Server mainboard

By integrating a CPU module, RISER card module, and PCIe trusted module on the server motherboard, and combining a trusted platform and cryptographic module, the problem of traditional security protection being unable to cope with cross-platform threats is solved, achieving high security and flexibility, and making it suitable for a variety of computer systems.

CN223956037UActive Publication Date: 2026-02-27HANGZHOU EBOYLAMP ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202423208333.1
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2026-02-27
Estimated Expiration
2034-12-25

AI Technical Summary

Technical Problem

Traditional security measures are insufficient to effectively address cross-platform and cross-network security threats. Information systems in critical infrastructure, finance, healthcare, and government sectors face challenges to security and reliability, and users' trust in computing platforms continues to increase.

Method used

Design a server motherboard that includes a CPU module, a RISER card module, and a PCIe trusted module. Combined with a trusted platform module and a trusted cryptographic module, it is connected via a PCIe bus to achieve high security. It adopts a domestic Phytium S5000-C processor and a C2C interface, integrates 64 processor cores, supports a DDR5 memory transfer rate of 4000MT/s, and has rich PCI-E expansion capabilities.

Benefits of technology

It achieves high security and flexibility, reduces costs, is easy to maintain, provides strong security protection, and is suitable for different types of computer systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223956037U_ABST
    Figure CN223956037U_ABST
Patent Text Reader

Abstract

The utility model provides a server mainboard, and belongs to the technical field of computer application. The server mainboard comprises a CPU (central processing unit) module, an RISER card module and a PCIE (peripheral component interface express) trusted module. The PCIE trusted module is easy to install and replace, can be conveniently inserted and pulled out, is good in compatibility, can be suitable for different mainboards, is high in flexibility, is convenient to maintain, reduces the cost of the mainboards, combines the CPU module with the PCIE trusted module, can achieve high safety, and provides safety protection for a computer system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The utility model relates to computer application technical field, concretely relates to a server mainboard. BACKGROUND

[0002] With the rapid development and wide application of information technology, the security and reliability of information systems are facing increasingly severe challenges. In the network environment, security threats such as malicious software, hacker attacks, data leakage are emerging in an endless stream. Traditional security protection means, such as firewall, intrusion detection system, etc., often detect and respond after the attack, which is difficult to fundamentally guarantee the security of the system. With the continuous improvement of informatization, the importance of information systems in key infrastructure, finance, medical treatment, government affairs and other fields is increasingly prominent. The data and business processing in these systems have very high value and sensitivity, and once attacked or failed, it may cause serious economic loss, social chaos and even threaten national security.

[0003] The application of emerging technologies such as cloud computing, big data and Internet of Things makes the computing environment more complex and open. In this environment, the traditional security mechanism is difficult to effectively cope with the security threats across platforms and networks, and a more powerful security protection means is needed. In addition, due to the existence of software vulnerabilities and hardware design defects, information systems may have untrusted factors. In order to ensure the integrity, confidentiality and availability of the system, a trusted foundation needs to be established from the bottom of the computing platform. At the same time, users' demand for information systems is increasing. Users hope to be sure that the computing platform and information they use are real, reliable and secure, and trusted computing technology is developed to meet this demand. In summary, the emergence of trusted computing is to cope with the increasingly complex and severe information security situation, and to ensure the reliable operation of information systems and the trust of users. CONTENT OF THE UTILITY MODEL

[0004] The utility model aims at the shortage of prior art, and proposes a server mainboard.

[0005] The utility model proposes a server mainboard, including CPU module, RISER card module, PCIE credible module, RISER card module is connected in CPU module and PCIE credible module respectively.

[0006] Further, the PCIE credible module includes a trusted platform module and / or a trusted cryptographic module.

[0007] Further, the RISER card module includes at least one expansion slot, at least one RISER card, and the RISER card is inserted into the corresponding expansion slot.

[0008] Further, the server mainboard further comprises a memory module connected to the CPU module, a bridge module connected to the CPU module, a network module connected to the bridge module, a BMC module connected to the CPU module, a USB module connected to the bridge module, a display module connected to the BMC module, a storage module connected to the bridge module, and a remote management module connected to the BMC module.

[0009] Further, the RISER card module is connected to the CPU module through a PCIE bus, and the PCIE trusted module is connected to the RISER card module through a PCIE bus.

[0010] Further, the CPU module comprises a plurality of central processing units arranged integrally, and the plurality of central processing units are connected through C2C interfaces.

[0011] Further, the bridge module and the bridge module are respectively connected to the CPU module through PCIE buses, the network module comprises a network control chip and a network interface, the network module is connected to the bridge module through a PCIE bus, the USB module comprises a USB interface, the USB module is connected to the bridge module through a USB bus, and the memory module comprises a memory slot and at least one DDR5 memory unit inserted into the memory slot.

[0012] Further, the central processing unit is a central processing unit integrated with 64 processor cores.

[0013] Further, the bridge module is an X100 bridge, and the display module is a VGA display module.

[0014] Further, the storage module comprises at least one SATA interface and at least one NVME interface, the SATA interface is connected to the bridge module through a SATA bus, and the NVME interface is connected to the bridge module through a PCIE bus.

[0015] Further, the DDR5 memory unit is 16, and the total transmission rate is up to 4000MT / s.

[0016] The server mainboard has the following beneficial effects:

[0017] The PCIE trusted module is easy to install and replace, can be conveniently inserted and pulled out, has good compatibility, can be applied to different mainboards, has high flexibility, is convenient to maintain, reduces the cost of the mainboard, combines the CPU module and the PCIE trusted module, can realize high security, and provides security protection for a computer system. BRIEF DESCRIPTION OF DRAWINGS

[0018] The accompanying drawings incorporated in and forming a part of the specification illustrate embodiments of the application and, together with the description, serve to explain the principles of the application. In the drawings:

[0019] Figure 1 A structure schematic view in a server mainboard of the embodiment of the application.

[0020] In the figure: 1-CPU module, 2-RISER card module, 3-PCIE trusted module, 4-memory module, 5-bridge module, 6-BMC module, 7-network module, 8-storage module, 9-USB module, 10-display module, 11-remote management module. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical scheme and advantages of the embodiment of the application more clear, the technical scheme in the embodiment of the application will be described clearly and completely in combination with the drawings in the embodiment of the application. Obviously, the described embodiment is a part of the embodiments of the application, rather than all the embodiments of the application. Based on the embodiments in the application, all the other embodiments obtained by the ordinary skilled in the art without creative work belong to the protection scope of the application. It should be noted that, in the case of no conflict, the embodiments in the application and the features in the embodiments can be combined with each other at will.

[0022] Please refer to Figure 1 The server mainboard of the embodiment of the application comprises a CPU module 1, a RISER card module 2 and a PCIE trusted module 3, and the RISER card module 2 is connected to the CPU module 1 and the PCIE trusted module 3 respectively.

[0023] Here, the application is based on the trusted server mainboard, which can be applied to different types and configurations of computer systems; compared with the processor integration, the cost is relatively low; the combination of the CPU module and the PCIE trusted module can realize high security, and provide security protection for the computer system.

[0024] Specifically, PCIE is PCI-Express, which is a high-speed serial computer expansion bus standard. Its original name is "3GIO", which was proposed by Intel in 2001, aiming to replace the old PCI, PCI-X and AGP bus standards. PCIe belongs to high-speed serial point-to-point dual-channel high-bandwidth transmission, and the connected devices are allocated exclusive channel bandwidth, not shared bus bandwidth, mainly supporting active power management, error reporting, end-to-end reliable transmission, hot plug, and quality of service (QOS) functions. Riser card is a hardware device used to expand the server PCI Express PCIe slot, the main functions include expanding PCIe slot, adjusting the position of the expansion card, supporting multiple graphics cards for parallel computing, and improving server cooling. By using the Riser card, the expansion capability and performance of the server can be significantly improved.

[0025] Specifically, the trusted module generally refers to the trusted platform module TPM, which is a security chip. Basic principle: TPM chip is installed on the motherboard of the computer, which has its own independent processor and storage unit. During the computer startup process, TPM will first measure the integrity of key components such as BIOS and boot loader. For example, it will use a hash algorithm to calculate the hash value of these components, and then compare it with the correct hash value stored in advance; if the hash values are inconsistent, it may mean that the system has been tampered with, and appropriate security measures will be taken, such as preventing the system from starting or issuing a security alert. Main functions: encryption key management: TPM can securely generate, store and manage encryption keys. For example, when performing disk encryption, it can provide keys that are not exposed in plaintext form in the computer's memory or hard drive, greatly improving the security of encryption; digital signature: can provide digital signature services for data and software. When software developers want to prove the origin and integrity of the software, TPM can help generate digital signatures. Users can verify the signature when installing software to ensure that the software has not been tampered with. Application scenarios: enterprise security: in enterprise network environments, TPM helps protect the enterprise's data assets. For example, for enterprise laptops, TPM can prevent data leakage after the laptop is lost or stolen; cloud services: in cloud computing environments, cloud service providers can use TPM to enhance the security of user virtual machines and ensure the security of user data and applications in the cloud.

[0026] The PCIE trusted module 3 can include a trusted platform module and / or a trusted cryptographic module.

[0027] Specifically, the trusted platform module (Trusted Platform Module) is a chip implanted in the computer to provide a trusted root for the computer. The specification of the chip is developed by the Trusted Computing Group (Trusted Computing Group). The trusted platform module (Trusted Platform Module) security chip refers to a security chip that meets the TPM (Trusted Platform Module) standard. It can effectively protect the PC and prevent unauthorized access. TCM (Trusted Cryptography Module) is a hardware module of the trusted computing platform that can provide cryptographic operation functions and has a protected storage space. The trusted cryptography module (TCM) is a key basic component of the trusted computing cryptography support platform, providing independent cryptographic algorithm support. PCIE trusted module 3 can perform encryption algorithms or trusted computing bases to provide additional security protection for computer systems. These security features include but are not limited to data encryption, identity authentication, access control, tamper protection, and trusted boot.

[0028] The RISER card module 2 can include at least one expansion slot, at least one RISER card, and the RISER card is respectively plugged into the corresponding expansion slot.

[0029] Specifically, the expansion slot can be a PCIEX16 physical expansion slot. The expansion slot and the RISER card cooperate to form the RISER card module 2. The expansion slot can be three.

[0030] As one of the servers in this embodiment, the server mainboard can further include a memory module 4 connected to the CPU module 1, a bridge module 5 connected to the CPU module 1, a network module 7 connected to the bridge module 5, a BMC module 6 connected to the CPU module 1, a USB module 9 connected to the bridge module 5, a display module 10 connected to the BMC module 6, a storage module 8 connected to the bridge module 5, and a remote management module 11 connected to the BMC module 6.

[0031] Specifically, the remote management module 11 is used to monitor and manage the hardware state of the whole machine. The BMC module 6, Baseboard Management Controller, is an embedded microcontroller independent of the main processor, mainly responsible for monitoring, managing and controlling the server hardware. The BMC module 6 is usually integrated in the mainboard of the server and connected to the main processor. The bridge, i.e. the bridge chip, is an indispensable component in the hardware architecture of the computer, playing a key role in connection and data exchange. They interact directly with the CPU on the motherboard, building a bridge for data and instruction exchange.

[0032] The RISER card module 2 can be connected to the CPU module 1 through a PCIE bus, and the PCIE trusted module 3 is connected to the RISER card module 2 through a PCIE bus.

[0033] The CPU module 1 can include a plurality of central processing units integratedly arranged, and the plurality of central processing units are connected through a C2C interface.

[0034] Specifically, the central processing unit can be two. The C2C interface is a high-speed direct connection interface. The C2C interface, as a new inter-chip communication technology, has the core advantage of system-level optimization. Traditional mobile devices often use separate application processors and modems, while the C2C interface allows the two to be tightly integrated, reducing communication delay and energy loss in the middle link. This integrated approach helps original equipment manufacturers (OEMs) make full use of hardware resources, improve the energy efficiency of devices, and provide a smoother user experience for users. The C2C interface is not limited to the integration of modems. Its memory mapping transmission capability makes system expansion seamless and efficient, and can support more complex system architectures, such as the expansion of large-capacity storage. Although existing interfaces such as USB and PCI Express can also achieve similar functions, the C2C interface has significant advantages in speed, delay, and power consumption control, especially in the field of mobile devices that are sensitive to power consumption.

[0035] The central processing unit can be a central processing unit integrated with 64 processor cores.

[0036] Specifically, the central processing unit is an S5000-C Feiteng processor. Two S5000-C Feiteng processors are integrated to form the CPU module 1. The use of domestic Feiteng S5000 processors combines domestic processor motherboards with trusted modules to achieve high security, such as encryption algorithms or trusted computing bases, providing additional security protection for the system. The two central processing units can be connected through C2C, and the two central processing units can communicate directly, reducing data transmission delay and bandwidth limitations.

[0037] The bridge module 5 can be connected to the CPU module 1 through a PCIE bus, the network module 7 includes a network control chip and a network interface, the network module 7 is connected to the bridge module 5 through a PCIE bus, the USB module 9 includes at least one USB interface, the USB module 9 is connected to the bridge module 5 through a USB bus, and the memory module 4 can include a memory slot, and at least one DDR5 memory unit is plugged into the memory slot.

[0038] Specifically, the network control chip and the network interface constitute a network module 7, and an input end of the network module 7 is connected with the bridge module 5 through a PCIE bus. The USB interface constitutes a USB module 9. The network control chip can be a gigabit network controller WX1860, and the network interface adopts a standard RJ45 connector. The DDR5 is a computer memory specification. Compared with the DDR4 memory, the DDR5 standard has stronger performance and lower power consumption. The memory slot can be a DIMM slot, which refers to a DDR slot.

[0039] The DDR5 memory unit can be 16, and the total transmission rate supports a maximum transmission rate of 4000MT / s.

[0040] Specifically, 16 memory slots are arranged on the mainboard, and a plurality of DDR5 memory units are respectively plugged into the corresponding memory slots. The memory slot and the DDR5 memory unit constitute a memory module 4, and the memory module 4 is connected with the CPU module 1 through a DDR signal. The total transmission rate of the mainboard supports a maximum transmission rate of 4000MT / s.

[0041] The bridge module 5 can be an X100 bridge, the storage module 8 includes at least one SATA interface and at least one NVME interface, the SATA interface is connected with the bridge module 5 through a SATA bus, the NVME interface is connected with the bridge module 5 through a PCIE bus, and the display module 10 is a VGA display module.

[0042] Specifically, the X100 bridge is configured as a bridge module 5, and an input end of the bridge module 5 is connected with the CPU module 1 through a PCIE bus. VGA is an abbreviation of Video Graphics Array, which is a standard for computer display. VGA is a computer display standard using analog signals proposed by IBM in 1987. SATA is an abbreviation of Serial ATA, which is a computer bus established by the Serial ATA Working Group in November 2000. The main function of SATA is to transmit data between the motherboard and a large number of storage devices such as hard disks and optical disk drives. SATA is named because it uses a serial mode to transmit data, and has the advantages of simple structure and support for hot plug. NVME is an abbreviation of NVM Express, which is an abbreviation of Non-Volatile Memory Host Controller Interface Specification in English. NVME or NVM Express is a logical device interface specification. It is a bus transmission protocol specification based on the device logical interface similar to AHCI, which is an application layer in the communication protocol. It is used to access non-volatile memory media such as solid state hard drives using flash memory attached through a PCI Express (PCIe) bus. The NVME interface is an NVM Express interface.

[0043] Specifically, the VGA display module is connected with the BMC module 6 through a VGA display output standard. The BMC module 6 outputs a vga-related signal to the VGA display module.

[0044] Specifically, the SATA interface can be four.

[0045] Specifically, the remote management module 11 can be a management network port. The BMC module 6 can remotely manage the information of the motherboard through the management network port.

[0046] Specifically, the whole-board PCI-E topology of the present application takes two Feiteng S5000-C processors as the Root Complex, that is, the resources of the whole-board pcie are provided by the Feiteng S5000-C, which can be configured according to the actual use of the PCI-E topology design, can ensure that the PCI-E expansion slots are more evenly distributed under each CPU, achieve PCI-E flow balance, fully guarantee the actual PCI-E bandwidth, and can provide rich PCI-E resources to support the trusted cryptographic module scheme of the PCIE interface. This way has the following advantages: easy to install and replace, can be easily inserted and pulled out; good compatibility, suitable for different types and configurations of computer systems; compared with processor integration, the cost is relatively low.

[0047] Specifically, the present application carries 2 domestic processors Feiteng Tengyun S5000C to constitute CPU module 1, and a single Tengyun S5000C integrates 64 processor cores; 2 Tengyun S5000C-64 are interconnected through a high-speed direct connection interface, and two S5000-C Feiteng processors can be connected through a PCIE bus to provide a high-speed communication channel between processors; 16 onboard DDR5 DIMM slots constitute memory module 4, which supports a maximum transmission rate of 4000MT / s; up to 128 processor cores provide strong computing power performance for the whole machine.

[0048] Specifically, the mainboard has rich PCI-E expansion resources, which provide three PCIEX16 physical expansion slots for connecting three Riser Card PCI-E resources to constitute RISER card module 2; the RISER card module 2 can be used to support the trusted module of the PCIE interface. The trusted module of the PCIE interface is a hardware device equipped with a PCIE interface, which can not only be used as an expansion card of a computer system to provide external functions such as network, storage, and graphics processing, but also provide additional security protection for the system through the built-in security chip, encryption algorithm, or trusted computing base. These security features include but are not limited to data encryption, identity authentication, access control, tamper protection, and trusted boot, etc.

[0049] Specifically, the mainboard provides rich IO expansion capability, the X100 suite piece is taken as a bridge piece module 5, provides 4-way SATA interface, provides rich SATA expansion capability; provides two-way M.2 interface, compatible with NVME design, rich SATA interface and NVME interface constitute storage module 8. The on-board X100 suite piece exports 4-way USB3.0 compatible USB2.0 interface and constitutes USB module 9, provides flexible and rich USB interface resources. The on-board gigabit network controller WX1860 exports 2-way 10 / 100 / 1000M BASE-T interface and constitutes network module 7, wherein the network interface adopts a standard RJ45 connector; the CPU module 1 is connected with the BMC card as the BMC module 6 through the DDR4-SODIMM, is used for realizing the remote management module 11 for monitoring and managing the hardware state of the whole machine, the remote management module 11 provides 1 10 / 100 / 1000M BASE-T management network port for the mainboard, realizes the remote management function based on the IPMI protocol, the display module 10 provides 1 VGA display interface for the mainboard and constitutes the display module 10, supports 1920*1080 display resolution.

[0050] The above-described content can be implemented alone or in various combinations, and these variants are within the protection scope of the utility model.

[0051] It should be noted that in the description of the present application, the terms "upper end", "lower end", "bottom end" indicating the orientation or positional relationship are based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship when the product of the present application is used, which is only for the convenience of describing the present application and simplifying the description, and does not indicate or imply that the device must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present application. Moreover, the terms "include", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device containing a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including one" does not exclude the presence of another identical element in the process, method, article or device including the element.

[0052] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent substitutions for part of the technical features; and these modifications or substitutions do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A server motherboard, characterized in that: It includes a CPU module (1), a RISER card module (2), and a PCIE trusted module (3), wherein the RISER card module (2) is connected to the CPU module (1) and the PCIE trusted module (3) respectively.

2. A server motherboard as described in claim 1, characterized in that: The PCIE trusted module (3) includes a trusted platform module and / or a trusted cryptographic module.

3. A server motherboard as described in claim 1 or 2, characterized in that: The RISER card module (2) includes at least one expansion slot and at least one RISER card, which is plugged into the corresponding expansion slot.

4. A server motherboard as described in claim 1 or 2, characterized in that: It also includes a memory module (4) connected to the CPU module (1), a bridge chip module (5) connected to the CPU module (1), a network module (7) connected to the bridge chip module (5), a BMC module (6) connected to the CPU module (1), a USB module (9) connected to the bridge chip module (5), a display module (10) connected to the BMC module (6), a storage module (8) connected to the bridge chip module (5), and a remote management module (11) connected to the BMC module (6).

5. A server motherboard as described in claim 1 or 2, characterized in that: The RISER card module (2) is connected to the CPU module (1) via the PCIE bus, and the PCIE trusted module (3) is connected to the RISER card module (2) via the PCIE bus.

6. A server motherboard as described in claim 1 or 2, characterized in that: The CPU module (1) includes multiple central processing units integrated together, and the multiple central processing units are connected to each other via a C2C interface.

7. A server motherboard as described in claim 4, characterized in that: The bridge module (5) is connected to the CPU module (1) via a PCIe bus. The network module (7) includes a network control chip and at least one network interface. The network module (7) is connected to the bridge module (5) via a PCIe bus. The USB module (9) includes at least one USB interface. The USB module (9) is connected to the bridge module (5) via a USB bus. The memory module (4) includes a memory slot and at least one DDR5 memory unit plugged into the memory slot.

8. A server motherboard as described in claim 6, characterized in that: The central processing unit is a central processing unit that integrates 64 processor cores.

9. A server motherboard as described in claim 4, characterized in that: The bridge module (5) is an X100 bridge, the display module (10) is a VGA display module, and the storage module (8) includes at least one SATA interface and at least one NVME interface. The SATA interface is connected to the bridge module (5) via a SATA bus, and the NVME interface is connected to the bridge module (5) via a PCIE bus.

10. A server motherboard as described in claim 7, characterized in that: The DDR5 memory has 16 units, and the total transmission rate supports a maximum transmission rate of 4000MT / s.