Extended hardware-specific encrypted secure cellular communication devices and systems
Patent Information
- Application Number
- CN202521952757.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Priority Date
- 2024-09-14
- Filing Date
- 2025-09-11
- Publication Date
- 2026-08-11
- Estimated Expiration
- 2035-09-11
AI Technical Summary
[0003]为了在原有设备上集成硬件加密芯片,一般采用两种方式:第一种是通过修改原有设计来增加硬件加密芯片,该种方式一般都需要对原有设计进行升级,历经原理图设计、PCB Layout和测试认证等设计过程,改动量大,研发周期长,成本投入大;第二种是替换MiniPCIe板卡,在MiniPCIe板卡上集成硬件加密芯片,比如公开号为CN118488434A的发明专利申请,与第一种方式相比,无需改动原有设计,但由于其中硬件专用加密芯片与蜂窝通信模组之间通过SPI接口通信连接,导致数据的加密和解密需要经过蜂窝通信模组进行中转,无法直接对接现有软件架构框架(如OpenSSL),只能从下而上完全自己实现,加解密流程较为复杂,性能也较差,不利于通用性扩展与快速应用落地
[0015] (1) This utility model can achieve hardware security upgrade by directly replacing the cellular communication chip on the module board with the physical interface. The hardware expansion is simple, the R&D cycle is short, the R&D investment is low, and it meets the national cryptographic level 2 security certification.
Smart Images

Figure CN224626662U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of secure communication technology for the Internet of Things, and in particular to a secure cellular communication device and system with extended hardware dedicated encryption. Background Technology
[0002] The development and integration of the Internet of Things (IoT) has greatly improved business efficiency, but it has also brought serious security challenges. Traditional security measures are no longer sufficient to meet the ever-changing security requirements. Currently, hardware encryption is the most effective way to ensure the security of IoT devices. It uses a hardware encryption chip (SE) to encrypt data, which is more secure and harder to crack than software encryption. It can improve the security of data transmission, systems, and devices, effectively protecting user information security and playing an important role in protecting data security and confidential communications.
[0003] To integrate hardware encryption chips into existing devices, two methods are generally used: The first is to add the hardware encryption chip by modifying the original design. This method usually requires upgrading the original design, involving schematic design, PCB layout, and testing and certification, resulting in significant changes, long development cycles, and high costs. The second method is to replace the MiniPCIe board and integrate the hardware encryption chip on it, such as the invention patent application with publication number CN118488434A. Compared with the first method, this method does not require modification of the original design. However, because the dedicated hardware encryption chip communicates with the cellular communication module through the SPI interface, data encryption and decryption need to be relayed through the cellular communication module. It cannot be directly integrated with existing software architecture frameworks (such as OpenSSL) and must be implemented entirely from the bottom up. The encryption and decryption process is more complex, the performance is poorer, and it is not conducive to general expansion and rapid application deployment. Utility Model Content
[0004] The technical problem to be solved by this utility model is to overcome the shortcomings of the existing technology and provide a secure cellular communication device and system with dedicated encryption for extended hardware that is easy to expand, has low R&D investment, meets the national cryptographic level 2 security certification, and has a simplified encryption and decryption process and greatly improved performance.
[0005] The technical solution adopted by this utility model to solve its technical problem is: a secure cellular communication device with extended hardware dedicated encryption, including a module board and a cellular communication chip, a hardware encryption chip and a USB hub integrated on the module board. The data transceiver interface of the cellular communication chip is connected to the physical interface of the module board, and the USB hub is connected to the module board, the cellular communication chip and the hardware encryption chip respectively.
[0006] Furthermore, the USB hub is connected to the interface module board, the cellular communication chip, and the hardware encryption chip via a communication bus interface.
[0007] Furthermore, the communication bus interface is a USB interface.
[0008] Furthermore, the data transceiver interface is a UART interface and a USB interface.
[0009] Furthermore, the physical interface is a MiniPCIe interface.
[0010] A secure cellular communication system with extended hardware-specific encryption includes the aforementioned secure cellular communication device with extended hardware-specific encryption, a processor, and a cloud platform. The secure cellular communication device with extended hardware-specific encryption is connected to the cloud platform via the processor, and a security software package is installed in the processor.
[0011] Furthermore, the security software package is OpenSSL.
[0012] Furthermore, the processor is an MCU or an MPU.
[0013] Furthermore, the cloud platform is an IoT cloud platform.
[0014] The beneficial effects of this utility model are:
[0015] (1) This utility model can achieve hardware security upgrade by directly replacing the cellular communication chip on the module board with the physical interface. The hardware expansion is simple, the R&D cycle is short, the R&D investment is low, and it meets the national cryptographic level 2 security certification.
[0016] (2) With the setting of the USB hub, encryption and decryption do not need to be relayed through the cellular communication chip. They can be directly accessed through the USB interface to realize the hardware encryption chip, which simplifies the encryption and decryption process and greatly improves the performance.
[0017] (3) By extending the development of a secure cellular communication device with dedicated hardware encryption, this utility model only requires the hardware adaptation layer of OpenSSL to allow the driver of the hardware encryption chip to be carried on OpenSSL, which facilitates the connection with the system's OpenSSL security software package and provides security protection for information interaction, identity verification and application programs for existing Internet of Things applications. Attached Figure Description
[0018] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0019] Figure 1 This is a schematic diagram of the structure of Embodiment 1 of this utility model;
[0020] Figure 2 This is a circuit diagram of Embodiment 1 of this utility model;
[0021] Figure 3 This is a schematic diagram of the framework of Embodiment 2 of this utility model;
[0022] Figure 4 This is a schematic diagram of the processor in Embodiment 2 of this utility model;
[0023] Figure 5 This is a schematic diagram of the encryption and decryption process of this utility model;
[0024] Figure 6 This is a circuit diagram of Embodiment 1 of this utility model.
[0025] In the diagram: 100, module board; 200, cellular communication chip; 300, hardware encryption chip; 400, USB hub. Detailed Implementation
[0026] The present invention will now be further described with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the present invention, and therefore only show the components relevant to the present invention.
[0027] Example 1
[0028] like Figure 1 As shown, a secure cellular communication device with extended hardware-specific encryption includes a module board 100 and a cellular communication chip 200, a hardware encryption chip 300, and a USB hub 400 integrated on the module board 100. The data transceiver interface of the cellular communication chip 200 is connected to the physical interface of the module board 100. The USB hub 400 is connected to the module board 100, the cellular communication chip 200, and the hardware encryption chip 300. Specifically, the module board 100 has a length * width of 50.95 * 30.00 mm; its physical interface is a MiniPCIe interface; its data transceiver interfaces are a UART interface and a USB interface; the hardware encryption chip 300 has a USB interface; and the USB hub 400 is connected to the module board 100, the cellular communication chip 200, and the hardware encryption chip 300 via a communication bus interface, which is a USB interface.
[0029] Hardware security upgrades can be achieved simply by replacing the cellular communication chip 200 on the module board 100, which has a physical interface. This approach simplifies hardware expansion, shortens the development cycle, reduces R&D investment, and meets national cryptographic level 2 security certification. Through the USB hub 400, encryption and decryption no longer require the cellular communication chip 200 as an intermediary; they can be directly implemented by accessing the hardware encryption chip 300 via the USB interface, simplifying the encryption and decryption process and significantly improving performance.
[0030] The cellular communication chip 200 adopts the LTE industrial-grade wireless communication solution of the Unisoc UIS8850 platform, supporting FDD-LTE (Frequency Division Duplex LTE) and TDD-LTE (Time Division Duplex LTE) communication, and the network standard adopted is LTE-Cat1. The USB interface of the cellular communication chip 200 implements the Remote NDIS (Network Driver Interface Specification) protocol, allowing the cellular communication chip 200 to function as a virtual network card. With the corresponding driver (such as the RNDIS driver), a USB host (such as the MCU / MPU mentioned later) can connect to the 4G LTE network through the USB virtual network card (i.e., the cellular communication chip 200).
[0031] MiniPCIe is an interface based on the PCI-E bus (a universal bus specification), primarily used in laptops and digital devices. It employs the industry-standard point-to-point serial connection, unlike the shared parallel architecture of PCI and earlier computer buses, where each device has its own dedicated connection. The UART interface is also an asynchronous transceiver interface, a universal serial data bus used for asynchronous communication. This bus allows bidirectional communication, enabling full-duplex transmission and reception. USB is an external bus standard that regulates the connection and communication between computers and external devices.
[0032] The hardware encryption chip 300 uses the N32S032, a 32-bit multi-purpose high-performance security chip developed by National Technology for mobile internet identity authentication and IoT security encryption. It supports a full-speed USB 2.0 interface and provides application interfaces for implementing national commercial cryptographic security algorithms such as SM1 / SM2 / SM3 / SM4.
[0033] The USB hub 400 is a device that connects a USB host and USB devices, and is used to expand USB interfaces. It can expand one USB upstream interface into multiple downstream interfaces, allowing a USB host to connect to multiple USB devices simultaneously. The USB hub 400 uses the Chinheng CH334 chip, which is used to expand the USB interfaces of the cellular communication chip 200 and the hardware encryption chip 300, and communicates with the host through the USB interface on the MiniPCIe interface.
[0034] like Figure 2As shown, pins 11 and 12 of the USB hub 400 are connected to pins 36 and 38 of the MiniPCIe interface, respectively; pins 3 and 4 of the USB hub 400 are connected to pins 60 and 59 of the cellular communication chip 200, respectively, and pins 7 and 8 are connected to pins 2 and 1 of the hardware encryption chip 300, respectively; pins 22, 23 and 31 of the MiniPCIe interface are connected to pins 15, 17 and 18 of the cellular communication chip 200, respectively, and pins 8, 10, 12 and 14 are connected to pins 14, 11, 13 and 12 of the cellular communication chip 200, respectively.
[0035] like Figure 2 and Figure 6 As shown, the extended hardware-dedicated encryption secure cellular communication device also includes a crystal oscillator X1, a connector IPEX, capacitors C1, C2, C3, C4, and resistors R1 and R2; pin 1 of the crystal oscillator X1 is directly connected to pin 2 of the USB hub 400, and pin 3 is directly connected to pin 1 of the USB hub 400; pin 4 of the connector IPEX is connected to pin 35 of the cellular communication chip 200 through resistor R1; one end of resistor R1 is connected to pin 34 of the cellular communication chip 200 through capacitor C3, and the other end is connected to pin 34 of the cellular communication chip 200 through capacitor C4; pin 16 of the USB hub 400 is grounded through capacitors C1 and C2 respectively; pin 7 of the cellular communication chip 200 is grounded through resistor R2.
[0036] Example 2
[0037] like Figure 3 and Figure 4 As shown, a secure cellular communication system with extended hardware-specific encryption includes the secure cellular communication device with extended hardware-specific encryption described in Embodiment 1, a processor, and a cloud platform. The secure cellular communication device with extended hardware-specific encryption is connected to the cloud platform via the processor, which has a security software package installed. Specifically, the security software package is OpenSSL, an open-source software library package. OpenSSL's interface is an API (Application Programming Interface), which is a predefined set of functions used to implement communication and data exchange between different software systems, standardizing the access process through protocols such as HTTP / HTTPS (Hypertext Transfer Protocol Secure). The processor is an MCU (Microcontroller Unit) or MPU (Microprocessor); the cloud platform is an IoT (Internet of Things) cloud platform.
[0038] The processor enables independent access and communication between the cellular communication chip 200 and the hardware encryption chip 300 via the USB hub 400. The API interfaces of the existing software architecture framework in the processor can directly implement encryption and decryption through the hardware encryption chip 300 without modifying the upper-layer interface. It supports protocols such as HTTPS to provide data encryption, integrity verification and authentication, saving a lot of development and testing costs and promoting the rapid deployment of applications.
[0039] By extending the development of secure cellular communication devices with dedicated hardware encryption, only the OpenSSL hardware adaptation layer is needed to allow the driver of the hardware encryption chip 300 to be carried on OpenSSL, making it easy to interface with the system's OpenSSL security software package and provide security protection for information interaction, identity verification and application for existing IoT applications.
[0040] For external processors, the connection to the secure cellular communication device is still via the existing USB interface on the MiniPCIe interface. No hardware board redesign is required; simply adding the driver for the hardware encryption chip 300 upgrades the security encryption functionality. Furthermore, only the OpenSSL hardware adapter layer is needed to allow the driver for the hardware encryption chip 300 to run on OpenSSL. This makes it easy for the system to support functions such as national cryptographic security authentication by calling the OpenSSL interface. Existing security applications adapted to OpenSSL can be used directly without redevelopment.
[0041] like Figure 5 As shown, the specific encryption and decryption process is as follows:
[0042] S1. The MCU / MPU calls the OpenSSL API interface to encrypt data. After the hardware encryption chip 300 completes the encryption internally, it directly returns the result to the MCU / MPU application layer for processing through the aforementioned API interface.
[0043] S2.MCU / MPU sends encrypted data directly to the IoT cloud platform via IP data stream;
[0044] The S3.IoT cloud platform decrypts the encrypted data, generates and sends a response ciphertext to the terminal MCU / MPU;
[0045] After receiving the ciphertext response, the S4.MCU / MPU directly calls the OpenSSL API interface to decrypt it. After the hardware encryption chip 300 completes the decryption internally, it returns the result to the MCU / MPU application layer through the aforementioned API interface.
[0046] The above embodiments are only for illustrating the technical concept and features of this utility model. Their purpose is to enable those skilled in the art to understand the content of this utility model and implement it. They should not be used to limit the protection scope of this utility model. All equivalent changes or modifications made in accordance with the spirit and essence of this utility model should be covered within the protection scope of this utility model.
Claims
1. A secure cellular communication device with extended hardware-specific encryption, characterized in that: The device includes a module board (100) and a cellular communication chip (200), a hardware encryption chip (300), and a USB hub (400) integrated on the module board (100). The data transceiver interface of the cellular communication chip (200) is connected to the physical interface of the module board (100), and the USB hub (400) is connected to the module board (100), the cellular communication chip (200), and the hardware encryption chip (300).
2. The secure cellular communication device with extended hardware dedicated encryption according to claim 1, characterized in that: The USB hub (400) is connected to the interface module board (100), the cellular communication chip (200), and the hardware encryption chip (300) via the communication bus interface.
3. The secure cellular communication device with extended hardware dedicated encryption according to claim 2, characterized in that: The communication bus interface is a USB interface.
4. The secure cellular communication device with extended hardware dedicated encryption according to claim 1, characterized in that: The data transceiver interfaces are UART and USB.
5. The secure cellular communication device with extended hardware dedicated encryption according to claim 1, characterized in that: The physical interface is a MiniPCIe interface.
6. A secure cellular communication system with extended hardware-specific encryption, characterized in that: The invention includes the extended hardware dedicated encryption secure cellular communication device, processor, and cloud platform as described in any one of claims 1-5, wherein the extended hardware dedicated encryption secure cellular communication device is communicatively connected to the cloud platform via the processor, and the processor is equipped with a security software package.
7. The secure cellular communication system with dedicated encryption for extended hardware according to claim 6, characterized in that: The security software package is OpenSSL.
8. The secure cellular communication system with extended hardware dedicated encryption according to claim 6, characterized in that: The processor is either an MCU or an MPU.
9. The secure cellular communication system with extended hardware dedicated encryption according to claim 6, characterized in that: The cloud platform mentioned is an IoT cloud platform.
Citation Information
Patent Citations
Secure cellular communication device, communication system and communication method
CN118488434A