FPGA-based VPX system isolation access hardware device
Patent Information
- Application Number
- CN202522257214.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2035-10-24
AI Technical Summary
[0010]本公开实施例提供一种基于FPGA的VPX系统隔离接入硬件装置,以解决传统方案中电气隔离与千兆带宽难以兼顾、跨时钟域信号同步不稳定及安全加密延迟高三大核心问题
本实用新型通过FPGA芯片集成协议转换与缓冲模块、双PHY芯片的光耦隔离连接及安全芯片直连GMII总线的核心架构,实现以下进步:
Smart Images

Figure CN224708447U_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of hardware design technology, such as an FPGA-based VPX system isolation access hardware device. Background Technology
[0002] VPX (VITA 46), as a new generation of high-speed serial bus standard, provides ultra-high bandwidth (up to 10Gbps per link) and robust support for military, aerospace, and other fields through multi-channel SerDes serial communication, ruggedized connectors, and flexible topology design. In this system, Gigabit Ethernet is the core technology for realizing cross-module communication. Its underlying layer relies on the GMII parallel interface to process short-range signals within the board, and adapts to backplane and long-distance links through the SGMII serial protocol (1 Gbps data transmission per pair of differential lines).
[0003] However, existing VPX systems face significant challenges when communicating across security domains: First, there is a fundamental contradiction between electrical isolation and high-speed transmission. Traditional optocouplers or magnetic coupling isolation devices (such as the TI ISO7741) only support signals ≤150MHz, while the SGMII's 1.25Gbps rate requires an isolation bandwidth ≥1.5GHz. Existing solutions cannot simultaneously achieve high isolation withstand voltage (≥2500Vrms) and gigabit bandwidth, resulting in severe signal attenuation and a measured bit error rate exceeding 10%. -6 More seriously, the ground potential difference between the VPX system and external networks (such as the Industrial Internet) can introduce common-mode noise, which can directly damage sensitive circuits if not isolated.
[0004] Secondly, there is a significant conflict between security encryption mechanisms and real-time requirements. Software encryption schemes (such as IPsec) require multiple data transfers at the upper layer of the protocol stack, adding a latency of >5μs, which is difficult to meet the μs-level response requirements of military systems; while discrete hardware encryption chips (such as HSM modules) connect to the main control through interfaces such as PCIe, and the additional conversion results in a bandwidth loss of ≥20%, making them unsuitable for gigabit links.
[0005] Furthermore, the issue of signal desynchronization across clock domains is prominent. The VPX backplane clock, the external network PHY clock, and the encryption chip clock are independent of each other, and timing deviations cause data conflicts or loss. Discrete FIFO buffers further exacerbate signal jitter (Jitter>200ps) due to PCB trace delays, with a measured packet loss rate ≥0.1%.
[0006] Finally, system architecture redundancy leads to decreased reliability. The discrete design of isolation, encryption, and buffer modules (as shown in the example diagram) forces longer signal paths, increased transmission delays, and a 30%–50% increase in board area. Difficulties in multi-chip collaboration further increase system power consumption by 25% and significantly raise the failure rate.
[0007] In summary, existing technologies suffer from four major drawbacks: insufficient isolation bandwidth, excessive encryption latency, clock synchronization failure, and architectural redundancy. These limitations prevent them from achieving highly reliable isolated communication while maintaining gigabit speeds. This invention aims to overcome these bottlenecks through a hardware-level integrated architecture.
[0008] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this application, and therefore may include information that does not constitute prior art known to those skilled in the art. Utility Model Content
[0009] To provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. This summary is not a general commentary, nor is it intended to identify key / important components or describe the scope of protection of these embodiments, but rather serves as a prelude to the detailed description that follows.
[0010] This disclosure provides an FPGA-based VPX system isolation access hardware device to solve three core problems in traditional solutions: difficulty in balancing electrical isolation and gigabit bandwidth, unstable cross-clock domain signal synchronization, and high latency in security encryption.
[0011] In some embodiments, the isolated access hardware device includes an FPGA chip, a first PHY chip and a second PHY chip and a hardware security chip. The FPGA chip integrates an IP core and a buffer module. The IP core is used to convert the input SGMII serial signal into a GMII parallel signal and to convert the GMII parallel signal into an SGMII serial signal for output. The buffer module is connected to the GMII parallel data interface of the IP core for cross-clock domain data synchronization. The first PHY chip and the second PHY chip are connected to the internal network domain and the external network domain, respectively, and the SGMII interfaces of the first PHY chip and the second PHY chip are connected to the SGMII interface of the FPGA chip through a high-speed optocoupler isolator. The hardware security chip is directly connected to the GMII parallel data output terminal of the buffer module and is used for streaming encryption and decryption of the buffered data. Among them, the buffer module is the FIFO_generator buffer module, and the IP core is the gig_ethernet_pcs_pma IP core.
[0012] Optionally, the write clock input of the buffer module is connected to the receive clock of the IP core, and the read clock input is connected to the operating clock of the hardware security chip.
[0013] Optionally, the hardware security chip supports national cryptographic algorithms and enables end-to-end identity authentication based on digital certificates.
[0014] Optionally, the first and second PHY chips are Gigabit Ethernet PHY chips that support the SGMII protocol.
[0015] Optionally, the high-speed optocoupler has a signal bandwidth of ≥1.5GHz and an isolation withstand voltage of ≥2500Vrms.
[0016] Optional, IP cores include: The first SGMII-GMII conversion unit is connected to the SGMII interface on the external network side; The second GMII-SGMII conversion unit is connected to the SGMII interface on the internal network side.
[0017] Optionally, the data flow path of the device includes: External network to internal network: First PHY chip - High-speed optocoupler isolator - First SGMII-GMII conversion unit - Buffer module - Hardware security chip - Second GMII-SGMII conversion unit - High-speed optocoupler isolator - Second PHY chip; The encryption operation is performed in reverse order from the internal network to the external network.
[0018] Optionally, the hardware security chip is directly connected to the GMII data output terminal of the buffer module via a parallel data bus, without a protocol conversion chip or interface logic.
[0019] Optionally, the device is integrated into the VPX bus system and conforms to the VITA 46.0 standard.
[0020] Optionally, the device can be deployed between an internal encrypted network and an external untrusted network.
[0021] The FPGA-based VPX system isolation access hardware device provided in this disclosure can achieve the following technical effects: This invention achieves the following advancements through a core architecture that integrates a protocol conversion and buffer module on an FPGA chip, optically isolated connections with dual PHY chips, and a security chip directly connected to the GMII bus: 1. Efficient synergy between gigabit bandwidth and electrical isolation The high-speed optocoupler isolator is directly connected between the SGMII interface of the FPGA and the SGMII interface of the PHY chip, compressing the isolation point to a serialized SGMII signal link (single pair of differential lines). Compared with isolating parallel GMII signals (8-bit data + control lines), it reduces the number of isolation channels significantly, breaking through the bottleneck of "high isolation withstand voltage inevitably sacrifices bandwidth" in traditional solutions, and supporting full-speed gigabit Ethernet transmission while ensuring electrical isolation.
[0022] 2. Hardware-level simplification of cross-clock domain synchronization The FPGA integrates an IP core (serial-to-parallel conversion) and a buffer module. Through the internal hardware link of the FPGA, it realizes the pipelined processing of "protocol conversion → buffering → encryption", eliminates the interconnection delay between discrete buffers and the main control chip, avoids signal jitter caused by PCB traces, and significantly improves the stability of cross-clock domain data transmission.
[0023] 3. Deep coupling of security encryption and data processing The hardware security chip is directly connected to the GMII parallel data output terminal of the buffer module.
[0024] The encryption operation is applied directly to the buffered GMII parallel data stream, eliminating the need to move data to an external encryption module as in traditional solutions. This eliminates interface conversion latency from the hardware architecture perspective, achieving near-zero latency response for streaming encryption and decryption.
[0025] 4. Improved system integration quality A single FPGA chip integrates a protocol conversion (IP core) and a buffer module, and is directly connected to the security chip and dual PHYs through an optimized path.
[0026] At the physical layer: the optocoupler only needs to process two SGMII differential signals (one for the external network and one for the internal network), which greatly reduces the number of isolation devices; At the logic layer: protocol conversion, buffering, and encryption control are centrally scheduled by the FPGA, eliminating the complexity of multi-chip collaboration; The overall architecture minimizes board area and simplifies signal paths, improving reliability and power efficiency.
[0027] The above general description and the description below are exemplary and illustrative only and are not intended to limit this application. Attached Figure Description
[0028] One or more embodiments are illustrated by way of example with reference to the accompanying drawings. These illustrations and drawings do not constitute a limitation on the embodiments. Elements having the same reference numerals in the drawings are shown as similar elements. The drawings are not to be scaled. And wherein: Fig. 1 This is a schematic diagram of an FPGA-based VPX system isolation access hardware device provided in an embodiment of this disclosure; Fig. 2 This is a schematic diagram of the signal connection of an internal IP core of an FPGA provided in an embodiment of this disclosure. Detailed Implementation
[0029] To provide a more detailed understanding of the features and technical content of the embodiments of this disclosure, the implementation of the embodiments of this disclosure will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for illustrative purposes only and are not intended to limit the embodiments of this disclosure. In the following technical description, for ease of explanation, several details are used to provide a full understanding of the disclosed embodiments. However, one or more embodiments may still be implemented without these details. In other cases, well-known structures and devices may be simplified in their depiction to simplify the drawings.
[0030] The terms "first," "second," etc., used in the embodiments of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this disclosure described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion.
[0031] In this disclosure, the terms "upper," "lower," "inner," "middle," "outer," "front," and "rear," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. These terms are primarily for better describing the embodiments of this disclosure and their implementations, and are not intended to limit the indicated devices, elements, or components to having a specific orientation, or to require them to be constructed and operated in a specific orientation. Furthermore, some of the aforementioned terms may be used to indicate other meanings besides orientation or positional relationship; for example, the term "upper" may in some cases indicate a dependency or connection relationship. Those skilled in the art can understand the specific meaning of these terms in this disclosure according to the specific circumstances.
[0032] Furthermore, the terms "set up," "connect," and "fix" should be interpreted broadly. For example, "connection" can be a fixed connection, a detachable connection, or an integral structure; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, or it can be an internal connection between two devices, components, or parts. Those skilled in the art can understand the specific meaning of the above terms in the embodiments of this disclosure according to the specific circumstances.
[0033] Unless otherwise stated, the term "multiple" means two or more.
[0034] In this embodiment of the disclosure, the character " / " indicates that the objects before and after it are in an "or" relationship. For example, A / B means: A or B.
[0035] The term "and / or" describes an association between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or A and B.
[0036] It should be noted that, unless otherwise specified, the embodiments and features described in the present disclosure can be combined with each other.
[0037] Combination Figs. 1-2 As shown, this disclosure provides an FPGA-based VPX system isolation access hardware device, including an FPGA chip, a first PHY chip, a second PHY chip, and a hardware security chip.
[0038] The FPGA chip integrates an IP core and a buffer module. The IP core is used to convert the input SGMII serial signal into a GMII parallel signal and the GMII parallel signal into an SGMII serial signal for output. The buffer module is connected to the GMII parallel data interface of the IP core for cross-clock domain data synchronization. The buffer module is the FIFO_generator buffer module, and the IP core is the gig_ethernet_pcs_pma IP core.
[0039] The first PHY chip and the second PHY chip are connected to the internal network domain and the external network domain, respectively, and the SGMII interfaces of the first PHY chip and the second PHY chip are connected to the SGMII interface of the FPGA chip through a high-speed optocoupler isolator. The hardware security chip is directly connected to the GMII parallel data output terminal of the buffer module for streaming encryption and decryption of the buffered data. The FPGA-based VPX system isolation access hardware device provided in this disclosure is an integrated hardware architecture of "isolation-encryption-buffering". It is an integrated design centered on FPGA. By integrating a FIFO_generator buffer queue and a gig_ethernet_pcs_pma IP core inside the FPGA, it realizes bidirectional conversion between SGMII serial signal (from the external second PHY chip YT8531) and GMII parallel signal, and synchronously completes cross-clock domain synchronization and electrical isolation. The FIFO_generator buffer queue is set at key nodes of the data flow. Its write clock is driven by the clock of the gig_ethernet_pcs_pma receiving side, and its read clock is driven by the clock of the encryption module, eliminating signal jitter and loss caused by the difference between internal and external network clocks. A collaborative "isolation-encryption-buffering" mechanism is adopted. In the isolation layer, high-speed optocouplers are placed on both sides of the FPGA's SGMII interface to block electrical interference. In the encryption layer, the hardware security chip WX1860 is directly connected to the FPGA to encrypt and decrypt GMII parallel data buffered by the FIFO in real time. In the buffering layer, the FIFO_generator buffer module resolves cross-clock domain signal conflicts, ensuring zero data loss under gigabit bandwidth. External network data is converted to SGMII by the second PHY chip, then converted to GMII by the gig_ethernet_pcs_pma IP core of the FPGA chip via the high-speed optocoupler isolator, stored in the FIFO_generator buffer module, encrypted by the WX1860, and then converted back to SGMII before being sent to the first PHY chip via the high-speed optocoupler isolator to achieve signal purification and path optimization.
[0040] As an example: the FPGA chip model can be Xilinx Kintex-7 XC7K325T, which can support SGMII and GMII protocol conversion; the PHY chip model can be YT8531; and the high-speed optocoupler isolator can be AVAGEL HCPL-072L with a bandwidth of 1.5Gbps.
[0041] Optionally, the write clock input of the buffer module is connected to the receive clock of the IP core, and the read clock input is connected to the operating clock of the hardware security chip.
[0042] Understandably, by associating the write clock and read clock of the FIFO buffer module with the operating clocks of the protocol conversion unit and the security chip, respectively, this invention achieves precise synchronization of data across clock domains. This design effectively eliminates the metastability risk caused by the difference in clock frequencies between the receiving and encryption sides, significantly reducing the probability of data loss or misalignment, thus ensuring the integrity and timing consistency of data transmission even at gigabit speeds.
[0043] Optionally, the hardware security chip supports national cryptographic algorithms and enables end-to-end identity authentication based on digital certificates.
[0044] Understandably, by limiting the security chip to support national cryptographic algorithms and certificate-based end-to-end authentication mechanisms, this invention enhances the system's proactive defense capabilities at the hardware level. This feature not only enables real-time streaming encryption of transmitted data to ensure confidentiality but also verifies the identities of both communicating parties through digital certificates, effectively resisting man-in-the-middle attacks and data tampering, thus meeting the stringent requirements of high-security domain networks for identity authentication and data integrity.
[0045] Optionally, the first and second PHY chips are Gigabit Ethernet PHY chips that support the SGMII protocol.
[0046] Understandably, by explicitly specifying the physical layer chip as a Gigabit Ethernet PHY chip supporting the SGMII protocol, this invention ensures compatibility between the device and mainstream hardware interfaces in the industry. This design allows the device to be directly adapted to a wide range of Gigabit Ethernet PHY chips on the market, reducing the complexity and cost of hardware selection and system integration, and improving the versatility and replaceability of the solution.
[0047] Optionally, the high-speed optocoupler has a signal bandwidth of ≥1.5GHz and an isolation withstand voltage of ≥2500Vrms.
[0048] Understandably, by quantifying the key parameters of the optocoupler isolation device (bandwidth ≥ 1.5 GHz, isolation withstand voltage ≥ 2500 Vrms), this invention provides a clear performance guarantee for reliable electrical isolation at gigabit speeds. High bandwidth ensures distortion-free transmission of SGMII signals after isolation, while high isolation withstand voltage can withstand transient voltage surges in harsh environments, enabling the overall insulation performance of the system to meet high-standard application scenarios such as military and aerospace.
[0049] Optional, IP cores include: The first SGMII-GMII conversion unit is connected to the SGMII interface on the external network side; The second GMII-SGMII conversion unit is connected to the SGMII interface on the internal network side.
[0050] Understandably, by setting up an independent bidirectional signal conversion unit in the FPGA's internal IP core, this invention achieves complete physical isolation between internal and external network data streams. This architecture avoids crosstalk between bidirectional signals during processing, significantly improves the system's common-mode rejection capability, and ensures the purity and stability of data transmission in high-noise environments.
[0051] Optionally, the data flow path of the device includes: External network to internal network: First PHY chip - High-speed optocoupler isolator - First SGMII-GMII conversion unit - Buffer module - Hardware security chip - Second GMII-SGMII conversion unit - High-speed optocoupler isolator - Second PHY chip; The encryption operation is performed in reverse order from the internal network to the external network.
[0052] Understandably, by solidifying the specific transmission path of bidirectional data within the hardware, this invention clarifies the timing logic of the "isolation-buffering-encryption" three-in-one architecture. This design avoids potential timing conflicts between encryption / decryption operations and data buffering, ensuring the determinism and predictability of the data processing flow, thereby simplifying system control logic and improving operational reliability.
[0053] Optionally, the hardware security chip is directly connected to the GMII data output terminal of the buffer module via a parallel data bus, without a protocol conversion chip or interface logic.
[0054] Understandably, by emphasizing a direct parallel bus connection between the security chip and the FPGA without protocol conversion, this invention completely eliminates the additional latency introduced by interface conversion (such as PCIe) in traditional encryption modules. This direct connection method achieves seamless integration of encryption operations and data flow, maximizing the efficiency of encryption processing and the overall system throughput.
[0055] Optionally, the device is integrated into the VPX bus system and conforms to the VITA 46.0 standard.
[0056] Understandably, by explicitly adapting the device to the VPX standard (VITA 46.0) system, this invention achieves plug-and-play integration with existing high-performance embedded computing platforms. This feature allows the device to be directly deployed in standard 3U / 6U VPX slots, fully leveraging the high bandwidth, robustness, and modularity advantages of the VPX architecture to quickly build highly secure and isolated computing nodes.
[0057] Optionally, the device can be deployed between an internal encrypted network and an external untrusted network.
[0058] Understandably, by limiting the application of the device to high-risk scenarios with high confidentiality requirements, the comprehensive capabilities of this utility model—low latency, high isolation, and strong encryption—perfectly meet the extreme requirements of the battlefield environment for real-time data transmission, reliability, and security, proving the practical value and broad application prospects of this hardware architecture.
[0059] This invention achieves a synergistic breakthrough in performance, isolation, and security through a three-in-one hardware architecture centered on an FPGA. By precisely setting the isolation point on the serial SGMII link and integrating a protocol conversion and buffering module within the FPGA, the device supports full-bandwidth gigabit Ethernet transmission while ensuring high electrical isolation strength, fundamentally resolving the technical contradiction of balancing high isolation and high speed in traditional solutions. Combined with a design where the security chip is directly connected to the GMII bus, microsecond-level latency for streaming encryption is achieved, simultaneously meeting the dual requirements of high security and real-time response.
[0060] In terms of system reliability, this invention significantly improves anti-interference capability and data transmission stability through multiple technical means, including cross-clock domain synchronization mechanism, bidirectional signal physical isolation, and fixed data path. Its highly integrated hardware architecture greatly reduces board area and power consumption, while being compatible with VPX standard and mainstream gigabit PHY chips, giving the device excellent engineering applicability and easy deployment characteristics.
[0061] Furthermore, this invention demonstrates excellent application adaptability. Its standardized interface design supports applications in multiple fields such as industrial control and aerospace, while its customized features for military scenarios ensure reliable operation in extreme environments. This design concept, combining a general-purpose platform with a high-reliability subset, enables this invention to meet the needs of ordinary industrial environments while also fulfilling the stringent requirements of high-reliability fields, achieving an organic unity of universality and specialization.
[0062] In summary, this utility model, through innovative reconstruction of the hardware architecture, enables deep synergy among the three functions of isolation, encryption, and buffering, ultimately creating a hardware device that combines gigabit bandwidth, high-strength isolation, low-latency encryption, and high reliability, providing an advanced domestic solution for network boundary protection of critical infrastructure.
[0063] The foregoing description and accompanying drawings fully illustrate embodiments of the present disclosure to enable those skilled in the art to practice them. Other embodiments may include structural and other changes. The embodiments represent only possible variations. Individual components and functions are optional unless explicitly required, and the order of operation may vary. Parts and features of some embodiments may be included or substituted for parts and features of other embodiments. Embodiments of the present disclosure are not limited to the structures described above and shown in the accompanying drawings, and various modifications and changes may be made without departing from its scope. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A VPX system isolation access hardware device based on FPGA, characterized in that, include: The FPGA chip integrates an IP core and a buffer module. The IP core is used to convert the input SGMII serial signal into a GMII parallel signal and the GMII parallel signal into an SGMII serial signal for output. The buffer module is connected to the GMII parallel data interface of the IP core for cross-clock domain data synchronization. The first PHY chip and the second PHY chip are connected to the internal network domain and the external network domain, respectively, and the SGMII interfaces of the first PHY chip and the second PHY chip are connected to the SGMII interface of the FPGA chip through a high-speed optocoupler isolator. The hardware security chip is directly connected to the GMII parallel data output terminal of the buffer module and is used for streaming encryption and decryption of the buffered data. Among them, the buffer module is the FIFO_generator buffer module, and the IP core is the gig_ethernet_pcs_pma IP core.
2. The isolation access hardware device according to claim 1, characterized in that, The write clock input of the buffer module is connected to the receive clock of the IP core, and the read clock input is connected to the working clock of the hardware security chip.
3. The isolation access hardware device according to claim 1, characterized in that, The hardware security chip supports national cryptographic algorithms and enables end-to-end identity authentication based on digital certificates.
4. The isolation access hardware device according to claim 1, characterized in that, The first and second PHY chips are Gigabit Ethernet PHY chips that support the SGMII protocol.
5. The isolation access hardware device according to any one of claims 1 to 4, characterized in that, The high-speed optocoupler has a signal bandwidth of ≥1.5GHz and an isolation withstand voltage of ≥2500Vrms.
6. The isolation access hardware device according to claim 5, characterized in that, IP cores include: The first SGMII-GMII conversion unit is connected to the SGMII interface on the external network side; The second GMII-SGMII conversion unit is connected to the SGMII interface on the internal network side.
7. The isolation access hardware device according to claim 5, characterized in that, The device's data flow path includes: External network to internal network: First PHY chip - High-speed optocoupler isolator - First SGMII-GMII conversion unit - Buffer module - Hardware security chip - Second GMII-SGMII conversion unit - High-speed optocoupler isolator - Second PHY chip; The encryption operation is performed in reverse order from the internal network to the external network.
8. The isolation access hardware device according to claim 5, characterized in that, The hardware security chip is directly connected to the GMII data output terminal of the buffer module via a parallel data bus, without a protocol conversion chip or interface logic.
9. The isolation access hardware device according to claim 1, characterized in that, The device is integrated into the VPX bus system and conforms to the VITA 46.0 standard.
10. The isolation access hardware device according to claim 1, characterized in that, The device is deployed between an internal encrypted network and an external untrusted network.