Single-chip integrated encryption card
By integrating an encryption card into a single chip, utilizing an FPGA main control chip connected to multiple interfaces, and incorporating a built-in key generator and memory, the problem of encryption chips being easily cracked is solved, achieving high data security and anti-cracking capabilities.
Patent Information
- Application Number
- CN202423283567.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2034-12-30
AI Technical Summary
The encryption chips on existing encryption cards are vulnerable to external cracking, leading to data insecurity.
It adopts a single-chip integrated encryption card, which connects to SFP, PCIE, and SMBUS interfaces through an FPGA main control chip. It has a built-in key generator and memory, and realizes that the data transmission and encryption process are encapsulated in a single chip, thereby enhancing the anti-cracking capability.
It improves data security, prevents external cracking, and makes the encryption card difficult to tamper with in hardware, giving it strong anti-cracking capabilities.
Smart Images

Figure CN223566149U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model relates to communication technology and information security field, concretely relates to a single chip integrated encryption card. BACKGROUND
[0002] Data protection, governance and commercial cryptography technology are the core of national security and network security. At present, in order to protect the security of communication data, the encryption transmission mode is generally used. The encryption algorithm is stored in the encryption chip to realize the encryption and decryption function.
[0003] But the existing encryption card needs multi-chip linkage, that is, multiple chips are integrated on a PCB, which respectively correspond to realize data interaction function, encryption and decryption function and data processing function etc., and each chip transmits data through the wiring on the PCB, and finally outputs unified data code stream.
[0004] Therefore, the encryption chip on the existing encryption card is vulnerable to external cracking, so that the encryption is invalidated, resulting in that the data is no longer safe. UTILITY MODEL CONTENTS
[0005] The utility model discloses in order to solve the problem that the encryption chip on the existing encryption card is vulnerable to external cracking, and proposes a single chip integrated encryption card.
[0006] In order to achieve the above-mentioned purpose, the technical scheme adopted by the utility model is as follows:
[0007] A single chip integrated encryption card, including PCB carrier plate, be equipped with FPGA master control chip, SFP interface, PCIE interface and SMBUS interface on the PCB carrier plate, the FPGA master control chip is connected with SFP interface, PCIE interface, SMBUS interface respectively,
[0008] The FPGA master control chip is built-in key generator for generating key, and built-in memory is used for storing key.
[0009] In the above-mentioned scheme, through the connection of FPGA master control chip with SFP interface, PCIE interface and SMBUS interface, the process of data transmission and encryption is encapsulated in a single chip, avoids being cracked from outside, and makes it not easy to tamper on the hardware, has strong anti-cracking ability, can effectively improve the security of data.
[0010] Preferably, the SFP interface is connected with the FPGA master control chip through the XAUI interface.
[0011] Preferably, the SFP interface has two.
[0012] Preferably, the PCIE interface is PCIE4.0 interface.
[0013] Preferably, the PCIE interface is a PCIE 4.0 x8 interface.
[0014] Preferably, the key generator is a random entropy source.
[0015] Preferably, the memory is a RAM memory.
[0016] Preferably, the FPGA master control chip further has a built-in protection area for writing a user-defined seed and rejecting debugging access functions.
[0017] The utility model has beneficial technical effect:
[0018] The utility model provides a single chip integrated encryption card, is connected with SFP interface, PCIE interface, SMBUS interface respectively through FPGA master control chip, realizes the process encapsulation of data transmission, encryption in single chip, avoids being broken by outside, and makes it not easy to tamper on hardware, has strong anti -cracking ability, can effectively improve the security of data. BRIEF DESCRIPTION OF DRAWINGS
[0019] Figure 1 It is the overall structure diagram of the utility model;
[0020] Among them: 1, PCB carrier plate, 2, FPGA master control chip, 3, SFP interface, 4, PCIE interface, 5, SMBUS interface. DETAILED DESCRIPTION
[0021] In order to make the purpose, technical scheme and advantage of the utility model more clearly, the following is further detailed with examples to the utility model, but the scope of protection of the utility model is not limited to the following specific examples. EMBODIMENT
[0022] As Figure 1 Shown, a single chip integrated encryption card, including PCB carrier plate 1, be equipped with FPGA master control chip 2, SFP (Small Form-factor Pluggable, small hot-swappable optical module) interface 3, PCIE (peripheral component interconnect express, is a kind of high-speed serial computer expansion bus standard) interface 4 and SMBUS (System Management Bus, system management bus) interface 5 on the PCB carrier plate 1, the FPGA master control chip 2 is connected with SFP interface 3, PCIE interface 4, SMBUS interface 5 respectively;
[0023] The FPGA master control chip 2 is built-in key generator for generating key, built-in memory for storing key.
[0024] In the implementation process, the FPGA master chip 2 is connected with the SFP interface 3, the PCIE interface 4 and the SMBUS interface 5 respectively, so as to realize the process of data transmission and encryption encapsulated in a single chip, avoid being cracked externally, make it not easy to tamper with in hardware, have strong anti-cracking ability, and effectively improve the security of data.
[0025] In the implementation process, the FPGA master chip 2 can realize Ethernet communication with external network through the SFP interface 3, and realize data transmission function with the computer through the PCIE interface 4.
[0026] More specifically, the SFP interface 3 is connected with the FPGA master chip 2 through the XAUI (X-Ethernet Attachment Unit Interface) interface.
[0027] In the implementation process, the SFP interface 3 is connected with the FPGA master chip 2 through the XAUI interface, and the FPGA master chip 2 is connected with the computer through the PCIE interface 4 and the SMBUS interface 5.
[0028] More specifically, the SFP interface 3 has two.
[0029] In the implementation process, the FPGA master chip 2 has two transceivers to realize Ethernet communication with the external based on the XAUI interface
[0030] More specifically, the PCIE interface 4 is a PCIE 4.0 interface.
[0031] More specifically, the PCIE interface 4 is a PCIE 4.0x8 interface.
[0032] In the implementation process, in order to realize high-bandwidth transmission, the interface is a standard PCIE 4.0x8 interface, and a standard SMBUS bus is used for system management and synchronization of card state. According to different devices carried by the computer, the actual communication channel can be configured as x1, x2, x4 and x8 channels, and the communication specification of the second to fourth generation of PCIE is supported.
[0033] More specifically, the key generator is a random entropy source.
[0034] More specifically, the memory is a RAM memory.
[0035] In the implementation process, the RAM memory is used to store the buffered data and the key.
[0036] More specifically, the FPGA master chip 2 also has a protection area for writing user-defined seeds and rejecting debugging access.
[0037] In the specific implementation, the protection area is used to increase data security.
[0038] In the specific implementation, the encryption algorithm of the FPGA master chip 2 uses the AES algorithm, and the random entropy source of the FPGA master chip 2 can automatically generate a key and distribute it through an Ethernet point-to-point, so that a hardware-level encryption network card can be realized, and all outgoing data is encrypted and can be networked.
[0039] The FPGA master chip 2 implements several algorithms in parallel, one of which is an encryption algorithm based on the AES algorithm and the RSA algorithm. The RSA algorithm is used to generate initial public and private keys, and the AES algorithm is used for data encryption and decryption. The process is as follows:
[0040] (1) Update and generate public and private keys: When the networking device sends a request, it will automatically generate and distribute public and private keys based on the random entropy source and the RSA algorithm. After obtaining the public key, the public key is stored in the internal buffer of the FPGA master chip 2, and the public key of the device is broadcast to the network.
[0041] (2) Data encryption: When the computer transmits data to be encrypted, the FPGA master chip 2 encrypts the data based on the AES algorithm according to the data destination, and the key is encrypted using the key obtained in the first step. The encrypted data is transmitted directly to the external network through the Ethernet interface.
[0042] (3) Data decryption: When the FPGA master chip 2 receives data to be decrypted, it decrypts the data based on the internal stored private key, and then transmits it to the computer host through the PCIE interface 4.
[0043] To ensure the reliability of encryption, the encryption card needs to be specified with a random number seed by the user when it is enabled. This seed is used for updating and generating random entropy sources.
[0044] Encrypted data can only be transmitted through the XAUI interface, while decrypted and encrypted data can only be transmitted through the PCIE interface 4. The network transmission protocol is TCP / IP protocol, and the protocol encapsulation and unpacking steps are implemented inside the FPGA master chip 2, realizing the integration of functions.
[0045] According to the disclosure and teaching of the above description, the skilled in the art of the present application can also change and modify the above embodiments. Therefore, the present application is not limited to the specific embodiments disclosed and described above, and some modifications and changes of the present application should fall within the protection scope of the claims of the present application. In addition, although some specific terms are used in the specification, these terms are only for convenience and do not constitute any limitation on the present application.
Claims
1. A single-chip integrated encryption card, comprising a PCB substrate, characterized in that, The PCB carrier is equipped with an FPGA main control chip, an SFP interface, a PCIE interface, and an SMBUS interface; the FPGA main control chip is connected to the SFP interface, the PCIE interface, and the SMBUS interface respectively. The FPGA main control chip has a built-in key generator for generating keys and a built-in memory for storing keys.
2. The single-chip integrated encryption card according to claim 1, characterized in that, The SFP interface is connected to the FPGA main control chip via the XAUI interface.
3. The single-chip integrated encryption card according to claim 1, characterized in that, The SFP interface has two parts.
4. A single-chip integrated encryption card according to claim 1, characterized in that, The PCIe interface is a PCIe 4.0 interface.
5. A single-chip integrated encryption card according to claim 1, characterized in that, The PCIe interface is a PCIe 4.0 x8 interface.
6. A single-chip integrated encryption card according to claim 1, characterized in that, The key generator is a random entropy source.
7. A single-chip integrated encryption card according to claim 1, characterized in that, The memory is a RAM memory.
8. A single-chip integrated encryption card according to claim 1, characterized in that, The FPGA main control chip also has a built-in protected area for writing user-defined seeds and denying debug access.