Intelligent network connection automobile data credible acquisition method and terminal

By building a trusted execution environment and data tracking system in intelligent connected vehicles, and monitoring and uploading trusted data to the blockchain in real time, the issues of trustworthiness and security in the data collection process are solved, and reliable data transmission and storage are achieved.

CN121765773APending Publication Date: 2026-03-31XIAMEN YAXON ZHILLAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing intelligent connected vehicle data collection solutions face challenges in terms of data reliability, security, and privacy. In particular, it is difficult to guarantee the integrity and accuracy of data during data collection, transmission, and storage, which affects the healthy development of the data trading market.

Method used

A trusted execution environment is built using trusted hardware. Combined with a trusted environment monitoring system and a trusted data tracking system, driving data is collected in real time and safety violations are monitored. Trusted data is uploaded to the blockchain through a consistency protocol to ensure the trusted collection and transmission of data.

Benefits of technology

It effectively reduces the impact of security protection on system performance, ensures the trustworthiness of on-chain and off-chain data, guarantees the integrity and accuracy of data, and improves the reliability of data transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765773A_ABST
    Figure CN121765773A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent network connection automobile data credible acquisition method and terminal. The terminal comprises a credible execution environment constructed by adopting credible hardware, a credible environment monitoring system and a credible data tracking system, driving data is collected in real time based on the trusted execution environment, safety violation monitoring is carried out on the trusted execution environment based on the trusted environment monitoring system, and periodic events and emergencies of the trusted execution environment are continuously monitored based on the trusted data tracking system; and by adopting a consistency protocol, the driving data which do not violate the safety regulation and the monitored periodic events and emergencies are uploaded to the block chain from the trusted execution environment. According to the method, a trusted collection environment is constructed by adopting trusted hardware, a block chain and a physical sensing technology, so that the influence of security protection on system performance is effectively reduced, and on-chain and off-chain data are ensured to be trusted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a reliable data acquisition method and terminal for intelligent connected vehicles. Background Technology

[0002] Intelligent connected vehicle data possesses broad commercial value but also faces a series of security challenges. The most prominent is the trustworthiness of this data. Maintaining high integrity, accuracy, security, and privacy during the collection, transmission, processing, and storage of intelligent connected vehicle data is crucial to ensuring its reliability and effectiveness in subsequent services utilizing the data. If the trustworthiness of traded intelligent connected vehicle data cannot be guaranteed, the data's reliability will be questioned, which is extremely detrimental to the healthy development of the intelligent connected vehicle data trading market.

[0003] Existing solutions based on entity reputation or content rules still face challenges in areas such as sensitive data security, computational efficiency, and ensuring trustworthiness before data is uploaded to the blockchain. Summary of the Invention

[0004] The technical problem to be solved by this invention is to provide a trusted data collection method and terminal for intelligent connected vehicles, which uses trusted hardware, blockchain and physical sensing technology to build a trusted collection environment, effectively reducing the impact of security protection on system performance and ensuring that both on-chain and off-chain data are trusted.

[0005] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:

[0006] A reliable data collection method for intelligent connected vehicles includes the following steps:

[0007] S1. Build a trusted execution environment, a trusted environment monitoring system, and a trusted data tracing system using trusted hardware;

[0008] S2. Real-time collection of driving data based on the trusted execution environment, security violation monitoring of the trusted execution environment based on the trusted environment monitoring system, and continuous monitoring of periodic and sudden events of the trusted execution environment based on the trusted data tracking system;

[0009] S3. Using a consistency protocol, driving data that does not violate safety regulations, as well as the monitored periodic events and sudden events, are uploaded from the trusted execution environment to the blockchain.

[0010] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows:

[0011] A trusted data acquisition terminal for intelligent connected vehicles includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps in the trusted data acquisition method for intelligent connected vehicles as described above.

[0012] The beneficial effects of this invention are as follows: It provides a trusted data collection method and terminal for intelligent connected vehicles. By using trusted hardware to construct a trusted execution environment, a trusted environment monitoring system, and a trusted data tracking system, driving data is collected in real time within the trusted execution environment. Combined with the real-time monitoring of safety violations, periodic events, and sudden events by the trusted environment monitoring system and the trusted data tracking system, the credibility of the collected driving data is ensured. Finally, the trusted driving data and the monitored periodic events and sudden events are uploaded to the blockchain through a consensus protocol, effectively reducing the impact of security protection on system performance and ensuring that both on-chain and off-chain data are trustworthy. Attached Figure Description

[0013] Figure 1 This is a flowchart of a reliable data acquisition method for intelligent connected vehicles according to an embodiment of the present invention;

[0014] Figure 2 This is a monitoring flowchart of a reliable data acquisition method for intelligent connected vehicles according to an embodiment of the present invention;

[0015] Figure 3 This is a schematic diagram of the structure of a trusted data acquisition terminal for intelligent connected vehicles according to an embodiment of the present invention.

[0016] Label Explanation:

[0017] 1. A trusted data acquisition terminal for intelligent connected vehicles; 2. A memory; 3. A processor. Detailed Implementation

[0018] To explain in detail the technical content, objectives, and effects of the present invention, the following description is provided in conjunction with the embodiments and accompanying drawings.

[0019] Please refer to Figure 1 and Figure 2 A reliable data collection method for intelligent connected vehicles, comprising the following steps:

[0020] S1. Build a trusted execution environment, a trusted environment monitoring system, and a trusted data tracing system using trusted hardware;

[0021] S2. Real-time collection of driving data based on the trusted execution environment, security violation monitoring of the trusted execution environment based on the trusted environment monitoring system, and continuous monitoring of periodic and sudden events of the trusted execution environment based on the trusted data tracking system;

[0022] S3. Using a consistency protocol, driving data that does not violate safety regulations, as well as the monitored periodic events and sudden events, are uploaded from the trusted execution environment to the blockchain.

[0023] As can be seen from the above description, the beneficial effects of the present invention are as follows: It provides a trusted data collection method for intelligent connected vehicles. By using trusted hardware to construct a trusted execution environment, a trusted environment monitoring system, and a trusted data tracking system, driving data is collected in real time under the trusted execution environment. Combined with the real-time monitoring of safety violations and the monitoring of periodic and sudden events by the trusted environment monitoring system and the trusted data tracking system, the credibility of the collected driving data is ensured. Finally, the trusted driving data and the monitored periodic and sudden events are uploaded to the blockchain through a consensus protocol, which effectively reduces the impact of security protection on system performance and ensures that both on-chain and off-chain data are trusted.

[0024] Furthermore, the real-time collection of driving data based on the trusted execution environment specifically includes:

[0025] In the trusted execution environment, driving data is collected in real time through the data acquisition device of the intelligent connected vehicle. The data acquisition device includes the central gateway, T-box, edge computing gateway and intelligent computing unit of the intelligent connected vehicle.

[0026] Each data acquisition device is equipped with a reliable sensor and a permanent signal line. The permanent signal line is used to interact and work collaboratively with other ECU control units in the intelligent connected vehicle. The reliable sensor is used to acquire driving data collected in real time by the data acquisition device.

[0027] As described above, the data acquisition device can be a device with multiple sensors on an intelligent connected vehicle. With the increasing demands for vehicle intelligence, high computing power, and information security compliance, such devices are mostly designed with high-performance processor chips with a reliable hardware architecture, thus enabling effective reliable data acquisition from the vehicle.

[0028] Furthermore, the periodic event refers to the driving data collected by the data acquisition device periodically acquired by the trusted sensor, and the sudden event refers to the sudden change in the state of the data acquisition device.

[0029] Furthermore, the procedure before step S2 includes:

[0030] Predefined safety violations include the opening of the housing of the data acquisition device, the abnormality of the permanent signal line of the data acquisition device, and the loss of driving data.

[0031] As described above, before collecting data from intelligent connected vehicles, it is necessary to clarify security requirements and identify possible violations of these requirements. Since the data collected by the data acquisition device needs to be stored within the device, the trustworthiness of the acquisition device itself must be ensured to guarantee the reliability of the data. For embedded devices, the worst-case attack is often referred to as a "hardware attack" or "physical attack" because these attacks directly target the device's hardware, are often difficult to defend against, and have enormous destructive power. Therefore, it is necessary to consider the worst-case physical attack, i.e., to monitor physical attacks. This can be achieved by deploying trusted sensors to monitor the integrity of the data acquisition device's casing. Once unauthorized opening is detected, the sensor will trigger an alarm. Simultaneously, the device's permanent signal is connected to the vehicle's constant power supply. If the device is removed from the vehicle, the power failure can be detected momentarily.

[0032] Furthermore, in step S2, driving data is collected in real time based on the trusted execution environment, specifically as follows:

[0033] The trusted sensor periodically acquires the driving data collected in real time by the data acquisition device and converts it into digital timed records. Each digital timed record is represented as (t, C, π), where t is the timestamp when the record is created, C is the set of driving data acquired by the trusted sensor of different types, and π is the measure of data reliability.

[0034] If the digital timing records generated at the time are represented as a digital entity record chain α in chronological order, then record chain α is represented as:

[0035] α=(t0,C0,π0),…,(t i C i ,π i ),… (1);

[0036] The record chain α satisfies three constraints: all relevant records should accurately reflect the actual state of the physical world; events should be captured in real time in the form of records after they occur; and records should be uploaded to the blockchain and should not be lost or delayed.

[0037] The actual driving data to be uploaded by each of the trusted sensors is represented as follows:

[0038] C=(H,P,Γ S (2);

[0039] Where, in the case of a sudden event, H and P are the actual monitored values, and Γ S Set to null;

[0040] When it is a periodic event, H and P are normal valid values, and Γ S These are the values ​​monitored by the data equipment of actual intelligent connected vehicles;

[0041] The driving data C acquired by the trusted sensor is compared with the predefined legal pattern Γ to determine whether the recording is normal. The legal pattern Γ defines the correct pattern for normal driving data.

[0042] As described above, the physical world sensor entities in the device are mapped to digital record entities in the digital world. These records can be seen as digital descriptions of events, facilitating uploading and ensuring credibility.

[0043] Furthermore, in step S2, the trusted execution environment is monitored for security violations by the trusted environment monitoring system, specifically as follows:

[0044] The Hall sensor and permanent signal monitoring sensor placed in the data acquisition device determine whether the driving data C obtained by the trusted sensor has the safety violation item according to the predefined legal mode Γ. If so, the safety violation event is reported in the form of the emergency event record.

[0045] The Hall sensor always outputs 0 when the device housing is not disassembled, indicating that the device housing is intact; therefore, Γ is defined. H ={0}, H represents the actual binary data of the Hall sensor. If the applied magnetic flux density is higher than the magnetic flux density μ at the preset point, then H = 0, otherwise H = 1;

[0046] The permanent signal monitoring sensor always outputs 1 when the main power of the device is not interrupted, indicating that the device is continuously connected to the constant power supply of the vehicle. Therefore, Γ is defined as... P ={1}, where P represents the actual binary data of the permanent signal monitoring sensor. If the detected voltage is higher than the voltage threshold θ of the preset point, then P = 1; otherwise, P = 0.

[0047] As described above, once security violations are defined, situations involving security violations can be monitored. Security violations are reported in the form of emergencies, meaning that any security violation detected is immediately reported to detect intrusion in a timely manner. Therefore, in order to capture these security violations, Hall effect sensors and permanent signal monitoring sensors can be placed in the data acquisition equipment for effective monitoring.

[0048] Furthermore, step S2, which involves real-time collection of driving data based on the trusted execution environment, also includes:

[0049] Define Γ S ={(t s ,t e ),S i ,σ} represents the data acquisition event of an intelligent connected vehicle, where t s and te S represents the start and end times of the data collection process. i ∈S, where S represents the set of all types of driving data that the current data acquisition device can collect inside the vehicle. i This indicates the data type included in the driving data collected in the current time period, σ represents a summary of all driving data collected in the current time period, and the data collection event is reported in the form of a periodic event record;

[0050] If the data acquisition device detects the security violation event, it will no longer report the data acquisition event.

[0051] As described above, the monitoring of intelligent connected vehicle data collection events adopts a periodic event reporting method, that is, the traceable information of the collected data is periodically reported to the blockchain at certain time intervals. Meanwhile, the specific intelligent connected vehicle data is stored on the data collection device and is not uploaded to the blockchain, thus minimizing the overhead of blockchain uploading. Furthermore, if the data collection device detects a security violation, it will no longer report the intelligent connected vehicle data collection event. This is because detecting a security violation indicates that the device may have been compromised, and subsequent data collection would be unreliable. Continuing to monitor would waste bandwidth and transaction fees. The absence of a collection record on the blockchain also provides implicit information to potential data users, suggesting that subsequent data collection by the device may be unreliable, as data loss is also a security violation. This ensures that even if the device is attacked and unable to upload data, potential data users will still be aware that the device may have been compromised.

[0052] Furthermore, step S1 also includes:

[0053] The secure area and the normal area inside the trusted hardware are physically isolated, and the program implemented in the secure area is defined to be able to be called in the normal area through a specific API and cannot be modified or inspected by the program in the normal area.

[0054] The drivers for the Hall sensor and the permanent signal monitoring sensor are placed in a safe area and assigned FIQ priority, while the data acquisition device is also placed in a safe area.

[0055] As described above, after addressing the worst-case scenario of physical attacks, the remaining challenge is to consider software attacks. By combining trusted hardware with a trusted execution environment (TEX) monitoring and on-chain process, the trustworthiness and security of the software layer can be ensured. This involves physically isolating the secure area from the ordinary area within the trusted hardware, granting the secure area the highest security privileges. Programs implemented in the secure area can only be accessed through specific APIs in the ordinary area, and programs in the secure area cannot be modified or inspected by programs in the ordinary area. This effectively mitigates privilege escalation attacks. Therefore, the secure area can be used to execute security-critical tasks, while the ordinary area can execute non-security tasks. To ensure the system operates as expected, the drivers for Hall effect sensors and permanent signal monitoring sensors can be placed in the secure area and assigned a higher FIQ priority to achieve better real-time monitoring performance. Simultaneously, the collection and monitoring of data from intelligent connected vehicles is also placed in the secure area to ensure the security and trustworthiness of critical tasks.

[0056] Further, step S3 specifically includes:

[0057] Define the first algorithm, the second algorithm, and the third algorithm;

[0058] The driving data that does not violate safety regulations is placed in the first algorithm, and the driving data C is compared with the legal pattern Γ by the second algorithm to determine its credibility.

[0059] If driving data C violates the legal pattern Γ, a safety violation event is immediately generated and uploaded to the blockchain. Simultaneously, the current data acquisition device is set to untrusted, and driving data collected by the data acquisition device within the current period is verified using the third algorithm before being uploaded to the blockchain. Specifically:

[0060] Obtain the current system clock t, and package the driving data C to be uploaded into the record (t, C, π), where π is a measure of data reliability. The verifier uses this to verify that the driving data C comes from a reliable source, and then checks whether additional data needs to be transmitted. If so, it stores it in F. c Then use the session key syt from the upload protocol. sk F c ||(t,C,π) is encrypted and then uploaded to the blockchain;

[0061] TEE sk F is a private key used only in the trusted execution environment. c This is a data storage area used to temporarily cache and retransmit data.

[0062] As described above, for the sake of simplicity, all the data collected by the sensors is first stored in the first algorithm. The actual program is simply processed by different interrupt entry handlers. Then, the second algorithm is used to determine whether the data conforms to the predefined legal pattern. Finally, the third algorithm is used to verify the data before it is uploaded to the blockchain, effectively ensuring the reliability of the data.

[0063] Please refer to Figure 3 A trusted data acquisition terminal for intelligent connected vehicles includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps in the trusted data acquisition method for intelligent connected vehicles as described above.

[0064] As described above, the beneficial effects of this invention are as follows: Based on the same technical concept, and in conjunction with the aforementioned intelligent connected vehicle data trusted acquisition method, an intelligent connected vehicle data trusted acquisition terminal is provided. By employing trusted hardware to construct a trusted execution environment, a trusted environment monitoring system, and a trusted data tracking system, driving data is collected in real time within the trusted execution environment. Combined with the real-time monitoring of safety violations, periodic events, and sudden events by the trusted environment monitoring system and the trusted data tracking system, the credibility of the collected driving data is ensured. Finally, the trusted driving data and the monitored periodic events and sudden events are uploaded to the blockchain through a consensus protocol, effectively reducing the impact of security protection on system performance and ensuring that both on-chain and off-chain data are trusted.

[0065] This invention provides a reliable data collection method and terminal for intelligent connected vehicles, mainly applied in scenarios involving reliable data collection from intelligent connected vehicles. The following detailed description is provided in conjunction with specific embodiments:

[0066] Please refer to Figure 1 and Figure 2 Embodiment 1 of the present invention is as follows:

[0067] A reliable data collection method for intelligent connected vehicles, such as Figure 1 As shown, the steps include:

[0068] S1. Build a trusted execution environment, a trusted environment monitoring system, and a trusted data tracing system using trusted hardware.

[0069] The system includes an intelligent connected vehicle data tracking system designed on the data acquisition equipment to continuously monitor periodic and sudden events in the trusted execution environment. The system uses a trusted environment with trusted hardware for continuous monitoring and can systematically upload the monitored data from the trusted hardware and trusted execution environment to the blockchain.

[0070] like Figure 2 As shown, it also includes:

[0071] By physically isolating the secure area and the normal area within the trusted hardware, the secure area possesses the highest security privileges. In this embodiment, programs implemented in the secure area can only be invoked in the normal area via specific APIs, and programs in the secure area cannot be modified or inspected by programs in the normal area. This effectively mitigates privilege escalation attacks. Therefore, the secure area can be used to perform security-critical tasks, such as trusted data collection, security violation monitoring, and data encryption and decryption; while the normal area can perform non-security tasks, such as human-computer interaction or packet routing and forwarding.

[0072] S2. Real-time collection of driving data based on the trusted execution environment, monitoring of safety violations in the trusted execution environment based on the trusted environment monitoring system, and continuous monitoring of periodic and sudden events in the trusted execution environment based on the trusted data tracking system.

[0073] In this embodiment, driving data is collected in real time based on a trusted execution environment, specifically as follows:

[0074] In a trusted execution environment, driving data is collected in real time through data acquisition devices in intelligent connected vehicles. These devices include the central gateway, T-box, edge computing gateway, and intelligent computing unit of the intelligent connected vehicle. Each data acquisition device is equipped with trusted sensors and permanent signal lines. The permanent signal lines are used to interact and coordinate with other ECU control units in the intelligent connected vehicle, while the trusted sensors are used to acquire the driving data collected in real time by the data acquisition devices.

[0075] In other words, the data acquisition device can be a device with multiple sensors on a smart connected vehicle. With the increasing demands for vehicle intelligence, high computing power, and information security compliance, such devices are mostly designed with high-performance processor chips with a reliable hardware architecture, thus enabling effective and reliable data acquisition from the vehicle.

[0076] In this embodiment, periodic events are defined as driving data collected periodically from the data acquisition device, and sudden events are sudden changes in the state of the data acquisition device.

[0077] S3. Using a consensus protocol, driving data that does not violate safety regulations, as well as monitored periodic and sudden events, are uploaded from the trusted execution environment to the blockchain.

[0078] In this embodiment, a trusted execution environment, a trusted environment monitoring system, and a trusted data tracking system are constructed using trusted hardware. This allows for real-time collection of driving data within the trusted execution environment. The trusted environment monitoring system and trusted data tracking system monitor safety violations, periodic events, and emergencies in real time to ensure the credibility of the collected driving data. Finally, the trusted driving data and the monitored periodic and emergencies are uploaded to the blockchain through a consensus protocol, effectively reducing the impact of security protection on system performance and ensuring that both on-chain and off-chain data are trustworthy.

[0079] Please refer to Figure 2 Embodiment two of the present invention is as follows:

[0080] A reliable data collection method for intelligent connected vehicles, based on the above embodiment one, further includes the following step before step S2:

[0081] Predefined safety violations include the opening of the data acquisition equipment casing, abnormality of the permanent signal line of the data acquisition equipment, and loss of driving data.

[0082] In this embodiment, before collecting data from intelligent connected vehicles, security requirements need to be clearly defined, and possible violations of these requirements must be identified. Since the data collected by the data acquisition device needs to be stored within the device, the trustworthiness of the acquisition device itself must be guaranteed to ensure data reliability. For embedded devices, the worst-case attack is often referred to as a "hardware attack" or "physical attack" because these attacks directly target the device's hardware, are often difficult to defend against, and have significant destructive power. Common examples include stealing encryption keys through side-channel attacks, tampering with firmware to inject arbitrary code, and physically damaging storage media. Therefore, it is necessary to consider the worst-case physical attack, i.e., to monitor physical-level attacks. Trusted sensors are deployed to monitor the integrity of the data acquisition device's casing. Once unauthorized opening is detected, the sensor will trigger an alarm. In actual operation, the device's casing is sealed after it is pre-installed in the vehicle, and disassembly is prohibited. Simultaneously, the device's permanent signal is connected to the vehicle's constant power supply. If the device is removed from the vehicle, a power outage can be detected. Based on these security requirements, this embodiment defines possible violations of security requirements as described in the aforementioned security violation items.

[0083] In this embodiment, step S2 involves real-time collection of vehicle data based on a trusted execution environment, specifically as follows:

[0084] Trusted sensors periodically acquire driving data collected in real time by data acquisition devices and convert it into digital timed records. Each digital timed record is represented as (t, C, π), where t is the timestamp when the record is created, C is the set of driving data acquired by different types of trusted sensors, and π is a measure of data credibility or proof of the authenticity of the digital timed record.

[0085] If the digital timing records generated at the time are represented as a digital entity record chain α in chronological order, then record chain α is represented as:

[0086] α=(t0,C0,π0),…,(t i C i ,π i ),… (1).

[0087] The record chain α satisfies three constraints: all relevant records should accurately reflect the actual state of the physical world; events should be captured in real time in the form of records after they occur; and records should be uploaded to the blockchain and should not be lost or delayed.

[0088] The actual driving data to be uploaded by each trusted sensor is represented as follows:

[0089] C=(H,P,Γ S (2).

[0090] Where, in the case of a sudden event, H and P are the actual monitored values, and Γ S Set to null; when it is a periodic event, H and P are normal valid values, Γ S These are the values ​​monitored by the data devices of actual intelligent connected vehicles.

[0091] The driving data C acquired by the trusted sensor is compared with the predefined legal pattern Γ to determine whether the recording is normal. The legal pattern Γ defines the correct pattern for normal driving data.

[0092] This involves mapping the physical world sensor entities in the device to digital record entities in the digital world. These records can be seen as digital descriptions of events, facilitating uploading and ensuring credibility.

[0093] After defining security violations, violations can be detected. Specifically, step S2 involves monitoring the trusted execution environment for security violations using a trusted environment monitoring system.

[0094] By using Hall effect sensors and permanent signal monitoring sensors placed inside the data acquisition equipment, it is determined whether the driving data C obtained by the trusted sensors contains any safety violations according to the predefined legal mode Γ. If so, the safety violation event is reported in the form of an emergency event record.

[0095] If the Hall sensor consistently outputs 0 when the device casing is intact, indicating that the casing is undamaged, then Γ is defined as follows: H ={0}, where H represents the actual binary data of the Hall sensor. If the applied magnetic flux density is higher than the magnetic flux density μ at the preset point, then H = 0; otherwise, H = 1. The permanent signal monitoring sensor always outputs 1 when the device's main power is not interrupted, indicating that the device is continuously connected to the vehicle's constant power supply. Therefore, Γ is defined as... P ={1}, where P represents the actual binary data of the permanent signal monitoring sensor. If the detected voltage is higher than the voltage threshold θ of the preset point, then P = 1; otherwise, P = 0.

[0096] Once security violations are defined, situations involving security violations can be monitored, and security violations can be reported in the form of emergencies. In other words, any security violation detected will be reported immediately to detect intrusion in a timely manner. Therefore, in order to capture these security violations, Hall effect sensors and permanent signal monitoring sensors can be placed in the data acquisition equipment for effective monitoring.

[0097] Furthermore, in this embodiment, step S2, which involves real-time acquisition of vehicle data using a data acquisition device, also includes:

[0098] Define Γ S ={(t s ,t e ),S i ,σ} represents the data acquisition event of an intelligent connected vehicle, where t s and t e S represents the start and end times of the data collection process. i ∈S, where S represents the set of all types of driving data that the current data acquisition device can collect inside the vehicle. i This indicates the data type of the driving data collected in the current time period. σ represents a summary of all driving data collected in the current time period and reports data collection events in the form of periodic events.

[0099] Furthermore, in this embodiment, if the data acquisition device detects a security violation, it will no longer report the intelligent connected vehicle data acquisition event.

[0100] In other words, the monitoring of data collection events for intelligent connected vehicles adopts a periodic event reporting method. That is, traceable information of the collected data is reported to the blockchain periodically at certain time intervals (the specific time interval can be determined according to the actual application). At the same time, the specific intelligent connected vehicle data is stored on the data collection device and is not uploaded to the blockchain, thus minimizing the overhead of blockchain uploading. Furthermore, if the data collection device detects a security violation, it will stop reporting the intelligent connected vehicle data collection event. This is because detecting a security violation indicates that the device may have been compromised, and subsequent data collection is unreliable. Continuing to monitor would waste bandwidth and transaction fees. At the same time, the absence of a collection record on the blockchain can further provide implicit information to potential users of the data, suggesting that the data collected by the device in the future may be unreliable. Since data record loss is also a security violation, this ensures that even if the device is attacked and unable to upload data online, potential data users can still know that the device may have been attacked.

[0101] In this embodiment, step S1 further includes:

[0102] The secure area and the normal area within the trusted hardware are physically isolated, and programs implemented in the secure area are defined to be callable only through specific APIs in the normal area and cannot be modified or inspected by programs in the normal area.

[0103] And again Figure 2 As shown, in this embodiment, the drivers for the Hall sensor and the permanent signal monitoring sensor are placed in a safe area and assigned FIQ priority, while the data acquisition device is also placed in a safe area.

[0104] After addressing the worst-case scenario of physical attacks, the remaining challenge is to consider software attacks, such as firmware tampering, privilege escalation attacks, and malicious eavesdropping. This involves designing a monitoring and on-chain process within a trusted execution environment, incorporating trusted hardware. Figure 2 As shown. To ensure the system operates as expected, the drivers for both the Hall sensor and the permanent signal monitoring sensor are placed in a secure area and assigned a higher FIQ priority (higher than the standard priority) to achieve better real-time monitoring performance. Simultaneously, the acquisition and monitoring of data from intelligent connected vehicles is also placed in a secure area to ensure the security and reliability of critical tasks. Furthermore, this paper also enables a secure boot mechanism for trusted hardware, performing pre-boot loading verification on each code image during startup to ensure the trustworthiness of the static startup code and prevent firmware tampering attacks.

[0105] In this embodiment, step S3 specifically includes:

[0106] Define the first algorithm, the second algorithm, and the third algorithm.

[0107] Driving data that does not violate safety regulations is placed in the first algorithm, and the driving data C is compared with the legal pattern Γ by the second algorithm to determine its credibility.

[0108] If driving data C violates the legal pattern Γ, a security violation event is immediately generated and uploaded to the blockchain. Simultaneously, the current data acquisition device is set to untrusted. Furthermore, driving data collected by the data acquisition device within the current period is verified using a third algorithm before being uploaded to the blockchain. Specifically:

[0109] Obtain the current system clock t, and package the driving data C to be uploaded into the record (t, C, π), where π is a measure of data reliability. The verifier uses this to verify that the driving data C comes from a reliable source, and then checks whether additional data needs to be transmitted. If so, it stores it in F. c Then use the session key syt from the upload protocol. sk F c ||(t,C,π) is encrypted and then uploaded to the blockchain. TEE is used as the encryption method. sk F is a private key used only in a trusted execution environment. c This is a data storage area used to temporarily cache and retransmit data.

[0110] In this embodiment, the specific definitions of the first algorithm and the second algorithm are shown in Table 1 and Table 2:

[0111] Table 1:

[0112]

[0113] Table 2:

[0114]

[0115] In Table 1, H = ReadHallSensor() is the binary output of the Hall sensor, P = ReadPermanentSignalSensor() is the binary output of the permanent signal monitoring sensor, and Γ S =ReadOtherSensorsData() represents the value monitored by the data devices of the actual intelligent connected vehicle; the flag in Table 2 H =H XORΓ H This indicates whether the actual value and the standard value are the same; if they are different, the flag is non-zero. P =P XORΓ P This indicates whether the actual value and the standard value are the same; if they are different, the flag is non-zero. H ||flag P This indicates the monitoring result; a non-zero value indicates that an anomaly was detected.

[0116] For simplicity, all sensor-collected data is initially stored in the first algorithm. The actual program processes this data using different interrupt handlers. A second algorithm then checks if the data conforms to a predefined valid pattern. Finally, a third algorithm verifies the data before uploading it to the blockchain, effectively ensuring data trustworthiness. Additionally, a lightweight blockchain client is installed in trusted hardware within the device. This client primarily stores and forwards the data to be uploaded to the blockchain to a remote full-node blockchain proxy, which then interprets the data and packages and publishes the transaction.

[0117] Please refer to Figure 3 Embodiment 3 of the present invention is as follows:

[0118] A trusted data acquisition terminal 1 for intelligent connected vehicles includes a memory 2, a processor 3, and a computer program stored on the memory 2 and executable on the processor 3. When the processor 3 executes the computer program, it completes the steps in the trusted data acquisition method for intelligent connected vehicles described in Embodiment 1 or Embodiment 2.

[0119] In summary, the present invention provides a trusted data collection method and terminal for intelligent connected vehicles, which uses trusted hardware, blockchain and physical sensing technology to build a trusted collection environment, effectively reducing the impact of security protection on system performance and ensuring that both on-chain and off-chain data are trusted.

[0120] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A method for intelligent networked vehicle data trusted collection, characterized in that, The method comprises the steps of: S1, constructing a trusted execution environment, a trusted environment monitoring system and a trusted data tracking system by using trusted hardware; S2, collecting driving data in real time based on the trusted execution environment, monitoring the security violations of the trusted execution environment based on the trusted environment monitoring system, and continuously monitoring the periodic events and sudden events of the trusted execution environment based on the trusted data tracking system; S3, using a consistency protocol to upload the driving data that does not violate the safety regulations and the periodic events and sudden events monitored from the trusted execution environment to the blockchain. 2.The intelligent networked vehicle data trusted collection method of claim 1, wherein, The driving data collected in real time based on the trusted execution environment is specifically: Real-time collection of driving data by a data collection device of the intelligent connected vehicle under the trusted execution environment, wherein the data collection device comprises a central gateway, a T-box, an edge computing gateway and a wisdom calculation unit of the intelligent connected vehicle; Trusted sensors and permanent signal lines are arranged on the data collection device, the permanent signal lines are used for interactive and cooperative work with other ECU control units on the intelligent connected vehicle, and the trusted sensors are used to obtain the driving data collected in real time by the data collection device. 3.The intelligent networked vehicle data trusted collection method of claim 2, wherein, The periodic event is the driving data collected by the data collection device and obtained periodically by the trusted sensors, and the sudden event is the change of the state suddenly occurred by the data collection device. 4.The intelligent networked vehicle data trusted collection method of claim 3, wherein, The step S2 further comprises the following steps before it: Defining security violation items in advance, including disassembly of the shell of the data collection device, abnormality of the permanent signal line of the data collection device and loss of driving data. 5.The intelligent networked vehicle data trusted collection method of claim 4, wherein, The driving data collected in real time based on the trusted execution environment in the step S2 is specifically: The trusted sensors obtain the driving data collected in real time by the data collection device in a time manner, and convert it into digital timing records, each of which is represented as (t, C, π), wherein t is a time stamp when the record is created, C is a set of driving data obtained by different types of trusted sensors, and π is a measure of data credibility; The digital timing records generated in a time sequence are represented as a digital entity record chain α, and the record chain α is represented as: a = (t0, C0, π0),..., (tn, Cn, πn) (1) i i i ,..., (tn, Cn, πn) (1)​​ The record chain α satisfies three constraint conditions, including that all related records should accurately reflect the actual state of the physical world, the event should be captured and recorded in real time in the form of a record after the event occurs, and the record should be uploaded to the blockchain and cannot be lost or delayed; The actual driving data to be uploaded by each trusted sensor is represented as: C = (H, P, Γ S ) (2); where H and P are the actual monitored values, Γ S Set to null value; H and P are normal legal values when it is a periodic event, Γ S is the value monitored by the data device of the actual intelligent connected vehicle; The driving data C obtained by the trusted sensors is compared with the predefined legal mode Γ to determine whether the record is normal, wherein the legal mode Γ defines the correct mode of normal driving data. 6.The intelligent networked vehicle data trusted collection method of claim 5, wherein, The security violation monitoring of the trusted execution environment by the trusted environment monitoring system in the step S2 is specifically: The driving data C obtained by the trusted sensors is determined according to the predefined legal mode Γ by the Hall sensor and the permanent signal monitoring sensor placed in the data collection device to determine whether the driving data C obtained by the trusted sensors has the security violation item, and if so, the security violation event is reported in the form of a record of the sudden event; wherein the Hall sensor always outputs 0 if the device housing is not disassembled, indicating that the device housing is intact, then define H = {0}, H represents the actual binary data of the Hall sensor, if the applied magnetic flux density is higher than the magnetic flux density μ of the preset point, then H = 0, otherwise H = 1; The permanent signal monitoring sensor always outputs 1 when the main power of the device is not powered off, indicating that the device is continuously connected to the constant power on the vehicle, and is defined as Γ P ={1}, P represents the actual binary data of the permanent signal monitoring sensor, and if the detected voltage is higher than the preset voltage threshold θ, then P=1, otherwise P=0.

7. The intelligent network connected vehicle data trusted collection method of claim 6, wherein, The step S2 further includes: Definition Γ S = {(t s , t e ), S i , σ} as a data collection event of a smart connected vehicle, where t s and t e represent the start event and the end time of collecting driving data respectively, S i ∈ S, S represents a set of all types of driving data that can be collected by the data collection device in the vehicle, S i represents the data type contained in the driving data collected in the current time period, and σ represents a summary of all driving data collected in the current time period, which is reported in the form of a record of the periodic event. If the data collection device monitors the safety violation event, the data collection event is no longer reported. 8.The intelligent networked vehicle data trusted collection method of claim 7, wherein, The step S1 further includes: The secure area and the normal area in the trusted hardware are physically isolated, and the program implemented in the secure area is defined to be called by a specific API in the normal area and cannot be modified or checked by the program in the normal area; The driving program of the Hall sensor and the permanent signal monitoring sensor is placed in the secure area, and is assigned with FIQ priority, and the data collection device is also placed in the secure area. 9.The intelligent networked vehicle data trusted collection method of claim 6, wherein, The step S3 specifically includes: Defining a first algorithm, a second algorithm and a third algorithm; The driving data not violating the safety regulation is placed in the first algorithm, and the driving data C is compared with the legal mode Γ through the second algorithm to determine the credibility; If the driving data C violates the legal mode Γ, a safety violation event is immediately generated and uploaded to the blockchain, and the current data collection device is set as untrusted, and the driving data collected by the data collection device in the current period is verified through the third algorithm and then uploaded to the blockchain, specifically including: Obtain the current system clock t, and pack the driving data C to be uploaded into record (t, C, π), where π is a measure of data credibility, and the verifier checks whether the driving data C is from a trusted source after verifying it, and checks whether the data needs to be supplemented if so, and stores it in F c Then use the session key syt sk in the upload protocol to encrypt F c (t, C, π) and upload it to the blockchain; wherein TEE sk is a private key used only in the trusted execution environment, F c is a data store used to temporarily cache the patch data.

10. An intelligent networked vehicle data trusted collection terminal, characterized in that, The computer program stored in the memory and executable on the processor, when the processor executes the computer program, implements the steps of the intelligent networked vehicle data trusted collection method in any one of claims 1-9.