Data transmission encryption device realized based on V-By-One interface
By designing the data transmission encryption device of the FPGA encryption and decryption chip on the V-By-One interface of the high-bandwidth display device, the piracy and information leakage problems caused by the lack of encryption modules in the prior art are solved, and high-security data transmission is achieved.
Patent Information
- Application Number
- CN202510232103.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-10
AI Technical Summary
Existing high-bandwidth display devices such as 4K and 8K TVs/displays lack encryption modules in V-BY-ONE transmission mode, resulting in security issues of piracy and information leakage.
A data transmission encryption device based on the V-By-One interface is designed, including a main control PCB board and a display PCB board, which is equipped with an FPGA encryption chip and an FPGA decryption chip, and the encryption and decryption operations are performed through the V-By-One data line group.
The data transmission encryption of the V-By-One interface is realized, which improves the security of data transmission. It is suitable for encrypted transmission between devices that do not have standard HDCP interfaces, saving computing power and cost, and enhancing data security through deep buried routing.
Smart Images

Figure CN120128676A_ABST
Abstract
Description
Technical Field
[0001] The present invention mainly relates to data transmission technology, and particularly relates to a data transmission encryption device implemented based on a V-By-One interface. Background Art
[0002] Currently, most high-bandwidth display devices, such as 4K and 8K TVs / monitors, adopt the V-BY-ONE transmission method. There is no dedicated encryption module or solution designed for it on the current market. Therefore, the probability of piracy is relatively high, and there are information leakage security problems. In the application scenario where the main control board is connected to the panel, piracy only requires connecting a display screen with DRM protection, and then connecting the V-By-One interface connecting the driver board and the liquid crystal panel in the display screen to a recording device to record and save.
[0003] Therefore, designing a dedicated data transmission encryption device applied to high-bandwidth display devices is a technical problem to be solved. Summary of the Invention
[0004] Based on this, it is necessary to provide a data transmission encryption device implemented based on a V-By-One interface for existing problems.
[0005] An embodiment of the present application provides a data transmission encryption device implemented based on a V-By-One interface, which is characterized by including a main control PCB board and a display PCB board; Wherein, the main control PCB board includes a main control chip and an FPGA encryption chip; the display PCB board includes a display chip and an FPGA decryption chip; Wherein, the first end of the main control chip is connected to the FPGA encryption chip through a first group of V-By-One data lines, and its second end is connected to the display chip through a second group of V-By-One data lines; Wherein, the first end of the FPGA decryption chip is connected to the FPGA encryption chip through a first group of V-By-One data lines, and its second end is connected to the display chip through a first group of V-By-One data lines; Wherein, the first end of the main control chip transmits a first group of data to the FPGA encryption chip, the FPGA encryption chip encrypts the first data and outputs it to the FPGA decryption chip, and the FPGA decryption chip decrypts the encrypted first data and outputs it to the display chip; meanwhile, the second end of the main control chip transmits a second group of data to the display chip; finally, the first data and the second data are merged at the display chip and then output; Wherein, the first data and the second data form a complete data frame.
[0006] Preferably, the main control PCB board internally uses a deep buried wiring method to transmit signals.
[0007] Preferably, the internal of the display PCB board uses a buried trace method to transmit signals.
[0008] Preferably, the FPGA encryption chip encrypts the first data and outputs it to the FPGA decryption chip, including: The first data is accessed through the GTP high-speed input port of the FPGA encryption chip; Encrypt the first data according to the pre-stored encryption algorithm to obtain the encrypted first data; The encrypted first data is output to the FPGA decryption chip through the GTP high-speed output port of the FPGA encryption chip.
[0009] Preferably, the FPGA decryption chip decrypts the encrypted first data and outputs it to the display chip, including: The encrypted first data is accessed through the GTP high-speed input port of the FPGA decryption chip; Decrypt the first data according to the pre-stored decryption algorithm to obtain the first data; The first data is output to the display chip through the GTP high-speed output port of the FPGA decryption chip.
[0010] Preferably, the display chip is a TI-DLPC6540 display chip.
[0011] Preferably, the encryption algorithm is stored in the eFuse area of its corresponding chip.
[0012] Preferably, the decryption algorithm is stored in the eFuse area of its corresponding chip.
[0013] Compared with the prior art, the present invention has the following beneficial effects: (1) The V-By-One signal encryption solution of the present invention not only gives full play to the advantages of large bandwidth and low electromagnetic interference of V-By-One, but also makes up for the blank of encryption protection on the V-By-One interface. It not only improves the security of data transmission, but also helps to achieve encrypted transmission between devices without a standard HDCP interface; (2) Only encrypt the data transmitted by a group of data lines in the V-By-One interface, and transmit the data transmitted by the other group of data lines in the V-By-One interface in plain text. This not only saves computing power and cost, but also achieves the purpose of protecting data from being stolen, thus ensuring data security; (3) The data transmission on the same PCB board adopts the internal buried trace method, which not only increases the difficulty of data theft, but also further protects the secure transmission of data. Description of the Drawings
[0014] Exemplary embodiments of the present invention can be more fully understood by referring to the accompanying drawings below. The drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings, the same reference numerals generally represent the same components or steps.
[0015] Figure 1 FIG. 4 is a schematic structural diagram of a data transmission encryption device implemented based on a V-By-One interface according to an exemplary embodiment of the present application; Figure 2 FIG. 7 is a flowchart of data encryption of a data transmission encryption device implemented based on a V-By-One interface according to an exemplary embodiment of the present application; Figure 3 FIG. 10 is a flowchart of data decryption of a data transmission encryption device implemented based on a V-By-One interface according to an exemplary embodiment of the present application. Detailed Embodiments
[0016] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0017] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and should not be construed as indicating or implying relative importance.
[0018] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0019] In addition, the technical features involved in different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0020] An embodiment of the present application provides a data transmission encryption device implemented based on a V-By-One interface, which will be described below with reference to the accompanying drawings.
[0021] Refer to Figure 1 , which shows a data transmission encryption device implemented based on a V-By-One interface provided by some embodiments of the present application, including a main control PCB board 1 and a display PCB board 2.
[0022] Specifically, the main control PCB board 1 includes a main control chip 12 and an FPGA encryption chip 11, and the display PCB board 2 includes a display chip 22 and an FPGA decryption chip 21.
[0023] In this embodiment, the first end of the main control chip 1 is connected to the FPGA encryption chip 11 through a first group of V-By-One data lines, and its second end is connected to the display chip 22 through a second group of V-By-One data lines; the first end of the FPGA decryption chip 21 is connected to the FPGA encryption chip 11 through a first group of V-By-One data lines, and its second end is connected to the display chip 22 through a first group of V-By-One data lines.
[0024] Specifically, the first end of the main control chip 12 transmits a first group of data to the FPGA encryption chip 11, the FPGA encryption chip 11 encrypts the first data and then outputs it to the FPGA decryption chip 21, and the FPGA decryption chip 21 decrypts the encrypted first data and then outputs it to the display chip 22; at the same time, the second end of the main control chip 12 transmits a second group of data to the display chip 22; finally, the first data and the second data are merged at the display chip 22 and then output; In this embodiment, the first data and the second data form a complete data frame. In this embodiment, before encryption, they are divided into two groups for output. The first group undergoes the encryption and decryption process, and the remaining other data is transmitted normally. The two types of data are essentially the same and can be divided according to needs or according to data categories. It's just that one type undergoes the encryption and decryption process during transmission. It can be understood as a complete data frame, with one part encrypted for transmission and the other part transmitted in plain code. When arriving at the TI display chip, through frame buffer technology, it waits for the two parts to be combined into one and then sent for display.
[0025] Specifically, V-By-One increases the bandwidth by adding data lines. The interface data lines of its different specifications range from 1 group to 32 groups. To be compatible with all specifications of the V-By-One interface, in practical applications, it is possible to default to using the numbered TX0N and TX0P as the first group of data lines.
[0026] In this embodiment, the main control PCB board 1 and the display PCB board 2 adopt a deep buried wiring method to transmit signals. This setting can protect data security to the greatest extent and prevent data from being stolen.
[0027] In this embodiment, the AES key pre-burned into the eFuse area of the FPGA encryption chip is used for the AES-256-CBC (Advanced Encryption Standard with 256-bit key in Cipher Block Chaining mode) algorithm for encryption. Refer to Figure 2 , and the specific process is as follows: 1. Data Preparation Determine the plaintext: the data to be encrypted; Store the key: Determine a 256-bit (32-byte) encryption key and store it in the EFUSE area; Set the initial vector (IV): Determine a 128-bit (16-byte) initial vector for chaining encryption in CBC mode and store it in the EFUSE area.
[0028] 2. Plaintext Padding Specifically, AES is a block cipher algorithm with a block size of 128 bits (16 bytes). If the plaintext length is not a multiple of 16 bytes, padding is required. The commonly used padding method is PKCS#7.
[0029] 3. Data Blocking Divide the padded plaintext into multiple data blocks of 128 bits (16 bytes) each for subsequent use.
[0030] 4. Data Encryption in CBC Mode In CBC mode, each data block depends on the ciphertext of the previous data block, which can enhance security. Specifically, it includes the following: a. Encrypt the first data block: perform an exclusive OR (XOR) operation on the first plaintext block and the IV; then use the AES-256 encryption algorithm to encrypt the XORed data block with the key to generate the first ciphertext block; b. Encrypt subsequent data blocks: perform an exclusive OR (XOR) operation on the current plaintext block and the previous ciphertext block, and then use the AES-256 encryption algorithm to encrypt the XORed data block with the key to generate the current ciphertext block.
[0031] Specifically, the process of AES-256 encryption using a 256-bit key is as follows: 1. Key Expansion First, expand the 256-bit key into the sub-keys required for 14 rounds (each round has a different sub-key), and the size of each sub-key is 128 bits (16 bytes).
[0032] 2. Initial Round In the initial round, the plaintext is XORed with the initial sub-key; 3. Main Rounds AES-256 has 14 main rounds, and each round includes the following four steps: (1) SubBytes: Replace each byte in the state using the S-box; (2) ShiftRows: Cyclically shift the rows of the state to the left.
[0033] (3) MixColumns: Perform a linear mix between the columns (only in the first 13 rounds, this step is not performed in the last round); (4) AddRoundKey: XOR the state with the sub-key of the current round.
[0034] 4. Final Round Finally, in the 14th round, the MixColumns step is omitted, and only the SubBytes, ShiftRows, and AddRoundKey operations are performed.
[0035] Specifically, in this example, the decryption of the FPGA decryption chip also uses the AES-256-CBC algorithm. The decryption process is similar to the encryption process but in the reverse order. Refer to Figure 3 , and the specific implementation process is as follows: 1. Data Preparation Determine the ciphertext: Determine the data to be decrypted.
[0036] Set the key: Set the 256-bit (32-byte) decryption key. Here, it should be noted that for the same data, it must be the same as the key used during encryption.
[0037] Set the initial vector (IV): Set the 128-bit (16-byte) initial vector. Similarly, it must be the same as the IV used during encryption.
[0038] 2. Data Blocking Divide the ciphertext into multiple data blocks of 128 bits (16 bytes) each: 3. Data Decryption in CBC Mode Specifically, the decryption of each data block in CBC mode depends on the previous ciphertext block. The specific decryption process includes: (1) Decrypt the first data block First, use the AES-256 decryption algorithm to decrypt the first ciphertext block to generate intermediate data; then perform an XOR operation on the intermediate data and the IV to obtain the first plaintext block.
[0039] (2) Decrypt subsequent data blocks First, use the AES-256 decryption algorithm to decrypt the current ciphertext block to generate intermediate data; then perform an XOR operation on the intermediate data and the previous ciphertext block to obtain the current plaintext block.
[0040] 4. Plaintext unpadding Since the plaintext was padded before encryption, it is necessary to remove the padding after decryption. Usually, the PKCS#7 padding method is used. Therefore, when removing the padding, it is necessary to check the value of the last byte and remove the corresponding number of padding bytes.
[0041] Specifically, the eFuse (electronic fuse) area refers to the area inside the chip that is specifically used to store permanent data programmed through electronic fuse technology. It has the following characteristics: (1) Irreversibility: Once the eFuse is blown or programmed, the stored data cannot be modified or deleted. This irreversibility makes the eFuse very suitable for storing permanent data that requires high security, such as encryption keys, device identifiers, and configuration parameters; (2) Non-volatility: The data in the eFuse area remains after power-off and will not be lost. This feature makes them very suitable for important information that needs to be stored for a long time; (3) Anti-attack ability: Due to its irreversibility and physical fusing characteristics, it is very difficult to physically attack and reverse engineer the eFuse, and it has strong anti-attack ability.
[0042] In this embodiment, the encryption chip and the decryption chip use AMD Artix series FPGA chips. Use its built-in GTP Transceivers high-speed interface (GTP for short, Gigabit Transceiver with Low Power, GTP is a term proposed in Virtex-5 LXT / SXT, which is a data transmission platform for distributed applications and provides general transmission functions to meet the needs of enterprise-level applications according to requirements) for data transmission, and use its built-in AES encryption module for encryption and decryption operations. The GTP Transceivers high-speed interface has the following characteristics: (1) High bandwidth: The GTP high-speed interface supports data transfer rates of up to several Gbps, capable of meeting the transmission requirements of large amounts of data and high speeds. (2) Low latency: The GTP interface has low latency in data transmission, suitable for applications with high real-time requirements, such as communication and high-speed data processing. (3) Programmability: The programmable feature of the FPGA enables the GTP interface to be customized according to application requirements, supporting complex customized data protocols and logic control.
[0043] Compared with the prior art, the present invention has the following beneficial effects: (1) The signal encryption solution of V-By-One of the present invention not only gives full play to the advantages of large bandwidth and low electromagnetic interference of V-By-One, but also makes up for the blank of encryption protection on the V-By-One interface. It not only improves the security of data transmission, but also helps to achieve encrypted transmission between devices without a standard HDCP interface. (2) Only encrypts the data transmitted on a group of data lines in the V-By-One interface, and the data transmitted on the other group of data lines in the V-By-One interface is transmitted in plain text, which not only saves computing power and cost, but also achieves the purpose of protecting data from being stolen, thus ensuring data security. (3) The data transmission on the same PCB board adopts the method of internal buried wiring, which not only increases the difficulty of data theft, but also further protects the secure transmission of data.
[0044] It should be noted that the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of systems, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0045] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0046] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical or other forms.
[0047] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0048] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0049] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage media include: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks or optical disks and other media that can store program codes.
[0050] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of each embodiment of the present application, and they should all be covered by the scope of the claims and the description of the present application.
Claims
1. A data transmission encryption device based on a V-By-One interface, characterized in that: Including main control PCB board and display PCB board; Among them, the main control PCB board includes a main control chip and an FPGA encryption chip; the display PCB board includes a display chip and an FPGA decryption chip; Wherein, the first end of the main control chip is connected to the FPGA encryption chip through the first V-By-One data line group, and the second end thereof is connected to the display chip through the second V-By-One data line group; Wherein, the first end of the FPGA decryption chip is connected to the FPGA encryption chip through the first V-By-One data line group, and the second end thereof is connected to the display chip through the first V-By-One data line group; The first end of the main control chip transmits the first group of data to the FPGA encryption chip, the FPGA encryption chip encrypts the first data and outputs it to the FPGA decryption chip, the FPGA decryption chip decrypts the encrypted first data and outputs it to the display chip; at the same time, the second end of the main control chip transmits the second group of data to the display chip; finally, the first data and the second data are combined at the display chip and then output; The first data and the second data form a complete data frame.
2. According to claim 1, a data transmission encryption device based on a V-By-One interface is characterized in that: The main control PCB board uses deep buried wiring to transmit signals.
3. According to the data transmission encryption device based on the V-By-One interface of claim 1, it is characterized in that: The display PCB board uses deep buried wiring to transmit signals.
4. According to claim 1, a data transmission encryption device based on a V-By-One interface is characterized in that: The FPGA encryption chip encrypts the first data and outputs it to the FPGA decryption chip, including: The first data is accessed through the GTP high-speed input port of the FPGA encryption chip; Encrypting the first data according to a pre-stored encryption algorithm to obtain the encrypted first data; The encrypted first data is output to the FPGA decryption chip through the GTP high-speed output port of the FPGA encryption chip.
5. According to the data transmission encryption device based on the V-By-One interface of claim 1, it is characterized in that: The FPGA decryption chip decrypts the encrypted first data and outputs it to the display chip, including: The encrypted first data is accessed through the GTP high-speed input port of the FPGA decryption chip; Decrypting the first data according to a pre-stored decryption algorithm to obtain the first data; The first data is output to the display chip through the GTP high-speed output port of the FPGA decryption chip.
6. According to the data transmission encryption device based on V-By-One interface implementation as claimed in claim 1, it is characterized in that: The display chip is TI-DLPC6540.
7. According to claim 4, a data transmission encryption device based on a V-By-One interface is characterized in that: The encryption algorithm is stored in the eFuse area of its corresponding chip.
8. According to the data transmission encryption device based on V-By-One interface implementation as claimed in claim 5, it is characterized in that: The decryption algorithm is stored in the eFuse area of its corresponding chip.