A cross-domain information security interaction system based on a security chip

By employing a secure chip between domain controllers to achieve cross-domain signature verification, the problem of trusted state interaction verification between domain controllers is solved, thereby improving the security and protection capabilities of vehicle data.

CN122640184APending Publication Date: 2026-08-25HUIZHOU DESAY SV AUTOMOTIVE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610751881.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-28
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

In existing technologies, there is a lack of real-time trusted state interaction verification between domain controllers, network ports and CAN buses are easily accessed illegally, vehicle data is easily leaked, and data security is insufficient, especially when keys are lost or illegally copied.

Method used

A secure chip is used to implement cross-domain signature verification between domain controllers. Bidirectional signature verification is performed through a data interaction channel. The primary domain controller and the subdomain controller verify each other. The combination of timestamp and time window information sequence ensures the legitimacy and security of the interaction.

Benefits of technology

It improves the security of data interaction between domain controllers, prevents unauthorized access and data leakage, and enhances the security of vehicle data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122640184A_ABST
    Figure CN122640184A_ABST
Patent Text Reader

Abstract

The application discloses a cross-domain information security interaction system based on a security chip. The system comprises a plurality of domain controllers and a data interaction channel; each of the domain controllers is provided with a security chip; the plurality of domain controllers comprise a main domain controller and at least one sub-domain controller; the security chips in the plurality of domain controllers are connected with the data interaction channel, and the data interaction channel is used for data interaction between any two domain controllers; wherein, any two domain controllers comprise a first domain controller and a second domain controller; the security chip is used for mutual signature verification between the first domain controller and the second domain controller; wherein, the mutual signature verification comprises signature verification of the second domain controller by the first domain controller and signature verification of the first domain controller by the second domain controller. Cross-domain signature verification between decentralized domain controllers can be realized, and the security of vehicle data can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of information technology, and in particular to a cross-domain information security interaction system based on a security chip. Background Technology

[0002] In existing technologies, the Secure Element (SE) chip primarily performs encryption and signature verification for the domain controller (hereinafter referred to as the domain controller) itself, as well as signature verification for data interaction with the cloud. The encryption and signature verification process typically occurs during the initial startup of the domain controller, involving a secure boot and key generation by the SE chip. Some integrated Telematics Box (TBOX) solutions interact with the cloud and periodically perform signature verification. Furthermore, some solutions with a central gateway also perform key verification and other tasks on the Over-the-Air (OTA) upgrade package to ensure secure firmware upgrades.

[0003] However, the above solutions generally focus on the secure startup of each domain controller and the process of interacting with the cloud and central gateway. They do not perform real-time interactive verification of the trusted status between domain controllers. For controllers with Ethernet access capabilities, such as central gateways and central domain controllers, their network ports and CAN buses are easily accessed illegally and data is intercepted. In particular, for newly connected devices, there is a lack of effective access authentication mechanisms.

[0004] Furthermore, based on the TBOX and central gateway acting as the key issuers, they have higher master-slave role configuration privileges. If the central gateway or TBOX is replaced, the slave devices, as the access recipients, are easily attacked illegally through data channels such as network ports. Similarly, since each domain control key in a vehicle is generally generated only once, if the key is lost or illegally copied or tampered with through the SE chip, it can easily lead to the leakage of vehicle data such as personal data in the vehicle system and area controller data. Summary of the Invention

[0005] This invention provides a cross-domain information security interaction system based on a security chip, which can realize cross-domain signature verification between domain controllers and improve the security of vehicle data.

[0006] In a first aspect, embodiments of the present invention provide a cross-domain information security interaction system based on a security chip, the system comprising: multiple domain controllers and a data interaction channel; each of the domain controllers is equipped with a security chip; the multiple domain controllers include a master domain controller and at least one sub-domain controller; The security chips in the plurality of domain controllers are all connected to the data interaction channel, which is used for data interaction between any two domain controllers; wherein, any two domain controllers include a first domain controller and a second domain controller; the first domain controller is different from the second domain controller, and the first domain controller is either a master domain controller or a sub-domain controller, and the second domain controller is either a master domain controller or a sub-domain controller. The security chip is used for mutual signature verification between the first domain controller and the second domain controller; wherein, the mutual signature verification includes signature verification by the first domain controller to the second domain controller and signature verification by the second domain controller to the first domain controller.

[0007] This invention discloses a cross-domain information security interaction system based on a security chip. The system includes: multiple domain controllers and a data interaction channel; each domain controller is equipped with a security chip; the multiple domain controllers include a master domain controller and at least one sub-domain controller; the security chips in the multiple domain controllers are all connected to the data interaction channel, which is used for data interaction between any two domain controllers; wherein, any two domain controllers include a first domain controller and a second domain controller; the first domain controller and the second domain controller are different, and the first domain controller is either a master domain controller or a sub-domain controller, and the second domain controller is either a master domain controller or a sub-domain controller; the security chip is used for mutual signature verification between the first domain controller and the second domain controller; wherein, mutual signature verification includes signature verification by the first domain controller to the second domain controller and signature verification by the second domain controller to the first domain controller. The cross-domain information security interaction system based on a security chip provided by this invention can realize decentralized cross-domain signature verification between domain controllers, which can improve the security of vehicle data. Attached Figure Description

[0008] Figure 1 This is a schematic diagram of the structure of a cross-domain information security interaction system based on a security chip, according to Embodiment 1 of the present invention. Detailed Implementation

[0009] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.

[0010] Example 1 Figure 1 This is a schematic diagram of the structure of a cross-domain information security interaction system based on a security chip, as provided in Embodiment 1 of the present invention. Figure 1As shown, the system comprises multiple components: a primary domain controller, at least one subdomain controller, and data interaction channels. The primary domain controller and each subdomain controller are equipped with a security chip.

[0011] The data exchange channel can be an Ethernet (ETH) communication channel or a Controller Area Network (CAN) communication channel. The main domain controller and each subdomain controller include at least one functional unit, which can be a System on Chip (SoC), Microcontroller Unit (MCU), TBOX, or Bluetooth digital key, etc.

[0012] The security chip can be a SE chip, specifically a dual-port or multi-port SE chip, meaning it includes multiple communication interfaces. These interfaces are used by multiple domain controllers to access the security chip. The communication interfaces can be Serial Peripheral Interface (SPI), Inter-Integrated Circuit (I2C), or Secure Digital Input Output (SDIO). Each communication interface is connected as a SLAVE mode to a functional unit within the domain controller.

[0013] In this embodiment, the security chips in multiple domain controllers are all connected to a data interaction channel, which is used for data interaction between any two domain controllers. These two domain controllers include a first domain controller and a second domain controller. The first domain controller and the second domain controller are different, and the first domain controller is either the master domain controller or a sub-domain controller, while the second domain controller is either the master domain controller or a sub-domain controller. That is, bidirectional signature verification is possible between any two domain controllers in the system.

[0014] In this embodiment, the security chip is used for mutual signature verification between the first domain controller and the second domain controller; wherein, mutual signature verification includes the first domain controller verifying the signature of the second domain controller and the second domain controller verifying the signature of the first domain controller.

[0015] Specifically, the process of the first domain controller verifying the signature of the second domain controller can be as follows: the first domain controller accesses the security chip of the second domain controller through a data interaction channel to verify the signature of the second domain controller. The process of the second domain controller verifying the signature of the first domain controller can be as follows: the second domain controller accesses the security chip of the first domain controller through a data interaction channel to verify the signature of the first domain controller.

[0016] The first domain controller accessing the second domain controller's security chip via a data interaction channel can be understood as the first domain controller obtaining raw data, signature data, and the public key from the second controller's security chip through the data interaction channel. Similarly, the second domain controller accessing the first domain controller's security chip via a data interaction channel can be understood as the second domain controller obtaining raw data, signature data, and the public key from the first controller's security chip through the data interaction channel.

[0017] Optionally, the first domain controller may verify the signature of the second domain controller in the following manner: the first domain controller sends a signature verification request to the second domain controller through a data interaction channel; the security chip of the second domain controller processes the original data using a hash algorithm based on the signature verification request to obtain a first digest, and encrypts the first digest based on the private key to obtain signature data; the security chip of the second domain controller sends the original data, signature data, and public key to the security chip of the first domain controller through the data interaction channel; the security chip of the first domain controller processes the original data using a hash algorithm to obtain a second digest, and decrypts the signature data based on the public key to obtain a first digest; and performs a consistency check on the first digest and the second digest to obtain the signature verification result.

[0018] In this embodiment, if the first digest and the second digest are the same, it indicates that the second domain controller has passed the signature verification, and the second domain controller is legitimate. Other domain controllers in the system can then interact with the second domain controller.

[0019] Optionally, the second domain controller may verify the signature of the first domain controller in the following manner: the second domain controller sends a signature verification request to the first domain controller through a data interaction channel; the security chip of the first domain controller processes the original data using a hash algorithm based on the signature verification request to obtain a first digest, and encrypts the first digest based on the private key to obtain signature data; the security chip of the first domain controller sends the original data, signature data, and public key to the security chip of the second domain controller through the data interaction channel; the security chip of the second domain controller processes the original data using a hash algorithm to obtain a second digest, and decrypts the signature data based on the public key to obtain a first digest; and performs a consistency check between the second digest and the first digest to obtain the signature verification result.

[0020] In this embodiment, if the first digest and the second digest are the same, it indicates that the first domain controller has passed the signature verification, and the first domain controller is legitimate. Other domain controllers in the system can then interact with the first domain controller.

[0021] In this embodiment, the primary domain controller obtains timestamp information from a local clock source or a satellite positioning system and synchronizes the timestamp information to multiple subdomain controllers.

[0022] The timestamp information is used for mutual signature verification between any two domain controllers. The timestamp information can be a 1588 timestamp. The master domain controller synchronizes the timestamp information to multiple sub-domain controllers, ensuring time synchronization among all domain controllers in the system. In this embodiment, due to the performance limitations of the security chip itself, data conflicts may occur when domain controllers perform bidirectional cross-signature verification operations. Therefore, a 1588 clock source is used as the reference clock, and bidirectional signature verification operations between domain controllers are performed at preset time intervals.

[0023] In this embodiment, the primary domain controller obtains the time window information sequence from the cloud and sends the time window sequence to multiple subdomain controllers.

[0024] The time window information sequence includes the domain controller verifying the signature and the domain controller being verified within that time window. In this application scenario, the order and timing of signature verification among the domain controllers are pre-set by the cloud. For example, assuming the system includes a primary domain controller A, subdomain controllers B, C, D, and E, the time window information sequence can be represented by a matrix. The time window information sequence corresponding to a signature verification request initiated by the primary domain controller can be represented as follows: Where 1, 2...n are the period numbers, This represents the time window during which the primary domain controller A initiates signature verification to the subdomain controller B within the i-th cycle. This represents the time window during which the primary domain controller A initiates signature verification to the subdomain controller C within the i-th cycle. This represents the time window during which the primary domain controller A initiates signature verification to the subdomain controller D within the i-th cycle. This represents the time window during which the primary domain controller A initiates a signature verification request to the subdomain controller E within the i-th period. The sequence of time window information corresponding to the signature verification request initiated by the subdomain controller B can be represented as follows: Where 1, 2...n are the period numbers, This represents the time window during which subdomain controller B initiates signature verification to primary domain controller A within the i-th cycle. This represents the time window during which subdomain controller B initiates signature verification to subdomain controller C within the i-th cycle. This represents the time window during which subdomain controller B initiates signature verification to subdomain controller D within the i-th cycle. This represents the time window during which subdomain controller B initiates signature verification to subdomain controller E within the i-th period. The time window information sequence corresponding to signature verification requests initiated by subdomain controllers C, D, and E is similar to that described above and will not be repeated here.

[0025] In this embodiment, since the aforementioned time window information sequence has been synchronized from the primary domain controller to each subdomain controller, the process of the first domain controller verifying the signature of the second domain controller can be as follows: when the time reaches the corresponding first time window, the first domain controller verifies the signature of the second domain controller. Similarly, the process of the second domain controller verifying the signature of the first domain controller can be as follows: when the time reaches the corresponding second time window, the second domain controller verifies the signature of the first domain controller.

[0026] Taking the above time window information sequence as an example, if the time reaches... If the primary domain controller A initiates signature verification to the subdomain controller B, then similarly, if the time arrives... Then, subdomain controller B initiates signature verification to subdomain controller C.

[0027] In this application scenario, for signature verification outside the time window, the domain controller being verified can determine whether to respond to the signature verification request based on the deviation between the time point initiating the signature verification and the corresponding time window, thereby avoiding the risk of information leakage of the domain controller being verified due to the signature verification request being sent illegally.

[0028] Optionally, the primary domain controller obtains a sequence of window offset information from the cloud; the window offset information corresponds one-to-one with the time window information; and the window offset information includes a first threshold, a second threshold, and a third threshold, wherein the first threshold is less than the second threshold, and the second threshold is less than the third threshold.

[0029] In this embodiment, while setting the time window information, the cloud also sets the window offset information corresponding to each time window. The window offset information includes three thresholds, which are used to help the domain controller being verified determine whether to respond to the verification request.

[0030] Specifically, the deviation between the time point when the domain controller initiates the signature verification request and the corresponding time window is determined; if the deviation is less than or equal to a first threshold, the domain controller being verified responds to the signature verification request; if the deviation is greater than the first threshold and less than or equal to a second threshold, the domain controller verifying the signature performs two or more signature verifications on the domain controller being verified; if the deviation is greater than the second threshold and less than or equal to a third threshold, the domain controller being verified rejects the signature verification request.

[0031] The time window includes the start time and the end time. The deviation between the time when the domain controller initiates the signature verification request and the corresponding time window can be understood as: the time when the domain controller initiates the signature verification request is earlier than the start time or the time when the domain controller initiates the signature verification request is later than the end time.

[0032] Specifically, if the deviation is less than or equal to the first threshold, it indicates that the domain controller initiating the signature verification request was at the correct timing, and the domain controller being verified responded normally to the signature verification request. If the deviation is greater than the first threshold and less than or equal to the second threshold, it indicates that the domain controller initiating the signature verification request was at an off-time, and the domain controller performing signature verification on the domain controller being verified will perform secondary or multiple verifications. If the deviation is greater than the second threshold and less than or equal to the third threshold, it indicates that the domain controller initiating the signature verification did not initiate the verification within the preset time window, and the domain controller being verified will reject the signature verification request.

[0033] In this embodiment, as time progresses, an updated sequence of time window information and a sequence of window offset information are obtained from the cloud for each set duration to prevent them from being cracked and reused.

[0034] This invention provides a cross-domain information security interaction system based on a security chip. The system includes: multiple domain controllers and a data interaction channel; each domain controller is equipped with a security chip; the multiple domain controllers include one master domain controller and at least one sub-domain controller; the security chips in the multiple domain controllers are all connected to the data interaction channel, which is used for data interaction between any two domain controllers; wherein, any two domain controllers include a first domain controller and a second domain controller; the first domain controller and the second domain controller are different, and the first domain controller is either a master domain controller or a sub-domain controller, and the second domain controller is either a master domain controller or a sub-domain controller; the security chip is used for mutual signature verification between the first domain controller and the second domain controller; wherein, mutual signature verification includes the first domain controller verifying the signature of the second domain controller and the second domain controller verifying the signature of the first domain controller. This system enables decentralized cross-domain signature verification between domain controllers, thereby improving the security of vehicle data.

[0035] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0036] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A cross-domain information security interaction system based on a security chip, characterized in that, The system includes: multiple domain controllers and data interaction channels; each domain controller is equipped with a security chip; the multiple domain controllers include a primary domain controller and at least one subdomain controller. The security chips in the plurality of domain controllers are all connected to the data interaction channel, which is used for data interaction between any two domain controllers; wherein, any two domain controllers include a first domain controller and a second domain controller; the first domain controller is different from the second domain controller, and the first domain controller is either a master domain controller or a sub-domain controller, and the second domain controller is either a master domain controller or a sub-domain controller. The security chip is used for mutual signature verification between the first domain controller and the second domain controller; wherein, the mutual signature verification includes the first domain controller verifying the signature of the second domain controller and the second domain controller verifying the signature of the first domain controller.

2. The system according to claim 1, characterized in that, The security chip includes multiple communication interfaces; the multiple communication interfaces are used by the multiple domain controllers to access the security chip.

3. The system according to claim 1, characterized in that, The first domain controller verifies the signature of the second domain controller, including: the first domain controller accessing the security chip of the second domain controller through the data interaction channel to verify the signature of the second domain controller; the second domain controller verifies the signature of the first domain controller, including: the second domain controller accessing the security chip of the first domain controller through the data interaction channel to verify the signature of the first domain controller.

4. The system according to claim 1, characterized in that, The primary domain controller obtains timestamp information from a local clock source or a satellite positioning system and synchronizes the timestamp information to the multiple subdomain controllers; wherein, the timestamp information is used for mutual signature verification between any two domain controllers.

5. The system according to claim 4, characterized in that, The primary domain controller obtains a time window information sequence from the cloud and sends the time window sequence to the plurality of subdomain controllers; wherein, each time window information in the time window information sequence includes the domain controller that verifies the signature and the domain controller whose signature is being verified within the time window.

6. The system according to claim 5, characterized in that, The first domain controller verifies the signature of the second domain controller, including: when the time reaches the corresponding first time window, the first domain controller verifies the signature of the second domain controller; The second domain controller verifies the signature of the first domain controller, including: when the time reaches the corresponding second time window, the second domain controller verifies the signature of the first domain controller.

7. The system according to claim 5, characterized in that, The primary domain controller obtains a sequence of window offset information from the cloud; the window offset information corresponds one-to-one with the time window information; and the window offset information includes a first threshold, a second threshold, and a third threshold, wherein the first threshold is less than the second threshold, and the second threshold is less than the third threshold.

8. The system according to claim 7, characterized in that, The deviation between the time point when the domain controller initiates the signature verification request and the corresponding time window is determined; if the deviation is less than or equal to the first threshold, the domain controller being verified responds to the signature verification request; if the deviation is greater than the first threshold and less than or equal to the second threshold, the domain controller verifying the signature performs a second or multiple signature verifications on the domain controller being verified; if the deviation is greater than the second threshold and less than or equal to the third threshold, the domain controller being verified rejects the signature verification request.

9. The system according to claim 2, characterized in that, The first domain controller verifies the signature of the second domain controller, including: The first domain controller sends a signature verification request to the second domain controller through the data interaction channel; The security chip of the second domain controller processes the original data using a hash algorithm based on the signature verification request to obtain a first digest, and encrypts the first digest based on the private key to obtain signature data; the security chip of the second domain controller sends the original data, the signature data, and the public key to the security chip of the first domain controller through the data interaction channel. The security chip of the first domain controller processes the original data using a hash algorithm to obtain a second digest, and decrypts the signature data based on the public key to obtain a first digest; and performs a consistency check on the first digest and the second digest to obtain a signature verification result.

10. The system according to claim 2, characterized in that, The second domain controller performs signature verification on the first domain controller, including: The second domain controller sends a signature verification request to the first domain controller through the data interaction channel; The security chip of the first domain controller processes the original data using a hash algorithm based on the signature verification request to obtain a first digest, and encrypts the first digest based on the private key to obtain signature data; the security chip of the first domain controller sends the original data, the signature data and the public key to the security chip of the second domain controller through the data interaction channel; The security chip of the second domain controller processes the original data using a hash algorithm to obtain a second digest, and decrypts the signature data based on the public key to obtain a first digest; and performs a consistency check on the second digest and the first digest to obtain the signature verification result.