Terminal data trusted transmission system and method based on active identification carrier, terminal and medium
By using a terminal data trusted transmission system based on active identification carrier in terminal equipment, data encryption and decryption is used to encrypt and decrypt data through the communication interaction interface of the carrier body and the security chip, and wirelessly connect it with the Commercial Secret Platform through the IoT middle platform, the problems of low data transmission security and high encryption and decryption calculation load in the industrial Internet environment are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510267291.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-05-30
AI Technical Summary
In the industrial Internet environment, the data transmission security between terminal devices and cloud platforms is low, and the encryption and decryption calculation load is high, affecting other performance of terminal devices.
A terminal data trusted transmission system based on active identification carrier is adopted. The system includes a carrier body and a security chip. The carrier body and the security chip interact through a communication interaction interface, supporting data encryption, signature, signature verification and decryption, and wirelessly connect with the trade secret platform through the IoT middle platform to realize trusted transmission of data.
It improves the security of data transmission, reduces the computing load of terminal devices, improves the efficiency of data processing, and prevents static analysis of keys, enhancing the security of the system.
Smart Images

Figure CN120074820A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and particularly to a terminal data trusted transmission system, method, terminal and medium based on an active identification carrier. Background Art
[0002] With the booming development of the industrial Internet, the data interaction between terminal devices and cloud platforms has become increasingly frequent. These data cover important contents such as sensitive industrial information, national security and personal privacy, and their security, integrity and credibility during the transmission process are crucial.
[0003] To address this challenge, the industry has developed and applied a series of data transmission security technologies. Among them, the SSL / TLS (Secure Sockets Layer / Transport Layer Security) protocol is one of the most well-known. The SSL / TLS protocol effectively prevents data from being eavesdropped or tampered with during transmission by providing an encrypted channel for communication between the client and the server. At the same time, the protocol also realizes authentication through digital certificates and key exchange mechanisms, ensuring the authenticity and credibility of both communication parties.
[0004] However, in the complex industrial Internet environment, existing data transmission security technologies, including the SSL / TLS protocol, also expose some limitations. On the one hand, these technologies have relatively high requirements for hardware resources. There are a wide variety of terminal devices in the industrial Internet with different performances. Many devices are difficult to fully adapt to these advanced data transmission security technologies due to limited resources. This may lead to security risks in the data transmission process of some devices and they cannot be fully protected. On the other hand, existing data transmission security technologies have a greater impact on the performance of terminal devices when dealing with high-computation-load encryption and decryption processes. In the industrial Internet environment, many terminal devices need to interact with the cloud platform in real time and at high frequencies. If the encryption and decryption processes occupy too much computing resources, it may lead to a decline in the performance of terminal devices when processing other business logics, and even affect the stability and efficiency of the entire industrial system. Summary of the Invention
[0005] To solve the technical problems that in the industrial Internet environment, the data transmission security between terminal devices and cloud platforms is relatively low and the encryption and decryption computing load of terminal devices is relatively high, affecting other performances of terminal devices, the present invention provides a terminal data trusted transmission system based on an active identification carrier, and also provides a terminal data trusted transmission method, a terminal and a medium based on an active identification carrier.
[0006] To achieve the above object, in a first aspect, the technical solution adopted by a terminal data trusted transmission system based on an active identification carrier in the present invention is as follows: A terminal data trusted transmission system based on an active identification carrier includes an active identification carrier and a cloud platform server. The active identification carrier is located in the data acquisition terminal device. The active identification carrier includes a carrier body and a security chip. The cloud platform server includes an IoT middleware platform and a commercial cryptography platform. Among them, The carrier body and the security chip interact through a communication interface to achieve data transmission. The security chip supports the secure storage of a unique industrial Internet of Things identification and a device key. Once the industrial Internet of Things identification and the device key are written, they cannot be modified. The security chip can encrypt, sign, verify signatures, and decrypt data under the communication call of the carrier body; The carrier body is wirelessly connected to the IoT middleware platform to achieve data transmission. The IoT middleware platform and the commercial cryptography platform interact through a communication interface to achieve data transmission. The commercial cryptography platform can encrypt, sign, verify signatures, and decrypt data under the communication call of the IoT middleware platform.
[0007] As a preferred implementation of a terminal data trusted transmission system based on an active identification carrier, the carrier body includes a key management platform module, a key generation module, an encryption / decryption module, an identity authentication module, a communication interface, an identification management module, a storage medium module, and a data remote transmission module; Among them, the key management platform module, the key generation module, the encryption / decryption module, and the identity authentication module are virtual hardware security module trusted applications built based on a trusted execution environment; The identity authentication module performs trusted identity authentication with the cloud platform server based on authentication information; The communication interface is a communication interface for the carrier body to maintain protocol communication with the outside to achieve message communication with the outside; The identification management module and the storage medium module maintain the active identification code, support the presetting and OTA upgrade of the identification code of the carrier body, and support the writing, reading, modification, and deletion of the identification of the cloud platform server; The data remote transmission module maintains a communication protocol to perform wireless communication with the cloud platform server through a wireless communication module.
[0008] As a preferred implementation of a terminal data trusted transmission system based on an active identification carrier, the security chip includes a security engine module, a secure storage medium module, a communication interface module, and a national cryptography algorithm module; Among them, the security engine module provides encryption services for the carrier body; The secure storage medium module stores the industrial Internet of Things identification and the device key. The cloud platform server and the carrier body store their respective asymmetric algorithm encryption private keys and the public keys of each other in the secure storage medium module; The communication module conducts protocol communication with the carrier body; The national cryptography algorithm module supports national cryptography standards SM2, SM3, SM4, and SM9 algorithms.
[0009] In a second aspect, the technical solution adopted by a method for trusted transmission of terminal data based on an active identification carrier in the present invention is as follows: A method for trusted transmission of terminal data based on an active identification carrier, including: Constructing an edge-side data acquisition terminal device by using an active identification carrier with trusted computing capabilities; the active identification carrier includes a carrier body running in a trusted execution environment and a security chip; The carrier body and the security chip interact through a communication interface. The security chip can encrypt, sign, verify signatures, and decrypt data under the communication call of the carrier body. The security chip supports the secure storage of a unique industrial Internet identifier and a device key, and once the industrial Internet identifier and the device key are written, they cannot be modified; The carrier body and the Internet of Things middleware of the cloud platform server are wirelessly connected to achieve data transmission. The commercial cryptography platform in the cloud platform server can encrypt, sign, verify signatures, and decrypt data under the communication call of the Internet of Things middleware.
[0010] As a preferred implementation of a method for trusted transmission of terminal data based on an active identification carrier, in the uplink data transmission, the security chip is called to encrypt the uplink data using a symmetric encryption algorithm to obtain uplink ciphertext data. The security chip is called to sign the uplink ciphertext data using the private key of the asymmetric encryption algorithm of the carrier body. The uplink ciphertext data and the corresponding signature data are transmitted to the Internet of Things middleware of the cloud platform server. The commercial cryptography platform is called to verify the signature of the uplink ciphertext data and the corresponding signature data using the public key of the carrier body. After successful signature verification, the commercial cryptography platform is called to decrypt the uplink ciphertext data using a symmetric key to obtain the uplink data.
[0011] As a preferred implementation of a method for trusted transmission of terminal data based on an active identification carrier, in the downlink data transmission, the control data of the cloud platform server is encrypted using a symmetric encryption algorithm through the Internet of Things middleware to obtain downlink ciphertext data. The commercial cryptography platform is called to sign the downlink ciphertext data using the private key of the asymmetric encryption algorithm of the Internet of Things middleware. The downlink ciphertext data and the corresponding signature data are transmitted to the carrier body. The security chip is called to verify the signature of the downlink ciphertext data and the corresponding signature data using the public key of the physical middleware. After successful signature verification, the security chip is called to decrypt the downlink ciphertext data using a symmetric key to obtain the original control data.
[0012] As a preferred implementation of a method for trusted transmission of terminal data based on an active identification carrier, the symmetric encryption algorithm is SM4, and the asymmetric encryption algorithm is SM9.
[0013] As a preferred implementation of the terminal data trusted transmission method based on the active identification carrier, before each use of the symmetric key, it is obtained through a series of random number operations generated by a true random number generator. The real symmetric key is temporarily generated in the RAM and is lost when the power is off.
[0014] Thirdly, the technical solution adopted by a terminal in the present invention is as follows: A terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of any one of the above-mentioned terminal data trusted transmission methods based on the active identification carrier.
[0015] Fourthly, the technical solution adopted by a medium in the present invention is as follows: A storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of any one of the above-mentioned terminal data trusted transmission methods based on the active identification carrier.
[0016] The beneficial effects of the present invention include: 1. Improve the security of data transmission. By using the carrier body with trusted computing capabilities and the security chip, the present invention can effectively prevent data from being intercepted, tampered with, or forged during the transmission process, ensuring the security of the data.
[0017] 2. Reduce the computing load. By sending the encryption and decryption processes to the security chip with a dedicated cryptographic hardware computing unit for processing, the present invention reduces the computing burden of the data acquisition terminal device and improves the efficiency of data processing.
[0018] 3. Prevent static analysis: By obtaining the symmetric key through random number operations generated by a true random number generator and temporarily generating it in the RAM, which is lost when the power is off, the present invention effectively prevents the static analysis of the key and improves the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solution of the present invention, the drawings required for description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0020] Figure 1 It is a schematic structural diagram of a terminal data trusted transmission system based on the active identification carrier in the specific embodiment of the present invention; Figure 2 It is a schematic flowchart of a terminal data trusted transmission method based on the active identification carrier in the specific embodiment of the present invention; Figure 3 This is a schematic diagram of the data uplink data transmission process in a terminal data trusted transmission method based on an active identification carrier in the specific implementation manner of the present invention; Figure 4 This is a schematic diagram of the data downlink data transmission process in a terminal data trusted transmission method based on an active identification carrier in the specific implementation manner of the present invention. Specific implementation manner
[0021] Before describing the technical content of the specific embodiments of the present invention, first introduce the professional knowledge involved in the present invention: 1. An active identification carrier refers to an entity that can be embedded inside an industrial device, carry an industrial Internet identification code and its necessary security certificates, algorithms, and keys, and have an Internet connection communication function. It can actively initiate a connection to an identification resolution service node or an identification data application platform, etc., without the need to trigger by means of an identification reading and writing device.
[0022] 2. Trusted transmission of data acquisition terminal device data means that when data is transmitted between data acquisition terminal devices or between a data acquisition terminal device and a server, it can ensure the integrity, confidentiality, availability, and authenticity of the data, so as to ensure that the data is not tampered with, leaked, or damaged.
[0023] To make the objectives, features, and advantages of the present invention more obvious and understandable, the technical solutions in the present invention will be clearly and completely described below in conjunction with the accompanying drawings in this specific embodiment. Obviously, the embodiments described below are only a part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.
[0024] Refer to Figure 1 The technical solution adopted by a terminal data trusted transmission system based on an active identification carrier proposed in this embodiment is: A terminal data trusted transmission system based on an active identification carrier includes an active identification carrier and a cloud platform server. The active identification carrier is located in a data acquisition terminal device. The active identification carrier runs in a trusted execution environment (TEE) and has trusted computing capabilities. The active identification carrier includes a carrier body and a security chip. The cloud platform server includes an IoT middleware platform and a commercial cryptography platform, where: The carrier body and the security chip interact through a communication interface. The security chip supports the secure storage of a unique industrial Internet identification and a device key. Once the industrial Internet identification and the device key are written, they cannot be modified. The security chip can encrypt, sign, verify signatures, and decrypt data under the communication call of the carrier body; The carrier body is wirelessly connected to the Internet of Things middleware to achieve data transmission. The Internet of Things middleware and the commercial cryptography platform interact through a communication interface to achieve data transmission. The commercial cryptography platform can encrypt, sign, verify signatures, and decrypt data under the communication call of the Internet of Things middleware.
[0025] In this embodiment, the active identification carrier is located in the data acquisition terminal device, and the carrier body can perform protocol communication with the sensors for data acquisition in the terminal device.
[0026] In this embodiment, the active identification carrier is in the forms of chips, modules, boards, etc. The commercial cryptography platform supports national cryptography algorithms such as SM2, SM3, SM4, and SM9.
[0027] In this embodiment, the carrier body includes a key management platform module, a key generation module, an encryption / decryption module, an identity authentication module, a communication interface, an identification management module, a storage medium module, and a data remote transmission module; Among them, the key management platform module, the key generation module, the encryption / decryption module, and the identity authentication module are virtual hardware security module trusted applications built based on a trusted execution environment; The identity authentication module performs trusted identity authentication with the cloud platform server based on authentication information; The communication interface is a communication interface for the carrier body to maintain protocol communication with external devices (such as security chips and sensors for data acquisition in terminal devices) using protocols such as IIC, UART, SPI, RS485, and RS232 to achieve message communication with the outside; The identification management module and the storage medium module maintain the active identification code, support the presetting and OTA upgrade of the identification code of the carrier body, and support the writing, reading, modification, and deletion of the identification code with the cloud platform server; The data remote transmission module maintains communication protocols such as mqtt to perform wireless communication with the cloud platform server through wireless communication modules such as 4G / WIFI / NBIOT / LoRa for data transmission.
[0028] In this embodiment, the security chip includes a security engine module, a secure storage medium module, a communication interface module, and a national cryptography algorithm module; Among them, the security engine module provides encryption services for the carrier body; The secure storage medium module stores the industrial Internet identification and device keys. The cloud platform server and the carrier body store their respective asymmetric algorithm encryption private keys and the public keys of each other in the secure storage medium module. The asymmetric algorithm encryption private key is used for signing, and the public key is used for signature verification; The communication module performs protocol communication with the carrier body; The national cryptography algorithm module supports national cryptography standards SM2, SM3, SM4, and SM9 algorithms.
[0029] In this embodiment, the industrial Internet identifier and the device key can be prefabricated in the secure storage medium module of the secure chip at the time of factory shipment. Once written, the industrial Internet identifier and the device key cannot be modified and are protected against malicious tampering.
[0030] In this embodiment, the IoT middleware platform and the commercial cryptography platform can perform identity authentication, key management, encryption requests, and decryption requests.
[0031] Refer to Figure 2 , the following is a method for trusted transmission of terminal data based on an active identification carrier provided by an embodiment of the present disclosure. A method for trusted transmission of terminal data based on an active identification carrier and a system for trusted transmission of terminal data based on an active identification carrier in each of the above embodiments belong to the same inventive concept. Details not described in detail in the embodiment of the method for trusted transmission of terminal data based on an active identification carrier can refer to the embodiment of the system for trusted transmission of terminal data based on an active identification carrier.
[0032] A method for trusted transmission of terminal data based on an active identification carrier proposed in this embodiment includes: S01. Use an active identification carrier with trusted computing capabilities to construct an edge-side data acquisition terminal device; the active identification carrier includes a carrier body running in a trusted execution environment and a secure chip; S02. The carrier body and the secure chip interact through a communication interface. The secure chip can encrypt, sign, verify signatures, and decrypt data under the communication call of the carrier body. The secure chip supports the secure storage of a unique industrial Internet identifier and a device key, and once written, the industrial Internet identifier and the device key cannot be modified; The carrier body and the IoT middleware platform of the cloud platform server interact through a wireless connection to achieve data transmission. The commercial cryptography platform in the cloud platform server can encrypt, sign, verify signatures, and decrypt data under the communication call of the IoT middleware platform.
[0033] Figure 3 For the schematic diagram of the uplink data transmission process in this embodiment, refer to Figure 3 , in this embodiment, the uplink data transmission process is as follows: S11. Call the secure chip to encrypt the uplink data using a symmetric encryption algorithm to obtain uplink ciphertext data; S12. Call the secure chip to sign the uplink ciphertext data using the private key of the asymmetric encryption algorithm of the carrier body; S13. Transmit the uplink ciphertext data and the corresponding signature data to the IoT middleware platform of the cloud platform server; S14. Call the commercial cryptography platform to verify the signature of the uplink ciphertext data and the corresponding signature data using the public key of the carrier body; After the signature verification is successful, call the commercial cryptography platform to decrypt the uplink ciphertext data with the symmetric key to obtain the uplink data.
[0034] Figure 4 This is a schematic diagram of the process of downlink data transmission in this embodiment. Refer to Figure 4 In this embodiment, the process of downlink data transmission is as follows: S21. Use the symmetric encryption algorithm through the IoT middleware platform to encrypt the control data of the cloud platform server to obtain the downlink ciphertext data; S22. Call the commercial cryptography platform to sign the downlink ciphertext data with the private key of the asymmetric encryption algorithm of the IoT middleware platform; S23. Transmit the downlink ciphertext data and the corresponding signature data to the carrier body; S24. Call the security chip to verify the signature of the downlink ciphertext data and the corresponding signature data with the public key of the physical middleware platform; S25. After the signature verification is successful, call the security chip to decrypt the downlink ciphertext data with the symmetric key to obtain the original control data.
[0035] In the processes of uplink data transmission and downlink data transmission in this embodiment, the symmetric encryption algorithm is SM4, and the asymmetric encryption algorithm is SM9.
[0036] In the processes of uplink data transmission and downlink data transmission in this embodiment, before each use of the symmetric key, it is obtained through a series of random number operations generated by a true random number generator. The real symmetric key is temporarily generated in the RAM and is lost when the power is off. In other embodiments, the symmetric key can also be burned into the secure storage medium of the security chip before the active identification carrier leaves the factory.
[0037] In this embodiment, the key generation of the asymmetric encryption algorithm can be generated by the commercial cryptography platform of the cloud platform server and then burned into the secure storage medium before the active identification carrier leaves the factory. Taking the SM9 encryption algorithm as an example, the process is as follows: (1) Identity verification: The IoT middleware platform calls the token acquisition interface of the commercial cryptography platform and submits the instance APPID and instance SECRET as the identity verification request parameters. After verification by the commercial cryptography platform, the identity information key is returned. Among them, the instance APPID and instance SECRET are obtained after the instance is opened on the commercial cryptography platform.
[0038] (2) Identification type addition: The IoT middleware platform calls the SM9 identification type addition interface of the commercial cryptography platform and submits the identification type name, and the commercial cryptography platform returns the identification type id.
[0039] (3) Key generation: The IoT middleware platform calls the SM9 identification key generation interface of the commercial cryptography platform, provides the identification and the identification type id, and the commercial cryptography platform returns the signature public key and the signature private key.
[0040] In this embodiment, an example of the specific process of uplink data transmission is as follows: (1) The sensor data collected by the data acquisition terminal device is uplink data M1. The carrier body calls the national cryptography algorithm module of the security chip through message communication, and encrypts the uplink data using a symmetric encryption algorithm to obtain uplink ciphertext data D1.
[0041] (2) The carrier body uses its own private key of the asymmetric encryption algorithm, calls the national cryptography algorithm module of the security chip through message communication, and signs the uplink ciphertext data D1 to obtain signature data S1; among them, the digest algorithm used for signing is the SM3 national cryptography algorithm.
[0042] (3) The carrier body transmits the uplink ciphertext data and the corresponding signature data D1+S1 to the IoT middleware of the cloud platform server through a wireless communication module such as 4G / WIFI / NBIOT / LoRa.
[0043] (4) The IoT middleware uses the public key of the asymmetric encryption algorithm of the carrier body in the data acquisition terminal device, and calls the commercial cryptography platform to perform a signature verification operation on the uplink ciphertext data and the corresponding signature data D1+S1; among them, the digest algorithm used for signature verification is the SM3 national cryptography algorithm.
[0044] Taking the example of calling the commercial cryptography platform with the SM9 algorithm, the IoT middleware calls the SM9 signature verification interface, provides the identity token, the public key of the asymmetric encryption algorithm of the data acquisition terminal device, the uplink ciphertext data D1, the identifier, and the signature data S1. The commercial cryptography platform performs signature verification. If successful, it returns that the signature verification is successful.
[0045] (5) After the commercial cryptography platform successfully verifies the signature, the IoT middleware uses the symmetric key to decrypt the uplink ciphertext data D1 to obtain the sensor data M1 collected by the uplink data acquisition terminal device. The cloud platform server performs corresponding operations according to the information provided by the uplink data M1.
[0046] In this embodiment, an example of the specific process of downlink data transmission is as follows: (1) The IoT middleware encrypts the application control data M using a symmetric encryption algorithm to obtain downlink ciphertext data D.
[0047] (2) The IoT middleware calls the commercial cryptography platform to sign the downlink ciphertext data D using its own private key of the asymmetric encryption algorithm to obtain signature data S; among them, the digest algorithm used for signing is the SM3 national cryptography algorithm.
[0048] (3) The IoT middleware transmits the downlink ciphertext data and the corresponding signature data D+S to the carrier body on the data acquisition terminal device through a wireless communication module such as 4G / WIFI / NBIOT / LoRa.
[0049] (4) The carrier body on the data acquisition terminal device uses the public key of the asymmetric encryption algorithm of the Internet of Things middleware platform, and calls the national cryptography algorithm module of the security chip through message communication to perform a signature verification operation on the downlink ciphertext data and the corresponding signature data D+S; among them, the digest algorithm used for signature verification is the SM3 national cryptography algorithm.
[0050] (5) After the signature verification is passed, the carrier body on the data acquisition terminal device uses the symmetric key and calls the national cryptography algorithm module of the security chip through message communication to decrypt the downlink ciphertext data D to obtain the original application control data M; the data acquisition device terminal performs corresponding operations according to the information provided by the application control data M.
[0051] The embodiment of the present application also proposes a terminal, including a memory, a processor, a communication unit, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of a method for secure transmission of terminal data based on an active identification carrier; the memory, the processor, and the communication unit communicate through one or more buses.
[0052] The processor may include one or more processing units. For example: the processor may include a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processor (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.
[0053] Among them, the processor may be the nerve center and command center of the terminal. The controller may generate operation control signals according to the instruction operation code and timing signals to complete the control of fetching instructions and executing instructions.
[0054] The memory is used to store the execution instructions of the processor. The memory can be implemented by any type of volatile or non-volatile storage terminal or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. When the execution instructions in the memory are executed by the processor, the terminal can execute some or all of the steps in the above-mentioned embodiments of the terminal data trusted transmission method based on the active identification carrier.
[0055] The wireless communication function of the electronic device can be implemented by an antenna, a wireless communication module, a modulation and demodulation processor, a baseband processor, etc.
[0056] The wireless communication module can provide wireless communication solutions applied to the electronic device, including wireless local area network, Bluetooth, global navigation satellite system, frequency modulation, near field communication technology, infrared technology, etc.
[0057] This embodiment also proposes a storage medium, on which a computer program is stored. When the computer program is executed by the processor, it realizes the steps of any one of the above-mentioned terminal data trusted transmission methods based on the active identification carrier.
[0058] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A terminal data trusted transmission system based on active identification carrier, characterized in that: It includes an active identification carrier and a cloud platform server, wherein the active identification carrier is located in a data acquisition terminal device, the active identification carrier includes a carrier body and a security chip, and the cloud platform server includes an IoT middle station and a commercial secret platform, wherein: The carrier body interacts with the security chip through a communication interaction interface to achieve data transmission. The security chip supports secure storage of a unique industrial Internet identifier and a device key. Once the industrial Internet identifier and the device key are written, they cannot be modified. The security chip can encrypt, sign, verify and decrypt data under the communication call of the carrier body. The carrier body is wirelessly connected to the IoT middle station to realize data transmission, and the IoT middle station interacts with the commercial secret platform through a communication interaction interface to realize data transmission. The commercial secret platform can encrypt, sign, verify and decrypt data under the communication call of the IoT middle station.
2. According to claim 1, a terminal data trusted transmission system based on active identification carrier is characterized in that: The carrier body includes a key management platform module, a key generation module, an encryption / decryption module, an identity authentication module, a communication interaction interface, an identification management module, a storage medium module and a data remote transmission module; Among them, the key management platform module, key generation module, encryption / decryption module and identity authentication module are virtual hardware security module trusted applications built on a trusted execution environment; The identity authentication module performs trusted identity authentication with the cloud platform server based on the authentication information; The communication interaction interface is a communication interface for the carrier body to maintain protocol communication with the outside to achieve message communication with the outside; The identification management module and the storage medium module maintain the active identification code, support the identification code presetting and OTA upgrade of the carrier body, and support the identification writing, reading, modification and deletion with the cloud platform server; The data remote transmission module maintains the communication protocol and performs wireless communication with the cloud platform server through the wireless communication module.
3. According to claim 1, a terminal data trusted transmission system based on active identification carrier is characterized in that: The security chip includes a security engine module, a security storage medium module, a communication interaction port module and a national secret algorithm module; Wherein, the security engine module provides encryption services to the carrier body; The secure storage medium module stores the industrial Internet identifier and the device key, and the cloud platform server and the carrier body store their respective asymmetric algorithm encrypted private keys and each other's public keys in the secure storage medium module; The communication interaction module performs protocol communication with the carrier body; The national secret algorithm module supports the national secret standard SM2, SM3, SM4 and SM9 algorithms.
4. A terminal data trusted transmission method based on active identification carrier, characterized in that: include: An active identification carrier with trusted computing capability is used to construct a data acquisition terminal device at the edge side, wherein the active identification carrier includes a carrier body and a security chip running in a trusted execution environment; The carrier body interacts with the security chip through a communication interaction interface, and the security chip can encrypt, sign, verify and decrypt data under the communication call of the carrier body; the security chip supports the secure storage of the unique industrial Internet identifier and device key, and the industrial Internet identifier and device key cannot be modified once written; The carrier body and the IoT middle station of the cloud platform server are connected wirelessly to realize data transmission. The commercial encryption platform in the cloud platform server can encrypt, sign, verify and decrypt data under the communication call of the IoT middle station.
5. The method for trusted transmission of terminal data based on active identification carrier according to claim 4 is characterized in that: During uplink data transmission, the security chip is called to use a symmetric encryption algorithm to encrypt the uplink data to obtain uplink ciphertext data, the security chip is called to use the asymmetric encryption algorithm private key of the carrier body to sign the uplink ciphertext data, the uplink ciphertext data and the corresponding signature data are transmitted to the IoT middle station of the cloud platform server, the commercial secret platform is called to use the public key of the carrier body to verify the uplink ciphertext data and the corresponding signature data, and after the verification is successful, the commercial secret platform is called to use the symmetric key to decrypt the uplink ciphertext data to obtain the uplink data.
6. The method for trusted transmission of terminal data based on active identification carrier according to claim 4, characterized in that: During downlink data transmission, the control data of the cloud platform server is encrypted by a symmetric encryption algorithm through the IoT middle station to obtain downlink ciphertext data, and the commercial key platform is called to sign the downlink ciphertext data using the asymmetric encryption algorithm private key of the IoT middle station. The downlink ciphertext data and the corresponding signature data are transmitted to the carrier body, and the security chip is called to use the public key of the physical middle station to verify the downlink ciphertext data and the corresponding signature data. After the verification is successful, the security chip is called to use the symmetric key to decrypt the downlink ciphertext data to obtain the original control data.
7. A terminal data trusted transmission method based on active identification carrier according to claim 5 or 6, characterized in that: The symmetric encryption algorithm is SM4, and the asymmetric encryption algorithm is SM9.
8. A terminal data trusted transmission method based on active identification carrier according to claim 5 or 6, characterized in that: Before each use, the symmetric key is obtained through a series of random number operations generated by a true random number generator. The real symmetric key is temporarily generated in RAM and will be lost when power is off.
9. A terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of a terminal data trusted transmission method based on an active identification carrier as described in any one of claims 4 to 8 are implemented.
10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of a terminal data trusted transmission method based on an active identification carrier as described in any one of claims 4 to 8 are implemented.
Citation Information
Cited By
Trusted data acquisition method, equipment and medium
CN120567533A