics of high integration and good flexibility and is widely used in many fields. In the field of information security, the system-on-chip and the security chip are tightly coupled, the data interface type is closely related to the cryptographic module, and one encryption algorithm only supports a single form of data interface, with poor portability. Moreover, the single encryption algorithm corresponding to the single interface type is easily cracked by attackers through traversal means.
[0003] Therefore, how to improve the security of information data in the system-on-chip and avoid being cracked by attackers through traversal means is a technical problem to be solved by those skilled in the art. Summary of the Invention
[0004] The purpose of the present invention is to solve the technical problem of the security of information data in the existing system-on-chip, avoiding being cracked by attackers through traversal means and causing data leakage.
[0005] To achieve the above technical purpose, on the one hand, the present invention provides a low-coupling data encryption method, which includes: In response to an encryption instruction from the main processor, obtain the data stream to be encrypted from the system-on-chip through a preset module interface, and pack and convert the data stream to be encrypted according to a preset format to obtain a converted data packet, where the preset module interface includes various types of system-on-chip interfaces; Route the data packet to the corresponding encryption module in the encryption area for encryption according to a preset routing rule and the identifier of the data packet. The encryption area includes multiple groups of encryption modules, the encryption modules in each group are the same encryption engine, and each group is a different encryption engine; Save the encrypted data packet to the cache module in the order of the identifier.
[0006] Further, the identifier is specifically a number, the encryption module has a unique label, the preset routing rule specifically includes Rule 1 and Rule 2. Rule 1 specifically includes: route the data packet to the encryption module with the unique label being the same as the last two digits of the identifier; Rule 2 specifically includes: the identifier is divided into intervals, and each interval corresponds to one encryption module, and the encryption module is also used to decrypt the encrypted data packet.
[0007] Further, the method further includes: Determine the clock cycles required for different encryption engines to encrypt data packets of the same data length; Use the longest or shortest of the clock cycles as the reference clock cycle, and use the encryption engine corresponding to the reference clock cycle as the reference engine; Adjust the clock signal cycles of non-reference engines based on the reference clock cycle, so that different encryption engines take the same amount of time to encrypt data packets of the same data length.
[0008] Further, the method further includes: When there are at least two data packets that need to be multi-encrypted within a preset time period, use the corresponding data packets as the first data packets; Allocate an encryption module group for each of the first data packets, where the encryption modules in the encryption module group are different, and the encryption engines of the encryption module groups corresponding to each of the first data packets are the same but have different unique labels; Encrypt the first data packets sequentially through the encryption modules in the encryption module group to obtain encrypted data packets.
[0009] Further, the data packet specifically includes a packet header and data, and the packet header specifically includes a protocol type, an identifier, a source module address, and a destination module address.
[0010] Further, different cache areas are divided in the cache module, each cache area corresponds to an encryption module, the cache area is externally connected through a read-write bus, and the read-write bus is externally connected through a preset group of peripheral interfaces.
[0011] On the other hand, the present invention also provides a low-coupling data encryption device, and the device includes: A coprocessor, configured to respond to an encryption instruction from a main processor, obtain a data stream to be encrypted from a system-on-chip through a preset module interface, and perform a packing conversion on the data stream to be encrypted according to a preset format to obtain a converted data packet, where the preset module interface includes multiple types of system-on-chip interfaces; A routing module, configured to route a data packet to a corresponding encryption module in an encryption area for encryption according to a preset routing rule and an identifier of the data packet, where multiple groups of encryption modules are included in the encryption area, the encryption modules within each group are the same encryption engine, and each group is a different encryption engine; A cache control module, configured to save the encrypted data packets to the cache module in the order of the identifiers.
[0012] Further, the routing module is further configured to determine to execute rule one or rule two in the preset routing rules for the data packet.
[0013] A low-coupling data encryption method and device provided by the present invention, compared with the prior art, the method includes: in response to an encryption instruction from a main processor, obtaining a data stream to be encrypted from a system-on-chip through a preset module interface, and packing and converting the data stream to be encrypted according to a preset format to obtain a converted data packet, wherein the preset module interface includes various types of system-on-chip interfaces; routing the data packet to a corresponding encryption module in an encryption area for encryption according to a preset routing rule and an identifier of the data packet, where the encryption area includes multiple groups of encryption modules, the encryption modules within each group are the same encryption engine, and each group is a different encryption engine; saving the encrypted data packets to a cache module in the order of the identifiers. It can reduce the coupling degree of data encryption in the system-on-chip, has strong adaptability, can encrypt data in different types of system-on-chips, has high portability, and at the same time improves the security of encryption, thereby enhancing the security of information data in the system-on-chip. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments described in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0015] Figure 1 The figure shows a schematic flow chart of the low-coupling data encryption method provided by the embodiment of this specification; Figure 2 The figure shows a schematic structural diagram of the low-coupling data encryption device provided by the embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] In order to enable those of ordinary skill in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.
[0017] As Figure 1The following is a schematic flowchart of the low - coupling data encryption method provided by the embodiments of this specification. Although this specification provides the method operation steps or device structures shown in the following embodiments or drawings, based on routine or non - creative labor, more or fewer operation steps or module units may be included in the method or device. In steps or structures where there is no necessary causal relationship logically, the execution order of these steps or the module structure of the device is not limited to the execution order or module structure shown in the embodiments or drawings of this specification. When the method or module structure is applied to an actual device, server, or terminal product, it can be executed sequentially or in parallel according to the method or module structure shown in the embodiments or drawings (for example, in an environment of parallel processors or multi - threaded processing, and even including an implementation environment of distributed processing or server clusters).
[0018] The low - coupling data encryption method provided in the embodiments of this specification can be applied to various systems - on - chip, such as Figure 1 As shown, the method specifically includes the following steps: Step S101: In response to an encryption instruction from the main processor, obtain the data stream to be encrypted from the system - on - chip through a preset module interface, and pack - convert the data stream to be encrypted into a converted data packet according to a preset format, where the preset module interface includes various types of system - on - chip interfaces.
[0019] Specifically, in order to improve the portability of data encryption in the system - on - chip, this application sets a preset module interface. After the coprocessor receives an encryption instruction from the main processor, it obtains the data stream to be encrypted from the system - on - chip through the interface bus. More specifically, a preset module interface is externally connected to the interface bus to adapt to system - on - chips of different interface types, so as to obtain the data stream to be encrypted from system - on - chips of different interface types, and then pack - convert the data stream to be encrypted into a data packet format with data identifiers according to a preset format. Optionally, the data stream to be encrypted can also be converted into data packets of a unified length, such as 128 bits. The data packet specifically includes a packet header and data. The packet header specifically includes a protocol type, an identifier, a source module address, and a destination module address. The identifier is specifically a number, and the encryption module also has a unique label. When the encryption module performs encryption processing, it can calculate according to the data packet, and whether to perform single - layer encryption or multi - layer encryption on the data packet can be determined according to the encryption instruction of the main processor or by the intelligent judgment of the routing module.
[0020] In addition, other systems can also be accessed through the preset module interface bridge.
[0021] Step S102: Route the data packet to the corresponding encryption module in the encryption area for encryption according to the preset routing rule and the identifier of the data packet. The encryption area includes multiple groups of encryption modules. The encryption modules within each group are the same encryption engine, and each group is a different encryption engine.
[0022] Specifically, there are multiple groups of encryption modules in the encryption area of the solution of the present application. Each group of encryption modules is the same encryption engine, and each group is a different encryption engine. The encryption engine can be SM4, SM1, AES, DES, etc., which can be flexibly selected by those skilled in the art according to the actual situation. For example, the encryption engines in group A are all AM4, and the encryption engines in group B are all SM1. The preset routing rule specifically includes Rule 1 and Rule 2. Rule 1 specifically includes: Route the data packet to the encryption module with the same last two digits of the identifier as the unique label; Rule 2 specifically includes: The identifier is divided into intervals, and each interval corresponds to an encryption module. The encryption module is also used to decrypt the encrypted data packet.
[0023] In a specific application scenario, for example, the identifier can be a consecutive number, such as 0x01, 0x02, 0x03, 0x04, …, 0x103, 0x104…0xfff. It can be configured that 0x01, 0x02, 0x03, and 0x04 are respectively routed to encryption engine 01, encryption engine 02, encryption engine 03, and encryption engine 04 for encryption respectively, or the data packet to be encrypted can be routed to encryption engine 01, encryption engine 02, encryption engine 03, and encryption engine 04 in chronological order, and subsequent data packets repeat the above routing allocation in sequence; it can also be configured as follows. For example, there are 256 data packets, each data packet is 128bit. It can be configured that the data packet with the identifier 0 - 63 (decimal) is routed to cryptographic algorithm engine 1, the data packet with the identifier 64 - 127 is routed to cryptographic algorithm engine 2, the data packet with the identifier 128 - 191 is routed to cryptographic algorithm engine 3, and the data packet with the identifier 192 - 255 is routed to cryptographic algorithm engine 4. The identifier is the redundancy of the data, which is stored together when stored, or the identifier encoded according to the stored address information. Decryption and encryption are symmetric. The current description is mainly for the description of the encryption process. For the decryption process, only the order of using the secret key needs to be changed on the basis of the encryption process to change the encryption process to the decryption process.
[0024] In the embodiment of the present application, the method further includes: Determine the clock cycles required for different encryption engines to encrypt data packets of the same data length; Use the longest or shortest of the clock cycles as the reference clock cycle, and use the encryption engine corresponding to the reference clock cycle as the reference engine; Adjust the clock signal period of the non-reference engine based on the reference clock period, so that the time required for different encryption engines to encrypt data packets of the same data length is the same.
[0025] Specifically, to solve the problem that the time required for each encryption engine to encrypt data packets of the same data length is different, this application will adjust the clock periods in different encryption engines. For example, determine the clock periods required for different encryption engines to encrypt data packets of the same data length; then use the longest or shortest of these clock periods as the reference clock period, and use the encryption engine corresponding to the reference clock period as the reference engine; finally, adjust the clock signal period of the non-reference engine based on the reference clock period, so that the time required for different encryption engines to encrypt data packets of the same data length is the same. More specifically, for example, there are AES and SM4 encryption engines, and there are obvious differences in the encryption speeds of the two encryption engines for data packets. Suppose the time required for AES to encrypt a 128-bit packet is 600 clock cycles, while the time required for SM4 to complete the encryption of a 128-bit packet is 1200 clock cycles. Then, by adjusting the clock signal periods of the two encryption engines, for example, adjusting the clock period of AES to be the same as that of SM4, or adjusting the clock period of SM4 to be the same as that of AES, the encryption times of the two encryption engines for data packets of the same length can be synchronized.
[0026] More specifically, for encrypting data packets of the same length (such as 128 bits), some encryption engines require 64 clock cycles, and some engines require 128 clock cycles. The clock of the engine that requires 64 clock cycles can be set to twice the clock period of the latter encryption engine, so that the time error required for the two to perform parallel encryption processing on data packets of the same length (such as 128 bits) is minimized, which is convenient for improving the throughput rate during subsequent routing processing and reducing the waiting time.
[0027] In the embodiment of this application, the method further includes: When there are at least two data packets that need to be multi-encrypted within a preset time period, use the corresponding data packets as the first data packets; Allocate an encryption module group for each of the first data packets, where the encryption modules in the encryption module group are not the same, and the encryption engines corresponding to the encryption module groups of each first data packet are the same but have different unique labels; Encrypt the first data packets sequentially through the encryption modules in the encryption module group to obtain encrypted data packets.
[0028] Specifically, in a specific application scenario, there may be multiple encryption instructions specified in the encryption instruction. When multiple encryption is required for two or more data packets within a preset time period, it may lead to a large difference in encryption time. Therefore, the data packets that need multiple encryption are used as the first data packets, and then an encryption module group is assigned to each first data packet. Among them, the encryption modules in the encryption module group are different. The encryption engines of the encryption module group corresponding to each first data packet are the same but have different unique labels. That is to say, the encryption module group may include encryption engine 01, encryption engine 02, and encryption engine 03, and there is no requirement for the encryption order. After the entire encryption module group has completed execution, the time consumed is close, and the timing impact when writing the data packets into the storage medium in order at the end can be minimized.
[0029] In addition, partial encryption instructions can also be set in the encryption instruction, that is, select some identified data packets to perform encryption operations; and at the user receiving end, according to the matching decryption configuration method, select the encrypted data packets from the data stream and decrypt them. Moreover, when routing the data packets to the encryption module, select an idle encryption module to perform encryption processing. When there is no idle encryption module currently, select the encryption module with the fewest tasks, or select the encryption module that is expected to be idle first.
[0030] Step S103: Save the encrypted data packets to the cache module in the order of the identifiers.
[0031] Different cache areas are divided in the cache module, and each cache area corresponds to an encryption module. The cache area is externally connected through a read-write bus, and the read-write bus is externally connected through a preset peripheral interface group, which can effectively improve the portability of this solution so that it can adapt to on-chip systems or storage systems of different interface types.
[0032] Based on the above low-coupling data encryption method, one or more embodiments of this specification also provide a low-coupling data encryption platform and terminal. The platform or terminal may include devices, software, modules, plugins, servers, clients, etc. that use the method described in the embodiments of this specification and combine necessary implementation hardware devices. Based on the same innovative concept, the systems in one or more embodiments provided by the embodiments of this specification are as described in the following embodiments. Since the implementation schemes of the systems to solve problems are similar to the methods, the implementation of the specific systems in the embodiments of this specification can refer to the implementation of the foregoing methods, and the repeated parts will not be elaborated. The term "unit" or "module" used hereinafter can be a combination of software and / or hardware that can achieve a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, hardware and software combined implementations are also possible and contemplated.
[0033] Specifically, Figure 2It is a schematic diagram of the module structure of an embodiment of the low-coupling data encryption device provided in this specification. As Figure 2 shown, the low-coupling data encryption device provided in this specification includes: A coprocessor 201, configured to, in response to an encryption instruction from a main processor, obtain a data stream to be encrypted from a system-on-chip through a preset module interface, and pack and convert the data stream to be encrypted according to a preset format to obtain a converted data packet, where the preset module interface includes various types of system-on-chip interfaces; A routing module 202, configured to route a data packet to a corresponding encryption module in an encryption area for encryption according to a preset routing rule and an identifier of the data packet, where the encryption area includes multiple groups of encryption modules, the encryption modules within each group are the same encryption engine, and each group is a different encryption engine; A cache control module 203, configured to save the encrypted data packets to a cache module in the order of the identifiers.
[0034] In an embodiment of the present application, the routing module is further configured to determine to execute rule one or rule two in the preset routing rule on the data packet.
[0035] It should be noted that the above device may further include other implementation manners according to the description of the corresponding method embodiment. The specific implementation manner may refer to the description of the corresponding method embodiment above, and will not be elaborated here one by one.
[0036] An embodiment of the present application further provides an electronic device, including: A processor; A memory for storing executable instructions of the processor; The processor is configured to execute the method provided in the above embodiment.
[0037] The electronic device provided by the embodiment of the present application stores the executable instructions of the processor in a memory. When the processor executes the executable instructions, it can, in response to an encryption instruction from the main processor, obtain a data stream to be encrypted from the system-on-chip through a preset module interface, and pack and convert the data stream to be encrypted according to a preset format to obtain a converted data packet. Among them, the preset module interface includes various types of system-on-chip interfaces; route the data packet to the corresponding encryption module in the encryption area for encryption according to a preset routing rule and the identifier of the data packet. The encryption area includes multiple groups of encryption modules, the encryption modules within each group are the same encryption engine, and each group is a different encryption engine; save the encrypted data packet to the cache module in the order of the identifiers. It can reduce the coupling degree of data encryption in the system-on-chip, has strong adaptability, can encrypt data in different types of system-on-chips, has high portability, and at the same time improves the security of encryption, thereby enhancing the security of information data in the system-on-chip.
[0038] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0039] The method or device described in the above embodiments provided by this specification can implement the business logic through a computer program and record it on a storage medium. The storage medium can be read and executed by a computer to achieve the effects of the solutions described in the embodiments of this specification, such as: In response to an encryption instruction from the main processor, obtain a data stream to be encrypted from the system-on-chip through a preset module interface, and pack and convert the data stream to be encrypted according to a preset format to obtain a converted data packet. Among them, the preset module interface includes various types of system-on-chip interfaces; Route the data packet to the corresponding encryption module in the encryption area for encryption according to a preset routing rule and the identifier of the data packet. The encryption area includes multiple groups of encryption modules, the encryption modules within each group are the same encryption engine, and each group is a different encryption engine; Save the encrypted data packet to the cache module in the order of the identifiers.
[0040] The storage medium may include a physical device for storing information, usually by digitizing the information and then storing it in a medium using electrical, magnetic, or optical means. The storage medium may include: devices that store information using electrical energy, such as various memories, such as RAM, ROM, etc.; devices that store information using magnetic energy, such as hard disks, floppy disks, magnetic tapes, magnetic core memories, magnetic bubble memories, USB flash drives; devices that store information using optical means, such as CDs or DVDs. Of course, there are also other types of readable storage media, such as quantum memories, graphene memories, and so on.
[0041] The embodiments of this specification are not limited to those that must conform to industry communication standards, standard computer resource data update and data storage rules, or the situations described in one or more embodiments of this specification. Certain industry standards or implementation schemes slightly modified based on the implementation described by using a custom method or embodiment can also achieve the same, equivalent, or similar, or predictable implementation effects after deformation as the above embodiments. The embodiments obtained by applying these modified or deformed data acquisition, storage, judgment, processing methods, etc. still fall within the scope of the optional implementation schemes of the embodiments of this specification.
[0042] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, application specific integrated circuit (ASIC), programmable logic controller, and embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, the method steps can be logically programmed to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers to achieve the same function. Therefore, such a controller can be regarded as a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.
[0043] The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or plugins can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0044] These computer program instructions can also be loaded onto a computer or other programmable resource data update device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 the steps of the functions specified in one block or multiple blocks.
[0045] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. The relevant parts can refer to the description of the method embodiment. In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representations of the above terms do not have to be the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0046] Those of ordinary skill in the art will realize that the embodiments described here are for helping the reader understand the principles of the present invention. It should be understood that the protection scope of the present invention is not limited to such specific statements and embodiments. Those of ordinary skill in the art can make various other specific deformations and combinations without departing from the essence of the present invention according to these technical revelations disclosed in the present invention. These deformations and combinations are still within the protection scope of the present invention.
Claims
1. A low-coupling data encryption method, characterized in that: The method comprises: In response to an encryption instruction from a main processor, a data stream to be encrypted is obtained from a system on chip through a preset module interface, and the data stream to be encrypted is packaged and converted according to a preset format to obtain a converted data packet, wherein the preset module interface includes multiple types of system on chip interfaces; Routing the data packet to the corresponding encryption module in the encryption area for encryption according to the preset routing rule and the identifier of the data packet, wherein the encryption area includes multiple groups of encryption modules, the encryption modules in each group are the same encryption engine, and each group is a different encryption engine; The encrypted data packets are saved to the cache module in the order of identification.
2. The low-coupling data encryption method according to claim 1, characterized in that: The identifier is specifically a number, the encryption module has a unique label, the preset routing rules specifically include rule one and rule two, the rule one specifically includes: routing the data packet to an encryption module whose unique label is the same as the last two digits of the identifier; the rule two specifically includes: the identifier is divided into intervals, and each interval corresponds to one encryption module, and the encryption module is also used to decrypt the encrypted data packet.
3. The low-coupling data encryption method according to claim 1, characterized in that: The method further comprises: Determine the clock cycles required for different encryption engines to encrypt data packets of the same data length; The longest or shortest clock cycle is used as a reference clock cycle, and the encryption engine corresponding to the reference clock cycle is used as a reference engine; The clock signal period of the non-reference engine is adjusted based on the reference clock period so that the time required for different encryption engines to encrypt data packets with the same data length is the same.
4. The low-coupling data encryption method according to claim 2, characterized in that: The method further comprises: When there are at least two data packets that need to be multi-encrypted within a preset time period, the corresponding data packets are used as the first data packets; Allocating an encryption module group to each of the first data packets, wherein the encryption modules in the encryption module group are different, and the encryption engines of the encryption module group corresponding to each of the first data packets are the same but have different unique numbers; The first data packet is encrypted in sequence by each encryption module in the encryption module group to obtain an encrypted data packet.
5. The low-coupling data encryption method according to claim 1, characterized in that: The data packet specifically includes a packet header and data, and the packet header specifically includes a protocol type, an identifier, a source module address, and a destination module address.
6. The low-coupling data encryption method according to claim 1, characterized in that: The cache module is divided into different cache areas, each cache area corresponds to an encryption module, the cache area is connected to the outside through a read-write bus, and the read-write bus is connected to the outside through a preset peripheral interface group.
7. A low-coupling data encryption device, characterized in that: The device comprises: The coprocessor is used to respond to the encryption instruction from the main processor, obtain the data stream to be encrypted from the system on chip through the preset module interface, and package and convert the data stream to be encrypted according to the preset format to obtain a converted data packet, wherein the preset module interface includes multiple types of system on chip interfaces; A routing module, used for routing the data packet to the corresponding encryption module in the encryption area for encryption according to a preset routing rule and the identifier of the data packet, wherein the encryption area includes multiple groups of encryption modules, the encryption modules in each group are the same encryption engine, and each group is a different encryption engine; The cache control module is used to save the encrypted data packets to the cache module according to the identification order.
8. The low-coupling data encryption device according to claim 7, characterized in that: The routing module is also used to determine whether to execute rule one or rule two in the preset routing rules on the data packet.
Citation Information
Patent Citations
Non-invasive encryption for relational database management systems
CN101288065A
Service key creation and service data encryption method, device and system
CN110166234A
Encryption and decryption system, encryption and decryption control method, computer equipment and storage medium
CN116204911A
Model data processing method, device and equipment
CN117251867A
Blue-tooth intelligent module
CN1536776A