This invention discloses a multi-tenant end-to-end
data security isolation and
control system and method, belonging to the field of vehicle
network data security. It aims to solve the problems of easy data
crosstalk, discontinuous isolation, unreliable trust benchmarks, and difficulty in compliance
traceability in multi-tenant scenarios. The
system generates a tenant root identifier (TID) for vehicle enterprise tenants, which, together with the device sub-identifier (DID), forms a tenant identifier chain. This chain is synchronized with a trusted
authentication center to establish a vehicle-cloud hardware-level trust root. When the vehicle terminal accesses the
system, it completes two-way identity
authentication and allocates a dedicated
message queue telemetry transmission
MQTT topic partition and access permissions according to the TID. The terminal collects time-series
vehicle control data and generates encrypted data frames with intrinsic identifiers and checksums for uploading. The access gateway performs dual isolation
verification before transparent transmission. Data is forwarded to an independent logical storage partition for isolated storage according to the TID. This invention achieves strong hardware-level isolation, real-time
verification, and full
traceability throughout the entire end-to-cloud chain, effectively preventing cross-tenant data leakage.