Intelligent network card for network security access

By integrating network bridge and security processing modules and modules on the network card motherboard, the problem of ordinary network cards requiring additional network security equipment is solved, low-cost host network security protection is achieved, and anti-tamping and data encryption capabilities are available.

CN223285841UActive Publication Date: 2025-08-29BEIJING ANXIN ZHIXIN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202422639327.5
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-08-29
Estimated Expiration
2034-10-30

AI Technical Summary

Technical Problem

Existing network cards lack network security capabilities, and additional equipment or software needs to be deployed to increase network security protection, resulting in increased costs.

Method used

Install network bridge and security processing modules, PCIE extension network port modules, PCIE SWITCH modules, and internal network port modules on the network card motherboard, and use these modules to realize secure communication between the host and the external network interface, combining the security protection module to provide anti-tamping, anti-detection sensing and data encryption capabilities.

Benefits of technology

It reduces the cost of host network security protection, provides security protection for host network, has unique identity identification and device anti-cracking capabilities, and improves network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223285841U_ABST
    Figure CN223285841U_ABST
Patent Text Reader

Abstract

The utility model discloses a network security access intelligent network card, which is structurally characterized in that a host PCIE (Peripheral Component Interface Express) interface, an interface PCIE SWITCH module, an internal PCIE SWITCH module, a PCIE expansion network port module, an internal network port module, a network bridging and security processing module, an external network interface and a security protection module are respectively arranged on a network card mainboard, the host PCIE interface is expanded through the interface PCIE SWITCH module and then is connected with the PCIE expansion network port module, the host PCIE interface is converted into an Ethernet interface through the PCIE expansion network port module and is connected with the internal network port module, and the network bridging and safety processing module is connected with the internal network port module and an external network interface through the internal PCIE SWITCH module. The communication between the host PCIE interface and the external network interface is realized through a network bridging and security processing module; and the security protection module is directly connected with the network bridging and security processing module. According to the utility model, the network bridging and security processing module is directly installed on the network card, so that the network card directly has network security access capability, and the host network security access cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The utility model relates to the technical field of network cards, in particular to a network security access intelligent network card. Background Art

[0002] A network card is a common host network access device that generally lacks network security capabilities and cannot provide network security protection for the host network. Additional network security devices or software such as network firewalls and security gateways are required to achieve network security protection, which increases the cost of network security protection. Utility Model Content

[0003] This utility model aims to address the cost-prohibitive requirement of deploying additional network security equipment or software when using a standard network card to enhance network security protection for a host. The utility model provides a network security access smart network card. The network bridging and security processing module, a PCIE expansion network port module, a PCIE switch module, and an internal network port module are installed on the network card motherboard. Communication between the host PCIE interface and the external network interface is achieved through the network bridging and security processing module, the PCIE expansion network port module, the PCIE switch module, and the internal network port module. The network bridging and security processing module protects the host's network access security. This utility model reduces the cost of host network security protection.

[0004] In order to solve the above technical problems, the technical solution adopted by the present invention is:

[0005] A network security access intelligent network card comprises a network card mainboard, a host PCIE interface, an interface PCIE SWITCH module, an internal PCIE SWITCH module, a PCIE extended network port module, an internal network port module, a network bridging and security processing module, an external network interface, and a security protection module. The invention is characterized in that the host PCIE interface, the interface PCIE SWITCH module, the internal PCIE SWITCH module, the PCIE extended network port module, the internal network port module, the network bridging and security processing module, the external network interface, and the security protection module are respectively installed on the network card mainboard, wherein the host PCIE interface is connected to the PCIE extended network port module after being expanded through the interface PCIE SWITCH module, and is converted into an Ethernet interface through the PCIE extended network port module and connected to the internal network port module; the network bridging and security processing module is connected to the internal network port module and the external network interface through the internal PCIE SWITCH module; communication between the host PCIE interface and the external network interface is through the network bridging and security processing module; and the security protection module is directly connected to the network bridging and security processing module.

[0006] Optionally, the network bridging and security processing module is a network bridging and security processing module with CPU, DSP, MCU, FPGA and / or SoC as the core, supports multi-channel internal network port modules and external network interface bridging, and has network bridging and security processing capabilities of high-speed network bridging, data analysis and information filtering.

[0007] Optionally, the external network interface includes 1 / 2 / 4 or 8 external wired network interfaces; wherein, the external wired network interface supports 10M / 100M / 1G / 2.5G / 5G / 10G / 25G / 40G / 50G and / or 100G bandwidth.

[0008] Optionally, the host PCIE interface supports x1 / x2 / x4 / x8 or x16, and is expanded into 1 / 2 / 4 or 8 x1 / x2 / x4 / x8 or x16 PCIE interfaces through an interface PCIE SWITCH module, and is expanded into 1 / 2 / 4 or 8 Ethernet interfaces supporting 10M / 100M / 1G / 2.5G / 5G / 10G / 25G / 40G / 50G and / or 100G bandwidth through a PCIE expansion network port module. The host PCIE interface is an AIC form interface or an OCP form interface.

[0009] Optionally, the security protection module includes a security component and a signal line, wherein the security component is connected to the network bridging and security processing module via the signal line. The security protection module has anti-disassembly and anti-detection sensing capabilities, unique identification, physical key, and data encryption storage capabilities. It serves as the root of trust for the network bridging and security processing module, ensuring the security of the network bridging and security processing module's built-in software and user data, and providing the network secure access smart network card with a unique identification and device-wide anti-cracking protection capabilities.

[0010] Optionally, the signal line of the safety protection module is a coil-type signal line.

[0011] Optionally, the present invention further includes a network protocol conversion module, which is installed on the network card mainboard and connected between the PCIE extended network port module and the internal network port module to achieve network protocol conversion.

[0012] Compared with the prior art, the present invention has the following advantages:

[0013] Since the utility model is equipped with a network bridging and security processing module, a PCIE extended network port module, an interface PCIE Switch module, an internal PCIE Switch module and an internal network port module, the communication between the host PCIE interface and the external network interface is through the network bridging and security processing module, the PCIE extended network port module, the interface PCIE Switch module, the internal PCIE Switch module and the internal network port module, and the network access security of the host is protected by the network bridging and security processing module, thereby reducing the cost of network security protection of the host. At the same time, a security protection module is installed on the network card motherboard, and the security protection module has anti-disassembly, anti-detection perception, unique identity identification, physical key and data encryption storage capabilities, ensuring the security of the built-in software and user data of the network bridging and security processing module, and providing a unique identity identification and the device's own anti-cracking protection capability for network security access to the smart network card. In addition, a network protocol conversion module can also be installed on the network card motherboard, and the network protocol conversion module realizes network protocol conversion. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 This is a schematic diagram of the overall structure of Example 1 of the present utility model.

[0015] Figure 2 This is a schematic diagram of the layout of the network card mainboard of the first embodiment of the present utility model.

[0016] Figure 3 This is a schematic diagram of the overall structure of Example 2 of the present utility model.

[0017] Legend: 1. Network card motherboard; 2. Host PCIE interface; 3. Internal PCIE SWITCH module; 4. Interface PCIE SWITCH module; 5. First PCIE expansion network port module; 6. Second PCIE expansion network port module; 7. First internal network port module; 8. Second internal network port module; 9. First external wired network interface; 10. Second external wired network interface; 11. Network bridging and security processing module; 12. Security component; 13. Coil-type signal line; 14. Network protocol conversion module. DETAILED DESCRIPTION

[0018] The present invention is further described below with reference to the accompanying drawings and embodiments. The host PCIE interface, PCIE switch module, PCIE expansion network port module, internal network port module, network bridging and security processing module, external wired network interface, security component, coiled signal cable, and network protocol conversion module of the present invention are all existing structures and modules and are readily available.

[0019] Example 1:

[0020] like Figure 1 、 Figure 2 As shown, a network security access smart network card of the first embodiment of the present invention is a dual-port network card, including a network card mainboard 1, a host PCIE interface 2, an internal PCIE SWITCH module 3, an interface PCIE SWITCH module 4, a first PCIE extension network port module 5, a second PCIE extension network port module 6, a first internal network port module 7, a second internal network port module 8, a first external wired network interface 9, a second external wired network interface 10, a network bridging and security processing module 11, a security component 12, and a coil-type signal line 13; a host PCIE interface 2, an internal PCIE The SWITCH module 3, the interface PCIE SWITCH module 4, the first PCIE expansion network port module 5, the second PCIE expansion network port module 6, the first internal network port module 7, the second internal network port module 8, the first external wired network interface 9, the second external wired network interface 10, the network bridging and security processing module 11, the security component 12, and the coil-type signal line 13 are respectively installed on the network card motherboard 1, wherein the host PCIE interface 2 is connected to the first PCIE expansion network port module 5 and the second PCIE expansion network port module 6 after the interface is extended through the interface PCIE SWITCH module 4, and is converted into an Ethernet interface through the first PCIE expansion network port module 5 and the second PCIE expansion network port module 6 and is respectively connected to the first internal network port module 7 and the second internal network port module 8, and the network bridging and security processing module 11 is connected to the first internal network port module 7 and the second internal network port module 8 through the internal PCIE After expansion, the SWITCH module 3 is connected to the first internal network port module 7, the second internal network port module 8, the first external wired network interface 9, and the second external wired network interface 10, respectively, to form a "one-to-two" network card. The host PCIE interface 2 and the first external wired network interface 9 and the second external wired network interface 10 communicate through the network bridging and security processing module 11, and the network bridging and security processing module 11 protects the network access security of the two hosts. At the same time, the security protection module is connected to the network bridging and security processing module 11. The security protection module includes a security component 12 and a coil-type signal line 13, wherein the security component 12 is connected to the network bridging and security processing module 11 through the coil-type signal line 13. The security protection module has anti-disassembly, anti-detection perception, unique identity identification, physical key and data encryption storage capabilities. The security protection module ensures the security of the built-in software and user data of the network bridging and security processing module 11, and provides the network security access smart card with a unique identity identification and the device's own anti-cracking protection capability.

[0021] In this embodiment, the network bridging and security processing module 11 utilizes a CPU-based bridging and security processing module. The network bridging and security processing module 11 also includes storage components such as EMMC memory and DDR, as well as other supporting electronic devices. It supports bridging multiple internal network port modules and external network interfaces, and possesses network bridging and security processing capabilities such as high-speed network bridging, data analysis, and information filtering. It should be noted that the network bridging and security processing module 11 may also utilize a DSP, MCU, FPGA, and / or SoC as its core.

[0022] In this embodiment, the network card mainboard 1 is a multi-layer PCB board.

[0023] In this embodiment, the coil-type signal line 13 is a PCB wiring, wherein the coil-type signal line 13 is placed in the middle layer of a multi-layer PCB board.

[0024] In this embodiment, the external network interface supports two external wired network interfaces, namely a first external wired network interface 9 and a second external wired network interface 10. Both external wired network interfaces support 10M / 100M / 1G / 2.5G bandwidth.

[0025] In this embodiment, the host PCIE interface 2 is an AIC interface supporting x4. It is expanded into two x1 PCIE interfaces through the PCIE SWITCH module 4 and further expanded into two Ethernet interfaces supporting 10M / 100M / 1G / 2.5G bandwidth through the first PCIE expansion network port module 5 and the second PCIE expansion network port module 6. It should be noted that the host PCIE interface 2 can also be an OCP interface.

[0026] In summary, this embodiment 1 discloses a network security access smart network card. A network bridging and security processing module 11, a PCIE expansion network port module, a PCIE SWITCH module, and an internal network port module are installed on the network card motherboard 1. Communication between the host PCIE interface 2 and the external network interface is through the network bridging and security processing module 11, the PCIE expansion network port module, the PCIE SWITCH module, and the internal network port module. The network bridging and security processing module 11 protects the host network access security. At the same time, a security protection module is installed on the network card motherboard 1. The security protection module has anti-disassembly and anti-detection perception, a unique identity, a physical key, and data encryption storage capabilities. It ensures the security of the built-in software and user data of the network bridging and security processing module 11, and provides a unique identity and anti-cracking protection capabilities for the network security access smart network card.

[0027] Example 2:

[0028] This embodiment is basically the same as the first embodiment. Figure 3As shown, the main difference is that this embodiment adds a network protocol conversion module 14 to the network card mainboard 1. The network protocol conversion module 14 is connected to the first PCIE expansion network port module 5, the second PCIE expansion network port module 6, the first internal network port module 7, and the second internal network port module 8, respectively, to perform protocol conversion processing for host network access. Based on the first embodiment, this embodiment adds the network protocol conversion capability of the network security access smart network card.

[0029] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiment. All technical solutions based on the concept of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, certain improvements and modifications that do not depart from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A network security access smart network card, comprising a network card mainboard, a host PCIE interface, an interface PCIE switch module, an internal PCIE switch module, a PCIE expansion network port module, an internal network port module, a network bridging and security processing module, an external network interface, and a security protection module, characterized in that: The host PCIE interface, interface PCIE SWITCH module, internal PCIE SWITCH module, PCIE extended network port module, internal network port module, network bridging and security processing module, external network interface, and security protection module are respectively installed on the network card mainboard. Among them, the host PCIE interface is connected to the PCIE extended network port module after being expanded through the interface PCIE SWITCH module, and is converted into an Ethernet interface through the PCIE extended network port module and connected to the internal network port module. The network bridging and security processing module is connected to the internal network port module and the external network interface through the internal PCIE SWITCH module. Communication between the host PCIE interface and the external network interface is through the network bridging and security processing module; the security protection module is directly connected to the network bridging and security processing module.

2. The network security access smart network card according to claim 1, wherein: The network bridging and security processing module is a network bridging and security processing module with CPU, DSP, MCU, FPGA and / or SoC as the core.

3. The network security access smart network card according to claim 1, wherein: The external network interface includes 1 / 2 / 4 or 8 external wired network interfaces; wherein, the external wired network interface supports 10M / 100M / 1G / 2.5G / 5G / 10G / 25G / 40G / 50G and / or 100G bandwidth.

4. The network security access smart network card according to claim 1, wherein: The host PCIE interface supports x1 / x2 / x4 / x8 or x16, and is expanded to 1 / 2 / 4 or 8 x1 / x2 / x4 / x8 or x16 PCIE interfaces through the interface PCIE SWITCH module, and is expanded to 1 / 2 / 4 or 8 Ethernet interfaces supporting 10M / 100M / 1G / 2.5G / 5G / 10G / 25G / 40G / 50G and / or 100G bandwidth through the PCIE expansion network port module.

5. The network security access smart network card according to claim 4, characterized in that: The host PCIE interface is an AIC form interface or an OCP form interface.

6. The network security access smart network card according to claim 1, wherein: The security protection module includes a security component and a signal line, wherein the security component is connected to the network bridge and security processing module through the signal line.

7. The network security access smart network card according to claim 1, wherein: The signal line of the safety protection module is a coil-type signal line.

8. The network security access smart network card according to any one of claims 1 to 7, characterized in that: It also includes a network protocol conversion module, which is installed on the network card mainboard. The network protocol conversion module is connected between the PCIE extended network port module and the internal network port module to realize network protocol conversion.