基于PSPA架构的安全网关系统及设备

By constructing a trusted execution environment and a rich execution environment through a security gateway system based on the PSPA architecture, the system solves the problem of insufficient security in existing data gateways, realizes the security of data acquisition, processing, storage, and transmission, and improves the overall protection of the data gateway.

CN116582271BActive Publication Date: 2026-07-17CHINA POWER IND INTERNET CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA POWER IND INTERNET CO LTD
Filing Date
2023-04-23
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing data gateways lack sufficient security, are vulnerable to security risks from foreign chip firmware, rely solely on Level 1 trusted security certification, and lack proactive defense and systemic security protection, thus failing to effectively guarantee the security of data collection, processing, storage, and transmission.

Method used

The security gateway system based on PSPA architecture includes a secure boot subsystem, a port driver security subsystem, a protocol security authentication subsystem, a data storage security subsystem, a key management subsystem, a system security authentication subsystem, an application scheduling subsystem, and a trusted application (TA). It constructs a trusted execution environment and a rich execution environment to achieve security for secure boot, data transmission, storage, and upload.

Benefits of technology

It improves the overall security of the data gateway by using domestically produced chips and multi-level trusted boot to prevent vulnerabilities in foreign chip firmware, achieving proactive data immunity and systemic security protection, and ensuring data security at every stage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116582271B_ABST
    Figure CN116582271B_ABST
Patent Text Reader

Abstract

本申请涉及一种基于PSPA架构的安全网关系统及设备,通过由端口驱动安全子系统、协议安全认证子系统以及系统安全认证子系统构建丰富执行环境保证安全网关系统对网关数据进行保护,同时通过由数据存储安全子系统、密钥管理子系统、应用调度子系统、协议可信应用TA以及系统管理可信应用TA构建可信执行环境保证安全网关系统中应用程序在安全环境中运行,其次,还通过安全引导子系统保证安全网关系统的安全启动,本安全网关系统基于PSPA,将可信执行环境和丰富执行环境,与网关端口和应用业务安全相结合,从端口和业务数据两个角度保障网关数据的安全性,以实现对数据从采集、处理、存储以及传输等各环节的安全性,提高网关系统的整体防护性。
Need to check novelty before this filing date? Find Prior Art