Intelligent device system-oriented whole-process encryption supervision system and method with forced takeover function
By constructing an end-to-end "monitoring-authentication-takeover" closed-loop management system and adopting secure encryption chips and regulatory communication modules, the system solves problems such as fragmented lines, interrupted identity authentication, and weak communication links in intelligent device monitoring systems. This enables real-time monitoring and precise takeover across the entire domain, improving the system's security and real-time performance.
Patent Information
- Application Number
- CN202511587863.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-03
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2045-11-03
AI Technical Summary
Existing intelligent device monitoring systems suffer from problems such as fragmented lines, complex approval processes, lack of real-time command, interrupted identity authentication, weak communication link security, and crude monitoring methods. They lack the ability to accurately identify and take over across scenarios, and especially lack the means to force takeover in abnormal situations.
Construct an end-to-end "monitoring-authentication-takeover" closed-loop management and control system, adopt secure encryption chips and regulatory communication modules to achieve intelligent management and control across the entire domain and encryption protection throughout the entire process. Through hardware-level identity authentication, two-way authentication and session key negotiation, combined with the cloud control platform, it performs situational awareness and hierarchical handling, establishes an independent encrypted communication link, and supports forced takeover function.
It enables real-time monitoring and precise takeover across the entire domain, improves communication security and the real-time performance and coverage of the monitoring system, reduces hardware modification costs, enhances the ability to resist malicious imitation and data tampering, and ensures the accuracy and timeliness of real-time transmission and processing of critical instructions.
Smart Images

Figure CN121056244B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent device monitoring technology, specifically to a comprehensive encrypted monitoring system that combines hardware security chips, communication protocols, and dynamic security maps to achieve forced takeover, end-to-end encryption, real-time monitoring, and two-way authentication of intelligent devices. More specifically, it relates to a full-process encrypted monitoring system and method for intelligent device systems with forced takeover functionality. Background Technology
[0002] Smart device technology has developed rapidly in recent years and has been widely used in the market. However, with the surge in the number of smart devices, the existing regulatory system has exposed many problems: First, comprehensive management faces systemic challenges such as fragmented lines, complex approval processes, and a lack of real-time command, making it difficult to meet the needs of large-scale operations. Second, traditional broadcast or network-based identification mechanisms based on plaintext Remote-ID have obvious defects, and identity reporting is prone to interruption or information distortion when applied across operators and scenarios. Third, the existing smart device communication links have weak security protection, and the transmission of operating commands and images often uses weak encryption or plaintext, making them extremely vulnerable to security threats such as eavesdropping, tampering, replay attacks, and firmware tampering. Finally, regulatory measures are too crude, generally employing large-scale electronic interference or physical interception, which not only affects legitimate driving activities but also lacks the ability to accurately identify and take over illegal smart devices.
[0003] In particular, given the lack of effective mandatory takeover measures during driving activities under abnormal circumstances, and the lack of different supervision for different scenarios, we propose a full-process encrypted supervision system and method for intelligent device systems with mandatory takeover function to solve the above problems. Summary of the Invention
[0004] (a) Technical problems to be solved
[0005] To address the shortcomings of existing technologies, this invention provides a full-process encrypted monitoring system and method for intelligent device systems with forced takeover functionality. It constructs an end-to-end "monitoring-authentication-takeover" closed-loop control system, achieving full-domain intelligent control, full-process encrypted protection, real-time verifiable identity, and hardware-level precise takeover, thus solving the problems mentioned in the background technology.
[0006] (II) Technical Solution
[0007] To achieve the above objectives, the present invention specifically adopts the following technical solution:
[0008] A full-process encrypted monitoring system for intelligent device systems with forced takeover capability includes: a device end, a ground-based multi-functional station, a cloud control platform, and an end-to-end encrypted communication link established between the three. The device end integrates a security encryption chip and a monitoring communication module, supporting both strong and weak monitoring modes. In strong monitoring mode, the security encryption chip is embedded in the core data link for intelligent device driving control and task processing. The cloud control platform monitors and judges all data from the fully encrypted sensor systems, control units, and task processing units, thereby issuing commands to the control units in real time when necessary to complete control of the intelligent device and achieve takeover. In weak monitoring mode, the security encryption chip is externally connected to the original intelligent device system through an interface. The cloud control platform monitors and judges the data from the fully encrypted control units and task processing units, thereby issuing commands to the control units in real time when necessary to achieve takeover. In strong monitoring mode, the cloud control platform has priority access to the sensor information of the intelligent device, but does not have this capability in weak monitoring mode. Therefore, in strong monitoring mode, the cloud control platform can control the intelligent device before the local device.
[0009] The secure encryption chip has a built-in, tamper-proof, unique device identification code (one code per device) to achieve hardware-level identity authentication, which is used to perform hardware-level identity authentication when the communication link is established. The encrypted communication link is independent of the original communication system of the smart device and supports two-way identity authentication and session key negotiation between the device and the site, and between the site and the cloud platform. The cloud control platform includes a key management center, a decryption and visualization monitoring module, a situation analysis and alarm module, and a policy issuance and forced takeover module, which realizes full-domain situational awareness, abnormal behavior identification, and hierarchical handling command issuance for all smart devices. The ground-end multi-functional station can be deployed on a communication tower or a GNSS global navigation satellite system and has the ability to establish encrypted communication through the GNSS global navigation satellite system cloud platform. It has multi-source sensing units and edge security chips for full-domain data acquisition, encrypted data decryption / verification, and localized command execution.
[0010] Furthermore, the device includes: a control unit, a task processing unit, a security encryption chip, a monitoring communication chip, a positioning and sensing module, and a power management module; the ground-based multi-functional station includes: a station security chip with two-way authentication capabilities, an edge computing unit, a multi-source detection unit, a local processing unit, and a communication unit; the encrypted communication link is used to establish an end-to-end encrypted session between the device, the ground-based multi-functional station, and the cloud control platform to transmit driving data, authentication information, global management information, and forced takeover commands.
[0011] Furthermore, the security encryption chip adopts a hybrid encryption architecture: symmetric encryption algorithms are used for telemetry data and control commands; asymmetric encryption algorithms are used for key negotiation and authentication; the chip integrates a physically unclonable function (PUF) and a one-time programmable storage unit for generating a root key and deriving a session key; the chip has a built-in true random number generator and generates an independent initialization vector for each encryption operation.
[0012] Furthermore, the encrypted communication link is divided into three dedicated channels: a global management link for transmitting security map data, meteorological information, and global restriction commands; a situational awareness link for transmitting the location, driving trajectory, attitude, and identity authentication data of intelligent devices; and a forced takeover link for transmitting commands to return, drive, stop, or intervene in the driving direction. Through a service quality assurance mechanism, resources are reserved and dynamically prioritized for critical communication needs.
[0013] Furthermore, the key management center of the cloud control platform performs two-way authentication and dynamic negotiation of session keys with the device's security encryption chip; supports key lifecycle management, emergency key revocation and batch expiration mechanisms; all key operations are completed in a high-security isolation zone and are prevented from being tampered with by a hardware security module.
[0014] Furthermore, the forced takeover module executes a tiered handling process: Warning level: Triggers audio-visual alarms within the safety map and platform notifications: For minor or short-term deviations from the driving route, only visual, SMS / email notifications and audio / visual signal alerts within the safety map are triggered; Restriction level: Issues speed limit, stop, or return-to-preset route commands: For medium-risk behaviors (such as entering the entire controlled area or prolonged stay), the platform issues "speed limit," "forced stop," or "return to preset driving route" commands; Takeover level: Issues hardware-level forced stop or return commands, executed by the security encryption chip switching the device control interface shortly after signature verification: For high-risk or malicious illegal devices (such as forged identity codes or disabled Remote-ID), the platform issues "hardware-level forced stop" or "forced return" commands, and can also issue "forced hover" commands to drones, automatically recording the entire process.
[0015] Furthermore, the cloud control platform integrates a dynamic security map engine: dynamically generating security map boundaries based on global control rules, meteorological data, and illegal device warnings; periodically sending fence coordinates to the device's security chip via an encrypted link; and the security chip comparing the positioning data in real time to trigger boundary crossing warnings or take appropriate action.
[0016] Furthermore, the ground-based multi-functional station integrates multi-source sensing data: it collects global information through radar detection, multispectral cameras, and meteorological sensors; it uses multi-site collaborative ranging and angle of arrival (AoA) technology to achieve precise positioning of intelligent devices; and it performs spatiotemporal data fusion in the edge computing unit to construct a local global situation map.
[0017] A full-process encrypted monitoring system for smart device systems with forced takeover capabilities includes the following steps:
[0018] S1. Before the intelligent equipment is put into operation, two-way authentication is performed between the device-side security encryption chip and the site security chip based on the device identity code and asymmetric encryption algorithm; a session key is negotiated and generated and updated regularly.
[0019] S2. During operation, data is transmitted in encrypted form. The device encrypts telemetry, location, and identity data using a security chip and uploads it to the site via an independent link. The site decrypts the data, verifies its integrity, and then forwards it to the cloud control platform.
[0020] S3: Global situational analysis and response. The cloud control platform integrates multi-source data to identify abnormal behavior and generates encrypted response instructions according to hierarchical strategies. The instructions are broadcast to the target smart device via the site and executed as hardware-level takeover operations after being verified by the security chip.
[0021] S4: Forced takeover in abnormal situations. In strong monitoring mode, the cloud control platform directly takes over in response to abnormal situations exhibited by the sensor system. In weak monitoring mode, external monitoring equipment monitors abnormal behavior and implements forced takeover upon detection.
[0022] Furthermore, the execution of the forced takeover command includes: verifying the digital signature and identity code matching of the command via the security chip; injecting the command into the control unit through the dedicated device control terminal interface after decryption; and feeding back the status to the cloud control platform through an encrypted link after execution, and recording the entire process audit log.
[0023] (III) Beneficial Effects
[0024] Compared with existing technologies, this invention provides a full-process encrypted monitoring system and method for intelligent device systems with forced takeover functionality, which has the following beneficial effects:
[0025] In the robust monitoring mode of this invention, the security monitoring chip is directly embedded in the core data link of the intelligent equipment, communicating directly with multiple sub-modules of the system. It performs real-time monitoring of data transmitted by the control unit, sensor system, communication module, and task processing unit, enabling real-time acquisition and encryption of all data. The significant hardware modification cost is compensated by higher security and handling accuracy. With the security monitoring chip and communication monitoring chip located in the core data channel, any attempt to bypass or falsify sensor data is monitored in real time, significantly enhancing the monitoring system's ability to combat malicious imitation and data tampering.
[0026] In this invention, under the weak supervision mode, a security encryption and communication module is added through a standardized interface. This allows for modification without structural alterations to the existing intelligent device control system, significantly reducing hardware modification costs. Furthermore, this invention employs a secure channel independent of the original wireless signal link, achieving isolated transmission of control, telemetry, and image transmission data over an end-to-end encrypted link, significantly improving communication security.
[0027] This invention introduces a "one device, one code" hardware identity authentication mechanism, assigning each smart device a unique and tamper-proof device identity code, enhancing identity credibility and preventing impersonation; this invention utilizes a nationwide network of sites to synchronously extract and report device identity codes and location information, enabling second-level full-domain tracking and anomaly alerts for smart devices, improving the real-time nature and coverage of supervision.
[0028] This invention integrates digital signature verification and hardware-level takeover logic into a security chip, supporting the issuance and execution of forced takeover commands within 2 seconds, thus enhancing the ability to deal with unauthorized devices in real time. This invention also achieves integrated monitoring of the overall operational status by fusing driving data and site location information of multiple intelligent devices through a cloud control platform.
[0029] This invention constructs a unified cloud control platform that integrates key management, decryption visualization, situational analysis, and policy distribution functions, enabling intelligent, visualized, and centralized control of the entire domain. Attached Figure Description
[0030] Figure 1 This is a schematic diagram of the device-side weak monitoring mode of the present invention;
[0031] Figure 2 This is a schematic diagram of the device-side strong supervision mode of the present invention;
[0032] Figure 3 This is a data flow diagram for the security supervision of the present invention;
[0033] Figure 4 This is a flowchart of the ground / cloud monitoring and handling process of the present invention;
[0034] Figure 5This is a schematic diagram of the process method of the present invention. Detailed Implementation
[0035] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0036] Example
[0037] refer to Figure 1-5 As shown, this application proposes a full-process encrypted monitoring system for intelligent device systems, including a device end, a ground-based multi-functional station, a cloud control platform, and an end-to-end encrypted communication link established between the three. The communication link includes 5G, 6G, Wi-Fi, LoRa, or GNSS global navigation satellite systems. The station includes a 5G base station, a Wi-Fi router, and a ground station for the GNSS global navigation satellite system. The device end is an intelligent equipment system, including but not limited to: aircraft, drones, spacecraft, automobiles, eVTOL, airships, instruments, and robots. The device end integrates a security encryption chip and a monitoring communication module, supporting both strong and weak monitoring modes: In strong monitoring mode, the security encryption chip is embedded in the intelligent device's driving control... The core data link for control and task processing involves a cloud-based control platform that monitors and evaluates data from all encrypted sensor systems, control units, and task processing units throughout the entire process. This allows the platform to issue commands to the control units in real time when necessary, enabling control of the intelligent device and takeover. In the weak monitoring mode, the security encryption chip is externally connected to the original system of the intelligent device via an interface. The cloud-based control platform monitors and evaluates data from the fully encrypted control units and task processing units, enabling control of the control units in real time when necessary and takeover. In the strong monitoring mode, the cloud-based control platform has priority in acquiring sensor information from the intelligent device, but this capability is not available in the weak monitoring mode. Therefore, in the strong monitoring mode, the cloud-based control platform takes precedence over the local machine in controlling the intelligent device.
[0038] In a robust monitoring model, the cloud-based control platform prioritizes acquiring sensor information from intelligent devices, thus allowing it to make judgments and controls before the devices themselves. In this invention, under this robust monitoring model, the safety monitoring chip is directly embedded in the core data link of the intelligent equipment, communicating directly with multiple sub-modules of the system. It monitors the data transmitted by the control unit, sensor system, communication module, and task processing unit in real time, enabling real-time acquisition and encryption of all data. The significant hardware modification cost results in higher security and handling accuracy. The safety monitoring chip and communication monitoring chip are located in the core data channel; any attempt to bypass or falsify sensor data is monitored in real time, significantly improving the monitoring system's ability to combat malicious imitation and data tampering. For example, if flight attitude is acquired via IMU or position / flight path via satellite navigation, and the cloud-based control platform detects an abnormal flight attitude, it takes over the control before the controller / the main body, enabling forced hovering or forced landing.
[0039] In the weak monitoring mode, the cloud control platform does not directly obtain sensor information from smart devices, but controls the smart devices only through the control unit and task processing unit. In this invention, the weak monitoring mode uses a standardized interface with added security encryption and communication modules, eliminating the need for structural modifications to the existing smart device control system and significantly reducing hardware modification costs. This invention employs a secure channel independent of the original wireless signal link, achieving isolated transmission of control, telemetry, and image transmission data over an end-to-end encrypted link, significantly improving communication security. For example, when sensor data cannot be directly obtained, and communication is only possible with the control unit and task processing unit, or information can only be obtained through external monitoring equipment, the entity may bypass regulatory control. The weak monitoring mode is used when rapid judgment cannot be made using a security map.
[0040] The security encryption chip has a built-in, tamper-proof, unique device identity code for hardware-level authentication when the communication link is established. The encrypted communication link is independent of the smart device's original communication system and supports two-way authentication and session key negotiation between the device and the site, and between the site and the cloud platform. This invention introduces a "one device, one code" hardware identity authentication mechanism, assigning each smart device an tamper-proof, unique device identity code, enhancing identity credibility and preventing impersonation. This invention utilizes a nationwide site network to synchronously extract and report device identity codes and location information, achieving second-level full-domain tracking and anomaly alerts for smart devices, improving the real-time nature and coverage of supervision.
[0041] The cloud control platform includes a key management center, a decryption and visualization monitoring module, a situation analysis and alarm module, and a policy issuance and forced takeover module, enabling full-domain situational awareness, abnormal behavior identification, and hierarchical handling command issuance for all intelligent devices. The ground-based multi-functional station is deployed on communication towers and GNSS global navigation satellite systems, and is equipped with multi-source sensing units and edge security chips for full-domain data acquisition, encrypted data decryption / verification, and localized command execution.
[0042] Among them, the security encryption chip refers to a dedicated hardware module with cryptographic computing capabilities, specifically implemented using a cryptographic chip integrating physically unclonable functions, used to generate a unique device identifier and encryption key. The end-to-end encrypted communication link refers to a dedicated data transmission path independent of the smart device's original communication channel, used to ensure the integrity and confidentiality of monitoring data. Strong monitoring mode refers to the security chip being directly embedded in the operating status of the control system's data bus, specifically implemented using a high-speed hardware interface connection, used for real-time encrypted processing of driving commands. Weak monitoring mode refers to the communication module connecting to the smart device through an external interface, specifically implemented using standard interfaces such as USB or RS485 interfaces, for compatibility with different smart device models. The key management center refers to the key generation and management system on the cloud platform.
[0043] Specifically, in a strongly monitored mode, the device's security encryption chip directly connects to the core data bus of the control system, encrypting driving control commands in real time. When the intelligent device enters the monitored area, it establishes a secure connection with the ground station via an independent encrypted link, completing two-way authentication. The ground station uploads the decrypted driving data to the cloud platform, generating a comprehensive situational awareness map through the fusion of multi-source sensing data. When abnormal driving behavior is detected, the cloud platform generates encrypted handling commands, which are broadcast to the target intelligent device via the station network. After verifying the legitimacy of the commands, the security chip injects control commands into the control system through a dedicated interface, enabling precise takeover operations.
[0044] Compared to existing technologies, traditional solutions rely on software encryption and a single communication channel, which pose risks of identity forgery and command tampering. This solution ensures end-to-end security of regulatory data through dual protection of hardware-level encryption chips and independent communication links. The problem of existing systems being unable to achieve continuous monitoring across scenarios is effectively solved by building a site network and a cloud-based collaborative mechanism. Compared to the crude approach of dealing with regional signal interference, this solution can implement precise control over specific targets, avoiding impact on the operation of legitimate smart devices.
[0045] Through the above technical solutions, this application effectively addresses the regulatory vulnerabilities caused by identity authentication interruptions, preventing control commands from being stolen or tampered with during transmission. Hardware-level encryption mechanisms ensure the unforgeability of critical data, and independent communication links avoid secure coupling with existing systems. The multi-mode design caters to the regulatory needs of different scenarios, and the site network deployment enables continuous data collection across the entire domain. The precise takeover mechanism, through encrypted command verification and dedicated interface control, ensures the accuracy and timeliness of emergency response.
[0046] This application further proposes that the device side includes a control unit, a task processing unit, a security encryption chip, a monitoring communication chip, a positioning and sensing module, and a power management module; the ground-side multi-functional station includes a station security chip with two-way authentication capabilities, an edge computing unit, a multi-source detection unit, a local processing unit, and a communication unit; the encrypted communication link is used to establish an end-to-end encrypted session between the device side, the ground-side multi-functional station, and the cloud control platform to transmit driving data, authentication information, global management information, and forced takeover commands.
[0047] The system comprises the following components: A control unit, a hardware module that processes driving control commands for the intelligent device (usually an embedded microcontroller), receives and executes encrypted commands from a security encryption chip. A task processing unit, a computing module that processes task data from the intelligent device (usually a multi-core processor), performs real-time processing of image and sensor data. A security encryption chip, an independent chip providing hardware-level encryption (usually a security module integrating physically unclonable functions and a true random number generator), encrypts driving control commands and communication data. A monitoring communication chip, a dedicated communication module independent of the intelligent device's existing communication system (usually a wireless chip supporting multi-band communication), establishes an encrypted link with ground stations. A site security chip, a security authentication module deployed at ground stations (usually a hardware security unit supporting asymmetric encryption algorithms), performs two-way authentication and session key negotiation. An edge computing unit, a local data processing module deployed at the site (usually a computing card with AI inference capabilities), performs real-time analysis of decrypted data. A multi-source detection unit refers to a data acquisition module that integrates multiple sensors. Specifically, it can be implemented by combining radar, cameras, and meteorological sensors to acquire environmental information across the entire region.
[0048] Specifically, the device-side core control layer is formed by the control unit and the task processing unit, while the security encryption chip and the regulatory communication chip constitute an independent security communication layer. Hardware isolation ensures that control commands and regulatory data are physically separated. After encrypting the driving control commands, the security encryption chip transmits them to the ground station via an independent link through the regulatory communication chip. The ground station's security chip decrypts and authenticates the received data, the edge computing unit performs localized analysis on the decrypted driving data, and the multi-source detection unit collects real-time environmental data and aligns it spatiotemporally with the driving data. The encrypted communication link transmits driving data, authentication information, overall management information, and forced takeover commands separately. Authentication information is protected end-to-end using an asymmetric encryption algorithm, while forced takeover commands are transmitted through an independent channel and allocated the highest priority bandwidth.
[0049] Specifically, intelligent equipment systems include, but are not limited to, intelligent devices such as aircraft, drones, spacecraft, automobiles, eVTOL, airships, instruments, and robots. The corresponding control units are as follows:
[0050] Aviation equipment: flight control unit, motor controller, attitude and trajectory control module;
[0051] Aerospace equipment: attitude control system, propulsion / servo control unit, environmental control and life support system;
[0052] Vehicle-related equipment: ECU, powertrain control module, braking and steering control module;
[0053] Robot equipment: main control board, actuator drive controller, task scheduling controller;
[0054] Industrial / Instrumentation Intelligent Equipment: Process control unit, motion control card, control and scheduling module.
[0055] Compared to existing technologies, traditional intelligent device monitoring systems use a single communication module to transmit mixed data, leading to competition for communication resources between identity authentication and driving control commands, resulting in priority conflicts and data tampering risks. Existing solutions lack localized data processing capabilities at ground stations, relying on centralized verification in the cloud, causing command response delays. This solution achieves physical separation between the secure communication layer and the core control layer through hardware isolation, preventing malicious intrusion into the control system; the edge computing unit and multi-source detection unit at the ground station work collaboratively, enabling local data verification and environmental perception, reducing reliance on the cloud; the encrypted communication link employs a classified transmission mechanism, ensuring the real-time performance and integrity of critical commands through independent channels.
[0056] Through the above technical solutions, this application addresses the problem of insufficient component coordination in intelligent device monitoring systems. The hardware modules on the device and ground ends have clearly defined roles, and the secure communication layer operates independently to avoid interference from existing systems. Identity authentication and data transmission security are enhanced through end-to-end encryption and two-way authentication mechanisms. Categorized transmission of driving data and comprehensive management information reduces the risk of link congestion. Localized data processing capabilities enable stations to respond quickly to abnormal events, performing initial handling actions without waiting for cloud instructions, thus improving system real-time performance. The independent transmission channel design for forced takeover commands ensures that commands arrive and are executed first in emergencies, avoiding the problem of commands being blocked by other data traffic in traditional systems.
[0057] This application further proposes a security encryption chip that adopts a hybrid encryption architecture, using a symmetric encryption algorithm for telemetry data and control commands, and an asymmetric encryption algorithm for key negotiation and authentication. The chip integrates physically unclonable functions and a one-time programmable storage unit to generate the root key and derive the session key. The chip has a built-in true random number generator and generates an independent initialization vector for each encryption operation.
[0058] Hybrid encryption architecture refers to a composite encryption system that combines symmetric and asymmetric encryption, matching the security requirements of different data types through algorithmic characteristics. Physically unclonable functions refer to circuit structures that generate unique physical characteristics using differences in semiconductor manufacturing processes. One-time programmable memory refers to storage media that allows only a single write operation. A true random number generator is a random number generation device based on a physical entropy source, specifically implemented using quantum noise or thermal noise acquisition circuits, to ensure the unpredictability of encryption parameters. An independent initialization vector refers to generating a unique random number seed for each encryption operation, specifically implemented using a combination of a counter mode and random numbers, to eliminate security vulnerabilities caused by the repetition of encryption modes.
[0059] Specifically, in the communication link of smart devices, high-frequency telemetry data and control commands are encrypted in real time using symmetric encryption algorithms, such as AES-CTR mode for low-latency encryption. During the key negotiation phase, asymmetric algorithms are used to establish a secure channel, such as the ECDH protocol to negotiate the session key. A physically unclonable function extracts inherent silicon characteristics to generate a root key when the chip is activated; this key is then stored in an OTP memory and serves as the trusted anchor point for the key derivation tree. Before each encryption operation, a true random number generator generates an independent initialization vector.
[0060] Compared to existing technologies, traditional solutions often employ a single encryption algorithm, resulting in long key update cycles and predictable initialization vectors, which pose a risk of replay attacks. Existing key storage methods mostly rely on erasable and rewritable memory, making them vulnerable to physical attacks that could extract the keys.
[0061] Through the above technical solutions, this application addresses the risk of duplicate ciphertext caused by the predictability of encryption operations and eliminates pattern recognition vulnerabilities introduced by static initialization vectors. It prevents systemic security risks arising from root key leakage during key derivation and effectively resists side-channel attacks and physical probing. Furthermore, it reduces the overall power consumption of the encryption system through layered algorithm application.
[0062] This application further proposes dividing the encrypted communication link into three types of dedicated channels: a global management link for transmitting secure map data, meteorological information, and global restriction commands; a situational awareness link for transmitting the location, trajectory, attitude, and authentication data of intelligent devices; and a forced takeover link for transmitting commands for returning, driving, stopping, or intervention in driving direction, including drone hovering commands. Through a quality of service assurance mechanism, resources are reserved and dynamically prioritized for critical communication needs.
[0063] Specifically, the overall management link independently carries security map coordinate updates and weather warning data, employing a periodic broadcast mechanism to ensure information synchronization across the entire domain. The situational awareness link continuously transmits the location coordinates and driving parameters of intelligent devices, ensuring the integrity of status updates through data packet fragmentation and verification mechanisms. The forced takeover link uses a dedicated encryption protocol to transmit emergency control commands, prioritizing communication resources to issue commands when abnormal behavior is detected. These three types of links achieve service separation through a combination of physical and logical isolation. The bandwidth resources of the forced takeover link are pre-reserved, allowing it to immediately activate its maximum transmission capacity when the system detects a need for emergency takeover.
[0064] Compared to existing technologies, traditional intelligent device monitoring systems use a single communication channel to transmit various types of data, which is prone to delays in critical commands due to surges in data traffic. Existing technologies typically employ simple priority queue management, failing to achieve true channel isolation and resource reservation. This solution fundamentally solves the problem of transmission conflicts between different types of business data by establishing three types of dedicated communication channels and implementing a resource reservation strategy. In particular, it establishes an independent transmission channel for the highest priority mandatory takeover commands, ensuring the real-time transmission capability of critical commands can still be maintained during peak system load periods.
[0065] Through the above technical solution, this application effectively solves the communication congestion problem caused by the mixed transmission of different business data streams in the intelligent device monitoring system, and significantly reduces the transmission delay of critical instructions. By establishing a dedicated forced takeover link and implementing the highest priority bandwidth allocation, the physical isolation design of the three types of links ensures that in the event of illegal equipment or unauthorized operation, and also enhances system security, preventing attackers from penetrating the critical control system through conventional data channels.
[0066] This application further proposes a cloud-based control platform key management center that performs two-way authentication and dynamic negotiation of session keys with the device-side security encryption chip, supports key lifecycle management, emergency key revocation and batch expiration mechanisms, and all key operations are completed in a high-security isolation zone and prevented from being tampered with by a hardware security module.
[0067] Two-way authentication refers to mutual verification between communicating parties based on hardware-level trusted identities. This can be achieved using asymmetric encryption algorithms combined with unique device identifiers to prevent forged terminals from accessing the system. Dynamic session key negotiation involves generating an independent encryption key each time communication is established. This can be implemented using elliptic curve key exchange protocols to avoid the risk of key reuse and leakage. Key lifecycle management refers to the full-process control of key generation, distribution, updating, and destruction. This can be implemented using an automated policy engine to ensure key timeliness and reduce the possibility of expired keys being exploited. Emergency key revocation and batch expiration mechanisms are rapid response measures for security incidents. These can be implemented using blacklist synchronization and key index database marking to block unauthorized access when devices are stolen or keys are leaked. A high-security isolation zone is a protected area independent of the ordinary computing environment. This can be implemented using trusted execution environments or physical isolation chips to isolate key operations from potential malicious programs. Hardware security modules are dedicated cryptographic devices with tamper-proof capabilities to protect key storage and computation processes from physical or software attacks.
[0068] Specifically, during the communication initialization phase, the key management center exchanges digital certificates with the onboard chip to complete two-way authentication. After confirming the device's legitimacy, it generates a session key based on random numbers. Once generated, the key is distributed to both communicating parties via an encrypted channel and automatically updated at preset intervals or upon triggering events. When a device anomaly is detected or an emergency command is received, the system batch-marks invalid keys and synchronizes this information to all sites, blocking unauthorized terminal communication. All key operations are performed within an independent, secure isolation zone. Key storage and encryption / decryption operations are handled by a hardware security module to prevent operating system vulnerabilities or malware from stealing key data.
[0069] Compared to existing technologies, traditional key management systems rely on statically stored, long-term valid keys, which are vulnerable to brute-force attacks or prolonged use after leakage. Furthermore, key revocation requires manual intervention, leading to response delays. This solution employs a dynamic key negotiation mechanism to ensure each session uses an independent key. Combined with hardware-level protection measures, it achieves secure control over the entire key generation and storage process. Simultaneously, it establishes an automated emergency response mechanism to enhance the system's real-time resistance to attacks.
[0070] Through the above technical solutions, this application solves the problem that static cloud key storage is easily cracked, and reduces the impact of key leakage through dynamic negotiation and independent session key generation mechanisms; it solves the problem of low key revocation efficiency in emergency scenarios, and achieves minute-level key access permission cutoff through blacklist synchronization and batch invalidation mechanisms; it solves the problem that the key operation process is easily tampered with by external means, and blocks software-level attack and penetration paths through hardware security modules and isolation environments.
[0071] This application further proposes a tiered handling process for the forced takeover module, including three handling levels: warning level, restriction level, and takeover level. The warning level triggers audible and visual alarms within the safety map and platform notifications; the restriction level issues speed limit or return commands; and the takeover level executes hardware-level forced stop or return operations through a secure encryption chip, which also includes forced hovering operations on the drone.
[0072] For example, early warning-level audible and visual alarms refer to the use of a combination of LED warning lights and buzzers integrated into intelligent devices to emit visual and auditory alarm signals. This can be achieved using a multi-color strobe LED array combined with a directional sound wave transmitter, creating a non-intrusive warning effect within the safety map area. Restriction-level command issuance refers to the transmission of driving parameter constraint commands via encrypted communication links. For example, this can be achieved by encapsulating JSON format control command packets using the AES-256 encryption algorithm, used for dynamic correction of the driving trajectory. Takeover-level hardware switching refers to a secure encrypted chip directly controlling the control system's execution port. This can be achieved using an embedded trusted execution environment isolated control bus interface, used to ensure a reliable transfer of driving control in high-risk situations.
[0073] Specifically, when a smart device deviates from the preset driving route but remains within the safe map, the warning-level mechanism triggers the onboard audio-visual device by broadcasting an encrypted alarm signal at the station, while simultaneously sending an event log to the monitoring platform. If the smart device continuously exceeds a set threshold within the controlled area, the restriction-level mechanism generates an encrypted control command packet, which, after digital signature verification, is sent to the target smart device via a dedicated channel. The security chip decrypts the packet and modifies the control parameters to achieve speed limits or route correction. When identity forgery or malicious evasion of supervision is detected, the takeover-level mechanism initiates a hardware-level verification process. After completing the command signature verification, the security chip directly takes over the device's control interface, cuts off the original control link, and executes a forced return procedure.
[0074] In another specific embodiment, this system is applied to the monitoring of low-altitude flight of unmanned aerial vehicles (UAVs). The UAV equipment includes a flight control unit (as a control unit), a task processing unit, a security encryption chip, and a monitoring communication module. Flight attitude parameters are acquired in real time by an inertial measurement unit (IMU), and position and flight path information are provided by a GNSS global navigation satellite system. After being processed by the security encryption chip, the data is uploaded to a ground-based multi-functional station via an independent encrypted link and then forwarded to a cloud-based monitoring platform.
[0075] When the monitoring platform detects abnormal drone behavior (such as sudden attitude deflection or deviation from the preset path) by integrating IMU attitude data and satellite navigation tracks with a real-time safety map, the system uses the dynamic safety map to assess the risk. In a heavily monitored mode, the cloud platform can take over flight control before the operator and issue "forced hovering" or "forced landing" commands based on the severity of the situation. After completing digital signature verification, the device's security chip switches to takeover mode shortly to ensure the drone is safely handled within the controlled area.
[0076] It should be understood that this embodiment is only an application example of the present invention in the drone scenario, and the present invention is also applicable to other types of intelligent equipment.
[0077] Compared to existing technologies, traditional intelligent device control systems employ indiscriminate methods such as full-band signal jamming or physical interception networks, which can easily lead to malfunctions of legitimate intelligent devices. This solution, however, establishes a three-tiered response mechanism that matches different response intensities based on risk levels. For example, in medium-risk scenarios, it only restricts driving speed without interrupting task execution; in high-risk scenarios, it uses hardware-level takeover to ensure rapid handling of malicious intelligent devices, effectively reducing the impact on normal driving activities.
[0078] Through the above technical solution, this application solves the problem of accidental injury during lawful driving caused by the single handling method in the prior art, and realizes precise control based on risk level. When a slight deviation from the driving route occurs, a non-intrusive alarm mechanism avoids excessive intervention; when a full-domain intrusion is detected, driving parameters are constrained through dynamic command issuance; in the face of malicious and illegal device events, hardware-level takeover ensures a reliable transfer of control. The automatic recording function of the entire process operation log provides a complete chain of evidence for subsequent accountability.
[0079] This application further proposes a cloud-based control platform that integrates a dynamic security map engine. Based on the overall control rules, meteorological data, and early warnings of illegal devices, the platform dynamically generates security map boundaries. The fence coordinates are periodically sent to the security chip on the device via an encrypted link. The security chip compares the location data in real time and triggers boundary crossing warnings or handling actions.
[0080] For example, in drones, a dynamic electronic fence engine refers to an algorithm module that generates driving restriction areas in real time based on multi-source data. This can be implemented using a rule engine and data fusion framework to integrate global control instructions, weather trends, and illegal driving warnings. Periodic encrypted link transmission refers to transmitting fence coordinates at preset time intervals via an end-to-end encrypted communication channel. This can be achieved using a dynamic data encapsulation mechanism based on session keys to ensure the timeliness and tamper-proof nature of fence data updates. Real-time security chip comparison refers to performing coordinate matching calculations through a hardware-level positioning data processing unit. This can be implemented using geofencing algorithms and hardware acceleration modules to complete collision detection between location data and fence boundaries within milliseconds.
[0081] Specifically, the dynamic safety map engine runs on a cloud-based control platform, continuously receiving coordinates of temporary driving restriction areas issued by the overall control department, real-time wind speed and precipitation distribution data provided by the meteorological monitoring system, and heat maps of high-risk areas generated from historical statistics of illegal equipment incidents. The engine fuses this data using a spatial overlay algorithm to generate a composite safety map boundary that includes basic control areas, meteorological avoidance zones, and extended illegal equipment warning zones. The generated fence coordinate data is sent to the onboard safety chip via an encrypted link at fixed intervals, and the safety chip stores it in a protected memory area. During operation, the safety chip continuously acquires the real-time location information of the smart device and calculates the spatial relationship between the current location and the fence boundary using a hardware-accelerated geofencing algorithm. When a smart device is detected approaching or entering a restricted area, the safety chip triggers a tiered response based on the degree of boundary violation: for minor boundary violations, only an alarm signal is sent to the control unit; for persistent boundary violations or entry into high-risk areas, a hardware-level forced takeover process is directly initiated.
[0082] Compared to existing technologies, traditional security maps use fixed coordinate ranges and rely on manual updates, making them unable to respond to temporary controls or sudden weather changes. This solution uses a dynamic generation mechanism to automatically adjust fence boundaries according to external conditions. Combined with encrypted transmission and hardware-level execution, it solves the problems of delayed updates and insufficient reliability in static fences. In existing technologies, fence data is easily tampered with or forged. This solution ensures the authenticity and integrity of fence commands through end-to-end encrypted links and tamper-proof storage via a secure chip.
[0083] Through the above technical solutions, this application achieves the ability to dynamically adjust the security map according to the overall control rules, weather conditions, and security threats, avoiding control failures caused by lagging fence information. The periodic encrypted transmission mechanism ensures the timeliness and security of fence data updates, and the hardware-level comparison and execution module eliminates the risk of malicious bypass at the software level, ensuring reliable triggering and accurate execution of boundary violation handling actions.
[0084] This application further proposes a ground-based multi-functional station that integrates multi-source sensing data, collects global information through radar detection, multispectral cameras and meteorological sensors, and uses multi-site collaborative ranging and angle of arrival technology to achieve precise positioning of intelligent devices. At the edge computing unit, data spatiotemporal fusion is performed to construct a local global situation map.
[0085] Multi-source sensing data refers to the comprehensive, multi-dimensional information acquired through three types of heterogeneous sensors: radar, multispectral cameras, and meteorological sensors. Specifically, millimeter-wave radar can be used for target detection, multispectral sensors for optical recognition, and meteorological sensors for collecting temperature and humidity data. By complementing each other, the blind spots of a single sensor in complex environments can be eliminated. Multi-site collaborative ranging and angle-of-arrival technology refers to the joint calculation of the time difference and angle difference of arrival of signals from the same intelligent device using three or more stations. Localized processing reduces cloud transmission latency, ensuring real-time updates of the comprehensive situational map.
[0086] Specifically, the radar detection module continuously scans the entire area to acquire reflected signals from smart devices, while multispectral cameras simultaneously collect visible and infrared spectral images, and meteorological sensors monitor wind speed and temperature / humidity parameters in real time. Multiple stations calculate three-dimensional coordinates based on triangulation principles by measuring the time difference of arrival and incident angle of the smart device signals. The edge computing unit performs spatiotemporal registration of radar point cloud data with optical images from different timestamps, and combines this with meteorological parameters to construct a multi-dimensional global situational map containing the location, trajectory, and environmental status of smart devices, providing a real-time spatial reference for the monitoring system.
[0087] Compared with existing technologies, traditional intelligent device monitoring systems rely on a single radar or camera for target detection, which is prone to misjudgment and missed detection in rainy or foggy weather, and single-site positioning suffers from positioning errors due to signal attenuation.
[0088] Through the above technical solutions, this application effectively solves the problem of regulatory blind spots caused by the single dimension of the whole-domain information collection, significantly improves the target recognition capability under complex weather conditions, realizes intelligent device tracking with centimeter-level accuracy through multi-site collaborative positioning, and ensures the real-time and reliability of the whole-domain situational awareness by relying on the data processing capability of the edge computing unit.
[0089] refer to Figure 1-5 As shown, this application further proposes a full-process encrypted monitoring method for smart device systems with forced takeover functionality, including the following steps:
[0090] S1. Before the intelligent equipment is put into operation, two-way authentication is performed between the device-side security encryption chip and the site security chip based on the device identity code and asymmetric encryption algorithm; a session key is negotiated and generated and updated regularly.
[0091] S2. During operation, data is transmitted in encrypted form. The device encrypts telemetry, location, and identity data using a security chip and uploads it to the site via an independent link. The site decrypts the data, verifies its integrity, and then forwards it to the cloud control platform.
[0092] S3: Global situational analysis and response. The cloud control platform integrates multi-source data to identify abnormal behavior and generates encrypted response instructions according to hierarchical strategies. The instructions are broadcast to the target smart device via the site and executed as hardware-level takeover operations after being verified by the security chip.
[0093] S4: Forced takeover in abnormal situations. In the strong supervision mode, the cloud control platform directly takes over when the sensor system exhibits abnormal behavior. In the weak supervision mode, external monitoring equipment monitors abnormal behavior and implements forced takeover upon detection.
[0094] Two-way authentication refers to the identity verification process between the device and the ground station based on an asymmetric encryption algorithm. Specifically, it can be implemented using an elliptic curve digital signature algorithm combined with the device's unique identification code to ensure the authenticity of both parties' identities. An independent link refers to a dedicated transmission channel independent of the smart device's original communication system. This can be implemented using physically isolated wireless communication modules to prevent data leakage caused by vulnerabilities in the original communication system. Secure chip signature verification refers to the verification of the digital signature of encrypted commands. This can be implemented using a signature verification circuit based on a hardware security module to ensure the legitimacy and integrity of the command's origin.
[0095] Specifically, during the preparation phase, the airborne security chip and the site security chip exchange digital certificates to complete two-way authentication, using the device's unique identification code as the authentication credential. After successful authentication, both parties negotiate and generate a temporary session key using an asymmetric encryption algorithm. This key is automatically updated at preset time intervals during operation. During operation, telemetry data and control commands generated by the intelligent device are hardware-encrypted by the security chip and transmitted to the ground station via an independent communication link. The station decrypts and verifies the integrity of the received encrypted data before forwarding the plaintext data to the cloud platform for real-time analysis. The cloud platform identifies abnormal driving behavior by integrating multi-source sensing data and generates encrypted handling commands based on a preset tiered response strategy. After the encrypted commands are broadcast to the target intelligent device via the station, the airborne security chip verifies the matching of the command's digital signature with the device's identification code. Upon successful verification, a forced takeover operation is directly executed through the dedicated device control interface.
[0096] Compared to existing technologies, traditional smart device monitoring methods rely on plaintext transmission of Remote-ID information, which poses risks of identity forgery and data tampering. Existing technologies issue anomaly handling commands through the software layer, making them vulnerable to interception or bypassing by malicious programs. This method achieves end-to-end security protection for identity authentication, data transmission, and anomaly handling by constructing an end-to-end encrypted link and a hardware-level command execution mechanism. While existing technologies use fixed-key encryption, this method effectively resists key-cracking attacks through a dynamic key negotiation mechanism.
[0097] Through the above technical solutions, this application addresses the security risks caused by the disconnect in the intelligent device monitoring link. The two-way authentication mechanism before intelligent equipment operation effectively prevents unauthorized devices from accessing the monitoring network, and dynamic key negotiation significantly reduces the possibility of communication data being cracked. Independent encrypted link transmission ensures physical isolation between critical data and ordinary business data, avoiding security vulnerabilities caused by mixed transmission. The hardware-level instruction verification and execution mechanism achieves millisecond-level response speeds, ensuring the real-time and reliable handling of abnormal behavior. The multi-level encrypted instruction distribution mechanism enables precise control of specific intelligent devices, avoiding the impact of traditional electronic interference methods on legitimate intelligent devices.
[0098] This application further proposes that the execution of the forced takeover command includes verifying the digital signature and identity code matching of the command via a security chip, decrypting it, injecting the command into the control unit through a dedicated device control terminal interface, and, after execution, feeding back the status to the cloud platform through an encrypted link and recording the entire process audit log.
[0099] Among them, the security chip verification instruction digital signature and identity code matching refers to using asymmetric encryption algorithms to verify the legitimacy of the instruction source. The full-process audit log refers to recording the key operation nodes in the instruction execution process, which can be implemented using blockchain technology or secure storage chips to ensure that the log is tamper-proof and has timestamp traceability capabilities.
[0100] Specifically, upon receiving a forced takeover command, the security chip first verifies the validity of the digital signature using a pre-installed root certificate, and then compares the device identification code carried in the command with the unique code stored within the chip. If the verification is successful, the security chip decrypts the command using a session key and transmits it directly to the control unit via a physically isolated dedicated interface. After the command is executed, the security chip encrypts the execution status code and sends it back to the cloud platform, while simultaneously recording an audit log containing a timestamp, command content, and execution result in the chip's internal secure storage area.
[0101] Compared to existing technologies, traditional smart device monitoring systems rely on plaintext command transmission and lack hardware-level verification mechanisms, posing a risk of command interception and forgery. Existing technologies typically send commands to the control system through software, making them susceptible to malware interception or system vulnerabilities. Furthermore, the lack of execution status feedback and reliable log recording makes it difficult to effectively trace abnormal events.
[0102] Through the above technical solutions, this application achieves end-to-end encrypted verification and physically isolated execution of forced takeover commands, preventing illegal command injection and man-in-the-middle attacks, and ensuring that commands only act on the target smart device. Hardware-level identity matching and digital signature verification avoid erroneous operations caused by identity forgery. Encrypted feedback mechanisms and audit log recording provide regulators with a reliable chain of execution evidence, supporting post-event traceability and liability determination.
[0103] The full-process encrypted monitoring system and method for intelligent device systems with forced takeover function provided in this application solves the problems of communication security vulnerabilities, identity recognition distortion and crude handling methods in the traditional monitoring system through device-side hardware-level encryption, independent communication links and cloud-based hierarchical handling mechanisms. It has the advantages of improving the security of intelligent device communication links, achieving accurate full-domain monitoring and ensuring that legitimate driving activities are not interfered with.
[0104] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A full-process encryption supervision system for a smart device system with a forced takeover function, characterized in that, The application relates to a device end, a ground end multifunctional station, a cloud end control platform and an end-to-end encrypted communication link established among the three. The device end is integrated with a secure encryption chip and a supervision communication module, and supports a strong supervision mode and a weak supervision mode; in the strong supervision mode, the secure encryption chip of the device end is directly connected to a core data bus of a control system to perform real-time encryption processing on a driving control instruction; when the intelligent device enters a supervision domain, the secure encryption chip establishes a secure connection with the ground end multifunctional station through an independent encryption link, completes bidirectional identity authentication, the ground end multifunctional station uploads the decrypted driving data to the cloud end control platform, generates a global situation map through multi-source sensing data fusion, the cloud end control platform monitors and judges all sensor system information, control units and task processing unit data which are encrypted in a whole process, and when an abnormal driving behavior is detected, the cloud end control platform generates an encrypted disposal instruction which is broadcast to the target intelligent device end through a station network, the secure chip verifies the legality of the instruction, and then injects a control command into the control system through a special interface to realize accurate takeover operation; in the weak supervision mode, the secure encryption chip is externally connected to the original system of the intelligent device through an interface, and the cloud end control platform monitors and judges the data of the control units and the task processing units which are encrypted in a whole process, so that the control units can be commanded in real time to realize takeover; in the strong supervision mode, the cloud end control platform has a priority in acquiring the sensor information of the intelligent device, but does not have the priority in the weak supervision mode, so the cloud end control platform has a priority in controlling the intelligent device over the local control in the strong supervision mode. The cloud end control platform comprises a key management center, a decryption and visual monitoring module, a situation analysis and alarm module and a strategy issuing and forced takeover module, and realizes global situation awareness, abnormal behavior identification and hierarchical disposal instruction issuing of global intelligent devices.
2. The full-process encryption supervision system for a smart device system with a forced takeover function according to claim 1, characterized in that: The ground end multifunctional station is arranged on a communication tower and a GNSS global navigation satellite system, is provided with a multi-source sensing unit and an edge security chip, and is used for global data acquisition, encrypted data decryption / verification and localized instruction execution. The device end comprises a control unit, a task processing unit, a secure encryption chip, a supervision communication chip, a positioning and sensing module and a power management module, the ground end multifunctional station comprises a station security chip with bidirectional identity authentication capability, an edge computing unit, a multi-source detection unit, a local disposal unit and a communication unit. 3.The full-process encryption supervision system for intelligent device system with forced takeover function according to claim 1, characterized in that: The encrypted communication link is used for establishing an end-to-end encryption session among the device end, the ground end multifunctional station and the cloud end control platform, and transmitting driving data, identity authentication information, global management information and forced takeover instructions. The secure encryption chip is internally provided with an unalterable unique device identity code which is used for performing hardware-level identity authentication when the communication link is established; the encrypted communication link is independent of an original communication system of the intelligent device, and supports bidirectional identity authentication and session key negotiation between the device end and the station and between the station and the cloud end control platform; 4. The full-process encryption supervision system for intelligent device system with forced takeover function according to claim 1, characterized in that: The secure encryption chip adopts a hybrid encryption architecture: a symmetric encryption algorithm is used for telemetry data and control instructions. The asymmetric encryption algorithm is used for key negotiation and identity authentication. The physical unclonable function and one-time programmable storage unit are integrated into the chip to generate root keys and derive session keys. The true random number generator is built-in the chip to generate independent initialization vectors for each encryption operation.
5. The full-process encryption supervision system for intelligent device system with forced takeover function according to claim 1, characterized in that: The encrypted communication link is divided into three types of dedicated channels: Global management link: transmits secure map data, weather information, and global restriction commands; Situation awareness link: transmits intelligent device location, driving track, attitude, and identity authentication data; Forced takeover link: transmits return, driving, stop, or driving direction intervention commands; Through the quality of service guarantee mechanism, resource reservation and dynamic priority allocation are implemented for critical communication needs.
6. The full-process encryption supervision system for intelligent device system with forced takeover function according to claim 1, characterized in that: The key management center of the cloud control platform: performs two-way identity authentication with the device end security encryption chip and dynamic negotiation of session keys; supports key life cycle management, emergency key revocation and batch invalidation mechanism; all key operations are completed in a high-security isolation area and are protected from external tampering by a hardware security module.
7. The full-process encryption supervision system for intelligent device system with forced takeover function according to claim 2, characterized in that: The forced takeover module executes a hierarchical disposal process: Warning level: trigger sound and light warning in the secure map and platform notification; Restriction level: issue speed limit, stop, or return to the default route command; Takeover level: issue hardware-level forced stop or return command, and switch device control interface for execution by the security encryption chip after signature verification within a short period of time. 8.The full-process encryption supervision system for intelligent device system with forced takeover function according to claim 1, characterized in that: The cloud control platform integrates a dynamic security map engine: dynamically generates a security map boundary based on global regulation rules, weather data, and illegal device early warning; periodically issues the fence coordinates to the device end security chip through the encrypted link; The security chip compares the positioning data in real time, triggers the out-of-bound early warning or disposal action. 9.The full-process encryption supervision system for smart device system with forced takeover function according to claim 1, characterized in that: The ground end multi-functional site fuses multi-source sensing data: collects global information through radar detection, multi-spectral cameras, and weather sensors; uses multi-site cooperative ranging and angle of arrival technology to achieve accurate positioning of intelligent devices; performs spatio-temporal fusion of data in the edge computing unit to construct a local global situation map.
10. A full-process encryption supervision method for a smart device system with a forced takeover function, which is used in the full-process encryption supervision system for a smart device system with a forced takeover function according to any one of claims 1-9, characterized in that, The steps include: S1, two-way authentication before the operation of intelligent equipment, the device end security encryption chip and the site security chip complete two-way authentication based on device identity code and asymmetric encryption algorithm; Negotiate to generate session keys and update them regularly; S2, encrypted data transmission during operation, the device end encrypts telemetry, location, and identity data through the security chip and uploads them to the site through independent links; the site decrypts and verifies the data integrity before forwarding them to the cloud control platform; S3: global situation analysis and disposal, the cloud control platform fuses multi-source data to identify abnormal behavior and generates encrypted disposal instructions according to the hierarchical strategy; the instructions are broadcasted to the target intelligent device end by the site, and the security chip verifies and executes the hardware-level takeover operation after signature verification; S4: forced takeover in abnormal situations, in the strong supervision mode, the cloud control platform directly takes over in response to abnormal situations exhibited by the sensor system; in the weak supervision mode, the external monitoring device monitors abnormal behavior and implements forced takeover after detection.
Citation Information
Patent Citations
Intelligent automobile basic map data safety protection assembly
CN114827200A
High-precision positioning and navigation remote emergency takeover system
CN119967395A