A kind of hardware data transmission interface inside intelligence center without bypass
Patent Information
- Application Number
- CN202610395013.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-29
- Publication Date
- 2026-08-21
AI Technical Summary
本发明的目的在于克服现有技术的缺陷,提供一种智算中心内部无旁路硬件数据传输接口,解决现有数据传输接口易被旁路窃听、依赖软件校验加密易被破解、传输可控性差、安全响应滞后的技术问题,实现全硬件闭环、无旁路、不易被篡改的智算中心内部安全数据传输
1. 实现了全链路无旁路硬件闭环传输,传输通路全链路无任何内置、外置旁路可接入节点,采用全封闭硬件封装结构,与外部通用通信接口物理定义、电气特性完全不兼容,无法通过通用转接设备对接,从物理层面大幅降低了飞线、拆封、隐藏旁路、转接窃听等非法接入行为的发生概率,实现了物理层的安全防护;
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security transmission technology for intelligent computing centers, and particularly relates to a hardware closed-loop, bypass-free hardware data transmission interface for the internal data transmission of intelligent computing centers. Background Technology
[0002] The artificial intelligence training data, model parameters, and user privacy data transmitted within the intelligent computing center are all core and sensitive data. The security of data transmission, its ability to prevent eavesdropping, and its resistance to tampering are the core bottom line for data security in intelligent computing centers. Currently, data transmission within intelligent computing centers uses general communication interfaces and protocols, relying on software encryption and verification for security protection. However, this approach has the following inherent technical flaws that cannot be resolved: 1. Vulnerable to eavesdropping and unauthorized access: Existing general interface transmission paths have a large number of accessible nodes. Attackers can use methods such as wire jumping, unsealing, built-in hidden bypass, and transfer devices to achieve eavesdropping and unauthorized access, and steal core sensitive data. Existing software protection systems have difficulty detecting physical layer bypass access behavior. 2. Reliance on software verification and encryption makes it vulnerable to cracking and bypassing: Data verification and encryption are both implemented through software algorithms. Malicious code can crack the encryption algorithm and tamper with the verification results through operating system vulnerabilities, driver privilege escalation, etc., thereby achieving data theft and tampering, which poses a fundamental security risk. 3. Poor transmission controllability and delayed security response: Existing bypass detection and anomaly blocking rely on software systems, resulting in high detection response delays and difficulty in achieving real-time blocking. Often, data has already been stolen before the software system detects the anomaly, making it impossible to provide proactive protection. 4. No true hardware-level bypass-free transmission solution: All existing publicly available solutions cannot be separated from the participation of software and firmware, and cannot achieve bypass-free closed-loop control of the entire physical layer, nor can they reduce the risk of bypass eavesdropping and unauthorized access at the physical level. Summary of the Invention
[0003] Technical problems to be solved The purpose of this invention is to overcome the shortcomings of the prior art and provide a hardware data transmission interface for intelligent computing centers without bypass, solving the technical problems of existing data transmission interfaces being easily eavesdropped, relying on software verification and encryption which are easily cracked, having poor transmission controllability, and lagging security response, thereby realizing secure data transmission within intelligent computing centers that is fully hardware closed-loop, without bypass, and not easily tampered with. Technical solution
[0004] To achieve the above objectives, the present invention adopts the following technical solution: A hardware data transmission interface for intelligent computing centers without bypasses includes a full-link closed-loop hardware transmission path, a full-link bypass hardware detection circuit, a hardware data verification module, and a physical isolation protection module. This interface is a custom-designed physical interface for hardware-level data interaction within computing infrastructure such as intelligent computing centers and supercomputing centers. It adopts a fully enclosed hardware encapsulation structure, with no built-in or external bypass nodes throughout the entire transmission path. Its physical pin definitions and electrical characteristics are completely incompatible with external general-purpose communication interfaces, making it impossible to interface with general-purpose adapters. The full-link bypass hardware detection circuit monitors the physical integrity and electrical stability of the entire transmission path in real time. Features include: upon detecting unauthorized bypassing, unsealing, or illegal wire connection, the system immediately blocks all data transmission and triggers a hardware-level alarm through pure hardware logic; the detection and blocking actions are performed without any software intervention, software shielding, or firmware operation ports; the hardware data verification module completes real-time hardware verification of all data through a fixed hardware cyclic redundancy verification circuit, with verification and data transmission completed synchronously, without any software or firmware verification steps; and the physical isolation protection module achieves full hardware electrical isolation between the interface and all unauthorized external circuits, preventing external signal interference and data eavesdropping, and ensuring end-to-end hardware-level controllability of data transmission within the computing infrastructure.
[0005] Furthermore, the full-link hardware closed-loop transmission path adopts a differential signal transmission design, which can significantly improve the anti-interference capability of data transmission and reduce the risk of side-channel eavesdropping.
[0006] Furthermore, the interface is equipped with a data transmission hardware encryption unit, which adopts a national standard commercial block cipher algorithm hardware encryption circuit. The encryption key is embedded in the hardware chip, which is unreadable and unalterable, and does not require the participation of software encryption programs, thus realizing full hardware end-to-end encryption of data transmission. Beneficial effects
[0007] Compared with the prior art, the present invention has the following outstanding substantive features and significant beneficial effects: 1. It achieves closed-loop hardware transmission without any bypasses throughout the entire transmission path. There are no built-in or external bypass nodes that can be accessed. It adopts a fully enclosed hardware encapsulation structure, which is completely incompatible with the physical definition and electrical characteristics of external general communication interfaces. It cannot be connected through general adapters. It significantly reduces the probability of illegal access behaviors such as flying wires, unsealing, hidden bypasses, and eavesdropping at the physical level, and achieves physical layer security protection. 2. Real-time hardware-level detection and blocking of bypass anomalies are achieved. The full-link bypass hardware detection circuit monitors the physical integrity and electrical characteristics of the transmission path in real time. When illegal bypass behavior is detected, the full-link data transmission is immediately blocked and a hardware alarm is triggered through pure hardware logic. The detection and blocking response time is less than 1 microsecond. There is no software intervention or port blocking throughout the process. It cannot be tampered with or bypassed by software. It solves the problems of delayed response and easy blocking of existing software solutions and achieves real-time protection in advance. 3. The entire process is software-free, which greatly reduces the risk of data being cracked or tampered with. Data verification is completed in real time through a fixed hardware cyclic redundancy verification circuit, which is synchronized with data transmission without any software verification step. Optional hardware encryption unit is available, and the key is hard-coded in the hardware and cannot be read or tampered with. No software encryption program is required, which fundamentally reduces the security risks caused by software cracking and algorithm vulnerabilities. 4. Full-link hardware electrical isolation effectively prevents external signal interference and unauthorized access. The physical isolation protection module achieves full hardware electrical isolation between the interface and all unauthorized external circuits. Even if the external general interface is compromised, it is difficult to break through the physical isolation protection of this interface. This provides underlying security for the transmission of core sensitive data within intelligent computing centers and supercomputing centers, and can meet the data security compliance requirements of national-level computing infrastructure. Detailed Implementation
[0008] The technical solution of the present invention will be further described in detail below.
[0009] The bypass-free hardware data transmission interface within the intelligent computing center described in this embodiment is used for the transmission of core sensitive data within the AI training cluster of the intelligent computing center, including training datasets, model parameters, user privacy data, etc., providing a dedicated bypass-free secure data transmission channel between the storage nodes and graphics processor computing power nodes of the intelligent computing center.
[0010] The interface includes a full-link hardware closed-loop transmission path, a full-link bypass hardware detection circuit, a hardware data verification module, and a physical isolation protection module. The modules are directly connected to each other through onboard hardware lines without any software intermediaries.
[0011] The interface is a custom-designed physical interface with a fully enclosed metal shielded hardware package structure. It is completely incompatible with the physical pin definitions and electrical characteristics of general communication interfaces such as external high-speed serial computer expansion buses, computer LANs, and unlimited bandwidth technologies. It cannot be connected through general adapters, thus reducing the risk of unauthorized transfers and access by general devices from a physical structure perspective. The full-link hardware closed-loop transmission path is a fully shielded onboard differential signal transmission path with no built-in or external bypass nodes that can be accessed. There are no exposed nodes that can be soldered or transferred throughout the path, which significantly reduces the probability of eavesdropping by flying wires, unpacking, or built-in hidden bypasses from a physical perspective.
[0012] The end-to-end bypass hardware detection circuit is deployed in a distributed manner along the entire transmission path, and monitors the physical integrity and electrical characteristics of the entire transmission path in real time, including key parameters such as path impedance, signal attenuation, and encapsulation integrity. The detection circuit uses fixed hardware logic to preset a baseline threshold. When it detects abnormal parameters caused by illegal bypassing, unsealing, or flying wire access, it immediately blocks the entire link data transmission through pure hardware logic. At the same time, it triggers hardware audible and visual alarms and relay hard cut-off. The detection and blocking actions are carried out without any software intervention, software shielding, or firmware operation ports, and cannot be tampered with or bypassed by software. The response time is less than 1 microsecond, realizing real-time hardware-level blocking of illegal bypassing behavior.
[0013] The hardware data verification module is implemented through a fixed 32-bit cyclic redundancy check circuit, which completes real-time hardware verification of all data. Verification is completed synchronously with data transmission, without any software or firmware verification steps. If a verification error occurs during data transmission, the corresponding data frame is immediately retransmitted through hardware logic without software intervention. This significantly reduces the probability of tampering and packet loss during data transmission and ensures the integrity of data transmission.
[0014] The interface is equipped with a data transmission hardware encryption unit, which adopts a national standard commercial block cipher algorithm hardware encryption circuit. The encryption key is embedded in the hardware security chip, which is unreadable and tamper-proof. No software encryption program is required, realizing full hardware end-to-end encryption of data transmission. The encryption and decryption process is completed synchronously with data transmission without additional delay, which greatly reduces the risk of software encryption algorithm being cracked and key leakage.
[0015] The physical isolation protection module uses a hardware isolation chip to achieve full hardware electrical isolation between the interface and all unauthorized external circuits. The isolation voltage can reach 2500 volts, which can effectively prevent external signal interference and signal injection from unauthorized circuits. Even if the external general communication interface is compromised by malicious code, it is difficult to break through the physical isolation protection of this interface, thus achieving complete physical isolation between the core data transmission network inside the intelligent computing center and the external public network.
[0016] The interface described in this embodiment operates without any software involvement, significantly reducing the risks of eavesdropping, unauthorized access, data tampering, and data breaches at the physical level. The data transmission rate can reach 100 gigabits per second, with no additional delay in encryption and verification. It can meet the high-security, high-bandwidth transmission requirements of massive amounts of core and sensitive data in intelligent computing centers, and complies with the data security compliance requirements of the Data Security Law and the Regulations on the Security Protection of Critical Information Infrastructure for national-level computing infrastructure.
Claims
1. A non-bypass hardware data transmission interface for an intelligent computing center, characterized in that, It includes a full-link hardware closed-loop transmission path, a full-link bypass hardware detection circuit, a hardware data verification module, and a physical isolation protection module. The interface is a dedicated customized physical interface for internal hardware-level data interaction in computing infrastructures such as intelligent computing centers and supercomputing centers. It adopts a fully enclosed hardware packaging structure, with no built-in or external bypass nodes that can be accessed throughout the entire transmission path. It is completely incompatible with the physical pin definitions and electrical characteristics of external general communication interfaces and cannot be connected through general adapters. The full-link bypass hardware detection circuit monitors the physical integrity and electrical characteristics of the entire transmission path in real time. When illegal bypassing, unsealing, or flying wire access is detected, it immediately blocks the entire link data transmission and triggers a hardware-level alarm through pure hardware logic. The detection and blocking actions are carried out without any software intervention, software shielding, or firmware operation ports. The hardware data verification module completes real-time hardware verification of all data through a fixed hardware cyclic redundancy verification circuit. Verification and data transmission are completed synchronously, without any software verification or firmware verification steps. The physical isolation protection module achieves full hardware electrical isolation between the interface and all unauthorized external circuits, eliminating external signal interference and data eavesdropping, and ensuring end-to-end hardware-level controllability of data transmission within the computing infrastructure.
2. The intelligent computing center's internal bypass-free hardware data transmission interface according to claim 1, characterized in that, The entire hardware closed-loop transmission path adopts a differential signal transmission design.
3. The intelligent computing center internal bypass-free hardware data transmission interface according to claim 1, characterized in that, The interface is equipped with a hardware encryption unit for data transmission. The encryption key is embedded in the hardware chip, making it unreadable and tamper-proof, requiring no software encryption program.