Data security storage method and system and storage medium

By introducing a trusted execution environment into the vehicle system, trusted time fusion and block hashing are performed on multimodal data, and software and hardware measurement digests and compact signatures are generated. This solves the security problems in data transmission and storage, and ensures the integrity and security of the data.

CN121727701APending Publication Date: 2026-03-24DALIAN JOYSON PREH INTELLIGENT VEHICLE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-03
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing data transmission and storage methods are vulnerable to theft, tampering, or loss due to network outages, making it difficult to guarantee data integrity and security.

Method used

The vehicle's multimodal data is sent to the trusted execution environment via a secure path. Trusted time fusion, segmentation, and hash construction are performed to generate a data packet that includes a trusted timestamp, confidence level, and data integrity root hash. Software and hardware measurement digests and compact signatures are also generated, and the cloud server stores the data after verification.

Benefits of technology

This approach eliminates the risk of data hijacking and tampering at the source, ensures the authenticity and reliability of data generation, achieves traceability of data time authenticity and integrity, reduces the risk of storing untrusted data, forms a complete data trust chain, and guarantees the integrity and security of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121727701A_ABST
    Figure CN121727701A_ABST
Patent Text Reader

Abstract

The invention provides a data security storage method and system and a storage medium, and the method comprises the steps: transmitting the multi-modal data of a vehicle machine to a trusted execution environment through a security path; controlling the trusted execution environment to carry out trusted time fusion, blocking and hash construction on the multi-modal data to obtain a data packet comprising a trusted timestamp, confidence and data integrity root hash; and generating a software and hardware measurement abstract and a compact signature according to the data packet, and sending the software and hardware measurement abstract and the compact signature to the cloud server, so that the cloud server stores the data packet when the verification of the software and hardware measurement abstract and the compact signature is passed. According to the embodiment of the invention, the risk that the data is hijacked and tampered is avoided from the source, the data generation is ensured to be real and credible, software and hardware measurement abstracts and compact signatures are generated in combination with the data packets, the environmental security of the credible execution environment is verified, the responsibility of multiple parties is also verified, and the storage risk of uncredible data is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive electronics technology, and more specifically to a data security storage method, system, and storage medium. Background Technology

[0002] As autonomous driving technology rapidly evolves from assisted driving to highly automated driving and even fully automated driving, the vehicle's reliance on data has upgraded from "auxiliary reference" to "core decision-making foundation." At this point, vehicles need to collect massive amounts of data in real time at millisecond-level frequencies using multimodal sensors. This includes environmental data such as pedestrian positions, vehicle distances, traffic light status, and road marking information, as well as the vehicle's own operational data such as speed, steering angle, braking status, powertrain parameters, and the operating status of various sensors. The daily data collection volume for a single vehicle can reach tens or even hundreds of gigabytes.

[0003] However, data is currently vulnerable to theft, tampering, or loss due to network outages during transmission and storage, making it difficult to guarantee its integrity and security. Summary of the Invention

[0004] The problem addressed by this invention is the integrity and security issues in existing data transmission and storage processes.

[0005] To address the above problems, this invention provides a secure data storage method applied to in-vehicle systems, the secure data storage method comprising: The multimodal data from the vehicle's infotainment system is sent to the trusted execution environment via a secure path. The trusted execution environment is controlled to perform trusted time fusion, block division and hash construction on the multimodal data to obtain a data packet including trusted timestamp, confidence level and data integrity root hash; A hardware and software measurement digest and a compact signature are generated based on the data packet, and the hardware and software measurement digest and the compact signature are sent to the cloud server so that the cloud server stores the data packet when the hardware and software measurement digest and the compact signature are verified.

[0006] Optionally, controlling the trusted execution environment to perform trusted time fusion, block partitioning, and hash construction on the multimodal data includes: The trusted execution environment is controlled to perform anomaly detection and weighting on the multimodal data fusion drift model to obtain intermediate data packets including trusted timestamps and confidence levels; The trusted execution environment is controlled to divide the intermediate data packets into data blocks according to a fixed window or an event window, and to perform layer-by-layer aggregation calculation on all leaf hashes after data block division to obtain the data integrity root hash.

[0007] Optionally, generating the hardware and software measurement digest and compact signature based on the data packet includes: The trusted execution environment is controlled to generate a hardware and software measurement digest, including firmware hash, startup metric, and configuration digest, based on the data packet, and is then signed by the platform root trust. At least two participants are identified, and each party uses its own key share to perform a threshold signature on the hardware / software measurement digest and the data packet, and then aggregates them to obtain the compact signature.

[0008] Optionally, before generating the hardware and software measurement digest and compact signature based on the data packet, the secure data storage method further includes: A key ratchet mechanism is used, based on the master key and epoch count, to generate a one-time session key for each time epoch or event window to encrypt the data packets.

[0009] Optionally, before generating the hardware and software measurement digest and compact signature based on the data packet, the secure data storage method further includes: The data packets and hash chain pointers are written into an encrypted circular buffer, and the records are continuously rolled over when the network is disconnected.

[0010] Optionally, before sending the multimodal data of the vehicle system to the trusted execution environment via a secure path, the data secure storage method further includes: The multimodal data is obtained by acquiring data from at least one of a data transmission channel, an inertial measurement unit, video, lidar, or millimeter-wave radar.

[0011] This application embodiment also provides a data security storage system, the data security storage system comprising: A trusted execution environment is used to perform trusted time fusion, block segmentation, and hash construction on the received multimodal data to obtain a data packet including a trusted timestamp, confidence level, and data integrity root hash. An electronic device is configured to generate a hardware and software measurement digest and a compact signature based on the data packet, and send the hardware and software measurement digest and the compact signature to a cloud server; A cloud server is used to store the data packet when the hardware and software measurement digest and the compact signature verification pass.

[0012] Optionally, the cloud server is also used to verify the data integrity root hash and merge the trusted timestamp, the confidence level, the policy version associated with the compact signature, and the hardware and software measurement digest to form a trusted conclusion on the timeline.

[0013] Optionally, the cloud server is also used to output a standardized evidence package that includes conclusions on source credibility, integrity, time credibility, and chain of responsibility signatures, wherein the standardized evidence package does not include the data packet.

[0014] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the data security storage method described above.

[0015] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: the computer-readable storage medium in this embodiment operates the data security storage method as in any embodiment of the present invention, and therefore has all the beneficial effects of the simulation debugging method as in any embodiment of the present invention, which will not be repeated here.

[0016] The data security storage method provided in this application transmits multimodal data from the vehicle system to a trusted execution environment via a secure path, eliminating the risk of data hijacking and tampering at the source and ensuring the authenticity and reliability of the generated data. The trusted execution environment performs trusted time fusion and block hashing on the data to generate a data packet with a trusted timestamp, confidence level, and data integrity root hash, making the time authenticity and integrity of the data traceable and verifiable. Combined with the data packet, a software and hardware measurement digest and a compact signature are generated, which not only verifies the security of the trusted execution environment but also verifies the responsibilities of multiple parties. The data packet is only stored when the cloud verification is passed, which greatly reduces the risk of storing untrusted data. Finally, a complete "data trust chain" is formed from data generation, authentication to storage, ensuring the integrity and security of the data. Attached Figure Description

[0017] Figure 1 A flowchart illustrating the data security storage method provided in this application embodiment; Figure 2 for Figure 1 The diagram illustrates the process of obtaining data packets in the data security storage method shown. Figure 3 for Figure 1 The flowchart shown illustrates the process of generating hardware and software measurement digests and compact signatures in the data security storage method. Figure 4 A schematic diagram of a data security storage system provided in an embodiment of this application; Figure 5 for Figure 4 The diagram shows the principle framework of a secure data storage system. Detailed Implementation

[0018] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0019] In the existing data lifecycle, there are three core challenges: First, in the data generation stage, most data lacks hardware-level anti-tampering and measurement binding, timestamps are easily tampered with, and sensor data may be interfered with, making the data source unreliable; second, in the data transmission and storage stage, data is easily stolen, tampered with, or lost due to network outages, making it difficult to guarantee integrity and security; third, in the data application stage, there is a lack of unified and credible basis for defining data responsibility among various parties such as vehicle-side, OEMs, and suppliers, making it difficult to trace responsibility when disputes arise.

[0020] To address the aforementioned technical problems, embodiments of this application provide a data security storage method, system, and storage medium.

[0021] Please continue reading. Figure 1 , Figure 1 This is a flowchart illustrating a data security storage method provided in an embodiment of this application. The application provides a data security storage method applied to an in-vehicle system, comprising: 110. Send the vehicle's multimodal data to the trusted execution environment via a secure path.

[0022] Through a pre-built hardware-level secure transmission channel, multimodal data collected in real time by multimodal sensors on the vehicle's infotainment system is directly transmitted from the sensor interface to the Trusted Execution Environment (TEE). This path avoids untrusted areas such as the operating system kernel and application layer throughout the entire process. Hardware-level isolation and end-to-end encryption ensure that data is not intercepted, tampered with, or replaced by malicious processes during transmission. For example, point cloud data from the LiDAR, after being output from the sensor chip, is directly written to the encrypted memory of the TEE via a secure channel, avoiding the memory buffer of the vehicle's OS; image frames from the camera are transmitted through a dedicated secure interface and directly received and processed by a trusted driver within the TEE. This direct secure transmission cuts off the possibility of data contamination on the vehicle's infotainment system from both physical link and encryption mechanisms, providing a clean source foundation for subsequent data processing and solving the core security vulnerabilities of data being easily hijacked by malicious software and sensor data being forged in traditional vehicle infotainment systems.

[0023] Among them, the hardware-level secure transmission channel can be based on an on-chip isolated bus, encrypted DMA, or a trusted channel protocol.

[0024] Among them, multimodal sensors can be lidar, cameras, IMUs, etc.

[0025] In some embodiments, before sending the vehicle's multimodal data to the Trusted Execution Environment (TEE) via a secure path, the data secure storage method further includes: acquiring data from at least one of a data transmission channel, an inertial measurement unit (IMU), video, LiDAR, or millimeter-wave radar to obtain multimodal data. By selecting data from at least one or more sources among the vehicle's key data sources, the core perception data and transmission process data in the autonomous driving scenario can be comprehensively covered, ensuring that the multimodal data can fully reflect the vehicle's operating status and surrounding environment, providing a comprehensive and complete raw data foundation for subsequent trusted processing within the TEE. The core perception data can include, for example, 3D environmental point clouds from LiDAR, vehicle attitude data from the IMU, and obstacle distance information from millimeter-wave radar.

[0026] 120. Control the trusted execution environment to perform trusted time fusion, block division and hash construction on multimodal data to obtain data packets including trusted timestamps, confidence levels and data integrity root hashes.

[0027] For details on the specific steps of controlling the trusted execution environment to perform trusted time fusion of multimodal data, please refer to [link / reference]. Figure 2 , Figure 2 for Figure 1 The flowchart illustrating the data packet acquisition process in the data security storage method is as follows: 121. Control the trusted execution environment to perform anomaly detection and weighting on the multimodal data fusion drift model to obtain intermediate data packets including trusted timestamps and confidence levels.

[0028] For example, the trusted execution environment (CEX) identifies potential problems during the fusion process based on a pre-defined anomaly detection mechanism, combined with deviation analysis of historical data baselines, cross-validation of multi-sensor data, and monitoring of model output stability. These problems include decreased point cloud accuracy of LiDAR due to environmental interference, attitude data shifts in inertial measurement units caused by vibration, or abnormal logical connections between different modal data. This allows for the filtering of distorted data and the marking of suspicious data segments. Furthermore, data weights are dynamically allocated based on the real-time performance parameters and scene adaptability of each modal sensor to complete high-quality fusion computation. Simultaneously, relying on trusted time sources such as the hardware real-time clock and BeiDou or GPS timing information integrated within the CEX, an immutable trusted timestamp is added to the fusion result. Combined with the execution status of anomaly detection and weighting strategies, a quantified confidence score is generated, ultimately forming an intermediate data packet containing the trusted timestamp and confidence score. The entire process is completed in a closed loop within the CEX, preventing malicious tampering of anomaly detection rules and weighting parameters while ensuring the authenticity of the timestamp and confidence score. This provides a time-traceable and quality-quantifiable trusted foundation for subsequent data segmentation and hash construction.

[0029] 122. Control the trusted execution environment to divide intermediate data packets into blocks according to a fixed window or event window, and perform layer-by-layer aggregation calculation on all leaf hashes after data block division to obtain the data integrity root hash.

[0030] The fixed window can be understood as automatically dividing data into blocks based on the set data packet size or time interval, ensuring that the block division process is uniform and controllable; the event window can be understood as triggering block division based on specific business events such as a vehicle completing a turn or a sensor completing a full environmental scan, so that the data blocks accurately correspond to the actual scene actions.

[0031] In some embodiments, performing layer-by-layer aggregation calculations on all leaf hashes after data block division to obtain the data integrity root hash can be understood as follows: after block division is completed, the trusted execution environment first calculates the hash value for each data block separately, generating all leaf hashes in the Merkle hash tree structure; then, starting from the bottom layer of the hash tree, it combines adjacent leaf hashes in pairs and calculates the hash value again to form the parent hash of the next layer, and so on, aggregating and calculating layer by layer until the unique top-level hash value is finally obtained, which is the data integrity root hash.

[0032] By completing the entire block division and hash aggregation process in a closed loop within a trusted execution environment, it not only avoids the tampering of block division rules and the forgery of leaf hashes, but also ensures that the root hash of the final generated data integrity can accurately map the state of all block data. Furthermore, subsequent verification of the root hash can quickly determine whether intermediate data packets have been tampered with or missing during storage or transmission, providing key technical support for the integrity of the entire data chain.

[0033] 130. Generate a hardware and software measurement digest and a compact signature based on the data packet, and send the hardware and software measurement digest and compact signature to the cloud server so that the cloud server stores the data packet when the hardware and software measurement digest and compact signature are verified.

[0034] For details on generating hardware and software measurement summaries and compact signatures, please refer to [link / reference needed]. Figure 3 , Figure 3 for Figure 1 The flowchart illustrating the data security storage method for generating hardware and software measurement digests and compact signatures is as follows: 131. Control the trusted execution environment to generate hardware and software measurement digests, including firmware hash, startup metric, and configuration digest, based on the data packet, and sign them by the platform root trust.

[0035] For example, at the firmware level, hash values ​​of key components such as vehicle sensor firmware and operating system kernel firmware are calculated to form a firmware hash. For the boot process, a full-link boot log from hardware power-on to trusted execution environment initialization is recorded and a summary is generated to obtain a boot metric. For the runtime configuration, key configuration information such as sensor parameter settings, data processing strategies, and security rules is summarized and a summary is calculated to form a configuration summary. Finally, these three types of information are integrated to generate a complete hardware and software measurement summary. Based on this, the platform root trust built into the vehicle system digitally signs the hardware and software measurement summary to ensure the authenticity and immutability of the summary itself. The entire process is completed in a closed loop within the trusted execution environment, ensuring that the collection and calculation of firmware hash, boot metric, and configuration summary are not subject to external malicious interference. Furthermore, the signature by the platform root trust endows the summary with traceable origin and verifiable status attributes, allowing subsequent cloud or other participants to verify only the signature to confirm whether the vehicle's hardware and software environment was in a preset trusted state when the data packet was generated.

[0036] Platform root trust can be exemplified by, for example, the root key in a hardware security module.

[0037] 132. Obtain at least two participants, use their respective key shares to perform a threshold signature on the hardware and software measurement digest and data packet, and aggregate them to obtain a compact signature.

[0038] For example, the vehicle and at least two other parties, such as the OEM and the supplier, each hold a key share established through distributed key generation (DKG). Each party uses its own key share to jointly perform a threshold signature on the data packet, which includes a trusted timestamp, confidence level, data integrity root hash, policy version, and hardware / software measurement digest. Then, a compact signature is obtained through aggregation calculation.

[0039] In some embodiments, before generating a hardware / software measurement digest and a compact signature based on the data packet, the data secure storage method further includes: using a key ratchet mechanism to generate a one-time session key for each time epoch or event window, based on the master key and epoch count, to encrypt the data packet.

[0040] For example, based on a pre-established master key, key derivation operations are performed using a real-time updated epoch count to generate a unique one-time session key for each independent time epoch or event window. This session key is used only for encrypting data packets within the corresponding time epoch or event window. The encryption process is completed in a closed loop within a trusted execution environment, avoiding the risk of key leakage at the execution environment level. Because the session key has a one-time pad characteristic, even if a session key is accidentally leaked, it only affects data packets within the corresponding interval and will not affect the data security of other time epochs or event windows. Furthermore, the dynamic generation of one-time keys through a key ratchet mechanism ensures both the continuity and security of key updates and provides forward security protection. Even if the current key is leaked, hackers can only decrypt newly generated data after the leak, not previously encrypted data, thus minimizing the risk. This effectively resists attacks such as key cracking and data theft, providing a solid guarantee for the confidentiality of data packets before transmission and storage.

[0041] The epoch count can be exemplified by a counting parameter that increments according to a fixed time period or a data volume threshold. The time epoch can be exemplified by time intervals divided into hours or days. The event window can be exemplified by the event cycle of a vehicle completing a full driving task or a sensor completing a round of full-scene data collection.

[0042] In some embodiments, before generating a hardware and software measurement digest and a compact signature based on the data packet, the data secure storage method further includes: writing the data packet and a hash chain pointer to an encrypted circular buffer and continuously rolling the record during network outages.

[0043] For example, through preset control logic, encrypted data packets and their corresponding hash chain pointers are written together into the vehicle's built-in encrypted circular buffer. This encrypted circular buffer adopts a fixed storage capacity design, supports cyclic overwriting of data storage, and relies on hardware-level encryption mechanisms to protect the stored content in real time, preventing local data from being tampered with or stolen. When the vehicle is offline and unable to transmit data to the cloud, the encrypted circular buffer continuously records newly generated data packets and their corresponding hash chain pointers according to a first-in-first-out (FIFO) rule, automatically overwriting the oldest expired data, ensuring that multimodal data generated during the offline period is not lost. This design not only solves the data storage problem in offline scenarios but also maintains the temporal integrity and correlation of data through hash chain pointers. After the network is restored, the integrity of the data in the buffer can be quickly verified based on the hash chain pointers before being uploaded to the cloud in batches, achieving local data security assurance of no data loss during offline scenarios and traceability during online scenarios, providing key support for the continuity and reliability of end-to-end data storage.

[0044] Please continue reading. Figure 4 and Figure 5This application also provides a data security storage system 100, which includes a trusted execution environment 10, an electronic device 20, and a cloud server 30, as detailed below: The Trusted Execution Environment 10 is used to perform trusted time fusion, block division and hash construction on the multimodal data when it is received, so as to obtain a data packet including trusted timestamp, confidence level and data integrity root hash; Electronic device 20 is used to generate a hardware and software measurement summary and a compact signature based on the data packet, and send the hardware and software measurement summary and compact signature to a cloud server; The cloud server 30 is used to store data packets when the hardware and software measurement digests and compact signature verifications pass.

[0045] The electronic device 20 is used to execute the data security storage method described in any of the above-mentioned methods. The meanings of the terms are the same as in the data security storage method described above. For specific implementation details, please refer to the description in the method embodiment, which will not be repeated here.

[0046] It should be noted that the Trusted Execution Environment 10 and the electronic device 20 can be installed in the vehicle's infotainment system.

[0047] The cloud server's 30-pair software and hardware measurement digest verification can be understood as verifying the certificate chain and whitelist of the software and hardware measurement digests to confirm the trustworthy operating status of the data generating device. Specifically, it first verifies whether the certificate chain corresponding to the software and hardware measurement digest is complete and valid, that is, whether the signature link from the platform root trust to each level of sub-certificates is continuous and has not been tampered with. Then, it checks whether the digest information matches the preset whitelist. Through these two layers of verification, it can be accurately confirmed that the vehicle's hardware and software environment that generates the data packets is in a preset trusted state, ensuring the environmental security of the data source from the device's underlying layer.

[0048] The 30-pair compact signature verification on the cloud server can be understood as verifying the validity of the compact signature's binding fields, such as the root hash of data integrity; that is, verifying whether the signature and these fields form a unique and tamper-proof association. During the verification process, two methods can be chosen based on the actual scenario requirements: one is to disclose the set of parties involved in the signing (such as the vehicle end, OEM, supplier, etc.) and complete the verification by verifying the matching of each party's key share with the signature; the other is to confirm validity solely by verifying the consistency between the group public key (the aggregate public key jointly generated by the key shares of all parties) and the compact signature, without disclosing specific participants. This flexible verification mechanism ensures the reliability of the binding between the signature and core data fields while allowing the verification process to be adjusted according to privacy protection or efficiency requirements, adapting to the security verification needs of different scenarios.

[0049] In some embodiments, after completing other verification steps, the cloud server 30 is also used to verify the root hash of data integrity and merge the trusted timestamp, confidence level, policy version associated with the compact signature, and hardware / software measurement digest to form a trusted conclusion on the timeline. This conclusion clearly presents the key information and verification results of the entire process from data generation to upload, providing unified closed-loop evidence for the time authenticity, integrity, and environmental trustworthiness of the data.

[0050] In some embodiments, the cloud server 30 is also used to output a standardized evidence package that includes conclusions on source credibility, integrity, time credibility, and chain of responsibility signatures. The standardized evidence package does not include data packets. This avoids redundant transmission and storage of sensitive data while providing clear and directly credible evidence support for subsequent data compliance audits and accident liability tracing through structured conclusion information, thus realizing the value of issuing minimal disclosure evidence.

[0051] This application embodiment may also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the data security storage method as described above.

[0052] In the several embodiments provided in this application, it should be understood that the disclosed data security storage method can also be implemented in other ways. The embodiments described above are merely illustrative.

[0053] If the functionality is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned readable storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0054] The above provides a detailed description of a data security storage method, system, and storage medium provided in the embodiments of this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A data security storage method, applied to in-vehicle systems, characterized in that, The data secure storage method includes: The multimodal data from the vehicle's infotainment system is sent to the trusted execution environment via a secure path. The trusted execution environment is controlled to perform trusted time fusion, block division and hash construction on the multimodal data to obtain a data packet including trusted timestamp, confidence level and data integrity root hash; A hardware and software measurement digest and a compact signature are generated based on the data packet, and the hardware and software measurement digest and the compact signature are sent to the cloud server so that the cloud server stores the data packet when the hardware and software measurement digest and the compact signature are verified.

2. The data security storage method according to claim 1, characterized in that, The control of the trusted execution environment to perform trusted time fusion, block segmentation, and hash construction on the multimodal data includes: The trusted execution environment is controlled to perform anomaly detection and weighting on the multimodal data fusion drift model to obtain intermediate data packets including trusted timestamps and confidence levels; The trusted execution environment is controlled to divide the intermediate data packets into data blocks according to a fixed window or an event window, and to perform layer-by-layer aggregation calculation on all leaf hashes after data block division to obtain the data integrity root hash.

3. The data security storage method according to claim 1, characterized in that, The step of generating a hardware / software measurement digest and a compact signature based on the data packet includes: The trusted execution environment is controlled to generate a hardware and software measurement digest, including firmware hash, startup metric, and configuration digest, based on the data packet, and is then signed by the platform root trust. At least two participants are identified, and each party uses its own key share to perform a threshold signature on the hardware / software measurement digest and the data packet, and then aggregates them to obtain the compact signature.

4. The data security storage method according to any one of claims 1 to 3, characterized in that, Prior to generating the hardware / software measurement digest and compact signature based on the data packet, the secure data storage method further includes: A key ratchet mechanism is used, based on the master key and epoch count, to generate a one-time session key for each time epoch or event window to encrypt the data packets.

5. The data security storage method according to any one of claims 1 to 3, characterized in that, Prior to generating the hardware and software measurement digest and compact signature based on the data packet, the secure data storage method further includes: The data packets and hash chain pointers are written into an encrypted circular buffer, and the records are continuously rolled over when the network is disconnected.

6. The data security storage method according to any one of claims 1 to 3, characterized in that, Before sending the multimodal data of the vehicle system to the trusted execution environment via a secure path, the data secure storage method further includes: The multimodal data is obtained by acquiring data from at least one of a data transmission channel, an inertial measurement unit, video, lidar, or millimeter-wave radar.

7. A data security storage system, characterized in that, The secure data storage system includes: A trusted execution environment is used to perform trusted time fusion, block segmentation, and hash construction on the received multimodal data to obtain a data packet including a trusted timestamp, confidence level, and data integrity root hash. An electronic device is configured to generate a hardware and software measurement digest and a compact signature based on the data packet, and send the hardware and software measurement digest and the compact signature to a cloud server; A cloud server is used to store the data packet when the hardware and software measurement digest and the compact signature verification pass.

8. The data security storage system according to claim 7, characterized in that, The cloud server is also used to verify the data integrity root hash and merge the trusted timestamp, the confidence level, the policy version associated with the compact signature, and the hardware and software measurement digest to form a trusted conclusion on the timeline.

9. The data security storage system according to claim 7, characterized in that, The cloud server is also used to output a standardized evidence package that includes conclusions on source credibility, integrity, time credibility, and chain of responsibility signatures. The standardized evidence package does not include the data packet.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the data secure storage method as described in any one of claims 1 to 6.