Dual mode keyboard with secure encryption module

By integrating a security chip into the wireless keyboard for hardware-level encryption, supporting national cryptographic algorithms, and combining mode switching and USB interface authentication, the security and power consumption issues of wireless keyboard data transmission are solved. This achieves end-to-end hardware-level encryption protection and national cryptographic compliance, making it suitable for wireless keyboards in high-security scenarios.

CN122111241APending Publication Date: 2026-05-29SHANGHAI SHUJIU SECRET EDUCATION TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANGHAI SHUJIU SECRET EDUCATION TECHNOLOGY CO LTD
Filing Date
2026-03-16
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing wireless keyboards suffer from problems such as plaintext exposure during data transmission, lack of end-to-end hardware encryption in wireless transmission links, lack of support for national cryptographic algorithms, and difficulty in balancing security features with power consumption. Current technologies lack a secure reconstruction of the keyboard's internal data processing structure.

Method used

Design a dual-mode keyboard with a security encryption module. Hardware-level encryption is achieved by connecting an independent security chip in series between the main control MCU and the wireless communication module. It supports Chinese national cryptographic algorithms and balances security and power consumption through a mode switching switch. A USB interface is integrated for bidirectional encryption authentication, and security indicator lights and trigger buttons are set to visualize the status.

Benefits of technology

It achieves hardware-level encryption protection from the input source, complies with national cryptographic algorithm requirements, prevents data leakage, takes into account both high security scenarios and low power consumption requirements, provides visualized security status, and supports integrated wired and wireless use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122111241A_ABST
    Figure CN122111241A_ABST
Patent Text Reader

Abstract

The application discloses a dual-mode keyboard with a security encryption module, and relates to the technical fields of information security and input device. The keyboard comprises a shell, a key array, a main control circuit board, a wireless communication module and a security encryption module. The wireless communication module supports at least a Bluetooth communication mode. The security encryption module is integrated on the main control circuit board and comprises a separate security chip which is electrically connected to a data transmission path of the key array and used for performing hardware-level encryption processing on original data input by a user. The application adds a separate security chip in the traditional dual-mode keyboard, constructs an end-to-end encryption channel from key input to wireless transmission, effectively prevents wireless signal sniffing and malicious software keyboard recording, and significantly improves the data security of the wireless keyboard in high-sensitive scenes such as financial payment and identity authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer peripherals technology, and more specifically, to a keyboard device for information input, particularly a dual-mode keyboard with a built-in hardware-level security encryption module and support for wireless communication.

[0002] This invention belongs to the interdisciplinary field of information security and input devices, specifically involving improvements to the internal circuit structure of a keyboard. It aims to solve the problem of preventing data theft during the input of sensitive information and is applicable to high-security scenarios such as online banking transactions, digital signatures, and encrypted communication. Background Technology

[0003] With the rapid development of internet technology, the keyboard, as the core input device for human-computer interaction, has expanded its application scenarios from traditional word processing and gaming to sensitive areas involving property security and identity authentication, such as e-commerce, online banking, and digital currency transactions. At the same time, malicious methods of stealing keyboard input data are constantly evolving, with threats such as keyloggers, wireless signal sniffing, and man-in-the-middle attacks becoming increasingly serious, posing severe security challenges to users' sensitive information.

[0004] Currently, keyboards on the market are mainly divided into two categories: wired keyboards and wireless keyboards. Wired keyboards connect directly to the host via USB or PS / 2 interfaces, and data transmission relies on physical lines, making them relatively difficult to remotely intercept. However, with the increasing demand for mobile work and multi-device collaboration, users' need for the convenience of wireless connectivity is becoming increasingly urgent, and the market share of wireless keyboards has been rising year by year. Most mainstream wireless keyboards currently use Bluetooth or 2.4G radio frequency technology for communication, allowing users to move freely within a certain range and free themselves from the constraints of cables.

[0005] However, existing wireless keyboards have significant technical shortcomings in terms of security design. Analysis reveals the following technical deficiencies in the transmission of keystroke data in existing wireless keyboards:

[0006] First, there's the issue of plaintext exposure during data transmission. Taking a Bluetooth keyboard as an example, although the Bluetooth protocol specification includes link-layer encryption, its protection is limited to the wireless link between the Bluetooth chip and the host Bluetooth adapter. The transmission of key data from the keyboard's main control MCU to the Bluetooth chip is completed through the keyboard's internal PCB traces, and this data transmission is unprotected. If the keyboard's main control MCU firmware has vulnerabilities, or if an attacker reads the MCU's internal data through debugging interfaces such as JTAG / SWD, they can obtain all the key input information, including sensitive data such as passwords and private keys.

[0007] Secondly, the security of 2.4G wireless keyboards is weak. Wireless keyboards using proprietary 2.4G protocols have relatively fixed data packet formats and modulation methods, with some products even lacking data encryption. Even those products claiming encryption capabilities often use simple, custom-designed algorithms with low encryption strength, making them easily crackable by professional wireless sniffing devices. Related research has confirmed the risk of long-distance interception of 2.4G wireless keyboard input.

[0008] Third, software encryption schemes have inherent flaws. To address these issues, some existing technologies propose installing encryption drivers at the operating system level, whereby the driver encrypts keyboard input before transmission over the network. However, this software encryption method relies on the security of the operating system kernel. Once malware is implanted in the operating system, the encryption driver itself can be bypassed or tampered with, rendering the encryption process ineffective. Furthermore, software encryption can only process data after it arrives at the host, failing to protect the data transmission link from the keyboard to the host.

[0009] Fourth, external security devices are cumbersome to operate and cannot cover the input source. Existing technologies employ independent USB tokens, dongles, or smart card readers for identity authentication and data encryption. For example, users need to insert a USB token and manually enter their password when making online banking transactions. However, these devices can only perform secondary signatures or encryption on the entered transaction data; they cannot protect the keyboard input process itself. The process of users entering their passwords on the keyboard remains exposed to the aforementioned risks, and since these devices and keyboards are independent physical entities, there is a security gap between them. Furthermore, users need to carry and unplug external devices, making the operation cumbersome.

[0010] Fifth, existing technologies lack support for Chinese national cryptographic algorithms. With the promulgation and implementation of the Cryptography Law of the People's Republic of China, compliance requirements for cryptographic applications in the financial and government sectors are becoming increasingly stringent, demanding the priority adoption of Chinese national cryptographic algorithms such as SM2, SM3, and SM4. However, the security mechanisms built into most keyboard products currently on the market only support internationally accepted algorithms, making it difficult to meet the requirements for domestic substitution and compliance review.

[0011] To address the aforementioned technical issues, the industry has proposed several improvement solutions. Some solutions employ a parallel structure between the encryption module and the main control unit, but the main control unit can still obtain plaintext data, failing to fundamentally resolve the risk of data leakage on the main control side. Another solution integrates fingerprint recognition functionality, but only for local identity verification, without encrypting and protecting regular key input data.

[0012] More specifically, some existing patent documents attempt to improve the data security of input devices through encryption modules or security control mechanisms. For example, Chinese invention patent CN108920386B proposes a secure keyboard input method and device, which reduces the risk of input information being stolen by malicious programs by randomizing input data or implementing software-level security controls. This type of technical solution mainly focuses on software-level input protection mechanisms. Its security control logic typically relies on the operating system or terminal software environment, and no independent security execution unit is established at the keyboard hardware structure level. Therefore, when the host system is controlled by low-level malicious programs, the input data may still be intercepted before entering the encryption process.

[0013] For example, Chinese invention patent CN109977215B proposes a password input protection method and terminal device, which improves the security of users inputting sensitive information by adding security prompts, randomized interaction, or multi-step verification to the input interface or input process. This type of solution focuses more on protecting the input interaction process or interface level, and does not provide hardware-level security isolation for the data processing structure inside the keyboard. Therefore, it still cannot avoid the problem of plaintext exposure of keystroke data in the keyboard's main control circuit or transmission link.

[0014] Furthermore, US Patent 10282356B2 discloses a secure input system for electronic devices, which reduces the risk of input event leakage in the communication link by encrypting input device events or transmitting them through a secure channel. However, this type of technical solution mainly focuses on secure transmission at the communication link level, without specifically designing for the data flow and hardware structure constraints within the keyboard. The keyboard controller can still access the original key data, making it difficult to completely prevent the possibility of plaintext data leakage at the hardware architecture level.

[0015] In summary, while existing technologies have proposed various improvements in software-level input protection, input interaction security, and communication link encryption, they generally lack a secure reconstruction of the keyboard's internal data processing structure. In particular, they lack a structural design that uses an independent security chip connected in series between the main control and communication modules to force all input data to be processed by the security module at the hardware level. Furthermore, existing solutions rarely address a unified security mechanism for both wireless and wired communication modes, nor do they support Chinese cryptographic algorithms. Therefore, it remains necessary to propose an input device structure capable of establishing an independent secure execution environment within the keyboard and implementing mandatory encryption processing through a hardware-level serial data path. Summary of the Invention

[0016] The technical problem this invention aims to solve is to address the shortcomings of existing technologies, such as the keyboard's main control MCU having access to plaintext data, the lack of end-to-end hardware encryption in the wireless transmission link, the absence of support for national cryptographic algorithms, and the difficulty in balancing security functions and power consumption. This invention provides a dual-mode keyboard with a security encryption module that can perform hardware-level encryption from the input source, supports multiple communication modes, and possesses national cryptographic algorithm capabilities. To solve the above technical problems, this invention provides the following technical solution:

[0017] A dual-mode keyboard with a security encryption module includes: a housing; a key array disposed on the housing; a main control circuit board disposed within the housing and electrically connected to the key array, the main control circuit board integrating a main control MCU; a wireless communication module disposed on the main control circuit board, the wireless communication module supporting at least Bluetooth communication mode; and a security encryption module disposed within the housing and integrated on the main control circuit board, the security encryption module including an independent security chip.

[0018] The feature is that the data input terminal of the security chip is electrically connected to the main control MCU, and the data output terminal of the security chip is electrically connected to the wireless communication module, so that the input data generated by the key array flows sequentially through the main control MCU and the security chip, and is then hardware encrypted by the security chip to generate encrypted data, which is then sent to the external host by the wireless communication module;

[0019] Furthermore, there is no direct data transmission path between the main control MCU and the wireless communication module that bypasses the security chip.

[0020] In the technical solution described in this invention, the security chip is connected in series on the data transmission path between the main control MCU and the wireless communication module to form a mandatory hardware encryption channel.

[0021] Furthermore, as a preferred embodiment of the present invention, the security chip is a national cryptographic security chip, supporting at least one of the SM2 elliptic curve public key cryptography algorithm, the SM3 cryptographic hash algorithm, and the SM4 block cipher algorithm. The security chip integrates a true random number generator to generate dynamic session keys to prevent replay attacks.

[0022] Furthermore, as a preferred embodiment of the present invention, the main control circuit board is also provided with a mode switching switch, which has at least two positions: a first position and a second position. When the mode switching switch is in the first position, the input data generated by the button array is directly transmitted to the wireless communication module without being encrypted by the security chip. When the mode switching switch is in the second position, the input data generated by the button array is transmitted to the security chip for encryption before being transmitted to the wireless communication module.

[0023] Furthermore, as a preferred embodiment of the present invention, the dual-mode keyboard further includes a USB wired interface, which is electrically connected to the main control circuit board; when connected to an external host through the USB wired interface, the security encryption module is also used to perform bidirectional encryption authentication with the external host through the USB channel.

[0024] Furthermore, as a preferred technical solution of the present invention, the security encryption module further includes a security indicator light, which is disposed on the housing and electrically connected to the main control circuit board or the security chip; the security indicator light is configured to emit a first color light when the data stream passes through the security chip for encryption processing, and emit a second color light or flash when an anomaly is detected.

[0025] Furthermore, as a preferred embodiment of the present invention, the button array includes a security trigger button, which is electrically connected to the interrupt pin of the main control circuit board; when the security trigger button is pressed, the main control circuit board responds to the interrupt signal to wake up the security encryption module, causing it to enter the working state from the low power state.

[0026] Furthermore, as a preferred embodiment of the present invention, the security chip has a built-in non-volatile memory for storing private keys, digital certificates, and encryption algorithm firmware; the non-volatile memory has an anti-tampering design, including at least one of a voltage detection sensor, a frequency detection sensor, and an active shielding layer; when an attack is detected, the security chip automatically erases the sensitive data stored in the non-volatile memory.

[0027] Furthermore, as a preferred embodiment of the present invention, the wireless communication module also supports 2.4G wireless communication mode, which together with Bluetooth mode constitutes dual-mode wireless communication; when the keyboard is working in 2.4G mode and the security mode is enabled, the security chip also encrypts the data.

[0028] Compared with the prior art, the present invention has the following beneficial effects:

[0029] First, this invention electrically connects the data input terminal of the security chip to the main control MCU and the data output terminal to the wireless communication module, and restricts the direct data transmission path between the main control MCU and the wireless communication module to avoid bypassing the security chip. This constructs a forced serial data link of "main control MCU → security chip → wireless communication module," ensuring that key data must be hardware encrypted through the security chip before being sent. This technical solution allows the main control MCU to only be responsible for key scanning and basic control, unable to obtain plaintext key data, and unable to communicate directly with the wireless communication module without bypassing the security chip. It fundamentally solves the problem of data leakage on the main control side and achieves end-to-end hardware encryption from the input source.

[0030] Second, this invention uses a security chip that supports national cryptographic algorithms (SM2 / SM3 / SM4) and integrates a true random number generator. It generates a dynamic session key for each communication, which complies with the compliance requirements of the Cryptography Law of the People's Republic of China and related national standards for cryptographic applications. It can effectively prevent replay attacks and is suitable for government, finance, military and other fields with strict requirements for cryptographic compliance.

[0031] Third, this invention allows users to freely switch between normal and security modes via a mode switch. In normal mode, data is transmitted directly without encryption, and the security chip can enter a low-power state to extend battery life. In security mode, all data is transmitted after hardware encryption, providing the highest level of security. This technical solution balances data protection in high-security scenarios with low power consumption requirements in daily use, resolving the technical contradiction of balancing security and power consumption.

[0032] Fourth, this invention visualizes the security status by setting a safety indicator light and configuring its illumination mode in different states. Users can intuitively understand the current security status of the keyboard without relying on a software interface, effectively avoiding misoperation and security oversights caused by unclear status.

[0033] Fifth, this invention provides a convenient secure mode wake-up mechanism by setting a security trigger button and connecting it to the interrupt pin of the main control MCU. When users need to input sensitive information, they only need to press the security trigger button to wake up the security chip and automatically switch to secure mode, avoiding the power waste caused by the continuous operation of the security chip and significantly improving ease of use.

[0034] Sixth, by integrating a USB wired interface and supporting two-way encryption authentication, this invention enables the keyboard to be used simultaneously as an input device and a hardware encryption device in wired mode, which can replace the traditional U-shield function and realize a wired and wireless integrated secure input solution.

[0035] Seventh, this invention achieves financial-grade key lifecycle management capabilities by embedding tamper-proof non-volatile memory and multiple sensors within the security chip. The private key is generated, stored, and used internally within the chip, never leaving the security chip; voltage and frequency detection sensors and an active shielding layer effectively resist physical attacks; once an attack attempt is detected, sensitive data is automatically erased, ensuring the absolute security of the key materials.

[0036] Eighth, by supporting Bluetooth and 2.4G dual-mode wireless communication and ensuring that encryption is uniformly performed by a security chip in different modes, this invention decouples security functions from wireless communication modes, avoids security degradation caused by switching wireless modes, and ensures a uniform security level under different wireless connection methods.

[0037] In summary, this invention reconstructs the keyboard's data processing link at the hardware architecture level, bringing security encryption capabilities down to the very front of the input device. Through the organic combination of a series of technical features such as the serial structure of the security chip, support for national cryptographic algorithms, mode switching, status indication, physical triggering, wired expansion, tamper-proof storage, and dual-mode compatibility, it effectively overcomes various defects in the prior art, and has outstanding substantive features and significant progress. Attached Figure Description

[0038] Figure 1 This is a schematic diagram of the overall structure of a dual-mode keyboard with a security encryption module in an embodiment of the present invention;

[0039] Figure 2 This is a block diagram of the internal circuit module and a schematic diagram of the data flow of the dual-mode keyboard in an embodiment of the present invention;

[0040] Figure 3 This is a schematic diagram of the circuit connection and state switching of the mode switching switch in an embodiment of the present invention;

[0041] Figure 4 This is a schematic diagram of the internal functional modules and anti-tampering structure of the security chip in an embodiment of the present invention;

[0042] Figure 5 This is a schematic diagram showing the connection between the safety trigger button and the interrupt pin of the main control MCU in an embodiment of the present invention;

[0043] Figure 6 This is a timing diagram illustrating the data encryption and transmission process in an embodiment of the present invention. Detailed Implementation

[0044] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0045] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.

[0046] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.

[0047] Example 1: Basic Hardware Architecture and Data Encryption Path

[0048] This embodiment mainly corresponds to the infrastructure described in claim 1.

[0049] like Figure 1 and Figure 2 As shown, this embodiment provides a dual-mode keyboard with a security encryption module, including a housing 100, a key array 200, a main control circuit board 300, a wireless communication module 400, and a security encryption module 500.

[0050] The housing 100 is made of insulating material, and its interior forms a receiving space for accommodating and securing the main control circuit board 300 and other electronic components. The housing 100 includes an upper cover 110 and a bottom cover 120, which are fixedly connected by snap-fits or screws. Multiple mounting holes are provided on the upper surface of the housing 100 for mounting the button array 200. USB interface mounting holes and mode switch mounting holes are also provided on the sides or rear of the housing 100. Preferably, the housing 100 can be manufactured using ABS+PC plastic through injection molding; in other embodiments, the housing 100 can also be made of aluminum alloy through CNC machining.

[0051] A button array 200 is disposed on the upper surface of the housing 100, including multiple button caps 210 and corresponding button switches 220. The button switches 220 can employ mechanical shafts or membrane contact structures. When a user presses a button cap 210, the button switch 220 generates a corresponding electrical signal, which is transmitted to the main control circuit board 300 through conductive lines. The layout of the button array 200 can adopt a standard 104-key layout or an 87-key compact layout, which can be adjusted according to the actual product positioning. In this embodiment, the button array 200 uses mechanical shafts; in other embodiments, membrane switches or optical shaft switches can also be used.

[0052] The main control circuit board 300 is fixedly mounted inside the housing 100 and adopts a multi-layer PCB design. The main control circuit board 300 integrates a main control MCU chip 310, which is responsible for the scanning, debouncing, key value mapping, and communication protocol processing of the entire keyboard. Preferably, the main control MCU chip 310 can be an ARM Cortex-M series processor, such as the STM32F103RET6; in other embodiments, processors with similar functions, such as GD32 or MM32, or MCUs with other architectures can also be used. The main control circuit board 300 also includes a key interface circuit 320 electrically connected to the key array 200, used to receive and filter the electrical signals generated by the key switches 220. The key interface circuit 320 can use a matrix scanning method, with row and column lines connected to the GPIO pins of the main control MCU chip 310, and detects the on / off state of the keys through a row and column scanning algorithm. The main control circuit board 300 also includes a power management circuit 330 to provide stable operating voltage for each module. The power management circuit 330 may include a lithium battery charging management chip, a boost converter, and a low dropout linear regulator, supporting both built-in lithium battery power supply and external USB power supply modes.

[0053] The wireless communication module 400 is mounted on the main control circuit board 300 and electrically connected to the main control MCU chip 310. In this embodiment, the wireless communication module 400 supports at least Bluetooth communication mode. Preferably, the wireless communication module 400 can use a Bluetooth 5.0 chip, such as the Nordic nRF52840, which supports Bluetooth Low Energy mode; in other embodiments, other types of Bluetooth chips or a combination chip supporting multiple wireless protocols can also be used. The wireless communication module 400 includes a radio frequency antenna 410 and a matching circuit. The radio frequency antenna 410 can be an on-board inverted-F antenna or an external ceramic antenna.

[0054] The security encryption module 500 is also housed within the housing 100 and integrated onto the main control circuit board 300. The core component of the security encryption module 500 is an independent security chip 510. Preferably, the security chip 510 can be a dedicated financial-grade security chip, such as the Huada Electronics CIU98_B series, which supports the national cryptographic algorithms SM2 / SM3 / SM4 and has EAL4+ security level certification. In other embodiments, the Unisplendour THD89 series or other security chips with hardware encryption functions can also be used. The security chip 510 is mounted on the main control circuit board 300 using SMT technology, and its power supply pins are equipped with decoupling capacitors to filter out power supply noise.

[0055] The key structural feature of this embodiment lies in the circuit connection method of the security chip 510. For example... Figure 2 As shown, the data input terminal of the security chip 510 is electrically connected to the main control MCU chip 310, and the data output terminal of the security chip 510 is electrically connected to the data input terminal of the wireless communication module 400. Specifically, a first data bus 511 connects the main control MCU chip 310 and the security chip 510, and a second data bus 512 connects the security chip 510 and the wireless communication module 400. The first data bus 511 and the second data bus 512 are physically isolated from each other, and the security chip 510 acts as an intermediate node to process the data passing through it.

[0056] In this embodiment, the data input terminal of the security chip 510 is electrically connected to the SPI pin of the main control MCU chip 310 via an SPI interface, and the data output terminal of the security chip 510 is electrically connected to the UART input terminal of the wireless communication module 400 via a UART interface. Preferably, the SPI interface transmission rate can be set between 1Mbps and 10Mbps, and in this embodiment, 2Mbps is preferred; the UART interface baud rate can be set between 9600bps and 921600bps, and in this embodiment, 115200bps is preferred. In other embodiments, I2C, USB, or other communication interfaces can also be used to achieve the above connection.

[0057] It is particularly important to emphasize that in the circuit layout of this embodiment, the security chip 510 is connected in series in the data transmission path between the main control MCU chip 310 and the wireless communication module 400, forming a serial data link of "main control MCU → security chip → wireless communication module". There is no direct data path between the main control MCU chip 310 and the wireless communication module 400 that does not pass through the security chip 510. During PCB routing, the TXD / UART output pin of the main control MCU chip 310 is only connected to the RXD / UART input pin of the security chip 510, and not connected to any pin of the wireless communication module 400, thereby physically ensuring the mandatory and unbypassable nature of the data transmission path. This feature corresponds to the limitation in claim 1 that "there is no direct data transmission path between the main control MCU and the wireless communication module that bypasses the security chip".

[0058] When a user presses any key in the key array 200, the electrical signal generated by the key switch 220 is acquired by the key interface circuit 320 and converted into a digital signal. The main control MCU chip 310 reads the digital signal through a row and column scanning algorithm and performs key value mapping processing to generate a raw data packet containing the key code. Preferably, the data packet format may include a start byte, device ID, key code, timestamp, and checksum; in other embodiments, other custom formats may also be used. This raw data packet is sent to the security chip 510 through the first data bus 511.

[0059] After receiving the original data packet, the security chip 510 first verifies the integrity of the data packet, then calls its internally embedded encryption algorithm and uses a pre-stored key or a dynamically generated session key to encrypt the data packet, generating an encrypted data packet. The encryption algorithm can be either symmetric or asymmetric. After encryption, the security chip 510 sends the encrypted data packet to the wireless communication module 400 via the second data bus 512. The wireless communication module 400 assembles and modulates the encrypted data packet according to the Bluetooth protocol specification and transmits the wireless signal to the external host via the radio frequency antenna 410.

[0060] After receiving the wireless signal, the external host demodulates and parses it using the corresponding driver or security middleware to recover the encrypted data packets. Subsequently, the host software uses the corresponding key to decrypt the data, recover the original button information, and injects it into the operating system's input subsystem.

[0061] Through the above structural design, this embodiment achieves hardware-level encryption protection starting from the source of button input. In the entire data processing chain, the original button data only appears in two locations: the instant the button switch 220 generates an electrical signal, and inside the security chip 510. Although the main control MCU chip 310 is responsible for key-value mapping, it sends the original data that needs to be encrypted to the security chip 510; the data inside the security chip 510 cannot be directly read through an external interface. Therefore, even if the data during wireless communication is maliciously intercepted, an attacker cannot decrypt and restore the original button content; even if the firmware of the main control MCU chip 310 is maliciously tampered with or the debugging interface is illegally accessed, because the security chip 510 operates independently of the main control MCU chip 310 and has a physical anti-attack design, attackers still cannot obtain plaintext button data.

[0062] Example 2: Support for Chinese Cryptographic Algorithms and True Random Number Generator

[0063] This embodiment is a further optimization based on embodiment 1, and mainly corresponds to the technical solutions described in claims 2 and 3.

[0064] like Figure 2 and Figure 4 As shown, the security chip 510 used in this embodiment is a national cryptographic security chip, specifically supporting the SM2 elliptic curve public key cryptography algorithm, the SM3 cryptographic hash algorithm, and the SM4 block cipher algorithm. The security chip 510 integrates a hardware true random number generator 511, which generates random numbers based on internal physical noise sources to generate dynamic session keys each time the keyboard is powered on or each time secure mode is initiated.

[0065] Specifically, when the keyboard powers on and initializes, the main control MCU chip 310 sends an initialization command to the security chip 510. In response to this command, the security chip 510 starts a true random number generator 511 to generate a pair of temporary session public and private keys. The session private key is stored in a secure storage area within the security chip 510, while the session public key is sent to an external host via the wireless communication module 400. Upon receiving the session public key, the host signs it using its own private key and returns an authentication data packet. After the security chip 510 verifies the host's identity, both parties establish a secure encrypted channel. The session key generation process conforms to the SM2 key pair generation specification.

[0066] In each subsequent key press encryption operation, the security chip 510 uses the SM4 algorithm combined with a session key to encrypt the key press data. Preferably, the encryption mode can be CBC mode or CTR mode. Since the session key is randomly generated each time it is powered on and is not transmitted in plaintext over the wireless link, even if an attacker intercepts a wireless data packet at a certain moment, they cannot use it to decrypt key press data from other time periods, effectively preventing replay attacks.

[0067] The true random number generator 511 can be implemented using a ring oscillator sampling circuit. It accumulates entropy through the phase jitter of multiple ring oscillators, and then generates true random numbers via a digital post-processing module. Preferably, the digital post-processing module can employ a de-biasing algorithm conforming to the NIST SP800-90B standard. In other embodiments, other physical true random number generation techniques may also be used.

[0068] In addition, the security chip 510 integrates an SM3 hash algorithm module 512, which performs hash operations on critical data to ensure data integrity. For example, during firmware upgrades, the security chip 510 uses the SM3 algorithm to verify the hash value of the firmware package, preventing malicious firmware from being loaded.

[0069] Example 3: Mode Switching and Power Consumption Optimization

[0070] This embodiment is a further optimization based on embodiment 1 or embodiment 2, and mainly corresponds to the technical solution described in claim 4.

[0071] like Figure 2 and Figure 3 As shown, the main control circuit board 300 also includes a mode switch 600, which has at least two positions: a first position 610 and a second position 620. The mode switch 600 is connected to the main control MCU chip 310 via GPIO pins. Preferably, the mode switch 600 can be a three-pin two-position toggle switch; in other embodiments, a rotary encoder switch, a push-button switch, or other switching elements with position detection function can also be used.

[0072] The circuit connection of the mode switching switch 600 is as follows: Figure 3 As shown: the first gear position 610 is connected to the first detection pin of the main control MCU chip 310, and the second gear position 620 is connected to the second detection pin of the main control MCU chip 310. The main control MCU chip 310 determines the current gear position by detecting the level status of the two pins.

[0073] When the mode switch 600 is in the first position 610, the main control MCU chip 310 configures the keyboard to normal mode. In normal mode, the input data generated by the key array 200 is directly transmitted to the wireless communication module 400 without being encrypted by the security chip 510. Specifically, one of the following solutions can be adopted: the main control MCU chip 310 is configured with a transparent transmission mode for the data interface, and the security chip 510 only acts as a data repeater without encryption; or a simulated switch is set, so that the data path bypasses the security chip 510 in normal mode; or the security chip 510 enters a low-power sleep mode, and the main control MCU chip 310 communicates directly with the wireless communication module 400 through a bypass path. This embodiment preferably adopts the simulated switch solution. In normal mode, the security chip 510 can enter a low-power state, reducing power consumption to the microamp level to extend battery life. Normal mode is suitable for non-sensitive scenarios such as daily text input and web browsing.

[0074] When the mode switch 600 is in the second position 620, the main control MCU chip 310 configures the keyboard to secure mode. In secure mode, the main control MCU chip 310 first wakes up the security chip 510, and then encrypts all key data through the security chip 510 before sending it to the wireless communication module 400. Wake-up can be achieved by sending a pulse signal via a dedicated wake-up pin. After being woken up, the security chip 510 performs a self-test and session key negotiation, and then enters full-function operation. Secure mode is suitable for highly sensitive scenarios such as online banking transactions, digital signatures, and password input.

[0075] Through the above design, this embodiment realizes hardware-level switching between normal mode and security mode, which users can freely choose according to their actual needs. It ensures data protection in high-security scenarios while also taking into account the low power consumption requirements during daily use.

[0076] Example 4: USB wired interface and two-way encryption authentication

[0077] This embodiment is a further optimization based on any one of the embodiments 1 to 3, and mainly corresponds to the technical solution described in claim 5.

[0078] like Figure 1 and Figure 2 As shown, the dual-mode keyboard also includes a USB wired interface 700, which is disposed on the housing 100 and electrically connected to the main control circuit board 300. Preferably, the USB wired interface 700 can be a USB Type-C interface conforming to the USB 2.0 specification; in other embodiments, a Micro USB or standard USB-A interface can also be used.

[0079] When connected to an external host via the USB wired interface 700, the keyboard receives power through the USB cable and establishes a USB communication link. In this operating mode, the wireless communication module 400 can be turned off to save power or kept on to meet the needs of multiple device connections. Upon detecting a USB insertion event, the main control MCU chip 310 automatically switches to USBHID device mode.

[0080] The improvement in this embodiment is that when the keyboard is working in wired mode and security mode is enabled, the security encryption module 500 not only undertakes the task of encrypting the key data, but also performs bidirectional encryption authentication with the external host through the USB channel. Specifically, the security chip 510 has a digital certificate pre-stored inside, which contains a public key and identity information, and the certificate format can adopt the X.509 v3 standard.

[0081] The two-way encryption authentication process is as follows: The host generates a random number and sends it to the keyboard via USB interface; the main control MCU chip 310 forwards the random number to the security chip 510; the security chip 510 signs the random number using its internal private key and returns the signature result and digital certificate to the host; the host verifies the validity of the digital certificate and the correctness of the signature; after successful verification, both parties establish an encrypted channel. After the encrypted channel is established, subsequent key press data is transmitted within this encrypted channel. Simultaneously, the security chip 510 can also receive encryption commands from the host, such as digitally signing or encrypting specified data, and return the result to the host.

[0082] In this mode, the keyboard is used as both an input device and a hardware encryption device, replacing the traditional U-shield function.

[0083] Example 5: Safety Indicator Lights and Status Visualization

[0084] This embodiment is a further optimization based on any one of the embodiments 1 to 4, and mainly corresponds to the technical solution described in claim 6.

[0085] like Figure 1 and Figure 5 As shown, the security encryption module 500 also includes a security indicator light 800, which is located in an easily observable position on the housing 100, such as the upper right corner of the keyboard or near the Caps Lock indicator light. The security indicator light 800 is electrically connected to the main control circuit board 300 or the security chip 510.

[0086] The security indicator light 800 is configured to emit a first color light, such as green, when data flows through the security chip 510 for encryption, i.e., when the keyboard is in secure mode and under normal encryption. This visually indicates to the user that the system is currently in a secure encryption state. When the security chip 510 detects an anomaly, such as authentication failure, key tampering, or a physical attack, the security indicator light 800 emits a second color light or flashes, such as a flashing red light, to warn the user of a potential security risk.

[0087] When the keyboard is in normal mode, the security indicator light 800 can be turned off. When security mode is enabled but the security chip 510 is not yet ready, the security indicator light 800 can emit a third color light or flash slowly, such as yellow light, to prompt the user to wait.

[0088] Preferably, the safety indicator light 800 can use a dual-color LED (e.g., a red-green dual-color LED), and the brightness and combination of the red and green colors can be controlled by PWM to achieve multiple color indications. In other embodiments, a single-color LED with different flashing frequencies can also be used to achieve status indication, or an RGB LED can be used to achieve richer indication effects.

[0089] Through the above design, this embodiment achieves visualization of the security status, allowing users to intuitively understand the current security status of the keyboard without the need for a software interface.

[0090] Example 6: Safety Trigger Button and Instant Wake-up

[0091] This embodiment is a further optimization based on any one of the embodiments 1 to 5, and mainly corresponds to the technical solution described in claim 7.

[0092] like Figure 1 and Figure 5 As shown, the key array 200 includes a safety trigger button 230, which is located at a specific position on the keyboard, such as the function key area. The keycap may be printed with an easily identifiable symbol, such as a lock icon. The safety trigger button 230 is electrically connected to the interrupt pin of the main control circuit board 300.

[0093] Specifically, the safety trigger button 230 is electrically connected to the GPIO pin of the main control MCU chip 310. This pin is configured as an external interrupt input and has an internal pull-up resistor enabled. When the button is not pressed, the pin is at a high level; when the button is pressed, the pin is grounded and becomes low, generating a falling edge interrupt signal.

[0094] When the keyboard is in normal mode or standby mode and the security chip 510 is in low-power sleep mode, if the user needs to input sensitive information, they only need to press the security trigger button 230. When the security trigger button 230 is pressed, an interrupt signal is generated. After the main control MCU chip 310 detects the interrupt signal, it immediately executes the preset interrupt service routine. This routine performs the following operations: stops the current normal data flow; wakes up the security chip 510; waits for the security chip 510 to be ready; switches the data path to secure mode; re-establishes the encrypted channel with the host; and illuminates the security indicator light 800.

Claims

1. A dual-mode keyboard with a security encryption module, characterized in that, include: The device comprises: a housing (100); a key array (200) disposed on the housing (100); a main control circuit board (300) disposed inside the housing (100) and electrically connected to the key array (200), wherein a main control MCU (310) is integrated on the main control circuit board (300); a wireless communication module (400) disposed on the main control circuit board (300), wherein the wireless communication module (400) supports at least Bluetooth communication mode; and a security encryption module (500) disposed inside the housing (100) and integrated on the main control circuit board (300), wherein the security encryption module (500) includes an independent security chip (510); its features are as follows: The data input terminal of the security chip (510) is electrically connected to the main control MCU (310), and the data output terminal of the security chip (510) is electrically connected to the wireless communication module (400). This allows the input data generated by the key array (200) to flow sequentially through the main control MCU (310) and the security chip (510), whereby the security chip (510) performs hardware encryption to generate encrypted data, which is then sent to an external host by the wireless communication module (400). Furthermore, there is no direct data transmission path between the main control MCU (310) and the wireless communication module (400) that bypasses the security chip (510).

2. The dual-mode keyboard according to claim 1, characterized in that, The security chip (510) is a national cryptographic security chip that supports at least one of the following: SM2 elliptic curve public key cryptography algorithm, SM3 cryptographic hash algorithm and SM4 block cipher algorithm.

3. The dual-mode keyboard according to claim 2, characterized in that, The security chip (510) integrates a true random number generator (511) for generating dynamic session keys.

4. The dual-mode keyboard according to claim 1, characterized in that, The main control circuit board (300) is also provided with a mode switching switch (600), which has at least two positions: a first position (610) and a second position (620). When the mode switching switch (600) is in the first position (610), the input data generated by the key array (200) is directly transmitted to the wireless communication module (400) without being encrypted by the security chip (510). When the mode switching switch (600) is in the second position (620), the input data generated by the key array (200) is transmitted to the security chip (510) for encryption before being transmitted to the wireless communication module (400).

5. The dual-mode keyboard according to claim 1, characterized in that, It also includes a USB wired interface (700), which is electrically connected to the main control circuit board (300); when connected to an external host through the USB wired interface (700), the security encryption module (500) is also used to perform bidirectional encryption authentication with the external host through the USB channel.

6. The dual-mode keyboard according to claim 1, characterized in that, The security encryption module (500) further includes a security indicator light (800), which is disposed on the housing (100) and electrically connected to the main control circuit board (300) or the security chip (510). The security indicator light (800) is configured to emit a first color light when the data stream passes through the security chip (510) for encryption processing, and emit a second color light or flash when an anomaly is detected.

7. The dual-mode keyboard according to claim 1, characterized in that, The button array (200) includes a security trigger button (230), which is electrically connected to the interrupt pin of the main control circuit board (300). When the security trigger button (230) is pressed, the main control circuit board (300) responds to the interrupt signal to wake up the security encryption module (500) and make it enter the working state from the low power state.

8. The dual-mode keyboard according to claim 1, characterized in that, The security chip (510) has a built-in non-volatile memory (513) for storing private keys, digital certificates and encryption algorithm firmware; the non-volatile memory (513) has an anti-tamper design, including at least one of a voltage detection sensor (514), a frequency detection sensor (515) and an active shielding layer (517); when an attack is detected, the security chip (510) automatically erases the sensitive data stored in the non-volatile memory (513).

9. The dual-mode keyboard according to claim 1, characterized in that, The wireless communication module (400) also supports 2.4G wireless communication mode, which together with Bluetooth mode constitutes dual-mode wireless communication; When the keyboard is working in 2.4G mode and security mode is enabled, the security chip (510) also encrypts the data.

10. A secure input method based on the dual-mode keyboard according to any one of claims 1-9, characterized in that, The steps include: the key array (200) generates input data in response to user presses; The main control MCU (310) collects the input data and generates a raw data packet; the raw data packet is sent to the security chip (510); the security chip (510) performs hardware encryption on the raw data packet to generate an encrypted data packet; the encrypted data packet is sent to the wireless communication module (400) or the USB wired interface (700); the wireless communication module (400) or the USB wired interface (700) outputs the encrypted data packet to an external host.