Encryption device for information system equipment

The encryption device controlled by the main control chip uses relays and encryption chips to achieve local and remote communication isolation of information system equipment, which solves the problem of balancing security and efficiency in the existing technology and improves the security and robustness of the system.

CN224264988UActive Publication Date: 2026-05-19JINZHONG BOTE AUTOMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
JINZHONG BOTE AUTOMATION TECH CO LTD
Filing Date
2025-04-22
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing information system equipment encryption schemes cannot dynamically switch between local security environments and remote communication, making it difficult to balance security and communication efficiency, and making them vulnerable to software vulnerability attacks.

Method used

The encryption device, controlled by the main control chip, achieves physical isolation between local and remote communication through relays and encryption chips. It connects to the local terminal and the remote terminal through the first and second communication modules respectively, and processes all communication links through the encryption chip. The main control chip automatically switches the communication path according to the security policy.

Benefits of technology

It achieves physical isolation between local and remote environments, improves security, prevents data theft and tampering, enhances communication efficiency and system robustness, and resists man-in-the-middle attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN224264988U_ABST
    Figure CN224264988U_ABST
Patent Text Reader

Abstract

The utility model relates to an encryption device for information system equipment, which relates to the field of information system equipment and comprises a main control chip, an encryption chip, a first relay, a first communication module and a second communication module. The first relay comprises a first normally open contact, a normally closed contact and a first driving part for driving the first normally open contact and the normally closed contact to act; when the main control chip communicates with a local terminal, the relay is controlled to act, the first normally open contact is closed, data is transmitted after being encrypted through the first communication module and the encryption chip, and high safety of local sensitive data is ensured. When communication with a remote terminal is needed, the main control chip controls the relay to recover, the normally-closed contact is closed, data are transmitted through the second communication module, meanwhile, the encryption chip is still used for protection, and plaintext leakage is avoided. The main control chip can only communicate with one of the local terminal and the remote terminal at the same time, isolation of the local environment and the remote environment is achieved from the physical level, and safety is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This utility model relates to the field of information system equipment, and in particular to an encryption device for information system equipment. Background Technology

[0002] With the rapid development of information technology, information system equipment (such as servers and IoT terminals) faces increasingly severe security threats during data transmission, including data theft, man-in-the-middle attacks, and malicious tampering. Traditional encryption schemes typically rely solely on software encryption or fixed hardware encryption modules, which have the following technical shortcomings:

[0003] Existing encryption devices typically use fixed communication paths, making it impossible to dynamically switch between local secure environments and remote communication, resulting in a trade-off between security and communication efficiency. For example, when high-security local data processing is required, transmission through remote encrypted channels is still necessary, increasing latency and risk. Some solutions use software to control network access, but hackers could exploit software vulnerabilities to bypass control and directly access sensitive data. Utility Model Content

[0004] In view of this, the present invention aims to provide an encryption device for information system equipment to solve the problem that existing encryption devices cannot dynamically switch between local security environments and remote communication.

[0005] To achieve the above objectives, the technical solution of this utility model is implemented as follows:

[0006] This utility model discloses an encryption device for information system equipment, comprising:

[0007] The system includes a main control chip, an encryption chip, a first relay, a first communication module, and a second communication module; the first relay includes a first normally open contact, a normally closed contact, and a first driving unit for driving the first normally open contact and the normally closed contact to operate.

[0008] The main control chip has a first communication terminal connected to an encryption chip, a second communication terminal connected to one end of a first communication module, a third communication terminal connected to one end of a second communication module, and a first control terminal connected to a first drive unit. The other end of the first communication module is connected to one end of a first normally open contact, which is connected to a local terminal. The other end of the second communication module is connected to one end of a normally closed contact, which is connected to a remote terminal, enabling the main control chip to communicate with the local terminal, control the relay to operate, communicate with the remote terminal, and control the relay to recover.

[0009] Furthermore, the first communication module is selected from one or more of the following: serial communication module, Ethernet communication module, Bluetooth communication module, WIFI communication module, Zigbee communication module, and LoRa communication module.

[0010] Furthermore, the second communication module is selected from one or more of the following: serial communication module, Ethernet communication module, WIFI communication module, Zigbee communication module, LoRa communication module, and 4G communication module.

[0011] Furthermore, the encryption device also includes a debugging communication module for external devices to communicate with the main control chip to debug the main control chip;

[0012] The fourth communication terminal of the main control chip is connected to the debugging communication module;

[0013] The debugging communication module is selected from one or more of the serial communication module and the Ethernet communication module.

[0014] Furthermore, the encryption device also includes a second relay;

[0015] The second relay includes a second normally open contact, a third normally open contact, and a second drive unit for driving the second normally open contact and the third normally open contact to operate;

[0016] The second control terminal of the main control chip is connected to the second drive unit;

[0017] The other end of the first normally open contact is connected to one end of the second normally open contact, and the other end of the second normally open contact is connected to the local terminal.

[0018] The other end of the normally closed contact is connected to one end of the third normally open contact, and the other end of the third normally open contact is connected to the remote terminal.

[0019] Furthermore, the encryption device also includes a digital-to-analog conversion module and an analog-to-digital conversion module;

[0020] The fifth communication terminal of the main control chip is connected to the analog-to-digital converter module;

[0021] The sixth communication terminal of the main control chip is connected to the digital-to-analog converter module.

[0022] Furthermore, the relay is an optocoupler relay.

[0023] Compared with the prior art, this utility model has the following advantages:

[0024] In this invention, when the main control chip communicates with a local terminal (such as an intranet device), it controls the relay to close the first normally open contact. Data is transmitted through the first communication module and encrypted by the encryption chip, ensuring high security for sensitive local data. When communication with a remote terminal (such as a cloud server) is required, the main control chip controls the relay to return to its original position, closing the normally closed contact. Data is transmitted through the second communication module, while still protected by the encryption chip to prevent plaintext leakage.

[0025] At any given time, the main control chip can only communicate with one of the local terminal and the remote terminal, achieving physical isolation between the local and remote environments, thus ensuring high security.

[0026] By directly controlling the physical on / off state through the first relay, even if a hacker breaches the software system, they cannot bypass the hardware isolation, effectively resisting man-in-the-middle attacks or data theft.

[0027] All communication links must be processed by encryption chips to ensure that data is encrypted before transmission and after reception, preventing tampering or eavesdropping.

[0028] When the main control chip detects a communication failure or attack, it can immediately disconnect high-risk links (such as remote connections) and switch to local security mode. After the fault is cleared, communication is automatically restored, improving system robustness. Attached Figure Description

[0029] The accompanying drawings, which form part of this utility model, are used to provide a further understanding of the utility model. The illustrative embodiments of the utility model and their descriptions are used to explain the utility model and do not constitute an undue limitation of the utility model. In the drawings:

[0030] Figure 1 This is a schematic diagram of the structure of the first embodiment of the present utility model;

[0031] Figure 2 This is a schematic diagram of the structure of the second embodiment of the present invention.

[0032] Figure 3 This is a structural diagram showing the connection of other functional modules of this utility model. Detailed Implementation

[0033] It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be combined with each other.

[0034] In the description of this utility model, it should be noted that the terms "upper," "lower," "inner," and "back," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this utility model and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this utility model. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0035] Furthermore, in the description of this utility model, unless otherwise explicitly defined, the terms "installation," "connection," "joining," and "connector" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this utility model in light of the specific circumstances.

[0036] The following will refer to the appendix. Figures 1 to 3 The present invention will be described in detail with reference to the embodiments.

[0037] Overall, such as Figure 1 As shown, this utility model discloses an encryption device for information system equipment, comprising:

[0038] The system includes a main control chip, an encryption chip, a first relay, a first communication module, and a second communication module. The first relay includes a first normally open contact KA1, a normally closed contact KB1, and a first driving unit for driving the first normally open contact KA1 and the normally closed contact KB1.

[0039] The main control chip has a first communication terminal connected to an encryption chip, a second communication terminal connected to one end of a first communication module, a third communication terminal connected to one end of a second communication module, and a first control terminal connected to a first drive unit. The other end of the first communication module is connected to one end of a first normally open contact KA1, and the other end of the first normally open contact KA1 is connected to a local terminal. The other end of the second communication module is connected to one end of a normally closed contact KB1, and the other end of the normally closed contact KB1 is connected to a remote terminal, so that the main control chip can communicate with the local terminal. The main control chip controls the relay to operate, the first normally open contact KA1 closes, the normally closed contact KB1 opens, the main control chip communicates with the remote terminal, and the main control chip controls the relay to recover, the first normally open contact KA1 opens, and the normally closed contact KB1 closes.

[0040] It should be noted that in this disclosure, the main control chip can automatically switch communication paths according to security policies (such as network threat detection) without manual intervention, which ensures both security and improves communication efficiency.

[0041] In this invention, when the main control chip communicates with a local terminal (such as an intranet device), it controls the relay to close the first normally open contact. Data is transmitted through the first communication module and encrypted by the encryption chip, ensuring high security for sensitive local data. When communication with a remote terminal (such as a cloud server) is required, the main control chip controls the relay to return to its original position, closing the normally closed contact. Data is transmitted through the second communication module, while still protected by the encryption chip to prevent plaintext leakage.

[0042] At any given time, the main control chip can only communicate with one of the local terminal and the remote terminal, achieving physical isolation between the local and remote environments, thus ensuring high security.

[0043] By directly controlling the physical on / off state through the first relay, even if a hacker breaches the software system, they cannot bypass the hardware isolation, effectively resisting man-in-the-middle attacks or data theft.

[0044] All communication links must be processed by encryption chips to ensure that data is encrypted before transmission and after reception, preventing tampering or eavesdropping.

[0045] When the main control chip detects a communication failure or attack, it can immediately disconnect high-risk links (such as remote connections) and switch to local security mode. After the fault is cleared, communication is automatically restored, improving system robustness.

[0046] In one example, the first communication module is selected from one or more of the following: serial communication module, Ethernet communication module, Bluetooth communication module, WIFI communication module, Zigbee communication module, and LoRa communication module.

[0047] In one example, the second communication module is selected from one or more of a serial communication module, an Ethernet communication module, a WIFI communication module, a Zigbee communication module, a LoRa communication module, and a 4G communication module.

[0048] The serial communication module can use the 485 communication protocol. It should be noted that when the second communication module is an Ethernet communication module, it should be understood that routers, switches, communication management machines, photoelectric converters, and other devices can also be set up according to the specific usage environment to realize the communication connection between the remote terminal and the main control chip. For example, if the main control chip and the remote terminal are transmitted via optical fiber, then the second communication module adopts an Ethernet module. The second communication module is connected to the remote terminal in sequence through the first photoelectric converter, the optical fiber router, and the second photoelectric converter. This disclosure does not impose any restrictions on this.

[0049] In one specific implementation, if security is a priority, local communication (first module) can be selected from Zigbee or LoRa (low power consumption and high security), and remote communication (second module) can use 4G communication module or Ethernet (high reliability); if lower cost is required, the first and second communication modules can use serial communication module or WiFi communication module, taking into account both low price and flexibility.

[0050] In one example, such as Figure 2 As shown, the encryption device also includes a debugging communication module for external devices to communicate with the main control chip to debug the main control chip;

[0051] The fourth communication terminal of the main control chip is connected to the debugging communication module;

[0052] The debugging communication module is selected from one or more of the serial communication module and the Ethernet communication module.

[0053] Integrating a debugging communication module (serial communication or Ethernet module) into the encryption device can significantly improve the development efficiency of the main control chip, system maintenance capabilities, and security.

[0054] In one example, such as Figure 2 As shown, the encryption device also includes a digital-to-analog conversion module and an analog-to-digital conversion module;

[0055] The fifth communication terminal of the main control chip is connected to the analog-to-digital converter module;

[0056] The sixth communication terminal of the main control chip is connected to the digital-to-analog converter module.

[0057] Through an analog-to-digital converter (ADC), the encryption device can directly process analog signals (such as temperature, pressure, and sound) output from sensors, audio devices, etc., converting them into digital signals which are then encrypted by the main control chip. For example, in the Industrial Internet of Things (IIoT), analog data collected by sensors can be transmitted in real time with encryption to prevent the leakage of sensitive information.

[0058] A digital-to-analog converter (DAC) can restore encrypted digital signals to analog signals, driving actuators (such as analog control valves and audio equipment) and meeting the needs of traditional devices requiring analog interfaces. For example, encrypted control commands can be converted into 4-20mA current signals by the DAC to directly control industrial valves.

[0059] In one example, such as Figure 2 The relay shown is an optocoupler relay.

[0060] The relay uses optocouplers or high-performance electromagnetic drives, and the contact switching time can be controlled in milliseconds, meeting the needs of scenarios with high real-time requirements.

[0061] Optocoupler relays are based on the principle of opto-isolation, have no mechanical contacts, and can switch at a speed of microseconds. They are suitable for high-frequency attack detection scenarios such as DDoS attacks, and can achieve near-instantaneous disconnection of communication links.

[0062] Optocoupler relays utilize electronic switches (MOSFETs / thyristors) to achieve complete physical isolation between input and output circuits, preventing hackers from bypassing encryption protections through software vulnerabilities. Optocoupler relays transmit signals via light, making them unaffected by electromagnetic interference (EMI); high-performance electromagnetic relays employ silver alloy contacts and shielding designs to reduce noise interference.

[0063] In one example, such as Figure 2 As shown, the encryption device also includes a third communication module, which is connected to the seventh communication terminal of the main control chip. The third communication module is selected from one or more of the following: serial communication module, Bluetooth communication module, Ethernet communication module, WIFI communication module, Zigbee communication module, and LoRa communication module. The third communication module is used to communicate with other local terminals to build a local area network.

[0064] Example 2

[0065] like Figure 3 As shown, the scheme in this embodiment is the same as that in embodiment 1, except that the first communication terminal of the main control chip is connected to the encryption chip, the second communication terminal is connected to one end of the first communication module, the third communication terminal is connected to one end of the second communication module, and the first control terminal is connected to the first driving unit; the other end of the first communication module is connected to one end of the first normally open contact, and the other end of the first normally open contact is connected to the local terminal; the other end of the second communication module is connected to one end of the normally closed contact, and the other end of the normally closed contact is connected to the remote terminal, so that the main control chip can communicate with the local terminal, the main control chip can control the relay to operate, the main control chip can communicate with the remote terminal, and the main control chip can control the relay to recover.

[0066] The difference is that the encryption device also includes a second relay;

[0067] The second relay includes a second normally open contact KA2, a third normally open contact KA3, and a second drive unit for driving the second normally open contact KA2 and the third normally open contact KA3 to operate;

[0068] The second control terminal of the main control chip is connected to the second drive unit;

[0069] The other end of the first normally open contact KA1 is connected to one end of the second normally open contact KA2, and the other end of the second normally open contact is connected to the local terminal.

[0070] The other end of the normally closed contact KB1 is connected to one end of the third normally open contact KA3, and the other end of the third normally open contact is connected to the remote terminal.

[0071] When the main control chip detects an anomaly (such as data tampering or unauthorized access), it immediately disconnects the second normally open contact KA2 and the third normally open contact KA3 of the second relay via the second drive unit, directly severing the physical connection between the local terminal and the remote terminal and preventing hackers from further penetrating through the communication link.

[0072] The first relay is responsible for normal path switching, while the second relay acts as a "safety gate," forming dual hardware isolation that still ensures the link is forcibly disconnected.

[0073] During normal operation, the first normally open contact KA1 and the second normally open contact KA2 are connected in series to the local terminal to form an encrypted channel. Once the main control chip detects an attack, it controls the second normally open contact KA2 to disconnect, completely isolating the local terminal from the outside world and preventing the leakage of sensitive data.

[0074] Normally closed contact KB1 and third normally open contact KA3 are connected in series to the remote terminal. When the main control chip detects an attack, it controls the third normally open contact KA3 to disconnect, and the remote link is immediately interrupted to prevent attackers from making reverse intrusions from the remote end.

[0075] The relay's contact operation is unaffected by software vulnerabilities; even if a hacker attempts to tamper with the main control chip's instructions, they cannot force the contacts to close.

[0076] The above are merely preferred embodiments of the present utility model and are not intended to limit the present utility model. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present utility model shall be included within the protection scope of the present utility model.

Claims

1. An encryption device for an information system equipment, characterized in that, include: The system includes a main control chip, an encryption chip, a first relay, a first communication module, and a second communication module; the first relay includes a first normally open contact, a normally closed contact, and a first driving unit for driving the first normally open contact and the normally closed contact to operate. The main control chip has a first communication terminal connected to an encryption chip, a second communication terminal connected to one end of a first communication module, a third communication terminal connected to one end of a second communication module, and a first control terminal connected to a first drive unit. The other end of the first communication module is connected to one end of a first normally open contact, which is connected to a local terminal. The other end of the second communication module is connected to one end of a normally closed contact, which is connected to a remote terminal, enabling the main control chip to communicate with the local terminal. The main control chip controls the relay to operate and communicates with the remote terminal. The main control chip also controls the relay to recover.

2. The encryption device for information system equipment according to claim 1, characterized in that: The first communication module is selected from one or more of the following: serial communication module, Ethernet communication module, Bluetooth communication module, WIFI communication module, Zigbee communication module, and LoRa communication module.

3. The encryption device for information system equipment according to claim 1, characterized in that: The second communication module is selected from one or more of the following: serial communication module, Ethernet communication module, WIFI communication module, Zigbee communication module, LoRa communication module, and 4G communication module.

4. The encryption device for information system equipment according to claim 1, characterized in that: The encryption device also includes a debugging communication module for external devices to communicate with the main control chip to debug the main control chip; The fourth communication terminal of the main control chip is connected to the debugging communication module; The debugging communication module is selected from one or more of the serial communication module and the Ethernet communication module.

5. The encryption device for information system equipment according to claim 1, characterized in that: The encryption device also includes a second relay; The second relay includes a second normally open contact, a third normally open contact, and a second drive unit for driving the second normally open contact and the third normally open contact to operate; The second control terminal of the main control chip is connected to the second drive unit; The other end of the first normally open contact is connected to one end of the second normally open contact, and the other end of the second normally open contact is connected to the local terminal; The other end of the normally closed contact is connected to one end of the third normally open contact, and the other end of the third normally open contact is connected to the remote terminal.

6. The encryption device for information system equipment according to claim 1, characterized in that: The encryption device further includes a digital-to-analog conversion module and an analog-to-digital conversion module; The fifth communication terminal of the main control chip is connected to the analog-to-digital converter module; The sixth communication terminal of the main control chip is connected to the digital-to-analog converter module.

7. The encryption device for information system equipment according to claim 1, characterized in that: The relay is an optocoupler relay.