Data processing system
By integrating the security verification module and encryption module into the processor and combining it with the flexible control of the control device, the high cost problem of ASIC chips is solved, low-cost firewall and encryption functions are realized, and the security and reliability of the data processing system are improved.
Patent Information
- Application Number
- CN202510908344.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-14
AI Technical Summary
In the prior art, the design cost of firewall functions based on ASIC chips is relatively high, especially when confidentiality functions are added, resulting in excessively high costs for building data processing systems.
The integrated security verification module and encryption module are used in the processor. The security verification module is used to verify the data security to realize the firewall function, and the encryption module is used to encrypt or decrypt the data. Combined with the control device, the data transmission path is flexibly controlled to realize the firewall and encryption functions.
Firewall and encryption functions are implemented at a relatively low cost, which improves the security and integrity of data transmission, reduces the construction and maintenance costs of the data processing system, and enhances the reliability and fault tolerance of the system.
Smart Images

Figure CN120785587A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a data processing system. BACKGROUND
[0002] In the field of network security, the firewall function is an important line of defense to protect the network from unauthorized access and malicious attacks.
[0003] In the prior art, an Application Specific Integrated Circuit (ASIC) chip is used in the electronic device to implement the firewall function.
[0004] However, the ASIC chip implements the firewall function through hardware logic, and if the security function needs to be added, the ASIC chip needs to be re-customized, which is costly. SUMMARY
[0005] Embodiments of the present application provide a data processing system to implement the firewall function and the encryption function at low cost.
[0006] In a first aspect, embodiments of the present application provide a data processing system, comprising: a first network port, a second network port, a control device, and a processor, wherein,
[0007] The processor is connected with the control device, and the control device is further connected with the first network port and the second network port.
[0008] The first network port is configured to process data of a first network, and the second network port is configured to process data of a second network.
[0009] The control device is configured to control the first network port to be connected with the second network port, or control the processor to be connected with the first network port and the second network port respectively.
[0010] The processor comprises a security verification module and an encryption module, the security verification module is configured to perform security verification on data transmitted by the first network port and the second network port, and the encryption module is configured to perform encryption or decryption on the data transmitted by the first network port and the second network port.
[0011] In some embodiments, the processor comprises a first virtual area, a second virtual area, and a first memory.
[0012] The first virtual area comprises the security verification module.
[0013] The second virtual area comprises the encryption module.
[0014] The first memory is used for data transmission between the security verification module and the encryption module.
[0015] In some embodiments, the system further comprises:
[0016] The security verification module is further configured to store the data that passes the security verification to the first memory, and the encryption module is further configured to obtain the data that passes the security verification from the first memory and decrypt the data that passes the security verification.
[0017] The encryption module is further configured to store the encrypted data to the first memory, and the security verification module is further configured to obtain the encrypted data from the first memory and perform security verification on the encrypted data.
[0018] In some embodiments, when the first network transmits data to the second network, the system comprises:
[0019] The security verification module is configured to perform security verification on the data transmitted by the first network interface and store the data that passes the security verification to the first memory.
[0020] The encryption module is further configured to obtain the data that passes the security verification from the first memory, decrypt the data that passes the security verification, and transmit the decrypted data to the second network interface.
[0021] In some embodiments, when the second network transmits data to the first network, the system comprises:
[0022] The encryption module is further configured to encrypt the data transmitted by the second network interface and store the encrypted data to the first memory.
[0023] The security verification module is further configured to obtain the encrypted data from the first memory, perform security verification on the encrypted data, and transmit the data that passes the security verification to the first network interface.
[0024] In some embodiments, the processor is further configured to obtain the state of the electronic device and transmit a control instruction associated with the state to the control device.
[0025] The control device is further configured to control the first network interface to connect with the second network interface according to the control instruction, or control the processor to connect with the first network interface and the second network interface respectively.
[0026] In some embodiments, the control device comprises a micro control unit and a relay group.
[0027] The micro control unit is connected with the processor and the relay group respectively;
[0028] The relay group is connected with the first network interface, the second network interface and the processor respectively;
[0029] The micro control unit is configured to receive the control instruction associated with the state;
[0030] The micro control unit is further configured to control the relay group according to the control instruction, so as to connect the first network interface with the second network interface, or connect the processor with the first network interface and the second network interface respectively.
[0031] In some embodiments, the state of the electronic device includes a normal state, and the relay group includes a first relay and a second relay;
[0032] The first relay is connected with the first network interface, the processor and the micro control unit respectively;
[0033] The second relay is connected with the second network interface, the processor and the micro control unit respectively;
[0034] The first relay is further connected with the second relay;
[0035] The processor is further configured to send a first instruction associated with the normal state to the micro control unit when the state of the electronic device is the normal state;
[0036] The micro control unit is further configured to control the first relay and the second relay to be disconnected according to the first instruction, so as to connect the processor with the first network interface and the second network interface respectively.
[0037] In some embodiments, the state of the electronic device includes an abnormal state;
[0038] The processor is further configured to send a second instruction associated with the abnormal state to the micro control unit when the state of the electronic device is the abnormal state;
[0039] The micro control unit is further configured to control the first relay and the second relay to be connected according to the second instruction, so as to connect the first network interface with the second network interface.
[0040] In some embodiments, the system further includes a connector;
[0041] The connector is connected with the processor;
[0042] The connector is configured to update the security verification module and the encryption module.
[0043] The data processing system provided by the embodiment of the application comprises a first network port, a second network port, a control device and a processor, wherein the processor is connected with the control device, the control device is further connected with the first network port and the second network port; the first network port is used for processing data of a first network, and the second network port is used for processing data of a second network; the control device is used for controlling the first network port to be connected with the second network port, or controlling the processor to be connected with the first network port and the second network port respectively; the processor comprises a security verification module and an encryption module, the security verification module is used for performing security verification on data transmitted by the first network port and the second network port, and the encryption module is used for performing encryption or decryption on data transmitted by the first network port and the second network port. In the above manner, by integrating the security verification module and the encryption module in the processor, the security verification module can perform security verification on data transmitted by the first network port and the second network port, realize a firewall function, timely intercept abnormal data, and effectively resist network attacks; the encryption module can accurately complete encryption and decryption operations of data, realize an encryption function, and guarantee the confidentiality and integrity of data transmission, and the two modules work together to realize the firewall function and the encryption function at a low cost, thereby significantly reducing the construction cost of the data processing system. BRIEF DESCRIPTION OF DRAWINGS
[0044] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.
[0045] Figure 1 A scene schematic diagram of an electronic device provided by the application;
[0046] Figure 2 A structure schematic diagram of a data processing system provided by the embodiment of the application Figure 1 ;
[0047] Figure 3 A structure schematic diagram of a data processing system provided by the embodiment of the application Figure 2 ;
[0048] Figure 4 A flow schematic diagram of a data processing method provided by the embodiment of the application Figure 1 ;
[0049] Figure 2 A flow schematic diagram of a data processing method provided by the embodiment of the application Figure 6 ;
[0050] Figure 3 A structure schematic diagram of a data processing system provided by the embodiment of the application Figure 7 ;
[0051] Figure 4 A structure schematic diagram of a data processing system provided by the embodiment of the applicationFigure 8 ;
[0052] Figure 5 Structure diagram of a data processing system provided by an embodiment of the present application Figure 9 ;
[0053] Figure 6 Structure diagram of a data processing system provided by an embodiment of the present application Figure 10 ;
[0054] Figure 1 Schematic diagram of a differential pair cross mode of a first network port and a second network port provided by an embodiment of the present application.
[0055] Reference signs:
[0056] 1 - first network port; 2 - second network port; 3 - control device; 4 - processor; 5 - connector; 6 - real-time clock circuit; 7 - low-power memory chip; 8 - embedded memory chip; 9 - power supply circuit;
[0057] 31 - micro control unit; 32 - relay group; 41 - first virtual area; 42 - second virtual area; 43 - first memory;
[0058] 321 - first relay; 322 - second relay.
[0059] The specific embodiments of the present application have been shown by the above-mentioned drawings, and will be described in more detail hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application by any means, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0060] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals represent like elements, unless the context of use indicates otherwise. The following exemplary embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present application as detailed in the appended claims.
[0061] In the field of network security technology, the firewall function is an important line of defense to protect the network from unauthorized access and malicious attacks.
[0062] Figure 1 A scene diagram of an electronic device provided by the present application. As shown in Figure 2 , it includes an electronic device, a first network, and a second network.
[0063] The electronic device is connected to the first network and the second network, respectively.
[0064] The electronic device is configured to receive data of a first network and a second network, and to perform security verification on data transmitted by the first network interface and the second network interface.
[0065] The electronic device is designed based on an Application Specific Integrated Circuit (ASIC) chip. The ASIC chip implements the firewall function through hardware logic, and a specific hardware logic ASIC chip needs to be customized to implement the firewall function, which is costly. If a security function is needed, the ASIC chip needs to be re-customized, which further increases the cost.
[0066] Therefore, the present application provides a data processing system applied to an electronic device. The processor includes a security verification module and an encryption module. The security verification module is configured to perform security verification on data transmitted by the first network interface and the second network interface. The encryption module is configured to encrypt or decrypt data transmitted by the first network interface and the second network interface. In the above manner, the security verification module and the encryption module are integrated in the processor. The security verification module can perform security verification on data transmitted by the first network interface and the second network interface, implement the firewall function, intercept abnormal data in time, and effectively resist network attacks. The encryption module can accurately complete the encryption and decryption operations of the data, implement the encryption function, and guarantee the confidentiality and integrity of the data transmission. The security verification module and the encryption module work together to simultaneously implement the firewall function and the encryption function at a low cost, and significantly reduce the construction cost of the data processing system.
[0067] The technical solutions of the present application and how the technical solutions solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0068] Figure 1 Structure of the data processing system provided by the embodiments of the present application Figure 2 As shown in Figure 2 , the data processing system includes a first network interface 1, a second network interface 2, a control device 3, and a processor 4.
[0069] The data processing system is applied to an electronic device.
[0070] The electronic device is, for example, a network security device, an industrial control device, an Internet of Things device, or the like.
[0071] The processor 4 is, for example, an Advanced RISC Machine (ARM).
[0072] The processor 4 is connected to the control device 3.
[0073] The control device 3 is also connected with the first network port 1 and the second network port 2, specifically, the first end of the control device 3 is connected with the first network port 1 and the second network port 2.
[0074] The first network port 1 is used for processing data of the first network, specifically, the first network port 1 is used for receiving data of the first network.
[0075] The second network port 2 is used for processing data of the second network, specifically, the second network port 2 is used for receiving data of the second network.
[0076] Optionally, the first network can be an external network, and the second network can be an internal network.
[0077] The control device 3 is used for controlling the first network port 1 to be connected with the second network port 2, or the processor 4 to be connected with the first network port 1 and the second network port 2 respectively.
[0078] Specifically, when the control device 3 controls the first network port 1 to be connected with the second network port 2, the processor 4 is disconnected with the first network port 1 and the second network port 2 respectively; when the control device 3 controls the processor 4 to be connected with the first network port 1 and the second network port 2 respectively, the first network port 1 is disconnected with the second network port 2.
[0079] The processor 4 includes a security verification module and an encryption module, the security verification module is used for performing security verification on data transmitted by the first network port 1 and the second network port 2, and the encryption module is used for performing encryption or decryption on data transmitted by the first network port 1 and the second network port 2.
[0080] The security verification software is run in the security verification module, and the encryption software is run in the encryption module.
[0081] Specifically, the security verification software is used for performing security verification on data transmitted by the first network port 1 and the second network port 2. The encryption software is used for performing encryption or decryption on data transmitted by the first network port 1 and the second network port 2.
[0082] Optionally, the encryption software adopts a symmetric encryption technology, has fast encryption and decryption speed, and has low calculation resource occupation in the encryption and decryption process, so that the influence of the encryption or decryption process on the data processing rate can be minimized.
[0083] In Figure 2In an embodiment, the processor includes a security verification module and an encryption module. The security verification module is used to perform security verification on data transmitted through the first and second network ports, and the encryption module is used to encrypt or decrypt data transmitted through the first and second network ports. In the above-described method, the security verification module and the encryption module are integrated into the processor. The security verification module can perform security verification on data transmitted through the first and second network ports, thereby implementing a firewall function, timely intercepting abnormal data, and effectively resisting network attacks. The encryption module can accurately complete data encryption and decryption operations, implement encryption functions, and ensure the confidentiality and integrity of data transmission. The two work together to simultaneously implement firewall functions and encryption functions at a relatively low cost, significantly reducing the cost of setting up the data processing system.
[0084] In addition, Figure 3 In an embodiment, the control device is used to control the connection between the first network port and the second network port, or to control the connection between the processor and the first network port and the second network port, respectively. In the above method, the control device, with its flexible and intelligent control mechanism, can accurately switch the data transmission path. It can directly establish a connection channel between the first network port and the second network port to achieve rapid direct data transmission; it can also connect the processor between the first network port and the second network port to perform data security verification and encryption and decryption processing. In the event of a malfunction in the electronic device, the control device can quickly activate the bypass (BYPASS) function to directly control the direct connection between the first network port and the second network port, ensuring that the link between the first network and the second network is unobstructed, thereby enhancing the reliability and stability of the data processing system.
[0085] The following combination Figure 2 ,exist Figure 3 Based on the embodiments, the processor is further described.
[0086] Figure 2 Schematic diagram of the structure of the data processing system provided in the embodiment of the present application Figure 3 ,like Figure 3 As shown, the processor 4 includes a first virtual area 41 , a second virtual area 42 , and a first memory 43 .
[0087] The processor 4 creates a first virtual area 41 and a second virtual area 42 on the processor 4 through a virtualization manager (Hypervisor) in the processor 4 .
[0088] The hypervisor may allocate independent computing resources of the processor 4 to the first virtual area 41 and the second virtual area 42 respectively.
[0089] Optionally, computing resources include but are not limited to CPU, running memory, and storage space.
[0090] Optionally, the first virtual area 41 and the second virtual area 42 independently run complete operating systems.
[0091] The first virtual area 41 includes a security verification module, and the second virtual area 42 includes an encryption module.
[0092] The first virtual area 41 includes a security verification module, which can be understood as running in the first virtual area 41. The second virtual area 42 includes an encryption module 42, which can be understood as running in the second virtual area 42.
[0093] Optionally, the hypervisor may also monitor the load of computing resources of the first virtual area 41 and the second virtual area 42 , and update the computing resources of the first virtual area 41 and the second virtual area 42 according to the load of computing resources of the first virtual area 41 and the second virtual area 42 .
[0094] The first memory 43 is used for data transmission between the first virtual area 41 and the second virtual area 42 .
[0095] Specifically, the first memory 43 is used for data transmission between the security verification module and the encryption module.
[0096] The first memory 43 may be referred to as a shared memory or a shared buffer.
[0097] Both the security verification module and the encryption module can perform data reading operations and data writing operations on the first memory 43 to achieve data transmission between the security verification module and the encryption module.
[0098] Specifically, the security verification module is used to store the data that has passed the security verification in the first memory 43, and the encryption module is used to obtain the data that has passed the security verification in the first memory 43 and decrypt the data that has passed the security verification.
[0099] Specifically, the encryption module is used to store the encrypted data in the first memory 43, and the security verification module is used to obtain the encrypted data in the first memory 43 and perform security verification on the encrypted data.
[0100] exist Figure 3 In one embodiment, a processor includes a first virtual area, a second virtual area, and a first memory; the first virtual area includes a security verification module; the second virtual area includes an encryption module; and the first memory is used for data transmission between the security verification module and the encryption module. In this embodiment, the security verification module and the encryption module operate independently in the first and second virtual areas, respectively, without interfering with each other. If the security verification module fails, the encryption module can continue to operate independently, ensuring that the encryption function is not affected. Conversely, if the encryption module fails, the security verification module can also operate independently, ensuring that the firewall function is not affected, thereby improving the fault tolerance of the data processing system.
[0101] existFigure 4 The embodiments are based on the following Figure 5 and Figure 4 The data processing method suitable for the data processing system is described in detail.
[0102] The following Figure 4 The data processing method provided by the embodiments of the present application is used for sending data from the first network to the second network.
[0103] Figure 1 The flowchart of the data processing method provided by the embodiments of the present application is shown in Figure 4 As Figure 4 shown, the method comprises the following steps.
[0104] S401, the first network port receives data of the first network.
[0105] The first network is, for example, an external network.
[0106] S402, the control device controls the first network port to be connected with the second network port, or the processor is controlled to be connected with the first network port and the second network port respectively.
[0107] When the control device controls the first network port to be connected with the second network port, S403-S404 are executed, and when the control device controls the processor to be connected with the first network port and the second network port respectively, S405-S408 are executed.
[0108] In some embodiments, the control device controls the first network port to be connected with the second network port, or the processor is controlled to be connected with the first network port and the second network port respectively, comprising:
[0109] The processor acquires the state of the electronic device and sends a control instruction associated with the state to the control device;
[0110] The control device controls the first network port to be connected with the second network port, or the processor is controlled to be connected with the first network port and the second network port respectively according to the control instruction.
[0111] The state of the electronic device comprises a normal state and an abnormal state.
[0112] In some embodiments, the control device controls the first network port to be connected with the second network port, comprising:
[0113] When the state of the electronic device acquired by the processor is the abnormal state, the processor sends a second instruction associated with the abnormal state to the control device;
[0114] The first network port is controlled to be connected with the second network port according to the second instruction.
[0115] In some embodiments, the control device controls the first network port to be connected with the second network port, comprising:
[0116] The processor sends a first instruction associated with the normal state to the control device when the state of the electronic device is the normal state.
[0117] The control device controls the processor to connect with the first network port and the second network port according to the first instruction.
[0118] S403, the first network port sends the data of the first network to the second network port.
[0119] The first network port sends the data of the first network to the second network port, so as to realize the BYPASS function when the state of the electronic device is the abnormal state, that is, the first network port is directly connected with the second network port.
[0120] S404, the second network port sends the data of the first network to the second network.
[0121] The second network is, for example, an intranet.
[0122] S405, the first network port transmits the data of the first network to the processor.
[0123] S406, a security verification module in the processor performs security verification on the data transmitted by the first network port, and stores the data that passes the security verification to the first memory.
[0124] Optionally, the security verification module performs security verification on the data transmitted by the first network port, which can be that the security verification module performs security verification on the data transmitted by the first network port according to a preset security verification rule.
[0125] The preset security verification rule includes but is not limited to one or more of the following: data format verification, data authority verification, data content compliance verification, or data source legality verification.
[0126] Optionally, when the security verification fails, the security verification module discards the data that fails the security verification.
[0127] Optionally, when the data that fails the security verification is discarded, the security verification module can also record the discard information of the data that fails the security verification in a log.
[0128] The discard information of the data includes but is not limited to one or more of the following: the reason why the data fails the security verification, the time when the data is discarded, or the data identifier of the data.
[0129] The reason why the security verification fails is, for example, that the data format verification fails, or the data format verification and the data authority verification fail.
[0130] In some embodiments, the processor can determine whether the security verification module is running normally.
[0131] In some embodiments, before the security verification module in the processor performs security verification on the data transmitted by the first network port, the method comprises:
[0132] The processor determines whether the security verification module is operating normally;
[0133] When the security verification module is operating normally, S406 is performed;
[0134] When the security verification module is not operating normally, the data transmitted by the first network port is stored in the first memory, and S407 is performed.
[0135] S407, the encryption module in the processor acquires the data that has passed the security verification from the first memory, decrypts the data that has passed the security verification, and sends the decrypted data to the second network port.
[0136] S408, the second network port sends the decrypted data to the second network.
[0137] In some embodiments, Figure 5 In the embodiments, when the control device controls the processor to be connected to the first network port and the second network port respectively, the security verification module in the processor performs security verification on the data transmitted by the first network port, and stores the data that has passed the security verification in the first memory; the encryption module in the processor acquires the data that has passed the security verification from the first memory, decrypts the data that has passed the security verification, and sends the decrypted data to the second network port. In the above method, when the external network (the first network) sends data to the internal network (the second network), the data is subjected to double verification through the security verification of the security verification module and the decryption of the encryption module in turn, so that the security protection of the data is ensured, and the risk of failure of the electronic device is reduced.
[0138] The following Figure 5 For the data processing method provided by the embodiments of the present application when the second network sends data to the first network.
[0139] Figure 2 The flowchart of the data processing method provided by the embodiments of the present application Figure 5 As Figure 5 shown, the method comprises:
[0140] S501, the second network port receives data of the second network.
[0141] S502, the control device controls the first network port to be connected to the second network port, or controls the processor to be connected to the first network port and the second network port respectively.
[0142] When the control device controls the first network port to be connected to the second network port, S503-S504 are performed; when the control device controls the processor to be connected to the first network port and the second network port respectively, S505-S508 are performed.
[0143] The specific implementation process is the same as that of S402, which will not be described here.
[0144] S503, the second network port sends data of the second network to the first network port.
[0145] The second network port sends data of the second network to the first network port, so as to realize the BYPASS function when the state of the electronic device is the abnormal state, that is, the first network port is directly connected with the second network port.
[0146] S504, the first network port sends the data of the second network to the first network.
[0147] S505, the second network port transmits the data of the second network to the processor.
[0148] S506, an encryption module in the processor encrypts the data transmitted by the second network port, and stores the encrypted data into the first memory.
[0149] S507, a security verification module in the processor acquires the encrypted data from the first memory, performs security verification on the encrypted data, and sends the data after security verification to the first network port.
[0150] The specific implementation process is similar to that of S406, which will not be described here.
[0151] In some embodiments, before the security verification module in the processor acquires the encrypted data from the first memory, the method comprises:
[0152] The processor judges whether the security verification module is normally running or not.
[0153] When the security verification module is normally running, S507 is performed.
[0154] When the security verification module is abnormally running, the processor acquires the encrypted data from the first memory, and sends the encrypted data to the first network port, and S508 is performed.
[0155] S508, the first network port sends the data after security verification to the first network.
[0156] When the security verification module is abnormally running, the first network port sends the encrypted data to the first network.
[0157] In Figure 6In this embodiment, when the control device controls the processor to connect to the first and second network ports, respectively, the encryption module in the processor encrypts data transmitted from the second network port and stores the encrypted data in the first memory. The security verification module in the processor retrieves the encrypted data from the first memory, performs security verification on the encrypted data, and transmits the verified data to the first network port. In this method, when data is transmitted from the intranet (the second network) to the extranet (the first network), it undergoes dual verification, sequentially through encryption by the encryption module and security verification by the security verification module. This ensures data security and reduces the risk of electronic device failure.
[0158] The following combination Figure 3 ,exist Figure 6 Based on the embodiments, the control device is further described.
[0159] Figure 3 Schematic diagram of the structure of the data processing system provided in the embodiment of the present application Figure 6 ,like Figure 6 As shown, the control device 3 includes a microcontroller unit (MCU) 31 and a relay group 32 .
[0160] The micro control unit 31 is connected to the processor 4 and the relay group 32 respectively.
[0161] The relay group 32 is connected to the first network port 1 , the second network port 2 , and the processor 4 respectively.
[0162] Optionally, the relay group 32 and the processor 4 are connected in sequence through a gigabit transformer and a physical layer interface chip (Physical Layer Device, PHY).
[0163] The micro control unit 31 is used to receive control instructions associated with the state.
[0164] The micro control unit 31 is further configured to control the relay group 32 according to a control instruction so that the first network port 1 is connected to the second network port 2 , or so that the processor 4 is connected to the first network port 1 and the second network port 2 respectively.
[0165] Specifically, the micro control unit 31 controls the relay group 32 to be engaged according to the control instruction, thereby connecting the first network port 1 to the second network port 2 , or the processor 4 is connected to the first network port 1 and the second network port 2 , respectively.
[0166] In some embodiments, when the electronic device is powered on, the micro control unit 31 can complete startup in milliseconds and control the relay group 32 to connect the first network port 1 to the second network port 2 .
[0167] After the electronic device is powered on stably, the micro control unit 31 controls the relay group 32 according to the control instruction, so as to connect the first network port 1 with the second network port 2, or connect the processor 4 with the first network port 1 and the second network port 2 respectively.
[0168] In Figure 7 In the embodiment, the control device comprises a micro control unit and a relay group; the micro control unit is connected with the processor and the relay group respectively; the relay group is connected with the first network port, the second network port and the processor respectively; the micro control unit is used for receiving the control instruction associated with the state; the micro control unit is also used for controlling the relay group according to the control instruction, so as to connect the first network port with the second network port, or connect the processor with the first network port and the second network port respectively. In the above manner, the control device adopts the architecture of the micro control unit and the relay group, and controls the relay group through the micro control unit, so as to flexibly switch the connection state among the first network port, the second network port and the processor, which can not only establish the direct connection channel between the first network port and the second network port, and realize the BYPASS function, but also can connect the processor into the link, and realize the data security verification and encryption and decryption processing, so as to ensure the realization of the BYPASS function, and improve the system fault tolerance capability.
[0169] In addition, when the electronic device is powered on, the processor has a 2-3 second start-up blank period due to the complex start-up process, during which the processor cannot send the control instruction associated with the state to the control unit, while the micro control unit can complete the start-up in milliseconds, control the relay group to connect the first network port with the second network port, avoid the communication interruption between the networks, and ensure the normal communication between the first network and the second network.
[0170] The following will be described in combination with Figure 4 In Figure 7 the embodiment, the relay group is further described.
[0171] Figure 7 The structure schematic of the data processing system provided by the embodiment of the present application is shown in Figure 8 As shown in Figure 7 The relay group 32 comprises a first relay 321 and a second relay 322.
[0172] The first relay 321 is connected with the first network port 1, the processor 4 and the micro control unit 31 respectively, the second relay 322 is connected with the second network port 2, the processor 4 and the micro control unit 31 respectively, and the first relay 321 is also connected with the second relay 322.
[0173] Specifically, a first general purpose input / output (GPIO) pin of the micro control unit 31 is connected with the first relay 321, a second GPIO pin of the micro control unit 31 is connected with the second relay 322, and a third GPIO pin and a universal asynchronous receiver / transmitter (UART) pin of the micro control unit 31 are connected with the processor 4 respectively.
[0174] In some embodiments, the processor 4 is further configured to send, to the micro control unit 31, a first instruction associated with the normal state when the state of the electronic device is the normal state; and the micro control unit 31 is further configured to control the first relay 321 and the second relay 322 to be disconnected according to the first instruction, so that the processor is connected with the first network interface 1 and the second network interface 2 respectively.
[0175] When the first relay 321 and the second relay 322 are disconnected, the first relay 321 controls the first network interface 1 to be connected with the processor 4, and the second relay 322 controls the second network interface 2 to be connected with the processor 4.
[0176] Optionally, the processor 4 is further configured to send, to the micro control unit 31, the first instruction associated with the normal state through the third GPIO pin or the UART pin when the state of the electronic device is the normal state.
[0177] Optionally, the micro control unit 31 is further configured to control the first relay 321 and the second relay 322 to be disconnected through the first GPIO pin and the second GPIO pin of the micro control unit 31 according to the first instruction.
[0178] In some embodiments, the processor 4 is further configured to send, to the micro control unit 31, a second instruction associated with the abnormal state when the state of the electronic device is the abnormal state; and the micro control unit 31 is further configured to control the first relay 321 and the second relay 322 to be connected according to the second instruction, so that the first network interface 1 is connected with the second network interface 2.
[0179] When the first relay 321 and the second relay 322 are connected, the first relay 321 controls the first network interface 1 to be disconnected with the processor 4, and the second relay 322 controls the second network interface 2 to be disconnected with the processor 4.
[0180] Optionally, the processor 4 is further configured to send, to the micro control unit 31, the second instruction associated with the abnormal state through the third GPIO pin or the UART pin when the state of the electronic device is the abnormal state.
[0181] Optionally, the micro control unit 31 is further configured to control the connection between the first relay 321 and the second relay 322 through the first GPIO pin and the second GPIO pin of the micro control unit 31 according to the first instruction.
[0182] exist Figure 8 In an embodiment, when the state of the electronic device is normal, the second instruction sent by the processor drives the microcontroller unit to control the first relay and the second relay to be disconnected, and the processor is cut into the link between the first network port and the second network port to perform security verification and encryption or decryption operations on the data. When the state of the electronic device is abnormal, the second instruction sent by the processor drives the microcontroller unit to control the first relay and the second relay to be connected, so that the first network port and the second network port are directly connected, realizing the BYPASS function, and greatly improving the reliability, flexibility and risk resistance of the data processing system.
[0183] In some embodiments, the data processing system of the present application further includes: a connector.
[0184] The following combination Figure 5 ,exist Figure 8 Based on the embodiments, the data processing system including the connector is further described.
[0185] Figure 8 Schematic diagram of the structure of the data processing system provided in the embodiment of the present application Figure 9 ,like Figure 8 As shown, the data processing system further includes: a connector 5 .
[0186] The connector 5 is connected to the processor 4 .
[0187] Connector 5 is used to update the security verification module and encryption module.
[0188] Updating the security verification module and the encryption module can be understood as updating the security verification software in the security verification module and the encryption software in the encryption module.
[0189] Furthermore, the connector 5 includes a third network port and a high-speed serial computer expansion bus standard (Peripheral Component Interconnect Express, PCIe) interface.
[0190] The processor 4 is connected to the third network port and the PCIe interface respectively.
[0191] Specifically, the third network port is connected to the processor 4 via a gigabit transformer and a PHY in sequence. The PCIe interface is connected to the processor 4 via a PCIe bus.
[0192] Optionally, the PHY is connected to the third network port via an Ethernet communication path (Ethernet, ETH).
[0193] The connector 5 updates the security verification module and the encryption module, including: updating the security verification module and the encryption module through the third network port, or updating the security verification module and the encryption module through the PCIe interface.
[0194] exist Figure 9 In an embodiment, the data processing system further includes a connector connected to the processor; the connector is used to update the security verification module and the encryption module. In the above method, the security verification module and the encryption module are updated by connecting the connector to the processor. This allows for rapid updates of the module software to address new attack vectors and encryption vulnerabilities, ensuring that the data processing system remains protected against the latest security risks and avoiding data security risks caused by lagging module functionality. Furthermore, this update method eliminates the need for large-scale disassembly or hardware replacement of the entire data processing system, significantly reducing maintenance costs for the data processing system.
[0195] In some embodiments, the data processing system of the present application further includes a real-time clock (RTC) circuit, a low-power double data rate (LPDDR4) chip, an embedded multi-media card (eMMC) chip, and a power supply circuit.
[0196] The following combination Figure 6 ,exist Figure 9 Based on the embodiment, a data processing system including an RTC circuit, an LPDDR4 chip, an eMMC chip, and a power supply circuit is further described.
[0197] Figure 9 Schematic diagram of the structure of the data processing system provided in the embodiment of the present application Figure 10 ,like Figure 10 As shown, the data processing system further includes: an RTC circuit 6, an LPDDR4 chip 7, an eMMC chip 8, and a power supply circuit 9.
[0198] The RTC circuit 6 , the LPDDR4 chip 7 , and the eMMC chip 8 are respectively connected to the processor 4 .
[0199] The power supply circuit 9 is connected to the connector 5 .
[0200] Optionally, the RTC circuit 6 is connected to the processor 4 via an Inter-Integrated Circuit (I2C) bus.
[0201] The RTC circuit 6, the LPDDR4 chip 7, and the eMMC chip 8 are peripheral circuits of the processor 4, and provide an operating environment for the processor 4.
[0202] The RTC circuit 6 is configured to provide an accurate time reference for the processor 4.
[0203] Optionally, the processor 4 can obtain the time of data loss through the RTC circuit 6.
[0204] The LPDDR4 chip 7 is configured to provide low-power running memory for the processor 4.
[0205] The eMMC chip 8 is configured to provide storage space for the processor 4.
[0206] Optionally, when the processor 4 allocates independent computing resources of the processor 4 to the first virtual area 41 and the second virtual area 42, the processor 4 can allocate low-power running memory in the LPDDR4 chip 7 and storage space in the eMMC chip 8.
[0207] The power circuit 9 is configured to obtain a first voltage through the connector 5, convert the first voltage into a second voltage, and provide the second voltage for the micro control unit 3, the processor 4, and the peripheral circuits in the electronic device.
[0208] Optionally, the power circuit 9 can also store power when the electronic device is powered on, and provide power for the micro control unit 3, the processor 4, and the peripheral circuits when the electronic device is powered off.
[0209] The second voltage is, for example, 5V or 3.3V.
[0210] In Figure 10 In some embodiments, the data processing system can be constructed to have a complete and efficient and stable operating system by integrating the RTC circuit, the LPDDR4 chip, the eMMC chip, and the power circuit. The power circuit obtains a first voltage through the connector and converts the first voltage into a second voltage that is suitable for the electronic device, thereby providing stable power support for the micro control unit, the processor, and the peripheral circuits, and reducing device failures caused by voltage fluctuations. The power circuit stores power when the electronic device is powered on, and continuously provides power when the electronic device is powered off, thereby ensuring that the data processing system can still process current data in the event of a sudden power failure, avoiding data loss, and enhancing the risk resistance and reliability of the data processing system.
[0211] In some embodiments, the first network port and the second network port are connected in a differential pair cross mode.
[0212] The differential pair cross mode of the first network port and the second network port will be further described below. Figure 10
[0213] A schematic diagram of the differential pair cross connection mode of the first network port and the second network port provided by the embodiment of the present application is shown in The first network port includes 8 pins, and the second network port includes 8 pins.
[0214] The 8 pins are pin 1, pin 2, pin 3, pin 4, pin 5, pin 6, pin 7, and pin 8.
[0215] The differential pair cross connection mode is, for example, 13-31, 26-62, 47-74, or 58-85.
[0216] For example, 13-31 means that the pin 1 of the first network port is connected to the pin 3 of the second network port, and the pin 3 of the first network port is connected to the pin 1 of the second network port.
[0217] Specifically, the pin 1 of the first network port and the pin 3 of the first network port are respectively connected to the first relay, and the pin 3 of the second network port and the pin 1 of the second network port are respectively connected to the second relay, so that the pin 1 of the first network port is connected to the pin 3 of the second network port, and the pin 3 of the first network port is connected to the pin 1 of the second network port through the first relay and the second relay.
[0218] In In the embodiment, in the implementation of the double network port BYPASS function, the differential pair cross connection mode is adopted, through the connection mode of the differential pair (for example, 13-31), the signals with opposite polarities can be transmitted through the double pins, the data is carried by the voltage difference of the double pins, the electromagnetic interference and common mode noise can be effectively suppressed, even in a complex electromagnetic environment, the accurate and stable transmission of data between the first network port and the second network port can be ensured, the data packet loss and the bit error rate are greatly reduced, and the communication quality between the networks is improved.
[0219] Finally, it should be noted that: other embodiments of the present application will be easily conceived by those skilled in the art after considering the specification and practicing the application disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include known or customary technical means in the art that are not disclosed in the present application, and is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the present application is only limited by the appended claims.
Claims
1. A data processing system, characterized in that: Applied to electronic equipment, the system includes: a first network port, a second network port, a control device and a processor, wherein: The processor is connected to the control device, and the control device is also connected to the first network port and the second network port; The first network port is used to process data of the first network, and the second network port is used to process data of the second network; The control device is used to control the first network port to connect to the second network port, or control the processor to connect to the first network port and the second network port respectively; The processor includes a security verification module and an encryption module. The security verification module is used to perform security verification on data transmitted by the first network port and the second network port. The encryption module is used to encrypt or decrypt data transmitted by the first network port and the second network port.
2. The system according to claim 1, wherein: The processor includes a first virtual area, a second virtual area, and a first memory; The first virtual area includes the security verification module; The second virtual area includes the encryption module; The first memory is used for data transmission between the security verification module and the encryption module.
3. The system according to claim 2, characterized in that The system further comprises: The security verification module is further configured to store the data after the security verification is passed in the first memory, and the encryption module is further configured to obtain the data after the security verification is passed in the first memory and decrypt the data after the security verification is passed; The encryption module is further used to store the encrypted data in the first memory, and the security verification module is further used to obtain the encrypted data in the first memory and perform security verification on the encrypted data.
4. The system according to claim 3, characterized in that When the first network sends data to the second network, the system includes: The security verification module is used to perform security verification on the data transmitted by the first network port, and store the data that passes the security verification into the first memory; The encryption module is further configured to obtain the data after the security verification has passed from the first memory, decrypt the data after the security verification has passed, and send the decrypted data to the second network port.
5. The system according to claim 3, wherein: When the second network sends data to the first network, the system includes: The encryption module is further configured to encrypt data transmitted by the second network port and store the encrypted data in the first memory; The security verification module is further configured to obtain the encrypted data from the first memory, perform security verification on the encrypted data, and send the data that passes the security verification to the first network port.
6. The system according to claim 1, wherein: The processor is further configured to obtain a status of the electronic device and send a control instruction associated with the status to the control device; The control device is further configured to control the first network port to connect to the second network port according to the control instruction, or to control the processor to connect to the first network port and the second network port respectively.
7. The system according to claim 6, characterized in that The control device includes a micro control unit and a relay group; The micro control unit is connected to the processor and the relay group respectively; The relay group is connected to the first network port, the second network port, and the processor respectively; The micro control unit is used to receive the control instruction associated with the state; The micro control unit is further configured to control the relay group according to the control instruction so that the first network port is connected to the second network port, or the processor is connected to the first network port and the second network port respectively.
8. The system according to claim 7, characterized in that The state of the electronic device includes a normal state, and the relay group includes a first relay and a second relay; The first relay is connected to the first network port, the processor, and the micro control unit respectively; The second relay is connected to the second network port, the processor, and the micro control unit respectively; The first relay is also connected to the second relay; The processor is further configured to, when the state of the electronic device is the normal state, send a first instruction associated with the normal state to the micro control unit; The micro control unit is further configured to control the first relay and the second relay to be disconnected according to the first instruction, so that the processor is connected to the first network port and the second network port respectively.
9. The system according to claim 8, characterized in that The state of the electronic device includes an abnormal state; The processor is further configured to, when the state of the electronic device is the abnormal state, send a second instruction associated with the abnormal state to the micro control unit; The micro control unit is further configured to control the connection between the first relay and the second relay according to the second instruction, so that the first network port is connected to the second network port.
10. The system according to claim 1, wherein: The system further comprises: a connector; The connector is connected to the processor; The connector is used to update the security verification module and the encryption module.