Polarization encryption one-way data ferrying device and method
By using a polarization-encrypted one-way data transfer device, combined with dynamic keys and optical links, the problems of low data transmission efficiency and insufficient security in existing technologies are solved, achieving efficient and secure data transmission and adapting to diverse transmission needs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN ANCHE TECH
- Filing Date
- 2026-01-21
- Publication Date
- 2026-05-01
AI Technical Summary
Existing data transfer methods suffer from low efficiency, easy loss or damage, and risks of human error and data leakage. Dedicated hardware and network isolation equipment are expensive, inflexible, and complex to configure and maintain. Optical encryption technology is not fully applied, has insufficient encryption strength, is difficult to balance transmission efficiency and security, and has poor system compatibility.
A polarization-encrypted one-way data transfer device is adopted, including an integrated transfer host with built-in transmission and reception units, polarization encryption and demodulation modules, combined with dynamic key storage and optical links to achieve high-security and efficient data transmission.
It improves the security and efficiency of data transmission, reduces maintenance costs, adapts to different security levels and installation environments, supports multiple data format conversions, and is suitable for isolated network environments.
Smart Images

Figure CN121966982A_ABST
Abstract
Description
A polarization-encrypted one-way data transfer device and method Technical Field
[0001] This invention relates to the field of data security transmission technology, and in particular to a polarization-encrypted one-way data transfer device and method for use in isolated network environments such as vehicle inspection stations. It enables highly secure and efficient one-way transmission of intranet data to the outside world without connecting to the Internet or relying on wired or wireless external connections. Background Technology
[0002] With the increasing demand for data security, data transfer technology in isolated network environments has become a core means of ensuring the security of sensitive data transmission. Currently, mainstream data transfer solutions mainly fall into three categories: First, physical media transmission, such as USB flash drives, optical discs, or magnetic tapes. While simple to operate, these are inefficient and susceptible to data leakage due to loss, damage, or human error. Second, dedicated hardware devices, such as data diodes, achieve unidirectional transmission through hardware design, offering high security, but are costly, lack configuration flexibility, and are difficult to adapt to diverse transmission needs. Third, network isolation devices rely on physical isolation for data transmission, offering good security, but are complex to configure, have high maintenance costs, and their transmission efficiency is insufficient to meet the needs of large-scale, rapid data transfer.
[0003] In recent years, optical encryption technology has gradually attracted attention due to its strong anti-interference ability and high security. However, existing technologies have not yet applied it in depth. On the one hand, there is a lack of effective integration schemes for polarization encryption technology with unidirectional data transfer systems, which cannot give full play to the advantages of optical encryption in physical layer protection. On the other hand, existing devices have problems such as insufficient encryption strength, fixed keys that are easy to crack, poor module compatibility, and difficulty in balancing transmission efficiency and security. At the same time, the low degree of integration leads to cumbersome configuration and high maintenance costs, making it difficult to meet the needs of efficient, secure and flexible data transfer in isolated network environments. Summary of the Invention
[0004] The purpose of this invention is to provide a polarization-encrypted one-way data transfer device and method, which can solve the problems of low physical medium transmission efficiency, easy loss and damage, and risks of human operation and data leakage in existing traditional data transfer methods; high cost, poor flexibility, and complex configuration and maintenance of dedicated hardware and network isolation equipment; and insufficient application of optical encryption methods, insufficient encryption strength, difficulty in balancing transmission efficiency and security, and poor system compatibility in existing technologies.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a polarization-encrypted unidirectional data transfer device, comprising an integrated transfer host, wherein a transmitting unit mounting cavity and a receiving unit mounting cavity are respectively arranged on both sides inside the integrated transfer host; a transmitting integrated motherboard is arranged inside the transmitting unit mounting cavity, and a data access module, a polarization encryption module, and an optical transmitting module are electrically connected to the top of the transmitting integrated motherboard; a receiving integrated motherboard is arranged inside the receiving unit mounting cavity, and an optical receiving module, a polarization demodulation module, and a data output module are electrically connected to the top of the receiving integrated motherboard; a vehicle inspection data interface is embedded on the left side of the integrated transfer host, and an external data interface is embedded on the right side; the vehicle inspection data interface is electrically connected to the data access module, and the external data interface is electrically connected to the data output module; the optical receiving module and the optical transmitting module are unidirectionally connected via a high-transmittance optical fiber link.
[0006] Furthermore, the output of the data access module is electrically connected to the input of the polarization encryption module, which uses an optical encryption device based on a liquid crystal polarizer; a dynamic key storage unit is provided on the top of the transmitter integrated motherboard, which is electrically connected to the polarization encryption module and is used to store and synchronize encryption keys.
[0007] Furthermore, the optical emission module includes a laser and a beam calibration component. The laser is fixed to the rear side of the emission unit mounting cavity via an angle-adjustable bracket, and its input end is optically connected to the output end of the polarization encryption module. The beam calibration component is in close contact with the laser's emission end. The optical receiving module includes an optical signal detector and a filtering component. The optical signal detector is fixed to the rear side of the receiving unit mounting cavity and is electrically connected to the input end of the polarization demodulation module via a shielded data line. The filtering component is fixedly connected to the inside of the beam entrance of the optical signal detector.
[0008] Furthermore, a key matching unit is provided on the top of the receiving integrated motherboard. The key matching unit is electrically connected to the polarization demodulation module and synchronizes the key with the dynamic key storage unit through a preset algorithm for accurate demodulation of polarization encrypted optical signals.
[0009] Furthermore, the input end of the data output module is electrically connected to the output end of the polarization demodulation module. It supports multiple data format conversions and has a built-in data verification unit, which is used to verify the integrity of the restored data.
[0010] Furthermore, the polarization encryption module can be replaced with a quantum encryption module, maintaining electrical compatibility with the transmitting integrated motherboard after replacement; the high transmittance fiber optic link can be replaced with a free-space optical communication link, achieving adaptation by adjusting the installation angles of the optical transmitting module and the optical receiving module and the parameters of the optical devices after replacement.
[0011] This invention also proposes a polarization-encrypted one-way data transfer method based on the above-mentioned device, comprising the following steps: S1: The vehicle inspection data center prepares the data to be transmitted and transmits it to the data access module through the vehicle inspection data interface; S2: The polarization encryption module is activated, the dynamic key storage unit loads and synchronizes the encryption key, and the polarization encryption module performs polarization modulation on the data to be transmitted based on the key to generate a polarization-encrypted electrical signal; S3: The optical transmission module converts the polarization-encrypted electrical signal into a polarization-encrypted optical signal, which is then calibrated and transmitted to the optical receiving module through a one-way optical link; S4: The optical receiving module filters stray light and converts the optical signal into an electrical signal, which is then transmitted to the polarization demodulation module; S5: The key matching unit synchronizes the key to the polarization demodulation module, and demodulates and restores the original data; S6: The data output module performs format conversion and integrity verification, and outputs the data to the external data center through the external data interface after the verification is passed.
[0012] Furthermore, in step S2, the encryption key is 256 bits, and the polarization angle of the polarization encryption module is adjustable from 0° to 180°. Data encoding encryption is achieved by controlling the change in the polarization state of light. The encryption key adopts a dynamic update mechanism, and the dynamic key storage unit automatically generates a new key every fixed time and synchronizes it to the key matching unit.
[0013] Furthermore, in step S3, the unidirectional optical link is a high-transmittance optical fiber link or a free-space optical communication link, and the transmission rate of the polarization-encrypted optical signal is 10Gbps.
[0014] Furthermore, in step S6, the integrity verification is achieved by comparing the feature values of the original data and the restored data through the data verification unit. The feature values include data length, checksum, and hash value of key fields.
[0015] Compared with existing technologies, the beneficial effects of the technical solution of this invention are as follows: 1. Significantly improved security: By combining a polarization encryption module with a 256-bit encryption key, physical layer encryption is achieved using the polarization state encoding of light. Even if data is intercepted during transmission, the original content cannot be deciphered without a matching key. With the addition of a dynamic key update mechanism, the key is automatically updated at fixed intervals, further enhancing the anti-cracking capability. At the same time, the unidirectional transmission design of the optical link and the physical isolation structure eliminate the risk of reverse data leakage from the hardware level, solving the problems of insufficient encryption strength and data leakage risks in existing technologies.
[0016] 2. Balancing Transmission Efficiency and Reliability: Employing high-transmittance fiber optic links or adaptable free-space optical communication links fully leverages the high bandwidth characteristics of optical transmission, significantly improving data transfer efficiency and meeting the demands for large-scale, rapid data transmission. The beam calibration component of the optical transmitting module works in conjunction with the filtering component of the optical receiving module to reduce optical signal transmission loss and stray light interference, ensuring signal transmission stability. The integrity verification unit built into the data output module ensures that data transmission is complete and tamper-free by comparing data length, checksum, and hash values of key fields.
[0017] 3. Simplified structure and controllable cost: The integrated shuttle host has a unified design, which centrally arranges the transmitting unit, receiving unit and various functional modules. It does not rely on physical media such as USB flash drives or optical discs, avoiding the risks of human operation. At the same time, it simplifies the configuration process and reduces maintenance costs. The electrical compatibility design of each module of the device allows the polarization encryption module to be directly replaced with the quantum encryption module, and the optical link can be flexibly switched to the free space optical communication link without modifying the core structure. It adapts to different security levels and installation environment requirements, solving the problems of poor flexibility and high upgrade costs of existing dedicated hardware equipment.
[0018] 4. Wide compatibility and applicability: The data output module supports multiple data format conversions and can adapt to the receiving needs of different external data centers; the device as a whole does not rely on external networks and is suitable for various isolated network environments such as vehicle inspection stations. At the same time, the method and process are clear and easy to operate, and can be quickly deployed, taking into account both practicality and scalability. Attached Figure Description
[0019] Figure 1 is an overall structural diagram of the polarization encryption unidirectional data transfer device of the present invention; Figure 2 is a structural diagram of the integrated transfer host of the present invention; Figure 3 is a structural diagram of the transmitting unit mounting cavity of the present invention; Figure 4 is a structural diagram of the optical transmitting module of the present invention; Figure 5 is a structural diagram of the receiving unit mounting cavity of the present invention; Figure 6 is a structural diagram of the optical receiving module of the present invention.
[0020] Figure 7 is a schematic diagram of the circuit connection of the present invention.
[0021] Figure 8 is a flowchart of the data transfer method of the present invention.
[0022] In the diagram: 1. Integrated shuttle host; 2. Transmitter unit mounting cavity; 3. Receiver unit mounting cavity; 4. Transmitter integrated motherboard; 5. Data access module; 6. Polarization encryption module; 7. Optical transmission module; 701. Laser; 702. Beam calibration component; 8. Receiver integrated motherboard; 9. Optical receiver module; 901. Optical signal detector; 902. Filter component; 10. Polarization demodulation module; 11. Data output module; 12. Vehicle inspection data interface; 13. External data interface; 14. High transmittance fiber optic link; 15. Dynamic key storage unit; 16. Key matching unit. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] Please refer to Figures 1-7. The present invention provides a technical solution: a polarization-encrypted unidirectional data transfer device, comprising an integrated transfer host 1. A transmitting unit mounting cavity 2 and a receiving unit mounting cavity 3 are respectively arranged on both sides inside the integrated transfer host 1. A transmitting integrated motherboard 4 is arranged inside the transmitting unit mounting cavity 2. A data access module 5, a polarization encryption module 6, and an optical transmitting module 7 are electrically connected to the top of the transmitting integrated motherboard 4. A receiving integrated motherboard 8 is arranged inside the receiving unit mounting cavity 3. An optical receiving module 9, a polarization demodulation module 10, and a data output module 11 are electrically connected to the top of the receiving integrated motherboard 8. A vehicle inspection data interface 12 is embedded on the left side of the integrated transfer host 1, and an external data interface 13 is embedded on the right side. The vehicle inspection data interface 12 is electrically connected to the data access module 5, and the external data interface 13 is electrically connected to the data output module 11. The optical receiving module 9 and the optical transmitting module 7 are unidirectionally connected via a high-transmittance optical fiber link 14.
[0025] In this embodiment, by setting up an integrated shuttle host 1, a transmitting unit mounting cavity 2, a receiving unit mounting cavity 3, a transmitting integrated motherboard 4, a receiving integrated motherboard 8, a vehicle inspection data interface 12, an external data interface 13, and a high-transmittance fiber optic link 14, the transmitting integrated motherboard 4 is first installed inside the transmitting unit mounting cavity 2. The data access module 5, the polarization encryption module 6, and the optical transmitting module 7 are electrically connected to the top of the transmitting integrated motherboard 4. At the same time, the receiving integrated motherboard 8 is installed inside the receiving unit mounting cavity 3. The optical receiving module 9, the polarization demodulation module 10, and the data output module 11 are electrically connected to the top of the receiving integrated motherboard 8. This layout ensures that the modules are neatly installed, stably connected, and convenient for subsequent maintenance. Next, using the vehicle inspection data interface 12 embedded on the left side of the integrated shuttle host 1, an electrical connection is established between the vehicle inspection data center and the data access module 5. Then, through the external data interface 13 embedded on the right side of the host, an electrical connection is established between the data output module 11 and the external data center. The entire connection process does not rely on physical media such as USB flash drives or optical discs. It also avoids connecting to external networks, thus preventing data leakage risks caused by human error from the source. Subsequently, the data to be transmitted from the vehicle inspection data center is transmitted to the data access module 5 through the vehicle inspection data interface 12. After being encrypted by the polarization encryption module 6, it is transmitted to the optical transmission module 7. The optical transmission module 7 converts the encrypted electrical signal into an optical signal, which is transmitted unidirectionally to the optical receiving module 9 in the receiving unit mounting cavity 3 through the high-transmittance fiber optic link 14. After being received by the optical receiving module 9, the optical signal is converted into an electrical signal, demodulated by the polarization demodulation module 10, and processed by the data output module 11. Then, it is transmitted to the external data center through the external data interface 13. The high-transmittance fiber optic link 14 not only ensures the stability and efficiency of optical signal transmission, but also achieves physical isolation between the transmitting and receiving units, avoiding signal crosstalk. At the same time, the overall integrated design simplifies the configuration process, reduces equipment costs and maintenance difficulty, fully leverages the advantages of optical transmission, and solves the problems of low efficiency, insufficient security, and poor flexibility in traditional data transfer methods.
[0026] Specifically, as shown in Figure 3, the output end of the data access module 5 is electrically connected to the input end of the polarization encryption module 6, which uses an optical encryption device based on a liquid crystal polarizer.
[0027] Specifically, as shown in Figure 3, a dynamic key storage unit 15 is provided on the top of the transmitter integrated motherboard 4. The dynamic key storage unit 15 is electrically connected to the polarization encryption module 6 and is used to store and synchronize encryption keys.
[0028] Specifically, as shown in Figure 4, the optical emission module 7 includes a laser 701 and a beam calibration component 702. The laser 701 is fixed to the rear side inside the emission unit mounting cavity 2 by an angle-adjustable bracket. The input end of the laser 701 is optically connected to the output end of the polarization encryption module 6. The beam calibration component 702 is in close contact with the output end of the laser 701.
[0029] In this embodiment: the output end of the data access module 5 is electrically connected to the input end of the polarization encryption module 6, which can stably transmit the data stream from the vehicle inspection data interface 12 to the polarization encryption module 6. The polarization encryption module 6 adopts an optical encryption device based on a liquid crystal polarizer, and works with the dynamic key storage unit 15 (electrically connected to the polarization encryption module 6) set on the top of the transmitting integrated motherboard 4. The dynamic key storage unit 15 can store and synchronize the encryption key, allowing the polarization encryption module 6 to perform high-strength encryption on the data based on the key, preventing the data from being cracked during transmission and solving the problem of insufficient encryption strength in traditional methods. The laser 701 of the optical transmitting module 7 is fixed inside the rear side of the transmitting unit mounting cavity 2 by an angle-adjustable bracket. Its input end is optically connected to the output end of the polarization encryption module 6, which can receive the encrypted signal and convert it into an optical signal. The beam calibration component 702 is close to the output end of the laser 701, which can calibrate the dispersed optical signal into parallel light, ensuring that the optical signal transmission is more concentrated and the loss is less, thus improving the transmission efficiency. At the same time, the angle-adjustable bracket facilitates the adjustment of the position of the laser 701, allowing the optical signal to be accurately aligned with the subsequent transmission link.
[0030] Specifically, as shown in Figure 6, the optical receiving module 9 includes a light signal detector 901 and a filter component 902. The light signal detector 901 is fixed to the rear side inside the receiving unit mounting cavity 3. The light signal detector 901 is electrically connected to the input end of the polarization demodulation module 10 through a shielded data line. The filter component 902 is fixedly connected to the inside of the beam entrance of the light signal detector 901.
[0031] Specifically, as shown in Figure 5, a key matching unit 16 is provided on the top of the receiving integrated motherboard 8. The key matching unit 16 is electrically connected to the polarization demodulation module 10. The key matching unit 16 and the dynamic key storage unit 15 synchronize the key through a preset algorithm for accurate demodulation of the polarization encrypted optical signal.
[0032] In this embodiment: the optical signal detector 901 of the optical receiving module 9 is fixed inside the rear side of the receiving unit mounting cavity 3. A filter component 902 is fixedly connected to the inner side of its beam entrance. The filter component 902 can filter out stray light interference in the optical signal, allowing the optical signal detector 901 to receive only the pure target optical signal, thus improving the accuracy of signal reception. The optical signal detector 901 is electrically connected to the input terminal of the polarization demodulation module 10 through a shielded data cable, which can stably transmit the converted electrical signal to the polarization demodulation module 10. The key matching unit 16 on the top of the receiving integrated motherboard 8 is electrically connected to the polarization demodulation module 10 and can synchronize the key with the dynamic key storage unit 15 through a preset algorithm, ensuring that the polarization demodulation module 10 can accurately demodulate the encrypted optical signal and restore the original data. This solves the problems of inaccurate demodulation of encrypted signals and data loss, and ensures the integrity of data transmission.
[0033] Specifically, as shown in Figure 5, the input terminal of the data output module 11 is electrically connected to the output terminal of the polarization demodulation module 10. The data output module 11 supports multiple data format conversions and has a built-in data verification unit, which is used to verify the integrity of the restored data.
[0034] Specifically, as shown in Figure 5, the polarization encryption module 6 can be replaced with a quantum encryption module, and after replacement, it remains electrically compatible with the transmission integrated motherboard 4.
[0035] In this embodiment, the input terminal of the data output module 11 is electrically connected to the output terminal of the polarization demodulation module 10, and can receive the demodulated raw data. The data output module 11 supports multiple data format conversions and can adapt to the receiving needs of different external data centers, solving the problem of poor compatibility of traditional equipment. At the same time, its built-in data verification unit can verify the integrity of the restored data, avoiding omissions or errors in data during transmission or demodulation, further ensuring the quality of data transmission. In addition, the polarization encryption module 6 can be replaced with a quantum encryption module, and after replacement, it remains electrically compatible with the transmitting integrated motherboard 4. The encryption method can be flexibly upgraded according to the security level requirements of different scenarios, improving the flexibility and applicability of the device, without replacing the entire motherboard, thus reducing upgrade costs.
[0036] Specifically, as shown in Figures 4 and 6, the high-transmittance fiber optic link 14 can be replaced with a free-space optical communication link. After the replacement, the optical transmitting module 7 and the optical receiving module 9 can be adapted by adjusting the installation angle and optical device parameters.
[0037] Specifically, as shown in Figures 4 and 6, the high-transmittance fiber optic link 14 is located outside the integrated shuttle host 1, and its two ends are fixed to the optical transmitting module 7 and the optical receiving module 9 respectively through sealed optical interfaces.
[0038] In this embodiment, the high-transmittance fiber optic link 14 is located outside the integrated transfer host 1. Its two ends are fixed to the optical transmitting module 7 and the optical receiving module 9 respectively through sealed optical interfaces. The sealed design can play a role in waterproofing and dustproofing, protecting the stability of the interface connection and avoiding environmental factors from affecting signal transmission. The high transmittance characteristic ensures the high efficiency of optical signal transmission and meets the needs of large-scale data transfer. At the same time, the externally arranged link avoids signal crosstalk with other modules inside the host and does not damage the physical isolation design between the transmitting unit mounting cavity 2 and the receiving unit mounting cavity 3. In addition, the high-transmittance fiber optic link 14 can be replaced with a free-space optical communication link. After replacement, adaptation can be achieved by adjusting the installation angle and optical device parameters of the optical transmitting module 7 and the optical receiving module 9 without modifying the core structure of the device. This allows the device to adapt to different installation environments and transmission distance requirements, further improving the flexibility and practicality of the device.
[0039] Working Principle: In applications such as vehicle inspection stations, the transmitting integrated motherboard 4 is first installed in the transmitting unit mounting cavity 2 on one side of the integrated shuttle host 1. The data access module 5, polarization encryption module 6, and optical transmission module 7 are electrically connected to the top of the transmitting integrated motherboard 4. Simultaneously, the receiving integrated motherboard 8 is installed in the receiving unit mounting cavity 3 on the other side of the host. The optical receiving module 9, polarization demodulation module 10, and data output module 11 are electrically connected to the top of the receiving integrated motherboard 8, ensuring that each module is neatly installed and stably connected. Next, through the vehicle inspection data interface 12 embedded on the left side of the integrated shuttle host 1, an electrical connection is established between the vehicle inspection data center and the data access module 5. Then, through the external data interface 1 embedded on the right side of the host... 3. Establish an electrical connection between the data output module 11 and the external data center. The entire connection process does not rely on physical media such as USB flash drives or optical discs, nor does it access an external network. At this time, the dynamic key storage unit 15 on the top of the transmitting integrated motherboard 4 is electrically connected to the polarization encryption module 6 to start storing and synchronizing the encryption key. The key matching unit 16 on the top of the receiving integrated motherboard 8 is electrically connected to the polarization demodulation module 10 to complete key synchronization with the dynamic key storage unit 15 through a preset algorithm, preparing for subsequent encryption and demodulation. After that, the data to be transmitted from the vehicle inspection data center is transmitted to the data access module 5 through the vehicle inspection data interface 12. The output end of the data access module 5 is electrically connected to the input end of the polarization encryption module 6 to stably transmit the data stream to the polarization encryption module 6.The polarization encryption module 6 employs an optical encryption device based on a liquid crystal polarizer. It performs high-strength encryption on the data using a synchronized key. The encrypted signal is then transmitted to the optical transmitting module 7. The laser 701 of the optical transmitting module 7 is fixed inside the rear side of the transmitting unit mounting cavity 2 via an angle-adjustable bracket. Its input end is optically connected to the output end of the polarization encryption module 6. After receiving the encrypted signal, it converts it into an optical signal. The beam calibration component 702, located close to the output end of the laser 701, calibrates the dispersed optical signal into parallel light. By adjusting the angle-adjustable bracket, the optical signal is precisely aligned with the transmission link. The optical signal is transmitted unidirectionally through a high-transmittance fiber optic link 14 located outside the integrated transfer host 1. Both ends of the fiber optic link are fixed to the optical transmitting module 7 and the optical receiving module 9 respectively via sealed optical interfaces to ensure stability during transmission. After the optical signal reaches the optical receiving module 9 in the receiving unit mounting cavity 3, it first passes through the filter component 902 inside the beam entrance of the optical signal detector 901 to filter out stray light interference. The pure optical signal is then received by the optical signal detector 901 and converted into an electrical signal. The optical signal detector 901 transmits the electrical signal to the polarization demodulation module 10 via a shielded data cable. With the cooperation of the key matching unit 16, the polarization demodulation module 10 accurately demodulates the encrypted electrical signal to restore the original data. Finally, the demodulated original data is transmitted to the data output module 11. The input of the data output module 11 is electrically connected to the output of the polarization demodulation module 10. It supports multiple data format conversions and can adapt to the receiving requirements of external data centers. Simultaneously, the built-in data verification unit verifies data integrity, ensuring no omissions or errors. After successful verification, the data is stably transmitted to the external data center via the external data interface 13, completing the entire data transfer process. If adaptation to different security levels or installation environments is required, the polarization encryption module 6 can be replaced with a quantum encryption module. After replacement, it remains electrically compatible with the transmitting integrated motherboard 4. The high-transmittance fiber optic link 14 can be replaced with a free-space optical communication link. After replacement, adaptation can be achieved by adjusting the installation angle and optical device parameters of the optical transmitting module 7 and the optical receiving module 9, without modifying the core structure.
[0040] Please refer to Figure 8. Based on the above device, another embodiment is also provided, which is a polarization-encrypted one-way data transfer method. The specific steps are as follows: Step S1: Data preparation and access; The vehicle inspection data center organizes the data to be transmitted according to the needs of vehicle inspection business, including structured data such as vehicle inspection parameters and certificate of conformity information. After the data to be transmitted is verified to be correct by the internal verification of the vehicle inspection data center, it is transmitted to the data access module 5 in the transmitting unit mounting cavity 2 in the form of an electrical signal through the vehicle inspection data interface 12 embedded on the left side of the integrated transfer host 1. The data access module 5 performs preliminary filtering and format regularization on the received electrical signal to ensure the stability of data transmission.
[0041] Step S2: Polarization encryption processing; The polarization encryption module 6 on the transmitting integrated motherboard 4 is activated. The dynamic key storage unit 15 loads the preset 256-bit encryption key and synchronizes it to the polarization encryption module 6. The encryption key adopts a dynamic update mechanism. In this embodiment, the preset update cycle is 12 hours. The dynamic key storage unit 15 automatically generates a new 256-bit random key every 12 hours and synchronizes it to the key matching unit 16 on the receiving integrated motherboard 8 through a preset symmetric encryption algorithm to ensure the consistency of the encryption and decryption keys.
[0042] The polarization encryption module 6 uses an optical encryption device based on a liquid crystal polarizer. Its polarization angle is adjustable from 0° to 180°. After receiving the normalized data transmitted by the data access module 5, it controls the change of polarization angle of the liquid crystal polarizer according to the encryption key, and maps the binary data to the polarization state one by one. For example, 0° linear polarization corresponds to binary "0", and 90° linear polarization corresponds to binary "1". Data encoding is achieved by switching polarization states, generating polarization encryption electrical signals and completing the physical layer encryption process.
[0043] If the actual application scenario requires a higher level of encryption, the polarization encryption module 6 can be replaced with a quantum encryption module. After replacement, the quantum encryption module and the transmitter integrated motherboard 4 remain electrically compatible without any changes to other hardware structures. The quantum encryption module generates an absolutely secure encryption key through quantum key distribution technology, performs quantum encryption processing on the data, and generates a quantum encrypted electrical signal. The subsequent transmission and demodulation process remains compatible with the polarization encryption scenario.
[0044] Step S3: Optical signal conversion and unidirectional transmission; The laser 701 of the optical emission module 7 receives the polarization encryption electrical signal output by the polarization encryption module 6 and converts it into the corresponding polarization encryption optical signal. In this embodiment, the laser 701 uses an infrared laser with a wavelength of 1550nm and an output optical power of 10dBm to ensure the transmission distance and stability of the optical signal.
[0045] The beam calibration component 702 is attached to the output end of the laser 701 to collimate and calibrate the converted polarization encrypted light signal, adjusting the divergent light signal into parallel light and reducing energy loss during transmission. The calibrated polarization encrypted light signal is transmitted to the optical receiving module 9 of the receiving unit mounting cavity 3 through a unidirectional optical link.
[0046] In this embodiment, the unidirectional optical link defaults to a high-transmittance fiber optic link 14, which has a transmission rate of up to 10Gbps, meeting the needs of rapid transfer of large-scale vehicle inspection data. If the installation environment is limited by space and fiber optic cables cannot be laid, the high-transmittance fiber optic link 14 can be replaced with a free-space optical communication link. After replacement, the angle adjustable bracket of the optical transmitting module 7 is adjusted so that the emission direction of the laser 701 is aligned with the beam entrance of the optical receiving module 9. At the same time, the focal length parameters of the beam calibration component 702 and the aperture of the filter component 902 of the optical receiving module 9 are optimized to ensure effective reception of optical signals during free-space transmission.
[0047] Step S4: Optical signal reception and electrical signal restoration; The filter component 902 of the optical receiving module 9 is fixed inside the beam entrance of the optical signal detector 901 to filter stray light from the received polarization-encrypted optical signal, allowing only the polarization-encrypted optical signal with a target wavelength of 1550nm to enter the optical signal detector 901, thus avoiding interference from ambient light and other wavelength optical signals.
[0048] The optical signal detector 901 uses an avalanche photodiode (APD) to convert the filtered polarization-encrypted optical signal into a corresponding polarization-encrypted electrical signal, which is then transmitted to the polarization demodulation module 10 via a shielded data line. The shielded data line uses a twisted-pair shielding structure to effectively reduce the impact of electromagnetic interference on signal transmission.
[0049] Step S5: Polarization demodulation and data restoration; The key matching unit 16 transmits the synchronously stored encryption key to the polarization demodulation module 10. The key matching unit 16 and the dynamic key storage unit 15 maintain real-time synchronization. The polarization demodulation module 10 controls the polarization angle of the internal optical device in reverse according to the polarization state encoding rule corresponding to the encryption key, and demodulates the polarization encrypted electrical signal to restore the electrical signal data consistent with the original data of the vehicle inspection data center.
[0050] Step S6: Data format conversion and integrity verification output; The data output module 11 receives the electrical signal data restored by the polarization demodulation module 10, and performs format conversion according to the receiving requirements of the external data center, supporting the conversion of the original XML format into JSON, CSV and other common data formats.
[0051] The built-in data verification unit of the data output module 11 initiates the integrity verification process. It calculates the data length, CRC32 checksum, and SHA256 hash value of key fields (such as vehicle identification number VIN) of the restored data and compares them with the original data feature values pre-stored in the vehicle inspection data center. If all three are consistent, the data is determined to be complete and tamper-free. If there are inconsistencies, a retransmission instruction is triggered, and the transmitting unit is notified to re-execute the data transmission process through the internal feedback link.
[0052] After verification, the data output module 11 transmits the processed complete data to the external data center through the external data interface 13 embedded on the right side of the integrated transfer host 1, thus completing the entire polarization-encrypted one-way data transfer process.
[0053] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A polarization-encrypted one-way data transfer device, comprising an integrated transfer host (1), characterized in that: The integrated shuttle host (1) has a transmitter unit mounting cavity (2) and a receiver unit mounting cavity (3) on its two sides respectively. The transmitter unit mounting cavity (2) is equipped with a transmitter integrated motherboard (4). The top of the transmitter integrated motherboard (4) is electrically connected to a data access module (5), a polarization encryption module (6), and an optical transmitter module (7). The receiver unit mounting cavity (3) is equipped with a receiver integrated motherboard (8). The top of the receiver integrated motherboard (8) is electrically connected to an optical receiver module (9), a polarization demodulation module (10), and a data output module (11). The integrated shuttle host (1) has a vehicle inspection data interface (12) embedded on its left side and an external data interface (13) embedded on its right side. The vehicle inspection data interface (12) is electrically connected to the data access module (5), and the external data interface (13) is electrically connected to the data output module (11). The optical receiver module (9) and the optical transmitter module (7) are unidirectionally connected through a high-transmittance optical fiber link (14).
2. The polarization-encrypted unidirectional data transfer device according to claim 1, characterized in that: The output of the data access module (5) is electrically connected to the input of the polarization encryption module (6). The polarization encryption module (6) uses an optical encryption device based on a liquid crystal polarizer. A dynamic key storage unit (15) is provided on the top of the transmitting integrated motherboard (4). The dynamic key storage unit (15) is electrically connected to the polarization encryption module (6) and is used to store and synchronize encryption keys.
3. The polarization-encrypted unidirectional data transfer device according to claim 1, characterized in that: The optical emission module (7) includes a laser (701) and a beam calibration component (702). The laser (701) is fixed to the rear side inside the emission unit mounting cavity (2) by an angle-adjustable bracket. Its input end is optically connected to the output end of the polarization encryption module (6). The beam calibration component (702) is close to the emission end of the laser (701). The optical receiving module (9) includes a light signal detector (901) and a filter component (902). The light signal detector (901) is fixed to the rear side inside the receiving unit mounting cavity (3). It is electrically connected to the input end of the polarization demodulation module (10) through a shielded data line. The filter component (902) is fixedly connected to the inside of the beam inlet of the light signal detector (901).
4. The polarization-encrypted unidirectional data transfer device according to claim 1, characterized in that: The receiving integrated motherboard (8) is provided with a key matching unit (16) on the top. The key matching unit (16) is electrically connected to the polarization demodulation module (10) and synchronizes the key with the dynamic key storage unit (15) through a preset algorithm for precise demodulation of polarization encrypted optical signals.
5. The polarization-encrypted unidirectional data transfer device according to claim 1, characterized in that: The input end of the data output module (11) is electrically connected to the output end of the polarization demodulation module (10). It supports multiple data format conversions and has a built-in data verification unit, which is used to verify the integrity of the restored data.
6. The polarization-encrypted unidirectional data transfer device according to claim 1, characterized in that: The polarization encryption module (6) can be replaced with a quantum encryption module, and after replacement, it remains electrically compatible with the transmission integrated motherboard (4); the high transmittance optical fiber link (14) can be replaced with a free space optical communication link, and after replacement, it can be adapted by adjusting the installation angle of the optical transmission module (7) and the optical receiving module (9) and the optical device parameters.
7. A polarization-encrypted unidirectional data transfer method based on the device described in any one of claims 1-6, characterized in that, Includes the following steps: S1: The vehicle inspection data center prepares the data to be transmitted and transmits it to the data access module (5) through the vehicle inspection data interface (12); S2: The polarization encryption module (6) is started, the dynamic key storage unit (15) loads and synchronizes the encryption key, and the polarization encryption module (6) performs polarization modulation on the data to be transmitted based on the key to generate a polarization encrypted electrical signal; S3: The optical transmission module (7) converts the polarization encrypted electrical signal into a polarization encrypted optical signal, and transmits it to the optical receiving module (9) through a unidirectional optical link after calibration; S4: The optical receiving module (9) filters stray light and converts the optical signal into an electrical signal, and transmits it to the polarization demodulation module (10); S5: The key matching unit (16) synchronizes the key to the polarization demodulation module (10) and demodulates and restores the original data; S6: The data output module (11) performs format conversion and integrity verification, and outputs it to the external data center through the external data interface (13) after the verification is passed.
8. The polarization-encrypted unidirectional data transfer method according to claim 7, characterized in that: In step S2, the encryption key is 256 bits, and the polarization angle of the polarization encryption module (6) is adjustable from 0° to 180°. Data encoding encryption is achieved by controlling the change of the polarization state of light. The encryption key adopts a dynamic update mechanism. The dynamic key storage unit (15) automatically generates a new key every fixed time and synchronizes it to the key matching unit (16).
9. The polarization-encrypted unidirectional data transfer method according to claim 7, characterized in that: In step S3, the unidirectional optical link is a high-transmittance optical fiber link (14) or a free-space optical communication link, and the transmission rate of the polarization encrypted optical signal is 10Gbps.
10. The polarization-encrypted unidirectional data transfer method according to claim 7, characterized in that: In step S6, the integrity verification is achieved by comparing the feature values of the original data and the restored data through the data verification unit. The feature values include data length, checksum, and hash value of key fields.