Independent data isolation system and method based on hardware-level physical isolation
By using a hardware-level physical isolation system and multi-core heterogeneous system-on-a-chip to achieve hardware-level data flow control, the problems of unreliable data isolation and delayed emergency response are solved, and high-security and fast-response data protection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING ZHONGHAI WATSON MEDICAL TECHNOLOGY CO LTD
- Filing Date
- 2026-01-22
- Publication Date
- 2026-05-29
Smart Images

Figure CN122113179A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data isolation, and in particular relates to an independent data isolation system and method based on hardware-level physical isolation. Background Technology
[0002] The core purpose of data isolation is to differentiate data of different security levels at the storage, processing, and transmission levels, thereby preventing low-value or poorly protected data from becoming a springboard for attacks on high-value data. Since no complex system can be assumed to be "absolutely unbreakable" in reality, data isolation effectively curbs the lateral spread of attacks by limiting the accessibility and flow path of data, controlling the impact of security incidents within a local scope, while reducing system complexity, improving security controllability, and meeting the basic requirements of compliance auditing and high-level security protection.
[0003] The existing technology has the following drawbacks: Isolation is unreliable. The virtualization layer is a software isolation layer, which has the vulnerability of unauthorized access, which may lead to the leakage of targeted data through shared hardware resources; The encryption security is insufficient. The software encryption key is stored in memory and can be extracted through cold start attacks, which means that high-value data is at risk of being cracked offline. The delayed emergency response, relying on software erasure, takes more than 10 seconds, making it impossible to deal with physical hijacking attack scenarios. Summary of the Invention
[0004] In view of this, the present invention aims to propose an independent data isolation system and method based on hardware-level physical isolation, in order to solve at least one of the above-mentioned technical problems.
[0005] To achieve the above objectives, the technical solution of the present invention is implemented as follows: The first aspect of this invention proposes an independent data isolation system based on hardware-level physical isolation, comprising: A dedicated security processing unit, which is a multi-core heterogeneous system-on-a-chip, integrates multiple functional modules interconnected via a hardware security bus. These multiple functional modules include at least: The national cryptographic algorithm acceleration core is used to implement the encryption, decryption, and computation processing of national cryptographic algorithms; A general-purpose control core is used to perform task scheduling, inter-core communication, and external interface protocol processing. A secure storage core is used to generate unique physical keys and support quantum key injection. An isolation control core is used for physical isolation of data flows via hardware mutexes and bus tag controllers; A self-destruct circuit breaker module, which is connected to a dedicated security processing unit and controlled by an isolation control core, is used to quickly destroy critical data and pathways. In this dedicated security processing unit, all data streams are physically isolated and controlled via an isolation control core, which does not rely on any software for execution.
[0006] Furthermore, the national cryptographic algorithm acceleration core executes the encryption and decryption processing of the national cryptographic standard algorithm through a hardware state machine. The hardware state machine does not support software instruction intervention, and the encryption and decryption operations are completely implemented by hardware.
[0007] Furthermore, the hardware mutex of the isolation control core achieves mode switching through a physical trigger circuit. The mode switching can only be triggered by an external hardware authentication signal, and the state of the hardware mutex does not support software modification.
[0008] Furthermore, the bus tag controller implements data classification management through hardware-level data tagging. The data tags include "public" tags and "directed" tags. Data with "directed" tags can only flow in a dedicated directed path within the dedicated security processing unit and cannot be accessed through public interfaces.
[0009] Furthermore, the dedicated security processing unit is connected to an external fuse self-destruct module via a high-speed electrical pulse signal. When the fuse self-destruct module detects a security threat, it responds by physically breaking and destroying the critical data stored in the system. The critical data includes at least the root key, session key, and their encryption information.
[0010] The second aspect of this invention proposes an independent data isolation method based on hardware-level physical isolation, applying the independent data isolation system based on hardware-level physical isolation described in the first aspect, comprising: S1. The directional device initiates a connection request to the dedicated security processing unit through the physical direct connection network. The dedicated security processing unit verifies the hardware identity of the directional device and completes hardware-level authentication. The authentication process is based on dedicated hardware resources. S2. After hardware authentication is passed, the dedicated security processing unit will limit the system to the targeted isolation mode and open the physical isolation data channel corresponding to the targeted device at the hardware level. S3. When targeted data enters the dedicated security processing unit, the isolation control core automatically generates a corresponding hardware tag at the hardware level. Data carrying the hardware tag only flows in the matched physical isolation data channel. S4. For data carrying hardware tags, call hardware cryptographic computing resources and encrypt the data based on the key material protected by the secure storage kernel. The processed data is then written to the physical isolation storage area corresponding to the directional isolation mode. S5. When a security threat is detected, the dedicated security processing unit triggers a hardware-level self-destruct mechanism to physically destroy critical data through a fuse circuit.
[0011] Furthermore, in step S1: The hardware identity verification is based at least on the physical unique identifier of the targeted device. The physical unique identifier is derived from the physical difference characteristics in the device manufacturing process, and the hardware identity verification process does not depend on software configuration parameters or rewritable storage content. The physical direct connection network is an IP-free topology network. The physical direct connection network does not support address-based routing and forwarding mechanisms at the protocol layer, so that a non-redirectable data connection relationship is formed between the directional device and the dedicated security processing unit.
[0012] Furthermore, in step S3: The hardware tag is generated by the isolation control core through non-softwareable hardware logic, and the hardware tag is propagated synchronously with the data during data transmission. Any data that does not carry a matching hardware tag is blocked from the corresponding physical path.
[0013] Furthermore, in step S4: The key material includes a root key generated by a Physically Unclonable Function (PUF) and a session key protected by the root key, and the session key is updated according to a preset strategy.
[0014] Furthermore, in step S5: The hardware-level self-destruct mechanism uses a backup power source to physically destroy critical storage units and data paths in the event of a power failure or power outage.
[0015] Compared with existing technologies, the independent data isolation system and method based on hardware-level physical isolation described in this invention has the following advantages: By employing hardware-level physical isolation technology, we have successfully protected against all potential bypass attacks with a 0% bypass success rate. Compared to existing virtualization-based solutions, which have a bypass success rate of up to 23%, this solution demonstrates an absolute advantage in physical isolation.
[0016] By combining quantum key distribution technology and hardware acceleration, the key cracking time exceeds 100 years, significantly enhancing the system's security. In contrast, existing technologies relying on memory extraction can crack the key in just about 2 hours, demonstrating a five-order-of-magnitude improvement in key protection offered by this solution.
[0017] Employing a hardware-level self-destruct mechanism, the response time is 8.3 milliseconds, enabling data destruction within milliseconds, far superior to the existing technology's 12.4-second response time, achieving a 1500-fold improvement in response speed. Attached Figure Description
[0018] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings: Figure 1 This is a schematic diagram illustrating the workflow of the independent data isolation method based on hardware-level physical isolation as described in an embodiment of the present invention. Detailed Implementation
[0019] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.
[0020] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.
[0021] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art will understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0022] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0023] Independent data isolation systems based on hardware-level physical isolation include: A dedicated security processing unit, which is a multi-core heterogeneous system-on-a-chip, integrates multiple functional modules interconnected via a hardware security bus. These multiple functional modules include at least: The national cryptographic algorithm acceleration core is used to implement the encryption, decryption, and computation processing of national cryptographic algorithms; A general-purpose control core is used to perform task scheduling, inter-core communication, and external interface protocol processing. A secure storage core is used to generate unique physical keys and support quantum key injection. An isolation control core is used for physical isolation of data flows via hardware mutexes and bus tag controllers; A self-destruct circuit breaker module, which is connected to a dedicated security processing unit and controlled by an isolation control core, is used to quickly destroy critical data and pathways. In this dedicated security processing unit, all data streams are physically isolated and controlled via an isolation control core, which does not rely on any software for execution.
[0024] The national cryptographic algorithm acceleration core executes the encryption and decryption processing of the national cryptographic standard algorithm through a hardware state machine. The hardware state machine does not support software instruction intervention, and the encryption and decryption operations are completely implemented by hardware.
[0025] The hardware mutex of the isolation control core achieves mode switching through a physical trigger circuit. The mode switching can only be triggered by an external hardware authentication signal, and the state of the hardware mutex does not support software modification.
[0026] The bus tag controller classifies and manages data through hardware-level data tagging. The data tags include "public" tags and "directed" tags. Data with "directed" tags can only flow in a dedicated directed path within the dedicated security processing unit and cannot be accessed through public interfaces.
[0027] The dedicated security processing unit is connected to an external fuse self-destruct module via a high-speed electrical pulse signal. When the fuse self-destruct module detects a security threat, it responds by physically breaking and destroying the critical data stored in the system. The critical data includes at least the root key, session key, and their encryption information.
[0028] In some embodiments, the specific architecture of the above-described independent data isolation system based on hardware-level physical isolation is shown below: The core idea of the independent data isolation system is to integrate functions such as isolation control, national cryptographic algorithm acceleration, quantum key fusion, and emergency destruction into a single security chip (SPU) through a multi-core heterogeneous architecture, thereby ensuring the separation and control of data flow at the physical level.
[0029] The system mainly includes: a dedicated security processing unit (SPU), a directional data storage array, a public data processing unit, a hardware mutex control circuit, an IP-free topology direct connection network, and a fuse self-destruct module. All directional data I / O and control must pass through the SPU, forming a "security heart" architecture with the SPU as the only trusted hardware.
[0030] The SPU adopts a self-developed multi-core heterogeneous system-on-a-chip (SoC) design, integrating the following core functional modules at the physical silicon level and interconnecting them through an internal hardware security bus: The national cryptographic algorithm acceleration core implements national cryptographic standard algorithms such as SM2 (asymmetric encryption), SM3 (hash algorithm), and SM4 (symmetric encryption) in the form of hardware logic circuits, providing high-speed, software-free cryptographic operation capabilities. It transforms encryption operations from software execution on general-purpose CPUs to physical execution on dedicated hardware, completely eliminating side-channel attacks (such as timing attacks and power consumption analysis) caused by CPU cache and memory timing, and significantly improving encryption efficiency.
[0031] The general-purpose control core, employing a reduced instruction set, is responsible for basic control logic such as task scheduling, inter-core communication, and external interface protocol processing within the SPU. It is decoupled from the security function core to ensure the simplicity and reliability of the control flow and reduce the potential vulnerability surface introduced by complex logic.
[0032] The secure storage core integrates a Physically Unclonable Function (PUF) unit, utilizing the non-replicable physical differences generated during chip manufacturing to generate a root key unique to each chip and unreadable externally. Simultaneously, the core provides a quantum key injection interface for receiving truly random session keys from external quantum key distribution (QKD) devices.
[0033] It achieves the fusion of "chip fingerprinting" and "quantum random numbers". The PUF root key never leaves the chip and cannot be extracted. It is used to encrypt and protect externally injected quantum session keys, forming a dual key protection system of "hardware root of trust + quantum enhancement", which fundamentally solves the risk of key leakage in the storage stage.
[0034] The isolation control core, a pure digital logic circuit that does not run any software, is crucial for achieving physical isolation. It includes: A hardware mutex is a two-state switch composed of a physical trigger circuit. Its state ("open mode" / "directed mode") is directly switched by a certified hardware signal. The state change directly changes the electrical connection of the relevant physical channel. The two modes are mutually exclusive at the circuit level, and no software instruction can make it conduct at the same time or be in an intermediate state. The bus tag controller monitors all data transmissions on the SPU's internal security bus. When data enters from a specific port (such as a directed network interface), the controller automatically tags the data packet with the corresponding hardware tag ("public" or "directed") based on the current state of the hardware mutex. Data with the "directed" tag can only flow within the dedicated buffer and path configured for directed data within the SPU.
[0035] By switching control modes using a "mutex lock," the "tag controller" classifies the data. The two work together at the hardware level to achieve physical separation of the data flow. Even if malicious software gains control of the general control core, it cannot change the physical state of the mutex lock or tamper with the data tags already attached by the hardware, thus ensuring the unbreakable isolation.
[0036] The hardware fuse circuit interface provides a dedicated, high-drive-capability electrical pulse output pin that connects directly to an external thyristor fuse circuit. This interface is directly controlled by the isolation control core, bypassing all memory and software stacks. This ensures that the self-destruct instruction can be executed with the shortest hardware path and the fastest speed, which is the basis for achieving millisecond-level emergency response.
[0037] Independent data isolation methods based on hardware-level physical isolation, and the application of independent data isolation systems based on hardware-level physical isolation, including: S1. The directional device initiates a connection request to the dedicated security processing unit through the physical direct connection network. The dedicated security processing unit verifies the hardware identity of the directional device and completes hardware-level authentication. The authentication process is based on dedicated hardware resources. The hardware identity verification is based at least on the physical unique identifier of the targeted device. The physical unique identifier is derived from the physical difference characteristics in the device manufacturing process, and the hardware identity verification process does not depend on software configuration parameters or rewritable storage content. The physical direct connection network is an IP-free topology network. The physical direct connection network does not support address-based routing and forwarding mechanisms at the protocol layer, so that a non-redirectable data connection relationship is formed between the directional device and the dedicated security processing unit.
[0038] S2. After hardware authentication is passed, the dedicated security processing unit will restrict the system to a targeted isolation mode and open a physically isolated data channel corresponding to the targeted device at the hardware level.
[0039] S3. When targeted data enters the dedicated security processing unit, the isolation control core automatically generates a corresponding hardware tag at the hardware level. Data carrying the hardware tag only flows in the matched physical isolation data channel. The hardware tag is generated by the isolation control core through non-softwareable hardware logic, and the hardware tag is propagated synchronously with the data during data transmission. Any data that does not carry a matching hardware tag is blocked from the corresponding physical path.
[0040] S4. For data carrying hardware tags, call hardware cryptographic computing resources and encrypt the data based on the key material protected by the secure storage kernel. The processed data is then written to the physical isolation storage area corresponding to the directional isolation mode. The key material includes a root key generated by a Physically Unclonable Function (PUF) and a session key protected by the root key, and the session key is updated according to a preset strategy.
[0041] S5. When a security threat is detected, the dedicated security processing unit triggers a hardware-level self-destruct mechanism to physically destroy critical data through a fuse circuit. The hardware-level self-destruct mechanism uses a backup power source to physically destroy critical storage units and data paths in the event of a power failure or power outage.
[0042] In some embodiments, the specific execution flow of the above-described independent data isolation method based on hardware-level physical isolation is as follows: The entire lifecycle processing of targeted data follows a hardware-mandated process, which can be divided into five stages: Phase 1: Connection Establishment and Hardware Authentication The directional device sends a connection request frame through a non-IP topology network. The frame structure is: `[frame header][source hardware ID][destination hardware ID][random number]`; Without an IP header, it avoids the inherent vulnerability attack surface of the TCP / IP protocol stack, such as IP spoofing and TCP sequence number prediction. After receiving the frame, the isolation control core of the SPU first checks whether the target hardware ID is the local SPU. Then, it checks the physical state of the hardware mutex lock. If the lock is in "public mode", the request is directly discarded at the hardware level. If in "directed mode" or authorized to switch, the SPU uses the PUF key in the secure storage core to sign the random number and returns the signature result to the directed device to complete hardware-based two-way authentication.
[0043] Phase Two: Isolation Channel Activation and Data Tagging After authentication, the isolation control core will ensure that the hardware mutex is stably in "directional mode" through an uninterruptible hardware signal; Simultaneously, the bus tag controller is activated. From this point onward, all data flowing into the directional device port is automatically tagged with a "directional" hardware tag the instant it enters the SPU's internal security bus. This "tag" is a physical state on the bus level or a specific signal line, not a value in memory. The data flow is determined by a dedicated hardware path with this physical tag, which is invisible and unchangeable by software.
[0044] Phase Three: Data Encryption and Security Processing Data tagged with "directed" is imported into the national cryptographic algorithm acceleration core. The encryption process is as follows: Key preparation: Extract the quantum session key encrypted and protected by the PUF root key from the secure storage core; Encryption execution: Using this quantum session key, data is encrypted through the SM4 algorithm hardware circuit in the national cryptographic algorithm acceleration core; One-time pad reinforcement: After each session or after transmitting a specified amount of data, the quantum session key is updated to achieve "one-time pad" or high-frequency key updates. The encryption key comes from a quantum random source and is protected by the chip hardware PUF, achieving physical security throughout the entire process from generation and storage to use.
[0045] Phase Four: Secure Storage and Auditing The encrypted ciphertext data still carries a "directional" hardware tag and is written to a physically independent directional data storage array through a dedicated channel; After the write operation is completed, the SPU generates audit information for this operation (such as: operation type, target storage block hash, timestamp), and transmits it unidirectionally to an independent audit log system through a physical shutter; The physical optical gate can only transmit optical signals in one direction, ensuring that even if the audit log system is compromised, attackers will never be able to intrude into the SPU or the targeted storage area through this path.
[0046] Phase 5: Millisecond-level circuit breaker self-destruct mechanism: When the system sensors detect physical intrusion (such as the chassis being opened) or receive a remote destruction command that has been encrypted and authenticated through multiple layers, the SPU immediately triggers the circuit breaker self-destruct process. Independent power supply activation: Power is switched by the supercapacitor module within microseconds to ensure that the self-destruct command circuit is completely disconnected from the main power system, which may have been cut off or interfered with. Physical destruction execution: The SPU's fuse circuit interface outputs a high-energy electrical pulse, which drives the silicon controlled rectifier (SCR) to conduct instantly, forming a continuous large current that flows precisely to the data storage unit of the memory chip (such as the floating gate of the Flash memory unit), causing it to be physically melted or broken down. Experiments have verified that from the moment the trigger signal reaches the SPU pin to the moment the critical structure of the memory chip is physically destroyed, the entire process takes less than 10ms, achieving true instantaneous and irreversible destruction.
[0047] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered within the scope of the claims and specification of the present invention.
[0048] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An independent data isolation system based on hardware-level physical isolation, characterized in that, include: A dedicated security processing unit, which is a multi-core heterogeneous system-on-a-chip, integrates multiple functional modules interconnected via a hardware security bus. These multiple functional modules include at least: The national cryptographic algorithm acceleration core is used to implement the encryption, decryption, and computation processing of national cryptographic algorithms; A general-purpose control core is used to perform task scheduling, inter-core communication, and external interface protocol processing. A secure storage core is used to generate unique physical keys and support quantum key injection. An isolation control core is used for physical isolation of data flows via hardware mutexes and bus tag controllers; A self-destruct circuit breaker module, which is connected to a dedicated security processing unit and controlled by an isolation control core, is used to quickly destroy critical data and pathways. In this dedicated security processing unit, all data streams are physically isolated and controlled via an isolation control core, which does not rely on any software for execution.
2. The independent data isolation system based on hardware-level physical isolation according to claim 1, characterized in that: The national cryptographic algorithm acceleration core executes the encryption and decryption processing of the national cryptographic standard algorithm through a hardware state machine. The hardware state machine does not support software instruction intervention, and the encryption and decryption operations are completely implemented by hardware.
3. The independent data isolation system based on hardware-level physical isolation according to claim 1, characterized in that: The hardware mutex of the isolation control core achieves mode switching through a physical trigger circuit. The mode switching can only be triggered by an external hardware authentication signal, and the state of the hardware mutex does not support software modification.
4. The independent data isolation system based on hardware-level physical isolation according to claim 1, characterized in that: The bus tag controller classifies and manages data through hardware-level data tagging. The data tags include "public" tags and "directed" tags. Data with "directed" tags can only flow in a dedicated directed path within the dedicated security processing unit and cannot be accessed through public interfaces.
5. The independent data isolation system based on hardware-level physical isolation according to claim 1, characterized in that: The dedicated security processing unit is connected to an external fuse self-destruct module via a high-speed electrical pulse signal. When the fuse self-destruct module detects a security threat, it responds by physically breaking and destroying the critical data stored in the system. The critical data includes at least the root key, session key, and their encryption information.
6. A method for independent data isolation based on hardware-level physical isolation, using the independent data isolation system based on hardware-level physical isolation as described in claim 1, characterized in that: include: S1. The directional device initiates a connection request to the dedicated security processing unit through the physical direct connection network. The dedicated security processing unit verifies the hardware identity of the directional device and completes hardware-level authentication. The authentication process is based on dedicated hardware resources. S2. After hardware authentication is passed, the dedicated security processing unit will limit the system to the targeted isolation mode and open the physical isolation data channel corresponding to the targeted device at the hardware level. S3. When targeted data enters the dedicated security processing unit, the isolation control core automatically generates a corresponding hardware tag at the hardware level. Data carrying the hardware tag only flows in the matched physical isolation data channel. S4. For data carrying hardware tags, call hardware cryptographic computing resources and encrypt the data based on the key material protected by the secure storage kernel. The processed data is written to the physical isolation storage area corresponding to the directional isolation mode. S5. When a security threat is detected, the dedicated security processing unit triggers a hardware-level self-destruct mechanism to physically destroy critical data through a fuse circuit.
7. The independent data isolation method based on hardware-level physical isolation according to claim 6, characterized in that, In step S1: The hardware identity verification is based at least on the physical unique identifier of the targeted device. The physical unique identifier is derived from the physical difference characteristics in the device manufacturing process, and the hardware identity verification process does not depend on software configuration parameters or rewritable storage content. The physical direct connection network is an IP-free topology network. The physical direct connection network does not support address-based routing and forwarding mechanisms at the protocol layer, so that a non-redirectable data connection relationship is formed between the directional device and the dedicated security processing unit.
8. The independent data isolation method based on hardware-level physical isolation according to claim 6, characterized in that, In step S3: The hardware tag is generated by the isolation control core through non-software-programmable hardware logic, and the hardware tag is propagated synchronously with the data during data transmission. Any data that does not carry a matching hardware tag is blocked from the corresponding physical path.
9. The independent data isolation method based on hardware-level physical isolation according to claim 6, characterized in that, In step S4: The key material includes a root key generated by a Physically Unclonable Function (PUF) and a session key protected by the root key, and the session key is updated according to a preset strategy.
10. The independent data isolation method based on hardware-level physical isolation according to claim 6, characterized in that, In step S5: The hardware-level self-destruct mechanism uses a backup power source to physically destroy critical storage units and data paths in the event of a power failure or power outage.