A safety monitoring device based on VPX architecture

By adopting domestically produced core components and a modularly designed VPX architecture safety monitoring device, the problems of supply chain risk and insufficient reliability have been solved. Real-time parameter monitoring and fault diagnosis have been achieved, making it suitable for harsh environments such as national defense and aerospace, and improving the reliability and service life of the system.

CN122268787APending Publication Date: 2026-06-23SHENZHEN EWARE INFORMATION TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN EWARE INFORMATION TECH CO LTD
Filing Date
2026-03-31
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing security monitoring devices based on the VPX architecture pose supply chain security risks, have limited functionality, struggle to monitor key parameters in real time, and lack reliability in harsh environments.

Method used

It adopts core components such as the domestically produced Phytium D2000 processor, Phytium X100 bridge chip, GD32 microcontroller, Netcom network controller and TCM trusted card, and integrates intelligent management channels. Through the design of a heat conduction structure and modular combination, it realizes system status monitoring and management. It adopts a conductive heat dissipation method to eliminate supply chain risks and improve reliability.

Benefits of technology

It achieves full-chain autonomous control of the system, eliminates the risk of supply chain disruption, has real-time parameter monitoring and fault diagnosis capabilities, improves the perception and management efficiency of equipment health status, and is suitable for high-reliability operation in harsh environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122268787A_ABST
    Figure CN122268787A_ABST
Patent Text Reader

Abstract

This invention belongs to the field of information security and relates to a security monitoring device based on a VPX architecture. It includes: a main processing module for processing and computing business data; a bridge module electrically connected to the main processing module for expanding auxiliary peripherals; a management and control module electrically connected to both the main processing module and the bridge module for system status monitoring and management; a network communication module electrically connected to the bridge module for providing four gigabit Ethernet interfaces to enable data interaction between systems; and a first level conversion module electrically connected to both the management and control module and the main processing module. This invention achieves end-to-end autonomous control from computation and control to security, enabling the perception and management of device health status, significantly improving fault diagnosis efficiency and system maintainability. It can operate stably in harsh environments such as national defense and aerospace, significantly improving system reliability and lifespan.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and more specifically, to a security monitoring device based on the VPX architecture. Background Technology

[0002] Embedded computer systems are widely used in fields such as defense, aerospace, industrial control, and critical infrastructure for tasks such as data acquisition, signal processing, real-time control, and status monitoring. As application scenarios become increasingly complex, higher and higher demands are being placed on the computing power, reliability, security, and manageability of embedded computers.

[0003] Currently, most VPX-based security monitoring devices on the market use foreign processors and chips, posing potential risks to supply chain and information security. Meanwhile, traditional embedded computers have limited functionality in status monitoring, health management, and fault diagnosis, lacking a unified intelligent management channel and making it difficult to achieve real-time monitoring and reporting of key parameters such as system voltage, temperature, and FRU (Field Replaceable Unit) information. Furthermore, traditional designs struggle to meet the demands of high-reliability applications in harsh environments, such as heat dissipation and vibration resistance.

[0004] The VPX (VITA 46) architecture, as a high-reliability, high-bandwidth embedded system standard, has been widely used in military and aerospace fields. The 6U VPX standard size provides ample board space and rich interface definitions, suitable for integrating high-performance computing units and various peripheral interfaces. Conductive cooling avoids reliability issues associated with active cooling components such as fans, making it suitable for harsh environments.

[0005] Therefore, there is an urgent need to develop a safety monitoring device based on the VPX architecture, which is based on domestically produced core components, has complete status monitoring and management functions, and adopts a high-reliability structural design, in order to meet the comprehensive requirements of key fields for the security, reliability and manageability of embedded computers. Summary of the Invention

[0006] To address the aforementioned deficiencies in existing technologies, this invention provides a security monitoring device based on a VPX architecture, comprising: The main processing module is used for the calculation and processing of business data; The bridge module is electrically connected to the main processing module and is used to enable auxiliary peripheral expansion; The management and control module is electrically connected to the main processing module and the bridge module respectively, and is used to realize the status monitoring and management of the system. The network communication module, electrically connected to the bridge chip module, is used to provide four gigabit Ethernet interfaces to realize data interaction between systems. The first level conversion module is electrically connected to the management control module and the main processing module respectively, and is used to realize level matching between the management control module and the main processing module; The second level conversion module is electrically connected to the management and control module; the management sub-card is electrically connected to the second level conversion module and is used to collect environmental parameters and provide a management interface. A trusted security module, comprising a TCM trusted card, electrically connected to the main processing module, is used to enable trusted system startup and data encryption; A data storage module, including an SSD solid-state drive, is electrically connected to the bridge chip module and is used to store business data and system logs; The front panel interface module is electrically connected to the management and control module, and the front panel interface module is equipped with multiple status indicator LEDs. The main processing module, the bridge chip module, the management and control module, the network communication module, the first level conversion module, the second level conversion module, the management daughter card, the trusted security module, the data storage module, and the front panel interface module are all mounted on a standard 6U VPX architecture heat-conducting structure carrier board, and the modules are electrically connected to each other through VPX connectors and on-board wiring.

[0007] Preferably, the management sub-card includes a temperature sensor, an EEPROM memory, a test serial port, and an IPMB interface; The temperature sensor is electrically connected to the management sub-card and is used to collect internal temperature data of the device; The EEPROM memory is electrically connected to the management daughter card and is used to store FRU (Field Replaceable Unit) information; The test serial port is electrically connected to the management sub-card and is used to output debugging information; The IPMB interface is electrically connected to the management sub-card and is used to connect to the intelligent platform management bus to enable external management units to manage and communicate with the device.

[0008] Preferably, the plurality of status indicator LEDs provided on the front panel interface module include: A power LED, electrically connected to the management and control module, is used to indicate the power status of the device. The status LED, electrically connected to the management and control module, is used to indicate the operating status of the device; The hard drive LED, electrically connected to the management and control module, is used to indicate the working status of the data storage module; An alarm LED, electrically connected to the management and control module, is used to indicate the device's fault alarm status. A network LED, electrically connected to the management and control module, is used to indicate the link status of the network communication module; The TCM status LED is electrically connected to the management and control module and is used to indicate the working status of the trusted security module. The TCM alarm LED is electrically connected to the management and control module and is used to indicate the alarm status of the trusted security module.

[0009] Preferably, the first level conversion module includes a first bidirectional level conversion chip, with terminal A of the first bidirectional level conversion chip connected to the general-purpose input / output interface of the management and control module, and terminal B of the first bidirectional level conversion chip connected to the general-purpose input / output interface of the main processing module, for converting the 3.3V level signal of the management and control module into a 1.8V level signal acceptable to the main processing module, or converting the 1.8V level signal of the main processing module into a 3.3V level signal acceptable to the management and control module.

[0010] Preferably, the second level conversion module includes a second bidirectional level conversion chip. The A end of the second bidirectional level conversion chip is connected to the general-purpose input / output interface of the management control module, and the B end of the second bidirectional level conversion chip is connected to the general-purpose input / output interface of the management sub-card. It is used to convert the 3.3V level signal of the management control module into a 1.8V level signal acceptable to the management sub-card, or to convert the 1.8V level signal of the management sub-card into a 3.3V level signal acceptable to the management control module.

[0011] Preferably, the management control module is configured to execute blade power-on / off timing control, the blade power-on / off timing control including: The front panel switch signal is detected. When the switch signal is detected to be valid, the management and control module outputs the main processing module core power enable signal, the main processing module auxiliary power enable signal, the bridge module power enable signal, the data storage module power enable signal, and the network communication module power enable signal in sequence according to a preset timing sequence. The time interval between two adjacent power enable signals is Δt, where Δt ranges from 50ms to 200ms and satisfies the following relationship: Δt = t 稳定 +t 延时 , where t 稳定 t is the time required for the output voltage of the preceding power supply to reach a steady state. 延时 The preset redundancy delay time, t 延时 The value range is from 10ms to 50ms.

[0012] Preferably, the management control module is further configured to perform reset control, the reset control including: The management control module receives a watchdog timeout signal from the main processing module or a reset signal from the front panel; When the management and control module receives a valid reset signal, the management and control module outputs the main processing module reset signal, the bridge chip module reset signal, and the network communication module reset signal in sequence according to the preset reset timing. After outputting a reset signal, the management and control module continuously monitors the power supply normal signal of the main processing module. If no valid power supply normal signal is detected within a preset time T, the management and control module triggers an alarm LED to flash at a preset frequency f, where the preset frequency f satisfies the following relationship: f = 1 / T 周期 =1 / (2×(t 复位 +t 监测 ), where t 复位 The duration of the reset signal output, ranging from 100ms to 500ms, is t. 监测 The time window for monitoring normal power supply signals ranges from 1 second to 5 seconds, T. 周期 The complete cycle time for the alarm LED to flash.

[0013] Preferably, the management control module is further configured to perform temperature monitoring and fan control, the temperature monitoring and fan control including: The management and control module periodically reads the temperature data collected by the temperature sensor through the second level conversion module and the management sub-card, denoted as T. curr ; The management and control module determines the fan speed control signal based on a preset temperature threshold table. The fan speed control signal is a PWM signal, and its duty cycle D is determined by the following piecewise function: , among which, T low The lower limit threshold temperature is T, with a value ranging from 40℃ to 50℃. high This is the upper temperature threshold, ranging from 70℃ to 85℃, T curr The temperature value is currently read, and D is the duty cycle of the output PWM signal. When D=0%, the fan stops, and when D=100%, the fan runs at full speed. The management control module outputs the PWM signal corresponding to the duty cycle D to the management sub-card through the second level conversion module, and the management sub-card drives the external fan.

[0014] Preferably, the bridge module provides multiple input / output interfaces via a VPX connector, including a SATA 3.0 interface, a USB 3.0 interface, a VGA interface, a serial communication interface, and a gigabit RJ45 network port; The SATA 3.0 interface is electrically connected to the data storage module to enable high-speed data transmission between the data storage module and the bridge module. The USB 3.0 interface is electrically connected to the USB controller of the bridge module and is used to connect external USB devices; The VGA interface is electrically connected to the display controller of the bridge module and is used to output video signals; The serial communication interface is electrically connected to the serial communication controller of the bridge chip module and is used to provide a serial communication channel; The gigabit RJ45 network port is electrically connected to the network communication module and is used to provide a physical network connection interface.

[0015] Preferably, the device further includes a power management module, which is electrically connected to the management control module, and the power management module includes: The input power supply filter circuit is used to filter the input VPX power supply. A multi-channel DC-DC converter, electrically connected to the input power filter circuit, is used to convert the +12V and +5V power input from the VPX into the operating voltages required by each module, including +3.3V, +1.8V, +1.2V, and +0.9V. The power timing control circuit is electrically connected to the management control module, receives the power enable signal from the management control module, and starts the multi-channel DC-DC converters sequentially according to a preset timing sequence. The power timing control circuit includes multiple power monitoring chips connected in series. The enable output of each power monitoring chip is connected to the enable input of the next power monitoring chip, forming a timing chain to realize hardware-level power-on timing control.

[0016] The security monitoring device based on the VPX architecture of the present invention has the following beneficial effects: (1) By adopting domestic core components such as Phytium D2000 processor, Phytium X100 bridge chip, GD32 microcontroller, Netcom network controller and TCM trusted card, we have achieved full-link independent control from computing, control to security, completely eliminated the risk of supply chain disruption, and avoided potential backdoor risks from the underlying hardware level, meeting the high requirements of key areas for information security and supply chain security. (2) By integrating the GD32 management and control module and a dedicated management sub-card, an independent intelligent management channel was constructed, which can collect system voltage, temperature, FRU information and environmental parameters in real time, and present them intuitively through status indicator LEDs. This enables comprehensive perception and refined management of equipment health status, and significantly improves fault diagnosis efficiency and system maintainability. (3) Each module is integrated on a standard 6U VPX heat conduction structure carrier board and adopts heat conduction heat dissipation. It eliminates easily damaged active components such as fans. Combined with the high bandwidth and high reliability connection characteristics of the VPX architecture, this device is superior to traditional designs in terms of vibration resistance, wide temperature operation and heat dissipation efficiency. It can operate stably in harsh environments such as national defense and aerospace, significantly improving the reliability and service life of the system. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the structures shown in these drawings without creative effort. The present invention will be further described below in conjunction with the drawings and embodiments. In the drawings: Figure 1 This is a schematic diagram of a preferred embodiment of the security monitoring device based on the VPX architecture of the present invention.

[0018] In the diagram, 100 is the main processing module, 200 is the bridge chip module, 300 is the management and control module, 400 is the network communication module, 510 is the first level conversion module, 520 is the second level conversion module, 600 is the management daughter card, 700 is the trusted security module, 800 is the data storage module, and 900 is the front panel interface module. Detailed Implementation

[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0020] It should be noted that if the embodiments of the present invention involve directional indicators (such as up, down, left, right, front, back, etc.), the directional indicators are only used to explain the relative positional relationship and movement of the components in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indicators will also change accordingly.

[0021] Furthermore, if the embodiments of this invention involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed by this invention.

[0022] Please see Figure 1 This is a block diagram illustrating a preferred embodiment of the security monitoring device based on the VPX architecture of the present invention. This embodiment provides a security monitoring device based on the VPX architecture, which utilizes a domestically produced Phytium processor and the VPX architecture, possessing powerful data processing capabilities and comprehensive intelligent management functions.

[0023] like Figure 1 As shown, the security monitoring device based on the VPX architecture provided in the first embodiment of the present invention includes at least a main processing module 100, a bridge chip module 200, a management and control module 300, a network communication module 400, a first level conversion module 510, a second level conversion module 520, a management daughter card 600, a trusted security module 700, a data storage module 800, a front panel interface module 900, and a power management module. Figure 1 (Not shown in the image). All these modules are integrated onto a 6U VPX compliant heat-conducting carrier board. The carrier board employs a multi-layer PCB design, providing excellent signal and power integrity. The heat-conducting structure, through locking strips on both sides of the board, makes tight contact with the chassis rails, transferring heat to the chassis housing for fanless cooling.

[0024] The core of the main processing module 100 is the Phytium D2000 octa-core CPU processor. This processor is manufactured using an advanced 14nm process, integrating eight FTC663 cores with a maximum clock speed of 2.3GHz, a 4MB L3 cache, and supports dual-channel DDR4 memory with a maximum memory capacity of 32GB. In this embodiment, the main processing module 100 also includes four DDR4 memory chips with a total capacity of 16GB, directly soldered onto the carrier board, improving vibration resistance. The Phytium D2000 processor supports national cryptographic algorithms such as SM2, SM3, and SM4, and combined with the trusted security module 700, it can achieve full-stack trusted computing from hardware to software. The Phytium D2000 processor is responsible for running the operating system and application software, completing high-speed computation and processing of business data, such as data encryption and decryption, protocol conversion, and data fusion.

[0025] The bridge module 200 uses the Phytium X100 bridge chip. The Phytium X100 bridge chip connects to the main processing module 100 via a PCIe 3.0 x8 interface, providing a high-speed data channel. The Phytium X100 bridge chip integrates various peripheral controllers, including a display controller, audio controller, USB controller, SATA controller, and PCIe controller. The bridge module 200 expands the I / O interfaces to a rich set. Specifically, the bridge module 200 provides SATA 3.0, USB 3.0, VGA, and serial communication interfaces via VPX connectors P2 and P4. The SATA 3.0 interface connects to the data storage module 800. The data storage module 800 uses an industrial-grade mSATA SSD with a capacity of 512GB, supports the SATA 3.0 protocol, and achieves sequential read and write speeds of up to 500MB / s and 400MB / s, respectively. The USB 3.0 interface is routed to a designated pin on the VPX connector P2 for connecting external USB devices to the backplane. The VGA interface, after being processed by a video digital-to-analog converter chip (such as GM7123), outputs an analog RGB signal, which is brought out through the VPX connector P4. The serial communication interface, after being processed by a UART to RS-232 level converter chip (such as MAX3232), is brought out through the VPX connector P4, supporting a baud rate of 115200bps.

[0026] The network communication module 400 uses the Netcom WX1860AL4-B network controller. The WX1860AL4-B connects to the PCIe controller of the bridge module 200 via a PCIe 2.1x4 interface. The WX1860AL4-B integrates four Gigabit Ethernet MACs and PHYs, supporting 10 / 100 / 1000Mbps auto-negotiation. The four Gigabit Ethernet signals are isolated by an isolation transformer (such as an HX1188) and then led out through VPX connectors P3 and P5, forming four independent Gigabit Ethernet interfaces for high-speed data exchange between the device and external systems. The network communication module 400 also supports the IEEE 1588 time synchronization protocol and Wake-on-LAN functionality, making it suitable for applications with high time synchronization requirements.

[0027] The core of the management and control module 300 is the GD32F103RBT6 microcontroller. This MCU is based on the ARM Cortex-M3 core, with a main frequency of 72MHz, 128KB Flash and 20KB SRAM, and peripherals including multiple UARTs, I2C, SPI, GPIO, and ADC. The MCU is connected to the first level conversion module 510 and the second level conversion module 520 through its GPIO pins.

[0028] The first level conversion module 510 uses the TI TXS0108E bidirectional level conversion chip. Port A (1.8V) of the TXS0108E is connected to the GPIO pin of the main processing module 100, used to receive status signals such as watchdog timeout and power-on status signals from the Phytium D2000 processor, and simultaneously output reset and control signals. Port B (3.3V) of the TXS0108E is connected to the GPIO pin of the MCU, enabling bidirectional communication between the MCU and the main processing module 100.

[0029] The second level conversion module 520 also uses the TXS0108E chip. Its B port (3.3V) is connected to the GPIO pin of the MCU, and its A port (1.8V) is connected to the interface of the management daughter card 600. The management daughter card 600 is an independent daughter board that is connected to the main board via a board-to-board connector.

[0030] The management daughter card 600 integrates a temperature sensor (model: LM75A), an EEPROM memory (model: AT24C1024), a test serial port (leading out a Micro USB interface via a UART to USB chip), and an IPMB interface (leading out via an I2C bus).

[0031] The LM75A temperature sensor is connected to the second level conversion module 520 via an I2C bus, and the MCU reads the temperature data via the I2C protocol. The EEPROM AT24C1024 is also connected to the same I2C bus, storing FRU information, including the board model (e.g., "SECMON-VPX-6U"), serial number, hardware version, production date, MAC address, etc.

[0032] The test serial port is converted to a USB interface via the FT232RQ chip, making it convenient for maintenance personnel to connect to the debugging terminal and view the MCU's debugging information and system logs.

[0033] The IPMB interface is directly brought out through the VPX connector P0 and is used to connect to the chassis management controller (ChMC) to achieve IPMI communication.

[0034] The front panel interface module 900 is located at the edge of the carrier board and is directly connected to the GPIO pins of the MCU. The front panel interface module 900 has seven LEDs: a power LED (green), a status LED (green), a hard disk LED (yellow), an alarm LED (red), a network LED (green), a TCM status LED (blue), and a TCM alarm LED (red). The MCU controls the on / off state and blinking of these LEDs by outputting high and low levels via GPIO according to the system's operating status. For example, during normal system operation, the status LED blinks at a frequency of 1Hz; when the temperature exceeds 85℃, the alarm LED remains constantly lit; and when the SSD is performing read / write operations, the hard disk LED blinks.

[0035] The Trusted Security Module 700 uses a TCM Trusted Card, model TF32XX. The TCM Trusted Card is connected to the main processing module 100 via an LPC bus or an SPI bus. The TCM Trusted Card integrates a cryptographic algorithm engine, a true random number generator, and non-volatile storage units, providing functions such as trusted measurement, trusted storage, and trusted reporting.

[0036] During system startup, the BIOS / UEFI first performs a trust measurement via TCM to ensure that the firmware and bootloader have not been tampered with. It then sequentially measures the operating system kernel and critical applications, building a complete chain of trust. TCM also provides hardware-level key storage and cryptographic services for data encryption, authentication, and secure communication.

[0037] The power management module (not shown separately) includes an input filter circuit, a multi-channel DC-DC converter, and a power timing control circuit. The input filter circuit consists of a common-mode choke (such as the TCM series), X capacitors, Y capacitors, and TVS diodes, filtering and suppressing surges on the +12V and +5V power supplies provided by the VPX backplane. The multi-channel DC-DC converters include: a DC-DC chip (such as TPS54620) for generating +3.3V, with an input of +12V and an output current up to 6A; a DC-DC chip (such as TPS62130) for generating +1.8V, with an input of +5V and an output current up to 3A; a DC-DC chip (such as TPS53319) for generating +1.2V, with an input of +12V and an output current up to 8A; and a DC-DC chip (such as TPS53681) for generating +0.9V, with an input of +12V and an output current up to 10A, specifically designed to power the core of the Phytium D2000 processor.

[0038] The power supply timing control circuit employs multiple TPS3808 power monitoring chips connected in series. The TPS3808 features programmable delay output functionality. The first TPS3808 monitors +3.3V; when +3.3V reaches the threshold, it outputs an enable signal after a preset delay (e.g., 50ms), enabling the generation of a +1.8V DC-DC converter. The second TPS3808 monitors +1.8V and, after a delay, enables the generation of a +1.2V DC-DC converter. The third TPS3808 monitors +1.2V and, after a delay, enables the generation of a +0.9V DC-DC converter. This hardware timing chain, combined with the MCU's software timing control, creates redundancy, ensuring absolute reliability of the power-on timing.

[0039] The following describes in detail the security monitoring device based on the VPX architecture of the present invention, with reference to the specific working process.

[0040] During device power-up, the VPX backplane initially provides +12V and +5V standby power via the P0 connector. After the power management module's input filtering circuit filters the power, a portion of the DC-DC converters activate, generating +3.3V standby power to supply the MCU and some monitoring circuits. Upon power-up, the MCU executes the firmware, initializes peripherals, enters standby mode, and monitors the front panel power switch signal. When the user presses the front panel power switch, or the backplane sends a power-on command via IPMB, the MCU detects a valid switch signal. The MCU then sends a power enable signal to the main processing module, bridge module, etc., through the first level conversion module according to the preset power timing sequence. The timing interval Δt strictly follows the formula Δt = t 稳定 +t 延时 Settings. For example, for a DC-DC converter that generates a +1.2V core power supply, its t 稳定 The actual measurement is 30ms, and t is set. 延时 If the time interval is 20ms, then Δt = 50ms. After the MCU outputs +1.2V power to enable, it waits 50ms before outputting +0.9V power to enable. Once all power supply voltages are established normally, each module enters the working state.

[0041] During normal system operation, the management control module 300 periodically (e.g., every 2 seconds) reads the temperature data T from the temperature sensor LM75A through the management sub-card 600. curr The MCU calculates the PWM duty cycle D based on the temperature data. Assume T... low Set to 45℃, T high Set to 80℃. When T is read... curr When the temperature is 60℃, substituting into the piecewise function: D=(60-45) / (80-45)×100%=15 / 35×100%≈42.9%.

[0042] The MCU outputs a PWM signal with a duty cycle of 42.9%, which is transmitted to the fan drive circuit on the management daughter card 600 via the second level conversion module. The fan drive circuit controls the chassis fan to operate at approximately 43% speed. When T curr At 90℃, D=100%, the fan runs at full speed. When T... curr When the temperature reaches 40℃, D=0%, the fan stops.

[0043] Meanwhile, the management and control module 300 also communicates with the chassis management controller (ChMC) via the IPMB interface. The MCU encapsulates the collected temperature, voltage, FRU information, etc., into IPMI command format and sends it to the ChMC via the IPMB bus to achieve remote monitoring and management. The ChMC can also send commands to the MCU via IPMB, such as remote power-on, reset, and setting fan speed.

[0044] During system operation, the watchdog timer inside the main processing module 100 needs to be periodically "fed" by the operating system driver. If feeding fails due to a software infinite loop or hardware failure, the watchdog timer times out, and the main processing module 100 outputs a watchdog timeout signal (active low) to the management control module 300 via GPIO. Upon detecting this signal, the MCU determines that a system abnormality has occurred. Following the reset sequence, the MCU sequentially outputs the main processing module reset signal, the bridge chip module reset signal, and the network communication module reset signal. The reset signal is output for a duration of t. 复位 Set to 200ms. After the reset signal is released, the MCU begins monitoring the main processing module's power supply status signal. If in t 监测 If no valid power signal is detected within 3 seconds, it indicates a system reset failure or a power supply fault. At this time, the MCU will drive the alarm LED to flash. According to the formula: f = 1 / (2 × (t) 复位 +t 监测 The frequency of the alarm LED is approximately 0.156Hz, meaning it flashes at a frequency of approximately 0.156Hz, or about once every 6.4 seconds. The LED lights up and then goes out once per cycle. The duration of the flashing is related to the frequency of the LED flashing. 复位 Related to the time it takes for the lights to go out and t 监测 Related. Maintenance personnel can determine whether the flashing frequency indicates a reset failure or a power supply fault. If the system restarts normally after a reset and the power supply signal is valid, the MCU will resume normal monitoring, and the alarm LED will turn off.

[0045] Furthermore, the Trusted Security Module 700 plays a crucial role in the system startup process. After the system powers on, the BIOS first reads the metric value from the TCM Trusted Card and compares it with the value in the Platform Configuration Register (PCR) to verify the integrity of the BIOS itself. If the verification is successful, the BIOS transfers control to the bootloader, which then verifies the operating system kernel through the TCM. The system will only boot normally if the trust chain is fully established. If the metric value at any link in the chain does not match, the TCM Trusted Card will trigger a TCM alarm LED and prevent the system from booting, thus preventing malware or unauthorized code from running.

[0046] The data storage module 800 is connected to the bridge module 200 via a SATA 3.0 interface. The operating system and application software run on the SSD, and business data is also stored on the SSD. The read / write status of the SSD is transmitted to the MCU via the activity indicator signal of the SATA interface, and the MCU controls the hard drive LED to blink.

[0047] External devices connect to the device via interfaces provided by VPX connectors. For example, keyboards, mice, and USB flash drives can be connected via USB 3.0 interfaces; monitors via VGA interfaces; sensors or other control devices via serial communication interfaces; and switches or other network devices via four Gigabit RJ45 Ethernet ports. The network communication module 400 handles all network data transmission and reception, communicating with the bridge module 200 via a PCIe interface, and subsequently exchanging data with the main processing module 100. The main processing module 100 runs the network protocol stack and application software to implement network communication functions.

[0048] This invention's VPX-based security monitoring device utilizes domestically produced core components such as the Phytium D2000 processor, Phytium X100 bridge chip, GD32F103RBT6 MCU, and Netcom WX1860AL4-B network controller, achieving a fully domestically produced design from processor to management controller, thus eliminating supply chain security risks. By treating the management control module as an independent BMC channel, it enables real-time monitoring and reporting of information such as voltage, temperature, and FRU, as well as precise control of blade power-on / off timing and reset operations. The TCM trusted card enables trusted system startup and data encryption, enhancing system security. The 6U VPX architecture and cooling structure design improve the device's reliability, environmental adaptability, and maintainability. This device can meet the needs of defense, aerospace, and critical infrastructure sectors for high-security, high-reliability embedded computers.

[0049] The beneficial effects of the present invention, through the design of the above embodiments, are as follows: (1) By adopting domestic core components such as Phytium D2000 processor, Phytium X100 bridge chip, GD32 microcontroller, Netcom network controller and TCM trusted card, we have achieved full-link independent control from computing, control to security, completely eliminated the risk of supply chain disruption, and avoided potential backdoor risks from the underlying hardware level, meeting the high requirements of key areas for information security and supply chain security. (2) By integrating the GD32 management and control module and a dedicated management sub-card, an independent intelligent management channel was constructed, which can collect system voltage, temperature, FRU information and environmental parameters in real time, and present them intuitively through status indicator LEDs. This enables comprehensive perception and refined management of equipment health status, and significantly improves fault diagnosis efficiency and system maintainability. (3) Each module is integrated on a standard 6U VPX heat conduction structure carrier board and adopts heat conduction heat dissipation. It eliminates easily damaged active components such as fans. Combined with the high bandwidth and high reliability connection characteristics of the VPX architecture, this device is superior to traditional designs in terms of vibration resistance, wide temperature operation and heat dissipation efficiency. It can operate stably in harsh environments such as national defense and aerospace, significantly improving the reliability and service life of the system.

[0050] This invention has been described with reference to specific embodiments, but those skilled in the art will understand that various changes and equivalent substitutions can be made without departing from the scope of the invention. Furthermore, numerous modifications can be made to this invention to suit specific applications without departing from its protection scope. Therefore, this invention is not limited to the specific embodiments disclosed herein, but includes all embodiments falling within the scope of the claims.

Claims

1. A security monitoring device based on VPX architecture, characterized in that, include: The main processing module is used for the calculation and processing of business data; The bridge module is electrically connected to the main processing module and is used to enable auxiliary peripheral expansion; The management and control module is electrically connected to the main processing module and the bridge module respectively, and is used to realize the status monitoring and management of the system. The network communication module, electrically connected to the bridge chip module, is used to provide four gigabit Ethernet interfaces to realize data interaction between systems. The first level conversion module is electrically connected to the management control module and the main processing module respectively, and is used to realize level matching between the management control module and the main processing module; The second level conversion module is electrically connected to the management and control module; the management sub-card is electrically connected to the second level conversion module and is used to collect environmental parameters and provide a management interface. A trusted security module, comprising a TCM trusted card, electrically connected to the main processing module, is used to enable trusted system startup and data encryption; A data storage module, including an SSD solid-state drive, is electrically connected to the bridge chip module and is used to store business data and system logs; The front panel interface module is electrically connected to the management and control module, and the front panel interface module is equipped with multiple status indicator LEDs. The main processing module, the bridge chip module, the management and control module, the network communication module, the first level conversion module, the second level conversion module, the management daughter card, the trusted security module, the data storage module, and the front panel interface module are all mounted on a standard 6U VPX architecture heat-conducting structure carrier board, and the modules are electrically connected to each other through VPX connectors and on-board wiring.

2. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The management sub-card includes a temperature sensor, an EEPROM memory, a test serial port, and an IPMB interface; The temperature sensor is electrically connected to the management sub-card and is used to collect internal temperature data of the device; The EEPROM memory is electrically connected to the management daughter card and is used to store FRU (Field Replaceable Unit) information; The test serial port is electrically connected to the management sub-card and is used to output debugging information; The IPMB interface is electrically connected to the management sub-card and is used to connect to the intelligent platform management bus to enable external management units to manage and communicate with the device.

3. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The multiple status indicator LEDs provided on the front panel interface module include: A power LED, electrically connected to the management and control module, is used to indicate the power status of the device. The status LED, electrically connected to the management and control module, is used to indicate the operating status of the device; The hard drive LED, electrically connected to the management and control module, is used to indicate the working status of the data storage module; An alarm LED, electrically connected to the management and control module, is used to indicate the device's fault alarm status. A network LED, electrically connected to the management and control module, is used to indicate the link status of the network communication module; The TCM status LED is electrically connected to the management and control module and is used to indicate the working status of the trusted security module. The TCM alarm LED is electrically connected to the management and control module and is used to indicate the alarm status of the trusted security module.

4. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The first level conversion module includes a first bidirectional level conversion chip. The A terminal of the first bidirectional level conversion chip is connected to the general-purpose input / output interface of the management and control module, and the B terminal of the first bidirectional level conversion chip is connected to the general-purpose input / output interface of the main processing module. It is used to convert the 3.3V level signal of the management and control module into a 1.8V level signal acceptable to the main processing module, or to convert the 1.8V level signal of the main processing module into a 3.3V level signal acceptable to the management and control module.

5. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The second level conversion module includes a second bidirectional level conversion chip. The A end of the second bidirectional level conversion chip is connected to the general-purpose input / output interface of the management and control module, and the B end of the second bidirectional level conversion chip is connected to the general-purpose input / output interface of the management sub-card. It is used to convert the 3.3V level signal of the management and control module into a 1.8V level signal acceptable to the management sub-card, or to convert the 1.8V level signal of the management sub-card into a 3.3V level signal acceptable to the management and control module.

6. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The management control module is configured to execute blade power-on / off timing control, which includes: The front panel switch signal is detected. When the switch signal is detected to be valid, the management and control module outputs the main processing module core power enable signal, the main processing module auxiliary power enable signal, the bridge module power enable signal, the data storage module power enable signal, and the network communication module power enable signal in sequence according to a preset timing sequence. The time interval between two adjacent power enable signals is Δt, where Δt ranges from 50ms to 200ms and satisfies the following relationship: Δt = t 稳定 +t 延时 , where t 稳定 t is the time required for the output voltage of the preceding power supply to reach a steady state. 延时 The preset redundancy delay time, t 延时 The value range is from 10ms to 50ms.

7. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The management control module is also configured to perform reset control, which includes: The management control module receives a watchdog timeout signal from the main processing module or a reset signal from the front panel; When the management and control module receives a valid reset signal, the management and control module outputs the main processing module reset signal, the bridge chip module reset signal, and the network communication module reset signal in sequence according to the preset reset timing. After outputting a reset signal, the management and control module continuously monitors the power supply normal signal of the main processing module. If no valid power supply normal signal is detected within a preset time T, the management and control module triggers an alarm LED to flash at a preset frequency f, where the preset frequency f satisfies the following relationship: f = 1 / T 周期 =1 / (2×(t 复位 +t 监测 ), where t 复位 The duration of the reset signal output, ranging from 100ms to 500ms, is t. 监测 The time window for monitoring normal power supply signals ranges from 1 second to 5 seconds, T. 周期 The complete cycle time for the alarm LED to flash.

8. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The management and control module is also configured to perform temperature monitoring and fan control, the temperature monitoring and fan control including: The management and control module periodically reads the temperature data collected by the temperature sensor through the second level conversion module and the management sub-card, denoted as T. curr ; The management and control module determines the fan speed control signal based on a preset temperature threshold table. The fan speed control signal is a PWM signal, and its duty cycle D is determined by the following piecewise function: , among which, T low The lower limit threshold temperature is T, with a value ranging from 40℃ to 50℃. high This is the upper temperature threshold, ranging from 70℃ to 85℃, T curr The temperature value is currently read, and D is the duty cycle of the output PWM signal. When D=0%, the fan stops, and when D=100%, the fan runs at full speed. The management control module outputs the PWM signal corresponding to the duty cycle D to the management sub-card through the second level conversion module, and the management sub-card drives the external fan.

9. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The bridge module provides multiple input / output interfaces via a VPX connector, including a SATA 3.0 interface, a USB 3.0 interface, a VGA interface, a serial communication interface, and a gigabit RJ45 network port. The SATA 3.0 interface is electrically connected to the data storage module to enable high-speed data transmission between the data storage module and the bridge module. The USB 3.0 interface is electrically connected to the USB controller of the bridge module and is used to connect external USB devices; The VGA interface is electrically connected to the display controller of the bridge module and is used to output video signals; The serial communication interface is electrically connected to the serial communication controller of the bridge chip module and is used to provide a serial communication channel; The gigabit RJ45 network port is electrically connected to the network communication module and is used to provide a physical network connection interface.

10. The security monitoring device based on VPX architecture according to claim 1, characterized in that, The device further includes a power management module, which is electrically connected to the management control module. The power management module includes: The input power supply filter circuit is used to filter the input VPX power supply. A multi-channel DC-DC converter, electrically connected to the input power filter circuit, is used to convert the +12V and +5V power input from the VPX into the operating voltages required by each module, including +3.3V, +1.8V, +1.2V, and +0.9V. The power timing control circuit is electrically connected to the management control module, receives the power enable signal from the management control module, and starts the multi-channel DC-DC converters sequentially according to a preset timing sequence. The power timing control circuit includes multiple power monitoring chips connected in series. The enable output of each power monitoring chip is connected to the enable input of the next power monitoring chip, forming a timing chain to realize hardware-level power-on timing control.