General encryption chip research and development design method and device based on national cryptographic algorithm
By establishing unified interface standards and integration specifications in the encryption chip, combining hardware accelerator technology and dynamic resource scheduling, an encryption chip architecture with configurable functions and scalable performance is realized, solving the limitations of the existing technology in functional scalability, computing resource scheduling and security authentication, and achieving efficient and flexible security solutions.
Patent Information
- Application Number
- CN202510031764.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-06-06
AI Technical Summary
Existing encryption chips have limitations in functional scalability, computing resource scheduling and security authentication, and lack of standardization of interface design, single implementation methods of hardware accelerator, and lack of flexibility in the equipment authentication mechanism, making it difficult to adapt to diversified security needs and high load conditions.
By establishing unified interface standards and integration specifications, combining hardware accelerator technology and dynamic resource scheduling mechanisms, an encryption chip architecture with configurable functions and scalable performance is realized. Systematically integrate Guoxin algorithm components, digital signature authentication, secure communication protocols and edge computing environments, adopting flexible resource scheduling strategies and optimized data processing processes.
It achieves improvements in versatility, performance and scalability of encryption chips, meets diverse security needs, ensures the stable operation of the system under high load conditions, and improves chip compatibility and portability.
Smart Images

Figure CN120105979A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data processing, and in particular to a method and device for developing and designing a universal encryption chip based on a national secret algorithm. Background Art
[0002] With the rapid development of the Internet of Things and edge computing, information security has become an important technical challenge. Traditional encryption chips are mainly designed for fixed scenarios, usually using a single encryption algorithm and a fixed authentication mechanism. This design approach has obvious limitations in terms of functional scalability and computing resource scheduling. At the same time, existing encryption chips often implement cryptographic algorithms directly in hardware circuits, lacking flexible algorithm configuration and update mechanisms. In terms of security authentication, existing technologies mostly use static certificate verification methods, which are difficult to adapt to dynamically changing security requirements. In addition, during data transmission, performance bottlenecks and security vulnerabilities are prone to occur due to the lack of a unified security communication protocol and an effective resource scheduling mechanism.
[0003] The existing technology has the following major deficiencies: First, the interface design of encryption chips lacks standardization, which requires additional interface adapter circuits during system integration, increasing hardware complexity and power consumption; second, the implementation method of hardware accelerators is relatively simple, and it is impossible to give full play to the performance advantages of different types of cryptographic algorithms; third, the device authentication mechanism lacks flexibility and is difficult to support diverse authentication requirements; finally, in edge computing scenarios, due to the lack of an effective resource scheduling mechanism, it is difficult to ensure the stable operation of the system under high load conditions. These problems have seriously restricted the promotion and application of encryption chips in new application scenarios. Summary of the invention
[0004] The present invention provides a method and device for the development and design of a universal encryption chip based on the national secret algorithm. By establishing a unified interface standard and integration specification, combined with hardware accelerator technology and dynamic resource scheduling mechanism, an encryption chip architecture with configurable functions and scalable performance is realized. The national secret algorithm components, digital signature authentication, secure communication protocols and edge computing environment are systematically integrated, and the technical problems of existing encryption chips in terms of versatility, performance and scalability are effectively solved through flexible resource scheduling strategies and optimized data processing processes.
[0005] According to the first aspect of the present disclosure, a general-purpose encryption chip research and development design method based on the national secret algorithm is provided, including: standardizing the interface according to the chip function requirements to obtain the chip pin definition scheme and the chip integration specification; integrating the national secret algorithm component with the hardware accelerator according to the chip pin definition scheme and the chip integration specification to obtain the basic cryptographic algorithm unit; performing signature authentication processing on the device certificate through the basic cryptographic algorithm unit, and performing certificate verification according to the chip integration specification to obtain the digital signature authentication unit and the device identity authentication credential; based on the basic cryptographic algorithm unit and the device identity authentication credential, performing encryption protocol processing on the data transmission process to obtain the secure communication protocol unit; performing resource scheduling processing on the computing processing unit and the algorithm container according to the data transmission requirements in the secure communication protocol unit and the chip integration specification to obtain the edge computing environment unit; performing system integration processing on the basic cryptographic algorithm unit, the digital signature authentication unit, the secure communication protocol unit and the edge computing environment unit according to the chip pin definition scheme and the chip integration specification to obtain the edge computing general-purpose encryption chip.
[0006] According to a second aspect of the present disclosure, a general-purpose encryption chip R&D and design device based on a national encryption algorithm is provided, comprising:
[0007] A processing module is used to standardize the interface according to the chip functional requirements to obtain the chip pin definition scheme and chip integration specifications;
[0008] An analysis module, used to perform hardware accelerator integration processing on the national cryptographic algorithm component according to the chip pin definition scheme and the chip integration specification to obtain a basic cryptographic algorithm unit;
[0009] An authentication module, used to perform signature authentication processing on the device certificate through the basic cryptographic algorithm unit, and to perform certificate verification according to the chip integration specification to obtain a digital signature authentication unit and a device identity authentication credential;
[0010] An encryption module, used to perform encryption protocol processing on the data transmission process based on the basic cryptographic algorithm unit and the device identity authentication credential to obtain a secure communication protocol unit;
[0011] A scheduling module, used to perform resource scheduling processing on the computing processing unit and the algorithm container according to the data transmission requirements in the secure communication protocol unit and the chip integration specification to obtain an edge computing environment unit;
[0012] The integrated module is used to perform system integration processing on the basic cryptographic algorithm unit, digital signature authentication unit, secure communication protocol unit and edge computing environment unit according to the chip pin definition scheme and the chip integration specification to obtain a general-purpose encryption chip for edge computing.
[0013] The present invention realizes the standardized processing of interfaces by rationally analyzing the functional requirements of chips, and obtains a unified chip pin definition scheme and integration specification, which not only reduces the complexity of chip design, but also improves the compatibility and portability of chips, and effectively solves the problem of difficult interface adaptation in the prior art. At the same time, based on the chip pin definition scheme and chip integration specification, the national secret algorithm component is integrated with a hardware accelerator to form a complete basic cryptographic algorithm unit, which significantly improves the cryptographic operation performance. The signature authentication processing of the device certificate is realized through the basic cryptographic algorithm unit, and the certificate verification is performed in combination with the chip integration specification, so as to obtain a reliable digital signature authentication unit and device identity authentication credential, which provides security for device access. , and based on the basic cryptographic algorithm unit and device identity authentication credentials, the data transmission process is encrypted and processed to obtain a secure communication protocol unit, which effectively ensures the security and reliability of data transmission. Further, in accordance with the data transmission requirements and chip integration specifications in the secure communication protocol unit, the computing processing unit and the algorithm container are resource scheduled, and an efficient edge computing environment unit is established to achieve optimal configuration of computing resources. Finally, through system integration of the basic cryptographic algorithm unit, digital signature authentication unit, secure communication protocol unit and edge computing environment unit, a general-purpose encryption chip for edge computing with complete functions and excellent performance is formed, which not only meets diverse security needs, but also achieves efficient utilization of computing resources.
[0014] It should be understood that the contents described in the summary of the invention are not intended to limit the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. The accompanying drawings are used to better understand the present solution and do not constitute a limitation of the present disclosure. In the accompanying drawings, the same or similar reference numerals represent the same or similar elements, among which:
[0016] Figure 1 A flowchart of a method for developing and designing a general encryption chip based on a national encryption algorithm according to an embodiment of the present disclosure is shown;
[0017] Figure 2A block diagram of a general encryption chip R&D and design device based on a national encryption algorithm according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0018] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.
[0019] In addition, the term "and / or" in this article is only a description of the association relationship between the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0020] Figure 1 A schematic diagram of a general encryption chip development and design method 100 based on a national encryption algorithm in an embodiment of the present disclosure is shown. Figure 1 As shown, the method 100 includes:
[0021] S110: Standardize the interface according to the chip functional requirements to obtain a chip pin definition solution and a chip integration specification;
[0022] Optionally, the chip interfaces are grouped through interface type analysis to obtain an encryption unit interface group, an authentication unit interface group, a communication interface group and an algorithm scheduling interface group; the signal timing of the encryption unit interface group, the authentication unit interface group, the communication interface group and the algorithm scheduling interface group is processed by protocol definition to obtain an interface signal timing specification; the interface data transmission rate is dynamically configured according to the interface signal timing specification to obtain an interface transmission control parameter = the interface configuration data is register mapped according to the interface transmission control parameter to obtain an interface configuration register group; the data transmission mode is scheduled and controlled through the interface configuration register group to obtain an interface scheduling control mechanism; the interface signal timing specification, the interface transmission control parameter and the interface scheduling control mechanism are unified and standardized to obtain a chip pin definition scheme and a chip integration specification.
[0023] Among them, in the interface grouping stage, the chip interfaces are systematically classified based on the interface functional attributes. The encryption unit interface group is responsible for processing data interactions related to cryptographic operations, including data input ports, key input ports, and operation result output ports. The authentication unit interface group is mainly responsible for device identity authentication and certificate verification functions, and is equipped with certificate data interface, signature value interface, and authentication status interface. The communication interface group is specifically used for external data communication, and is equipped with data transceiver interface, handshake signal interface, and clock synchronization interface. The algorithm scheduling interface group mainly serves the scheduling management of algorithm operation resources, including algorithm selection interface, operation status interface, and interrupt control interface. The signal timing protocol definition link focuses on solving the data transmission synchronization problem between each interface group. For the encryption unit interface group, a strict handshake timing is used to ensure the safe transmission of key data, and the data valid signal must be maintained for at least two clock cycles. The authentication unit interface group adopts a phased authentication mechanism, and each authentication stage has an independent status indication signal. The communication interface group adopts an asynchronous communication protocol, and the reliability of data transmission is guaranteed through a request-response mechanism. The algorithm scheduling interface group adopts an interrupt-driven method to dynamically adjust the signal timing according to the algorithm execution status.
[0024] The dynamic configuration process of the interface data transmission rate involves the calculation and adjustment of multiple key parameters. The transmission rate configuration parameters include the reference clock frequency, frequency division coefficient, baud rate setting, etc. The reference clock frequency determines the operating speed of the entire chip and is usually set in the range of 100MHz to 500MHz. The frequency division coefficient is used to adjust the operating frequency of different interface groups. The encryption unit interface group needs to perform a large number of cryptographic operations, so its frequency division coefficient is small to obtain a higher operating frequency; while the communication interface group dynamically adjusts the frequency division coefficient according to the communication capability of the external device. The baud rate setting is mainly for the serial communication interface, supporting multi-speed configuration from 9600bps to 115200bps. The register mapping link converts the interface configuration parameters into a register address space that can be directly accessed by the hardware. The interface configuration register group includes three categories: control register, status register and data register. The control register is used to set parameters such as the interface working mode and interrupt enable. Each interface group has an independent control register block. The status register reflects the current working status of the interface, including information such as the data transmission completion flag and the error status flag. The data register is used to temporarily store the data to be processed and the processing results.
[0025] The scheduling control mechanism of the data transmission mode is based on the interface configuration register group, and the data transmission process is precisely controlled by reading and writing registers. The transmission modes include polling mode, interrupt mode and direct memory access mode. The polling mode is mainly used in scenarios with small data volume, and the data transmission status is confirmed by continuously querying the status register. The interrupt mode is suitable for sudden data transmission needs. When the data transmission is completed or an error occurs, the processor is notified through an interrupt signal. The direct memory access mode is used for large-scale data transmission, and data can be moved without processor intervention.
[0026] For example, when a piece of data needs to be encrypted, the data to be encrypted is first transmitted through the data input port of the encryption unit interface group, and the encryption key is imported through the key input port. The control register in the interface configuration register group sets the working mode to encryption mode and enables related interrupts. During the encryption process, the status register reflects the encryption progress in real time. When the encryption is completed, the processor is notified by interruption, and the encryption result is read out through the data output port. During the whole process, the interface signal timing strictly follows the pre-defined protocol specification, and the transmission rate is dynamically adjusted according to the amount of data to ensure the efficiency and reliability of data transmission. This interface standardization processing method provides reliable interface support for the hardware implementation of the national secret algorithm through systematic group management, standardized protocol definition, flexible rate configuration, reasonable register mapping and efficient scheduling control. At the same time, the unified interface specification also facilitates the connection between the chip and external devices, improving the versatility and scalability of the chip. In actual applications, the flexible configuration of interface parameters can adapt to different application scenario requirements. In the process of formulating the chip pin definition scheme and integration specification, the characteristics and requirements of different types of national secret algorithms are fully considered, and the corresponding interface resources are set in a targeted manner, while sufficient interface expansion space is reserved.
[0027] S120: Perform hardware accelerator integration processing on the national cryptographic algorithm component according to the chip pin definition scheme and the chip integration specification to obtain a basic cryptographic algorithm unit;
[0028] Optionally, the national secret algorithm components are classified through performance requirement analysis to obtain symmetric encryption components, asymmetric encryption components, cryptographic hash components and block cipher components; the operation instructions of the symmetric encryption components, asymmetric encryption components, cryptographic hash components and block cipher components are processed by instruction pipeline to obtain an algorithm operation instruction stream; the operation data is processed in parallel according to the algorithm operation instruction stream to obtain an algorithm operation acceleration strategy; the data operation units are pipeline cascaded according to the algorithm operation acceleration strategy to obtain a hardware acceleration operation unit; the key data of the hardware acceleration operation unit is securely isolated to obtain a key management mechanism; the key data is distributed and controlled through the key management mechanism to obtain a key scheduling strategy; the algorithm operation acceleration strategy, the hardware acceleration operation unit and the key scheduling strategy are combined according to the chip pin definition scheme and the chip integration specification to obtain a basic cryptographic algorithm unit.
[0029] Among them, the national secret algorithm components mainly include four categories: symmetric encryption components such as SM1 and SM4 algorithms, which are used for data encryption and decryption; asymmetric encryption components such as SM2 algorithm, which are used for key exchange and digital signature; cryptographic hash components such as SM3 algorithm, which are used for message authentication; and block cipher components are used for block encryption processing of large-scale data. This classification method is based on the functional characteristics and performance requirements of the algorithm, and provides a clear direction for the subsequent hardware accelerator design. In the instruction pipeline processing stage, corresponding instruction pipeline structures are designed for different types of algorithm components. Taking the SM4 algorithm as an example, its basic operation instructions include key extension instructions, round function operation instructions, and data transformation instructions. By organizing these instructions into pipelines according to data dependencies, a complete algorithm operation instruction stream is formed. In the specific implementation, the key extension instruction first generates the round key, then the round function operation instruction performs 32 rounds of iterative operations on the data block, and finally the result is output through the data transformation instruction. This pipelined instruction processing method significantly improves the instruction execution efficiency.
[0030] The parallel computing processing link focuses on solving the performance optimization problem of algorithm operations. By analyzing the data dependencies in the algorithm operation instruction stream, the computing units that can be executed in parallel are identified. In the implementation of the SM2 algorithm, the dot multiplication operation can be decomposed into multiple independent modular multiplication operations, which can be executed in parallel. By setting multiple parallel modular multiplication operation units and coordinating appropriate task scheduling strategies, the algorithm's operation speed is significantly improved. At the same time, considering the characteristics of different algorithms, an adaptive parallel degree configuration mechanism is adopted to dynamically adjust the allocation of parallel computing resources according to the actual computing load. The pipeline cascade processing stage mainly solves the coordination problem between data operation units. Based on the aforementioned parallel computing processing results, multiple operation units are cascaded according to the data flow direction. Taking the SM3 algorithm as an example, its message expansion and compression functions can be processed in a pipeline manner. When the first group of messages is expanded, the first group of compression function operations can be started, and the expansion operation of the second group of messages can be started at the same time. This pipeline cascade method significantly improves the data processing throughput.
[0031] The design of the key management mechanism focuses on the security of key data. By setting up an independent key storage area, physical isolation is used to ensure that key data will not be illegally accessed. The key storage area uses a special storage unit with anti-tampering and anti-reading characteristics. At the same time, during the transmission of key data, a dedicated data bus is used to avoid sharing with the ordinary data bus, further improving the security of key data. The key scheduling strategy mainly solves the distribution and update problems of key data. Corresponding key distribution mechanisms are designed for different algorithm components. In the process of symmetric encryption, it is necessary to ensure the synchronization of encryption keys and decryption keys. Asymmetric encryption requires proper management of the use rights of public and private keys. By establishing a complete key life cycle management mechanism, including key generation, distribution, use and destruction, key data is always under control.
[0032] In the process of integrating the basic cryptographic algorithm unit, it is necessary to organically combine the algorithm operation acceleration strategy, hardware acceleration operation unit and key scheduling strategy. According to the chip pin definition scheme, a unified data interface format is designed to ensure that the data interaction between various functional modules complies with the predetermined interface specifications. At the same time, according to the requirements of the chip integration specification, the physical layout of each functional module is reasonably planned, the signal wiring is optimized, and the signal interference is reduced.
[0033] For example, when an encryption request is received, the required key data is first obtained through the key management mechanism, and then the appropriate parallel computing strategy is selected according to the amount of data, and the corresponding hardware acceleration computing unit is started. During the operation, the instruction pipeline ensures the close connection of each operation step, and the data is transmitted between each operation unit according to the predetermined pipeline cascade method. Throughout the process, the key scheduling strategy ensures the safe use of key data until the encryption operation is completed and the result is output. This implementation method based on hardware accelerators has significantly improved the execution efficiency and security of the national encryption algorithm through reasonable algorithm classification, efficient instruction pipeline, flexible parallel computing strategy, optimized pipeline cascade structure and secure key management mechanism.
[0034] S130: Performing signature authentication processing on the device certificate through the basic cryptographic algorithm unit, and performing certificate verification according to the chip integration specification to obtain a digital signature authentication unit and a device identity authentication credential;
[0035] Optionally, the identity information and security parameters in the device certificate are parsed to obtain a certificate data set; the certificate signature data is checked for validity based on the certificate data set to obtain a certificate verification rule; the certificate verification rule is signature calculated by the basic cryptographic algorithm unit to obtain a certificate signature value; the certificate signature value is normalized according to the chip integration specification to obtain standardized authentication data; the certificate authorization information is feature extracted according to the standardized authentication data to obtain a certificate verification result; the credit authority is graded according to the certificate verification result to obtain a device credit level; the certificate verification rule, the standardized authentication data and the device credit level are combined to obtain a digital signature authentication unit; the device identity is authenticated according to the digital signature authentication unit to obtain a device identity authentication credential.
[0036] Among them, the certificate content is systematically parsed and processed. The identity information contained in the device certificate covers basic information such as the device serial number, manufacturer code, product model, etc., and the security parameters include security-related parameters such as key algorithm identification, certificate validity period, and usage restrictions. By performing structured parsing on this information, a certificate data set that is convenient for subsequent processing is formed, laying the foundation for the validity verification of the certificate. The validity verification of the certificate signature data is a key link to ensure the authenticity of the certificate. The verification process first extracts the signature data in the certificate, which is usually generated using the national secret SM2 algorithm. The verification rules include multiple levels: first, the format normative check to ensure that the signature data conforms to the predetermined data format; second, the time validity check to verify whether the certificate is within the validity period; third, the signature algorithm matching check to confirm that the signature algorithm used is consistent with the certificate declaration; and finally, the certificate chain integrity check to verify the integrity of the certificate trust chain. Through these hierarchical verification rules, a complete set of certificate verification rules is formed.
[0037] In the signature calculation and processing stage, the basic cryptographic algorithm unit undertakes the core cryptographic calculation tasks. Based on the SM2 algorithm, the digital signature calculation is performed on the certificate verification rules. The calculation process first uses the SM3 algorithm to calculate the message digest of the certificate content, and then uses the signer's private key to sign the digest value to generate a digital signature value. The signature calculation process strictly follows the national secret algorithm specifications to ensure the standardization and security of the signature results. The standardized processing of certificate signature values is an important part of achieving certificate interoperability. According to the data format requirements defined in the chip integration specification, the original signature value is standardized and converted. This process includes operations such as data format conversion, byte order adjustment, and encoding normalization to ensure that the authentication data conforms to a unified standard format, which facilitates data exchange and processing between different systems.
[0038] Feature extraction of certificate authorization information is the basis for determining device permissions. By analyzing the authorization attribute fields in standardized authentication data, key authorization feature information is extracted. These features include the functional permission range of the device, resource access restrictions, and operation authorization levels. The feature extraction process uses a structured data analysis method to ensure accurate identification and extraction of all relevant authorization information. The hierarchical processing of credit permissions is an important mechanism for achieving differentiated access control. Based on the certificate verification results, a multi-level device credit system is established. The credit level is usually divided into multiple levels, each corresponding to a different scope of permissions and security requirements. Higher credit levels have more system access rights and higher operation permissions, while lower credit levels are subject to more restrictions.
[0039] In the combined processing of the digital signature authentication unit, it is necessary to systematically integrate the certificate verification rules, standardized authentication data and device credit level. The integration process follows the modular design principle to ensure interface matching and data consistency between various functional modules. By establishing a unified data processing process and control mechanism, the organic combination of certificate verification, signature authentication and authorization management is achieved. In the process of generating device identity authentication credentials, the digital signature authentication unit plays a core role. The authentication process first verifies the identity information provided by the device and matches it with the information recorded in the certificate. After the verification is passed, the corresponding identity authentication credential is generated according to the device's credit level. The credential contains key information such as the device's identity information, authorization scope, and validity period, and is attached with a digital signature to ensure its integrity and non-tamperability.
[0040] For example, when a device requests to access the system, it first submits its digital certificate. The system obtains the identity information and security parameters in the certificate through data analysis to form a certificate data set. Then, the validity of the certificate is verified according to the preset verification rules, and the signature value is calculated and normalized through the basic cryptographic algorithm unit. The system analyzes the authorization information in the certificate, determines the trust level of the device, and finally generates a device identity authentication credential containing complete authentication information.
[0041] S140: Based on the basic cryptographic algorithm unit and the device identity authentication credential, the data transmission process is processed by an encryption protocol to obtain a secure communication protocol unit;
[0042] Optionally, the basic cryptographic algorithm unit and the device identity authentication credentials are processed for protocol parameter configuration to obtain basic parameters of the communication protocol; the data transmission frame is encapsulated according to the basic parameters of the communication protocol to obtain a standardized transmission data packet; the protocol layer is divided through the standardized transmission data packet to obtain a layered protocol architecture; the protocol state information is converted according to the layered protocol architecture to obtain a protocol state machine; the transmission data of the protocol state machine is processed for integrity verification to obtain a data verification mechanism; the data transmission process is monitored for abnormalities according to the data verification mechanism to obtain a transmission abnormality handling strategy; the transmission abnormality handling strategy is verified for security through the basic cryptographic algorithm unit to obtain a protocol security policy; the layered protocol architecture, the data verification mechanism and the protocol security policy are integrated to obtain a secure communication protocol unit.
[0043] Among them, the configuration of protocol parameters is based on the basic cryptographic algorithm unit and the device identity authentication credentials. The configuration process involves multiple key parameters: cryptographic algorithm parameters include encryption algorithm type selection, key length setting, operation mode configuration, etc.; authentication parameters include authentication method selection, authentication strength setting, session timeout limit, etc.; communication parameters include transmission rate setting, data packet size configuration, retransmission limit, etc. Through the reasonable configuration of these parameters, a complete communication protocol basic parameter set is formed. The encapsulation processing of data transmission frames is a key link to ensure the standardization of data transmission. The encapsulation process first fragments the original data, and adds a frame header and frame footer to each data fragment. The frame header contains control information such as source address, destination address, data length, sequence number, etc., and the frame footer contains a checksum and end mark. By adopting a unified data frame format, the standardization and reliability of data transmission are ensured. The encapsulated data is transmitted in the form of standardized transmission data packets, which is convenient for processing and forwarding at the network layer.
[0044] Protocol layer division is an important means to achieve functional modular management. Based on the characteristics of standardized transmission data packets, the communication protocol is divided into multiple functional layers: the physical layer is responsible for the transmission of bit streams; the data link layer is responsible for the encapsulation and error control of data frames; the network layer is responsible for the routing and forwarding of data packets; the transport layer is responsible for end-to-end reliable transmission; and the application layer is responsible for the processing of specific business data. Each layer of the protocol has a clear functional definition and interface specification, and complete communication functions are achieved through data transmission between layers. The design of the protocol state machine focuses on the state transition logic in the communication process. Based on the layered protocol architecture, the corresponding state set and transition rules are defined for each layer of the protocol. Taking the transport layer as an example, the states include connection establishment, data transmission, connection disconnection, etc. = The state transition is triggered by specific communication events, such as receiving a connection request, data packet arrival, timeout events, etc. Through the state machine mechanism, precise control and management of the communication process can be achieved.
[0045] The data integrity check mechanism is the basis for ensuring communication reliability. A multi-level check mechanism is designed for the transmission data in the protocol state machine: the frame-level check uses the CRC check code to detect bit errors during the transmission process; the packet-level check uses the checksum mechanism to verify the integrity of the data packet; the message-level check uses the cryptographic hash algorithm to ensure that the entire message cannot be tampered with. This multi-level check mechanism can effectively detect and handle various errors in the transmission process. Abnormal monitoring and processing is an important means to ensure communication reliability. Based on the feedback information of the data verification mechanism, a complete abnormal handling system is established: transmission error handling includes mechanisms such as data retransmission and link reconstruction; protocol abnormal handling includes strategies such as state reset and session recovery; security abnormal handling includes measures such as key update and authentication refresh. Through these abnormal handling strategies, it is ensured that the communication system can cope with various abnormal situations.
[0046] Security verification is a key link to ensure communication security. Through the basic cryptographic algorithm unit, the transmission exception handling strategy is analyzed and verified to ensure that the exception handling process does not introduce new security risks. The verification content includes: the security of the key update mechanism, the integrity of the authentication process, the confidentiality of data transmission, etc. After the verification is passed, a complete protocol security strategy is formed to guide the specific implementation of secure communication.
[0047] In the secure communication protocol unit, the layered protocol architecture, data verification mechanism and protocol security strategy need to be systematically integrated. The integration process follows the modular design principle to ensure interface matching and data consistency between various functional modules. By establishing a unified data processing process and control mechanism, a secure, reliable and efficient communication function can be achieved. For example: when a device initiates a communication request, it first authenticates the device based on the device authentication credential, and configures the communication protocol parameters after verification. During data transmission, the original data is processed by the layered protocol, and corresponding security processing and verification are performed at each layer. If an abnormality is found, it is processed according to the predetermined strategy. The entire communication process is always under the monitoring of the protocol state machine to ensure the security and reliability of communication.
[0048] S150: According to the data transmission requirements in the secure communication protocol unit and the chip integration specification, the computing processing unit and the algorithm container are resource scheduled to obtain an edge computing environment unit;
[0049] Optionally, the data transmission requirements in the secure communication protocol unit are subjected to parameter extraction processing to obtain computing resource demand parameters; the computing processing unit is performance analyzed according to the computing resource demand parameters and the chip integration specifications to obtain computing power distribution data; the algorithm container is spatially divided according to the computing power distribution data to obtain a resource isolation scheme; the computing tasks are prioritized according to the resource isolation scheme to obtain a task scheduling strategy; the computing resources are dynamically allocated according to the task scheduling strategy to obtain a resource load balancing mechanism; the operating status is monitored in real time according to the resource load balancing mechanism to obtain resource utilization data; the computing power distribution data, the task scheduling strategy and the resource utilization data are integrated to obtain an edge computing environment unit.
[0050] Among them, key data transmission requirement parameters are extracted from the secure communication protocol unit. These parameters include multiple dimensions: transmission bandwidth requirements reflect the data transmission rate requirements, delay requirements define the time limit for data processing, concurrency indicates the number of data streams processed simultaneously, and quality of service parameters specify the reliability requirements for transmission. By systematically extracting and analyzing these parameters, a complete set of computing resource requirement parameters is formed, providing a basis for subsequent resource scheduling. The performance analysis of the computing processing unit is the basis for resource scheduling. Based on the computing resource requirement parameters and combined with the hardware resource restrictions in the chip integration specification, the computing processing unit is evaluated in multiple dimensions. The evaluation content includes the computing power of the processor core, the access speed of the storage unit, the transmission bandwidth of the data bus, the response time of the peripheral interface, etc. By establishing a performance evaluation model, the performance indicators of each processing unit are quantitatively analyzed to generate detailed computing power distribution data. These data reflect the processing power and performance characteristics of each computing resource in the system.
[0051] The spatial division of algorithm containers is a key link in achieving resource isolation. Based on the computing power distribution data, the system resources are reasonably divided. The division process takes into account multiple factors: first, functional isolation, ensuring that different types of algorithms run in independent resource spaces; second, performance isolation, to prevent high-load tasks from affecting the normal execution of other tasks; and third, security isolation, to prevent sensitive data from leaking between different containers. Through this systematic spatial division, a complete resource isolation solution is formed. The priority sorting of computing tasks is the core of task scheduling. According to the resource isolation solution, the computing tasks in the system are prioritized and sorted. The evaluation factors include the urgency of the task, the resource demand, the execution time limit, the data dependency, etc. By establishing a task priority evaluation model, each task is assigned an appropriate execution priority to form a complete task scheduling strategy. This priority-based scheduling mechanism ensures that critical tasks can be processed in a timely manner.
[0052] Dynamic allocation of computing resources is an important means to achieve load balancing. Based on the task scheduling strategy, the allocation of system resources is dynamically adjusted. The allocation process adopts an adaptive mechanism: when a processing unit is overloaded, some tasks are migrated to units with lower loads; when new high-priority tasks appear, the resource allocation of existing tasks is appropriately adjusted; when system resources encounter bottlenecks, the resource recovery and redistribution mechanism is started. Through this dynamic adjustment, balanced use of system resources is achieved. Real-time monitoring of the operating status is the basis for system optimization. A complete monitoring system is established for the execution of the resource load balancing mechanism. The monitoring content includes key indicators such as processor usage, memory occupancy, bus bandwidth utilization, and task response time. By collecting and analyzing these data in real time, a detailed resource utilization report is generated to provide data support for system optimization.
[0053] In the edge computing environment unit, it is necessary to systematically integrate computing power distribution data, task scheduling strategies, and resource utilization data. The integration process follows the modular design principle to ensure interface matching and data consistency between various functional modules. By establishing a unified data processing process and control mechanism, an efficient, flexible, and reliable edge computing environment can be achieved.
[0054] For example, when the system receives a new computing task, it extracts resource requirement parameters based on the task characteristics, and then allocates a suitable algorithm container to the task based on the current computing power distribution of the system. During task execution, the system continuously monitors resource usage and dynamically adjusts resource allocation based on the load balancing strategy. If performance bottlenecks or abnormal conditions are found, the corresponding optimization mechanism is triggered to ensure the normal execution of the task. Throughout the process, each processing link works closely together to ensure the efficient operation of the edge computing environment. Through systematic parameter extraction, precise performance analysis, reasonable space division, flexible task scheduling, dynamic resource allocation, and real-time status monitoring, efficient and reliable computing resource management is achieved.
[0055] S160: According to the chip pin definition scheme and the chip integration specification, the basic cryptographic algorithm unit, the digital signature authentication unit, the secure communication protocol unit and the edge computing environment unit are system-integrated to obtain a general-purpose encryption chip for edge computing.
[0056] Optionally, the functional units are divided into modules according to the interface identification information in the chip pin definition scheme to obtain a basic functional unit deployment scheme; the signal timing of the basic cryptographic algorithm unit, the digital signature authentication unit, the secure communication protocol unit and the edge computing environment unit are synchronously configured according to the basic functional unit deployment scheme to obtain system timing configuration data; the signal transmission interface is channel allocated according to the system timing configuration data to obtain a signal transmission channel mapping table; the data transmission requests in the signal transmission channel mapping table are prioritized to obtain data transmission priority rules; the data interaction processes of the basic cryptographic algorithm unit, the digital signature authentication unit, the secure communication protocol unit and the edge computing environment unit are parallel scheduled according to the data transmission priority rules to obtain a system integration scheduling scheme; the system integration process is bus arbitrated according to the system integration scheduling scheme to obtain a general-purpose encryption chip for edge computing.
[0057] Among them, the module division of the functional unit is carried out based on the interface identification information in the chip pin definition scheme. The division process needs to consider several key factors: first, the logical grouping of functional modules, dividing the closely related functional units into the same module group; second, the correlation of signal timing, combining the functional units with synchronization requirements; third, the consistency of data flow, ensuring the rationality of the data transmission path. Through this systematic division method, a complete basic functional unit deployment scheme is formed. The synchronous configuration of signal timing is the basis for ensuring the stable operation of the system. Based on the basic functional unit deployment scheme, the timing parameters of each functional unit are uniformly configured. The configuration content includes clock frequency setting, synchronization signal definition, delay parameter adjustment, etc. In the specific implementation, the clock frequency of the basic cryptographic algorithm unit is usually set higher because it needs to perform intensive data operations; the digital signature authentication unit needs to be synchronized with external devices, and the timing requirements are relatively flexible; the secure communication protocol unit and the edge computing environment unit need to balance the processing performance and power consumption requirements. By establishing a unified timing system, a complete system timing configuration data is formed.
[0058] The allocation of signal transmission channels is the key to optimizing system performance. According to the system timing configuration data, the corresponding transmission channels are allocated to each functional unit. The allocation process takes into account multiple factors: the transmission bandwidth requirement determines the data bit width of the channel, the transmission timing requirement affects the operating frequency of the channel, and the transmission priority determines the arbitration mechanism of the channel. Through reasonable channel allocation, a complete signal transmission channel mapping table is established to ensure the efficiency and reliability of data transmission. The priority sorting of data transmission requests is the basis for achieving efficient scheduling. The transmission requests in the signal transmission channel mapping table are systematically analyzed and sorted. The sorting basis includes: the urgency of the request, such as encryption operation requests usually have a higher priority; the size of the data volume, large-capacity data transmission may require sufficient channel resources to be reserved; the transmission timeliness requirements, and requests with high real-time requirements need to be processed first. Through this multi-dimensional priority evaluation, a complete data transmission priority rule is formed. Parallel scheduling is an important means to improve system processing efficiency. Based on the data transmission priority rule, the data interaction process of each functional unit is scheduled in parallel. The scheduling process uses a multi-level control mechanism: first, task-level parallelism, which allows multiple functional units to execute different tasks simultaneously; second, data-level parallelism, which supports pipeline processing of data; and third, instruction-level parallelism, which optimizes the execution of instructions within the functional unit. Through this multi-level parallel mechanism, an efficient system integration scheduling solution is formed.
[0059] Bus arbitration is a key link in resolving resource competition. Based on the system integration scheduling solution, a complete bus arbitration mechanism is established. The arbitration process adopts a hierarchical processing strategy: high-priority requests can interrupt low-priority transmissions; requests of the same priority are processed in a polling manner; and emergency requests are set up with a dedicated fast channel. Through this flexible arbitration mechanism, the rational use of system resources is ensured, and a complete edge computing universal encryption chip is finally formed.
[0060] For example, when the system receives an encryption request, the secure communication protocol unit first receives and parses the request content, and then verifies the legitimacy of the request through the digital signature authentication unit. After the verification, the basic cryptographic algorithm unit starts to perform encryption operations, while the edge computing environment unit is responsible for resource scheduling and monitoring. During the entire process, each functional unit interacts with data through a pre-configured signal channel, and the system dynamically adjusts resource allocation according to priority rules to ensure the efficiency and reliability of the processing process.
[0061] The above is an introduction to the method embodiment. The following is a further explanation of the disclosed solution through an apparatus embodiment.
[0062] Figure 2 FIG. 2 is a block diagram of a general-purpose encryption chip R&D and design device 200 based on a national encryption algorithm according to an embodiment of the present disclosure. Figure 2 As shown, the device 200 includes:
[0063] The processing module 210 is used to standardize the interface according to the chip function requirements to obtain the chip pin definition scheme and chip integration specifications;
[0064] The analysis module 220 is used to perform hardware accelerator integration processing on the national cryptographic algorithm component according to the chip pin definition scheme and the chip integration specification to obtain a basic cryptographic algorithm unit;
[0065] The authentication module 230 is used to perform signature authentication processing on the device certificate through the basic cryptographic algorithm unit, and to perform certificate verification according to the chip integration specification to obtain a digital signature authentication unit and a device identity authentication credential;
[0066] The encryption module 240 is used to perform encryption protocol processing on the data transmission process based on the basic cryptographic algorithm unit and the device identity authentication credential to obtain a secure communication protocol unit;
[0067] The scheduling module 250 is used to perform resource scheduling processing on the computing processing unit and the algorithm container according to the data transmission requirements in the secure communication protocol unit and the chip integration specification to obtain an edge computing environment unit;
[0068] The integration module 260 is used to perform system integration processing on the basic cryptographic algorithm unit, digital signature authentication unit, secure communication protocol unit and edge computing environment unit according to the chip pin definition scheme and the chip integration specification to obtain a general-purpose encryption chip for edge computing.
[0069] The above specific implementations do not constitute a limitation on the protection scope of the present disclosure. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.
Claims
1. A method for developing and designing a universal encryption chip based on a national secret algorithm, characterized in that: include: Standardize the interface according to the chip functional requirements to obtain the chip pin definition scheme and chip integration specifications; According to the chip pin definition scheme and the chip integration specification, the national cryptographic algorithm component is integrated with the hardware accelerator to obtain a basic cryptographic algorithm unit; Perform signature authentication processing on the device certificate through the basic cryptographic algorithm unit, and verify the certificate according to the chip integration specification to obtain a digital signature authentication unit and a device identity authentication certificate; Based on the basic cryptographic algorithm unit and the device identity authentication credential, the data transmission process is processed by encryption protocol to obtain a secure communication protocol unit; According to the data transmission requirements in the secure communication protocol unit and the chip integration specifications, the computing processing unit and the algorithm container are resource scheduled to obtain an edge computing environment unit; According to the chip pin definition scheme and the chip integration specification, the basic cryptographic algorithm unit, digital signature authentication unit, secure communication protocol unit and edge computing environment unit are system-integrated to obtain a general-purpose encryption chip for edge computing.
2. The method for developing and designing a universal encryption chip based on a national secret algorithm according to claim 1 is characterized in that: The interface is standardized according to the chip functional requirements to obtain a chip pin definition scheme and a chip integration specification, including: The chip interfaces are grouped by interface type analysis to obtain an encryption unit interface group, an authentication unit interface group, a communication interface group, and an algorithm scheduling interface group; Performing protocol definition processing on the signal timing of the encryption unit interface group, the authentication unit interface group, the communication interface group and the algorithm scheduling interface group to obtain an interface signal timing specification; Dynamically configure the interface data transmission rate according to the interface signal timing specification to obtain interface transmission control parameters; Performing register mapping processing on the interface configuration data according to the interface transmission control parameters to obtain an interface configuration register group; Performing scheduling control processing on the data transmission mode through the interface configuration register group to obtain an interface scheduling control mechanism; The interface signal timing specification, the interface transmission control parameter and the interface scheduling control mechanism are uniformly standardized to obtain a chip pin definition scheme and a chip integration specification.
3. The method for developing and designing a universal encryption chip based on a national secret algorithm according to claim 1 is characterized in that: The hardware accelerator integration processing of the national cryptographic algorithm component is performed according to the chip pin definition scheme and the chip integration specification to obtain a basic cryptographic algorithm unit, including: Through performance requirement analysis, the national encryption algorithm components are classified into symmetric encryption components, asymmetric encryption components, cryptographic hash components and block cipher components; Processing the operation instructions of the symmetric encryption component, the asymmetric encryption component, the cryptographic hash component and the block cipher component through an instruction pipeline to obtain an algorithm operation instruction stream; Performing parallel computing on the computing data according to the algorithm computing instruction stream to obtain an algorithm computing acceleration strategy; According to the algorithm operation acceleration strategy, the data operation unit is subjected to pipeline cascade processing to obtain a hardware acceleration operation unit; Performing secure isolation processing on the key data of the hardware acceleration computing unit to obtain a key management mechanism; The key data is distributed and controlled by the key management mechanism to obtain a key scheduling strategy; The algorithm operation acceleration strategy, the hardware acceleration operation unit and the key scheduling strategy are combined and processed according to the chip pin definition scheme and the chip integration specification to obtain a basic cryptographic algorithm unit.
4. The method for developing and designing a universal encryption chip based on a national secret algorithm according to claim 1 is characterized in that: The method of performing signature authentication processing on the device certificate through the basic cryptographic algorithm unit and performing certificate verification according to the chip integration specification to obtain a digital signature authentication unit and a device identity authentication credential includes: Perform data parsing on the identity information and security parameters in the device certificate to obtain a certificate data set; Performing validity verification on the certificate signature data according to the certificate data set to obtain certificate verification rules; Performing signature calculation processing on the certificate verification rule through the basic cryptographic algorithm unit to obtain a certificate signature value; Normalizing the certificate signature value according to the chip integration specification to obtain standardized authentication data; Performing feature extraction processing on the certificate authorization information according to the standardized authentication data to obtain a certificate verification result; The credit authority is graded based on the certificate verification result to obtain the device credit level; Combining the certificate verification rule, the standardized authentication data and the device trust level to obtain a digital signature authentication unit; The device identity is authenticated according to the digital signature authentication unit to obtain a device identity authentication certificate.
5. The method for developing and designing a universal encryption chip based on a national secret algorithm according to claim 1 is characterized in that: The method of performing encryption protocol processing on the data transmission process based on the basic cryptographic algorithm unit and the device identity authentication credential to obtain a secure communication protocol unit includes: Perform protocol parameter configuration processing on the basic cryptographic algorithm unit and the device identity authentication credential to obtain basic communication protocol parameters; Encapsulating the data transmission frame according to the basic parameters of the communication protocol to obtain a standardized transmission data packet; The standardized transmission data packet is processed by performing protocol layer division to obtain a layered protocol architecture. The protocol state information is converted and processed according to the layered protocol architecture to obtain a protocol state machine; The transmission data of the protocol state machine is processed for integrity verification to obtain a data verification mechanism = Performing abnormal monitoring and processing on the data transmission process according to the data verification mechanism to obtain a transmission abnormality processing strategy; Performing security verification processing on the transmission exception handling strategy through the basic cryptographic algorithm unit to obtain a protocol security strategy; The layered protocol architecture, the data verification mechanism and the protocol security policy are integrated to obtain a secure communication protocol unit.
6. The method for developing and designing a universal encryption chip based on a national secret algorithm according to claim 1 is characterized in that: According to the data transmission requirements in the secure communication protocol unit and the chip integration specification, the computing processing unit and the algorithm container are subjected to resource scheduling processing to obtain an edge computing environment unit, including: Performing parameter extraction processing on the data transmission requirements in the secure communication protocol unit to obtain computing resource requirement parameters; Performing performance analysis on the computing processing unit according to the computing resource requirement parameters and the chip integration specification to obtain computing capacity distribution data; Performing spatial partitioning processing on the algorithm container according to the computing power distribution data to obtain a resource isolation solution; Prioritize the computing tasks according to the resource isolation scheme to obtain a task scheduling strategy; Dynamically allocate computing resources according to the task scheduling strategy to obtain a resource load balancing mechanism; Perform real-time monitoring and processing of the operating status according to the resource load balancing mechanism to obtain resource utilization data; The computing power distribution data, the task scheduling strategy and the resource utilization data are integrated and processed to obtain an edge computing environment unit.
7. The method for developing and designing a universal encryption chip based on a national secret algorithm according to claim 1 is characterized in that: According to the chip pin definition scheme and the chip integration specification, the basic cryptographic algorithm unit, the digital signature authentication unit, the secure communication protocol unit and the edge computing environment unit are system-integrated to obtain an edge computing universal encryption chip, including: Perform module division processing on the functional units according to the interface identification information in the chip pin definition scheme to obtain a basic functional unit deployment scheme; According to the basic functional unit deployment plan, synchronously configure the signal timing of the basic cryptographic algorithm unit, the digital signature authentication unit, the secure communication protocol unit and the edge computing environment unit to obtain system timing configuration data; Perform channel allocation processing on the signal transmission interface according to the system timing configuration data to obtain a signal transmission channel mapping table; Prioritize the data transmission requests in the signal transmission channel mapping table to obtain a data transmission priority rule; According to the data transmission priority rule, the data interaction process of the basic cryptographic algorithm unit, the digital signature authentication unit, the secure communication protocol unit and the edge computing environment unit is parallelly scheduled to obtain a system integration scheduling plan; The system integration scheduling scheme is used to perform bus arbitration processing on the system integration process to obtain a general-purpose encryption chip for edge computing.
8. A general-purpose encryption chip R&D and design device based on a national secret algorithm, used to implement a general-purpose encryption chip R&D and design method based on a national secret algorithm as described in any one of claims 1 to 7, characterized in that: The general-purpose encryption chip R&D and design device based on the national secret algorithm includes: A processing module is used to standardize the interface according to the chip functional requirements to obtain the chip pin definition scheme and chip integration specifications; An analysis module, used to perform hardware accelerator integration processing on the national cryptographic algorithm component according to the chip pin definition scheme and the chip integration specification to obtain a basic cryptographic algorithm unit; An authentication module, used to perform signature authentication processing on the device certificate through the basic cryptographic algorithm unit, and to perform certificate verification according to the chip integration specification to obtain a digital signature authentication unit and a device identity authentication credential; An encryption module, used to perform encryption protocol processing on the data transmission process based on the basic cryptographic algorithm unit and the device identity authentication credential to obtain a secure communication protocol unit; A scheduling module, used to perform resource scheduling processing on the computing processing unit and the algorithm container according to the data transmission requirements in the secure communication protocol unit and the chip integration specification to obtain an edge computing environment unit; The integrated module is used to perform system integration processing on the basic cryptographic algorithm unit, digital signature authentication unit, secure communication protocol unit and edge computing environment unit according to the chip pin definition scheme and the chip integration specification to obtain a general-purpose encryption chip for edge computing.