A multi-link lightweight secure communication device
Patent Information
- Application Number
- CN202522397040.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-12
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2035-11-12
AI Technical Summary
但现有方案存在明显缺陷:其一,如中国实用新型CN214481281U所示的早期无线传输装置,在数据传输过程中缺乏加密,安全性不足;其二,更为先进的“警用无线安全网关”虽提升了安全等级,却普遍采用“主控芯片+安全芯片”的多芯片架构,不仅硬件复杂、成本高昂,更关键的是,数据在芯片间中转时易遭受中间人攻击,反而引入了新的安全风险
[0014]与现有技术相比较,本实用新型通过采用以高性能安全芯片为核心的单芯片硬件架构,并集成基于PUF的轻量级身份认证机制,有效解决了现有警用通信设备存在的三大核心问题:其一,从物理层面消除了多芯片间数据中转导致的中间人攻击风险,显著提升了安全性;其二,高度集成的设计大幅降低了设备的硬件复杂度、功耗与制造成本,更利于规模化部署;其三,所提供的多链路通信能力(涵盖PWL、公网4G/5G及有线以太网)确保了在不同实战环境下的连接可靠性与灵活性。因此,本实用新型为公共安全领域的移动物联网应用提供了高效可靠的接入解决方案。
Smart Images

Figure CN224804953U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to a multi-link lightweight secure communication device, belonging to the field of data transmission technology. Background Technology
[0002] In the field of public safety, real-time and secure transmission of field data is crucial. Currently, various police data collection terminals typically transmit data wirelessly to the central control center via industry-specific mobile information networks. However, due to extremely high security considerations, the use of conventional wireless local area networks (such as Wi-Fi) is strictly prohibited, forcing a large number of IoT devices to rely on wired Ethernet for data transmission, severely limiting deployment flexibility and emergency response efficiency.
[0003] To balance convenience and security in wireless communication, the industry has introduced Police Wireless Local Area Network (PWL) technology. However, existing solutions have significant drawbacks: First, early wireless transmission devices, such as the one shown in Chinese utility model CN214481281U, lack encryption during data transmission, resulting in insufficient security. Second, while more advanced "police wireless security gateways" improve security levels, they generally employ a multi-chip architecture of "main control chip + security chip," which is not only complex and costly, but more importantly, vulnerable to man-in-the-middle attacks when data is transferred between chips, introducing new security risks. Furthermore, most existing security devices rely on traditional Public Key Infrastructure (PKI) systems for authentication. This system involves cumbersome certificate management processes, resulting in significant computational, storage, and communication overhead. Its cumbersome authentication mechanism is ill-suited to the urgent needs of grassroots units for low-cost, high-efficiency deployment.
[0004] In summary, the current field of secure communication faces three core challenges: the inflexibility of wired transmission, the insufficient security of early wireless solutions, and the overly cumbersome architecture, cost, and authentication mechanisms of existing advanced security devices. Therefore, there is an urgent need for a new type of communication device that can balance high security, low power consumption and cost, multi-link adaptability, and lightweight authentication to support the large-scale, practical application of mobile IoT in public safety. Utility Model Content
[0005] The technical problem to be solved by this utility model is to provide a multi-link lightweight secure communication device.
[0006] To achieve the above technical objectives, the present invention adopts the following technical solution: According to an embodiment of this utility model, a multi-link lightweight secure communication device is provided, including a PUF module, a security chip, and a data transmission module; wherein... The PUF module is a circuit based on the physical non-cloning property of hardware, used to generate unique device identity authentication information; The output of the PUF module is connected to the authentication input of the security chip. The security chip serves as both the main control chip and the security chip, used to perform lightweight identity authentication based on PUF and to encrypt transmitted data at the service layer. The input terminal of the data transmission module is connected to the output terminal of the security chip; The data transmission module includes a police wireless local area network module, a public network 4G / 5G communication module, and a wired Ethernet module to achieve multi-link communication.
[0007] Preferably, the security chip connects to the police wireless LAN module and the public 4G / 5G communication module via a USB interface, and to the wired Ethernet module via an RGMII interface.
[0008] Preferably, the secure communication device further includes a BeiDou positioning module, which is connected to the secure chip via a UART interface.
[0009] Preferably, both the PUF module and the data transmission module are integrated with the security chip via a bus to form a single-chip hardware architecture.
[0010] Preferably, the PUF module is a physically non-clonable functional circuit based on the power-on state of the SRAM memory cell.
[0011] Preferably, the security chip is a cryptographic SOC chip of model S580.
[0012] Preferably, the public network 4G communication module is EC20, and the public network 5G communication module is RG200U-CN.
[0013] Preferably, the police wireless local area network module is PWL-W-STA.
[0014] Compared with existing technologies, this invention effectively solves three core problems of existing police communication equipment by adopting a single-chip hardware architecture with a high-performance security chip at its core and integrating a lightweight identity authentication mechanism based on PUF: First, it eliminates the risk of man-in-the-middle attacks caused by data relay between multiple chips at the physical level, significantly improving security; second, the highly integrated design greatly reduces the hardware complexity, power consumption, and manufacturing cost of the device, making it more conducive to large-scale deployment; third, the provided multi-link communication capabilities (covering PWL, public 4G / 5G, and wired Ethernet) ensure the reliability and flexibility of connections in different combat environments. Therefore, this invention provides an efficient and reliable access solution for mobile IoT applications in the public safety field. Attached Figure Description
[0015] Figure 1 A schematic diagram of the structure of a multi-link lightweight secure communication device provided for an embodiment of this utility model; Figure 2 This is a schematic diagram of the PUF module in an embodiment of the present invention; Figure 3 This is a schematic diagram of the security chip structure in an embodiment of the present invention; Figure 4 This is a schematic diagram of the data transmission module in an embodiment of the present invention; Figure 5 This is a schematic diagram of the structure of the Beidou positioning module in an embodiment of this utility model; Figure 6 This is a schematic diagram illustrating the working principle of a multi-link lightweight secure communication device provided in an embodiment of the present invention. Detailed Implementation
[0016] The technical content of this utility model will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0017] like Figure 1 As shown, this embodiment of the invention provides a multi-link lightweight secure communication device, comprising at least a PUF (Physically Unclonable Function) module, a security chip, and a data transmission module. The output of the PUF module is connected to the authentication input of the security chip; the output of the security chip is connected to the input of the data transmission module. It should be noted that both the PUF module and the data transmission module are integrated with the security chip via a bus, forming a single-chip hardware architecture.
[0018] like Figure 2 As shown, in one embodiment of this invention, the PUF module is a physically unclonable functional circuit based on the power-on state of SRAM memory cells. This circuit utilizes inherent random physical differences in semiconductor manufacturing (such as transistor threshold voltage deviations and wire resistance fluctuations) to generate a unique and uncopyable physical response signal (PUF Response) upon receiving a specific excitation signal (such as a fixed voltage or clock pulse). This physical response signal has physical binding, meaning that each device's response signal is unique and cannot be forged or copied by algorithms. The authentication process based on this mechanism is also lightweight; the authentication process does not require complex key exchange. The security chip only needs to send the response signal to the backend server, where it is compared with a pre-registered PUF template to complete the authentication. The entire process takes only milliseconds, far less than traditional RSA asymmetric authentication, perfectly adapting to the computing power limitations of various police data acquisition terminals.
[0019] like Figure 3As shown, in one embodiment of this utility model, the security chip is a high-performance chip, model S580. This chip serves as both a security chip and the main control chip for the entire device, responsible for encrypting communication data at the service layer, and also for controlling and scheduling all other communication modules.
[0020] The S580 is a cryptographic SoC chip designed for edge computing and IoT security. It utilizes a domestically produced high-performance RISC-V core (up to 500MHz) and integrates multiple high-speed interfaces and encryption modules, specifically designed for portable security devices. This chip supports high-speed communication interfaces such as PCIe 2.0x1, USB 3.0, and four Gigabit Ethernet ports, while also being compatible with lower-speed interfaces such as eMMC, QSPI, I2C, and UART, meeting the multi-interface collaboration needs of complex devices. Furthermore, the chip incorporates a hardware acceleration engine, supporting the national cryptographic algorithms SM1 / SM2 / SM3 / SM4 / SM7. Symmetric algorithms (such as SM4) achieve a performance of up to 2Gbps, and asymmetric algorithms (such as SM2 signatures) achieve 16,000 encryption / decryption operations per second, capable of handling real-time encryption and decryption of thousands of messages per second in V2X communication. Further details about the S580 can be found at the following link: https: / / www.mucse.com / , and will not be elaborated upon here.
[0021] It should be noted that the S580's integrated design, serving as both a security chip and a main control chip, is one of the core innovations of this secure communication device. Compared to the traditional separate architecture of a security chip + independent main control chip, it has three significant advantages: First, data interaction latency is significantly reduced. In existing discrete architectures, encrypted data needs to be transmitted between the security chip and the main control chip via SPI or USB interface. A single transmission of 1KB of data takes about 10ms, and there is a risk of data hijacking. In contrast, in the integrated design of this invention, data is transmitted directly on the internal bus of the chip, with a very short transmission time (≤1ms). At the same time, encrypted data is stored in a secure area through memory isolation technology, completely eliminating security risks during transmission.
[0022] Secondly, it reduces system complexity and cost. Existing discrete architectures require additional design of communication protocols between the main control and security chips, increasing software development difficulty and debugging cycle; while the integrated design of this utility model eliminates the need for additional protocols, significantly improving software development efficiency and reducing the procurement and soldering costs of a single chip, resulting in a significant reduction in hardware costs.
[0023] Third, security is significantly improved. In the existing separate architecture, if the main control chip is hijacked, attackers can forge control commands to deceive the security chip; however, in the integrated design of this utility model, the security function and the main control function share the same kernel, and the main control function's access to the security area is strictly restricted through a security isolation mechanism. Even if the main control function has vulnerabilities, it cannot affect core security functions such as encryption and authentication.
[0024] Furthermore, business layer encryption differs from traditional transport layer encryption in that its core lies in the precise encryption of specific business data. Traditional transport layer encryption only encrypts the data transmission channel, failing to distinguish data types and exhibiting coarse encryption granularity. Business layer encryption, on the other hand, selects appropriate encryption algorithms and granularities based on data type, achieving on-demand encryption. For example, for high-definition law enforcement video, the SM4 symmetric encryption algorithm is used, employing 1024KB blocks for encryption, balancing efficiency and security. For device control commands, the SM2 asymmetric encryption algorithm is used for signature encryption, ensuring the uniqueness and immutability of the command source. For temperature and humidity data collected by sensors, the SM7 lightweight encryption algorithm is used, reducing computational consumption while ensuring security. This refined encryption design avoids both the inefficiency caused by over-encryption and the security risks associated with insufficient encryption.
[0025] like Figure 4 As shown, in one embodiment of this utility model, the data transmission module includes a public network 4G / 5G module, a wired Ethernet module, and a PWL (Police Wireless Local Area Network) module. The security chip is connected to the public network 4G / 5G module and the police wireless local area network module via a USB interface; the security chip is connected to the wired Ethernet module via an RGMII interface.
[0026] In one embodiment of this utility model, the public network 4G module is EC20, and the public network 5G module is RG200U-CN. EC20 and RG200U-CN are two communication modules launched by Quectel. EC20 is an LTE Cat4 module designed by Quectel specifically for M2M and IoT, supporting a maximum downlink rate of 150Mbps and an uplink rate of 50Mbps, and is compatible with mainstream global LTE frequency bands (such as B1 / B3 / B5 / B8, etc.). RG200U-CN is Quectel's 5G module for industrial applications, supporting the 3GP PRELESS A15 / 16 standard, compatible with NSA and SA dual-mode networking, and backward compatible with 4G / 3G. Further details about EC20 and RG200U-CN can be found at the following link: https: / / www.quectel.com.cn / , and will not be elaborated upon here.
[0027] In one embodiment of this utility model, the police wireless LAN module is PWL-W-STA. PWL-W-STA is a client device in the police wireless LAN, mainly used for mobile police communication and secure access in the public security system. It is a high-security wireless communication module designed for public security, judicial, and other fields. This module implements end-to-end encryption based on the WAPI protocol. By integrating a security encryption card from the First Research Institute of the Ministry of Public Security, it only allows devices with dedicated security cards to access the network and supports dual encryption of management frames and data frames to prevent communication content from being stolen or tampered with. Further details about PWL-W-STA can be found at the following link: https: / / www.td-tech.com / , and will not be elaborated upon here.
[0028] In one embodiment of this utility model, the secure communication device further includes a BeiDou positioning module, and the secure chip is connected to the BeiDou positioning module via a UART interface. Figure 5 As shown, the BeiDou positioning module is implemented by the FH-BDM306. The FH-BDM306 is a BeiDou communication module specifically designed for high-precision positioning and communication needs. Internally, it integrates a receiving low-noise amplifier module, a transmitting power amplifier module, and a positioning module, supporting highly integrated short message communication (RSMC), navigation positioning (RNSS), and location reporting functions. Simultaneously, this module supports RNSS positioning on the B1I / B1C frequency bands and is compatible with the RSMC short message communication protocol. Further details about the FH-BDM306 can be found at the following link: https: / / chinacomm.com.cn / cpzx, and will not be elaborated upon here.
[0029] like Figure 6 As shown below, the working principle of this secure communication device is explained: S1: The security chip initializes all modules and sends an excitation signal to the PUF module.
[0030] S2: The PUF module generates a unique response signal and feeds it back to the security chip.
[0031] S3: The security chip sends the device ID and unique response signal to the data processing center through the data transmission module.
[0032] S4: The data processing center queries the device's preset PUF template and compares the unique response signal with the preset PUF template. If the comparison results match, an authentication success command is sent to the security chip, and a unique encryption key is assigned, proceeding to step S5. If the comparison results do not match, an access denial command is sent to the security chip, and all data transmission is prohibited.
[0033] S5: Various police data collection terminals (such as cameras, microphones, and sensors) collect business data and send it to the security chip.
[0034] S6: The security chip uses a dedicated encryption key to encrypt business data at the business layer, and selects the optimal link based on the current link status to send the encrypted business data to the data processing center.
[0035] It should be noted that the priority for link selection is: PWL link > public 4G / 5G link > wired Ethernet link.
[0036] When using a public 4G / 5G link, in step S3, it is also necessary to collect the detailed location information of the current device and send the detailed location information of the current device, along with the device ID and unique response signal, to the data processing center through the data transmission module.
[0037] It should be noted that the above embodiments are merely illustrative examples. The technical solutions of the various embodiments can be combined, and all are within the protection scope of this utility model.
[0038] The present invention provides a detailed description of a multi-link lightweight secure communication device. Any obvious modifications made by those skilled in the art without departing from the essential content of this invention will constitute an infringement of the patent rights of this invention and will incur corresponding legal liability.
Claims
1. A multi-link lightweight secure communication device, characterized in that... This includes a PUF module, a security chip, and a data transmission module; among which, The PUF module is a circuit based on the physical non-cloning property of hardware, used to generate unique device identity authentication information; The output of the PUF module is connected to the authentication input of the security chip. The security chip serves as both the main control chip and the security chip, used to perform lightweight identity authentication based on PUF and to encrypt transmitted data at the service layer. The input terminal of the data transmission module is connected to the output terminal of the security chip; The data transmission module includes a police wireless local area network module, a public network 4G / 5G communication module, and a wired Ethernet module to achieve multi-link communication.
2. The secure communication device as described in claim 1, characterized in that: The security chip connects to the police wireless LAN module and the public 4G / 5G communication module via a USB interface, and to the wired Ethernet module via an RGMII interface.
3. The secure communication device as described in claim 1, characterized in that... It also includes a BeiDou positioning module, which is connected to the security chip via a UART interface.
4. The secure communication device according to any one of claims 1 to 3, characterized in that: Both the PUF module and the data transmission module are integrated with the security chip via a bus, forming a single-chip hardware architecture.
5. The secure communication device as described in claim 4, characterized in that: The PUF module is a physically unclonable functional circuit based on the power-on state of SRAM memory cells.
6. The secure communication device as described in claim 1, characterized in that: The security chip is a cryptographic SOC chip of model S580.
7. The secure communication device as described in claim 1, characterized in that: The public network 4G communication module is EC20, and the public network 5G communication module is RG200U-CN.
8. The secure communication device as described in claim 1, characterized in that: The police wireless LAN module is PWL-W-STA.
Citation Information
Patent Citations
Data transmission device used between mobile police service terminal and police peripheral
CN214481281U